[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftY8pgzyrroRd-bNLQM5Gk1lwpZZtmso0dt3PBHlU1sI":3,"$fFj6rZ0EMts81EKBUtfzhYSfp3MPDVn63QotQjsjALno":122,"$fjDNG6Kg2DG4YZHi8hHnEPWoDUDI8k8xDX3Mf9K6LETI":127},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"cybernote-security-checker","CyberNote Security Checker","1.0.0","teeeda1129","https:\u002F\u002Fprofiles.wordpress.org\u002Fteeeda1129\u002F","\u003Cp>CyberNote Security Checker is a lightweight plugin that audits your WordPress site’s security posture without sending any data to external servers.\u003C\u002Fp>\n\u003Cp>Many security plugins are powerful but heavy, English-only, and full of technical jargon. CyberNote Security Checker takes the opposite approach: it targets Japanese individual bloggers and small business owners who need to understand exactly what to do — delivered quickly and without specialist knowledge.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>12 diagnostic checks. Zero external requests.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A widget appears on the WordPress dashboard showing results in three levels: good (no action needed) \u002F attention (improvement recommended) \u002F recommended (priority action required). Each item includes a plain-Japanese explanation of the risk and step-by-step remediation guidance.\u003C\u002Fp>\n\u003Ch4>Category A: Version Freshness (3 checks)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>WordPress core\u003C\u002Fstrong> — Detects whether security-only maintenance releases are unapplied. Distinguishes urgency between security patches and feature updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP version\u003C\u002Fstrong> — Evaluated against official PHP support status. End-of-life versions flagged as “priority action”; security-only branches as “attention”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin and theme updates\u003C\u002Fstrong> — Displays the count and names of pending updates. A direct link opens the standard WordPress update screen; the plugin never performs updates itself.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Category B: Hardening Settings (9 checks)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Debug display\u003C\u002Fstrong> — WP_DEBUG with screen output on a production site is flagged as “priority action”; log-only mode as “attention”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File editing\u003C\u002Fstrong> — If the theme and plugin code editor is enabled in the admin panel, flagged as “priority action”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin username\u003C\u002Fstrong> — If a user named admin or administrator exists, flagged as “attention” (changing it carries migration risk, so no urgent push).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HTTPS\u003C\u002Fstrong> — Sites running on plain HTTP are flagged as “priority action”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database table prefix\u003C\u002Fstrong> — Default wp_ prefix flagged as “attention” (live-site changes carry risk, so no urgent push).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC\u003C\u002Fstrong> — Enabled XML-RPC is flagged as “attention”; use-case guidance included before recommending disablement.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API user enumeration\u003C\u002Fstrong> — If anonymous requests to \u002Fwp\u002Fv2\u002Fusers return user data, flagged as “attention”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security keys (salts)\u003C\u002Fstrong> — Checks whether the wp-config.php authentication unique keys and salts are set and not left at the default placeholder. Missing or default keys are flagged as “priority action” (login cookies could be forged). Key values are never read out or displayed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unused plugins and themes\u003C\u002Fstrong> — Inactive plugins and unused themes still ship files on the server that can be exploited if vulnerable. Their presence is flagged as “attention” with removal guidance (keeping one fallback theme is fine).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Design Principles\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Read-only\u003C\u002Fstrong> — The plugin only presents diagnostic results. It never automatically changes site settings or files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external requests\u003C\u002Fstrong> — Every check reads WordPress built-in APIs and site configuration only. Nothing leaves your server.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight\u003C\u002Fstrong> — No real-time file scanning, no custom WAF, no resident processes. Diagnostics run once when the admin page loads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plain language\u003C\u002Fstrong> — Technical terms are avoided. Each check explains why it matters and what to do in everyday language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Vulnerability alerts (separate external service)\u003C\u002Fh4>\n\u003Cp>This plugin is free and fully functional on its own. Matching your installed plugins and themes against external vulnerability databases (CVE) requires server-side processing that cannot be done locally, so it is offered separately as an external service called CyberNote, not bundled in this plugin. See https:\u002F\u002Fwww.cybernote.click\u002Fwp-security-checker-guide\u002F for details.\u003C\u002Fp>\n","Diagnoses WordPress security settings and version status, presenting plain-language improvement steps in Japanese. No external requests. Lightweight.",0,84,"2026-07-03T12:26:00.000Z","7.0.2","5.9","7.4",[18,19,20,21,22],"audit","diagnostic","hardening","maintenance","security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcybernote-security-checker.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},1,30,94,"2026-08-26T02:26:04.582Z",[36,52,69,89,107],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":25,"downloaded":44,"rating":11,"num_ratings":11,"last_updated":45,"tested_up_to":14,"requires_at_least":46,"requires_php":16,"tags":47,"homepage":50,"download_link":51,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"aipatch-security-scanner","Aipatch Security Scanner","2.0.2","Esteban","https:\u002F\u002Fprofiles.wordpress.org\u002Festebandezafra\u002F","\u003Cp>\u003Cstrong>Aipatch Security Scanner\u003C\u002Fstrong> is a modular security audit engine built for site owners, developers, and AI-powered agents who need deep visibility into WordPress security posture — without the bloat of all-in-one security suites.\u003C\u002Fp>\n\u003Ch4>Why Aipatch Security Scanner?\u003C\u002Fh4>\n\u003Cp>Most WordPress security plugins are either too simple to be useful or too heavy to be practical. Aipatch takes a different approach:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Audit-first architecture.\u003C\u002Fstrong> Every check is a standalone, testable module that returns structured findings with severity, confidence, evidence, and fingerprints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built for automation.\u003C\u002Fstrong> 23 MCP abilities expose the full audit, scanning, and remediation surface to external AI agents — making Aipatch the first WordPress security plugin designed for agentic workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero external dependencies.\u003C\u002Fstrong> Everything runs locally. No accounts, no cloud services, no API keys required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reversible by design.\u003C\u002Fstrong> Every automated remediation stores rollback data so you can undo any change with one click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Core Capabilities\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>36-Point Security Audit\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Aipatch runs 36 automated checks across 8 categories — core, plugins, themes, users, configuration, server, access control, and malware surface:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Outdated WordPress core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Default admin username, excessive admin accounts, inactive admin users, user ID 1 exposure\u003C\u002Fli>\n\u003Cli>XML-RPC, file editor, debug mode, debug log, REST API exposure, directory listing\u003C\u002Fli>\n\u003Cli>PHP version, HTTPS, file permissions, security headers (X-Frame-Options, CSP, etc.)\u003C\u002Fli>\n\u003Cli>Database prefix, sensitive files, PHP execution in uploads, auto-update configuration\u003C\u002Fli>\n\u003Cli>Salt key strength, cron health, cookie security flags, CORS, application passwords\u003C\u002Fli>\n\u003Cli>Exposed backup files, phpinfo files, uploads directory indexing, default login URL\u003C\u002Fli>\n\u003Cli>Database credential security, file installation permissions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Every finding includes a severity (critical \u002F high \u002F medium \u002F low \u002F info), confidence score, human-readable explanation, and actionable recommendation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Weighted Security Score (0–100)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A logarithmic scoring engine computes an overall security score and per-area breakdown across six risk dimensions: software, access control, configuration, infrastructure, malware surface, and vulnerability exposure. Severity weights and confidence multipliers ensure the score reflects actual risk, not just issue count.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Multi-Layer Malware File Scanner\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A three-layer file scanner (content 55%, context 25%, integrity 20%) with 27 detection signatures, Shannon entropy analysis, and malware family classification detects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Code execution patterns: eval(), assert(), create_function(), preg_replace \u002Fe\u003C\u002Fli>\n\u003Cli>System command functions: shell_exec, exec, passthru, backtick operators\u003C\u002Fli>\n\u003Cli>Obfuscation techniques: base64 encoding, hex encoding, str_rot13, gzinflate chains, chr() concatenation, variable variables, suspiciously long lines\u003C\u002Fli>\n\u003Cli>Network\u002Fexfiltration: cURL execution, fsockopen, remote file_get_contents\u003C\u002Fli>\n\u003Cli>Known backdoor signatures: c99, r57, WSO, b374k, weevely, FilesMan\u003C\u002Fli>\n\u003Cli>WordPress-specific threats: unauthorized admin creation, critical option injection, security function removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Scanning runs in batches via an async job system with configurable batch sizes — safe for shared hosting.\u003C\u002Fp>\n\u003Cp>Files are classified into 11 malware families (web shell, obfuscated loader, dropper, persistence backdoor, cloaked PHP, code injector, and more) with confidence scores and remediation hints.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Core Integrity Verification\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Verifies every core file against official checksums from api.wordpress.org. Detects modified core files (checksum mismatch), missing core files, and unexpected files planted in wp-admin\u002F or wp-includes\u002F. Core tampering findings are automatically escalated to critical severity with zero false-positive likelihood.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Build a known-good hash baseline of all PHP files in your installation. Diff against it at any time to detect modified, deleted, or newly added files. Origin detection distinguishes core, plugin, theme, and upload files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A local knowledge base of known plugin, theme, and core vulnerabilities with a database-backed caching layer for fast lookups. Provider architecture allows extending with external feeds.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-Click Remediation with Rollback\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Apply fixes directly from findings — change WordPress options, delete suspicious files, rename files, patch file contents, or add .htaccess rules. Every automated action stores a full rollback payload so you can reverse any change. Manual remediations can be logged for audit trails.\u003C\u002Fp>\n\u003Cp>Six supported action types: \u003Ccode>wp_option\u003C\u002Fcode>, \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>rename_file\u003C\u002Fcode>, \u003Ccode>file_patch\u003C\u002Fcode>, \u003Ccode>htaccess_rule\u003C\u002Fcode>, \u003Ccode>manual\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hardening Module\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Five toggleable hardening rules with clear explanations and compatibility warnings:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable XML-RPC — blocks external XML-RPC requests and removes X-Pingback header\u003C\u002Fli>\n\u003Cli>Hide WordPress Version — removes version leaks from source, RSS feeds, scripts, and styles\u003C\u002Fli>\n\u003Cli>Restrict REST API — limits sensitive endpoints to authenticated users\u003C\u002Fli>\n\u003Cli>Block Author Scanning — prevents user enumeration via author archives\u003C\u002Fli>\n\u003Cli>Login Brute-Force Protection — rate-limits login attempts per IP with configurable thresholds and lockout duration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Persistent Findings Store\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All audit findings persist in a dedicated database table with automatic deduplication by fingerprint. Track findings over time — dismissed findings stay dismissed across scans; resolved findings reopen if the issue reappears.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Event Logging\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Every scan, hardening change, remediation, and significant event is logged to a dedicated table. Logs are filterable by severity and exportable as CSV.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Site Health Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Adds 6 security tests to the built-in Site Health screen: file editor, debug mode, XML-RPC, admin username, SSL, and overall security score.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Diagnostics\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Built-in performance profiling to identify slow queries, high memory usage, and resource bottlenecks related to security operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>10 authenticated endpoints under the \u003Ccode>aipatch-security-scanner\u002Fv1\u003C\u002Fcode> namespace for triggering scans, retrieving summaries, toggling hardening, exporting logs, and running performance diagnostics.\u003C\u002Fp>\n\u003Ch4>MCP Surface for AI Agents (23 Abilities)\u003C\u002Fh4>\n\u003Cp>Aipatch exposes 23 structured abilities via the WordPress Abilities API — making your site’s security surface fully accessible to external AI agents, coding assistants, and orchestration tools:\u003C\u002Fp>\n\u003Cp>By default, only \u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> is enabled. You can enable additional abilities from \u003Cstrong>Aipatch Security Scanner -> Settings -> MCP Abilities\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> — Run a full 36-check security audit with scored findings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-suspicious\u003C\u002Fstrong> — Quick heuristic scan for suspicious files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fstart-file-scan\u003C\u002Fstrong> — Launch an async multi-layer malware scan job\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fprocess-file-scan-batch\u003C\u002Fstrong> — Process next batch of files in a running scan\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-progress\u003C\u002Fstrong> — Check file scan progress\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-results\u003C\u002Fstrong> — Retrieve enriched scan results with family, reasons, layer scores\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-scan-summary\u003C\u002Fstrong> — Comprehensive latest scan summary with classification breakdown\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-suspicious-files\u003C\u002Fstrong> — List suspicious files from latest scan (no job_id needed)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Integrity & Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fverify-core-integrity\u003C\u002Fstrong> — Verify WP core files against official api.wordpress.org checksums\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-build\u003C\u002Fstrong> — Build or refresh the known-good file hash baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-diff\u003C\u002Fstrong> — Compare current filesystem against stored baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-stats\u003C\u002Fstrong> — Baseline statistics by origin type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-baseline-drift\u003C\u002Fstrong> — Combined baseline drift + core integrity report\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Findings & Monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-findings\u003C\u002Fstrong> — Query persistent findings with status\u002Fseverity\u002Fcategory filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-stats\u003C\u002Fstrong> — Aggregate finding statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-diff\u003C\u002Fstrong> — New and resolved findings since a point in time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-file-finding-detail\u003C\u002Fstrong> — Single finding with decoded metadata, layer scores, family\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fdismiss-finding\u003C\u002Fstrong> — Dismiss a finding as accepted risk\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Remediation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fapply-remediation\u003C\u002Fstrong> — Apply a security fix with rollback support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Frollback-remediation\u003C\u002Fstrong> — Undo a previously applied fix\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-remediations\u003C\u002Fstrong> — List remediation history with filters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Jobs & Status\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-jobs\u003C\u002Fstrong> — List scan\u002Faudit jobs with filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-async-job-status\u003C\u002Fstrong> — Check async job status and retrieve results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>20 abilities are read-only; only 3 (dismiss, apply-remediation, rollback) modify site state. All abilities include typed input\u002Foutput schemas, permission checks (\u003Ccode>manage_options\u003C\u002Fcode>), and structured error responses.\u003C\u002Fp>\n\u003Ch4>What Aipatch Does NOT Do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>It is NOT a firewall or WAF — it does not filter incoming traffic.\u003C\u002Fli>\n\u003Cli>It does NOT intercept frontend requests or affect page load performance.\u003C\u002Fli>\n\u003Cli>It does NOT phone home, require an account, or send data externally.\u003C\u002Fli>\n\u003Cli>It does NOT inject ads, upsells, or nag notices.\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress security scanner with 36 checks, malware scanning, core integrity verification, remediation, and 23 MCP abilities.",477,"2026-05-03T09:18:00.000Z","6.5",[18,20,48,22,49],"malware-scanner","vulnerability","https:\u002F\u002Fgithub.com\u002Festebanstifli\u002Faipatch-security-scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.2.0.2.zip",{"slug":53,"name":54,"version":55,"author":56,"author_profile":57,"description":58,"short_description":59,"active_installs":32,"downloaded":60,"rating":11,"num_ratings":11,"last_updated":61,"tested_up_to":14,"requires_at_least":62,"requires_php":16,"tags":63,"homepage":67,"download_link":68,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"codewp-shield-monitor","CodeWP Shield Monitor","1.4.1","CodeWP","https:\u002F\u002Fprofiles.wordpress.org\u002Fvithanhlam\u002F","\u003Cp>CodeWP Shield Monitor (ShieldPress) adds a careful baseline of WordPress security controls without sending site data to third parties by default.\u003C\u002Fp>\n\u003Cp>Monitor your website health anywhere — visit \u003Ca href=\"https:\u002F\u002Fshieldpress.net\" rel=\"nofollow ugc\">shieldpress.net\u003C\u002Fa> or download the ShieldPress app on \u003Ca href=\"https:\u002F\u002Fapps.apple.com\u002Fapp\u002Fshieldpress\" rel=\"nofollow ugc\">iOS\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fplay.google.com\u002Fstore\u002Fapps\u002Fdetails?id=net.shieldpress.app\" rel=\"nofollow ugc\">Android\u003C\u002Fa> to keep track of your site’s security status, receive real-time alerts, and manage protection settings on the go.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security & Hardening\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Rate limits repeated failed logins by hashed IP address.\u003C\u002Fli>\n\u003Cli>Restricts public user enumeration.\u003C\u002Fli>\n\u003Cli>Adds conservative browser security headers.\u003C\u002Fli>\n\u003Cli>Optionally disables XML-RPC.\u003C\u002Fli>\n\u003Cli>Disables dashboard file editing.\u003C\u002Fli>\n\u003Cli>Hides the default login\u002Fadmin paths behind a custom login slug when enabled.\u003C\u002Fli>\n\u003Cli>Shows failed-login IPs with manual block and unlock controls.\u003C\u002Fli>\n\u003Cli>Adds honeypot fields to login, registration, and comment forms to silently block automated bots.\u003C\u002Fli>\n\u003Cli>Blocks PHP execution inside the uploads directory and prevents uploading dangerous file types.\u003C\u002Fli>\n\u003Cli>Supports comment and registration rate limiting per IP with optional math CAPTCHA challenges.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Monitoring & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records a local security audit log with configurable retention (30 days default).\u003C\u002Fli>\n\u003Cli>Monitors important WordPress files every five minutes using SHA-256 hashes.\u003C\u002Fli>\n\u003Cli>Runs lightweight suspicious-code and database scans with severity-based findings.\u003C\u002Fli>\n\u003Cli>Adds threat intelligence checks for admin anomalies, executable uploads, suspicious options, cron hooks, MU plugins, fake CAPTCHA content, external scripts, cloaking signals, and hardening gaps.\u003C\u002Fli>\n\u003Cli>Ships 38 built-in threat detection patterns covering web shells, backdoors, obfuscation techniques, credit card skimmers, SEO spam, PHP object injection, SQL injection, SSRF, and more — based on real-world CVEs and active malware campaigns (Balada Injector, Sign1, SocGholish, mu-plugins backdoors).\u003C\u002Fli>\n\u003Cli>Skips previously clean malware-scan files while their SHA-256 hash is unchanged.\u003C\u002Fli>\n\u003Cli>Flags external JavaScript and URLs outside the current site domain in source or database content.\u003C\u002Fli>\n\u003Cli>Lets administrators run manual scans or schedule scans daily, weekly, or monthly.\u003C\u002Fli>\n\u003Cli>Emails alerts for administrator logins, blocked login attacks, file changes, and suspicious scan findings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Threat Patterns\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Includes a Web Application Firewall (WAF) to block SQL injection, XSS, path traversal, PHP object injection, SSRF, CRLF injection, and other common attack patterns.\u003C\u002Fli>\n\u003Cli>Provides an extensible threat pattern engine for custom malware signatures, WAF rules, and database content patterns with import\u002Fexport support.\u003C\u002Fli>\n\u003Cli>Rate-limits audit log events to prevent database flooding during brute-force attacks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Activity & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records recent public content create\u002Fupdate activity and new administrator access.\u003C\u002Fli>\n\u003Cli>Records WordPress core, plugin, and theme update events.\u003C\u002Fli>\n\u003Cli>Records plugin and theme lifecycle events, including activation, deactivation, installs, and updates.\u003C\u002Fli>\n\u003Cli>Pushes Contact Form 7 submissions, WooCommerce orders, and selected custom post type creations to the authenticated events API.\u003C\u002Fli>\n\u003Cli>Provides an incident-response summary with prioritized findings and next review steps.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>App & API Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Displays basic WordPress security and update status in wp-admin.\u003C\u002Fli>\n\u003Cli>Provides token-authenticated REST endpoints for the ShieldPress App and Web dashboard.\u003C\u002Fli>\n\u003Cli>Pairs the App using a local QR code and a short-lived, one-time exchange code.\u003C\u002Fli>\n\u003Cli>Creates scoped, one-time quick-login URLs for paired App\u002FWeb clients when enabled.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Tools\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Provides database cleanup tools for spam, revisions, orphaned data, expired transients, and inactive subscriber accounts.\u003C\u002Fli>\n\u003Cli>Offers media optimization with optional thumbnail generation control and automatic WebP conversion on upload.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>CodeWP Shield Monitor hashes IP addresses in its 30-day audit log. For failed-login lockout management, it may also store recent source IP addresses, attempt counts, lockout status, and last failed-login time so administrators can block or unlock those IPs. File contents and post body content are never stored.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>CodeWP Shield Monitor can connect to the official WordPress.org checksum API when the administrator enables core checksum verification. The service is used to compare local WordPress core file hashes with official release hashes. It sends the installed WordPress version and site locale at most once every 12 hours; it does not send stored credentials, file contents, full database values, post body content, audit-log IP hashes, API tokens, or CAPTCHA tokens. WordPress.org provides this service under the WordPress.org Terms of Service and Privacy Policy.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms-of-service\u002F\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>CodeWP Shield Monitor can connect to Cloudflare Turnstile only when an administrator enables CAPTCHA challenges, selects Cloudflare Turnstile, saves a Turnstile site key and secret key, and chooses the forms to protect. Public pages that may contain selected login, registration, or WooCommerce checkout forms can load Cloudflare’s Turnstile JavaScript from challenges.cloudflare.com to display the challenge. During protected form submissions, the plugin sends the Turnstile response token, configured secret key, and visitor IP address to Cloudflare’s siteverify endpoint to validate the challenge. This is required for the optional Turnstile CAPTCHA feature.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\u003C\u002Fp>\n\u003Cp>CodeWP Shield Monitor can connect to Google reCAPTCHA only when an administrator enables CAPTCHA challenges, selects Google reCAPTCHA v2 or v3, saves a reCAPTCHA site key and secret key, and chooses the forms to protect. Public pages that may contain selected login, registration, or WooCommerce checkout forms can load Google’s reCAPTCHA JavaScript from google.com to display or run the challenge. During protected form submissions, the plugin sends the reCAPTCHA response token, configured secret key, and visitor IP address to Google’s siteverify endpoint to validate the challenge. When Google reCAPTCHA v3 is selected, the plugin also checks the returned score against the configured threshold, which defaults to 0.1. This is required for the optional Google reCAPTCHA feature.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n","Privacy-first WordPress security hardening, login protection, and local audit logging.",200,"2026-07-15T09:48:00.000Z","6.4",[64,20,65,66,22],"audit-log","login","privacy","https:\u002F\u002Fshieldpress.net","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcodewp-shield-monitor.zip",{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":32,"downloaded":77,"rating":78,"num_ratings":79,"last_updated":80,"tested_up_to":81,"requires_at_least":82,"requires_php":23,"tags":83,"homepage":86,"download_link":87,"security_score":88,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"plugin-auditor","Plugin Auditor","2.4.3","Tom Greenwood","https:\u002F\u002Fprofiles.wordpress.org\u002Fwholegraindigital\u002F","\u003Cp>Have you ever had that situation where you have a bunch of plugins installed and you can’t remember why half of them are there?\u003C\u002Fp>\n\u003Cp>It is important to clean out unused plugins and keep your plugins up to date, but this can be difficult if you have forgotten why you installed them in the first place.  This is particularly true for sites with multiple admin users, and for agencies that manage their clients sites.\u003C\u002Fp>\n\u003Cp>You don’t want to delete an old plugin without being 100% sure why it was installed and therefore know if it is still needed.\u003C\u002Fp>\n\u003Cp>The Plugin Auditor tells you why each plugin was installed and also keeps a record of who installed it so that you know who to ask if you have any questions when performing maintenance on the site.\u003C\u002Fp>\n\u003Cp>Plugin Auditor can be installed at any time but to get the most benefit from it, it should be installed as the first plugin that you install on any WordPress site that you manage.\u003C\u002Fp>\n","Have you ever had that situation where you have a bunch of plugins installed and you can't remember why half of them are there?",4217,86,7,"2019-04-22T17:28:00.000Z","5.1.22","4.0",[18,84,21,85,22],"audit-trail","plugin-audit","http:\u002F\u002Fwww.wholegraindigital.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fplugin-auditor.zip",85,{"slug":90,"name":91,"version":92,"author":93,"author_profile":94,"description":95,"short_description":96,"active_installs":97,"downloaded":98,"rating":11,"num_ratings":11,"last_updated":99,"tested_up_to":14,"requires_at_least":100,"requires_php":16,"tags":101,"homepage":105,"download_link":106,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"npc-maintenance-inspector","NPC Maintenance Inspector","1.0.1","npc01","https:\u002F\u002Fprofiles.wordpress.org\u002Fnpc01\u002F","\u003Cp>NPC Maintenance Inspector performs 9-point health diagnostics on your WordPress site directly from the admin dashboard:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>WordPress core updates\u003C\u002Fstrong> — Detect missing core updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin updates\u003C\u002Fstrong> — List plugins with available updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site Health issues\u003C\u002Fstrong> — Extract critical issues from WP standard Site Health API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP version\u003C\u002Fstrong> — Warn on end-of-life PHP versions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Error log analysis\u003C\u002Fstrong> — Summarize debug.log entries and save a one-click backup to uploads\u002F for safe review.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File integrity\u003C\u002Fstrong> — Detect suspicious code patterns in core files (eval \u002F base64_decode \u002F etc.) by comparing checksums against the WordPress.org Checksum API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suspicious files\u003C\u002Fstrong> — Find unexpected PHP files in wp-content\u002Fuploads\u002F, with built-in whitelist for known legitimate plugin files (Ajax Load More templates, WP STAGING index.php, AIOS firewall rules, etc.).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SSL certificate\u003C\u002Fstrong> — Check days until expiration (warn under 30 days, critical at 0).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File permissions\u003C\u002Fstrong> — Check critical files like wp-config.php, .htaccess, wp-content\u002F.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Operational features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>History\u003C\u002Fstrong> — Keep the last 10 diagnoses as a custom post type.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled auto-check\u003C\u002Fstrong> — Run daily, weekly, or monthly via WP Cron.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email notifications\u003C\u002Fstrong> — Send alerts only on critical issues.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click debug.log clear\u003C\u002Fstrong> — Truncate the log while preserving file permissions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optional AI report\u003C\u002Fstrong> — Generate maintenance suggestions via Anthropic Claude API. Disabled by default; opt-in via a wp-config.php constant.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin is locked to the user who activated it and to the original site URL, so it stays inert after backup restores to a different domain.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin can optionally connect to the \u003Cstrong>Anthropic Claude API\u003C\u002Fstrong> (\u003Ccode>https:\u002F\u002Fapi.anthropic.com\u002Fv1\u002Fmessages\u003C\u002Fcode>) to generate AI-powered maintenance reports. This is the only external service the plugin ever contacts.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When is data sent?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>When you manually click the “Generate AI Report” button in the admin.\u003C\u002Fli>\n\u003Cli>When an automatic scheduled diagnosis detects a critical issue \u003Cstrong>and\u003C\u002Fstrong> notifications are enabled. In that case the AI report is generated once per critical run and attached to the notification email.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What data is sent?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>The diagnosis result text only:\n\u003Cul>\n\u003Cli>Site URL, site name, WordPress version, theme name\u003C\u002Fli>\n\u003Cli>Counts of plugin updates \u002F Site Health issues \u002F error-log entries\u003C\u002Fli>\n\u003Cli>PHP version, memory limit, max upload size\u003C\u002Fli>\n\u003Cli>SSL expiration date and days remaining\u003C\u002Fli>\n\u003Cli>File-permission status of critical files\u003C\u002Fli>\n\u003Cli>Suspicious code patterns detected (function names like \u003Ccode>eval\u003C\u002Fcode>, \u003Ccode>base64_decode\u003C\u002Fcode>)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>No login data, no post content, no personal data of site visitors.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Is the data sent unconditionally?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>No. The AI feature is \u003Cstrong>completely disabled\u003C\u002Fstrong> unless you define \u003Ccode>NPCMI_API_KEY\u003C\u002Fcode> in \u003Ccode>wp-config.php\u003C\u002Fcode>. Without that constant, no external connection to Anthropic is ever made.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Anthropic’s terms and privacy policy:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Consumer Terms of Service: https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fconsumer-terms\u003C\u002Fli>\n\u003Cli>Privacy Policy: https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fprivacy\u003C\u002Fli>\n\u003Cli>Commercial Terms of Service (if you use a paid API plan): https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fcommercial-terms\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>By enabling the AI report feature (i.e. by defining \u003Ccode>NPCMI_API_KEY\u003C\u002Fcode>), you agree to Anthropic’s applicable terms.\u003C\u002Fp>\n","WordPress maintenance health-check tool with 9-point diagnostics, history tracking, and optional AI-powered reports.",20,211,"2026-05-20T09:32:00.000Z","6.0",[102,103,21,104,22],"diagnostics","healthcheck","monitoring","https:\u002F\u002Fn-pc.jp\u002Fproducts\u002Fmaintenance-inspector\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnpc-maintenance-inspector.1.0.1.zip",{"slug":108,"name":109,"version":110,"author":111,"author_profile":112,"description":113,"short_description":114,"active_installs":97,"downloaded":115,"rating":11,"num_ratings":11,"last_updated":116,"tested_up_to":117,"requires_at_least":62,"requires_php":118,"tags":119,"homepage":23,"download_link":121,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"steel-security","Steel Security & Hardening – Site Audit Tools","1.0.4","sweetwatermedia","https:\u002F\u002Fprofiles.wordpress.org\u002Fsweetwatermedia\u002F","\u003Cp>Steel Security & Hardening – Site Audit Tools focuses on practical security hygiene for WordPress administrators.\u003C\u002Fp>\n\u003Cp>The free plugin provides:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>on-demand security scans\u003C\u002Fli>\n\u003Cli>risk summaries grouped by severity and category\u003C\u002Fli>\n\u003Cli>checks for common WordPress hardening gaps\u003C\u002Fli>\n\u003Cli>checks for exposed root-level artifacts such as \u003Ccode>.env\u003C\u002Fcode>, SQL dumps, \u003Ccode>phpinfo\u003C\u002Fcode> files, and backup archives\u003C\u002Fli>\n\u003Cli>a quarantine vault for operator-reviewed file isolation\u003C\u002Fli>\n\u003Cli>uploads PHP execution blocking on supported server environments\u003C\u002Fli>\n\u003Cli>manual guidance when automatic server hardening is not safely supported\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is positioned as an auditing and hardening tool. It helps surface risk and apply selected preventive controls, but it does not promise malware removal, incident response, or complete server protection.\u003C\u002Fp>\n\u003Ch4>Included checks\u003C\u002Fh4>\n\u003Cp>The scan currently looks for items such as:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP error display exposure\u003C\u002Fli>\n\u003Cli>\u003Ccode>WP_DEBUG\u003C\u002Fcode> and \u003Ccode>debug.log\u003C\u002Fcode> exposure\u003C\u002Fli>\n\u003Cli>XML-RPC availability\u003C\u002Fli>\n\u003Cli>author and REST user enumeration exposure\u003C\u002Fli>\n\u003Cli>theme\u002Fplugin file editor availability\u003C\u002Fli>\n\u003Cli>WordPress generator meta output\u003C\u002Fli>\n\u003Cli>comments enabled by default\u003C\u002Fli>\n\u003Cli>uploads PHP execution hardening status\u003C\u002Fli>\n\u003Cli>root-level sensitive files and archives\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Server-aware behavior\u003C\u002Fh4>\n\u003Cp>This plugin only auto-applies server config changes where it can do so in a scoped and reversible way.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Apache and LiteSpeed: uploads PHP blocking is managed through a Steel Security-marked \u003Ccode>.htaccess\u003C\u002Fcode> block\u003C\u002Fli>\n\u003Cli>IIS: uploads PHP blocking is managed through a Steel Security-marked \u003Ccode>web.config\u003C\u002Fcode> section\u003C\u002Fli>\n\u003Cli>Nginx and unsupported environments: Steel Security provides manual guidance instead of claiming automatic protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro companion\u003C\u002Fh4>\n\u003Cp>This plugin can work with a separate Pro companion plugin that adds features such as scheduled scans, scan history, reports, and managed server-level controls such as directory listing protection and baseline security headers. The free plugin remains usable on its own.\u003C\u002Fp>\n","High-signal WordPress security auditing and hardening with practical site audit tools for administrators.",218,"2026-04-28T22:21:00.000Z","6.9.5","8.0",[18,20,120,22],"scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsteel-security.1.0.4.zip",{"error":123,"url":124,"statusCode":125,"statusMessage":126,"message":126},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fcybernote-security-checker\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":31,"versions":128},[129],{"version":6,"download_url":24,"svn_tag_url":130,"released_at":26,"has_diff":131,"diff_files_changed":132,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":133,"is_current":123},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcybernote-security-checker\u002Ftags\u002F1.0.0\u002F",false,[],[]]