[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdCRdwusEt7Ll7my3fH1wfGie_aN-cYl1qzfJmIWQ2U8":3,"$fgQLr9e0zTyqtwyN24XMSYOBQKJuTkG_1tqLDhFP5XjA":115,"$f169lWo5qicOMl3cRGNGYOWn4PBXJ12L4WRXdGEOuAyU":120},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":37,"analysis":26,"fingerprints":26},"anonindo-security-advisor","Anonindo Security Advisor","1.1.1","Akshay Vasoya","https:\u002F\u002Fprofiles.wordpress.org\u002Fanonymoustech\u002F","\u003Cp>Anonindo Security Advisor helps site owners understand and improve their WordPress security posture without acting like a full firewall suite.\u003C\u002Fp>\n\u003Cp>The plugin follows a simple workflow:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Scan for common WordPress security issues and misconfigurations\u003C\u002Fli>\n\u003Cli>Explain what each issue means in beginner-friendly language\u003C\u002Fli>\n\u003Cli>Show practical guidance and safer best practices\u003C\u002Fli>\n\u003Cli>Offer safe auto-fix actions for selected hardening steps\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is designed to be lightweight, educational, and operationally safe.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Detects debug mode enabled in production\u003C\u002Fli>\n\u003Cli>Detects dashboard file editing enabled\u003C\u002Fli>\n\u003Cli>Detects XML-RPC exposure\u003C\u002Fli>\n\u003Cli>Detects weak file permissions on common paths\u003C\u002Fli>\n\u003Cli>Detects potentially exposed \u003Ccode>wp-config.php\u003C\u002Fcode> backup patterns\u003C\u002Fli>\n\u003Cli>Detects outdated plugins and themes\u003C\u002Fli>\n\u003Cli>Detects suspicious administrator account patterns\u003C\u002Fli>\n\u003Cli>Detects REST API user enumeration exposure\u003C\u002Fli>\n\u003Cli>Heuristically scans active theme and plugin PHP files for basic SQL injection and XSS risk patterns\u003C\u002Fli>\n\u003Cli>Scans selected database content for suspicious script-like patterns\u003C\u002Fli>\n\u003Cli>Provides a security score and prioritized recommendations\u003C\u002Fli>\n\u003Cli>Includes an activity log for meaningful security-related site events\u003C\u002Fli>\n\u003Cli>Supports safe auto-fixes for selected hardening improvements\u003C\u002Fli>\n\u003C\u002Ful>\n","Lightweight WordPress security coach for scanning risks, explaining issues clearly, and guiding safer site improvements.",0,143,"2026-05-14T11:13:00.000Z","6.9.5","6.4","7.4",[18,19,20,21,22],"admin","audit","hardening","scanner","security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanonindo-security-advisor.1.1.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":25,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"anonymoustech",5,50,30,94,"2026-08-25T01:35:31.105Z",[38,55,69,84,99],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":25,"downloaded":46,"rating":11,"num_ratings":11,"last_updated":47,"tested_up_to":48,"requires_at_least":49,"requires_php":16,"tags":50,"homepage":53,"download_link":54,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"aipatch-security-scanner","Aipatch Security Scanner","2.0.2","Esteban","https:\u002F\u002Fprofiles.wordpress.org\u002Festebandezafra\u002F","\u003Cp>\u003Cstrong>Aipatch Security Scanner\u003C\u002Fstrong> is a modular security audit engine built for site owners, developers, and AI-powered agents who need deep visibility into WordPress security posture — without the bloat of all-in-one security suites.\u003C\u002Fp>\n\u003Ch4>Why Aipatch Security Scanner?\u003C\u002Fh4>\n\u003Cp>Most WordPress security plugins are either too simple to be useful or too heavy to be practical. Aipatch takes a different approach:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Audit-first architecture.\u003C\u002Fstrong> Every check is a standalone, testable module that returns structured findings with severity, confidence, evidence, and fingerprints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built for automation.\u003C\u002Fstrong> 23 MCP abilities expose the full audit, scanning, and remediation surface to external AI agents — making Aipatch the first WordPress security plugin designed for agentic workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero external dependencies.\u003C\u002Fstrong> Everything runs locally. No accounts, no cloud services, no API keys required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reversible by design.\u003C\u002Fstrong> Every automated remediation stores rollback data so you can undo any change with one click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Core Capabilities\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>36-Point Security Audit\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Aipatch runs 36 automated checks across 8 categories — core, plugins, themes, users, configuration, server, access control, and malware surface:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Outdated WordPress core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Default admin username, excessive admin accounts, inactive admin users, user ID 1 exposure\u003C\u002Fli>\n\u003Cli>XML-RPC, file editor, debug mode, debug log, REST API exposure, directory listing\u003C\u002Fli>\n\u003Cli>PHP version, HTTPS, file permissions, security headers (X-Frame-Options, CSP, etc.)\u003C\u002Fli>\n\u003Cli>Database prefix, sensitive files, PHP execution in uploads, auto-update configuration\u003C\u002Fli>\n\u003Cli>Salt key strength, cron health, cookie security flags, CORS, application passwords\u003C\u002Fli>\n\u003Cli>Exposed backup files, phpinfo files, uploads directory indexing, default login URL\u003C\u002Fli>\n\u003Cli>Database credential security, file installation permissions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Every finding includes a severity (critical \u002F high \u002F medium \u002F low \u002F info), confidence score, human-readable explanation, and actionable recommendation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Weighted Security Score (0–100)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A logarithmic scoring engine computes an overall security score and per-area breakdown across six risk dimensions: software, access control, configuration, infrastructure, malware surface, and vulnerability exposure. Severity weights and confidence multipliers ensure the score reflects actual risk, not just issue count.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Multi-Layer Malware File Scanner\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A three-layer file scanner (content 55%, context 25%, integrity 20%) with 27 detection signatures, Shannon entropy analysis, and malware family classification detects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Code execution patterns: eval(), assert(), create_function(), preg_replace \u002Fe\u003C\u002Fli>\n\u003Cli>System command functions: shell_exec, exec, passthru, backtick operators\u003C\u002Fli>\n\u003Cli>Obfuscation techniques: base64 encoding, hex encoding, str_rot13, gzinflate chains, chr() concatenation, variable variables, suspiciously long lines\u003C\u002Fli>\n\u003Cli>Network\u002Fexfiltration: cURL execution, fsockopen, remote file_get_contents\u003C\u002Fli>\n\u003Cli>Known backdoor signatures: c99, r57, WSO, b374k, weevely, FilesMan\u003C\u002Fli>\n\u003Cli>WordPress-specific threats: unauthorized admin creation, critical option injection, security function removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Scanning runs in batches via an async job system with configurable batch sizes — safe for shared hosting.\u003C\u002Fp>\n\u003Cp>Files are classified into 11 malware families (web shell, obfuscated loader, dropper, persistence backdoor, cloaked PHP, code injector, and more) with confidence scores and remediation hints.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Core Integrity Verification\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Verifies every core file against official checksums from api.wordpress.org. Detects modified core files (checksum mismatch), missing core files, and unexpected files planted in wp-admin\u002F or wp-includes\u002F. Core tampering findings are automatically escalated to critical severity with zero false-positive likelihood.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Build a known-good hash baseline of all PHP files in your installation. Diff against it at any time to detect modified, deleted, or newly added files. Origin detection distinguishes core, plugin, theme, and upload files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A local knowledge base of known plugin, theme, and core vulnerabilities with a database-backed caching layer for fast lookups. Provider architecture allows extending with external feeds.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-Click Remediation with Rollback\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Apply fixes directly from findings — change WordPress options, delete suspicious files, rename files, patch file contents, or add .htaccess rules. Every automated action stores a full rollback payload so you can reverse any change. Manual remediations can be logged for audit trails.\u003C\u002Fp>\n\u003Cp>Six supported action types: \u003Ccode>wp_option\u003C\u002Fcode>, \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>rename_file\u003C\u002Fcode>, \u003Ccode>file_patch\u003C\u002Fcode>, \u003Ccode>htaccess_rule\u003C\u002Fcode>, \u003Ccode>manual\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hardening Module\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Five toggleable hardening rules with clear explanations and compatibility warnings:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable XML-RPC — blocks external XML-RPC requests and removes X-Pingback header\u003C\u002Fli>\n\u003Cli>Hide WordPress Version — removes version leaks from source, RSS feeds, scripts, and styles\u003C\u002Fli>\n\u003Cli>Restrict REST API — limits sensitive endpoints to authenticated users\u003C\u002Fli>\n\u003Cli>Block Author Scanning — prevents user enumeration via author archives\u003C\u002Fli>\n\u003Cli>Login Brute-Force Protection — rate-limits login attempts per IP with configurable thresholds and lockout duration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Persistent Findings Store\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All audit findings persist in a dedicated database table with automatic deduplication by fingerprint. Track findings over time — dismissed findings stay dismissed across scans; resolved findings reopen if the issue reappears.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Event Logging\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Every scan, hardening change, remediation, and significant event is logged to a dedicated table. Logs are filterable by severity and exportable as CSV.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Site Health Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Adds 6 security tests to the built-in Site Health screen: file editor, debug mode, XML-RPC, admin username, SSL, and overall security score.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Diagnostics\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Built-in performance profiling to identify slow queries, high memory usage, and resource bottlenecks related to security operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>10 authenticated endpoints under the \u003Ccode>aipatch-security-scanner\u002Fv1\u003C\u002Fcode> namespace for triggering scans, retrieving summaries, toggling hardening, exporting logs, and running performance diagnostics.\u003C\u002Fp>\n\u003Ch4>MCP Surface for AI Agents (23 Abilities)\u003C\u002Fh4>\n\u003Cp>Aipatch exposes 23 structured abilities via the WordPress Abilities API — making your site’s security surface fully accessible to external AI agents, coding assistants, and orchestration tools:\u003C\u002Fp>\n\u003Cp>By default, only \u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> is enabled. You can enable additional abilities from \u003Cstrong>Aipatch Security Scanner -> Settings -> MCP Abilities\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> — Run a full 36-check security audit with scored findings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-suspicious\u003C\u002Fstrong> — Quick heuristic scan for suspicious files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fstart-file-scan\u003C\u002Fstrong> — Launch an async multi-layer malware scan job\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fprocess-file-scan-batch\u003C\u002Fstrong> — Process next batch of files in a running scan\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-progress\u003C\u002Fstrong> — Check file scan progress\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-results\u003C\u002Fstrong> — Retrieve enriched scan results with family, reasons, layer scores\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-scan-summary\u003C\u002Fstrong> — Comprehensive latest scan summary with classification breakdown\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-suspicious-files\u003C\u002Fstrong> — List suspicious files from latest scan (no job_id needed)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Integrity & Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fverify-core-integrity\u003C\u002Fstrong> — Verify WP core files against official api.wordpress.org checksums\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-build\u003C\u002Fstrong> — Build or refresh the known-good file hash baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-diff\u003C\u002Fstrong> — Compare current filesystem against stored baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-stats\u003C\u002Fstrong> — Baseline statistics by origin type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-baseline-drift\u003C\u002Fstrong> — Combined baseline drift + core integrity report\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Findings & Monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-findings\u003C\u002Fstrong> — Query persistent findings with status\u002Fseverity\u002Fcategory filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-stats\u003C\u002Fstrong> — Aggregate finding statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-diff\u003C\u002Fstrong> — New and resolved findings since a point in time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-file-finding-detail\u003C\u002Fstrong> — Single finding with decoded metadata, layer scores, family\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fdismiss-finding\u003C\u002Fstrong> — Dismiss a finding as accepted risk\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Remediation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fapply-remediation\u003C\u002Fstrong> — Apply a security fix with rollback support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Frollback-remediation\u003C\u002Fstrong> — Undo a previously applied fix\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-remediations\u003C\u002Fstrong> — List remediation history with filters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Jobs & Status\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-jobs\u003C\u002Fstrong> — List scan\u002Faudit jobs with filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-async-job-status\u003C\u002Fstrong> — Check async job status and retrieve results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>20 abilities are read-only; only 3 (dismiss, apply-remediation, rollback) modify site state. All abilities include typed input\u002Foutput schemas, permission checks (\u003Ccode>manage_options\u003C\u002Fcode>), and structured error responses.\u003C\u002Fp>\n\u003Ch4>What Aipatch Does NOT Do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>It is NOT a firewall or WAF — it does not filter incoming traffic.\u003C\u002Fli>\n\u003Cli>It does NOT intercept frontend requests or affect page load performance.\u003C\u002Fli>\n\u003Cli>It does NOT phone home, require an account, or send data externally.\u003C\u002Fli>\n\u003Cli>It does NOT inject ads, upsells, or nag notices.\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress security scanner with 36 checks, malware scanning, core integrity verification, remediation, and 23 MCP abilities.",477,"2026-05-03T09:18:00.000Z","7.0.2","6.5",[19,20,51,22,52],"malware-scanner","vulnerability","https:\u002F\u002Fgithub.com\u002Festebanstifli\u002Faipatch-security-scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.2.0.2.zip",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":63,"downloaded":64,"rating":11,"num_ratings":11,"last_updated":65,"tested_up_to":14,"requires_at_least":15,"requires_php":66,"tags":67,"homepage":23,"download_link":68,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"steel-security","Steel Security & Hardening – Site Audit Tools","1.0.4","sweetwatermedia","https:\u002F\u002Fprofiles.wordpress.org\u002Fsweetwatermedia\u002F","\u003Cp>Steel Security & Hardening – Site Audit Tools focuses on practical security hygiene for WordPress administrators.\u003C\u002Fp>\n\u003Cp>The free plugin provides:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>on-demand security scans\u003C\u002Fli>\n\u003Cli>risk summaries grouped by severity and category\u003C\u002Fli>\n\u003Cli>checks for common WordPress hardening gaps\u003C\u002Fli>\n\u003Cli>checks for exposed root-level artifacts such as \u003Ccode>.env\u003C\u002Fcode>, SQL dumps, \u003Ccode>phpinfo\u003C\u002Fcode> files, and backup archives\u003C\u002Fli>\n\u003Cli>a quarantine vault for operator-reviewed file isolation\u003C\u002Fli>\n\u003Cli>uploads PHP execution blocking on supported server environments\u003C\u002Fli>\n\u003Cli>manual guidance when automatic server hardening is not safely supported\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is positioned as an auditing and hardening tool. It helps surface risk and apply selected preventive controls, but it does not promise malware removal, incident response, or complete server protection.\u003C\u002Fp>\n\u003Ch4>Included checks\u003C\u002Fh4>\n\u003Cp>The scan currently looks for items such as:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP error display exposure\u003C\u002Fli>\n\u003Cli>\u003Ccode>WP_DEBUG\u003C\u002Fcode> and \u003Ccode>debug.log\u003C\u002Fcode> exposure\u003C\u002Fli>\n\u003Cli>XML-RPC availability\u003C\u002Fli>\n\u003Cli>author and REST user enumeration exposure\u003C\u002Fli>\n\u003Cli>theme\u002Fplugin file editor availability\u003C\u002Fli>\n\u003Cli>WordPress generator meta output\u003C\u002Fli>\n\u003Cli>comments enabled by default\u003C\u002Fli>\n\u003Cli>uploads PHP execution hardening status\u003C\u002Fli>\n\u003Cli>root-level sensitive files and archives\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Server-aware behavior\u003C\u002Fh4>\n\u003Cp>This plugin only auto-applies server config changes where it can do so in a scoped and reversible way.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Apache and LiteSpeed: uploads PHP blocking is managed through a Steel Security-marked \u003Ccode>.htaccess\u003C\u002Fcode> block\u003C\u002Fli>\n\u003Cli>IIS: uploads PHP blocking is managed through a Steel Security-marked \u003Ccode>web.config\u003C\u002Fcode> section\u003C\u002Fli>\n\u003Cli>Nginx and unsupported environments: Steel Security provides manual guidance instead of claiming automatic protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro companion\u003C\u002Fh4>\n\u003Cp>This plugin can work with a separate Pro companion plugin that adds features such as scheduled scans, scan history, reports, and managed server-level controls such as directory listing protection and baseline security headers. The free plugin remains usable on its own.\u003C\u002Fp>\n","High-signal WordPress security auditing and hardening with practical site audit tools for administrators.",20,218,"2026-04-28T22:21:00.000Z","8.0",[19,20,21,22],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsteel-security.1.0.4.zip",{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":11,"downloaded":77,"rating":11,"num_ratings":11,"last_updated":78,"tested_up_to":48,"requires_at_least":79,"requires_php":16,"tags":80,"homepage":82,"download_link":83,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"shieldscope-site-security-scanner","ShieldScope – Site Security Scanner","1.3.1","Dhiren Patel","https:\u002F\u002Fprofiles.wordpress.org\u002Fdhirenpatel22\u002F","\u003Cp>\u003Cstrong>ShieldScope – Site Security Scanner\u003C\u002Fstrong> runs a deep, read-only security audit across your entire WordPress site and produces a clear report of issues grouped by severity: Critical, High, Medium, Low, and Info.\u003C\u002Fp>\n\u003Cp>Most security scanners either freeze your admin panel while they run, or quietly hammer your server in the background. ShieldScope does neither. It runs in small, controlled steps with a built-in speed limit — so your site stays fast and responsive the whole time. If you switch to another browser tab, the scan automatically pauses and picks up exactly where it left off when you return.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Here is what ShieldScope checks:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch4>WordPress Core Health\u003C\u002Fh4>\n\u003Cp>Checks that your WordPress installation is up to date and securely configured. Flags outdated versions, exposed debug settings, insecure table prefixes, and other common setup mistakes that attackers actively look for.\u003C\u002Fp>\n\u003Ch4>Core File Integrity\u003C\u002Fh4>\n\u003Cp>Verifies that every WordPress core file is exactly as it should be by comparing against official WordPress checksums. Flags any modified or unexpected files inside core WordPress folders — a common sign of a hacked or tampered site.\u003C\u002Fp>\n\u003Ch4>User Accounts\u003C\u002Fh4>\n\u003Cp>Reviews all administrator accounts for common weaknesses: a default “admin” username, too many admin accounts, weak or outdated password storage, empty passwords, and accounts whose login name is visible to the public.\u003C\u002Fp>\n\u003Ch4>Files & Folders\u003C\u002Fh4>\n\u003Cp>Scans your site’s file system for risky permissions, sensitive configuration files left publicly accessible, leftover backup files that should never be on a live server, and unexpected files in folders where only media should live.\u003C\u002Fp>\n\u003Ch4>Plugins\u003C\u002Fh4>\n\u003Cp>Flags plugins with pending security updates, plugins that are installed but inactive (a common attack surface), and plugins that appear to have been abandoned by their developers with no recent maintenance.\u003C\u002Fp>\n\u003Ch4>Themes\u003C\u002Fh4>\n\u003Cp>Flags themes with pending updates, extra inactive themes that add unnecessary risk, and checks whether your site has a proper active theme configured.\u003C\u002Fp>\n\u003Ch4>Malicious Code Patterns\u003C\u002Fh4>\n\u003Cp>Scans plugin and theme files for known malware signatures, hidden backdoors, and dangerous code patterns that attackers commonly plant on compromised WordPress sites.\u003C\u002Fp>\n\u003Ch4>SSL & HTTPS\u003C\u002Fh4>\n\u003Cp>Checks that your SSL certificate is valid and not about to expire, that your site uses a modern version of HTTPS encryption, that all pages load securely, and that visitors are always redirected from HTTP to HTTPS automatically.\u003C\u002Fp>\n\u003Ch4>Security Headers\u003C\u002Fh4>\n\u003Cp>Checks that your site sends the right security instructions to visitors’ browsers — protections that help prevent clickjacking, content-type attacks, and referrer leaks. Also checks whether your WordPress version number is being broadcast publicly, which gives attackers a head start.\u003C\u002Fp>\n\u003Ch4>Database Settings\u003C\u002Fh4>\n\u003Cp>Checks database-level security settings: whether open user registration is configured with too many permissions, whether your site URLs are consistent, and whether any administrator accounts were created recently without your knowledge.\u003C\u002Fp>\n\u003Ch4>Injection Vulnerabilities\u003C\u002Fh4>\n\u003Cp>Scans plugin and theme code for common vulnerability patterns including SQL injection, cross-site scripting (XSS), and other code weaknesses that attackers exploit to take control of WordPress sites or steal visitor data.\u003C\u002Fp>\n\u003Ch4>Access Control\u003C\u002Fh4>\n\u003Cp>Tests whether parts of your site that should require a login are actually protected. Looks for username leaks through public author pages, missing brute-force login protection, lack of two-factor authentication, and whether admin pages and API endpoints enforce proper access checks.\u003C\u002Fp>\n\u003Ch4>Server Configuration\u003C\u002Fh4>\n\u003Cp>Checks for server-level security issues: outdated PHP versions that no longer receive security patches, sensitive files accidentally left accessible to the public (such as environment config files or debug logs), and server settings that leak technical information to potential attackers.\u003C\u002Fp>\n\u003Ch4>Server-Side Request Forgery (SSRF)\u003C\u002Fh4>\n\u003Cp>Looks for code patterns in plugins and themes that could allow an attacker to trick your server into making unauthorised requests to other systems — both on the internet and inside your private network.\u003C\u002Fp>\n\u003Ch4>Vulnerable & Outdated Components\u003C\u002Fh4>\n\u003Cp>Checks your database software version, WordPress version, and installed plugins against known vulnerability records and end-of-support dates. Flags anything running on software that no longer receives security patches.\u003C\u002Fp>\n\u003Ch4>Vulnerability Database\u003C\u002Fh4>\n\u003Cp>Cross-references your installed plugins and themes against a known vulnerability database. A free WPScan API key (optional) enables live lookups for every plugin and theme on your site. Without a key, a built-in list of the most commonly exploited plugins is checked automatically — no setup needed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>ShieldScope never makes any changes to your site.\u003C\u002Fstrong> It is strictly read-only. It scans, reports, and recommends — nothing else.\u003C\u002Fp>\n\u003Ch3>Third-Party Services\u003C\u002Fh3>\n\u003Cp>This plugin communicates with the following external services \u003Cstrong>only while a scan is actively running\u003C\u002Fstrong>. No data is sent on regular page loads.\u003C\u002Fp>\n\u003Ch4>WordPress.org Core Checksums API\u003C\u002Fh4>\n\u003Cp>During the Core Integrity check, the plugin fetches the official file checksums for your exact WordPress version and locale from the WordPress.org API. The only data sent is your WordPress version number and site locale (for example, en_US). No personal data, usernames, or site URLs are transmitted.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service: https:\u002F\u002Fapi.wordpress.org\u002Fcore\u002Fchecksums\u002F1.0\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WPScan Vulnerability Database (optional)\u003C\u002Fh4>\n\u003Cp>If you enter a WPScan API key in Settings, the Vulnerability Database check sends the slug and version number of each installed plugin and theme to wpscan.com to retrieve known vulnerability data. This feature is \u003Cstrong>disabled by default\u003C\u002Fstrong> and requires you to explicitly provide an API key. The free tier allows 25 requests per day; results are cached for 24 hours.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service: https:\u002F\u002Fwpscan.com\u002Fapi\u002Fv3\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\u003C\u002Fli>\n\u003Cli>Terms of service: https:\u002F\u002Fwpscan.com\u002Fterms\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Disclaimer\u003C\u002Fh3>\n\u003Cp>ShieldScope uses automated analysis to identify potential security issues. Findings should be reviewed before acting on them — particularly for plugins and themes, where a finding may require verification with the plugin or theme developer.\u003C\u002Fp>\n\u003Cp>This plugin is designed to help website owners identify security risks on their own sites. It does not guarantee detection of every possible vulnerability.\u003C\u002Fp>\n\u003Cp>All scanning is performed locally on your own server. No scan data, site content, or personal information is stored externally or shared with any third party. For questions, please use the support forum.\u003C\u002Fp>\n","A thorough WordPress security scanner that checks your entire site for vulnerabilities and misconfigurations — without slowing it down.",114,"2026-07-01T07:52:00.000Z","5.8",[19,20,81,21,22],"malware","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fshieldscope-site-security-scanner\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshieldscope-site-security-scanner.1.3.1.zip",{"slug":85,"name":86,"version":87,"author":88,"author_profile":89,"description":90,"short_description":91,"active_installs":11,"downloaded":92,"rating":11,"num_ratings":11,"last_updated":93,"tested_up_to":48,"requires_at_least":94,"requires_php":16,"tags":95,"homepage":97,"download_link":98,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"treder-security-snapshot","Treder Security Snapshot","1.0.0","Ben Treder","https:\u002F\u002Fprofiles.wordpress.org\u002Fbdtreder\u002F","\u003Cp>Treder Security Snapshot gives WordPress site owners a simple local security health report.\u003C\u002Fp>\n\u003Cp>It is not a firewall, malware removal tool, or all-in-one security suite. It focuses on clear visibility, practical recommendations, and easy reporting.\u003C\u002Fp>\n\u003Cp>The plugin checks common WordPress security basics and gives you a security score from 0 to 100.\u003C\u002Fp>\n\u003Ch4>Included Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Security score from 0 to 100\u003C\u002Fli>\n\u003Cli>Dashboard tab\u003C\u002Fli>\n\u003Cli>Detailed audit tab\u003C\u002Fli>\n\u003Cli>Scan history tab\u003C\u002Fli>\n\u003Cli>WordPress dashboard widget\u003C\u002Fli>\n\u003Cli>Beginner-friendly explanations\u003C\u002Fli>\n\u003Cli>Suggested fixes\u003C\u002Fli>\n\u003Cli>Local scan history\u003C\u002Fli>\n\u003Cli>Local HTML report download\u003C\u002Fli>\n\u003Cli>Email latest report to a chosen address\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security Checks\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress core update status\u003C\u002Fli>\n\u003Cli>Plugin update status\u003C\u002Fli>\n\u003Cli>Theme update status\u003C\u002Fli>\n\u003Cli>Default admin usernames\u003C\u002Fli>\n\u003Cli>User enumeration risk\u003C\u002Fli>\n\u003Cli>XML-RPC status\u003C\u002Fli>\n\u003Cli>File editing status\u003C\u002Fli>\n\u003Cli>Debug mode status\u003C\u002Fli>\n\u003Cli>Directory browsing indicators\u003C\u002Fli>\n\u003Cli>HTTPS and SSL status\u003C\u002Fli>\n\u003Cli>Database prefix check\u003C\u002Fli>\n\u003Cli>WordPress version visibility\u003C\u002Fli>\n\u003Cli>Public registration status\u003C\u002Fli>\n\u003Cli>Inactive plugins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Separate Pro Companion\u003C\u002Fh4>\n\u003Cp>A separate Pro companion plugin is available from the author’s website for users who want additional tools such as advanced checks, scheduled reports, file integrity monitoring, white-label reporting, and AI-assisted fix plans.\u003C\u002Fp>\n\u003Cp>The WordPress.org plugin includes all functionality described in this readme.\u003C\u002Fp>\n","A lightweight WordPress security health report with a simple score, clear findings, local reports, and beginner-friendly suggested fixes.",81,"2026-06-15T13:32:00.000Z","6.0",[18,19,20,96,22],"report","https:\u002F\u002Fbentreder.com\u002Fplugins\u002Ftreder-security-snapshot","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftreder-security-snapshot.1.0.0.zip",{"slug":100,"name":101,"version":102,"author":103,"author_profile":104,"description":105,"short_description":106,"active_installs":25,"downloaded":107,"rating":25,"num_ratings":108,"last_updated":109,"tested_up_to":48,"requires_at_least":94,"requires_php":16,"tags":110,"homepage":23,"download_link":114,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"lockora-security-audit","Lockora Security Audit","0.2.0","Guido Schad","https:\u002F\u002Fprofiles.wordpress.org\u002Fcmdgw\u002F","\u003Cp>Lockora Security Audit helps site owners and agencies review a WordPress site’s security posture from the admin area.\u003C\u002Fp>\n\u003Cp>Current prototype features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Manual security scans.\u003C\u002Fli>\n\u003Cli>Weighted security score out of 100.\u003C\u002Fli>\n\u003Cli>WordPress core file integrity checks using official checksums.\u003C\u002Fli>\n\u003Cli>WordPress authentication key and salt checks, with an explicit action to generate missing salts.\u003C\u002Fli>\n\u003Cli>Must-use plugin directory presence checks.\u003C\u002Fli>\n\u003Cli>PHP version status using WordPress.org Serve Happy data.\u003C\u002Fli>\n\u003Cli>HTTPS and HTTP security header checks.\u003C\u002Fli>\n\u003Cli>WordPress core, plugin, and theme update posture checks.\u003C\u002Fli>\n\u003Cli>Administrator account posture checks for default usernames, excess admins, inactive admins, user ID 1 exposure, and an admin username\u002Femail inventory.\u003C\u002Fli>\n\u003Cli>Public exposure checks: debug.log and readme.html reachability, uploads directory listing, PHP execution inside uploads, and author archive user enumeration.\u003C\u002Fli>\n\u003Cli>SSL certificate expiry check, database table prefix check, automatic update posture check, and detection of login protection \u002F two-factor plugins.\u003C\u002Fli>\n\u003Cli>Site Health integration: scan summary plus key configuration checks appear under Tools > Site Health > Status.\u003C\u002Fli>\n\u003Cli>WP-CLI support: \u003Ccode>wp lockora scan\u003C\u002Fcode> and \u003Ccode>wp lockora report\u003C\u002Fcode>, with \u003Ccode>--format=json\u003C\u002Fcode> and a \u003Ccode>--strict\u003C\u002Fcode> flag for CI pipelines.\u003C\u002Fli>\n\u003Cli>Optional known vulnerability matching with a configured Wordfence Intelligence API key.\u003C\u002Fli>\n\u003Cli>Optional AI client reports on WordPress 7.0+ when the site’s AI Connector is configured.\u003C\u002Fli>\n\u003Cli>Reversible hardening toggles for XML-RPC, REST user routes, generator tag output, and basic security headers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Lockora Security Audit may connect to external services only when the administrator runs a scan or generates an AI client report.\u003C\u002Fp>\n\u003Cp>During a scan the plugin also sends HTTP requests to the site’s own public URL (loopback requests) to inspect response headers, debug.log and readme.html reachability, uploads directory behavior, and author archive redirects, and it opens a TLS connection to the site’s own hostname to read the SSL certificate expiry date. These requests stay within the site being scanned and send no data to third parties.\u003C\u002Fp>\n\u003Cp>WordPress.org APIs:\u003Cbr \u002F>\n* Used for WordPress core checksums, PHP version support status, and WordPress core\u002Fplugin\u002Ftheme update data.\u003Cbr \u002F>\n* Data sent: the site’s WordPress version and locale for core checksums and PHP compatibility; WordPress itself may send installed plugin and theme slugs\u002Fversions to WordPress.org when update data is refreshed.\u003Cbr \u002F>\n* WordPress.org terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms\u002F\u003Cbr \u002F>\n* WordPress.org privacy policy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>Wordfence Intelligence:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when a Wordfence Intelligence API key is configured and an administrator runs a scan that includes vulnerability matching.\u003Cbr \u002F>\n* Used to retrieve vulnerability data and match it locally against installed WordPress core, plugin, and theme versions.\u003Cbr \u002F>\n* Data sent: the configured Wordfence Intelligence API key is sent in an Authorization header when requesting the vulnerability feed. Installed software details are not sent by this plugin to the Wordfence Intelligence endpoint; matching is performed locally after the feed is retrieved.\u003Cbr \u002F>\n* Wordfence Intelligence terms: https:\u002F\u002Fwww.wordfence.com\u002Fwordfence-intelligence-terms-and-conditions\u002F\u003Cbr \u002F>\n* Wordfence privacy policy: https:\u002F\u002Fwww.wordfence.com\u002Fprivacy-policy\u002F\u003C\u002Fp>\n\u003Cp>WordPress AI Client \u002F Connectors:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when the administrator clicks Generate Client Report.\u003Cbr \u002F>\n* Data sent: sanitized scan findings, score, counts, and recommendations needed to generate a client-facing report. The plugin is designed not to send passwords, salts, API keys, raw logs, full user lists, or file contents.\u003Cbr \u002F>\n* The configured AI provider is controlled by the site owner’s WordPress Connector settings.\u003Cbr \u002F>\n* Terms and privacy policy: these depend on the AI provider configured by the site owner in WordPress. Site owners should review the selected provider’s terms and privacy policy before enabling AI reports.\u003C\u002Fp>\n","Lockora Security Audit checks WordPress security posture, hardening, core integrity, vulnerabilities, and optional AI reports.",511,3,"2026-07-12T20:50:00.000Z",[111,20,22,112,113],"ai","site-health","vulnerability-scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flockora-security-audit.0.2.0.zip",{"error":116,"url":117,"statusCode":118,"statusMessage":119,"message":119},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fanonindo-security-advisor\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":121,"versions":122},1,[123],{"version":6,"download_url":24,"svn_tag_url":124,"released_at":26,"has_diff":125,"diff_files_changed":126,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":127,"is_current":116},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fanonindo-security-advisor\u002Ftags\u002F1.1.1\u002F",false,[],[]]