Where tools run
In your browser
Sent to a server
Nothing you type
Sign-up needed
None
Share link settings
In the URL hash

Handling Secrets

Some tools work with values you would not paste into a chat: database passwords, security keys, IP allowlists. Here is how BucketWP handles them and what to do on your side.

Database passwords

The password you type into the WP-Config Generator is only used to build the file in the page. It is not sent anywhere, but it is a field value, so it is included in a share link. Clear the field before pressing Share Link.

Keys and salts

The eight keys and salts in wp-config.php are 64-character random strings made by your browser when the page loads. Each visit gets a new set and they are never part of a share link.

Reused saltswp-config.php

Copying salts from another site or a tutorial means anyone who has seen them can forge login cookies.

define( 'AUTH_KEY', 'put your unique phrase here' );
Fresh per siteGenerated

Generate a new file for every site. The salts are unique to that download.

define( 'AUTH_KEY', '64 random characters' );

After a breach

Generate a new set of keys and salts and replace the old ones. Every logged-in user is signed out, including any attacker using a stolen cookie. Then change the database password and update DB_PASSWORD to match.