# Infrastructure audit (read-only SSH) **Production modifications:** NONE **DNS modifications:** NONE ## Confirmed | Item | Value | How | |------|--------|------| | Domain | alyatrip.com | live HTTPS | | Host | de-fra-web2149.main-hosting.eu | `hostname` | | Provider | Hostinger shared (path `/home/u869888345/domains/alyatrip.com/public_html`) | path + plugins `hostinger*` | | SSH | port 65002 | used read-only | | PHP CLI | 8.5.4 NTS + OPcache | `php -v` | | WordPress | 7.1 | WP-CLI | | Cache | LiteSpeed Cache plugin present | plugins list | | Backups | WPvivid (`wpvivid-backup-mainwp`) | plugin present; **jobs not inspected** | | Firewall / CDN | LiteSpeed + Hostinger stack | **details UNKNOWN** | | Staging | **NOT CONFIRMED** | | | SMTP | **UNKNOWN** (wp_mail used in plugin) | | | SSL | HTTPS works on alyatrip.com | live browse | ## Not inspected (would require extra access) - Exact A/CNAME records - MariaDB version / table dumps (PII risk — not dumped) - php.ini FPM vs CLI mismatch - Cron crontab vs WP-Cron ## Secrets SSH/WP passwords are **not** stored in this documentation. --- ## Production vs sandbox Cockpit badge **SANDBOX** `VERIFIED LIVE`. Plugin vault stores `sand_` and `prod_` separately. Switching to production is an **ops gate**, not claimed as done. ## WordPress cron (plugin hooks) Scheduled (code): `alya_hs_cron_purge_logs`, `alya_hs_cron_ops_alerts`, `alya_hs_cron_ops_digest`, `alya_hs_cron_ops_tick`. Host crontab vs WP-Cron: `UNKNOWN`. ## Database MariaDB/MySQL: **not dumped** (PII). Tables exist per `Schema.php` when plugin is active. Live plugin path: `/home/u869888345/domains/alyatrip.com/public_html/wp-content/plugins/nuitee`. ## SSL / DNS HTTPS works on alyatrip.com. Exact A/CNAME: `UNKNOWN` (panel not used). DNS was **not** modified. ## PHP Requires ≥ 8.1 (plugin header). Live CLI 8.5.4. FPM vs CLI mismatch: `UNKNOWN`.