[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fP5p_fihETGq8y6qgGnVdyinaEvo6185muUEwQwMvB8U":3,"$fBSazFpCx8cdvrQh4896wbz0o0hpiHMMRJqhOilI-Y0o":143,"$fDmFT8gOS9a95VRrJfZbnGSFG0qMnPYooaZ6fdkBGUsM":148},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":37,"analysis":26,"fingerprints":26},"authdock","AuthDock — Login Security, 2FA, Social Login & Brute Force Protection","1.0.2","RAKIBUZZAMAN","https:\u002F\u002Fprofiles.wordpress.org\u002Frakibantor\u002F","\u003Cp>\u003Cstrong>AuthDock\u003C\u002Fstrong> is a professional-grade WordPress authentication and user access management plugin that replaces 5–7 separate security plugins with a single, unified solution. Built with WordPress-native UI, REST API, and zero bloat.\u003C\u002Fp>\n\u003Cp>Whether you run a membership site, WooCommerce store, multi-author blog, or corporate intranet — AuthDock gives you full control over how users log in, stay safe, and interact with your site.\u003C\u002Fp>\n\u003Ch4>🔑 Social Login\u003C\u002Fh4>\n\u003Cp>Let users sign in with one click using their existing accounts. No more forgotten passwords.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Google OAuth 2.0\u003C\u002Fstrong> — Sign in with Google using OAuth 2.0 authorization\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Facebook Login\u003C\u002Fstrong> — Authenticate via the Facebook Graph API\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GitHub OAuth\u003C\u002Fstrong> — Developer-friendly sign in with GitHub\u003C\u002Fli>\n\u003Cli>\u003Cstrong>X (Twitter) OAuth 2.0\u003C\u002Fstrong> — Uses OAuth 2.0 with PKCE (S256) for maximum security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Button Style\u003C\u002Fstrong> — Choose between icon + text, icon only, or text only button styles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Button Layout\u003C\u002Fstrong> — Display buttons vertically or horizontally\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Button Order\u003C\u002Fstrong> — Drag and drop to reorder provider buttons\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Default Role\u003C\u002Fstrong> — Assign a specific WordPress role to new social registrations (e.g., Subscriber, Customer)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Registration\u003C\u002Fstrong> — Automatically create WordPress accounts from social profiles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Domain Restriction\u003C\u002Fstrong> — Restrict social login to specific email domains (e.g., \u003Ccode>company.com\u003C\u002Fcode>, \u003Ccode>university.edu\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Avatar Integration\u003C\u002Fstrong> — Automatically set user profile pictures from social account avatars\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Account Linking\u003C\u002Fstrong> — Users can link\u002Funlink social accounts from their WordPress profile page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shortcode\u003C\u002Fstrong> — Place social login buttons anywhere using \u003Ccode>[authdock_social_login]\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer Filters\u003C\u002Fstrong> — \u003Ccode>authdock_allow_social_account_linking\u003C\u002Fcode> and \u003Ccode>authdock_allow_social_registration\u003C\u002Fcode> for custom control\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>✉️ Magic Link Login\u003C\u002Fh4>\n\u003Cp>Passwordless authentication — users receive a one-time login link via email. No passwords to remember or leak.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for passwordless login\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Link Expiry\u003C\u002Fstrong> — Set how long each magic link stays valid (default: 10 minutes)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting\u003C\u002Fstrong> — Max magic link requests per email per hour (default: 5\u002Fhour) to prevent abuse\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allowed Roles\u003C\u002Fstrong> — Restrict magic login to specific user roles (e.g., Subscribers, Editors)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Force Magic Login Mode\u003C\u002Fstrong> — Hide the standard WordPress password form and show only the magic link form\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Email Subject\u003C\u002Fstrong> — Personalize the magic link email subject line\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Email Body\u003C\u002Fstrong> — Customize using merge tags: \u003Ccode>{user_name}\u003C\u002Fcode>, \u003Ccode>{magic_link}\u003C\u002Fcode>, \u003Ccode>{expiry_time}\u003C\u002Fcode>, \u003Ccode>{site_name}\u003C\u002Fcode>, \u003Ccode>{ip_address}\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-Time Use\u003C\u002Fstrong> — Each magic link is cryptographically random and single-use\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Token Invalidation\u003C\u002Fstrong> — Magic links are automatically invalidated when a user changes their password\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anti-Enumeration\u003C\u002Fstrong> — Generic success messages prevent attackers from discovering valid email addresses\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shortcode\u003C\u002Fstrong> — Display the form anywhere with \u003Ccode>[authdock_magic_login]\u003C\u002Fcode> and optional \u003Ccode>redirect\u003C\u002Fcode> attribute\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔐 Two-Factor Authentication (2FA)\u003C\u002Fh4>\n\u003Cp>Add a second layer of security to every login. Supports TOTP authenticator apps and email-based verification codes.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for two-factor authentication\u003C\u002Fli>\n\u003Cli>\u003Cstrong>TOTP Method\u003C\u002Fstrong> — Time-based One-Time Passwords (RFC 6238) with QR code provisioning via Google Authenticator, Authy, Microsoft Authenticator, etc.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Method\u003C\u002Fstrong> — Receive a 6-digit numeric verification code via email\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enforced Roles\u003C\u002Fstrong> — Force specific WordPress roles (e.g., Administrator, Editor) to enable 2FA\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Grace Period\u003C\u002Fstrong> — Give users configurable days to set up 2FA before enforcement kicks in (default: 3 days)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trusted Devices\u003C\u002Fstrong> — Allow users to skip 2FA on recognized devices for configurable days (default: 30 days)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backup Recovery Codes\u003C\u002Fstrong> — Generate 10 one-time-use backup codes for account recovery if the authenticator is lost\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-Force Protection\u003C\u002Fstrong> — Rate-limited to 5 verification attempts per session to prevent code guessing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Encrypted Secret Storage\u003C\u002Fstrong> — TOTP secrets encrypted with AES-256-CBC before storing in the database\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Replay Protection\u003C\u002Fstrong> — Each TOTP code can only be used once per time window (RFC 6238 §5.2)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clock Drift Tolerance\u003C\u002Fstrong> — Accepts codes from ±1 time step (30 seconds) to handle minor clock differences\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Interstitial Challenge Screen\u003C\u002Fstrong> — Clean, WordPress-native verification screen after primary authentication\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Management\u003C\u002Fstrong> — Administrators can view and disable 2FA for any user from the profile page\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🛡️ Brute Force Protection (Login Limiter)\u003C\u002Fh4>\n\u003Cp>Stop brute-force attacks with intelligent lockout rules that escalate automatically.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for login attempt limiting\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Max Attempts\u003C\u002Fstrong> — Set the number of failed login attempts before lockout (default: 5)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lockout Duration\u003C\u002Fstrong> — Initial lockout period in minutes (default: 15 minutes)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Progressive Lockout\u003C\u002Fstrong> — Lockouts escalate: 15 min \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> 1 hour \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> 24 hours for repeat offenders\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Blacklist\u003C\u002Fstrong> — Permanently ban an IP after a configurable number of lockouts (e.g., after 5)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Whitelist\u003C\u002Fstrong> — Allow trusted IPs to bypass login limits (supports exact match, CIDR ranges like \u003Ccode>192.168.1.0\u002F24\u003C\u002Fcode>, and wildcards like \u003Ccode>10.0.0.*\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Blacklist\u003C\u002Fstrong> — Permanently block specific IP addresses, CIDR ranges, or wildcard patterns\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notify Admin on Lockout\u003C\u002Fstrong> — Email alerts when an IP gets locked out\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notify Threshold\u003C\u002Fstrong> — Configure after how many lockouts the notification triggers (default: 1)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC Integration\u003C\u002Fstrong> — Automatically block XML-RPC authentication from locked-out IPs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Page Warnings\u003C\u002Fstrong> — Display remaining attempt count and lockout timers on the login page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Log Retention\u003C\u002Fstrong> — Configure how long failed login data is retained (default: 30 days)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trusted Proxies\u003C\u002Fstrong> — Specify trusted reverse proxy IPs for accurate client IP detection behind load balancers\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔄 Dynamic Login & Logout Redirects\u003C\u002Fh4>\n\u003Cp>Send users exactly where they need to go — based on their role, or if it is their first login.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Role-Based Login Redirects\u003C\u002Fstrong> — Set a custom URL per WordPress role after login (e.g., Editors \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Ccode>\u002Feditorial-dashboard\u003C\u002Fcode>, Subscribers \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Ccode>\u002Fmembers-area\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Role-Based Logout Redirects\u003C\u002Fstrong> — Set a custom URL per WordPress role after logout\u003C\u002Fli>\n\u003Cli>\u003Cstrong>First-Login Redirect\u003C\u002Fstrong> — Redirect new users to a welcome page, onboarding wizard, or setup screen on their first login\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Relative & Absolute URLs\u003C\u002Fstrong> — Supports both relative paths (\u003Ccode>\u002Fdashboard\u003C\u002Fcode>) and full URLs (\u003Ccode>https:\u002F\u002Fexample.com\u002Fwelcome\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Open Redirect Prevention\u003C\u002Fstrong> — Redirects validated via \u003Ccode>wp_safe_redirect()\u003C\u002Fcode> and \u003Ccode>wp_validate_redirect()\u003C\u002Fcode> to prevent open redirect attacks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>📋 Audit Logging\u003C\u002Fh4>\n\u003Cp>Keep a complete, searchable record of every authentication event happening on your site.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for audit logging\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tracked Events\u003C\u002Fstrong> — Login success\u002Ffailure, logout, password reset\u002Fchange, user registration, profile updates, social login\u002Flinking, magic link requests\u002Fusage, 2FA changes, session termination, access blocked, lockout events\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Event Details\u003C\u002Fstrong> — Each entry records: user ID, event type, IP, user agent, JSON context, and timestamp\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Retention Period\u003C\u002Fstrong> — Choose how long to keep logs: 30, 60, 90, 180, 365 days, or unlimited\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Cleanup\u003C\u002Fstrong> — Daily WP-Cron job removes expired entries in batches of 1,000 to prevent database locks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Filter by Event Type\u003C\u002Fstrong> — View specific event categories (e.g., only failed logins)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Filter by Date Range\u003C\u002Fstrong> — Narrow results by \u003Ccode>date_from\u003C\u002Fcode> and \u003Ccode>date_to\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Filter by User\u003C\u002Fstrong> — View all events for a specific user ID\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Search by IP\u003C\u002Fstrong> — Find all events from a particular IP address\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full-Text Search\u003C\u002Fstrong> — Search across event types, IPs, and context data\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV Export\u003C\u002Fstrong> — Download audit logs as a CSV file with formula injection protection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>JSON Export\u003C\u002Fstrong> — Export logs in JSON format for integration with external tools\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purge All Logs\u003C\u002Fstrong> — One-click purge to clear all historical log data\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin UI Viewer\u003C\u002Fstrong> — Built-in admin page with paginated table, filters, and export buttons\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Database Table\u003C\u002Fstrong> — Logs stored in a dedicated \u003Ccode>authdock_audit_logs\u003C\u002Fcode> table with proper indexes for fast queries\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🏰 Security Hardening\u003C\u002Fh4>\n\u003Cp>Close common WordPress security holes without installing another plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Custom Login URL\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Custom Slug\u003C\u002Fstrong> — Replace \u003Ccode>wp-login.php\u003C\u002Fcode> with your own secret URL (e.g., \u003Ccode>\u002Fmy-secure-login\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Block Action\u003C\u002Fstrong> — Choose what happens when someone visits \u003Ccode>wp-login.php\u003C\u002Fcode>: return a 404 error or redirect to the homepage\u003Cbr \u002F>\n* \u003Cstrong>Recovery Key\u003C\u002Fstrong> — Access the login page via a secret query parameter even when the custom URL is active\u003C\u002Fp>\n\u003Cp>\u003Cstrong>XML-RPC Control\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Disable XML-RPC\u003C\u002Fstrong> — Completely disable XML-RPC to block remote brute-force attacks\u003Cbr \u002F>\n* \u003Cstrong>Partial Disable\u003C\u002Fstrong> — Remove only authentication methods while keeping pingbacks functional\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API Restriction\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Restrict to Authenticated Users\u003C\u002Fstrong> — Block all REST API access for unauthenticated visitors\u003Cbr \u002F>\n* \u003Cstrong>Namespace Whitelist\u003C\u002Fstrong> — Allow specific third-party REST namespaces (e.g., WooCommerce, Jetpack) to remain public\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Enumeration Prevention\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Block Author Archives\u003C\u002Fstrong> — Redirect \u003Ccode>?author=N\u003C\u002Fcode> enumeration queries to the homepage\u003Cbr \u002F>\n* \u003Cstrong>Restrict User REST Endpoint\u003C\u002Fstrong> — Block \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode> for non-logged-in users\u003Cbr \u002F>\n* \u003Cstrong>Generic Login Errors\u003C\u002Fstrong> — Replace “username not found” or “wrong password” messages with a generic error\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Password Strength Enforcement\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Force Strong Passwords\u003C\u002Fstrong> — Master toggle for password policy enforcement\u003Cbr \u002F>\n* \u003Cstrong>Minimum Length\u003C\u002Fstrong> — Set the minimum password length (default: 8 characters)\u003Cbr \u002F>\n* \u003Cstrong>Require Uppercase\u003C\u002Fstrong> — Mandate at least one uppercase letter\u003Cbr \u002F>\n* \u003Cstrong>Require Lowercase\u003C\u002Fstrong> — Mandate at least one lowercase letter\u003Cbr \u002F>\n* \u003Cstrong>Require Number\u003C\u002Fstrong> — Mandate at least one numeric digit\u003Cbr \u002F>\n* \u003Cstrong>Require Special Character\u003C\u002Fstrong> — Mandate at least one special character (e.g., \u003Ccode>!@#$%\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Enforced Roles\u003C\u002Fstrong> — Apply password rules only to specific roles\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security HTTP Headers\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>X-Content-Type-Options\u003C\u002Fstrong> — Prevents MIME-type sniffing (\u003Ccode>nosniff\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>X-Frame-Options\u003C\u002Fstrong> — Blocks clickjacking by restricting iframe embedding (\u003Ccode>SAMEORIGIN\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>X-XSS-Protection\u003C\u002Fstrong> — Legacy XSS filter for older browsers (\u003Ccode>1; mode=block\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Referrer-Policy\u003C\u002Fstrong> — Controls referrer information sent with requests (\u003Ccode>strict-origin-when-cross-origin\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Strict-Transport-Security (HSTS)\u003C\u002Fstrong> — Enforces HTTPS connections for 1 year (\u003Ccode>max-age=31536000; includeSubDomains\u003C\u002Fcode>)\u003Cbr \u002F>\n* \u003Cstrong>Permissions-Policy\u003C\u002Fstrong> — Restricts access to camera, microphone, and geolocation APIs\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Role-Based Session Duration\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Per-Role Cookie Lifetime\u003C\u002Fstrong> — Set different authentication cookie durations per WordPress role (in hours)\u003C\u002Fp>\n\u003Ch4>📧 Email Notifications\u003C\u002Fh4>\n\u003Cp>Stay informed about critical security events with real-time email alerts — for admins and users.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin Notifications\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Multiple Failed Logins\u003C\u002Fstrong> — Alert every N failed attempts from the same IP (default: every 3)\u003Cbr \u002F>\n* \u003Cstrong>IP Lockout\u003C\u002Fstrong> — Alert when an IP gets locked out\u003Cbr \u002F>\n* \u003Cstrong>Admin Login Alert\u003C\u002Fstrong> — Notify when an administrator account logs in\u003Cbr \u002F>\n* \u003Cstrong>New User Registration\u003C\u002Fstrong> — Alert on every new user registration\u003Cbr \u002F>\n* \u003Cstrong>User Promoted to Admin\u003C\u002Fstrong> — Alert when any user is promoted to the Administrator role\u003Cbr \u002F>\n* \u003Cstrong>Admin Password Changed\u003C\u002Fstrong> — Alert when an administrator’s password is changed or reset\u003Cbr \u002F>\n* \u003Cstrong>2FA Disabled\u003C\u002Fstrong> — Alert when any user disables two-factor authentication\u003Cbr \u002F>\n* \u003Cstrong>Login from New IP\u003C\u002Fstrong> — Alert when a user logs in from a previously unseen IP address\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Self-Notifications\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Password Changed\u003C\u002Fstrong> — Notify the user when their password is changed\u003Cbr \u002F>\n* \u003Cstrong>Email Changed\u003C\u002Fstrong> — Notify at the OLD email address when a user’s email is updated (security measure)\u003Cbr \u002F>\n* \u003Cstrong>2FA Status Changed\u003C\u002Fstrong> — Notify the user when 2FA is enabled or disabled on their account\u003Cbr \u002F>\n* \u003Cstrong>Social Account Linked\u003C\u002Fstrong> — Notify when a social provider is connected to their account\u003Cbr \u002F>\n* \u003Cstrong>New Device Login\u003C\u002Fstrong> — Notify the user when a login is detected from a new IP address\u003Cbr \u002F>\n* \u003Cstrong>Account Locked\u003C\u002Fstrong> — Notify the user when their account is locked due to failed attempts\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification Settings\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Custom Recipients\u003C\u002Fstrong> — Set custom email addresses for admin notifications (defaults to site admin email)\u003Cbr \u002F>\n* \u003Cstrong>Throttle Period\u003C\u002Fstrong> — Configurable cooldown in minutes to prevent notification flooding (default: 60 minutes)\u003Cbr \u002F>\n* \u003Cstrong>Digest Mode\u003C\u002Fstrong> — Option to batch notifications instead of sending them individually\u003Cbr \u002F>\n* \u003Cstrong>Test Email\u003C\u002Fstrong> — Send a test notification to verify email configuration is working\u003C\u002Fp>\n\u003Ch4>🚪 wp-admin Access Control\u003C\u002Fh4>\n\u003Cp>Restrict who can access the WordPress dashboard — by role, by IP, or both.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for access control\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocked Roles\u003C\u002Fstrong> — Select which roles are blocked from accessing \u003Ccode>\u002Fwp-admin\u003C\u002Fcode> (e.g., Subscriber, Customer)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Restriction Mode\u003C\u002Fstrong> — Enable IP-based restrictions so only whitelisted IPs can access wp-admin\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Whitelist\u003C\u002Fstrong> — Specify allowed IP addresses and CIDR ranges (e.g., \u003Ccode>203.0.113.5\u003C\u002Fcode>, \u003Ccode>192.168.1.0\u002F24\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Admin Bar\u003C\u002Fstrong> — Remove the WordPress admin bar from the frontend for blocked roles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Redirect Action\u003C\u002Fstrong> — Choose what happens when access is denied: redirect to homepage, custom URL, or show a 403 Forbidden page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Redirect URL\u003C\u002Fstrong> — Set a specific URL for the access-denied redirect\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Emergency Bypass Key\u003C\u002Fstrong> — Secret query parameter (\u003Ccode>?authdock_bypass=YOUR_KEY\u003C\u002Fcode>) to regain access if locked out\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Exceptions\u003C\u002Fstrong> — AJAX requests, WP-Cron, and \u003Ccode>admin-post.php\u003C\u002Fcode> always allowed through\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Administrator Immunity\u003C\u002Fstrong> — Administrators are never blocked, regardless of settings\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>⏱️ Session Management\u003C\u002Fh4>\n\u003Cp>Take control of user sessions — limit concurrent logins, enforce idle timeouts, and terminate sessions remotely.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Enable\u002FDisable\u003C\u002Fstrong> — Master toggle for session management\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Concurrent Session Limit\u003C\u002Fstrong> — Maximum simultaneous sessions per user (0 = unlimited). Oldest sessions are destroyed when the limit is exceeded\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Idle Session Timeout\u003C\u002Fstrong> — Auto-logout after configurable inactivity period (in minutes, 0 = disabled)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-Role Session Duration\u003C\u002Fstrong> — Different session lifetimes for each WordPress role (in hours)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Session Viewer\u003C\u002Fstrong> — View all active sessions via the REST API, including user details and last activity timestamps\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remote Session Termination\u003C\u002Fstrong> — Administrators can terminate all sessions for any user via a single API call\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Throttled Activity Tracking\u003C\u002Fstrong> — Last-activity timestamps updated at most once per 5 minutes to minimize database writes\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>⚡ Performance & Infrastructure\u003C\u002Fh4>\n\u003Cp>AuthDock is built for speed and follows WordPress best practices from top to bottom.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Conditional Asset Loading\u003C\u002Fstrong> — CSS and JavaScript files load only on pages where they are needed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Indexed Database Tables\u003C\u002Fstrong> — Custom tables use proper indexes for fast lookups\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-Cron Maintenance\u003C\u002Fstrong> — Audit log cleanup runs via non-blocking WP-Cron\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Transient-Based Tracking\u003C\u002Fstrong> — Brute force tracking uses transients (no additional DB queries per login attempt)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Powered\u003C\u002Fstrong> — All admin data operations go through the \u003Ccode>authdock\u002Fv1\u003C\u002Fcode> namespace with 15+ endpoints\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hook-Based Architecture\u003C\u002Fstrong> — Centralized Loader class registers all hooks for clean dependency management\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Capabilities\u003C\u002Fstrong> — \u003Ccode>authdock_manage_settings\u003C\u002Fcode>, \u003Ccode>authdock_view_audit_logs\u003C\u002Fcode>, \u003Ccode>authdock_export_audit_logs\u003C\u002Fcode>, \u003Ccode>authdock_manage_sessions\u003C\u002Fcode>, \u003Ccode>authdock_manage_lockouts\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean Activation\u003C\u002Fstrong> — Creates database tables, sets defaults, registers capabilities, and schedules cron\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean Deactivation\u003C\u002Fstrong> — Clears cron events but preserves all settings for reactivation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full Uninstall\u003C\u002Fstrong> — Removes everything: options, user meta, database tables, capabilities, and transients\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full i18n\u003C\u002Fstrong> — All user-facing strings use WordPress internationalization functions with the \u003Ccode>authdock\u003C\u002Fcode> text domain\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🤔 Why Choose AuthDock?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Replace 5–7 plugins\u003C\u002Fstrong> — Social login + magic links + 2FA + brute force + audit logs + session management + access control — all in one\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress-native UI\u003C\u002Fstrong> — Looks and feels like core WordPress, not a foreign dashboard\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API powered\u003C\u002Fstrong> — Modern, secure data handling for all admin operations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight & fast\u003C\u002Fstrong> — Conditional loading, object caching, zero external frameworks in admin\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer-friendly\u003C\u002Fstrong> — Extensive hooks, filters, and custom capabilities for extensibility\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress.org compliant\u003C\u002Fstrong> — No tracking, no encoded code, no forced upsells, full GPL-2.0+\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔗 Shortcodes\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>[authdock_social_login]\u003C\u002Fcode> — Display social login buttons (attributes: \u003Ccode>layout\u003C\u002Fcode>, \u003Ccode>style\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Ccode>[authdock_magic_login]\u003C\u002Fcode> — Display magic link login form (attributes: \u003Ccode>redirect\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>\u003Ccode>[authdock_login_form]\u003C\u002Fcode> — Display login form with 2FA support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Google OAuth\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Facebook Login\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Flegal\u002Fterms\" rel=\"nofollow ugc\">Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fprivacy\u002Fpolicy\u002F\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GitHub OAuth\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fgithub-terms\u002Fgithub-terms-of-service\" rel=\"nofollow ugc\">Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fsite-policy\u002Fprivacy-policies\u002Fgithub-general-privacy-statement\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>X (Twitter) OAuth\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fx.com\u002Fen\u002Ftos\" rel=\"nofollow ugc\">Terms\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fx.com\u002Fen\u002Fprivacy\" rel=\"nofollow ugc\">Privacy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","All-in-one WordPress authentication: social login, magic links, 2FA, brute force protection, session management & security hardening.",0,173,"2026-06-10T09:19:00.000Z","7.0.2","6.0","7.4",[18,19,20,21,22],"access-control","brute-force-protection","login-security","social-login","two-factor-authentication","https:\u002F\u002Fdegird.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fauthdock.1.0.2.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":25,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"rakibantor",3,80,30,94,"2026-08-24T01:47:23.511Z",[38,60,83,105,124],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":34,"downloaded":46,"rating":25,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":55,"download_link":56,"security_score":57,"vuln_count":58,"unpatched_count":11,"last_vuln_date":59,"fetched_at":27},"admin-safety-guard","Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection","1.3.0","Themepaste","https:\u002F\u002Fprofiles.wordpress.org\u002Fthemepaste\u002F","\u003Cp>\u003Cstrong>Admin Safety Guard\u003C\u002Fstrong> is a powerful yet lightweight WordPress security plugin that protects your login page and admin dashboard from hackers, bots, and brute-force attacks. It is built for anyone — from first-time bloggers to experienced developers — with a clean interface, clear settings, and features that work from the moment you activate it.\u003C\u002Fp>\n\u003Cp>WordPress is the most popular website platform in the world, which also makes it the most targeted. Every day, thousands of automated bots scan WordPress sites looking for weak passwords, exposed login pages, and unpatched vulnerabilities. Admin Safety Guard closes those doors quickly and reliably, without slowing down your site or requiring any technical expertise.\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FKFNUmTHtODE?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch3>Why WordPress Sites Get Hacked — And How Admin Safety Guard Stops It\u003C\u002Fh3>\n\u003Cp>Most successful WordPress attacks follow the same pattern:\u003C\u002Fp>\n\u003Col>\n\u003Cli>A bot finds your login page at the default \u003Ccode>wp-login.php\u003C\u002Fcode> address.\u003C\u002Fli>\n\u003Cli>It tries thousands of username and password combinations (brute-force attack).\u003C\u002Fli>\n\u003Cli>Once inside, it installs malware, steals data, or takes over your site.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Admin Safety Guard blocks every step of this attack chain — for free.\u003C\u002Fp>\n\u003Ch3>Free Features\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Limit Login Attempts (Active by Default)\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically block any IP address that fails too many login attempts. You control the number of allowed attempts, the lockout duration, and the message shown to blocked users. Brute-force attacks become impossible when attackers are locked out after 3 failed tries. Login Limit Attempts is the only feature enabled by default on fresh install, so your site is protected the moment you activate the plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Custom Login URL\u003C\u002Fstrong>\u003Cbr \u002F>\nMove your login page away from the default \u003Ccode>wp-login.php\u003C\u002Fcode> address. Bots and automated scanners will never find your login page because it simply does not exist at the expected location. You can set any slug you like, and the plugin handles redirect rules automatically. You can also set a custom redirect URL for after login and after logout.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Two-Factor Authentication (2FA) via Email OTP\u003C\u002Fstrong>\u003Cbr \u002F>\nAfter a user enters their correct password, a one-time passcode (OTP) is sent to their email address. They must enter that code to complete the login. Even if a hacker steals a password, they cannot get in without also accessing the user’s email inbox. You can customise the OTP email subject and body to match your brand.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Google reCAPTCHA (v2 & v3)\u003C\u002Fstrong>\u003Cbr \u002F>\nAdd Google reCAPTCHA to your login form to block automated bots in real time. Both reCAPTCHA v2 (the familiar checkbox) and v3 (invisible, score-based) are supported. Simply enter your site key and secret key from Google, choose your version, and reCAPTCHA will handle the rest silently in the background.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP Blocking\u003C\u002Fstrong>\u003Cbr \u002F>\nManually block specific IP addresses from accessing your login page entirely. If you notice a suspicious IP in your activity log or receive repeated failed login alerts, add that IP to the block list and it will be turned away immediately. Perfect for stopping known bad actors before they become a problem.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Logs & Activity Tracking\u003C\u002Fstrong>\u003Cbr \u002F>\nSee exactly who is logging in to your site and when. The activity dashboard shows successful logins, failed login attempts, IP addresses, user agents, and timestamps in a clear, searchable table. You will always know if something unusual is happening on your site, and you have the evidence to act on it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Analytics Dashboard\u003C\u002Fstrong>\u003Cbr \u002F>\nThe built-in analytics dashboard gives you a real-time overview of your site’s security health. It shows your overall Security Score (based on how many features you have enabled), recent login activity, failed login trends, and a breakdown of which security features are active versus inactive. It is the first page you see when you open the plugin, giving you immediate situational awareness.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hide Admin Bar (by Role)\u003C\u002Fstrong>\u003Cbr \u002F>\nChoose which user roles see the WordPress admin bar on the front end of your site. For example, you can hide the admin bar from subscribers and customers while keeping it visible for editors and administrators. This reduces information leakage and gives non-admin users a cleaner experience.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Password Protection (Site-Wide)\u003C\u002Fstrong>\u003Cbr \u002F>\nLock your entire website behind a password. Visitors must enter the correct password before they can view any content. This is ideal for staging sites, coming-soon pages, client previews, or any situation where you want to restrict public access temporarily. You can set the access duration and exclude specific user roles from the password requirement.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy Hardening — Disable XML-RPC\u003C\u002Fstrong>\u003Cbr \u002F>\nThe WordPress XML-RPC interface is a common target for brute-force and DDoS amplification attacks. With one toggle, you can disable it completely. Unless you rely on XML-RPC for mobile app publishing or specific third-party integrations, disabling it is a safe and recommended step for almost every WordPress site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Page Customisation & Branding\u003C\u002Fstrong>\u003Cbr \u002F>\nReplace the default WordPress logo on the login page with your own logo. Set the logo width, height, and URL. Choose from pre-built login page templates to give your login form a professional, branded appearance. This is especially useful for agencies delivering client sites and for anyone who wants a polished, consistent look.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall & Malware Overview\u003C\u002Fstrong>\u003Cbr \u002F>\nThe Firewall & Malware section gives you a central view of your site’s firewall and malware protection status. It shows all related features in one place so you can see what is active and what still needs attention, making it easy to build up your security layer by layer.\u003C\u002Fp>\n\u003Ch3>Pro Features\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Admin Safety Guard Pro\u003C\u002Fa> extends the plugin with advanced security tools designed for agencies, developers, and high-traffic sites.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Passwordless Login (Magic Links)\u003C\u002Fstrong>\u003Cbr \u002F>\nLet users log in with a secure, one-time link sent to their email — no password needed. Magic links expire after a single use, making them more secure than passwords for many workflows.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2FA via Mobile Authenticator App\u003C\u002Fstrong>\u003Cbr \u002F>\nAdd Google Authenticator or Authy-compatible two-factor authentication to your login flow. Users scan a QR code once, then generate time-based OTP codes from their phone app. This is the same method used by banks and enterprise software.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Social Login\u003C\u002Fstrong>\u003Cbr \u002F>\nAllow users to log in with their existing Google, Facebook, or other social media accounts. Reduce friction at sign-up and login, while keeping full control over which providers are allowed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Database Table Prefix Check\u003C\u002Fstrong>\u003Cbr \u002F>\nThe default WordPress database prefix \u003Ccode>wp_\u003C\u002Fcode> is well-known to attackers and makes SQL injection easier. This Pro tool detects your current prefix and guides you through changing it to a unique, random value to close that vulnerability.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Strong Password Enforcement\u003C\u002Fstrong>\u003Cbr \u002F>\nSet a minimum password strength policy for your users. When they update their password, it must meet your requirements — rejecting weak, guessable passwords before they become a security risk.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Firewall & Malware Scanner\u003C\u002Fstrong>\u003Cbr \u002F>\nScan your WordPress files and database for known malware signatures, suspicious code injections, and modified core files. Get alerts when threats are detected and take action directly from the plugin dashboard.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Upgrade to Pro\u003C\u002Fa>\u003C\u002Fstrong> to unlock all Pro features.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Who Is Admin Safety Guard For?\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Bloggers & Content Creators\u003C\u002Fstrong>\u003Cbr \u002F>\nYou focus on writing — not on managing server security. Admin Safety Guard protects your login page and admin area quietly in the background with zero ongoing maintenance required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Small Business Owners\u003C\u002Fstrong>\u003Cbr \u002F>\nYour website is your business. A hack can bring it down, damage your reputation, and cost you money. Admin Safety Guard gives you enterprise-level login protection without the enterprise price tag.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WooCommerce Store Owners\u003C\u002Fstrong>\u003Cbr \u002F>\nAn online store holds customer data, payment details, and order history. Limit login attempts, add 2FA, and lock down your admin area so only you and your trusted team can get in.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Freelancers & Web Designers\u003C\u002Fstrong>\u003Cbr \u002F>\nDeliver more secure sites to clients out of the box. Customise the login page with the client’s branding, lock down the admin bar by role, and hand over a professional, secure WordPress installation every time.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Agencies & Development Teams\u003C\u002Fstrong>\u003Cbr \u002F>\nManage security across multiple client sites with a consistent, repeatable setup. All features are toggle-based and clearly documented, making it easy to onboard new team members and maintain a security standard across your portfolio.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Developers & Site Administrators\u003C\u002Fstrong>\u003Cbr \u002F>\nFine-tune every setting — login attempt limits, lockout durations, OTP email templates, reCAPTCHA version, redirect URLs, IP block lists, and more. Admin Safety Guard is built on WordPress hooks and filters, so it plays well with the rest of your stack.\u003C\u002Fp>\n\u003Ch3>What Makes Admin Safety Guard Different?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Lightweight by design.\u003C\u002Fstrong> Assets are loaded only on the pages that need them. The plugin has no impact on your site’s front-end load time.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No configuration required to get started.\u003C\u002Fstrong> Limit Login Attempts is enabled automatically on install. Your site is more secure the moment you activate the plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>All features are clearly labelled Free or Pro.\u003C\u002Fstrong> You can see exactly what is available and what requires the Pro version before making any decisions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean, modern dashboard.\u003C\u002Fstrong> The settings UI is built with React for a fast, app-like experience. Finding and configuring features takes seconds, not minutes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built to WordPress standards.\u003C\u002Fstrong> Every input is sanitised, every output is escaped, all AJAX requests use nonce verification, and every database query uses prepared statements.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For any issues, questions, or feature requests, please reach out via \u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fcontact\" rel=\"nofollow ugc\">Support\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin uses the following third-party and external services:\u003C\u002Fp>\n\u003Cp>1) Google reCAPTCHA (Google LLC)\u003C\u002Fp>\n\u003Cp>Purpose:\u003Cbr \u002F>\nUsed to protect forms from spam and automated abuse.\u003C\u002Fp>\n\u003Cp>When it is used:\u003Cbr \u002F>\n– When reCAPTCHA is enabled in plugin settings\u003Cbr \u002F>\n– On login forms and support forms protected by reCAPTCHA\u003C\u002Fp>\n\u003Cp>What data is sent:\u003Cbr \u002F>\n– User IP address\u003Cbr \u002F>\n– reCAPTCHA response token generated by Google\u003Cbr \u002F>\n– Browser information as required by Google reCAPTCHA\u003C\u002Fp>\n\u003Cp>Service provider:\u003Cbr \u002F>\nGoogle LLC\u003C\u002Fp>\n\u003Cp>Terms of Service:\u003Cbr \u002F>\nhttps:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fp>\n\u003Cp>Privacy Policy:\u003Cbr \u002F>\nhttps:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n\u003Cp>2) ThemePaste API (Plugin Author Service)\u003C\u002Fp>\n\u003Cp>Purpose:\u003Cbr \u002F>\nUsed for:\u003Cbr \u002F>\n– Collecting optional admin email addresses for plugin updates and notifications\u003Cbr \u002F>\n– Sending support requests from the plugin support form\u003Cbr \u002F>\n– Collecting optional feedback when a user attempts to deactivate the plugin\u003Cbr \u002F>\n– Managing plugin-related notifications (only if the user provides contact details)\u003C\u002Fp>\n\u003Cp>When it is used:\u003Cbr \u002F>\n– When a user submits the built-in support form\u003Cbr \u002F>\n– When a user opts to send diagnostic information\u003Cbr \u002F>\n– Submitting the optional deactivation feedback form\u003C\u002Fp>\n\u003Cp>What data is sent:\u003Cbr \u002F>\n– Name\u003Cbr \u002F>\n– Email address\u003Cbr \u002F>\n– Phone number (if provided)\u003Cbr \u002F>\n– Message content\u003Cbr \u002F>\n– Site URL\u003Cbr \u002F>\n– Plugin name\u003Cbr \u002F>\n– Feedback text (if provided)\u003Cbr \u002F>\n– Support message content\u003Cbr \u002F>\n– Deactivation reason (if provided)\u003C\u002Fp>\n\u003Cp>No data is sent without user action.\u003C\u002Fp>\n\u003Cp>Service provider:\u003Cbr \u002F>\nThemePaste.com\u003C\u002Fp>\n\u003Cp>Terms of Service:\u003Cbr \u002F>\nhttps:\u002F\u002Fthemepaste.com\u002Fterms-condition\u003C\u002Fp>\n\u003Cp>Privacy Policy:\u003Cbr \u002F>\nhttps:\u002F\u002Fthemepaste.com\u002Fprivacy-policy\u003C\u002Fp>\n\u003Ch3>Development \u002F Source Code\u003C\u002Fh3>\n\u003Cp>This plugin includes compiled JavaScript bundles in:\u003Cbr \u002F>\n– assets\u002Fadmin\u002Fbuild\u002F*.bundle.js\u003C\u002Fp>\n\u003Cp>The original (human-readable) source files are included in this plugin under:\u003Cbr \u002F>\n– spa\u002Fadmin\u002F\u003C\u002Fp>\n\u003Cp>Build Tools\u003Cbr \u002F>\n– Node.js (LTS recommended)\u003Cbr \u002F>\n– npm\u003Cbr \u002F>\n– Webpack + Babel\u003C\u002Fp>\n\u003Cp>Source Entry Points\u003Cbr \u002F>\nThe admin SPA bundles are built from the following entry points:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>spa\u002Fadmin\u002Flogin-template\u002FMain.jsx            -> assets\u002Fadmin\u002Fbuild\u002FloginTemplate.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Flogin-logs-activity\u002FMain.jsx       -> assets\u002Fadmin\u002Fbuild\u002FloginLogActivity.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fanalytics\u002FMain.jsx                 -> assets\u002Fadmin\u002Fbuild\u002Fanalytics.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fsecurity-core\u002FMain.jsx             -> assets\u002Fadmin\u002Fbuild\u002FsecurityCore.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Ffirewall-malware\u002FMain.jsx          -> assets\u002Fadmin\u002Fbuild\u002FfirewallMalware.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fprivacy-hardening\u002FMain.jsx         -> assets\u002Fadmin\u002Fbuild\u002FprivacyHardening.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fmonitoring-analytics\u002FMain.jsx      -> assets\u002Fadmin\u002Fbuild\u002FmonitoringAnalytics.bundle.js\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Install Dependencies\u003Cbr \u002F>\nFrom the plugin root directory (or the directory where package.json exists):\u003C\u002Fp>\n\u003Cp>1) Install dependencies:\u003Cbr \u002F>\n   npm install\u003C\u002Fp>\n\u003Cp>Build (Production)\u003Cbr \u002F>\nTo generate the production bundles:\u003C\u002Fp>\n\u003Cp>npm run build\u003C\u002Fp>\n\u003Cp>Output Location\u003Cbr \u002F>\nWebpack outputs the compiled bundles to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>assets\u002Fadmin\u002Fbuild\u002F[name].bundle.js\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Important Notes\u003Cbr \u002F>\n– Do not edit files in assets\u002Fadmin\u002Fbuild\u002F directly. They are generated files.\u003Cbr \u002F>\n– Edit the source files under spa\u002Fadmin\u002F and re-run the build command.\u003Cbr \u002F>\n– For WordPress.org distribution, production builds should be used (mode=production).\u003C\u002Fp>\n\u003Ch3>Links\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fthemepaste.com\" rel=\"nofollow ugc\">Website\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct-doc\u002Fhide-admin-bar-pro\u002F?doc_id=389\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Pro Version\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fthemepaste\" rel=\"nofollow ugc\">Facebook\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fuk.pinterest.com\u002Fthemepaste\u002F\" rel=\"nofollow ugc\">Pinterest\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fthemepaste\" rel=\"nofollow ugc\">LinkedIn\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.instagram.com\u002Fthemepasteuk\" rel=\"nofollow ugc\">Instagram\u003C\u002Fa>\u003C\u002Fp>\n","Protect your WP site from hackers for free. Limit logins, add 2FA, reCAPTCHA, block IPs, hide wp-login.php & track activity logs.",2435,4,"2026-06-17T08:54:00.000Z","6.9.5","5.8","7.0",[19,53,54,20,22],"custom-login-url","limit-login-attempts","http:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fthemepaste-secure-admin-pro\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-safety-guard.1.3.0.zip",99,1,"2026-03-16 00:00:00",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":68,"downloaded":69,"rating":35,"num_ratings":70,"last_updated":71,"tested_up_to":14,"requires_at_least":72,"requires_php":73,"tags":74,"homepage":78,"download_link":79,"security_score":80,"vuln_count":81,"unpatched_count":11,"last_vuln_date":82,"fetched_at":27},"all-in-one-wp-security-and-firewall","All-In-One Security (AIOS) – Security and Firewall","5.4.9","David Anderson \u002F Team Updraft","https:\u002F\u002Fprofiles.wordpress.org\u002Fdavidanderson\u002F","\u003Ch3>THE TOP RATED WORDPRESS SECURITY AND FIREWALL PLUGIN\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios&utm_creative_format=description\" rel=\"nofollow ugc\">All-in-One Security (AIOS)\u003C\u002Fa> is a WordPress security plugin from the same, trusted team that brought you UpdraftPlus.\u003C\u002Fp>\n\u003Cp>It’s called ‘All-In-One’ because it’s packed full of ways to keep your WordPress website(s) safe and secure.\u003C\u002Fp>\n\u003Cp>It includes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login security features\u003C\u002Fstrong> keep bots at bay. Lock out users based on a configurable number of login attempts, get two-factor authentication and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File and database security.\u003C\u002Fstrong> Get notified of file changes that occur outside of normal operations. Block access to key files and scan files and folders to spot insecure permissions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall.\u003C\u002Fstrong> Get PHP, .htaccess and 6G firewall rules courtesy of Perishable Press. Spot and block fake Google Bots and more!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Spam prevention.\u003C\u002Fstrong> Prevent annoying spam comments and reduce unnecessary load on the server. Automatically and permanently block IP addresses that exceed a set number of spam comments.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit log.\u003C\u002Fstrong> View events happening on your WordPress website. Find out if a plugin or theme has been added, removed, updated and more.\u003C\u002Fp>\n\u003Ch4>WHY ALL-IN-ONE SECURITY?\u003C\u002Fh4>\n\u003Cp>AIOS has a near-perfect \u003Cstrong>4.7 \u002F 5-star user rating\u003C\u002Fstrong> across more than 1 million installs.\u003C\u002Fp>\n\u003Cp>Great for beginners and experts alike. AIOS guides you logically and clearly through each of its features which are all clearly explained. Security features are marked as basic, intermediate and advanced. Each step increases your security score. Turn them on and watch your protection grow!\u003C\u002Fp>\n\u003Cp>We have a large support team of software developers. That means we have the availability and the skillset to help you with the trickiest of queries.\u003C\u002Fp>\n\u003Cp>We comb the WordPress plugin directory for support tickets daily – most queries are responded to within 24 hours.\u003C\u002Fp>\n\u003Cp>\u003Cem>Excellent plugin with numerous well-thought-out options for making a website more secure. I have been using it for years and am very happy with it. I recently had a small problem setting up a website and – even as a non-premium user – I received support very quickly. Highly recommended!\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>For even more ways to stay safe and secure, upgrade to \u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002Fpricing?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios_premium&utm_creative_format=description\" rel=\"nofollow ugc\">AIOS Premium\u003C\u002Fa> – it packs a punch security-wise, whilst being \u003Cstrong>extremely cost-competitive\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>LOGIN SECURITY\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication (TFA)\u003C\u002Fstrong> – Require TFA for specific user roles. Supports Google Authenticator, Microsoft Authenticator, Authy, and many more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detect and manage ‘admin’ usernames\u003C\u002Fstrong> – Identify default ‘admin’ usernames and guide users to change them to protect against brute force attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identify and correct identical login and display names\u003C\u002Fstrong> – Detect cases where the display name matches the username and provide guidance to improve login security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent user enumeration\u003C\u002Fstrong> – Block unauthorised access to URLs that can reveal sensitive information such as usernames or other details.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control login attempts\u003C\u002Fstrong> – Prevent brute force attacks by limiting the number of failed login attempts. Choose how many login attempts are allowed, set lockout durations, and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Force user logout\u003C\u002Fstrong> – Automatically log out users after a specified period of time. Unattended sessions are closed, reducing the risk of unauthorised access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manually approve new registrations\u003C\u002Fstrong> – Review and approve new user registrations to prevent spam and fake sign-ups.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhance WordPress salt security\u003C\u002Fstrong> – Adds 64 extra characters to WordPress salts, rotating them weekly. Makes cracking passwords virtually impossible, even if your database is stolen.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002F\u003Cbr \u002F>\n\u003Cstrong>Monitor and manage active sessions\u003C\u002Fstrong> – If a user is logged in who shouldn’t be, log them out or add them to a blacklist.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SPAM PREVENTION\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block spam coming from bots\u003C\u002Fstrong> – Reduce the load on your server and improve the user experience by automatically blocking spam comments from bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitor spam IP addresses\u003C\u002Fstrong> – Monitor the IP addresses of people or bots leaving spam comments. Choose which ones to block based on a configurable number of comments left.\u003C\u002Fp>\n\u003Ch4>FILE \u002F DATABASE Security\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Scan and fix file permissions\u003C\u002Fstrong> – Scan for insecure file permissions. Click once to fix issues and safeguard critical files and folders.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable PHP file editing\u003C\u002Fstrong> – Disable editing of PHP files (such as plugins and themes) via the dashboard. It’s often the first tool that attackers use as it allows for code execution.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protect sensitive files\u003C\u002Fstrong> – Prevent access to files like readme.html that might reveal information about your WordPress installation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File change scanner\u003C\u002Fstrong> – Get notified of any file changes which occur on your system. Exclude files and folders which change as part of normal operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent image hotlinking\u003C\u002Fstrong> – Prevent other websites from displaying your images via hotlinking and protect server bandwidth.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure database backups\u003C\u002Fstrong> – Perform a database backup via UpdraftPlus from AIOS. Change the default ‘wp_’ prefix to hide your WordPress database from hackers.\u003C\u002Fp>\n\u003Ch4>FIREWALL\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Get .htaccess firewall rules\u003C\u002Fstrong> – Deny access to the .htaccess and wp-config.php files. Disable the server signature and limit file uploads to a configurable size.**\u003C\u002Fp>\n\u003Cp>Block access to the debug.log file and prevent Apache servers from listing the contents of a directory when an index.php file is not present\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Get PHP firewall rules\u003C\u002Fstrong> – PHP firewall rules prevent malicious users from exploiting well-known vulnerabilities in XML-RPC. Safeguard your content by disabling RSS and Atom feeds and avoid cross-site scripting (XSS) attacks.\u003Cbr \u002F>\nBlock fake Google bots and POST requests made by bots – Block fake Google bots and stop bots from making POST requests by blocking IP addresses where the user-agent and referrer fields are blank.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Utilise 6G firewall rules\u003C\u002Fstrong> – Employ flexible blacklist rules to reduce the number of malicious URL requests that hit your website (courtesy of Perishable Press).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>And more\u003C\u002Fstrong> – Blacklist (and whitelist) IP ranges and user agents and block unauthorized access to data by disabling REST API access for non-logged-in requests.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION ENHANCED [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication\u003C\u002Fstrong> is included in the free plugin. Upgrade to Premium if you’d like to:\u003Cbr \u002F>\nRequire TFA after a set time period – Mandate TFA for all admins or other roles after their accounts reach a specified age.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control how often TFA is required\u003C\u002Fstrong> – Set TFA to be required after a certain number of days on trusted devices instead of every login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customise design layout\u003C\u002Fstrong> – Adjust the TFA design to match your website’s existing layout and branding.\u003Cbr \u002F>\nEmergency codes – Generate one-time use emergency codes to regain access if you lose your TFA device.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Multisite Compatible\u003C\u002Fstrong> – Ensure compatibility with WordPress multisite networks and their sub-sites for consistent TFA application.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Integration with login forms\u003C\u002Fstrong> – Integrate TFA with various login forms, including WooCommerce, Affiliates-WP, Elementor Pro, bbPress, and ‘Theme My Login’ without additional coding.\u003C\u002Fp>\n\u003Ch4>SMART 404 BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block IPs based on 404 errors\u003C\u002Fstrong> – Detect hackers probing your URLs via script and bots by the 404 errors they leave behind.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 Configuration\u003C\u002Fstrong> – Set a figure for the maximum number of 404 events allowed before an IP address is blocked. Choose a time period within which the 404 events must occur (e.g., 10 errors within 10 minutes).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 block by URL string\u003C\u002Fstrong> – Instantly block an IP address if a 404 event includes a specific URL string.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 whitelisting\u003C\u002Fstrong> – Prevent particular IP addresses from being permanently blocked due to 404 events.\u003C\u002Fp>\n\u003Ch4>COUNTRY BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block traffic to the entire site or to specific pages or posts\u003C\u002Fstrong> – Useful if you’re an e-commerce site and you want to block sales to some countries for shipping or tax reasons.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Whitelist some users from blocked countries\u003C\u002Fstrong> – Whitelist IP addresses or IP ranges even if they are part of a blocked country.\u003C\u002Fp>\n\u003Ch4>MALWARE SCANNING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Automatic malware scanning\u003C\u002Fstrong> – Detect and protect against the latest malware, trojans, and spyware.\u003Cbr \u002F>\nAlerts you to blacklisting by search engines – Monitor your site for blacklisting by search engines due to malicious code.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Response time monitoring\u003C\u002Fstrong> – Keep track of your website’s response time to identify and address any performance issues.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Uptime monitoring\u003C\u002Fstrong> – Checks your website’s uptime every 5 minutes and alerts you immediately if your site or server goes down.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advice and malware removal\u003C\u002Fstrong> – Need hands-on advice and support for malware removal? Our team of genuine cybersecurity experts is here to help.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification if something’s amiss\u003C\u002Fstrong> – Receive notifications about any issues with your site so you can address problems before they escalate.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cp>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u003C\u002Fp>\n\u003Ch4>Developers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you are a developer and you need some extra hooks or filters for this plugin then let us know.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All-In-One Security plugin can be translated to any language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Currently available translations:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>Hungarian\u003C\u002Fli>\n\u003Cli>Italian\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Chinese\u003C\u002Fli>\n\u003Cli>Portuguese (Brazil)\u003C\u002Fli>\n\u003Cli>Persian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy Policy\u003C\u002Fh4>\n\u003Cp>This plugin may collect IP addresses for security reasons such as mitigating brute force login threats and malicious activity.\u003C\u002Fp>\n\u003Cp>The collected information is stored on your server. No information is transmitted to third parties or remote server locations.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n","Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.",1000000,37886136,1710,"2026-06-05T06:33:00.000Z","5.0","5.6",[75,20,76,77,22],"firewall","malware-scanning","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fall-in-one-wp-security-and-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fall-in-one-wp-security-and-firewall.5.4.9.zip",75,27,"2026-06-05 11:51:22",{"slug":84,"name":85,"version":86,"author":87,"author_profile":88,"description":89,"short_description":90,"active_installs":91,"downloaded":92,"rating":93,"num_ratings":94,"last_updated":95,"tested_up_to":14,"requires_at_least":96,"requires_php":16,"tags":97,"homepage":100,"download_link":101,"security_score":102,"vuln_count":103,"unpatched_count":11,"last_vuln_date":104,"fetched_at":27},"better-wp-security","Kadence Security – Password, Two Factor Authentication, and Brute Force Protection","10.0.2","Nexcess","https:\u002F\u002Fprofiles.wordpress.org\u002Fstellarwp\u002F","\u003Ch4>Reduce your WordPress website’s risk to nearly zero with Kadence Security\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgo.solidwp.com\u002Fwporg-security-ithemes\" rel=\"nofollow ugc\">Formerly iThemes Security. Looking for iThemes? Learn more here.\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>On average, 30,000 websites are hacked every day.* Cyberattacks in the US increased by 57% in 2022.** Bad actors who want to hack your site, steal your data, and cripple your business are a 24\u002F7\u002F365 threat.\u003C\u002Fp>\n\u003Cp>You need a proactive, strategic approach to WordPress website security that protects your site from brute force attacks, malware infections, and other cyber threats.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgo.solidwp.com\u002Fsolid-security-pro\" rel=\"nofollow ugc\">Kadence Security\u003C\u002Fa> shields your site from cyberattacks and prevents security vulnerabilities. It automatically locks out bad users identified by our Brute Force Protection Network that is nearly 1 million sites strong and leverages your own blacklist. It secures and protects your most commonly attacked part of your WordPress website – user login authentication.\u003C\u002Fp>\n\u003Cp>With Patchstack integration (Pro) protects your site before you even have a chance to address vulnerabilities and before a plugin or theme vendor or developer can even issue a patch.\u003C\u002Fp>\n\u003Cp>That’s 24\u002F7\u002F365 always-on truly Kadence Security.\u003C\u002Fp>\n\u003Ch4>🌐 Secure your Website in Minutes\u003C\u002Fh4>\n\u003Cp>The Kadence Security setup and onboarding experience allows anyone to secure their WordPress website in under 10 minutes, regardless of technical acumen. Knowing that you have enabled all the right security settings for your website will leave you feeling like your site has never been more secure.\u003C\u002Fp>\n\u003Ch4>📚 Security Site Templates to Fit Your Type of Site\u003C\u002Fh4>\n\u003Cp>Enabling the correct security settings based on the type of website you are building or maintaining is essential for proper security. An eCommerce site requires a different level of security than a basic blog. Kadence Security Site Templates make it quick and easy to apply the right security settings for your website.\u003C\u002Fp>\n\u003Cp>Choose from six different site templates to apply the type of security your site needs:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Ecommerce\u003C\u002Fstrong> – websites that sell products or services\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Network\u003C\u002Fstrong> – websites that connect people or communities\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Non-Profit\u003C\u002Fstrong> – websites that promote your cause and collect donations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blog\u003C\u002Fstrong> – websites that share your thoughts or start a conversation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Portfolio\u003C\u002Fstrong> – websites that showcase your craft\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brochure\u003C\u002Fstrong> – simple websites that promote your business\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>⌚ Real-Time Website Security Dashboard\u003C\u002Fh4>\n\u003Cp>Every day, lots of activity is happening on your website that you can’t see. Many of these activities can be related to your site’s security, so monitoring these events is vital to keeping your site secure.\u003C\u002Fp>\n\u003Cp>The \u003Ca href=\"https:\u002F\u002Fgo.solidwp.com\u002Fsolid-security-pro\" rel=\"nofollow ugc\">Kadence Security Pro\u003C\u002Fa> plugin provides a real-time WordPress security dashboard that monitors security-related events on your site around the clock. The Kadence Security Dashboard is a dynamic dashboard with all your WordPress website’s security activity stats in one place, including brute force attacks, banned users, active lockouts, site scan results, and user security stats (Pro).\u003C\u002Fp>\n\u003Ch4>🗝️ WordPress Login Security\u003C\u002Fh4>\n\u003Cp>Setting up and maintaining proper WordPress configurations and managing user account access are essential aspects of hardening your site against threats and vulnerabilities. Basic and Pro include features that address both of these factors.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Two Factor Authentication (2FA)\u003C\u002Fstrong> – Make your WordPress login nearly impenetrable to attack by requiring users to enter a security code along with a password to login. The Kadence Security plugin allows you to add two-factor authentication to your WordPress login with several authentication methods, including mobile apps like Authy and Google Authenticator, email, and backup codes.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Password Requirements\u003C\u002Fstrong> – Create and enforce a password policy for your users in less than a minute.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>reCAPTCHA\u003C\u002Fstrong> (Pro) – Stop bad bots from engaging in abusive activities on your website, such as attempting to break into your website using compromised passwords, posting spam, or even scraping your content.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Passwordless Logins\u003C\u002Fstrong> (Pro) – WordPress security made easy. Secure your user accounts with 2fa & strong passwords while allowing real users login with a click of a mouse.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Trusted Devices\u003C\u002Fstrong> (Pro) – Identify the devices you and other users use to block session hijacking attacks and limit Administrator privileges to Trusted Devices.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Automated Vulnerability Patching\u003C\u002Fstrong> (Pro) – Kadence Security Pro includes Patchstack which patches vulnerabilities before you have a chance to and applies fixes even before a plugin developer or vendor has issued a patch.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Learn more about how \u003Ca href=\"https:\u002F\u002Fgo.solidwp.com\u002Fwporgpasswordless\" rel=\"nofollow ugc\">passwordless login is the future\u003C\u002Fa> and how Kadence Security can help you implement it today.\u003C\u002Fp>\n\u003Ch4>👨‍👩‍👧‍👦 The Right Amount of Security for Every User Level\u003C\u002Fh4>\n\u003Cp>Different types of user levels require different levels of security. During the Kadence Security setup process, you can identify your website’s key user groups. Once the different types of users are identified, you can apply the level of security that is just right for each user group.\u003C\u002Fp>\n\u003Cp>Here are a couple of examples of how User Groups are useful for securing your site:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>For Clients\u003C\u002Fstrong> – Let’s say you are configuring Kadence Security on a client’s website. You will decide whether or not they are required to use two-factor authentication and if they should have access to the Kadence Security settings.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>For Customers\u003C\u002Fstrong> – If you have an eCommerce website, you will decide whether or not you want to protect customer accounts with a password policy.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Privilege Escalation\u003C\u002Fstrong> (Pro) also adds a safe, secure way to grant temporary admin-level access to your website.\u003C\u002Fp>\n\u003Ch4>🤖 Block Bad Bots & Ban User Agents with Lockouts\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Ban Users\u003C\u002Fstrong> (Basic and Pro) – Permanently block repeat offenders from accessing your site.\u003Cbr \u002F>\nLocal Brute Force Protection – Automatically identify and stop the most common method of attack on WordPress sites.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Local Brute Force Protection\u003C\u002Fstrong> (Basic and Pro) – Automatically identify and stop the most common method of attack on WordPress sites.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Network Brute Force Protection\u003C\u002Fstrong> (Basic and Pro) – The network is the Kadence Security community and is nearly one million websites strong. If someone tries to break into websites in the Kadence Security community, Kadence Security will block them across the network.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Magic Links\u003C\u002Fstrong> (Pro) – Security shouldn’t get in your way. Magic Links allow you to log in to your WordPress site while your username is locked out by the Kadence Security Local Brute Force Protection feature.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔍 Monitor Your Site’s Security Health\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>File Change Detection\u003C\u002Fstrong> (Basic and Pro) – Kadence Security logs changes made to your website that can help detect malicious activity on your website.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Site Scanner (Basic and Pro)\u003C\u002Fstrong> – Schedule checks to run four times per day (Basic) or hourly (Pro) for known vulnerabilities of WordPress core file, plugins and themes. Using the Google Safe Browsing API, the Site Scan also checks your Google’s blocklist status and will alert you if Google has found any malware on your website.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Patchstack integration (Pro)\u003C\u002Fstrong> – Automated virtual patching of some vulnerabilities before you even have a chance to address them yourself, and before a plugin or theme vendor or developer can even issue a patch.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Site Scanner\u003C\u002Fstrong> (Pro) – Unlock Version Management to automatically apply a patch to vulnerable software detected by the Site Scan when one is available.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>User Logging\u003C\u002Fstrong> (Pro) – Keep a record of user activity in your WordPress security logs, including login\u002Flogout, user registration, adding\u002Fremoving plugins, switching themes, changes to posts and pages, and more.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Version Management\u003C\u002Fstrong> (Pro) – The Version Management feature in Kadence Security Pro allows you to auto-update WordPress, plugins, and themes. Beyond that, Version Management also has options to harden your website when you are running outdated software and scan for old websites.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🧠 Smarter, More Actionable Vulnerability Prioritization\u003C\u002Fh4>\n\u003Cp>Not all vulnerabilities pose the same level of risk, and the traditional Common Vulnerability Scoring System (CVSS) score doesn’t always reflect the realities of running a WordPress site.\u003C\u002Fp>\n\u003Cp>Kadence Security now uses the Patchstack Priority score, which goes beyond CVSS to provide a real-world risk assessment tailored to WordPress. It factors in how likely a vulnerability is to be exploited and its actual impact on your site.\u003C\u002Fp>\n\u003Cp>With Patchstack Priority, you get a clearer picture of what really matters, helping you focus on the vulnerabilities that pose the greatest risk, and worry less about noise from low-impact issues.\u003C\u002Fp>\n\u003Ch4>🛠️ Website Security Utilities\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Enforce SSL\u003C\u002Fstrong> – Force all connections to the website to be made over SSL\u002FTLS.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Database Backups\u003C\u002Fstrong> – Create backups of your WordPress database. (Not a complete backup.)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Geolocation\u003C\u002Fstrong> (Pro) – Improve Trusted Devices by connecting to an external location or mapping API.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🚀 Advanced Security Tools\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Identify Server IPs\u003C\u002Fstrong> – Prevent issues caused by inadvertently locking out your server IPs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change User ID 1\u003C\u002Fstrong> – Change the user ID for the first WordPress user, potentially preventing attacks that assume the user with ID1 exists and is an administrator.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change Database Prefix\u003C\u002Fstrong> – Change the database prefix that WordPress uses, potentially preventing attacks that assume the database prefix is “wp_”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Check File Permission\u003C\u002Fstrong> – See the file and directory permissions of key areas of your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Server Config Rules\u003C\u002Fstrong> – View or flush the server security rules generated by Kadence Security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>wp-config.php Rules\u003C\u002Fstrong> – View or flush the wp-config.php security rules generated by Kadence Security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change WordPress Salts\u003C\u002Fstrong> – Secure your site after a successful attack by changing the WordPress salts used to secure cookies and security tokens.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Login URL\u003C\u002Fstrong> – change the login URL of your site, making it harder for bots to find your login page and attack it.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🛟 Need Help?\u003C\u002Fh4>\n\u003Cp>Free support may be available with the community’s help in the WordPress.org support forums. Our Kadence Security support team provides top-notch technical support to all our Kadence Security Basic users there.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fgo.solidwp.com\u002Fsecurity-help-center\" rel=\"nofollow ugc\">Our Help Center will help you become an iThemes Security expert.\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Get additional peace of mind with professional support from our expert team and pro features to take your site’s security to the next level with Kadence Security Pro.\u003C\u002Fp>\n\u003Ch4>Recover From a Hacked Site\u003C\u002Fh4>\n\u003Cp>Kadence Security makes regular backups of your WordPress database, allowing you to get back online quickly in the event of a hack or security breach. Use Kadence Security to create and email database backups on a customizable schedule.\u003C\u002Fp>\n\u003Cp>For complete site backups and the ability to restore or move WordPress to a new host or domain, check out \u003Ca href=\"https:\u002F\u002Fgo.solidwp.com\u002Fsecurity-basic-solid-backups\" rel=\"nofollow ugc\">Solid Backups\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Solid Central Integration\u003C\u002Fh4>\n\u003Cp>Manage more than one WordPress site? Release lockouts and keep your themes, plugins, and WordPress core up to date from one dashboard with \u003Ca href=\"https:\u002F\u002Fgo.solidwp.com\u002Fsecurity-basic-solid-central\" rel=\"nofollow ugc\">Solid Central\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>*Zippia. “30 Crucial Cybersecurity Statistics [2023]: Data, Trends And More” Zippia.com. Jun. 15, 2023, https:\u002F\u002Fwww.zippia.com\u002Fadvice\u002Fcybersecurity-statistics\u002F\u003C\u002Fp>\n\u003Cp>**https:\u002F\u002Fblog.checkpoint.com\u002F2023\u002F01\u002F05\u002F38-increase-in-2022-global-cyberattacks\u002F\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>Released under the terms of the GNU General Public License.\u003C\u002Fp>\n","Harden your site security with Login Security, Two-Factor Authentication (2FA), Vulnerability Scanner, Firewall, and more. Formerly iThemes Security.",700000,38696531,92,3987,"2026-05-28T21:36:00.000Z","6.5",[19,98,99,77,22],"malware","password-protection","https:\u002F\u002Fwww.kadencewp.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbetter-wp-security.10.0.2.zip",96,19,"2024-06-20 00:00:00",{"slug":106,"name":107,"version":108,"author":109,"author_profile":110,"description":111,"short_description":112,"active_installs":113,"downloaded":114,"rating":115,"num_ratings":116,"last_updated":117,"tested_up_to":14,"requires_at_least":118,"requires_php":51,"tags":119,"homepage":122,"download_link":123,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wordfence-login-security","Wordfence Login Security","1.1.16","wfryan","https:\u002F\u002Fprofiles.wordpress.org\u002Fwfryan\u002F","\u003Ch3>WORDFENCE LOGIN SECURITY\u003C\u002Fh3>\n\u003Cp>Wordfence Login Security contains a subset of the functionality found in the full Wordfence plugin: Two-factor Authentication, XML-RPC Protection, and Login Page CAPTCHA.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>This plugin is being discontinued on or around July 1, 2026.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All of its features are already included in the main Wordfence plugin, which is also available to use for free. We recommend installing Wordfence to continue receiving updates, security improvements, and full functionality.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwordfence\u002F\" rel=\"ugc\">Install the full Wordfence plugin\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Two-factor authentication (2FA), one of the most secure forms of remote system authentication available.\u003C\u002Fli>\n\u003Cli>Use any TOTP-based authenticator app or service like Google Authenticator, Authy, 1Password or FreeOTP.\u003C\u002Fli>\n\u003Cli>Enable 2FA for any WordPress user role.\u003C\u002Fli>\n\u003Cli>Completely free to use, no limits or restrictions of any kind.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>LOGIN PAGE CAPTCHA\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easily enable Google ReCAPTCHA v3 on your login and registration pages.\u003C\u002Fli>\n\u003Cli>Stops bots from logging in without inconveniencing your site visitors.\u003C\u002Fli>\n\u003Cli>Robust protection against password guessing and credential stuffing attacks distributed across large IP pools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>XML-RPC PROTECTION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>XML-RPC is the biggest target for WordPress attacks, but is often overlooked.\u003C\u002Fli>\n\u003Cli>Protect XML-RPC with 2FA or disable it altogether if it’s not needed.\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.",60000,1329360,78,26,"2026-04-29T15:29:00.000Z","4.7",[120,121,20,77,22],"2fa","captcha","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwordfence-login-security.1.1.16.zip",{"slug":125,"name":126,"version":127,"author":128,"author_profile":129,"description":130,"short_description":131,"active_installs":132,"downloaded":133,"rating":134,"num_ratings":135,"last_updated":136,"tested_up_to":14,"requires_at_least":73,"requires_php":16,"tags":137,"homepage":140,"download_link":141,"security_score":57,"vuln_count":32,"unpatched_count":11,"last_vuln_date":142,"fetched_at":27},"anti-spam","Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter","7.5.2","Themeisle","https:\u002F\u002Fprofiles.wordpress.org\u002Fthemeisle\u002F","\u003Cp>Titan Anti-Spam & Security is a complete protection solution designed to secure your website against spam, login attacks, and unauthorized access.\u003C\u002Fp>\n\u003Cp>Websites are constantly targeted by automated spam bots, brute force login attempts, and malicious access patterns. Titan helps you block spam comments, protect your login page, enforce strong authentication, and apply essential security hardening rules from a single dashboard.\u003C\u002Fp>\n\u003Cp>Whether you run a blog, business site, WooCommerce store, membership platform, or agency network, Titan helps you:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Stop comment spam automatically\u003C\u002Fli>\n\u003Cli>Protect your login area from brute force attacks\u003C\u002Fli>\n\u003Cli>Limit login attempts and lock suspicious activity\u003C\u002Fli>\n\u003Cli>Monitor login activity and security events\u003C\u002Fli>\n\u003Cli>Apply security hardening best practices\u003C\u002Fli>\n\u003Cli>Enable two-factor authentication for stronger account security in \u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=2fa\" rel=\"nofollow ugc\">Pro\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Create backups with advanced storage options in \u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=backup\" rel=\"nofollow ugc\">Pro\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Titan is designed to reduce risk without affecting legitimate visitors or requiring captcha challenges.\u003C\u002Fp>\n\u003Ch3>Quick links\u003C\u002Fh3>\n\u003Cp>📘 \u003Ca href=\"https:\u002F\u002Fdocs.themeisle.com\u002Ftitan-anti-spam-security\u002F\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa> – Complete setup and configuration guide\u003Cbr \u002F>\n💬 \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fanti-spam\u002F\" rel=\"ugc\">Support Forum\u003C\u002Fa> – Get help with spam protection, login security, and plugin settings from the community and support team.\u003Cbr \u002F>\n⭐ \u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=quicklinks\" rel=\"nofollow ugc\">Go Pro\u003C\u002Fa> – Unlock Machine Learning spam detection, two-factor authentication, backups, and priority support.\u003C\u002Fp>\n\u003Ch3>Anti Spam Protection\u003C\u002Fh3>\n\u003Cp>Spam comments can damage your SEO, clutter your database, and waste moderation time. Titan provides automated spam protection that works in the background without interrupting real users.\u003C\u002Fp>\n\u003Cp>Every comment is checked against a global spam database and evaluated using intelligent filtering rules. Suspicious comments are automatically marked as spam and hidden from public view.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Automatic spam comment blocking:\u003C\u002Fstrong> Blocks spam comments in real time using a global spam database and intelligent filtering rules. Suspicious submissions are automatically marked as spam before they appear publicly.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Block spam comments without captcha:\u003C\u002Fstrong> Protect your site from comment spam without forcing visitors to solve captcha challenges. Real users experience a smooth commenting process.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Save spam comments for review:\u003C\u002Fstrong> Optionally store filtered spam comments in the moderation area so you can verify filtering accuracy and review blocked content.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detailed spam processing logs:\u003C\u002Fstrong> View logs of processed comments to understand how spam filtering works and monitor spam activity trends.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy policy link integration:\u003C\u002Fstrong> Display a privacy policy notice under comment forms to help with transparency and compliance requirements.\u003C\u002Fp>\n\u003Cp>This ensures real visitors can interact freely while bots are filtered automatically.\u003C\u002Fp>\n\u003Ch3>Security Hardening Tools\u003C\u002Fh3>\n\u003Cp>Titan includes built-in security hardening options that reduce publicly exposed information and protect your website from common automated attacks.\u003C\u002Fp>\n\u003Cp>Many bots scan websites looking for version numbers, exposed login patterns, weak passwords, or XML-RPC endpoints. Titan helps minimize those risks with configurable hardening controls that strengthen overall site security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Strong Password Enforcement:\u003C\u002Fstrong> Force users to create strong passwords based on the WordPress password strength meter. Weak passwords are a leading cause of account compromise. Enforcing strong credentials significantly improves login security and reduces unauthorized** access risks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hide Author Login:\u003C\u002Fstrong> Attackers can attempt to discover usernames using author archive URLs. Titan prevents user enumeration by restricting access patterns that reveal valid login names. This reduces the effectiveness of targeted brute force login attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable XML-RPC:\u003C\u002Fstrong> XML-RPC can be abused for automated login attacks and pingback spam. Disabling XML-RPC reduces exposure to remote brute force attempts and limits unnecessary resource usage.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hide Version Information:\u003C\u002Fstrong> WordPress core and plugins sometimes expose version numbers in the source code. Attackers use this information to target known vulnerabilities. Titan removes version references to reduce fingerprinting risks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Remove Version Query Strings:\u003C\u002Fstrong> JavaScript and CSS files often include version query parameters. Removing these prevents attackers from identifying the exact WordPress or plugin version running on your site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Remove Meta Generator Tag:\u003C\u002Fstrong> The generator meta tag can reveal your CMS version. Titan removes it to reduce publicly visible system information and lower exposure.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Remove HTML Comments:\u003C\u002Fstrong> Some themes and plugins output HTML comments that may expose structural details. Titan can remove these comments to limit unnecessary information disclosure.\u003C\u002Fp>\n\u003Cp>Together, these security hardening options reduce your attack surface and strengthen your website without affecting normal functionality.\u003C\u002Fp>\n\u003Ch3>Activity Monitoring and Logs\u003C\u002Fh3>\n\u003Cp>Security is not only about blocking attacks. It is also about visibility and awareness.\u003C\u002Fp>\n\u003Cp>Titan includes built-in monitoring tools that help you understand login behavior and security activity on your website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Attempts Log:\u003C\u002Fstrong> Track failed login attempts in real time. See which IP addresses are attempting access, how many retries were made, and when lockouts were triggered. This helps you evaluate brute force protection effectiveness.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Activity Logger:\u003C\u002Fstrong> Monitor security-related events across your site, including login activity and system actions. Identify suspicious patterns before they escalate.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Error Log Viewer:\u003C\u002Fstrong> View plugin-related errors directly from the dashboard. Diagnose configuration issues quickly without accessing server files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Debug Information Export:\u003C\u002Fstrong> Export diagnostic information when contacting support. This reduces troubleshooting time and speeds up issue resolution.\u003C\u002Fp>\n\u003Cp>With proper monitoring and logging, you are not only blocking attacks but also gaining insight into how your website is being targeted.\u003C\u002Fp>\n\u003Ch3>PRO Anti Spam Features\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Machine Learning spam detection:\u003C\u002Fstrong> Advanced spam filtering powered by Machine Learning improves detection accuracy by analyzing behavioral patterns across large datasets.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scan existing comments for spam:\u003C\u002Fstrong> Identify previously approved spam comments and clean up your database.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scan registered users for spam accounts:\u003C\u002Fstrong> Detect and flag suspicious user accounts that may have been created by spam bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhanced background spam analysis:\u003C\u002Fstrong> Apply additional invisible tests that improve spam protection without affecting legitimate visitors.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=antispam\" rel=\"nofollow ugc\">Upgrade to unlock\u003C\u002Fa> advanced anti-spam capabilities.\u003C\u002Fp>\n\u003Ch3>PRO Two Factor Authentication\u003C\u002Fh3>\n\u003Cp>Two-factor authentication adds an additional verification step beyond a password. Even if a password is compromised, attackers cannot access the account without the second authentication factor.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>QR Code Setup:\u003C\u002Fstrong> Scan a QR code with an authenticator app to activate two-factor authentication quickly and securely.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manual Secret Key Configuration:\u003C\u002Fstrong> Set up two-factor authentication manually if QR code scanning is unavailable.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Per User 2FA Management:\u003C\u002Fstrong> Enable or manage two-factor authentication individually for specific users or roles.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Compatible with TOTP Apps:\u003C\u002Fstrong> Works with popular authenticator apps such as Google Authenticator and other TOTP-compatible applications.\u003C\u002Fp>\n\u003Cp>Two-factor authentication significantly strengthens login security for administrators and users.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=2fa\" rel=\"nofollow ugc\">Upgrade to Titan Pro\u003C\u002Fa> to enable Two Factor Authentication and advanced account protection.\u003C\u002Fp>\n\u003Ch3>PRO Backup and Recovery\u003C\u002Fh3>\n\u003Cp>Regular backups are essential for website security and recovery planning. If something goes wrong, having a recent backup allows you to restore your site quickly.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scheduled Automatic Backups:\u003C\u002Fstrong> Automatically create backups at defined intervals to ensure recent recovery points are always available.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manual Backup Creation:\u003C\u002Fstrong> Generate a backup instantly before making major changes to your website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>FTP Storage Support:\u003C\u002Fstrong> Store backups on a remote FTP server for additional protection and redundancy.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Dropbox Storage Integration:\u003C\u002Fstrong> Save backups to Dropbox for secure off-site storage.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Automatic Archive Cleanup:\u003C\u002Fstrong> Remove older backup files automatically to manage storage usage efficiently.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Adjustable Backup Performance:\u003C\u002Fstrong> Control backup speed to balance performance and server resource usage.\u003C\u002Fp>\n\u003Cp>Backups can be managed directly from the Titan dashboard for centralized control.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=backup\" rel=\"nofollow ugc\">Upgrade to Titan Pro\u003C\u002Fa> to unlock scheduled backups and external storage options.\u003C\u002Fp>\n\u003Ch3>Use Cases\u003C\u002Fh3>\n\u003Cp>Titan is suitable for:\u003C\u002Fp>\n\u003Cp>• Blogs receiving large volumes of comment spam\u003Cbr \u002F>\n• WooCommerce stores protecting customer login pages\u003Cbr \u002F>\n• Membership websites securing user accounts\u003Cbr \u002F>\n• Agencies managing multiple client websites\u003Cbr \u002F>\n• Educational platforms enforcing stronger authentication\u003Cbr \u002F>\n• Website owners looking for anti-spam and login security in one plugin\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>Need help? Open a new thread in the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fanti-spam\u002F\" rel=\"ugc\">Support Forum\u003C\u002Fa>, and we’ll be happy to assist.\u003C\u002Fp>\n\u003Ch3>Documentation\u003C\u002Fh3>\n\u003Cp>Discover how to make the most of Robin with our detailed and user-friendly \u003Ca href=\"https:\u002F\u002Fdocs.themeisle.com\u002F\" rel=\"nofollow ugc\">documentation\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Titan is backed by Themeisle, trusted by over 1 million WordPress users worldwide.\u003C\u002Fp>\n","Block spam comments, defend against login attacks, strengthen site security. Anti-spam, brute-force protection & two-factor authentication built in.",50000,3499574,90,369,"2026-05-19T11:25:00.000Z",[138,19,77,139,22],"antispam","spam-protection","http:\u002F\u002Fwordpress.org\u002Fplugins\u002Fanti-spam\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanti-spam.7.5.2.zip","2024-07-11 00:00:00",{"error":144,"url":145,"statusCode":146,"statusMessage":147,"message":147},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fauthdock\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":32,"versions":149},[150,156,163],{"version":6,"download_url":24,"svn_tag_url":151,"released_at":26,"has_diff":152,"diff_files_changed":153,"diff_lines":26,"trac_diff_url":154,"vulnerabilities":155,"is_current":144},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fauthdock\u002Ftags\u002F1.0.2\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fauthdock%2Ftags%2F1.0.1&new_path=%2Fauthdock%2Ftags%2F1.0.2",[],{"version":157,"download_url":158,"svn_tag_url":159,"released_at":26,"has_diff":152,"diff_files_changed":160,"diff_lines":26,"trac_diff_url":161,"vulnerabilities":162,"is_current":152},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fauthdock.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fauthdock\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fauthdock%2Ftags%2F1.0.0&new_path=%2Fauthdock%2Ftags%2F1.0.1",[],{"version":164,"download_url":165,"svn_tag_url":166,"released_at":26,"has_diff":152,"diff_files_changed":167,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":168,"is_current":152},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fauthdock.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fauthdock\u002Ftags\u002F1.0.0\u002F",[],[]]