[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMTpSvshA3UlMjtnSoFNtJRgXTnaEticPG9WFmOY14Kk":3,"$fbUrAJlUjBnUvjzZufsKPDVB3z_2DstoGpSJJstSmhHU":131,"$f3Q9cpP-5hKwCzhms9BW7FU3Ykiqu1hVJxGuVDHJOD5A":136},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"pura-vida-vulnerability-scanner","Pura Vida Vulnerability Scanner","1.1.0","trgomez","https:\u002F\u002Fprofiles.wordpress.org\u002Ftrgomez\u002F","\u003Cp>Pura Vida Vulnerability Scanner checks everything installed on your site, including plugins, themes and WordPress core, against the \u003Cstrong>Wordfence Intelligence\u003C\u002Fstrong> vulnerability database, audits your site’s security posture, and shows you exactly what is at risk and how to fix it.\u003C\u002Fp>\n\u003Cp>It does not invent findings. It correlates your installed software and configuration against authoritative public sources (Wordfence Intelligence, CVE\u002FMITRE, the WordPress.org update channel) and live checks of your own server.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security overview\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The dashboard opens with an at-a-glance status table covering:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress Version: OK \u002F Warning\u003C\u002Fli>\n\u003Cli>Vulnerable Plugins: OK \u002F Critical \u002F High \u002F Medium\u003C\u002Fli>\n\u003Cli>Missing Headers: Present \u002F Missing \u002F N\u002FA (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy)\u003C\u002Fli>\n\u003Cli>SSL: Valid \u002F Expiring soon \u002F Expired \u002F N\u002FA (certificate expiry)\u003C\u002Fli>\n\u003Cli>DNS: OK \u002F Issues \u002F N\u002FA\u003C\u002Fli>\n\u003Cli>Email Security: SPF and DMARC (DKIM is selector-specific)\u003C\u002Fli>\n\u003Cli>CDN\u002FWAF: Detected \u002F Not detected \u002F N\u002FA\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What it does\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Inventories every installed plugin, theme and the WordPress core version.\u003C\u002Fli>\n\u003Cli>Matches each item and version against a continuously updated vulnerability feed.\u003C\u002Fli>\n\u003Cli>Shows severity (CVSS), the CVE identifier, a description and the recommended fix for every finding.\u003C\u002Fli>\n\u003Cli>Audits your configuration and lists prioritized hardening recommendations (2FA, updates, HTTPS, file editor, and more).\u003C\u002Fli>\n\u003Cli>Optional scheduled scans with email alerts when new critical\u002Fhigh issues appear.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data sources\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Wordfence Intelligence Vulnerability Data Feed: free for personal and commercial use; includes CVE (MITRE) and CVSS information.\u003C\u002Fli>\n\u003Cli>CVE (MITRE Corporation): the canonical vulnerability identifiers.\u003C\u002Fli>\n\u003Cli>WordPress.org update channel: available core, plugin and theme updates.\u003C\u002Fli>\n\u003Cli>Live site checks performed by the plugin: HTTP headers, SSL, DNS, SPF\u002FDMARC and CDN\u002FWAF.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This product includes data that may be copyrighted by Defiant Inc. (Wordfence Intelligence) and by the MITRE Corporation (CVE®); their notices are displayed alongside the relevant findings.\u003C\u002Fp>\n\u003Cp>Developed by Pura Vida Design Studio, Open Source Security & Website Tools (https:\u002F\u002Fpuravidadesignstudio.com\u002F).\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to one external service to function: the Wordfence Intelligence Vulnerability Data Feed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Wordfence Intelligence Vulnerability Data Feed (Defiant Inc.)\u003C\u002Fstrong>\u003Cbr \u002F>\nThis plugin downloads the public WordPress vulnerability database from Wordfence in order to match it against the plugins, themes and core version installed on your site.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>What is sent: your Wordfence Intelligence API key (in the request Authorization header) and your site’s URL (in the request User-Agent header), sent to https:\u002F\u002Fwww.wordfence.com\u002F. The list of plugins and themes installed on your site is NOT transmitted; matching is performed locally on your own server.\u003C\u002Fli>\n\u003Cli>When it is sent: when you run a manual scan, and when a scheduled scan runs (about once per day). The downloaded database is cached locally for 24 hours so the service is contacted at most about once per day.\u003C\u002Fli>\n\u003Cli>Service terms: https:\u002F\u002Fwww.wordfence.com\u002Fwordfence-intelligence-terms-and-conditions\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fwww.wordfence.com\u002Fprivacy-policy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin also performs read-only checks against your own site for the Security Overview: a loopback HTTP request to your own home URL (to inspect response headers and detect a CDN\u002FWAF) and DNS lookups for your own domain (to check DNS resolution and SPF\u002FDMARC records). These query your own domain and public DNS only; no data is sent to any third party.\u003C\u002Fp>\n","Scan your plugins, themes and WordPress core against trusted vulnerability databases and get a clear, prioritized security overview.",0,132,"2026-06-16T17:46:00.000Z","7.0.2","5.6","7.2",[18,19,20,21,22],"hardening","malware","scanner","security","vulnerability","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpura-vida-vulnerability-scanner.1.1.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},1,30,94,"2026-08-25T00:33:23.884Z",[36,53,76,100,114],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":25,"downloaded":44,"rating":11,"num_ratings":11,"last_updated":45,"tested_up_to":14,"requires_at_least":46,"requires_php":47,"tags":48,"homepage":51,"download_link":52,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"aipatch-security-scanner","Aipatch Security Scanner","2.0.2","Esteban","https:\u002F\u002Fprofiles.wordpress.org\u002Festebandezafra\u002F","\u003Cp>\u003Cstrong>Aipatch Security Scanner\u003C\u002Fstrong> is a modular security audit engine built for site owners, developers, and AI-powered agents who need deep visibility into WordPress security posture — without the bloat of all-in-one security suites.\u003C\u002Fp>\n\u003Ch4>Why Aipatch Security Scanner?\u003C\u002Fh4>\n\u003Cp>Most WordPress security plugins are either too simple to be useful or too heavy to be practical. Aipatch takes a different approach:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Audit-first architecture.\u003C\u002Fstrong> Every check is a standalone, testable module that returns structured findings with severity, confidence, evidence, and fingerprints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built for automation.\u003C\u002Fstrong> 23 MCP abilities expose the full audit, scanning, and remediation surface to external AI agents — making Aipatch the first WordPress security plugin designed for agentic workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero external dependencies.\u003C\u002Fstrong> Everything runs locally. No accounts, no cloud services, no API keys required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reversible by design.\u003C\u002Fstrong> Every automated remediation stores rollback data so you can undo any change with one click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Core Capabilities\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>36-Point Security Audit\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Aipatch runs 36 automated checks across 8 categories — core, plugins, themes, users, configuration, server, access control, and malware surface:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Outdated WordPress core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Default admin username, excessive admin accounts, inactive admin users, user ID 1 exposure\u003C\u002Fli>\n\u003Cli>XML-RPC, file editor, debug mode, debug log, REST API exposure, directory listing\u003C\u002Fli>\n\u003Cli>PHP version, HTTPS, file permissions, security headers (X-Frame-Options, CSP, etc.)\u003C\u002Fli>\n\u003Cli>Database prefix, sensitive files, PHP execution in uploads, auto-update configuration\u003C\u002Fli>\n\u003Cli>Salt key strength, cron health, cookie security flags, CORS, application passwords\u003C\u002Fli>\n\u003Cli>Exposed backup files, phpinfo files, uploads directory indexing, default login URL\u003C\u002Fli>\n\u003Cli>Database credential security, file installation permissions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Every finding includes a severity (critical \u002F high \u002F medium \u002F low \u002F info), confidence score, human-readable explanation, and actionable recommendation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Weighted Security Score (0–100)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A logarithmic scoring engine computes an overall security score and per-area breakdown across six risk dimensions: software, access control, configuration, infrastructure, malware surface, and vulnerability exposure. Severity weights and confidence multipliers ensure the score reflects actual risk, not just issue count.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Multi-Layer Malware File Scanner\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A three-layer file scanner (content 55%, context 25%, integrity 20%) with 27 detection signatures, Shannon entropy analysis, and malware family classification detects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Code execution patterns: eval(), assert(), create_function(), preg_replace \u002Fe\u003C\u002Fli>\n\u003Cli>System command functions: shell_exec, exec, passthru, backtick operators\u003C\u002Fli>\n\u003Cli>Obfuscation techniques: base64 encoding, hex encoding, str_rot13, gzinflate chains, chr() concatenation, variable variables, suspiciously long lines\u003C\u002Fli>\n\u003Cli>Network\u002Fexfiltration: cURL execution, fsockopen, remote file_get_contents\u003C\u002Fli>\n\u003Cli>Known backdoor signatures: c99, r57, WSO, b374k, weevely, FilesMan\u003C\u002Fli>\n\u003Cli>WordPress-specific threats: unauthorized admin creation, critical option injection, security function removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Scanning runs in batches via an async job system with configurable batch sizes — safe for shared hosting.\u003C\u002Fp>\n\u003Cp>Files are classified into 11 malware families (web shell, obfuscated loader, dropper, persistence backdoor, cloaked PHP, code injector, and more) with confidence scores and remediation hints.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Core Integrity Verification\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Verifies every core file against official checksums from api.wordpress.org. Detects modified core files (checksum mismatch), missing core files, and unexpected files planted in wp-admin\u002F or wp-includes\u002F. Core tampering findings are automatically escalated to critical severity with zero false-positive likelihood.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Build a known-good hash baseline of all PHP files in your installation. Diff against it at any time to detect modified, deleted, or newly added files. Origin detection distinguishes core, plugin, theme, and upload files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A local knowledge base of known plugin, theme, and core vulnerabilities with a database-backed caching layer for fast lookups. Provider architecture allows extending with external feeds.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-Click Remediation with Rollback\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Apply fixes directly from findings — change WordPress options, delete suspicious files, rename files, patch file contents, or add .htaccess rules. Every automated action stores a full rollback payload so you can reverse any change. Manual remediations can be logged for audit trails.\u003C\u002Fp>\n\u003Cp>Six supported action types: \u003Ccode>wp_option\u003C\u002Fcode>, \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>rename_file\u003C\u002Fcode>, \u003Ccode>file_patch\u003C\u002Fcode>, \u003Ccode>htaccess_rule\u003C\u002Fcode>, \u003Ccode>manual\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hardening Module\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Five toggleable hardening rules with clear explanations and compatibility warnings:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable XML-RPC — blocks external XML-RPC requests and removes X-Pingback header\u003C\u002Fli>\n\u003Cli>Hide WordPress Version — removes version leaks from source, RSS feeds, scripts, and styles\u003C\u002Fli>\n\u003Cli>Restrict REST API — limits sensitive endpoints to authenticated users\u003C\u002Fli>\n\u003Cli>Block Author Scanning — prevents user enumeration via author archives\u003C\u002Fli>\n\u003Cli>Login Brute-Force Protection — rate-limits login attempts per IP with configurable thresholds and lockout duration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Persistent Findings Store\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All audit findings persist in a dedicated database table with automatic deduplication by fingerprint. Track findings over time — dismissed findings stay dismissed across scans; resolved findings reopen if the issue reappears.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Event Logging\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Every scan, hardening change, remediation, and significant event is logged to a dedicated table. Logs are filterable by severity and exportable as CSV.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Site Health Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Adds 6 security tests to the built-in Site Health screen: file editor, debug mode, XML-RPC, admin username, SSL, and overall security score.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Diagnostics\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Built-in performance profiling to identify slow queries, high memory usage, and resource bottlenecks related to security operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>10 authenticated endpoints under the \u003Ccode>aipatch-security-scanner\u002Fv1\u003C\u002Fcode> namespace for triggering scans, retrieving summaries, toggling hardening, exporting logs, and running performance diagnostics.\u003C\u002Fp>\n\u003Ch4>MCP Surface for AI Agents (23 Abilities)\u003C\u002Fh4>\n\u003Cp>Aipatch exposes 23 structured abilities via the WordPress Abilities API — making your site’s security surface fully accessible to external AI agents, coding assistants, and orchestration tools:\u003C\u002Fp>\n\u003Cp>By default, only \u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> is enabled. You can enable additional abilities from \u003Cstrong>Aipatch Security Scanner -> Settings -> MCP Abilities\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> — Run a full 36-check security audit with scored findings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-suspicious\u003C\u002Fstrong> — Quick heuristic scan for suspicious files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fstart-file-scan\u003C\u002Fstrong> — Launch an async multi-layer malware scan job\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fprocess-file-scan-batch\u003C\u002Fstrong> — Process next batch of files in a running scan\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-progress\u003C\u002Fstrong> — Check file scan progress\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-results\u003C\u002Fstrong> — Retrieve enriched scan results with family, reasons, layer scores\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-scan-summary\u003C\u002Fstrong> — Comprehensive latest scan summary with classification breakdown\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-suspicious-files\u003C\u002Fstrong> — List suspicious files from latest scan (no job_id needed)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Integrity & Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fverify-core-integrity\u003C\u002Fstrong> — Verify WP core files against official api.wordpress.org checksums\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-build\u003C\u002Fstrong> — Build or refresh the known-good file hash baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-diff\u003C\u002Fstrong> — Compare current filesystem against stored baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-stats\u003C\u002Fstrong> — Baseline statistics by origin type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-baseline-drift\u003C\u002Fstrong> — Combined baseline drift + core integrity report\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Findings & Monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-findings\u003C\u002Fstrong> — Query persistent findings with status\u002Fseverity\u002Fcategory filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-stats\u003C\u002Fstrong> — Aggregate finding statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-diff\u003C\u002Fstrong> — New and resolved findings since a point in time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-file-finding-detail\u003C\u002Fstrong> — Single finding with decoded metadata, layer scores, family\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fdismiss-finding\u003C\u002Fstrong> — Dismiss a finding as accepted risk\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Remediation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fapply-remediation\u003C\u002Fstrong> — Apply a security fix with rollback support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Frollback-remediation\u003C\u002Fstrong> — Undo a previously applied fix\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-remediations\u003C\u002Fstrong> — List remediation history with filters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Jobs & Status\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-jobs\u003C\u002Fstrong> — List scan\u002Faudit jobs with filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-async-job-status\u003C\u002Fstrong> — Check async job status and retrieve results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>20 abilities are read-only; only 3 (dismiss, apply-remediation, rollback) modify site state. All abilities include typed input\u002Foutput schemas, permission checks (\u003Ccode>manage_options\u003C\u002Fcode>), and structured error responses.\u003C\u002Fp>\n\u003Ch4>What Aipatch Does NOT Do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>It is NOT a firewall or WAF — it does not filter incoming traffic.\u003C\u002Fli>\n\u003Cli>It does NOT intercept frontend requests or affect page load performance.\u003C\u002Fli>\n\u003Cli>It does NOT phone home, require an account, or send data externally.\u003C\u002Fli>\n\u003Cli>It does NOT inject ads, upsells, or nag notices.\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress security scanner with 36 checks, malware scanning, core integrity verification, remediation, and 23 MCP abilities.",477,"2026-05-03T09:18:00.000Z","6.5","7.4",[49,18,50,21,22],"audit","malware-scanner","https:\u002F\u002Fgithub.com\u002Festebanstifli\u002Faipatch-security-scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.2.0.2.zip",{"slug":54,"name":55,"version":56,"author":57,"author_profile":58,"description":59,"short_description":60,"active_installs":61,"downloaded":62,"rating":63,"num_ratings":64,"last_updated":65,"tested_up_to":14,"requires_at_least":66,"requires_php":15,"tags":67,"homepage":71,"download_link":72,"security_score":73,"vuln_count":74,"unpatched_count":11,"last_vuln_date":75,"fetched_at":27},"wp-malware-removal","Malcure Malware Shield — Removal, Repair, Monitor","19.9.6","Malcure Web Security","https:\u002F\u002Fprofiles.wordpress.org\u002Fmalcure\u002F","\u003Cp>Is your website acting strangely? Seeing ‘Deceptive Site Ahead’ warnings, Japanese SEO hack, or random redirects? Time to fix and monitor your site with \u003Cstrong>Malcure Malware Shield\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Malcure Malware Shield scans for infections, runs silent scheduled scans, and sends alerts before threats spread — turning one-time cleanup into always-on protection.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Malcure scans files, databases, and user accounts to find malware casual scanners miss — backdoors hidden in images, injections in your database, rogue, hidden admin accounts buried in your tables that don’t show up in the admin area. Then it watches your site with scheduled scans and alerts, so one-time cleanup becomes always-on protection.\u003C\u002Fp>\n\u003Cp>Detection runs against 50,000+ signatures with real-time threat intelligence — the same definitions for every user, free or paid. You see every infection with exact file paths and line numbers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Activate \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Know \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>What Our Users Say\u003C\u002Fh3>\n\u003Cp>Quotes are verbatim from WordPress.org support reviews, except for bracketed edits (for example, competitor names removed).\u003C\u002Fp>\n\u003Ch4>Best by far, better than [competitor name removed] and other giants\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“You can see it is a bunch of geeks that created this, with skill and visual creativity at that. I spent hours trying to find a plugin like this. So many options and such bad results until now. Great job guys. You deserve it. Simple and effective. (Disclaimer to other potential readers: there are many types of hacks\u002Fmalware out there, every scenario is different, but start with the Malcure scan and see how it goes. 9\u002F10 you won’t be disappointed, my guess)” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-by-far-better-than-wordfence-and-other-giants\u002F\" rel=\"ugc\">@dalingzaf\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>The ONLY plugin that scans every file-type…\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“I am a web developer and have tried many malware removal plugins, including popular ones [competitor names removed]. However, none of them detected some unusual files that were actually malware causing regular attacks. Some of these files were in JPG format.” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fthe-only-plugin-that-scans-files-in-real-time-2\u002F\" rel=\"ugc\">@devzeeshanx\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>Best Malware Removal Plugin in just few minutes\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“Most security plugins that are free only scan the code, but Malcure Malware Removal Plugin scans the wordpress database and the code files in few minutes. Accurately shows which Database table row is infected and it helps resolve the hacking attempt instantly. Saves a lot of time for the developers. Thank You Team Malcure” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbest-malware-removal-plugin-in-just-few-minutes\u002F\" rel=\"ugc\">@s3630\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>It’s not just a “teaser”\u003C\u002Fh4>\n\u003Cblockquote>\n\u003Cp>“This plugin really found the malware, and removed it. Really for free. Thanks guys, I’m going to donate now!” — \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fits-not-just-a-teaser\u002F\" rel=\"ugc\">@halucska\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>What Malcure Does\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Detection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>File Scan:\u003C\u002Fstrong> Core files, themes, plugins, images, uploads — backdoors, shells, obfuscated code, and malware hidden inside image files and archives.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Database Scan:\u003C\u002Fstrong> Finds malicious injections, recurring malware, and SEO injection links that other non-thorough scanners never see.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Scan:\u003C\u002Fstrong> Detects rogue admin accounts and compromised metadata, including application passwords that bypass your login page.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DeepScan™:\u003C\u002Fstrong> Scans every file-type without skipping within resource-limits and hidden files where malware hides.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checksum Verification:\u003C\u002Fstrong> Compares your core, plugin, and theme files against official repository checksums. Tampered files are flagged by severity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Hack Detection:\u003C\u002Fstrong> Catches Japanese Keyword Hack, Pharma Hack, and other SEO hacks in page titles and database records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Scanner:\u003C\u002Fstrong> Checks installed plugins and themes against a real-time vulnerability database.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checksum Intelligence:\u003C\u002Fstrong> Checksum-based verification reduces false alarms compared to heuristic-only scanners.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>50,000+ Signatures:\u003C\u002Fstrong> Detects known variants — C99, R57, RootShell, and many more — plus unknown threats via behavioral analysis.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Monitoring & Alerts\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Scheduled Scans:\u003C\u002Fstrong> Set a cadence — daily, weekly, or monthly. Runs silently in the background.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Weekly Security Pulse Email:\u003C\u002Fstrong> A verdict-first security-critical weekly summary — gives you a heads-up — “All Clear”, “Please Review”, or “Needs Immediate Attention” — delivered to your inbox. Covers scan results, failed logins, privileged activity, file edits, and updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled Scan Results Email:\u003C\u002Fstrong> Email report of scheduled scans — clean or infected. Know immediately when a scheduled scan finishes. Gives you early heads-up if malware found and before it spreads and affects SEO or gets the site blacklisted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Recipients:\u003C\u002Fstrong> Choose who gets notified. Licensee, Registrant and additional CC recipients. Send a test Pulse to verify your mail configuration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Event Log:\u003C\u002Fstrong> 100-day forensic record of every security event for root-cause analysis.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Inspector:\u003C\u002Fstrong> See who’s logged in — IP, user-agent, login time, and session expiration.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Hardening & Firewall\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Block Path Traversal:\u003C\u002Fstrong> Stops attackers from accessing sensitive system files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block PHP Uploads:\u003C\u002Fstrong> Prevents malicious scripts from being uploaded.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stop User Enumeration:\u003C\u002Fstrong> Blocks bots from fishing for usernames.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API Protection:\u003C\u002Fstrong> Prevents user data leakage via the WP REST API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack Counter:\u003C\u002Fstrong> See how many attacks the firewall has blocked, right on your dashboard.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Incident Response\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Session Nuke:\u003C\u002Fstrong> Force-logout every user instantly to kick out intruders.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Salt Shuffler:\u003C\u002Fstrong> One-click rotation of \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5230\" rel=\"nofollow ugc\">security keys (salts)\u003C\u002Fa> to invalidate all browser cookies.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Real-Time Threat Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero-Day:\u003C\u002Fstrong> Threat definitions served in real time via the Malcure Cloud. No days-long delay.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Search Console:\u003C\u002Fstrong> Connect directly to fetch security warnings and blacklist status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> Scans send file checksums and your site’s domain to Malcure servers. No sensitive user data is transmitted. Use of the API is subject to our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=1720\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=3\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight:\u003C\u002Fstrong> Runs only on demand or on schedule. No persistent background processes. No bloat.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Dashboard & Experience\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Dashboard Widget:\u003C\u002Fstrong> At-a-glance malware status, attack count, and quick-scan CTA on the WP dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Skins:\u003C\u002Fstrong> Classic and Dark skins to match your workflow.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan Completion Audio Preferences:\u003C\u002Fstrong> Configure sound-notifications for scans.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Diagnostics Page:\u003C\u002Fstrong> Environment diagnostics for troubleshooting.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Who This Plugin Is For\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Agencies and developers\u003C\u002Fstrong> who need fast triage across multiple sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce, membership, and lead-gen sites\u003C\u002Fstrong> where downtime and SEO damage are expensive.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site owners\u003C\u002Fstrong> who want clear results — what was flagged, exactly where.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works (Scan \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Review \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Clean \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Monitor)\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\u003Cstrong>Scan\u003C\u002Fstrong> — Open \u003Cstrong>Malcure Scanner\u003C\u002Fstrong> in your Admin Dashboard. Run a scan to check files, database, users, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Review\u003C\u002Fstrong> — Every finding comes with an exact location: file path, line number, or database record. Decide what to repair, delete, or keep.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean & Recover\u003C\u002Fstrong> — Shows every infection so you can clean it yourself. Advanced Edition adds repair tools, file operations, whitelisting, and WP-CLI automation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Monitor\u003C\u002Fstrong> — Set up scheduled scans. Get email alerts the moment a threat is found.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Is It Free?\u003C\u002Fh4>\n\u003Cp>We believe in 100% transparency.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Professional-grade Detection (Knowledge). You see every infected file and database row (exact file path & line number), so you can clean it yourself for free.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free Forever:\u003C\u002Fstrong> Real-time Threat Intelligence, Scheduled Scans, Weekly Security Pulse email, and Firewall & Hardening.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pro Upgrade:\u003C\u002Fstrong> File Repairs, Deletions, Whitelisting, Advanced Scan Filters, WP-CLI Automation, Auto-Definition Updates, Bulk Client-Servicing Features & Premium Support (Expertise).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>You are never forced to pay to \u003Cem>find\u003C\u002Fem> a hack.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FEbSbxiTOc8k?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Ch4>Advanced Edition\u003C\u002Fh4>\n\u003Cp>For when detection is not enough — you need to remediate.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>1-Click Repairs:\u003C\u002Fstrong> Repair infected files from the official source via Malcure Cloud.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Delete Files:\u003C\u002Fstrong> Remove infected or irreparable files directly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File & DB Whitelisting:\u003C\u002Fstrong> Suppress alarms on specific files and database records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI Integration:\u003C\u002Fstrong> Full command-line control — async scans, definitions sync, checksum refresh, reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Definition Updates:\u003C\u002Fstrong> Hourly cron keeps definitions current without manual intervention.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Scan Filters:\u003C\u002Fstrong> Include or exclude directories, custom regex signatures for database and files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Inspector:\u003C\u002Fstrong> Inspect files inline instead of having to go via s\u002Fftp or ssh or file-managers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Copy Scan Results:\u003C\u002Fstrong> Copy results to clipboard for client reporting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP Config & Diagnostics:\u003C\u002Fstrong> View full PHP configuration in diagnostics.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Factory Reset:\u003C\u002Fstrong> One-click plugin reset.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Premium Support:\u003C\u002Fstrong> Direct access to our security analysts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116\" rel=\"nofollow ugc\">\u003Cstrong>Get Malcure Advanced Edition\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Expert Malware Removal Service\u003C\u002Fh4>\n\u003Cp>In over your head? Our security analysts will clean your site for you — 100% removal guarantee, same-day service, blacklist removal, and 15-day post-cleanup cover.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">\u003Cstrong>Book Expert Malware Removal\u003C\u002Fstrong>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Troubleshooting\u003C\u002Fh3>\n\u003Ch4>Some files are detected by Malcure Malware Shield as “suspicious”. What gives?\u003C\u002Fh4>\n\u003Cp>Malcure’s DeepScan checks each file for malware. However some files aren’t pure malware but may contain code that is suspicious and could potentially do nasty things. You should carefully review and analyse them to see if they indeed do anything nasty.\u003C\u002Fp>\n\u003Ch4>I can’t get Malcure Malware Shield to work. It hangs \u002F doesn’t complete the scan \u002F breaks for some reason.\u003C\u002Fh4>\n\u003Cp>If you think that the plugin is broken, \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Malcure Malware Shield (or for that matter other plugins) may break on malware affected \u002F broken websites. \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=116\" rel=\"nofollow ugc\">Malcure Advanced Edition\u003C\u002Fa> integrates with WP CLI and allows you to complete the scan from WP CLI even when the site is blocked by the webhost or when you are unable to login to the website.\u003C\u002Fp>\n\u003Ch4>My site is infected however Malcure Malware Shield doesn’t detect the infection.\u003C\u002Fh4>\n\u003Cp>Malware keeps evolving. If you come across malware that Malcure Malware Shield is not able to identify, you may \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=157\" rel=\"nofollow ugc\">please report it here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>The scan gets stuck midway. What should I do?\u003C\u002Fh4>\n\u003Cp>In case of such an event, please file a support request with us and we’ll be more than happy to troubleshoot the issue.\u003C\u002Fp>\n\u003Cp>Please visit \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=5677\" rel=\"nofollow ugc\">this page\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I cleaned my site but it got infected again. What should I do?\u003C\u002Fh4>\n\u003Cp>Malware cleanup is a waste of time and effort unless you find the root cause behind the malware infection and monitor for recurrence. How was someone able to infect your website? Have you plugged in that security hole?\u003C\u002Fp>\n\u003Cp>Please read \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002Fblog\u002Fsecurity\u002Fwhy-do-wordpress-websites-get-hacked\u002F\" rel=\"nofollow ugc\">Why Do Websites Get Hacked\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Google Safe Browsing site status (or some other scanner) still shows my site as infected. What should I do?\u003C\u002Fh4>\n\u003Cp>First make sure you purge your site cache. Second, Google (and other scanners) cache the results for some time. You’ll need to force or refresh the scan. You can also file a request with us to \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">get your site off any blacklists\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>I found a suspicious file, what now?\u003C\u002Fh4>\n\u003Cp>If Malcure flags it, it’s likely malicious. You can inspect the file content using our built-in inspector. If you’re unsure, consider our \u003Ca href=\"https:\u002F\u002Fmalcure.com\u002F?p=107\" rel=\"nofollow ugc\">Expert Malware Removal Service\u003C\u002Fa>.\u003C\u002Fp>\n","Your WordPress site hacked? Malcure scans files AND database to find and help you remove malware casual scanners miss. Free. No bloat.",10000,662306,90,72,"2026-07-14T03:24:00.000Z","6.2",[68,50,21,69,70],"antivirus","virus","vulnerability-scanner","https:\u002F\u002Fmalcure.com\u002F?p=116","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-malware-removal.19.9.6.zip",96,3,"2025-09-03 00:00:00",{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":84,"downloaded":85,"rating":86,"num_ratings":87,"last_updated":88,"tested_up_to":14,"requires_at_least":15,"requires_php":89,"tags":90,"homepage":95,"download_link":96,"security_score":97,"vuln_count":98,"unpatched_count":11,"last_vuln_date":99,"fetched_at":27},"sitelock","SiteLock Security – WP Hardening, Login Security & Malware Scans","5.1.2","SiteLock","https:\u002F\u002Fprofiles.wordpress.org\u002Fsitelocksecurity\u002F","\u003Cblockquote>\n\u003Cp>\u003Cstrong>🌟 Completely redesigned in Version 5.0 — now even stronger with 2FA in 5.1 🌟\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The SiteLock WordPress plugin was recently rebuilt with three goals: make it faster, make it clearer and move the heavy work to the cloud. We built a cloudfirst architecture, modernized UI, expanded security controls and stripped out everything that didn’t need to be there. Our latest 5.1 release builds on that foundation with TwoFactor Authentication (2FA) to strengthen login security and give you tighter control over access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>The big changes:\u003C\u002Fstrong>\u003Cbr \u002F>\n  – 🔒 Enhanced WordPress-specific hardening and login security controls\u003Cbr \u002F>\n  – ☁️ Cloud-powered scanning architecture for zero performance impact\u003Cbr \u002F>\n  – 🩺 New Site Health interface that shows you what matters in one view\u003Cbr \u002F>\n  – ⚡ Streamlined controls (fewer clicks to get protected)\u003Cbr \u002F>\n  – ✨ Modern codebase built for the WordPress you’re actually using today\u003Cbr \u002F>\n  – 🔢 Two-Factor Authentication (2FA) now available for stronger login protection\u003C\u002Fp>\n\u003Cp>If you used the old plugin: this is a different tool. If you’re new: you’re starting with the cleanest, fastest version of the plugin.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>Your website deserves protection that’s simple, fast and built for WordPress. SiteLock WordPress Security focuses on the everyday controls that matter most and helps you establish a secure baseline in minutes — WordPress-specific hardening, login protection with Two-Factor Authentication (2FA) and a clear Site Health dashboard that keeps you in control without slowing your site down. It’s lightweight, action-first protection that complements your host defenses: essential safeguards run inside WordPress while deeper checks happen securely in the SiteLock cloud. Skip heavy on-server scans and alert fatigue — run on-demand checks when you need extra assurance, so you can ship updates with confidence.\u003C\u002Fp>\n\u003Ch4>Security that grows with you\u003C\u002Fh4>\n\u003Cp>Our goal is straightforward: maintain a strong baseline with minimal overhead while giving you clear visibility and room to grow as your needs evolve.\u003Cbr \u002F>\nAnd because security is never static, this plugin keeps pace. Two-Factor Authentication (2FA) is now available to strengthen login security with an extra layer of protection.\u003C\u002Fp>\n\u003Ch4>Commercial plugin\u003C\u002Fh4>\n\u003Cp>This plugin is free but offers additional paid commercial upgrades or support.\u003C\u002Fp>\n\u003Ch3>What’s included\u003C\u002Fh3>\n\u003Ch4>WordPress Hardening: Cut common attack paths in just a few clicks\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Disable directory listing\u003C\u002Fli>\n\u003Cli>Restrict PHP execution in upload folders\u003C\u002Fli>\n\u003Cli>Limit unsafe script types\u003C\u002Fli>\n\u003Cli>Force strong configuration defaults to close risky gaps\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>All options are toggle-based and reversible — safe to enable, easy to test and lightweight on performance.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch4>Login Security: Protect what matters most — your access\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong>: Add a second layer of verification to protect admin access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-force defense\u003C\u002Fstrong>: Blocks repeated failed logins and temporarily locks abusive IPs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password policy prompts\u003C\u002Fstrong>: Encourage stronger credentials without breaking workflows\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session timeouts\u003C\u002Fstrong>: Automatically end idle sessions to prevent account hijacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity awareness\u003C\u002Fstrong>: View recent logins and admin changes in the \u003Cstrong>Activity Log\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Site Health & Cloud Checks: Clarity without noise\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Site Health Dashboard\u003C\u002Fstrong>: Surface key signals in one view — WordPress hardening status, last scan timestamp and actionable indicators\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud Checks\u003C\u002Fstrong>: Connect your free SiteLock account to enable recurring off-server checks (Webpage Scan, SSL Verification, Email Reputation and more)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scan Now\u003C\u002Fstrong>: Run on-demand checks after updates or changes for instant assurance — no heavy, always-on local scanners\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Activity Log\u003C\u002Fstrong>: Track what’s happening across your WordPress admin. See admin\u002Flogin events at a glance making it easy to spot anomalies early and keep accountability clear\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Choose SiteLock WordPress Security?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Lightweight by design\u003C\u002Fstrong>: All high-impact protections, no unnecessary load\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real visibility\u003C\u002Fstrong>: Know your security posture in seconds with Site Health\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloud-powered assurance\u003C\u002Fstrong>: Checks run off-server, protecting performance\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible setup\u003C\u002Fstrong>: Use standalone or connect a SiteLock account for added layers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Strong login protection\u003C\u002Fstrong>: Two-Factor Authentication (2FA) alongside brute-force defense and session controls\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trusted heritage\u003C\u002Fstrong>: From the global leader in SMB website security backed by continuous innovation and research\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Aligned to WordPress\u003C\u002Fstrong>: Designed to stay out of your way and keep performance priorities intact\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who It’s For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Small businesses & startups\u003C\u002Fli>\n\u003Cli>Portfolio & personal brand sites\u003C\u002Fli>\n\u003Cli>WooCommerce shops & small e-commerce\u003C\u002Fli>\n\u003Cli>Agencies & website maintenance services\u003C\u002Fli>\n\u003Cli>Freelance developers & web designers\u003C\u002Fli>\n\u003Cli>Bloggers, creators & publishers\u003C\u002Fli>\n\u003Cli>Community & membership sites\u003C\u002Fli>\n\u003Cli>Nonprofits & educational sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>If you manage a WordPress website, SiteLock gives you confidence and control whether you run one site or hundreds.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch4>Can I Fix an Already-Infected Site with This Plugin?\u003C\u002Fh4>\n\u003Cp>The plugin focuses on prevention, posture and visibility — not full malware removal. It isn’t designed to fully clean up sites that were infected before it was active.\u003Cbr \u002F>\nIf your site is already compromised, act quickly, we recommend:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Restoring from a clean backup if available\u003C\u002Fli>\n\u003Cli>Remove malicious files manually or with professional help\u003C\u002Fli>\n\u003Cli>For urgent assistance, consider \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fproducts\u002Ffix-hacked-site\u002F\" rel=\"nofollow ugc\">SiteLock 911 – Emergency Malware Removal\u003C\u002Fa> for rapid cleanup\u003C\u002Fli>\n\u003Cli>For ongoing defense, consider \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fpricing\u002F\" rel=\"nofollow ugc\">choosing a comprehensive SiteLock plan\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Don’t Know Where To Start? Try This\u003C\u002Fh4>\n\u003Cp>Here are common first moves teams take with SiteLock. Order isn’t enforced — choose what fits your site and workflow:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enable WordPress hardening that matches your hosting and theme setup\u003C\u002Fli>\n\u003Cli>Turn on Login Security controls: brute-force lockouts, session timeouts, and password-hygiene prompts\u003C\u002Fli>\n\u003Cli>Connect a free SiteLock account, then use Scan Now to run an on-demand check after plugin\u002Ftheme updates\u003C\u002Fli>\n\u003Cli>Review the Activity Log after major changes to spot unexpected admin\u002Flogin events quickly\u003Cbr \u002F>\nMake one change at a time, validate and roll back any toggle that conflicts with your stack.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Need Help with Setup or Fixes?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Visit \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fhelp-center\u002F?topics=wordpress-plugin\" rel=\"nofollow ugc\">Help Center – WordPress\u003C\u002Fa> for plugin specific help\u003C\u002Fli>\n\u003Cli>For broader topics explore the \u003Ca href=\"https:\u002F\u002Fwww.sitelock.com\u002Fhelp-center\u002F\" rel=\"nofollow ugc\">SiteLock Help Center\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security\u003C\u002Fh4>\n\u003Cp>Protecting our customers and systems is a top priority, and we take security very seriously. If you believe you’ve found a security vulnerability in the SiteLock WordPress plugin, please let us know at vuln-reporting@sitelock.com before sharing any details publicly.\u003C\u002Fp>\n","Free, lightweight WordPress security. Harden your site with login protection & 2FA, see Site Health clearly and run on-demand checks—setup in minutes.",1000,53167,68,14,"2026-06-23T18:46:00.000Z","8.0",[91,92,93,70,94],"login-security","malware-scan","site-health","wordpress-security","https:\u002F\u002Fwww.sitelock.com\u002Fwordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsitelock.5.1.2.zip",98,2,"2026-01-25 00:00:00",{"slug":101,"name":102,"version":103,"author":104,"author_profile":105,"description":106,"short_description":107,"active_installs":25,"downloaded":108,"rating":25,"num_ratings":74,"last_updated":109,"tested_up_to":14,"requires_at_least":110,"requires_php":47,"tags":111,"homepage":23,"download_link":113,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"lockora-security-audit","Lockora Security Audit","0.2.0","Guido Schad","https:\u002F\u002Fprofiles.wordpress.org\u002Fcmdgw\u002F","\u003Cp>Lockora Security Audit helps site owners and agencies review a WordPress site’s security posture from the admin area.\u003C\u002Fp>\n\u003Cp>Current prototype features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Manual security scans.\u003C\u002Fli>\n\u003Cli>Weighted security score out of 100.\u003C\u002Fli>\n\u003Cli>WordPress core file integrity checks using official checksums.\u003C\u002Fli>\n\u003Cli>WordPress authentication key and salt checks, with an explicit action to generate missing salts.\u003C\u002Fli>\n\u003Cli>Must-use plugin directory presence checks.\u003C\u002Fli>\n\u003Cli>PHP version status using WordPress.org Serve Happy data.\u003C\u002Fli>\n\u003Cli>HTTPS and HTTP security header checks.\u003C\u002Fli>\n\u003Cli>WordPress core, plugin, and theme update posture checks.\u003C\u002Fli>\n\u003Cli>Administrator account posture checks for default usernames, excess admins, inactive admins, user ID 1 exposure, and an admin username\u002Femail inventory.\u003C\u002Fli>\n\u003Cli>Public exposure checks: debug.log and readme.html reachability, uploads directory listing, PHP execution inside uploads, and author archive user enumeration.\u003C\u002Fli>\n\u003Cli>SSL certificate expiry check, database table prefix check, automatic update posture check, and detection of login protection \u002F two-factor plugins.\u003C\u002Fli>\n\u003Cli>Site Health integration: scan summary plus key configuration checks appear under Tools > Site Health > Status.\u003C\u002Fli>\n\u003Cli>WP-CLI support: \u003Ccode>wp lockora scan\u003C\u002Fcode> and \u003Ccode>wp lockora report\u003C\u002Fcode>, with \u003Ccode>--format=json\u003C\u002Fcode> and a \u003Ccode>--strict\u003C\u002Fcode> flag for CI pipelines.\u003C\u002Fli>\n\u003Cli>Optional known vulnerability matching with a configured Wordfence Intelligence API key.\u003C\u002Fli>\n\u003Cli>Optional AI client reports on WordPress 7.0+ when the site’s AI Connector is configured.\u003C\u002Fli>\n\u003Cli>Reversible hardening toggles for XML-RPC, REST user routes, generator tag output, and basic security headers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Lockora Security Audit may connect to external services only when the administrator runs a scan or generates an AI client report.\u003C\u002Fp>\n\u003Cp>During a scan the plugin also sends HTTP requests to the site’s own public URL (loopback requests) to inspect response headers, debug.log and readme.html reachability, uploads directory behavior, and author archive redirects, and it opens a TLS connection to the site’s own hostname to read the SSL certificate expiry date. These requests stay within the site being scanned and send no data to third parties.\u003C\u002Fp>\n\u003Cp>WordPress.org APIs:\u003Cbr \u002F>\n* Used for WordPress core checksums, PHP version support status, and WordPress core\u002Fplugin\u002Ftheme update data.\u003Cbr \u002F>\n* Data sent: the site’s WordPress version and locale for core checksums and PHP compatibility; WordPress itself may send installed plugin and theme slugs\u002Fversions to WordPress.org when update data is refreshed.\u003Cbr \u002F>\n* WordPress.org terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms\u002F\u003Cbr \u002F>\n* WordPress.org privacy policy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>Wordfence Intelligence:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when a Wordfence Intelligence API key is configured and an administrator runs a scan that includes vulnerability matching.\u003Cbr \u002F>\n* Used to retrieve vulnerability data and match it locally against installed WordPress core, plugin, and theme versions.\u003Cbr \u002F>\n* Data sent: the configured Wordfence Intelligence API key is sent in an Authorization header when requesting the vulnerability feed. Installed software details are not sent by this plugin to the Wordfence Intelligence endpoint; matching is performed locally after the feed is retrieved.\u003Cbr \u002F>\n* Wordfence Intelligence terms: https:\u002F\u002Fwww.wordfence.com\u002Fwordfence-intelligence-terms-and-conditions\u002F\u003Cbr \u002F>\n* Wordfence privacy policy: https:\u002F\u002Fwww.wordfence.com\u002Fprivacy-policy\u002F\u003C\u002Fp>\n\u003Cp>WordPress AI Client \u002F Connectors:\u003Cbr \u002F>\n* Optional.\u003Cbr \u002F>\n* Used only when the administrator clicks Generate Client Report.\u003Cbr \u002F>\n* Data sent: sanitized scan findings, score, counts, and recommendations needed to generate a client-facing report. The plugin is designed not to send passwords, salts, API keys, raw logs, full user lists, or file contents.\u003Cbr \u002F>\n* The configured AI provider is controlled by the site owner’s WordPress Connector settings.\u003Cbr \u002F>\n* Terms and privacy policy: these depend on the AI provider configured by the site owner in WordPress. Site owners should review the selected provider’s terms and privacy policy before enabling AI reports.\u003C\u002Fp>\n","Lockora Security Audit checks WordPress security posture, hardening, core integrity, vulnerabilities, and optional AI reports.",511,"2026-07-12T20:50:00.000Z","6.0",[112,18,21,93,70],"ai","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flockora-security-audit.0.2.0.zip",{"slug":115,"name":116,"version":117,"author":118,"author_profile":119,"description":120,"short_description":121,"active_installs":122,"downloaded":123,"rating":25,"num_ratings":124,"last_updated":125,"tested_up_to":14,"requires_at_least":110,"requires_php":47,"tags":126,"homepage":129,"download_link":130,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"sitefort","SiteFort Security – Malware Scanner, Firewall, Login Security & Hardening","1.7.5","securewpteam","https:\u002F\u002Fprofiles.wordpress.org\u002Fsecurewpteam\u002F","\u003Cp>Most WordPress hacks start with a door someone left open. An unpatched plugin, an exposed backup, a weak admin password. SiteFort closes these weak points before attackers find them, then backs that up with a firewall, login protection, and cloud malware scanning.\u003C\u002Fp>\n\u003Cp>Malware analysis runs in the SiteFort cloud rather than on your hosting, so full scans stay fast even on shared servers. The free plugin is not a trial. The protections most sites need are included without a paywall.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fdemo.securewp.net\u002F\" rel=\"nofollow ugc\">Try the Live Demo\u003C\u002Fa>\u003C\u002Fstrong> | \u003Ca href=\"https:\u002F\u002Fsecurewp.net\u002Fwordpress-security-plugin\u002F\" rel=\"nofollow ugc\">Features\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fsecurewp.net\u002Fsecurity-checker\u002F\" rel=\"nofollow ugc\">Free Remote Scan\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Comprehensive WordPress Protection\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Cloud Malware Scanner:\u003C\u002Fstrong> Detects backdoors, web shells, injected code, and SEO spam, with the heavy analysis running in the cloud instead of on your server.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Verified Hardening:\u003C\u002Fstrong> Locks down XML-RPC, user enumeration, sensitive files, and PHP execution, then verifies each rule is enforced on the server, not just enabled in the dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Firewall & Bot Filter:\u003C\u002Fstrong> Country blocking, rate limits, a community IP blocklist, and bot filtering that never blocks real search engines.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Security & 2FA:\u003C\u002Fstrong> Custom login URL, CAPTCHA, brute-force lockouts, breached-password blocking, and role-based 2FA enforcement. No separate login plugin needed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Backdoor Admin & Account Audit:\u003C\u002Fstrong> Finds admin accounts hidden from the WordPress users list, plus weak, breached, and suspicious accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Checks:\u003C\u002Fstrong> Scans core, plugins, and themes against CVE intelligence and shows affected versions, severity, and fix guidance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Repair & Quarantine:\u003C\u002Fstrong> Quarantine suspicious files (restorable if something breaks) or repair infected files from clean sources in one click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Edge Sync:\u003C\u002Fstrong> Push IP, country, and bot rules to Cloudflare so attacks are blocked before they ever reach WordPress.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress Security Scanner\u003C\u002Fh3>\n\u003Cp>A single scan covers files, accounts, content, and reputation.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malware Detection:\u003C\u002Fstrong> Known files clear instantly by local hash. Only unknown or suspicious files go to deep cloud analysis for backdoors, web shells, injected code, SEO spam, and malicious redirects.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Integrity:\u003C\u002Fstrong> Catches tampered core, plugin, and theme files, and flags files that should not exist on the site at all.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Account Security:\u003C\u002Fstrong> Flags weak, breached, and suspicious accounts, including backdoor admins hidden from the WordPress users list or created outside normal site workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content & Database Safety:\u003C\u002Fstrong> Checks WordPress data locally for injected content, suspicious options, unsafe URLs, and spam or redirect indicators. Database content never leaves your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Domain & IP Reputation:\u003C\u002Fstrong> Checks your domain and server IP against blocklists and abuse feeds so a listing surfaces early, before it affects traffic or email deliverability.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sensitive File Exposure:\u003C\u002Fstrong> Finds exposed backups, logs, config files, debug files, and other files attackers commonly target.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability Scanner:\u003C\u002Fstrong> Checks WordPress core, plugins, and themes for known vulnerabilities, affected versions, severity, and CVE references where available.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress Security Hardening\u003C\u002Fh3>\n\u003Cp>SiteFort closes the exposure points attackers check first.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>XML-RPC Controls:\u003C\u002Fstrong> Disable XML-RPC, restrict authentication, or block pingback abuse.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Enumeration Blocking:\u003C\u002Fstrong> Reduces username leaks from author archives, REST endpoints, and common discovery paths.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sensitive File Protection:\u003C\u002Fstrong> Blocks public access to \u003Ccode>.env\u003C\u002Fcode>, backups, logs, debug files, \u003Ccode>.git\u003C\u002Fcode> metadata, lock files, sample configs, and server fragments.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP Execution Protection:\u003C\u002Fstrong> Blocks PHP execution in uploads and direct PHP access inside plugin and theme folders where supported.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Directory Listing Protection:\u003C\u002Fstrong> Reduces exposure from browsable upload, plugin, theme, or backup directories.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File Editor Protection:\u003C\u002Fstrong> Disables the built-in theme and plugin file editor to limit damage from compromised admin accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST & Application Password Controls:\u003C\u002Fstrong> Restricts risky REST access and application password behavior based on site needs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Version & Metadata Cleanup:\u003C\u002Fstrong> Hides WordPress version output and reduces exposed generator and header signals.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Headers:\u003C\u002Fstrong> Analyze and manage CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and disclosure headers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enforcement Checks:\u003C\u002Fstrong> Confirms supported hardening rules are active on the server. Items that require manual hosting or server configuration are flagged separately.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Login Security & 2FA\u003C\u002Fh3>\n\u003Cp>Account takeover is one of the fastest ways to lose control of a WordPress site. SiteFort adds layered login protection without requiring separate plugins.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom Login URL:\u003C\u002Fstrong> Move your login page to a private address; anything hitting wp-login.php gets a redirect, a 403, or a 404, your choice.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack Prevention:\u003C\u002Fstrong> Brute-force lockouts, CAPTCHA, generic login errors, and XML-RPC\u002FREST authentication controls.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication:\u003C\u002Fstrong> Role-based 2FA enforcement with authenticator app codes, email codes, and recovery codes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password Policy:\u003C\u002Fstrong> Weak and breached password detection, role-based strength enforcement, and expiration rules.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress Firewall\u003C\u002Fh3>\n\u003Cp>SiteFort blocks unwanted traffic before it consumes server resources, with no custom rule syntax to learn.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>IP & Country Rules:\u003C\u002Fstrong> Block or allow traffic by IP address, CIDR range, country, bot, crawler, or user agent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Country Blocking:\u003C\u002Fstrong> Supports both block-selected and allow-only modes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sensitive File Protection:\u003C\u002Fstrong> Stops bots probing for \u003Ccode>.env\u003C\u002Fcode>, \u003Ccode>.git\u003C\u002Fcode>, \u003Ccode>wp-config.php\u003C\u002Fcode> backups, SQL dumps, debug logs, installer files, and other risky paths.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Sync:\u003C\u002Fstrong> Pushes supported IP, country, and user-agent rules to Cloudflare so high-volume blocks happen at the edge, including temporary edge blocks for repeat attackers.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate Limiting & 404 Controls:\u003C\u002Fstrong> Reduces abusive traffic spikes, repeated missing-page requests, and automated noise.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Community Threat Intelligence:\u003C\u002Fstrong> Blocks traffic from malicious IPs seen across the SiteFort network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vulnerability-Hunting Bot Protection:\u003C\u002Fstrong> Blocks bots probing for vulnerable plugins, themes, backup files, and configuration leaks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Bot Filter Policy\u003C\u002Fh3>\n\u003Cp>Not all bots are bad. Pick one of three protection levels; unwanted automation gets blocked while legitimate search crawlers always pass through, so bot filtering does not put your SEO at risk.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Basic:\u003C\u002Fstrong> Blocks known hacking tools and bots probing for vulnerable files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Balanced:\u003C\u002Fstrong> Blocks hacking tools, scraping bots, and automated scripts. Recommended for most sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Maximum:\u003C\u002Fstrong> Blocks hacking tools, scrapers, automated scripts, and unrecognized bot traffic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block AI Training Crawlers:\u003C\u002Fstrong> Optional block for AI scrapers that harvest content for model training (GPTBot, ClaudeBot, CCBot, Bytespider). AI assistants and AI search crawlers stay allowed.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Choose the level that fits the site, then adjust individual rules from the firewall dashboard.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch3>Vulnerability Management\u003C\u002Fh3>\n\u003Cp>SiteFort checks installed WordPress core, plugin, and theme versions against vulnerability intelligence and shows affected assets, severity, CVE references where available, and the update that fixes each issue. While you apply updates, the firewall blocks the scanner bots that hunt for vulnerable components.\u003C\u002Fp>\n\u003Ch3>One-Click Repair & Restore\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Pro:\u003C\u002Fstrong> Guided repair workflows let you act on scan findings without manually editing files over FTP or SSH.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Repair or delete malicious files directly from scan results.\u003C\u002Fli>\n\u003Cli>Restore clean WordPress core, plugin, and theme files when a trusted clean source is available.\u003C\u002Fli>\n\u003Cli>Repair supported paid plugin and theme files when clean-source matching is available.\u003C\u002Fli>\n\u003Cli>Quarantine suspicious files safely, with one-click restore if something on the site breaks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>For an active compromise, \u003Ca href=\"https:\u002F\u002Fsecurewp.net\u002Fwordpress-malware-removal\u002F\" rel=\"nofollow ugc\">Securewp expert cleanup\u003C\u002Fa> and managed security services are available when hands-on investigation, root-cause patching, blocklist help, or post-cleanup review is needed.\u003C\u002Fem>\u003C\u002Fp>\n\u003Ch3>Audit Log & SiteFort Console\u003C\u002Fh3>\n\u003Cp>SiteFort keeps a security event history so you can quickly see what changed, what was blocked, and what needs attention.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Login Activity:\u003C\u002Fstrong> Successful logins, failed attempts, lockouts, 2FA events, and account-related actions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User & Site Changes:\u003C\u002Fstrong> User updates, plugin and theme changes, settings changes, and sensitive admin actions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Firewall Activity:\u003C\u002Fstrong> Blocked IPs, country rules, bot blocks, rate-limit events, and suspicious request activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scanner Results:\u003C\u002Fstrong> Malware findings, vulnerability findings, reputation checks, hardening issues, and scan history.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Site-level security features are available from the WordPress dashboard. SiteFort Console is optional for teams that need centralized visibility across multiple sites, downloadable reports for clients, and team roles and support workflows.\u003C\u002Fp>\n\u003Ch3>Hosting Compatibility\u003C\u002Fh3>\n\u003Cp>SiteFort is built for real WordPress environments.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Compatible with shared hosting, managed WordPress hosting, VPS, and dedicated servers.\u003C\u002Fli>\n\u003Cli>Works with Apache, Nginx, and LiteSpeed.\u003C\u002Fli>\n\u003Cli>Cloudflare-friendly: supports proxied sites and optional Cloudflare rule sync.\u003C\u002Fli>\n\u003Cli>Cloud-assisted scanning reduces heavy scan work on lower-resource hosting plans.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Free vs Pro\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Free includes\u003C\u002Fstrong> the firewall, bot filter, login security and 2FA, verified hardening, vulnerability checks, audit log, quarantine, and cloud malware scanning with 3,000 scan credits every month.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Pro adds:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Unlimited cloud scanning with deep threat analysis\u003C\u002Fli>\n\u003Cli>Scheduled scans and automated vulnerability alerts\u003C\u002Fli>\n\u003Cli>One-click malware repair with clean-file restore for core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Uptime and SSL expiry monitoring\u003C\u002Fli>\n\u003Cli>Slack, Discord, email, and webhook alerts\u003C\u002Fli>\n\u003Cli>Remote scan history, advanced reports, and white-label options for agencies\u003C\u002Fli>\n\u003Cli>Expert cleanup discounts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Managed\u003C\u002Fstrong> adds hands-on monitoring, response workflows, and expert cleanup coverage by the SecureWP team.\u003C\u002Fp>\n\u003Cp>Looking for a market comparison? See the \u003Ca href=\"https:\u002F\u002Fsecurewp.net\u002Fwordpress-security-plugin-comparison\u002F\" rel=\"nofollow ugc\">WordPress Security Plugin Comparison\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>SiteFort connects to external services only when needed for license activation, cloud-assisted malware analysis, vulnerability intelligence, firewall intelligence, optional Console sync, optional CAPTCHA, optional GeoIP, Cloudflare sync, and administrator-enabled notifications.\u003C\u002Fp>\n\u003Cp>Optional integrations are not contacted unless they are configured or used.\u003C\u002Fp>\n\u003Ch4>SiteFort Cloud\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Servers:\u003C\u002Fstrong> securewp.net, intel.securewp.net, console.securewp.net\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Used for:\u003C\u002Fstrong> License activation, service metadata, cloud malware analysis, vulnerability intelligence, firewall intelligence, reputation checks, community blocklist sync, clean-file repair, and optional Console sync.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Email address, license key\u002Ftoken, site URL, WordPress\u002Fplugin versions, installed plugin\u002Ftheme names and versions, file hashes, scan results, vulnerability findings, reputation status, firewall metadata, blocked IPs, and security configuration metadata.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Malware scanning:\u003C\u002Fstrong> File hashes are sent first. Only unknown or suspicious files may be uploaded for deeper analysis and are deleted after processing. Database and content checks run on your website. SiteFort does not upload your database or database-stored content to the cloud. If wp-config.php requires analysis, sensitive configuration values are removed before upload.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Temporary storage:\u003C\u002Fstrong> SiteFort Cloud may return temporary upload\u002Fdownload URLs on *.amazonaws.com for scan uploads or clean-file repair downloads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fsecurewp.net\u002Fprivacy-policy\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fsecurewp.net\u002Fterms-and-conditions\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storage provider policies:\u003C\u002Fstrong> AWS privacy https:\u002F\u002Faws.amazon.com\u002Fprivacy\u002F and terms https:\u002F\u002Faws.amazon.com\u002Fservice-terms\u002F; Cloudflare privacy https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F and terms https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Optional integrations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>MaxMind GeoLite2\u003C\u002Fstrong> (download.maxmind.com) is used only when an administrator downloads or updates the local GeoIP database. It sends the configured MaxMind account ID and license key. Visitor IPs are resolved locally and are not sent to MaxMind during normal requests. Privacy: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fprivacy-policy Terms: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fgeolite2\u002Feula\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Have I Been Pwned Passwords\u003C\u002Fstrong> (api.pwnedpasswords.com) is used for breached-password checks when enabled. SiteFort sends only the first 5 characters of the SHA-1 password hash. Full passwords and full hashes are never sent. Privacy: https:\u002F\u002Fhaveibeenpwned.com\u002FPrivacy Terms: https:\u002F\u002Fhaveibeenpwned.com\u002FTermsOfUse\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google reCAPTCHA\u003C\u002Fstrong> (www.google.com) and \u003Cstrong>Cloudflare Turnstile\u003C\u002Fstrong> (challenges.cloudflare.com) are used only when selected and configured for CAPTCHA protection. They receive the challenge token, site key, and visitor\u002Fbrowser data required by the selected provider. Policies: https:\u002F\u002Fpolicies.google.com\u002Fprivacy https:\u002F\u002Fpolicies.google.com\u002Fterms https:\u002F\u002Fwww.cloudflare.com\u002Fturnstile-privacy-policy\u002F https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare API\u003C\u002Fstrong> (api.cloudflare.com) is used only when Cloudflare Sync is enabled. It sends Zone ID, API token\u002Fcredentials, zone details, blocked IPs, country rules, selected user-agent rules, and firewall rule data. Privacy: https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F Terms: https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Notification webhooks\u003C\u002Fstrong> may send security alerts to Slack (hooks.slack.com), Discord (discord.com, discordapp.com), or a custom HTTPS webhook entered by the administrator. Webhook payloads may include site name, site URL, event type, severity, scan counts, vulnerability names, CVE identifiers, firewall counts, usernames, IP addresses, browser names, action URLs, timestamps, and event details. Slack policies: https:\u002F\u002Fslack.com\u002Ftrust\u002Fprivacy\u002Fprivacy-policy https:\u002F\u002Fslack.com\u002Fterms-of-service\u002Fuser Discord policies: https:\u002F\u002Fdiscord.com\u002Fprivacy https:\u002F\u002Fdiscord.com\u002Fterms\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Local site checks\u003C\u002Fh4>\n\u003Cp>Some requests are loopback checks against the protected site’s own public URL, such as security-header checks, public-file exposure checks, and homepage link collection. These contact the site being protected, not a third-party service.\u003C\u002Fp>\n","Prevention-first WordPress security. Hardening, firewall, bot filter, and 2FA close the doors; cloud-assisted malware scanning keeps your site fast.",40,1807,4,"2026-07-20T15:57:00.000Z",[127,128,50,21,22],"2fa","firewall","https:\u002F\u002Fsecurewp.net\u002Fwordpress-security-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsitefort.1.7.5.zip",{"error":132,"url":133,"statusCode":134,"statusMessage":135,"message":135},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fpura-vida-vulnerability-scanner\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":98,"versions":137},[138,144],{"version":6,"download_url":24,"svn_tag_url":139,"released_at":26,"has_diff":140,"diff_files_changed":141,"diff_lines":26,"trac_diff_url":142,"vulnerabilities":143,"is_current":132},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fpura-vida-vulnerability-scanner\u002Ftags\u002F1.1.0\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fpura-vida-vulnerability-scanner%2Ftags%2F1.0.9&new_path=%2Fpura-vida-vulnerability-scanner%2Ftags%2F1.1.0",[],{"version":145,"download_url":146,"svn_tag_url":147,"released_at":26,"has_diff":140,"diff_files_changed":148,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":149,"is_current":140},"1.0.9","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpura-vida-vulnerability-scanner.1.0.9.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fpura-vida-vulnerability-scanner\u002Ftags\u002F1.0.9\u002F",[],[]]