[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKHxLcs_C7R--msLEew6H2A6HYJi6oqA_de75S_4-yi8":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"obsyde","https:\u002F\u002Fprofiles.wordpress.org\u002Fobsyde\u002F",1,0,100,30,94,"2026-08-28T19:39:32.798Z",[13],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":7,"num_ratings":7,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"obsyde-aegis","Obsyde Aegis","1.0.1","\u003Cp>Obsyde Aegis protects your WordPress site with enterprise-grade security monitoring. The plugin intercepts every request, checks it against known attack signatures, and blocks threats in real time. Local protection runs unconditionally — no account required. When connected to the optional Obsyde dashboard service, detected events are additionally reported for centralised monitoring, geo maps, and AI-powered analysis.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Real-time local threat detection\u003C\u002Fstrong> — SQL injection, XSS, path traversal, remote code execution, and 50+ attack patterns. Works without any account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress-specific protection\u003C\u002Fstrong> — wp-login.php brute force detection, xmlrpc.php abuse blocking, REST API user enumeration prevention. Works without any account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automated IP blocking\u003C\u002Fstrong> — Local pattern-match blocks and (optionally) a curated blocklist synced from the Obsyde platform\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Community threat intelligence\u003C\u002Fstrong> — 44,000+ known malicious IPs from 8 free intelligence sources (via the optional Obsyde sync), updated every 6 hours\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Centralised dashboard (optional)\u003C\u002Fstrong> — When an Obsyde API key is configured, view all security data on obsyde.com with real-time alerts, geo maps, and AI analysis\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero performance impact\u003C\u002Fstrong> — Pattern matching runs in under 5ms; no external API calls during page load (reporting is batched via WP-Cron)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare compatible\u003C\u002Fstrong> — Proper IP detection behind Cloudflare, nginx, and other reverse proxies\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>How It Works:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Install and activate the plugin — local firewall protection starts immediately\u003C\u002Fli>\n\u003Cli>The plugin intercepts every HTTP request before WordPress processes it\u003C\u002Fli>\n\u003Cli>Requests are checked against local attack signatures and (if an API key is configured) the synced Obsyde blocklist\u003C\u002Fli>\n\u003Cli>Threats are blocked with a 403 response\u003C\u002Fli>\n\u003Cli>If an Obsyde API key is configured, events are batched and sent to your dashboard every 60 seconds; the Obsyde blocklist syncs every 5 minutes. Without a key, local protection still runs — events are just not reported externally.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Protection Levels:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Low\u003C\u002Fstrong> — Block known attacks only\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Medium\u003C\u002Fstrong> — Block attacks and suspicious patterns (recommended)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>High\u003C\u002Fstrong> — Aggressive blocking including empty User-Agent rejection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Paranoid\u003C\u002Fstrong> — Maximum protection (may cause false positives)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin provides local firewall protection that runs entirely in your WordPress installation and does not require any external service.\u003C\u002Fp>\n\u003Cp>When you choose to connect the plugin to the optional Obsyde dashboard service by entering an API key, the plugin communicates with the Obsyde API at https:\u002F\u002Fobsyde.com\u002Fapi\u002Fv1\u002Fplugin\u002F for centralised threat monitoring. This service is provided by Obsyde Ltd.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent, when, and why:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Threat events\u003C\u002Fstrong> — When the local firewall blocks a request, an event containing the attacker’s IP address, a UTC timestamp, the attack type (e.g. “sqli_probe”), severity, HTTP method, request path (truncated to 2048 characters), and User-Agent string (truncated to 512 characters) is queued. Once per minute (via WP-Cron) any queued events are POSTed in a single batch to \u003Ccode>\u002Fplugin\u002Fevents\u003C\u002Fcode>. This lets the Obsyde dashboard display, analyse, and correlate threats across all of your sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocklist sync\u003C\u002Fstrong> — Once every 5 minutes (via WP-Cron) the plugin sends a GET request to \u003Ccode>\u002Fplugin\u002Fblocklist\u003C\u002Fcode> to retrieve the current curated list of malicious IPs. No site data is sent in this request; only the site API key identifies the request.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Heartbeat\u003C\u002Fstrong> — Once every 5 minutes (via WP-Cron) the plugin sends a POST request to \u003Ccode>\u002Fplugin\u002Fheartbeat\u003C\u002Fcode> containing your WordPress version, PHP version, and plugin version so the Obsyde dashboard can show whether the site is reachable and up to date.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Connection test\u003C\u002Fstrong> — When you click the “Test Connection” button in the settings, a single GET request is sent to \u003Ccode>\u002Fplugin\u002Fconfig\u003C\u002Fcode> to verify your API key.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>No data is sent to any external service until you configure an API key.\u003C\u002Fstrong> If you remove the API key or deactivate the plugin, no further external communication occurs.\u003C\u002Fp>\n\u003Cp>This service’s terms and privacy policy:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Terms of service: https:\u002F\u002Fobsyde.com\u002Fterms\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fobsyde.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n","Real-time threat detection, automated IP blocking, and AI-powered security analysis.",161,"2026-04-28T09:37:00.000Z","6.9.5","6.0","8.0",[25,26,27,28,29],"firewall","malware","monitoring","security","waf","https:\u002F\u002Fobsyde.com\u002Fproducts","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fobsyde-aegis.1.0.1.zip",null,"2026-07-22T17:31:50.256Z"]