Last updated 25 August 2026
The Pharos plugin sends us nothing. There is no account, no telemetry, and no server of ours involved in anything it does.
That is unusual enough to be worth stating plainly at the top. Pharos runs entirely on your own site. It has no “phone home”, and we could not identify your site if we wanted to. Everything below is the detail behind that sentence.
Pharos makes requests to two outside services, and to your own site. All of them exist to check your installation for problems.
| Destination | What is sent | When |
|---|---|---|
| api.wordpress.org WordPress.org |
Your WordPress version and locale, to fetch the official file checksums for your release. | When an assessment runs |
| api.wordpress.org via WordPress itself |
Pharos asks WordPress to refresh its own update information. WordPress then sends what it normally sends twice a day regardless: your site address, WordPress, PHP and database versions, locale, and the list of installed plugins and themes. Pharos adds nothing to this. | When an assessment runs |
| www.wpvulnerability.net WPVulnerability |
The directory slug of one component at a time — for example akismet. Nothing that identifies your site, and nothing about your users. |
When a vulnerability scan runs |
| Your own site | A request to your site’s own REST API, to see whether usernames are visible to anonymous visitors. It never leaves your server. | When an assessment runs |
Advisory results are cached on your site for twelve hours, so a scan does not repeat lookups it has already made.
These services have their own policies: WordPress.org privacy and WPVulnerability privacy.
Everything Pharos records is stored in your own WordPress database, on your own server. That is:
The activity log is the only place Pharos records anything about a person, and it records the same information your web server’s access log already holds. It exists so that a site owner can answer “what did this plugin change, and who asked for it?” — which is a reasonable thing to want from software that alters security settings.
Deleting the plugin removes all of it. Pharos ships an uninstall routine that clears its options, its cached advisory data, its scheduled task and its activity log.
pharos-secure.com is a set of static pages. It sets no cookies, runs no analytics or tracking scripts, and loads no third-party fonts or resources. Our web server keeps standard access logs, including IP addresses, for security and troubleshooting; these are retained for 30 days and then deleted.
If you email us we will hold that message, and your address, for as long as it takes to deal with your query and for a reasonable period afterwards in case you follow up. We do not add you to a mailing list.
A paid tier is planned in which our servers scan connected sites on a schedule and alert you when something changes. It does not exist yet, and nothing described above involves it.
When it launches it will necessarily involve holding an account and a record of the sites you connect, and this page will be updated before that happens rather than after. Two commitments we are willing to make in advance: Pharos will never hold your WordPress username or password, and payments will be handled by a third-party payment provider so that card details never reach our systems.
Under UK GDPR you may ask for a copy of any personal data we hold about you, ask us to correct or delete it, or object to how we are using it. Because the free plugin sends us nothing, in most cases the answer will be that we hold nothing at all — but ask, and we will tell you honestly.
If you are not satisfied with how we have handled a request you can complain to the Information Commissioner’s Office.
Data controller: James Betchley.
Email: privacy@pharos-secure.com
If this policy changes materially, the date at the top changes with it, and the previous versions remain available in the site’s public repository history.