Skip to content
Uursy.recipes
Appearance
Colour profile

ursy.recipes · The instrument and the live record

How this instrument is built

The runtime that is really running on this site, the file-level fingerprint a reader compares against the other sites' to prove the bytes match — this page vouches for this host only — which module comes from where, the security posture exactly as configured, every correction we have published, and the way this page itself is made.

Runtime 2.5.16 on this host: 41 files fingerprinted on this host; a reader proves the same bytes run elsewhere by comparing this fingerprint with each other site's — this page vouches for this host only.

  • Every number carries its source, its window, the rule that produced it and whether it is live or frozen.
  • Every table reconciles, or says in writing why it cannot.
  • Every mistake we have found is listed, dated, in the main text.

Room 09 of 12

2.5.16Runtime versionloader constant URSY_ESTATE_RUNTIME_VERSION · as at 12 Sep 2026 · intended to be the same on every built URSY site; this page can vouch for this host only — compare the fingerprint at each site's /wp-json/ursy-runtime/v1/status · Live
41Files fingerprintedfiles on disk under mu-plugins/ursy-estate · read now · one md5 over the loader, every module and every asset (41 files) · Live

The workings, in plain English

URSY.RECIPES runs the shared URSY estate runtime: one package of PHP files under mu-plugins, intended to be identical on every built URSY site, with a site file of a few dozen lines that says which modules this host takes from the runtime, which from its own theme, and which it has ruled off. Everything the other eleven rooms report — knocks, reads, API calls, tokens — is counted by that package. This room is about the package itself on this host: which version is running, the fingerprint a reader compares against the other sites' to prove the bytes match (this page can vouch for this host only), who provides each module, and what the site is configured to do about security.

It is also where the instrument keeps its own conscience. Every correction and revision ever published on these pages is listed here with its date, and the last section explains how this page is made, so a reader can check that no figure was assembled in the browser and no style or script was slipped in inline.

The runtime

One package, every site

The runtime this site is really running, stated from the loader's own constant and the files on disk, not from a version string in a footer. The package is intended to be the same on every built URSY site — this page can vouch for this host only; a reader proves parity by comparing the fingerprint at each site's /wp-json/ursy-runtime/v1/status.

  • Runtimeursy-estate-runtime 2.5.16
  • Familymu — the shared package under mu-plugins provides every module this site has not ruled off
  • Response headerX-URSY-Runtime: 2.5.16
  • Package fingerprint1a33fb22b6a9cf9646c51c15d694fbcc
  • Files fingerprinted41
  • This host's site fileursy-recipes.php 622de98d

loader constant URSY_ESTATE_RUNTIME_VERSION · as at 12 Sep 2026 · intended to be the same on every built URSY site; this page can vouch for this host only — compare the fingerprint at each site's /wp-json/ursy-runtime/v1/status · Live

files on disk under mu-plugins/ursy-estate · read now · one md5 over the loader, every module and every asset (41 files) · Live

config family · as at 12 Sep 2026 · mu or theme, as the site file declares; header line from the loader constant · Frozen until the site file changes

The files

Every file, its hash

Every file the runtime is made of, with the first eight characters of its md5, read from disk on this render. Two sites that print the same fingerprint are running the same bytes.

Every file in the runtime package, with the first eight characters of its md5
FileHash (8 hex)
ursy-estate-runtime.php97cfde81
ursy-estate/adapter.phpe3a61027
ursy-estate/ads.php6a5b0515
ursy-estate/ai-surfaces.php0ddb538f
ursy-estate/analytics.phpf1bacc0a
ursy-estate/api-ledger.phpf522392c
ursy-estate/citations.php8b232b7f
ursy-estate/hardening.php0566cfd1
ursy-estate/hospitality.php5663e042
ursy-estate/mcp.phpa57daafd
ursy-estate/mint.php3122e2ce
ursy-estate/nicola.php69ec68a1
ursy-estate/runtime-status.php6fe8d575
ursy-estate/sponsor-context.php6a056d3b
ursy-estate/sponsor-contract.php84f84c61
ursy-estate/sponsor-events.php67cec746
ursy-estate/sponsor.php9849fe3c
ursy-estate/uth.phpd29d814a
ursy-estate/assets/cards-teas.json0a07a8b5
ursy-estate/assets/estate-ad.cssfe4f4aae
ursy-estate/assets/estate-admin.js8bcf04b5
ursy-estate/assets/estate-runtime.cssf289990b
ursy-estate/assets/estate-runtime.jsb3ebbb0d
ursy-estate/assets/uth2.cssa207c4fe
ursy-estate/uth2/bootstrap.phpd0702572
ursy-estate/uth2/components.php09bcb751
ursy-estate/uth2/facts.php499ae777
ursy-estate/uth2/register.phpb205dead
ursy-estate/uth2/router.php1b413fef
ursy-estate/uth2/rooms/dictionary.php68c58ad1
ursy-estate/uth2/rooms/doors.php6efc3428
ursy-estate/uth2/rooms/evidence.php12cfe5d5
ursy-estate/uth2/rooms/humans.php2fca71c2
ursy-estate/uth2/rooms/index.phpd47823d3
ursy-estate/uth2/rooms/leaderboard.php55bcc6ca
ursy-estate/uth2/rooms/machines.phpf0a12134
ursy-estate/uth2/rooms/mint.php3595cb16
ursy-estate/uth2/rooms/numbers.php2e69c59a
ursy-estate/uth2/rooms/story.php43f77eff
ursy-estate/uth2/rooms/study.php35b401ad
ursy-estate/uth2/rooms/workings.phpb9e5cfce
41 files fingerprinted — every one is in this table

Source: files on disk under mu-plugins/ursy-estate. Window: read now, this render. Rule: the first eight hexadecimal characters of each file's md5; the package fingerprint is one md5 over every path:md5 line, so the same fingerprint on every site means the same bytes on every site. Freshness: Live.

Package fingerprint 1a33fb22b6a9cf9646c51c15d694fbcc · the same fingerprint and file list are served to machines at https://ursy.recipes/wp-json/ursy-runtime/v1/status · the live REST server · this request · the parity proof; a reader compares the string across sites · Live

The modules

Who provides what

The thirteen modules the loader names, and for each whether this site takes it from the shared runtime, from its own theme, or has ruled it off. Nothing here is inferred: it is the loader's record of what it required at boot.

The modules the loader names, and who provides each on this site
ModuleState
analyticson — provided by the shared runtime
citationson — provided by the shared runtime
api-ledgeron — provided by the shared runtime
hospitalityon — provided by the shared runtime
hardeningon — provided by the shared runtime
minton — provided by the shared runtime
nicolaon — provided by the shared runtime
mcpon — provided by the shared runtime
uthon — provided by the shared runtime
ai-surfaceson — provided by the shared runtime
adson — provided by the shared runtime
sponsoron — provided by the shared runtime
runtime-statuson — provided by the shared runtime
sponsor-contracton — provided by the shared runtime
sponsor-contexton — provided by the shared runtime
sponsor-eventson — provided by the shared runtime
16 modules listed against the 13 this release of the loader names — the difference is stated, not hidden

Source: the loader's own record of what it required at boot, plus config theme_provides. Window: this request. Rule: runtime = the shared package loaded the module; theme = this site's theme provides it and the loader skipped it; off = ruled off in the site file. Freshness: Live.

16 from the shared runtime · 0 (honest zero) from this site's theme · 0 (honest zero) ruled off · the loader's module record · this request · counts of the table above · Live

Security posture

As configured, not as tested

What this site is configured to do about headers, the operator seal, hardening and crawlers. Every line is a statement of configuration read this request; none is a test result, and this page does not claim a header was received.

  • Security headersconfigured on — the hospitality module is configured to send them; not tested by this page
  • Lockdownruntime — only the runtime's own admin surfaces are sealed to the operator door
  • Hardening extrasfile_mod, app_passwords, registration, pings — 4 configured, applied at init regardless of lockdown; stated as configuration, not tested
  • Hardeningon — provided by the shared runtime
  • SEO crawlers blocked in robotsconfigured yes — the hardening module is configured to append a Disallow block for SemrushBot, AhrefsBot and MJ12bot to robots.txt; not tested by this page
  • Users sitemapdropped — configured: the hardening module removes the core users sitemap provider wherever it runs (revision 2.0.2, 4 September 2026)
  • Rate limiteron — the hospitality module's published buckets apply, per client hash; the limits themselves are in The Doors

This section states configuration. It does not claim a header was received; a reader can check with a single request.

config and the loader's module record · as at 12 Sep 2026 · what the site is configured to do, stated as configuration, not as a test result · Frozen until the site file changes

Corrections

Every mistake we have found, dated

Every correction and revision published on this instrument, newest first, each with its date and the room it touches. A figure that changed meaning is never quietly replaced; the old reading stays in the sentence.

Corrected 4 September 2026: The single-page truth room was replaced by twelve rooms; no stored value changed, every figure the old page showed appears in a room with the same source. Where it appears: every room, footer of The Workings.

Corrected 4 September 2026: The AI-reads windows read empty on every site from 2 to 4 September 2026 because of a reserved-word alias in the window query; rows were recorded throughout and the tables were never wrong, only the window read was. uth2 reads the table directly. Where it appears: The Story, The Numbers (runtime 2.0.1).

Corrected 4 September 2026: The 'REST namespaces present' line once listed every ursy-* namespace the server reported, including private application APIs; it now names only the package's own five and config public_namespaces. Where it appears: The Doors (fix pass).

No further correction has been needed on this site — 0 (honest zero) — and this sentence will change the day one is.

3 corrections and revisions listed, of which 0 (honest zero) are specific to this site · honesty.corrections · as at 12 Sep 2026 · the estate list in uth2/rooms/workings.php plus config uth_corrections, newest first; "revised" or "corrected", never "patched" · Live

How this page is made

No data is assembled in the browser

How this room reaches you: rendered on the server from one facts tree, styled by one enqueued file, twinned as JSON at the same address, with no script that computes anything. The build's own checks are listed by name.

  • Server-renderedOne facts tree is built per request and held for up to 120 seconds; every figure on this page was in the HTML before the browser opened it. Nothing is fetched, computed or filled in on the client.
  • JavaScriptScript this page ships: 0 (honest zero). The page renders fully without it, tables scroll inside their own panel by CSS, and there is no data assembled in the browser to need it; its one script element is the JSON-LD data block, which is data, not code, and is never executed. Inline script elements counted in the delivered document, the JSON-LD data block excepted: 7. Those elements were added by WordPress core, the theme or another plugin through wp_head and wp_footer, not by this page; the runtime removes the core ones it knows of (the emoji script, the admin bar) and counts whatever remains rather than hiding it. the wp_head and wp_footer output captured for this document · this request · every <style> block and every <script> element other than the JSON-LD data block, counted in the captured markup · Live
  • StylesheetOne file, assets/uth2.css, enqueued by the runtime. This page's own markup carries no inline style attribute and no inline style block: ursy.fm's Content-Security-Policy is style-src 'self', which silently drops anything inline, and one estate runs one stylesheet so no site's page is the odd one out. Inline style blocks counted in this document: 2. Those blocks were added by WordPress core, the theme or another plugin through wp_head and wp_footer, not by this page; the runtime removes the core ones it knows of (emoji, global styles, admin bar) and counts whatever remains rather than hiding it. the wp_head and wp_footer output captured for this document · this request · every <style> block and every <script> element other than the JSON-LD data block, counted in the captured markup · Live
  • Theme handlersOn a theme-family site the theme may register its own anonymous handler for /under-the-hood/ ahead of this page; the router removes those closures for a claimed room request and counts them. Theme handlers stood aside on this request: not counted — the router recorded no count on this render. uth2/router.php ursy_estate_uth2_clear_theme_closures · this request · anonymous closures on template_redirect at priorities 0 to 5 removed for a claimed room on a theme-family site so uth2 can render; named handlers are never touched · Live
  • JSON twinhttps://ursy.recipes/wp-json/ursy-runtime/v1/uth?room=workings serves the same facts tree from the same 120-second cache, one shape for every room; the room key tells a machine reader which sections this page shows.
  • Headers sent by this pageCache-Control: public, max-age=120 · X-Robots-Tag: index, follow · X-URSY-Runtime: 2.5.16 · Link: <https://ursy.recipes/wp-json/ursy-runtime/v1/uth?room=workings>; rel="alternate"; type="application/json". No Content-Security-Policy is sent by this page: the site's own policy stands, and two would conflict.
  • What the brand layer addsThe estate brand layer wraps this document through its output buffer: the network bar after the body opens, the aurora field and the network footer before it closes, data-theme=light where the host is configured light, and rel=nofollow on every cross-estate link. This page prints no header, wordmark or footer of its own.

uth2/router.php, uth2/components.php and this file · as at 12 Sep 2026 · stated by the code that renders this page · Frozen until the runtime changes

  • 01 · Lint gate — php -l on every uth2 file and the stylesheet before it is called finished; a failure stops the build.
  • 02 · Class audit — every uth2-* class in components.php and rooms/*.php has a rule in assets/uth2.css, and every rule has a use; both lists match the blueprint's contract.
  • 03 · Inline audit — a search of uth2/ and the stylesheet for inline style attributes, style blocks and script elements returns only the JSON-LD data block in components.php; then a plain GET of a rendered room counts the inline style blocks and script elements in the delivered document, because wp_head and wp_footer can add what the source audit cannot see.
  • 04 · Escaping audit — every echo and every string built into HTML in rooms/*.php passes through a component helper or an esc_* call.
  • 05 · Render proof without WordPress — every room rendered against three fixture trees (nothing installed; installed and empty; realistic): every stat carries a provenance line, every table a reconciliation pill and a source line, the absence words appear where the blueprint says, and no zero appears without the words (honest zero) beside it.
  • 06 · Facts proof with WordPress — the facts tree builds without a notice under WP_DEBUG and the JSON twin validates as JSON.
  • 07 · Deploy proof — one site first, then a plain GET of all twelve rooms and the twin on each site before the next.

The checks are named, not scored: their last result is not printed because this page cannot know it, and a page about verifiable state must not claim a pass it did not witness. The build log lives with the build, not on the site.

Honesty note

How this room was read. Every figure in this room was read at 12 Sep 2026 18:38 UTC and is held for up to 120 seconds; this copy was served at 12 Sep 2026 18:38 UTC from that held tree.

Where the runtime cannot read a fact on this site family the line says "not kept on this site"; where a ledger is installed and empty a figure reads 0 (honest zero); where a ledger is not installed the section says "not counting yet". Configuration is stated as configuration, never as a test result. Nothing here is modelled, sampled or estimated.

Revised 4 September 2026: The single-page truth room was replaced by twelve rooms; no stored value changed, every figure the old page showed appears in a room with the same source. Every correction and revision is listed, dated, in the Corrections section above.

AI agents and integrators: llms.txt · agents.json · ai-entry.json · sitemap · humans.txt · this instrument · Nicola · MCP (POST only) · runtime status · apis nicola v1 · apis ursy-mcp v1 · apis ursy-runtime v1 · apis ursy-mint v1 · this room as JSON · traffic ledger · mint status · mint contract

Ask Nicola

Ask about this site, its runtime or its public evidence.

Your URSY account

URSY ID manages your account across the network. This site is coming soon; it has no private product workspace yet.

Open URSY ID · Account setup and API guide