Current runtime state#
Local installation and records#
The foundation stores a local installation UUID, account/registration state and module/tool entitlement records. Registration states are fresh, registration_required and registered; entitlement states are active, pending, revoked and expired.
The active-entitlement checker considers state and validity dates. Stored payload/signature fields do not prove signature validation or remote activation.
First-party subjects#
All seven current builtin manifests declare tier=free and requires_entitlement=true, with stable module subjects and static tool subjects. This metadata describes an architectural boundary; it does not mean execution currently requires an issued free entitlement.
Dynamic external MCP tools have no YAADMIN per-tool entitlement subjects. The validator preserves that separation.
Planned / architectural direction#
Not verified#
Remote license activation, email verification, purchase/checkout, a licensing server client and concrete activation API are not verified in the source. An explicit Core pricing/free-distribution contract and a future no-connection-fee guarantee were not established by this technical audit.
The Update Manager endpoint contracts are unrelated to licensing activation. This page describes YAADMIN application source, not a WordPress licensing plugin.