Keep license keys, activation tokens, download tickets and update credentials inside Hotel Booking Pro or the dedicated update service. Free remains usable without a license and must not contain Pro license or updater runtime. An expired installed Pro can continue its intentional runtime policy while updates and support are disabled; revoked, invalid, deactivated or incompatible states fall back to Free behavior. License loss must not delete bookings, tax lines, payment ledgers, OTA credentials or external inventory blocks.
For an Aurelia update, use the trusted HTTPS origin https://kimorapro.com/themes/aurelia and the native WordPress updater hook. Reauthorize immediately before download, reject redirects, verify the package identity and require a strictly newer version. Compare exact byte size and a constant-time SHA-256 digest, preflight the single aurelia/ ZIP root and fail with WP_Error before unpacking when any check fails. Do not enable automatic updates by default, and never accept a downgrade as an update offer.
Operator safeguards
- Back up the database and current packages before updating.
- Keep the accepted rollback bytes until the web smoke and compatibility banner are verified.
- Do not paste license or download values into logs or tickets.
- If a package is rejected, preserve the last valid installation and escalate the digest, origin or version mismatch with redacted evidence.