[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7fMUFhM3QPXmCr3yaMy-J0F-IUcgIDPsHe_sU60yLgg":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"rakibantor","RAKIBUZZAMAN","https:\u002F\u002Fprofiles.wordpress.org\u002Frakibantor\u002F",3,80,100,30,94,"2026-08-24T03:21:41.106Z",[14,36,53],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":21,"num_ratings":21,"last_updated":22,"tested_up_to":23,"requires_at_least":24,"requires_php":25,"tags":26,"homepage":32,"download_link":33,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"guestdock","GuestDock — Guest Post Management, Contributor Sandbox, Editorial Workflow & Content Security","1.1.0","\u003Cp>\u003Cstrong>GuestDock\u003C\u002Fstrong> is the most secure and feature-complete way to accept guest posts on WordPress. It creates a fully sandboxed contributor environment where guest authors get temporary, strictly limited, and completely isolated access to the WordPress backend — without ever seeing other users’ content, media, or site settings.\u003C\u002Fp>\n\u003Cp>Unlike the default WordPress contributor role, GuestDock enforces real isolation. Guest authors are completely siloed: they can only view, edit, and interact with their own posts and their own media uploads. No data leaks, no accidental exposure, and no security risks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Who is GuestDock for?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>GuestDock is the ideal guest post plugin for multi-author blogs, online magazines, news sites, content agencies, and any brand that needs to accept guest contributions without compromising WordPress security or editorial quality.\u003C\u002Fp>\n\u003Ch3>✨ Key Features\u003C\u002Fh3>\n\u003Ch4>Sandbox & Access Control\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>True Sandbox Isolation\u003C\u002Fstrong> — Guests are restricted at the query level via \u003Ccode>pre_get_posts\u003C\u002Fcode>, \u003Ccode>ajax_query_attachments\u003C\u002Fcode>, and REST API filters. They only see content they created. No other user’s drafts, media, or data is ever visible.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Time-Limited Guest Access\u003C\u002Fstrong> — Set exact expiration dates for every guest author. Accounts automatically lose access once the time is up — zero manual cleanup.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Post Submission Limits\u003C\u002Fstrong> — Control exactly how many posts each guest can submit. Prevent unlimited content flooding.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Runtime Capability Enforcement\u003C\u002Fstrong> — Belt-and-suspenders: even if another plugin grants capabilities, GuestDock’s runtime filter ensures guests cannot exceed their allowed permissions.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Editorial Workflow\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Approval & Feedback System\u003C\u002Fstrong> — Return posts to “Draft” with inline admin feedback notes. Guests see feedback on their dashboard and in the editor. Automatic email notifications keep everyone in the loop.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Review Queue\u003C\u002Fstrong> — Centralized queue with inline post preview, word count badges, QA status indicators, and direct edit links for efficient editorial review.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Submission Checklist\u003C\u002Fstrong> — A live-updating Gutenberg sidebar panel replaces the old notice-based QA with a modern, visual experience. Color-coded checks for word count, featured image, excerpt, and external links — always visible while writing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Quality Enforcement\u003C\u002Fstrong> — Block submission until guests meet minimum word counts, upload a featured image, and provide a custom excerpt.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Content & SEO Protection\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>SEO & Spam Link Protection\u003C\u002Fstrong> — Limit external links per post and automatically inject \u003Ccode>rel=\"nofollow sponsored\"\u003C\u002Fcode> attributes to safeguard your site’s SEO authority.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Pre-Check Panel\u003C\u002Fstrong> — Built-in Gutenberg sidebar SEO audit: focus keyword detection, heading structure analysis, image alt text coverage, meta description length check, and internal\u002Fexternal link ratio — all with a visual score.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Category Locking\u003C\u002Fstrong> — Restrict guest posts to specific pre-approved categories to maintain your site’s content organization.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gutenberg Block Restriction\u003C\u002Fstrong> — Prevent script injection by denying dangerous blocks (Custom HTML, Shortcode, Code) while allowing access to all other Gutenberg blocks for full content creation. Fully customizable via the \u003Ccode>guestdock_denied_block_types\u003C\u002Fcode> filter.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Media & Upload Security\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Media Upload Security\u003C\u002Fstrong> — Strict MIME type validation (JPG, PNG, GIF, WebP only), configurable file size limits, double-extension checks, and per-user upload quotas with race condition protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>API & XML-RPC Hardening\u003C\u002Fstrong> — Completely disables XML-RPC access and tightly secures REST API endpoints for guest accounts to prevent unauthorized programmatic access.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Analytics & Reporting\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Analytics Dashboard\u003C\u002Fstrong> — Per-guest metrics: posts submitted, approval rate, average word count. Overview cards showing total published posts, active guests, and performance trends.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV Export\u003C\u002Fstrong> — One-click export of all contributor analytics data for stakeholder reporting and content strategy.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Dashboard Widget\u003C\u002Fstrong> — “GuestDock at a Glance” widget on the WordPress dashboard showing pending post count, active guest count, and recent submissions with one-click links to the Review Queue.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Content Templates\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Post Templates\u003C\u002Fstrong> — Admins create reusable content templates (e.g., “Product Review”, “How-To Guide”) with pre-filled structure. Guests select a template when starting a new post, ensuring consistent content format across all contributions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Template Selector Modal\u003C\u002Fstrong> — Beautiful modal overlay intercepts the “Add New Post” button, presenting available templates and a “Start Blank” option.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Guest Experience\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Guest Onboarding Modal\u003C\u002Fstrong> — When a guest first logs in, a branded welcome overlay shows site-specific writing guidelines, content requirements summary, post allowance tracker, and a “Start Writing” call-to-action.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Guest Contributor Profiles\u003C\u002Fstrong> — Public author bio pages with custom bio, website, and social media links (X\u002FTwitter, LinkedIn). Automatically displayed on author archive pages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Writing Guidelines\u003C\u002Fstrong> — Add editorial instructions that appear directly in the guest’s dashboard widget and post list page with smart dismissible notices.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Admin Experience\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Admin Onboarding Wizard\u003C\u002Fstrong> — First-time 4-step setup wizard: configure content rules, create your first invite, set up secure login, and copy the shortcode — all without leaving the page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Inline Guest Management\u003C\u002Fstrong> — Edit expiration dates and post limits directly from the admin dashboard without opening each user profile.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Safe Guest Removal\u003C\u002Fstrong> — Delete guest accounts while safely reassigning their published posts to an administrator, preventing content loss. Automatically cleans up orphaned media.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto Username Generation\u003C\u002Fstrong> — Automatically generate clean usernames from email prefixes during guest creation.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Integrations & Developer Tools\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>REST API\u003C\u002Fstrong> — Full REST API under \u003Ccode>guestdock\u002Fv1\u003C\u002Fcode> namespace: list guests, get guest details, list submissions, view stats. All endpoints require \u003Ccode>manage_options\u003C\u002Fcode> authentication.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Webhooks\u003C\u002Fstrong> — Configure webhook URLs to receive POST notifications on \u003Ccode>guest.invited\u003C\u002Fcode>, \u003Ccode>post.submitted\u003C\u002Fcode>, and \u003Ccode>post.approved\u003C\u002Fcode> events. Compatible with Zapier, Make, Slack, and custom endpoints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Frontend Request Form\u003C\u002Fstrong> — Use the \u003Ccode>[guestdock_request_form]\u003C\u002Fcode> shortcode to let visitors apply for guest author access directly from your site. Built-in honeypot and rate limiting for spam protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Template Customization\u003C\u002Fstrong> — Fully customize the subject and body of all 6 automated email types: Invitations, Feedback Notifications, Approval Confirmations, Submission Alerts, Request Confirmations, and Access Requests.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure Login Integration\u003C\u002Fstrong> — One-click install and activate AuthDock from within GuestDock for magic link authentication, eliminating password management for guest authors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>30+ Developer Hooks\u003C\u002Fstrong> — Over 30 WordPress-style filters and actions across every plugin class for full extensibility, from capabilities and email notifications to validation rules and upload quotas.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>In-Plugin Help Center\u003C\u002Fstrong> — Built-in “Help” and “Shortcode Reference” tabs for instant admin guidance — no external docs needed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean Uninstall\u003C\u002Fstrong> — Proper \u003Ccode>uninstall.php\u003C\u002Fcode> removes all plugin data (options, user meta, post meta, custom post types, transients) when the plugin is deleted.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Documentation & Resources\u003C\u002Fh3>\n\u003Cp>For a complete step-by-step guide on how to use GuestDock, including setup instructions and workflows for both administrators and guest authors, please read our \u003Ca href=\"https:\u002F\u002Fwpinlearn.com\u002Fguestdock-user-guide\" rel=\"nofollow ugc\">GuestDock User Guide\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>To learn more about the philosophy behind GuestDock and why it’s the most secure way to manage guest posts, check out our blog post: \u003Ca href=\"https:\u002F\u002Fwpinlearn.com\u002Fmanage-guest-posts-wordpress-guestdock\" rel=\"nofollow ugc\">The Ultimate Way to Manage Guest Posts on WordPress\u003C\u002Fa>.\u003C\u002Fp>\n","Securely manage guest posts on WordPress. Invite contributors with time-limited access, sandboxed isolation, editorial workflow, analytics, content te &hellip;",1418,0,"2026-06-09T20:17:00.000Z","7.0.2","5.8","7.4",[27,28,29,30,31],"content-security","contributor-management","editorial-workflow","guest-author","guest-post","https:\u002F\u002Fdegird.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fguestdock.1.1.0.zip",null,"2026-07-22T17:31:50.256Z",{"slug":37,"name":38,"version":39,"author":5,"author_profile":6,"description":40,"short_description":41,"active_installs":21,"downloaded":42,"rating":21,"num_ratings":21,"last_updated":43,"tested_up_to":23,"requires_at_least":44,"requires_php":25,"tags":45,"homepage":51,"download_link":52,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"authdock","AuthDock — Login Security, 2FA, Social Login & Brute Force Protection","1.0.2","\u003Cp>\u003Cstrong>AuthDock\u003C\u002Fstrong> is a professional-grade WordPress authentication and user access management plugin that replaces 5–7 separate security plugins with a single, unified solution. Built with WordPress-native UI, REST API, and zero bloat.\u003C\u002Fp>\n\u003Cp>Whether you run a membership site, WooCommerce store, multi-author blog, or corporate intranet — AuthDock gives you full control over how users log in, stay safe, and interact with your site.\u003C\u002Fp>\n\u003Ch4>🔑 Social Login\u003C\u002Fh4>\n\u003Cp>Let users sign in with one click using their existing accounts. No more forgotten passwords.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Google OAuth 2.0\u003C\u002Fstrong> — Sign in with Google using OAuth 2.0 authorization\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Facebook Login\u003C\u002Fstrong> — Authenticate via the Facebook Graph API\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GitHub OAuth\u003C\u002Fstrong> — Developer-friendly sign in with GitHub\u003C\u002Fli>\n\u003Cli>\u003Cstrong>X (Twitter) OAuth 2.0\u003C\u002Fstrong> — Uses OAuth 2.0 with PKCE (S256) for maximum security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Button Style\u003C\u002Fstrong> — Choose between icon + text, icon only, or text only button styles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Button Layout\u003C\u002Fstrong> — Display buttons vertically or horizontally\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Button Order\u003C\u002Fstrong> — Drag and drop to reorder provider buttons\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Default Role\u003C\u002Fstrong> — Assign a specific WordPress role to new social registrations (e.g., Subscriber, Customer)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Registration\u003C\u002Fstrong> — Automatically create WordPress accounts from social profiles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Domain Restriction\u003C\u002Fstrong> — Restrict social login to specific email domains (e.g., \u003Ccode>company.com\u003C\u002Fcode>, \u003Ccode>university.edu\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Avatar Integration\u003C\u002Fstrong> — Automatically set user profile pictures from social account avatars\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Account Linking\u003C\u002Fstrong> — Users can link\u002Funlink social accounts from their WordPress profile page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shortcode\u003C\u002Fstrong> — Place social login buttons anywhere using \u003Ccode>[authdock_social_login]\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer Filters\u003C\u002Fstrong> — \u003Ccode>authdock_allow_social_account_linking\u003C\u002Fcode> and \u003Ccode>authdock_allow_social_registration\u003C\u002Fcode> for custom control\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>✉️ Magic Link Login\u003C\u002Fh4>\n\u003Cp>Passwordless authentication — users receive a one-time login link via email. No passwords to remember or leak.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for passwordless login\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Link Expiry\u003C\u002Fstrong> — Set how long each magic link stays valid (default: 10 minutes)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting\u003C\u002Fstrong> — Max magic link requests per email per hour (default: 5\u002Fhour) to prevent abuse\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allowed Roles\u003C\u002Fstrong> — Restrict magic login to specific user roles (e.g., Subscribers, Editors)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Force Magic Login Mode\u003C\u002Fstrong> — Hide the standard WordPress password form and show only the magic link form\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Email Subject\u003C\u002Fstrong> — Personalize the magic link email subject line\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Email Body\u003C\u002Fstrong> — Customize using merge tags: \u003Ccode>{user_name}\u003C\u002Fcode>, \u003Ccode>{magic_link}\u003C\u002Fcode>, \u003Ccode>{expiry_time}\u003C\u002Fcode>, \u003Ccode>{site_name}\u003C\u002Fcode>, \u003Ccode>{ip_address}\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-Time Use\u003C\u002Fstrong> — Each magic link is cryptographically random and single-use\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Token Invalidation\u003C\u002Fstrong> — Magic links are automatically invalidated when a user changes their password\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anti-Enumeration\u003C\u002Fstrong> — Generic success messages prevent attackers from discovering valid email addresses\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shortcode\u003C\u002Fstrong> — Display the form anywhere with \u003Ccode>[authdock_magic_login]\u003C\u002Fcode> and optional \u003Ccode>redirect\u003C\u002Fcode> attribute\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔐 Two-Factor Authentication (2FA)\u003C\u002Fh4>\n\u003Cp>Add a second layer of security to every login. Supports TOTP authenticator apps and email-based verification codes.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for two-factor authentication\u003C\u002Fli>\n\u003Cli>\u003Cstrong>TOTP Method\u003C\u002Fstrong> — Time-based One-Time Passwords (RFC 6238) with QR code provisioning via Google Authenticator, Authy, Microsoft Authenticator, etc.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Method\u003C\u002Fstrong> — Receive a 6-digit numeric verification code via email\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enforced Roles\u003C\u002Fstrong> — Force specific WordPress roles (e.g., Administrator, Editor) to enable 2FA\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Grace Period\u003C\u002Fstrong> — Give users configurable days to set up 2FA before enforcement kicks in (default: 3 days)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trusted Devices\u003C\u002Fstrong> — Allow users to skip 2FA on recognized devices for configurable days (default: 30 days)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backup Recovery Codes\u003C\u002Fstrong> — Generate 10 one-time-use backup codes for account recovery if the authenticator is lost\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-Force Protection\u003C\u002Fstrong> — Rate-limited to 5 verification attempts per session to prevent code guessing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Encrypted Secret Storage\u003C\u002Fstrong> — TOTP secrets encrypted with AES-256-CBC before storing in the database\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Replay Protection\u003C\u002Fstrong> — Each TOTP code can only be used once per time window (RFC 6238 §5.2)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clock Drift Tolerance\u003C\u002Fstrong> — Accepts codes from ±1 time step (30 seconds) to handle minor clock differences\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Interstitial Challenge Screen\u003C\u002Fstrong> — Clean, WordPress-native verification screen after primary authentication\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Management\u003C\u002Fstrong> — Administrators can view and disable 2FA for any user from the profile page\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🛡️ Brute Force Protection (Login Limiter)\u003C\u002Fh4>\n\u003Cp>Stop brute-force attacks with intelligent lockout rules that escalate automatically.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for login attempt limiting\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Max Attempts\u003C\u002Fstrong> — Set the number of failed login attempts before lockout (default: 5)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lockout Duration\u003C\u002Fstrong> — Initial lockout period in minutes (default: 15 minutes)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Progressive Lockout\u003C\u002Fstrong> — Lockouts escalate: 15 min \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> 1 hour \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> 24 hours for repeat offenders\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Blacklist\u003C\u002Fstrong> — Permanently ban an IP after a configurable number of lockouts (e.g., after 5)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Whitelist\u003C\u002Fstrong> — Allow trusted IPs to bypass login limits (supports exact match, CIDR ranges like \u003Ccode>192.168.1.0\u002F24\u003C\u002Fcode>, and wildcards like \u003Ccode>10.0.0.*\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Blacklist\u003C\u002Fstrong> — Permanently block specific IP addresses, CIDR ranges, or wildcard patterns\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notify Admin on Lockout\u003C\u002Fstrong> — Email alerts when an IP gets locked out\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notify Threshold\u003C\u002Fstrong> — Configure after how many lockouts the notification triggers (default: 1)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC Integration\u003C\u002Fstrong> — Automatically block XML-RPC authentication from locked-out IPs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Page Warnings\u003C\u002Fstrong> — Display remaining attempt count and lockout timers on the login page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Log Retention\u003C\u002Fstrong> — Configure how long failed login data is retained (default: 30 days)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trusted Proxies\u003C\u002Fstrong> — Specify trusted reverse proxy IPs for accurate client IP detection behind load balancers\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔄 Dynamic Login & Logout Redirects\u003C\u002Fh4>\n\u003Cp>Send users exactly where they need to go — based on their role, or if it is their first login.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Role-Based Login Redirects\u003C\u002Fstrong> — Set a custom URL per WordPress role after login (e.g., Editors \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Ccode>\u002Feditorial-dashboard\u003C\u002Fcode>, Subscribers \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Ccode>\u002Fmembers-area\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Role-Based Logout Redirects\u003C\u002Fstrong> — Set a custom URL per WordPress role after logout\u003C\u002Fli>\n\u003Cli>\u003Cstrong>First-Login Redirect\u003C\u002Fstrong> — Redirect new users to a welcome page, onboarding wizard, or setup screen on their first login\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Relative & Absolute URLs\u003C\u002Fstrong> — Supports both relative paths (\u003Ccode>\u002Fdashboard\u003C\u002Fcode>) and full URLs (\u003Ccode>https:\u002F\u002Fexample.com\u002Fwelcome\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Open Redirect Prevention\u003C\u002Fstrong> — Redirects validated via \u003Ccode>wp_safe_redirect()\u003C\u002Fcode> and \u003Ccode>wp_validate_redirect()\u003C\u002Fcode> to prevent open redirect attacks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>📋 Audit Logging\u003C\u002Fh4>\n\u003Cp>Keep a complete, searchable record of every authentication event happening on your site.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for audit logging\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tracked Events\u003C\u002Fstrong> — Login success\u002Ffailure, logout, password reset\u002Fchange, user registration, profile updates, social login\u002Flinking, magic link requests\u002Fusage, 2FA changes, session termination, access blocked, lockout events\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Event Details\u003C\u002Fstrong> — Each entry records: user ID, event type, IP, user agent, JSON context, and timestamp\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Retention Period\u003C\u002Fstrong> — Choose how long to keep logs: 30, 60, 90, 180, 365 days, or unlimited\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Cleanup\u003C\u002Fstrong> — Daily WP-Cron job removes expired entries in batches of 1,000 to prevent database locks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Filter by Event Type\u003C\u002Fstrong> — View specific event categories (e.g., only failed logins)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Filter by Date Range\u003C\u002Fstrong> — Narrow results by \u003Ccode>date_from\u003C\u002Fcode> and \u003Ccode>date_to\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Filter by User\u003C\u002Fstrong> — View all events for a specific user ID\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Search by IP\u003C\u002Fstrong> — Find all events from a particular IP address\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full-Text Search\u003C\u002Fstrong> — Search across event types, IPs, and context data\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV Export\u003C\u002Fstrong> — Download audit logs as a CSV file with formula injection protection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>JSON Export\u003C\u002Fstrong> — Export logs in JSON format for integration with external tools\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purge All Logs\u003C\u002Fstrong> — One-click purge to clear all historical log data\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin UI Viewer\u003C\u002Fstrong> — Built-in admin page with paginated table, filters, and export buttons\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Database Table\u003C\u002Fstrong> — Logs stored in a dedicated \u003Ccode>authdock_audit_logs\u003C\u002Fcode> table with proper indexes for fast queries\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🏰 Security Hardening\u003C\u002Fh4>\n\u003Cp>Close common WordPress security holes without installing another plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Custom Login URL\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Custom Slug\u003C\u002Fstrong> — Replace \u003Ccode>wp-login.php\u003C\u002Fcode> with your own secret URL (e.g., \u003Ccode>\u002Fmy-secure-login\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Block Action\u003C\u002Fstrong> — Choose what happens when someone visits \u003Ccode>wp-login.php\u003C\u002Fcode>: return a 404 error or redirect to the homepage\u003Cbr \u002F>\n* \u003Cstrong>Recovery Key\u003C\u002Fstrong> — Access the login page via a secret query parameter even when the custom URL is active\u003C\u002Fp>\n\u003Cp>\u003Cstrong>XML-RPC Control\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Disable XML-RPC\u003C\u002Fstrong> — Completely disable XML-RPC to block remote brute-force attacks\u003Cbr \u002F>\n* \u003Cstrong>Partial Disable\u003C\u002Fstrong> — Remove only authentication methods while keeping pingbacks functional\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API Restriction\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Restrict to Authenticated Users\u003C\u002Fstrong> — Block all REST API access for unauthenticated visitors\u003Cbr \u002F>\n* \u003Cstrong>Namespace Whitelist\u003C\u002Fstrong> — Allow specific third-party REST namespaces (e.g., WooCommerce, Jetpack) to remain public\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Enumeration Prevention\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Block Author Archives\u003C\u002Fstrong> — Redirect \u003Ccode>?author=N\u003C\u002Fcode> enumeration queries to the homepage\u003Cbr \u002F>\n* \u003Cstrong>Restrict User REST Endpoint\u003C\u002Fstrong> — Block \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode> for non-logged-in users\u003Cbr \u002F>\n* \u003Cstrong>Generic Login Errors\u003C\u002Fstrong> — Replace “username not found” or “wrong password” messages with a generic error\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Password Strength Enforcement\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Force Strong Passwords\u003C\u002Fstrong> — Master toggle for password policy enforcement\u003Cbr \u002F>\n* \u003Cstrong>Minimum Length\u003C\u002Fstrong> — Set the minimum password length (default: 8 characters)\u003Cbr \u002F>\n* \u003Cstrong>Require Uppercase\u003C\u002Fstrong> — Mandate at least one uppercase letter\u003Cbr \u002F>\n* \u003Cstrong>Require Lowercase\u003C\u002Fstrong> — Mandate at least one lowercase letter\u003Cbr \u002F>\n* \u003Cstrong>Require Number\u003C\u002Fstrong> — Mandate at least one numeric digit\u003Cbr \u002F>\n* \u003Cstrong>Require Special Character\u003C\u002Fstrong> — Mandate at least one special character (e.g., \u003Ccode>!@#$%\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Enforced Roles\u003C\u002Fstrong> — Apply password rules only to specific roles\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security HTTP Headers\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>X-Content-Type-Options\u003C\u002Fstrong> — Prevents MIME-type sniffing (\u003Ccode>nosniff\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>X-Frame-Options\u003C\u002Fstrong> — Blocks clickjacking by restricting iframe embedding (\u003Ccode>SAMEORIGIN\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>X-XSS-Protection\u003C\u002Fstrong> — Legacy XSS filter for older browsers (\u003Ccode>1; mode=block\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Referrer-Policy\u003C\u002Fstrong> — Controls referrer information sent with requests (\u003Ccode>strict-origin-when-cross-origin\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Strict-Transport-Security (HSTS)\u003C\u002Fstrong> — Enforces HTTPS connections for 1 year (\u003Ccode>max-age=31536000; includeSubDomains\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Permissions-Policy\u003C\u002Fstrong> — Restricts access to camera, microphone, and geolocation APIs\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Role-Based Session Duration\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Per-Role Cookie Lifetime\u003C\u002Fstrong> — Set different authentication cookie durations per WordPress role (in hours)\u003C\u002Fp>\n\u003Ch4>📧 Email Notifications\u003C\u002Fh4>\n\u003Cp>Stay informed about critical security events with real-time email alerts — for admins and users.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin Notifications\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Multiple Failed Logins\u003C\u002Fstrong> — Alert every N failed attempts from the same IP (default: every 3)\u003Cbr \u002F>\n* \u003Cstrong>IP Lockout\u003C\u002Fstrong> — Alert when an IP gets locked out\u003Cbr \u002F>\n* \u003Cstrong>Admin Login Alert\u003C\u002Fstrong> — Notify when an administrator account logs in\u003Cbr \u002F>\n* \u003Cstrong>New User Registration\u003C\u002Fstrong> — Alert on every new user registration\u003Cbr \u002F>\n* \u003Cstrong>User Promoted to Admin\u003C\u002Fstrong> — Alert when any user is promoted to the Administrator role\u003Cbr \u002F>\n* \u003Cstrong>Admin Password Changed\u003C\u002Fstrong> — Alert when an administrator’s password is changed or reset\u003Cbr \u002F>\n* \u003Cstrong>2FA Disabled\u003C\u002Fstrong> — Alert when any user disables two-factor authentication\u003Cbr \u002F>\n* \u003Cstrong>Login from New IP\u003C\u002Fstrong> — Alert when a user logs in from a previously unseen IP address\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Self-Notifications\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Password Changed\u003C\u002Fstrong> — Notify the user when their password is changed\u003Cbr \u002F>\n* \u003Cstrong>Email Changed\u003C\u002Fstrong> — Notify at the OLD email address when a user’s email is updated (security measure)\u003Cbr \u002F>\n* \u003Cstrong>2FA Status Changed\u003C\u002Fstrong> — Notify the user when 2FA is enabled or disabled on their account\u003Cbr \u002F>\n* \u003Cstrong>Social Account Linked\u003C\u002Fstrong> — Notify when a social provider is connected to their account\u003Cbr \u002F>\n* \u003Cstrong>New Device Login\u003C\u002Fstrong> — Notify the user when a login is detected from a new IP address\u003Cbr \u002F>\n* \u003Cstrong>Account Locked\u003C\u002Fstrong> — Notify the user when their account is locked due to failed attempts\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification Settings\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Custom Recipients\u003C\u002Fstrong> — Set custom email addresses for admin notifications (defaults to site admin email)\u003Cbr \u002F>\n* \u003Cstrong>Throttle Period\u003C\u002Fstrong> — Configurable cooldown in minutes to prevent notification flooding (default: 60 minutes)\u003Cbr \u002F>\n* \u003Cstrong>Digest Mode\u003C\u002Fstrong> — Option to batch notifications instead of sending them individually\u003Cbr \u002F>\n* \u003Cstrong>Test Email\u003C\u002Fstrong> — Send a test notification to verify email configuration is working\u003C\u002Fp>\n\u003Ch4>🚪 wp-admin Access Control\u003C\u002Fh4>\n\u003Cp>Restrict who can access the WordPress dashboard — by role, by IP, or both.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for access control\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocked Roles\u003C\u002Fstrong> — Select which roles are blocked from accessing \u003Ccode>\u002Fwp-admin\u003C\u002Fcode> (e.g., Subscriber, Customer)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Restriction Mode\u003C\u002Fstrong> — Enable IP-based restrictions so only whitelisted IPs can access wp-admin\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Whitelist\u003C\u002Fstrong> — Specify allowed IP addresses and CIDR ranges (e.g., \u003Ccode>203.0.113.5\u003C\u002Fcode>, \u003Ccode>192.168.1.0\u002F24\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Admin Bar\u003C\u002Fstrong> — Remove the WordPress admin bar from the frontend for blocked roles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Redirect Action\u003C\u002Fstrong> — Choose what happens when access is denied: redirect to homepage, custom URL, or show a 403 Forbidden page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Redirect URL\u003C\u002Fstrong> — Set a specific URL for the access-denied redirect\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Emergency Bypass Key\u003C\u002Fstrong> — Secret query parameter (\u003Ccode>?authdock_bypass=YOUR_KEY\u003C\u002Fcode>) to regain access if locked out\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Exceptions\u003C\u002Fstrong> — AJAX requests, WP-Cron, and \u003Ccode>admin-post.php\u003C\u002Fcode> always allowed through\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Administrator Immunity\u003C\u002Fstrong> — Administrators are never blocked, regardless of settings\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>⏱️ Session Management\u003C\u002Fh4>\n\u003Cp>Take control of user sessions — limit concurrent logins, enforce idle timeouts, and terminate sessions remotely.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for session management\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Concurrent Session Limit\u003C\u002Fstrong> — Maximum simultaneous sessions per user (0 = unlimited). Oldest sessions are destroyed when the limit is exceeded\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Idle Session Timeout\u003C\u002Fstrong> — Auto-logout after configurable inactivity period (in minutes, 0 = disabled)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-Role Session Duration\u003C\u002Fstrong> — Different session lifetimes for each WordPress role (in hours)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Session Viewer\u003C\u002Fstrong> — View all active sessions via the REST API, including user details and last activity timestamps\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remote Session Termination\u003C\u002Fstrong> — Administrators can terminate all sessions for any user via a single API call\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Throttled Activity Tracking\u003C\u002Fstrong> — Last-activity timestamps updated at most once per 5 minutes to minimize database writes\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>⚡ Performance & Infrastructure\u003C\u002Fh4>\n\u003Cp>AuthDock is built for speed and follows WordPress best practices from top to bottom.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Conditional Asset Loading\u003C\u002Fstrong> — CSS and JavaScript files load only on pages where they are needed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Indexed Database Tables\u003C\u002Fstrong> — Custom tables use proper indexes for fast lookups\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-Cron Maintenance\u003C\u002Fstrong> — Audit log cleanup runs via non-blocking WP-Cron\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Transient-Based Tracking\u003C\u002Fstrong> — Brute force tracking uses transients (no additional DB queries per login attempt)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Powered\u003C\u002Fstrong> — All admin data operations go through the \u003Ccode>authdock\u002Fv1\u003C\u002Fcode> namespace with 15+ endpoints\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hook-Based Architecture\u003C\u002Fstrong> — Centralized Loader class registers all hooks for clean dependency management\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Capabilities\u003C\u002Fstrong> — \u003Ccode>authdock_manage_settings\u003C\u002Fcode>, \u003Ccode>authdock_view_audit_logs\u003C\u002Fcode>, \u003Ccode>authdock_export_audit_logs\u003C\u002Fcode>, \u003Ccode>authdock_manage_sessions\u003C\u002Fcode>, \u003Ccode>authdock_manage_lockouts\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean Activation\u003C\u002Fstrong> — Creates database tables, sets defaults, registers capabilities, and schedules cron\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean Deactivation\u003C\u002Fstrong> — Clears cron events but preserves all settings for reactivation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full Uninstall\u003C\u002Fstrong> — Removes everything: options, user meta, database tables, capabilities, and transients\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full i18n\u003C\u002Fstrong> — All user-facing strings use WordPress internationalization functions with the \u003Ccode>authdock\u003C\u002Fcode> text domain\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🤔 Why Choose AuthDock?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Replace 5–7 plugins\u003C\u002Fstrong> — Social login + magic links + 2FA + brute force + audit logs + session management + access control — all in one\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress-native UI\u003C\u002Fstrong> — Looks and feels like core WordPress, not a foreign dashboard\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API powered\u003C\u002Fstrong> — Modern, secure data handling for all admin operations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight & fast\u003C\u002Fstrong> — Conditional loading, object caching, zero external frameworks in admin\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer-friendly\u003C\u002Fstrong> — Extensive hooks, filters, and custom capabilities for extensibility\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress.org compliant\u003C\u002Fstrong> — No tracking, no encoded code, no forced upsells, full GPL-2.0+\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔗 Shortcodes\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>[authdock_social_login]\u003C\u002Fcode> — Display social login buttons (attributes: \u003Ccode>layout\u003C\u002Fcode>, \u003Ccode>style\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Ccode>[authdock_magic_login]\u003C\u002Fcode> — Display magic link login form (attributes: \u003Ccode>redirect\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Ccode>[authdock_login_form]\u003C\u002Fcode> — Display login form with 2FA support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Google OAuth\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Facebook Login\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Flegal\u002Fterms\" rel=\"nofollow ugc\">Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fprivacy\u002Fpolicy\u002F\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GitHub OAuth\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fgithub-terms\u002Fgithub-terms-of-service\" rel=\"nofollow ugc\">Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fprivacy-policies\u002Fgithub-general-privacy-statement\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>X (Twitter) OAuth\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fx.com\u002Fen\u002Ftos\" rel=\"nofollow ugc\">Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fx.com\u002Fen\u002Fprivacy\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","All-in-one WordPress authentication: social login, magic links, 2FA, brute force protection, session management & security hardening.",173,"2026-06-10T09:19:00.000Z","6.0",[46,47,48,49,50],"access-control","brute-force-protection","login-security","social-login","two-factor-authentication","https:\u002F\u002Fdegird.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fauthdock.1.0.2.zip",{"slug":54,"name":55,"version":56,"author":5,"author_profile":6,"description":57,"short_description":58,"active_installs":21,"downloaded":59,"rating":21,"num_ratings":21,"last_updated":60,"tested_up_to":23,"requires_at_least":61,"requires_php":25,"tags":62,"homepage":68,"download_link":69,"security_score":9,"vuln_count":21,"unpatched_count":21,"last_vuln_date":34,"fetched_at":35},"syncdock","SyncDock","1.0.1","\u003Cp>\u003Cstrong>SyncDock\u003C\u002Fstrong> is a headless MCP-style API gateway plugin that transforms your WordPress site into a fully controllable content intelligence and publishing platform — accessible by AI agents, SaaS applications, browser extensions, desktop apps, and any external client.\u003C\u002Fp>\n\u003Ch4>Why SyncDock?\u003C\u002Fh4>\n\u003Cp>WordPress’s native REST API provides basic CRUD operations, but modern AI workflows, automation pipelines, and external integrations demand much more. SyncDock bridges the gap with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Secure API Key Authentication\u003C\u002Fstrong> — SHA-256 hashed keys with per-key scopes, rate limits, and expiration\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HMAC-SHA256 Signature Verification\u003C\u002Fstrong> — Tamper-proof request signing with replay protection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gutenberg Block Converter\u003C\u002Fstrong> — Bidirectional JSON \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">↔\u003C\u002Fspan> block markup for 18+ core block types\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Context Layer\u003C\u002Fstrong> — AI-optimized intelligence endpoints for content discovery and gap analysis\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Query Engine\u003C\u002Fstrong> — Multi-filter content search with taxonomy AND\u002FOR logic\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Plugin Bridge\u003C\u002Fstrong> — Auto-detects Yoast, Rank Math, and AIOSEO for transparent SEO metadata\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Response Caching\u003C\u002Fstrong> — Configurable TTL with auto-invalidation on content changes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity Logging\u003C\u002Fstrong> — Full request audit trail with retention policies\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>🔐 Multi-Layer Security\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>API Key authentication with SHA-256 hashing (keys never stored in plaintext)\u003C\u002Fli>\n\u003Cli>Optional HMAC-SHA256 request signing with 5-minute replay window\u003C\u002Fli>\n\u003Cli>10 granular permission scopes (\u003Ccode>read_posts\u003C\u002Fcode>, \u003Ccode>write_posts\u003C\u002Fcode>, \u003Ccode>delete_posts\u003C\u002Fcode>, etc.)\u003C\u002Fli>\n\u003Cli>Per-key and per-IP rate limiting with sliding window\u003C\u002Fli>\n\u003Cli>Failed authentication brute-force protection (10 failures \u002F 15 min \u002F IP)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>📝 Full Post Lifecycle\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Create, read, update (PUT\u002FPATCH), and delete posts\u003C\u002Fli>\n\u003Cli>Structured Gutenberg block input\u002Foutput (JSON \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">↔\u003C\u002Fspan> block markup)\u003C\u002Fli>\n\u003Cli>Partial block-level updates (insert\u002Freplace\u002Fdelete by index)\u003C\u002Fli>\n\u003Cli>Post revision listing and one-click restore\u003C\u002Fli>\n\u003Cli>Scheduled publishing via \u003Ccode>status: future\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>SEO metadata sync with popular SEO plugins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🧠 Content Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>\u002Fcontext\u002Fposts\u003C\u002Fcode> — Recent, popular, and similar posts with content gap analysis\u003C\u002Fli>\n\u003Cli>\u003Ccode>\u002Fcontext\u002Ftaxonomies\u003C\u002Fcode> — Hierarchical category trees and tag clouds\u003C\u002Fli>\n\u003Cli>\u003Ccode>\u002Fcontext\u002Fmedia\u003C\u002Fcode> — Library summary, MIME distribution, unattached files\u003C\u002Fli>\n\u003Cli>\u003Ccode>\u002Fcontext\u002Fsite-info\u003C\u002Fcode> — Site configuration, image sizes, post types\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🔍 Query Engine\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Multi-taxonomy filters with AND\u002FOR logic\u003C\u002Fli>\n\u003Cli>Date range queries on publish or modified dates\u003C\u002Fli>\n\u003Cli>Full-text search with highlighted excerpts\u003C\u002Fli>\n\u003Cli>Site-wide content discovery endpoint\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>📁 Media Management\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Upload via multipart\u002Fform-data or base64 JSON\u003C\u002Fli>\n\u003Cli>Server-side MIME type validation\u003C\u002Fli>\n\u003Cli>Attach\u002Fdetach media from posts\u003C\u002Fli>\n\u003Cli>Full image metadata and size information\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>⚙️ Admin Dashboard\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Real-time API metrics (requests, errors, response times)\u003C\u002Fli>\n\u003Cli>API key management with one-click creation and revocation\u003C\u002Fli>\n\u003Cli>Filterable activity log with status\u002Fmethod\u002Fsearch\u003C\u002Fli>\n\u003Cli>System health monitoring\u003C\u002Fli>\n\u003Cli>Configurable rate limits, caching, and data retention\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Is SyncDock For?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>AI Agents\u003C\u002Fstrong> — Connect Claude, GPT, or custom models to publish and manage content\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SaaS Applications\u003C\u002Fstrong> — Build external content management dashboards\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Browser Extensions\u003C\u002Fstrong> — Create write-from-anywhere tools\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Desktop Apps\u003C\u002Fstrong> — Build native publishing applications\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automation Pipelines\u003C\u002Fstrong> — Integrate WordPress into CI\u002FCD or content workflows\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mobile Apps\u003C\u002Fstrong> — Power native mobile content creation tools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin does \u003Cstrong>not\u003C\u002Fstrong> connect to any external third-party services. All data processing — including API key management, authentication, rate limiting, caching, and content operations — is performed entirely on your WordPress server.\u003C\u002Fp>\n\u003Cp>Gravatar avatar URLs may appear in API responses for post authors. This is standard WordPress core behavior (\u003Ccode>get_avatar_url()\u003C\u002Fcode>) and is not initiated by SyncDock.\u003C\u002Fp>\n","A universal MCP-style API gateway that transforms WordPress into a fully controllable content intelligence and publishing platform.",61,"2026-07-18T12:57:00.000Z","6.4",[63,64,65,66,67],"api","content-management","headless","publishing","rest-api","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsyncdock.1.0.1.zip"]