Of course the script can be made no-modify and no-transfer and so nobody will be able to read it but we all know there are means to get access to it if someone really really wants to especially OpenSim-based grids..
All in-world requests need to be signed or the plugin will refuse access this prevents someone not knowing secret key and PIN and trying to only send HTTP request to be need access..
Your first line of protection is simply to delete the perpetrator all objects registered with WP site will be listed and you can simply delete the objects from the.
Of course hacker having access to the script will be able not only to figure out the original keys but also to remove the code for the cover command.
This means that hacker will not be able to create design and place hacked script SL and OpenSim send the owner's like and the plugin can refuse requests from someone not on the list.
This can be well subverted if hacker knows avatar name and knows what keys and PIN are in use they can register on OpenSim with your name and continue to create terms on WP site..
avatar will be not able to create login ever again but they might still have registration object and this area will not prevent others from registering from their object meaning that the hacker will be able to create alts to log in..
Also please note that them name avatar names and so forth are word on HTTP requests made by the in-world object and these are sent by SL grid or OpenSim grid.
This will also prevent programmers from using their own webservers word can be forged but IP address from.
Avatar names have to be unique across blog which means that the user from different grids with the same name but they can shift the password if forgot it and don't need to log in back to grid.
Read more