[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fE7eAkqq0VSddUsm3SF-0IkuPlpqcCOmG3GjilWVNiPw":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"nexurasecurity","Nexura Security","https:\u002F\u002Fprofiles.wordpress.org\u002Fnexurasecurity\u002F",1,0,100,30,94,"2026-08-28T18:28:52.337Z",[14],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":8,"num_ratings":8,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"nexura-security","Nexura Security — Malware Scanner, Firewall, 2FA & WordPress Security","1.0.9","\u003Cp>\u003Cstrong>Nexura Security\u003C\u002Fstrong> is a complete, enterprise-grade WordPress security plugin that protects your website from hackers, malware, and brute-force attacks — \u003Cstrong>completely free\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Whether you run a personal blog, a WooCommerce store, or a business website, Nexura Security gives you the same level of protection used by enterprise websites — without slowing your site down and without expensive subscriptions.\u003C\u002Fp>\n\u003Ch4>⚡ The Faster, Lighter Alternative to Wordfence & Sucuri\u003C\u002Fh4>\n\u003Cp>Tired of heavy security plugins that slow down your site, bloat your database, and charge a premium for basic features?\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Nexura Security is built differently:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero Database Bloat\u003C\u002Fstrong> — Smart micro-batching runs scans quietly in the background without overloading your server.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Performance Hit\u003C\u002Fstrong> — Your visitors will never experience slowdowns during or after a security scan.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-Click Setup\u003C\u002Fstrong> — No technical knowledge required. Get protected in under 60 seconds.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>100% Free Core\u003C\u002Fstrong> — Every essential security feature is included at no cost, forever.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🛡️ Free Features (Everything You Need to Stay Secure)\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>🔍 Deep WordPress Malware Scanner\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically scans your entire WordPress installation — plugins, themes, uploads, and core files — for hidden backdoors, obfuscated PHP code, suspicious JavaScript injections, web shells, and known malware patterns. Detected threats are displayed with severity ratings and can be removed with a single click.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔥 Web Application Firewall (WAF)\u003C\u002Fstrong>\u003Cbr \u002F>\nBlocks SQL injection (SQLi), Cross-Site Scripting (XSS), remote file inclusion (RFI), and other OWASP Top 10 attacks before they ever reach your WordPress database. The WAF loads via \u003Ccode>auto_prepend_file\u003C\u002Fcode> — before WordPress boots — for the earliest possible threat interception.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⚠️ Automated Security Alert Emails\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen Nexura Security detects malware or threats during a scan, it automatically sends a beautifully formatted HTML security alert email to the site administrator with a full threat summary and a direct link to the dashboard. Alerts are rate-limited to once per 24 hours to prevent inbox spam.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>📂 WordPress Core File Integrity Monitor\u003C\u002Fstrong>\u003Cbr \u002F>\nCompares every WordPress core file against clean, official checksums from WordPress.org to detect any unauthorized modifications. If a hacker modifies \u003Ccode>wp-login.php\u003C\u002Fcode>, \u003Ccode>wp-config.php\u003C\u002Fcode>, or any other core file, you will know immediately.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>📁 Root Directory Integrity Checker\u003C\u002Fstrong>\u003Cbr \u002F>\nDetects suspicious and unknown files dropped directly into your WordPress root folder — a common technique used by attackers to plant backdoors and web shells.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔐 Two-Factor Authentication (2FA)\u003C\u002Fstrong>\u003Cbr \u002F>\nProtect your WordPress admin login with TOTP-based two-factor authentication. Works with Google Authenticator, Authy, Microsoft Authenticator, and any standard TOTP app. Includes a full-screen QR code setup wizard.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔗 Passwordless Magic Link Login\u003C\u002Fstrong>\u003Cbr \u002F>\nAllow trusted users to log in via a secure, time-limited link sent to their email — no password required. Eliminates password-based brute-force risks entirely.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🚫 Brute-Force Attack Protection\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically blocks IP addresses after repeated failed login attempts. Fully configurable lockout duration, attempt thresholds, and whitelisting.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔑 Pwned Password Checker\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen users set or change their passwords, Nexura Security silently checks against the HaveIBeenPwned database using the k-Anonymity model — your full password is \u003Cstrong>never\u003C\u002Fstrong> transmitted. If a compromised password is detected, the user is warned immediately.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🤖 Anti-Spam & Bot Protection (CAPTCHA)\u003C\u002Fstrong>\u003Cbr \u002F>\nProtect your login, registration, and comment forms from automated spam bots using Cloudflare Turnstile (privacy-respecting) or Google reCAPTCHA v2\u002Fv3 integration.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🌍 Real-Time Threat Intelligence\u003C\u002Fstrong>\u003Cbr \u002F>\nSyncs with the Nexura Threat Intel Cloud to receive up-to-date malicious IP blocklists and WAF attack signatures, keeping your firewall rules current against the latest threats.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🛠️ One-Click Security Hardening\u003C\u002Fstrong>\u003Cbr \u002F>\nApply all WordPress security best practices in one click:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable the built-in file editor\u003C\u002Fli>\n\u003Cli>Block PHP execution in the uploads folder\u003C\u002Fli>\n\u003Cli>Disable directory listing\u003C\u002Fli>\n\u003Cli>Block XML-RPC attacks\u003C\u002Fli>\n\u003Cli>Disable user enumeration via REST API\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🚑 Fatal Error Auto-Heal (White Screen of Death Protection)\u003C\u002Fstrong>\u003Cbr \u002F>\nUses the official WordPress Drop-in pattern (\u003Ccode>wp-content\u002Ffatal-error-handler.php\u003C\u002Fcode>) to catch PHP fatal errors before they crash your entire site. If a newly installed plugin or theme causes a “White Screen of Death,” Nexura automatically detects the faulty plugin, safely disables it, and reloads the page.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🗄️ Database Security Scanner\u003C\u002Fstrong>\u003Cbr \u002F>\nScans your WordPress database for rogue administrator accounts, suspicious option values, and malicious content injected into posts and pages by attackers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>💾 Database Backup\u003C\u002Fstrong>\u003Cbr \u002F>\nCreate a full database backup with one click before performing any cleanup operation — so you can always roll back safely.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>📊 Real-Time Upload Scanning\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery file uploaded through WordPress (media, plugins, themes) is automatically scanned for malware signatures before it is saved to your server.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔍 Google Safe Browsing Check\u003C\u002Fstrong>\u003Cbr \u002F>\nInstantly verify whether your website has been flagged by Google as containing malware or phishing content. Catch blacklisting before your visitors do.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>📡 SSL & HTTPS Monitor\u003C\u002Fstrong>\u003Cbr \u002F>\nMonitors your SSL certificate health and enforces HTTPS redirects to prevent mixed-content warnings and insecure connections.\u003C\u002Fp>\n\u003Ch3>🌟 Pro Features — Advanced Protection & Automation\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Nexura Security Pro\u003C\u002Fstrong> extends the free version with powerful automation, advanced scanning, and enterprise-grade protection:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Tokenizer-Based Smart Scanner\u003C\u002Fstrong> — Uses PHP’s \u003Ccode>token_get_all()\u003C\u002Fcode> AST engine to detect zero-day backdoors and polymorphic malware that regex-based scanners miss entirely.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automated Malware Cleanup\u003C\u002Fstrong> — One-click automated removal of detected malware without needing developer access.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress Core Auto-Restore\u003C\u002Fstrong> — Downloads clean copies of modified core files from WordPress.org and replaces them using atomic, crash-safe file writes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Quarantine System\u003C\u002Fstrong> — Moves suspicious files to an isolated, execution-blocked quarantine zone where they cannot cause harm while you review them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Login URL (Hide wp-admin)\u003C\u002Fstrong> — Rename \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-admin\u003C\u002Fcode> to a secret URL, blocking 99% of automated brute-force bots before they even reach your login page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HTTP Security Headers\u003C\u002Fstrong> — Add Content-Security-Policy (CSP), HSTS, X-Frame-Options, Permissions-Policy, Referrer-Policy, and more. Includes Recommended, Strict, and Custom presets.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Security\u003C\u002Fstrong> — Block unauthenticated REST API access and prevent username enumeration via \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce Security\u003C\u002Fstrong> — Anti-card-testing protection on checkout pages and account takeover prevention for customer accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Audit\u003C\u002Fstrong> — Automatically detects plugins, themes, and WordPress core versions with known CVEs (Common Vulnerabilities and Exposures).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database Optimizer\u003C\u002Fstrong> — Removes post revisions, expired transients, orphaned metadata, and spam comments to improve database performance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage Cleanup Scanner\u003C\u002Fstrong> — Safely identifies unused images, PDFs, and orphaned upload files to reclaim disk space.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Conflict Cleaner\u003C\u002Fstrong> — Detects and safely removes database leftovers from conflicting or previously deleted security plugins.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Trust Badge\u003C\u002Fstrong> — Display a dynamic “Protected by Nexura Security” seal on your website to build visitor confidence.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>📡 Active Visitor Monitoring\u003C\u002Fstrong> — Real-time visitor tracking dashboard with live stats, 4 interactive charts (Traffic Trend, Browser, Device, OS), auto-refreshing visitor table, and intelligent bot detection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>📌 Visitor Stats Shortcodes\u003C\u002Fstrong> — 5 shortcodes (\u003Ccode>[nexura_visitors]\u003C\u002Fcode>, \u003Ccode>[nexura_stats]\u003C\u002Fcode>, \u003Ccode>[nexura_live]\u003C\u002Fcode>, \u003Ccode>[nexura_popular]\u003C\u002Fcode>, \u003Ccode>[nexura_page_views]\u003C\u002Fcode>) to display live security and visitor stats anywhere on your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled Automatic Scans\u003C\u002Fstrong> — Set malware scans to run every 2 hours, daily, weekly, or monthly — fully automatic, no manual action required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Audit Logs\u003C\u002Fstrong> — A complete, tamper-evident log of every security event, user login, file change, settings modification, and admin action.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Priority Support\u003C\u002Fstrong> — Direct access to the Nexura Security expert team for fast, personalized help.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fnexurasecurity.com\" rel=\"nofollow ugc\">Upgrade to Nexura Security Pro \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>🔗 Third-Party Services & External API Connections\u003C\u002Fh4>\n\u003Cp>To provide comprehensive security, Nexura Security connects to several trusted third-party services. \u003Cstrong>All connections are opt-in — nothing is sent automatically without your explicit action.\u003C\u002Fstrong> Here is a complete and transparent list:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. Cloudflare Turnstile\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Privacy-friendly CAPTCHA on login, registration, and comment forms to stop spam bots.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Browser fingerprint and interaction data (processed by Cloudflare, never stored by us).\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> Only when you enable Turnstile in the Anti-Spam settings.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\" rel=\"nofollow ugc\">Cloudflare Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\" rel=\"nofollow ugc\">Cloudflare Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2. Google reCAPTCHA\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Alternative CAPTCHA option for login and registration pages.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Browser data and interaction signals (processed by Google).\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> Only when you enable Google reCAPTCHA in the Anti-Spam settings.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Google Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">Google Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>3. HaveIBeenPwned API (Pwned Passwords)\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Checking whether a user’s password has appeared in known data breaches.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Only the first 5 characters of a SHA-1 hash of the password (k-Anonymity model). Your actual password is NEVER sent.\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> Only when a user sets or changes their password and the feature is enabled.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Fhaveibeenpwned.com\u002FPrivacy\" rel=\"nofollow ugc\">HaveIBeenPwned Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fhaveibeenpwned.com\u002FAPI\u002Fv3#Terms\" rel=\"nofollow ugc\">API Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>4. Google Safe Browsing API\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Checking whether your website has been flagged by Google as containing malware or phishing.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Your website’s URL.\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> Only when you manually trigger a Safe Browsing check from the dashboard.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Google Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fdevelopers.google.com\u002Fsafe-browsing\u002Fterms\" rel=\"nofollow ugc\">Safe Browsing Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>5. VirusTotal API\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Scanning file hashes against 70+ antivirus engines to detect malware.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Only the SHA-256 cryptographic hash of the file. The actual file is NEVER uploaded.\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> Only during a manual malware scan when unknown files are detected and the feature is enabled.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Fdocs.virustotal.com\u002Fdocs\u002Fprivacy-policy\" rel=\"nofollow ugc\">VirusTotal Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fdocs.virustotal.com\u002Fdocs\u002Fterms-of-service\" rel=\"nofollow ugc\">VirusTotal Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>6. Nexura Threat Intel Cloud\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Syncing the latest WAF rules, malicious IP blocklists, and malware detection signatures.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Blocked attacker IP addresses and blocked payload patterns (anonymized). No personal user data is ever collected.\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> Only when Global Threat Intelligence is enabled in settings.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Fnexurasecurity.com\u002Fprivacy-policy.html\" rel=\"nofollow ugc\">Nexura Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fnexurasecurity.com\u002Fterms-conditions.html\" rel=\"nofollow ugc\">Nexura Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>7. WordPress.org API\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Downloading official WordPress core file checksums for integrity scanning and official WordPress ZIP files for the Core Auto-Restore feature.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Your WordPress version number.\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> During core file integrity checks or when Core Auto-Restore is triggered.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\" rel=\"ugc\">WordPress Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>8. FlagCDN (flagpedia.net)\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Displaying country flags next to IP addresses in the Blocked IPs table.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Country code (derived from IP). No personal data is sent.\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> Only when viewing the Blocked IPs admin page.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Fflagpedia.net\u002Fprivacy-policy\" rel=\"nofollow ugc\">FlagCDN Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fflagpedia.net\u002Fterms\" rel=\"nofollow ugc\">FlagCDN Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>9. Freemius SDK\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cem>Used for:\u003C\u002Fem> Plugin licensing, activation, opt-in analytics, and in-dashboard upgrade flow.\u003Cbr \u002F>\n\u003Cem>Data sent:\u003C\u002Fem> Site URL, WordPress version, plugin version, admin email (only if you opt in during activation).\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> On plugin activation (opt-in dialog) and when checking license status.\u003Cbr \u002F>\n\u003Cem>Links:\u003C\u002Fem> \u003Ca href=\"https:\u002F\u002Ffreemius.com\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Freemius Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Ffreemius.com\u002Fterms\u002F\" rel=\"nofollow ugc\">Freemius Terms\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>📜 Privacy Policy\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What We Collect:\u003C\u002Fstrong>\u003Cbr \u002F>\nNexura Security does NOT collect any personal data from your website visitors. We do not track users, sell data, or place tracking cookies.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What We May Report:\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen the WAF blocks a malicious attack, the attacker’s IP and the blocked payload pattern may be anonymously reported to the Nexura Threat Intel Cloud to help protect other WordPress sites. \u003Cstrong>You can disable this at any time\u003C\u002Fstrong> in Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Global Threat Intelligence.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Your Data, Your Control:\u003C\u002Fstrong>\u003Cbr \u002F>\nAll scan results, logs, and settings are stored locally in your own WordPress database. Nothing is sent to any external server unless you explicitly enable a cloud feature.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Compliance:\u003C\u002Fstrong>\u003Cbr \u002F>\nOur practices comply with GDPR, CCPA, and other major international privacy regulations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Full Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fnexurasecurity.com\u002Fprivacy-policy.html\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fnexurasecurity.com\u002Fterms-conditions.html\" rel=\"nofollow ugc\">Terms & Conditions\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Changelog (Full)\u003C\u002Fh3>\n\u003Cp>For a full structured changelog, see \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fnexurasecurity\u002Fnexura-security\u002Fblob\u002Fmain\u002FCHANGELOG.md\" rel=\"nofollow ugc\">CHANGELOG.md\u003C\u002Fa> on GitHub.\u003C\u002Fp>\n","Free WordPress security plugin with malware scanner, firewall, 2FA & brute force protection. Lightweight alternative to Wordfence & Sucuri.",304,"2026-07-21T17:41:00.000Z","7.0.2","5.8","7.4",[26,27,28,29,30],"brute-force-protection","firewall","malware-scanner","security","two-factor-authentication","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fnexura-security\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnexura-security.1.0.9.zip",null,"2026-07-22T17:31:50.256Z"]