[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZXnNhVtdIWJCDQ3TynCb8WL9Y0vrtO7a1QQJBixE5vE":3,"$f4Wztuk2sov2mcHDpzHkSDLnRd5sSQ2_E6JqBa_JmL4M":141,"$ft7-mLi3SiXIUr7THwyXyy27IwVPMI4DvmSzyjbYi0WA":146},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"catcher24-connector","Catcher24 Connector – Vulnerability Scanner","1.0.0","Catcher24","https:\u002F\u002Fprofiles.wordpress.org\u002Fcatcherdev\u002F","\u003Cp>The \u003Cstrong>Catcher24 Vulnerability Scanner\u003C\u002Fstrong> provides an automated, enterprise-grade security audit for your WordPress installation. Designed for IT teams, developers, and security-conscious site owners, this lightweight connector bridges your WordPress environment with Catcher24’s powerful external scanning infrastructure.\u003Cbr \u002F>\nInstead of running heavy, resource-intensive scans locally on your web server – which can slow down site performance and degrade the user experience – our plugin acts as a secure conduit. It triggers on-demand, cloud-based assessments to identify critical security flaws.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Core Capabilities:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Targeted CMS Vulnerability Detection:\u003C\u002Fstrong> Identifies vulnerable, outdated plugins, themes, and WordPress core versions using continuously updated threat intelligence templates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>External Exposure Checks:\u003C\u002Fstrong> Performs a non-intrusive perimeter check to discover exposed services or database ports that should not be publicly accessible.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Minimal-Impact Auditing:\u003C\u002Fstrong> Black-box scanning is performed entirely on Catcher24’s infrastructure, ensuring minimal performance impact on your WordPress host.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Centralized Reporting:\u003C\u002Fstrong> View high-level scan results directly within your WordPress admin dashboard, with deep-dive technical reports and remediation steps available in the Catcher24 dashboard.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>How It Works:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>On-Demand Scanning:\u003C\u002Fstrong> Start a deep, non-intrusive scan of your WordPress environment directly from your dashboard. The scan is executed by the Catcher24 platform against the specific target you created for your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Live Progress Tracking:\u003C\u002Fstrong> While the scan is running remotely, a lightweight WebSocket connection provides real-time progress updates directly in your WordPress UI.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Direct Results:\u003C\u002Fstrong> Once the scan is complete, the plugin pulls a high-level overview of the results straight from the Catcher24 API. No continuous background communication is needed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Deep Analysis:\u003C\u002Fstrong> You can easily jump from the plugin into the Catcher24 platform to view the full, detailed results of any vulnerabilities, CVEs, or security threats found.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> This plugin requires an active Catcher24 account. The plugin initiates the scans and fetches the results, while all actual scanning operations occur safely and efficiently on the Catcher24 cloud.\u003C\u002Fp>\n\u003Ch3>Pricing and Licensing\u003C\u002Fh3>\n\u003Cp>The \u003Cstrong>Catcher24 Connector\u003C\u002Fstrong> plugin and all its integrated functionality are completely \u003Cstrong>free to use\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Upon registering for a Catcher24 account—available via email, password, or social login—you automatically receive \u003Cstrong>one free WordPress target\u003C\u002Fstrong>, allowing a single WordPress site to be scanned at no cost.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Upgrade Path:\u003C\u002Fstrong>\u003Cbr \u002F>\nThe plugin provides on-demand vulnerability scanning for new users. To unlock continuous scheduled scanning, DNS configuration auditing (SPF\u002FDKIM\u002FDMARC), and proactive SSL certificate monitoring, users can upgrade their target configuration within the Catcher24 dashboard.\u003Cbr \u002F>\nNote: The free WordPress target is an introductory tier. Existing Catcher24 SaaS users cannot add a free target via the plugin.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>If you encounter any issues connecting your site to Catcher24 or running a scan, we are here to help.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Documentation:\u003C\u002Fstrong> Visit our full documentation at \u003Ca href=\"https:\u002F\u002Fhelp.catcher24.net\u002F\" rel=\"nofollow ugc\">our help desk\u003C\u002Fa> for detailed setup guides and troubleshooting.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy & Data Usage\u003C\u002Fh3>\n\u003Cp>Transparency and data security are our top priorities. Because the Catcher24 Connector integrates with an external cloud service, here is exactly how your data is handled:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>No Background Tracking:\u003C\u002Fstrong> The plugin does not continuously track user activity, visitor data, or stream telemetry in the background.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>On-Demand Execution:\u003C\u002Fstrong> Communication with the Catcher24 API only occurs when you explicitly initiate a scan from your WordPress dashboard, or when the plugin fetches the results of that scan.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan Data:\u003C\u002Fstrong> During an active scan, the Catcher24 platform analyzes your site’s public-facing endpoints and structural data (like plugin versions and core files) to identify vulnerabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Storage:\u003C\u002Fstrong> Scan results and vulnerability reports are stored securely in your Catcher24 cloud account.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the external Catcher24 platform (including its API gateway and Keycloak authentication service) to perform on-demand vulnerability scans and retrieve security reports for your site.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Free Account Authentication:\u003C\u002Fstrong> The user signs into Catcher24 with a free account. During this process, standard user profile details (email, first name, last name) are authenticated securely.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Target Registration:\u003C\u002Fstrong> Once signed in, the user is asked to create a target. The WordPress site’s hostname and site name are prefilled for convenience.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Background Transmission:\u003C\u002Fstrong> No data is sent to the Catcher24 platform without the user explicitly clicking a button or initiating the connection process. No visitor data or continuous server metrics are ever tracked in the background.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time Synchronization:\u003C\u002Fstrong> When a target is selected, the plugin establishes a WebSocket connection to monitor changes for that target in the Catcher24 platform and automatically refresh the dashboard details.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider:\u003C\u002Fstrong> Catcher24.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Links:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>Terms and Conditions: \u003Ca href=\"https:\u002F\u002Fcatcher24.com\u002Fterms-and-conditions\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fcatcher24.com\u002Fterms-and-conditions\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Privacy Policy: \u003Ca href=\"https:\u002F\u002Fcatcher24.com\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fcatcher24.com\u002Fprivacy-policy\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Development\u003C\u002Fh3>\n\u003Cp>The source code for this plugin is managed in a public GitHub repository.\u003Cbr \u002F>\nYou can view the development history, report issues, and access the raw\u003Cbr \u002F>\nsource files (including build scripts) here:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fcatcher24\u002FWordpressConnector\" rel=\"nofollow ugc\">https:\u002F\u002Fgithub.com\u002Fcatcher24\u002FWordpressConnector\u003C\u002Fa>\u003C\u002Fp>\n","Connect your WordPress site to Catcher24 for automated vulnerability scanning and security analysis with minimal performance impact.",0,176,"2026-06-19T12:59:00.000Z","7.0.2","6.5","7.4",[18,19,20,21,22],"cve","port-scanner","security","security-audit","vulnerability-scanner","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcatcher24-connector.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"catcherdev",1,30,94,"2026-08-29T04:05:02.327Z",[37,61,85,109,126],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":14,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":56,"download_link":57,"security_score":58,"vuln_count":59,"unpatched_count":11,"last_vuln_date":60,"fetched_at":27},"wp-malware-removal","Malcure Malware Shield — Removal, Repair, Monitor","19.9.6","Malcure Web Security","https:\u002F\u002Fprofiles.wordpress.org\u002Fmalcure\u002F","\u003Cp>Is your website acting strangely? Seeing ‘Deceptive Site Ahead’ warnings, Japanese SEO hack, or random redirects? Time to fix and monitor your site with \u003Cstrong>Malcure Malware Shield\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Malcure Malware Shield scans for infections, runs silent scheduled scans, and sends alerts before threats spread — turning one-time cleanup into always-on protection.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Malcure scans files, databases, and user accounts to find malware casual scanners miss — backdoors hidden in images, injections in your database, rogue, hidden admin accounts buried in your tables that don’t show up in the admin area. Then it watches your site with scheduled scans and alerts, so one-time cleanup becomes always-on protection.\u003C\u002Fp>\n\u003Cp>Detection runs against 50,000+ signatures with real-time threat intelligence — the same definitions for every user, free or paid. You see every infection with exact file paths and line numbers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Activate \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Know \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>What Our Users Say\u003C\u002Fh3>\n\u003Cp>Quotes are verbatim from WordPress.org support reviews, except for bracketed edits (for example, competitor names removed).\u003C\u002Fp>\n\u003Ch4>Best by far, better than [competitor name removed] and other giants\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“You can see it is a bunch of geeks that created this, with skill and visual creativity at that. I spent hours trying to find a plugin like this. So many options and such bad results until now. Great job guys. You deserve it. Simple and effective. (Disclaimer to other potential readers: there are many types of hacks\u002Fmalware out there, every scenario is different, but start with the Malcure scan and see how it goes. 9\u002F10 you won’t be disappointed, my guess)” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-by-far-better-than-wordfence-and-other-giants\u002F\" rel=\"ugc\">@dalingzaf\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>The ONLY plugin that scans every file-type…\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“I am a web developer and have tried many malware removal plugins, including popular ones [competitor names removed]. However, none of them detected some unusual files that were actually malware causing regular attacks. Some of these files were in JPG format.” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fthe-only-plugin-that-scans-files-in-real-time-2\u002F\" rel=\"ugc\">@devzeeshanx\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>Best Malware Removal Plugin in just few minutes\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“Most security plugins that are free only scan the code, but Malcure Malware Removal Plugin scans the wordpress database and the code files in few minutes. Accurately shows which Database table row is infected and it helps resolve the hacking attempt instantly. Saves a lot of time for the developers. Thank You Team Malcure” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-malware-removal-plugin-in-just-few-minutes\u002F\" rel=\"ugc\">@s3630\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>It’s not just a “teaser”\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“This plugin really found the malware, and removed it. Really for free. Thanks guys, I’m going to donate now!” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fits-not-just-a-teaser\u002F\" rel=\"ugc\">@halucska\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>What Malcure Does\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Detection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>File Scan:\u003C\u002Fstrong> Core files, themes, plugins, images, uploads — backdoors, shells, obfuscated code, and malware hidden inside image files and archives.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database Scan:\u003C\u002Fstrong> Finds malicious injections, recurring malware, and SEO injection links that other non-thorough scanners never see.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Scan:\u003C\u002Fstrong> Detects rogue admin accounts and compromised metadata, including application passwords that bypass your login page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DeepScan™:\u003C\u002Fstrong> Scans every file-type without skipping within resource-limits and hidden files where malware hides.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checksum Verification:\u003C\u002Fstrong> Compares your core, plugin, and theme files against official repository checksums. Tampered files are flagged by severity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Hack Detection:\u003C\u002Fstrong> Catches Japanese Keyword Hack, Pharma Hack, and other SEO hacks in page titles and database records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Scanner:\u003C\u002Fstrong> Checks installed plugins and themes against a real-time vulnerability database.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checksum Intelligence:\u003C\u002Fstrong> Checksum-based verification reduces false alarms compared to heuristic-only scanners.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>50,000+ Signatures:\u003C\u002Fstrong> Detects known variants — C99, R57, RootShell, and many more — plus unknown threats via behavioral analysis.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Monitoring & Alerts\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scheduled Scans:\u003C\u002Fstrong> Set a cadence — daily, weekly, or monthly. Runs silently in the background.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Weekly Security Pulse Email:\u003C\u002Fstrong> A verdict-first security-critical weekly summary — gives you a heads-up — “All Clear”, “Please Review”, or “Needs Immediate Attention” — delivered to your inbox. Covers scan results, failed logins, privileged activity, file edits, and updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled Scan Results Email:\u003C\u002Fstrong> Email report of scheduled scans — clean or infected. Know immediately when a scheduled scan finishes. Gives you early heads-up if malware found and before it spreads and affects SEO or gets the site blacklisted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Recipients:\u003C\u002Fstrong> Choose who gets notified. Licensee, Registrant and additional CC recipients. Send a test Pulse to verify your mail configuration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Event Log:\u003C\u002Fstrong> 100-day forensic record of every security event for root-cause analysis.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Inspector:\u003C\u002Fstrong> See who’s logged in — IP, user-agent, login time, and session expiration.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Hardening & Firewall\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Block Path Traversal:\u003C\u002Fstrong> Stops attackers from accessing sensitive system files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block PHP Uploads:\u003C\u002Fstrong> Prevents malicious scripts from being uploaded.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stop User Enumeration:\u003C\u002Fstrong> Blocks bots from fishing for usernames.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Protection:\u003C\u002Fstrong> Prevents user data leakage via the WP REST API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack Counter:\u003C\u002Fstrong> See how many attacks the firewall has blocked, right on your dashboard.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Incident Response\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Session Nuke:\u003C\u002Fstrong> Force-logout every user instantly to kick out intruders.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Salt Shuffler:\u003C\u002Fstrong> One-click rotation of \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5230\" rel=\"nofollow ugc\">security keys (salts)\u003C\u002Fa> to invalidate all browser cookies.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Real-Time Threat Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero-Day:\u003C\u002Fstrong> Threat definitions served in real time via the Malcure Cloud. No days-long delay.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Search Console:\u003C\u002Fstrong> Connect directly to fetch security warnings and blacklist status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> Scans send file checksums and your site’s domain to Malcure servers. No sensitive user data is transmitted. Use of the API is subject to our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=1720\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=3\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight:\u003C\u002Fstrong> Runs only on demand or on schedule. No persistent background processes. No bloat.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Dashboard & Experience\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Dashboard Widget:\u003C\u002Fstrong> At-a-glance malware status, attack count, and quick-scan CTA on the WP dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Skins:\u003C\u002Fstrong> Classic and Dark skins to match your workflow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan Completion Audio Preferences:\u003C\u002Fstrong> Configure sound-notifications for scans.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Diagnostics Page:\u003C\u002Fstrong> Environment diagnostics for troubleshooting.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Who This Plugin Is For\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Agencies and developers\u003C\u002Fstrong> who need fast triage across multiple sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce, membership, and lead-gen sites\u003C\u002Fstrong> where downtime and SEO damage are expensive.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> who want clear results — what was flagged, exactly where.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works (Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Review \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Clean \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Scan\u003C\u002Fstrong> — Open \u003Cstrong>Malcure Scanner\u003C\u002Fstrong> in your Admin Dashboard. Run a scan to check files, database, users, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Review\u003C\u002Fstrong> — Every finding comes with an exact location: file path, line number, or database record. Decide what to repair, delete, or keep.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean & Recover\u003C\u002Fstrong> — Shows every infection so you can clean it yourself. Advanced Edition adds repair tools, file operations, whitelisting, and WP-CLI automation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Monitor\u003C\u002Fstrong> — Set up scheduled scans. Get email alerts the moment a threat is found.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Is It Free?\u003C\u002Fh4>\n\u003Cp>We believe in 100% transparency.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Professional-grade Detection (Knowledge). You see every infected file and database row (exact file path & line number), so you can clean it yourself for free.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Real-time Threat Intelligence, Scheduled Scans, Weekly Security Pulse email, and Firewall & Hardening.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pro Upgrade:\u003C\u002Fstrong> File Repairs, Deletions, Whitelisting, Advanced Scan Filters, WP-CLI Automation, Auto-Definition Updates, Bulk Client-Servicing Features & Premium Support (Expertise).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>You are never forced to pay to \u003Cem>find\u003C\u002Fem> a hack.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FEbSbxiTOc8k?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Advanced Edition\u003C\u002Fh4>\n\u003Cp>For when detection is not enough — you need to remediate.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>1-Click Repairs:\u003C\u002Fstrong> Repair infected files from the official source via Malcure Cloud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Delete Files:\u003C\u002Fstrong> Remove infected or irreparable files directly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File & DB Whitelisting:\u003C\u002Fstrong> Suppress alarms on specific files and database records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI Integration:\u003C\u002Fstrong> Full command-line control — async scans, definitions sync, checksum refresh, reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Definition Updates:\u003C\u002Fstrong> Hourly cron keeps definitions current without manual intervention.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Scan Filters:\u003C\u002Fstrong> Include or exclude directories, custom regex signatures for database and files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Inspector:\u003C\u002Fstrong> Inspect files inline instead of having to go via s\u002Fftp or ssh or file-managers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Copy Scan Results:\u003C\u002Fstrong> Copy results to clipboard for client reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP Config & Diagnostics:\u003C\u002Fstrong> View full PHP configuration in diagnostics.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Factory Reset:\u003C\u002Fstrong> One-click plugin reset.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Premium Support:\u003C\u002Fstrong> Direct access to our security analysts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116\" rel=\"nofollow ugc\">\u003Cstrong>Get Malcure Advanced Edition\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Expert Malware Removal Service\u003C\u002Fh4>\n\u003Cp>In over your head? Our security analysts will clean your site for you — 100% removal guarantee, same-day service, blacklist removal, and 15-day post-cleanup cover.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">\u003Cstrong>Book Expert Malware Removal\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Troubleshooting\u003C\u002Fh3>\n\u003Ch4>Some files are detected by Malcure Malware Shield as “suspicious”. What gives?\u003C\u002Fh4>\n\u003Cp>Malcure’s DeepScan checks each file for malware. However some files aren’t pure malware but may contain code that is suspicious and could potentially do nasty things. You should carefully review and analyse them to see if they indeed do anything nasty.\u003C\u002Fp>\n\u003Ch4>I can’t get Malcure Malware Shield to work. It hangs \u002F doesn’t complete the scan \u002F breaks for some reason.\u003C\u002Fh4>\n\u003Cp>If you think that the plugin is broken, \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Malcure Malware Shield (or for that matter other plugins) may break on malware affected \u002F broken websites. \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116\" rel=\"nofollow ugc\">Malcure Advanced Edition\u003C\u002Fa> integrates with WP CLI and allows you to complete the scan from WP CLI even when the site is blocked by the webhost or when you are unable to login to the website.\u003C\u002Fp>\n\u003Ch4>My site is infected however Malcure Malware Shield doesn’t detect the infection.\u003C\u002Fh4>\n\u003Cp>Malware keeps evolving. If you come across malware that Malcure Malware Shield is not able to identify, you may \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=157\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>The scan gets stuck midway. What should I do?\u003C\u002Fh4>\n\u003Cp>In case of such an event, please file a support request with us and we’ll be more than happy to troubleshoot the issue.\u003C\u002Fp>\n\u003Cp>Please visit \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677\" rel=\"nofollow ugc\">this page\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I cleaned my site but it got infected again. What should I do?\u003C\u002Fh4>\n\u003Cp>Malware cleanup is a waste of time and effort unless you find the root cause behind the malware infection and monitor for recurrence. How was someone able to infect your website? Have you plugged in that security hole?\u003C\u002Fp>\n\u003Cp>Please read \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002Fblog\u002Fsecurity\u002Fwhy-do-wordpress-websites-get-hacked\u002F\" rel=\"nofollow ugc\">Why Do Websites Get Hacked\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Google Safe Browsing site status (or some other scanner) still shows my site as infected. What should I do?\u003C\u002Fh4>\n\u003Cp>First make sure you purge your site cache. Second, Google (and other scanners) cache the results for some time. You’ll need to force or refresh the scan. You can also file a request with us to \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">get your site off any blacklists\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I found a suspicious file, what now?\u003C\u002Fh4>\n\u003Cp>If Malcure flags it, it’s likely malicious. You can inspect the file content using our built-in inspector. If you’re unsure, consider our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">Expert Malware Removal Service\u003C\u002Fa>.\u003C\u002Fp>\n","Your WordPress site hacked? Malcure scans files AND database to find and help you remove malware casual scanners miss. Free. No bloat.",10000,662306,90,72,"2026-07-14T03:24:00.000Z","6.2","5.6",[53,54,20,55,22],"antivirus","malware-scanner","virus","https:\u002F\u002Fmalcure.com\u002F?p=116","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-malware-removal.19.9.6.zip",96,3,"2025-09-03 00:00:00",{"slug":62,"name":63,"version":64,"author":65,"author_profile":66,"description":67,"short_description":68,"active_installs":69,"downloaded":70,"rating":71,"num_ratings":72,"last_updated":73,"tested_up_to":14,"requires_at_least":51,"requires_php":74,"tags":75,"homepage":80,"download_link":81,"security_score":82,"vuln_count":83,"unpatched_count":11,"last_vuln_date":84,"fetched_at":27},"sitelock","SiteLock Security – WP Hardening, Login Security & Malware Scans","5.1.2","SiteLock","https:\u002F\u002Fprofiles.wordpress.org\u002Fsitelocksecurity\u002F","\u003Cblockquote>\n\u003Cp>\u003Cstrong>🌟 Completely redesigned in Version 5.0 — now even stronger with 2FA in 5.1 🌟\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The SiteLock WordPress plugin was recently rebuilt with three goals: make it faster, make it clearer and move the heavy work to the cloud. We built a cloudfirst architecture, modernized UI, expanded security controls and stripped out everything that didn’t need to be there. Our latest 5.1 release builds on that foundation with TwoFactor Authentication (2FA) to strengthen login security and give you tighter control over access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>The big changes:\u003C\u002Fstrong>\u003Cbr \u002F>\n  – 🔒 Enhanced WordPress-specific hardening and login security controls\u003Cbr \u002F>\n  – ☁️ Cloud-powered scanning architecture for zero performance impact\u003Cbr \u002F>\n  – 🩺 New Site Health interface that shows you what matters in one view\u003Cbr \u002F>\n  – ⚡ Streamlined controls (fewer clicks to get protected)\u003Cbr \u002F>\n  – ✨ Modern codebase built for the WordPress you’re actually using today\u003Cbr \u002F>\n  – 🔢 Two-Factor Authentication (2FA) now available for stronger login protection\u003C\u002Fp>\n\u003Cp>If you used the old plugin: this is a different tool. If you’re new: you’re starting with the cleanest, fastest version of the plugin.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>Your website deserves protection that’s simple, fast and built for WordPress. SiteLock WordPress Security focuses on the everyday controls that matter most and helps you establish a secure baseline in minutes — WordPress-specific hardening, login protection with Two-Factor Authentication (2FA) and a clear Site Health dashboard that keeps you in control without slowing your site down. It’s lightweight, action-first protection that complements your host defenses: essential safeguards run inside WordPress while deeper checks happen securely in the SiteLock cloud. Skip heavy on-server scans and alert fatigue — run on-demand checks when you need extra assurance, so you can ship updates with confidence.\u003C\u002Fp>\n\u003Ch4>Security that grows with you\u003C\u002Fh4>\n\u003Cp>Our goal is straightforward: maintain a strong baseline with minimal overhead while giving you clear visibility and room to grow as your needs evolve.\u003Cbr \u002F>\nAnd because security is never static, this plugin keeps pace. Two-Factor Authentication (2FA) is now available to strengthen login security with an extra layer of protection.\u003C\u002Fp>\n\u003Ch4>Commercial plugin\u003C\u002Fh4>\n\u003Cp>This plugin is free but offers additional paid commercial upgrades or support.\u003C\u002Fp>\n\u003Ch3>What’s included\u003C\u002Fh3>\n\u003Ch4>WordPress Hardening: Cut common attack paths in just a few clicks\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Disable directory listing\u003C\u002Fli>\n\u003Cli>Restrict PHP execution in upload folders\u003C\u002Fli>\n\u003Cli>Limit unsafe script types\u003C\u002Fli>\n\u003Cli>Force strong configuration defaults to close risky gaps\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>All options are toggle-based and reversible — safe to enable, easy to test and lightweight on performance.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch4>Login Security: Protect what matters most — your access\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong>: Add a second layer of verification to protect admin access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-force defense\u003C\u002Fstrong>: Blocks repeated failed logins and temporarily locks abusive IPs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password policy prompts\u003C\u002Fstrong>: Encourage stronger credentials without breaking workflows\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session timeouts\u003C\u002Fstrong>: Automatically end idle sessions to prevent account hijacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity awareness\u003C\u002Fstrong>: View recent logins and admin changes in the \u003Cstrong>Activity Log\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Site Health & Cloud Checks: Clarity without noise\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site Health Dashboard\u003C\u002Fstrong>: Surface key signals in one view — WordPress hardening status, last scan timestamp and actionable indicators\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud Checks\u003C\u002Fstrong>: Connect your free SiteLock account to enable recurring off-server checks (Webpage Scan, SSL Verification, Email Reputation and more)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan Now\u003C\u002Fstrong>: Run on-demand checks after updates or changes for instant assurance — no heavy, always-on local scanners\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity Log\u003C\u002Fstrong>: Track what’s happening across your WordPress admin. See admin\u002Flogin events at a glance making it easy to spot anomalies early and keep accountability clear\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Choose SiteLock WordPress Security?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Lightweight by design\u003C\u002Fstrong>: All high-impact protections, no unnecessary load\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real visibility\u003C\u002Fstrong>: Know your security posture in seconds with Site Health\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud-powered assurance\u003C\u002Fstrong>: Checks run off-server, protecting performance\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible setup\u003C\u002Fstrong>: Use standalone or connect a SiteLock account for added layers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Strong login protection\u003C\u002Fstrong>: Two-Factor Authentication (2FA) alongside brute-force defense and session controls\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trusted heritage\u003C\u002Fstrong>: From the global leader in SMB website security backed by continuous innovation and research\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Aligned to WordPress\u003C\u002Fstrong>: Designed to stay out of your way and keep performance priorities intact\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who It’s For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Small businesses & startups\u003C\u002Fli>\n\u003Cli>Portfolio & personal brand sites\u003C\u002Fli>\n\u003Cli>WooCommerce shops & small e-commerce\u003C\u002Fli>\n\u003Cli>Agencies & website maintenance services\u003C\u002Fli>\n\u003Cli>Freelance developers & web designers\u003C\u002Fli>\n\u003Cli>Bloggers, creators & publishers\u003C\u002Fli>\n\u003Cli>Community & membership sites\u003C\u002Fli>\n\u003Cli>Nonprofits & educational sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>If you manage a WordPress website, SiteLock gives you confidence and control whether you run one site or hundreds.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch4>Can I Fix an Already-Infected Site with This Plugin?\u003C\u002Fh4>\n\u003Cp>The plugin focuses on prevention, posture and visibility — not full malware removal. It isn’t designed to fully clean up sites that were infected before it was active.\u003Cbr \u002F>\nIf your site is already compromised, act quickly, we recommend:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Restoring from a clean backup if available\u003C\u002Fli>\n\u003Cli>Remove malicious files manually or with professional help\u003C\u002Fli>\n\u003Cli>For urgent assistance, consider \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fproducts\u002Ffix-hacked-site\u002F\" rel=\"nofollow ugc\">SiteLock 911 – Emergency Malware Removal\u003C\u002Fa> for rapid cleanup\u003C\u002Fli>\n\u003Cli>For ongoing defense, consider \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fpricing\u002F\" rel=\"nofollow ugc\">choosing a comprehensive SiteLock plan\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Don’t Know Where To Start? Try This\u003C\u002Fh4>\n\u003Cp>Here are common first moves teams take with SiteLock. Order isn’t enforced — choose what fits your site and workflow:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enable WordPress hardening that matches your hosting and theme setup\u003C\u002Fli>\n\u003Cli>Turn on Login Security controls: brute-force lockouts, session timeouts, and password-hygiene prompts\u003C\u002Fli>\n\u003Cli>Connect a free SiteLock account, then use Scan Now to run an on-demand check after plugin\u002Ftheme updates\u003C\u002Fli>\n\u003Cli>Review the Activity Log after major changes to spot unexpected admin\u002Flogin events quickly\u003Cbr \u002F>\nMake one change at a time, validate and roll back any toggle that conflicts with your stack.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Need Help with Setup or Fixes?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Visit \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fhelp-center\u002F?topics=wordpress-plugin\" rel=\"nofollow ugc\">Help Center – WordPress\u003C\u002Fa> for plugin specific help\u003C\u002Fli>\n\u003Cli>For broader topics explore the \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fhelp-center\u002F\" rel=\"nofollow ugc\">SiteLock Help Center\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security\u003C\u002Fh4>\n\u003Cp>Protecting our customers and systems is a top priority, and we take security very seriously. If you believe you’ve found a security vulnerability in the SiteLock WordPress plugin, please let us know at vuln-reporting@sitelock.com before sharing any details publicly.\u003C\u002Fp>\n","Free, lightweight WordPress security. Harden your site with login protection & 2FA, see Site Health clearly and run on-demand checks—setup in minutes.",1000,53167,68,14,"2026-06-23T18:46:00.000Z","8.0",[76,77,78,22,79],"login-security","malware-scan","site-health","wordpress-security","https:\u002F\u002Fwww.sitelock.com\u002Fwordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsitelock.5.1.2.zip",98,2,"2026-01-25 00:00:00",{"slug":86,"name":87,"version":88,"author":89,"author_profile":90,"description":91,"short_description":92,"active_installs":69,"downloaded":93,"rating":94,"num_ratings":95,"last_updated":96,"tested_up_to":97,"requires_at_least":98,"requires_php":99,"tags":100,"homepage":106,"download_link":107,"security_score":108,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wp-admin-audit","WP Admin Audit","1.2.16","brandtoss","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrandtoss\u002F","\u003Cp>\u003Cstrong>The modern activity log solution for WordPress\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">WP Admin Audit\u003C\u002Fa> is the powerful monitoring log plugin for WordPress.\u003Cbr \u002F>\nSite owners and administrators can sleep better at night knowing the plugin keeps track of all site changes, security events, and admin activities.\u003C\u002Fp>\n\u003Cp>Ever wondered\u003C\u002Fp>\n\u003Cul>\n\u003Cli>who unpublished a post?\u003C\u002Fli>\n\u003Cli>when a plugin was deactivated?\u003C\u002Fli>\n\u003Cli>how that strange new admin account appeared?\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The WordPress activity log in WP Admin Audit answers these questions.\u003C\u002Fp>\n\u003Cp>Keep track of everything that happens on your WordPress sites to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Have a log of every change that’s made\u003C\u002Fli>\n\u003Cli>Know about security-relevant activities\u003C\u002Fli>\n\u003Cli>Find out who did what and when they did it\u003C\u002Fli>\n\u003Cli>Analyze the steps that led to a technical problem\u003C\u002Fli>\n\u003Cli>Identify and mitigate automated login attempts by bots\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>What is being logged?\u003C\u002Fh3>\n\u003Cp>The short answer: almost all changes on your WordPress site, but you can decide what is kept in the audit log.\u003C\u002Fp>\n\u003Cp>The longer answer: WP Admin Audit has sensors that monitor the changes in your WordPress site and record what actions were performed by which user at which time on which item. A summary of the types of monitored events is below.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Content:\u003C\u002Fstrong> Page and Post changes (e.g. post created\u002Fupdated\u002Fpublished\u002Funpublished\u002Fdeleted)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Taxonomy:\u003C\u002Fstrong> Changes to Categories and Tags (e.g. tag is created, updated, or deleted)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User:\u003C\u002Fstrong> User registration, user profile updates, password resets, user deletions, login, and logout\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress:\u003C\u002Fstrong> Updates of the WordPress core version, settings updates (general\u002Fwriting\u002Freading\u002Fdiscussion\u002Fmedia\u002Fpermalink\u002Fprivacy settings)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin:\u003C\u002Fstrong> Installation, activation, updates, deactivation, and deletion of plugins\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Theme:\u003C\u002Fstrong> Installation, activation (theme switch), update, and deletion of themes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media:\u003C\u002Fstrong> Media file and data creations, updates, and deletions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Menu:\u003C\u002Fstrong> Creation, updates, and deletions of menus\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comment:\u003C\u002Fstrong> Comment creations, updates, deletions, and status changes (approved, unapproved, spammed, etc.)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File:\u003C\u002Fstrong> File changes via the  plugin file editor and theme file editor\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>See the complete list of sensors, i.e. \u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002Fdocumentation\u002Fwp-admin-audit\u002Fsensors\u002Fevent-types\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">the event types that are stored in the WordPress activity log\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>For every event WP Admin Audit records:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Event type\u003C\u002Fli>\n\u003Cli>Date and time\u003C\u002Fli>\n\u003Cli>IP address (the action\u002Fevent originated from)\u003C\u002Fli>\n\u003Cli>Acting user (the user who did the change)\u003C\u002Fli>\n\u003Cli>Subject (the item affected e.g. a post the action is done with\u002Fto)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features (free)\u003C\u002Fh3>\n\u003Cp>Besides the WordPress event log, WP Admin Audit also features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Powerful search & filtering:\u003C\u002Fstrong> Powerful free-text search as well as filtering by all sorts of categories makes it easy to find the data you are interested in.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Administrator & user audit:\u003C\u002Fstrong> Find inactive administrator accounts and review the users’ last login dates. Check on their individual activity log.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login attempts audit:\u003C\u002Fstrong> Monitor logins to be aware of automated (brute-force) attacks and to identify IP addresses for blocking.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features (premium editions)\u003C\u002Fh3>\n\u003Cp>Upgrade to the \u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002Fpricing\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">premium editions\u003C\u002Fa> for the following features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Third-party plugin support:\u003C\u002Fstrong> Optional extensions help you capture events happening in other WordPress plugins. \u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002Fextensions\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">See our extension directory for more details.\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications:\u003C\u002Fstrong> Select event types or event severity levels (e.g. critical and high) for instant notification via email. You can choose whole user groups (e.g. administrators), individual WordPress users, or selected email addresses.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Offsite archive \u002F Replication:\u003C\u002Fstrong> To increase security and for backup purposes, you can forward the events for storage to an external logging provider.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enforce password changes:\u003C\u002Fstrong> You can enable a policy that requires users (with specific user roles) to change their passwords regularly. For example, administrator accounts can be required to change their passwords at least every 90 days.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV export:\u003C\u002Fstrong> Export events, users, and login attempts to CSV files.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpadminaudit.com\u002Ffeature-comparison\u002F?utm_source=wordpress.org&utm_medium=referral&utm_campaign=WADA&utm_content=plugin+repo+description\" rel=\"nofollow ugc\">Click here for more details and for a complete feature list\u003C\u002Fa>\u003C\u002Fp>\n","WP Admin Audit monitors the security-relevant activities on your site, keeps an event log and tells you when something out of the ordinary happens.",14233,74,6,"2025-07-23T21:45:00.000Z","6.8.6","5.5","7.0",[101,102,103,104,105],"activity-log","audit-log","audit-trail","security-audit-log","user-log","https:\u002F\u002Fwpadminaudit.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-admin-audit.1.2.16.zip",92,{"slug":110,"name":111,"version":112,"author":113,"author_profile":114,"description":115,"short_description":116,"active_installs":25,"downloaded":117,"rating":25,"num_ratings":32,"last_updated":118,"tested_up_to":119,"requires_at_least":15,"requires_php":120,"tags":121,"homepage":23,"download_link":125,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"ht-security","HT Security","1.5.0","WPFastSec","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpfastsec\u002F","\u003Cp>HT Security is a complete security suite for WordPress, offering multiple layers of protection for your website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Important – External Service:\u003C\u002Fstrong>\u003Cbr \u002F>\nThis plugin queries the National Vulnerability Database (NVD) API to check for known CVE vulnerabilities. Requests are made to:\u003Cbr \u002F>\n* API URL: https:\u002F\u002Fservices.nvd.nist.gov\u002Frest\u002Fjson\u002Fcves\u002F2.0\u003Cbr \u002F>\n* Terms of Use: https:\u002F\u002Fnvd.nist.gov\u002Fgeneral\u002Flegal-disclaimer\u003Cbr \u002F>\n* Privacy Policy: https:\u002F\u002Fwww.nist.gov\u002Fprivacy-policy\u003Cbr \u002F>\n* Frequency: Automatic check every 12 hours or manual on-demand\u003Cbr \u002F>\n* Data sent: Name and version of WordPress\u002Finstalled plugins (no personal data is sent)\u003C\u002Fp>\n\u003Cp>The NVD API query is essential for the plugin’s CVE vulnerability detection functionality.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security Headers\u003C\u002Fstrong> – HSTS, X-Frame-Options, Content-Security-Policy, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Alerts\u003C\u002Fstrong> – Email notifications for successful and failed login attempts with rate limiting\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Core Integrity Check\u003C\u002Fstrong> – Verify WordPress core files against official checksums with 24h cache\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CVE Vulnerability Detection\u003C\u002Fstrong> – Check WordPress Core and active plugins against NVD database\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Enumeration Protection\u003C\u002Fstrong> – Block user enumeration via REST API and author parameters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Maintenance Mode\u003C\u002Fstrong> – Maintenance mode with authorized IP whitelist (IPv4, IPv6, CIDR support)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Permissions Audit\u003C\u002Fstrong> – Audit and automatic correction of critical file permissions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Security Indicators\u003C\u002Fstrong> – Visual badges on plugins page showing vulnerability status\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>CVE Detection Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Integration with NVD (National Vulnerability Database) API 2.0\u003C\u002Fli>\n\u003Cli>Check WordPress Core and active plugins for known vulnerabilities\u003C\u002Fli>\n\u003Cli>Intelligent batch processing with rate limiting\u003C\u002Fli>\n\u003Cli>\u003Cstrong>8 layers of anti-false-positive validation\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Vulnerability badges on plugins page (enable\u002Fdisable option)\u003C\u002Fli>\n\u003Cli>Dismissible alerts per user\u003C\u002Fli>\n\u003Cli>Email notification when vulnerabilities are detected\u003C\u002Fli>\n\u003Cli>Automatic check every 12 hours\u003C\u002Fli>\n\u003Cli>NVD API Key support (increased rate limit)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security Improvements in v1.5.0\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>IP Spoofing Fix\u003C\u002Fstrong> – Properly detects real IP behind Cloudflare, proxies, and load balancers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Capability Check Fix\u003C\u002Fstrong> – Authorization verified before processing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting by IP\u003C\u002Fstrong> – More granular rate limiting for login alerts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Input Validation\u003C\u002Fstrong> – Maximum length validation for feedback form\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Supported Languages\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>English (US) – 100%\u003C\u002Fli>\n\u003Cli>English (UK) – 100%\u003C\u002Fli>\n\u003Cli>Português do Brasil – 100%\u003C\u002Fli>\n\u003Cli>Português de Portugal – 100%\u003C\u002Fli>\n\u003Cli>Español – 100%\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GNU General Public License v2.0 or later. For more information, visit https:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html.\u003C\u002Fp>\n","Complete Security Suite: Security Headers, CVE Detection, Core Integrity Check, Login Alerts, and Maintenance Mode.",1332,"2026-03-15T14:04:00.000Z","6.9.5","8.2",[18,122,123,20,124],"headers","maintenance","vulnerabilities","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fht-security.1.5.0.zip",{"slug":127,"name":128,"version":129,"author":130,"author_profile":131,"description":132,"short_description":133,"active_installs":25,"downloaded":134,"rating":25,"num_ratings":59,"last_updated":135,"tested_up_to":14,"requires_at_least":136,"requires_php":16,"tags":137,"homepage":23,"download_link":140,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"lockora-security-audit","Lockora Security Audit","0.2.0","Guido Schad","https:\u002F\u002Fprofiles.wordpress.org\u002Fcmdgw\u002F","\u003Cp>Lockora Security Audit helps site owners and agencies review a WordPress site’s security posture from the admin area.\u003C\u002Fp>\n\u003Cp>Current prototype features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Manual security scans.\u003C\u002Fli>\n\u003Cli>Weighted security score out of 100.\u003C\u002Fli>\n\u003Cli>WordPress core file integrity checks using official checksums.\u003C\u002Fli>\n\u003Cli>WordPress authentication key and salt checks, with an explicit action to generate missing salts.\u003C\u002Fli>\n\u003Cli>Must-use plugin directory presence checks.\u003C\u002Fli>\n\u003Cli>PHP version status using WordPress.org Serve Happy data.\u003C\u002Fli>\n\u003Cli>HTTPS and HTTP security header checks.\u003C\u002Fli>\n\u003Cli>WordPress core, plugin, and theme update posture checks.\u003C\u002Fli>\n\u003Cli>Administrator account posture checks for default usernames, excess admins, inactive admins, user ID 1 exposure, and an admin username\u002Femail inventory.\u003C\u002Fli>\n\u003Cli>Public exposure checks: debug.log and readme.html reachability, uploads directory listing, PHP execution inside uploads, and author archive user enumeration.\u003C\u002Fli>\n\u003Cli>SSL certificate expiry check, database table prefix check, automatic update posture check, and detection of login protection \u002F two-factor plugins.\u003C\u002Fli>\n\u003Cli>Site Health integration: scan summary plus key configuration checks appear under Tools > Site Health > Status.\u003C\u002Fli>\n\u003Cli>WP-CLI support: \u003Ccode>wp lockora scan\u003C\u002Fcode> and \u003Ccode>wp lockora report\u003C\u002Fcode>, with \u003Ccode>--format=json\u003C\u002Fcode> and a \u003Ccode>--strict\u003C\u002Fcode> flag for CI pipelines.\u003C\u002Fli>\n\u003Cli>Optional known vulnerability matching with a configured Wordfence Intelligence API key.\u003C\u002Fli>\n\u003Cli>Optional AI client reports on WordPress 7.0+ when the site’s AI Connector is configured.\u003C\u002Fli>\n\u003Cli>Reversible hardening toggles for XML-RPC, REST user routes, generator tag output, and basic security headers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Lockora Security Audit may connect to external services only when the administrator runs a scan or generates an AI client report.\u003C\u002Fp>\n\u003Cp>During a scan the plugin also sends HTTP requests to the site’s own public URL (loopback requests) to inspect response headers, debug.log and readme.html reachability, uploads directory behavior, and author archive redirects, and it opens a TLS connection to the site’s own hostname to read the SSL certificate expiry date. These requests stay within the site being scanned and send no data to third parties.\u003C\u002Fp>\n\u003Cp>WordPress.org APIs:\u003Cbr \u002F>\n* Used for WordPress core checksums, PHP version support status, and WordPress core\u002Fplugin\u002Ftheme update data.\u003Cbr \u002F>\n* Data sent: the site’s WordPress version and locale for core checksums and PHP compatibility; WordPress itself may send installed plugin and theme slugs\u002Fversions to WordPress.org when update data is refreshed.\u003Cbr \u002F>\n* WordPress.org terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms\u002F\u003Cbr \u002F>\n* WordPress.org privacy policy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>Wordfence Intelligence:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when a Wordfence Intelligence API key is configured and an administrator runs a scan that includes vulnerability matching.\u003Cbr \u002F>\n* Used to retrieve vulnerability data and match it locally against installed WordPress core, plugin, and theme versions.\u003Cbr \u002F>\n* Data sent: the configured Wordfence Intelligence API key is sent in an Authorization header when requesting the vulnerability feed. Installed software details are not sent by this plugin to the Wordfence Intelligence endpoint; matching is performed locally after the feed is retrieved.\u003Cbr \u002F>\n* Wordfence Intelligence terms: https:\u002F\u002Fwww.wordfence.com\u002Fwordfence-intelligence-terms-and-conditions\u002F\u003Cbr \u002F>\n* Wordfence privacy policy: https:\u002F\u002Fwww.wordfence.com\u002Fprivacy-policy\u002F\u003C\u002Fp>\n\u003Cp>WordPress AI Client \u002F Connectors:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when the administrator clicks Generate Client Report.\u003Cbr \u002F>\n* Data sent: sanitized scan findings, score, counts, and recommendations needed to generate a client-facing report. The plugin is designed not to send passwords, salts, API keys, raw logs, full user lists, or file contents.\u003Cbr \u002F>\n* The configured AI provider is controlled by the site owner’s WordPress Connector settings.\u003Cbr \u002F>\n* Terms and privacy policy: these depend on the AI provider configured by the site owner in WordPress. Site owners should review the selected provider’s terms and privacy policy before enabling AI reports.\u003C\u002Fp>\n","Lockora Security Audit checks WordPress security posture, hardening, core integrity, vulnerabilities, and optional AI reports.",511,"2026-07-12T20:50:00.000Z","6.0",[138,139,20,78,22],"ai","hardening","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flockora-security-audit.0.2.0.zip",{"error":142,"url":143,"statusCode":144,"statusMessage":145,"message":145},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fcatcher24-connector\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":32,"versions":147},[148],{"version":6,"download_url":24,"svn_tag_url":149,"released_at":26,"has_diff":150,"diff_files_changed":151,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":152,"is_current":142},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcatcher24-connector\u002Ftags\u002F1.0.0\u002F",false,[],[]]