[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fc648iAzK_q_-cYF1WFlV4MjMWulcfHg1Y-VY1I3ef5s":3,"$fG7s9A4KQEXzLhAl6BPiMpU5wuIFhzFXNM7_YBTvMPBY":125,"$fHyEDwCwdEDoXjxeoNnsklqqBv18nPKqgdlv4jouZJJk":130},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":11,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":37,"analysis":26,"fingerprints":26},"aipatch-security-scanner","Aipatch Security Scanner","2.0.2","Esteban","https:\u002F\u002Fprofiles.wordpress.org\u002Festebandezafra\u002F","\u003Cp>\u003Cstrong>Aipatch Security Scanner\u003C\u002Fstrong> is a modular security audit engine built for site owners, developers, and AI-powered agents who need deep visibility into WordPress security posture — without the bloat of all-in-one security suites.\u003C\u002Fp>\n\u003Ch4>Why Aipatch Security Scanner?\u003C\u002Fh4>\n\u003Cp>Most WordPress security plugins are either too simple to be useful or too heavy to be practical. Aipatch takes a different approach:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Audit-first architecture.\u003C\u002Fstrong> Every check is a standalone, testable module that returns structured findings with severity, confidence, evidence, and fingerprints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built for automation.\u003C\u002Fstrong> 23 MCP abilities expose the full audit, scanning, and remediation surface to external AI agents — making Aipatch the first WordPress security plugin designed for agentic workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero external dependencies.\u003C\u002Fstrong> Everything runs locally. No accounts, no cloud services, no API keys required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reversible by design.\u003C\u002Fstrong> Every automated remediation stores rollback data so you can undo any change with one click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Core Capabilities\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>36-Point Security Audit\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Aipatch runs 36 automated checks across 8 categories — core, plugins, themes, users, configuration, server, access control, and malware surface:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Outdated WordPress core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Default admin username, excessive admin accounts, inactive admin users, user ID 1 exposure\u003C\u002Fli>\n\u003Cli>XML-RPC, file editor, debug mode, debug log, REST API exposure, directory listing\u003C\u002Fli>\n\u003Cli>PHP version, HTTPS, file permissions, security headers (X-Frame-Options, CSP, etc.)\u003C\u002Fli>\n\u003Cli>Database prefix, sensitive files, PHP execution in uploads, auto-update configuration\u003C\u002Fli>\n\u003Cli>Salt key strength, cron health, cookie security flags, CORS, application passwords\u003C\u002Fli>\n\u003Cli>Exposed backup files, phpinfo files, uploads directory indexing, default login URL\u003C\u002Fli>\n\u003Cli>Database credential security, file installation permissions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Every finding includes a severity (critical \u002F high \u002F medium \u002F low \u002F info), confidence score, human-readable explanation, and actionable recommendation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Weighted Security Score (0–100)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A logarithmic scoring engine computes an overall security score and per-area breakdown across six risk dimensions: software, access control, configuration, infrastructure, malware surface, and vulnerability exposure. Severity weights and confidence multipliers ensure the score reflects actual risk, not just issue count.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Multi-Layer Malware File Scanner\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A three-layer file scanner (content 55%, context 25%, integrity 20%) with 27 detection signatures, Shannon entropy analysis, and malware family classification detects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Code execution patterns: eval(), assert(), create_function(), preg_replace \u002Fe\u003C\u002Fli>\n\u003Cli>System command functions: shell_exec, exec, passthru, backtick operators\u003C\u002Fli>\n\u003Cli>Obfuscation techniques: base64 encoding, hex encoding, str_rot13, gzinflate chains, chr() concatenation, variable variables, suspiciously long lines\u003C\u002Fli>\n\u003Cli>Network\u002Fexfiltration: cURL execution, fsockopen, remote file_get_contents\u003C\u002Fli>\n\u003Cli>Known backdoor signatures: c99, r57, WSO, b374k, weevely, FilesMan\u003C\u002Fli>\n\u003Cli>WordPress-specific threats: unauthorized admin creation, critical option injection, security function removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Scanning runs in batches via an async job system with configurable batch sizes — safe for shared hosting.\u003C\u002Fp>\n\u003Cp>Files are classified into 11 malware families (web shell, obfuscated loader, dropper, persistence backdoor, cloaked PHP, code injector, and more) with confidence scores and remediation hints.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Core Integrity Verification\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Verifies every core file against official checksums from api.wordpress.org. Detects modified core files (checksum mismatch), missing core files, and unexpected files planted in wp-admin\u002F or wp-includes\u002F. Core tampering findings are automatically escalated to critical severity with zero false-positive likelihood.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Build a known-good hash baseline of all PHP files in your installation. Diff against it at any time to detect modified, deleted, or newly added files. Origin detection distinguishes core, plugin, theme, and upload files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A local knowledge base of known plugin, theme, and core vulnerabilities with a database-backed caching layer for fast lookups. Provider architecture allows extending with external feeds.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-Click Remediation with Rollback\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Apply fixes directly from findings — change WordPress options, delete suspicious files, rename files, patch file contents, or add .htaccess rules. Every automated action stores a full rollback payload so you can reverse any change. Manual remediations can be logged for audit trails.\u003C\u002Fp>\n\u003Cp>Six supported action types: \u003Ccode>wp_option\u003C\u002Fcode>, \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>rename_file\u003C\u002Fcode>, \u003Ccode>file_patch\u003C\u002Fcode>, \u003Ccode>htaccess_rule\u003C\u002Fcode>, \u003Ccode>manual\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hardening Module\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Five toggleable hardening rules with clear explanations and compatibility warnings:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable XML-RPC — blocks external XML-RPC requests and removes X-Pingback header\u003C\u002Fli>\n\u003Cli>Hide WordPress Version — removes version leaks from source, RSS feeds, scripts, and styles\u003C\u002Fli>\n\u003Cli>Restrict REST API — limits sensitive endpoints to authenticated users\u003C\u002Fli>\n\u003Cli>Block Author Scanning — prevents user enumeration via author archives\u003C\u002Fli>\n\u003Cli>Login Brute-Force Protection — rate-limits login attempts per IP with configurable thresholds and lockout duration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Persistent Findings Store\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All audit findings persist in a dedicated database table with automatic deduplication by fingerprint. Track findings over time — dismissed findings stay dismissed across scans; resolved findings reopen if the issue reappears.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Event Logging\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Every scan, hardening change, remediation, and significant event is logged to a dedicated table. Logs are filterable by severity and exportable as CSV.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Site Health Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Adds 6 security tests to the built-in Site Health screen: file editor, debug mode, XML-RPC, admin username, SSL, and overall security score.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Diagnostics\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Built-in performance profiling to identify slow queries, high memory usage, and resource bottlenecks related to security operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>10 authenticated endpoints under the \u003Ccode>aipatch-security-scanner\u002Fv1\u003C\u002Fcode> namespace for triggering scans, retrieving summaries, toggling hardening, exporting logs, and running performance diagnostics.\u003C\u002Fp>\n\u003Ch4>MCP Surface for AI Agents (23 Abilities)\u003C\u002Fh4>\n\u003Cp>Aipatch exposes 23 structured abilities via the WordPress Abilities API — making your site’s security surface fully accessible to external AI agents, coding assistants, and orchestration tools:\u003C\u002Fp>\n\u003Cp>By default, only \u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> is enabled. You can enable additional abilities from \u003Cstrong>Aipatch Security Scanner -> Settings -> MCP Abilities\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> — Run a full 36-check security audit with scored findings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-suspicious\u003C\u002Fstrong> — Quick heuristic scan for suspicious files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fstart-file-scan\u003C\u002Fstrong> — Launch an async multi-layer malware scan job\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fprocess-file-scan-batch\u003C\u002Fstrong> — Process next batch of files in a running scan\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-progress\u003C\u002Fstrong> — Check file scan progress\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-results\u003C\u002Fstrong> — Retrieve enriched scan results with family, reasons, layer scores\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-scan-summary\u003C\u002Fstrong> — Comprehensive latest scan summary with classification breakdown\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-suspicious-files\u003C\u002Fstrong> — List suspicious files from latest scan (no job_id needed)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Integrity & Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fverify-core-integrity\u003C\u002Fstrong> — Verify WP core files against official api.wordpress.org checksums\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-build\u003C\u002Fstrong> — Build or refresh the known-good file hash baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-diff\u003C\u002Fstrong> — Compare current filesystem against stored baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-stats\u003C\u002Fstrong> — Baseline statistics by origin type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-baseline-drift\u003C\u002Fstrong> — Combined baseline drift + core integrity report\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Findings & Monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-findings\u003C\u002Fstrong> — Query persistent findings with status\u002Fseverity\u002Fcategory filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-stats\u003C\u002Fstrong> — Aggregate finding statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-diff\u003C\u002Fstrong> — New and resolved findings since a point in time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-file-finding-detail\u003C\u002Fstrong> — Single finding with decoded metadata, layer scores, family\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fdismiss-finding\u003C\u002Fstrong> — Dismiss a finding as accepted risk\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Remediation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fapply-remediation\u003C\u002Fstrong> — Apply a security fix with rollback support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Frollback-remediation\u003C\u002Fstrong> — Undo a previously applied fix\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-remediations\u003C\u002Fstrong> — List remediation history with filters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Jobs & Status\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-jobs\u003C\u002Fstrong> — List scan\u002Faudit jobs with filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-async-job-status\u003C\u002Fstrong> — Check async job status and retrieve results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>20 abilities are read-only; only 3 (dismiss, apply-remediation, rollback) modify site state. All abilities include typed input\u002Foutput schemas, permission checks (\u003Ccode>manage_options\u003C\u002Fcode>), and structured error responses.\u003C\u002Fp>\n\u003Ch4>What Aipatch Does NOT Do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>It is NOT a firewall or WAF — it does not filter incoming traffic.\u003C\u002Fli>\n\u003Cli>It does NOT intercept frontend requests or affect page load performance.\u003C\u002Fli>\n\u003Cli>It does NOT phone home, require an account, or send data externally.\u003C\u002Fli>\n\u003Cli>It does NOT inject ads, upsells, or nag notices.\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress security scanner with 36 checks, malware scanning, core integrity verification, remediation, and 23 MCP abilities.",100,477,0,"2026-05-03T09:18:00.000Z","7.0.2","6.5","7.4",[19,20,21,22,23],"audit","hardening","malware-scanner","security","vulnerability","https:\u002F\u002Fgithub.com\u002Festebanstifli\u002Faipatch-security-scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.2.0.2.zip",null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":11,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"estebandezafra",6,6850,30,94,"2026-08-24T22:08:00.395Z",[38,55,69,93,108],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":13,"downloaded":46,"rating":13,"num_ratings":13,"last_updated":47,"tested_up_to":48,"requires_at_least":49,"requires_php":17,"tags":50,"homepage":52,"download_link":53,"security_score":11,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":54},"boonrisk-site-security-check-report","BoonRisk – Site Security Check & Report","1.0.2","Boon Band","https:\u002F\u002Fprofiles.wordpress.org\u002Fboonband\u002F","\u003Cp>BoonRisk gives you a \u003Cstrong>clear security and readiness report\u003C\u002Fstrong> for your WordPress site. See exactly what security risks exist, why they matter, and what to do about them — all explained in plain language.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Safe & Read-Only:\u003C\u002Fstrong> This plugin only reads your site configuration. It does not scan files, block traffic, or make any changes to your WordPress installation.\u003C\u002Fp>\n\u003Ch4>What You Get\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security Check Report\u003C\u002Fstrong> — See your site’s security status: PHP version, WordPress updates, user settings, HTTPS, and 30+ configuration checks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clear Explanations\u003C\u002Fstrong> — Every finding explains “why this matters” and “what to do about it” in plain language\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prioritized Risks\u003C\u002Fstrong> — Top risks ranked by impact so you know what to fix first\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Printable Report\u003C\u002Fstrong> — Professional HTML report you can view, print, or share directly from WordPress admin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What This Plugin Does NOT Do (100% Safe)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No file scanning\u003C\u002Fstrong> — Does not scan your files or look for malware\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No traffic blocking\u003C\u002Fstrong> — Does not act as a firewall or block visitors\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No site changes\u003C\u002Fstrong> — Does not modify settings, files, or database\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No active testing\u003C\u002Fstrong> — Does not simulate attacks or run security scans\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read-only analysis\u003C\u002Fstrong> — Only reads your configuration, never writes or changes anything\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Is It For?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> — Understand your security risks without technical expertise\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Freelancers & agencies\u003C\u002Fstrong> — Generate client-ready reports in minutes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> — Quick baseline check before or after deployments\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Teams\u003C\u002Fstrong> — Consistent security reporting across multiple WordPress sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Free Security Check (No Account Required)\u003C\u002Fh4>\n\u003Cp>Run a complete security and readiness check instantly — 100% local, no data sent anywhere:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Overall Risk Level\u003C\u002Fstrong> — Clear Low\u002FMedium\u002FHigh rating with explanation of what it means\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Top Risks First\u003C\u002Fstrong> — See your biggest security issues ranked by impact\u003C\u002Fli>\n\u003Cli>\u003Cstrong>30+ Configuration Checks\u003C\u002Fstrong> — WordPress updates, PHP version, HTTPS, user permissions, backups, 2FA, debug mode, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action Plan\u003C\u002Fstrong> — Every issue includes “why it matters” and “how to fix it”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional Report\u003C\u002Fstrong> — Printable HTML report you can view in WordPress admin or share with your team\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What you’ll learn:\u003C\u002Fstrong> “Is my site at risk?” and “What should I fix first?”\u003C\u002Fp>\n\u003Cp>\u003Cstrong>100% Private:\u003C\u002Fstrong> All checks run on your server. Nothing is sent externally. No account or email required.\u003C\u002Fp>\n\u003Ch4>Optional: Web Dashboard\u003C\u002Fh4>\n\u003Cp>Connect the plugin to the \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">BoonRisk web dashboard\u003C\u002Fa> for additional capabilities (optional, requires free account):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002Fscanner\u002F\" rel=\"nofollow ugc\">Surface Scan\u003C\u002Fa>\u003C\u002Fstrong> — External scan of your site’s public-facing security headers, SSL configuration, and exposed services\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong> — Known CVEs matched to your installed plugins and themes with severity ratings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Continuous Monitoring\u003C\u002Fstrong> — Automatic daily checks with alerts when your security posture changes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Track Over Time\u003C\u002Fstrong> — See how your site security improves (or changes) month over month\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PDF Reports\u003C\u002Fstrong> — Download professional reports to share with clients or management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> The local security check is fully functional on its own. The web dashboard is completely optional.\u003C\u002Fp>\n\u003Cp>Learn more at \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">boonrisk.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Ch4>Local Assessment (Default)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate the plugin\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>BoonRisk\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Local Assessment\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Run Assessment Now\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>View your Security Posture Summary and Top Risks\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>View Full Report\u003C\u002Fstrong> for a printable HTML report\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>All analysis happens on your server. Nothing is sent externally.\u003C\u002Fp>\n\u003Ch4>Web Dashboard (Optional)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Create a free account at \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">boonrisk.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>BoonRisk\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Connect (Optional)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Enter your API key\u003C\u002Fli>\n\u003Cli>Send your assessment to the dashboard for vulnerability intelligence, surface scan, and monitoring\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>External API calls only happen when you explicitly request them.\u003C\u002Fp>\n\u003Ch3>Data Usage\u003C\u002Fh3>\n\u003Ch4>Local Assessment\u003C\u002Fh4>\n\u003Cp>In local mode, \u003Cstrong>no data is sent externally\u003C\u002Fstrong>. All checks run inside WordPress.\u003C\u002Fp>\n\u003Ch4>Web Dashboard (Optional)\u003C\u002Fh4>\n\u003Cp>When you send data to the dashboard, the following is transmitted:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP and WordPress versions\u003C\u002Fli>\n\u003Cli>Active plugin and theme names\u002Fversions\u003C\u002Fli>\n\u003Cli>Configuration flags (debug mode, file editor status, etc.)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>What you get in return:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Known vulnerability data for your installed plugins and themes\u003C\u002Fli>\n\u003Cli>Surface scan results for public-facing security\u003C\u002Fli>\n\u003Cli>Severity context for identified risks\u003C\u002Fli>\n\u003Cli>Historical trend data and monitoring alerts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What is never collected:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>User data or personal information\u003C\u002Fli>\n\u003Cli>Passwords or credentials\u003C\u002Fli>\n\u003Cli>Post\u002Fpage content\u003C\u002Fli>\n\u003Cli>Database contents\u003C\u002Fli>\n\u003Cli>File contents\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Data is sent \u003Cstrong>only when you click\u003C\u002Fstrong> Send to Dashboard or enable automatic daily sync. No personal data is collected.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Read our full privacy policy at https:\u002F\u002Fboonrisk.com\u002Fprivacy\u003C\u002Fp>\n","Security posture report for WordPress — 30+ checks, prioritized risks, and a printable report. Get a clear picture in minutes.",171,"2026-02-16T17:38:00.000Z","6.9.4","5.0",[19,20,22,51,23],"site-health","https:\u002F\u002Fboonrisk.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fboonrisk-site-security-check-report.1.0.2.zip","2026-04-16T10:56:18.058Z",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":13,"downloaded":63,"rating":13,"num_ratings":13,"last_updated":64,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":65,"homepage":67,"download_link":68,"security_score":11,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"compatshield-site-auditor","CompatShield WP Site Auditor","0.1.0","CompatShield","https:\u002F\u002Fprofiles.wordpress.org\u002Fcompatshield\u002F","\u003Cp>CompatShield Site Auditor gives WordPress site owners and agencies a full picture of their site’s security posture in one scan. Unlike basic security plugins, it audits every layer — environment, plugins, themes, users, files, and database — and produces a single weighted score out of 100 with a per-category breakdown.\u003C\u002Fp>\n\u003Ch4>What it checks\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Environment & Hardening\u003C\u002Fstrong>\u003Cbr \u002F>\n* PHP version (flags below 8.2)\u003Cbr \u002F>\n* WordPress core version\u003Cbr \u002F>\n* WP_DEBUG exposure\u003Cbr \u002F>\n* XML-RPC enabled\u003Cbr \u002F>\n* wp-config.php file permissions\u003Cbr \u002F>\n* Database table prefix (flags default wp_)\u003Cbr \u002F>\n* Directory listing enabled\u003Cbr \u002F>\n* .htaccess integrity\u003Cbr \u002F>\n* HTTPS enforcement\u003Cbr \u002F>\n* readme.html \u002F license.txt version leakage\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Plugin & Theme Intelligence\u003C\u002Fstrong>\u003Cbr \u002F>\n* Lists all installed plugins (active and inactive)\u003Cbr \u002F>\n* Hits WordPress.org API for last updated date and install count\u003Cbr \u002F>\n* Flags plugins not updated in 6, 12, or 24 months\u003Cbr \u002F>\n* Flags plugins removed from the WordPress.org directory\u003Cbr \u002F>\n* Flags abandoned themes\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User & Access Audit\u003C\u002Fstrong>\u003Cbr \u002F>\n* Lists all administrator accounts\u003Cbr \u002F>\n* Flags the default “admin” username still in use\u003Cbr \u002F>\n* Detects dormant admin accounts (no login in 90+ days)\u003Cbr \u002F>\n* Checks for two-factor authentication plugins\u003Cbr \u002F>\n* Flags non-admin users with elevated capabilities (manage_options, install_plugins, etc.)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity & Backdoor Detection\u003C\u002Fstrong>\u003Cbr \u002F>\n* Hashes WordPress core files against official checksums\u003Cbr \u002F>\n* Flags modified core files\u003Cbr \u002F>\n* Scans theme and plugin files for dangerous PHP patterns: eval(base64_decode), gzinflate, str_rot13, shell_exec, exec, system, preg_replace with \u002Fe modifier\u003Cbr \u002F>\n* Flags PHP files inside \u002Fuploads\u002F directory\u003Cbr \u002F>\n* Flags .git directory exposure\u003Cbr \u002F>\n* Detects suspicious WordPress cron jobs\u003Cbr \u002F>\n* Flags PHP files modified in the last 7 or 30 days\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Database Security\u003C\u002Fstrong>\u003Cbr \u002F>\n* Checks for publicly accessible phpMyAdmin\u003Cbr \u002F>\n* Scans published posts for injected content (hidden links, base64 blobs, external iframes)\u003Cbr \u002F>\n* Scans wp_options autoloaded data for malicious PHP patterns and oversized entries\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Score\u003C\u002Fstrong>\u003Cbr \u002F>\n* Weighted score out of 100 (Environment 25, Plugins 20, Headers 20, Users 15, Database 10, Themes 10)\u003Cbr \u002F>\n* Per-category score breakdown with issue count\u003Cbr \u002F>\n* Historical score tracking with week-over-week change\u003C\u002Fp>\n\u003Ch4>Who is this for?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress site owners who want to know their security posture\u003C\u002Fli>\n\u003Cli>Freelancers and developers managing client sites\u003C\u002Fli>\n\u003Cli>Agencies auditing multiple client sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All of the scanning and reporting features described above are fully\u003Cbr \u002F>\nincluded in this free plugin — nothing here is time-limited or\u003Cbr \u002F>\nfeature-gated. CompatShield may offer separate, optional products in\u003Cbr \u002F>\nthe future (such as a multi-site management dashboard); any such\u003Cbr \u002F>\nproduct would be a distinct, separately-installed plugin or service,\u003Cbr \u002F>\nnot a restriction on this one.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>This plugin makes outbound requests to:\u003Cbr \u002F>\n* \u003Cstrong>WordPress.org API\u003C\u002Fstrong> (api.wordpress.org) — to retrieve plugin and theme metadata\u003Cbr \u002F>\n* \u003Cstrong>Your own site’s URL\u003C\u002Fstrong> — to check phpMyAdmin exposure and security headers\u003C\u002Fp>\n\u003Cp>No data is sent to third-party servers by the free version.\u003C\u002Fp>\n","Comprehensive WordPress security auditor. Scans for vulnerabilities, misconfigurations and threats — scored report with actionable fix steps.",91,"2026-06-26T10:10:00.000Z",[19,20,66,22,23],"malware","https:\u002F\u002Fcompatshield.com\u002Fcompatshield-site-auditor","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcompatshield-site-auditor.zip",{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":77,"downloaded":78,"rating":79,"num_ratings":80,"last_updated":81,"tested_up_to":15,"requires_at_least":82,"requires_php":83,"tags":84,"homepage":88,"download_link":89,"security_score":90,"vuln_count":91,"unpatched_count":13,"last_vuln_date":92,"fetched_at":27},"wp-malware-removal","Malcure Malware Shield — Removal, Repair, Monitor","19.9.6","Malcure Web Security","https:\u002F\u002Fprofiles.wordpress.org\u002Fmalcure\u002F","\u003Cp>Is your website acting strangely? Seeing ‘Deceptive Site Ahead’ warnings, Japanese SEO hack, or random redirects? Time to fix and monitor your site with \u003Cstrong>Malcure Malware Shield\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Malcure Malware Shield scans for infections, runs silent scheduled scans, and sends alerts before threats spread — turning one-time cleanup into always-on protection.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Malcure scans files, databases, and user accounts to find malware casual scanners miss — backdoors hidden in images, injections in your database, rogue, hidden admin accounts buried in your tables that don’t show up in the admin area. Then it watches your site with scheduled scans and alerts, so one-time cleanup becomes always-on protection.\u003C\u002Fp>\n\u003Cp>Detection runs against 50,000+ signatures with real-time threat intelligence — the same definitions for every user, free or paid. You see every infection with exact file paths and line numbers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Activate \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Know \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>What Our Users Say\u003C\u002Fh3>\n\u003Cp>Quotes are verbatim from WordPress.org support reviews, except for bracketed edits (for example, competitor names removed).\u003C\u002Fp>\n\u003Ch4>Best by far, better than [competitor name removed] and other giants\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“You can see it is a bunch of geeks that created this, with skill and visual creativity at that. I spent hours trying to find a plugin like this. So many options and such bad results until now. Great job guys. You deserve it. Simple and effective. (Disclaimer to other potential readers: there are many types of hacks\u002Fmalware out there, every scenario is different, but start with the Malcure scan and see how it goes. 9\u002F10 you won’t be disappointed, my guess)” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-by-far-better-than-wordfence-and-other-giants\u002F\" rel=\"ugc\">@dalingzaf\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>The ONLY plugin that scans every file-type…\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“I am a web developer and have tried many malware removal plugins, including popular ones [competitor names removed]. However, none of them detected some unusual files that were actually malware causing regular attacks. Some of these files were in JPG format.” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fthe-only-plugin-that-scans-files-in-real-time-2\u002F\" rel=\"ugc\">@devzeeshanx\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>Best Malware Removal Plugin in just few minutes\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“Most security plugins that are free only scan the code, but Malcure Malware Removal Plugin scans the wordpress database and the code files in few minutes. Accurately shows which Database table row is infected and it helps resolve the hacking attempt instantly. Saves a lot of time for the developers. Thank You Team Malcure” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-malware-removal-plugin-in-just-few-minutes\u002F\" rel=\"ugc\">@s3630\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>It’s not just a “teaser”\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“This plugin really found the malware, and removed it. Really for free. Thanks guys, I’m going to donate now!” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fits-not-just-a-teaser\u002F\" rel=\"ugc\">@halucska\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>What Malcure Does\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Detection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>File Scan:\u003C\u002Fstrong> Core files, themes, plugins, images, uploads — backdoors, shells, obfuscated code, and malware hidden inside image files and archives.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database Scan:\u003C\u002Fstrong> Finds malicious injections, recurring malware, and SEO injection links that other non-thorough scanners never see.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Scan:\u003C\u002Fstrong> Detects rogue admin accounts and compromised metadata, including application passwords that bypass your login page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DeepScan™:\u003C\u002Fstrong> Scans every file-type without skipping within resource-limits and hidden files where malware hides.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checksum Verification:\u003C\u002Fstrong> Compares your core, plugin, and theme files against official repository checksums. Tampered files are flagged by severity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Hack Detection:\u003C\u002Fstrong> Catches Japanese Keyword Hack, Pharma Hack, and other SEO hacks in page titles and database records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Scanner:\u003C\u002Fstrong> Checks installed plugins and themes against a real-time vulnerability database.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checksum Intelligence:\u003C\u002Fstrong> Checksum-based verification reduces false alarms compared to heuristic-only scanners.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>50,000+ Signatures:\u003C\u002Fstrong> Detects known variants — C99, R57, RootShell, and many more — plus unknown threats via behavioral analysis.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Monitoring & Alerts\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scheduled Scans:\u003C\u002Fstrong> Set a cadence — daily, weekly, or monthly. Runs silently in the background.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Weekly Security Pulse Email:\u003C\u002Fstrong> A verdict-first security-critical weekly summary — gives you a heads-up — “All Clear”, “Please Review”, or “Needs Immediate Attention” — delivered to your inbox. Covers scan results, failed logins, privileged activity, file edits, and updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled Scan Results Email:\u003C\u002Fstrong> Email report of scheduled scans — clean or infected. Know immediately when a scheduled scan finishes. Gives you early heads-up if malware found and before it spreads and affects SEO or gets the site blacklisted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Recipients:\u003C\u002Fstrong> Choose who gets notified. Licensee, Registrant and additional CC recipients. Send a test Pulse to verify your mail configuration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Event Log:\u003C\u002Fstrong> 100-day forensic record of every security event for root-cause analysis.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Inspector:\u003C\u002Fstrong> See who’s logged in — IP, user-agent, login time, and session expiration.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Hardening & Firewall\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Block Path Traversal:\u003C\u002Fstrong> Stops attackers from accessing sensitive system files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block PHP Uploads:\u003C\u002Fstrong> Prevents malicious scripts from being uploaded.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stop User Enumeration:\u003C\u002Fstrong> Blocks bots from fishing for usernames.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Protection:\u003C\u002Fstrong> Prevents user data leakage via the WP REST API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack Counter:\u003C\u002Fstrong> See how many attacks the firewall has blocked, right on your dashboard.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Incident Response\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Session Nuke:\u003C\u002Fstrong> Force-logout every user instantly to kick out intruders.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Salt Shuffler:\u003C\u002Fstrong> One-click rotation of \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5230\" rel=\"nofollow ugc\">security keys (salts)\u003C\u002Fa> to invalidate all browser cookies.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Real-Time Threat Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero-Day:\u003C\u002Fstrong> Threat definitions served in real time via the Malcure Cloud. No days-long delay.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Search Console:\u003C\u002Fstrong> Connect directly to fetch security warnings and blacklist status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> Scans send file checksums and your site’s domain to Malcure servers. No sensitive user data is transmitted. Use of the API is subject to our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=1720\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=3\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight:\u003C\u002Fstrong> Runs only on demand or on schedule. No persistent background processes. No bloat.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Dashboard & Experience\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Dashboard Widget:\u003C\u002Fstrong> At-a-glance malware status, attack count, and quick-scan CTA on the WP dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Skins:\u003C\u002Fstrong> Classic and Dark skins to match your workflow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan Completion Audio Preferences:\u003C\u002Fstrong> Configure sound-notifications for scans.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Diagnostics Page:\u003C\u002Fstrong> Environment diagnostics for troubleshooting.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Who This Plugin Is For\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Agencies and developers\u003C\u002Fstrong> who need fast triage across multiple sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce, membership, and lead-gen sites\u003C\u002Fstrong> where downtime and SEO damage are expensive.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> who want clear results — what was flagged, exactly where.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works (Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Review \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Clean \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Scan\u003C\u002Fstrong> — Open \u003Cstrong>Malcure Scanner\u003C\u002Fstrong> in your Admin Dashboard. Run a scan to check files, database, users, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Review\u003C\u002Fstrong> — Every finding comes with an exact location: file path, line number, or database record. Decide what to repair, delete, or keep.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean & Recover\u003C\u002Fstrong> — Shows every infection so you can clean it yourself. Advanced Edition adds repair tools, file operations, whitelisting, and WP-CLI automation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Monitor\u003C\u002Fstrong> — Set up scheduled scans. Get email alerts the moment a threat is found.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Is It Free?\u003C\u002Fh4>\n\u003Cp>We believe in 100% transparency.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Professional-grade Detection (Knowledge). You see every infected file and database row (exact file path & line number), so you can clean it yourself for free.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Real-time Threat Intelligence, Scheduled Scans, Weekly Security Pulse email, and Firewall & Hardening.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pro Upgrade:\u003C\u002Fstrong> File Repairs, Deletions, Whitelisting, Advanced Scan Filters, WP-CLI Automation, Auto-Definition Updates, Bulk Client-Servicing Features & Premium Support (Expertise).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>You are never forced to pay to \u003Cem>find\u003C\u002Fem> a hack.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FEbSbxiTOc8k?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Advanced Edition\u003C\u002Fh4>\n\u003Cp>For when detection is not enough — you need to remediate.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>1-Click Repairs:\u003C\u002Fstrong> Repair infected files from the official source via Malcure Cloud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Delete Files:\u003C\u002Fstrong> Remove infected or irreparable files directly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File & DB Whitelisting:\u003C\u002Fstrong> Suppress alarms on specific files and database records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI Integration:\u003C\u002Fstrong> Full command-line control — async scans, definitions sync, checksum refresh, reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Definition Updates:\u003C\u002Fstrong> Hourly cron keeps definitions current without manual intervention.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Scan Filters:\u003C\u002Fstrong> Include or exclude directories, custom regex signatures for database and files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Inspector:\u003C\u002Fstrong> Inspect files inline instead of having to go via s\u002Fftp or ssh or file-managers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Copy Scan Results:\u003C\u002Fstrong> Copy results to clipboard for client reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP Config & Diagnostics:\u003C\u002Fstrong> View full PHP configuration in diagnostics.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Factory Reset:\u003C\u002Fstrong> One-click plugin reset.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Premium Support:\u003C\u002Fstrong> Direct access to our security analysts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116\" rel=\"nofollow ugc\">\u003Cstrong>Get Malcure Advanced Edition\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Expert Malware Removal Service\u003C\u002Fh4>\n\u003Cp>In over your head? Our security analysts will clean your site for you — 100% removal guarantee, same-day service, blacklist removal, and 15-day post-cleanup cover.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">\u003Cstrong>Book Expert Malware Removal\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Troubleshooting\u003C\u002Fh3>\n\u003Ch4>Some files are detected by Malcure Malware Shield as “suspicious”. What gives?\u003C\u002Fh4>\n\u003Cp>Malcure’s DeepScan checks each file for malware. However some files aren’t pure malware but may contain code that is suspicious and could potentially do nasty things. You should carefully review and analyse them to see if they indeed do anything nasty.\u003C\u002Fp>\n\u003Ch4>I can’t get Malcure Malware Shield to work. It hangs \u002F doesn’t complete the scan \u002F breaks for some reason.\u003C\u002Fh4>\n\u003Cp>If you think that the plugin is broken, \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Malcure Malware Shield (or for that matter other plugins) may break on malware affected \u002F broken websites. \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116\" rel=\"nofollow ugc\">Malcure Advanced Edition\u003C\u002Fa> integrates with WP CLI and allows you to complete the scan from WP CLI even when the site is blocked by the webhost or when you are unable to login to the website.\u003C\u002Fp>\n\u003Ch4>My site is infected however Malcure Malware Shield doesn’t detect the infection.\u003C\u002Fh4>\n\u003Cp>Malware keeps evolving. If you come across malware that Malcure Malware Shield is not able to identify, you may \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=157\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>The scan gets stuck midway. What should I do?\u003C\u002Fh4>\n\u003Cp>In case of such an event, please file a support request with us and we’ll be more than happy to troubleshoot the issue.\u003C\u002Fp>\n\u003Cp>Please visit \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677\" rel=\"nofollow ugc\">this page\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I cleaned my site but it got infected again. What should I do?\u003C\u002Fh4>\n\u003Cp>Malware cleanup is a waste of time and effort unless you find the root cause behind the malware infection and monitor for recurrence. How was someone able to infect your website? Have you plugged in that security hole?\u003C\u002Fp>\n\u003Cp>Please read \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002Fblog\u002Fsecurity\u002Fwhy-do-wordpress-websites-get-hacked\u002F\" rel=\"nofollow ugc\">Why Do Websites Get Hacked\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Google Safe Browsing site status (or some other scanner) still shows my site as infected. What should I do?\u003C\u002Fh4>\n\u003Cp>First make sure you purge your site cache. Second, Google (and other scanners) cache the results for some time. You’ll need to force or refresh the scan. You can also file a request with us to \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">get your site off any blacklists\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I found a suspicious file, what now?\u003C\u002Fh4>\n\u003Cp>If Malcure flags it, it’s likely malicious. You can inspect the file content using our built-in inspector. If you’re unsure, consider our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">Expert Malware Removal Service\u003C\u002Fa>.\u003C\u002Fp>\n","Your WordPress site hacked? Malcure scans files AND database to find and help you remove malware casual scanners miss. Free. No bloat.",10000,662306,90,72,"2026-07-14T03:24:00.000Z","6.2","5.6",[85,21,22,86,87],"antivirus","virus","vulnerability-scanner","https:\u002F\u002Fmalcure.com\u002F?p=116","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-malware-removal.19.9.6.zip",96,3,"2025-09-03 00:00:00",{"slug":94,"name":95,"version":96,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":11,"downloaded":101,"rating":11,"num_ratings":91,"last_updated":102,"tested_up_to":15,"requires_at_least":103,"requires_php":17,"tags":104,"homepage":106,"download_link":107,"security_score":11,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"lockora-security-audit","Lockora Security Audit","0.2.0","Guido Schad","https:\u002F\u002Fprofiles.wordpress.org\u002Fcmdgw\u002F","\u003Cp>Lockora Security Audit helps site owners and agencies review a WordPress site’s security posture from the admin area.\u003C\u002Fp>\n\u003Cp>Current prototype features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Manual security scans.\u003C\u002Fli>\n\u003Cli>Weighted security score out of 100.\u003C\u002Fli>\n\u003Cli>WordPress core file integrity checks using official checksums.\u003C\u002Fli>\n\u003Cli>WordPress authentication key and salt checks, with an explicit action to generate missing salts.\u003C\u002Fli>\n\u003Cli>Must-use plugin directory presence checks.\u003C\u002Fli>\n\u003Cli>PHP version status using WordPress.org Serve Happy data.\u003C\u002Fli>\n\u003Cli>HTTPS and HTTP security header checks.\u003C\u002Fli>\n\u003Cli>WordPress core, plugin, and theme update posture checks.\u003C\u002Fli>\n\u003Cli>Administrator account posture checks for default usernames, excess admins, inactive admins, user ID 1 exposure, and an admin username\u002Femail inventory.\u003C\u002Fli>\n\u003Cli>Public exposure checks: debug.log and readme.html reachability, uploads directory listing, PHP execution inside uploads, and author archive user enumeration.\u003C\u002Fli>\n\u003Cli>SSL certificate expiry check, database table prefix check, automatic update posture check, and detection of login protection \u002F two-factor plugins.\u003C\u002Fli>\n\u003Cli>Site Health integration: scan summary plus key configuration checks appear under Tools > Site Health > Status.\u003C\u002Fli>\n\u003Cli>WP-CLI support: \u003Ccode>wp lockora scan\u003C\u002Fcode> and \u003Ccode>wp lockora report\u003C\u002Fcode>, with \u003Ccode>--format=json\u003C\u002Fcode> and a \u003Ccode>--strict\u003C\u002Fcode> flag for CI pipelines.\u003C\u002Fli>\n\u003Cli>Optional known vulnerability matching with a configured Wordfence Intelligence API key.\u003C\u002Fli>\n\u003Cli>Optional AI client reports on WordPress 7.0+ when the site’s AI Connector is configured.\u003C\u002Fli>\n\u003Cli>Reversible hardening toggles for XML-RPC, REST user routes, generator tag output, and basic security headers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Lockora Security Audit may connect to external services only when the administrator runs a scan or generates an AI client report.\u003C\u002Fp>\n\u003Cp>During a scan the plugin also sends HTTP requests to the site’s own public URL (loopback requests) to inspect response headers, debug.log and readme.html reachability, uploads directory behavior, and author archive redirects, and it opens a TLS connection to the site’s own hostname to read the SSL certificate expiry date. These requests stay within the site being scanned and send no data to third parties.\u003C\u002Fp>\n\u003Cp>WordPress.org APIs:\u003Cbr \u002F>\n* Used for WordPress core checksums, PHP version support status, and WordPress core\u002Fplugin\u002Ftheme update data.\u003Cbr \u002F>\n* Data sent: the site’s WordPress version and locale for core checksums and PHP compatibility; WordPress itself may send installed plugin and theme slugs\u002Fversions to WordPress.org when update data is refreshed.\u003Cbr \u002F>\n* WordPress.org terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms\u002F\u003Cbr \u002F>\n* WordPress.org privacy policy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>Wordfence Intelligence:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when a Wordfence Intelligence API key is configured and an administrator runs a scan that includes vulnerability matching.\u003Cbr \u002F>\n* Used to retrieve vulnerability data and match it locally against installed WordPress core, plugin, and theme versions.\u003Cbr \u002F>\n* Data sent: the configured Wordfence Intelligence API key is sent in an Authorization header when requesting the vulnerability feed. Installed software details are not sent by this plugin to the Wordfence Intelligence endpoint; matching is performed locally after the feed is retrieved.\u003Cbr \u002F>\n* Wordfence Intelligence terms: https:\u002F\u002Fwww.wordfence.com\u002Fwordfence-intelligence-terms-and-conditions\u002F\u003Cbr \u002F>\n* Wordfence privacy policy: https:\u002F\u002Fwww.wordfence.com\u002Fprivacy-policy\u002F\u003C\u002Fp>\n\u003Cp>WordPress AI Client \u002F Connectors:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when the administrator clicks Generate Client Report.\u003Cbr \u002F>\n* Data sent: sanitized scan findings, score, counts, and recommendations needed to generate a client-facing report. The plugin is designed not to send passwords, salts, API keys, raw logs, full user lists, or file contents.\u003Cbr \u002F>\n* The configured AI provider is controlled by the site owner’s WordPress Connector settings.\u003Cbr \u002F>\n* Terms and privacy policy: these depend on the AI provider configured by the site owner in WordPress. Site owners should review the selected provider’s terms and privacy policy before enabling AI reports.\u003C\u002Fp>\n","Lockora Security Audit checks WordPress security posture, hardening, core integrity, vulnerabilities, and optional AI reports.",511,"2026-07-12T20:50:00.000Z","6.0",[105,20,22,51,87],"ai","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flockora-security-audit.0.2.0.zip",{"slug":109,"name":110,"version":111,"author":112,"author_profile":113,"description":114,"short_description":115,"active_installs":116,"downloaded":117,"rating":11,"num_ratings":118,"last_updated":119,"tested_up_to":15,"requires_at_least":103,"requires_php":17,"tags":120,"homepage":123,"download_link":124,"security_score":11,"vuln_count":13,"unpatched_count":13,"last_vuln_date":26,"fetched_at":27},"sitefort","SiteFort Security – Malware Scanner, Firewall, Login Security & Hardening","1.7.5","securewpteam","https:\u002F\u002Fprofiles.wordpress.org\u002Fsecurewpteam\u002F","\u003Cp>Most WordPress hacks start with a door someone left open. An unpatched plugin, an exposed backup, a weak admin password. SiteFort closes these weak points before attackers find them, then backs that up with a firewall, login protection, and cloud malware scanning.\u003C\u002Fp>\n\u003Cp>Malware analysis runs in the SiteFort cloud rather than on your hosting, so full scans stay fast even on shared servers. The free plugin is not a trial. The protections most sites need are included without a paywall.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fdemo.securewp.net\u002F\" rel=\"nofollow ugc\">Try the Live Demo\u003C\u002Fa>\u003C\u002Fstrong> | \u003Ca href=\"https:\u002F\u002Fsecurewp.net\u002Fwordpress-security-plugin\u002F\" rel=\"nofollow ugc\">Features\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fsecurewp.net\u002Fsecurity-checker\u002F\" rel=\"nofollow ugc\">Free Remote Scan\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Comprehensive WordPress Protection\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Cloud Malware Scanner:\u003C\u002Fstrong> Detects backdoors, web shells, injected code, and SEO spam, with the heavy analysis running in the cloud instead of on your server.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Verified Hardening:\u003C\u002Fstrong> Locks down XML-RPC, user enumeration, sensitive files, and PHP execution, then verifies each rule is enforced on the server, not just enabled in the dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Firewall & Bot Filter:\u003C\u002Fstrong> Country blocking, rate limits, a community IP blocklist, and bot filtering that never blocks real search engines.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Security & 2FA:\u003C\u002Fstrong> Custom login URL, CAPTCHA, brute-force lockouts, breached-password blocking, and role-based 2FA enforcement. No separate login plugin needed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backdoor Admin & Account Audit:\u003C\u002Fstrong> Finds admin accounts hidden from the WordPress users list, plus weak, breached, and suspicious accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Checks:\u003C\u002Fstrong> Scans core, plugins, and themes against CVE intelligence and shows affected versions, severity, and fix guidance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Repair & Quarantine:\u003C\u002Fstrong> Quarantine suspicious files (restorable if something breaks) or repair infected files from clean sources in one click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Edge Sync:\u003C\u002Fstrong> Push IP, country, and bot rules to Cloudflare so attacks are blocked before they ever reach WordPress.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress Security Scanner\u003C\u002Fh3>\n\u003Cp>A single scan covers files, accounts, content, and reputation.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malware Detection:\u003C\u002Fstrong> Known files clear instantly by local hash. Only unknown or suspicious files go to deep cloud analysis for backdoors, web shells, injected code, SEO spam, and malicious redirects.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Integrity:\u003C\u002Fstrong> Catches tampered core, plugin, and theme files, and flags files that should not exist on the site at all.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Account Security:\u003C\u002Fstrong> Flags weak, breached, and suspicious accounts, including backdoor admins hidden from the WordPress users list or created outside normal site workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content & Database Safety:\u003C\u002Fstrong> Checks WordPress data locally for injected content, suspicious options, unsafe URLs, and spam or redirect indicators. Database content never leaves your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Domain & IP Reputation:\u003C\u002Fstrong> Checks your domain and server IP against blocklists and abuse feeds so a listing surfaces early, before it affects traffic or email deliverability.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sensitive File Exposure:\u003C\u002Fstrong> Finds exposed backups, logs, config files, debug files, and other files attackers commonly target.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Scanner:\u003C\u002Fstrong> Checks WordPress core, plugins, and themes for known vulnerabilities, affected versions, severity, and CVE references where available.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress Security Hardening\u003C\u002Fh3>\n\u003Cp>SiteFort closes the exposure points attackers check first.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>XML-RPC Controls:\u003C\u002Fstrong> Disable XML-RPC, restrict authentication, or block pingback abuse.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Enumeration Blocking:\u003C\u002Fstrong> Reduces username leaks from author archives, REST endpoints, and common discovery paths.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sensitive File Protection:\u003C\u002Fstrong> Blocks public access to \u003Ccode>.env\u003C\u002Fcode>, backups, logs, debug files, \u003Ccode>.git\u003C\u002Fcode> metadata, lock files, sample configs, and server fragments.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP Execution Protection:\u003C\u002Fstrong> Blocks PHP execution in uploads and direct PHP access inside plugin and theme folders where supported.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Directory Listing Protection:\u003C\u002Fstrong> Reduces exposure from browsable upload, plugin, theme, or backup directories.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Editor Protection:\u003C\u002Fstrong> Disables the built-in theme and plugin file editor to limit damage from compromised admin accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST & Application Password Controls:\u003C\u002Fstrong> Restricts risky REST access and application password behavior based on site needs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Version & Metadata Cleanup:\u003C\u002Fstrong> Hides WordPress version output and reduces exposed generator and header signals.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Headers:\u003C\u002Fstrong> Analyze and manage CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and disclosure headers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enforcement Checks:\u003C\u002Fstrong> Confirms supported hardening rules are active on the server. Items that require manual hosting or server configuration are flagged separately.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Login Security & 2FA\u003C\u002Fh3>\n\u003Cp>Account takeover is one of the fastest ways to lose control of a WordPress site. SiteFort adds layered login protection without requiring separate plugins.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom Login URL:\u003C\u002Fstrong> Move your login page to a private address; anything hitting wp-login.php gets a redirect, a 403, or a 404, your choice.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack Prevention:\u003C\u002Fstrong> Brute-force lockouts, CAPTCHA, generic login errors, and XML-RPC\u002FREST authentication controls.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication:\u003C\u002Fstrong> Role-based 2FA enforcement with authenticator app codes, email codes, and recovery codes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password Policy:\u003C\u002Fstrong> Weak and breached password detection, role-based strength enforcement, and expiration rules.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress Firewall\u003C\u002Fh3>\n\u003Cp>SiteFort blocks unwanted traffic before it consumes server resources, with no custom rule syntax to learn.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>IP & Country Rules:\u003C\u002Fstrong> Block or allow traffic by IP address, CIDR range, country, bot, crawler, or user agent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Country Blocking:\u003C\u002Fstrong> Supports both block-selected and allow-only modes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sensitive File Protection:\u003C\u002Fstrong> Stops bots probing for \u003Ccode>.env\u003C\u002Fcode>, \u003Ccode>.git\u003C\u002Fcode>, \u003Ccode>wp-config.php\u003C\u002Fcode> backups, SQL dumps, debug logs, installer files, and other risky paths.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Sync:\u003C\u002Fstrong> Pushes supported IP, country, and user-agent rules to Cloudflare so high-volume blocks happen at the edge, including temporary edge blocks for repeat attackers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting & 404 Controls:\u003C\u002Fstrong> Reduces abusive traffic spikes, repeated missing-page requests, and automated noise.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Community Threat Intelligence:\u003C\u002Fstrong> Blocks traffic from malicious IPs seen across the SiteFort network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability-Hunting Bot Protection:\u003C\u002Fstrong> Blocks bots probing for vulnerable plugins, themes, backup files, and configuration leaks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Bot Filter Policy\u003C\u002Fh3>\n\u003Cp>Not all bots are bad. Pick one of three protection levels; unwanted automation gets blocked while legitimate search crawlers always pass through, so bot filtering does not put your SEO at risk.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Basic:\u003C\u002Fstrong> Blocks known hacking tools and bots probing for vulnerable files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Balanced:\u003C\u002Fstrong> Blocks hacking tools, scraping bots, and automated scripts. Recommended for most sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Maximum:\u003C\u002Fstrong> Blocks hacking tools, scrapers, automated scripts, and unrecognized bot traffic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block AI Training Crawlers:\u003C\u002Fstrong> Optional block for AI scrapers that harvest content for model training (GPTBot, ClaudeBot, CCBot, Bytespider). AI assistants and AI search crawlers stay allowed.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Choose the level that fits the site, then adjust individual rules from the firewall dashboard.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch3>Vulnerability Management\u003C\u002Fh3>\n\u003Cp>SiteFort checks installed WordPress core, plugin, and theme versions against vulnerability intelligence and shows affected assets, severity, CVE references where available, and the update that fixes each issue. While you apply updates, the firewall blocks the scanner bots that hunt for vulnerable components.\u003C\u002Fp>\n\u003Ch3>One-Click Repair & Restore\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Pro:\u003C\u002Fstrong> Guided repair workflows let you act on scan findings without manually editing files over FTP or SSH.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Repair or delete malicious files directly from scan results.\u003C\u002Fli>\n\u003Cli>Restore clean WordPress core, plugin, and theme files when a trusted clean source is available.\u003C\u002Fli>\n\u003Cli>Repair supported paid plugin and theme files when clean-source matching is available.\u003C\u002Fli>\n\u003Cli>Quarantine suspicious files safely, with one-click restore if something on the site breaks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>For an active compromise, \u003Ca href=\"https:\u002F\u002Fsecurewp.net\u002Fwordpress-malware-removal\u002F\" rel=\"nofollow ugc\">Securewp expert cleanup\u003C\u002Fa> and managed security services are available when hands-on investigation, root-cause patching, blocklist help, or post-cleanup review is needed.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch3>Audit Log & SiteFort Console\u003C\u002Fh3>\n\u003Cp>SiteFort keeps a security event history so you can quickly see what changed, what was blocked, and what needs attention.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Login Activity:\u003C\u002Fstrong> Successful logins, failed attempts, lockouts, 2FA events, and account-related actions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User & Site Changes:\u003C\u002Fstrong> User updates, plugin and theme changes, settings changes, and sensitive admin actions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Firewall Activity:\u003C\u002Fstrong> Blocked IPs, country rules, bot blocks, rate-limit events, and suspicious request activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scanner Results:\u003C\u002Fstrong> Malware findings, vulnerability findings, reputation checks, hardening issues, and scan history.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Site-level security features are available from the WordPress dashboard. SiteFort Console is optional for teams that need centralized visibility across multiple sites, downloadable reports for clients, and team roles and support workflows.\u003C\u002Fp>\n\u003Ch3>Hosting Compatibility\u003C\u002Fh3>\n\u003Cp>SiteFort is built for real WordPress environments.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Compatible with shared hosting, managed WordPress hosting, VPS, and dedicated servers.\u003C\u002Fli>\n\u003Cli>Works with Apache, Nginx, and LiteSpeed.\u003C\u002Fli>\n\u003Cli>Cloudflare-friendly: supports proxied sites and optional Cloudflare rule sync.\u003C\u002Fli>\n\u003Cli>Cloud-assisted scanning reduces heavy scan work on lower-resource hosting plans.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Free vs Pro\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Free includes\u003C\u002Fstrong> the firewall, bot filter, login security and 2FA, verified hardening, vulnerability checks, audit log, quarantine, and cloud malware scanning with 3,000 scan credits every month.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Pro adds:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Unlimited cloud scanning with deep threat analysis\u003C\u002Fli>\n\u003Cli>Scheduled scans and automated vulnerability alerts\u003C\u002Fli>\n\u003Cli>One-click malware repair with clean-file restore for core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Uptime and SSL expiry monitoring\u003C\u002Fli>\n\u003Cli>Slack, Discord, email, and webhook alerts\u003C\u002Fli>\n\u003Cli>Remote scan history, advanced reports, and white-label options for agencies\u003C\u002Fli>\n\u003Cli>Expert cleanup discounts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Managed\u003C\u002Fstrong> adds hands-on monitoring, response workflows, and expert cleanup coverage by the SecureWP team.\u003C\u002Fp>\n\u003Cp>Looking for a market comparison? See the \u003Ca href=\"https:\u002F\u002Fsecurewp.net\u002Fwordpress-security-plugin-comparison\u002F\" rel=\"nofollow ugc\">WordPress Security Plugin Comparison\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>SiteFort connects to external services only when needed for license activation, cloud-assisted malware analysis, vulnerability intelligence, firewall intelligence, optional Console sync, optional CAPTCHA, optional GeoIP, Cloudflare sync, and administrator-enabled notifications.\u003C\u002Fp>\n\u003Cp>Optional integrations are not contacted unless they are configured or used.\u003C\u002Fp>\n\u003Ch4>SiteFort Cloud\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Servers:\u003C\u002Fstrong> securewp.net, intel.securewp.net, console.securewp.net\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Used for:\u003C\u002Fstrong> License activation, service metadata, cloud malware analysis, vulnerability intelligence, firewall intelligence, reputation checks, community blocklist sync, clean-file repair, and optional Console sync.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Email address, license key\u002Ftoken, site URL, WordPress\u002Fplugin versions, installed plugin\u002Ftheme names and versions, file hashes, scan results, vulnerability findings, reputation status, firewall metadata, blocked IPs, and security configuration metadata.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Malware scanning:\u003C\u002Fstrong> File hashes are sent first. Only unknown or suspicious files may be uploaded for deeper analysis and are deleted after processing. Database and content checks run on your website. SiteFort does not upload your database or database-stored content to the cloud. If wp-config.php requires analysis, sensitive configuration values are removed before upload.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Temporary storage:\u003C\u002Fstrong> SiteFort Cloud may return temporary upload\u002Fdownload URLs on *.amazonaws.com for scan uploads or clean-file repair downloads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fsecurewp.net\u002Fprivacy-policy\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fsecurewp.net\u002Fterms-and-conditions\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage provider policies:\u003C\u002Fstrong> AWS privacy https:\u002F\u002Faws.amazon.com\u002Fprivacy\u002F and terms https:\u002F\u002Faws.amazon.com\u002Fservice-terms\u002F; Cloudflare privacy https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F and terms https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Optional integrations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>MaxMind GeoLite2\u003C\u002Fstrong> (download.maxmind.com) is used only when an administrator downloads or updates the local GeoIP database. It sends the configured MaxMind account ID and license key. Visitor IPs are resolved locally and are not sent to MaxMind during normal requests. Privacy: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fprivacy-policy Terms: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fgeolite2\u002Feula\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Have I Been Pwned Passwords\u003C\u002Fstrong> (api.pwnedpasswords.com) is used for breached-password checks when enabled. SiteFort sends only the first 5 characters of the SHA-1 password hash. Full passwords and full hashes are never sent. Privacy: https:\u002F\u002Fhaveibeenpwned.com\u002FPrivacy Terms: https:\u002F\u002Fhaveibeenpwned.com\u002FTermsOfUse\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google reCAPTCHA\u003C\u002Fstrong> (www.google.com) and \u003Cstrong>Cloudflare Turnstile\u003C\u002Fstrong> (challenges.cloudflare.com) are used only when selected and configured for CAPTCHA protection. They receive the challenge token, site key, and visitor\u002Fbrowser data required by the selected provider. Policies: https:\u002F\u002Fpolicies.google.com\u002Fprivacy https:\u002F\u002Fpolicies.google.com\u002Fterms https:\u002F\u002Fwww.cloudflare.com\u002Fturnstile-privacy-policy\u002F https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare API\u003C\u002Fstrong> (api.cloudflare.com) is used only when Cloudflare Sync is enabled. It sends Zone ID, API token\u002Fcredentials, zone details, blocked IPs, country rules, selected user-agent rules, and firewall rule data. Privacy: https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F Terms: https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notification webhooks\u003C\u002Fstrong> may send security alerts to Slack (hooks.slack.com), Discord (discord.com, discordapp.com), or a custom HTTPS webhook entered by the administrator. Webhook payloads may include site name, site URL, event type, severity, scan counts, vulnerability names, CVE identifiers, firewall counts, usernames, IP addresses, browser names, action URLs, timestamps, and event details. Slack policies: https:\u002F\u002Fslack.com\u002Ftrust\u002Fprivacy\u002Fprivacy-policy https:\u002F\u002Fslack.com\u002Fterms-of-service\u002Fuser Discord policies: https:\u002F\u002Fdiscord.com\u002Fprivacy https:\u002F\u002Fdiscord.com\u002Fterms\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Local site checks\u003C\u002Fh4>\n\u003Cp>Some requests are loopback checks against the protected site’s own public URL, such as security-header checks, public-file exposure checks, and homepage link collection. These contact the site being protected, not a third-party service.\u003C\u002Fp>\n","Prevention-first WordPress security. Hardening, firewall, bot filter, and 2FA close the doors; cloud-assisted malware scanning keeps your site fast.",40,1807,4,"2026-07-20T15:57:00.000Z",[121,122,21,22,23],"2fa","firewall","https:\u002F\u002Fsecurewp.net\u002Fwordpress-security-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsitefort.1.7.5.zip",{"error":126,"url":127,"statusCode":128,"statusMessage":129,"message":129},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Faipatch-security-scanner\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":91,"versions":131},[132,138,145],{"version":6,"download_url":25,"svn_tag_url":133,"released_at":26,"has_diff":134,"diff_files_changed":135,"diff_lines":26,"trac_diff_url":136,"vulnerabilities":137,"is_current":126},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Faipatch-security-scanner\u002Ftags\u002F2.0.2\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Faipatch-security-scanner%2Ftags%2F2.0.1&new_path=%2Faipatch-security-scanner%2Ftags%2F2.0.2",[],{"version":139,"download_url":140,"svn_tag_url":141,"released_at":26,"has_diff":134,"diff_files_changed":142,"diff_lines":26,"trac_diff_url":143,"vulnerabilities":144,"is_current":134},"2.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.2.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Faipatch-security-scanner\u002Ftags\u002F2.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Faipatch-security-scanner%2Ftags%2F1.0.2&new_path=%2Faipatch-security-scanner%2Ftags%2F2.0.1",[],{"version":41,"download_url":146,"svn_tag_url":147,"released_at":26,"has_diff":134,"diff_files_changed":148,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":149,"is_current":134},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Faipatch-security-scanner\u002Ftags\u002F1.0.2\u002F",[],[]]