[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0zFP-WzphMFGljtNRisrPJEgK3fJ90pm8lRtvHLCQLY":3,"$fSK4qOeZLD4Y1JEuskvDeMK64R1m5rqtvQKY-e4di5Sk":126,"$f2NhWWR3mYSlNBQqWz2a3GwR17INOFZRHYL2D5GrKIqM":131},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":27,"fingerprints":27},"lockora-security-audit","Lockora Security Audit","0.2.0","Guido Schad","https:\u002F\u002Fprofiles.wordpress.org\u002Fcmdgw\u002F","\u003Cp>Lockora Security Audit helps site owners and agencies review a WordPress site’s security posture from the admin area.\u003C\u002Fp>\n\u003Cp>Current prototype features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Manual security scans.\u003C\u002Fli>\n\u003Cli>Weighted security score out of 100.\u003C\u002Fli>\n\u003Cli>WordPress core file integrity checks using official checksums.\u003C\u002Fli>\n\u003Cli>WordPress authentication key and salt checks, with an explicit action to generate missing salts.\u003C\u002Fli>\n\u003Cli>Must-use plugin directory presence checks.\u003C\u002Fli>\n\u003Cli>PHP version status using WordPress.org Serve Happy data.\u003C\u002Fli>\n\u003Cli>HTTPS and HTTP security header checks.\u003C\u002Fli>\n\u003Cli>WordPress core, plugin, and theme update posture checks.\u003C\u002Fli>\n\u003Cli>Administrator account posture checks for default usernames, excess admins, inactive admins, user ID 1 exposure, and an admin username\u002Femail inventory.\u003C\u002Fli>\n\u003Cli>Public exposure checks: debug.log and readme.html reachability, uploads directory listing, PHP execution inside uploads, and author archive user enumeration.\u003C\u002Fli>\n\u003Cli>SSL certificate expiry check, database table prefix check, automatic update posture check, and detection of login protection \u002F two-factor plugins.\u003C\u002Fli>\n\u003Cli>Site Health integration: scan summary plus key configuration checks appear under Tools > Site Health > Status.\u003C\u002Fli>\n\u003Cli>WP-CLI support: \u003Ccode>wp lockora scan\u003C\u002Fcode> and \u003Ccode>wp lockora report\u003C\u002Fcode>, with \u003Ccode>--format=json\u003C\u002Fcode> and a \u003Ccode>--strict\u003C\u002Fcode> flag for CI pipelines.\u003C\u002Fli>\n\u003Cli>Optional known vulnerability matching with a configured Wordfence Intelligence API key.\u003C\u002Fli>\n\u003Cli>Optional AI client reports on WordPress 7.0+ when the site’s AI Connector is configured.\u003C\u002Fli>\n\u003Cli>Reversible hardening toggles for XML-RPC, REST user routes, generator tag output, and basic security headers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Lockora Security Audit may connect to external services only when the administrator runs a scan or generates an AI client report.\u003C\u002Fp>\n\u003Cp>During a scan the plugin also sends HTTP requests to the site’s own public URL (loopback requests) to inspect response headers, debug.log and readme.html reachability, uploads directory behavior, and author archive redirects, and it opens a TLS connection to the site’s own hostname to read the SSL certificate expiry date. These requests stay within the site being scanned and send no data to third parties.\u003C\u002Fp>\n\u003Cp>WordPress.org APIs:\u003Cbr \u002F>\n* Used for WordPress core checksums, PHP version support status, and WordPress core\u002Fplugin\u002Ftheme update data.\u003Cbr \u002F>\n* Data sent: the site’s WordPress version and locale for core checksums and PHP compatibility; WordPress itself may send installed plugin and theme slugs\u002Fversions to WordPress.org when update data is refreshed.\u003Cbr \u002F>\n* WordPress.org terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms\u002F\u003Cbr \u002F>\n* WordPress.org privacy policy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>Wordfence Intelligence:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when a Wordfence Intelligence API key is configured and an administrator runs a scan that includes vulnerability matching.\u003Cbr \u002F>\n* Used to retrieve vulnerability data and match it locally against installed WordPress core, plugin, and theme versions.\u003Cbr \u002F>\n* Data sent: the configured Wordfence Intelligence API key is sent in an Authorization header when requesting the vulnerability feed. Installed software details are not sent by this plugin to the Wordfence Intelligence endpoint; matching is performed locally after the feed is retrieved.\u003Cbr \u002F>\n* Wordfence Intelligence terms: https:\u002F\u002Fwww.wordfence.com\u002Fwordfence-intelligence-terms-and-conditions\u002F\u003Cbr \u002F>\n* Wordfence privacy policy: https:\u002F\u002Fwww.wordfence.com\u002Fprivacy-policy\u002F\u003C\u002Fp>\n\u003Cp>WordPress AI Client \u002F Connectors:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when the administrator clicks Generate Client Report.\u003Cbr \u002F>\n* Data sent: sanitized scan findings, score, counts, and recommendations needed to generate a client-facing report. The plugin is designed not to send passwords, salts, API keys, raw logs, full user lists, or file contents.\u003Cbr \u002F>\n* The configured AI provider is controlled by the site owner’s WordPress Connector settings.\u003Cbr \u002F>\n* Terms and privacy policy: these depend on the AI provider configured by the site owner in WordPress. Site owners should review the selected provider’s terms and privacy policy before enabling AI reports.\u003C\u002Fp>\n","Lockora Security Audit checks WordPress security posture, hardening, core integrity, vulnerabilities, and optional AI reports.",100,511,3,"2026-07-12T20:50:00.000Z","7.0.2","6.0","7.4",[19,20,21,22,23],"ai","hardening","security","site-health","vulnerability-scanner","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flockora-security-audit.0.2.0.zip",0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":11,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"cmdgw",1,30,94,"2026-08-26T01:25:08.166Z",[38,62,78,94,112],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":49,"last_updated":50,"tested_up_to":15,"requires_at_least":51,"requires_php":52,"tags":53,"homepage":57,"download_link":58,"security_score":59,"vuln_count":60,"unpatched_count":26,"last_vuln_date":61,"fetched_at":28},"sitelock","SiteLock Security – WP Hardening, Login Security & Malware Scans","5.1.2","SiteLock","https:\u002F\u002Fprofiles.wordpress.org\u002Fsitelocksecurity\u002F","\u003Cblockquote>\n\u003Cp>\u003Cstrong>🌟 Completely redesigned in Version 5.0 — now even stronger with 2FA in 5.1 🌟\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The SiteLock WordPress plugin was recently rebuilt with three goals: make it faster, make it clearer and move the heavy work to the cloud. We built a cloudfirst architecture, modernized UI, expanded security controls and stripped out everything that didn’t need to be there. Our latest 5.1 release builds on that foundation with TwoFactor Authentication (2FA) to strengthen login security and give you tighter control over access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>The big changes:\u003C\u002Fstrong>\u003Cbr \u002F>\n  – 🔒 Enhanced WordPress-specific hardening and login security controls\u003Cbr \u002F>\n  – ☁️ Cloud-powered scanning architecture for zero performance impact\u003Cbr \u002F>\n  – 🩺 New Site Health interface that shows you what matters in one view\u003Cbr \u002F>\n  – ⚡ Streamlined controls (fewer clicks to get protected)\u003Cbr \u002F>\n  – ✨ Modern codebase built for the WordPress you’re actually using today\u003Cbr \u002F>\n  – 🔢 Two-Factor Authentication (2FA) now available for stronger login protection\u003C\u002Fp>\n\u003Cp>If you used the old plugin: this is a different tool. If you’re new: you’re starting with the cleanest, fastest version of the plugin.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>Your website deserves protection that’s simple, fast and built for WordPress. SiteLock WordPress Security focuses on the everyday controls that matter most and helps you establish a secure baseline in minutes — WordPress-specific hardening, login protection with Two-Factor Authentication (2FA) and a clear Site Health dashboard that keeps you in control without slowing your site down. It’s lightweight, action-first protection that complements your host defenses: essential safeguards run inside WordPress while deeper checks happen securely in the SiteLock cloud. Skip heavy on-server scans and alert fatigue — run on-demand checks when you need extra assurance, so you can ship updates with confidence.\u003C\u002Fp>\n\u003Ch4>Security that grows with you\u003C\u002Fh4>\n\u003Cp>Our goal is straightforward: maintain a strong baseline with minimal overhead while giving you clear visibility and room to grow as your needs evolve.\u003Cbr \u002F>\nAnd because security is never static, this plugin keeps pace. Two-Factor Authentication (2FA) is now available to strengthen login security with an extra layer of protection.\u003C\u002Fp>\n\u003Ch4>Commercial plugin\u003C\u002Fh4>\n\u003Cp>This plugin is free but offers additional paid commercial upgrades or support.\u003C\u002Fp>\n\u003Ch3>What’s included\u003C\u002Fh3>\n\u003Ch4>WordPress Hardening: Cut common attack paths in just a few clicks\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Disable directory listing\u003C\u002Fli>\n\u003Cli>Restrict PHP execution in upload folders\u003C\u002Fli>\n\u003Cli>Limit unsafe script types\u003C\u002Fli>\n\u003Cli>Force strong configuration defaults to close risky gaps\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>All options are toggle-based and reversible — safe to enable, easy to test and lightweight on performance.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch4>Login Security: Protect what matters most — your access\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong>: Add a second layer of verification to protect admin access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-force defense\u003C\u002Fstrong>: Blocks repeated failed logins and temporarily locks abusive IPs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password policy prompts\u003C\u002Fstrong>: Encourage stronger credentials without breaking workflows\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session timeouts\u003C\u002Fstrong>: Automatically end idle sessions to prevent account hijacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity awareness\u003C\u002Fstrong>: View recent logins and admin changes in the \u003Cstrong>Activity Log\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Site Health & Cloud Checks: Clarity without noise\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site Health Dashboard\u003C\u002Fstrong>: Surface key signals in one view — WordPress hardening status, last scan timestamp and actionable indicators\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud Checks\u003C\u002Fstrong>: Connect your free SiteLock account to enable recurring off-server checks (Webpage Scan, SSL Verification, Email Reputation and more)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan Now\u003C\u002Fstrong>: Run on-demand checks after updates or changes for instant assurance — no heavy, always-on local scanners\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity Log\u003C\u002Fstrong>: Track what’s happening across your WordPress admin. See admin\u002Flogin events at a glance making it easy to spot anomalies early and keep accountability clear\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Choose SiteLock WordPress Security?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Lightweight by design\u003C\u002Fstrong>: All high-impact protections, no unnecessary load\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real visibility\u003C\u002Fstrong>: Know your security posture in seconds with Site Health\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud-powered assurance\u003C\u002Fstrong>: Checks run off-server, protecting performance\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible setup\u003C\u002Fstrong>: Use standalone or connect a SiteLock account for added layers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Strong login protection\u003C\u002Fstrong>: Two-Factor Authentication (2FA) alongside brute-force defense and session controls\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trusted heritage\u003C\u002Fstrong>: From the global leader in SMB website security backed by continuous innovation and research\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Aligned to WordPress\u003C\u002Fstrong>: Designed to stay out of your way and keep performance priorities intact\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who It’s For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Small businesses & startups\u003C\u002Fli>\n\u003Cli>Portfolio & personal brand sites\u003C\u002Fli>\n\u003Cli>WooCommerce shops & small e-commerce\u003C\u002Fli>\n\u003Cli>Agencies & website maintenance services\u003C\u002Fli>\n\u003Cli>Freelance developers & web designers\u003C\u002Fli>\n\u003Cli>Bloggers, creators & publishers\u003C\u002Fli>\n\u003Cli>Community & membership sites\u003C\u002Fli>\n\u003Cli>Nonprofits & educational sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>If you manage a WordPress website, SiteLock gives you confidence and control whether you run one site or hundreds.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch4>Can I Fix an Already-Infected Site with This Plugin?\u003C\u002Fh4>\n\u003Cp>The plugin focuses on prevention, posture and visibility — not full malware removal. It isn’t designed to fully clean up sites that were infected before it was active.\u003Cbr \u002F>\nIf your site is already compromised, act quickly, we recommend:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Restoring from a clean backup if available\u003C\u002Fli>\n\u003Cli>Remove malicious files manually or with professional help\u003C\u002Fli>\n\u003Cli>For urgent assistance, consider \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fproducts\u002Ffix-hacked-site\u002F\" rel=\"nofollow ugc\">SiteLock 911 – Emergency Malware Removal\u003C\u002Fa> for rapid cleanup\u003C\u002Fli>\n\u003Cli>For ongoing defense, consider \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fpricing\u002F\" rel=\"nofollow ugc\">choosing a comprehensive SiteLock plan\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Don’t Know Where To Start? Try This\u003C\u002Fh4>\n\u003Cp>Here are common first moves teams take with SiteLock. Order isn’t enforced — choose what fits your site and workflow:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enable WordPress hardening that matches your hosting and theme setup\u003C\u002Fli>\n\u003Cli>Turn on Login Security controls: brute-force lockouts, session timeouts, and password-hygiene prompts\u003C\u002Fli>\n\u003Cli>Connect a free SiteLock account, then use Scan Now to run an on-demand check after plugin\u002Ftheme updates\u003C\u002Fli>\n\u003Cli>Review the Activity Log after major changes to spot unexpected admin\u002Flogin events quickly\u003Cbr \u002F>\nMake one change at a time, validate and roll back any toggle that conflicts with your stack.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Need Help with Setup or Fixes?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Visit \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fhelp-center\u002F?topics=wordpress-plugin\" rel=\"nofollow ugc\">Help Center – WordPress\u003C\u002Fa> for plugin specific help\u003C\u002Fli>\n\u003Cli>For broader topics explore the \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fhelp-center\u002F\" rel=\"nofollow ugc\">SiteLock Help Center\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security\u003C\u002Fh4>\n\u003Cp>Protecting our customers and systems is a top priority, and we take security very seriously. If you believe you’ve found a security vulnerability in the SiteLock WordPress plugin, please let us know at vuln-reporting@sitelock.com before sharing any details publicly.\u003C\u002Fp>\n","Free, lightweight WordPress security. Harden your site with login protection & 2FA, see Site Health clearly and run on-demand checks—setup in minutes.",1000,53167,68,14,"2026-06-23T18:46:00.000Z","5.6","8.0",[54,55,22,23,56],"login-security","malware-scan","wordpress-security","https:\u002F\u002Fwww.sitelock.com\u002Fwordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsitelock.5.1.2.zip",98,2,"2026-01-25 00:00:00",{"slug":63,"name":64,"version":65,"author":66,"author_profile":67,"description":68,"short_description":69,"active_installs":70,"downloaded":71,"rating":26,"num_ratings":26,"last_updated":72,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":73,"homepage":24,"download_link":77,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"cca-site-health-advisor","CCA Site Health Advisor","0.2.5","chriscourtassociates","https:\u002F\u002Fprofiles.wordpress.org\u002Fchriscourtassociates\u002F","\u003Cp>CCA Site Health Advisor helps WordPress website owners understand common maintenance, security, SEO, performance and plugin health issues without unnecessary jargon.\u003C\u002Fp>\n\u003Cp>It is designed for DIY website owners, small businesses and freelancers who want a clear overview of their site health without being overwhelmed by technical warnings.\u003C\u002Fp>\n\u003Cp>CCA Site Health Advisor scans for common issues, explains why they matter, and suggests practical next steps in plain English.\u003C\u002Fp>\n\u003Cp>Current features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Site Health Score\u003C\u002Fli>\n\u003Cli>Priority issue summaries\u003C\u002Fli>\n\u003Cli>Full Report with clear explanations\u003C\u002Fli>\n\u003Cli>Plugin Health checks\u003C\u002Fli>\n\u003Cli>Inactive plugin detection\u003C\u002Fli>\n\u003Cli>Outdated plugin and theme checks\u003C\u002Fli>\n\u003Cli>PHP version check\u003C\u002Fli>\n\u003Cli>WordPress version check\u003C\u002Fli>\n\u003Cli>Debug mode check\u003C\u002Fli>\n\u003Cli>File editing check\u003C\u002Fli>\n\u003Cli>Backup plugin detection\u003C\u002Fli>\n\u003Cli>SEO plugin detection\u003C\u002Fli>\n\u003Cli>Caching plugin detection\u003C\u002Fli>\n\u003Cli>Search engine visibility check\u003C\u002Fli>\n\u003Cli>Admin username checks\u003C\u002Fli>\n\u003Cli>Default content detection\u003C\u002Fli>\n\u003Cli>Plugin complexity and overlap guidance\u003C\u002Fli>\n\u003Cli>Ignored recommendation controls\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>CCA Site Health Advisor is advisory. It does not automatically delete plugins, change settings or make destructive changes to your website.\u003C\u002Fp>\n","Simple WordPress health checks with clear explanations and practical recommendations for DIY website owners.",10,188,"2026-06-01T13:02:00.000Z",[74,75,21,22,76],"maintenance","plugin-health","wordpress-health","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcca-site-health-advisor.0.2.5.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":70,"downloaded":86,"rating":11,"num_ratings":33,"last_updated":87,"tested_up_to":15,"requires_at_least":88,"requires_php":52,"tags":89,"homepage":92,"download_link":93,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"site-cliniq","Site CliniQ","1.0.4","Bilal Mahmood","https:\u002F\u002Fprofiles.wordpress.org\u002Fbilalmahmooddev\u002F","\u003Cp>\u003Cstrong>Site CliniQ\u003C\u002Fstrong> scans your WordPress site for PHP errors, SEO issues, oversized images, missing alt tags, broken links, plugin health issues, and more — then optionally uses AI to explain what is wrong and exactly how to fix it.\u003C\u002Fp>\n\u003Cp>No more raw error logs. No more cryptic numbers. Just plain English.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Core Features (Free)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>AI Error Diagnosis\u003C\u002Fstrong> — Reads your PHP error log and explains each error in plain English with a step-by-step fix (requires your own Claude API key).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site Health Score\u003C\u002Fstrong> — A–F grade based on PHP version, memory limit, WP version, SSL, debug mode, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Health Checker\u003C\u002Fstrong> — Flags plugins not updated in 2+ years or not tested with your current WordPress version.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Bloat Detector\u003C\u002Fstrong> — Ranks every plugin by JS\u002FCSS payload so you know which one is slowing your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Update Risk Scorer\u003C\u002Fstrong> — AI reads each plugin changelog and scores the update Safe \u002F Caution \u002F High Risk before you click Update.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Image Size Audit\u003C\u002Fstrong> — Finds every image over 500 KB and shows which pages use it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Alt Tag Auditor\u003C\u002Fstrong> — Scans Media Library and post content for missing alt text. Edit and save alt text directly from the plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Checks\u003C\u002Fstrong> — Site-wide scan for missing meta descriptions, H1 issues, noindex, thin content, duplicate titles, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Broken Link Report\u003C\u002Fstrong> — Crawls up to 100 published URLs and flags 404s, 5xx errors, and long redirect chains.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Report\u003C\u002Fstrong> — Send a formatted health report to your admin email with one click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Source Code\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The full source code including React source files and build tools is available at:\u003Cbr \u002F>\nhttps:\u002F\u002Fbilalmahmood.dev\u002Fprojects\u002Fsite-cliniq\u003C\u002Fp>\n\u003Cp>Build instructions: run \u003Ccode>npm install && npm run build\u003C\u002Fcode> inside the plugin folder.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>External Services\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin connects to the following external services:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Anthropic Claude API\u003C\u002Fstrong> (api.anthropic.com) — Used to generate plain English explanations and fix instructions for detected issues. Optional — the plugin works without it. Requires the user to provide their own API key in Settings. \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fconsumer-terms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress.org Plugins API\u003C\u002Fstrong> (api.wordpress.org) — Used to fetch plugin info for update risk scoring and plugin health checks. No API key required. \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\" rel=\"ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress.org Core API\u003C\u002Fstrong> (api.wordpress.org) — Used to check the latest WordPress version. No API key required. \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\" rel=\"ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Scans your WordPress site and explains every problem in plain English — PHP errors, SEO issues, broken links, oversized images, and more.",427,"2026-07-20T21:48:00.000Z","6.3",[19,90,21,91,22],"performance","seo","https:\u002F\u002Fbilalmahmood.dev\u002Fprojects\u002Fsite-cliniq","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsite-cliniq.1.0.4.zip",{"slug":95,"name":96,"version":97,"author":98,"author_profile":99,"description":100,"short_description":101,"active_installs":26,"downloaded":102,"rating":26,"num_ratings":26,"last_updated":103,"tested_up_to":104,"requires_at_least":105,"requires_php":17,"tags":106,"homepage":109,"download_link":110,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":111},"boonrisk-site-security-check-report","BoonRisk – Site Security Check & Report","1.0.2","Boon Band","https:\u002F\u002Fprofiles.wordpress.org\u002Fboonband\u002F","\u003Cp>BoonRisk gives you a \u003Cstrong>clear security and readiness report\u003C\u002Fstrong> for your WordPress site. See exactly what security risks exist, why they matter, and what to do about them — all explained in plain language.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Safe & Read-Only:\u003C\u002Fstrong> This plugin only reads your site configuration. It does not scan files, block traffic, or make any changes to your WordPress installation.\u003C\u002Fp>\n\u003Ch4>What You Get\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security Check Report\u003C\u002Fstrong> — See your site’s security status: PHP version, WordPress updates, user settings, HTTPS, and 30+ configuration checks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clear Explanations\u003C\u002Fstrong> — Every finding explains “why this matters” and “what to do about it” in plain language\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prioritized Risks\u003C\u002Fstrong> — Top risks ranked by impact so you know what to fix first\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Printable Report\u003C\u002Fstrong> — Professional HTML report you can view, print, or share directly from WordPress admin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What This Plugin Does NOT Do (100% Safe)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No file scanning\u003C\u002Fstrong> — Does not scan your files or look for malware\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No traffic blocking\u003C\u002Fstrong> — Does not act as a firewall or block visitors\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No site changes\u003C\u002Fstrong> — Does not modify settings, files, or database\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No active testing\u003C\u002Fstrong> — Does not simulate attacks or run security scans\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read-only analysis\u003C\u002Fstrong> — Only reads your configuration, never writes or changes anything\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Is It For?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> — Understand your security risks without technical expertise\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Freelancers & agencies\u003C\u002Fstrong> — Generate client-ready reports in minutes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developers\u003C\u002Fstrong> — Quick baseline check before or after deployments\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Teams\u003C\u002Fstrong> — Consistent security reporting across multiple WordPress sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Free Security Check (No Account Required)\u003C\u002Fh4>\n\u003Cp>Run a complete security and readiness check instantly — 100% local, no data sent anywhere:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Overall Risk Level\u003C\u002Fstrong> — Clear Low\u002FMedium\u002FHigh rating with explanation of what it means\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Top Risks First\u003C\u002Fstrong> — See your biggest security issues ranked by impact\u003C\u002Fli>\n\u003Cli>\u003Cstrong>30+ Configuration Checks\u003C\u002Fstrong> — WordPress updates, PHP version, HTTPS, user permissions, backups, 2FA, debug mode, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action Plan\u003C\u002Fstrong> — Every issue includes “why it matters” and “how to fix it”\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional Report\u003C\u002Fstrong> — Printable HTML report you can view in WordPress admin or share with your team\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What you’ll learn:\u003C\u002Fstrong> “Is my site at risk?” and “What should I fix first?”\u003C\u002Fp>\n\u003Cp>\u003Cstrong>100% Private:\u003C\u002Fstrong> All checks run on your server. Nothing is sent externally. No account or email required.\u003C\u002Fp>\n\u003Ch4>Optional: Web Dashboard\u003C\u002Fh4>\n\u003Cp>Connect the plugin to the \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">BoonRisk web dashboard\u003C\u002Fa> for additional capabilities (optional, requires free account):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002Fscanner\u002F\" rel=\"nofollow ugc\">Surface Scan\u003C\u002Fa>\u003C\u002Fstrong> — External scan of your site’s public-facing security headers, SSL configuration, and exposed services\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong> — Known CVEs matched to your installed plugins and themes with severity ratings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Continuous Monitoring\u003C\u002Fstrong> — Automatic daily checks with alerts when your security posture changes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Track Over Time\u003C\u002Fstrong> — See how your site security improves (or changes) month over month\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PDF Reports\u003C\u002Fstrong> — Download professional reports to share with clients or management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> The local security check is fully functional on its own. The web dashboard is completely optional.\u003C\u002Fp>\n\u003Cp>Learn more at \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">boonrisk.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Ch4>Local Assessment (Default)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate the plugin\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>BoonRisk\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Local Assessment\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Run Assessment Now\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>View your Security Posture Summary and Top Risks\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>View Full Report\u003C\u002Fstrong> for a printable HTML report\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>All analysis happens on your server. Nothing is sent externally.\u003C\u002Fp>\n\u003Ch4>Web Dashboard (Optional)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Create a free account at \u003Ca href=\"https:\u002F\u002Fboonrisk.com\u002F\" rel=\"nofollow ugc\">boonrisk.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>BoonRisk\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Connect (Optional)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Enter your API key\u003C\u002Fli>\n\u003Cli>Send your assessment to the dashboard for vulnerability intelligence, surface scan, and monitoring\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>External API calls only happen when you explicitly request them.\u003C\u002Fp>\n\u003Ch3>Data Usage\u003C\u002Fh3>\n\u003Ch4>Local Assessment\u003C\u002Fh4>\n\u003Cp>In local mode, \u003Cstrong>no data is sent externally\u003C\u002Fstrong>. All checks run inside WordPress.\u003C\u002Fp>\n\u003Ch4>Web Dashboard (Optional)\u003C\u002Fh4>\n\u003Cp>When you send data to the dashboard, the following is transmitted:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP and WordPress versions\u003C\u002Fli>\n\u003Cli>Active plugin and theme names\u002Fversions\u003C\u002Fli>\n\u003Cli>Configuration flags (debug mode, file editor status, etc.)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>What you get in return:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Known vulnerability data for your installed plugins and themes\u003C\u002Fli>\n\u003Cli>Surface scan results for public-facing security\u003C\u002Fli>\n\u003Cli>Severity context for identified risks\u003C\u002Fli>\n\u003Cli>Historical trend data and monitoring alerts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What is never collected:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>User data or personal information\u003C\u002Fli>\n\u003Cli>Passwords or credentials\u003C\u002Fli>\n\u003Cli>Post\u002Fpage content\u003C\u002Fli>\n\u003Cli>Database contents\u003C\u002Fli>\n\u003Cli>File contents\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Data is sent \u003Cstrong>only when you click\u003C\u002Fstrong> Send to Dashboard or enable automatic daily sync. No personal data is collected.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Read our full privacy policy at https:\u002F\u002Fboonrisk.com\u002Fprivacy\u003C\u002Fp>\n","Security posture report for WordPress — 30+ checks, prioritized risks, and a printable report. Get a clear picture in minutes.",171,"2026-02-16T17:38:00.000Z","6.9.4","5.0",[107,20,21,22,108],"audit","vulnerability","https:\u002F\u002Fboonrisk.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fboonrisk-site-security-check-report.1.0.2.zip","2026-04-16T10:56:18.058Z",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":26,"downloaded":120,"rating":26,"num_ratings":26,"last_updated":121,"tested_up_to":15,"requires_at_least":122,"requires_php":17,"tags":123,"homepage":24,"download_link":125,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"cybernote-security-checker","CyberNote Security Checker","1.0.0","teeeda1129","https:\u002F\u002Fprofiles.wordpress.org\u002Fteeeda1129\u002F","\u003Cp>CyberNote Security Checker is a lightweight plugin that audits your WordPress site’s security posture without sending any data to external servers.\u003C\u002Fp>\n\u003Cp>Many security plugins are powerful but heavy, English-only, and full of technical jargon. CyberNote Security Checker takes the opposite approach: it targets Japanese individual bloggers and small business owners who need to understand exactly what to do — delivered quickly and without specialist knowledge.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>12 diagnostic checks. Zero external requests.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A widget appears on the WordPress dashboard showing results in three levels: good (no action needed) \u002F attention (improvement recommended) \u002F recommended (priority action required). Each item includes a plain-Japanese explanation of the risk and step-by-step remediation guidance.\u003C\u002Fp>\n\u003Ch4>Category A: Version Freshness (3 checks)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>WordPress core\u003C\u002Fstrong> — Detects whether security-only maintenance releases are unapplied. Distinguishes urgency between security patches and feature updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP version\u003C\u002Fstrong> — Evaluated against official PHP support status. End-of-life versions flagged as “priority action”; security-only branches as “attention”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin and theme updates\u003C\u002Fstrong> — Displays the count and names of pending updates. A direct link opens the standard WordPress update screen; the plugin never performs updates itself.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Category B: Hardening Settings (9 checks)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Debug display\u003C\u002Fstrong> — WP_DEBUG with screen output on a production site is flagged as “priority action”; log-only mode as “attention”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File editing\u003C\u002Fstrong> — If the theme and plugin code editor is enabled in the admin panel, flagged as “priority action”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin username\u003C\u002Fstrong> — If a user named admin or administrator exists, flagged as “attention” (changing it carries migration risk, so no urgent push).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HTTPS\u003C\u002Fstrong> — Sites running on plain HTTP are flagged as “priority action”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database table prefix\u003C\u002Fstrong> — Default wp_ prefix flagged as “attention” (live-site changes carry risk, so no urgent push).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC\u003C\u002Fstrong> — Enabled XML-RPC is flagged as “attention”; use-case guidance included before recommending disablement.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API user enumeration\u003C\u002Fstrong> — If anonymous requests to \u002Fwp\u002Fv2\u002Fusers return user data, flagged as “attention”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security keys (salts)\u003C\u002Fstrong> — Checks whether the wp-config.php authentication unique keys and salts are set and not left at the default placeholder. Missing or default keys are flagged as “priority action” (login cookies could be forged). Key values are never read out or displayed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unused plugins and themes\u003C\u002Fstrong> — Inactive plugins and unused themes still ship files on the server that can be exploited if vulnerable. Their presence is flagged as “attention” with removal guidance (keeping one fallback theme is fine).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Design Principles\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Read-only\u003C\u002Fstrong> — The plugin only presents diagnostic results. It never automatically changes site settings or files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external requests\u003C\u002Fstrong> — Every check reads WordPress built-in APIs and site configuration only. Nothing leaves your server.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight\u003C\u002Fstrong> — No real-time file scanning, no custom WAF, no resident processes. Diagnostics run once when the admin page loads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plain language\u003C\u002Fstrong> — Technical terms are avoided. Each check explains why it matters and what to do in everyday language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Vulnerability alerts (separate external service)\u003C\u002Fh4>\n\u003Cp>This plugin is free and fully functional on its own. Matching your installed plugins and themes against external vulnerability databases (CVE) requires server-side processing that cannot be done locally, so it is offered separately as an external service called CyberNote, not bundled in this plugin. See https:\u002F\u002Fwww.cybernote.click\u002Fwp-security-checker-guide\u002F for details.\u003C\u002Fp>\n","Diagnoses WordPress security settings and version status, presenting plain-language improvement steps in Japanese. No external requests. Lightweight.",84,"2026-07-03T12:26:00.000Z","5.9",[107,124,20,74,21],"diagnostic","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcybernote-security-checker.1.0.0.zip",{"error":127,"url":128,"statusCode":129,"statusMessage":130,"message":130},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Flockora-security-audit\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":132,"versions":133},4,[134,140,147,154],{"version":6,"download_url":25,"svn_tag_url":135,"released_at":27,"has_diff":136,"diff_files_changed":137,"diff_lines":27,"trac_diff_url":138,"vulnerabilities":139,"is_current":127},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Flockora-security-audit\u002Ftags\u002F0.2.0\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Flockora-security-audit%2Ftags%2F0.1.2&new_path=%2Flockora-security-audit%2Ftags%2F0.2.0",[],{"version":141,"download_url":142,"svn_tag_url":143,"released_at":27,"has_diff":136,"diff_files_changed":144,"diff_lines":27,"trac_diff_url":145,"vulnerabilities":146,"is_current":136},"0.1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flockora-security-audit.0.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Flockora-security-audit\u002Ftags\u002F0.1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Flockora-security-audit%2Ftags%2F0.1.1&new_path=%2Flockora-security-audit%2Ftags%2F0.1.2",[],{"version":148,"download_url":149,"svn_tag_url":150,"released_at":27,"has_diff":136,"diff_files_changed":151,"diff_lines":27,"trac_diff_url":152,"vulnerabilities":153,"is_current":136},"0.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flockora-security-audit.0.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Flockora-security-audit\u002Ftags\u002F0.1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Flockora-security-audit%2Ftags%2F0.1.0&new_path=%2Flockora-security-audit%2Ftags%2F0.1.1",[],{"version":155,"download_url":156,"svn_tag_url":157,"released_at":27,"has_diff":136,"diff_files_changed":158,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":159,"is_current":136},"0.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flockora-security-audit.0.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Flockora-security-audit\u002Ftags\u002F0.1.0\u002F",[],[]]