Skip to content
ECZ-IDPlugin

The boundary

Permissions and integrity

A plugin asks for permissions, and someone has to decide whether to grant them. An ECZ-ID helps with the part of that decision it can actually help with — who is asking — and says nothing about the rest.

What it answers

Who is publishing this, and is that the same publisher as last time

Those two questions are answerable from a public record, and today they are usually answered by guessing from a store account name.
  • The publisher is named

    The record names the organisation that operates the plugin, as its Parent, with the date the declaration was made.

  • The identity is stable

    The same plugin keeps the same ECZ-ID across releases, renames and store moves, so a reader can tell continuity from coincidence.

  • The listings are declared

    Each store listing is recorded as a binding, so a second listing claiming to be the same plugin either is bound or is not.

  • The record is re-checkable

    Nothing is taken on the strength of a badge. A reader follows it to the record and reads the current state for themselves.

What it is not

A Passport is not a permission approval and not a certification

An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything.
  • Holding an ECZ-ID does not mean a marketplace has reviewed the plugin. Marketplaces run their own review processes, under their own rules, and an ECZ-ID is not an input to any of them.
  • It does not mean the permissions a plugin requests are appropriate, minimal or safe. That judgement belongs to whoever is granting them.
  • It does not mean the code has been read, tested, scanned or audited by anyone.
  • It does not grant, prove or imply authority to act. A binding shows a relationship has been declared; authority is a separate layer and is never carried by a Passport.
  • A VERIFIED or ASSURED Parent verifies the publishing organisation. It does not verify the plugin.

Optional

Plugin Publisher & Permission Integrity

Publisher-level identity and permission integrity across the plugins and apps you publish.

The boundary

It records what you publish and declare. It is not a marketplace review and not an approval.

It is optional in the strict sense: no part of it is needed to hold a free Plugin Passport, to publish its record or to have it resolved.

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.