Short version: we add a folder. On nearly every product we make no edits to the developer’s files at all.
Here is the whole picture, because you should not have to take that on faith.
What we add
Every product carries a 99plugs/ folder. Inside it is one file, product.json, four lines naming the product and its ID in our store. It is text. It does not run.
That folder is how the 99Plugs Update Manager finds our products on your site. The Update Manager is a separate plugin you install once, and it does not live inside the products.
For the large majority of the catalog that is the entire difference. A folder, one small text file, and no edits to the developer’s own files.
What we change, and where
Two things, on a small number of products, and both are worth naming plainly.
A license gate removed, on fewer than fifty products out of more than three thousand. These are the plugins that refuse to run at all without an active license, rather than the ones that just nag you. The check comes out so the plugin runs.
A small guard file, on roughly ten products, plus one line in the main plugin file that loads it. These are free WordPress.org plugins sitting underneath a premium add-on. Without the guard, the next WordPress.org update installs straight over our copy, and the premium features stop working until you reinstall ours.
Those two sets overlap heavily. It is largely the same handful of products seen from two angles.
Why we publish this
Because it is what you would find. If our copy of a plugin ever sat next to the developer’s download, that is the difference: a folder, and on a few products, the two changes above.
A company that tells you first is easier to trust than one hoping you never look. It is also the honest version of the word authentic. Every file is the developer’s own release, it was paid for, and it is scanned for malware before it reaches you. Every product, every version, updates included. What we do not claim is that every file is identical to the developer’s download, because on a few of them it is not.
Nothing here comes from the free download sites that give this corner of WordPress its reputation. Those are anonymous, nobody’s name is on anything, and in the Georgia Tech study of plugin piracy the files nobody could trace back to a source were 100% malicious. The difference is not where a file was bought. It is whether anybody is accountable for it, and whether the business makes money by helping you or by compromising you.
What this does not change
Your plugin works the way the developer built it. The features are theirs and the code is theirs.
What you give up is their support desk, anything that runs on their servers, and 24 to 48 hours of update speed. Known Limitations lists the specific products where the middle one bites.
The full argument, including the parts genuinely worth arguing about, is in Are GPL WordPress sites legal, safe, and ethical?
