[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fol3H2JHUuR51bZHwZNMb5w6YwGPmkkz4xuA3Asp7J24":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":27,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":128,"crawl_stats":37,"alternatives":136,"analysis":236,"fingerprints":1691},"defender-security","Defender Security – Malware Scanner, Login Security & Firewall","5.10.0","WPMU DEV - Your All-in-One WordPress Platform","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpmudev\u002F","\u003Cp>\u003Cstrong>Defender adds the best in WordPress plugin security to your website with just a few clicks, including malware scanner, firewall, password protection, and login security features. Stop brute force login attacks, weak password usage, SQL injections, cross-site scripting (XSS), and other WordPress security vulnerabilities and hacks with Defender’s malware scanner, providing antivirus scans, IP blocking, firewall, activity log, security log, and two-factor authentication (2FA) login security.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>No more complex security settings, Defender’s malware scanner, firewall, and login security features add all the hardening and security you need.\u003C\u002Fp>\n\u003Cp>Defender is brought to you by the WordPress speed specialists that created Smush image optimization, now active on more than +1 million websites.\u003C\u002Fp>\n\u003Cp>Plus, connect for free to WPMU DEV’s AntiBot Global Firewall to block harmful IPs with data from over 750,000 sites.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enjoy complete site protection from malware, vulnerabilities, bot attacks, and session hijacking from the start with \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fproject\u002Fwp-defender\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme-above-the-fold&utm_content=wp_defender_pro\" rel=\"nofollow ugc\">Defender Pro\u003C\u002Fa>.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Level up security immediately with exclusive Pro features like scheduled malware scanning, Safe Repair for suspicious files, and known WordPress vulnerability detection. \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fproject\u002Fwp-defender\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme-above-the-fold&utm_content=wp_defender_pro\" rel=\"nofollow ugc\">Learn more about Pro\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Security Recommendations\u003C\u002Fh3>\n\u003Cp>Defender’s one-click security hardening recommendations instantly adds layers of protection and security to your site.\u003C\u002Fp>\n\u003Ch3>Enhance Security and Block Hackers At Every Level:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malware Scanner\u003C\u002Fstrong> – Scan WordPress core files for modifications and unexpected changes which may be caused by malware. Scan for malware and tighten up the security of your files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Outdated & Removed Plugins\u003C\u002Fstrong> – Scans for plugins removed from WordPress.org or not updated in 2+ years.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AntiBot Global Firewall\u003C\u002Fstrong> – Connect for free to WPMU DEV to block harmful IPs with data from over 750,000 sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress Security Firewall\u003C\u002Fstrong> – Block or allowlist IPs, implement IP blocking, and Geo IP blocking, user agent banning and protect against brute force attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong> – Easily set up better security with 2FA to prevent most login attacks such as brute force, App verification, backup codes, lost device email, WooCommerce 2FA, and Web Authentication.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Masking\u003C\u002Fstrong> – Change the location of WordPress’s default login area to improve login security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Lockout\u003C\u002Fstrong> – Failed login attempts lockout for even more security assurance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Agent Banning\u003C\u002Fstrong> – Fortify security by blocking bad bots and user agents from accessing your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Headers\u003C\u002Fstrong> – Add an extra layer of defense security and protect against common attacks like: XSS, code injection, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>404 Detection Security\u003C\u002Fstrong> – Automated block of bot IPs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Configs\u003C\u002Fstrong> – Create your ideal Defender security plugin settings and export \u002F import saved configs to any other site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geolocation IP Lockout Security\u003C\u002Fstrong> – Block users based on location and country (IP blocking).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Trackbacks And Pingbacks\u003C\u002Fstrong> – Disable these notifications to enhance spam protection and site security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Core And Server Update Security Recommendations\u003C\u002Fstrong> – Stay on top of your system security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Antivirus Scan\u003C\u002Fstrong> – Scan for active security threats, viruses, and other malware.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable File Editor\u003C\u002Fstrong> – If they get in, they won’t get far.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Error Reporting\u003C\u002Fstrong> – Hide code errors on the frontend so hackers can’t exploit site security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Update Security Keys\u003C\u002Fstrong> – Update old WordPress security keys to be more encrypted and provide better security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prevent Information Disclosure\u003C\u002Fstrong> – Improve server security and protect sensitive files by locking down specific file types.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prevent PHP Execution\u003C\u002Fstrong> – Defender bolsters security by automatically preventing any PHP code from being executed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk Apply Security Recommendations\u003C\u002Fstrong> – Apply multiple recommended security improvements at once for quicker site hardening.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google reCAPTCHA Security\u003C\u002Fstrong> – Easy to add, stop fraud and abuse – including BuddyPress and WooCommerce.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Turnstile\u003C\u002Fstrong> – Captcha-free protection from spam and automated attacks, including BuddyPress and WooCommerce support.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pwned Password Check\u003C\u002Fstrong> – Increase security by protecting against compromised passwords.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Force Password Reset\u003C\u002Fstrong> – Force users with selected roles to reset passwords.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Force Strong Passwords\u003C\u002Fstrong> – Ensure users create secure credentials by enforcing robust password requirements.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Agent Blocklist Presets\u003C\u002Fstrong> – Easily block unwanted bots and scripts using curated user agent presets.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Known Vulnerability & Suspicious Code Scan (Pro Only)\u003C\u002Fstrong> – Scan WordPress core, themes, and plugins for vulnerabilities and harmful code.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Malicious Bot Detector (Pro Only)\u003C\u002Fstrong> – Block malicious bots with layered defenses, including traps for bots that ignore robots.txt and checks for fake crawlers posing as search engines.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Blocklist Monitoring (Pro Only)\u003C\u002Fstrong> – Get instant alerts if your site is flagged by Google.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Protection (Pro Only)\u003C\u002Fstrong> – Stop session hijacking and prevent unauthorized account access.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Safe Repair For Suspicious Files (Pro Only)\u003C\u002Fstrong> – Restore or replace compromised files safely with a single click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automated Reports (Pro Only)\u003C\u002Fstrong> – Receive scheduled security reports straight to your inbox.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Learn The Ropes With These Hands-On Defender Security Plugin Tutorials\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fblog\u002Fhow-to-get-the-most-out-of-defender-security\u002F\" rel=\"nofollow ugc\">How to Get the Most Out of Defender Security\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fblog\u002Fstop-hackers-with-defender-wordpress-security-plugin\u002F\" rel=\"nofollow ugc\">How to Stop Hackers in Their Tracks with Defender Security\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fblog\u002Fdelete-suspicious-code-defender\u002F\" rel=\"nofollow ugc\">Find Out if You’re Hacked: How to Find and Delete Suspicious Code with Defender Security\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fblog\u002Fdefender-ip-address-lockout-firewall\u002F\" rel=\"nofollow ugc\">How to Create a Powerful and Secure Customized Firewall with Defender Security\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress Security Scans\u003C\u002Fh3>\n\u003Cp>Defender’s malware scanner security checks for suspicious code and malware. It also compares your WordPress install with the WP directory master copy, and reports any changes so you can restore the original file with a click.\u003C\u002Fp>\n\u003Ch3>Two-Factor Authentication (2FA) Security\u003C\u002Fh3>\n\u003Cp>Easily add an extra layer of protection and security to your WordPress sites with Defender’s two-factor authentication (2FA) features. Including: mobile app verification (Google Authenticator, Microsoft Authenticator, Authy), backup code generation, lost device emails, WooCommerce 2FA, Biometric Authentication (fingerprint\u002Ffacial recognition), and Hardware Key Authentication (USB security keys). Easily prevent brute force attacks and login security vulnerabilities.\u003C\u002Fp>\n\u003Ch3>Login Protection\u003C\u002Fh3>\n\u003Cp>Brute force attacks are no match for Defender’s login security. Limit login attempts so hackers can’t guess passwords. Permanently ban IPs or trigger a timed lockout after a set number of failed login attempts. Use Geo IP blocking to ban users from specific countries or locations.\u003C\u002Fp>\n\u003Ch3>Firewall Security and IP Manager\u003C\u002Fh3>\n\u003Cp>Improve your website security with Defender’s IP manager and firewall. Manually block specific IPs, import a list of banned IPs, and set automated timed and permanent lockouts. Defender makes it easy to block and unblock specific locations quickly thanks to its advanced firewall security(WAF) offering Geographical IP blocking.\u003C\u002Fp>\n\u003Ch3>User Agent Banning\u003C\u002Fh3>\n\u003Cp>Add user agents to the block or allowlist and stop bad bots from spamming and scraping your site. All major search engines and special network bots are allow-listed out of the box. Easy to set up, Defender’s user agent banning tool now includes built-in bot and script presets to help you quickly block malicious traffic. It does all the security work for you—no editing of the .htaccess file required.\u003C\u002Fp>\n\u003Ch3>Google reCAPTCHA Integration\u003C\u002Fh3>\n\u003Cp>Add reCAPTCHA security to your login \u002F registration pages, lost password forms, and post comments in a couple of steps to up security and help protect from fraud and abuse. Select reCAPTCHA type, language, location, and style to suit. As well as Google, Defender also supports the following reCAPTCHA types:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>BuddyPress reCAPTCHA\u003C\u002Fli>\n\u003Cli>WooCommerce reCAPTCHA\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Login Screen Masking\u003C\u002Fh3>\n\u003Cp>Defender makes it easy to move your login screen to a custom URL. Not only does login screen masking improve security, but it also lets you white label your login user experience and improves branding.\u003C\u002Fp>\n\u003Ch3>Force Password Reset\u003C\u002Fh3>\n\u003Cp>Enhance site security by forcing all users with selected roles to reset their password at any time. Especially helpful if you suspect a possible data breach on your site.\u003C\u002Fp>\n\u003Ch3>Security Headers\u003C\u002Fh3>\n\u003Cp>Protect your site against common attacks, such as: XSS, code injection, cross site scripting, and more. Enable the following security headers:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>X-Frame-Options\u003C\u002Fli>\n\u003Cli>X-XSS-Protection\u003C\u002Fli>\n\u003Cli>X-Content-Type-Options\u003C\u002Fli>\n\u003Cli>Strict Transport\u003C\u002Fli>\n\u003Cli>Referrer Policy\u003C\u002Fli>\n\u003Cli>Permissions-Policy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>404 Limiter\u003C\u002Fh3>\n\u003Cp>Detect when bots are being used to scan your site for security vulnerabilities and shut them down. The 404 limiter lets you stop the scan by detecting when a bot keeps visiting pages that do not exist, which can also save you from a giant strain on your site’s performance.\u003C\u002Fp>\n\u003Ch3>Security Notifications and Reports\u003C\u002Fh3>\n\u003Cp>Defender runs surveillance and sends security notifications with information that matters. All activity and notifications are recorded in the activity log to let you see at a glance the website security actions that have been taken by the Defender security plugin.\u003C\u002Fp>\n\u003Ch3>Reduce Security Setup Time With Saved Configs\u003C\u002Fh3>\n\u003Cp>Save your Defender security plugin configurations and reapply them to your other sites in just a few clicks. You can create and save an unlimited number of security configurations.\u003C\u002Fp>\n\u003Ch3>Pwned Password Check\u003C\u002Fh3>\n\u003Cp>Entered passwords are checked against public database breach records to further boost security. If a password is identified as compromised, the user will be asked to change it.\u003C\u002Fp>\n\u003Ch3>Custom IP Block\u002FAllowlist\u003C\u002Fh3>\n\u003Cp>Create your IP block\u002Fallow list once, then apply and automatically sync it to all your other sites with just a single click. Save hours by not having to manually add IPs to each individual site. *Note: a [free WPMU DEV account] (https:\u002F\u002Fwpmudev.com\u002Fregister) is required to access this feature.\u003C\u002Fp>\n\u003Ch3>What Do People Say About Defender?\u003C\u002Fh3>\n\u003Cp>★★★★★\u003Cbr \u002F>\n“I found other pro security plugins a bit too fiddly for my taste…I’m delighted with Defender” – \u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fkeithadv\" rel=\"nofollow ugc\">KeithADV\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>★★★★★\u003Cbr \u002F>\n“Thank you for bringing back a free and easy to use 2-Factor Authentication after Clef! Defender helps keep me aware of my site’s security.” – \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fusers\u002Fawijasa\u002F\" rel=\"ugc\">awijasa\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>★★★★★\u003Cbr \u002F>\n“Defender’s interface is very intuitive with warnings that are very helpful” – \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fprofile\u002Fdjohns\" rel=\"nofollow ugc\">djohns\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>★★★★★\u003Cbr \u002F>\n“Defender Recently blocked over 3000 attacks in one week without any noticeable impact on the website. WPMUDEV knocking it out of the park on this one.” – \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fprofile\u002Fdavidoswald\u002F\" rel=\"nofollow ugc\">David Oswald\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Secure Websites, More Trust, Better Profit\u003C\u002Fh3>\n\u003Cp>If you’re running a business website or eCommerce store, privacy, security, uptime and trust are essential.\u003C\u002Fp>\n\u003Cp>The Defender security plugin is here to help you: it’s a one of a kind WordPress security plugin that makes web security easy for anyone, for free!\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Malware scanner\u003C\u002Fli>\n\u003Cli>Google two-factor authentication (2FA)\u003C\u002Fli>\n\u003Cli>Web Authentication\u003C\u002Fli>\n\u003Cli>Firewall setup and configuration\u003C\u002Fli>\n\u003Cli>One-click site hardening and security tweaking\u003C\u002Fli>\n\u003Cli>WordPress core file scanning and repair\u003C\u002Fli>\n\u003Cli>Ongoing firewall security\u003C\u002Fli>\n\u003Cli>Google reCAPTCHA\u003C\u002Fli>\n\u003Cli>Security headers\u003C\u002Fli>\n\u003Cli>One-click security configs\u003C\u002Fli>\n\u003Cli>Login Screen Masking\u003C\u002Fli>\n\u003Cli>Pwned Password Check\u003C\u002Fli>\n\u003Cli>IP Blocklist manager and logging\u003C\u002Fli>\n\u003Cli>Geo IP blocking\u003C\u002Fli>\n\u003Cli>User agent banning\u003C\u002Fli>\n\u003Cli>Unlimited file scans\u003C\u002Fli>\n\u003Cli>Timed Lockout brute force login attack shield for login security\u003C\u002Fli>\n\u003Cli>404 limiter for blocking vulnerability scans\u003C\u002Fli>\n\u003Cli>IP lockout notifications and security reports\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All the above is free and will enhance WordPress security for you. If you need extra security for your WordPress site, \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme&utm_content=you_should_get_wpmudev_membership#trial\" rel=\"nofollow ugc\">you should get a WPMU DEV Membership\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Our Membership gives you access to Defender Pro – which security features include automated scanning, scheduled malware scans for Core, themes, plugins and other files, audit logs, firewall protection, Safe Repair, Blocklist monitoring – alongside Snapshot Pro cloud backups, the Hub with automated plugin, theme and core updates and safe-upgrade scans, all our premium WordPress plugins, 24\u002F7 WordPress support and if your sites already been hacked our team of security experts will clean it up at no additional cost.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme&utm_content=and_you_can_find_out_more_here#trial\" rel=\"nofollow ugc\">It’s an incredible deal, and you can find out more here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>About Us\u003C\u002Fh3>\n\u003Cp>WPMU DEV is a premium supplier of quality WordPress plugins and themes. For premium support with any WordPress-related issues you can join us here:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme&utm_content=wpmu_dev_link\" rel=\"nofollow ugc\">https:\u002F\u002Fwpmudev.com\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Don’t forget to stay up to date on everything WordPress from the Internet’s number one resource:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme&utm_content=wpmu_dev_blog_link\" rel=\"nofollow ugc\">WPMU DEV Blog\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Hey, one more thing… we hope you \u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002FWPMUDEV\u002F\" rel=\"nofollow ugc\">enjoy our free offerings\u003C\u002Fa> as much as we’ve loved making them for you!\u003C\u002Fp>\n","WordPress security plugin with malware scanner, IP blocking, audit logs, antivirus scans, firewall, 2FA, brute force login security, and more.",90000,4036012,96,329,"2026-03-03T11:21:00.000Z","6.9.4","6.4","8.0.0",[20,21,22,23,24],"firewall","login-security","malware","malware-scanner","security","https:\u002F\u002Fwpmudev.com\u002Fproject\u002Fwp-defender\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefender-security.5.10.0.zip",7,0,"2024-06-28 00:00:00","2026-03-15T15:16:48.613Z",[32,48,63,77,88,99,114],{"id":33,"url_slug":34,"title":35,"description":36,"plugin_slug":4,"theme_slug":37,"affected_versions":38,"patched_in_version":39,"severity":40,"cvss_score":41,"cvss_vector":42,"vuln_type":43,"published_date":29,"updated_date":44,"references":45,"days_to_patch":47},"CVE-2024-37444","defender-security-missing-authorization","Defender Security \u003C= 4.7.2 - Missing Authorization","The Defender Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clear_config_transient() function in versions up to, and including, 4.7.2. This makes it possible for unauthenticated attackers to clear config data.",null,"\u003C=4.7.2","4.7.3","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2024-07-02 14:23:17",[46],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F26963b32-db2c-430b-99e5-65a2cc7d478d?source=api-prod",5,{"id":49,"url_slug":50,"title":51,"description":52,"plugin_slug":4,"theme_slug":37,"affected_versions":53,"patched_in_version":54,"severity":40,"cvss_score":55,"cvss_vector":56,"vuln_type":57,"published_date":58,"updated_date":59,"references":60,"days_to_patch":62},"CVE-2024-25595","defender-security-ip-address-spoofing","Defender Security \u003C= 4.4.1 - IP Address Spoofing","The Defender Security – Malware Scanner, Login Security & Firewall plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 4.4.1 due to user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass IP Address restrictions.","\u003C=4.4.1","4.4.2",6.5,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:N","Protection Mechanism Failure","2024-02-12 00:00:00","2024-02-14 15:59:38",[61],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fe014d8b6-9ce3-40ec-862e-ab5f220f1b6d?source=api-prod",3,{"id":64,"url_slug":65,"title":66,"description":67,"plugin_slug":4,"theme_slug":37,"affected_versions":68,"patched_in_version":69,"severity":40,"cvss_score":41,"cvss_vector":70,"vuln_type":71,"published_date":72,"updated_date":73,"references":74,"days_to_patch":76},"CVE-2023-51490","defender-security-sensitive-information-exposure-via-log-file","Defender Security \u003C= 4.1.0 - Sensitive Information Exposure via Log File","The Defender Security – Malware Scanner, Login Security & Firewall plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1.0 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including system and plugin information.","\u003C=4.1.0","4.2.0","CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N","Insertion of Sensitive Information into Log File","2023-12-27 00:00:00","2024-01-22 19:56:02",[75],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F94c8979a-db2e-490f-b055-cdf19a48cf73?source=api-prod",27,{"id":78,"url_slug":79,"title":80,"description":81,"plugin_slug":4,"theme_slug":37,"affected_versions":82,"patched_in_version":83,"severity":40,"cvss_score":41,"cvss_vector":42,"vuln_type":57,"published_date":84,"updated_date":73,"references":85,"days_to_patch":87},"CVE-2023-47189","defender-security-masked-login-area-security-feature-bypass","Defender Security \u003C= 4.2.0 - Masked Login Area Security Feature Bypass","The Defender Security – Malware Scanner, Login Security & Firewall plugin for WordPress is vulnerable to security feature bypass in all versions up to, and including, 4.2.0. This is due to an unspecified issue. This makes it possible for unauthenticated attackers to bypass the login masking security feature.","\u003C=4.2.0","4.2.1","2023-11-03 00:00:00",[86],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F66122be6-7c28-44cc-a8dd-7b2ec64346f7?source=api-prod",81,{"id":89,"url_slug":90,"title":91,"description":92,"plugin_slug":4,"theme_slug":37,"affected_versions":93,"patched_in_version":94,"severity":40,"cvss_score":41,"cvss_vector":42,"vuln_type":57,"published_date":95,"updated_date":73,"references":96,"days_to_patch":98},"CVE-2023-5089","defender-security-hide-login-page-feature-protection-bypass","Defender Security \u003C= 4.0.2 - Hide Login Page Feature Protection Bypass","The Defender Security plugin for WordPress is vulnerable to protection bypass in versions up to, and including, 4.0.2. This is due to the plugin failing to prevent redirects via the auth_redirect WordPress function. This makes it possible for unauthenticated attackers to bypass the 'Hide Login Page' security feature.","\u003C=4.0.2","4.1.0","2023-09-06 00:00:00",[97],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F08dee232-7373-4da4-9c2c-c3aa52f9b588?source=api-prod",139,{"id":100,"url_slug":101,"title":102,"description":103,"plugin_slug":4,"theme_slug":37,"affected_versions":104,"patched_in_version":105,"severity":106,"cvss_score":107,"cvss_vector":108,"vuln_type":109,"published_date":110,"updated_date":73,"references":111,"days_to_patch":113},"CVE-2022-44581","defender-security-sensitive-information-disclosure","Defender Security \u003C= 3.3.2 - Sensitive Information Disclosure","The Defender Security plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 3.3.2. This is due to 2fa-codes being stored in plaintext. This makes it possible for unauthenticated attackers to access them under certain circumstances.","\u003C=3.3.2","3.3.3","high",7.5,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N","Exposure of Sensitive Information to an Unauthorized Actor","2022-11-23 00:00:00",[112],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F662ca451-5c69-4973-afc8-5dc1caf57ad7?source=api-prod",426,{"id":115,"url_slug":116,"title":117,"description":118,"plugin_slug":4,"theme_slug":37,"affected_versions":119,"patched_in_version":120,"severity":40,"cvss_score":121,"cvss_vector":122,"vuln_type":123,"published_date":124,"updated_date":73,"references":125,"days_to_patch":127},"CVE-2021-4425","defender-security-cross-site-request-forgery-bypass","Defender Security \u003C= 2.4.6 - Cross-Site Request Forgery Bypass","The Defender Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.6. This is due to missing or incorrect nonce validation on the verify_otp_login_time() function. This makes it possible for unauthenticated attackers to verify a one time login via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","\u003C=2.4.6","2.4.6.1",4.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Cross-Site Request Forgery (CSRF)","2021-03-01 00:00:00",[126],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fe772fbbe-33d5-46fa-a041-ab07d3f9318f?source=api-prod",1058,{"slug":129,"display_name":7,"profile_url":8,"plugin_count":130,"total_installs":131,"avg_security_score":132,"avg_patch_time_days":133,"trust_score":134,"computed_at":135},"wpmudev",9,2430000,91,396,73,"2026-04-03T18:38:39.964Z",[137,158,176,197,217],{"slug":138,"name":139,"version":140,"author":141,"author_profile":142,"description":143,"short_description":144,"active_installs":145,"downloaded":146,"rating":13,"num_ratings":147,"last_updated":148,"tested_up_to":16,"requires_at_least":149,"requires_php":150,"tags":151,"homepage":153,"download_link":154,"security_score":155,"vuln_count":156,"unpatched_count":28,"last_vuln_date":157,"fetched_at":30},"bulletproof-security","BulletProof Security","7.1","AITpro","https:\u002F\u002Fprofiles.wordpress.org\u002Faitpro\u002F","\u003Cp>WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam… View Security feature highlights below. View BulletProof Security feature details under the FAQ help section below. Effective, Reliable & Easy to use WordPress Security Plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>BulletProof Security is a proactive security plugin that automatically fixes 100+ known issues\u002Fconflicts with other plugins\u003C\u002Fstrong>.\u003Cbr \u002F>\n* \u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fforums\u002Ftopic\u002Fsetup-wizard-autofix\u002F\" title=\"BPS Setup Wizard AutoFix\" rel=\"nofollow ugc\">BPS Setup Wizard AutoFix\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>BulletProof Security Installation and Setup Video Tutorial\u003C\u002Fh4>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FRZ1ARaEE0_I?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>BulletProof Security Feature Highlights\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>One-Click Setup Wizard\u003C\u002Fli>\n\u003Cli>Setup Wizard AutoFix (AutoWhitelist|AutoSetup|AutoCleanup)\u003C\u002Fli>\n\u003Cli>MScan Malware Scanner\u003C\u002Fli>\n\u003Cli>.htaccess Website Security Protection (Firewalls)\u003C\u002Fli>\n\u003Cli>Hidden Plugin Folders|Files Cron (HPF)\u003C\u002Fli>\n\u003Cli>Login Security & Monitoring\u003C\u002Fli>\n\u003Cli>JTC-Lite (Limited version of BPS Pro JTC Anti-Spam|Anti-Hacker)\u003C\u002Fli>\n\u003Cli>Idle Session Logout (ISL)\u003C\u002Fli>\n\u003Cli>Auth Cookie Expiration (ACE)\u003C\u002Fli>\n\u003Cli>DB Backup: Full|Partial DB Backups | Manual|Scheduled DB Backups | Email Zip Backups | Cron Delete Old Backups\u003C\u002Fli>\n\u003Cli>DB Table Prefix Changer\u003C\u002Fli>\n\u003Cli>Security Logging\u003C\u002Fli>\n\u003Cli>HTTP Error Logging\u003C\u002Fli>\n\u003Cli>FrontEnd|BackEnd Maintenance Mode\u003C\u002Fli>\n\u003Cli>Extensive System Info (System Info page)\u003C\u002Fli>\n\u003Cli>WordPress Automatic Update Options\u003C\u002Fli>\n\u003Cli>Force Strong Passwords (FSP)\u003C\u002Fli>\n\u003Cli>Send email alerts when new Plugin & Theme updates are available\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>BulletProof Security Pro Feature Highlights\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>One-Click Setup Wizard\u003C\u002Fli>\n\u003Cli>Setup Wizard AutoFix (AutoWhitelist|AutoSetup|AutoCleanup)\u003C\u002Fli>\n\u003Cli>AutoRestore Intrusion Detection & Prevention System (ARQ IDPS)\u003C\u002Fli>\n\u003Cli>Quarantine Intrusion Detection & Prevention System (ARQ IDPS)\u003C\u002Fli>\n\u003Cli>Real-time File Monitor (IDPS)\u003C\u002Fli>\n\u003Cli>MScan Malware Scanner\u003C\u002Fli>\n\u003Cli>DB Monitor Intrusion Detection System (IDS)\u003C\u002Fli>\n\u003Cli>DB Diff Tool: data comparison tool\u003C\u002Fli>\n\u003Cli>DB Backup: Full|Partial DB Backups | Manual|Scheduled DB Backups | Email Zip Backups | Cron Delete Old Backups\u003C\u002Fli>\n\u003Cli>DB Status & Info: extensive database status & info\u003C\u002Fli>\n\u003Cli>Plugin Firewall (IP Firewall): Automated Whitelisting & IP Address Updated in Real-time\u003C\u002Fli>\n\u003Cli>JTC Anti-Spam|Anti-Hacker\u003C\u002Fli>\n\u003Cli>Uploads Folder Anti-Exploit Guard (UAEG)\u003C\u002Fli>\n\u003Cli>.htaccess Website Security Protection (Firewalls)\u003C\u002Fli>\n\u003Cli>Hidden Plugin Folders|Files Cron (HPF)\u003C\u002Fli>\n\u003Cli>Custom php.ini Website Security\u003C\u002Fli>\n\u003Cli>Login Security & Monitoring w\u002FDashboard Alerting|Status Display & additional options\u002Ffeatures\u003C\u002Fli>\n\u003Cli>Idle Session Logout (ISL)\u003C\u002Fli>\n\u003Cli>Auth Cookie Expiration (ACE)\u003C\u002Fli>\n\u003Cli>File|Folder Lock: File Locking | Detect & Lock Folders that were not created by you\u003C\u002Fli>\n\u003Cli>FrontEnd|BackEnd Maintenance Mode\u003C\u002Fli>\n\u003Cli>Security Logging\u003C\u002Fli>\n\u003Cli>HTTP Error Logging\u003C\u002Fli>\n\u003Cli>PHP Error Logging\u003C\u002Fli>\n\u003Cli>DB Table Prefix Changer\u003C\u002Fli>\n\u003Cli>Pro-Tools: 16 mini-plugins\u003C\u002Fli>\n\u003Cli>Heads Up Dashboard Status Display\u003C\u002Fli>\n\u003Cli>Extensive System Info (System Info page)\u003C\u002Fli>\n\u003Cli>WordPress Automatic Update Options\u003C\u002Fli>\n\u003Cli>Force Strong Passwords (FSP)\u003C\u002Fli>\n\u003Cli>Send email alerts when new Plugin & Theme updates are available\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.ait-pro.com\u002Fbps-features\u002F\" title=\"BulletProof Security Features\" rel=\"nofollow ugc\">View All BulletProof Security Pro Feature Details\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>BulletProof Security Recommended Video Tutorials\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fvideo-tutorials\u002F#custom-code\" title=\"BulletProof Security Custom Code Video Tutorial\" rel=\"nofollow ugc\">BulletProof Security Custom Code Video Tutorial\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fvideo-tutorials\u002F#security-log-firewall\" title=\"BulletProof Security Security Log Video Tutorial\" rel=\"nofollow ugc\">BulletProof Security Security Log Video Tutorial\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Help Info\u003C\u002Fh3>\n\u003Cp>For details about BulletProof Security plugin features and frequently asked questions see the \u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fforums\u002Ftopic\u002Fbulletproof-security-plugin-frequently-asked-questions\u002F\" title=\"AIT-pro.com Forum\" rel=\"nofollow ugc\">BulletProof Security Plugin Frequently Asked Questions\u003C\u002Fa> forum topic. Extensive Help Info can be found on the \u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fforums\u002Ftopic\u002Fread-me-first-free\u002F#bps-free-general-troubleshooting\" title=\"AIT-pro.com Forum\" rel=\"nofollow ugc\">AIT-pro.com Forum\u003C\u002Fa> website and by clicking the Question Mark Help buttons on BulletProof Security plugin pages.\u003C\u002Fp>\n","WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam...",30000,4509595,674,"2025-12-08T15:11:00.000Z","5.0","7.0",[20,21,23,152,24],"secure","https:\u002F\u002Fforum.ait-pro.com\u002Fread-me-first\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbulletproof-security.7.1.zip",89,12,"2026-01-06 00:00:00",{"slug":159,"name":160,"version":161,"author":162,"author_profile":163,"description":164,"short_description":165,"active_installs":166,"downloaded":167,"rating":28,"num_ratings":28,"last_updated":168,"tested_up_to":16,"requires_at_least":169,"requires_php":170,"tags":171,"homepage":173,"download_link":174,"security_score":175,"vuln_count":28,"unpatched_count":28,"last_vuln_date":37,"fetched_at":30},"bearmor-security","Bearmor Security","0.9.16","bearmor","https:\u002F\u002Fprofiles.wordpress.org\u002Fandeirz\u002F","\u003Cp>\u003Cstrong>Finally, a WordPress security plugin that doesn’t slow down your site.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Bearmor Security is built for \u003Cstrong>small to medium businesses, freelancers, and agencies\u003C\u002Fstrong> who need real protection without the bloat. No confusing dashboards, no technical jargon, no performance hit.\u003C\u002Fp>\n\u003Ch3>Why Bearmor?\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>🎯 Built for Non-Technical Users\u003C\u002Fstrong>\u003Cbr \u002F>\nYou shouldn’t need a security degree to protect your website. Bearmor gives you clear, actionable insights in plain English.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⚡ Lightweight & Fast\u003C\u002Fstrong>\u003Cbr \u002F>\nUnlike bloated competitors, Bearmor won’t slow down your site. Clean code, efficient scans, zero impact on performance.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>💰 Most Features FREE\u003C\u002Fstrong>\u003Cbr \u002F>\nWhile others lock everything behind paywalls, Bearmor gives you professional-grade security for free. Compare us to Wordfence, Sucuri, or iThemes Security – we’re more generous.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🛡️ Real Protection, Not Theater\u003C\u002Fstrong>\u003Cbr \u002F>\nWe focus on what actually matters: detecting threats, blocking attacks, and keeping you informed. No fake “critical alerts” to scare you into upgrading.\u003C\u002Fp>\n\u003Ch3>🆓 FREE Features (Yes, Really Free)\u003C\u002Fh3>\n\u003Ch3>Malware Scanner\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Deep file scanning\u003C\u002Fstrong> for backdoors, shells, and malicious code\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart detection\u003C\u002Fstrong> with pattern matching and heuristics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Quarantine threats\u003C\u002Fstrong> with one click\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Whitelist false positives\u003C\u002Fstrong> to prevent future alerts\u003C\u002Fli>\n\u003Cli>Scans plugins, themes, uploads, and core files\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>File Integrity Monitoring\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Real-time tracking\u003C\u002Fstrong> of all file changes\u003C\u002Fli>\n\u003Cli>See exactly what changed, when, and where\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Quarantine suspicious changes\u003C\u002Fstrong> instantly\u003C\u002Fli>\n\u003Cli>Mark safe changes to keep your dashboard clean\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Login Security\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Brute force protection\u003C\u002Fstrong> with automatic IP blocking\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login activity log\u003C\u002Fstrong> – see every login attempt\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anomaly detection\u003C\u002Fstrong> – alerts for suspicious login patterns\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geographic tracking\u003C\u002Fstrong> – know where logins come from\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong> via email – completely free\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Hardening\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>One-click hardening\u003C\u002Fstrong> for common vulnerabilities\u003C\u002Fli>\n\u003Cli>Disable XML-RPC, file editing, directory browsing\u003C\u002Fli>\n\u003Cli>Hide WordPress version and login errors\u003C\u002Fli>\n\u003Cli>Enforce strong passwords\u003C\u002Fli>\n\u003Cli>All with simple on\u002Foff toggles\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Activity Logging\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Track all admin actions\u003C\u002Fli>\n\u003Cli>See who changed what and when\u003C\u002Fli>\n\u003Cli>Filter by user, action type, or date\u003C\u002Fli>\n\u003Cli>Essential for multi-user sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Dashboard\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>At-a-glance overview\u003C\u002Fstrong> of your security status\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security score\u003C\u002Fstrong> with clear letter grade (A-F)\u003C\u002Fli>\n\u003Cli>See threats, recent activity, and recommendations\u003C\u002Fli>\n\u003Cli>No clutter, just what matters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🚀 PRO Features (Optional Upgrade)\u003C\u002Fh3>\n\u003Ch3>What’s FREE Forever\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malware Scanner\u003C\u002Fstrong> – Full file scanning with quarantine\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Monitoring\u003C\u002Fstrong> – Real-time change tracking\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Security\u003C\u002Fstrong> – Brute force protection and blocking\u003C\u002Fli>\n\u003Cli>\u003Cstrong>2FA Authentication\u003C\u002Fstrong> – TOTP support built-in\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Quarantine Threats\u003C\u002Fstrong> – One-click isolation of malware\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Hardening\u003C\u002Fstrong> – All hardening options included\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Upgrade to PRO\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>🔥 \u003Cstrong>Advanced Firewall\u003C\u002Fstrong> – Block attacks before they reach WordPress\u003C\u002Fli>\n\u003Cli>🤖 \u003Cstrong>AI Security Analysis\u003C\u002Fstrong> – ChatGPT explains threats in plain English\u003C\u002Fli>\n\u003Cli>📊 \u003Cstrong>Deep Vulnerability Scanner\u003C\u002Fstrong> – Database scanning and comprehensive CVE checks\u003C\u002Fli>\n\u003Cli>⏰ \u003Cstrong>24\u002F7 Uptime Monitoring\u003C\u002Fstrong> – External monitoring with instant email alerts\u003C\u002Fli>\n\u003Cli>🌍 \u003Cstrong>Geo-Blocking\u003C\u002Fstrong> – Block entire countries and IP ranges\u003C\u002Fli>\n\u003Cli>🎯 \u003Cstrong>Priority Support\u003C\u002Fstrong> – Email support with faster response times\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fbearmor.eu\u002Fpricing\" rel=\"nofollow ugc\">Learn more about PRO \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>🎯 Perfect For\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Small Business Owners\u003C\u002Fstrong> who need protection without complexity\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Freelancers\u003C\u002Fstrong> managing multiple client sites\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agencies\u003C\u002Fstrong> who want reliable security without performance issues\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anyone\u003C\u002Fstrong> tired of bloated, confusing security plugins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔒 Privacy & External Services\u003C\u002Fh3>\n\u003Cp>Bearmor Security connects to our secure API server (bearmor.eu) for:\u003Cbr \u002F>\n– \u003Cstrong>License verification\u003C\u002Fstrong> (PRO users only)\u003Cbr \u002F>\n– \u003Cstrong>Uptime monitoring\u003C\u002Fstrong> (PRO users only)\u003Cbr \u002F>\n– \u003Cstrong>AI analysis\u003C\u002Fstrong> (PRO users only)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data sent to our servers:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Site URL\u003Cbr \u002F>\n– Admin email (for notifications)\u003Cbr \u002F>\n– Security scan results (PRO AI analysis only)\u003Cbr \u002F>\n– Site ID (anonymous identifier)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>We DO NOT:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Sell your data\u003Cbr \u002F>\n– Track your visitors\u003Cbr \u002F>\n– Store sensitive information\u003Cbr \u002F>\n– Share data with third parties\u003C\u002Fp>\n\u003Cp>For FREE users, only basic site registration data is sent (URL + email). No security data leaves your server.\u003C\u002Fp>\n\u003Cp>Read our full privacy policy: https:\u002F\u002Fbearmor.eu\u002Fprivacy\u003C\u002Fp>\n\u003Ch3>📊 Why Choose Bearmor?\u003C\u002Fh3>\n\u003Ch3>vs. Wordfence FREE\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>We include 2FA (they lock it behind PRO)\u003C\u002Fli>\n\u003Cli>We include quarantine (they lock it behind PRO)\u003C\u002Fli>\n\u003Cli>Lighter performance impact\u003C\u002Fli>\n\u003Cli>Simpler, cleaner interface\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>vs. Sucuri FREE\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>We include malware scanner (they lock it behind PRO)\u003C\u002Fli>\n\u003Cli>We include file monitoring (they lock it behind PRO)\u003C\u002Fli>\n\u003Cli>We include 2FA and quarantine\u003C\u002Fli>\n\u003Cli>More features in free version\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>vs. iThemes Security\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>More generous free tier\u003C\u002Fli>\n\u003Cli>Better malware detection\u003C\u002Fli>\n\u003Cli>Cleaner dashboard\u003C\u002Fli>\n\u003Cli>Faster scans\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🚀 Quick Start\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Install and activate Bearmor Security\u003C\u002Fli>\n\u003Cli>Run your first malware scan (Dashboard \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Scan Now)\u003C\u002Fli>\n\u003Cli>Enable recommended hardening options (Dashboard \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Hardening)\u003C\u002Fli>\n\u003Cli>Set up 2FA for your account (Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Two-Factor Auth)\u003C\u002Fli>\n\u003Cli>You’re protected! 🎉\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>No configuration needed. Works out of the box.\u003C\u002Fp>\n\u003Ch3>💬 Support\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Documentation:\u003C\u002Fstrong> https:\u002F\u002Fbearmor.eu\u002Fdocs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Support Forum:\u003C\u002Fstrong> https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fbearmor-security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email:\u003C\u002Fstrong> security@bearmor.eu (PRO users get priority)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🌟 What Users Say\u003C\u002Fh3>\n\u003Cp>\u003Cem>“Finally, a security plugin that doesn’t make me feel stupid. Everything just works.”\u003C\u002Fem> – Sarah M., Freelancer\u003C\u002Fp>\n\u003Cp>\u003Cem>“Switched from Wordfence. Bearmor is faster and the free version has more features.”\u003C\u002Fem> – Mike T., Agency Owner\u003C\u002Fp>\n\u003Cp>\u003Cem>“The AI analysis feature is a game-changer. It explains threats in plain English.”\u003C\u002Fem> – David R., Small Business Owner\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Bearmor Security respects your privacy. Here’s exactly what data we collect and why:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>FREE Users:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Site URL (to identify your installation)\u003Cbr \u002F>\n– Admin email (for security notifications)\u003Cbr \u002F>\n– Plugin version (for update checks)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>PRO Users (in addition to above):\u003C\u002Fstrong>\u003Cbr \u002F>\n– Security scan results (for AI analysis)\u003Cbr \u002F>\n– Uptime monitoring data (ping responses)\u003Cbr \u002F>\n– Firewall block logs (for threat intelligence)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>We NEVER:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Sell your data to third parties\u003Cbr \u002F>\n– Track your website visitors\u003Cbr \u002F>\n– Store passwords or sensitive user data\u003Cbr \u002F>\n– Share data without your explicit consent\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Storage:\u003C\u002Fstrong>\u003Cbr \u002F>\n– All data encrypted in transit (HTTPS)\u003Cbr \u002F>\n– Stored on secure servers in EU\u003Cbr \u002F>\n– Retained for 90 days, then automatically deleted\u003Cbr \u002F>\n– You can request data deletion anytime\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Third-Party Services:\u003C\u002Fstrong>\u003Cbr \u002F>\n– OpenAI (ChatGPT) for AI analysis (PRO only)\u003Cbr \u002F>\n– Our own servers for uptime monitoring (PRO only)\u003C\u002Fp>\n\u003Cp>Full privacy policy: https:\u002F\u002Fbearmor.eu\u002Fprivacy\u003Cbr \u002F>\nContact: security@bearmor.eu\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to external services in certain situations:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Bearmor API (bearmor.eu)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> Plugin activation, license verification, PRO features\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> Site URL, admin email, security scan results (PRO only)\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> License management, AI analysis, uptime monitoring\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fbearmor.eu\u002Fprivacy\u003Cbr \u002F>\n– \u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fbearmor.eu\u002Fterms\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress.org API (api.wordpress.org)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> Checking WordPress core file integrity\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> WordPress version number\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> Verify core files haven’t been tampered with\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003Cbr \u002F>\n– \u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fwordpress.org\u002Fabout\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WPVulnerability.net API (wpvulnerability.net)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> Scanning for known plugin\u002Ftheme vulnerabilities\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> Plugin and theme slugs (names only, no site data)\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> Check for known security vulnerabilities\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fwww.wpvulnerability.net\u002Fprivacy-policy\u003Cbr \u002F>\n– \u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fwww.wpvulnerability.net\u002Fterms-of-service\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP-API.com (ip-api.com)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> Firewall blocks an IP or login from restricted country\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> IP address only\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> Determine country of origin for geo-blocking\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003Cbr \u002F>\n– \u003Cstrong>Terms:\u003C\u002Fstrong> Free tier for non-commercial use\u003C\u002Fp>\n\u003Cp>\u003Cstrong>OpenAI API (PRO only)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> AI security analysis is requested\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> Anonymized security scan results\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> Generate security recommendations\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fopenai.com\u002Fprivacy\u003Cbr \u002F>\n– \u003Cstrong>Note:\u003C\u002Fstrong> No personally identifiable information is sent\u003C\u002Fp>\n\u003Cp>All external connections use HTTPS encryption. FREE users connect for: initial registration, vulnerability checks, and geo-blocking. No security scan data leaves your server unless you upgrade to PRO.\u003C\u002Fp>\n","Lightweight, powerful WordPress security for small businesses. Malware scanning, login protection, 2FA, hardening - most features FREE.",50,855,"2026-02-28T15:35:00.000Z","5.8","7.4",[20,21,23,24,172],"two-factor-authentication","https:\u002F\u002Fbearmor.eu","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbearmor-security.0.9.16.zip",100,{"slug":177,"name":178,"version":179,"author":180,"author_profile":181,"description":182,"short_description":183,"active_installs":184,"downloaded":185,"rating":186,"num_ratings":187,"last_updated":188,"tested_up_to":16,"requires_at_least":149,"requires_php":189,"tags":190,"homepage":192,"download_link":193,"security_score":194,"vuln_count":195,"unpatched_count":28,"last_vuln_date":196,"fetched_at":30},"all-in-one-wp-security-and-firewall","All-In-One Security (AIOS) – Security and Firewall","5.4.6","David Anderson \u002F Team Updraft","https:\u002F\u002Fprofiles.wordpress.org\u002Fdavidanderson\u002F","\u003Ch3>THE TOP RATED WORDPRESS SECURITY AND FIREWALL PLUGIN\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios&utm_creative_format=description\" rel=\"nofollow ugc\">All-in-One Security (AIOS)\u003C\u002Fa> is a WordPress security plugin from the same, trusted team that brought you UpdraftPlus.\u003C\u002Fp>\n\u003Cp>It’s called ‘All-In-One’ because it’s packed full of ways to keep your WordPress website(s) safe and secure.\u003C\u002Fp>\n\u003Cp>It includes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login security features\u003C\u002Fstrong> keep bots at bay. Lock out users based on a configurable number of login attempts, get two-factor authentication and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File and database security.\u003C\u002Fstrong> Get notified of file changes that occur outside of normal operations. Block access to key files and scan files and folders to spot insecure permissions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall.\u003C\u002Fstrong> Get PHP, .htaccess and 6G firewall rules courtesy of Perishable Press. Spot and block fake Google Bots and more!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Spam prevention.\u003C\u002Fstrong> Prevent annoying spam comments and reduce unnecessary load on the server. Automatically and permanently block IP addresses that exceed a set number of spam comments.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit log.\u003C\u002Fstrong> View events happening on your WordPress website. Find out if a plugin or theme has been added, removed, updated and more.\u003C\u002Fp>\n\u003Ch4>WHY ALL-IN-ONE SECURITY?\u003C\u002Fh4>\n\u003Cp>AIOS has a near-perfect \u003Cstrong>4.7 \u002F 5-star user rating\u003C\u002Fstrong> across more than 1 million installs.\u003C\u002Fp>\n\u003Cp>Great for beginners and experts alike. AIOS guides you logically and clearly through each of its features which are all clearly explained. Security features are marked as basic, intermediate and advanced. Each step increases your security score. Turn them on and watch your protection grow!\u003C\u002Fp>\n\u003Cp>We have a large support team of software developers. That means we have the availability and the skillset to help you with the trickiest of queries.\u003C\u002Fp>\n\u003Cp>We comb the WordPress plugin directory for support tickets daily – most queries are responded to within 24 hours.\u003C\u002Fp>\n\u003Cp>\u003Cem>Excellent plugin with numerous well-thought-out options for making a website more secure. I have been using it for years and am very happy with it. I recently had a small problem setting up a website and – even as a non-premium user – I received support very quickly. Highly recommended!\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>For even more ways to stay safe and secure, upgrade to \u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002Fpricing?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios_premium&utm_creative_format=description\" rel=\"nofollow ugc\">AIOS Premium\u003C\u002Fa> – it packs a punch security-wise, whilst being \u003Cstrong>extremely cost-competitive\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>LOGIN SECURITY\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication (TFA)\u003C\u002Fstrong> – Require TFA for specific user roles. Supports Google Authenticator, Microsoft Authenticator, Authy, and many more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detect and manage ‘admin’ usernames\u003C\u002Fstrong> – Identify default ‘admin’ usernames and guide users to change them to protect against brute force attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identify and correct identical login and display names\u003C\u002Fstrong> – Detect cases where the display name matches the username and provide guidance to improve login security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent user enumeration\u003C\u002Fstrong> – Block unauthorised access to URLs that can reveal sensitive information such as usernames or other details.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control login attempts\u003C\u002Fstrong> – Prevent brute force attacks by limiting the number of failed login attempts. Choose how many login attempts are allowed, set lockout durations, and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Force user logout\u003C\u002Fstrong> – Automatically log out users after a specified period of time. Unattended sessions are closed, reducing the risk of unauthorised access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manually approve new registrations\u003C\u002Fstrong> – Review and approve new user registrations to prevent spam and fake sign-ups.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhance WordPress salt security\u003C\u002Fstrong> – Adds 64 extra characters to WordPress salts, rotating them weekly. Makes cracking passwords virtually impossible, even if your database is stolen.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002F\u003Cbr \u002F>\n\u003Cstrong>Monitor and manage active sessions\u003C\u002Fstrong> – If a user is logged in who shouldn’t be, log them out or add them to a blacklist.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SPAM PREVENTION\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block spam coming from bots\u003C\u002Fstrong> – Reduce the load on your server and improve the user experience by automatically blocking spam comments from bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitor spam IP addresses\u003C\u002Fstrong> – Monitor the IP addresses of people or bots leaving spam comments. Choose which ones to block based on a configurable number of comments left.\u003C\u002Fp>\n\u003Ch4>FILE \u002F DATABASE Security\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Scan and fix file permissions\u003C\u002Fstrong> – Scan for insecure file permissions. Click once to fix issues and safeguard critical files and folders.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable PHP file editing\u003C\u002Fstrong> – Disable editing of PHP files (such as plugins and themes) via the dashboard. It’s often the first tool that attackers use as it allows for code execution.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protect sensitive files\u003C\u002Fstrong> – Prevent access to files like readme.html that might reveal information about your WordPress installation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File change scanner\u003C\u002Fstrong> – Get notified of any file changes which occur on your system. Exclude files and folders which change as part of normal operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent image hotlinking\u003C\u002Fstrong> – Prevent other websites from displaying your images via hotlinking and protect server bandwidth.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure database backups\u003C\u002Fstrong> – Perform a database backup via UpdraftPlus from AIOS. Change the default ‘wp_’ prefix to hide your WordPress database from hackers.\u003C\u002Fp>\n\u003Ch4>FIREWALL\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Get .htaccess firewall rules\u003C\u002Fstrong> – Deny access to the .htaccess and wp-config.php files. Disable the server signature and limit file uploads to a configurable size.**\u003C\u002Fp>\n\u003Cp>Block access to the debug.log file and prevent Apache servers from listing the contents of a directory when an index.php file is not present\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Get PHP firewall rules\u003C\u002Fstrong> – PHP firewall rules prevent malicious users from exploiting well-known vulnerabilities in XML-RPC. Safeguard your content by disabling RSS and Atom feeds and avoid cross-site scripting (XSS) attacks.\u003Cbr \u002F>\nBlock fake Google bots and POST requests made by bots – Block fake Google bots and stop bots from making POST requests by blocking IP addresses where the user-agent and referrer fields are blank.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Utilise 6G firewall rules\u003C\u002Fstrong> – Employ flexible blacklist rules to reduce the number of malicious URL requests that hit your website (courtesy of Perishable Press).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>And more\u003C\u002Fstrong> – Blacklist (and whitelist) IP ranges and user agents and block unauthorized access to data by disabling REST API access for non-logged-in requests.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION ENHANCED [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication\u003C\u002Fstrong> is included in the free plugin. Upgrade to Premium if you’d like to:\u003Cbr \u002F>\nRequire TFA after a set time period – Mandate TFA for all admins or other roles after their accounts reach a specified age.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control how often TFA is required\u003C\u002Fstrong> – Set TFA to be required after a certain number of days on trusted devices instead of every login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customise design layout\u003C\u002Fstrong> – Adjust the TFA design to match your website’s existing layout and branding.\u003Cbr \u002F>\nEmergency codes – Generate one-time use emergency codes to regain access if you lose your TFA device.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Multisite Compatible\u003C\u002Fstrong> – Ensure compatibility with WordPress multisite networks and their sub-sites for consistent TFA application.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Integration with login forms\u003C\u002Fstrong> – Integrate TFA with various login forms, including WooCommerce, Affiliates-WP, Elementor Pro, bbPress, and ‘Theme My Login’ without additional coding.\u003C\u002Fp>\n\u003Ch4>SMART 404 BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block IPs based on 404 errors\u003C\u002Fstrong> – Detect hackers probing your URLs via script and bots by the 404 errors they leave behind.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 Configuration\u003C\u002Fstrong> – Set a figure for the maximum number of 404 events allowed before an IP address is blocked. Choose a time period within which the 404 events must occur (e.g., 10 errors within 10 minutes).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 block by URL string\u003C\u002Fstrong> – Instantly block an IP address if a 404 event includes a specific URL string.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 whitelisting\u003C\u002Fstrong> – Prevent particular IP addresses from being permanently blocked due to 404 events.\u003C\u002Fp>\n\u003Ch4>COUNTRY BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block traffic to the entire site or to specific pages or posts\u003C\u002Fstrong> – Useful if you’re an e-commerce site and you want to block sales to some countries for shipping or tax reasons.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Whitelist some users from blocked countries\u003C\u002Fstrong> – Whitelist IP addresses or IP ranges even if they are part of a blocked country.\u003C\u002Fp>\n\u003Ch4>MALWARE SCANNING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Automatic malware scanning\u003C\u002Fstrong> – Detect and protect against the latest malware, trojans, and spyware.\u003Cbr \u002F>\nAlerts you to blacklisting by search engines – Monitor your site for blacklisting by search engines due to malicious code.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Response time monitoring\u003C\u002Fstrong> – Keep track of your website’s response time to identify and address any performance issues.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Uptime monitoring\u003C\u002Fstrong> – Checks your website’s uptime every 5 minutes and alerts you immediately if your site or server goes down.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advice and malware removal\u003C\u002Fstrong> – Need hands-on advice and support for malware removal? Our team of genuine cybersecurity experts is here to help.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification if something’s amiss\u003C\u002Fstrong> – Receive notifications about any issues with your site so you can address problems before they escalate.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cp>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u003C\u002Fp>\n\u003Ch4>Developers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you are a developer and you need some extra hooks or filters for this plugin then let us know.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All-In-One Security plugin can be translated to any language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Currently available translations:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>Hungarian\u003C\u002Fli>\n\u003Cli>Italian\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Chinese\u003C\u002Fli>\n\u003Cli>Portuguese (Brazil)\u003C\u002Fli>\n\u003Cli>Persian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy Policy\u003C\u002Fh4>\n\u003Cp>This plugin may collect IP addresses for security reasons such as mitigating brute force login threats and malicious activity.\u003C\u002Fp>\n\u003Cp>The collected information is stored on your server. No information is transmitted to third parties or remote server locations.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n","Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.",1000000,36139406,94,1693,"2026-01-28T22:15:00.000Z","5.6",[20,21,191,24,172],"malware-scanning","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fall-in-one-wp-security-and-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fall-in-one-wp-security-and-firewall.5.4.6.zip",93,26,"2024-02-08 00:00:00",{"slug":198,"name":199,"version":200,"author":201,"author_profile":202,"description":203,"short_description":204,"active_installs":184,"downloaded":205,"rating":206,"num_ratings":207,"last_updated":208,"tested_up_to":16,"requires_at_least":209,"requires_php":150,"tags":210,"homepage":213,"download_link":214,"security_score":215,"vuln_count":47,"unpatched_count":28,"last_vuln_date":216,"fetched_at":30},"sg-security","Security Optimizer – The All-In-One Protection Plugin","1.5.9","SiteGround","https:\u002F\u002Fprofiles.wordpress.org\u002Fsiteground\u002F","\u003Cp>\u003Cstrong>Bulletproof your website security in a few clicks against a range of security breaches, including brute-force attacks, malware threats and bots, with our free WordPress security plugin – Security Optimizer.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Proactively monitor your site’s security to detect any suspicious activity and take immediate actions to protect your site and prevent further damage with these essential features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enable \u003Cstrong>2FA (Two-Factor Authentication)\u003C\u002Fstrong> for an extra layer of website security\u003C\u002Fli>\n\u003Cli>Set \u003Cstrong>Limit Login Attempts\u003C\u002Fstrong> to deter malicious login attempts and brute-force attacks\u003C\u002Fli>\n\u003Cli>Change your default login URL to \u003Cstrong>Custom Login URL\u003C\u002Fstrong> to avoid attacks\u003C\u002Fli>\n\u003Cli>Activate \u003Cstrong>Advanced XSS Protection\u003C\u002Fstrong> to fortify your website against malicious attacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lock and Protect System Folders\u003C\u002Fstrong> to ensure no unauthorized or malicious scripts can be executed in your system folders\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Themes & Plugins Editor\u003C\u002Fstrong> to safeguard your website from unauthorized access via the WordPress editor\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide WordPress Version\u003C\u002Fstrong> effortlessly, keeping it hidden from prying eyes\u003C\u002Fli>\n\u003Cli>Use \u003Cstrong>Activity Log\u003C\u002Fstrong> to monitor your site and quickly prevent malicious actions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Post-Hack Actions\u003C\u002Fstrong> to take immediate actions and prevent further damages\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Developed by the website security experts at \u003Ca href=\"https:\u002F\u002Fwww.siteground.com\u002Fwordpress-plugins\u002Fsiteground-security\" rel=\"nofollow ugc\">SiteGround\u003C\u002Fa> and trusted by over 900,000 webmasters for its robust security shield and ease of use to safeguard WordPress applications from possible attacks on any hosting platform.\u003C\u002Fp>\n\u003Ch4>AWARDS:\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.templatemonster.com\u002Fawards\u002Fwinners-2022\u002F\" rel=\"nofollow ugc\">Monster Awards 2022\u003C\u002Fa>: Best WordPress Security Plugin 🥇\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.templatemonster.com\u002Fawards\u002Fwinners-2021\u002F\" rel=\"nofollow ugc\">Monster Awards 2021\u003C\u002Fa>: Best WordPress Security Plugin 🥇\u003C\u002Fp>\n\u003Ch4>Plugin Video\u003C\u002Fh4>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FFOheCz7sm9A?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Plugin Tutorial\u003C\u002Fh4>\n\u003Cp>Unveil the vast array of features and unleash the full potential of our security plugin in our \u003Ca href=\"https:\u002F\u002Fwww.siteground.com\u002Ftutorials\u002Fwordpress\u002Fsg-security\u002F\" rel=\"nofollow ugc\">Security Optimizer Tutorial\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>SITE PROTECTION FEATURES\u003C\u002Fh3>\n\u003Cp>Safeguard your WordPress application using our powerful site security toolset. Our comprehensive features are specifically designed to strengthen your website’s defenses against malware, exploits, and various malicious activities. With these tools at your disposal, you can ensure the utmost bot, malware and brute force protection for your website:\u003C\u002Fp>\n\u003Ch4>Lock and Protect System Folders\u003C\u002Fh4>\n\u003Cp>Ensure the maximum security for your application’s system folders by preventing the execution of any unauthorized or malicious scripts. The Lock and Protect System Folders feature acts as a powerful shield against potential threats.\u003C\u002Fp>\n\u003Ch4>Hide WordPress Version\u003C\u002Fh4>\n\u003Cp>Protect your website from mass attacks by hiding the WordPress version, which helps to mitigate version-specific vulnerabilities.\u003C\u002Fp>\n\u003Ch4>Disable Themes & Plugins Editor\u003C\u002Fh4>\n\u003Cp>Enhance the security of your WordPress admin area by disabling the Themes & Plugins Editor, preventing potential coding errors and unauthorized access through the editor.\u003C\u002Fp>\n\u003Ch4>Disable XML-RPC\u003C\u002Fh4>\n\u003Cp>Mitigate potential security risks by disabling the XML-RPC protocol, which has been exploited in various attacks. Please note that disabling XML-RPC will restrict WordPress from communicating with third-party systems. We recommend enabling this feature unless you have a specific need for it.\u003C\u002Fp>\n\u003Ch4>Disable RSS and ATOM Feeds\u003C\u002Fh4>\n\u003Cp>Prevent content scraping and specific attacks on your site by disabling RSS and ATOM feeds. Unless you have readers accessing your site via RSS readers, it is recommended to keep this feature enabled.\u003C\u002Fp>\n\u003Ch4>Advanced XSS Protection\u003C\u002Fh4>\n\u003Cp>Add an extra layer of website security against cross-site scripting (XSS) attacks by enabling Advanced XSS Protection, bolstering the overall security of your website.\u003C\u002Fp>\n\u003Ch4>Delete Default Readme.html\u003C\u002Fh4>\n\u003Cp>Eliminate potential vulnerabilities by deleting the default readme.txt file, which contains information about your website. By removing this file, you reduce the risk of your site being listed in vulnerable sites targeted by hackers.\u003C\u002Fp>\n\u003Ch3>Login Security\u003C\u002Fh3>\n\u003Ch4>Custom Login Url\u003C\u002Fh4>\n\u003Cp>Personalize your login URL to thwart potential attacks and create a strong entry point. Bid farewell to the default login URL and embrace a bespoke path of your choosing. Additionally, you have the freedom to modify the default sign-up URL as well.\u003C\u002Fp>\n\u003Ch4>Login Access\u003C\u002Fh4>\n\u003Cp>Restrict login page access to specific IP addresses or IP ranges, effectively thwarting malicious login attempts and deterring brute force attacks.\u003C\u002Fp>\n\u003Ch4>2FA (Two-Factor Authentication)\u003C\u002Fh4>\n\u003Cp>Immerse your website in an impenetrable shield of security with 2FA. This formidable feature demands that all admin users furnish a unique token, generated exclusively through the Google Authentication application, during the login process.\u003C\u002Fp>\n\u003Ch4>Disable Common Usernames\u003C\u002Fh4>\n\u003Cp>Don’t fall victim to predictable security breaches! The use of common usernames, such as ‘admin,’ poses a significant threat to the integrity of your website. Activate this option to disable the creation of common usernames. If any weak usernames already exist, we’ll prompt you to provide new, stronger alternatives.\u003C\u002Fp>\n\u003Ch4>Limit Login Attempts\u003C\u002Fh4>\n\u003Cp>Maintain control over unauthorized access attempts with Limit Login Attempts. Set a specific threshold for the number of login failures users can endure before consequences arise. After reaching the limit, the IP address associated with the unsuccessful login attempts will be blocked for one hour. Persistent failures will result in longer restrictions, starting with 24 hours and escalating to a week.\u003C\u002Fp>\n\u003Ch3>ACTIVITY MONITORING\u003C\u002Fh3>\n\u003Cp>Monitor your website and login page for unauthorized visitors and brute force attempts to prevent malicious actions\u003C\u002Fp>\n\u003Ch4>Activity Log\u003C\u002Fh4>\n\u003Cp>The Activity Log page provides you with a comprehensive view of the activities performed by registered, unknown, and blocked visitors. It allows you to closely monitor any suspicious behavior and take appropriate actions in case of a compromised user, plugin, or hacking attempt. You can leverage the quick tools available to swiftly block future attempts.\u003C\u002Fp>\n\u003Ch4>Weekly Security Reports\u003C\u002Fh4>\n\u003Cp>Receive a weekly traffic summary for your website directly to your inbox. This \u003Cstrong>Weekly Security Report\u003C\u002Fstrong> compiles data on both bot and human traffic, along with details about blocked login and visit attempts to proactively monitor traffic and promptly identify suspicious activity.\u003C\u002Fp>\n\u003Ch3>POST-HACK ACTIONS\u003C\u002Fh3>\n\u003Cp>Take immediate measures to protect your website if you suspect a compromise and prevent further damage. Here, you’ll find convenient solutions to address the situation effectively:\u003C\u002Fp>\n\u003Ch4>Reinstall All Free Plugins\u003C\u002Fh4>\n\u003Cp>In the event of a hack, utilizing the Reinstall All Free Plugins feature can help mitigate potential harm. This action reinstalls all of your free plugins, reducing the likelihood of additional exploits or the reuse of malicious code.\u003C\u002Fp>\n\u003Ch4>Log Out All Users\u003C\u002Fh4>\n\u003Cp>To prevent any further unauthorized activities by users or attackers, you can choose to log out all users instantly using the Log Out All Users feature.\u003C\u002Fp>\n\u003Ch4>Force Password Reset\u003C\u002Fh4>\n\u003Cp>By enforcing a password reset, you can ensure that all users are prompted to change their passwords during their next login. This not only strengthens the security of their accounts but also immediately logs out all currently logged-in users.\u003C\u002Fp>\n\u003Ch3>Requirements\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>WordPress 4.7\u003C\u002Fli>\n\u003Cli>PHP 7.0\u003C\u002Fli>\n\u003Cli>Working .htaccess file\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Data Collection\u003C\u002Fh3>\n\u003Cp>Collection of technical data is optional and is \u003Ca href=\"https:\u002F\u002Fwww.siteground.com\u002Fkb\u002Fwhat-information-wp-plugins-collect\" rel=\"nofollow ugc\">listed here\u003C\u002Fa>. This data is collected only for technical analysis, improvements and the possibility to contact the plugin user in case urgent issues need to be fixed (for example a critical security release that needs to be communicated to site owners). The plugin user can manage their preferences within the WP admin to control the collection of technical data. We advise opting in for this data collection, as it can enhance the plugin’s performance. You may find more information on data collection in our \u003Ca href=\"https:\u002F\u002Fwww.siteground.com\u002Fviewtos\u002Fsiteground_plugins_privacy_notice\" rel=\"nofollow ugc\">Plugins Privacy Notice\u003C\u002Fa>.\u003C\u002Fp>\n","Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.",31890492,90,153,"2026-01-15T09:21:00.000Z","4.7",[20,211,23,24,212],"login","web-application-firewall","https:\u002F\u002Fsiteground.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsg-security.1.5.9.zip",86,"2025-11-30 00:00:00",{"slug":218,"name":219,"version":220,"author":221,"author_profile":222,"description":223,"short_description":224,"active_installs":225,"downloaded":226,"rating":215,"num_ratings":227,"last_updated":228,"tested_up_to":16,"requires_at_least":229,"requires_php":150,"tags":230,"homepage":234,"download_link":235,"security_score":175,"vuln_count":28,"unpatched_count":28,"last_vuln_date":37,"fetched_at":30},"malcare-security","MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall","6.36","malcare","https:\u002F\u002Fprofiles.wordpress.org\u002Fmalcare\u002F","\u003Ch3>MALCARE SECURITY SERVICES\u003C\u002Fh3>\n\u003Cp>Security Plugin For WordPress Websites\u003Cbr \u002F>\n★★★★★\u003C\u002Fp>\n\u003Cp>A WordPress security plugin ensures that your website remains completely safe and secure, always. We created \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002F\" rel=\"nofollow ugc\">MalCare Security Plugin\u003C\u002Fa> to help website owners worry less about their site security, achieve peace of mind and focus all their energies on growing their business or website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why you need MalCare Security?\u003C\u002Fstrong>\u003Cbr \u002F>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fj3h0JF0we4o?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Difference Between MalCare Free vs Premium\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F4ja5ix9WDCo?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>\u003Cstrong>Why MalCare is best WordPress security plugin?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fvt-0TrMV-TQ?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>\u003Cstrong>MalCare in 1 Minute – Overview\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FH1XRntW_FeE?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003Cbr \u002F>\n\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Important Links: \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Ffeatures\u002F\" rel=\"nofollow ugc\">Security Features\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002F\" rel=\"nofollow ugc\">Why Choose MalCare?\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Ftop-wordpress-security-plugins-compared\u002F\" rel=\"nofollow ugc\">Comparisons\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fmalcare-free-premium\u002F\" rel=\"nofollow ugc\">Free vs Paid\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>MalCare is the \u003Cstrong>fastest\u003C\u002Fstrong> malware detection and removal plugin loved by thousands of developers and agencies. With an industry-first \u003Cstrong>automatic one-click malware removal\u003C\u002Fstrong>, your WordPress website is clean before Google blacklists it or your web host takes it down. MalCare has been developed from the ground up after \u003Cstrong>analyzing over 240,000 websites over 2.5+ years\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Its \u003Cstrong>intelligent scanning methodology\u003C\u002Fstrong> will \u003Cstrong>never slow down your WordPress site\u003C\u002Fstrong> and \u003Cstrong>accurately identifies\u003C\u002Fstrong> the most complex malware that typically goes undetected in other popular WordPress security plugins.\u003C\u002Fp>\n\u003Cp>The \u003Cstrong>one-click malware cleaner\u003C\u002Fstrong> offers unlimited automated cleanups while the inbuilt \u003Cstrong>powerful cloud-based firewall\u003C\u002Fstrong> ensures round-the-clock website protection against spam attacks. Moreover, you can \u003Cstrong>block countries\u003C\u002Fstrong> to mitigate hack attacks.\u003C\u002Fp>\n\u003Cp>MalCare comes integrated with a \u003Cstrong>complete website management\u003C\u002Fstrong> module that ensures better WP security and site management to your websites from a single dashboard.\u003C\u002Fp>\n\u003Cp>The WP security plugin \u003Cstrong>notifies you if the WordPress site goes down\u003C\u002Fstrong> so that you can handle the situation before you start losing visitors. Performance Check enables WordPress users to keep an eye on their \u003Cstrong>loading speed\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>MalCare offers a premium \u003Cstrong>White-Label\u003C\u002Fstrong> solution that lets agencies provide better website security to their clients without risking their business. And enables users to \u003Cstrong>generate beautiful reports\u003C\u002Fstrong> for their clients.\u003C\u002Fp>\n\u003Ch3>Why Choose MalCare WordPress Security Plugin?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Ch4>WordPress Malware Scanner\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Cloud Based Deep malware scanner\u003C\u002Fli>\n\u003Cli>Doesn’t Slow down your WordPress site\u003C\u002Fli>\n\u003Cli>Detects malware BEFORE it’s too late\u003C\u002Fli>\n\u003Cli>NO impact on your website\u003C\u002Fli>\n\u003Cli>Finds ALL types of malware, even new & complex ones\u003C\u002Fli>\n\u003Cli>Get Alerts about Security Risks with our WordPress Vulnerability Scanner\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>WordPress Malware Removal\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>View hacked file details\u003C\u002Fli>\n\u003Cli>Cleans your site INSTANTLY, in less than 60 Secs\u003C\u002Fli>\n\u003Cli>Removes ALL traces of malware\u003C\u002Fli>\n\u003Cli>UNLIMITED hack cleanups\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>WordPress Website Protection\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Blocks hacker BOTS from attacking login page\u003C\u002Fli>\n\u003Cli>Identifies & blocks MALICIOUS traffic\u003C\u002Fli>\n\u003Cli>Enables users to HARDEN their WordPress sites\u003C\u002Fli>\n\u003Cli>Enables users to block ENTIRE countries\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Easy to Use\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Set up an account in 60 secs\u003C\u002Fli>\n\u003Cli>Configure security once & never look at it again\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Agile & responsive customer support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Why Is MalCare Such a Game-Changer?\u003C\u002Fh3>\n\u003Cp>MalCare offers unparalleled security services. Some services are free and others are paid.\u003C\u002Fp>\n\u003Ch4>MalCare’s FREE Services –\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\n\u003Ch4>Cloud-Based Malware Scanning (Free)\u003C\u002Fh4>\n\u003Cp>MalCare’s Cloud-based Scanning ensures no impact on your website ever. Moreover, it detects Complex Malware missed by other popular security plugins for WordPress.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Web-Application WordPress Firewall (Free)\u003C\u002Fh4>\n\u003Cp>Get Real-Time Protection for your WordPress website against the latest security threats with MalCare’s Smart Firewall. Block hackers & bots before they harm your site.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>CAPTCHA-Based Login Page Protection (Free)\u003C\u002Fh4>\n\u003Cp>Automatically prevent brute force attacks with MalCare’s Smart Captcha-Based Login Page Protection. Round-the-clock protection against malicious traffic.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>MalCare’s PAID Services –\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\n\u003Ch4>Viewing Hacked Files (Paid)\u003C\u002Fh4>\n\u003Cp>View the infected files present on your WordPress website. Learn which themes or plugins or files or folders were infected by hackers.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Industry-First Instant Malware Removal (Paid)\u003C\u002Fh4>\n\u003Cp>Clean your hacked site instantly in less than 60 secs with MalCare’s 1-Click Cleaner. Clean your website before Google blacklists it or your web host takes it down.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>WordPress Recommended Website Hardening (Paid)\u003C\u002Fh4>\n\u003Cp>Easily configure WordPress recommended best security practices with just 1-Click from right within MalCare’s dashboard. No technical knowledge needed.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Geo-blocking (Paid)\u003C\u002Fh4>\n\u003Cp>Restrict access to users based on their geographical location. Easily block all visitors from certain countries to mitigate the risk of being hacked.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Uptime Monitoring (Paid)\u003C\u002Fh4>\n\u003Cp>With MalCare’s Uptime Monitoring keep a steady eye on your WordPress site. It ensures that you are not oblivious to website downtime.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Common Hack Attacks Prevented By MalCare\u003C\u002Fh3>\n\u003Cp>MalCare protects websites against all common hack attacks which includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-brute-force\u002F\" rel=\"nofollow ugc\">Brute force attacks\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fjapanese-keyword-hack\u002F\" rel=\"nofollow ugc\">Japanese keyword hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-hacked-redirect\u002F\" rel=\"nofollow ugc\">WordPress redirect hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwhat-is-pharma-hack-how-to-clean-it\u002F\" rel=\"nofollow ugc\">Pharma hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fseo-spam\u002F\" rel=\"nofollow ugc\">SEO spam hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-theme-hacked\u002F\" rel=\"nofollow ugc\">WordPress theme hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fspam-link-injection-wordpress\u002F\" rel=\"nofollow ugc\">WordPress spam link injections\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Frevslider-exploit\u002F\" rel=\"nofollow ugc\">Revslider hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-timthumb\u002F\" rel=\"nofollow ugc\">TimThumb hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fadminer-php-hack\u002F\" rel=\"nofollow ugc\">Adminer.php hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fcross-site-scripting-xss-attacks-what-how-prevent-them\u002F\" rel=\"nofollow ugc\">XSS or cross-site scripting hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fhow-to-detect-and-remove-wp-vcd-malware-a-step-by-step-guide-and-a-bonus-plugin\u002F\" rel=\"nofollow ugc\">WP-VCD hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fpreventing-sql-injections\u002F\" rel=\"nofollow ugc\">SQL injection hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-malvertising\u002F\" rel=\"nofollow ugc\">WordPress malvertising hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fremove-google-blacklist-warning\u002F\" rel=\"nofollow ugc\">Google Blacklist hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fgoogle-adwords-account-suspended\u002F\" rel=\"nofollow ugc\">Google Adwords hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fsession-hijacking-cookie-stealing\u002F\" rel=\"nofollow ugc\">Cookie stealing & session hijacking\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fhow-to-remove-phishing\u002F\" rel=\"nofollow ugc\">WordPress phishing hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Ffavicon-ico-virus-wordpress\u002F\" rel=\"nofollow ugc\">Favicon.ico virus hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fremoving-wp-feed-php-malware\u002F\" rel=\"nofollow ugc\">WP-Feed.php & WP-Tmp.php\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fhow-to-scan-malware-and-backdoors-of-your-wordpress-site\u002F\" rel=\"nofollow ugc\">Backdoor hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fcoinhive-malware-wordpress\u002F\" rel=\"nofollow ugc\">Coinhive hack\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fdeface-wordpress\u002F\" rel=\"nofollow ugc\">WordPress deface hack\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>MalCare Free vs. MalCare Premium\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\n\u003Ch4>Cloud Based Malware Scanner (FREE)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Cloud-Based Malware Scanning \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Deep Malware Scanning – Files & Database \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Website Firewall (FREE)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Web Application Firewall \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Plugin Based Firewall \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Rules update every 7 days \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Login Page Protection \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Bot Protection \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Rules update every 5 mins \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Geo-Blocking \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Website Hardening \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Instant Malware Removal (PAID)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>View Malware Insights \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Instant One-Click Clean Ups \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Automatic Clean-Ups \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Unlimited Clean-Ups \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Personalized Customer Support (Paid)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Support on WordPress forum \u003Cstrong>(Free)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Support via email and chat \u003Cstrong>(Paid)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Who Can Benefit From MalCare?\u003C\u002Fh3>\n\u003Cp>MalCare is perfect for:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Any WordPress Websites\u003C\u002Fli>\n\u003Cli>Small Business Websites\u003C\u002Fli>\n\u003Cli>Developer Websites\u003C\u002Fli>\n\u003Cli>Web Designing Websites\u003C\u002Fli>\n\u003Cli>eCommerce Stores\u003C\u002Fli>\n\u003Cli>Niche Sites\u003C\u002Fli>\n\u003Cli>Artists & Photographers Sites\u003C\u002Fli>\n\u003Cli>Amateur & Professional Bloggers\u003C\u002Fli>\n\u003Cli>Local Business Sites\u003C\u002Fli>\n\u003Cli>Website for Startups\u003C\u002Fli>\n\u003Cli>Websites Selling Courses\u003C\u002Fli>\n\u003Cli>Influencer Sites\u003C\u002Fli>\n\u003Cli>Web Hosting Companies\u003C\u002Fli>\n\u003Cli>Website Maintenance Services or Agencies\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Detailed Setup Step-by-Step Tutorials\u003C\u002Fh3>\n\u003Cp>This WordPress security plugin works in tandem with the \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\" rel=\"nofollow ugc\">MalCare\u003C\u002Fa> servers. MalCare servers do all the heavy processing and will alert you if your site has any security issues.\u003C\u002Fp>\n\u003Cp>Hence a MalCare account is needed to use the plugin. This account can also be used by our other products including \u003Ca href=\"https:\u002F\u002Fblogvault.net\" rel=\"nofollow ugc\">BlogVault\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcare.freshdesk.com\u002Fsupport\u002Fsolutions\u002Farticles\u002F35000055512-how-do-i-set-up-a-malcare-account-\" rel=\"nofollow ugc\">How to Set Up a MalCare Account?\u003C\u002Fa> (Help Doc)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=v8L_DZllk7k&list=\" rel=\"nofollow ugc\">How to Set Up a MalCare Account?\u003C\u002Fa> (Video)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>MalCare Full Security Features List\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Ch4>Cloud Based Malware Scanner\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Daily Scan Frequency\u003C\u002Fli>\n\u003Cli>On-demand Site Scans\u003C\u002Fli>\n\u003Cli>Scan Non-WP Files\u003C\u002Fli>\n\u003Cli>Does not slow down your website ever\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Instant Malware Removal\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>View Hacked Files details\u003C\u002Fli>\n\u003Cli>Instant Automatic Malware Removal\u003C\u002Fli>\n\u003Cli>Removal of Unknown & New Malware\u003C\u002Fli>\n\u003Cli>Unlimited Malware Removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Intelligent Malware Protection\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Web Application Firewall\u003C\u002Fli>\n\u003Cli>IP Whitelisting\u003C\u002Fli>\n\u003Cli>CAPTCHA-based Login Page Protection\u003C\u002Fli>\n\u003Cli>Traffic Logs\u003C\u002Fli>\n\u003Cli>Login Logs\u003C\u002Fli>\n\u003Cli>Geo-Blocking\u003C\u002Fli>\n\u003Cli>Alerts for Suspicious Logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Website Hardening\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Block PHP Execution in Untrusted Folders\u003C\u002Fli>\n\u003Cli>Disable Files Editor\u003C\u002Fli>\n\u003Cli>Block Plugin or Theme Installation\u003C\u002Fli>\n\u003Cli>Change Security Keys\u003C\u002Fli>\n\u003Cli>Reset All Passwords\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Complete Website Management\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Centralized Dashboard\u003C\u002Fli>\n\u003Cli>Plugins & Themes Management & Update\u003C\u002Fli>\n\u003Cli>User Management\u003C\u002Fli>\n\u003Cli>Team Management\u003C\u002Fli>\n\u003Cli>Client Management\u003C\u002Fli>\n\u003Cli>Generate & Schedule Reports\u003C\u002Fli>\n\u003Cli>White-Labeling Solution\u003C\u002Fli>\n\u003Cli>Uptime Monitoring\u003C\u002Fli>\n\u003Cli>Site Speed Monitoring\u003C\u002Fli>\n\u003Cli>Blacklist Alarm\u003C\u002Fli>\n\u003Cli>Slack Integration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Ch4>Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Email\u003C\u002Fli>\n\u003Cli>Chat\u003C\u002Fli>\n\u003Cli>Social Media\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Fans Are Raving About Us\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fvisualcomposer.com\u002Fblog\u002Fmalcare-review\u002F\" rel=\"nofollow ugc\">MalCare Review on VisualComposer\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.elegantthemes.com\u002Fblog\u002Fresources\u002Fmalcare-security-and-firewall-the-right-security-plugin-for-your-site\" rel=\"nofollow ugc\">MalCare Review on ElegantThemes\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fblog.weglot.com\u002Fideal-security-solution-malcare-review\u002F\" rel=\"nofollow ugc\">MalCare Review on Weglot\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.wpwhitesecurity.com\u002Fmalcare-wordpress-site-security-service-reviewed\u002F\" rel=\"nofollow ugc\">MalCare Review on WPWhiteSecurity\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=2yNIb4Pc_ig\" rel=\"nofollow ugc\">MalCare Reviews by WordPress Influencer Adam Preiser (Plus Real Malware Removal Demo)\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Connect With Our Team of Security Experts\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fgroups\u002FWordPressForWebCreators\u002F\" rel=\"nofollow ugc\">Join MalCare’s Facebook Community\u003C\u002Fa> – The purpose of the group is to enable Web Creators to gain valuable insights and help from community members which will be valuable to their business. So, if you are a WordPress user & want to keep up with the latest industry news and get help for your business, \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fgroups\u002FWordPressForWebCreators\u002F\" rel=\"nofollow ugc\">join us\u003C\u002Fa>!\u003C\u002Fp>\n\u003Ch3>Don’t Know Where to Getting Started? Start From Here –\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcare.freshdesk.com\u002Fsupport\u002Fsolutions\u002Farticles\u002F35000055512-how-do-i-set-up-a-malcare-account-\" rel=\"nofollow ugc\">How to Setup MalCare Account?\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fgroups\u002FWordPressForWebCreators\u002F\" rel=\"nofollow ugc\">Join MalCare Facebook Group MalCare\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fchannel\u002FUC5oQAXXvndQJuyVrWgMRWqg\" rel=\"nofollow ugc\">MalCare Tutorial Videos\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcare.freshdesk.com\u002Fsupport\u002Fhome\" rel=\"nofollow ugc\">User Help Documentations\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Ffaq\u002F\" rel=\"nofollow ugc\">Frequently Asked Questions\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fmalcare.freshdesk.com\u002Fsupport\u002Ftickets\u002Fnew\" rel=\"nofollow ugc\">Support for MalCare Users\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>MalCare vs. Others\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.codeinwp.com\u002Fblog\u002Fsucuri-vs-wordfence-vs-malcare\u002F\" rel=\"nofollow ugc\">MalCare vs Sucuri vs Wordfence by CodeinWP\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmayor.com\u002Fmalcare-sucuri-wordfence-sitelock-ithemes-security-comparison\u002F\" rel=\"nofollow ugc\">MalCare vs Sucuri vs Wordfence vs SiteLock vs iThemes Security by WPMayor\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Get Bulletproof Security for your WordPress site. WordPress security plugin packed with comprehensive Firewall, malware scanner, cleaner & more.",200000,17387894,519,"2026-01-29T13:26:00.000Z","4.0",[20,231,23,232,233],"malware-removal","vulnerabilities","wordpress-security","https:\u002F\u002Fwww.malcare.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmalcare-security.6.36.zip",{"attackSurface":237,"codeSignals":1094,"taintFlows":1647,"riskAssessment":1674,"analyzedAt":1690},{"hooks":238,"ajaxHandlers":1023,"restRoutes":1074,"shortcodes":1075,"cronEvents":1079,"entryPointCount":1092,"unprotectedCount":1093},[239,246,250,254,257,262,266,270,273,276,279,282,285,289,295,298,301,305,309,314,319,324,329,332,336,338,342,346,349,352,354,357,362,367,371,375,379,383,386,389,392,395,396,401,404,409,412,417,420,424,429,433,437,442,446,451,456,461,463,467,470,472,475,479,483,488,492,497,499,502,505,507,509,514,517,520,525,530,534,538,542,545,547,551,553,556,558,560,562,565,567,569,573,577,580,584,587,590,594,597,600,605,607,611,615,618,622,625,629,632,636,639,642,646,649,653,656,658,661,665,669,673,676,680,682,684,686,689,692,695,698,700,703,707,711,715,717,718,719,721,725,727,730,732,735,738,741,744,747,749,750,752,755,758,761,764,767,771,774,777,781,784,787,790,794,797,800,803,806,810,812,814,817,819,821,823,825,826,828,832,835,838,841,842,843,846,848,850,852,855,858,862,866,869,871,873,875,877,881,882,884,887,890,892,894,896,899,900,902,904,907,908,911,914,916,917,919,923,926,929,931,932,935,939,942,946,949,951,954,956,959,963,967,971,973,975,979,982,985,988,990,992,994,996,999,1001,1004,1007,1010,1012,1014,1016,1019,1021],{"type":240,"name":241,"callback":242,"priority":243,"file":244,"line":245},"action","wpmudev_register_notices","register",10,"extra\\free-dashboard\\classes\\class-handler.php",124,{"type":240,"name":247,"callback":248,"file":244,"line":249},"load-index.php","admin_notice",130,{"type":240,"name":251,"callback":252,"file":244,"line":253},"all_admin_notices","render_admin_notice",204,{"type":240,"name":251,"callback":255,"file":244,"line":256},"render_plugin_notice",217,{"type":240,"name":258,"callback":259,"priority":243,"file":260,"line":261},"wpmudev_notices_after_notice_action","maybe_dismiss_all","extra\\free-dashboard\\classes\\notices\\class-giveaway.php",70,{"type":240,"name":263,"callback":264,"file":265,"line":166},"wpmudev_scheduled_jobs","hub_sync","extra\\hub-connector\\inc\\class-actions.php",{"type":240,"name":267,"callback":268,"file":265,"line":269},"after_switch_theme","set_shutdown_sync",52,{"type":240,"name":271,"callback":268,"file":265,"line":272},"activated_plugin",56,{"type":240,"name":274,"callback":268,"file":265,"line":275},"deactivated_plugin",57,{"type":240,"name":277,"callback":268,"file":265,"line":278},"deleted_plugin",58,{"type":240,"name":280,"callback":268,"file":265,"line":281},"deleted_theme",59,{"type":240,"name":283,"callback":268,"file":265,"line":284},"upgrader_process_complete",60,{"type":240,"name":286,"callback":287,"file":265,"line":288},"shutdown","shutdown_action",63,{"type":290,"name":291,"callback":292,"file":293,"line":294},"filter","admin_body_class","add_body_class","extra\\hub-connector\\inc\\class-admin.php",48,{"type":240,"name":296,"callback":297,"file":293,"line":166},"wpmudev_hub_connector_ui","render",{"type":240,"name":299,"callback":300,"file":293,"line":269},"admin_init","process_auth_callback",{"type":290,"name":302,"callback":303,"file":293,"line":304},"extra_plugin_headers","include_wdp_id_header",54,{"type":290,"name":306,"callback":307,"file":293,"line":308},"wpmudev_hub_connector_localize_vars","closure",639,{"type":240,"name":310,"callback":311,"priority":312,"file":313,"line":284},"init","run_request",999,"extra\\hub-connector\\inc\\class-remote.php",{"type":240,"name":315,"callback":316,"file":317,"line":318},"rest_api_init","register_routes","extra\\hub-connector\\inc\\class-rest.php",37,{"type":290,"name":320,"callback":321,"file":322,"line":323},"upgrader_package_options","filter_overwrite","extra\\hub-connector\\inc\\class-upgrader.php",212,{"type":240,"name":325,"callback":326,"file":327,"line":328},"admin_enqueue_scripts","enqueue_assets","extra\\plugins-cross-sell-page\\app\\submenus\\class-cross-sell.php",113,{"type":290,"name":291,"callback":330,"file":327,"line":331},"admin_body_classes",115,{"type":240,"name":333,"callback":334,"file":327,"line":335},"admin_menu","register_submenu",121,{"type":240,"name":337,"callback":334,"file":327,"line":245},"network_admin_menu",{"type":290,"name":339,"callback":340,"file":327,"line":341},"admin_footer_text","rm_footer_text",144,{"type":290,"name":343,"callback":344,"file":327,"line":345},"update_footer","rm_footer_verion",147,{"type":290,"name":339,"callback":347,"file":327,"line":348},"hide_wp_footer",150,{"type":240,"name":350,"callback":307,"file":327,"line":351},"admin_head",306,{"type":240,"name":325,"callback":307,"priority":312,"file":327,"line":353},688,{"type":240,"name":315,"callback":316,"file":355,"line":356},"extra\\plugins-cross-sell-page\\core\\class-rest-api.php",105,{"type":290,"name":358,"callback":359,"priority":243,"file":360,"line":361},"wpmudev_hub_connector_localize_text_vars","customize_text_vars","framework\\base\\class-controller.php",95,{"type":240,"name":363,"callback":364,"file":365,"line":366},"plugins_loaded","maybe_create_tables","src\\class-actionscheduler-setup.php",31,{"type":240,"name":368,"callback":369,"file":365,"line":370},"wp_initialize_site","create_tables_for_new_site",32,{"type":240,"name":372,"callback":373,"priority":243,"file":365,"line":374},"action_scheduler\u002Fcreated_table","set_autoincrement",67,{"type":240,"name":350,"callback":376,"file":377,"line":378},"add_global_styles","src\\class-admin.php",43,{"type":240,"name":380,"callback":381,"file":377,"line":382},"admin_footer-plugins.php","load_deactivation_survey_modal",46,{"type":290,"name":384,"callback":384,"priority":243,"file":377,"line":385},"plugin_row_meta",65,{"type":240,"name":387,"callback":388,"priority":243,"file":377,"line":134},"wpdef_fixed_scan_issue","after_scan_fix",{"type":240,"name":350,"callback":390,"file":377,"line":391},"retarget_submenu_callout",79,{"type":240,"name":393,"callback":394,"file":377,"line":194},"network_admin_notices","admin_notices",{"type":240,"name":394,"callback":394,"file":377,"line":361},{"type":240,"name":397,"callback":398,"file":399,"line":400},"wp_footer","add_captcha_scripts","src\\component\\class-captcha.php",274,{"type":240,"name":402,"callback":398,"file":399,"line":403},"login_footer",276,{"type":240,"name":405,"callback":406,"priority":243,"file":407,"line":408},"wp_login_failed","process_fail_attempt","src\\component\\class-login-lockout.php",75,{"type":240,"name":405,"callback":410,"priority":243,"file":407,"line":411},"process_fail_attempt_compatibility",77,{"type":290,"name":413,"callback":414,"priority":415,"file":407,"line":416},"authenticate","show_attempt_left",9999,80,{"type":240,"name":418,"callback":419,"file":407,"line":87},"wp_login","clear_login_attempt",{"type":240,"name":421,"callback":422,"priority":243,"file":407,"line":423},"wd_2fa_lockout","two_factor_lockout",82,{"type":290,"name":425,"callback":426,"file":427,"line":428},"smartcrawl_robots_txt_content","add_bot_trap_to_smartcrawl_robots","src\\component\\class-malicious-bot.php",132,{"type":290,"name":430,"callback":431,"file":427,"line":432},"robots_txt","add_rules_to_content",179,{"type":240,"name":286,"callback":434,"file":435,"line":436},"check_and_execute_callbacks","src\\component\\class-network-cron-manager.php",62,{"type":240,"name":310,"callback":438,"priority":439,"file":440,"line":441},"maybe_detect_suspicious_request",1,"src\\component\\class-notfound-lockout.php",49,{"type":240,"name":443,"callback":444,"file":440,"line":445},"template_redirect","process_404_detect_multiple",151,{"type":240,"name":447,"callback":448,"file":449,"line":450},"admin_print_styles-plugins.php","show_plugin_admin_styles","src\\component\\class-scan.php",709,{"type":290,"name":452,"callback":453,"file":454,"line":455},"password_hint","__return_empty_string","src\\component\\class-strong-password.php",231,{"type":290,"name":457,"callback":458,"file":459,"line":460},"wpmu_users_columns","alter_users_table","src\\component\\class-two-fa.php",756,{"type":240,"name":393,"callback":394,"file":459,"line":462},757,{"type":290,"name":464,"callback":465,"priority":243,"file":459,"line":466},"ms_user_row_actions","display_user_actions",758,{"type":290,"name":468,"callback":458,"file":459,"line":469},"manage_users_columns",760,{"type":240,"name":394,"callback":394,"file":459,"line":471},761,{"type":290,"name":473,"callback":465,"priority":243,"file":459,"line":474},"user_row_actions",762,{"type":290,"name":476,"callback":477,"priority":243,"file":459,"line":478},"manage_users_custom_column","alter_user_table_row",764,{"type":290,"name":480,"callback":481,"file":459,"line":482},"ms_shortcode_ajax_login","m2_no_ajax",765,{"type":240,"name":484,"callback":485,"file":486,"line":487},"wpdef_confirm_antibot_toggle_on_hosting","confirm_toggle_on_hosting","src\\component\\ip\\class-antibot-global-firewall.php",102,{"type":240,"name":489,"callback":490,"file":486,"line":491},"wp_loaded","clear_antibot_on_disconnection",103,{"type":240,"name":493,"callback":494,"file":495,"line":496},"send_headers","append_header","src\\component\\security-headers\\class-sh-content-type-options.php",76,{"type":240,"name":493,"callback":494,"file":498,"line":134},"src\\component\\security-headers\\class-sh-feature-policy.php",{"type":240,"name":493,"callback":494,"file":500,"line":501},"src\\component\\security-headers\\class-sh-referrer-policy.php",69,{"type":240,"name":493,"callback":494,"file":503,"line":504},"src\\component\\security-headers\\class-sh-strict-transport.php",242,{"type":240,"name":493,"callback":494,"file":506,"line":194},"src\\component\\security-headers\\class-sh-x-frame.php",{"type":240,"name":493,"callback":494,"file":508,"line":215},"src\\component\\security-headers\\class-sh-xss-protection.php",{"type":290,"name":510,"callback":511,"file":512,"line":513},"xmlrpc_enabled","__return_false","src\\component\\security-tweaks\\class-disable-xml-rpc.php",98,{"type":290,"name":515,"callback":516,"file":512,"line":175},"wp_xmlrpc_server_class","send_forbidden_response",{"type":290,"name":518,"callback":519,"file":512,"line":487},"xmlrpc_methods","__return_empty_array",{"type":290,"name":521,"callback":522,"priority":243,"file":523,"line":524},"auth_cookie_expiration","cookie_duration","src\\component\\security-tweaks\\class-login-duration.php",101,{"type":290,"name":526,"callback":527,"priority":528,"file":529,"line":423},"oembed_response_data","oembed_author_filter",99,"src\\component\\security-tweaks\\class-prevent-enum-users.php",{"type":290,"name":531,"callback":532,"priority":528,"file":529,"line":533},"wp_sitemaps_users_pre_url_list","block_user_url_sitemap",83,{"type":290,"name":535,"callback":536,"priority":528,"file":529,"line":537},"wp_sitemaps_add_provider","block_user_provider_sitemap",84,{"type":290,"name":539,"callback":540,"file":529,"line":541},"rest_authentication_errors","block_rest_api_user_endpoint",85,{"type":290,"name":543,"callback":544,"file":529,"line":186},"redirect_canonical","maybe_block",{"type":240,"name":394,"callback":394,"file":546,"line":87},"src\\component\\two-factor\\providers\\class-backup-codes.php",{"type":240,"name":548,"callback":326,"file":549,"line":550},"defender_enqueue_assets","src\\controller\\class-advanced-tools.php",39,{"type":240,"name":548,"callback":326,"file":552,"line":501},"src\\controller\\class-antibot-global-firewall.php",{"type":240,"name":554,"callback":555,"file":552,"line":408},"wpmudev_hub_connector_first_sync_completed","maybe_hcm_connection_attempt",{"type":240,"name":310,"callback":557,"file":552,"line":513},"sync_state",{"type":240,"name":310,"callback":559,"file":552,"line":175},"handle_expired_membership",{"type":240,"name":310,"callback":561,"file":552,"line":524},"maybe_set_notice_time",{"type":240,"name":548,"callback":326,"file":563,"line":564},"src\\controller\\class-audit-logging.php",74,{"type":240,"name":286,"callback":566,"file":563,"line":87},"cache_audit_logs",{"type":240,"name":548,"callback":326,"file":568,"line":288},"src\\controller\\class-blacklist.php",{"type":240,"name":570,"callback":571,"file":568,"line":572},"wd_blacklist_this_ip","blacklist_an_ip",66,{"type":290,"name":574,"callback":575,"file":576,"line":87},"wp_defender_advanced_tools_data","script_data","src\\controller\\class-captcha.php",{"type":290,"name":578,"callback":578,"priority":243,"file":576,"line":579},"script_loader_tag",87,{"type":290,"name":581,"callback":582,"file":576,"line":583},"cfturnstile_widget_disable","__return_true",109,{"type":290,"name":585,"callback":519,"file":576,"line":586},"easy_cloudflare_turnstile_render_list",110,{"type":290,"name":588,"callback":519,"file":576,"line":589},"easy_cloudflare_turnstile_verify_list",111,{"type":240,"name":591,"callback":592,"file":576,"line":593},"login_enqueue_scripts","remove_duplicate_captcha_scripts",112,{"type":290,"name":413,"callback":595,"priority":415,"file":576,"line":596},"validate_login_captcha",123,{"type":240,"name":598,"callback":599,"file":576,"line":245},"login_form","display_login_captcha",{"type":290,"name":601,"callback":602,"priority":603,"file":576,"line":604},"wp_authenticate_user","validate_captcha_field_on_login",8,125,{"type":240,"name":606,"callback":599,"file":576,"line":249},"register_form",{"type":290,"name":608,"callback":609,"priority":243,"file":576,"line":610},"registration_errors","validate_captcha_field_on_registration",131,{"type":240,"name":612,"callback":613,"file":576,"line":614},"signup_extra_fields","display_signup_captcha",140,{"type":240,"name":616,"callback":613,"file":576,"line":617},"signup_blogform",141,{"type":290,"name":619,"callback":620,"priority":243,"file":576,"line":621},"wpmu_validate_user_signup","validate_captcha_field_on_wpmu_registration",142,{"type":240,"name":623,"callback":599,"file":576,"line":624},"lostpassword_form",154,{"type":240,"name":626,"callback":627,"file":576,"line":628},"lostpassword_post","validate_captcha_field_on_lostpassword",156,{"type":290,"name":630,"callback":630,"priority":243,"file":576,"line":631},"comment_form_defaults",162,{"type":240,"name":633,"callback":634,"file":576,"line":635},"pre_comment_on_post","validate_captcha_field_on_comment",163,{"type":240,"name":397,"callback":637,"file":576,"line":638},"add_scripts_for_lazy_load",166,{"type":240,"name":640,"callback":599,"file":576,"line":641},"woocommerce_login_form",175,{"type":290,"name":643,"callback":644,"priority":243,"file":576,"line":645},"woocommerce_process_login_errors","validate_captcha_field_on_woo_login",176,{"type":240,"name":647,"callback":599,"file":576,"line":648},"woocommerce_register_form",187,{"type":290,"name":650,"callback":651,"priority":243,"file":576,"line":652},"woocommerce_registration_errors","validate_captcha_field_on_woo_registration",188,{"type":240,"name":654,"callback":599,"file":576,"line":655},"woocommerce_lostpassword_form",199,{"type":240,"name":626,"callback":627,"file":576,"line":657},203,{"type":240,"name":659,"callback":599,"file":576,"line":660},"woocommerce_after_checkout_billing_form",214,{"type":240,"name":662,"callback":663,"priority":243,"file":576,"line":664},"woocommerce_after_checkout_validation","validate_captcha_field_on_woo_checkout",221,{"type":240,"name":666,"callback":667,"file":576,"line":668},"bp_before_registration_submit_buttons","display_buddypress_recaptcha",237,{"type":240,"name":670,"callback":671,"priority":243,"file":576,"line":672},"bp_signup_validate","validate_captcha_field_on_buddypress_registration",244,{"type":240,"name":674,"callback":599,"file":576,"line":675},"bp_after_group_details_creation_step",255,{"type":240,"name":677,"callback":678,"file":576,"line":679},"groups_group_before_save","validate_captcha_field_on_buddypress_group",256,{"type":240,"name":548,"callback":326,"file":681,"line":294},"src\\controller\\class-dashboard.php",{"type":290,"name":683,"callback":582,"file":681,"line":441},"custom_menu_order",{"type":290,"name":685,"callback":685,"file":681,"line":166},"menu_order",{"type":240,"name":299,"callback":687,"priority":528,"file":681,"line":688},"maybe_redirect_notification_request",51,{"type":240,"name":548,"callback":326,"file":690,"line":691},"src\\controller\\class-expert-services.php",38,{"type":240,"name":310,"callback":693,"file":694,"line":378},"load_crawlers","src\\controller\\class-fake-bot-detection.php",{"type":240,"name":310,"callback":696,"file":694,"line":697},"validate_legit_crawler",44,{"type":240,"name":548,"callback":326,"file":699,"line":564},"src\\controller\\class-firewall-logs.php",{"type":290,"name":701,"callback":702,"priority":243,"file":699,"line":194},"http_response","akismet_http_response",{"type":240,"name":548,"callback":326,"priority":704,"file":705,"line":706},11,"src\\controller\\class-firewall.php",173,{"type":240,"name":708,"callback":709,"file":705,"line":710},"admin_print_scripts","print_emoji_script",174,{"type":290,"name":712,"callback":713,"file":705,"line":714},"upload_mimes","extend_mime_types",1109,{"type":240,"name":548,"callback":326,"file":716,"line":436},"src\\controller\\class-global-ip.php",{"type":240,"name":570,"callback":571,"file":716,"line":87},{"type":240,"name":310,"callback":559,"file":716,"line":533},{"type":240,"name":299,"callback":555,"file":720,"line":550},"src\\controller\\class-hub-connector.php",{"type":290,"name":722,"callback":723,"file":724,"line":275},"wdp_register_hub_action","add_hub_endpoint","src\\controller\\class-hub.php",{"type":240,"name":726,"callback":264,"file":724,"line":278},"defender_hub_sync",{"type":240,"name":548,"callback":326,"file":728,"line":729},"src\\controller\\class-login-lockout.php",53,{"type":240,"name":548,"callback":326,"file":731,"line":416},"src\\controller\\class-main-setting.php",{"type":240,"name":733,"callback":734,"priority":243,"file":731,"line":361},"wd_settings_update","intercept_settings_update",{"type":240,"name":310,"callback":310,"file":736,"line":737},"src\\controller\\class-malicious-bot.php",42,{"type":240,"name":739,"callback":740,"file":736,"line":378},"wpdef_rotate_malicious_bot_secret_hash","rotate_hash",{"type":290,"name":742,"callback":743,"file":736,"line":697},"query_vars","add_query_var",{"type":240,"name":267,"callback":745,"file":736,"line":746},"flush_rewrite",45,{"type":240,"name":397,"callback":748,"file":736,"line":166},"inject_footer",{"type":240,"name":402,"callback":748,"file":736,"line":688},{"type":240,"name":443,"callback":751,"file":736,"line":269},"handle_hash_url",{"type":290,"name":574,"callback":575,"file":753,"line":754},"src\\controller\\class-mask-login.php",61,{"type":290,"name":756,"callback":757,"priority":243,"file":753,"line":155},"wp_redirect","filter_wp_redirect",{"type":290,"name":759,"callback":760,"priority":175,"file":753,"line":132},"site_url","filter_site_url",{"type":290,"name":762,"callback":760,"priority":175,"file":753,"line":763},"network_site_url",92,{"type":290,"name":765,"callback":766,"priority":243,"file":753,"line":13},"update_welcome_email","update_welcome_email_prosite_case",{"type":290,"name":768,"callback":769,"priority":243,"file":753,"line":770},"lostpassword_redirect","change_lostpassword_redirect",97,{"type":290,"name":772,"callback":773,"priority":243,"file":753,"line":528},"report_email_logs_link","update_report_logs_link",{"type":290,"name":775,"callback":776,"priority":243,"file":753,"line":524},"bbp_redirect_login","make_sure_wpadmin_after_login",{"type":240,"name":778,"callback":779,"file":753,"line":780},"login_form_rp","handle_password_reset",106,{"type":240,"name":782,"callback":779,"file":753,"line":783},"login_form_resetpass",107,{"type":290,"name":785,"callback":786,"priority":243,"file":753,"line":583},"retrieve_password_message","flywheel_change_password_message",{"type":290,"name":788,"callback":789,"priority":243,"file":753,"line":331},"admin_url","change_subsites_admin_url",{"type":290,"name":791,"callback":792,"priority":243,"file":753,"line":793},"myblogs_blog_actions","update_myblogs_blog_actions",119,{"type":240,"name":795,"callback":796,"priority":175,"file":753,"line":596},"admin_bar_menu","update_admin_bar_menu",{"type":240,"name":310,"callback":798,"file":753,"line":799},"set_locale",127,{"type":240,"name":310,"callback":801,"priority":528,"file":753,"line":802},"handle_login_request",133,{"type":290,"name":804,"callback":307,"file":753,"line":805},"allowed_redirect_hosts",501,{"type":290,"name":807,"callback":808,"priority":243,"file":753,"line":809},"posts_where","posts_where_title",982,{"type":240,"name":548,"callback":326,"file":811,"line":729},"src\\controller\\class-nf-lockout.php",{"type":240,"name":548,"callback":326,"file":813,"line":501},"src\\controller\\class-notification.php",{"type":240,"name":815,"callback":816,"priority":243,"file":813,"line":408},"defender_notify","send_notify",{"type":240,"name":394,"callback":818,"file":813,"line":155},"show_actions_with_subscription",{"type":240,"name":548,"callback":326,"file":820,"line":754},"src\\controller\\class-onboard.php",{"type":290,"name":291,"callback":291,"file":820,"line":822},318,{"type":290,"name":574,"callback":575,"file":824,"line":729},"src\\controller\\class-password-protection.php",{"type":290,"name":762,"callback":760,"priority":175,"file":824,"line":754},{"type":290,"name":601,"callback":827,"priority":175,"file":824,"line":288},"handle_login_password",{"type":240,"name":829,"callback":830,"priority":175,"file":824,"line":831},"validate_password_reset","handle_reset_check_password",64,{"type":240,"name":833,"callback":834,"priority":439,"file":824,"line":385},"user_profile_update_errors","handle_profile_update_password",{"type":290,"name":836,"callback":837,"file":824,"line":374},"woocommerce_reset_password_message","add_woocommerce_error_message",{"type":290,"name":574,"callback":575,"file":839,"line":840},"src\\controller\\class-password-reset.php",55,{"type":290,"name":762,"callback":760,"priority":175,"file":839,"line":288},{"type":240,"name":829,"callback":830,"priority":243,"file":839,"line":385},{"type":240,"name":844,"callback":845,"priority":243,"file":839,"line":572},"profile_update","handle_update_user",{"type":240,"name":847,"callback":779,"priority":243,"file":839,"line":374},"password_reset",{"type":290,"name":601,"callback":827,"priority":312,"file":839,"line":849},68,{"type":240,"name":548,"callback":326,"file":851,"line":13},"src\\controller\\class-scan.php",{"type":240,"name":853,"callback":854,"file":851,"line":528},"defender\u002Fasync_scan","process",{"type":240,"name":856,"callback":857,"file":851,"line":524},"_core_updated_successfully","clean_up_data",{"type":290,"name":859,"callback":860,"priority":243,"file":851,"line":861},"heartbeat_nopriv_send","nopriv_heartbeat",126,{"type":240,"name":863,"callback":864,"file":851,"line":865},"action_scheduler_completed_action","scan_completed_analytics",128,{"type":290,"name":574,"callback":575,"file":867,"line":868},"src\\controller\\class-security-headers.php",33,{"type":240,"name":548,"callback":326,"file":870,"line":770},"src\\controller\\class-security-tweaks.php",{"type":240,"name":489,"callback":872,"file":870,"line":513},"should_output_error",{"type":290,"name":574,"callback":575,"file":874,"line":378},"src\\controller\\class-session-protection.php",{"type":240,"name":310,"callback":876,"file":874,"line":382},"handle_session_timeout",{"type":240,"name":878,"callback":879,"file":874,"line":880},"wp_enqueue_scripts","enqueue_idle_scripts",47,{"type":240,"name":325,"callback":879,"file":874,"line":294},{"type":240,"name":418,"callback":883,"file":874,"line":166},"update_last_activity",{"type":290,"name":885,"callback":886,"file":874,"line":729},"wp_login_errors","login_modal_message",{"type":240,"name":888,"callback":889,"file":874,"line":304},"login_head","login_modal_message_styles",{"type":290,"name":891,"callback":891,"file":874,"line":278},"attach_session_information",{"type":290,"name":574,"callback":575,"file":893,"line":281},"src\\controller\\class-strong-password.php",{"type":240,"name":325,"callback":895,"file":893,"line":411},"scripts",{"type":240,"name":833,"callback":897,"priority":175,"file":893,"line":898},"on_profile_update",78,{"type":240,"name":591,"callback":895,"file":893,"line":423},{"type":240,"name":829,"callback":901,"priority":175,"file":893,"line":533},"on_password_reset",{"type":240,"name":601,"callback":903,"priority":175,"file":893,"line":537},"during_core_authentication",{"type":290,"name":905,"callback":906,"priority":243,"file":893,"line":541},"random_password","generate_password",{"type":240,"name":878,"callback":895,"file":893,"line":763},{"type":240,"name":909,"callback":910,"priority":175,"file":893,"line":194},"woocommerce_save_account_details_errors","on_woo_account_update",{"type":290,"name":912,"callback":913,"priority":175,"file":893,"line":487},"woocommerce_process_registration_errors","during_woo_registration",{"type":290,"name":643,"callback":915,"priority":175,"file":893,"line":586},"during_woo_authentication",{"type":290,"name":836,"callback":837,"file":893,"line":793},{"type":240,"name":548,"callback":326,"file":918,"line":583},"src\\controller\\class-two-factor.php",{"type":240,"name":920,"callback":921,"priority":243,"file":918,"line":922},"update_option_jetpack_active_modules","listen_for_jetpack_option",116,{"type":240,"name":299,"callback":924,"file":918,"line":925},"get_providers",122,{"type":240,"name":927,"callback":928,"file":918,"line":596},"pre_get_users","filter_users_by_2fa",{"type":240,"name":930,"callback":930,"file":918,"line":245},"show_user_profile",{"type":240,"name":844,"callback":844,"file":918,"line":604},{"type":290,"name":413,"callback":933,"priority":934,"file":918,"line":865},"maybe_show_otp_form",30,{"type":240,"name":936,"callback":937,"file":918,"line":938},"set_logged_in_cookie","store_session_key",129,{"type":240,"name":940,"callback":941,"file":918,"line":249},"login_form_defender-verify-otp","verify_otp_login_time",{"type":240,"name":943,"callback":944,"priority":439,"file":918,"line":945},"current_screen","maybe_redirect_to_show_2fa_enabler",146,{"type":240,"name":310,"callback":947,"file":918,"line":948},"wp_defender_2fa_endpoint",161,{"type":290,"name":742,"callback":950,"priority":28,"file":918,"line":631},"wp_defender_2fa_query_vars",{"type":290,"name":952,"callback":953,"file":918,"line":635},"woocommerce_account_menu_items","wp_defender_2fa_link_my_account",{"type":240,"name":443,"callback":955,"file":918,"line":641},"save_2fa_details",{"type":240,"name":957,"callback":958,"file":918,"line":432},"wd_2fa_enabled_provider_slugs","enable_provider_slugs",{"type":290,"name":960,"callback":961,"priority":243,"file":918,"line":962},"woocommerce_prevent_admin_access","handle_woocommerce_prevent_admin_access",1240,{"type":290,"name":964,"callback":965,"priority":243,"file":918,"line":966},"woocommerce_login_redirect","handle_woocommerce_login_redirect",1250,{"type":240,"name":968,"callback":969,"file":918,"line":970},"woocommerce_login_form_end","add_redirect_to_input",1252,{"type":240,"name":548,"callback":326,"file":972,"line":272},"src\\controller\\class-ua-lockout.php",{"type":240,"name":548,"callback":326,"file":974,"line":441},"src\\controller\\class-waf.php",{"type":240,"name":976,"callback":977,"file":978,"line":318},"mainwp_child_site_stats","set_whitelist_dashboard_public_ip","src\\integrations\\class-main-wp.php",{"type":240,"name":299,"callback":307,"file":980,"line":981},"src\\traits\\defender-bootstrap.php",665,{"type":240,"name":983,"callback":307,"file":980,"line":984},"after_setup_theme",692,{"type":290,"name":986,"callback":986,"file":980,"line":987},"cron_schedules",695,{"type":240,"name":310,"callback":307,"priority":130,"file":980,"line":989},702,{"type":240,"name":363,"callback":310,"file":980,"line":991},710,{"type":240,"name":310,"callback":310,"priority":130,"file":980,"line":993},712,{"type":240,"name":299,"callback":310,"file":980,"line":995},714,{"type":240,"name":325,"callback":997,"file":980,"line":998},"init_deactivation_survey",716,{"type":240,"name":310,"callback":310,"priority":528,"file":980,"line":1000},722,{"type":240,"name":274,"callback":1002,"file":980,"line":1003},"intercept_deactivate",724,{"type":240,"name":888,"callback":1005,"priority":156,"file":1006,"line":294},"wp_shake_js","src\\view\\two-fa\\otp.php",{"type":240,"name":1008,"callback":307,"file":1006,"line":1009},"wp_print_footer_scripts",258,{"type":240,"name":1008,"callback":307,"file":1006,"line":1011},416,{"type":240,"name":363,"callback":307,"file":1013,"line":938},"wp-defender.php",{"type":240,"name":310,"callback":1015,"file":1013,"line":624},"run",{"type":240,"name":325,"callback":1017,"file":1013,"line":1018},"register_assets",155,{"type":290,"name":291,"callback":1020,"priority":528,"file":1013,"line":628},"add_sui_to_body",{"type":240,"name":1022,"callback":307,"file":1013,"line":631},"before_woocommerce_init",[1024,1029,1033,1037,1040,1042,1043,1046,1050,1053,1056,1059,1062,1063,1066,1067,1068,1069,1070,1071],{"action":1025,"nopriv":1026,"callback":1027,"hasNonce":1028,"hasCapCheck":1026,"file":244,"line":799},"wpmudev_notices_action",false,"process_action",true,{"action":1030,"nopriv":1026,"callback":1031,"hasNonce":1028,"hasCapCheck":1028,"file":377,"line":1032},"defender_ip_detection_notice_dismiss","dismiss_notice",40,{"action":1034,"nopriv":1026,"callback":1035,"hasNonce":1028,"hasCapCheck":1028,"file":377,"line":1036},"defender_ip_detection_switch_to_xff","switch_to_xff",41,{"action":1038,"nopriv":1026,"callback":1039,"hasNonce":1028,"hasCapCheck":1028,"file":377,"line":737},"defender_track_deactivate","track_deactivate",{"action":1041,"nopriv":1026,"callback":854,"hasNonce":1026,"hasCapCheck":1026,"file":851,"line":770},"defender_process_scan",{"action":1041,"nopriv":1028,"callback":854,"hasNonce":1026,"hasCapCheck":1026,"file":851,"line":513},{"action":1044,"nopriv":1026,"callback":1045,"hasNonce":1026,"hasCapCheck":1026,"file":874,"line":441},"wpdef_logout","logout",{"action":1047,"nopriv":1026,"callback":1048,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":304},"defender_webauthn_create_challenge","create_challenge","src\\controller\\class-webauthn.php",{"action":1051,"nopriv":1026,"callback":1052,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":840},"defender_webauthn_verify_challenge","verify_challenge",{"action":1054,"nopriv":1026,"callback":1055,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":275},"defender_webauthn_remove_authenticator","remove_authenticator",{"action":1057,"nopriv":1026,"callback":1058,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":281},"defender_webauthn_rename_authenticator","rename_authenticator",{"action":1060,"nopriv":1026,"callback":1061,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":754},"defender_webauthn_get_option","get_credential_request_option",{"action":1060,"nopriv":1028,"callback":1061,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":436},{"action":1064,"nopriv":1026,"callback":1065,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":501},"defender_webauthn_verify_response","verify_response",{"action":1064,"nopriv":1028,"callback":1065,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":261},{"action":1047,"nopriv":1028,"callback":1048,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":134},{"action":1051,"nopriv":1028,"callback":1052,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":564},{"action":1054,"nopriv":1028,"callback":1055,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":408},{"action":1057,"nopriv":1028,"callback":1058,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":423},{"action":1072,"nopriv":1026,"callback":1073,"hasNonce":1026,"hasCapCheck":1026,"file":1049,"line":763},"defender_webauthn_disable_user_handle_match_failed_notice","disable_user_handle_match_failed_notice",[],[1076],{"tag":1077,"callback":1078,"file":918,"line":706},"wp_defender_2fa_user_settings","display_2fa_user_settings",[1080,1082,1084,1086,1089],{"hook":726,"callback":726,"file":1081,"line":175},"src\\class-central.php",{"hook":726,"callback":726,"file":1083,"line":249},"src\\class-controller.php",{"hook":484,"callback":484,"file":486,"line":1085},502,{"hook":1087,"callback":1087,"file":980,"line":1088},"wpdef_smart_ip_detection_ping",170,{"hook":726,"callback":726,"file":1090,"line":1091},"src\\traits\\defender-hub-client.php",775,21,16,{"dangerousFunctions":1095,"sqlUsage":1096,"outputEscaping":1167,"fileOperations":934,"externalRequests":195,"nonceChecks":156,"capabilityChecks":1642,"bundledLibraries":1643},[],{"prepared":1097,"raw":868,"locations":1098},104,[1099,1103,1106,1108,1110,1114,1116,1118,1120,1122,1124,1126,1128,1130,1132,1134,1136,1138,1140,1142,1144,1147,1150,1153,1155,1156,1158,1160,1162,1163,1164,1165,1166],{"file":1100,"line":1101,"context":1102},"extra\\plugins-cross-sell-page\\core\\class-utilities.php",193,"$wpdb->query() with variable interpolation",{"file":1104,"line":1105,"context":1102},"extra\\wpmudev-analytics\\core\\class-wpmudev-analytics-v4.php",160,{"file":1104,"line":1107,"context":1102},165,{"file":1104,"line":645,"context":1109},"$wpdb->get_var() with variable interpolation",{"file":1111,"line":1112,"context":1113},"src\\class-upgrader.php",527,"$wpdb->get_row() with variable interpolation",{"file":1111,"line":1115,"context":1102},532,{"file":1111,"line":1117,"context":1113},545,{"file":1111,"line":1119,"context":1102},550,{"file":1111,"line":1121,"context":1113},563,{"file":1111,"line":1123,"context":1102},568,{"file":1111,"line":1125,"context":1113},581,{"file":1111,"line":1127,"context":1102},586,{"file":1111,"line":1129,"context":1113},599,{"file":1111,"line":1131,"context":1102},604,{"file":1111,"line":1133,"context":1102},1036,{"file":1111,"line":1135,"context":1102},1556,{"file":1111,"line":1137,"context":1102},1558,{"file":1111,"line":1139,"context":1102},1560,{"file":1111,"line":1141,"context":1102},1852,{"file":1111,"line":1143,"context":1102},1856,{"file":1145,"line":1146,"context":1109},"src\\model\\class-onboard.php",25,{"file":1148,"line":934,"context":1149},"src\\model\\class-spam-comment.php","$wpdb->get_results() with variable interpolation",{"file":1151,"line":1152,"context":1102},"uninstall.php",19,{"file":1151,"line":1154,"context":1102},20,{"file":1151,"line":1092,"context":1102},{"file":1151,"line":1157,"context":1102},22,{"file":1151,"line":1159,"context":1102},23,{"file":1151,"line":1161,"context":1102},24,{"file":1151,"line":1146,"context":1102},{"file":1151,"line":195,"context":1102},{"file":1151,"line":76,"context":1102},{"file":1151,"line":691,"context":1149},{"file":1151,"line":294,"context":1102},{"escaped":1168,"rawEcho":1169,"locations":1170},435,240,[1171,1174,1176,1178,1180,1183,1184,1186,1188,1189,1192,1194,1196,1198,1199,1200,1202,1204,1206,1209,1211,1213,1214,1216,1218,1220,1221,1223,1225,1227,1229,1231,1233,1235,1237,1240,1242,1244,1246,1247,1249,1251,1253,1255,1256,1257,1259,1261,1263,1265,1267,1269,1270,1271,1273,1275,1277,1279,1281,1283,1285,1287,1289,1291,1293,1295,1297,1299,1301,1303,1305,1307,1309,1311,1313,1315,1317,1319,1321,1323,1325,1327,1329,1331,1333,1335,1337,1339,1341,1343,1345,1347,1349,1351,1353,1355,1357,1359,1361,1363,1365,1367,1369,1371,1373,1375,1377,1379,1381,1384,1386,1388,1390,1392,1394,1396,1398,1399,1401,1403,1405,1407,1409,1411,1413,1415,1417,1419,1421,1423,1425,1427,1429,1431,1433,1435,1437,1439,1441,1443,1445,1447,1449,1451,1453,1455,1457,1459,1461,1463,1465,1467,1469,1471,1472,1474,1476,1478,1480,1482,1484,1486,1488,1490,1492,1494,1496,1498,1500,1502,1504,1506,1508,1509,1511,1513,1515,1517,1519,1521,1523,1525,1527,1529,1531,1533,1535,1537,1539,1541,1543,1545,1547,1549,1551,1553,1555,1557,1559,1561,1563,1565,1567,1569,1571,1573,1575,1577,1579,1581,1583,1585,1587,1589,1591,1593,1595,1598,1601,1603,1605,1606,1607,1609,1611,1613,1615,1617,1619,1621,1623,1625,1627,1628,1630,1632,1633,1635,1637,1639],{"file":360,"line":1172,"context":1173},189,"raw output",{"file":377,"line":1175,"context":1173},467,{"file":377,"line":1177,"context":1173},483,{"file":377,"line":1179,"context":1173},584,{"file":1181,"line":1182,"context":1173},"src\\component\\class-cli.php",455,{"file":546,"line":1018,"context":1173},{"file":546,"line":1185,"context":1173},157,{"file":1187,"line":596,"context":1173},"src\\component\\two-factor\\providers\\class-fallback-email.php",{"file":1187,"line":861,"context":1173},{"file":1190,"line":1191,"context":1173},"src\\component\\two-factor\\providers\\class-totp.php",169,{"file":1193,"line":1107,"context":1173},"src\\component\\two-factor\\providers\\class-webauthn.php",{"file":705,"line":1195,"context":1173},693,{"file":731,"line":1197,"context":1173},557,{"file":813,"line":802,"context":1173},{"file":870,"line":922,"context":1173},{"file":918,"line":1201,"context":1173},1298,{"file":918,"line":1203,"context":1173},1344,{"file":918,"line":1205,"context":1173},1401,{"file":1207,"line":1208,"context":1173},"src\\extra\\php-codesniffer-php-token\\Config.php",1254,{"file":1207,"line":1210,"context":1173},1572,{"file":1212,"line":278,"context":1173},"src\\extra\\php-codesniffer-php-token\\Tokenizers\\Comment.php",{"file":1212,"line":524,"context":1173},{"file":1212,"line":1215,"context":1173},137,{"file":1212,"line":1217,"context":1173},152,{"file":1219,"line":491,"context":1173},"src\\extra\\php-codesniffer-php-token\\Tokenizers\\CSS.php",{"file":1219,"line":861,"context":1173},{"file":1219,"line":1222,"context":1173},285,{"file":1219,"line":1224,"context":1173},339,{"file":1219,"line":1226,"context":1173},356,{"file":1219,"line":1228,"context":1173},377,{"file":1219,"line":1230,"context":1173},412,{"file":1219,"line":1232,"context":1173},428,{"file":1219,"line":1234,"context":1173},447,{"file":1219,"line":1236,"context":1173},462,{"file":1238,"line":1239,"context":1173},"src\\extra\\php-codesniffer-php-token\\Tokenizers\\JS.php",326,{"file":1238,"line":1241,"context":1173},341,{"file":1238,"line":1243,"context":1173},362,{"file":1238,"line":1245,"context":1173},395,{"file":1238,"line":1182,"context":1173},{"file":1238,"line":1248,"context":1173},481,{"file":1238,"line":1250,"context":1173},494,{"file":1238,"line":1252,"context":1173},513,{"file":1238,"line":1254,"context":1173},544,{"file":1238,"line":1121,"context":1173},{"file":1238,"line":1123,"context":1173},{"file":1238,"line":1258,"context":1173},585,{"file":1238,"line":1260,"context":1173},593,{"file":1238,"line":1262,"context":1173},612,{"file":1238,"line":1264,"context":1173},633,{"file":1238,"line":1266,"context":1173},649,{"file":1238,"line":1268,"context":1173},687,{"file":1238,"line":993,"context":1173},{"file":1238,"line":1003,"context":1173},{"file":1238,"line":1272,"context":1173},1001,{"file":1238,"line":1274,"context":1173},1061,{"file":1238,"line":1276,"context":1173},1062,{"file":1238,"line":1278,"context":1173},1078,{"file":1238,"line":1280,"context":1173},1079,{"file":1238,"line":1282,"context":1173},1090,{"file":1238,"line":1284,"context":1173},1091,{"file":1238,"line":1286,"context":1173},1125,{"file":1238,"line":1288,"context":1173},1126,{"file":1238,"line":1290,"context":1173},1151,{"file":1238,"line":1292,"context":1173},1152,{"file":1238,"line":1294,"context":1173},1170,{"file":1238,"line":1296,"context":1173},1171,{"file":1238,"line":1298,"context":1173},1172,{"file":1238,"line":1300,"context":1173},1173,{"file":1238,"line":1302,"context":1173},1181,{"file":1238,"line":1304,"context":1173},1182,{"file":1238,"line":1306,"context":1173},1201,{"file":1238,"line":1308,"context":1173},1202,{"file":1238,"line":1310,"context":1173},1229,{"file":1238,"line":1312,"context":1173},1230,{"file":1238,"line":1314,"context":1173},1237,{"file":1238,"line":1316,"context":1173},1238,{"file":1318,"line":805,"context":1173},"src\\extra\\php-codesniffer-php-token\\Tokenizers\\PHP.php",{"file":1318,"line":1320,"context":1173},503,{"file":1318,"line":1322,"context":1173},506,{"file":1318,"line":1324,"context":1173},718,{"file":1318,"line":1326,"context":1173},796,{"file":1318,"line":1328,"context":1173},830,{"file":1318,"line":1330,"context":1173},1099,{"file":1318,"line":1332,"context":1173},1147,{"file":1318,"line":1334,"context":1173},1162,{"file":1318,"line":1336,"context":1173},1177,{"file":1318,"line":1338,"context":1173},1337,{"file":1318,"line":1340,"context":1173},1356,{"file":1318,"line":1342,"context":1173},1423,{"file":1318,"line":1344,"context":1173},1424,{"file":1318,"line":1346,"context":1173},1732,{"file":1318,"line":1348,"context":1173},1743,{"file":1318,"line":1350,"context":1173},1770,{"file":1318,"line":1352,"context":1173},1786,{"file":1318,"line":1354,"context":1173},1798,{"file":1318,"line":1356,"context":1173},1891,{"file":1318,"line":1358,"context":1173},1920,{"file":1318,"line":1360,"context":1173},1970,{"file":1318,"line":1362,"context":1173},1972,{"file":1318,"line":1364,"context":1173},1990,{"file":1318,"line":1366,"context":1173},2015,{"file":1318,"line":1368,"context":1173},2034,{"file":1318,"line":1370,"context":1173},2075,{"file":1318,"line":1372,"context":1173},2104,{"file":1318,"line":1374,"context":1173},2108,{"file":1318,"line":1376,"context":1173},2138,{"file":1318,"line":1378,"context":1173},2174,{"file":1318,"line":1380,"context":1173},2175,{"file":1382,"line":1383,"context":1173},"src\\extra\\php-codesniffer-php-token\\Tokenizers\\Tokenizer.php",689,{"file":1382,"line":1385,"context":1173},690,{"file":1382,"line":1387,"context":1173},697,{"file":1382,"line":1389,"context":1173},698,{"file":1382,"line":1391,"context":1173},705,{"file":1382,"line":1393,"context":1173},706,{"file":1382,"line":1395,"context":1173},720,{"file":1382,"line":1397,"context":1173},721,{"file":1382,"line":1003,"context":1173},{"file":1382,"line":1400,"context":1173},725,{"file":1382,"line":1402,"context":1173},743,{"file":1382,"line":1404,"context":1173},744,{"file":1382,"line":1406,"context":1173},745,{"file":1382,"line":1408,"context":1173},753,{"file":1382,"line":1410,"context":1173},754,{"file":1382,"line":1412,"context":1173},755,{"file":1382,"line":1414,"context":1173},768,{"file":1382,"line":1416,"context":1173},769,{"file":1382,"line":1418,"context":1173},770,{"file":1382,"line":1420,"context":1173},785,{"file":1382,"line":1422,"context":1173},786,{"file":1382,"line":1424,"context":1173},787,{"file":1382,"line":1426,"context":1173},863,{"file":1382,"line":1428,"context":1173},898,{"file":1382,"line":1430,"context":1173},899,{"file":1382,"line":1432,"context":1173},925,{"file":1382,"line":1434,"context":1173},926,{"file":1382,"line":1436,"context":1173},928,{"file":1382,"line":1438,"context":1173},932,{"file":1382,"line":1440,"context":1173},935,{"file":1382,"line":1442,"context":1173},951,{"file":1382,"line":1444,"context":1173},958,{"file":1382,"line":1446,"context":1173},975,{"file":1382,"line":1448,"context":1173},976,{"file":1382,"line":1450,"context":1173},991,{"file":1382,"line":1452,"context":1173},1005,{"file":1382,"line":1454,"context":1173},1006,{"file":1382,"line":1456,"context":1173},1018,{"file":1382,"line":1458,"context":1173},1019,{"file":1382,"line":1460,"context":1173},1028,{"file":1382,"line":1462,"context":1173},1037,{"file":1382,"line":1464,"context":1173},1043,{"file":1382,"line":1466,"context":1173},1046,{"file":1382,"line":1468,"context":1173},1049,{"file":1382,"line":1470,"context":1173},1108,{"file":1382,"line":714,"context":1173},{"file":1382,"line":1473,"context":1173},1115,{"file":1382,"line":1475,"context":1173},1132,{"file":1382,"line":1477,"context":1173},1133,{"file":1382,"line":1479,"context":1173},1139,{"file":1382,"line":1481,"context":1173},1155,{"file":1382,"line":1483,"context":1173},1156,{"file":1382,"line":1485,"context":1173},1180,{"file":1382,"line":1487,"context":1173},1189,{"file":1382,"line":1489,"context":1173},1208,{"file":1382,"line":1491,"context":1173},1215,{"file":1382,"line":1493,"context":1173},1228,{"file":1382,"line":1495,"context":1173},1265,{"file":1382,"line":1497,"context":1173},1291,{"file":1382,"line":1499,"context":1173},1308,{"file":1382,"line":1501,"context":1173},1309,{"file":1382,"line":1503,"context":1173},1323,{"file":1382,"line":1505,"context":1173},1324,{"file":1382,"line":1507,"context":1173},1348,{"file":1382,"line":1340,"context":1173},{"file":1382,"line":1510,"context":1173},1376,{"file":1382,"line":1512,"context":1173},1377,{"file":1382,"line":1514,"context":1173},1382,{"file":1382,"line":1516,"context":1173},1383,{"file":1382,"line":1518,"context":1173},1397,{"file":1382,"line":1520,"context":1173},1409,{"file":1382,"line":1522,"context":1173},1410,{"file":1382,"line":1524,"context":1173},1460,{"file":1382,"line":1526,"context":1173},1461,{"file":1382,"line":1528,"context":1173},1468,{"file":1382,"line":1530,"context":1173},1471,{"file":1382,"line":1532,"context":1173},1483,{"file":1382,"line":1534,"context":1173},1484,{"file":1382,"line":1536,"context":1173},1513,{"file":1382,"line":1538,"context":1173},1514,{"file":1382,"line":1540,"context":1173},1539,{"file":1382,"line":1542,"context":1173},1540,{"file":1382,"line":1544,"context":1173},1541,{"file":1382,"line":1546,"context":1173},1542,{"file":1382,"line":1548,"context":1173},1543,{"file":1382,"line":1550,"context":1173},1544,{"file":1382,"line":1552,"context":1173},1551,{"file":1382,"line":1554,"context":1173},1552,{"file":1382,"line":1556,"context":1173},1559,{"file":1382,"line":1558,"context":1173},1567,{"file":1382,"line":1560,"context":1173},1574,{"file":1382,"line":1562,"context":1173},1575,{"file":1382,"line":1564,"context":1173},1595,{"file":1382,"line":1566,"context":1173},1596,{"file":1382,"line":1568,"context":1173},1601,{"file":1382,"line":1570,"context":1173},1602,{"file":1382,"line":1572,"context":1173},1615,{"file":1382,"line":1574,"context":1173},1616,{"file":1382,"line":1576,"context":1173},1641,{"file":1382,"line":1578,"context":1173},1642,{"file":1382,"line":1580,"context":1173},1643,{"file":1382,"line":1582,"context":1173},1644,{"file":1382,"line":1584,"context":1173},1645,{"file":1382,"line":1586,"context":1173},1646,{"file":1382,"line":1588,"context":1173},1654,{"file":1590,"line":822,"context":1173},"src\\extra\\php-codesniffer-php-token\\Util\\Standards.php",{"file":1590,"line":1592,"context":1173},322,{"file":1594,"line":496,"context":1173},"src\\extra\\php-codesniffer-php-token\\Util\\Timing.php",{"file":1596,"line":1597,"context":1173},"src\\functions.php",36,{"file":1599,"line":1600,"context":1173},"src\\view\\email\\2fa-lost-phone.php",29,{"file":1602,"line":156,"context":1173},"src\\view\\email\\tweak-issue.php",{"file":1604,"line":408,"context":1173},"src\\view\\ip-lockout\\locked.php",{"file":1604,"line":87,"context":1173},{"file":1604,"line":945,"context":1173},{"file":1604,"line":1608,"context":1173},230,{"file":1604,"line":1610,"context":1173},241,{"file":1604,"line":1612,"context":1173},423,{"file":1604,"line":1614,"context":1173},433,{"file":1604,"line":1616,"context":1173},477,{"file":1604,"line":1618,"context":1173},478,{"file":1604,"line":1620,"context":1173},479,{"file":1604,"line":1622,"context":1173},497,{"file":1604,"line":1624,"context":1173},537,{"file":1626,"line":378,"context":1173},"src\\view\\mask-login\\reset.php",{"file":1626,"line":528,"context":1173},{"file":1006,"line":1629,"context":1173},266,{"file":1006,"line":1631,"context":1173},315,{"file":1006,"line":1239,"context":1173},{"file":1006,"line":1634,"context":1173},424,{"file":1636,"line":261,"context":1173},"src\\view\\two-fa\\providers\\backup-codes.php",{"file":1638,"line":925,"context":1173},"src\\view\\two-fa\\providers\\totp-disabled.php",{"file":1640,"line":1641,"context":1173},"src\\view\\two-fa\\providers\\totp-enabled.php",28,15,[1644],{"name":1645,"version":37,"knownCves":1646},"Select2",[],[1648,1666],{"entryPoint":1649,"graph":1650,"unsanitizedCount":28,"severity":1665},"process_action (extra\\free-dashboard\\classes\\class-handler.php:263)",{"nodes":1651,"edges":1663},[1652,1657],{"id":1653,"type":1654,"label":1655,"file":244,"line":1656},"n0","source","$_POST (x3)",275,{"id":1658,"type":1659,"label":1660,"file":244,"line":1661,"wp_function":1662},"n1","sink","call_user_func() [RCE]",298,"call_user_func",[1664],{"from":1653,"to":1658,"sanitized":1028},"low",{"entryPoint":1667,"graph":1668,"unsanitizedCount":28,"severity":1665},"\u003Cclass-handler> (extra\\free-dashboard\\classes\\class-handler.php:0)",{"nodes":1669,"edges":1672},[1670,1671],{"id":1653,"type":1654,"label":1655,"file":244,"line":1656},{"id":1658,"type":1659,"label":1660,"file":244,"line":1661,"wp_function":1662},[1673],{"from":1653,"to":1658,"sanitized":1028},{"summary":1675,"deductions":1676},"The Defender Security plugin (v5.10.0) presents a mixed security posture. While it demonstrates some good practices, such as a majority of SQL queries utilizing prepared statements and a significant number of output escaping checks, there are notable areas of concern.  The plugin has a substantial attack surface, with a large number of AJAX handlers (20 total) and a concerning proportion of these (16) lacking authentication checks. This opens up a significant vector for potential unauthorized actions if these handlers are not properly secured at the WordPress core level. The taint analysis shows no critical or high severity flows, which is a positive sign, but the limited scope of analysis (only 2 flows) might not be exhaustive.\n\nThe vulnerability history is a more significant red flag. With a total of 7 known CVEs, including one high severity and six medium severity vulnerabilities, it indicates a pattern of past security weaknesses. The common vulnerability types, such as Missing Authorization and Exposure of Sensitive Information, directly correlate with the static analysis findings of numerous unprotected AJAX handlers. Although there are no currently unpatched vulnerabilities, the historical trend suggests a need for continued vigilance and robust security practices within the plugin's development lifecycle. The last vulnerability being as recent as June 2024 also points to ongoing security challenges. Overall, while the plugin has some foundational security measures in place, the large unprotected attack surface and its history of significant vulnerabilities necessitate a cautious approach.",[1677,1679,1681,1683,1686,1688],{"reason":1678,"points":603},"Unprotected AJAX handlers",{"reason":1680,"points":27},"High number of past medium vulnerabilities",{"reason":1682,"points":243},"Past high severity vulnerability",{"reason":1684,"points":1685},"Some SQL queries without prepared statements",4,{"reason":1687,"points":47},"Lower percentage of properly escaped outputs",{"reason":1689,"points":62},"Bundled library (Select2) may be outdated","2026-03-16T17:11:11.621Z",{"wat":1692,"direct":1706},{"assetPaths":1693,"generatorPatterns":1699,"scriptPaths":1700,"versionParams":1701},[1694,1695,1696,1697,1698],"\u002Fwp-content\u002Fplugins\u002Fdefender-security\u002Fbuild\u002Fcss\u002Fmain.css","\u002Fwp-content\u002Fplugins\u002Fdefender-security\u002Fbuild\u002Fjs\u002Fmain.js","\u002Fwp-content\u002Fplugins\u002Fdefender-security\u002Fassets\u002Fcss\u002Fmain.css","\u002Fwp-content\u002Fplugins\u002Fdefender-security\u002Fassets\u002Fjs\u002Fmain.js","\u002Fwp-content\u002Fplugins\u002Fdefender-security\u002Fvendor\u002Fincsub\u002Fwp-removable-strings\u002Fassets\u002Fcss\u002Fmain.css",[],[1695,1697],[1702,1703,1704,1705],"defender-security\u002Fbuild\u002Fcss\u002Fmain.css?ver=","defender-security\u002Fbuild\u002Fjs\u002Fmain.js?ver=","defender-security\u002Fassets\u002Fcss\u002Fmain.css?ver=","defender-security\u002Fassets\u002Fjs\u002Fmain.js?ver=",{"cssClasses":1707,"htmlComments":1713,"htmlAttributes":1717,"restEndpoints":1720,"jsGlobals":1722,"shortcodeOutput":1725},[1708,1709,1710,1711,1712],"defender-security-admin","wp-defender-network-admin-bar","sui-box-title","sui-box-body","sui-tab-item",[1714,1715,1716],"\u003C!-- WPMU DEV Defender: Settings -->","\u003C!-- WPMU DEV Defender: Dashboard Widget -->","\u003C!-- WPMU DEV Defender: Scan Results -->",[1718,1719],"data-module=defender-security","data-controller=defender-security",[1721],"\u002Fwp-json\u002Fdefender\u002Fv1\u002F",[1723,1724],"defender_vars","Defender",[]]