[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5lnamrCSin3ZLXrcXUBMk5Q6goXPkJd5LeGAs_NYLyk":3,"$fkNTLsh371JDDgiLpaqNQcACPKLtR7xGuiGkJVTh4-j8":388,"$fh0QaUAH9p5eI_-ECtwBjmWCdnwPd_8ATSbV6HxJ93sQ":392},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":36,"analysis":147,"fingerprints":357},"login-security-with-telegram-alerts","Login Security with Telegram Alerts","1.0.0","gabrielrosca","https:\u002F\u002Fprofiles.wordpress.org\u002Fgabrielrosca\u002F","\u003Cp>Login Security with Telegram Alerts is your comprehensive solution for fortifying WordPress login security and staying informed about critical site activities. It actively combats brute-force attacks, enhances user authentication with multi-factor options, and provides real-time alerts directly to your Telegram. Scalable for any site size, from personal blogs to large enterprises, it ensures your WordPress site remains secure and you’re always in the loop.\u003C\u002Fp>\n\u003Cp>Key Features:\u003Cbr \u002F>\nLogin Security with Telegram Alerts is packed with powerful features designed to give you peace of mind and full control over your site’s access.\u003C\u002Fp>\n\u003Cp>Brute-Force Protection: Automatically blocks suspicious IP addresses after a configurable number of failed login attempts, effectively preventing dictionary attacks and credential stuffing.\u003C\u002Fp>\n\u003Cp>Real-time Telegram Notifications: Receive instant alerts for failed login attempts and successful logins, delivered directly to your chosen Telegram channel, group, or private chat. This provides immediate awareness of critical site events, enabling prompt action.\u003C\u002Fp>\n\u003Cp>Comprehensive Activity Logging: Maintains detailed records of both failed and successful login events, capturing critical information such as IP addresses, usernames, login times, and user agents. This log is invaluable for auditing and identifying suspicious patterns.\u003C\u002Fp>\n\u003Cp>IP Management: Block or unblock IP addresses directly from the Activity Log with one-click actions. Administrators can manually manage IP blacklists and whitelists from the plugin’s settings page.\u003Cbr \u002F>\nWordPress Core Files Integrity Check: Verify that WordPress core files haven’t been tampered with by comparing them against official checksums from WordPress.org.\u003C\u002Fp>\n\u003Cp>File Permissions Management: Automatically check and fix file permissions to match WordPress security standards, ensuring your installation follows best practices.\u003Cbr \u002F>\nCustom Admin URL: Hide your wp-admin login URL by creating a custom access point, adding an extra layer of security by obscurity.\u003C\u002Fp>\n\u003Cp>Geolocation Integration: Includes location data in Telegram notifications, adding crucial context to security alerts and aiding in the investigation of suspicious activities.\u003Cbr \u002F>\nUser-Friendly Admin Interface: An intuitive, tabbed settings page contributes to a clean and easy-to-use experience.\u003Cbr \u002F>\nWhy Choose Login Security with Telegram Alerts?\u003C\u002Fp>\n\u003Cp>Comprehensive Security: Provides advanced features that actively defend your site against common and persistent threats.\u003Cbr \u002F>\nInstant Awareness: Critical updates are delivered directly to Telegram, facilitating immediate action and providing peace of mind to site administrators.\u003Cbr \u002F>\nUser-Friendly: Engineered for quick setup, often achievable in minutes, with an intuitive interface that makes configuration accessible to users of all technical levels.\u003Cbr \u002F>\nPerformance Optimized: Built with efficiency in mind, ensuring that robust security measures do not compromise site speed.\u003Cbr \u002F>\nDedicated Support: A passionate team is committed to providing prompt and helpful support, aiming to ensure users maximize the plugin’s potential.\u003Cbr \u002F>\nCompatibility & Requirements:\u003C\u002Fp>\n\u003Cp>WordPress Version: 5.0 or higher (Tested up to 6.9)\u003Cbr \u002F>\nPHP Version: 7.2 or higher (PHP 7.4+ recommended for optimal performance and security)\u003Cbr \u002F>\nPerformance Considerations:\u003Cbr \u002F>\nLogin Security with Telegram Alerts is designed with performance in mind:\u003C\u002Fp>\n\u003Cp>Efficient API Calls: When interacting with external services like Telegram’s API, the plugin uses WordPress’s built-in HTTP API for reliable and performant requests, minimizing impact on page load times.\u003Cbr \u002F>\nOptimized Database Interactions: Designed to minimize database queries and employs best practices for data storage and retrieval, ensuring your site’s database remains lean and responsive.\u003Cbr \u002F>\nLightweight Codebase: Development emphasizes avoiding bloated scripts and unnecessary assets, ensuring the plugin adds minimal overhead to site resources.\u003Cbr \u002F>\nSecurity Best Practices:\u003Cbr \u002F>\nBeyond merely claiming to be “secure,” Login Security with Telegram Alerts implements rigorous security measures:\u003C\u002Fp>\n\u003Cp>Nonces: All critical actions and forms within the plugin utilize WordPress Nonces to protect against Cross-Site Request Forgery (CSRF) attacks.\u003Cbr \u002F>\nInput Sanitization: All user input is rigorously sanitized before processing or storage to prevent malicious code injection, such as Cross-Site Scripting (XSS) attacks.\u003Cbr \u002F>\nOutput Escaping: Data displayed on both the frontend and backend is properly escaped to prevent XSS vulnerabilities.\u003Cbr \u002F>\nCapability Checks: Access to plugin functionalities is strictly controlled by checking user capabilities using current_user_can(), preventing unauthorized users from performing actions they are not permitted to.\u003Cbr \u002F>\nRegular Audits: The plugin’s codebase undergoes regular scanning and updates to address emerging security vulnerabilities.\u003Cbr \u002F>\nInternationalization (i18n):\u003Cbr \u002F>\nLogin Security with Telegram Alerts is fully internationalized, allowing for seamless translation into any language. All strings are meticulously wrapped in gettext functions, and a dedicated text domain (login-security-with-telegram-alerts) ensures compatibility with WordPress’s robust translation system.\u003C\u002Fp>\n\u003Ch3>Third-Party Services\u003C\u002Fh3>\n\u003Cp>This plugin may connect to external services to provide certain features:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Telegram API (api.telegram.org)\u003C\u002Fstrong>\u003Cbr \u002F>\n– Used for: Sending security notifications to your configured Telegram bot\u003Cbr \u002F>\n– Triggered when: You enable Telegram notifications and configure a bot token and chat ID\u003Cbr \u002F>\n– Privacy Policy: https:\u002F\u002Ftelegram.org\u002Fprivacy\u003Cbr \u002F>\n– Terms: https:\u002F\u002Ftelegram.org\u002Ftos\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP Geolocation (ip-api.com)\u003C\u002Fstrong>\u003Cbr \u002F>\n– Used for: Looking up geographical location of login attempts\u003Cbr \u002F>\n– Triggered when: Geolocation is enabled in settings (optional feature)\u003Cbr \u002F>\n– Privacy Policy: https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003Cbr \u002F>\n– Data sent: IP addresses only\u003C\u002Fp>\n\u003Cp>All external service connections are optional and only occur when explicitly enabled by the administrator. No data is sent without your configuration and consent.\u003C\u002Fp>\n","Login Security with Telegram Alerts protects WordPress logins, stops brute force, logs activity, and sends real-time Telegram alerts.",10,297,0,"2025-12-15T19:26:00.000Z","6.9.5","5.0","7.2",[19,20,21,22,23],"activity-log","brute-force","login-security","notifications","telegram","https:\u002F\u002Fgabirosca.com\u002Flogin-security-with-telegram-alerts-wordpress-security-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flogin-security-with-telegram-alerts.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},1,30,94,"2026-08-24T04:16:58.038Z",[37,57,78,98,120],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":26,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":55,"download_link":56,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"login-armor","Login Armor","2.4.5","wpformation","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpformation\u002F","\u003Cp>\u003Cstrong>Twelve security modules. One lightweight plugin. Zero compromise.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Login Armor is a complete WordPress security stack built for agencies, freelancers and pros who deliver audit-ready sites. No premium tier, no bundled marketing dashboard, no telemetry. Every module runs locally, ships with safe defaults, and stays out of your way.\u003C\u002Fp>\n\u003Cp>Stop juggling Wordfence’s bloat, Solid Security’s upsells, and Limit Login Attempts’ gaps — Login Armor delivers twelve independent modules in about one megabyte.\u003C\u002Fp>\n\u003Ch4>New in 2.4.0\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Request Firewall\u003C\u002Fstrong> — an optional, 8G-inspired PHP filter that blocks malicious requests (SQL injection, code execution, traversal, XSS, disallowed HTTP methods) before WordPress finishes loading, on Apache, Nginx and LiteSpeed alike. Off by default, it starts in monitor mode and never filters logged-in administrators; every block is logged, aggregated to one incident per IP per hour.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Guided onboarding\u003C\u002Fstrong> — a first-run wizard offers a one-click “safe baseline” that turns on the no-risk essentials, so a beginner is protected in seconds. The same “Apply safe baseline” button stays available any time.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Login Armor\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>No upsells, ever.\u003C\u002Fstrong> No “premium” tier, no greyed-out “Pro” buttons. Every feature is GPL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external services to sign up for.\u003C\u002Fstrong> No API keys, no remote dashboards, no telemetry. The only outbound calls are opt-in: Have I Been Pwned (breach\u002Fpassword checks), Slack\u002FDiscord\u002Fwebhook (notifications), the keyless ipwho.is API (geolocation), and your own WordPress 7 AI connector.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built to be invisible.\u003C\u002Fstrong> Sub-megabyte ZIP, lazy-loaded modules, indexed queries — under 2 ms on a normal login flow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multisite-aware, PHP 8.1-native, production-grade defaults.\u003C\u002Fstrong> Network-activate a fleet, configure per-site, manage from a complete WP-CLI suite; zero-config gets you 80 percent of the protection.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Twelve independent modules\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Hide Login\u003C\u002Fstrong> — Replace wp-login.php with a custom slug; the old URL returns a 404, and a branded pre-activation modal lets you pick or generate the slug and emails it to you so you can’t lock yourself out. Compatible with multisite, reverse proxies and password-recovery flows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute Force Protection\u003C\u002Fstrong> — Cascading lockouts escalating to a 24-hour ban, with subnet blocking and trusted X-Forwarded-For; lostpassword, register, XML-RPC and the REST users endpoint are all gated when an IP is locked, and every lockout surfaces as an incident.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hardening\u003C\u002Fstrong> — Fifteen one-click toggles across surface reduction, credential hardening, request filtering and account monitoring: disable XML-RPC\u002Fpingbacks, the file editor, version exposure, application passwords and author enumeration; block reserved usernames (Unicode-confusable detection); add a login honeypot; get alerted on new administrators.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong> — TOTP, one-time codes by email and printable backup codes, with trusted devices for thirty days, per-role enforcement, a configurable grace period and an email recovery flow when the authenticator is lost.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Detection and Incidents\u003C\u002Fstrong> — A real-time engine groups raw events into six attack patterns, each with a drill-down (timeline, source IPs, target users, severity, UA fingerprint) and one-click actions (reset password, block subnet, mark resolved).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity Log\u003C\u002Fstrong> — A compliance-ready, tamper-evident (hash-chained) audit trail of admin actions across seven logger domains, with filtering, CSV export, configurable retention and optional signed webhook forwarding to a SIEM.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Page Security Headers\u003C\u002Fstrong> — Content-Security-Policy, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options on wp-login.php and the lockout page, in two presets with an optional CSP report-uri; baseline headers can optionally extend site-wide.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Breach Check\u003C\u002Fstrong> — Detect logins using a breached password via privacy-preserving k-anonymity against Have I Been Pwned (only a 5-character SHA-1 prefix leaves the server); optional XposedOrNot email lookup, fail-soft so an outage never blocks login.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password Policy\u003C\u002Fstrong> — Enforce strong, unique passwords at registration, profile update and reset: minimum length and character classes, forbid the username inside the password, optionally reject breached passwords, with optional non-locking expiration nudges.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Management\u003C\u002Fstrong> — Idle-timeout logout measured on real page loads, a maximum session lifetime regardless of “remember me”, an optional single-active-device restriction, and a one-click “sign out all other devices”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Geolocation\u003C\u002Fstrong> — Show the attacker’s country on the Incidents and Events tabs; lazy, cached thirty days, capped per page load, private ranges never sent. Keyless ipwho.is by default, swappable for an offline database via a filter.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Request Firewall\u003C\u002Fstrong> — An optional, 8G-inspired PHP filter that blocks malicious query strings, paths, HTTP methods and (opt-in) user-agents\u002Freferrers before WordPress loads, on Apache\u002FNginx\u002FLiteSpeed alike; off by default, starts in monitor mode, never filters admins, skips REST\u002Fcron\u002FWP-CLI, with an IP\u002Fpath allowlist (CIDR). Not scored.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>AI Security Briefing (optional)\u003C\u002Fh4>\n\u003Cp>Built on the WordPress 7 native AI Client, one click turns your last thirty days of activity into a plain-language verdict, an IP picture and a short list of prioritised actions; “Explain with AI” does the same on a single incident. Minimised mode (anonymised signals) is the default and deep mode is an explicit opt-in. No API key is stored — it uses your own WordPress AI connector, so provider and cost stay yours. It always leads with a deterministic facts snapshot that works with or without AI.\u003C\u002Fp>\n\u003Ch4>Plus\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Guided onboarding\u003C\u002Fstrong> — a first-run wizard with a one-click safe baseline (Simple) or manual setup (Advanced); the “Apply safe baseline” button stays available, and upgrading sites never see the wizard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security score\u003C\u002Fstrong> — a weighted 0-100 read of your posture with a one-click “next best action”; observability features (geolocation, notifications, the AI assistant) are deliberately not scored.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conflict detection\u003C\u002Fstrong> — warns when another login-security plugin (Wordfence, Solid Security, Sucuri, All-In-One Security, SecuPress and more) or a cache plugin (with Hide Login on) could clash.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications\u003C\u002Fstrong> — email, Slack, Discord or webhook with SSRF-safe URL validation, severity threshold and rate limiting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI suite\u003C\u002Fstrong> and a \u003Cstrong>dashboard widget\u003C\u002Fstrong> (14-day sparkline, six headline metrics).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Douze modules de sécurité. Une seule extension légère. Zéro compromis.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Login Armor est une stack complète de sécurité WordPress conçue pour les agences, les freelances et les pros qui livrent des sites prêts à passer un audit. Pas de version premium, pas de tableau de bord marketing intégré, pas de télémétrie. Chaque module tourne en local, embarque des réglages par défaut sécurisés, et reste discret.\u003C\u002Fp>\n\u003Cp>Fini de jongler entre la lourdeur de Wordfence, les fenêtres d’upsell de Solid Security et les angles morts de Limit Login Attempts — Login Armor regroupe douze modules indépendants en environ un méga-octet.\u003C\u002Fp>\n\u003Ch4>Nouveau en 2.4.0\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Pare-feu de requêtes\u003C\u002Fstrong> : un filtre PHP optionnel, inspiré du pare-feu 8G, qui bloque les requêtes malveillantes (injection SQL, exécution de code, traversée de répertoires, XSS, méthodes HTTP non autorisées) avant même que WordPress ait fini de charger, aussi bien sur Apache que Nginx ou LiteSpeed. Désactivé par défaut, il démarre en mode surveillance et ne filtre jamais les administrateurs connectés ; chaque blocage est journalisé, agrégé en un incident par IP et par heure.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Assistant de configuration\u003C\u002Fstrong> : à la première activation, un assistant propose une « base sûre » en un clic qui active les essentiels sans risque — un débutant est protégé en quelques secondes. Le même bouton « Appliquer la base sûre » reste disponible à tout moment.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pourquoi Login Armor\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Aucun upsell, jamais.\u003C\u002Fstrong> Pas de niveau « premium », pas de boutons « Pro » grisés. Tout est en GPL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Aucun service externe à activer.\u003C\u002Fstrong> Pas de clé API, pas de tableau distant, pas de télémétrie. Les seuls appels sortants sont opt-in : Have I Been Pwned (fuites\u002Fmots de passe), Slack\u002FDiscord\u002Fwebhook (notifications), l’API sans clé ipwho.is (géolocalisation) et votre propre connecteur IA WordPress 7.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Conçu pour être invisible.\u003C\u002Fstrong> ZIP de moins d’un méga, modules chargés à la demande, requêtes indexées — sous 2 ms sur un flux de connexion normal.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compatible multisite, natif PHP 8.1, réglages prêts pour la production.\u003C\u002Fstrong> Activation réseau d’une flotte, configuration par site, pilotage via une suite WP-CLI complète ; sans configuration, vous avez déjà 80 % de la protection.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Douze modules indépendants\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Masquer la connexion\u003C\u002Fstrong> : remplace wp-login.php par une URL personnalisée (l’ancienne renvoie une 404) ; une modale de pré-activation choisit ou génère le slug et vous l’envoie par e-mail pour éviter tout verrouillage. Compatible multisite, reverse proxies et récupération de mot de passe.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Protection contre la force brute\u003C\u002Fstrong> : verrouillages en cascade montant à un bannissement de 24 h, blocage de sous-réseaux et support X-Forwarded-For ; lostpassword, register, XML-RPC et l’endpoint REST users sont bloqués pour une IP verrouillée, et chaque verrouillage devient un incident.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Renforcement\u003C\u002Fstrong> : quinze bascules en un clic (réduction de surface, identifiants, filtrage des requêtes, surveillance des comptes) — désactiver XML-RPC\u002Fpingbacks, l’éditeur de fichiers, l’exposition de version, les mots de passe applicatifs et l’énumération d’auteurs ; bloquer les identifiants réservés (homoglyphes Unicode) ; ajouter un pot de miel ; être alerté à la création d’un administrateur.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authentification à deux facteurs\u003C\u002Fstrong> : TOTP, codes à usage unique par e-mail et codes de secours imprimables, avec appareils de confiance 30 jours, application par rôle, période de grâce configurable et récupération par e-mail en cas de perte.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection et incidents\u003C\u002Fstrong> : un moteur en temps réel regroupe les événements en six patterns d’attaque, chacun avec une vue détaillée (chronologie, IP sources, comptes cibles, sévérité, empreinte UA) et des actions en un clic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Journal d’activité\u003C\u002Fstrong> : piste d’audit conforme et inviolable (chaîne de hachage) des actions admin sur sept domaines, avec filtrage, export CSV, rétention configurable et transfert webhook signé optionnel vers un SIEM.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>En-têtes de sécurité\u003C\u002Fstrong> : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options sur wp-login.php et la page de verrouillage, en deux préréglages avec CSP report-uri optionnel ; les en-têtes de base peuvent s’étendre à tout le site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection de fuites\u003C\u002Fstrong> : repère les connexions avec un mot de passe fuité via k-anonymat sur Have I Been Pwned (seul un préfixe SHA-1 de 5 caractères sort) ; vérification e-mail XposedOrNot optionnelle, fail-soft.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Politique de mot de passe\u003C\u002Fstrong> : impose des mots de passe forts à l’inscription, au profil et à la réinitialisation (longueur, classes de caractères, interdiction de l’identifiant, rejet optionnel des mots de passe fuités), avec expiration optionnelle qui ne verrouille jamais personne dehors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gestion des sessions\u003C\u002Fstrong> : déconnexion sur inactivité mesurée sur les vrais chargements, durée de vie maximale indépendante de « se souvenir de moi », limitation optionnelle à un seul appareil actif, et « déconnecter tous les autres appareils » en un clic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Géolocalisation IP\u003C\u002Fstrong> : affiche le pays des IP attaquantes dans Incidents et Événements ; recherches paresseuses, cache 30 jours, plafonnées par page, plages privées jamais envoyées. ipwho.is sans clé par défaut, base hors ligne possible via un filtre.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pare-feu de requêtes\u003C\u002Fstrong> : filtre PHP optionnel inspiré du 8G qui bloque chaînes de requête, chemins, méthodes HTTP et (en option) user-agents\u002Freferrers malveillants avant le chargement de WordPress, sur Apache\u002FNginx\u002FLiteSpeed ; désactivé par défaut, démarre en mode surveillance, ne filtre jamais les admins, ignore REST\u002Fcron\u002FWP-CLI, allowlist IP\u002Fchemins (CIDR). Non noté.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Briefing de sécurité IA (optionnel)\u003C\u002Fh4>\n\u003Cp>Bâti sur le client IA natif de WordPress 7, un clic transforme vos trente derniers jours d’activité en un verdict en langage clair, un panorama des IP et une courte liste d’actions prioritaires ; « Expliquer avec l’IA » fait de même sur un incident. Le mode minimisé (signaux anonymisés) est par défaut, le mode approfondi est un opt-in explicite. Aucune clé API stockée : il utilise votre propre connecteur IA WordPress, le coût et le fournisseur restent les vôtres. Il s’ouvre toujours sur un instantané de faits déterministes, utile avec ou sans IA.\u003C\u002Fp>\n\u003Ch4>En plus\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Assistant de configuration\u003C\u002Fstrong> : un assistant à la première activation propose une base sûre en un clic (Simple) ou une voie manuelle (Avancée) ; le bouton « Appliquer la base sûre » reste disponible, et les sites en mise à jour ne le voient jamais.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Score de sécurité\u003C\u002Fstrong> : lecture pondérée 0-100 de votre posture avec une action prioritaire en un clic ; les fonctions d’observabilité (géolocalisation, notifications, assistant IA) ne sont pas notées.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Détection de conflits\u003C\u002Fstrong> : alerte quand une autre extension de sécurité axée connexion (Wordfence, Solid Security, Sucuri, All-In-One Security, SecuPress et d’autres) ou un plugin de cache (avec Hide Login actif) peut entrer en conflit.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notifications\u003C\u002Fstrong> : e-mail, Slack, Discord ou webhook, avec validation d’URL anti-SSRF, seuil de sévérité et rate limiting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suite WP-CLI\u003C\u002Fstrong> et \u003Cstrong>widget Tableau de bord\u003C\u002Fstrong> (sparkline 14 jours, six métriques clés).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Conçu par\u003C\u002Fh4>\n\u003Cp>Login Armor est conçu et maintenu par Fabrice Ducarme de \u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Flogin-armor\u002F\" rel=\"nofollow ugc\">WPFormation\u003C\u002Fa>, expert WordPress français obsédé par les sites propres, rapides et prêts pour l’audit. On l’utilise sur chaque site qu’on livre.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Flogin-armor\u002F\" rel=\"nofollow ugc\">Présentation et fonctionnement de Login Armor\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Fsecurite-wordpress\u002F\" rel=\"nofollow ugc\">Guides de sécurité WordPress\u003C\u002Fa> sur WPFormation\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpformation.com\u002Foutils\u002Fveille-securite\u002F\" rel=\"nofollow ugc\">Veille des vulnérabilités WordPress\u003C\u002Fa> : l’outil de veille sécurité de WPFormation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Ch4>AI Security Briefing (optional)\u003C\u002Fh4>\n\u003Cp>The AI Security Briefing and the “Explain with AI” incident analysis are powered by the \u003Cstrong>WordPress 7 native AI Client\u003C\u002Fstrong> (\u003Ccode>wp_ai_client_prompt()\u003C\u002Fcode>). When the administrator clicks the analysis button, LoginArmor asks WordPress to send a prompt to the \u003Cstrong>AI connector that the administrator configured in their own WordPress\u003C\u002Fstrong> (for example OpenAI, Anthropic or Google, depending on the connector). LoginArmor itself stores no API key and contacts no endpoint directly: the request, the provider and the cost are owned by the site’s own AI connector.\u003C\u002Fp>\n\u003Cp>Data sent: a text prompt describing the security situation. In \u003Cstrong>minimised mode (the default)\u003C\u002Fstrong>, only anonymised, non-identifying signals are included (counts, categories, severities, role buckets) – no IP address and no username in clear. In \u003Cstrong>deep mode\u003C\u002Fstrong> (an explicit, off-by-default opt-in), the prompt additionally includes real IP addresses and event details so the analysis can name specific sources. No data is ever sent unless the administrator clicks the analysis button.\u003C\u002Fp>\n\u003Cp>This feature is inactive unless WordPress 7 (or the AI Building Blocks feature plugin) is present with a configured, approved AI connector. The applicable terms and privacy policy are those of the AI provider the administrator chose for their connector; please refer to that provider’s documentation.\u003C\u002Fp>\n\u003Ch4>Webhook Notifications (optional)\u003C\u002Fh4>\n\u003Cp>When explicitly enabled and configured by the administrator in LoginArmor > Settings > Notifications, the plugin sends incident data to third-party services via webhooks.\u003C\u002Fp>\n\u003Cp>Data sent: incident type, severity level, IP address, target username, event count, and site URL.\u003C\u002Fp>\n\u003Cp>No data is sent unless the administrator actively enables and configures a notification channel.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Slack\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fslack.com\u002Fterms-of-service\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fslack.com\u002Fprivacy-policy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Discord\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fdiscord.com\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fdiscord.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Webhook URL\u003C\u002Fstrong> – User-configured endpoint (administrator’s responsibility)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Gravatar (Automattic)\u003C\u002Fh4>\n\u003Cp>The Activity Log tab uses WordPress core’s \u003Ccode>get_avatar()\u003C\u002Fcode> function to display user avatars. WordPress may send a hashed email address to \u003Ca href=\"https:\u002F\u002Fgravatar.com\u002F\" rel=\"nofollow ugc\">Gravatar\u003C\u002Fa> servers to retrieve avatar images. This is controlled by Settings > Discussion > Avatars.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Gravatar\u003C\u002Fstrong> – \u003Ca href=\"https:\u002F\u002Fautomattic.com\u002Ftos\u002F\" rel=\"nofollow ugc\">Automattic Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Breach Check – Have I Been Pwned (optional)\u003C\u002Fh4>\n\u003Cp>When the administrator explicitly enables the \u003Cstrong>Breach Check\u003C\u002Fstrong> module (LoginArmor > Settings > Breach  &hellip;\u003C\u002Fp>\n","Twelve security modules + AI briefing: hide login, request firewall, brute force, 2FA, password policy, sessions, hardening, audit log. No upsells.",200,2619,3,"2026-07-22T03:46:00.000Z","7.0.2","6.8","8.1",[19,20,53,54,21],"hide-login","limit-login","https:\u002F\u002Fwpformation.com\u002Flogin-armor","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flogin-armor.2.4.5.zip",{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":65,"downloaded":66,"rating":67,"num_ratings":68,"last_updated":69,"tested_up_to":49,"requires_at_least":16,"requires_php":70,"tags":71,"homepage":70,"download_link":75,"security_score":67,"vuln_count":76,"unpatched_count":13,"last_vuln_date":77,"fetched_at":28},"limit-login-attempts-reloaded","Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention","3.3.4","WPChef","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpchefgadget\u002F","\u003Cp>Protect your WordPress website against brute force attacks, bot attacks, and unauthorized login attempts with one of the most trusted login security plugins for WordPress.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\" rel=\"nofollow ugc\">Limit Login Attempts Security\u003C\u002Fa> strengthens your WordPress login security by limiting failed login attempts, blocking malicious IPs, securing wp-login.php, protecting XML-RPC, and adding powerful firewall and 2FA protection without slowing down your website.\u003C\u002Fp>\n\u003Cp>Trusted by 2 million WordPress websites, Limit Login Attempts Security is designed specifically to protect the most targeted part of your website: the login page.\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FS3nf8Zpbcfs?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Why Use Limit Login Attempts Security?\u003C\u002Fh4>\n\u003Cp>By default, WordPress allows unlimited login attempts. This creates a major security vulnerability where bots and attackers can repeatedly guess usernames and passwords until they gain access. This is especially important in the age of AI, where attackers now have access to faster and more sophisticated tools than ever before.\u003C\u002Fp>\n\u003Cp>Limit Login Attempts Security helps stop:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brute force attacks\u003C\u002Fli>\n\u003Cli>Bot login attacks\u003C\u002Fli>\n\u003Cli>Credential stuffing attacks\u003C\u002Fli>\n\u003Cli>XML-RPC attacks\u003C\u002Fli>\n\u003Cli>Unauthorized login attempts\u003C\u002Fli>\n\u003Cli>WooCommerce login abuse\u003C\u002Fli>\n\u003Cli>Malicious IP access attempts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin automatically blocks excessive login attempts and locks out suspicious IP addresses and usernames before attackers can gain access.\u003C\u002Fp>\n\u003Ch4>Features Included in the Free Version\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Login Security & Brute Force Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Limit login attempts by IP address and username\u003C\u002Fli>\n\u003Cli>Automatically lock out suspicious login activity\u003C\u002Fli>\n\u003Cli>Adjustable lockout duration and retry limits\u003C\u002Fli>\n\u003Cli>Protect wp-login.php from automated attacks\u003C\u002Fli>\n\u003Cli>Prevent brute force login attacks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>2FA \u002F Multi-Factor Authentication (MFA)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Built-in two-factor authentication (2FA)\u003C\u002Fli>\n\u003Cli>Add an additional layer of login protection\u003C\u002Fli>\n\u003Cli>Improve WordPress account security\u003C\u002Fli>\n\u003Cli>Secure administrator and user logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Bot Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Block malicious login requests\u003C\u002Fli>\n\u003Cli>Detect suspicious login behavior\u003C\u002Fli>\n\u003Cli>Reduce bot-based login attacks\u003C\u002Fli>\n\u003Cli>Lightweight firewall-focused login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce & Plugin Compatibility\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Protects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WooCommerce login pages\u003C\u002Fli>\n\u003Cli>XML-RPC login requests\u003C\u002Fli>\n\u003Cli>Custom login pages\u003C\u002Fli>\n\u003Cli>WordPress multisite installations\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Compatible With:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence\u003C\u002Fli>\n\u003Cli>Sucuri\u003C\u002Fli>\n\u003Cli>Ultimate Member\u003C\u002Fli>\n\u003Cli>MemberPress\u003C\u002Fli>\n\u003Cli>WPS Hide Login\u003C\u002Fli>\n\u003Cli>Cloudflare and reverse proxy setups\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Login Monitoring & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Failed login attempt logs\u003C\u002Fli>\n\u003Cli>Lockout email notifications\u003C\u002Fli>\n\u003Cli>Denied attempt tracking\u003C\u002Fli>\n\u003Cli>Login retry visibility for users\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Access Controls\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>IP safelist and denylist support\u003C\u002Fli>\n\u003Cli>Username safelist and denylist support\u003C\u002Fli>\n\u003Cli>IPv6 range support\u003C\u002Fli>\n\u003Cli>Custom IP origin configuration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium Features (Start Your Free 14 Day Trial)\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.limitloginattempts.com\u002Fplans\u002F\" rel=\"nofollow ugc\">Upgrade to Limit Login Attempts Security Premium\u003C\u002Fa> to extend protection with cloud-based login security and advanced attack prevention.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advanced Cloud Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Real-time malicious IP intelligence\u003C\u002Fli>\n\u003Cli>Global denylist protection\u003C\u002Fli>\n\u003Cli>Synchronized lockouts across websites\u003C\u002Fli>\n\u003Cli>Auto IP denylist generation\u003C\u002Fli>\n\u003Cli>Cloud-based login attack mitigation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Enhanced Performance Protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Offload excessive failed login requests from your server\u003C\u002Fli>\n\u003Cli>Reduce server strain during attacks\u003C\u002Fli>\n\u003Cli>Improve stability under heavy attack conditions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced Security Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Country-based login blocking\u003C\u002Fli>\n\u003Cli>Enhanced throttling and lockout escalation\u003C\u002Fli>\n\u003Cli>Registration page protection\u003C\u002Fli>\n\u003Cli>Successful login tracking\u003C\u002Fli>\n\u003Cli>Enhanced lockout analytics and geolocation data\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Multi-Site & Team Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Shared safelist and denylist syncing\u003C\u002Fli>\n\u003Cli>Shared lockout protection between domains\u003C\u002Fli>\n\u003Cli>Cloud backups of IP security data\u003C\u002Fli>\n\u003Cli>CSV exports of login and IP activity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Premium Support\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Access to security-focused support specialists\u003C\u002Fli>\n\u003Cli>Faster troubleshooting and assistance\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Lightweight Security Built for WordPress\u003C\u002Fh4>\n\u003Cp>Unlike many large security suites, Limit Login Attempts Security focuses specifically on login security and brute force protection.\u003C\u002Fp>\n\u003Cp>This means:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Faster performance\u003C\u002Fli>\n\u003Cli>Less server overhead\u003C\u002Fli>\n\u003Cli>Easier configuration\u003C\u002Fli>\n\u003Cli>Strong protection without unnecessary bloat\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Protect More Than Just wp-login.php\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security secures:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>wp-login.php\u003C\u002Fli>\n\u003Cli>XML-RPC\u003C\u002Fli>\n\u003Cli>WooCommerce logins\u003C\u002Fli>\n\u003Cli>Custom login forms\u003C\u002Fli>\n\u003Cli>Registration pages\u003C\u002Fli>\n\u003Cli>Multisite logins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Trusted by Millions of WordPress Websites\u003C\u002Fh4>\n\u003Cp>Limit Login Attempts Security is one of the most widely used WordPress login security plugins and has helped protect millions of websites from brute force attacks and malicious login activity.\u003C\u002Fp>\n\u003Cp>Whether you run:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A personal blog\u003C\u002Fli>\n\u003Cli>WooCommerce store\u003C\u002Fli>\n\u003Cli>Membership website\u003C\u002Fli>\n\u003Cli>Agency\u003C\u002Fli>\n\u003Cli>Business website\u003C\u002Fli>\n\u003Cli>Enterprise WordPress network\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Limit Login Attempts Security helps secure your login experience with modern WordPress login protection.\u003C\u002Fp>\n\u003Ch4>Upgrading from the Original Limit Login Attempts Plugin?\u003C\u002Fh4>\n\u003Cp>Switching is easy:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Remove the old Limit Login Attempts plugin\u003C\u002Fli>\n\u003Cli>Install Limit Login Attempts Security\u003C\u002Fli>\n\u003Cli>Your settings will remain intact\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Translation Support\u003C\u002Fh4>\n\u003Cp>Currently translated into multiple languages including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Dutch\u003C\u002Fli>\n\u003Cli>Turkish\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Romanian\u003C\u002Fli>\n\u003Cli>Chinese (Traditional)\u003C\u002Fli>\n\u003Cli>Brazilian Portuguese\u003C\u002Fli>\n\u003Cli>And more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Secure Your WordPress Login Today\u003C\u002Fh4>\n\u003Cp>Install Limit Login Attempts Security and protect your WordPress website with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Login security\u003C\u002Fli>\n\u003Cli>Two-Factor Authentication (2FA)\u003C\u002Fli>\n\u003Cli>Brute force protection\u003C\u002Fli>\n\u003Cli>Firewall security\u003C\u002Fli>\n\u003Cli>Bot protection\u003C\u002Fli>\n\u003Cli>XML-RPC protection\u003C\u002Fli>\n\u003Cli>WooCommerce login protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Without slowing down your website.\u003C\u002Fp>\n","WordPress login security with brute force protection, Two-factor authentication (2FA\u002FMFA), firewall, IP\u002Fcountry blocking, and login monitoring",1000000,91831747,98,1468,"2026-07-08T11:06:00.000Z","",[72,20,73,21,74],"2fa","firewall","security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flimit-login-attempts-reloaded.3.3.4.zip",4,"2023-12-20 00:00:00",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":86,"downloaded":87,"rating":26,"num_ratings":88,"last_updated":89,"tested_up_to":15,"requires_at_least":90,"requires_php":91,"tags":92,"homepage":96,"download_link":97,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wptelegram","WP Telegram (Auto Post and Notifications)","4.2.15","WP Socio","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpsocio\u002F","\u003Cp>Integrate your WordPress site perfectly with Telegram with full control.\u003C\u002Fp>\n\u003Ch3>Modules\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>1. Post to Telegram\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>📝 Send posts automatically to Telegram when published or updated\u003C\u002Fli>\n\u003Cli>📢 You can send to a Telegram Channel, Group, Supergroup or private chat\u003C\u002Fli>\n\u003Cli>👥 Supports multiple Channels\u002Fchats\u003C\u002Fli>\n\u003Cli>🙂 Has Message Template composer with Emojis\u003C\u002Fli>\n\u003Cli>⏳ Supports Conditional logic inside Message Template\u003C\u002Fli>\n\u003Cli>🖼 Supports sending featured image along with the text\u003C\u002Fli>\n\u003Cli>🏞 You can choose to send only the Featured Image\u003C\u002Fli>\n\u003Cli>⏱ Supports scheduled (future) posts\u003C\u002Fli>\n\u003Cli>🕰 Messages can be delayed by a specific interval\u003C\u002Fli>\n\u003Cli>⬜️ You can add an Inline button for the post URL\u003C\u002Fli>\n\u003Cli>🛒 Supports WooCommerce products and other Custom Post Types\u003C\u002Fli>\n\u003Cli>✒️ Direct Support for sending Custom Fields\u003C\u002Fli>\n\u003Cli>🗃 You can send Custom Taxonomy Terms\u003C\u002Fli>\n\u003Cli>📋 You can select the post types to be sent\u003C\u002Fli>\n\u003Cli>⏲ You can choose when to send (New and\u002For existing posts)\u003C\u002Fli>\n\u003Cli>🎛 Make use of Custom Rules to filter posts by authors, categories, tags, post formats or custom taxonomy terms\u003C\u002Fli>\n\u003Cli>🎚 You can override the default settings on post edit page\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwptelegram.pro\" rel=\"nofollow ugc\">WP Telegram Pro\u003C\u002Fa> supports multiple channels based upon category\u002Ftag\u002Fauthor\u002Fpost type etc. and also supports unlimited Reaction buttons.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2. Private Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>📧 Get your email notifications on Telegram\u003C\u002Fli>\n\u003Cli>🔔 Supports \u003Cstrong>WooCommerce\u003C\u002Fstrong> order notifications, \u003Cstrong>Contact Form 7\u003C\u002Fstrong> and other plugin notifications\u003C\u002Fli>\n\u003Cli>🔕 Allow users to receive their email notifications on Telegram\u003C\u002Fli>\n\u003Cli>🔐 Integrated with \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwptelegram-login\" rel=\"ugc\">WP Telegram Login\u003C\u002Fa> to let users connect their Telegram.\u003C\u002Fli>\n\u003Cli>🖊 Users can also enter their Telegram Chat ID manually on page\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>3. Proxy\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>🚫 If your host blocks Telegram, you can use this module\u003C\u002Fli>\n\u003Cli>✅ Bypass the ban on Telegram by making use of proxy\u003C\u002Fli>\n\u003Cli>🚀 Supports \u003Cstrong>Cloudflare worker as proxy\u003C\u002Fstrong> which supports file upload\u003C\u002Fli>\n\u003Cli>😍 Option to use custom \u003Cstrong>Google Script as proxy\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>❇️ Supports all proxies supported by PHP\u003C\u002Fli>\n\u003Cli>🔛 You can select Proxy type – HTTP, SOCKS4, SOCKS4A, SOCKS5, SOCKS5_HOSTNAME\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Excellent LIVE Support on Telegram\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Easy to install and set up for the admin\u003C\u002Fli>\n\u003Cli>Fully customizable with actions and filters\u003C\u002Fli>\n\u003Cli>Can be extended with custom code\u003C\u002Fli>\n\u003Cli>Translation ready\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Getting Started | Post to Telegram\u003C\u002Fh4>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fm48V-gWz9-o?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>WooCommerce, CF7 etc. Notifications\u003C\u002Fh4>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FgVJCtwkorMA?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch3>Contribution\u003C\u002Fh3>\n\u003Cp>Development takes place in our \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwpsocio\u002Fwp-projects\" rel=\"nofollow ugc\">Github monorepo\u003C\u002Fa>, and all contributions welcome.\u003C\u002Fp>\n\u003Ch3>Excellent LIVE Support on Telegram\u003C\u002Fh3>\n\u003Ch4>Join the Chat\u003C\u002Fh4>\n\u003Cp>We have a public group on Telegram to provide help setting up the plugin, discuss issues, features, translations etc. Join \u003Ca href=\"https:\u002F\u002Ft.me\u002FWPTelegramChat\" rel=\"nofollow ugc\">@WPTelegramChat\u003C\u002Fa>\u003Cbr \u002F>\nFor rules, see the pinned message. No spam please.\u003C\u002Fp>\n\u003Ch4>Get in touch\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Website \u003Ca href=\"https:\u002F\u002Fwpsocio.com\" rel=\"nofollow ugc\">wpsocio.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Telegram \u003Ca href=\"https:\u002F\u002Ft.me\u002FWPTelegram\" rel=\"nofollow ugc\">@WPTelegram\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Facebook \u003Ca href=\"https:\u002F\u002Ffb.com\u002FWPTelegram\" rel=\"nofollow ugc\">@WPTelegram\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Twitter \u003Ca href=\"https:\u002F\u002Ftwitter.com\u002FWPTelegram\" rel=\"nofollow ugc\">@WPTelegram\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Upgrade to Pro\u003C\u002Fh4>\n\u003Cp>WP Telegram Pro comes with more powerful features to give you more control. \u003Ca href=\"https:\u002F\u002Fwptelegram.pro\" rel=\"nofollow ugc\">Upgrade NOW\u003C\u002Fa>\u003C\u002Fp>\n","Integrate your WordPress site perfectly with Telegram with full control.",30000,1262445,426,"2026-02-14T15:23:00.000Z","6.6","8.0",[93,94,22,95,23],"channel","group","posts","https:\u002F\u002Ft.me\u002FWPTelegram","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwptelegram.4.2.15.zip",{"slug":99,"name":100,"version":101,"author":102,"author_profile":103,"description":104,"short_description":105,"active_installs":106,"downloaded":107,"rating":108,"num_ratings":109,"last_updated":110,"tested_up_to":49,"requires_at_least":111,"requires_php":112,"tags":113,"homepage":117,"download_link":118,"security_score":34,"vuln_count":76,"unpatched_count":13,"last_vuln_date":119,"fetched_at":28},"melapress-login-security","Melapress Login Security","2.3.0","Melapress","https:\u002F\u002Fprofiles.wordpress.org\u002Fmelapress\u002F","\u003Cp>\u003Cstrong> COMPREHENSIVE WORDPRESS LOGIN SECURITY PLUGIN \u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa> enables you to effortlessly set login security policies that put you firmly in the driver’s seat of your WordPress sites. Policies are highly customizable and granular and can be implemented by user role or site-wide for complete control over the security of your WordPress login processes.\u003C\u002Fp>\n\u003Cp>Use the free edition of Melapress Login Security to implement WordPress password requirements such as minimum length and complexity rules. The plugin also allows you to set password expiration policies, prevent password reuse, limit failed login attempts, and automatically disable inactive user accounts, among other things. This helps you:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Prevent unauthorized login attempts\u003C\u002Fli>\n\u003Cli>Protect against brute force attacks\u003C\u002Fli>\n\u003Cli>Comply with GDPR with a login consent notice\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔐 Features list\u003C\u002Fh3>\n\u003Cp>A secure WordPress login starts right here. Explore all of the features included with the free edition of \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa>:\u003C\u002Fp>\n\u003Ch3>Set password policies\u003C\u002Fh3>\n\u003Cp>Strong passwords are your first line of defense against bad actors looking to gain access to your site. Set password requirement policies to make sure users set strong passwords. Set policies by user role or site-wide and define policy priority for users with multiple roles.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Set minimum password length\u003C\u002Fli>\n\u003Cli>Require uppercase and lowercase characters, numbers, and special characters\u003C\u002Fli>\n\u003Cli>Set an automatic password expiration policy and advise users when their password is about to expire\u003C\u002Fli>\n\u003Cli>Disallow users from reusing passwords\u003C\u002Fli>\n\u003Cli>Provide users with helpful instructions during the password configuration stage\u003C\u002Fli>\n\u003Cli>Disable password reset links\u003C\u002Fli>\n\u003Cli>Mandate WordPress password reset on the first login\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Limit login attempts\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fsupport\u002Fkb\u002Fmelapress-login-security-failed-logins-policy-wordpress\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Limit failed login attempts\u003C\u002Fa> and put an end to brute force attacks. Protect your login form by automatically disabling user accounts after a number of failed login attempts. Choose between manual unlocking by an admin or automatic unlocking after a cooldown period.\u003C\u002Fp>\n\u003Ch3>Temporary login without password\u003C\u002Fh3>\n\u003Cp>Provide temporary and secure login access to third parties, like developers, editors, employees or others, without a password. It works by providing the user with a temporary login link that expires after a certain amount of time, or after a number of uses. This prevents you from having to create new user accounts manually, while simultaneously reducing the security risks associated with old, unused user accounts.\u003C\u002Fp>\n\u003Ch3>Change WordPress login URL\u003C\u002Fh3>\n\u003Cp>Easily deploy security-by-obscurity tactics and change your WordPress login page URL using a plugin! Hiding the default login page from hackers makes it more difficult to find, potentially reducing brute force attacks and other unauthorized access attempts. After you change the default wp-admin URL, you can set a 404 for the old login page or redirect it to any page of your choosing.\u003C\u002Fp>\n\u003Ch3>Limit login page access by IP address(es)\u003C\u002Fh3>\n\u003Cp>Limit access to the WordPress login page by IP address(es) for additional security.\u003C\u002Fp>\n\u003Ch3>GDPR login page consent notice\u003C\u002Fh3>\n\u003Cp>Easily meet GDPR requirements by adding a GDPR consent notice to the login page. This is required for GDPR and PCI DSS compliance, thus ensuring your WordPress site login page is in compliance.\u003C\u002Fp>\n\u003Ch3>Emergency password reset\u003C\u002Fh3>\n\u003Cp>Discovered suspicious behavior? Reset all users’ passwords with just one click and regain instant control.\u003C\u002Fp>\n\u003Ch3>Upgrade to Melapress Login Security Premium and get even more benefits.\u003C\u002Fh3>\n\u003Cp>The premium edition of Melapress Login Security comes bundled with even more features, which enable you to take your WordPress website login security to the next level. Disable inactive WordPress user accounts and force passwords to be reset once accounts have been unlocked. Inactive accounts can be managed within a single dashboard for increased efficiency and faster response times. Moreover, you can set accounts to be locked out after a number of failed login attempts and customize the duration and method of unlocking them.\u003C\u002Fp>\n\u003Ch3>Premium features list\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Everything included in the free edition\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manually lock user accounts\u003C\u002Fstrong> to immediately prevent login access for rarely used accounts or users on extended leave\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Add an extra security layer with security questions\u003C\u002Fstrong> users must answer when performing sensitive actions such as password resets and account unlocks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Receive email alerts for unrecognized device logins\u003C\u002Fstrong>, with the option to remotely terminate the session\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Control user session duration\u003C\u002Fstrong> by extending or shortening session timeouts to balance security and convenience\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click integration with third-party plugins\u003C\u002Fstrong> such as WooCommerce, LearnDash, MemberPress, and many others\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatically \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Finactive-users-wordpress\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">disable inactive WordPress users\u003C\u002Fa>\u003C\u002Fstrong> after a configurable period of inactivity\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Apply Geo-blocking rules\u003C\u002Fstrong> to allow or block login access based on specific countries\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fsupport\u002Fkb\u002Fmelapress-login-security-limit-login-ips\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Restrict users’ login to specific IP addresses\u003C\u002Fa>\u003C\u002Fstrong>, including support for multiple allowed IPs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fsupport\u002Fkb\u002Frestrict-users-log-in-time-wordpress-website\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Restrict WordPress user login times\u003C\u002Fa>\u003C\u002Fstrong> by day and\u002For hours\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Limit login credentials\u003C\u002Fstrong> to email address, username, or both\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Add a GDPR consent notice\u003C\u002Fstrong> to the WordPress login page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>View detailed user security reports\u003C\u002Fstrong>, including last activity, password age, and expired passwords\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Receive weekly email summary reports\u003C\u002Fstrong> covering password resets, password changes, user account lockouts, and more\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>|💎 \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\u002Fpricing\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">UPGRADE TO PREMIUM\u003C\u002Fa> |\u003C\u002Fp>\n\u003Ch3>Why you should use Melapress Login Security\u003C\u002Fh3>\n\u003Cp>Melapress Login Security is a WordPress plugin built from the ground up to help you improve the security of your user accounts and secure your WordPress login. Supercharge login credentials for maximum effectiveness and put a stop to unlimited login attempts, weak passwords, and inactive users. Set up policies to reduce your attack surface area such as login times restrictions, change the WordPress login URL, and much more.\u003C\u002Fp>\n\u003Ch3>Free and premium support\u003C\u002Fh3>\n\u003Cp>Support for the free edition of Melapress Login Security is free on the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fmelapress-login-security\u002F\" rel=\"ugc\">WordPress support forums\u003C\u002Fa>. Premium world-class support via one-to-one email is available to the Premium users – \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\u002Fpricing\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">upgrade to premium\u003C\u002Fa> to benefit from priority support.\u003C\u002Fp>\n\u003Cp>For any other queries, feedback, or if you simply want to get in touch with us, please use our \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fcontact\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">contact form\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>MAINTAINED & SUPPORTED BY MELAPRESS\u003C\u002Fh4>\n\u003Cp>Melapress builds high-quality WordPress security & admin plugins such as \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-2fa\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">WP 2FA\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-user-roles-editor\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Melapress Role Editor\u003C\u002Fa>,and \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-activity-log\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">WP Activity Log\u003C\u002Fa>, the #1 user-rated activity log plugin for WordPress.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002F?utm_source=wp+repo&utm_medium=repo+link&utm_campaign=wordpress_org&utm_content=mls\" rel=\"nofollow ugc\">Visit our website\u003C\u002Fa> to see how our plugins can help you better manage and improve the security and administration of your WordPress websites and users.\u003C\u002Fp>\n\u003Ch3>Install the plugin from within WordPress\u003C\u002Fh3>\n\u003Cp>Keeping a secure WordPress login page is easy with \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa>. Simply:\u003C\u002Fp>\n\u003Col>\n\u003Cli>From your WordPress dashboard, navigate to Plugins > Add New\u003C\u002Fli>\n\u003Cli>Search for “\u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa>”\u003C\u002Fli>\n\u003Cli>Install & activate \u003Ca href=\"https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\" rel=\"nofollow ugc\">Melapress Login Security\u003C\u002Fa> from your Plugins page\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Install the plugin manually (via file upload)\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Download the plugin from the WordPress plugins repository\u003C\u002Fli>\n\u003Cli>Unzip the zip file and upload the folder to the \u003Ccode>\u002Fwp-content\u002Fplugins\u002F\u003C\u002Fcode> directory\u003C\u002Fli>\n\u003Cli>Activate the Melapress Login Security plugin through the Plugins page in WordPress\u003C\u002Fli>\n\u003C\u002Fol>\n","Enforce WordPress login and password security policies to protect user accounts and prevent unauthorized logins.",2000,27376,96,19,"2026-05-20T18:29:00.000Z","5.5","7.3",[20,114,115,116,21],"limit-login-attempts","limit-logins","login","https:\u002F\u002Fmelapress.com\u002Fwordpress-login-security\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmelapress-login-security.2.3.0.zip","2025-07-25 16:23:06",{"slug":121,"name":122,"version":123,"author":124,"author_profile":125,"description":126,"short_description":127,"active_installs":128,"downloaded":129,"rating":130,"num_ratings":131,"last_updated":132,"tested_up_to":133,"requires_at_least":134,"requires_php":135,"tags":136,"homepage":142,"download_link":143,"security_score":144,"vuln_count":145,"unpatched_count":32,"last_vuln_date":146,"fetched_at":28},"bot-for-telegram-on-woocommerce","Bot for Telegram on WooCommerce","1.3.0","Guru Team","https:\u002F\u002Fprofiles.wordpress.org\u002Fguruteam\u002F","\u003Cp>Bot for Telegram on WooCommerce\u003C\u002Fp>\n\u003Cp>🎉 Great news! We’ve added the Pro plugin features to our free plugin! 🚀 The Pro plugin is no longer supported — all those awesome features are now available for free! 🎁 If you were using the Pro version, make sure to deactivate it. 🙌\u003C\u002Fp>\n\u003Cp>Many sites on WordPress use eCommerce with WooCommerce. Nowadays we have a lot of trading platforms apart from WebSite. And one of them is Telegram, currently growing into powerful chat system with channels and automatic notices from bots.\u003C\u002Fp>\n\u003Cp>🟢 \u003Ca href=\"https:\u002F\u002Ft.me\u002FGuruWCTGBot\" rel=\"nofollow ugc\">Bot demo\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>🟢 \u003Ca href=\"https:\u002F\u002Fwp-guruteam.com\u002Fwoocommerce-telegram\u002F\" rel=\"nofollow ugc\">About plugin\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>This plugin will give you an opportunity to sell products via Telegram. All you need is to create bot and add it in the WooCommerce settings.\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FyKAPhXAwXZI?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>Supported product types\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Simple\u003C\u002Fli>\n\u003Cli>Grouped\u003C\u002Fli>\n\u003Cli>Affiliate\u003C\u002Fli>\n\u003Cli>Variable\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Features\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Automatic registration with phone number\u003C\u002Fli>\n\u003Cli>Synchronized cart between Telegram and WooCommerce\u003C\u002Fli>\n\u003Cli>NEW!!! Telegram Login\u003C\u002Fli>\n\u003Cli>Product catalog based on WP Rest API\u003C\u002Fli>\n\u003Cli>Native integration in WooCommerce settings with option to translate Telegram buttons from WordPress admin dashboard\u003C\u002Fli>\n\u003Cli>Automatic notice on order status change\u003C\u002Fli>\n\u003Cli>WooCommerce categories\u003C\u002Fli>\n\u003Cli>Fast Checkout\u003C\u002Fli>\n\u003Cli>My account section\u003C\u002Fli>\n\u003Cli>My orders section\u003C\u002Fli>\n\u003Cli>Order notifications on status changed\u003C\u002Fli>\n\u003Cli>Notification when new users are registered\u003C\u002Fli>\n\u003Cli>Parse user location\u003C\u002Fli>\n\u003Cli>Sending messages to all users of the bot\u003C\u002Fli>\n\u003Cli>Select categories to display in the bot\u003C\u002Fli>\n\u003Cli>Search products\u003C\u002Fli>\n\u003Cli>Custom Buttons\u003C\u002Fli>\n\u003Cli>Checkout in telegram (without redirect to the website)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>New!!!\u003C\u002Fstrong> Web App setting in custom keyboard\u003C\u002Fli>\n\u003Cli>\u003Cstrong>New!!!\u003C\u002Fstrong> Resend WooCommerce emails to Telegram\u003C\u002Fli>\n\u003C\u002Ful>\n","Bot for Telegram on WooCommerce is a plugin that allows you to create a telegram online store based on your website with WooCommerce.",300,16235,78,13,"2026-05-28T07:40:00.000Z","6.8.6","5.3","7.0",[137,138,139,140,141],"telegram-bot","telegram-login","telegram-notifications","telegram-shop","woocommerce-telegram-addon","https:\u002F\u002Fwp-guruteam.com\u002Fwoocommerce-telegram\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbot-for-telegram-on-woocommerce.1.3.0.zip",76,2,"2025-05-19 00:00:00",{"attackSurface":148,"codeSignals":253,"taintFlows":317,"riskAssessment":353,"analyzedAt":356},{"hooks":149,"ajaxHandlers":244,"restRoutes":250,"shortcodes":251,"cronEvents":252,"entryPointCount":32,"unprotectedCount":13},[150,155,159,163,166,169,172,175,180,185,189,192,195,198,202,206,208,212,214,216,218,220,222,226,229,232,236,240],{"type":151,"name":152,"callback":153,"file":154,"line":109},"action","admin_init","register_settings","includes\\class-lsec-admin-settings.php",{"type":151,"name":156,"callback":157,"file":154,"line":158},"admin_menu","add_admin_menu",20,{"type":151,"name":160,"callback":161,"file":154,"line":162},"admin_enqueue_scripts","admin_enqueue_assets",21,{"type":151,"name":152,"callback":164,"file":154,"line":165},"handle_unblock_ip",22,{"type":151,"name":152,"callback":167,"file":154,"line":168},"handle_block_ip",23,{"type":151,"name":152,"callback":170,"file":154,"line":171},"handle_clear_failed_log",24,{"type":151,"name":152,"callback":173,"file":154,"line":174},"handle_clear_activity_log",25,{"type":176,"name":177,"callback":178,"priority":11,"file":154,"line":179},"filter","wp_redirect","filter_options_page_redirect",28,{"type":151,"name":181,"callback":182,"priority":32,"file":183,"line":184},"init","handle_custom_admin_url","includes\\class-lsec-advanced-security.php",14,{"type":151,"name":186,"callback":187,"file":188,"line":184},"login_form_login","check_if_ip_blocked_before_login","includes\\class-lsec-login-tracker.php",{"type":151,"name":190,"callback":187,"file":188,"line":191},"login_form_lostpassword",15,{"type":151,"name":193,"callback":187,"file":188,"line":194},"login_form_retrievepassword",16,{"type":151,"name":196,"callback":187,"file":188,"line":197},"login_form_register",17,{"type":151,"name":199,"callback":200,"priority":158,"file":188,"line":201},"wp_login_failed","track_failed_login",18,{"type":151,"name":203,"callback":204,"priority":205,"file":188,"line":109},"wp_login","log_successful_login_activity",5,{"type":151,"name":203,"callback":207,"priority":191,"file":188,"line":158},"reset_attempts",{"type":151,"name":209,"callback":210,"file":188,"line":211},"admin_notices","closure",250,{"type":151,"name":209,"callback":210,"file":188,"line":213},290,{"type":151,"name":209,"callback":210,"file":188,"line":215},315,{"type":151,"name":209,"callback":210,"file":188,"line":217},350,{"type":151,"name":209,"callback":210,"file":188,"line":219},388,{"type":151,"name":209,"callback":210,"file":188,"line":221},417,{"type":151,"name":223,"callback":224,"priority":11,"file":225,"line":184},"lsec_send_successful_login_notification","send_successful_login_notification","includes\\class-lsec-telegram-notifier.php",{"type":151,"name":227,"callback":228,"priority":11,"file":225,"line":191},"lsec_send_failed_login_notification","send_failed_login_telegram_notification",{"type":151,"name":230,"callback":231,"priority":11,"file":225,"line":194},"lsec_send_account_lockout_notification","send_account_lockout_notification",{"type":151,"name":181,"callback":233,"priority":32,"file":234,"line":235},"lsec_check_manual_blacklist","login-security-with-telegram-alerts.php",57,{"type":176,"name":237,"callback":238,"priority":11,"file":234,"line":239},"plugin_row_meta","lsec_add_plugin_row_meta",61,{"type":151,"name":241,"callback":242,"file":234,"line":243},"plugins_loaded","lsec_init",63,[245],{"action":246,"nopriv":247,"callback":248,"hasNonce":249,"hasCapCheck":249,"file":225,"line":131},"lsec_send_test_telegram",false,"ajax_send_test_telegram",true,[],[],[],{"dangerousFunctions":254,"sqlUsage":255,"outputEscaping":272,"fileOperations":13,"externalRequests":47,"nonceChecks":257,"capabilityChecks":315,"bundledLibraries":316},[],{"prepared":256,"raw":257,"locations":258},27,6,[259,262,265,267,270,271],{"file":154,"line":260,"context":261},317,"$wpdb->get_results() with variable interpolation",{"file":188,"line":263,"context":264},378,"$wpdb->query() with variable interpolation",{"file":188,"line":266,"context":264},407,{"file":268,"line":269,"context":264},"uninstall.php",26,{"file":268,"line":179,"context":264},{"file":268,"line":33,"context":264},{"escaped":273,"rawEcho":158,"locations":274},103,[275,278,280,282,284,286,288,290,292,294,296,298,300,302,304,305,307,309,311,313],{"file":154,"line":276,"context":277},567,"raw output",{"file":154,"line":279,"context":277},576,{"file":154,"line":281,"context":277},612,{"file":154,"line":283,"context":277},613,{"file":154,"line":285,"context":277},614,{"file":154,"line":287,"context":277},615,{"file":154,"line":289,"context":277},632,{"file":154,"line":291,"context":277},649,{"file":154,"line":293,"context":277},656,{"file":154,"line":295,"context":277},777,{"file":154,"line":297,"context":277},790,{"file":154,"line":299,"context":277},794,{"file":154,"line":301,"context":277},820,{"file":188,"line":303,"context":277},251,{"file":188,"line":128,"context":277},{"file":188,"line":306,"context":277},316,{"file":188,"line":308,"context":277},360,{"file":188,"line":310,"context":277},389,{"file":188,"line":312,"context":277},418,{"file":234,"line":314,"context":277},126,7,[],[318,335,344],{"entryPoint":319,"graph":320,"unsanitizedCount":13,"severity":334},"handle_unblock_ip (includes\\class-lsec-login-tracker.php:245)",{"nodes":321,"edges":332},[322,327],{"id":323,"type":324,"label":325,"file":188,"line":326},"n0","source","$_GET (x2)",248,{"id":328,"type":329,"label":330,"file":188,"line":303,"wp_function":331},"n1","sink","echo() [XSS]","echo",[333],{"from":323,"to":328,"sanitized":249},"low",{"entryPoint":336,"graph":337,"unsanitizedCount":13,"severity":334},"handle_block_ip (includes\\class-lsec-login-tracker.php:309)",{"nodes":338,"edges":342},[339,341],{"id":323,"type":324,"label":325,"file":188,"line":340},312,{"id":328,"type":329,"label":330,"file":188,"line":306,"wp_function":331},[343],{"from":323,"to":328,"sanitized":249},{"entryPoint":345,"graph":346,"unsanitizedCount":13,"severity":334},"\u003Cclass-lsec-login-tracker> (includes\\class-lsec-login-tracker.php:0)",{"nodes":347,"edges":351},[348,350],{"id":323,"type":324,"label":349,"file":188,"line":326},"$_GET (x4)",{"id":328,"type":329,"label":330,"file":188,"line":303,"wp_function":331},[352],{"from":323,"to":328,"sanitized":249},{"summary":354,"deductions":355},"The \"login-security-with-telegram-alerts\" plugin v1.0.0 exhibits a generally good security posture based on the provided static analysis.  The absence of critical or high severity taint flows, dangerous functions, file operations, and the overall low number of entry points with proper authentication checks are positive indicators.  The plugin also shows a commitment to secure coding practices with a high percentage of SQL queries using prepared statements and outputs being properly escaped.  Furthermore, the complete lack of known vulnerabilities in its history is a significant strength, suggesting a well-maintained and secure codebase.",[],"2026-03-17T00:42:11.304Z",{"wat":358,"direct":369},{"assetPaths":359,"generatorPatterns":363,"scriptPaths":364,"versionParams":365},[360,361,362],"\u002Fwp-content\u002Fplugins\u002Flogin-security-with-telegram-alerts\u002Fassets\u002Fcss\u002Fadmin-styles.css","\u002Fwp-content\u002Fplugins\u002Flogin-security-with-telegram-alerts\u002Fassets\u002Fjs\u002Fadmin-scripts.js","\u002Fwp-content\u002Fplugins\u002Flogin-security-with-telegram-alerts\u002Fassets\u002Fcss\u002Flogin-styles.css",[],[361],[366,367,368],"login-security-with-telegram-alerts\u002Fassets\u002Fcss\u002Fadmin-styles.css?ver=","login-security-with-telegram-alerts\u002Fassets\u002Fjs\u002Fadmin-scripts.js?ver=","login-security-with-telegram-alerts\u002Fassets\u002Fcss\u002Flogin-styles.css?ver=",{"cssClasses":370,"htmlComments":379,"htmlAttributes":381,"restEndpoints":384,"jsGlobals":385,"shortcodeOutput":387},[371,372,373,374,375,376,377,378],"lsec-admin-settings-page","lsec-settings-section","lsec-field-wrapper","lsec-field-label","lsec-field-input","lsec-field-textarea","lsec-button-save","lsec-message-container",[380],"\u003C!-- IMPORTANT: Add this filter to capture the redirect after saving options -->",[382,383],"data-lsec-setting-id","data-lsec-section-id",[],[386],"window.lsec_ajax_object",[],{"error":249,"url":389,"statusCode":390,"statusMessage":391,"message":391},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Flogin-security-with-telegram-alerts\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":32,"versions":393},[394],{"version":6,"download_url":25,"svn_tag_url":395,"released_at":27,"has_diff":247,"diff_files_changed":396,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":397,"is_current":249},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Flogin-security-with-telegram-alerts\u002Ftags\u002F1.0.0\u002F",[],[]]