[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhZUVcZbSMTu6YRoHUHqaynk8_Kv8YDgKf-WwHyC0Tfc":3,"$f3DGNQgXfSHD6mLj20I6_Ya6dzm_uPqpNT9Cp_Hgo1MM":115,"$flToaY9l-HlAVFo-NxpkDy3BlaKytpPl39ypgAhTbzqk":120},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":22,"download_link":23,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26,"discovery_status":27,"vulnerabilities":28,"developer":29,"crawl_stats":25,"alternatives":34,"analysis":25,"fingerprints":25},"janric-simple-security-hardening","Janric Simple Security Hardening","1.0.0","keithlunt","https:\u002F\u002Fprofiles.wordpress.org\u002Fkeithlunt\u002F","\u003Cp>A lightweight plugin that disables XML-RPC, restricts the REST API to logged-in users, and hides the WordPress version number\u003C\u002Fp>\n","A lightweight plugin to disable XML-RPC, restrict the REST API, and hide the WordPress version.",0,118,"2026-05-20T14:01:00.000Z","6.9.5","5.0","7.4",[18,19,20,21],"hardening","rest-api","security","xml-rpc","https:\u002F\u002Fjanric.co.uk\u002Fjanric_simple_hardening.php","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fjanric-simple-security-hardening.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":30,"total_installs":11,"avg_security_score":24,"avg_patch_time_days":31,"trust_score":32,"computed_at":33},2,30,94,"2026-08-29T02:56:12.726Z",[35,46,63,81,99],{"slug":36,"name":37,"version":6,"author":7,"author_profile":8,"description":38,"short_description":39,"active_installs":11,"downloaded":40,"rating":11,"num_ratings":11,"last_updated":41,"tested_up_to":42,"requires_at_least":15,"requires_php":16,"tags":43,"homepage":44,"download_link":45,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"janric-simple-attack-monitor","Janric Simple Attack Monitor","\u003Cp>Most security plugins try to do everything — firewall, blocking, malware scanning, email alerts — and end up bloated, slow, and full of upsells. Attack Monitor does one thing: it watches your site for common attack patterns and quietly logs them, so you always know what’s being thrown at your site.\u003Cbr \u002F>\nWhat it detects\u003C\u002Fp>\n\u003Cp>Brute force login attempts\u003Cbr \u002F>\nXML-RPC abuse (including system.multicall floods)\u003Cbr \u002F>\nUser enumeration via ?author= and the REST API\u003Cbr \u002F>\nAdmin area probing by unauthenticated visitors\u003Cbr \u002F>\nPath and plugin scanning (phpinfo.php, .env, phpmyadmin, wp-config.php and more)\u003Cbr \u002F>\nSQL injection attempts in URLs and POST data\u003Cbr \u002F>\nXSS attempts in URLs and POST data\u003Cbr \u002F>\nComment flooding\u003C\u002Fp>\n\u003Cp>What you get\u003C\u002Fp>\n\u003Cp>A dashboard widget showing this week’s attacks by category at a glance\u003Cbr \u002F>\nA full log page with day \u002F week \u002F 30-day \u002F all-time views\u003Cbr \u002F>\nA bar chart of attack volume over time\u003Cbr \u002F>\nTop attacking IPs ranked by hit count\u003Cbr \u002F>\nFilterable event log with timestamps, IPs, URLs and detail\u003Cbr \u002F>\nSafe IP whitelist — exclude your own monitoring tools, cron jobs or office IP ranges\u003Cbr \u002F>\nCIDR range support (e.g. 192.168.1.0\u002F24) for the whitelist\u003Cbr \u002F>\nA single lightweight database table — nothing else added to your WordPress installation\u003C\u002Fp>\n\u003Cp>Philosophy\u003Cbr \u002F>\nDetection and blocking are separate concerns. This plugin handles detection only, leaving you free to choose how you respond — whether that’s Fail2ban, Cloudflare, a companion blocking plugin, or simply reviewing the data. No firewall rules are added, no requests are blocked or slowed down, and no data is sent anywhere outside your own database.\u003Cbr \u002F>\nIdeal for developers, agencies and site owners who want visibility without handing over control to an all-in-one security suite.\u003C\u002Fp>\n","Lightweight attack detection for WordPress. Logs brute force, XML-RPC abuse, SQL injection, XSS attempts and more. No bloat, no blocking — just data.",87,"2026-06-15T16:11:00.000Z","7.0.2",[18,19,20,21],"https:\u002F\u002Fjanricshield.com\u002Fjanric-attack-monitor.php","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fjanric-simple-attack-monitor.1.0.0.zip",{"slug":47,"name":48,"version":49,"author":50,"author_profile":51,"description":52,"short_description":53,"active_installs":54,"downloaded":55,"rating":11,"num_ratings":11,"last_updated":56,"tested_up_to":14,"requires_at_least":57,"requires_php":16,"tags":58,"homepage":61,"download_link":62,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"ghostgate","GhostGate","1.3.3","codegee0958","https:\u002F\u002Fprofiles.wordpress.org\u002Fcodegee0958\u002F","\u003Cp>\u003Cstrong>GhostGate\u003C\u002Fstrong> is a lightweight yet powerful WordPress security plugin that eliminates the login page as an attack surface. Instead of just defending, it \u003Cstrong>erases the entrance\u003C\u002Fstrong> entirely with dynamic login URLs and multi-layer access verification.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>🔒 Hide your login URL with a custom slug and time-based code\u003C\u002Fli>\n\u003Cli>🔑 Built-in 2FA via email verification\u003C\u002Fli>\n\u003Cli>🚫 Auto-block brute force attacks by IP\u003C\u002Fli>\n\u003Cli>🧱 Disable\u002Flimit unused endpoints like XML-RPC and REST API\u003C\u002Fli>\n\u003Cli>👤 Prevent user enumeration via REST, RSS, and author queries\u003C\u002Fli>\n\u003Cli>🔍 Visualize security status and detect conflicts\u003C\u002Fli>\n\u003Cli>📜 Activity logs with optional file rotation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>GhostGate doesn’t just defend — it disappears.\u003Cbr \u002F>\nInvisible to bots. Intuitive for users.\u003C\u002Fp>\n\u003Cp>👉 \u003Cstrong>Full features \u002F screenshots \u002F pricing \u002F docs\u003C\u002Fstrong>:\u003Cbr \u002F>\nhttps:\u002F\u002Farce-experience.com\u002Fproduct\u002F\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>GhostGate can store the following data locally on your site to provide rate-limiting and security auditing:\u003Cbr \u002F>\n– IP addresses (for temporary throttling \u002F block lists)\u003Cbr \u002F>\n– Timestamps and event metadata (login attempts, REST\u002FXML-RPC hits)\u003Cbr \u002F>\n– Optional log files under \u003Ccode>wp-content\u002Fuploads\u002Fghostgate\u002Flogs\u003C\u002Fcode> (if enabled)\u003C\u002Fp>\n\u003Cp>No data is sent to third-party services.\u003Cbr \u002F>\nSite owners are responsible for informing users\u002Fvisitors where required by local laws. You can clear blocks\u002Flogs from the admin UI or by deleting the log files.\u003C\u002Fp>\n","Invisible, intelligent protection for WordPress. GhostGate hides your login page, blocks bots, and turns your site into a ghost fortress.",20,629,"2026-01-21T00:06:00.000Z","5.8",[59,19,20,60,21],"limit-login-attempts","two-factor-authentication","https:\u002F\u002Farce-experience.com\u002Fproduct\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fghostgate.1.3.3.zip",{"slug":64,"name":65,"version":66,"author":67,"author_profile":68,"description":69,"short_description":70,"active_installs":71,"downloaded":72,"rating":11,"num_ratings":11,"last_updated":73,"tested_up_to":42,"requires_at_least":74,"requires_php":75,"tags":76,"homepage":79,"download_link":80,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"keys-master","Keys Master","2.5.0","Pierre Lannoy","https:\u002F\u002Fprofiles.wordpress.org\u002Fpierrelannoy\u002F","\u003Cp>\u003Cstrong>Keys Master\u003C\u002Fstrong> is a powerful application passwords manager for WordPress with role-based usage control and full analytics reporting about passwords usages. It relies on the “application password” core feature introduced in WordPress 5.6. and add it extra features and controls.\u003C\u002Fp>\n\u003Cp>You can limit usage of application passwords, on a per role basis:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>maximum passwords per user;\u003C\u002Fli>\n\u003Cli>specific usage: none (blocks usage), only authentication and revocation or full management (with password creation).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For each roles defined on your site, you can define a period during which a password can be unused before auto-revocation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Keys Master\u003C\u002Fstrong> can report the following main items and metrics:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>KPIs: authentication success, number, creations and revocations of passwords, adoption and usage rate;\u003C\u002Fli>\n\u003Cli>channels breakdown;\u003C\u002Fli>\n\u003Cli>clients breakdown (requires the free \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fdevice-detector\u002F\" rel=\"ugc\">Device Detector\u003C\u002Fa> plugin);\u003C\u002Fli>\n\u003Cli>countries breakdown (requires the free \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fip-locator\u002F\" rel=\"ugc\">IP Locator\u003C\u002Fa> plugin);\u003C\u002Fli>\n\u003Cli>site breakdowns in multisites environments.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Keys Master\u003C\u002Fstrong> supports a set of WP-CLI commands to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>manage WordPress application passwords (list, create and revoke) – see \u003Ccode>wp help apwd password\u003C\u002Fcode> for details;\u003C\u002Fli>\n\u003Cli>toggle on\u002Foff main settings – see \u003Ccode>wp help apwd settings\u003C\u002Fcode> for details;\u003C\u002Fli>\n\u003Cli>modify operations mode – see \u003Ccode>wp help apwd mode\u003C\u002Fcode> for details;\u003C\u002Fli>\n\u003Cli>display passwords statistics – see \u003Ccode>wp help apwd analytics\u003C\u002Fcode> for details.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For a full help on WP-CLI commands in Keys Master, please \u003Ca href=\"https:\u002F\u002Fperfops.one\u002Fkeys-master-wpcli\" rel=\"nofollow ugc\">read this guide\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>Keys Master\u003C\u002Fstrong> is part of \u003Ca href=\"https:\u002F\u002Fperfops.one\u002F\" rel=\"nofollow ugc\">PerfOps One\u003C\u002Fa>, a suite of free and open source WordPress plugins dedicated to observability and operations performance.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>Keys Master\u003C\u002Fstrong> is a free and open source plugin for WordPress. It integrates many other free and open source works (as-is or modified). Please, see ‘about’ tab in the plugin settings to see the details.\u003C\u002Fp>\n\u003Ch4>Support\u003C\u002Fh4>\n\u003Cp>This plugin is free and provided without warranty of any kind. Use it at your own risk, I’m not responsible for any improper use of this plugin, nor for any damage it might cause to your site. Always backup all your data before installing a new plugin.\u003C\u002Fp>\n\u003Cp>Anyway, I’ll be glad to help you if you encounter issues when using this plugin. Please read carefully the FAQ at the bottom of this page before requesting support.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>This plugin, as any piece of software, is neither compliant nor non-compliant with privacy laws and regulations. It is your responsibility to use it – by activating the corresponding options or services – with respect for the personal data of your users and applicable laws.\u003C\u002Fp>\n\u003Cp>This plugin doesn’t set any cookie in the user’s browser.\u003C\u002Fp>\n\u003Cp>This plugin doesn’t handle personally identifiable information (PII).\u003C\u002Fp>\n\u003Ch4>Donation\u003C\u002Fh4>\n\u003Cp>If you like this plugin or find it useful and want to thank me for the work done, please consider making a donation to \u003Ca href=\"https:\u002F\u002Fwww.laquadrature.net\u002Fen\" rel=\"nofollow ugc\">La Quadrature Du Net\u003C\u002Fa> or the \u003Ca href=\"https:\u002F\u002Fwww.eff.org\u002F\" rel=\"nofollow ugc\">Electronic Frontier Foundation\u003C\u002Fa> which are advocacy groups defending the rights and freedoms of citizens on the Internet. By supporting them, you help the daily actions they perform to defend our fundamental freedoms!\u003C\u002Fp>\n","Powerful application passwords manager for WordPress with role-based usage control and full analytics reporting capabilities.",10,6410,"2026-03-20T08:59:00.000Z","6.4","8.2",[77,78,19,20,21],"application-password","authentication","https:\u002F\u002Fperfops.one\u002Fkeys-master","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkeys-master.2.5.0.zip",{"slug":82,"name":83,"version":6,"author":84,"author_profile":85,"description":86,"short_description":87,"active_installs":11,"downloaded":88,"rating":11,"num_ratings":11,"last_updated":89,"tested_up_to":90,"requires_at_least":91,"requires_php":16,"tags":92,"homepage":95,"download_link":96,"security_score":97,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":98},"pf-secure-toolkit","PF Secure Toolkit","Poet Farmer","https:\u002F\u002Fprofiles.wordpress.org\u002Fpoetfarmer\u002F","\u003Cp>PF Secure Toolkit helps you secure your site by turning off WordPress components you may not need or want exposed.\u003C\u002Fp>\n\u003Cp>Features include:\u003Cbr \u002F>\n* Disable Author Archives (301 redirect + remove users sitemap).\u003Cbr \u002F>\n* Disable Comments site-wide (removes UI, blocks REST, hides existing).\u003Cbr \u002F>\n* Disable WP Emojis (scripts, styles, TinyMCE, email\u002FRSS, CDN prefetch).\u003Cbr \u002F>\n* Disable XML-RPC (removes headers, blocks pingback methods).\u003Cbr \u002F>\n* Quick toggle settings in the admin panel.\u003C\u002Fp>\n","PF Secure Toolkit is a lightweight, modular plugin to harden WordPress by disabling unnecessary features.",297,"2025-08-27T10:54:00.000Z","6.8.5","5.6",[93,94,18,20,21],"comments","emojis","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpf-secure-toolkit.1.0.0.zip",92,"2026-04-16T10:56:18.058Z",{"slug":100,"name":101,"version":102,"author":103,"author_profile":104,"description":105,"short_description":106,"active_installs":11,"downloaded":107,"rating":11,"num_ratings":11,"last_updated":108,"tested_up_to":109,"requires_at_least":57,"requires_php":16,"tags":110,"homepage":95,"download_link":113,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":114},"rest-armor-security","RestArmor Security","2.3","Md. Rakib Ullah","https:\u002F\u002Fprofiles.wordpress.org\u002Frakib417\u002F","\u003Cp>RestArmor Security is a “Plug & Play” security suite that hardens your WordPress site instantly upon activation. No complex setup required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Disable XML-RPC:\u003C\u002Fstrong> Blocks XML-RPC attacks and Pingbacks.\u003Cbr \u002F>\n* \u003Cstrong>Block REST API:\u003C\u002Fstrong> Restricts API access to logged-in users only.\u003Cbr \u002F>\n* \u003Cstrong>Stop User Enumeration:\u003C\u002Fstrong> Blocks bot scans for \u002F?author=1.\u003Cbr \u002F>\n* \u003Cstrong>Hide WP Version:\u003C\u002Fstrong> Removes version number from source code.\u003Cbr \u002F>\n* \u003Cstrong>Admin Indicator:\u003C\u002Fstrong> Shows security status in the admin bar.\u003C\u002Fp>\n","Advanced security suite. Blocks REST API, disables XML-RPC, prevents user enumeration, and secures endpoints.",160,"2026-02-11T12:35:00.000Z","6.9.4",[111,112,19,20,21],"disable-rest-api","protection","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Frest-armor-security.2.3.zip","2026-04-06T09:54:40.288Z",{"error":116,"url":117,"statusCode":118,"statusMessage":119,"message":119},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fjanric-simple-security-hardening\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":121,"versions":122},1,[123],{"version":6,"download_url":23,"svn_tag_url":124,"released_at":25,"has_diff":125,"diff_files_changed":126,"diff_lines":25,"trac_diff_url":25,"vulnerabilities":127,"is_current":116},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fjanric-simple-security-hardening\u002Ftags\u002F1.0.0\u002F",false,[],[]]