[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNtMaBMScFE3vcxawir1HBZX_sP6JY0CTh1kQr3DQOno":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"vithanhlam","CodeWP","https:\u002F\u002Fprofiles.wordpress.org\u002Fvithanhlam\u002F",3,70,95,30,91,"2026-08-25T04:04:23.808Z",[14,37,52],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":10,"downloaded":20,"rating":21,"num_ratings":21,"last_updated":22,"tested_up_to":23,"requires_at_least":24,"requires_php":25,"tags":26,"homepage":32,"download_link":33,"security_score":34,"vuln_count":21,"unpatched_count":21,"last_vuln_date":35,"fetched_at":36},"codewp-shield-monitor","CodeWP Shield Monitor","1.4.1","\u003Cp>CodeWP Shield Monitor (ShieldPress) adds a careful baseline of WordPress security controls without sending site data to third parties by default.\u003C\u002Fp>\n\u003Cp>Monitor your website health anywhere — visit \u003Ca href=\"https:\u002F\u002Fshieldpress.net\" rel=\"nofollow ugc\">shieldpress.net\u003C\u002Fa> or download the ShieldPress app on \u003Ca href=\"https:\u002F\u002Fapps.apple.com\u002Fapp\u002Fshieldpress\" rel=\"nofollow ugc\">iOS\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fplay.google.com\u002Fstore\u002Fapps\u002Fdetails?id=net.shieldpress.app\" rel=\"nofollow ugc\">Android\u003C\u002Fa> to keep track of your site’s security status, receive real-time alerts, and manage protection settings on the go.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security & Hardening\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Rate limits repeated failed logins by hashed IP address.\u003C\u002Fli>\n\u003Cli>Restricts public user enumeration.\u003C\u002Fli>\n\u003Cli>Adds conservative browser security headers.\u003C\u002Fli>\n\u003Cli>Optionally disables XML-RPC.\u003C\u002Fli>\n\u003Cli>Disables dashboard file editing.\u003C\u002Fli>\n\u003Cli>Hides the default login\u002Fadmin paths behind a custom login slug when enabled.\u003C\u002Fli>\n\u003Cli>Shows failed-login IPs with manual block and unlock controls.\u003C\u002Fli>\n\u003Cli>Adds honeypot fields to login, registration, and comment forms to silently block automated bots.\u003C\u002Fli>\n\u003Cli>Blocks PHP execution inside the uploads directory and prevents uploading dangerous file types.\u003C\u002Fli>\n\u003Cli>Supports comment and registration rate limiting per IP with optional math CAPTCHA challenges.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Monitoring & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records a local security audit log with configurable retention (30 days default).\u003C\u002Fli>\n\u003Cli>Monitors important WordPress files every five minutes using SHA-256 hashes.\u003C\u002Fli>\n\u003Cli>Runs lightweight suspicious-code and database scans with severity-based findings.\u003C\u002Fli>\n\u003Cli>Adds threat intelligence checks for admin anomalies, executable uploads, suspicious options, cron hooks, MU plugins, fake CAPTCHA content, external scripts, cloaking signals, and hardening gaps.\u003C\u002Fli>\n\u003Cli>Ships 38 built-in threat detection patterns covering web shells, backdoors, obfuscation techniques, credit card skimmers, SEO spam, PHP object injection, SQL injection, SSRF, and more — based on real-world CVEs and active malware campaigns (Balada Injector, Sign1, SocGholish, mu-plugins backdoors).\u003C\u002Fli>\n\u003Cli>Skips previously clean malware-scan files while their SHA-256 hash is unchanged.\u003C\u002Fli>\n\u003Cli>Flags external JavaScript and URLs outside the current site domain in source or database content.\u003C\u002Fli>\n\u003Cli>Lets administrators run manual scans or schedule scans daily, weekly, or monthly.\u003C\u002Fli>\n\u003Cli>Emails alerts for administrator logins, blocked login attacks, file changes, and suspicious scan findings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Threat Patterns\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Includes a Web Application Firewall (WAF) to block SQL injection, XSS, path traversal, PHP object injection, SSRF, CRLF injection, and other common attack patterns.\u003C\u002Fli>\n\u003Cli>Provides an extensible threat pattern engine for custom malware signatures, WAF rules, and database content patterns with import\u002Fexport support.\u003C\u002Fli>\n\u003Cli>Rate-limits audit log events to prevent database flooding during brute-force attacks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Activity & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records recent public content create\u002Fupdate activity and new administrator access.\u003C\u002Fli>\n\u003Cli>Records WordPress core, plugin, and theme update events.\u003C\u002Fli>\n\u003Cli>Records plugin and theme lifecycle events, including activation, deactivation, installs, and updates.\u003C\u002Fli>\n\u003Cli>Pushes Contact Form 7 submissions, WooCommerce orders, and selected custom post type creations to the authenticated events API.\u003C\u002Fli>\n\u003Cli>Provides an incident-response summary with prioritized findings and next review steps.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>App & API Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Displays basic WordPress security and update status in wp-admin.\u003C\u002Fli>\n\u003Cli>Provides token-authenticated REST endpoints for the ShieldPress App and Web dashboard.\u003C\u002Fli>\n\u003Cli>Pairs the App using a local QR code and a short-lived, one-time exchange code.\u003C\u002Fli>\n\u003Cli>Creates scoped, one-time quick-login URLs for paired App\u002FWeb clients when enabled.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Tools\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Provides database cleanup tools for spam, revisions, orphaned data, expired transients, and inactive subscriber accounts.\u003C\u002Fli>\n\u003Cli>Offers media optimization with optional thumbnail generation control and automatic WebP conversion on upload.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>CodeWP Shield Monitor hashes IP addresses in its 30-day audit log. For failed-login lockout management, it may also store recent source IP addresses, attempt counts, lockout status, and last failed-login time so administrators can block or unlock those IPs. File contents and post body content are never stored.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>CodeWP Shield Monitor can connect to the official WordPress.org checksum API when the administrator enables core checksum verification. The service is used to compare local WordPress core file hashes with official release hashes. It sends the installed WordPress version and site locale at most once every 12 hours; it does not send stored credentials, file contents, full database values, post body content, audit-log IP hashes, API tokens, or CAPTCHA tokens. WordPress.org provides this service under the WordPress.org Terms of Service and Privacy Policy.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms-of-service\u002F\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>CodeWP Shield Monitor can connect to Cloudflare Turnstile only when an administrator enables CAPTCHA challenges, selects Cloudflare Turnstile, saves a Turnstile site key and secret key, and chooses the forms to protect. Public pages that may contain selected login, registration, or WooCommerce checkout forms can load Cloudflare’s Turnstile JavaScript from challenges.cloudflare.com to display the challenge. During protected form submissions, the plugin sends the Turnstile response token, configured secret key, and visitor IP address to Cloudflare’s siteverify endpoint to validate the challenge. This is required for the optional Turnstile CAPTCHA feature.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\u003C\u002Fp>\n\u003Cp>CodeWP Shield Monitor can connect to Google reCAPTCHA only when an administrator enables CAPTCHA challenges, selects Google reCAPTCHA v2 or v3, saves a reCAPTCHA site key and secret key, and chooses the forms to protect. Public pages that may contain selected login, registration, or WooCommerce checkout forms can load Google’s reCAPTCHA JavaScript from google.com to display or run the challenge. During protected form submissions, the plugin sends the reCAPTCHA response token, configured secret key, and visitor IP address to Google’s siteverify endpoint to validate the challenge. When Google reCAPTCHA v3 is selected, the plugin also checks the returned score against the configured threshold, which defaults to 0.1. This is required for the optional Google reCAPTCHA feature.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n","Privacy-first WordPress security hardening, login protection, and local audit logging.",200,0,"2026-07-15T09:48:00.000Z","7.0.2","6.4","7.4",[27,28,29,30,31],"audit-log","hardening","login","privacy","security","https:\u002F\u002Fshieldpress.net","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcodewp-shield-monitor.zip",100,null,"2026-07-22T17:31:50.256Z",{"slug":38,"name":39,"version":40,"author":5,"author_profile":6,"description":41,"short_description":42,"active_installs":10,"downloaded":43,"rating":21,"num_ratings":21,"last_updated":44,"tested_up_to":45,"requires_at_least":46,"requires_php":47,"tags":48,"homepage":50,"download_link":51,"security_score":34,"vuln_count":21,"unpatched_count":21,"last_vuln_date":35,"fetched_at":36},"order-tags-code-wp","Order Tags","1.0.4","\u003Cp>This application easily assigns tags to orders, and you can effortlessly customize unlimited colors.\u003C\u002Fp>\n\u003Cp>Advantages include the ease of quickly adding and removing tags with the ability to select custom colors that appear alongside order information.\u003C\u002Fp>\n\u003Cp>Support https:\u002F\u002Fcode-wp.com\u003C\u002Fp>\n","Easily assign tags to orders and customize unlimited colors effortlessly.",1119,"2026-04-09T12:56:00.000Z","6.4.8","6.4.2","7.4.0",[49],"tags-order","https:\u002F\u002Fcode-wp.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Forder-tags-code-wp.zip",{"slug":53,"name":54,"version":55,"author":5,"author_profile":6,"description":56,"short_description":57,"active_installs":58,"downloaded":59,"rating":34,"num_ratings":60,"last_updated":61,"tested_up_to":62,"requires_at_least":24,"requires_php":25,"tags":63,"homepage":50,"download_link":65,"security_score":66,"vuln_count":21,"unpatched_count":21,"last_vuln_date":35,"fetched_at":36},"api-code-wp","API CODE-WP kết nối ứng dụng Android – iOS","1.1.9","\u003Cp>Ứng dụng quản lý website WordPress sử dụng Woocommerce giúp bạn dễ dàng quản lý thông tin và dữ liệu trên điện thoại di động một cách dễ dàng nhất, hiện tại ứng dụng đã hỗ trợ quản lý.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Đơn hàng\u003C\u002Fli>\n\u003Cli>Sản phẩm\u003C\u002Fli>\n\u003Cli>Bài viết\u003C\u002Fli>\n\u003Cli>Trang\u003C\u002Fli>\n\u003Cli>Danh mục sản phẩm\u003C\u002Fli>\n\u003Cli>Danh mục bài viết \u003C\u002Fli>\n\u003Cli>Từ khóa\u003C\u002Fli>\n\u003Cli>Yoast SEO \u003C\u002Fli>\n\u003Cli>Contact Form 7\u003C\u002Fli>\n\u003Cli>Woocommerce\u003C\u002Fli>\n\u003Cli>Sản phẩm có thuộc tính\u003C\u002Fli>\n\u003Cli>Sản phẩm biến thể\u003C\u002Fli>\n\u003Cli>Sản phẩm đơn giản\u003C\u002Fli>\n\u003Cli>Thống kê dữ liệu\u003C\u002Fli>\n\u003Cli>Nhận thông báo đơn hàng và liên hệ qua ứng dụng \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>CodeWP API for Android and iOS\u003C\u002Fp>\n\u003Cp>This plugin provides an API for Android and iOS applications.\u003C\u002Fp>\n\u003Ch3>3rd Party Services\u003C\u002Fh3>\n\u003Cp>This plugin uses the following 3rd party services:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Expo Push Notification Service\u003C\u002Fstrong>: This service is used to send push notifications.\u003C\u002Fli>\n\u003Cli>Service URL: \u003Ca href=\"https:\u002F\u002Fexp.host\u002F--\u002Fapi\u002Fv2\u002Fpush\u002Fsend\" rel=\"nofollow ugc\">https:\u002F\u002Fexp.host\u002F–\u002Fapi\u002Fv2\u002Fpush\u002Fsend\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Privacy Policy & Terms of Use API CODE-WP: \u003Ca href=\"https:\u002F\u002Fcode-wp.com\u002Fchinh-sach-bao-mat\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fcode-wp.com\u002Fchinh-sach-bao-mat\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Use Expo\u003C\u002Fstrong>: \u003Ca href=\"https:\u002F\u002Fexpo.io\u002Fterms\" rel=\"nofollow ugc\">Expo Terms of Use\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy Expo\u003C\u002Fstrong>: \u003Ca href=\"https:\u002F\u002Fexpo.io\u002Fprivacy\" rel=\"nofollow ugc\">Expo Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Sanitization, Validation, and Escaping\u003C\u002Fh3>\n\u003Cp>All data inputs in this plugin are sanitized, validated, and escaped to prevent security vulnerabilities such as XSS and MITM attacks.\u003C\u002Fp>\n\u003Cp>Để sử dụng các bạn đăng ký tài khoản tại \u003Ca href=\"https:\u002F\u002Fcode-wp.com\u002Fapp-code-wp\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fcode-wp.com\u002Fapp-code-wp\u002F\u003C\u002Fa> và bấm mua ứng dụng API CODE-WP để kết nối với website và đăng nhập sử dụng\u003C\u002Fp>\n","Ứng dụng đồng bộ và kết nối với ứng dụng CODE-WP trên Android và iOS, giúp bạn dễ dàng quản lý website và thao tác.",10,1203,1,"2024-07-20T02:19:00.000Z","6.5.8",[64,53],"api","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fapi-code-wp.zip",85]