Developer Hooks & Filters
Filters for licensing, shortcode and rendered-site behavior.
v0.20.0 exposes filters that are especially useful for site-specific integrations.
ist_scan_shortcode
Controls whether a discovered shortcode should be executed by the scanner.
Conceptual example:
add_filter( 'ist_scan_shortcode', function ( $allowed, $tag, $full_shortcode, $post_id, $origin ) {
if ( 'dangerous_action_shortcode' === $tag ) {
return false;
}
return $allowed;
}, 10, 5 );
Use this when a shortcode performs an action or depends on a context that should not run during scanning.
ist_rendered_site_scan_request_args
Filters the WordPress HTTP request arguments used by the automatic rendered-site crawler.
add_filter( 'ist_rendered_site_scan_request_args', function ( $args, $url, $post_id ) {
// Site-specific request customization.
return $args;
}, 10, 3 );
ist_rendered_site_scan_url
Allows a site integration to alter the URL the rendered scanner requests for a specific content object.
ist_rendered_site_scan_max_segments_per_object
Controls the maximum rendered-discovery segments stored for one content object. The built-in default is designed to prevent pathological pages from creating an unbounded number of segments.
Treat scan hooks as backend integration points. Validate custom behavior carefully because they can affect whole-site scanning and automated provider usage.