Pro settings
Pro settings is a level-0 category browser. The primary path is the Pro group under /all-settings; /settings/pro remains a direct legacy route and is not entitlement proof. Numeric categories, IDs, controls, and values come from project responses. Fixed Dashboard source also adds three named Pro entries: Languages and Developers are marked enabled in menu construction, while Custom Orders is enabled only after a plugin-key read reports it installed. Those source flags do not prove runtime availability.
/all-settings is level 0. Its Pro group requires Pro or Enterprise source state plus returned Pro categories. Loading the group issues authenticated category reads and can also check plugin state; no category or plugin was requested.
Runtime remains blocked. Numeric category values are project-returned data and must not be copied between environments or treated as stable article URLs. Selecting Languages, Developers, or Custom Orders mounts a dedicated manager with its own authenticated reads and write-capable boundaries; none was opened.
The shared source form renders controls from returned type/options. Text/select changes can stage until Save, which persists configurations sequentially and can partially complete. Image crop confirmation can invoke an immediate config/media write. None was opened or executed.
Returned Pro categories can contain credentials, provider configuration, payment state, webhooks, or customer/order data. All values and security details are absolute exclusions; no field inventory or provider availability is inferred from a category name.
The direct /settings/pro route remains a terminal audit-only exclusion. It must not bypass the canonical Pro/Enterprise plan and returned-category gates, and it does not receive a separate page. Re-entry requires a synthetic eligible project plus proof of unique direct-route behavior.
Related guides: Settings overview · Online payments