{"id":360773,"date":"2026-08-30T10:37:18","date_gmt":"2026-08-30T10:37:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/juliet-just-mask\/"},"modified":"2026-08-30T10:36:48","modified_gmt":"2026-08-30T10:36:48","slug":"juliet-just-masks","status":"publish","type":"plugin","link":"https:\/\/es.wordpress.org\/plugins\/juliet-just-masks\/","author":15613181,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Juliet Just Masks","header_author":"Harsh Trivedi","header_description":"URL masking, mask manager, and stealth reverse proxy companion for Romeo Redirect Manager. Maps local paths to remote applications and renders them natively \u2014 no iframes, no Nginx rules.","assets_banners_color":"3966a7","last_updated":"2026-08-30 10:36:48","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/buymeacoffee.com\/harshtrivedi","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/juliet-just-masks\/","header_author_uri":"https:\/\/harsh98trivedi.github.io\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":55,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"harsh98trivedi","date":"2026-08-30 10:36:48","revision":3672382}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3672382,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3672382,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3672382,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3672382,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3672382,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3672382,"resolution":"1","location":"assets","locale":"","width":772,"height":481},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3672382,"resolution":"2","location":"assets","locale":"","width":772,"height":481},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3672382,"resolution":"3","location":"assets","locale":"","width":772,"height":481},"screenshot-4.jpg":{"filename":"screenshot-4.jpg","revision":3672382,"resolution":"4","location":"assets","locale":"","width":772,"height":481},"screenshot-5.jpg":{"filename":"screenshot-5.jpg","revision":3672382,"resolution":"5","location":"assets","locale":"","width":772,"height":481},"screenshot-6.jpg":{"filename":"screenshot-6.jpg","revision":3672382,"resolution":"6","location":"assets","locale":"","width":772,"height":481}},"screenshots":{"1":"Main Dashboard (Card View) \u2014 Overview of all active and inactive URL masks with instant toggles, quick copy actions, real-time search, and status filtering.","2":"Create &amp; Edit Mask Interface \u2014 Clean configuration form with custom local path prefixing, target URL routing, and dynamic  tag injection.","3":"Interactive  Tag &amp; SPA Guide Modal \u2014 Educational popup guide explaining Single Page Applications (React, Vue, Vite, Next.js, Angular, Svelte) and chunk proxy isolation.","4":"One-Click Backup &amp; JSON Import \u2014 Safe migration modal with automated duplicate slug conflict detection and smart merge options.","5":"Fully Responsive Mobile Interface \u2014 Optimized layout and touch-friendly controls across smartphones, tablets, and desktop devices.","6":"Live Permalink Conflict Detection \u2014 Real-time warning alert preventing collisions with existing WordPress Pages, Posts, and Romeo 301 redirects before saving."}},"plugin_section":[],"plugin_tags":[278305,45950,278307,278306,278304],"plugin_category":[],"plugin_contributors":[252880],"plugin_business_model":[],"class_list":["post-360773","plugin","type-plugin","status-publish","hentry","plugin_tags-mask-manager","plugin_tags-reverse-proxy","plugin_tags-stealth-routing","plugin_tags-url-masker","plugin_tags-url-masking","plugin_contributors-harsh98trivedi","plugin_committers-harsh98trivedi"],"banners":{"banner":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/banner-772x250.png?rev=3672382","banner_2x":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/banner-1544x500.png?rev=3672382","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/icon.svg?rev=3672382","icon":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/icon.svg?rev=3672382","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/screenshot-1.jpg?rev=3672382","caption":"Main Dashboard (Card View) \u2014 Overview of all active and inactive URL masks with instant toggles, quick copy actions, real-time search, and status filtering."},{"src":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/screenshot-2.jpg?rev=3672382","caption":"Create &amp; Edit Mask Interface \u2014 Clean configuration form with custom local path prefixing, target URL routing, and dynamic  tag injection."},{"src":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/screenshot-3.jpg?rev=3672382","caption":"Interactive  Tag &amp; SPA Guide Modal \u2014 Educational popup guide explaining Single Page Applications (React, Vue, Vite, Next.js, Angular, Svelte) and chunk proxy isolation."},{"src":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/screenshot-4.jpg?rev=3672382","caption":"One-Click Backup &amp; JSON Import \u2014 Safe migration modal with automated duplicate slug conflict detection and smart merge options."},{"src":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/screenshot-5.jpg?rev=3672382","caption":"Fully Responsive Mobile Interface \u2014 Optimized layout and touch-friendly controls across smartphones, tablets, and desktop devices."},{"src":"https:\/\/ps.w.org\/juliet-just-masks\/assets\/screenshot-6.jpg?rev=3672382","caption":"Live Permalink Conflict Detection \u2014 Real-time warning alert preventing collisions with existing WordPress Pages, Posts, and Romeo 301 redirects before saving."}],"raw_content":"<!--section=description-->\n<p><strong>Juliet Just Masks<\/strong> is a high-performance URL masking and reverse proxy <strong>mask manager<\/strong> for WordPress. While Romeo Redirect Manager handles open redirects, Juliet provides seamless <strong>stealth routing<\/strong> and <strong>URL masking<\/strong>.<\/p>\n\n<p>As a lightweight, native <strong>URL masker<\/strong>, Juliet lets WordPress act as a stealth reverse proxy. It intercepts specific incoming paths, keeps the visitor's address bar unchanged, and fetches\/renders dynamic HTML, React\/Vue SPAs, or external landing pages behind the scenes.<\/p>\n\n<h4>Why use Juliet Mask Manager?<\/h4>\n\n<ul>\n<li><strong>Native URL Masking<\/strong> \u2014 Serve remote applications, microservices, and landing pages on your own custom domain without iframes or server configuration.<\/li>\n<li><strong>Smart Mask Manager<\/strong> \u2014 Visual dashboard to create, manage, sort, search, and toggle active\/inactive URL masks in real time.<\/li>\n<li><strong>Fast Path Reverse Proxy<\/strong> \u2014 Zero-latency early route matching hooks before WP Query to proxy requests at top speed.<\/li>\n<li><strong>SPA &amp; <code>&lt;base&gt;<\/code> Tag Injector<\/strong> \u2014 Keeps relative script chunks, assets, and API requests properly routed through the proxy.<\/li>\n<li><strong>Asset &amp; Link Patcher<\/strong> \u2014 Rewrites root-relative URLs, internal CSS <code>url()<\/code> assets, and external navigation links into your local mask namespace.<\/li>\n<li><strong>SSRF Protection &amp; Security<\/strong> \u2014 Enterprise-grade IP and protocol validation protects your server from unsafe outbound requests.<\/li>\n<li><strong>Companion to Romeo Redirect Manager<\/strong> \u2014 The complete routing suite: Romeo for redirection, Juliet for masking.<\/li>\n<\/ul>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>Stealth Routing Engine<\/strong> \u2014 Bypasses WP_Query to serve remote HTML without triggering a 404, supporting unlimited sub-paths.<\/li>\n<li><strong>Mask Manager Dashboard<\/strong> \u2014 Intuitive card and list views with live search, custom dropdown filtering, and instant AJAX toggles.<\/li>\n<li><strong>URL Masker &amp; Link Masking<\/strong> \u2014 Automatically rewrites remote URLs and same-origin links into your local slug namespace.<\/li>\n<li><strong>Asset Dependency Patcher<\/strong> \u2014 Rewrites root-relative asset paths (<code>\/css\/style.css<\/code>, <code>srcset<\/code>, inline <code>url()<\/code>, data-src) on the fly.<\/li>\n<li><strong>Proxy Header Passthrough<\/strong> \u2014 Forwards visitor IP (<code>X-Forwarded-For<\/code>), User-Agent, language, and protocol for accurate analytics.<\/li>\n<li><strong>SSRF Protection<\/strong> \u2014 Validates protocols, credentials, and DNS against private IP ranges.<\/li>\n<li><strong>DOM <code>&lt;base&gt;<\/code> Injector<\/strong> \u2014 Smart <code>&lt;base href&gt;<\/code> injection tailored for complex JavaScript\/AJAX-heavy SPAs.<\/li>\n<li><strong>Asset Caching &amp; MIME Typing<\/strong> \u2014 Built-in static asset caching headers and strict MIME type detection for scripts and styles.<\/li>\n<li><strong>Graceful Failsafe<\/strong> \u2014 Theme-native 404 fallback if a remote server is unreachable.<\/li>\n<li><strong>Method Pass-Through<\/strong> \u2014 Supports GET, POST, PUT, PATCH, DELETE, and CORS OPTIONS preflight requests.<\/li>\n<\/ul>\n\n<h4>Example<\/h4>\n\n<ol>\n<li>Go to <strong>Juliet Just Masks<\/strong> in wp-admin.<\/li>\n<li>Click <strong>Create New Mask<\/strong>.<\/li>\n<li>Enter the Local Path: <code>marketing-hub<\/code>.<\/li>\n<li>Enter the Remote Target URL: <code>https:\/\/external-landing-page.com\/promo-1<\/code>.<\/li>\n<li>Save.<\/li>\n<\/ol>\n\n<p>Visiting <code>yoursite.com\/marketing-hub<\/code> now renders the remote landing page while the address bar still shows <code>yoursite.com\/marketing-hub<\/code>. Deeper paths work too: <code>yoursite.com\/marketing-hub\/pricing<\/code> proxies the remote app's <code>\/pricing<\/code> route.<\/p>\n\n<h4>Known limitations<\/h4>\n\n<ul>\n<li><strong>CORS<\/strong> \u2014 if the remote server sends strict CORS headers for its assets, browsers may block cross-origin subresources. The remote must allow your domain (or serve assets with permissive CORS).<\/li>\n<li><strong>Remote sessions<\/strong> \u2014 <code>Set-Cookie<\/code> responses are not forwarded (cookies would be scoped incorrectly). Authenticated remote applications need additional cookie handling; forwarding the visitor's cookies upstream is available via the <code>juliet_forward_cookies<\/code> filter but leaks this site's auth cookies, so only enable it for trusted targets.<\/li>\n<li><strong>DNS rebinding<\/strong> \u2014 SSRF validation resolves DNS separately from the fetch. A hostile target could rotate DNS between check and fetch. Only mask targets you control or trust.<\/li>\n<li><strong>Lazy-loaded assets<\/strong> \u2014 attributes such as <code>data-src<\/code> set by JavaScript after load cannot be patched server-side; enable <code>&lt;base&gt;<\/code> injection for those apps.<\/li>\n<\/ul>\n\n<h3>Filters (developer reference)<\/h3>\n\n<ul>\n<li><code>juliet_target_url<\/code> \u2014 filter the final outbound URL (args: <code>$url<\/code>, <code>$mask<\/code>, <code>$subpath<\/code>).<\/li>\n<li><code>juliet_timeout<\/code> \u2014 remote fetch timeout in seconds (default 15).<\/li>\n<li><code>juliet_cache_ttl<\/code> \u2014 response cache TTL in seconds (default 300, 0 disables).<\/li>\n<li><code>juliet_max_cache_bytes<\/code> \u2014 max cacheable body size (default 2 MB).<\/li>\n<li><code>juliet_proxy_headers<\/code> \u2014 outbound proxy headers (args: <code>$headers<\/code>, <code>$mask<\/code>, <code>$url<\/code>).<\/li>\n<li><code>juliet_forward_cookies<\/code> \u2014 forward the visitor's Cookie header upstream (default false).<\/li>\n<li><code>juliet_allow_private_targets<\/code> \u2014 allow private\/internal network targets (default false).<\/li>\n<li><code>juliet_apply_link_masking<\/code> \u2014 rewrite same-origin remote links into the slug namespace (default true).<\/li>\n<li><code>juliet_reserved_slugs<\/code> \u2014 slugs that may never be registered as masks.<\/li>\n<li><code>juliet_request_args<\/code> \u2014 full <code>wp_remote_request()<\/code> argument override.<\/li>\n<li><code>juliet_honor_loop_guard<\/code> \u2014 block requests that already carry the proxy signature (default true).<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>juliet-just-masks<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install via the Plugins screen.<\/li>\n<li>Activate <strong>Juliet Just Masks<\/strong> through the <strong>Plugins<\/strong> menu (the registry table is created automatically).<\/li>\n<li>Navigate to <strong>Juliet Just Masks<\/strong> in the admin menu and create your first mask.<\/li>\n<\/ol>\n\n<p>If routes return 404s after manual database edits, visit <strong>Settings \u2192 Permalinks<\/strong> once to flush rewrite rules.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20change%20my%20.htaccess%20or%20nginx%20config%3F\"><h3>Does this change my .htaccess or Nginx config?<\/h3><\/dt>\n<dd><p>No. Juliet uses WordPress rewrite rules and <code>template_redirect<\/code>, so it works on managed hosting where server configs are off-limits.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20save%20or%20delete%20a%20mask%3F\"><h3>What happens when I save or delete a mask?<\/h3><\/dt>\n<dd><p>Rewrite rules are flushed automatically, so new routes go live instantly.<\/p><\/dd>\n<dt id=\"can%20a%20mask%20hide%20an%20existing%20page%3F\"><h3>Can a mask hide an existing page?<\/h3><\/dt>\n<dd><p>Masks register at top priority. If you pick a path already used by a page, the mask wins and the admin will warn you about the conflict on save.<\/p><\/dd>\n<dt id=\"how%20do%20i%20disable%20caching%3F\"><h3>How do I disable caching?<\/h3><\/dt>\n<dd><p>add_filter( 'juliet_cache_ttl', '__return_zero' );<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: Stealth Routing Engine, Mask Registry UI, Asset Dependency Patcher, link masking, header passthrough, SSRF protection, base-tag injection, response caching and native 404 fallback.<\/li>\n<\/ul>","raw_excerpt":"High-performance URL masking and stealth routing mask manager. Reverse proxy remote apps and landing pages on your own domain without iframes.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/360773","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=360773"}],"author":[{"embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/harsh98trivedi"}],"wp:attachment":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=360773"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=360773"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=360773"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=360773"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=360773"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=360773"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}