[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYtoIfilbBL2DsjTX6V_ipCDmWedQ4J0WAfZUZYE1qg4":3,"$fP07G7g9CVjiLGL8H7lr1I9pSt0K21BmHKPIZEy7Ju7E":131,"$fTdo8NZK8p-qANE9S1VUHYSk47ydJUnwnAJ6pdUAWI8A":136},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"discovery_status":30,"vulnerabilities":31,"developer":32,"crawl_stats":28,"alternatives":36,"analysis":28,"fingerprints":28},"cleverhog-malware-scanner","Cleverhog Malware Scanner","1.6.9","cleverhog","https:\u002F\u002Fprofiles.wordpress.org\u002Fcleverhog\u002F","\u003Cp>\u003Cstrong>Cleverhog Malware Scanner\u003C\u002Fstrong> helps you investigate a suspicious or compromised WordPress site from the admin dashboard. It is \u003Cstrong>free\u003C\u002Fstrong> and may be used on \u003Cstrong>unlimited websites\u003C\u002Fstrong> with no license keys or per-site fees.\u003C\u002Fp>\n\u003Cp>This plugin \u003Cstrong>detects and reports\u003C\u002Fstrong> potential security issues. It does \u003Cstrong>not\u003C\u002Fstrong> automatically remove malware or guarantee that a site is clean. Always back up your site before changing or deleting files.\u003C\u002Fp>\n\u003Ch4>What it scans\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Files\u003C\u002Fstrong> — Pattern-based scan of themes, plugins, uploads, wp-content, or the full site (with code snippets, file size, and last-modified date)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backdoors\u003C\u002Fstrong> — Must-use plugins, drop-ins, wp-config, cron jobs, and suspicious hooks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>.htaccess\u003C\u002Fstrong> — Discovers \u003Ccode>.htaccess\u003C\u002Fcode> files site-wide and lists suspicious redirects, PHP handlers in uploads, auto_prepend, cloaking rules, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authentication\u003C\u002Fstrong> — XML-RPC, user enumeration, weak salts, file editor, and SSL-related checks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database\u003C\u002Fstrong> — Suspicious autoloaded options and injected post content\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Administrators\u003C\u002Fstrong> — All admin users with registration dates and risk flags\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Updates\u003C\u002Fstrong> — Outdated plugins, themes, and core (medium for major\u002Fminor updates, low for patch-only updates)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin integrity\u003C\u002Fstrong> — WordPress.org plugins compared to official checksums (one summary per plugin)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Live threat counter during scans\u003C\u002Fli>\n\u003Cli>Results sorted by severity (critical, high, medium, low)\u003C\u002Fli>\n\u003Cli>Last scan results restored when you reopen the dashboard\u003C\u002Fli>\n\u003Cli>Admin menu badge showing critical issue count\u003C\u002Fli>\n\u003Cli>Excludes this plugin’s own files from file scans to reduce false positives\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin runs entirely on your server. Scans do not send your site files to the plugin author.\u003C\u002Fp>\n\u003Cp>When you run a scan, the plugin may contact:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>WordPress.org\u003C\u002Fstrong> (\u003Ccode>downloads.wordpress.org\u003C\u002Fcode>) — to fetch official plugin checksums for integrity verification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress.org update APIs\u003C\u002Fstrong> — to check for available plugin, theme, and core updates (standard WordPress behavior)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No personal data is collected by the plugin author. Scan results are stored in your WordPress database (options and transients) for display in the admin dashboard and are visible to users who can manage the site.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>Support is provided through the WordPress.org support forums after publication.\u003C\u002Fp>\n","Free WordPress malware scanner by Cleverhog: detect suspicious files, backdoors, weak logins, and outdated software from your dashboard.",20,251,100,1,"2026-05-29T11:32:00.000Z","7.0.2","5.8","7.4",[20,21,22,23,24],"backdoor","hacked","malware","scanner","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcleverhog-malware-scanner\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcleverhog-malware-scanner.1.6.9.zip",0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":13,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},30,94,"2026-08-29T09:44:00.542Z",[37,55,73,88,110],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":33,"downloaded":45,"rating":13,"num_ratings":14,"last_updated":46,"tested_up_to":16,"requires_at_least":47,"requires_php":48,"tags":49,"homepage":53,"download_link":54,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"content-guard-pro","Content Guard Pro – Database Malware Scanner & SEO Spam Detector","1.4.0","contentguardpro","https:\u002F\u002Fprofiles.wordpress.org\u002Fcontentguardpro\u002F","\u003Ch4>File scanner clean but Google still shows spam?\u003C\u002Fh4>\n\u003Cp>File scanner says your WordPress site is clean, but Google still shows spam pages, strange redirects, pharma keywords, hidden links, or Japanese keyword hack results?\u003C\u002Fp>\n\u003Cp>Content Guard Pro scans the WordPress database for hidden SEO spam, malicious scripts, suspicious iframes, spam links, encoded payloads, and cloaked content inside posts, pages, custom post types, titles, excerpts, and Gutenberg blocks.\u003C\u002Fp>\n\u003Cp>Most WordPress security plugins focus on files, firewalls, login protection, or vulnerability checks. Content Guard Pro adds the missing database-content layer, so you can inspect the places attackers often abuse after a hacked-site cleanup: post content, block markup, titles, excerpts, and deeper database fields when Standard Scan is enabled.\u003C\u002Fp>\n\u003Ch4>What the free WordPress.org version scans\u003C\u002Fh4>\n\u003Cp>The free plugin includes Quick Scan for \u003Ccode>wp_posts\u003C\u002Fcode>, including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Posts, pages, and custom post types\u003C\u002Fli>\n\u003Cli>Post titles, excerpts, and post content\u003C\u002Fli>\n\u003Cli>Gutenberg block content stored in the database\u003C\u002Fli>\n\u003Cli>Classic Editor and Block Editor content during single-post scans\u003C\u002Fli>\n\u003Cli>Hidden links, suspicious scripts, iframes, SEO spam, and encoded payloads in supported content fields\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The free version also includes unlimited manual scans, all findings visible, on-save single post scanning, confidence scores, severity labels, admin notices, dashboard alerts, 30-day scan history, and allowlist\u002Fdenylist controls.\u003C\u002Fp>\n\u003Ch4>What this database malware scanner detects\u003C\u002Fh4>\n\u003Cp>Content Guard Pro helps find content-layer threats such as:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Hidden SEO spam links and cloaked text using CSS tricks such as \u003Ccode>display:none\u003C\u002Fcode>, \u003Ccode>visibility:hidden\u003C\u002Fcode>, \u003Ccode>opacity:0\u003C\u002Fcode>, off-screen positioning, and tiny or hidden elements\u003C\u002Fli>\n\u003Cli>Pharma spam, casino spam, gambling spam, crypto spam, financial scam phrases, counterfeit goods spam, and redirect spam\u003C\u002Fli>\n\u003Cli>Japanese keyword hack content and cloaked search-result spam\u003C\u002Fli>\n\u003Cli>Suspicious external scripts, iframes, object\u002Fembed tags, and links in posts and blocks\u003C\u002Fli>\n\u003Cli>JavaScript redirects, meta refresh redirects, \u003Ccode>javascript:\u003C\u002Fcode> links, and suspicious inline event handlers\u003C\u002Fli>\n\u003Cli>Obfuscated JavaScript patterns such as \u003Ccode>eval()\u003C\u002Fcode>, \u003Ccode>fromCharCode()\u003C\u002Fcode>, \u003Ccode>atob()\u003C\u002Fcode>, Base64 payloads, and large \u003Ccode>data:\u003C\u002Fcode> URIs\u003C\u002Fli>\n\u003Cli>URL shorteners and redirectors that hide the final destination\u003C\u002Fli>\n\u003Cli>Cryptocurrency miner patterns and known cryptojacking script indicators\u003C\u002Fli>\n\u003Cli>Encoded attacks hidden with HTML entities, URL encoding, Base64, ROT13, hex, or octal encoding\u003C\u002Fli>\n\u003Cli>Serialized malware in postmeta, selected options, and Elementor data when Standard Scan is enabled\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>When to use Content Guard Pro\u003C\u002Fh4>\n\u003Cp>Use Content Guard Pro when:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Google flags hacked content, spam pages, or strange search results, but your file scanner looks clean\u003C\u002Fli>\n\u003Cli>You cleaned a hacked WordPress site and want to check whether spam remains in posts or blocks\u003C\u002Fli>\n\u003Cli>You inherited a client site and need to inspect the database content layer before making changes\u003C\u002Fli>\n\u003Cli>You see pharma keywords, Japanese keyword spam, casino links, hidden iframes, or suspicious redirects in search results\u003C\u002Fli>\n\u003Cli>You want to review risky Gutenberg or Classic Editor content before publishing\u003C\u002Fli>\n\u003Cli>You need a database malware scanner alongside your existing firewall, file scanner, and vulnerability scanner\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why database-first scanning matters\u003C\u002Fh4>\n\u003Cp>File scanners are important, but many SEO spam infections do not live in plugin files or theme files. Attackers often inject spam links, hidden text, malicious scripts, or redirect code directly into WordPress content stored in the database.\u003C\u002Fp>\n\u003Cp>Content Guard Pro focuses on that content layer. It is designed to complement your existing security stack, not replace it.\u003C\u002Fp>\n\u003Cp>Think of it as database forensics for WordPress content: scan posts, pages, custom post types, block markup, and deeper database fields with a scanner built specifically for content-resident threats.\u003C\u002Fp>\n\u003Ch4>Low-noise findings for real cleanup work\u003C\u002Fh4>\n\u003Cp>Not every external link or hidden element is malicious. Content Guard Pro uses confidence scores, Critical\u002FSuspicious\u002FReview severity labels, accessibility-aware rules, and allowlists to reduce obvious false positives.\u003C\u002Fp>\n\u003Cp>Findings include the affected content location, matched rule, confidence score, context excerpt, and suggested next action so you can review problems faster.\u003C\u002Fp>\n\u003Ch4>Free plugin features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Quick Scan for \u003Ccode>wp_posts\u003C\u002Fcode> content, including posts, pages, custom post types, titles, excerpts, and Gutenberg blocks\u003C\u002Fli>\n\u003Cli>Unlimited manual scans\u003C\u002Fli>\n\u003Cli>All findings visible in the plugin dashboard\u003C\u002Fli>\n\u003Cli>Gutenberg-aware scanning with block parsing\u003C\u002Fli>\n\u003Cli>Classic Editor and Block Editor single-post scanning on save\u003C\u002Fli>\n\u003Cli>Confidence scores from 0 to 100\u003C\u002Fli>\n\u003Cli>Severity labels: Critical, Suspicious, and Review\u003C\u002Fli>\n\u003Cli>Admin notices for important findings\u003C\u002Fli>\n\u003Cli>Admin bar alerts and WordPress dashboard summary\u003C\u002Fli>\n\u003Cli>30-day scan history\u003C\u002Fli>\n\u003Cli>Allowlist and denylist controls to reduce false positives\u003C\u002Fli>\n\u003Cli>One-click Edit Post workflow for manual cleanup\u003C\u002Fli>\n\u003Cli>Ignore\u002Ffalse-positive workflow for accepted findings\u003C\u002Fli>\n\u003Cli>Local scanning with bundled detection rules\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium adds deeper database coverage\u003C\u002Fh4>\n\u003Cp>Premium plans add deeper coverage and workflow automation for site owners and agencies:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Standard Scan for \u003Ccode>wp_posts\u003C\u002Fcode>, \u003Ccode>wp_postmeta\u003C\u002Fcode>, and selected \u003Ccode>wp_options\u003C\u002Fcode> data\u003C\u002Fli>\n\u003Cli>Deeper inspection of serialized data and Elementor data stored in postmeta\u003C\u002Fli>\n\u003Cli>Scheduled daily scans\u003C\u002Fli>\n\u003Cli>Non-destructive quarantine to neutralize risky content without deleting database content\u003C\u002Fli>\n\u003Cli>Revision-based rollback for affected posts\u003C\u002Fli>\n\u003Cli>Email alerts and daily digest emails\u003C\u002Fli>\n\u003Cli>Webhooks for agency monitoring on supported plans\u003C\u002Fli>\n\u003Cli>Reputation checks through supported security services\u003C\u002Fli>\n\u003Cli>Faster rule updates\u003C\u002Fli>\n\u003Cli>CSV\u002FJSON export and REST API access on supported agency plans\u003C\u002Fli>\n\u003Cli>Extended scan history on paid plans\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy and external services\u003C\u002Fh4>\n\u003Cp>Content Guard Pro scans locally on your WordPress server and works without creating an account or connecting to the cloud service.\u003C\u002Fp>\n\u003Cp>Optional external service: Content Guard Pro Cloud, provided by contentguardpro.com.\u003C\u002Fp>\n\u003Cp>The optional cloud service can be used for rule-pack hints, community allowlist sync, optional anonymous telemetry, optional developer contact, and optional security newsletter preferences. It is consent-based and can be skipped.\u003C\u002Fp>\n\u003Cp>If you choose to connect, the service may receive the site URL, site name, plugin version, WordPress version, PHP version, anonymous installation ID, consent choices, optional email address if you provide it, and anonymous scan metrics such as scan count, findings count, duration, and items scanned when telemetry is enabled.\u003C\u002Fp>\n\u003Cp>Content Guard Pro does not send post content, database contents, matched excerpts, scan result details, usernames, passwords, payment details, visitor data, or stored customer data to the cloud service.\u003C\u002Fp>\n\u003Cp>Terms: \u003Ca href=\"https:\u002F\u002Fcontentguardpro.com\u002Fterms\" rel=\"nofollow ugc\">https:\u002F\u002Fcontentguardpro.com\u002Fterms\u003C\u002Fa>\u003Cbr \u002F>\nPrivacy Policy: \u003Ca href=\"https:\u002F\u002Fcontentguardpro.com\u002Fprivacy\" rel=\"nofollow ugc\">https:\u002F\u002Fcontentguardpro.com\u002Fprivacy\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Documentation and support\u003C\u002Fh4>\n\u003Cp>Documentation: \u003Ca href=\"https:\u002F\u002Fcontentguardpro.com\u002Fdocs\" rel=\"nofollow ugc\">https:\u002F\u002Fcontentguardpro.com\u002Fdocs\u003C\u002Fa>\u003Cbr \u002F>\nSupport forum: \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fcontent-guard-pro\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fcontent-guard-pro\u002F\u003C\u002Fa>\u003C\u002Fp>\n","Scan your WordPress database for hidden SEO spam, pharma hacks, malicious scripts, iframes and spam links in posts and blocks.",1043,"2026-05-21T21:22:00.000Z","6.1","8.0",[50,21,51,52,24],"database-security","malware-removal","malware-scanner","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcontent-guard-pro","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcontent-guard-pro.1.4.0.zip",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":27,"downloaded":63,"rating":64,"num_ratings":14,"last_updated":65,"tested_up_to":66,"requires_at_least":17,"requires_php":18,"tags":67,"homepage":71,"download_link":72,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"broodweb-malware-scanner","BroodWeb Malware Scanner","1.4.1","Md Jubayer Hossain","https:\u002F\u002Fprofiles.wordpress.org\u002Fjubayerhossain\u002F","\u003Cp>BroodWeb Malware Scanner helps WordPress site owners, agencies, and developers investigate suspicious files, database content, login activity, and security exposure from one admin screen.\u003C\u002Fp>\n\u003Cp>The scanner is built for careful review. It does not blindly delete files. It shows risk scores, findings, file paths, quarantine actions, whitelist controls, and exportable reports so you can inspect suspicious results before taking action.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Malware file scanner for WordPress core, plugins, themes, uploads, must-use plugins, and root files.\u003C\u002Fli>\n\u003Cli>Official WordPress core checksum verification to suppress false positives on clean core files.\u003C\u002Fli>\n\u003Cli>Detection for common malware indicators such as eval(), base64_decode(), gzinflate(), shell_exec(), obfuscated strings, suspicious filenames, disguised PHP payloads, and PHP files inside uploads.\u003C\u002Fli>\n\u003Cli>Database scanner for suspicious content in options, posts, and users.\u003C\u002Fli>\n\u003Cli>Quarantine, restore, delete, and whitelist tools for flagged files.\u003C\u002Fli>\n\u003Cli>Scan history with stored reports.\u003C\u002Fli>\n\u003Cli>Filterable scan report with filename search, risk filter, category filter, collapsible findings, and JSON\u002FCSV export.\u003C\u002Fli>\n\u003Cli>AJAX chunked scanning to reduce timeouts on larger websites.\u003C\u002Fli>\n\u003Cli>Scheduled scans and email alerts.\u003C\u002Fli>\n\u003Cli>Integrity monitor with file-change tracking and alert email support.\u003C\u002Fli>\n\u003Cli>Login security tools, including custom login URL support.\u003C\u002Fli>\n\u003Cli>Activity log for security events.\u003C\u002Fli>\n\u003Cli>Vulnerability review for WordPress core, plugins, and themes.\u003C\u002Fli>\n\u003Cli>Firewall-lite controls for basic request protection.\u003C\u002Fli>\n\u003Cli>Go Pro information tab explaining Pro features.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Official Core Verification\u003C\u002Fh4>\n\u003Cp>WordPress core files can contain functions that look suspicious in normal malware signatures. BroodWeb Malware Scanner verifies official WordPress core files against WordPress.org checksums before content heuristics are applied. If a core file matches the official source, it is not reported as suspicious.\u003C\u002Fp>\n\u003Cp>If a core file is changed or if an unexpected file appears inside a core directory, the scanner can report that as a higher-signal issue.\u003C\u002Fp>\n\u003Ch4>Designed For Manual Review\u003C\u002Fh4>\n\u003Cp>BroodWeb Malware Scanner is an investigation and triage tool. Always review flagged files before quarantining or deleting them, and always create a full backup before cleaning an infected site.\u003C\u002Fp>\n\u003Ch4>BroodWeb Malware Scanner Pro\u003C\u002Fh4>\n\u003Cp>The free plugin includes the core protection layer: malware scanning, database checks, quarantine, whitelist, integrity monitoring, login security, vulnerability review, firewall-lite, activity log, and reporting exports.\u003C\u002Fp>\n\u003Cp>BroodWeb Malware Scanner Pro adds advanced cleanup and intelligence tools, including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Hardening controls.\u003C\u002Fli>\n\u003Cli>Repair tools for comparing and restoring supported official WordPress, plugin, and theme files.\u003C\u002Fli>\n\u003Cli>AI-assisted malware triage with OpenAI-compatible providers.\u003C\u002Fli>\n\u003Cli>Professional reporting workflows for agencies and client work.\u003C\u002Fli>\n\u003C\u002Ful>\n","Scan WordPress files and database content for suspicious code, malware indicators, file integrity changes, login abuse, vulnerabilities, and firewall  &hellip;",340,80,"2026-06-03T23:57:00.000Z","6.9.5",[68,69,70,52,24],"backdoor-scanner","file-scanner","login-security","https:\u002F\u002Fbroodweb.com\u002Fplugins\u002Fbroodweb-malware-scanner\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbroodweb-malware-scanner.1.4.1.zip",{"slug":74,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":27,"downloaded":81,"rating":27,"num_ratings":27,"last_updated":82,"tested_up_to":16,"requires_at_least":83,"requires_php":48,"tags":84,"homepage":86,"download_link":87,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"genisoft-security-connector","Genisoft Security Connector","0.8.1","genisoftweb","https:\u002F\u002Fprofiles.wordpress.org\u002Fgenisoftweb\u002F","\u003Cp>\u003Cstrong>Genisoft Security Connector\u003C\u002Fstrong> is the official plugin for \u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.genisoft.fr\" rel=\"nofollow ugc\">WP Security\u003C\u002Fa>\u003C\u002Fstrong> (by Genisoft) — a remote \u003Cstrong>security audit and malware detection\u003C\u002Fstrong> service for WordPress.\u003C\u002Fp>\n\u003Cp>This plugin is a \u003Cstrong>lightweight connector\u003C\u002Fstrong>: it performs no analysis itself. It exposes a \u003Cstrong>read-only REST API authenticated with HMAC-SHA256\u003C\u002Fstrong> that the WP Security engine calls to audit your site \u003Cstrong>remotely\u003C\u002Fstrong>, without SSH or FTP. The heavy analysis (detection of \u003Cstrong>webshells, backdoors, injections, obfuscated code\u003C\u002Fstrong>, WordPress core integrity checks against the official \u003Ccode>api.wordpress.org\u003C\u002Fcode> checksums, and YARA rules) runs \u003Cstrong>on our servers\u003C\u002Fstrong>, in an isolated environment — your site stays light and fast.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What the scanner detects:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP webshells and backdoors\u003C\u002Fli>\n\u003Cli>Injectors and malicious redirects\u003C\u002Fli>\n\u003Cli>Obfuscated \u002F encoded code\u003C\u002Fli>\n\u003Cli>Modified WordPress core files\u003C\u002Fli>\n\u003Cli>Vulnerable plugins and themes (CVE)\u003C\u002Fli>\n\u003Cli>Code injected into the database (wp_options, etc.)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Secure by design:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>HMAC-SHA256 authentication on every request (signature + timestamp; requests older than 5 minutes are rejected). One unique key per site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read-only:\u003C\u002Fstrong> files are read for analysis, never executed (no \u003Ccode>eval\u003C\u002Fcode>, \u003Ccode>exec\u003C\u002Fcode> or \u003Ccode>include\u003C\u002Fcode> on external content).\u003C\u002Fli>\n\u003Cli>No SSH, no SFTP.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Third-party service\u003C\u002Fh4>\n\u003Cp>This plugin is a connector: it \u003Cstrong>requires an account on the external WP Security service\u003C\u002Fstrong> (\u003Ccode>https:\u002F\u002Fwordpress.genisoft.fr\u003C\u002Fcode>) to be useful. Each time you start a scan from your WP Security dashboard, the service calls the plugin’s read-only REST API to read the files to analyze. File contents are \u003Cstrong>not stored\u003C\u002Fstrong> by the service — only analysis results (metadata) are kept; hosting is in the EU (GDPR).\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service website: https:\u002F\u002Fwordpress.genisoft.fr\u003C\u002Fli>\n\u003Cli>Terms of service: https:\u002F\u002Fwordpress.genisoft.fr\u002Flegal\u002Fcgu\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fwordpress.genisoft.fr\u002Flegal\u002Fconfidentialite\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure read-only connector linking your WordPress site to the WP Security malware-scanning service for remote security audits.",57,"2026-07-18T16:33:00.000Z","6.0",[21,22,23,24,85],"security-audit","https:\u002F\u002Fwordpress.genisoft.fr","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgenisoft-security-connector.0.8.1.zip",{"slug":89,"name":90,"version":91,"author":92,"author_profile":93,"description":94,"short_description":95,"active_installs":96,"downloaded":97,"rating":34,"num_ratings":98,"last_updated":99,"tested_up_to":16,"requires_at_least":100,"requires_php":101,"tags":102,"homepage":105,"download_link":106,"security_score":107,"vuln_count":108,"unpatched_count":27,"last_vuln_date":109,"fetched_at":29},"wordfence","Wordfence Security – Firewall, Malware Scan, and Login Security","8.2.2","Mark Maunder","https:\u002F\u002Fprofiles.wordpress.org\u002Fmmaunder\u002F","\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fi4ZN2TwlaBE?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>THE MOST POPULAR WORDPRESS FIREWALL & SECURITY SCANNER\u003C\u002Fh4>\n\u003Cp>WordPress security requires a team of dedicated analysts researching the latest malware variants and WordPress exploits, turning them into firewall rules and malware signatures, and releasing those to customers in real-time.\u003C\u002Fp>\n\u003Cp>Choose the right protection for you: \u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fproducts\u002Fpricing\u002F\" rel=\"nofollow ugc\">Wordfence Free, Premium, Care or Response\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Wordfence is widely acknowledged as the number one WordPress security research team in the World. Our plugin provides a comprehensive suite of security features, and our team’s research is what powers our plugin and provides the level of security that we are known for.\u003C\u002Fp>\n\u003Cp>At Wordfence, WordPress security isn’t a division of our business – WordPress security is all we do. We employ a global 24-hour dedicated incident response team that provides our priority customers with a 1 hour response time for any security incident.\u003C\u002Fp>\n\u003Cp>The sun never sets on our global security team and we run a sophisticated threat intelligence platform to aggregate, analyze and produce ground breaking security research on the newest security threats.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Wordfence Security includes an endpoint firewall, malware scanner, robust login security features, live traffic views, and more.\u003C\u002Fstrong> Our \u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002F\" rel=\"nofollow ugc\">Threat Defense Feed\u003C\u002Fa> arms Wordfence with the newest firewall rules, malware signatures, and malicious IP addresses it needs to keep your website safe.\u003C\u002Fp>\n\u003Cp>Rounded out by 2FA and a suite of additional features, Wordfence is the most comprehensive WordPress security solution available.\u003C\u002Fp>\n\u003Ch3>🔥 WORDPRESS FIREWALL\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Ffirewall\u002F\" rel=\"nofollow ugc\">Web Application Firewall\u003C\u002Fa>\u003C\u002Fstrong> identifies and blocks malicious traffic. Built and maintained by a large team focused 100% on WordPress security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time firewall rule and malware signature [Premium]\u003C\u002Fstrong> updates via the Threat Defense Feed (free version is delayed by 30 days).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Fblocking\u002F\" rel=\"nofollow ugc\">Real-time IP Blocklist\u003C\u002Fa> [Premium]\u003C\u002Fstrong> blocks all requests from the most malicious IPs, protecting your site while reducing load.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Protects your site at the endpoint\u003C\u002Fstrong>, enabling deep integration with WordPress. Unlike cloud alternatives, it does not break encryption, cannot be bypassed and cannot leak data.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Fscan\u002F\" rel=\"nofollow ugc\">Integrated malware scanner\u003C\u002Fa>\u003C\u002Fstrong> blocks requests that include malicious code or content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Ffirewall\u002Fbrute-force\u002F\" rel=\"nofollow ugc\">Protection from brute force\u003C\u002Fa>\u003C\u002Fstrong> attacks by limiting login attempts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📡 WORDPRESS SECURITY SCANNER\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malware scanner\u003C\u002Fstrong> checks core files, themes and plugins for malware, bad URLs, backdoors, SEO spam, malicious redirects and code injections.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time malware signature updates [Premium]\u003C\u002Fstrong> via the Threat Defense Feed (free version is delayed by 30 days).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compares with WordPress.org repository\u003C\u002Fstrong> your core files, themes and plugins, checking their integrity and reporting any changes to you.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Repair WordPress core, theme, and plugin files\u003C\u002Fstrong> that have changed by overwriting them with a pristine, original version. Delete any files that don’t belong easily within the Wordfence interface.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Malware Removal Tools\u003C\u002Fstrong> “Delete File” and “Delete All Deletable Files” options allow for efficient malware removal. Remember to investigate the scan results and backup files first!\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checks your site for known security vulnerabilities\u003C\u002Fstrong> and alerts you to any issues. Also alerts you to potential security issues when a plugin has been closed or abandoned.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checks your content safety\u003C\u002Fstrong> by scanning file contents, posts and comments for dangerous URLs and suspicious content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checks to see if your site or IP have been blocklisted [Premium]\u003C\u002Fstrong> for malicious activity, generating spam or other security issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔒 LOGIN SECURITY\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Ftools\u002Ftwo-factor-authentication\u002F\" rel=\"nofollow ugc\">Two-factor authentication (2FA)\u003C\u002Fa>\u003C\u002Fstrong>, one of the most secure forms of remote system authentication available via any TOTP-based authenticator app or service.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Flogin-security\u002F\" rel=\"nofollow ugc\">Login Page CAPTCHA\u003C\u002Fa>\u003C\u002Fstrong> stops bots from logging in.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Flogin-security\u002F#woocommerce-and-custom-integrations\" rel=\"nofollow ugc\">2FA for WooCommerce and custom integrations\u003C\u002Fa>\u003C\u002Fstrong> allow for 2FA to be setup on custom account pages\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC\u003C\u002Fstrong> options including disabling or adding 2FA.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password Security:\u003C\u002Fstrong> Block logins for administrators using known compromised passwords.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📋 SECURITY AUDIT LOG [Premium]\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Faudit-log\" rel=\"nofollow ugc\">The Audit Log\u003C\u002Fa>\u003C\u002Fstrong> monitors all changes and actions in security-sensitive areas of the site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remote tamper-proof data storage\u003C\u002Fstrong> via Wordfence Central.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Monitor events and actions\u003C\u002Fstrong> ranging  from user creation and editing to plugin\u002Ftheme installation and updates to post and page changes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable\u003C\u002Fstrong> to log all events or significant events only, which includes all authentication, site configuration, and site functionality events.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🌐 WORDFENCE CENTRAL\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fproducts\u002Fwordfence-central\u002F\" rel=\"nofollow ugc\">Wordfence Central\u003C\u002Fa>\u003C\u002Fstrong> is a powerful and efficient way to manage the security for multiple sites in one place.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Centralized management:\u003C\u002Fstrong> Efficiently assess the security status of all your websites in one view. View detailed security findings without leaving Wordfence Central.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Powerful templates\u003C\u002Fstrong> make configuring Wordfence a breeze.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Highly configurable alerts\u003C\u002Fstrong> can be delivered via email, SMS or Slack. Improve the signal to noise ratio by leveraging severity level options and a daily digest option.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Track and alert on important security events\u003C\u002Fstrong> including administrator logins, breached password usage and surges in attack activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free to use\u003C\u002Fstrong> for unlimited sites.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🛠️ SECURITY TOOLS\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Ftools\u002Flive-traffic\u002F\" rel=\"nofollow ugc\">Live Traffic\u003C\u002Fa>\u003C\u002Fstrong> monitors visits and hack attempts not shown in other analytics packages in real time; including origin, their IP address, the time of day and time spent on your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block attackers by IP\u003C\u002Fstrong> or build advanced rules based on IP Range, Hostname, User Agent and Referrer.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Fblocking\u002Fcountry-blocking\u002F\" rel=\"nofollow ugc\">Country blocking\u003C\u002Fa>\u003C\u002Fstrong> available with Wordfence Premium.\u003C\u002Fli>\n\u003C\u002Ful>\n","Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.",5000000,419061680,4958,"2026-05-13T15:42:00.000Z","4.7","7.0",[103,104,22,23,24],"2fa","firewall","https:\u002F\u002Fwww.wordfence.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwordfence.8.2.2.zip",96,12,"2022-09-06 00:00:00",{"slug":111,"name":112,"version":113,"author":114,"author_profile":115,"description":116,"short_description":117,"active_installs":118,"downloaded":119,"rating":120,"num_ratings":121,"last_updated":122,"tested_up_to":16,"requires_at_least":100,"requires_php":101,"tags":123,"homepage":126,"download_link":127,"security_score":128,"vuln_count":129,"unpatched_count":27,"last_vuln_date":130,"fetched_at":29},"sg-security","Security Optimizer – The All-In-One Protection Plugin","1.6.5","SiteGround","https:\u002F\u002Fprofiles.wordpress.org\u002Fsiteground\u002F","\u003Cp>\u003Cstrong>Bulletproof your website security in a few clicks against a range of security breaches, including brute-force attacks, malware threats and bots, with our free WordPress security plugin – Security Optimizer.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Proactively monitor your site’s security to detect any suspicious activity and take immediate actions to protect your site and prevent further damage with these essential features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enable \u003Cstrong>2FA (Two-Factor Authentication)\u003C\u002Fstrong> for an extra layer of website security\u003C\u002Fli>\n\u003Cli>Set \u003Cstrong>Limit Login Attempts\u003C\u002Fstrong> to deter malicious login attempts and brute-force attacks\u003C\u002Fli>\n\u003Cli>Change your default login URL to \u003Cstrong>Custom Login URL\u003C\u002Fstrong> to avoid attacks\u003C\u002Fli>\n\u003Cli>Activate \u003Cstrong>Advanced XSS Protection\u003C\u002Fstrong> to fortify your website against malicious attacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lock and Protect System Folders\u003C\u002Fstrong> to ensure no unauthorized or malicious scripts can be executed in your system folders\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Themes & Plugins Editor\u003C\u002Fstrong> to safeguard your website from unauthorized access via the WordPress editor\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide WordPress Version\u003C\u002Fstrong> effortlessly, keeping it hidden from prying eyes\u003C\u002Fli>\n\u003Cli>Use \u003Cstrong>Activity Log\u003C\u002Fstrong> to monitor your site and quickly prevent malicious actions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Post-Hack Actions\u003C\u002Fstrong> to take immediate actions and prevent further damages\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Developed by the website security experts at \u003Ca href=\"https:\u002F\u002Fwww.siteground.com\u002Fwordpress-plugins\u002Fsiteground-security\" rel=\"nofollow ugc\">SiteGround\u003C\u002Fa> and trusted by over 900,000 webmasters for its robust security shield and ease of use to safeguard WordPress applications from possible attacks on any hosting platform.\u003C\u002Fp>\n\u003Ch4>AWARDS:\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.templatemonster.com\u002Fawards\u002Fwinners-2022\u002F\" rel=\"nofollow ugc\">Monster Awards 2022\u003C\u002Fa>: Best WordPress Security Plugin 🥇\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.templatemonster.com\u002Fawards\u002Fwinners-2021\u002F\" rel=\"nofollow ugc\">Monster Awards 2021\u003C\u002Fa>: Best WordPress Security Plugin 🥇\u003C\u002Fp>\n\u003Ch4>Plugin Video\u003C\u002Fh4>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FFOheCz7sm9A?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Plugin Tutorial\u003C\u002Fh4>\n\u003Cp>Unveil the vast array of features and unleash the full potential of our security plugin in our \u003Ca href=\"https:\u002F\u002Fwww.siteground.com\u002Ftutorials\u002Fwordpress\u002Fsg-security\u002F\" rel=\"nofollow ugc\">Security Optimizer Tutorial\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>SITE PROTECTION FEATURES\u003C\u002Fh3>\n\u003Cp>Safeguard your WordPress application using our powerful site security toolset. Our comprehensive features are specifically designed to strengthen your website’s defenses against malware, exploits, and various malicious activities. With these tools at your disposal, you can ensure the utmost bot, malware and brute force protection for your website:\u003C\u002Fp>\n\u003Ch4>Lock and Protect System Folders\u003C\u002Fh4>\n\u003Cp>Ensure the maximum security for your application’s system folders by preventing the execution of any unauthorized or malicious scripts. The Lock and Protect System Folders feature acts as a powerful shield against potential threats.\u003C\u002Fp>\n\u003Ch4>Hide WordPress Version\u003C\u002Fh4>\n\u003Cp>Protect your website from mass attacks by hiding the WordPress version, which helps to mitigate version-specific vulnerabilities.\u003C\u002Fp>\n\u003Ch4>Disable Themes & Plugins Editor\u003C\u002Fh4>\n\u003Cp>Enhance the security of your WordPress admin area by disabling the Themes & Plugins Editor, preventing potential coding errors and unauthorized access through the editor.\u003C\u002Fp>\n\u003Ch4>Disable XML-RPC\u003C\u002Fh4>\n\u003Cp>Mitigate potential security risks by disabling the XML-RPC protocol, which has been exploited in various attacks. Please note that disabling XML-RPC will restrict WordPress from communicating with third-party systems. We recommend enabling this feature unless you have a specific need for it.\u003C\u002Fp>\n\u003Ch4>Disable RSS and ATOM Feeds\u003C\u002Fh4>\n\u003Cp>Prevent content scraping and specific attacks on your site by disabling RSS and ATOM feeds. Unless you have readers accessing your site via RSS readers, it is recommended to keep this feature enabled.\u003C\u002Fp>\n\u003Ch4>Advanced XSS Protection\u003C\u002Fh4>\n\u003Cp>Add an extra layer of website security against cross-site scripting (XSS) attacks by enabling Advanced XSS Protection, bolstering the overall security of your website.\u003C\u002Fp>\n\u003Ch4>Delete Default Readme.html\u003C\u002Fh4>\n\u003Cp>Eliminate potential vulnerabilities by deleting the default readme.txt file, which contains information about your website. By removing this file, you reduce the risk of your site being listed in vulnerable sites targeted by hackers.\u003C\u002Fp>\n\u003Ch3>Login Security\u003C\u002Fh3>\n\u003Ch4>Custom Login Url\u003C\u002Fh4>\n\u003Cp>Personalize your login URL to thwart potential attacks and create a strong entry point. Bid farewell to the default login URL and embrace a bespoke path of your choosing. Additionally, you have the freedom to modify the default sign-up URL as well.\u003C\u002Fp>\n\u003Ch4>Login Access\u003C\u002Fh4>\n\u003Cp>Restrict login page access to specific IP addresses or IP ranges, effectively thwarting malicious login attempts and deterring brute force attacks.\u003C\u002Fp>\n\u003Ch4>2FA (Two-Factor Authentication)\u003C\u002Fh4>\n\u003Cp>Immerse your website in an impenetrable shield of security with 2FA. This formidable feature demands that all admin users furnish a unique token, generated exclusively through the Google Authentication application, during the login process.\u003C\u002Fp>\n\u003Ch4>Disable Common Usernames\u003C\u002Fh4>\n\u003Cp>Don’t fall victim to predictable security breaches! The use of common usernames, such as ‘admin,’ poses a significant threat to the integrity of your website. Activate this option to disable the creation of common usernames. If any weak usernames already exist, we’ll prompt you to provide new, stronger alternatives.\u003C\u002Fp>\n\u003Ch4>Limit Login Attempts\u003C\u002Fh4>\n\u003Cp>Maintain control over unauthorized access attempts with Limit Login Attempts. Set a specific threshold for the number of login failures users can endure before consequences arise. After reaching the limit, the IP address associated with the unsuccessful login attempts will be blocked for one hour. Persistent failures will result in longer restrictions, starting with 24 hours and escalating to a week.\u003C\u002Fp>\n\u003Ch3>ACTIVITY MONITORING\u003C\u002Fh3>\n\u003Cp>Monitor your website and login page for unauthorized visitors and brute force attempts to prevent malicious actions\u003C\u002Fp>\n\u003Ch4>Activity Log\u003C\u002Fh4>\n\u003Cp>The Activity Log page provides you with a comprehensive view of the activities performed by registered, unknown, and blocked visitors. It allows you to closely monitor any suspicious behavior and take appropriate actions in case of a compromised user, plugin, or hacking attempt. You can leverage the quick tools available to swiftly block future attempts.\u003C\u002Fp>\n\u003Ch4>Weekly Security Reports\u003C\u002Fh4>\n\u003Cp>Receive a weekly traffic summary for your website directly to your inbox. This \u003Cstrong>Weekly Security Report\u003C\u002Fstrong> compiles data on both bot and human traffic, along with details about blocked login and visit attempts to proactively monitor traffic and promptly identify suspicious activity.\u003C\u002Fp>\n\u003Ch3>POST-HACK ACTIONS\u003C\u002Fh3>\n\u003Cp>Take immediate measures to protect your website if you suspect a compromise and prevent further damage. Here, you’ll find convenient solutions to address the situation effectively:\u003C\u002Fp>\n\u003Ch4>Reinstall All Free Plugins\u003C\u002Fh4>\n\u003Cp>In the event of a hack, utilizing the Reinstall All Free Plugins feature can help mitigate potential harm. This action reinstalls all of your free plugins, reducing the likelihood of additional exploits or the reuse of malicious code.\u003C\u002Fp>\n\u003Ch4>Log Out All Users\u003C\u002Fh4>\n\u003Cp>To prevent any further unauthorized activities by users or attackers, you can choose to log out all users instantly using the Log Out All Users feature.\u003C\u002Fp>\n\u003Ch4>Force Password Reset\u003C\u002Fh4>\n\u003Cp>By enforcing a password reset, you can ensure that all users are prompted to change their passwords during their next login. This not only strengthens the security of their accounts but also immediately logs out all currently logged-in users.\u003C\u002Fp>\n\u003Ch3>Requirements\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>WordPress 4.7\u003C\u002Fli>\n\u003Cli>PHP 7.0\u003C\u002Fli>\n\u003Cli>Working .htaccess file\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Data Collection\u003C\u002Fh3>\n\u003Cp>Collection of technical data is optional and is \u003Ca href=\"https:\u002F\u002Fwww.siteground.com\u002Fkb\u002Fwhat-information-wp-plugins-collect\" rel=\"nofollow ugc\">listed here\u003C\u002Fa>. This data is collected only for technical analysis, improvements and the possibility to contact the plugin user in case urgent issues need to be fixed (for example a critical security release that needs to be communicated to site owners). The plugin user can manage their preferences within the WP admin to control the collection of technical data. We advise opting in for this data collection, as it can enhance the plugin’s performance. You may find more information on data collection in our \u003Ca href=\"https:\u002F\u002Fwww.siteground.com\u002Fviewtos\u002Fsiteground_plugins_privacy_notice\" rel=\"nofollow ugc\">Plugins Privacy Notice\u003C\u002Fa>.\u003C\u002Fp>\n","Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.",1000000,37020014,90,155,"2026-07-09T14:31:00.000Z",[104,124,52,24,125],"login","web-application-firewall","https:\u002F\u002Fsiteground.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsg-security.1.6.5.zip",88,5,"2025-11-30 00:00:00",{"error":132,"url":133,"statusCode":134,"statusMessage":135,"message":135},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fcleverhog-malware-scanner\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":137,"versions":138},2,[139,145],{"version":6,"download_url":26,"svn_tag_url":140,"released_at":28,"has_diff":141,"diff_files_changed":142,"diff_lines":28,"trac_diff_url":143,"vulnerabilities":144,"is_current":132},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcleverhog-malware-scanner\u002Ftags\u002F1.6.9\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fcleverhog-malware-scanner%2Ftags%2F1.6.8&new_path=%2Fcleverhog-malware-scanner%2Ftags%2F1.6.9",[],{"version":146,"download_url":147,"svn_tag_url":148,"released_at":28,"has_diff":141,"diff_files_changed":149,"diff_lines":28,"trac_diff_url":28,"vulnerabilities":150,"is_current":141},"1.6.8","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcleverhog-malware-scanner.1.6.8.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcleverhog-malware-scanner\u002Ftags\u002F1.6.8\u002F",[],[]]