Some tools work with values you would not paste into a chat: database passwords, security keys, IP allowlists. Here is how BucketWP handles them and what to do on your side.
Database passwords
The password you type into the WP-Config Generator is only used to build the file in the page. It is not sent anywhere, but it is a field value, so it is included in a share link. Clear the field before pressing Share Link.
Keys and salts
The eight keys and salts in wp-config.php are 64-character random strings made by your browser when the page loads. Each visit gets a new set and they are never part of a share link.
Copying salts from another site or a tutorial means anyone who has seen them can forge login cookies.
define( 'AUTH_KEY', 'put your unique phrase here' );
Generate a new file for every site. The salts are unique to that download.
define( 'AUTH_KEY', '64 random characters' );
After a breach
Generate a new set of keys and salts and replace the old ones. Every logged-in user is signed out, including any attacker using a stolen cookie. Then change the database password and update DB_PASSWORD to match.
