[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGqZfrFFkzbyt6b4eI-i-ip9iihVLIdVBWtDApolYbWs":3,"$f9DPUhtob1DkcfN-PnVRXmQB6uduvR55JkPPLZWhQyeo":120,"$fQ4LPxfh7JUgUgX9ax7JQ2HfCkHU9WWe0ssfkveueLdQ":125},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":27,"fingerprints":27},"bastora-security-audit","Bastora Security Audit","1.4.7","Bastora","https:\u002F\u002Fprofiles.wordpress.org\u002Fmathiasva\u002F","\u003Cp>\u003Cstrong>Bastora\u003C\u002Fstrong> ist ein ehrlicher WordPress-Sicherheits-Check. Statt tausend Schalter ohne Erklärung prüft Bastora Deine Installation gegen einen festen Katalog aus \u003Cstrong>62 Sicherheitspunkten\u003C\u002Fstrong> und zeigt Dir das Ergebnis als Klartext-Ampel direkt in Deinem Dashboard.\u003C\u002Fp>\n\u003Cp>Bastora unterscheidet sich von anderen Sicherheits-Plugins in drei Punkten:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Ehrliche Außensicht.\u003C\u002Fstrong> Bastora prüft Deine Seite so, wie ein Bot sie sieht: Versionslecks im HTML, offene Verzeichnis-Listen, fehlende Security-Header, sichtbare Endpoints. Die meisten anderen Plugins prüfen nur ihre eigene Konfiguration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Konflikt-erkennende Auto-Härtung.\u003C\u002Fstrong> Härtungen sind ab Werk aktiv. Bastora prüft, ob ein anderes Sicherheits-Plugin (Wordfence, Solid Security, AIOS, Limit Login Attempts und andere) denselben Punkt schon übernimmt, und tritt elegant zur Seite, statt einen Konflikt zu bauen.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Null Konfiguration.\u003C\u002Fstrong> Installieren, aktivieren, einmal „Sicherheitsprüfung starten” klicken, fertig. Bastora richtet sich selbst ein.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Was Bastora prüft\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zugangssicherheit (11 Punkte):\u003C\u002Fstrong> HTTPS-Login, Brute-Force-Schutz, Salt-Keys, geteilte Konten, Login-Verhalten\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Systemabsicherung (15 Punkte):\u003C\u002Fstrong> Datei-Editor, Verzeichnis-Listings, wp-config-Sperre, Debug-Modus, Dateirechte, Revisionen, \u003Cstrong>Kerndatei-Abgleich gegen das Original von wordpress.org mit automatischer Reparatur\u003C\u002Fstrong>, \u003Cstrong>täglicher Abgleich aller Plugins gegen wordpress.org\u003C\u002Fstrong>, \u003Cstrong>täglicher Abgleich aller Themes gegen wordpress.org\u003C\u002Fstrong>, \u003Cstrong>Schadcode-Prüfung der Theme-Dateien\u003C\u002Fstrong>, \u003Cstrong>Schadcode-Prüfung des Uploads-Verzeichnisses\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Informationsschutz (10 Punkte):\u003C\u002Fstrong> Generator-Tag, RSD-Link, WLW-Manifest, XML-RPC, REST-API-Benutzer, Pingbacks, X-Powered-By\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security-Header (5 Punkte):\u003C\u002Fstrong> X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pingbacks (2 Punkte):\u003C\u002Fstrong> ausgehende und eingehende Pingbacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auto-Updates (7 Punkte):\u003C\u002Fstrong> nächtlicher Schutz, Minor-\u002FMajor-Auto-Updates, Plugin-\u002FTheme-Auto-Updates, verwaiste Erweiterungen\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Monitoring und Betrieb (8 Punkte):\u003C\u002Fstrong> Transients, Revisions-Cleanup, Captcha, WordPress-Version, PHP-Version, \u002Fuploads\u002F-PHP-Sperre, Sicherheits-Plugin-Status, Schutz vor Verlinkung auf bekannte Schadseiten\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Was Bastora härtet (wenn kein Konflikt erkannt wird)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress-Version aus HTML und RSS-Feed entfernt\u003C\u002Fli>\n\u003Cli>RSD-Link und WLW-Manifest entfernt\u003C\u002Fli>\n\u003Cli>Login-Shake-Effekt deaktiviert\u003C\u002Fli>\n\u003Cli>Login-Fehlermeldung verallgemeinert (verrät nicht mehr, welche Benutzer existieren)\u003C\u002Fli>\n\u003Cli>Author-Seiten umgeleitet (verhindert das Aufzählen von Benutzernamen)\u003C\u002Fli>\n\u003Cli>XML-RPC abgeschaltet (außer ein konkurrierendes Plugin übernimmt das schon)\u003C\u002Fli>\n\u003Cli>Pingback-XML-RPC-Methoden gesperrt\u003C\u002Fli>\n\u003Cli>REST-API-Endpoint \u002Fusers für nicht eingeloggte Anfragen gesperrt\u003C\u002Fli>\n\u003Cli>Application Passwords deaktiviert\u003C\u002Fli>\n\u003Cli>X-Powered-By-Header entfernt (verrät sonst die PHP-Version)\u003C\u002Fli>\n\u003Cli>Beitrags-Revisionen auf 15 begrenzt (hält die Datenbank schlank, respektiert strengere Einstellungen)\u003C\u002Fli>\n\u003Cli>Uploads-Verzeichnis gegen PHP-Ausführung abgesichert (index.html gegen Verzeichnis-Listing, auf Apache zusätzlich eine .htaccess, tritt zur Seite wenn ein anderes Plugin das schon macht)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HTTPS-Umstellung mit einem Klick:\u003C\u002Fstrong> Bastora schreibt die eigenen http-Links Deiner Seite serialisierungssicher auf https um und richtet die Weiterleitung von http auf https ein. Auf reinen http-Seiten prüft Bastora vorab die HTTPS-Erreichbarkeit, schaltet mit einem 15-minütigen Probelauf um und dreht ohne Bestätigung von selbst zurück. Fremde Domains bleiben unberührt, ein laufendes SSL-Plugin hat Vorrang.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login-Honeypot:\u003C\u002Fstrong> verstecktes Formularfeld in der Login-Maske, das Bots ausfüllen und sich damit als Bot zu erkennen geben\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-Force-Schutz mit IP-Sperre:\u003C\u002Fstrong> 5 Fehlversuche \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> 30 Minuten Sperre. Bei wiederholten Sperren: Eskalation auf 4 Stunden, dann 24 Stunden. Zähler setzt sich nach erfolgreichem Login zurück. IPv6 wird auf dem \u002F64-Präfix gesperrt. Cloudflare- und Reverse-Proxy-IP-Erkennung ist eingebaut.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Kerndatei-Auto-Reparatur:\u003C\u002Fstrong> Bastora vergleicht täglich Deine WordPress-Kerndateien mit den offiziellen Hashes von wordpress.org. Wird eine Datei manipuliert oder fehlt, lädt Bastora die saubere Originaldatei aus der offiziellen WordPress-ZIP, validiert ihren Hash doppelt und ersetzt die kompromittierte Version automatisch. Die alte Datei wandert zur Spurensicherung in \u003Ccode>wp-content\u002Fuploads\u002Fbastora-quarantine\u002F\u003C\u002Fcode>. Du bekommst eine E-Mail mit der Liste der reparierten Dateien. Voraussetzung: Versions-Abgleich-Opt-in aktiv. Bei Hostern mit schreibgeschützten Core-Dateien bleibt die Anzeige + Mail erhalten.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bastora-Schwarm (opt-in):\u003C\u002Fstrong> Sobald eine teilnehmende Bastora-Website einen Brute-Force-Angriff erkennt, wandert die Angreifer-IP anonym in einen geteilten Sperrkatalog. Deine Seite holt diesen Katalog alle paar Minuten ab und blockiert die IPs, bevor sie überhaupt anklopfen. Im Gegenzug meldet Deine Seite Angreifer, die Du erkennst. Versendet wird ausschließlich die Angreifer-IP samt Angriffs-Typ und ein anonymer UUID-Token, keine Domain, keine Besucher-IPs, keine Owner-Daten. Aktivierung erfolgt im Onboarding-Wizard oder unter Einstellungen.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Konflikt-erkennend\u003C\u002Fh4>\n\u003Cp>Wenn eines der folgenden Plugins schon läuft, erkennt Bastora das und deaktiviert nur die überlappenden Bereiche:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence Security\u003C\u002Fli>\n\u003Cli>Sucuri Security\u003C\u002Fli>\n\u003Cli>Solid Security (früher iThemes)\u003C\u002Fli>\n\u003Cli>All-In-One WP Security & Firewall\u003C\u002Fli>\n\u003Cli>MalCare Security\u003C\u002Fli>\n\u003Cli>WP Cerber Security\u003C\u002Fli>\n\u003Cli>Limit Login Attempts Reloaded\u003C\u002Fli>\n\u003Cli>Disable XML-RPC\u003C\u002Fli>\n\u003Cli>Disable Application Passwords\u003C\u002Fli>\n\u003Cli>Really Simple SSL\u003C\u002Fli>\n\u003Cli>HTTP Headers\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Im Dashboard siehst Du pro Härtung im Klartext, warum sie aktiv oder inaktiv ist.\u003C\u002Fp>\n\u003Ch4>Was Bastora bewusst **nicht** macht\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Kein erzwungenes TOTP.\u003C\u002Fstrong> Solopreneure sperren sich regelmäßig mit Authenticator-Apps aus. Bastora setzt stattdessen auf Brute-Force-Schutz, Rate-Limit und Anomalie-Erkennung.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Kein Verstecken der Login-URL.\u003C\u002Fstrong> Eine umbenannte Login-URL macht den Passwort-Reset-Link in der Mail kaputt, sobald das Plugin deaktiviert wird. Rate-Limit plus Honeypot ist die saubere Lösung.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Keine Cloud-Verbindung ohne Zustimmung.\u003C\u002Fstrong> Alle externen Verbindungen (auch Versions-Abgleich gegen wordpress.org) sind ab Werk aus. Sie schalten sich erst ein, wenn Du sie im Welcome-Wizard oder in den Einstellungen ausdrücklich freigibst.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Optionale anonyme Statistik (Opt-in)\u003C\u002Fh4>\n\u003Cp>Wenn Du das Häkchen „Statistik aktivieren und teilen” in den Einstellungen setzt, schickt Bastora einmal sofort und danach nur alle 28 Tage eine kompakte anonyme Zusammenfassung per HTTPS-POST an \u003Ccode>https:\u002F\u002Fbastora.de\u002Fv1\u002Ftelemetry\u002F\u003C\u002Fcode>. Vor dem Häkchen geht kein einziger Request raus. Die niedrige Frequenz ist bewusst: Bastora will Masse-Infos über viele Sites sammeln, kein dichtes Zeitprofil einzelner Sites.\u003C\u002Fp>\n\u003Cp>Übertragen werden ausschließlich:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Eine zufällige anonyme Site-ID (UUID), lokal beim ersten Plugin-Start erzeugt\u003C\u002Fli>\n\u003Cli>Plugin-Version, WordPress-, PHP- und MySQL-Versions-Strings\u003C\u002Fli>\n\u003Cli>Locale (zum Beispiel de_DE)\u003C\u002Fli>\n\u003Cli>Multisite-Flag (ja\u002Fnein)\u003C\u002Fli>\n\u003Cli>Liste der installierten Plugins und Themes mit Versionsstand (max. 200 Einträge)\u003C\u002Fli>\n\u003Cli>Audit-Score und Counter pro Status (bestanden \u002F Hinweis \u002F offen \u002F nicht prüfbar)\u003C\u002Fli>\n\u003Cli>Installationsart (self \u002F agency \u002F org) samt Erstwahl, damit wir sehen, wer Bastora einsetzt. Nur diese drei Werte, keine Namen, keine Adressen.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Was \u003Cstrong>nie\u003C\u002Fstrong> übertragen wird: Domain, URL, IP-Adresse, E-Mail-Adressen, Benutzernamen, Beitragsinhalte, Dateiinhalte. Der bastora.de-Server loggt keine Aufrufer-IP. Pro Site-ID wird maximal ein Eintrag pro Tag akzeptiert (UPSERT), die normale Sende-Frequenz pro Site liegt ohnehin bei einem Datensatz alle 28 Tage. Bei Deinstallation des Plugins werden die lokale Site-ID und alle Bastora-Optionen entfernt.\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Ch4>Externe Verbindungen\u003C\u002Fh4>\n\u003Cp>Bastora kontaktiert externe Server in zwei klar getrennten Fällen. \u003Cstrong>Beide sind opt-in. Ab Werk macht das Plugin keine externen Verbindungen.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. Versions-Abgleich gegen api.wordpress.org (opt-in)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Wenn Du im Welcome-Wizard oder in den Einstellungen „Versions-Abgleich erlauben” aktivierst, fragt Bastora bei einem manuellen Scan die api.wordpress.org nach:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>der aktuellen WordPress-Core-Version: \u003Ccode>https:\u002F\u002Fapi.wordpress.org\u002Fcore\u002Fversion-check\u002F1.7\u002F\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>den offiziellen Datei-Hashes der installierten WordPress-Version (für den Kerndatei-Abgleich): \u003Ccode>https:\u002F\u002Fapi.wordpress.org\u002Fcore\u002Fchecksums\u002F1.0\u002F?version=\u003Cversion>&locale=en_US\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>pro erkennbarem Plugin nach dessen letztem Update-Datum: \u003Ccode>https:\u002F\u002Fapi.wordpress.org\u002Fplugins\u002Finfo\u002F1.0\u002F\u003Cslug>.json\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>pro erkennbarem Theme nach dessen letztem Update-Datum: \u003Ccode>https:\u002F\u002Fapi.wordpress.org\u002Fthemes\u002Finfo\u002F1.2\u002F?action=theme_information&request[slug]=\u003Cslug>\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Wenn Bastora bei der täglichen Prüfung manipulierte oder fehlende Kerndateien entdeckt, lädt Bastora zusätzlich die offizielle WordPress-ZIP herunter, um die saubere Originaldatei zu extrahieren:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>https:\u002F\u002Fdownloads.wordpress.org\u002Frelease\u002Fwordpress-\u003Cversion>.zip\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Die ZIP wird einmal pro Version 7 Tage lokal in \u003Ccode>wp-content\u002Fuploads\u002Fbastora-quarantine\u002F_core-cache\u002F\u003C\u002Fcode> gespeichert, um wiederholten Bandbreitenverbrauch zu vermeiden. Vor dem Ersetzen einer Datei prüft Bastora deren MD5-Hash gegen den von api.wordpress.org gemeldeten Wert (Doppel-Sicherung gegen Download-Pannen).\u003C\u002Fp>\n\u003Cp>Ab Plugin-Version 0.4.0 lädt Bastora für die tägliche Plugin- und Theme-Wache zusätzlich pro installiertem Plugin\u002FTheme die offizielle ZIP aus dem WordPress.org-Repository, um die einzelnen Dateien gegen das Original abzugleichen:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F\u003Cslug>.\u003Cversion>.zip\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>https:\u002F\u002Fdownloads.wordpress.org\u002Ftheme\u002F\u003Cslug>.\u003Cversion>.zip\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Die ZIPs werden 7 Tage lokal in \u003Ccode>wp-content\u002Fuploads\u002Fbastora-quarantine\u002F_asset-cache\u002F\u003C\u002Fcode> gespeichert. Plugins und Themes, die NICHT im offiziellen WordPress.org-Repository liegen (z.B. Premium-Plugins, Custom-Themes), werden als „extern, nicht prüfbar” markiert, es geht kein Request raus außer dem ersten API-Lookup, der mit 404 antwortet und das Ergebnis 24 Stunden zwischenspeichert. Bei Plugins findet eine automatische Reparatur bewusst NICHT statt; bei Funden bekommst Du eine Admin-Mail mit der Liste der abweichenden Dateien. Bei Themes aus dem WordPress.org-Repository schreibt Bastora ab Version 1.3.0 eine vom Original abweichende Datei selbst zurück und sichert die vorgefundene Fassung in der Quarantäne. Themes ohne Original bei wordpress.org bleiben vom Abgleich unangetastet; nur eindeutiger Schadcode (Webshell, Backdoor, Spuren-Verwischer) wird auch dort in die Quarantäne verschoben.\u003C\u002Fp>\n\u003Cp>Das ist dieselbe API, die WordPress selbst für seine eigenen Update-Checks nutzt. Übertragen wird nur der Slug pro Plugin oder Theme. Keine Domain, keine Nutzerdaten, keine Besucher-IP. Die Abfragen laufen nur bei manuellem Klick auf den Scan-Button, nie automatisch im Hintergrund. Antworten werden 24 Stunden zwischengespeichert.\u003C\u002Fp>\n\u003Cp>Wenn Du diesen Punkt nicht aktivierst, werden die update-relevanten Audit-Punkte als „nicht prüfbar” markiert und es geht keine Anfrage raus.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2. Bastora-Schwarm (opt-in, ab Plugin-Version 0.3.0)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Wenn Du den Bastora-Schwarm im Welcome-Wizard oder unter „Einstellungen \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Bastora-Schwarm” aktivierst, tauscht das Plugin Brute-Force-Angreifer-IPs anonym mit anderen teilnehmenden Sites aus. Drei Endpoints sind beteiligt:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>https:\u002F\u002Fbastora.de\u002Fapi\u002Fswarm-register.php\u003C\u002Fcode>, Einmaliger POST beim Aktivieren. Der Server vergibt einen anonymen UUID-Token. Übertragen wird: die Plugin-Version. Nicht übertragen wird: Domain, URL, IP-Adresse Deiner Besucher, Owner-Daten. Die Server-IP des HTTP-Requests wird nur als gesalzener SHA-256-Hash für ein Rate-Limit gespeichert und ist nicht zurückrechenbar.\u003C\u002Fli>\n\u003Cli>\u003Ccode>https:\u002F\u002Fbastora.de\u002Fapi\u002Fswarm-report.php\u003C\u002Fcode>, POST bei Erkennung eines Brute-Force-Angriffs. Übertragen wird: der anonyme Token, die Angreifer-IP, der Angriffs-Typ („login_bruteforce”), die Severity, die Plugin-Version. Nicht übertragen wird: alles andere.\u003C\u002Fli>\n\u003Cli>\u003Ccode>https:\u002F\u002Fbastora.de\u002Fapi\u002Fswarm-feed.php\u003C\u002Fcode>, GET-Abruf der aktuellen Sperrliste, alle 5 Minuten via WP-Cron plus on-demand bei Login-Versuchen, jeweils mit 60-Sekunden-Cache und ETag-Optimierung. Im HTTP-Header geht der anonyme Token mit, sonst nichts.\u003C\u002Fli>\n\u003Cli>\u003Ccode>https:\u002F\u002Fbastora.de\u002Fapi\u002Fswarm-disconnect.php\u003C\u002Fcode>, POST beim Opt-out in den Einstellungen oder beim Deinstallieren. Übertragen wird: der anonyme Token. Der Server löscht den Knoten unmittelbar.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Der HTTP-User-Agent ist bei allen vier Endpoints statisch „Bastora-Swarm\u002F”, damit WordPress die Domain nicht über den Default-UA mitschickt. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an Angriffsabwehr). Eingegangene Reports werden serverseitig nach 14 Tagen automatisch gelöscht (Datenminimierung). Sperrlisten-Einträge verfallen nach 72 Stunden ohne neue Meldungen.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Pwned-Passwords-Abgleich (Opt-in, nur Backend-Login)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Wenn Du in den Einstellungen den Passwort-Leak-Check aktivierst, schickt Bastora bei jedem Backend-Login (max. 1× pro 7 Tage pro Nutzer) die ersten fünf Hex-Zeichen des SHA-1-Hashes Deines eingegebenen Passworts an \u003Ccode>https:\u002F\u002Fbastora.de\u002Fv1\u002Fpwned\u002F\u003Cprefix>\u003C\u002Fcode>. Übertragen wird ausschließlich dieses 5-Zeichen-Prefix. Nicht übertragen wird: das Passwort selbst, das vollständige Hash, der Nutzername, die Domain, irgendeine ID. Der bastora.de-Proxy fragt die offizielle haveibeenpwned.com-API mit dem Prefix an, cached das Ergebnis 7 Tage lokal in einer deutschen MySQL-Datenbank und schickt die Liste der Hash-Suffixe zurück. Der Abgleich passiert lokal in WordPress. Das Verfahren heißt k-Anonymity und wird auch von 1Password, Firefox und Chrome genutzt. Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO. Bei Treffer wird der Nutzer im Backend per Notice aufgefordert, das Passwort zu ändern, der Login wird nie blockiert.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Schad-URL-Feed (Opt-in)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Wenn Du den Schad-URL-Feed in den Einstellungen aktivierst, holt Bastora einmal pro Tag eine aktualisierte Domain-Liste von \u003Ccode>https:\u002F\u002Fbastora.de\u002Fv1\u002Furl-feed\u002F\u003C\u002Fcode>. Übertragen wird ausschließlich ein anonymer GET-Request, optional mit dem Zeitstempel des letzten erfolgreichen Abrufs als \u003Ccode>?since=\u003Cunixts>\u003C\u002Fcode>, damit nur neu hinzugekommene Einträge geliefert werden. Es geht keine Domain Deiner Seite, keine Besucher-Daten und kein Identifier raus. Die Antwort ist eine reine JSON-Liste mit Schad-Domain, Typ („malware” oder „phishing”) und Severity, sie enthält keinen ausführbaren Code. Quellen, die der Bastora-Server aggregiert: URLhaus (abuse.ch, CC0 1.0) und der OpenPhish-Community-Feed. Die Liste wird lokal in einer WP-Option gespeichert (Hard-Cap 50 000 Einträge, 30 Tage Plugin-seitige TTL) und vom URL-Watch-Modul zusätzlich zur eingebauten Startliste für die Prüfung von Beiträgen und Kommentaren genutzt. Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO. Vor dem Opt-in-Häkchen wird kein einziger Aufruf an \u003Ccode>bastora.de\u002Fv1\u002Furl-feed\u002F\u003C\u002Fcode> ausgeführt.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Anonyme Sicherheits-Telemetrie an bastora.de (Opt-in)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Wenn Du in den Einstellungen den Schalter „Statistik aktivieren und teilen” setzt, schickt Bastora einmal sofort und danach nur alle 28 Tage einen JSON-POST an \u003Ccode>https:\u002F\u002Fwww.bastora.de\u002Fv1\u002Ftelemetry\u002F\u003C\u002Fcode>. Vor dem Häkchen wird \u003Cstrong>kein\u003C\u002Fstrong> Aufruf ausgeführt. Ab Plugin-Version 1.0.3 ist das Datenpaket bewusst umfangreicher, damit Bastora das gemeinsame Bedrohungsbild für die WordPress-Welt schärfen kann. Die niedrige Frequenz ist bewusst: Bastora will Masse-Infos über viele Sites sammeln, kein dichtes Zeitprofil einzelner Sites. Übertragen wird:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Eine zufällige anonyme Site-ID (UUID), lokal beim ersten Plugin-Start erzeugt\u003C\u002Fli>\n\u003Cli>Bastora-Plugin-Version\u003C\u002Fli>\n\u003Cli>WordPress-Version + die zum Zeitpunkt der Erfassung aktuelle Core-Version + Update-Status (ja\u002Fnein)\u003C\u002Fli>\n\u003Cli>PHP- und MySQL-Versions-Strings\u003C\u002Fli>\n\u003Cli>Server-Software-String (z.B. „Apache\u002F2.4″)\u003C\u002Fli>\n\u003Cli>Anonymer Hosting-Provider-Slug (z.B. „hetzner”, „ionos”, „kinsta”), ermittelt aus Konstanten-Markern bekannter Managed-Hoster, Reverse-DNS auf die Server-IP, sowie DOCUMENT_ROOT-Pfad-Pattern. Die Server-IP selbst wird NICHT gesendet.\u003C\u002Fli>\n\u003Cli>Locale (zum Beispiel de_DE), Zeitzone, Multisite-Flag\u003C\u002Fli>\n\u003Cli>Pro installiertem Plugin: Slug, installierte Version, neueste verfügbare Version (Quelle: api.wordpress.org-Cache), ob Update bereitsteht, ob Auto-Update aktiv ist, ob Plugin aktiv oder inaktiv. Max. 200 Plugins.\u003C\u002Fli>\n\u003Cli>Pro installiertem Theme: Slug, installierte Version, neueste verfügbare Version, Update-Status, Auto-Update, Eltern-Theme bei Child-Themes. Max. 75 Themes.\u003C\u002Fli>\n\u003Cli>Aktives Theme: Slug, Version, Eltern-Theme\u003C\u002Fli>\n\u003Cli>User-Counts pro Rolle (nur Zahlen, keine Namen oder Mails)\u003C\u002Fli>\n\u003Cli>Content-Counts: Anzahl veröffentlichter Beiträge, Seiten, Kommentare (total \u002F approved \u002F spam)\u003C\u002Fli>\n\u003Cli>WordPress-Konfigurations-Flags: WP_DEBUG, DISALLOW_FILE_EDIT, DISALLOW_FILE_MODS, FORCE_SSL_ADMIN, geschätzte autoload-Options-Größe in KB\u003C\u002Fli>\n\u003Cli>Audit-Summary (Counter pro Status) + Audit-Findings-Map: pro Audit-Punkt-ID ein kompakter Status-Code (0=bestanden, 1=Hinweis, 2=offen, 3=nicht prüfbar). Damit wertet die Server-Statistik die häufigsten Sicherheitslücken aus.\u003C\u002Fli>\n\u003Cli>Erkannte Sicherheits-Plugins mit Klassifizierung free \u002F Pro \u002F lizenz-aktiviert (z.B. Wordfence Free vs. Wordfence Premium per API-Key-Konstante)\u003C\u002Fli>\n\u003Cli>Bastora-eigene Härtungs-Schalter mit Aktiv-Status und erkannten Konflikten (welche Bereiche andere Sicherheits-Plugins schon übernehmen)\u003C\u002Fli>\n\u003Cli>Installationsart und deren Erstwahl (self = für mich selbst, agency = im Auftrag, org = für eine Organisation). Aus einem Wechsel gegenüber der Erstwahl lesen wir, wie oft sich die Rolle ändert. Nur diese Werte, keine Namen, keine Adressen.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Was \u003Cstrong>nie\u003C\u002Fstrong> übertragen wird: Domain, URL, Server-IP, Besucher-IPs, E-Mail-Adressen, Benutzernamen, Beitragsinhalte, Datei-Inhalte, Datenbank-Inhalte. Der bastora.de-Server loggt keine Aufrufer-IP. Pro Site-ID akzeptiert der Server maximal einen Eintrag pro Tag (UPSERT, der jeweils neueste Stand bleibt). Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO. Bei Deinstallation des Plugins wird die lokale Site-ID gelöscht.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Wichtige Einordnung zur Quasi-Eindeutigkeit:\u003C\u002Fstrong> Die Kombination aus Plugin-Inventar, Theme-Inventar, jeweiligen Versionen, Hosting-Provider-Slug und Locale ist statistisch sehr individuell. Auch ohne Domain entsteht damit ein „Fingerprint” der Installation. Bastora nutzt die Daten ausschließlich für die anonyme Statistik (häufigste Plugins, häufigste Lücken, Update-Rückstände) und führt die Telemetrie-Datenbank nie mit anderen Datenquellen zusammen. Wenn diese Einordnung für Dich nicht akzeptabel ist, lass das Telemetrie-Häkchen leer , das Plugin funktioniert auch ohne.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Lokale DNS-Anfrage zur Hosting-Provider-Erkennung (nur als Teil der Telemetrie-Funktion)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Wenn die Telemetrie aktiv ist, ermittelt Bastora einmalig den anonymen Hosting-Provider-Slug (z.B. „hetzner”, „ionos”, „kinsta”). Dafür ruft Bastora die lokale PHP-Funktion \u003Ccode>gethostbyaddr()\u003C\u002Fcode> mit der eigenen Server-IP auf, was eine PTR-Anfrage am Resolver des Hosters auslöst. Es geht KEIN Aufruf an einen Bastora-eigenen Server, keine externe API und keine Domain raus, nur die normale lokale Namensauflösung am Hoster-DNS. Das Ergebnis wird 30 Tage in einer WP-Option zwischengespeichert, damit das nur einmal alle 30 Tage passiert. Vor dem Telemetrie-Opt-in läuft auch diese Funktion nicht.\u003C\u002Fp>\n\u003Ch4>Datenschutzhinweis\u003C\u002Fh4>\n\u003Cp>Vollständige Datenschutzerklärung: https:\u002F\u002Fbastora.de\u002Fdatenschutz.php\u003Cbr \u002F>\nVerantwortliche Stelle laut Impressum: https:\u002F\u002Fbastora.de\u002Fimpressum.php\u003C\u002Fp>\n","62-Punkte-Sicherheits-Check mit Firewall, Schadcode-Scanner, URL-Reputation, Captcha, Schwarm-Schutz und Auto-Reparatur der WordPress-Kerndateien.",10,772,0,"2026-07-21T20:46:00.000Z","7.0.2","6.0","7.4",[19,20,21,22,23],"brute-force","firewall","hardening","malware","security","https:\u002F\u002Fbastora.de\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.4.7.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"mathiasva",1,30,94,"2026-08-25T02:42:18.769Z",[38,54,69,81,104],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":13,"downloaded":46,"rating":13,"num_ratings":13,"last_updated":47,"tested_up_to":15,"requires_at_least":48,"requires_php":49,"tags":50,"homepage":52,"download_link":53,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"apta-shield","Apta Shield","1.1.3","Lorenzo Romero","https:\u002F\u002Fprofiles.wordpress.org\u002Fmegapattern\u002F","\u003Cp>Apta Shield is a comprehensive, lightweight, and robust security engine designed to keep your WordPress site safe from modern threats.\u003C\u002Fp>\n\u003Cp>Key Features:\u003Cbr \u002F>\n* \u003Cstrong>Web Application Firewall (WAF)\u003C\u002Fstrong>: Active traffic inspection targeting SQLi, XSS, RCE, and LFI.\u003Cbr \u002F>\n* \u003Cstrong>Brute Force Protection\u003C\u002Fstrong>: Automatic detection and temporary lockout of suspicious IP addresses.\u003Cbr \u002F>\n* \u003Cstrong>URL Obfuscation\u003C\u002Fstrong>: Hide wp-login.php and wp-admin behind a custom secret slug.\u003Cbr \u002F>\n* \u003Cstrong>Security Hardening\u003C\u002Fstrong>: Disable XML-RPC, native code editors, author enumeration, and hide WordPress version.\u003Cbr \u002F>\n* \u003Cstrong>Malware & Integrity Scanner\u003C\u002Fstrong>: Compares local PHP files against official WordPress checksums and scans for heuristic malware signatures.\u003Cbr \u002F>\n* \u003Cstrong>Core Reinstallation\u003C\u002Fstrong>: Reinstall clean core files from WordPress.org in one click if corruption or modifications are found.\u003Cbr \u002F>\n* \u003Cstrong>Audit Log\u003C\u002Fstrong>: Keep track of user activity, login failures, profile updates, and settings modifications.\u003Cbr \u002F>\n* \u003Cstrong>Alert Notifications\u003C\u002Fstrong>: Immediate email alerts for critical security events.\u003C\u002Fp>\n","Premium WordPress security with WAF, brute force block, URL obfuscation, malware scanning, and core reinstallation.",197,"2026-06-24T22:43:00.000Z","5.8","",[19,20,21,51,23],"malware-scanner","https:\u002F\u002Fgithub.com\u002Florenrocu\u002Fapta-shield","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fapta-shield.1.1.3.zip",{"slug":55,"name":56,"version":57,"author":58,"author_profile":59,"description":60,"short_description":61,"active_installs":13,"downloaded":62,"rating":13,"num_ratings":13,"last_updated":63,"tested_up_to":64,"requires_at_least":65,"requires_php":49,"tags":66,"homepage":67,"download_link":68,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"kortech-shieldora","Kortech Shieldora","1.0.0","kolmic1","https:\u002F\u002Fprofiles.wordpress.org\u002Fkolmic1\u002F","\u003Cp>Kortech Shieldora is a high-performance security command center for WordPress. It provides professional-grade protection against modern attack vectors without compromising site performance.\u003C\u002Fp>\n\u003Cp>This plugin focuses on core system integrity and login security, ensuring your WordPress installation is hardened against the most common entry points for hackers.\u003C\u002Fp>\n\u003Cp>Free Core Features:\u003C\u002Fp>\n\u003Cp>Brute-Force Mitigation: Intelligent IP lockouts after repeated failed login attempts to prevent credential stuffing.\u003C\u002Fp>\n\u003Cp>Autonomous Hardening: One-click toggles to disable the built-in file editor and restrict REST API user enumeration.\u003C\u002Fp>\n\u003Cp>Security Command Center: A beautiful, real-time dashboard that calculates a dynamic “System Score” based on your current site configuration.\u003C\u002Fp>\n\u003Cp>Live Audit Logs: Detailed tracking of every blocked threat and system event stored directly in your database.\u003C\u002Fp>\n\u003Cp>Complete Cleanup: Includes a full uninstallation routine to ensure no data is left behind if you ever choose to remove the plugin.\u003C\u002Fp>\n\u003Cp>PRO Intelligence Upgrades:\u003C\u002Fp>\n\u003Cp>For high-traffic businesses and e-commerce stores, Kortech Shieldora PRO offers:\u003C\u002Fp>\n\u003Cp>Anti-Carding Engine: Protect Paystack, Flutterwave, and Stripe gateways from automated checkout bots.\u003C\u002Fp>\n\u003Cp>WhatsApp & SMS 2FA: Military-grade login security using real-time OTP via the Termii API.\u003C\u002Fp>\n\u003Cp>Virtual Patching: Automatically protect your site from known plugin vulnerabilities before updates are released.\u003C\u002Fp>\n\u003Cp>Geo-Fencing: Block traffic from entire high-risk countries to eliminate 90% of global bot noise.\u003C\u002Fp>\n","Enterprise-grade security engine featuring brute-force mitigation, autonomous system hardening, and a real-time command center.",127,"2026-05-19T16:34:00.000Z","6.9.5","5.0",[19,20,21,51,23],"https:\u002F\u002Fkortech.com.ng\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkortech-shieldora.1.0.0.zip",{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":13,"downloaded":77,"rating":13,"num_ratings":13,"last_updated":78,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":79,"homepage":49,"download_link":80,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"totalweb-security-firewall-malware-scanner","TotalWeb – Security, Firewall & Malware Scanner","1.0.1","Pranshtech Solutions Private Limited","https:\u002F\u002Fprofiles.wordpress.org\u002Fpranshtech\u002F","\u003Cp>TotalWeb offers a multi-layered approach to WordPress security, combining advanced protection mechanisms with an intuitive administrative interface. From real-time monitoring to proactive threat detection and prevention, TotalWeb empowers website administrators to maintain a secure online presence.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Ch3>1. Login Security\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Login Attempt Tracking:\u003C\u002Fstrong> Monitors and logs all login attempts, both successful and failed, including IP addresses and usernames.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication (2FA):\u003C\u002Fstrong> Enhances login security using TOTP-based 2FA with WooCommerce support.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP and User Lockouts:\u003C\u002Fstrong> Automatically locks IP addresses and users after a configurable number of failed login attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Log Management:\u003C\u002Fstrong> View, filter, bulk delete, and export login attempt logs to CSV.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>2. CAPTCHA Integration\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Multi-form CAPTCHA Protection:\u003C\u002Fstrong> Adds CAPTCHA to:\n\u003Cul>\n\u003Cli>Login Form  \u003C\u002Fli>\n\u003Cli>Registration Form  \u003C\u002Fli>\n\u003Cli>Lost Password Form  \u003C\u002Fli>\n\u003Cli>Reset Password Form  \u003C\u002Fli>\n\u003Cli>Comment Form  \u003C\u002Fli>\n\u003Cli>WooCommerce Forms  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Supported CAPTCHA Types:\u003C\u002Fstrong> reCAPTCHA v2, reCAPTCHA v3, hCaptcha, and Math CAPTCHA.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Contact Form 7 Integration:\u003C\u002Fstrong> Seamlessly injects CAPTCHA into CF7 forms.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>3. File and Database Security\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Comprehensive File Scanning:\u003C\u002Fstrong> Scans core files, plugins, and themes for modifications, new files, and deletions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled & On-Demand Scans:\u003C\u002Fstrong> Run daily scheduled scans or manual scans anytime.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Monitoring:\u003C\u002Fstrong> Configure file types, exclusions, and email alerts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Integration:\u003C\u002Fstrong> Initiate scans and check status programmatically.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>MD5 Hash Verification:\u003C\u002Fstrong> Detects unauthorized file changes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database Backup & Restore:\u003C\u002Fstrong> Perform manual or automated backups and restore previous versions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database Prefix Change:\u003C\u002Fstrong> Enhances security by changing the WP database prefix.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SQL Injection Protection:\u003C\u002Fstrong> Blocks suspicious queries and monitors DB activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Query Monitoring:\u003C\u002Fstrong> Detects and blocks suspicious SQL patterns.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress Hardening:\u003C\u002Fstrong> Disable insecure WP features such as:\n\u003Cul>\n\u003Cli>File Editor  \u003C\u002Fli>\n\u003Cli>Unfiltered HTML (non-admins)  \u003C\u002Fli>\n\u003Cli>XML-RPC  \u003C\u002Fli>\n\u003Cli>Force SSL  \u003C\u002Fli>\n\u003Cli>Hide WP version  \u003C\u002Fli>\n\u003Cli>Block PHP execution in uploads  \u003C\u002Fli>\n\u003Cli>Block dangerous file types  \u003C\u002Fli>\n\u003Cli>Protect sensitive files (e.g., wp-config.php, .htaccess)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Controls:\u003C\u002Fstrong> Manage security settings and logs via API.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>4. Malware Scanner\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malicious Code Detection:\u003C\u002Fstrong> Scans core, themes, plugins, and uploads for malware signatures.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manual & Scheduled Scans:\u003C\u002Fstrong> Flexible scanning options.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Issue Tracking:\u003C\u002Fstrong> Detects modified, missing, unknown, and infected files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Reports:\u003C\u002Fstrong> Sends alerts when malware is detected.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>5. Firewall\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Web Application Firewall (WAF):\u003C\u002Fstrong> Supports custom regex rules and ModSecurity CRS patterns.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Blacklist\u002FWhitelist:\u003C\u002Fstrong> Block malicious IPs or allow trusted ones.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geo-Blocking:\u003C\u002Fstrong> Restrict access by country.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting & DDoS Protection:\u003C\u002Fstrong> Limits requests per IP.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comment Spam IP Monitoring:\u003C\u002Fstrong> Auto-blocks frequent spam IPs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bad Bot Protection:\u003C\u002Fstrong> Blocks known scrapers and bots.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart 404 Blocking:\u003C\u002Fstrong> Blocks IPs generating excessive 404 errors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>General Firewall Options:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>Disable RSS\u002FATOM feeds  \u003C\u002Fli>\n\u003Cli>Block proxy comment submissions  \u003C\u002Fli>\n\u003Cli>Advanced string filtering  \u003C\u002Fli>\n\u003Cli>Enable 6G Firewall rules  \u003C\u002Fli>\n\u003Cli>Block unauthorized REST requests  \u003C\u002Fli>\n\u003Cli>Block blank user-agent or referrer POST requests  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>6. Redirects\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom 301 Redirects:\u003C\u002Fstrong> Manage permanent redirect rules.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Interface:\u003C\u002Fstrong> Add, edit, and delete redirects easily.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>URL Validation:\u003C\u002Fstrong> Prevents duplicates and formatting issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>7. Security Hardening\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>HTTP Security Headers:\u003C\u002Fstrong> Configure:\n\u003Cul>\n\u003Cli>HSTS  \u003C\u002Fli>\n\u003Cli>X-Frame-Options  \u003C\u002Fli>\n\u003Cli>Content Security Policy (CSP)  \u003C\u002Fli>\n\u003Cli>Referrer-Policy  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Role-Based Access Restrictions:\u003C\u002Fstrong> Limit access to specific plugin features.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-Click Setup Wizard:\u003C\u002Fstrong> Apply recommended hardening automatically.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>8. Audit Logging\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Logs:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>Logins (success\u002Ffailure)\u003C\u002Fli>\n\u003Cli>User profile changes\u003C\u002Fli>\n\u003Cli>Role\u002Fcapability changes\u003C\u002Fli>\n\u003Cli>Plugin\u002Ftheme activation\u002Fdeactivation\u002Fupdates\u003C\u002Fli>\n\u003Cli>Theme switches\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Daily summaries.\u003C\u002Fli>\n\u003Cli>Email alerts for important events.\u003C\u002Fli>\n\u003Cli>Dashboard widget with recent events.\u003C\u002Fli>\n\u003Cli>REST API access to logs.\u003C\u002Fli>\n\u003C\u002Ful>\n","TotalWeb strengthens your site security with malware defense, brute-force protection, firewall rules, and smart hardening controls.",468,"2026-05-21T06:43:00.000Z",[19,20,21,22,23],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftotalweb-security-firewall-malware-scanner.zip",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":89,"downloaded":90,"rating":91,"num_ratings":92,"last_updated":93,"tested_up_to":15,"requires_at_least":94,"requires_php":95,"tags":96,"homepage":99,"download_link":100,"security_score":101,"vuln_count":102,"unpatched_count":13,"last_vuln_date":103,"fetched_at":28},"gotmls","Anti-Malware Security and Brute-Force Firewall","4.23.90","Eli","https:\u002F\u002Fprofiles.wordpress.org\u002Fscheeeli\u002F","\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Download Definition Updates to protect against new threats.\u003C\u002Fli>\n\u003Cli>Run a Complete Scan to automatically remove known security threats, backdoor scripts, and database injections.\u003C\u002Fli>\n\u003Cli>Firewall block SoakSoak and other malware from exploiting Revolution Slider and other plugins with known vulnerabilites.\u003C\u002Fli>\n\u003Cli>Upgrade vulnerable versions of timthumb scripts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Premium Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Patch your wp-login and XMLRPC to block Brute-Force and DDoS attacks.\u003C\u002Fli>\n\u003Cli>Check the integrity of your WordPress Core files.\u003C\u002Fli>\n\u003Cli>Automatically download new Definition Updates when running a Complete Scan.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Register this plugin at \u003Ca href=\"http:\u002F\u002Fgotmls.net\u002F\" rel=\"nofollow ugc\">GOTMLS.NET\u003C\u002Fa> and get access to new definitions of “Known Threats” and added features like Automatic Removal, plus patches for specific security vulnerabilities like old versions of timthumb. Updated definition files can be downloaded automatically within the admin once your Key is registered. Otherwise, this plugin just scans for “Potential Threats” and leaves it up to you to identify and remove the malicious ones.\u003C\u002Fp>\n\u003Cp>NOTICE: This plugin makes calls to GOTMLS.NET to check for updates not unlike what WordPress does when checking your plugins and themes for new versions. Staying up-to-date is an essential part of any security plugin and this plugin can let you know when there are new plugin and definition update available. If you’re allergic to “phone home” scripts then don’t use this plugin (or WordPress at all for that matter).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Special thanks to:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Clarus Dignus for design suggestions and graphic design work on the banner image.\u003C\u002Fli>\n\u003Cli>Jelena Kovacevic and Andrew Kurtis of webhostinghub.com for providing the Spanish translation.\u003C\u002Fli>\n\u003Cli>Marcelo Guernieri for the Brazilian Portuguese translation.\u003C\u002Fli>\n\u003Cli>Umut Can Alparslan for the Turkish translation.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fmichacassola\u002F\" rel=\"nofollow ugc\">Micha Cassola\u003C\u002Fa> for the German translation.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fsitustarget\u002F\" rel=\"nofollow ugc\">Robi Erwin Setiawan\u003C\u002Fa> for the Indonesian translation.\u003C\u002Fli>\n\u003C\u002Ful>\n","This Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it helps you fix them.",100000,7863436,98,783,"2026-06-29T17:58:00.000Z","3.3","5.6",[97,19,20,98,23],"anti-malware","scanner","https:\u002F\u002Fgotmls.net\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgotmls.4.23.90.zip",81,11,"2026-07-09 00:00:00",{"slug":105,"name":106,"version":107,"author":108,"author_profile":109,"description":110,"short_description":111,"active_installs":112,"downloaded":113,"rating":26,"num_ratings":114,"last_updated":115,"tested_up_to":64,"requires_at_least":65,"requires_php":17,"tags":116,"homepage":118,"download_link":119,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wp-admin-protect","Protector – Malware Removal, Firewall & Core Repair","4.0.4","Marcello Ruoppolo","https:\u002F\u002Fprofiles.wordpress.org\u002Fmarcelloruoppolome\u002F","\u003Cp>Every day, thousands of WordPress sites are hacked. Most security plugins offer protection, but they come with a massive cost: they slow down your server with bloated features and complex settings.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protector is different.\u003C\u002Fstrong> It is a lightweight, AI-ready security layer that turns your WordPress site into a digital fortress without compromising speed. Whether you are trying to recover a hacked site or proactively defend your business, Protector delivers enterprise-grade security that anyone can configure.\u003C\u002Fp>\n\u003Cp>With our new \u003Cstrong>1-Click Security Overview Dashboard\u003C\u002Fstrong>, you can activate all recommended protections and block 98% of automated attacks in under 8 seconds.\u003C\u002Fp>\n\u003Cp>📖 \u003Cstrong>\u003Ca href=\"https:\u002F\u002Fkloxstudios.com\u002Fdocumentation\u002Fprotector\u002F\" rel=\"nofollow ugc\">Read the Official Documentation here\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>🦠 Malware Threat Scanner & Auto-Repair\u003C\u002Fh3>\n\u003Cp>Don’t just find malware; destroy it. Our deep, recursive local scanner verifies your WordPress integrity without crashing your server:\u003Cbr \u002F>\n* \u003Cstrong>Core Integrity Verification:\u003C\u002Fstrong> Cross-references all Core files against the official WordPress.org checksums.\u003Cbr \u002F>\n* \u003Cstrong>Advanced Pattern Detection:\u003C\u002Fstrong> Detects suspicious code patterns (like \u003Ccode>eval\u003C\u002Fcode>, \u003Ccode>base64_decode\u003C\u002Fcode>, \u003Ccode>shell_exec\u003C\u002Fcode>) hidden in your files.\u003Cbr \u002F>\n* \u003Cstrong>1-Click Auto-Repair:\u003C\u002Fstrong> Found a modified core file? Click “Repair” and Protector will automatically fetch a clean, original version directly from the official WP SVN and overwrite the infected file.\u003C\u002Fp>\n\u003Ch3>🛡️ Login Fortress (Brute-Force Protection)\u003C\u002Fh3>\n\u003Cp>Hackers relentlessly target the \u003Ccode>wp-login.php\u003C\u002Fcode> page. We make it disappear.\u003Cbr \u002F>\n* \u003Cstrong>Secret Login URL:\u003C\u002Fstrong> Hide \u003Ccode>wp-login.php\u003C\u002Fcode> completely. Any unauthorized attempt will be instantly redirected to a custom URL of your choice.\u003Cbr \u002F>\n* \u003Cstrong>Smart Honeypots:\u003C\u002Fstrong> Inject invisible fields into your login and comment forms to trap and block spam\u002Fbrute-force bots automatically.\u003Cbr \u002F>\n* \u003Cstrong>Block Username Scanning:\u003C\u002Fstrong> Prevent attackers from discovering your admin usernames via \u003Ccode>?author=1\u003C\u002Fcode> enumeration.\u003C\u002Fp>\n\u003Ch3>🔒 1-Click Site Hardening\u003C\u002Fh3>\n\u003Cp>Lock down common vulnerabilities instantly:\u003Cbr \u002F>\n* \u003Cstrong>Security Headers:\u003C\u002Fstrong> Protect against XSS, Clickjacking, and MIME-Sniffing attacks with a single toggle.\u003Cbr \u002F>\n* \u003Cstrong>XML-RPC Control:\u003C\u002Fstrong> Disable XML-RPC completely to eliminate one of the biggest brute-force attack vectors on WordPress.\u003Cbr \u002F>\n* \u003Cstrong>Version Obfuscation:\u003C\u002Fstrong> Hide your WordPress version from the source code so hackers can’t target known exploits.\u003Cbr \u002F>\n* \u003Cstrong>Restrict REST API:\u003C\u002Fstrong> Block public access to endpoints that expose sensitive user data.\u003C\u002Fp>\n\u003Ch3>📊 Live Attack Log\u003C\u002Fh3>\n\u003Cp>Peace of mind you can actually see. Monitor every blocked attack, triggered honeypot, and deleted malware in real-time straight from your dashboard.\u003C\u002Fp>\n\u003Ch3>🚀 Upgrade to KloxStudios Pro\u003C\u002Fh3>\n\u003Cp>Need absolute maximum power? Protector integrates seamlessly with the KloxStudios Cloud AI. Pro users unlock Cloud AI Malware Verification for 3rd-party plugins\u002Fthemes, Automatic IP Lockouts, Instant Admin Login Alerts (Email & Webhook), and 2FA.\u003C\u002Fp>\n","Protect your WordPress. The ultimate lightweight security suite. Block brute-force attacks, auto-repair infected core files, hide your login URL, set  &hellip;",200,5920,3,"2026-04-30T17:39:00.000Z",[19,20,51,117,23],"repair-core","https:\u002F\u002Fkloxstudios.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-admin-protect.4.0.4.zip",{"error":121,"url":122,"statusCode":123,"statusMessage":124,"message":124},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fbastora-security-audit\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":126,"versions":127},17,[128,134,141,148,155,162,169,176,183,190,197,204,211,218,225,232,239],{"version":6,"download_url":25,"svn_tag_url":129,"released_at":27,"has_diff":130,"diff_files_changed":131,"diff_lines":27,"trac_diff_url":132,"vulnerabilities":133,"is_current":121},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.4.7\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F1.4.6&new_path=%2Fbastora-security-audit%2Ftags%2F1.4.7",[],{"version":135,"download_url":136,"svn_tag_url":137,"released_at":27,"has_diff":130,"diff_files_changed":138,"diff_lines":27,"trac_diff_url":139,"vulnerabilities":140,"is_current":130},"1.4.6","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.4.6.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.4.6\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F1.3.8&new_path=%2Fbastora-security-audit%2Ftags%2F1.4.6",[],{"version":142,"download_url":143,"svn_tag_url":144,"released_at":27,"has_diff":130,"diff_files_changed":145,"diff_lines":27,"trac_diff_url":146,"vulnerabilities":147,"is_current":130},"1.3.8","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.3.8.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.3.8\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F1.3.6&new_path=%2Fbastora-security-audit%2Ftags%2F1.3.8",[],{"version":149,"download_url":150,"svn_tag_url":151,"released_at":27,"has_diff":130,"diff_files_changed":152,"diff_lines":27,"trac_diff_url":153,"vulnerabilities":154,"is_current":130},"1.3.6","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.3.6.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.3.6\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F1.3.0&new_path=%2Fbastora-security-audit%2Ftags%2F1.3.6",[],{"version":156,"download_url":157,"svn_tag_url":158,"released_at":27,"has_diff":130,"diff_files_changed":159,"diff_lines":27,"trac_diff_url":160,"vulnerabilities":161,"is_current":130},"1.3.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.3.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.3.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F1.2.9&new_path=%2Fbastora-security-audit%2Ftags%2F1.3.0",[],{"version":163,"download_url":164,"svn_tag_url":165,"released_at":27,"has_diff":130,"diff_files_changed":166,"diff_lines":27,"trac_diff_url":167,"vulnerabilities":168,"is_current":130},"1.2.9","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.2.9.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.2.9\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F1.2.8&new_path=%2Fbastora-security-audit%2Ftags%2F1.2.9",[],{"version":170,"download_url":171,"svn_tag_url":172,"released_at":27,"has_diff":130,"diff_files_changed":173,"diff_lines":27,"trac_diff_url":174,"vulnerabilities":175,"is_current":130},"1.2.8","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.2.8.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.2.8\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F1.2.7&new_path=%2Fbastora-security-audit%2Ftags%2F1.2.8",[],{"version":177,"download_url":178,"svn_tag_url":179,"released_at":27,"has_diff":130,"diff_files_changed":180,"diff_lines":27,"trac_diff_url":181,"vulnerabilities":182,"is_current":130},"1.2.7","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.2.7.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.2.7\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F1.2.5&new_path=%2Fbastora-security-audit%2Ftags%2F1.2.7",[],{"version":184,"download_url":185,"svn_tag_url":186,"released_at":27,"has_diff":130,"diff_files_changed":187,"diff_lines":27,"trac_diff_url":188,"vulnerabilities":189,"is_current":130},"1.2.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.1.2.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F1.2.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F0.3.0&new_path=%2Fbastora-security-audit%2Ftags%2F1.2.5",[],{"version":191,"download_url":192,"svn_tag_url":193,"released_at":27,"has_diff":130,"diff_files_changed":194,"diff_lines":27,"trac_diff_url":195,"vulnerabilities":196,"is_current":130},"0.3.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.0.3.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F0.3.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F0.2.9&new_path=%2Fbastora-security-audit%2Ftags%2F0.3.0",[],{"version":198,"download_url":199,"svn_tag_url":200,"released_at":27,"has_diff":130,"diff_files_changed":201,"diff_lines":27,"trac_diff_url":202,"vulnerabilities":203,"is_current":130},"0.2.9","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.0.2.9.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F0.2.9\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F0.2.7&new_path=%2Fbastora-security-audit%2Ftags%2F0.2.9",[],{"version":205,"download_url":206,"svn_tag_url":207,"released_at":27,"has_diff":130,"diff_files_changed":208,"diff_lines":27,"trac_diff_url":209,"vulnerabilities":210,"is_current":130},"0.2.7","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.0.2.7.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F0.2.7\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F0.2.6&new_path=%2Fbastora-security-audit%2Ftags%2F0.2.7",[],{"version":212,"download_url":213,"svn_tag_url":214,"released_at":27,"has_diff":130,"diff_files_changed":215,"diff_lines":27,"trac_diff_url":216,"vulnerabilities":217,"is_current":130},"0.2.6","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.0.2.6.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F0.2.6\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F0.2.5&new_path=%2Fbastora-security-audit%2Ftags%2F0.2.6",[],{"version":219,"download_url":220,"svn_tag_url":221,"released_at":27,"has_diff":130,"diff_files_changed":222,"diff_lines":27,"trac_diff_url":223,"vulnerabilities":224,"is_current":130},"0.2.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.0.2.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F0.2.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F0.2.4&new_path=%2Fbastora-security-audit%2Ftags%2F0.2.5",[],{"version":226,"download_url":227,"svn_tag_url":228,"released_at":27,"has_diff":130,"diff_files_changed":229,"diff_lines":27,"trac_diff_url":230,"vulnerabilities":231,"is_current":130},"0.2.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.0.2.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F0.2.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F0.2.3&new_path=%2Fbastora-security-audit%2Ftags%2F0.2.4",[],{"version":233,"download_url":234,"svn_tag_url":235,"released_at":27,"has_diff":130,"diff_files_changed":236,"diff_lines":27,"trac_diff_url":237,"vulnerabilities":238,"is_current":130},"0.2.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.0.2.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F0.2.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fbastora-security-audit%2Ftags%2F0.2.2&new_path=%2Fbastora-security-audit%2Ftags%2F0.2.3",[],{"version":240,"download_url":241,"svn_tag_url":242,"released_at":27,"has_diff":130,"diff_files_changed":243,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":244,"is_current":130},"0.2.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbastora-security-audit.0.2.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbastora-security-audit\u002Ftags\u002F0.2.2\u002F",[],[]]