[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7pKOyfZFN8A5-Vr6HsrWhBQWHXUeTu5zZUObGv_r1fc":3,"$fSGWEa0LmXMiIIpjdewqNgEaVjrApWBXteLYWt-MvgaY":135,"$fk50yw_3g8av3hMDwwQuE_uiq_iZi2gWCrHS1iODYjP4":140},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":38,"analysis":27,"fingerprints":27},"codewp-shield-monitor","CodeWP Shield Monitor","1.4.1","CodeWP","https:\u002F\u002Fprofiles.wordpress.org\u002Fvithanhlam\u002F","\u003Cp>CodeWP Shield Monitor (ShieldPress) adds a careful baseline of WordPress security controls without sending site data to third parties by default.\u003C\u002Fp>\n\u003Cp>Monitor your website health anywhere — visit \u003Ca href=\"https:\u002F\u002Fshieldpress.net\" rel=\"nofollow ugc\">shieldpress.net\u003C\u002Fa> or download the ShieldPress app on \u003Ca href=\"https:\u002F\u002Fapps.apple.com\u002Fapp\u002Fshieldpress\" rel=\"nofollow ugc\">iOS\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fplay.google.com\u002Fstore\u002Fapps\u002Fdetails?id=net.shieldpress.app\" rel=\"nofollow ugc\">Android\u003C\u002Fa> to keep track of your site’s security status, receive real-time alerts, and manage protection settings on the go.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security & Hardening\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Rate limits repeated failed logins by hashed IP address.\u003C\u002Fli>\n\u003Cli>Restricts public user enumeration.\u003C\u002Fli>\n\u003Cli>Adds conservative browser security headers.\u003C\u002Fli>\n\u003Cli>Optionally disables XML-RPC.\u003C\u002Fli>\n\u003Cli>Disables dashboard file editing.\u003C\u002Fli>\n\u003Cli>Hides the default login\u002Fadmin paths behind a custom login slug when enabled.\u003C\u002Fli>\n\u003Cli>Shows failed-login IPs with manual block and unlock controls.\u003C\u002Fli>\n\u003Cli>Adds honeypot fields to login, registration, and comment forms to silently block automated bots.\u003C\u002Fli>\n\u003Cli>Blocks PHP execution inside the uploads directory and prevents uploading dangerous file types.\u003C\u002Fli>\n\u003Cli>Supports comment and registration rate limiting per IP with optional math CAPTCHA challenges.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Monitoring & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records a local security audit log with configurable retention (30 days default).\u003C\u002Fli>\n\u003Cli>Monitors important WordPress files every five minutes using SHA-256 hashes.\u003C\u002Fli>\n\u003Cli>Runs lightweight suspicious-code and database scans with severity-based findings.\u003C\u002Fli>\n\u003Cli>Adds threat intelligence checks for admin anomalies, executable uploads, suspicious options, cron hooks, MU plugins, fake CAPTCHA content, external scripts, cloaking signals, and hardening gaps.\u003C\u002Fli>\n\u003Cli>Ships 38 built-in threat detection patterns covering web shells, backdoors, obfuscation techniques, credit card skimmers, SEO spam, PHP object injection, SQL injection, SSRF, and more — based on real-world CVEs and active malware campaigns (Balada Injector, Sign1, SocGholish, mu-plugins backdoors).\u003C\u002Fli>\n\u003Cli>Skips previously clean malware-scan files while their SHA-256 hash is unchanged.\u003C\u002Fli>\n\u003Cli>Flags external JavaScript and URLs outside the current site domain in source or database content.\u003C\u002Fli>\n\u003Cli>Lets administrators run manual scans or schedule scans daily, weekly, or monthly.\u003C\u002Fli>\n\u003Cli>Emails alerts for administrator logins, blocked login attacks, file changes, and suspicious scan findings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Threat Patterns\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Includes a Web Application Firewall (WAF) to block SQL injection, XSS, path traversal, PHP object injection, SSRF, CRLF injection, and other common attack patterns.\u003C\u002Fli>\n\u003Cli>Provides an extensible threat pattern engine for custom malware signatures, WAF rules, and database content patterns with import\u002Fexport support.\u003C\u002Fli>\n\u003Cli>Rate-limits audit log events to prevent database flooding during brute-force attacks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Activity & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records recent public content create\u002Fupdate activity and new administrator access.\u003C\u002Fli>\n\u003Cli>Records WordPress core, plugin, and theme update events.\u003C\u002Fli>\n\u003Cli>Records plugin and theme lifecycle events, including activation, deactivation, installs, and updates.\u003C\u002Fli>\n\u003Cli>Pushes Contact Form 7 submissions, WooCommerce orders, and selected custom post type creations to the authenticated events API.\u003C\u002Fli>\n\u003Cli>Provides an incident-response summary with prioritized findings and next review steps.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>App & API Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Displays basic WordPress security and update status in wp-admin.\u003C\u002Fli>\n\u003Cli>Provides token-authenticated REST endpoints for the ShieldPress App and Web dashboard.\u003C\u002Fli>\n\u003Cli>Pairs the App using a local QR code and a short-lived, one-time exchange code.\u003C\u002Fli>\n\u003Cli>Creates scoped, one-time quick-login URLs for paired App\u002FWeb clients when enabled.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Tools\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Provides database cleanup tools for spam, revisions, orphaned data, expired transients, and inactive subscriber accounts.\u003C\u002Fli>\n\u003Cli>Offers media optimization with optional thumbnail generation control and automatic WebP conversion on upload.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>CodeWP Shield Monitor hashes IP addresses in its 30-day audit log. For failed-login lockout management, it may also store recent source IP addresses, attempt counts, lockout status, and last failed-login time so administrators can block or unlock those IPs. File contents and post body content are never stored.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>CodeWP Shield Monitor can connect to the official WordPress.org checksum API when the administrator enables core checksum verification. The service is used to compare local WordPress core file hashes with official release hashes. It sends the installed WordPress version and site locale at most once every 12 hours; it does not send stored credentials, file contents, full database values, post body content, audit-log IP hashes, API tokens, or CAPTCHA tokens. WordPress.org provides this service under the WordPress.org Terms of Service and Privacy Policy.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms-of-service\u002F\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>CodeWP Shield Monitor can connect to Cloudflare Turnstile only when an administrator enables CAPTCHA challenges, selects Cloudflare Turnstile, saves a Turnstile site key and secret key, and chooses the forms to protect. Public pages that may contain selected login, registration, or WooCommerce checkout forms can load Cloudflare’s Turnstile JavaScript from challenges.cloudflare.com to display the challenge. During protected form submissions, the plugin sends the Turnstile response token, configured secret key, and visitor IP address to Cloudflare’s siteverify endpoint to validate the challenge. This is required for the optional Turnstile CAPTCHA feature.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\u003C\u002Fp>\n\u003Cp>CodeWP Shield Monitor can connect to Google reCAPTCHA only when an administrator enables CAPTCHA challenges, selects Google reCAPTCHA v2 or v3, saves a reCAPTCHA site key and secret key, and chooses the forms to protect. Public pages that may contain selected login, registration, or WooCommerce checkout forms can load Google’s reCAPTCHA JavaScript from google.com to display or run the challenge. During protected form submissions, the plugin sends the reCAPTCHA response token, configured secret key, and visitor IP address to Google’s siteverify endpoint to validate the challenge. When Google reCAPTCHA v3 is selected, the plugin also checks the returned score against the configured threshold, which defaults to 0.1. This is required for the optional Google reCAPTCHA feature.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n","Privacy-first WordPress security hardening, login protection, and local audit logging.",30,200,0,"2026-07-15T09:48:00.000Z","7.0.2","6.4","7.4",[19,20,21,22,23],"audit-log","hardening","login","privacy","security","https:\u002F\u002Fshieldpress.net","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcodewp-shield-monitor.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":34,"avg_security_score":35,"avg_patch_time_days":11,"trust_score":36,"computed_at":37},"vithanhlam",3,70,95,91,"2026-08-25T02:47:08.022Z",[39,62,80,99,115],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":47,"downloaded":48,"rating":49,"num_ratings":50,"last_updated":51,"tested_up_to":15,"requires_at_least":52,"requires_php":17,"tags":53,"homepage":58,"download_link":59,"security_score":26,"vuln_count":60,"unpatched_count":13,"last_vuln_date":61,"fetched_at":28},"wp-login-and-logout-redirect","Entryway – WP Login & Logout Redirect","4.0.0","Md Aminur Islam","https:\u002F\u002Fprofiles.wordpress.org\u002Faminurislam01\u002F","\u003Cp>Entryway – WP Login and Logout Redirect gives you full control over where users land after they sign in or out of your site — from a simple pair of default URLs to powerful per-role redirect rules. On top of that, it records login activity in a searchable audit log, alerts you by email when important users sign in, and lets you see (and force out) everyone currently logged in.\u003C\u002Fp>\n\u003Cp>Everything is managed from a fast, modern settings screen built with React — no page reloads, instant feedback, and a clean design that feels right at home in your WordPress admin.\u003C\u002Fp>\n\u003Ch4>🔀 Smart Redirect Rules\u003C\u002Fh4>\n\u003Cp>Go beyond one-size-fits-all redirects. Build an ordered list of rules and send different users to different places:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Target users by \u003Cstrong>role\u003C\u002Fstrong>, \u003Cstrong>specific user\u003C\u002Fstrong>, or \u003Cstrong>capability\u003C\u002Fstrong> — combine multiple conditions in one rule (all must match).\u003C\u002Fli>\n\u003Cli>Rules are evaluated \u003Cstrong>top to bottom; the first match wins\u003C\u002Fstrong> — reorder them with drag and drop.\u003C\u002Fli>\n\u003Cli>Each rule sets its own login and\u002For logout destination.\u003C\u002Fli>\n\u003Cli>Toggle rules on and off without deleting them.\u003C\u002Fli>\n\u003Cli>Personalize destination URLs with placeholders: \u003Ccode>{{username}}\u003C\u002Fcode>, \u003Ccode>{{user_slug}}\u003C\u002Fcode> and \u003Ccode>{{website_url}}\u003C\u002Fcode> — one click copies a placeholder to your clipboard.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🎯 Default Redirects\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Set a site-wide login redirect URL and logout redirect URL used whenever no rule matches.\u003C\u002Fli>\n\u003Cli>Leave a field empty to keep the WordPress default (dashboard after login, homepage after logout).\u003C\u002Fli>\n\u003Cli>Works with WooCommerce login too.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>📋 Audit Log\u003C\u002Fh4>\n\u003Cp>Know exactly who signed in, when, and from where:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records \u003Cstrong>logins, logouts, failed logins and forced logouts\u003C\u002Fstrong> with IP address, browser and OS.\u003C\u002Fli>\n\u003Cli>At-a-glance stat cards plus a searchable, filterable event table.\u003C\u002Fli>\n\u003Cli>Automatic cleanup — keep events for 7, 30 or 90 days, or forever.\u003C\u002Fli>\n\u003Cli>Delete single entries or clear the whole log at any time. Logging is off until you enable it.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>👥 Logged-in Users\u003C\u002Fh4>\n\u003Cp>A live view of every active session on your site:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>See who is currently logged in, their role, when they signed in and when the session expires.\u003C\u002Fli>\n\u003Cli>Inspect each user’s individual sessions (device, browser, IP).\u003C\u002Fli>\n\u003Cli>Force logout a single session, a user, a selection of users — or everyone at once (with an option to keep yourself logged in).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>📧 Email Notifications\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Get an instant email when a user with a role you watch (e.g. Administrator) signs in.\u003C\u002Fli>\n\u003Cli>Receive a \u003Cstrong>daily, weekly or monthly digest\u003C\u002Fstrong> summarizing login activity.\u003C\u002Fli>\n\u003Cli>Send notifications to any address — defaults to the site admin email.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🕐 Last Login Column\u003C\u002Fh4>\n\u003Cp>Every user’s most recent login date and time appears in a sortable column on the Users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> All Users screen.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>When audit logging is enabled, each event stores the user’s IP address and browser. Alert and digest emails include this login metadata and are sent only to the configured notification address (the site admin email by default). Notifications are off until you opt in.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>If you find this plugin useful, consider supporting its development through a \u003Ca href=\"https:\u002F\u002Fwww.buymeacoffee.com\u002Faiarnob\" rel=\"nofollow ugc\">donation\u003C\u002Fa>.\u003C\u002Fp>\n","Redirect users to any URL after login or logout with per-role rules, a searchable audit log, live session management, and email notifications.",6000,68842,96,5,"2026-07-17T21:12:00.000Z","6.6",[19,54,55,56,57],"login-redirect","login-security","logout-redirect","redirect","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-login-and-logout-redirect\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-login-and-logout-redirect.4.0.0.zip",1,"2024-04-10 00:00:00",{"slug":63,"name":64,"version":65,"author":66,"author_profile":67,"description":68,"short_description":69,"active_installs":12,"downloaded":70,"rating":13,"num_ratings":13,"last_updated":71,"tested_up_to":15,"requires_at_least":72,"requires_php":73,"tags":74,"homepage":78,"download_link":79,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"security-hardener","Security Hardener","2.4.4","Marc Armengou","https:\u002F\u002Fprofiles.wordpress.org\u002Fmarc4\u002F","\u003Cp>\u003Cstrong>Security Hardener\u003C\u002Fstrong> applies WordPress security best practices based on the \u003Ca href=\"https:\u002F\u002Fdeveloper.wordpress.org\u002Fadvanced-administration\u002Fsecurity\u002Fhardening\u002F\" rel=\"nofollow ugc\">WordPress Advanced Administration \u002F Security \u002F Hardening\u003C\u002Fa> documentation and widely accepted hardening measures. It uses WordPress core functions and follows best practices without modifying core files.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>File Security:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Disable file editor in WordPress admin\u003Cbr \u002F>\n* Optionally disable all file modifications\u003C\u002Fp>\n\u003Cp>\u003Cstrong>XML-RPC Protection:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Disable XML-RPC completely\u003Cbr \u002F>\n* Remove pingback methods when XML-RPC is enabled\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Pingback Protection:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Disable self-pingbacks\u003Cbr \u002F>\n* Remove X-Pingback header\u003Cbr \u002F>\n* Block incoming pingbacks\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Enumeration Protection:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Block \u003Ccode>\u002F?author=N\u003C\u002Fcode> queries (returns 404)\u003Cbr \u002F>\n* Secure REST API user endpoints (require authentication)\u003Cbr \u002F>\n* Remove users from XML sitemaps\u003Cbr \u002F>\n* Prevent canonical redirects that expose usernames\u003Cbr \u002F>\n* Optionally block author feed pages (\u003Ccode>\u002Fauthor\u002Fusername\u002Ffeed\u002F\u003C\u002Fcode>)\u003Cbr \u002F>\n* Optionally anonymize the author name in oEmbed responses\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Security:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Generic error messages (no username\u002Fpassword hints)\u003Cbr \u002F>\n* Login honeypot\u003Cbr \u002F>\n* Block unsafe usernames\u003Cbr \u002F>\n* Application Passwords disabled by default\u003Cbr \u002F>\n* IP-based rate limiting with configurable thresholds\u003Cbr \u002F>\n* Security event logging\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Headers:\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Ccode>X-Frame-Options: SAMEORIGIN\u003C\u002Fcode> (clickjacking protection)\u003Cbr \u002F>\n* \u003Ccode>X-Content-Type-Options: nosniff\u003C\u002Fcode> (MIME sniffing protection)\u003Cbr \u002F>\n* \u003Ccode>Referrer-Policy: strict-origin-when-cross-origin\u003C\u002Fcode>\u003Cbr \u002F>\n* \u003Ccode>Permissions-Policy\u003C\u002Fcode> (restricts geolocation, microphone, camera)\u003Cbr \u002F>\n* Optional HSTS (HTTP Strict Transport Security) for HTTPS sites — max-age set to 1 year\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Additional Hardening:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Hide WordPress version (meta generator tag and asset query strings)\u003Cbr \u002F>\n* Remove obsolete wp_head items (RSD, WLW manifest, shortlink, emoji scripts)\u003Cbr \u002F>\n* System Status — monitors file permissions, WP_DEBUG, user registration, PHP version, administrator accounts, and database version\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>⚠️ \u003Cstrong>Important:\u003C\u002Fstrong> Always test security settings in a staging environment first. Some features may affect third-party integrations or plugins.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong> This plugin does not send data to external services and does not create custom database tables. It stores plugin settings and a security event log in the WordPress options table, and uses transients for temporary login attempt tracking. All data is preserved on uninstall by default and only deleted if the “Delete all data on uninstall” option is explicitly enabled.\u003C\u002Fp>\n","Basic hardening: secure headers, login honeypot, user enumeration blocking, generic login errors, rate limiting, and more.",1779,"2026-06-13T18:25:00.000Z","6.9","8.2",[75,20,76,77,23],"brute-force","headers","login-protection","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsecurity-hardener\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecurity-hardener.2.4.4.zip",{"slug":81,"name":82,"version":83,"author":84,"author_profile":85,"description":86,"short_description":87,"active_installs":88,"downloaded":89,"rating":13,"num_ratings":13,"last_updated":90,"tested_up_to":91,"requires_at_least":92,"requires_php":93,"tags":94,"homepage":96,"download_link":97,"security_score":98,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"cellarweb-privacy-and-security-options","CellarWeb Privacy and Security Options","4.17","Rick Hellewell","https:\u002F\u002Fprofiles.wordpress.org\u002Frhellewellgmailcom\u002F","\u003Cp>Secure your WP site with common security settings that you can selectively enable. Includes several security and anti-hacking features, plus some customization of your login screen. Disables certain functions\u002Fprocesses that are potential security issues. Can block some comment spam (although our Block Comment Spam plugin \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fblock-comment-spam-bots\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fblock-comment-spam-bots\u002F\u003C\u002Fa> is more effective). Can ncrease memory allocations. Shows your current htaccess file contents with suggestions for improvements, so you can monitor any changes.\u003C\u002Fp>\n\u003Cp>NEW FEATURES:\u003Cbr \u002F>\n – Optionally adds directives to the WordPress virtual robots.txt file to block site scanning by AI bots. This blocks the use of your site content by those AI agents, such as ChatGPT, OpenAI, Bard, and others. It does not affect search engine scanning or any SEO, nor does it affect the user experience of your site.\u003Cbr \u002F>\n– Now shows any hidden plugins (which might be malicious), plus lists all plugins with versions and status (active, inactive).\u003C\u002Fp>\n\u003Cp>We use this on all of our managed WordPress sites, as a convenient way to secure the sites without using a bunch of different plugins.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>This plugin can be downloaded for free without any paid subscription from the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcellarweb-privacy-and-security-options\u002F\" rel=\"ugc\">official WordPress repository\u003C\u002Fa>.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>BEGIN – Added by ChatBot Blocker by CellarWeb plugin (Version 1.03)\u003C\u002Fh3>\n\u003Cpre>\u003Ccode>      #  Blocks ChatGPT bot scanning\n            User-agent: GPTBot\n            Disallow: \u002F\n      #  Blocks Bard bot scanning\n            User-agent: Bard\n            Disallow: \u002F\n      #  Blocks Bing bot scanning\n            User-agent: bingbot-chat\u002F2.0\n            Disallow: \u002F\n      #  Blocks Common Crawl bot scanning\n            User-agent: CCBot\n            Disallow: \u002F\n      #  Blocks omgili bot scanning\n            User-agent: Omgili\n            Disallow: \u002F\n      #  Blocks omgilibot bot scanning\n            User-agent: Omgili Bot\n            Disallow: \u002F\n      #  Blocks Diffbot bot scanning\n            User-agent: Diffbot\n            Disallow: \u002F\n      #  Blocks MJ12bot bot scanning\n            User-agent: MJ12bot\n            Disallow: \u002F\n      #  Blocks anthropic-ai bot scanning\n            User-agent: anthropic-ai\n            Disallow: \u002F\n      #  Blocks ClaudeBot bot scanning\n            User-agent: ClaudeBot\n            Disallow: \u002F\n      #  Blocks FacebookBot bot scanning\n            User-agent: FacebookBot\n            Disallow: \u002F\n      #  Blocks Google-Extended bot scanning\n            User-agent: Google-Extended\n            Disallow: \u002F\n      #  Blocks SentiBot bot scanning\n            User-agent: SentiBot\n            Disallow: \u002F\n      #  Blocks sentibot bot scanning\n            User-agent: sentibot\n            Disallow: \u002F\u003Ch3>END    - Added by ChatBot Blocker by CellarWeb plugin (Version 1.03)\u003C\u002Fh3>\n`\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>See additional chatbot agents added in the changelog below.\u003C\u002Fp>\n\u003Ch4>htaccess Security Settings\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Shows the current htaccess file for review. (Hackers like to change it, so it’s good to take a peek at it now and again.)\u003C\u002Fli>\n\u003Cli>Some suggestions for additional htaccess commands are shown.\u003C\u002Fli>\n\u003Cli>No changes are made to the htaccess file.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Wow! That’s a lot of settings!\u003C\u002Fh4>\n\u003Cp>Yep. But they are ones that we commonly use in all of our managed WP sites, so putting them into one plugin was easier than doing it manually on every site.\u003C\u002Fp>\n\u003Ch4>What if I want an additional setting?\u003C\u002Fh4>\n\u003Cp>Just add a message in the plugin’s support area. We’ll consider it.\u003C\u002Fp>\n\u003Ch4>Do you have other security-related plugins?\u003C\u002Fh4>\n\u003Cp>Yep!  One of our favorites will block all comment spam – and another that blocks bots from contact forms. It’s very effective. We put it on one site that was getting a lot of comment spam, and now there is none. Not one. And we don’t get any contact form spam on sites that use the technique.\u003C\u002Fp>\n\u003Cp>It’s called “Block Comment Spam Bots”, and can be found in the WP plugin repository. And there’s a link to it (and other plugins we’ve done) on this plugin’s Settings\u002FInformation page.  The Contact Form bot-blocker is called “FormSpammerTrap”, and is available at \u003Ca href=\"https:\u002F\u002Fwww.FormSpammerTrap.com\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.FormSpammerTrap.com\u003C\u002Fa> .\u003C\u002Fp>\n\u003Cp>Check out all our plugins at \u003Ca href=\"https:\u002F\u002Fcellarweb.com\u002Fwordpress-plugins\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fcellarweb.com\u002Fwordpress-plugins\u002F\u003C\u002Fa> .\u003C\u002Fp>\n","Security and privacy settings for your site, all in one place.",20,3041,"2024-08-30T20:28:00.000Z","6.6.5","4.9.6","7.2",[95],"site-security-privacy-safety-hardening","https:\u002F\u002Fwww.cellarweb.com\u002Fwordpress-plugins\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcellarweb-privacy-and-security-options.zip",92,{"slug":100,"name":101,"version":102,"author":103,"author_profile":104,"description":105,"short_description":106,"active_installs":88,"downloaded":107,"rating":13,"num_ratings":13,"last_updated":108,"tested_up_to":15,"requires_at_least":109,"requires_php":17,"tags":110,"homepage":113,"download_link":114,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"manicsoup-logger","ManicSoup Activity Log & Security Monitoring","2.0.0","ManicSoup","https:\u002F\u002Fprofiles.wordpress.org\u002Fmanicsoup\u002F","\u003Cp>ManicSoup Activity Log keeps a detailed, searchable record of everything that happens on your WordPress site — the who, what, when, and from-where of each change. Use it to monitor for security issues, hold users accountable, and troubleshoot problems fast.\u003C\u002Fp>\n\u003Cp>Everything logs to a dedicated database table (it doesn’t bloat your posts table) and shows up in a clean, fast admin viewer with search, filtering, and CSV export. No external service, no account required — your data stays on your site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What gets logged\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Logins & sessions\u003C\u002Fstrong> — successful logins, logouts, and failed login attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content\u003C\u002Fstrong> — publishing, editing, status changes, trashing, restoring, and deleting posts, pages, and custom post types.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Users\u003C\u002Fstrong> — registrations, deletions, role changes, profile edits, password changes and resets.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugins & themes\u003C\u002Fstrong> — installs, activations, deactivations, updates, deletions, and theme switches.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>System\u003C\u002Fstrong> — WordPress core updates and changes to key site settings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Built-in attack detection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The plugin watches your login activity and alerts you by email when it spots trouble — repeated failed logins, attacks targeting your admin or specific accounts, and logins from new locations. You stay informed about credential attacks as they happen.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Full activity logging engine\u003C\u002Fli>\n\u003Cli>Searchable, sortable, paginated log viewer\u003C\u002Fli>\n\u003Cli>Free-text search across the log\u003C\u002Fli>\n\u003Cli>CSV export of the current view\u003C\u002Fli>\n\u003Cli>Enable or disable individual event types\u003C\u002Fli>\n\u003Cli>Exclude specific users or IP addresses from logging\u003C\u002Fli>\n\u003Cli>Configurable retention (auto-purge old entries, or keep forever)\u003C\u002Fli>\n\u003Cli>Reverse proxy \u002F WAF support (resolves real client IPs)\u003C\u002Fli>\n\u003Cli>Attack detection & email alerts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Everything listed above is fully functional with no restrictions, no license key, and no time limits.\u003C\u002Fp>\n\u003Ch3>A separate premium edition\u003C\u002Fh3>\n\u003Cp>A separate premium edition of this plugin, with additional investigation, response, and automation tools, is available from the developer at https:\u002F\u002Fwww.manicsoup.com\u002F. The premium edition is a distinct product and is not hosted on WordPress.org. This free edition is complete and fully functional on its own; you never need the premium edition to use everything described above.\u003C\u002Fp>\n","A clean, self-hosted WordPress activity log with built-in attack detection. See who did what, when, and where — and catch credential attacks.",98,"2026-07-12T18:06:00.000Z","5.5",[111,19,55,23,112],"activity-log","user-activity","https:\u002F\u002Fmanicsoup.com\u002Fharvest\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmanicsoup-logger.2.0.0.zip",{"slug":116,"name":117,"version":118,"author":119,"author_profile":120,"description":121,"short_description":122,"active_installs":123,"downloaded":124,"rating":13,"num_ratings":13,"last_updated":125,"tested_up_to":126,"requires_at_least":127,"requires_php":128,"tags":129,"homepage":132,"download_link":133,"security_score":134,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"behind-closed-doors","Behind Closed Doors","1.1","spencersokol","https:\u002F\u002Fprofiles.wordpress.org\u002Fspencersokol\u002F","\u003Cp>Keep your site behind closed doors with this plugin, by redirecting visitors to a single page, and optionally giving users a login form to view the remainder of your site.\u003C\u002Fp>\n\u003Cp>Basic uses:\u003Cbr \u002F>\n1. Keeping your site hidden while in initial development, while still allowing test users and clients to login\u003Cbr \u002F>\n2. Putting your site in a “maintenance mode” quickly\u003C\u002Fp>\n\u003Ch3>Upgrade Notices\u003C\u002Fh3>\n\u003Ch3>Future Releases\u003C\u002Fh3>\n","Keep your site behind closed doors, by redirecting visitors to a single page, optionally giving them a login form to view the remainder of your site.",10,1938,"2019-02-14T20:04:00.000Z","5.0.25","3.5","",[21,130,131,22,23],"maintenance","maintenance-mode","http:\u002F\u002Fspencersokol.com\u002Fprojects\u002Fbehind-closed-doors\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbehind-closed-doors.1.1.zip",85,{"error":136,"url":137,"statusCode":138,"statusMessage":139,"message":139},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fcodewp-shield-monitor\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":60,"versions":141},[142],{"version":143,"download_url":144,"svn_tag_url":145,"released_at":27,"has_diff":146,"diff_files_changed":147,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":148,"is_current":146},"1.3.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcodewp-shield-monitor.1.3.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcodewp-shield-monitor\u002Ftags\u002F1.3.2\u002F",false,[],[]]