[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fa-82LnXqKX1DNE4ypGClGchhOBs_zHH7tXH5Q7jRmxk":3,"$fySQvVicd0SAnVRFXg4Q-QgcGwA1B5jXiE4BVszkRXjU":347,"$fFd2lp9H948qRFFeylzT1Axb08C96rUf7f370ZFQ1xY0":351},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":145,"fingerprints":320},"shield-wp-admin","Shield WP Admin","1.0","Differenz System","https:\u002F\u002Fprofiles.wordpress.org\u002Fdifferenzsystem\u002F","\u003Cp>\u003Cstrong>Shield WP Admin\u003C\u002Fstrong> is a lightweight yet powerful plugin designed to enhance the security of your WordPress admin area. With an easy-to-use interface and essential protection tools, it helps safeguard your site against common threats and vulnerabilities.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Custom Admin Login URL\u003C\u002Fstrong>\u003Cbr \u002F>\nHide or customize the default \u003Ccode>\u002Fwp-login.php\u003C\u002Fcode> URL to prevent unauthorized login attempts.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Limit Login Attempts\u003C\u002Fstrong>\u003Cbr \u002F>\nProtect against brute-force attacks by limiting failed login retries.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Google reCAPTCHA Integration\u003C\u002Fstrong>\u003Cbr \u002F>\nAdd reCAPTCHA to the login screen to block bots and automated scripts.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable XML-RPC\u003C\u002Fstrong>\u003Cbr \u002F>\nPrevent exploitation via XML-RPC by disabling its access entirely.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable File Editor\u003C\u002Fstrong>\u003Cbr \u002F>\nBlock access to the theme and plugin file editor in the WordPress dashboard.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Hide WordPress Version\u003C\u002Fstrong>\u003Cbr \u002F>\nConceal your WordPress version from source code to reduce exposure to targeted attacks.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Force HTTPS Redirection\u003C\u002Fstrong>\u003Cbr \u002F>\nRedirect all HTTP requests to HTTPS to ensure secure access.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Pingbacks & Trackbacks\u003C\u002Fstrong>\u003Cbr \u002F>\nProtect your site from spam and DDoS attacks by disabling pingbacks and trackbacks.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>IP Blacklisting\u003C\u002Fstrong>\u003Cbr \u002F>\nBlock specific IP addresses directly from the admin panel to protect the site.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Admin Login Form Logo Change\u003C\u002Fstrong>\u003Cbr \u002F>\nYou can change the logo of admin login form.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Why Shield WP Admin?\u003C\u002Fstrong>\u003Cbr \u002F>\nWhether you’re a developer or a site owner, Shield WP Admin provides a smart, flexible solution to strengthen your WordPress backend—without bloating your site or overwhelming your dashboard.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin uses Google reCAPTCHA to protect the admin login from automated brute-force attacks.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service Used\u003C\u002Fstrong>: Google reCAPTCHA\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Domain\u003C\u002Fstrong>: https:\u002F\u002Fwww.google.com\u002Frecaptcha\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Used to verify that the user is human, preventing spam or Brute-force attacks on admin login protected by the plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>What Data is Sent\u003C\u002Fstrong>: When a user interacts with a reCAPTCHA-protected form, their interaction (including IP address, user agent, and possibly cookies) is sent to Google’s reCAPTCHA service for validation and verification.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When Data is Sent\u003C\u002Fstrong>: This data is transmitted to Google when the form is loaded (due to the JS script) and again when the form is submitted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service Provider\u003C\u002Fstrong>: Google\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure and harden your WordPress admin area with powerful features like custom login URLs, reCAPTCHA, brute-force protection, and more.",10,325,0,"2026-02-10T06:27:00.000Z","6.8.5","5.0","7.2",[19,20,21,22,23],"admin-safe","admin-shield","hide-login","login-security","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fshield-wp-admin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshield-wp-admin.1.0.zip",100,null,"2026-04-16T10:56:18.058Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"differenzsystem",1,30,94,"2026-05-20T05:16:40.675Z",[38,62,84,106,126],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":26,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":52,"tags":53,"homepage":57,"download_link":58,"security_score":59,"vuln_count":33,"unpatched_count":33,"last_vuln_date":60,"fetched_at":61},"admin-safety-guard","Admin Safety Guard — Login Security & 2FA","1.2.6","Themepaste","https:\u002F\u002Fprofiles.wordpress.org\u002Fthemepaste\u002F","\u003Cp>\u003Cstrong>Admin Safety Guard\u003C\u002Fstrong> is a complete WordPress security helper focused on securing the login flow and hardening the admin area — without sacrificing usability or performance. It ships with a clean UI, smart defaults, and guardrails against the most common attacks (brute force, credential stuffing, bot logins, and XML-RPC abuse). You also get granular control over the login experience (custom URL, redirects, branding, and more).\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FKFNUmTHtODE?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>Whether you need to block suspicious IPs, enforce two-factor authentication, or ship a branded login for clients, \u003Cstrong>Admin Safety Guard\u003C\u002Fstrong> has you covered.\u003C\u002Fp>\n\u003Ch3>🌟 Admin Safety Guard Pro\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Admin Safety Guard Pro\u003C\u002Fa>\u003C\u002Fstrong> takes your security and customization to the next level. It strengthens defenses against unauthorized access, brute-force attacks, and data risks while giving you deeper control over how users log in and interact with your admin area. The Pro version also adds flexible design tools and smart automations — a complete solution for both \u003Cstrong>security\u003C\u002Fstrong> and \u003Cstrong>convenience\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch3>👥 Who Should Use Admin Safety Guard?\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Admin Safety Guard\u003C\u002Fstrong> is perfect for users who need more control, security, and customization in their WordPress admin area:\u003C\u002Fp>\n\u003Cp>👩‍💻 \u003Cstrong>Freelancers & Developers:\u003C\u002Fstrong> Add backend security and branding to client sites—no heavy coding.\u003Cbr \u002F>\n🏢 \u003Cstrong>Agencies & Teams:\u003C\u002Fstrong> Secure multiple websites with a single workflow and consistent branding.\u003Cbr \u002F>\n🔒 \u003Cstrong>Site Owners:\u003C\u002Fstrong> Protect dashboards from brute-force attacks and unauthorized logins.\u003Cbr \u002F>\n🧩 \u003Cstrong>Plugin\u002FTheme Authors:\u003C\u002Fstrong> Add layered protection in demo or test environments.\u003Cbr \u002F>\n📈 \u003Cstrong>Online Businesses:\u003C\u002Fstrong> Secure customer data with 2FA, CAPTCHA, and password protection.\u003Cbr \u002F>\n🎓 \u003Cstrong>Educators & Bloggers:\u003C\u002Fstrong> Maintain a professional look while increasing security.\u003C\u002Fp>\n\u003Ch3>✅ Free Features at a Glance\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Hide Admin Bar (with conditions)  \u003C\u002Fli>\n\u003Cli>Dashboard Overview (in progress)  \u003C\u002Fli>\n\u003Cli>Change Login URL  \u003C\u002Fli>\n\u003Cli>Redirect After Login \u002F Logout  \u003C\u002Fli>\n\u003Cli>Limit Login Attempts  \u003C\u002Fli>\n\u003Cli>CAPTCHA Protection  \u003C\u002Fli>\n\u003Cli>Login Logs & Activity Tracking  \u003C\u002Fli>\n\u003Cli>IP Blocking  \u003C\u002Fli>\n\u003Cli>Two-Factor Authentication (2FA)  \u003C\u002Fli>\n\u003Cli>Password Protection  \u003C\u002Fli>\n\u003Cli>Disable XML-RPC  \u003C\u002Fli>\n\u003Cli>Add Custom Logo on Login Form  \u003C\u002Fli>\n\u003Cli>Custom Logo & Branding  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>💎 Premium Feature List\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Passwordless Login  \u003C\u002Fli>\n\u003Cli>2FA via Mobile App (TOTP)  \u003C\u002Fli>\n\u003Cli>CSRF Protection  \u003C\u002Fli>\n\u003Cli>Database Table Prefix Check  \u003C\u002Fli>\n\u003Cli>Whitelist IP Addresses  \u003C\u002Fli>\n\u003Cli>Hide Admin Bar\u003C\u002Fli>\n\u003Cli>WP Directory File Permissions Check  \u003C\u002Fli>\n\u003Cli>Social Login (Google, Facebook, etc.)  \u003C\u002Fli>\n\u003Cli>Disallow Unauthorized REST Requests\u003C\u002Fli>\n\u003Cli>Password Strength Tool  \u003C\u002Fli>\n\u003Cli>Provide Login Template (ready-made)  \u003C\u002Fli>\n\u003Cli>Customize Design Pro (advanced styling)  \u003C\u002Fli>\n\u003Cli>Email Notification\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Free Feature Details\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>👤 Hide Admin Bar (With Conditions):\u003C\u002Fstrong> Hide the admin bar selectively for specific users or roles.\u003Cbr \u002F>\n\u003Cstrong>📊 Dashboard Overview:\u003C\u002Fstrong> Visualize user activity and security stats in one glance.\u003Cbr \u002F>\n\u003Cstrong>🔗 Change Login URL:\u003C\u002Fstrong> Customize the default \u003Ccode>wp-login.php\u003C\u002Fcode> to block automated bots.\u003Cbr \u002F>\n\u003Cstrong>🔁 Redirect After Login\u002FLogout:\u003C\u002Fstrong> Redirect users to any page after login\u002Flogout.\u003Cbr \u002F>\n\u003Cstrong>📋 Limit Login Attempts:\u003C\u002Fstrong> Block repeated failed logins to prevent brute-force attacks.\u003Cbr \u002F>\n\u003Cstrong>🤖 CAPTCHA Protection:\u003C\u002Fstrong> Stop bots with reCAPTCHA or similar human verifications.\u003Cbr \u002F>\n\u003Cstrong>🕵️‍♂️ Login Logs & Activity Tracking:\u003C\u002Fstrong> Track user login times and backend actions.\u003Cbr \u002F>\n\u003Cstrong>⛔ IP Blocking:\u003C\u002Fstrong> Block access by IP address to prevent hostile logins.\u003Cbr \u002F>\n\u003Cstrong>🔐 Two-Factor Authentication (2FA):\u003C\u002Fstrong> Add extra verification layers to secure logins.\u003Cbr \u002F>\n\u003Cstrong>🛂 Password Protection:\u003C\u002Fstrong> Protect private pages or areas with a password.\u003Cbr \u002F>\n\u003Cstrong>⚙️ Disable XML-RPC:\u003C\u002Fstrong> Disable vulnerable XML-RPC endpoints to stop exploits.\u003Cbr \u002F>\n\u003Cstrong>🖼️ Custom Logo on Login Form:\u003C\u002Fstrong> Replace WordPress logo with your brand.\u003Cbr \u002F>\n\u003Cstrong>🏷️ Custom Branding:\u003C\u002Fstrong> Apply your own design across login and admin pages.\u003C\u002Fp>\n\u003Ch4>🔐 Pro Feature Details\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>🔑 Passwordless Login:\u003C\u002Fstrong> Secure email-based login with one-time magic links—no password required.\u003Cbr \u002F>\n\u003Cstrong>📱 2FA via Mobile App:\u003C\u002Fstrong> Add app-based Two-Factor Authentication (Google Authenticator \u002F Authy).\u003Cbr \u002F>\n\u003Cstrong>🧩 CSRF Protection:\u003C\u002Fstrong> Prevent Cross-Site Request Forgery attacks with token verification.\u003Cbr \u002F>\n\u003Cstrong>🗃️ Database Table Prefix Check:\u003C\u002Fstrong> Detects and helps change the insecure \u003Ccode>wp_\u003C\u002Fcode> prefix.\u003Cbr \u002F>\n\u003Cstrong>🌐 Whitelist IP Addresses:\u003C\u002Fstrong> Restrict admin access to trusted IPs only.\u003Cbr \u002F>\n\u003Cstrong>🧑‍💻 Hide Admin Bar (Conditional):\u003C\u002Fstrong> Show or hide admin bar for specific roles or users.\u003Cbr \u002F>\n\u003Cstrong>🗂️ WP Directory File Permissions Check:\u003C\u002Fstrong> Scans and verifies file and directory permissions.\u003Cbr \u002F>\n\u003Cstrong>🌍 Social Login:\u003C\u002Fstrong> Allow users to log in with Google, Facebook, or Twitter accounts.\u003Cbr \u002F>\n\u003Cstrong>🚫 Disallow Unauthorized REST Requests:\u003C\u002Fstrong> Restrict REST API access conditionally.\u003Cbr \u002F>\n\u003Cstrong>💪 Password Strength Tool:\u003C\u002Fstrong> Enforce strong password rules for better protection.\u003Cbr \u002F>\n\u003Cstrong>🎨 Provide Login Template:\u003C\u002Fstrong> Instantly apply stylish, ready-to-use login templates.\u003Cbr \u002F>\n\u003Cstrong>🧰 Customize Design Pro:\u003C\u002Fstrong> Fully customize admin and login design with a simple UI.\u003Cbr \u002F>\n\u003Cstrong>📧 Email Notification:\u003C\u002Fstrong> Receive and customize security alerts directly to your inbox.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>Explore Pro Features: \u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Admin Safety Guard Pro\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For any issues, questions, or feature requests, please reach out via \u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fcontact\" rel=\"nofollow ugc\">Support\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin uses the following third-party and external services:\u003C\u002Fp>\n\u003Cp>1) Google reCAPTCHA (Google LLC)\u003C\u002Fp>\n\u003Cp>Purpose:\u003Cbr \u002F>\nUsed to protect forms from spam and automated abuse.\u003C\u002Fp>\n\u003Cp>When it is used:\u003Cbr \u002F>\n– When reCAPTCHA is enabled in plugin settings\u003Cbr \u002F>\n– On login forms and support forms protected by reCAPTCHA\u003C\u002Fp>\n\u003Cp>What data is sent:\u003Cbr \u002F>\n– User IP address\u003Cbr \u002F>\n– reCAPTCHA response token generated by Google\u003Cbr \u002F>\n– Browser information as required by Google reCAPTCHA\u003C\u002Fp>\n\u003Cp>Service provider:\u003Cbr \u002F>\nGoogle LLC\u003C\u002Fp>\n\u003Cp>Terms of Service:\u003Cbr \u002F>\nhttps:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fp>\n\u003Cp>Privacy Policy:\u003Cbr \u002F>\nhttps:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n\u003Cp>2) ThemePaste API (Plugin Author Service)\u003C\u002Fp>\n\u003Cp>Purpose:\u003Cbr \u002F>\nUsed for:\u003Cbr \u002F>\n– Collecting optional admin email addresses for plugin updates and notifications\u003Cbr \u002F>\n– Sending support requests from the plugin support form\u003Cbr \u002F>\n– Collecting optional feedback when a user attempts to deactivate the plugin\u003Cbr \u002F>\n– Managing plugin-related notifications (only if the user provides contact details)\u003C\u002Fp>\n\u003Cp>When it is used:\u003Cbr \u002F>\n– When a user submits the built-in support form\u003Cbr \u002F>\n– When a user opts to send diagnostic information\u003Cbr \u002F>\n– Submitting the optional deactivation feedback form\u003C\u002Fp>\n\u003Cp>What data is sent:\u003Cbr \u002F>\n– Name\u003Cbr \u002F>\n– Email address\u003Cbr \u002F>\n– Phone number (if provided)\u003Cbr \u002F>\n– Message content\u003Cbr \u002F>\n– Site URL\u003Cbr \u002F>\n– Plugin name\u003Cbr \u002F>\n– Feedback text (if provided)\u003Cbr \u002F>\n– Support message content\u003Cbr \u002F>\n– Deactivation reason (if provided)\u003C\u002Fp>\n\u003Cp>No data is sent without user action.\u003C\u002Fp>\n\u003Cp>Service provider:\u003Cbr \u002F>\nThemePaste.com\u003C\u002Fp>\n\u003Cp>Terms of Service:\u003Cbr \u002F>\nhttps:\u002F\u002Fthemepaste.com\u002Fterms-condition\u003C\u002Fp>\n\u003Cp>Privacy Policy:\u003Cbr \u002F>\nhttps:\u002F\u002Fthemepaste.com\u002Fprivacy-policy\u003C\u002Fp>\n\u003Ch3>Development \u002F Source Code\u003C\u002Fh3>\n\u003Cp>This plugin includes compiled JavaScript bundles in:\u003Cbr \u002F>\n– assets\u002Fadmin\u002Fbuild\u002F*.bundle.js\u003C\u002Fp>\n\u003Cp>The original (human-readable) source files are included in this plugin under:\u003Cbr \u002F>\n– spa\u002Fadmin\u002F\u003C\u002Fp>\n\u003Cp>Build Tools\u003Cbr \u002F>\n– Node.js (LTS recommended)\u003Cbr \u002F>\n– npm\u003Cbr \u002F>\n– Webpack + Babel\u003C\u002Fp>\n\u003Cp>Source Entry Points\u003Cbr \u002F>\nThe admin SPA bundles are built from the following entry points:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>spa\u002Fadmin\u002Flogin-template\u002FMain.jsx            -> assets\u002Fadmin\u002Fbuild\u002FloginTemplate.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Flogin-logs-activity\u002FMain.jsx       -> assets\u002Fadmin\u002Fbuild\u002FloginLogActivity.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fanalytics\u002FMain.jsx                 -> assets\u002Fadmin\u002Fbuild\u002Fanalytics.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fsecurity-core\u002FMain.jsx             -> assets\u002Fadmin\u002Fbuild\u002FsecurityCore.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Ffirewall-malware\u002FMain.jsx          -> assets\u002Fadmin\u002Fbuild\u002FfirewallMalware.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fprivacy-hardening\u002FMain.jsx         -> assets\u002Fadmin\u002Fbuild\u002FprivacyHardening.bundle.js\u003C\u002Fli>\n\u003Cli>spa\u002Fadmin\u002Fmonitoring-analytics\u002FMain.jsx      -> assets\u002Fadmin\u002Fbuild\u002FmonitoringAnalytics.bundle.js\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Install Dependencies\u003Cbr \u002F>\nFrom the plugin root directory (or the directory where package.json exists):\u003C\u002Fp>\n\u003Cp>1) Install dependencies:\u003Cbr \u002F>\n   npm install\u003C\u002Fp>\n\u003Cp>Build (Production)\u003Cbr \u002F>\nTo generate the production bundles:\u003C\u002Fp>\n\u003Cp>npm run build\u003C\u002Fp>\n\u003Cp>Output Location\u003Cbr \u002F>\nWebpack outputs the compiled bundles to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>assets\u002Fadmin\u002Fbuild\u002F[name].bundle.js\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Important Notes\u003Cbr \u002F>\n– Do not edit files in assets\u002Fadmin\u002Fbuild\u002F directly. They are generated files.\u003Cbr \u002F>\n– Edit the source files under spa\u002Fadmin\u002F and re-run the build command.\u003Cbr \u002F>\n– For WordPress.org distribution, production builds should be used (mode=production).\u003C\u002Fp>\n\u003Ch3>Links\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fthemepaste.com\" rel=\"nofollow ugc\">Website\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct-doc\u002Fhide-admin-bar-pro\u002F?doc_id=389\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fadmin-safety-guard-pro\" rel=\"nofollow ugc\">Pro Version\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Fthemepaste\" rel=\"nofollow ugc\">Facebook\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fuk.pinterest.com\u002Fthemepaste\u002F\" rel=\"nofollow ugc\">Pinterest\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fthemepaste\" rel=\"nofollow ugc\">LinkedIn\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.instagram.com\u002Fthemepasteuk\" rel=\"nofollow ugc\">Instagram\u003C\u002Fa>\u003C\u002Fp>\n","Admin Safety Guard secures WordPress: limit logins, 2FA, reCAPTCHA, IP block, disable XML-RPC, activity logs, custom URLs and branding.",20,1605,4,"2026-03-10T09:03:00.000Z","6.9.4","5.8","7.0",[54,39,55,22,56],"2fa","limit-login-attempts","recaptcha","http:\u002F\u002Fthemepaste.com\u002Fproduct\u002Fthemepaste-secure-admin-pro\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadmin-safety-guard.1.2.6.zip",78,"2026-03-16 00:00:00","2026-04-06T09:54:40.288Z",{"slug":63,"name":64,"version":65,"author":66,"author_profile":67,"description":68,"short_description":69,"active_installs":70,"downloaded":71,"rating":35,"num_ratings":72,"last_updated":73,"tested_up_to":52,"requires_at_least":16,"requires_php":74,"tags":75,"homepage":79,"download_link":80,"security_score":81,"vuln_count":82,"unpatched_count":13,"last_vuln_date":83,"fetched_at":28},"all-in-one-wp-security-and-firewall","All-In-One Security (AIOS) – Security and Firewall","5.4.6","David Anderson \u002F Team Updraft","https:\u002F\u002Fprofiles.wordpress.org\u002Fdavidanderson\u002F","\u003Ch3>THE TOP RATED WORDPRESS SECURITY AND FIREWALL PLUGIN\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios&utm_creative_format=description\" rel=\"nofollow ugc\">All-in-One Security (AIOS)\u003C\u002Fa> is a WordPress security plugin from the same, trusted team that brought you UpdraftPlus.\u003C\u002Fp>\n\u003Cp>It’s called ‘All-In-One’ because it’s packed full of ways to keep your WordPress website(s) safe and secure.\u003C\u002Fp>\n\u003Cp>It includes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login security features\u003C\u002Fstrong> keep bots at bay. Lock out users based on a configurable number of login attempts, get two-factor authentication and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File and database security.\u003C\u002Fstrong> Get notified of file changes that occur outside of normal operations. Block access to key files and scan files and folders to spot insecure permissions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Firewall.\u003C\u002Fstrong> Get PHP, .htaccess and 6G firewall rules courtesy of Perishable Press. Spot and block fake Google Bots and more!\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Spam prevention.\u003C\u002Fstrong> Prevent annoying spam comments and reduce unnecessary load on the server. Automatically and permanently block IP addresses that exceed a set number of spam comments.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit log.\u003C\u002Fstrong> View events happening on your WordPress website. Find out if a plugin or theme has been added, removed, updated and more.\u003C\u002Fp>\n\u003Ch4>WHY ALL-IN-ONE SECURITY?\u003C\u002Fh4>\n\u003Cp>AIOS has a near-perfect \u003Cstrong>4.7 \u002F 5-star user rating\u003C\u002Fstrong> across more than 1 million installs.\u003C\u002Fp>\n\u003Cp>Great for beginners and experts alike. AIOS guides you logically and clearly through each of its features which are all clearly explained. Security features are marked as basic, intermediate and advanced. Each step increases your security score. Turn them on and watch your protection grow!\u003C\u002Fp>\n\u003Cp>We have a large support team of software developers. That means we have the availability and the skillset to help you with the trickiest of queries.\u003C\u002Fp>\n\u003Cp>We comb the WordPress plugin directory for support tickets daily – most queries are responded to within 24 hours.\u003C\u002Fp>\n\u003Cp>\u003Cem>Excellent plugin with numerous well-thought-out options for making a website more secure. I have been using it for years and am very happy with it. I recently had a small problem setting up a website and – even as a non-premium user – I received support very quickly. Highly recommended!\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>For even more ways to stay safe and secure, upgrade to \u003Ca href=\"https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002Fpricing?utm_source=aios-wp-dir&utm_medium=referral&utm_campaign=plugin-dir&utm_content=aios_premium&utm_creative_format=description\" rel=\"nofollow ugc\">AIOS Premium\u003C\u002Fa> – it packs a punch security-wise, whilst being \u003Cstrong>extremely cost-competitive\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>LOGIN SECURITY\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication (TFA)\u003C\u002Fstrong> – Require TFA for specific user roles. Supports Google Authenticator, Microsoft Authenticator, Authy, and many more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detect and manage ‘admin’ usernames\u003C\u002Fstrong> – Identify default ‘admin’ usernames and guide users to change them to protect against brute force attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identify and correct identical login and display names\u003C\u002Fstrong> – Detect cases where the display name matches the username and provide guidance to improve login security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent user enumeration\u003C\u002Fstrong> – Block unauthorised access to URLs that can reveal sensitive information such as usernames or other details.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control login attempts\u003C\u002Fstrong> – Prevent brute force attacks by limiting the number of failed login attempts. Choose how many login attempts are allowed, set lockout durations, and more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Force user logout\u003C\u002Fstrong> – Automatically log out users after a specified period of time. Unattended sessions are closed, reducing the risk of unauthorised access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manually approve new registrations\u003C\u002Fstrong> – Review and approve new user registrations to prevent spam and fake sign-ups.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhance WordPress salt security\u003C\u002Fstrong> – Adds 64 extra characters to WordPress salts, rotating them weekly. Makes cracking passwords virtually impossible, even if your database is stolen.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u002F\u003Cbr \u002F>\n\u003Cstrong>Monitor and manage active sessions\u003C\u002Fstrong> – If a user is logged in who shouldn’t be, log them out or add them to a blacklist.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SPAM PREVENTION\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block spam coming from bots\u003C\u002Fstrong> – Reduce the load on your server and improve the user experience by automatically blocking spam comments from bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Monitor spam IP addresses\u003C\u002Fstrong> – Monitor the IP addresses of people or bots leaving spam comments. Choose which ones to block based on a configurable number of comments left.\u003C\u002Fp>\n\u003Ch4>FILE \u002F DATABASE Security\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Scan and fix file permissions\u003C\u002Fstrong> – Scan for insecure file permissions. Click once to fix issues and safeguard critical files and folders.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable PHP file editing\u003C\u002Fstrong> – Disable editing of PHP files (such as plugins and themes) via the dashboard. It’s often the first tool that attackers use as it allows for code execution.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protect sensitive files\u003C\u002Fstrong> – Prevent access to files like readme.html that might reveal information about your WordPress installation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File change scanner\u003C\u002Fstrong> – Get notified of any file changes which occur on your system. Exclude files and folders which change as part of normal operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Prevent image hotlinking\u003C\u002Fstrong> – Prevent other websites from displaying your images via hotlinking and protect server bandwidth.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Secure database backups\u003C\u002Fstrong> – Perform a database backup via UpdraftPlus from AIOS. Change the default ‘wp_’ prefix to hide your WordPress database from hackers.\u003C\u002Fp>\n\u003Ch4>FIREWALL\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Get .htaccess firewall rules\u003C\u002Fstrong> – Deny access to the .htaccess and wp-config.php files. Disable the server signature and limit file uploads to a configurable size.**\u003C\u002Fp>\n\u003Cp>Block access to the debug.log file and prevent Apache servers from listing the contents of a directory when an index.php file is not present\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Get PHP firewall rules\u003C\u002Fstrong> – PHP firewall rules prevent malicious users from exploiting well-known vulnerabilities in XML-RPC. Safeguard your content by disabling RSS and Atom feeds and avoid cross-site scripting (XSS) attacks.\u003Cbr \u002F>\nBlock fake Google bots and POST requests made by bots – Block fake Google bots and stop bots from making POST requests by blocking IP addresses where the user-agent and referrer fields are blank.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Utilise 6G firewall rules\u003C\u002Fstrong> – Employ flexible blacklist rules to reduce the number of malicious URL requests that hit your website (courtesy of Perishable Press).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>And more\u003C\u002Fstrong> – Blacklist (and whitelist) IP ranges and user agents and block unauthorized access to data by disabling REST API access for non-logged-in requests.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION ENHANCED [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Two-factor authentication\u003C\u002Fstrong> is included in the free plugin. Upgrade to Premium if you’d like to:\u003Cbr \u002F>\nRequire TFA after a set time period – Mandate TFA for all admins or other roles after their accounts reach a specified age.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Control how often TFA is required\u003C\u002Fstrong> – Set TFA to be required after a certain number of days on trusted devices instead of every login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Customise design layout\u003C\u002Fstrong> – Adjust the TFA design to match your website’s existing layout and branding.\u003Cbr \u002F>\nEmergency codes – Generate one-time use emergency codes to regain access if you lose your TFA device.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Multisite Compatible\u003C\u002Fstrong> – Ensure compatibility with WordPress multisite networks and their sub-sites for consistent TFA application.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Integration with login forms\u003C\u002Fstrong> – Integrate TFA with various login forms, including WooCommerce, Affiliates-WP, Elementor Pro, bbPress, and ‘Theme My Login’ without additional coding.\u003C\u002Fp>\n\u003Ch4>SMART 404 BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block IPs based on 404 errors\u003C\u002Fstrong> – Detect hackers probing your URLs via script and bots by the 404 errors they leave behind.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 Configuration\u003C\u002Fstrong> – Set a figure for the maximum number of 404 events allowed before an IP address is blocked. Choose a time period within which the 404 events must occur (e.g., 10 errors within 10 minutes).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 block by URL string\u003C\u002Fstrong> – Instantly block an IP address if a 404 event includes a specific URL string.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Smart 404 whitelisting\u003C\u002Fstrong> – Prevent particular IP addresses from being permanently blocked due to 404 events.\u003C\u002Fp>\n\u003Ch4>COUNTRY BLOCKING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Block traffic to the entire site or to specific pages or posts\u003C\u002Fstrong> – Useful if you’re an e-commerce site and you want to block sales to some countries for shipping or tax reasons.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Whitelist some users from blocked countries\u003C\u002Fstrong> – Whitelist IP addresses or IP ranges even if they are part of a blocked country.\u003C\u002Fp>\n\u003Ch4>MALWARE SCANNING [Premium]\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Automatic malware scanning\u003C\u002Fstrong> – Detect and protect against the latest malware, trojans, and spyware.\u003Cbr \u002F>\nAlerts you to blacklisting by search engines – Monitor your site for blacklisting by search engines due to malicious code.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Response time monitoring\u003C\u002Fstrong> – Keep track of your website’s response time to identify and address any performance issues.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Uptime monitoring\u003C\u002Fstrong> – Checks your website’s uptime every 5 minutes and alerts you immediately if your site or server goes down.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Advice and malware removal\u003C\u002Fstrong> – Need hands-on advice and support for malware removal? Our team of genuine cybersecurity experts is here to help.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Notification if something’s amiss\u003C\u002Fstrong> – Receive notifications about any issues with your site so you can address problems before they escalate.\u003C\u002Fp>\n\u003Ch4>Plugin Support\u003C\u002Fh4>\n\u003Cp>If you have a question or problem with the All-In-One Security plugin, post it on the support forum and we will help you. Premium customers can log queries directly with the team via https:\u002F\u002Fteamupdraft.com\u002Fall-in-one-security\u003C\u002Fp>\n\u003Ch4>Developers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>If you are a developer and you need some extra hooks or filters for this plugin then let us know.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Translations\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>All-In-One Security plugin can be translated to any language.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Currently available translations:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>German\u003C\u002Fli>\n\u003Cli>Spanish\u003C\u002Fli>\n\u003Cli>French\u003C\u002Fli>\n\u003Cli>Hungarian\u003C\u002Fli>\n\u003Cli>Italian\u003C\u002Fli>\n\u003Cli>Swedish\u003C\u002Fli>\n\u003Cli>Russian\u003C\u002Fli>\n\u003Cli>Chinese\u003C\u002Fli>\n\u003Cli>Portuguese (Brazil)\u003C\u002Fli>\n\u003Cli>Persian\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy Policy\u003C\u002Fh4>\n\u003Cp>This plugin may collect IP addresses for security reasons such as mitigating brute force login threats and malicious activity.\u003C\u002Fp>\n\u003Cp>The collected information is stored on your server. No information is transmitted to third parties or remote server locations.\u003C\u002Fp>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>Go to the settings menu after you activate the plugin and follow the instructions.\u003C\u002Fp>\n","Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.",1000000,36261587,1699,"2026-03-25T10:40:00.000Z","5.6",[76,22,77,23,78],"firewall","malware-scanning","two-factor-authentication","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fall-in-one-wp-security-and-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fall-in-one-wp-security-and-firewall.5.4.6.zip",93,26,"2024-02-08 00:00:00",{"slug":85,"name":86,"version":87,"author":88,"author_profile":89,"description":90,"short_description":91,"active_installs":92,"downloaded":93,"rating":94,"num_ratings":95,"last_updated":96,"tested_up_to":52,"requires_at_least":97,"requires_php":98,"tags":99,"homepage":102,"download_link":103,"security_score":94,"vuln_count":104,"unpatched_count":13,"last_vuln_date":105,"fetched_at":28},"defender-security","Defender Security – Malware Scanner, Login Security & Firewall","5.11.0","WPMU DEV - Your All-in-One WordPress Platform","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpmudev\u002F","\u003Cp>\u003Cstrong>Defender adds the best in WordPress plugin security to your website with just a few clicks, including malware scanner, firewall, password protection, and login security features. Stop brute force login attacks, weak password usage, SQL injections, cross-site scripting (XSS), and other WordPress security vulnerabilities and hacks with Defender’s malware scanner, providing antivirus scans, IP blocking, firewall, activity log, security log, and two-factor authentication (2FA) login security.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>No more complex security settings, Defender’s malware scanner, firewall, and login security features add all the hardening and security you need.\u003C\u002Fp>\n\u003Cp>Defender is brought to you by the WordPress speed specialists that created Smush image optimization, now active on more than +1 million websites.\u003C\u002Fp>\n\u003Cp>Plus, connect for free to WPMU DEV’s AntiBot Global Firewall to block harmful IPs with data from over 750,000 sites.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enjoy complete site protection from malware, vulnerabilities, bot attacks, and session hijacking from the start with \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fproject\u002Fwp-defender\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme-above-the-fold&utm_content=wp_defender_pro\" rel=\"nofollow ugc\">Defender Pro\u003C\u002Fa>.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Level up security immediately with exclusive Pro features like scheduled malware scanning, Safe Repair for suspicious files, and known WordPress vulnerability detection. \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fproject\u002Fwp-defender\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme-above-the-fold&utm_content=wp_defender_pro\" rel=\"nofollow ugc\">Learn more about Pro\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Security Recommendations\u003C\u002Fh3>\n\u003Cp>Defender’s one-click security hardening recommendations instantly adds layers of protection and security to your site.\u003C\u002Fp>\n\u003Ch3>Enhance Security and Block Hackers At Every Level:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malware Scanner\u003C\u002Fstrong> – Scan WordPress core files for modifications and unexpected changes which may be caused by malware. Scan for malware and tighten up the security of your files.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Outdated & Removed Plugins\u003C\u002Fstrong> – Scans for plugins removed from WordPress.org or not updated in 2+ years.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AntiBot Global Firewall\u003C\u002Fstrong> – Connect for free to WPMU DEV to block harmful IPs with data from over 750,000 sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress Security Firewall\u003C\u002Fstrong> – Block or allowlist IPs, implement IP blocking, and Geo IP blocking, user agent banning and protect against brute force attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two-Factor Authentication (2FA)\u003C\u002Fstrong> – Easily set up better security with 2FA to prevent most login attacks such as brute force, App verification, backup codes, lost device email, WooCommerce 2FA, and Web Authentication.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Masking\u003C\u002Fstrong> – Change the location of WordPress’s default login area to improve login security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Lockout\u003C\u002Fstrong> – Failed login attempts lockout for even more security assurance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Agent Banning\u003C\u002Fstrong> – Fortify security by blocking bad bots and user agents from accessing your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Headers\u003C\u002Fstrong> – Add an extra layer of defense security and protect against common attacks like: XSS, code injection, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>404 Detection Security\u003C\u002Fstrong> – Automated block of bot IPs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Configs\u003C\u002Fstrong> – Create your ideal Defender security plugin settings and export \u002F import saved configs to any other site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geolocation IP Lockout Security\u003C\u002Fstrong> – Block users based on location and country (IP blocking).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Trackbacks And Pingbacks\u003C\u002Fstrong> – Disable these notifications to enhance spam protection and site security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Core And Server Update Security Recommendations\u003C\u002Fstrong> – Stay on top of your system security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Antivirus Scan\u003C\u002Fstrong> – Scan for active security threats, viruses, and other malware.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable File Editor\u003C\u002Fstrong> – If they get in, they won’t get far.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Error Reporting\u003C\u002Fstrong> – Hide code errors on the frontend so hackers can’t exploit site security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Update Security Keys\u003C\u002Fstrong> – Update old WordPress security keys to be more encrypted and provide better security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prevent Information Disclosure\u003C\u002Fstrong> – Improve server security and protect sensitive files by locking down specific file types.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prevent PHP Execution\u003C\u002Fstrong> – Defender bolsters security by automatically preventing any PHP code from being executed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk Apply Security Recommendations\u003C\u002Fstrong> – Apply multiple recommended security improvements at once for quicker site hardening.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google reCAPTCHA Security\u003C\u002Fstrong> – Easy to add, stop fraud and abuse – including BuddyPress and WooCommerce.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Turnstile\u003C\u002Fstrong> – Captcha-free protection from spam and automated attacks, including BuddyPress and WooCommerce support.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pwned Password Check\u003C\u002Fstrong> – Increase security by protecting against compromised passwords.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Force Password Reset\u003C\u002Fstrong> – Force users with selected roles to reset passwords.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Force Strong Passwords\u003C\u002Fstrong> – Ensure users create secure credentials by enforcing robust password requirements.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Agent Blocklist Presets\u003C\u002Fstrong> – Easily block unwanted bots and scripts using curated user agent presets.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Known Vulnerability & Suspicious Code Scan (Pro Only)\u003C\u002Fstrong> – Scan WordPress core, themes, and plugins for vulnerabilities and harmful code.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Malicious Bot Detector (Pro Only)\u003C\u002Fstrong> – Block malicious bots with layered defenses, including traps for bots that ignore robots.txt and checks for fake crawlers posing as search engines.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Blocklist Monitoring (Pro Only)\u003C\u002Fstrong> – Get instant alerts if your site is flagged by Google.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session Protection (Pro Only)\u003C\u002Fstrong> – Stop session hijacking and prevent unauthorized account access.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Safe Repair For Suspicious Files (Pro Only)\u003C\u002Fstrong> – Restore or replace compromised files safely with a single click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automated Reports (Pro Only)\u003C\u002Fstrong> – Receive scheduled security reports straight to your inbox.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Learn The Ropes With These Hands-On Defender Security Plugin Tutorials\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fblog\u002Fhow-to-get-the-most-out-of-defender-security\u002F\" rel=\"nofollow ugc\">How to Get the Most Out of Defender Security\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fblog\u002Fstop-hackers-with-defender-wordpress-security-plugin\u002F\" rel=\"nofollow ugc\">How to Stop Hackers in Their Tracks with Defender Security\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fblog\u002Fdelete-suspicious-code-defender\u002F\" rel=\"nofollow ugc\">Find Out if You’re Hacked: How to Find and Delete Suspicious Code with Defender Security\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fblog\u002Fdefender-ip-address-lockout-firewall\u002F\" rel=\"nofollow ugc\">How to Create a Powerful and Secure Customized Firewall with Defender Security\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>WordPress Security Scans\u003C\u002Fh3>\n\u003Cp>Defender’s malware scanner security checks for suspicious code and malware. It also compares your WordPress install with the WP directory master copy, and reports any changes so you can restore the original file with a click.\u003C\u002Fp>\n\u003Ch3>Two-Factor Authentication (2FA) Security\u003C\u002Fh3>\n\u003Cp>Easily add an extra layer of protection and security to your WordPress sites with Defender’s two-factor authentication (2FA) features. Including: mobile app verification (Google Authenticator, Microsoft Authenticator, Authy), backup code generation, lost device emails, WooCommerce 2FA, Biometric Authentication (fingerprint\u002Ffacial recognition), and Hardware Key Authentication (USB security keys). Easily prevent brute force attacks and login security vulnerabilities.\u003C\u002Fp>\n\u003Ch3>Login Protection\u003C\u002Fh3>\n\u003Cp>Brute force attacks are no match for Defender’s login security. Limit login attempts so hackers can’t guess passwords. Permanently ban IPs or trigger a timed lockout after a set number of failed login attempts. Use Geo IP blocking to ban users from specific countries or locations.\u003C\u002Fp>\n\u003Ch3>Firewall Security and IP Manager\u003C\u002Fh3>\n\u003Cp>Improve your website security with Defender’s IP manager and firewall. Manually block specific IPs, import a list of banned IPs, and set automated timed and permanent lockouts. Defender makes it easy to block and unblock specific locations quickly thanks to its advanced firewall security(WAF) offering Geographical IP blocking.\u003C\u002Fp>\n\u003Ch3>User Agent Banning\u003C\u002Fh3>\n\u003Cp>Add user agents to the block or allowlist and stop bad bots from spamming and scraping your site. All major search engines and special network bots are allow-listed out of the box. Easy to set up, Defender’s user agent banning tool now includes built-in bot and script presets to help you quickly block malicious traffic. It does all the security work for you—no editing of the .htaccess file required.\u003C\u002Fp>\n\u003Ch3>Google reCAPTCHA Integration\u003C\u002Fh3>\n\u003Cp>Add reCAPTCHA security to your login \u002F registration pages, lost password forms, and post comments in a couple of steps to up security and help protect from fraud and abuse. Select reCAPTCHA type, language, location, and style to suit. As well as Google, Defender also supports the following reCAPTCHA types:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>BuddyPress reCAPTCHA\u003C\u002Fli>\n\u003Cli>WooCommerce reCAPTCHA\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Login Screen Masking\u003C\u002Fh3>\n\u003Cp>Defender makes it easy to move your login screen to a custom URL. Not only does login screen masking improve security, but it also lets you white label your login user experience and improves branding.\u003C\u002Fp>\n\u003Ch3>Force Password Reset\u003C\u002Fh3>\n\u003Cp>Enhance site security by forcing all users with selected roles to reset their password at any time. Especially helpful if you suspect a possible data breach on your site.\u003C\u002Fp>\n\u003Ch3>Security Headers\u003C\u002Fh3>\n\u003Cp>Protect your site against common attacks, such as: XSS, code injection, cross site scripting, and more. Enable the following security headers:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>X-Frame-Options\u003C\u002Fli>\n\u003Cli>X-XSS-Protection\u003C\u002Fli>\n\u003Cli>X-Content-Type-Options\u003C\u002Fli>\n\u003Cli>Strict Transport\u003C\u002Fli>\n\u003Cli>Referrer Policy\u003C\u002Fli>\n\u003Cli>Permissions-Policy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>404 Limiter\u003C\u002Fh3>\n\u003Cp>Detect when bots are being used to scan your site for security vulnerabilities and shut them down. The 404 limiter lets you stop the scan by detecting when a bot keeps visiting pages that do not exist, which can also save you from a giant strain on your site’s performance.\u003C\u002Fp>\n\u003Ch3>Security Notifications and Reports\u003C\u002Fh3>\n\u003Cp>Defender runs surveillance and sends security notifications with information that matters. All activity and notifications are recorded in the activity log to let you see at a glance the website security actions that have been taken by the Defender security plugin.\u003C\u002Fp>\n\u003Ch3>Reduce Security Setup Time With Saved Configs\u003C\u002Fh3>\n\u003Cp>Save your Defender security plugin configurations and reapply them to your other sites in just a few clicks. You can create and save an unlimited number of security configurations.\u003C\u002Fp>\n\u003Ch3>Pwned Password Check\u003C\u002Fh3>\n\u003Cp>Entered passwords are checked against public database breach records to further boost security. If a password is identified as compromised, the user will be asked to change it.\u003C\u002Fp>\n\u003Ch3>Custom IP Block\u002FAllowlist\u003C\u002Fh3>\n\u003Cp>Create your IP block\u002Fallow list once, then apply and automatically sync it to all your other sites with just a single click. Save hours by not having to manually add IPs to each individual site. *Note: a [free WPMU DEV account] (https:\u002F\u002Fwpmudev.com\u002Fregister) is required to access this feature.\u003C\u002Fp>\n\u003Ch3>What Do People Say About Defender?\u003C\u002Fh3>\n\u003Cp>★★★★★\u003Cbr \u002F>\n“I found other pro security plugins a bit too fiddly for my taste…I’m delighted with Defender” – \u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002Fkeithadv\" rel=\"nofollow ugc\">KeithADV\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>★★★★★\u003Cbr \u002F>\n“Thank you for bringing back a free and easy to use 2-Factor Authentication after Clef! Defender helps keep me aware of my site’s security.” – \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fusers\u002Fawijasa\u002F\" rel=\"ugc\">awijasa\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>★★★★★\u003Cbr \u002F>\n“Defender’s interface is very intuitive with warnings that are very helpful” – \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fprofile\u002Fdjohns\" rel=\"nofollow ugc\">djohns\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>★★★★★\u003Cbr \u002F>\n“Defender Recently blocked over 3000 attacks in one week without any noticeable impact on the website. WPMUDEV knocking it out of the park on this one.” – \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002Fprofile\u002Fdavidoswald\u002F\" rel=\"nofollow ugc\">David Oswald\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Secure Websites, More Trust, Better Profit\u003C\u002Fh3>\n\u003Cp>If you’re running a business website or eCommerce store, privacy, security, uptime and trust are essential.\u003C\u002Fp>\n\u003Cp>The Defender security plugin is here to help you: it’s a one of a kind WordPress security plugin that makes web security easy for anyone, for free!\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Malware scanner\u003C\u002Fli>\n\u003Cli>Google two-factor authentication (2FA)\u003C\u002Fli>\n\u003Cli>Web Authentication\u003C\u002Fli>\n\u003Cli>Firewall setup and configuration\u003C\u002Fli>\n\u003Cli>One-click site hardening and security tweaking\u003C\u002Fli>\n\u003Cli>WordPress core file scanning and repair\u003C\u002Fli>\n\u003Cli>Ongoing firewall security\u003C\u002Fli>\n\u003Cli>Google reCAPTCHA\u003C\u002Fli>\n\u003Cli>Security headers\u003C\u002Fli>\n\u003Cli>One-click security configs\u003C\u002Fli>\n\u003Cli>Login Screen Masking\u003C\u002Fli>\n\u003Cli>Pwned Password Check\u003C\u002Fli>\n\u003Cli>IP Blocklist manager and logging\u003C\u002Fli>\n\u003Cli>Geo IP blocking\u003C\u002Fli>\n\u003Cli>User agent banning\u003C\u002Fli>\n\u003Cli>Unlimited file scans\u003C\u002Fli>\n\u003Cli>Timed Lockout brute force login attack shield for login security\u003C\u002Fli>\n\u003Cli>404 limiter for blocking vulnerability scans\u003C\u002Fli>\n\u003Cli>IP lockout notifications and security reports\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All the above is free and will enhance WordPress security for you. If you need extra security for your WordPress site, \u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme&utm_content=you_should_get_wpmudev_membership#trial\" rel=\"nofollow ugc\">you should get a WPMU DEV Membership\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Our Membership gives you access to Defender Pro – which security features include automated scanning, scheduled malware scans for Core, themes, plugins and other files, audit logs, firewall protection, Safe Repair, Blocklist monitoring – alongside Snapshot Pro cloud backups, the Hub with automated plugin, theme and core updates and safe-upgrade scans, all our premium WordPress plugins, 24\u002F7 WordPress support and if your sites already been hacked our team of security experts will clean it up at no additional cost.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme&utm_content=and_you_can_find_out_more_here#trial\" rel=\"nofollow ugc\">It’s an incredible deal, and you can find out more here\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>About Us\u003C\u002Fh3>\n\u003Cp>WPMU DEV is a premium supplier of quality WordPress plugins and themes. For premium support with any WordPress-related issues you can join us here:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme&utm_content=wpmu_dev_link\" rel=\"nofollow ugc\">https:\u002F\u002Fwpmudev.com\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Don’t forget to stay up to date on everything WordPress from the Internet’s number one resource:\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwpmudev.com\u002F?utm_source=wordpress.org&utm_medium=readme&utm_campaign=defender-readme&utm_content=wpmu_dev_blog_link\" rel=\"nofollow ugc\">WPMU DEV Blog\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Hey, one more thing… we hope you \u003Ca href=\"https:\u002F\u002Fprofiles.wordpress.org\u002FWPMUDEV\u002F\" rel=\"nofollow ugc\">enjoy our free offerings\u003C\u002Fa> as much as we’ve loved making them for you!\u003C\u002Fp>\n","WordPress security plugin with malware scanner, IP blocking, audit logs, antivirus scans, firewall, 2FA, brute force login security, and more.",90000,4087538,96,330,"2026-04-07T13:07:00.000Z","6.4","8.0.0",[76,22,100,101,23],"malware","malware-scanner","https:\u002F\u002Fwpmudev.com\u002Fproject\u002Fwp-defender\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefender-security.5.11.0.zip",7,"2024-06-28 00:00:00",{"slug":107,"name":108,"version":109,"author":110,"author_profile":111,"description":112,"short_description":113,"active_installs":114,"downloaded":115,"rating":116,"num_ratings":117,"last_updated":118,"tested_up_to":119,"requires_at_least":120,"requires_php":52,"tags":121,"homepage":123,"download_link":124,"security_score":125,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"wordfence-login-security","Wordfence Login Security","1.1.15","wfryan","https:\u002F\u002Fprofiles.wordpress.org\u002Fwfryan\u002F","\u003Ch3>WORDFENCE LOGIN SECURITY\u003C\u002Fh3>\n\u003Cp>Wordfence Login Security contains a subset of the functionality found in the full Wordfence plugin: Two-factor Authentication, XML-RPC Protection and Login Page CAPTCHA.\u003C\u002Fp>\n\u003Cp>Are you looking for comprehensive WordPress Security? \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwordfence\u002F\" rel=\"ugc\">Check out the full Wordfence plugin\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>TWO-FACTOR AUTHENTICATION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Two-factor authentication (2FA), one of the most secure forms of remote system authentication available.\u003C\u002Fli>\n\u003Cli>Use any TOTP-based authenticator app or service like Google Authenticator, Authy, 1Password or FreeOTP.\u003C\u002Fli>\n\u003Cli>Enable 2FA for any WordPress user role.\u003C\u002Fli>\n\u003Cli>Completely free to use, no limits or restrictions of any kind.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>LOGIN PAGE CAPTCHA\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easily enable Google ReCAPTCHA v3 on your login and registration pages.\u003C\u002Fli>\n\u003Cli>Stops bots from logging in without inconveniencing your site visitors.\u003C\u002Fli>\n\u003Cli>Robust protection against password guessing and credential stuffing attacks distributed across large IP pools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>XML-RPC PROTECTION\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>XML-RPC is the biggest target for WordPress attacks, but is often overlooked.\u003C\u002Fli>\n\u003Cli>Protect XML-RPC with 2FA or disable it altogether if it’s not needed.\u003C\u002Fli>\n\u003C\u002Ful>\n","Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.",70000,1246273,80,25,"2025-01-15T17:05:00.000Z","6.7.5","4.7",[54,122,22,23,78],"captcha","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwordfence-login-security.1.1.15.zip",92,{"slug":127,"name":128,"version":129,"author":130,"author_profile":131,"description":132,"short_description":133,"active_installs":134,"downloaded":135,"rating":94,"num_ratings":136,"last_updated":137,"tested_up_to":50,"requires_at_least":16,"requires_php":52,"tags":138,"homepage":140,"download_link":141,"security_score":142,"vuln_count":143,"unpatched_count":13,"last_vuln_date":144,"fetched_at":28},"bulletproof-security","BulletProof Security","7.1","AITpro","https:\u002F\u002Fprofiles.wordpress.org\u002Faitpro\u002F","\u003Cp>WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam… View Security feature highlights below. View BulletProof Security feature details under the FAQ help section below. Effective, Reliable & Easy to use WordPress Security Plugin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>BulletProof Security is a proactive security plugin that automatically fixes 100+ known issues\u002Fconflicts with other plugins\u003C\u002Fstrong>.\u003Cbr \u002F>\n* \u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fforums\u002Ftopic\u002Fsetup-wizard-autofix\u002F\" title=\"BPS Setup Wizard AutoFix\" rel=\"nofollow ugc\">BPS Setup Wizard AutoFix\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>BulletProof Security Installation and Setup Video Tutorial\u003C\u002Fh4>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FRZ1ARaEE0_I?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>BulletProof Security Feature Highlights\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>One-Click Setup Wizard\u003C\u002Fli>\n\u003Cli>Setup Wizard AutoFix (AutoWhitelist|AutoSetup|AutoCleanup)\u003C\u002Fli>\n\u003Cli>MScan Malware Scanner\u003C\u002Fli>\n\u003Cli>.htaccess Website Security Protection (Firewalls)\u003C\u002Fli>\n\u003Cli>Hidden Plugin Folders|Files Cron (HPF)\u003C\u002Fli>\n\u003Cli>Login Security & Monitoring\u003C\u002Fli>\n\u003Cli>JTC-Lite (Limited version of BPS Pro JTC Anti-Spam|Anti-Hacker)\u003C\u002Fli>\n\u003Cli>Idle Session Logout (ISL)\u003C\u002Fli>\n\u003Cli>Auth Cookie Expiration (ACE)\u003C\u002Fli>\n\u003Cli>DB Backup: Full|Partial DB Backups | Manual|Scheduled DB Backups | Email Zip Backups | Cron Delete Old Backups\u003C\u002Fli>\n\u003Cli>DB Table Prefix Changer\u003C\u002Fli>\n\u003Cli>Security Logging\u003C\u002Fli>\n\u003Cli>HTTP Error Logging\u003C\u002Fli>\n\u003Cli>FrontEnd|BackEnd Maintenance Mode\u003C\u002Fli>\n\u003Cli>Extensive System Info (System Info page)\u003C\u002Fli>\n\u003Cli>WordPress Automatic Update Options\u003C\u002Fli>\n\u003Cli>Force Strong Passwords (FSP)\u003C\u002Fli>\n\u003Cli>Send email alerts when new Plugin & Theme updates are available\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>BulletProof Security Pro Feature Highlights\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>One-Click Setup Wizard\u003C\u002Fli>\n\u003Cli>Setup Wizard AutoFix (AutoWhitelist|AutoSetup|AutoCleanup)\u003C\u002Fli>\n\u003Cli>AutoRestore Intrusion Detection & Prevention System (ARQ IDPS)\u003C\u002Fli>\n\u003Cli>Quarantine Intrusion Detection & Prevention System (ARQ IDPS)\u003C\u002Fli>\n\u003Cli>Real-time File Monitor (IDPS)\u003C\u002Fli>\n\u003Cli>MScan Malware Scanner\u003C\u002Fli>\n\u003Cli>DB Monitor Intrusion Detection System (IDS)\u003C\u002Fli>\n\u003Cli>DB Diff Tool: data comparison tool\u003C\u002Fli>\n\u003Cli>DB Backup: Full|Partial DB Backups | Manual|Scheduled DB Backups | Email Zip Backups | Cron Delete Old Backups\u003C\u002Fli>\n\u003Cli>DB Status & Info: extensive database status & info\u003C\u002Fli>\n\u003Cli>Plugin Firewall (IP Firewall): Automated Whitelisting & IP Address Updated in Real-time\u003C\u002Fli>\n\u003Cli>JTC Anti-Spam|Anti-Hacker\u003C\u002Fli>\n\u003Cli>Uploads Folder Anti-Exploit Guard (UAEG)\u003C\u002Fli>\n\u003Cli>.htaccess Website Security Protection (Firewalls)\u003C\u002Fli>\n\u003Cli>Hidden Plugin Folders|Files Cron (HPF)\u003C\u002Fli>\n\u003Cli>Custom php.ini Website Security\u003C\u002Fli>\n\u003Cli>Login Security & Monitoring w\u002FDashboard Alerting|Status Display & additional options\u002Ffeatures\u003C\u002Fli>\n\u003Cli>Idle Session Logout (ISL)\u003C\u002Fli>\n\u003Cli>Auth Cookie Expiration (ACE)\u003C\u002Fli>\n\u003Cli>File|Folder Lock: File Locking | Detect & Lock Folders that were not created by you\u003C\u002Fli>\n\u003Cli>FrontEnd|BackEnd Maintenance Mode\u003C\u002Fli>\n\u003Cli>Security Logging\u003C\u002Fli>\n\u003Cli>HTTP Error Logging\u003C\u002Fli>\n\u003Cli>PHP Error Logging\u003C\u002Fli>\n\u003Cli>DB Table Prefix Changer\u003C\u002Fli>\n\u003Cli>Pro-Tools: 16 mini-plugins\u003C\u002Fli>\n\u003Cli>Heads Up Dashboard Status Display\u003C\u002Fli>\n\u003Cli>Extensive System Info (System Info page)\u003C\u002Fli>\n\u003Cli>WordPress Automatic Update Options\u003C\u002Fli>\n\u003Cli>Force Strong Passwords (FSP)\u003C\u002Fli>\n\u003Cli>Send email alerts when new Plugin & Theme updates are available\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.ait-pro.com\u002Fbps-features\u002F\" title=\"BulletProof Security Features\" rel=\"nofollow ugc\">View All BulletProof Security Pro Feature Details\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>BulletProof Security Recommended Video Tutorials\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fvideo-tutorials\u002F#custom-code\" title=\"BulletProof Security Custom Code Video Tutorial\" rel=\"nofollow ugc\">BulletProof Security Custom Code Video Tutorial\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fvideo-tutorials\u002F#security-log-firewall\" title=\"BulletProof Security Security Log Video Tutorial\" rel=\"nofollow ugc\">BulletProof Security Security Log Video Tutorial\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Help Info\u003C\u002Fh3>\n\u003Cp>For details about BulletProof Security plugin features and frequently asked questions see the \u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fforums\u002Ftopic\u002Fbulletproof-security-plugin-frequently-asked-questions\u002F\" title=\"AIT-pro.com Forum\" rel=\"nofollow ugc\">BulletProof Security Plugin Frequently Asked Questions\u003C\u002Fa> forum topic. Extensive Help Info can be found on the \u003Ca href=\"https:\u002F\u002Fforum.ait-pro.com\u002Fforums\u002Ftopic\u002Fread-me-first-free\u002F#bps-free-general-troubleshooting\" title=\"AIT-pro.com Forum\" rel=\"nofollow ugc\">AIT-pro.com Forum\u003C\u002Fa> website and by clicking the Question Mark Help buttons on BulletProof Security plugin pages.\u003C\u002Fp>\n","WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam...",30000,4516831,674,"2025-12-08T15:11:00.000Z",[76,22,101,139,23],"secure","https:\u002F\u002Fforum.ait-pro.com\u002Fread-me-first\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbulletproof-security.7.1.zip",89,12,"2026-01-06 00:00:00",{"attackSurface":146,"codeSignals":281,"taintFlows":289,"riskAssessment":316,"analyzedAt":319},{"hooks":147,"ajaxHandlers":277,"restRoutes":278,"shortcodes":279,"cronEvents":280,"entryPointCount":13,"unprotectedCount":13},[148,154,159,164,167,171,176,181,185,189,193,197,200,203,206,210,214,217,220,223,227,230,233,237,240,244,247,250,253,256,258,260,262,265,268,272,274],{"type":149,"name":150,"callback":151,"file":152,"line":153},"action","init","shield_wp_admin_block_blacklisted_ips","includes\u002Fshield_wp_admin-blacklist-ip.php",11,{"type":149,"name":155,"callback":156,"file":157,"line":158},"login_enqueue_scripts","shield_wp_admin_custom_login_logo","includes\u002Fshield_wp_admin-image-change.php",53,{"type":149,"name":160,"callback":161,"file":162,"line":163},"login_form","shield_wp_admin_recaptcha_form","includes\u002Fshield_wp_admin-login-hide.php",163,{"type":149,"name":150,"callback":165,"file":162,"line":166},"shield_wp_admin_handle_custom_login_slug",177,{"type":149,"name":168,"callback":169,"file":162,"line":170},"login_init","shield_wp_admin_login_using_auth",249,{"type":172,"name":173,"callback":174,"priority":11,"file":162,"line":175},"filter","login_redirect","shield_wp_admin_login_redirect",271,{"type":172,"name":177,"callback":178,"priority":179,"file":162,"line":180},"logout_url","shield_wp_admin_custom_logout_redirect_url",99,294,{"type":172,"name":182,"callback":183,"priority":11,"file":162,"line":184},"retrieve_password_message","shield_wp_admin_modify_password_reset_email",332,{"type":172,"name":186,"callback":187,"priority":11,"file":162,"line":188},"wp_new_user_notification_email","shield_wp_admin_customize_new_user_notification_email",377,{"type":149,"name":190,"callback":191,"file":162,"line":192},"login_form_bottom","shield_wp_admin_add_auth_hidden_field",406,{"type":172,"name":194,"callback":195,"priority":11,"file":162,"line":196},"wp_redirect","closure",421,{"type":149,"name":160,"callback":161,"file":198,"line":199},"includes\u002Fshield_wp_admin-login-limit.php",59,{"type":149,"name":160,"callback":201,"file":198,"line":202},"shield_wp_admin_show_remaining_attempts",63,{"type":172,"name":204,"callback":205,"priority":34,"file":198,"line":94},"authenticate","shield_wp_admin_block_locked_out_user",{"type":149,"name":207,"callback":208,"priority":11,"file":198,"line":209},"wp_login","shield_wp_admin_clear_failed_login_data",122,{"type":149,"name":211,"callback":212,"file":198,"line":213},"wp_login_failed","shield_wp_admin_handle_failed_login",164,{"type":149,"name":168,"callback":215,"file":198,"line":216},"shield_wp_admin_prevent_locked_login_form",200,{"type":149,"name":160,"callback":161,"file":218,"line":219},"includes\u002Fshield_wp_admin-recaptcha.php",34,{"type":172,"name":204,"callback":221,"priority":34,"file":218,"line":222},"shield_wp_admin_recaptcha_authenticate",141,{"type":149,"name":224,"callback":195,"file":225,"line":226},"admin_menu","includes\u002Fshield_wp_admin-settings.php",18,{"type":149,"name":228,"callback":195,"file":225,"line":229},"admin_init",33,{"type":149,"name":150,"callback":195,"file":231,"line":232},"includes\u002Fshield_wp_admin-toggle-hide.php",31,{"type":172,"name":234,"callback":235,"file":231,"line":236},"the_generator","__return_empty_string",41,{"type":172,"name":238,"callback":195,"priority":11,"file":231,"line":239},"rest_pre_serve_request",50,{"type":172,"name":241,"callback":242,"priority":243,"file":231,"line":116},"script_loader_src","shield_wp_admin_remove_wp_version_from_assets",9999,{"type":172,"name":245,"callback":242,"priority":243,"file":231,"line":246},"style_loader_src",81,{"type":149,"name":248,"callback":195,"file":231,"line":249},"plugins_loaded",88,{"type":172,"name":251,"callback":252,"file":231,"line":35},"xmlrpc_enabled","__return_false",{"type":172,"name":254,"callback":195,"file":231,"line":255},"xmlrpc_methods",97,{"type":149,"name":228,"callback":195,"file":231,"line":257},118,{"type":149,"name":150,"callback":195,"file":231,"line":259},133,{"type":172,"name":254,"callback":195,"file":231,"line":261},139,{"type":172,"name":263,"callback":195,"file":231,"line":264},"wp_headers",145,{"type":149,"name":155,"callback":266,"file":267,"line":26},"shield_wp_admin_login_styles","shield-wp-admin.php",{"type":149,"name":269,"callback":270,"file":267,"line":271},"admin_enqueue_scripts","shield_wp_admin_enqueue_styles",148,{"type":149,"name":150,"callback":195,"file":267,"line":273},154,{"type":149,"name":228,"callback":275,"file":267,"line":276},"shield_wp_admin_redirect_to_settings",229,[],[],[],[],{"dangerousFunctions":282,"sqlUsage":283,"outputEscaping":285,"fileOperations":13,"externalRequests":33,"nonceChecks":287,"capabilityChecks":33,"bundledLibraries":288},[],{"prepared":13,"raw":13,"locations":284},[],{"escaped":259,"rawEcho":13,"locations":286},[],8,[],[290,308],{"entryPoint":291,"graph":292,"unsanitizedCount":13,"severity":307},"shield_wp_admin_recaptcha_form (includes\u002Fshield_wp_admin-recaptcha.php:13)",{"nodes":293,"edges":304},[294,299],{"id":295,"type":296,"label":297,"file":218,"line":298},"n0","source","$_POST",23,{"id":300,"type":301,"label":302,"file":218,"line":117,"wp_function":303},"n1","sink","echo() [XSS]","echo",[305],{"from":295,"to":300,"sanitized":306},true,"low",{"entryPoint":309,"graph":310,"unsanitizedCount":13,"severity":307},"\u003Cshield_wp_admin-recaptcha> (includes\u002Fshield_wp_admin-recaptcha.php:0)",{"nodes":311,"edges":314},[312,313],{"id":295,"type":296,"label":297,"file":218,"line":298},{"id":300,"type":301,"label":302,"file":218,"line":117,"wp_function":303},[315],{"from":295,"to":300,"sanitized":306},{"summary":317,"deductions":318},"The 'shield-wp-admin' v1.0 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to best practices by having no identifiable AJAX handlers, REST API routes, shortcodes, or cron events that could serve as entry points. The absence of dangerous functions and file operations is also a positive indicator. Furthermore, all SQL queries are secured using prepared statements, and all output is properly escaped, mitigating common vulnerabilities like SQL injection and cross-site scripting. The plugin also correctly implements 8 nonce checks and 1 capability check, which are crucial for securing actions within WordPress.\n\nThe taint analysis reveals no critical or high-severity issues with unsanitized paths, reinforcing the plugin's secure handling of data. The lack of any known past vulnerabilities, critical, high, medium, or low, further suggests a development team that prioritizes security or has been fortunate to avoid past issues. The single external HTTP request, while a potential point of concern, is not flagged as an issue in the taint analysis, implying it is likely handled safely. The plugin's clean record and robust code practices indicate a low immediate risk.\n\nIn conclusion, 'shield-wp-admin' v1.0 presents as a very secure plugin. Its minimal attack surface, diligent use of security features like prepared statements, proper output escaping, and nonce\u002Fcapability checks are commendable. The absence of any vulnerability history is a significant strength. While the single external HTTP request warrants monitoring, it does not currently present a quantifiable risk based on this data.",[],"2026-04-16T12:04:36.314Z",{"wat":321,"direct":335},{"assetPaths":322,"generatorPatterns":327,"scriptPaths":328,"versionParams":330},[323,324,325,326],"\u002Fwp-content\u002Fplugins\u002Fshield-wp-admin\u002Fassets\u002Fcss\u002Fshield_wp_admin-style.css","\u002Fwp-content\u002Fplugins\u002Fshield-wp-admin\u002Fassets\u002Fjs\u002Fshield_wp_admin-login-hide.js","\u002Fwp-content\u002Fplugins\u002Fshield-wp-admin\u002Fassets\u002Fjs\u002Fshield_wp_admin-admin-media.js","\u002Fwp-content\u002Fplugins\u002Fshield-wp-admin\u002Fassets\u002Fjs\u002Fshield_wp_admin-recaptcha-toggle.js",[],[329],"https:\u002F\u002Fwww.google.com\u002Frecaptcha\u002Fapi.js",[331,332,333,334],"shield-wp-admin\u002Fassets\u002Fcss\u002Fshield_wp_admin-style.css?ver=","shield-wp-admin\u002Fassets\u002Fjs\u002Fshield_wp_admin-login-hide.js?ver=","shield-wp-admin\u002Fassets\u002Fjs\u002Fshield_wp_admin-admin-media.js?ver=","shield-wp-admin\u002Fassets\u002Fjs\u002Fshield_wp_admin-recaptcha-toggle.js?ver=",{"cssClasses":336,"htmlComments":337,"htmlAttributes":338,"restEndpoints":342,"jsGlobals":343,"shortcodeOutput":346},[],[],[339,340,341],"shield_wp_admin_upload_logo_title","shield_wp_admin_upload_button_text","shield_wp_admin_upload_button_updated_text",[],[344,345],"shield_wp_admin_login_data","shield_wp_admin_media",[],{"error":306,"url":348,"statusCode":349,"statusMessage":350,"message":350},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fshield-wp-admin\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":33,"versions":352},[353],{"version":6,"download_url":25,"svn_tag_url":354,"released_at":27,"has_diff":355,"diff_files_changed":356,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":357,"is_current":306},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fshield-wp-admin\u002Ftags\u002F1.0\u002F",false,[],[]]