{"version":"2.1.284","anchor":"plugin-marketplace-sources-embedded-credentials-stripped-s","canonical_anchor":"plugin-marketplace-sources-embedded-credentials-stripped-s","heading":"Plugin marketplace sources can now have credentials removed and odd URLs refused","tier":"notice","area":"Plugins","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/plugin-marketplace-sources-embedded-credentials-stripped-s","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Plugin marketplace sources can now have credentials removed and odd URLs refused\n\nClaude Code now has a check that strips usernames, passwords and headers from plugin marketplace sources and refuses suspicious URLs\n\n**Unclear.** It is not clear when Claude Code runs this check, for example when saving or when displaying marketplace sources.\n\n**What**\n\nA plugin marketplace is a place Claude Code can find and install plugins (add-on packages) from. Each marketplace has a source, which says where it lives: a web address, a git repository, an npm package, or an entry in your settings.\n\nClaude Code now has a check that cleans up these sources. It removes the username and password from a source's web address and drops any `headers` or `headersHelper` entries. For npm tarball addresses (a direct download link for an npm package), it also removes the username, password, query string and anything after a `#`.\n\nThe check refuses a source when:\n\n- its web address has a query string (the part after `?`) or a fragment (the part after `#`)\n\n- its path does not match what is expected\n\n- it contains an `@` or `#` whose meaning is ambiguous\n\n- it is a settings plugin whose source is a command\n\n**Why**\n\nThis looks designed to keep marketplace credentials out of a form that could be stored or passed along to others.\n\n- Area: Plugins\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}