Security, Updates, and Recovery

Step 1: Review Security Findings
Open Security and review HTTPS, headers, login protection, trusted proxy handling, origin access, file permissions, salts, XML-RPC, REST exposure, and commerce protections. Change one bounded control at a time so the exact setting can be reversed if authentication or public delivery fails.

Step 2: Verify the Release Identity
Open Builder settings and record the active version, immutable build hash, enabled modules, update channel, WordPress version, PHP version, database state, active theme, and companion requirements. The displayed version, manifest, ZIP hash, installed files, and asset query versions should describe one release.

Step 3: Prepare Recovery Before Updating
Keep a current database recovery point, the prior immutable plugin ZIP or directory, and any page or global layout data at risk. Confirm the recovery artifact is complete and readable before updating. A progress message or unfinished archive is not a rollback plan.

Step 4: Run Post-Update Regression
After the update, check public pages, Studio open and save, templates, mobile menus, forms, media, SEO output, commerce, cache behavior, and fresh logs. Confirm the updater reports no remaining Builder update only after the exact tested artifact and runtime behavior agree.
