[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUVI1nL4u1xOC-JGTmXAUI0vU6I99WAZ9mImoZzzXQRU":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"vulnerabilities":30,"developer":31,"crawl_stats":28,"alternatives":36,"analysis":130,"fingerprints":983},"ip-blocker-lite","IP & Country Blocker Lite","3.0.0","Nurul Islam","https:\u002F\u002Fprofiles.wordpress.org\u002Ffaqnurul\u002F","\u003Cp>IP & Country Blocker Lite is a comprehensive WordPress security plugin that provides multiple layers of protection for your website. Block unwanted visitors based on IP addresses or countries, and add an extra layer of security with two-factor authentication (2FA).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>IP Address Blocking\u003C\u002Fstrong>: Block or allow specific IP addresses, IP ranges, or subnets\u003Cbr \u002F>\n* \u003Cstrong>Country-Based Blocking\u003C\u002Fstrong>: Restrict access based on visitors’ countries\u003Cbr \u002F>\n* \u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong>: Secure admin logins with email-based 2FA or authenticator apps\u003Cbr \u002F>\n* \u003Cstrong>Recovery Codes\u003C\u002Fstrong>: Backup access codes for account recovery\u003Cbr \u002F>\n* \u003Cstrong>Emergency Recovery\u003C\u002Fstrong>: Generate secure recovery URLs to disable the plugin if locked out\u003Cbr \u002F>\n* \u003Cstrong>Advanced Security Dashboard\u003C\u002Fstrong>: Monitor blocked attempts and security events\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Benefits:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Protect against spam, bots, and malicious traffic\u003Cbr \u002F>\n* Prevent brute force attacks on admin login\u003Cbr \u002F>\n* Block entire countries or regions\u003Cbr \u002F>\n* Easy-to-use admin interface with real-time monitoring\u003Cbr \u002F>\n* Lightweight and fast performance\u003Cbr \u002F>\n* No external dependencies for core functionality\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Easy Management:\u003C\u002Fstrong>\u003Cbr \u002F>\n* One-click blocking\u002Funblocking\u003Cbr \u002F>\n* Intuitive admin panel with tabbed interface\u003Cbr \u002F>\n* Real-time activity logs\u003Cbr \u002F>\n* Bulk operations support\u003Cbr \u002F>\n* Custom blocked page templates\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitoring & Analytics:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Track blocked IP attempts\u003Cbr \u002F>\n* View country-wise access statistics\u003Cbr \u002F>\n* Monitor security events\u003Cbr \u002F>\n* Export blocking rules\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy & Compliance:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Uses free IP-API.com service for geolocation\u003Cbr \u002F>\n* No personal data storage\u003Cbr \u002F>\n* GDPR compliant\u003Cbr \u002F>\n* Respects user privacy\u003C\u002Fp>\n\u003Ch3>Data Collection & Privacy\u003C\u002Fh3>\n\u003Cp>For transparency, here’s what data the plugin collects and why:\u003C\u002Fp>\n\u003Ch3>\u003Cstrong>Essential Data Collection (Always Required for Functionality):\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>IP Addresses\u003C\u002Fstrong>: Collected for security blocking and geolocation features\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enable IP\u002Fcountry blocking, security monitoring, and access control\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage\u003C\u002Fstrong>: Temporary (not stored in database, only processed in memory)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Third Parties\u003C\u002Fstrong>: Sent to IP-API.com for country lookup (free service)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Country Information\u003C\u002Fstrong>: Derived from IP addresses via geolocation\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Enable country-based blocking and access statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage\u003C\u002Fstrong>: Not stored permanently (only used for blocking decisions)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Third Parties\u003C\u002Fstrong>: Retrieved from IP-API.com (free geolocation service)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>Optional Data Collection (Only with User Consent):\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Plugin Usage Statistics\u003C\u002Fstrong>: Anonymous plugin performance data\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Improve plugin quality and fix bugs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Collected\u003C\u002Fstrong>: Plugin version, WordPress version, PHP version, activation date\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage\u003C\u002Fstrong>: Remote server (only if user consents)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy\u003C\u002Fstrong>: Completely anonymous, no personal identifiers\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>User Feedback\u003C\u002Fstrong>: Plugin reviews and feedback submissions\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Understand user needs and improve features\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Collected\u003C\u002Fstrong>: Feedback text, rating, plugin version, PHP version\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage\u003C\u002Fstrong>: Remote server (only if user consents)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy\u003C\u002Fstrong>: Anonymous feedback, no personal data required\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: http:\u002F\u002Fcodecanvasbd\u002Fprivacy-policy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>Data Collection Controls:\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Consent Required\u003C\u002Fstrong>: Optional data collection requires explicit user consent\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Easy Opt-out\u003C\u002Fstrong>: Users can decline consent at any time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Automatic Collection\u003C\u002Fstrong>: No data sent without user permission\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Transparent Process\u003C\u002Fstrong>: Clear consent modal explains what data is collected\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>Third-Party Services:\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>IP-API.com\u003C\u002Fstrong>: Free geolocation service for country detection\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Data sent: Visitor IP addresses\u003C\u002Fli>\n\u003Cli>Purpose: Determine visitor country for blocking features\u003C\u002Fli>\n\u003Cli>Privacy: IP-API.com privacy policy applies\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Remote Analytics Server\u003C\u002Fstrong> (optional, consent required):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Data sent: Anonymous usage statistics\u003C\u002Fli>\n\u003Cli>Purpose: Plugin improvement and support\u003C\u002Fli>\n\u003Cli>Privacy: No personal data, fully anonymous\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>GDPR Compliance:\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>✅ No personal data storage without consent\u003C\u002Fli>\n\u003Cli>✅ Clear consent mechanisms\u003C\u002Fli>\n\u003Cli>✅ Easy opt-out options\u003C\u002Fli>\n\u003Cli>✅ Transparent data practices\u003C\u002Fli>\n\u003Cli>✅ Data minimization principles\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Main Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>IP & Country Blocking:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Block specific IP addresses or ranges (CIDR notation supported)\u003Cbr \u002F>\n* Block entire countries or allow only specific countries\u003Cbr \u002F>\n* Whitelist important IPs for access\u003Cbr \u002F>\n* Real-time blocking with immediate effect\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Two-Factor Authentication (2FA):\u003C\u002Fstrong>\u003Cbr \u002F>\n* Email-based 2FA for easy setup\u003Cbr \u002F>\n* Authenticator app support (Google Authenticator, Authy, etc.)\u003Cbr \u002F>\n* Recovery codes for account access\u003Cbr \u002F>\n* Secure code generation and validation\u003Cbr \u002F>\n* Admin email verification\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Emergency Recovery System:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Generate secure recovery URLs to disable plugin if locked out\u003Cbr \u002F>\n* Time-limited recovery hashes (24 hours expiration)\u003Cbr \u002F>\n* One-click plugin deactivation via recovery URL\u003Cbr \u002F>\n* Secure hash verification to prevent unauthorized access\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin Interface:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Modern, responsive dashboard\u003Cbr \u002F>\n* Tabbed navigation for easy access\u003Cbr \u002F>\n* Real-time statistics and charts\u003Cbr \u002F>\n* Activity logs with filtering\u003Cbr \u002F>\n* Bulk operations for efficiency\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Monitoring:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Track blocked access attempts\u003Cbr \u002F>\n* Country-wise visitor statistics\u003Cbr \u002F>\n* Failed login monitoring\u003Cbr \u002F>\n* Security event logging\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Optimized:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Lightweight codebase\u003Cbr \u002F>\n* Minimal database queries\u003Cbr \u002F>\n* Fast IP lookups\u003Cbr \u002F>\n* Caching support\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin uses the IP-API.com service to detect the user’s location based on their IP address.\u003Cbr \u002F>\n– \u003Cstrong>Service\u003C\u002Fstrong>: IP-API.com (http:\u002F\u002Fip-api.com)\u003Cbr \u002F>\n– \u003Cstrong>Purpose\u003C\u002Fstrong>: IP geolocation for country-based blocking\u003Cbr \u002F>\n– \u003Cstrong>Data Sent\u003C\u002Fstrong>: User’s IP address only\u003Cbr \u002F>\n– \u003Cstrong>Privacy Policy\u003C\u002Fstrong>: http:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003Cbr \u002F>\n– \u003Cstrong>Data Storage\u003C\u002Fstrong>: No personal data is stored by this plugin\u003C\u002Fp>\n\u003Cp>The plugin works without this service but country blocking features will be limited.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, bug reports, or feature requests:\u003Cbr \u002F>\n– \u003Cstrong>WordPress.org Support Forum\u003C\u002Fstrong>: https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fip-blocker-lite\u002F\u003Cbr \u002F>\n– \u003Cstrong>GitHub Issues\u003C\u002Fstrong>: Report bugs and request features\u003Cbr \u002F>\n– \u003Cstrong>Email\u003C\u002Fstrong>: Contact through WordPress.org profile\u003C\u002Fp>\n\u003Ch3>Contributing\u003C\u002Fh3>\n\u003Cp>Contributions are welcome! Please feel free to submit pull requests or open issues on GitHub.\u003C\u002Fp>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Developer\u003C\u002Fstrong>: Nurul Islam (faqnurul)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Icons\u003C\u002Fstrong>: Dashicons (WordPress)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geolocation\u003C\u002Fstrong>: IP-API.com (free tier)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Charts\u003C\u002Fstrong>: Chart.js library\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later.\u003Cbr \u002F>\nLicense URI: http:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-2.0.html\u003C\u002Fp>\n\u003Cp>Take control of your website’s security and protect it from unwanted visitors with IP & Country Blocker Lite!\u003C\u002Fp>\n","Advanced WordPress security plugin with IP\u002Fcountry blocking and two-factor authentication for comprehensive website protection.",300,1883,100,1,"2026-01-05T16:17:00.000Z","6.9.4","4.0","7.0",[20,21,22,23,24],"country-blocker","ip-blocker","login-security","two-factor-authentication","website-security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fip-blocker-lite.zip",0,null,"2026-03-15T15:16:48.613Z",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":13,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"faqnurul",30,94,"2026-04-03T21:29:41.429Z",[37,60,80,97,114],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":34,"num_ratings":47,"last_updated":48,"tested_up_to":16,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":55,"download_link":56,"security_score":57,"vuln_count":58,"unpatched_count":27,"last_vuln_date":59,"fetched_at":29},"all-in-one-wp-security-and-firewall","All-In-One Security (AIOS) – Security and Firewall","5.4.6","David Anderson \u002F Team Updraft","https:\u002F\u002Fprofiles.wordpress.org\u002Fdavidanderson\u002F","\u003Ch3>THE TOP RATED WORDPRESS SECURITY AND FIREWALL PLUGIN\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios&utm_creative_format=description\" rel=\"nofollow ugc\">All-in-One Security (AIOS)\u003C\u002Fa> is a WordPress security plugin from the same, trusted team that brought you UpdraftPlus.\u003C\u002Fp>\n\u003Cp>It’s called ‘All-In-One’ because it’s packed full of ways to keep your WordPress website(s) safe and secure.\u003C\u002Fp>\n\u003Cp>It includes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login security features\u003C\u002Fstrong> keep bots at bay. Lock out users based on a configurable number of login attempts, get two-factor authentication and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File and database security.\u003C\u002Fstrong> Get notified of file changes that occur outside of normal operations. Block access to key files and scan files and folders to spot insecure permissions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall.\u003C\u002Fstrong> Get PHP, .htaccess and 6G firewall rules courtesy of Perishable Press. Spot and block fake Google Bots and more!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Spam prevention.\u003C\u002Fstrong> Prevent annoying spam comments and reduce unnecessary load on the server. Automatically and permanently block IP addresses that exceed a set number of spam comments.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit log.\u003C\u002Fstrong> View events happening on your WordPress website. Find out if a plugin or theme has been added, removed, updated and more.\u003C\u002Fp>\n\u003Ch4>WHY ALL-IN-ONE SECURITY?\u003C\u002Fh4>\n\u003Cp>AIOS has a near-perfect \u003Cstrong>4.7 \u002F 5-star user rating\u003C\u002Fstrong> across more than 1 million installs.\u003C\u002Fp>\n\u003Cp>Great for beginners and experts alike. AIOS guides you logically and clearly through each of its features which are all clearly explained. Security features are marked as basic, intermediate and advanced. Each step increases your security score. Turn them on and watch your protection grow!\u003C\u002Fp>\n\u003Cp>We have a large support team of software developers. That means we have the availability and the skillset to help you with the trickiest of queries.\u003C\u002Fp>\n\u003Cp>We comb the WordPress plugin directory for support tickets daily – most queries are responded to within 24 hours.\u003C\u002Fp>\n\u003Cp>\u003Cem>Excellent plugin with numerous well-thought-out options for making a website more secure. I have been using it for years and am very happy with it. I recently had a small problem setting up a website and – even as a non-premium user – I received support very quickly. Highly recommended!\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>For even more ways to stay safe and secure, upgrade to \u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002Fpricing?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios_premium&utm_creative_format=description\" rel=\"nofollow ugc\">AIOS Premium\u003C\u002Fa> – it packs a punch security-wise, whilst being \u003Cstrong>extremely cost-competitive\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>LOGIN SECURITY\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication (TFA)\u003C\u002Fstrong> – Require TFA for specific user roles. Supports Google Authenticator, Microsoft Authenticator, Authy, and many more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detect and manage ‘admin’ usernames\u003C\u002Fstrong> – Identify default ‘admin’ usernames and guide users to change them to protect against brute force attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identify and correct identical login and display names\u003C\u002Fstrong> – Detect cases where the display name matches the username and provide guidance to improve login security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent user enumeration\u003C\u002Fstrong> – Block unauthorised access to URLs that can reveal sensitive information such as usernames or other details.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control login attempts\u003C\u002Fstrong> – Prevent brute force attacks by limiting the number of failed login attempts. Choose how many login attempts are allowed, set lockout durations, and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Force user logout\u003C\u002Fstrong> – Automatically log out users after a specified period of time. Unattended sessions are closed, reducing the risk of unauthorised access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manually approve new registrations\u003C\u002Fstrong> – Review and approve new user registrations to prevent spam and fake sign-ups.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhance WordPress salt security\u003C\u002Fstrong> – Adds 64 extra characters to WordPress salts, rotating them weekly. Makes cracking passwords virtually impossible, even if your database is stolen.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002F\u003Cbr \u002F>\n\u003Cstrong>Monitor and manage active sessions\u003C\u002Fstrong> – If a user is logged in who shouldn’t be, log them out or add them to a blacklist.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SPAM PREVENTION\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block spam coming from bots\u003C\u002Fstrong> – Reduce the load on your server and improve the user experience by automatically blocking spam comments from bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitor spam IP addresses\u003C\u002Fstrong> – Monitor the IP addresses of people or bots leaving spam comments. Choose which ones to block based on a configurable number of comments left.\u003C\u002Fp>\n\u003Ch4>FILE \u002F DATABASE Security\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Scan and fix file permissions\u003C\u002Fstrong> – Scan for insecure file permissions. Click once to fix issues and safeguard critical files and folders.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable PHP file editing\u003C\u002Fstrong> – Disable editing of PHP files (such as plugins and themes) via the dashboard. It’s often the first tool that attackers use as it allows for code execution.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protect sensitive files\u003C\u002Fstrong> – Prevent access to files like readme.html that might reveal information about your WordPress installation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File change scanner\u003C\u002Fstrong> – Get notified of any file changes which occur on your system. Exclude files and folders which change as part of normal operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent image hotlinking\u003C\u002Fstrong> – Prevent other websites from displaying your images via hotlinking and protect server bandwidth.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure database backups\u003C\u002Fstrong> – Perform a database backup via UpdraftPlus from AIOS. Change the default ‘wp_’ prefix to hide your WordPress database from hackers.\u003C\u002Fp>\n\u003Ch4>FIREWALL\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Get .htaccess firewall rules\u003C\u002Fstrong> – Deny access to the .htaccess and wp-config.php files. Disable the server signature and limit file uploads to a configurable size.**\u003C\u002Fp>\n\u003Cp>Block access to the debug.log file and prevent Apache servers from listing the contents of a directory when an index.php file is not present\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Get PHP firewall rules\u003C\u002Fstrong> – PHP firewall rules prevent malicious users from exploiting well-known vulnerabilities in XML-RPC. Safeguard your content by disabling RSS and Atom feeds and avoid cross-site scripting (XSS) attacks.\u003Cbr \u002F>\nBlock fake Google bots and POST requests made by bots – Block fake Google bots and stop bots from making POST requests by blocking IP addresses where the user-agent and referrer fields are blank.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Utilise 6G firewall rules\u003C\u002Fstrong> – Employ flexible blacklist rules to reduce the number of malicious URL requests that hit your website (courtesy of Perishable Press).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>And more\u003C\u002Fstrong> – Blacklist (and whitelist) IP ranges and user agents and block unauthorized access to data by disabling REST API access for non-logged-in requests.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION ENHANCED [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication\u003C\u002Fstrong> is included in the free plugin. Upgrade to Premium if you’d like to:\u003Cbr \u002F>\nRequire TFA after a set time period – Mandate TFA for all admins or other roles after their accounts reach a specified age.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control how often TFA is required\u003C\u002Fstrong> – Set TFA to be required after a certain number of days on trusted devices instead of every login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customise design layout\u003C\u002Fstrong> – Adjust the TFA design to match your website’s existing layout and branding.\u003Cbr \u002F>\nEmergency codes – Generate one-time use emergency codes to regain access if you lose your TFA device.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Multisite Compatible\u003C\u002Fstrong> – Ensure compatibility with WordPress multisite networks and their sub-sites for consistent TFA application.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Integration with login forms\u003C\u002Fstrong> – Integrate TFA with various login forms, including WooCommerce, Affiliates-WP, Elementor Pro, bbPress, and ‘Theme My Login’ without additional coding.\u003C\u002Fp>\n\u003Ch4>SMART 404 BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block IPs based on 404 errors\u003C\u002Fstrong> – Detect hackers probing your URLs via script and bots by the 404 errors they leave behind.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 Configuration\u003C\u002Fstrong> – Set a figure for the maximum number of 404 events allowed before an IP address is blocked. Choose a time period within which the 404 events must occur (e.g., 10 errors within 10 minutes).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 block by URL string\u003C\u002Fstrong> – Instantly block an IP address if a 404 event includes a specific URL string.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 whitelisting\u003C\u002Fstrong> – Prevent particular IP addresses from being permanently blocked due to 404 events.\u003C\u002Fp>\n\u003Ch4>COUNTRY BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block traffic to the entire site or to specific pages or posts\u003C\u002Fstrong> – Useful if you’re an e-commerce site and you want to block sales to some countries for shipping or tax reasons.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Whitelist some users from blocked countries\u003C\u002Fstrong> – Whitelist IP addresses or IP ranges even if they are part of a blocked country.\u003C\u002Fp>\n\u003Ch4>MALWARE SCANNING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Automatic malware scanning\u003C\u002Fstrong> – Detect and protect against the latest malware, trojans, and spyware.\u003Cbr \u002F>\nAlerts you to blacklisting by search engines – Monitor your site for blacklisting by search engines due to malicious code.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Response time monitoring\u003C\u002Fstrong> – Keep track of your website’s response time to identify and address any performance issues.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Uptime monitoring\u003C\u002Fstrong> – Checks your website’s uptime every 5 minutes and alerts you immediately if your site or server goes down.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advice and malware removal\u003C\u002Fstrong> – Need hands-on advice and support for malware removal? Our team of genuine cybersecurity experts is here to help.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification if something’s amiss\u003C\u002Fstrong> – Receive notifications about any issues with your site so you can address problems before they escalate.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cp>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u003C\u002Fp>\n\u003Ch4>Developers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you are a developer and you need some extra hooks or filters for this plugin then let us know.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All-In-One Security plugin can be translated to any language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Currently available translations:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>Hungarian\u003C\u002Fli>\n\u003Cli>Italian\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Chinese\u003C\u002Fli>\n\u003Cli>Portuguese (Brazil)\u003C\u002Fli>\n\u003Cli>Persian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy Policy\u003C\u002Fh4>\n\u003Cp>This plugin may collect IP addresses for security reasons such as mitigating brute force login threats and malicious activity.\u003C\u002Fp>\n\u003Cp>The collected information is stored on your server. No information is transmitted to third parties or remote server locations.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n","Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.",1000000,36139406,1693,"2026-01-28T22:15:00.000Z","5.0","5.6",[52,22,53,54,23],"firewall","malware-scanning","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fall-in-one-wp-security-and-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fall-in-one-wp-security-and-firewall.5.4.6.zip",93,26,"2024-02-08 00:00:00",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":68,"downloaded":69,"rating":70,"num_ratings":71,"last_updated":72,"tested_up_to":73,"requires_at_least":74,"requires_php":18,"tags":75,"homepage":25,"download_link":78,"security_score":79,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"wordfence-login-security","Wordfence Login Security","1.1.15","wfryan","https:\u002F\u002Fprofiles.wordpress.org\u002Fwfryan\u002F","\u003Ch3>WORDFENCE LOGIN SECURITY\u003C\u002Fh3>\n\u003Cp>Wordfence Login Security contains a subset of the functionality found in the full Wordfence plugin: Two-factor Authentication, XML-RPC Protection and Login Page CAPTCHA.\u003C\u002Fp>\n\u003Cp>Are you looking for comprehensive WordPress Security? \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwordfence\u002F\" rel=\"ugc\">Check out the full Wordfence plugin\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Two-factor authentication (2FA), one of the most secure forms of remote system authentication available.\u003C\u002Fli>\n\u003Cli>Use any TOTP-based authenticator app or service like Google Authenticator, Authy, 1Password or FreeOTP.\u003C\u002Fli>\n\u003Cli>Enable 2FA for any WordPress user role.\u003C\u002Fli>\n\u003Cli>Completely free to use, no limits or restrictions of any kind.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>LOGIN PAGE CAPTCHA\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easily enable Google ReCAPTCHA v3 on your login and registration pages.\u003C\u002Fli>\n\u003Cli>Stops bots from logging in without inconveniencing your site visitors.\u003C\u002Fli>\n\u003Cli>Robust protection against password guessing and credential stuffing attacks distributed across large IP pools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>XML-RPC PROTECTION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>XML-RPC is the biggest target for WordPress attacks, but is often overlooked.\u003C\u002Fli>\n\u003Cli>Protect XML-RPC with 2FA or disable it altogether if it’s not needed.\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.",70000,1239075,80,25,"2025-01-15T17:05:00.000Z","6.7.5","4.7",[76,77,22,54,23],"2fa","captcha","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwordfence-login-security.1.1.15.zip",92,{"slug":81,"name":82,"version":83,"author":84,"author_profile":85,"description":86,"short_description":87,"active_installs":88,"downloaded":89,"rating":13,"num_ratings":90,"last_updated":91,"tested_up_to":16,"requires_at_least":49,"requires_php":25,"tags":92,"homepage":25,"download_link":96,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"country-access-blocker","Country Access Blocker","1.6","Valeri Kluger","https:\u002F\u002Fprofiles.wordpress.org\u002Fvalerikluger\u002F","\u003Cp>Country Access Blocker lets you restrict or allow access to your WordPress site based on visitor countries.\u003C\u002Fp>\n\u003Cp>Features:\u003Cbr \u002F>\n* Block visitors from specific countries\u003Cbr \u002F>\n* Clean, GDPR-compliant country list\u003Cbr \u002F>\n* Easy admin interface to configure blocked countries\u003Cbr \u002F>\n* Enable or disable IP-based country blocking with one checkbox\u003Cbr \u002F>\n* No external dependencies or WooCommerce required\u003Cbr \u002F>\n* Uses ip-api.com free API for geolocation\u003C\u002Fp>\n\u003Cp>This plugin is ideal if you want to restrict access from certain countries or comply with geo-based regulations.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support or bug reports, please open an issue on the plugin’s GitHub repository or contact the author.\u003C\u002Fp>\n","Block or allow website visitors from specific countries based on IP geolocation.",500,1743,2,"2026-01-24T22:53:00.000Z",[93,94,20,95,21],"block-country","block-ip","geo-blocking","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcountry-access-blocker.1.6.zip",{"slug":98,"name":99,"version":100,"author":101,"author_profile":102,"description":103,"short_description":104,"active_installs":105,"downloaded":106,"rating":27,"num_ratings":27,"last_updated":107,"tested_up_to":16,"requires_at_least":108,"requires_php":109,"tags":110,"homepage":112,"download_link":113,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"bearmor-security","Bearmor Security","0.9.16","bearmor","https:\u002F\u002Fprofiles.wordpress.org\u002Fandeirz\u002F","\u003Cp>\u003Cstrong>Finally, a WordPress security plugin that doesn’t slow down your site.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Bearmor Security is built for \u003Cstrong>small to medium businesses, freelancers, and agencies\u003C\u002Fstrong> who need real protection without the bloat. No confusing dashboards, no technical jargon, no performance hit.\u003C\u002Fp>\n\u003Ch3>Why Bearmor?\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>🎯 Built for Non-Technical Users\u003C\u002Fstrong>\u003Cbr \u002F>\nYou shouldn’t need a security degree to protect your website. Bearmor gives you clear, actionable insights in plain English.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⚡ Lightweight & Fast\u003C\u002Fstrong>\u003Cbr \u002F>\nUnlike bloated competitors, Bearmor won’t slow down your site. Clean code, efficient scans, zero impact on performance.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>💰 Most Features FREE\u003C\u002Fstrong>\u003Cbr \u002F>\nWhile others lock everything behind paywalls, Bearmor gives you professional-grade security for free. Compare us to Wordfence, Sucuri, or iThemes Security – we’re more generous.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🛡️ Real Protection, Not Theater\u003C\u002Fstrong>\u003Cbr \u002F>\nWe focus on what actually matters: detecting threats, blocking attacks, and keeping you informed. No fake “critical alerts” to scare you into upgrading.\u003C\u002Fp>\n\u003Ch3>🆓 FREE Features (Yes, Really Free)\u003C\u002Fh3>\n\u003Ch3>Malware Scanner\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Deep file scanning\u003C\u002Fstrong> for backdoors, shells, and malicious code\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart detection\u003C\u002Fstrong> with pattern matching and heuristics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Quarantine threats\u003C\u002Fstrong> with one click\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Whitelist false positives\u003C\u002Fstrong> to prevent future alerts\u003C\u002Fli>\n\u003Cli>Scans plugins, themes, uploads, and core files\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>File Integrity Monitoring\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Real-time tracking\u003C\u002Fstrong> of all file changes\u003C\u002Fli>\n\u003Cli>See exactly what changed, when, and where\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Quarantine suspicious changes\u003C\u002Fstrong> instantly\u003C\u002Fli>\n\u003Cli>Mark safe changes to keep your dashboard clean\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Login Security\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Brute force protection\u003C\u002Fstrong> with automatic IP blocking\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login activity log\u003C\u002Fstrong> – see every login attempt\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anomaly detection\u003C\u002Fstrong> – alerts for suspicious login patterns\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geographic tracking\u003C\u002Fstrong> – know where logins come from\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong> via email – completely free\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Hardening\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>One-click hardening\u003C\u002Fstrong> for common vulnerabilities\u003C\u002Fli>\n\u003Cli>Disable XML-RPC, file editing, directory browsing\u003C\u002Fli>\n\u003Cli>Hide WordPress version and login errors\u003C\u002Fli>\n\u003Cli>Enforce strong passwords\u003C\u002Fli>\n\u003Cli>All with simple on\u002Foff toggles\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Activity Logging\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Track all admin actions\u003C\u002Fli>\n\u003Cli>See who changed what and when\u003C\u002Fli>\n\u003Cli>Filter by user, action type, or date\u003C\u002Fli>\n\u003Cli>Essential for multi-user sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Dashboard\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>At-a-glance overview\u003C\u002Fstrong> of your security status\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security score\u003C\u002Fstrong> with clear letter grade (A-F)\u003C\u002Fli>\n\u003Cli>See threats, recent activity, and recommendations\u003C\u002Fli>\n\u003Cli>No clutter, just what matters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🚀 PRO Features (Optional Upgrade)\u003C\u002Fh3>\n\u003Ch3>What’s FREE Forever\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malware Scanner\u003C\u002Fstrong> – Full file scanning with quarantine\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Monitoring\u003C\u002Fstrong> – Real-time change tracking\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Security\u003C\u002Fstrong> – Brute force protection and blocking\u003C\u002Fli>\n\u003Cli>\u003Cstrong>2FA Authentication\u003C\u002Fstrong> – TOTP support built-in\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Quarantine Threats\u003C\u002Fstrong> – One-click isolation of malware\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Hardening\u003C\u002Fstrong> – All hardening options included\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Upgrade to PRO\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>🔥 \u003Cstrong>Advanced Firewall\u003C\u002Fstrong> – Block attacks before they reach WordPress\u003C\u002Fli>\n\u003Cli>🤖 \u003Cstrong>AI Security Analysis\u003C\u002Fstrong> – ChatGPT explains threats in plain English\u003C\u002Fli>\n\u003Cli>📊 \u003Cstrong>Deep Vulnerability Scanner\u003C\u002Fstrong> – Database scanning and comprehensive CVE checks\u003C\u002Fli>\n\u003Cli>⏰ \u003Cstrong>24\u002F7 Uptime Monitoring\u003C\u002Fstrong> – External monitoring with instant email alerts\u003C\u002Fli>\n\u003Cli>🌍 \u003Cstrong>Geo-Blocking\u003C\u002Fstrong> – Block entire countries and IP ranges\u003C\u002Fli>\n\u003Cli>🎯 \u003Cstrong>Priority Support\u003C\u002Fstrong> – Email support with faster response times\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fbearmor.eu\u002Fpricing\" rel=\"nofollow ugc\">Learn more about PRO \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>🎯 Perfect For\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Small Business Owners\u003C\u002Fstrong> who need protection without complexity\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Freelancers\u003C\u002Fstrong> managing multiple client sites\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agencies\u003C\u002Fstrong> who want reliable security without performance issues\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anyone\u003C\u002Fstrong> tired of bloated, confusing security plugins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔒 Privacy & External Services\u003C\u002Fh3>\n\u003Cp>Bearmor Security connects to our secure API server (bearmor.eu) for:\u003Cbr \u002F>\n– \u003Cstrong>License verification\u003C\u002Fstrong> (PRO users only)\u003Cbr \u002F>\n– \u003Cstrong>Uptime monitoring\u003C\u002Fstrong> (PRO users only)\u003Cbr \u002F>\n– \u003Cstrong>AI analysis\u003C\u002Fstrong> (PRO users only)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data sent to our servers:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Site URL\u003Cbr \u002F>\n– Admin email (for notifications)\u003Cbr \u002F>\n– Security scan results (PRO AI analysis only)\u003Cbr \u002F>\n– Site ID (anonymous identifier)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>We DO NOT:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Sell your data\u003Cbr \u002F>\n– Track your visitors\u003Cbr \u002F>\n– Store sensitive information\u003Cbr \u002F>\n– Share data with third parties\u003C\u002Fp>\n\u003Cp>For FREE users, only basic site registration data is sent (URL + email). No security data leaves your server.\u003C\u002Fp>\n\u003Cp>Read our full privacy policy: https:\u002F\u002Fbearmor.eu\u002Fprivacy\u003C\u002Fp>\n\u003Ch3>📊 Why Choose Bearmor?\u003C\u002Fh3>\n\u003Ch3>vs. Wordfence FREE\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>We include 2FA (they lock it behind PRO)\u003C\u002Fli>\n\u003Cli>We include quarantine (they lock it behind PRO)\u003C\u002Fli>\n\u003Cli>Lighter performance impact\u003C\u002Fli>\n\u003Cli>Simpler, cleaner interface\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>vs. Sucuri FREE\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>We include malware scanner (they lock it behind PRO)\u003C\u002Fli>\n\u003Cli>We include file monitoring (they lock it behind PRO)\u003C\u002Fli>\n\u003Cli>We include 2FA and quarantine\u003C\u002Fli>\n\u003Cli>More features in free version\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>vs. iThemes Security\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>More generous free tier\u003C\u002Fli>\n\u003Cli>Better malware detection\u003C\u002Fli>\n\u003Cli>Cleaner dashboard\u003C\u002Fli>\n\u003Cli>Faster scans\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🚀 Quick Start\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Install and activate Bearmor Security\u003C\u002Fli>\n\u003Cli>Run your first malware scan (Dashboard \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Scan Now)\u003C\u002Fli>\n\u003Cli>Enable recommended hardening options (Dashboard \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Hardening)\u003C\u002Fli>\n\u003Cli>Set up 2FA for your account (Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Two-Factor Auth)\u003C\u002Fli>\n\u003Cli>You’re protected! 🎉\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>No configuration needed. Works out of the box.\u003C\u002Fp>\n\u003Ch3>💬 Support\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Documentation:\u003C\u002Fstrong> https:\u002F\u002Fbearmor.eu\u002Fdocs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Support Forum:\u003C\u002Fstrong> https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fbearmor-security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email:\u003C\u002Fstrong> security@bearmor.eu (PRO users get priority)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🌟 What Users Say\u003C\u002Fh3>\n\u003Cp>\u003Cem>“Finally, a security plugin that doesn’t make me feel stupid. Everything just works.”\u003C\u002Fem> – Sarah M., Freelancer\u003C\u002Fp>\n\u003Cp>\u003Cem>“Switched from Wordfence. Bearmor is faster and the free version has more features.”\u003C\u002Fem> – Mike T., Agency Owner\u003C\u002Fp>\n\u003Cp>\u003Cem>“The AI analysis feature is a game-changer. It explains threats in plain English.”\u003C\u002Fem> – David R., Small Business Owner\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Bearmor Security respects your privacy. Here’s exactly what data we collect and why:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>FREE Users:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Site URL (to identify your installation)\u003Cbr \u002F>\n– Admin email (for security notifications)\u003Cbr \u002F>\n– Plugin version (for update checks)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>PRO Users (in addition to above):\u003C\u002Fstrong>\u003Cbr \u002F>\n– Security scan results (for AI analysis)\u003Cbr \u002F>\n– Uptime monitoring data (ping responses)\u003Cbr \u002F>\n– Firewall block logs (for threat intelligence)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>We NEVER:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Sell your data to third parties\u003Cbr \u002F>\n– Track your website visitors\u003Cbr \u002F>\n– Store passwords or sensitive user data\u003Cbr \u002F>\n– Share data without your explicit consent\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Storage:\u003C\u002Fstrong>\u003Cbr \u002F>\n– All data encrypted in transit (HTTPS)\u003Cbr \u002F>\n– Stored on secure servers in EU\u003Cbr \u002F>\n– Retained for 90 days, then automatically deleted\u003Cbr \u002F>\n– You can request data deletion anytime\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Third-Party Services:\u003C\u002Fstrong>\u003Cbr \u002F>\n– OpenAI (ChatGPT) for AI analysis (PRO only)\u003Cbr \u002F>\n– Our own servers for uptime monitoring (PRO only)\u003C\u002Fp>\n\u003Cp>Full privacy policy: https:\u002F\u002Fbearmor.eu\u002Fprivacy\u003Cbr \u002F>\nContact: security@bearmor.eu\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to external services in certain situations:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Bearmor API (bearmor.eu)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> Plugin activation, license verification, PRO features\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> Site URL, admin email, security scan results (PRO only)\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> License management, AI analysis, uptime monitoring\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fbearmor.eu\u002Fprivacy\u003Cbr \u002F>\n– \u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fbearmor.eu\u002Fterms\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress.org API (api.wordpress.org)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> Checking WordPress core file integrity\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> WordPress version number\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> Verify core files haven’t been tampered with\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003Cbr \u002F>\n– \u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fwordpress.org\u002Fabout\u002F\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WPVulnerability.net API (wpvulnerability.net)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> Scanning for known plugin\u002Ftheme vulnerabilities\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> Plugin and theme slugs (names only, no site data)\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> Check for known security vulnerabilities\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fwww.wpvulnerability.net\u002Fprivacy-policy\u003Cbr \u002F>\n– \u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fwww.wpvulnerability.net\u002Fterms-of-service\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP-API.com (ip-api.com)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> Firewall blocks an IP or login from restricted country\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> IP address only\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> Determine country of origin for geo-blocking\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003Cbr \u002F>\n– \u003Cstrong>Terms:\u003C\u002Fstrong> Free tier for non-commercial use\u003C\u002Fp>\n\u003Cp>\u003Cstrong>OpenAI API (PRO only)\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>When:\u003C\u002Fstrong> AI security analysis is requested\u003Cbr \u002F>\n– \u003Cstrong>Data sent:\u003C\u002Fstrong> Anonymized security scan results\u003Cbr \u002F>\n– \u003Cstrong>Purpose:\u003C\u002Fstrong> Generate security recommendations\u003Cbr \u002F>\n– \u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fopenai.com\u002Fprivacy\u003Cbr \u002F>\n– \u003Cstrong>Note:\u003C\u002Fstrong> No personally identifiable information is sent\u003C\u002Fp>\n\u003Cp>All external connections use HTTPS encryption. FREE users connect for: initial registration, vulnerability checks, and geo-blocking. No security scan data leaves your server unless you upgrade to PRO.\u003C\u002Fp>\n","Lightweight, powerful WordPress security for small businesses. Malware scanning, login protection, 2FA, hardening - most features FREE.",50,855,"2026-02-28T15:35:00.000Z","5.8","7.4",[52,22,111,54,23],"malware-scanner","https:\u002F\u002Fbearmor.eu","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbearmor-security.0.9.16.zip",{"slug":115,"name":116,"version":117,"author":118,"author_profile":119,"description":120,"short_description":121,"active_installs":27,"downloaded":122,"rating":27,"num_ratings":27,"last_updated":123,"tested_up_to":124,"requires_at_least":49,"requires_php":109,"tags":125,"homepage":128,"download_link":129,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"facial-recognition-authentication","Facial Recognition Authentication","1.1.2","newwaypmsco","https:\u002F\u002Fprofiles.wordpress.org\u002Fnewwaypmsco\u002F","\u003Cp>For years, users worldwide have faced security risks due to insecure login pages. WordPress sites are no exception to these challenges. Our plugin provides an innovative solution for login security by integrating facial recognition technology with traditional username and password methods.\u003C\u002Fp>\n\u003Cp>Currently, users log in using either a username and password or a Two-Factor Authentication (2FA) method. While 2FA enhances security, it has its own vulnerabilities:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Phishing attacks\u003C\u002Fstrong>: Hackers can deceive users into entering their 2FA codes on fake websites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lost or stolen devices\u003C\u002Fstrong>: If the device used to receive 2FA codes (e.g., a mobile phone) is lost or stolen, unauthorized access becomes possible.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SMS-based 2FA\u003C\u002Fstrong>: SMS codes can be intercepted through SIM swapping attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Access issues\u003C\u002Fstrong>: Users may face challenges accessing 2FA codes due to technical issues.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Software flaws\u003C\u002Fstrong>: Authentication apps can have security vulnerabilities.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Our plugin addresses these issues by leveraging facial recognition for authentication. When a user attempts to log in, our plugin communicates with a secure Django server for authentication, ensuring no sensitive user data is stored in WordPress databases. The facial recognition system can distinguish between a live user and a static photo, making unauthorized access virtually impossible.\u003C\u002Fp>\n\u003Cp>For a complete tutorial on installing and using the plugin, \u003Ca href=\"https:\u002F\u002Fyoutu.be\u002FsBdnzxpg0UA\" rel=\"nofollow ugc\">watch this video\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Facial recognition authentication using a simple webcam.\u003C\u002Fli>\n\u003Cli>No storage of user credentials in WordPress databases.\u003C\u002Fli>\n\u003Cli>Interaction between the plugin and server is conducted through secure APIs with encrypted data transmission.\u003C\u002Fli>\n\u003Cli>Enhanced security with PBKDF2 password hashing (870,000 iterations with salt) on the Django server.\u003C\u002Fli>\n\u003Cli>Seamless integration with WordPress login pages, adding an extra layer of security.\u003C\u002Fli>\n\u003Cli>Simplified registration process for users to set up facial recognition and credentials.\u003C\u002Fli>\n\u003Cli>New \u003Cstrong>Manage Account\u003C\u002Fstrong> section for users to change their password, update photo, or delete their account, secured with OTP and facial recognition.\u003C\u002Fli>\n\u003Cli>Activation email sent during registration, with a 24-hour expiration period.\u003C\u002Fli>\n\u003Cli>Each user can only register with a single email address.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Why Choose Our Plugin?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Protects against brute-force attacks targeting WordPress login pages.\u003C\u002Fli>\n\u003Cli>Eliminates reliance on weak password hashing mechanisms in WordPress.\u003C\u002Fli>\n\u003Cli>Enhances user experience by enabling secure logins without expensive hardware.\u003C\u002Fli>\n\u003Cli>Provides a scalable solution for future platforms beyond WordPress.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Try Our Demo Before Installing!\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Want to test our plugin in a safe environment before installing it on your own site? We’ve set up a demo WordPress site where you can experience the plugin in action.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Email us at [support@newwaypmsco.com]\u003C\u002Fstrong> to request access – we’ll send you the demo site link, along with a username and password to log in and test the plugin.\u003C\u002Fp>\n\u003Cp>Once you’re satisfied, you can install it on your own WordPress site with confidence!\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to an external Django server to perform facial recognition authentication. The communication between the plugin and the server is secure, ensuring the safety of user data through encrypted transmission.\u003C\u002Fp>\n\u003Ch3>\u003Cstrong>Third-Party Service Details\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Service Name:\u003C\u002Fstrong> Django Server for Facial Recognition Authentication\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> To authenticate users using facial recognition.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>During login:\u003C\u002Fli>\n\u003Cli>Username and password entered by the user.\u003C\u002Fli>\n\u003Cli>Facial image captured by the webcam for authentication.\u003C\u002Fli>\n\u003Cli>During registration:\u003C\u002Fli>\n\u003Cli>Username and password chosen by the user.\u003C\u002Fli>\n\u003Cli>Facial image captured by the webcam to set up facial recognition.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage & Security:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>All data is transmitted securely using SSL encryption.\u003C\u002Fli>\n\u003Cli>Facial data is stored on our Django server with AES-256 encryption.\u003C\u002Fli>\n\u003Cli>No facial data is stored in WordPress databases.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conditions:\u003C\u002Fstrong> Data is sent only when users initiate login or registration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Control:\u003C\u002Fstrong> We’re working on adding a feature to let users delete their facial data in future updates. For now, contact our support team at \u003Cstrong>[support@newwaypmsco.com]\u003C\u002Fstrong> for assistance with data management.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fapi.newwaypmsco.com\u002Fterms-of-service\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fapi.newwaypmsco.com\u002Fterms-of-service\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fapi.newwaypmsco.com\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fapi.newwaypmsco.com\u002Fprivacy-policy\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>External API Endpoints Used:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>https:\u002F\u002Fapi.newwaypmsco.com\u002Fapi\u002Fuser\u002Flogin\u002F\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>https:\u002F\u002Fapi.newwaypmsco.com\u002Fapi\u002Fuser\u002Fregister\u002F\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>By using this plugin, users acknowledge and agree to the terms and conditions outlined above.\u003C\u002Fp>\n\u003Ch3>Resources\u003C\u002Fh3>\n\u003Cp>This plugin uses the open-source SweetAlert library for user alerts. Non-minified source code is available in:\u003Cbr \u002F>\n– assets\u002Fjs\u002Fbootstrap.js (non-minified version)\u003Cbr \u002F>\n– assets\u002Fjs\u002Fsweetalert.min.js (SweetAlert library)\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Official SweetAlert Website: https:\u002F\u002Fsweetalert.js.org\u002F\u003C\u002Fli>\n\u003Cli>SweetAlert CDN: https:\u002F\u002Fcdnjs.com\u002Flibraries\u002Fsweetalert\u002F2.1.2\u003C\u002Fli>\n\u003Cli>GitHub Repository: https:\u002F\u002Fgithub.com\u002Ft4t5\u002Fsweetalert\u003C\u002Fli>\n\u003C\u002Ful>\n","Facial Recognition Authentication plugin integrates facial recognition with WordPress login for enhanced security and user experience.",876,"2025-10-16T12:39:00.000Z","6.8.5",[126,22,23,127],"facial-recognition","wordpress-security","https:\u002F\u002Fnewwaypmsco.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffacial-recognition-authentication.1.1.2.zip",{"attackSurface":131,"codeSignals":411,"taintFlows":835,"riskAssessment":971,"analyzedAt":982},{"hooks":132,"ajaxHandlers":304,"restRoutes":406,"shortcodes":407,"cronEvents":408,"entryPointCount":409,"unprotectedCount":410},[133,140,145,149,152,157,161,163,167,171,175,178,182,186,190,194,197,201,205,209,213,216,219,223,226,229,232,235,238,241,244,247,250,253,255,257,260,262,265,269,273,277,281,285,288,292,296,300],{"type":134,"name":135,"callback":136,"priority":137,"file":138,"line":139},"filter","wp_authenticate_user","faqnurul_ipcbl_verify_2fa_login",10,"includes\\functions.php",2605,{"type":141,"name":142,"callback":143,"file":138,"line":144},"action","login_init","faqnurul_ipcbl_check_2fa_requirement",2611,{"type":141,"name":146,"callback":147,"file":138,"line":148},"admin_post_faqnurul_2fa_verify","faqnurul_ipcbl_handle_2fa_verification",2614,{"type":141,"name":150,"callback":147,"file":138,"line":151},"admin_post_nopriv_faqnurul_2fa_verify",2615,{"type":141,"name":153,"callback":154,"priority":14,"file":155,"line":156},"init","faqnurul_ipcbl_check_recovery_hash","ip-blocker-lite.php",77,{"type":141,"name":158,"callback":159,"file":155,"line":160},"admin_notices","closure",169,{"type":141,"name":158,"callback":159,"file":155,"line":162},174,{"type":141,"name":164,"callback":165,"file":155,"line":166},"admin_post_submit_plugin_feedback","handle_user_feedback_submission",180,{"type":141,"name":168,"callback":169,"file":155,"line":170},"admin_enqueue_scripts","faqnurul_ipcbl_enqueue_optin_scripts",196,{"type":141,"name":172,"callback":173,"file":155,"line":174},"admin_menu","faqnurul_ipcbl_admin_menu",200,{"type":141,"name":168,"callback":176,"file":155,"line":177},"faqnurul_ipcbl_admin_styles",203,{"type":141,"name":179,"callback":180,"file":155,"line":181},"login_form","faqnurul_ipcbl_add_turnstile_to_login",229,{"type":141,"name":183,"callback":184,"file":155,"line":185},"register_form","faqnurul_ipcbl_add_turnstile_to_register",230,{"type":141,"name":187,"callback":188,"file":155,"line":189},"lostpassword_form","faqnurul_ipcbl_add_turnstile_to_lost_password",231,{"type":141,"name":191,"callback":192,"file":155,"line":193},"comment_form_after_fields","faqnurul_ipcbl_add_turnstile_to_comments",232,{"type":134,"name":135,"callback":195,"priority":137,"file":155,"line":196},"faqnurul_ipcbl_validate_login_turnstile",233,{"type":134,"name":198,"callback":199,"priority":137,"file":155,"line":200},"registration_errors","faqnurul_ipcbl_validate_register_turnstile",234,{"type":134,"name":202,"callback":203,"file":155,"line":204},"lostpassword_post","faqnurul_ipcbl_validate_lost_password_turnstile",235,{"type":134,"name":206,"callback":207,"file":155,"line":208},"preprocess_comment","faqnurul_ipcbl_validate_comment_turnstile",236,{"type":141,"name":210,"callback":211,"file":155,"line":212},"woocommerce_login_form","faqnurul_ipcbl_add_turnstile_to_woocommerce",240,{"type":141,"name":214,"callback":211,"file":155,"line":215},"woocommerce_register_form",241,{"type":141,"name":217,"callback":211,"file":155,"line":218},"woocommerce_lostpassword_form",242,{"type":141,"name":220,"callback":221,"file":155,"line":222},"woocommerce_checkout_process","faqnurul_ipcbl_validate_woocommerce_turnstile",243,{"type":134,"name":224,"callback":221,"file":155,"line":225},"woocommerce_process_registration_errors",244,{"type":141,"name":179,"callback":227,"file":155,"line":228},"faqnurul_ipcbl_add_recaptcha_to_login",248,{"type":141,"name":183,"callback":230,"file":155,"line":231},"faqnurul_ipcbl_add_recaptcha_to_register",249,{"type":141,"name":187,"callback":233,"file":155,"line":234},"faqnurul_ipcbl_add_recaptcha_to_lost_password",250,{"type":141,"name":191,"callback":236,"file":155,"line":237},"faqnurul_ipcbl_add_recaptcha_to_comments",251,{"type":134,"name":135,"callback":239,"priority":137,"file":155,"line":240},"faqnurul_ipcbl_validate_login_recaptcha",252,{"type":134,"name":198,"callback":242,"priority":137,"file":155,"line":243},"faqnurul_ipcbl_validate_register_recaptcha",253,{"type":134,"name":202,"callback":245,"file":155,"line":246},"faqnurul_ipcbl_validate_lost_password_recaptcha",254,{"type":134,"name":206,"callback":248,"file":155,"line":249},"faqnurul_ipcbl_validate_comment_recaptcha",255,{"type":141,"name":210,"callback":251,"file":155,"line":252},"faqnurul_ipcbl_add_recaptcha_to_woocommerce",259,{"type":141,"name":214,"callback":251,"file":155,"line":254},260,{"type":141,"name":217,"callback":251,"file":155,"line":256},261,{"type":141,"name":220,"callback":258,"file":155,"line":259},"faqnurul_ipcbl_validate_woocommerce_recaptcha",262,{"type":134,"name":224,"callback":258,"file":155,"line":261},263,{"type":134,"name":135,"callback":263,"priority":14,"file":155,"line":264},"faqnurul_ipcbl_check_lockout_on_auth",267,{"type":141,"name":266,"callback":267,"file":155,"line":268},"wp_login_failed","faqnurul_ipcbl_handle_failed_login",268,{"type":141,"name":270,"callback":271,"file":155,"line":272},"wp_login","faqnurul_ipcbl_log_successful_login",269,{"type":141,"name":274,"callback":275,"file":155,"line":276},"activated_plugin","faqnurul_ipcbl_log_plugin_activation",272,{"type":141,"name":278,"callback":279,"file":155,"line":280},"deactivated_plugin","faqnurul_ipcbl_log_plugin_deactivation",273,{"type":141,"name":282,"callback":283,"file":155,"line":284},"deleted_plugin","faqnurul_ipcbl_log_plugin_deletion",274,{"type":141,"name":153,"callback":286,"file":155,"line":287},"faqnurul_ipcbl_admin_init",282,{"type":141,"name":289,"callback":290,"file":155,"line":291},"template_redirect","faqnurul_ipcbl_ip_blocker_check_access",344,{"type":141,"name":293,"callback":294,"file":155,"line":295},"wp_scheduled_delete","faqnurul_ipcbl_cleanup_expired_ips",402,{"type":141,"name":297,"callback":298,"file":155,"line":299},"wp_enqueue_scripts","faqnurul_ipcbl_enqueue_frontend_scripts",2665,{"type":141,"name":301,"callback":302,"file":155,"line":303},"login_enqueue_scripts","faqnurul_ipcbl_enqueue_login_scripts",2678,[305,311,315,319,323,327,331,335,339,343,347,351,353,357,361,365,369,373,377,381,385,388,391,394,397,400,402,404],{"action":306,"nopriv":307,"callback":308,"hasNonce":309,"hasCapCheck":309,"file":155,"line":310},"search_blocked_ips",false,"faqnurul_ipcbl_search_blocked_ips",true,206,{"action":312,"nopriv":307,"callback":313,"hasNonce":309,"hasCapCheck":309,"file":155,"line":314},"search_blocked_countries","faqnurul_ipcbl_search_blocked_countries",207,{"action":316,"nopriv":307,"callback":317,"hasNonce":309,"hasCapCheck":309,"file":155,"line":318},"search_whitelist","faqnurul_ipcbl_search_whitelist",208,{"action":320,"nopriv":307,"callback":321,"hasNonce":309,"hasCapCheck":309,"file":155,"line":322},"search_countries","faqnurul_ipcbl_search_countries",209,{"action":324,"nopriv":307,"callback":325,"hasNonce":309,"hasCapCheck":307,"file":155,"line":326},"ipcbl_submit_deactivation_feedback","faqnurul_ipcbl_submit_deactivation_feedback",210,{"action":328,"nopriv":307,"callback":329,"hasNonce":307,"hasCapCheck":307,"file":155,"line":330},"remove_whitelist","faqnurul_ipcbl_remove_whitelist_ajax",211,{"action":332,"nopriv":307,"callback":333,"hasNonce":307,"hasCapCheck":307,"file":155,"line":334},"faqnurul_ipcbl_add_whitelist","faqnurul_ipcbl_add_whitelist_ajax",212,{"action":336,"nopriv":307,"callback":337,"hasNonce":307,"hasCapCheck":307,"file":155,"line":338},"faqnurul_ipcbl_get_whitelist","faqnurul_ipcbl_get_whitelist_ajax",213,{"action":340,"nopriv":307,"callback":341,"hasNonce":307,"hasCapCheck":307,"file":155,"line":342},"faqnurul_regenerate_recovery_codes","faqnurul_ipcbl_ajax_regenerate_recovery_codes",214,{"action":344,"nopriv":307,"callback":345,"hasNonce":307,"hasCapCheck":307,"file":155,"line":346},"faqnurul_download_recovery_codes","faqnurul_ipcbl_ajax_download_recovery_codes",215,{"action":348,"nopriv":307,"callback":349,"hasNonce":307,"hasCapCheck":307,"file":155,"line":350},"faqnurul_send_2fa_email_ajax","faqnurul_ipcbl_send_2fa_email_ajax",216,{"action":348,"nopriv":309,"callback":349,"hasNonce":307,"hasCapCheck":307,"file":155,"line":352},217,{"action":354,"nopriv":307,"callback":355,"hasNonce":307,"hasCapCheck":307,"file":155,"line":356},"regenerate_totp_secret","faqnurul_ipcbl_ajax_regenerate_totp_secret",218,{"action":358,"nopriv":307,"callback":359,"hasNonce":307,"hasCapCheck":307,"file":155,"line":360},"faqnurul_verify_totp_code","faqnurul_ipcbl_ajax_verify_totp_code",219,{"action":362,"nopriv":307,"callback":363,"hasNonce":307,"hasCapCheck":307,"file":155,"line":364},"faqnurul_enable_2fa","faqnurul_ipcbl_ajax_enable_2fa",220,{"action":366,"nopriv":307,"callback":367,"hasNonce":307,"hasCapCheck":307,"file":155,"line":368},"faqnurul_check_2fa_status","faqnurul_ipcbl_ajax_check_2fa_status",221,{"action":370,"nopriv":307,"callback":371,"hasNonce":307,"hasCapCheck":307,"file":155,"line":372},"faqnurul_disable_2fa","faqnurul_ipcbl_ajax_disable_2fa",222,{"action":374,"nopriv":307,"callback":375,"hasNonce":307,"hasCapCheck":307,"file":155,"line":376},"submit_feedback","faqnurul_ipcbl_submit_feedback",223,{"action":378,"nopriv":307,"callback":379,"hasNonce":309,"hasCapCheck":307,"file":155,"line":380},"ipcbl_optin_choice","faqnurul_ipcbl_handle_optin_choice",224,{"action":382,"nopriv":307,"callback":383,"hasNonce":309,"hasCapCheck":309,"file":155,"line":384},"generate_recovery_hash","faqnurul_ipcbl_generate_recovery_hash",225,{"action":386,"nopriv":307,"callback":386,"hasNonce":309,"hasCapCheck":309,"file":155,"line":387},"faqnurul_ipcbl_block_ip_ajax",2689,{"action":389,"nopriv":307,"callback":389,"hasNonce":309,"hasCapCheck":309,"file":155,"line":390},"faqnurul_ipcbl_unblock_ip_ajax",2690,{"action":392,"nopriv":307,"callback":392,"hasNonce":309,"hasCapCheck":309,"file":155,"line":393},"faqnurul_ipcbl_block_country_ajax",2691,{"action":395,"nopriv":307,"callback":395,"hasNonce":309,"hasCapCheck":309,"file":155,"line":396},"faqnurul_ipcbl_unblock_country_ajax",2692,{"action":398,"nopriv":307,"callback":398,"hasNonce":307,"hasCapCheck":309,"file":155,"line":399},"faqnurul_ipcbl_get_blocked_ips_ajax",2693,{"action":332,"nopriv":307,"callback":333,"hasNonce":307,"hasCapCheck":307,"file":155,"line":401},2696,{"action":336,"nopriv":307,"callback":337,"hasNonce":307,"hasCapCheck":307,"file":155,"line":403},2697,{"action":345,"nopriv":307,"callback":345,"hasNonce":307,"hasCapCheck":307,"file":155,"line":405},2698,[],[],[],28,16,{"dangerousFunctions":412,"sqlUsage":413,"outputEscaping":415,"fileOperations":27,"externalRequests":831,"nonceChecks":832,"capabilityChecks":833,"bundledLibraries":834},[],{"prepared":27,"raw":27,"locations":414},[],{"escaped":416,"rawEcho":326,"locations":417},303,[418,422,423,424,426,427,429,430,432,434,436,438,440,442,444,446,448,450,452,454,455,457,459,461,463,465,467,469,471,473,475,477,479,481,483,485,487,489,491,493,495,497,499,501,503,505,507,509,511,513,515,517,519,521,523,525,527,529,531,533,535,537,539,541,543,545,547,549,551,553,555,557,559,561,563,565,567,569,571,573,575,577,579,581,583,585,587,589,591,593,595,597,599,601,603,605,607,609,611,613,615,617,619,621,623,625,627,629,631,633,635,637,639,641,643,645,647,649,651,653,655,657,659,661,663,665,667,669,671,673,675,677,679,681,683,685,687,689,691,693,695,697,699,701,703,705,707,709,711,713,715,717,718,720,722,724,726,728,730,732,734,736,738,740,742,744,746,748,750,752,754,756,758,760,762,764,766,768,770,772,773,775,777,779,781,783,785,787,789,791,793,795,797,799,801,803,805,807,808,810,811,813,815,817,819,821,823,825,827,829],{"file":419,"line":420,"context":421},"admin-page-tabs-template.php",24,"raw output",{"file":419,"line":71,"context":421},{"file":419,"line":58,"context":421},{"file":419,"line":425,"context":421},27,{"file":419,"line":409,"context":421},{"file":419,"line":428,"context":421},29,{"file":419,"line":33,"context":421},{"file":138,"line":431,"context":421},2187,{"file":138,"line":433,"context":421},2520,{"file":138,"line":435,"context":421},2540,{"file":138,"line":437,"context":421},2541,{"file":138,"line":439,"context":421},2545,{"file":138,"line":441,"context":421},2546,{"file":138,"line":443,"context":421},2550,{"file":138,"line":445,"context":421},2551,{"file":138,"line":447,"context":421},2580,{"file":138,"line":449,"context":421},2585,{"file":138,"line":451,"context":421},2590,{"file":138,"line":453,"context":421},2593,{"file":138,"line":453,"context":421},{"file":155,"line":456,"context":421},170,{"file":155,"line":458,"context":421},175,{"file":155,"line":460,"context":421},1357,{"file":155,"line":462,"context":421},1372,{"file":155,"line":464,"context":421},1395,{"file":155,"line":466,"context":421},1396,{"file":155,"line":468,"context":421},1406,{"file":155,"line":470,"context":421},1407,{"file":155,"line":472,"context":421},1416,{"file":155,"line":474,"context":421},1417,{"file":155,"line":476,"context":421},1425,{"file":155,"line":478,"context":421},1426,{"file":155,"line":480,"context":421},1433,{"file":155,"line":482,"context":421},1434,{"file":155,"line":484,"context":421},1435,{"file":155,"line":486,"context":421},1436,{"file":155,"line":488,"context":421},1437,{"file":155,"line":490,"context":421},1438,{"file":155,"line":492,"context":421},1439,{"file":155,"line":494,"context":421},1450,{"file":155,"line":496,"context":421},1461,{"file":155,"line":498,"context":421},1478,{"file":155,"line":500,"context":421},1484,{"file":155,"line":502,"context":421},1495,{"file":155,"line":504,"context":421},1496,{"file":155,"line":506,"context":421},1504,{"file":155,"line":508,"context":421},1507,{"file":155,"line":510,"context":421},1512,{"file":155,"line":512,"context":421},1516,{"file":155,"line":514,"context":421},1519,{"file":155,"line":516,"context":421},1520,{"file":155,"line":518,"context":421},1521,{"file":155,"line":520,"context":421},1522,{"file":155,"line":522,"context":421},1525,{"file":155,"line":524,"context":421},1530,{"file":155,"line":526,"context":421},1531,{"file":155,"line":528,"context":421},1537,{"file":155,"line":530,"context":421},1543,{"file":155,"line":532,"context":421},1548,{"file":155,"line":534,"context":421},1551,{"file":155,"line":536,"context":421},1558,{"file":155,"line":538,"context":421},1560,{"file":155,"line":540,"context":421},1584,{"file":155,"line":542,"context":421},1593,{"file":155,"line":544,"context":421},1606,{"file":155,"line":546,"context":421},1608,{"file":155,"line":548,"context":421},1642,{"file":155,"line":550,"context":421},1643,{"file":155,"line":552,"context":421},1648,{"file":155,"line":554,"context":421},1649,{"file":155,"line":556,"context":421},1650,{"file":155,"line":558,"context":421},1655,{"file":155,"line":560,"context":421},1657,{"file":155,"line":562,"context":421},1665,{"file":155,"line":564,"context":421},1666,{"file":155,"line":566,"context":421},1667,{"file":155,"line":568,"context":421},1677,{"file":155,"line":570,"context":421},1688,{"file":155,"line":572,"context":421},1705,{"file":155,"line":574,"context":421},1706,{"file":155,"line":576,"context":421},1716,{"file":155,"line":578,"context":421},1723,{"file":155,"line":580,"context":421},1737,{"file":155,"line":582,"context":421},1744,{"file":155,"line":584,"context":421},1762,{"file":155,"line":586,"context":421},1769,{"file":155,"line":588,"context":421},1788,{"file":155,"line":590,"context":421},1802,{"file":155,"line":592,"context":421},1804,{"file":155,"line":594,"context":421},1806,{"file":155,"line":596,"context":421},1825,{"file":155,"line":598,"context":421},1839,{"file":155,"line":600,"context":421},1844,{"file":155,"line":602,"context":421},1846,{"file":155,"line":604,"context":421},1849,{"file":155,"line":606,"context":421},1851,{"file":155,"line":608,"context":421},1863,{"file":155,"line":610,"context":421},1868,{"file":155,"line":612,"context":421},1870,{"file":155,"line":614,"context":421},1871,{"file":155,"line":616,"context":421},1872,{"file":155,"line":618,"context":421},1874,{"file":155,"line":620,"context":421},1877,{"file":155,"line":622,"context":421},1879,{"file":155,"line":624,"context":421},1882,{"file":155,"line":626,"context":421},1884,{"file":155,"line":628,"context":421},1899,{"file":155,"line":630,"context":421},1902,{"file":155,"line":632,"context":421},1912,{"file":155,"line":634,"context":421},1918,{"file":155,"line":636,"context":421},1923,{"file":155,"line":638,"context":421},1928,{"file":155,"line":640,"context":421},1933,{"file":155,"line":642,"context":421},1938,{"file":155,"line":644,"context":421},1946,{"file":155,"line":646,"context":421},1952,{"file":155,"line":648,"context":421},1957,{"file":155,"line":650,"context":421},1962,{"file":155,"line":652,"context":421},1967,{"file":155,"line":654,"context":421},1972,{"file":155,"line":656,"context":421},1984,{"file":155,"line":658,"context":421},1985,{"file":155,"line":660,"context":421},2001,{"file":155,"line":662,"context":421},2004,{"file":155,"line":664,"context":421},2008,{"file":155,"line":666,"context":421},2010,{"file":155,"line":668,"context":421},2013,{"file":155,"line":670,"context":421},2015,{"file":155,"line":672,"context":421},2027,{"file":155,"line":674,"context":421},2028,{"file":155,"line":676,"context":421},2046,{"file":155,"line":678,"context":421},2062,{"file":155,"line":680,"context":421},2064,{"file":155,"line":682,"context":421},2065,{"file":155,"line":684,"context":421},2067,{"file":155,"line":686,"context":421},2076,{"file":155,"line":688,"context":421},2080,{"file":155,"line":690,"context":421},2082,{"file":155,"line":692,"context":421},2090,{"file":155,"line":694,"context":421},2100,{"file":155,"line":696,"context":421},2109,{"file":155,"line":698,"context":421},2110,{"file":155,"line":700,"context":421},2115,{"file":155,"line":702,"context":421},2129,{"file":155,"line":704,"context":421},2132,{"file":155,"line":706,"context":421},2148,{"file":155,"line":708,"context":421},2149,{"file":155,"line":710,"context":421},2158,{"file":155,"line":712,"context":421},2161,{"file":155,"line":714,"context":421},2164,{"file":155,"line":716,"context":421},2168,{"file":155,"line":716,"context":421},{"file":155,"line":719,"context":421},2176,{"file":155,"line":721,"context":421},2189,{"file":155,"line":723,"context":421},2190,{"file":155,"line":725,"context":421},2198,{"file":155,"line":727,"context":421},2207,{"file":155,"line":729,"context":421},2208,{"file":155,"line":731,"context":421},2209,{"file":155,"line":733,"context":421},2210,{"file":155,"line":735,"context":421},2211,{"file":155,"line":737,"context":421},2227,{"file":155,"line":739,"context":421},2236,{"file":155,"line":741,"context":421},2237,{"file":155,"line":743,"context":421},2239,{"file":155,"line":745,"context":421},2243,{"file":155,"line":747,"context":421},2244,{"file":155,"line":749,"context":421},2247,{"file":155,"line":751,"context":421},2248,{"file":155,"line":753,"context":421},2253,{"file":155,"line":755,"context":421},2254,{"file":155,"line":757,"context":421},2255,{"file":155,"line":759,"context":421},2257,{"file":155,"line":761,"context":421},2260,{"file":155,"line":763,"context":421},2261,{"file":155,"line":765,"context":421},2265,{"file":155,"line":767,"context":421},2270,{"file":155,"line":769,"context":421},2274,{"file":155,"line":771,"context":421},2278,{"file":155,"line":771,"context":421},{"file":155,"line":774,"context":421},2289,{"file":155,"line":776,"context":421},2290,{"file":155,"line":778,"context":421},2296,{"file":155,"line":780,"context":421},2297,{"file":155,"line":782,"context":421},2309,{"file":155,"line":784,"context":421},2314,{"file":155,"line":786,"context":421},2316,{"file":155,"line":788,"context":421},2317,{"file":155,"line":790,"context":421},2330,{"file":155,"line":792,"context":421},2336,{"file":155,"line":794,"context":421},2337,{"file":155,"line":796,"context":421},2350,{"file":155,"line":798,"context":421},2356,{"file":155,"line":800,"context":421},2357,{"file":155,"line":802,"context":421},2381,{"file":155,"line":804,"context":421},2382,{"file":155,"line":806,"context":421},2385,{"file":155,"line":806,"context":421},{"file":155,"line":809,"context":421},2386,{"file":155,"line":809,"context":421},{"file":155,"line":812,"context":421},2421,{"file":155,"line":814,"context":421},2428,{"file":155,"line":816,"context":421},2438,{"file":155,"line":818,"context":421},2439,{"file":155,"line":820,"context":421},2442,{"file":155,"line":822,"context":421},2443,{"file":155,"line":824,"context":421},2446,{"file":155,"line":826,"context":421},2447,{"file":155,"line":828,"context":421},2450,{"file":155,"line":830,"context":421},2451,6,49,18,[],[836,911,944,960],{"entryPoint":837,"graph":838,"unsanitizedCount":909,"severity":910},"faqnurul_ipcbl_admin_page (ip-blocker-lite.php:1009)",{"nodes":839,"edges":899},[840,845,851,855,857,861,863,867,869,873,875,879,881,884,888,892,896],{"id":841,"type":842,"label":843,"file":155,"line":844},"n0","source","$_POST (x5)",1212,{"id":846,"type":847,"label":848,"file":155,"line":849,"wp_function":850},"n1","sink","update_option() [Settings Manipulation]",1213,"update_option",{"id":852,"type":842,"label":853,"file":155,"line":854},"n2","$_POST['captcha_version']",1278,{"id":856,"type":847,"label":848,"file":155,"line":854,"wp_function":850},"n3",{"id":858,"type":842,"label":859,"file":155,"line":860},"n4","$_POST['captcha_site_key']",1279,{"id":862,"type":847,"label":848,"file":155,"line":860,"wp_function":850},"n5",{"id":864,"type":842,"label":865,"file":155,"line":866},"n6","$_POST['captcha_secret_key']",1280,{"id":868,"type":847,"label":848,"file":155,"line":866,"wp_function":850},"n7",{"id":870,"type":842,"label":871,"file":155,"line":872},"n8","$_POST['lockout_max_attempts']",1298,{"id":874,"type":847,"label":848,"file":155,"line":872,"wp_function":850},"n9",{"id":876,"type":842,"label":877,"file":155,"line":878},"n10","$_POST['lockout_duration']",1299,{"id":880,"type":847,"label":848,"file":155,"line":878,"wp_function":850},"n11",{"id":882,"type":842,"label":883,"file":155,"line":844},"n12","$_POST",{"id":885,"type":847,"label":886,"file":155,"line":745,"wp_function":887},"n13","echo() [XSS]","echo",{"id":889,"type":842,"label":890,"file":155,"line":891},"n14","$_POST (x4)",1599,{"id":893,"type":894,"label":895,"file":155,"line":891},"n15","transform","→ faqnurul_ipcbl_pagination()",{"id":897,"type":847,"label":886,"file":138,"line":898,"wp_function":887},"n16",427,[900,901,902,903,904,905,906,907,908],{"from":841,"to":846,"sanitized":309},{"from":852,"to":856,"sanitized":309},{"from":858,"to":862,"sanitized":309},{"from":864,"to":868,"sanitized":309},{"from":870,"to":874,"sanitized":309},{"from":876,"to":880,"sanitized":309},{"from":882,"to":885,"sanitized":309},{"from":889,"to":893,"sanitized":307},{"from":893,"to":897,"sanitized":307},4,"medium",{"entryPoint":912,"graph":913,"unsanitizedCount":909,"severity":910},"\u003Cip-blocker-lite> (ip-blocker-lite.php:0)",{"nodes":914,"edges":934},[915,916,917,918,919,920,921,922,923,924,925,926,927,929,931,932,933],{"id":841,"type":842,"label":843,"file":155,"line":844},{"id":846,"type":847,"label":848,"file":155,"line":849,"wp_function":850},{"id":852,"type":842,"label":853,"file":155,"line":854},{"id":856,"type":847,"label":848,"file":155,"line":854,"wp_function":850},{"id":858,"type":842,"label":859,"file":155,"line":860},{"id":862,"type":847,"label":848,"file":155,"line":860,"wp_function":850},{"id":864,"type":842,"label":865,"file":155,"line":866},{"id":868,"type":847,"label":848,"file":155,"line":866,"wp_function":850},{"id":870,"type":842,"label":871,"file":155,"line":872},{"id":874,"type":847,"label":848,"file":155,"line":872,"wp_function":850},{"id":876,"type":842,"label":877,"file":155,"line":878},{"id":880,"type":847,"label":848,"file":155,"line":878,"wp_function":850},{"id":882,"type":842,"label":843,"file":155,"line":928},882,{"id":885,"type":847,"label":886,"file":155,"line":930,"wp_function":887},1577,{"id":889,"type":842,"label":890,"file":155,"line":891},{"id":893,"type":894,"label":895,"file":155,"line":891},{"id":897,"type":847,"label":886,"file":138,"line":898,"wp_function":887},[935,936,937,938,939,940,941,942,943],{"from":841,"to":846,"sanitized":309},{"from":852,"to":856,"sanitized":309},{"from":858,"to":862,"sanitized":309},{"from":864,"to":868,"sanitized":309},{"from":870,"to":874,"sanitized":309},{"from":876,"to":880,"sanitized":309},{"from":882,"to":885,"sanitized":309},{"from":889,"to":893,"sanitized":307},{"from":893,"to":897,"sanitized":307},{"entryPoint":945,"graph":946,"unsanitizedCount":27,"severity":959},"faqnurul_ipcbl_show_2fa_form (includes\\functions.php:2161)",{"nodes":947,"edges":956},[948,950,952,955],{"id":841,"type":842,"label":949,"file":138,"line":716},"$_GET (x2)",{"id":846,"type":847,"label":886,"file":138,"line":951,"wp_function":887},2344,{"id":852,"type":842,"label":953,"file":138,"line":954},"$_GET['2fa']",2558,{"id":856,"type":847,"label":886,"file":138,"line":954,"wp_function":887},[957,958],{"from":841,"to":846,"sanitized":309},{"from":852,"to":856,"sanitized":309},"low",{"entryPoint":961,"graph":962,"unsanitizedCount":27,"severity":959},"\u003Cfunctions> (includes\\functions.php:0)",{"nodes":963,"edges":968},[964,965,966,967],{"id":841,"type":842,"label":949,"file":138,"line":716},{"id":846,"type":847,"label":886,"file":138,"line":951,"wp_function":887},{"id":852,"type":842,"label":953,"file":138,"line":954},{"id":856,"type":847,"label":886,"file":138,"line":954,"wp_function":887},[969,970],{"from":841,"to":846,"sanitized":309},{"from":852,"to":856,"sanitized":309},{"summary":972,"deductions":973},"The \"ip-blocker-lite\" v3.0.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and showing a robust number of nonce and capability checks. The absence of any recorded vulnerabilities in its history is also a strong indicator of a generally secure development process.\n\nHowever, there are significant concerns regarding the attack surface. With 28 AJAX handlers, 16 of which lack proper authentication checks, a substantial portion of the plugin's functionality is potentially exposed to unauthorized users. The taint analysis, while limited in scope, revealed two flows with unsanitized paths, suggesting a potential for insecure handling of user-supplied data that could lead to vulnerabilities if exploited. Furthermore, the output escaping is only properly handled in 59% of cases, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities in the remaining 41% of outputs.\n\nWhile the plugin's history is clean, the identified weaknesses in the current version warrant caution. The large number of unprotected AJAX endpoints and the presence of unsanitized data flows are the most pressing concerns, outweighing the positive aspects of its SQL handling and vulnerability history. Remediation of these unprotected entry points and improved output sanitization are crucial for improving its overall security.",[974,977,979],{"reason":975,"points":976},"Unprotected AJAX handlers",8,{"reason":978,"points":831},"Unsanitized paths in taint flows",{"reason":980,"points":981},"Insufficient output escaping",5,"2026-03-16T19:55:58.786Z",{"wat":984,"direct":994},{"assetPaths":985,"generatorPatterns":989,"scriptPaths":990,"versionParams":991},[986,987,988],"\u002Fwp-content\u002Fplugins\u002Fip-blocker-lite\u002Fassets\u002Fcss\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Fip-blocker-lite\u002Fassets\u002Fjs\u002Fscripts.js","\u002Fwp-content\u002Fplugins\u002Fip-blocker-lite\u002Fassets\u002Fjs\u002Fip-blocker-lite-admin.js",[],[987,988],[992,993],"ip-blocker-lite\u002Fstyle.css?ver=","ip-blocker-lite\u002Fscript.js?ver=",{"cssClasses":995,"htmlComments":997,"htmlAttributes":1000,"restEndpoints":1003,"jsGlobals":1004,"shortcodeOutput":1006},[996],"ipcbl-ip-blocker-lite-settings",[998,999],"\u003C!-- IP & Country Blocker Lite Settings Page -->","\u003C!-- IP & Country Blocker Lite Admin Scripts -->",[1001,1002],"data-plugin-name=\"IP & Country Blocker Lite\"","data-plugin-version=\"3.0.0\"",[],[1005],"ip_blocker_lite_admin_ajax_object",[]]