[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAZlA9W95Cz34-FUIXWEmdKC_NWUxjTdDF2KtiH_knaQ":3,"$fQHmoPYGKEjIBM-XUursgrCTfRJXWiIKy_ZCzCpe1Y30":111,"$fU81EV-gWiwNCgqXjZ12E4ro0ElrZwZoyKwvTeWuHPnY":116},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"shieldscope-site-security-scanner","ShieldScope – Site Security Scanner","1.3.1","Dhiren Patel","https:\u002F\u002Fprofiles.wordpress.org\u002Fdhirenpatel22\u002F","\u003Cp>\u003Cstrong>ShieldScope – Site Security Scanner\u003C\u002Fstrong> runs a deep, read-only security audit across your entire WordPress site and produces a clear report of issues grouped by severity: Critical, High, Medium, Low, and Info.\u003C\u002Fp>\n\u003Cp>Most security scanners either freeze your admin panel while they run, or quietly hammer your server in the background. ShieldScope does neither. It runs in small, controlled steps with a built-in speed limit — so your site stays fast and responsive the whole time. If you switch to another browser tab, the scan automatically pauses and picks up exactly where it left off when you return.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Here is what ShieldScope checks:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch4>WordPress Core Health\u003C\u002Fh4>\n\u003Cp>Checks that your WordPress installation is up to date and securely configured. Flags outdated versions, exposed debug settings, insecure table prefixes, and other common setup mistakes that attackers actively look for.\u003C\u002Fp>\n\u003Ch4>Core File Integrity\u003C\u002Fh4>\n\u003Cp>Verifies that every WordPress core file is exactly as it should be by comparing against official WordPress checksums. Flags any modified or unexpected files inside core WordPress folders — a common sign of a hacked or tampered site.\u003C\u002Fp>\n\u003Ch4>User Accounts\u003C\u002Fh4>\n\u003Cp>Reviews all administrator accounts for common weaknesses: a default “admin” username, too many admin accounts, weak or outdated password storage, empty passwords, and accounts whose login name is visible to the public.\u003C\u002Fp>\n\u003Ch4>Files & Folders\u003C\u002Fh4>\n\u003Cp>Scans your site’s file system for risky permissions, sensitive configuration files left publicly accessible, leftover backup files that should never be on a live server, and unexpected files in folders where only media should live.\u003C\u002Fp>\n\u003Ch4>Plugins\u003C\u002Fh4>\n\u003Cp>Flags plugins with pending security updates, plugins that are installed but inactive (a common attack surface), and plugins that appear to have been abandoned by their developers with no recent maintenance.\u003C\u002Fp>\n\u003Ch4>Themes\u003C\u002Fh4>\n\u003Cp>Flags themes with pending updates, extra inactive themes that add unnecessary risk, and checks whether your site has a proper active theme configured.\u003C\u002Fp>\n\u003Ch4>Malicious Code Patterns\u003C\u002Fh4>\n\u003Cp>Scans plugin and theme files for known malware signatures, hidden backdoors, and dangerous code patterns that attackers commonly plant on compromised WordPress sites.\u003C\u002Fp>\n\u003Ch4>SSL & HTTPS\u003C\u002Fh4>\n\u003Cp>Checks that your SSL certificate is valid and not about to expire, that your site uses a modern version of HTTPS encryption, that all pages load securely, and that visitors are always redirected from HTTP to HTTPS automatically.\u003C\u002Fp>\n\u003Ch4>Security Headers\u003C\u002Fh4>\n\u003Cp>Checks that your site sends the right security instructions to visitors’ browsers — protections that help prevent clickjacking, content-type attacks, and referrer leaks. Also checks whether your WordPress version number is being broadcast publicly, which gives attackers a head start.\u003C\u002Fp>\n\u003Ch4>Database Settings\u003C\u002Fh4>\n\u003Cp>Checks database-level security settings: whether open user registration is configured with too many permissions, whether your site URLs are consistent, and whether any administrator accounts were created recently without your knowledge.\u003C\u002Fp>\n\u003Ch4>Injection Vulnerabilities\u003C\u002Fh4>\n\u003Cp>Scans plugin and theme code for common vulnerability patterns including SQL injection, cross-site scripting (XSS), and other code weaknesses that attackers exploit to take control of WordPress sites or steal visitor data.\u003C\u002Fp>\n\u003Ch4>Access Control\u003C\u002Fh4>\n\u003Cp>Tests whether parts of your site that should require a login are actually protected. Looks for username leaks through public author pages, missing brute-force login protection, lack of two-factor authentication, and whether admin pages and API endpoints enforce proper access checks.\u003C\u002Fp>\n\u003Ch4>Server Configuration\u003C\u002Fh4>\n\u003Cp>Checks for server-level security issues: outdated PHP versions that no longer receive security patches, sensitive files accidentally left accessible to the public (such as environment config files or debug logs), and server settings that leak technical information to potential attackers.\u003C\u002Fp>\n\u003Ch4>Server-Side Request Forgery (SSRF)\u003C\u002Fh4>\n\u003Cp>Looks for code patterns in plugins and themes that could allow an attacker to trick your server into making unauthorised requests to other systems — both on the internet and inside your private network.\u003C\u002Fp>\n\u003Ch4>Vulnerable & Outdated Components\u003C\u002Fh4>\n\u003Cp>Checks your database software version, WordPress version, and installed plugins against known vulnerability records and end-of-support dates. Flags anything running on software that no longer receives security patches.\u003C\u002Fp>\n\u003Ch4>Vulnerability Database\u003C\u002Fh4>\n\u003Cp>Cross-references your installed plugins and themes against a known vulnerability database. A free WPScan API key (optional) enables live lookups for every plugin and theme on your site. Without a key, a built-in list of the most commonly exploited plugins is checked automatically — no setup needed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>ShieldScope never makes any changes to your site.\u003C\u002Fstrong> It is strictly read-only. It scans, reports, and recommends — nothing else.\u003C\u002Fp>\n\u003Ch3>Third-Party Services\u003C\u002Fh3>\n\u003Cp>This plugin communicates with the following external services \u003Cstrong>only while a scan is actively running\u003C\u002Fstrong>. No data is sent on regular page loads.\u003C\u002Fp>\n\u003Ch4>WordPress.org Core Checksums API\u003C\u002Fh4>\n\u003Cp>During the Core Integrity check, the plugin fetches the official file checksums for your exact WordPress version and locale from the WordPress.org API. The only data sent is your WordPress version number and site locale (for example, en_US). No personal data, usernames, or site URLs are transmitted.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service: https:\u002F\u002Fapi.wordpress.org\u002Fcore\u002Fchecksums\u002F1.0\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WPScan Vulnerability Database (optional)\u003C\u002Fh4>\n\u003Cp>If you enter a WPScan API key in Settings, the Vulnerability Database check sends the slug and version number of each installed plugin and theme to wpscan.com to retrieve known vulnerability data. This feature is \u003Cstrong>disabled by default\u003C\u002Fstrong> and requires you to explicitly provide an API key. The free tier allows 25 requests per day; results are cached for 24 hours.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service: https:\u002F\u002Fwpscan.com\u002Fapi\u002Fv3\u002F\u003C\u002Fli>\n\u003Cli>Privacy policy: https:\u002F\u002Fautomattic.com\u002Fprivacy\u002F\u003C\u002Fli>\n\u003Cli>Terms of service: https:\u002F\u002Fwpscan.com\u002Fterms\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Disclaimer\u003C\u002Fh3>\n\u003Cp>ShieldScope uses automated analysis to identify potential security issues. Findings should be reviewed before acting on them — particularly for plugins and themes, where a finding may require verification with the plugin or theme developer.\u003C\u002Fp>\n\u003Cp>This plugin is designed to help website owners identify security risks on their own sites. It does not guarantee detection of every possible vulnerability.\u003C\u002Fp>\n\u003Cp>All scanning is performed locally on your own server. No scan data, site content, or personal information is stored externally or shared with any third party. For questions, please use the support forum.\u003C\u002Fp>\n","A thorough WordPress security scanner that checks your entire site for vulnerabilities and misconfigurations — without slowing it down.",0,114,"2026-07-01T07:52:00.000Z","7.0.2","5.8","7.4",[18,19,20,21,22],"audit","hardening","malware","scanner","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fshieldscope-site-security-scanner\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshieldscope-site-security-scanner.1.3.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"dhirenpatel22",1,30,94,"2026-08-25T00:33:06.878Z",[37,53,70,83,98],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":25,"downloaded":45,"rating":11,"num_ratings":11,"last_updated":46,"tested_up_to":14,"requires_at_least":47,"requires_php":16,"tags":48,"homepage":51,"download_link":52,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"aipatch-security-scanner","Aipatch Security Scanner","2.0.2","Esteban","https:\u002F\u002Fprofiles.wordpress.org\u002Festebandezafra\u002F","\u003Cp>\u003Cstrong>Aipatch Security Scanner\u003C\u002Fstrong> is a modular security audit engine built for site owners, developers, and AI-powered agents who need deep visibility into WordPress security posture — without the bloat of all-in-one security suites.\u003C\u002Fp>\n\u003Ch4>Why Aipatch Security Scanner?\u003C\u002Fh4>\n\u003Cp>Most WordPress security plugins are either too simple to be useful or too heavy to be practical. Aipatch takes a different approach:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Audit-first architecture.\u003C\u002Fstrong> Every check is a standalone, testable module that returns structured findings with severity, confidence, evidence, and fingerprints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built for automation.\u003C\u002Fstrong> 23 MCP abilities expose the full audit, scanning, and remediation surface to external AI agents — making Aipatch the first WordPress security plugin designed for agentic workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero external dependencies.\u003C\u002Fstrong> Everything runs locally. No accounts, no cloud services, no API keys required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reversible by design.\u003C\u002Fstrong> Every automated remediation stores rollback data so you can undo any change with one click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Core Capabilities\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>36-Point Security Audit\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Aipatch runs 36 automated checks across 8 categories — core, plugins, themes, users, configuration, server, access control, and malware surface:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Outdated WordPress core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Default admin username, excessive admin accounts, inactive admin users, user ID 1 exposure\u003C\u002Fli>\n\u003Cli>XML-RPC, file editor, debug mode, debug log, REST API exposure, directory listing\u003C\u002Fli>\n\u003Cli>PHP version, HTTPS, file permissions, security headers (X-Frame-Options, CSP, etc.)\u003C\u002Fli>\n\u003Cli>Database prefix, sensitive files, PHP execution in uploads, auto-update configuration\u003C\u002Fli>\n\u003Cli>Salt key strength, cron health, cookie security flags, CORS, application passwords\u003C\u002Fli>\n\u003Cli>Exposed backup files, phpinfo files, uploads directory indexing, default login URL\u003C\u002Fli>\n\u003Cli>Database credential security, file installation permissions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Every finding includes a severity (critical \u002F high \u002F medium \u002F low \u002F info), confidence score, human-readable explanation, and actionable recommendation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Weighted Security Score (0–100)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A logarithmic scoring engine computes an overall security score and per-area breakdown across six risk dimensions: software, access control, configuration, infrastructure, malware surface, and vulnerability exposure. Severity weights and confidence multipliers ensure the score reflects actual risk, not just issue count.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Multi-Layer Malware File Scanner\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A three-layer file scanner (content 55%, context 25%, integrity 20%) with 27 detection signatures, Shannon entropy analysis, and malware family classification detects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Code execution patterns: eval(), assert(), create_function(), preg_replace \u002Fe\u003C\u002Fli>\n\u003Cli>System command functions: shell_exec, exec, passthru, backtick operators\u003C\u002Fli>\n\u003Cli>Obfuscation techniques: base64 encoding, hex encoding, str_rot13, gzinflate chains, chr() concatenation, variable variables, suspiciously long lines\u003C\u002Fli>\n\u003Cli>Network\u002Fexfiltration: cURL execution, fsockopen, remote file_get_contents\u003C\u002Fli>\n\u003Cli>Known backdoor signatures: c99, r57, WSO, b374k, weevely, FilesMan\u003C\u002Fli>\n\u003Cli>WordPress-specific threats: unauthorized admin creation, critical option injection, security function removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Scanning runs in batches via an async job system with configurable batch sizes — safe for shared hosting.\u003C\u002Fp>\n\u003Cp>Files are classified into 11 malware families (web shell, obfuscated loader, dropper, persistence backdoor, cloaked PHP, code injector, and more) with confidence scores and remediation hints.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Core Integrity Verification\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Verifies every core file against official checksums from api.wordpress.org. Detects modified core files (checksum mismatch), missing core files, and unexpected files planted in wp-admin\u002F or wp-includes\u002F. Core tampering findings are automatically escalated to critical severity with zero false-positive likelihood.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Build a known-good hash baseline of all PHP files in your installation. Diff against it at any time to detect modified, deleted, or newly added files. Origin detection distinguishes core, plugin, theme, and upload files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A local knowledge base of known plugin, theme, and core vulnerabilities with a database-backed caching layer for fast lookups. Provider architecture allows extending with external feeds.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-Click Remediation with Rollback\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Apply fixes directly from findings — change WordPress options, delete suspicious files, rename files, patch file contents, or add .htaccess rules. Every automated action stores a full rollback payload so you can reverse any change. Manual remediations can be logged for audit trails.\u003C\u002Fp>\n\u003Cp>Six supported action types: \u003Ccode>wp_option\u003C\u002Fcode>, \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>rename_file\u003C\u002Fcode>, \u003Ccode>file_patch\u003C\u002Fcode>, \u003Ccode>htaccess_rule\u003C\u002Fcode>, \u003Ccode>manual\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hardening Module\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Five toggleable hardening rules with clear explanations and compatibility warnings:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable XML-RPC — blocks external XML-RPC requests and removes X-Pingback header\u003C\u002Fli>\n\u003Cli>Hide WordPress Version — removes version leaks from source, RSS feeds, scripts, and styles\u003C\u002Fli>\n\u003Cli>Restrict REST API — limits sensitive endpoints to authenticated users\u003C\u002Fli>\n\u003Cli>Block Author Scanning — prevents user enumeration via author archives\u003C\u002Fli>\n\u003Cli>Login Brute-Force Protection — rate-limits login attempts per IP with configurable thresholds and lockout duration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Persistent Findings Store\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All audit findings persist in a dedicated database table with automatic deduplication by fingerprint. Track findings over time — dismissed findings stay dismissed across scans; resolved findings reopen if the issue reappears.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Event Logging\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Every scan, hardening change, remediation, and significant event is logged to a dedicated table. Logs are filterable by severity and exportable as CSV.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Site Health Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Adds 6 security tests to the built-in Site Health screen: file editor, debug mode, XML-RPC, admin username, SSL, and overall security score.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Diagnostics\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Built-in performance profiling to identify slow queries, high memory usage, and resource bottlenecks related to security operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>10 authenticated endpoints under the \u003Ccode>aipatch-security-scanner\u002Fv1\u003C\u002Fcode> namespace for triggering scans, retrieving summaries, toggling hardening, exporting logs, and running performance diagnostics.\u003C\u002Fp>\n\u003Ch4>MCP Surface for AI Agents (23 Abilities)\u003C\u002Fh4>\n\u003Cp>Aipatch exposes 23 structured abilities via the WordPress Abilities API — making your site’s security surface fully accessible to external AI agents, coding assistants, and orchestration tools:\u003C\u002Fp>\n\u003Cp>By default, only \u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> is enabled. You can enable additional abilities from \u003Cstrong>Aipatch Security Scanner -> Settings -> MCP Abilities\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> — Run a full 36-check security audit with scored findings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-suspicious\u003C\u002Fstrong> — Quick heuristic scan for suspicious files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fstart-file-scan\u003C\u002Fstrong> — Launch an async multi-layer malware scan job\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fprocess-file-scan-batch\u003C\u002Fstrong> — Process next batch of files in a running scan\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-progress\u003C\u002Fstrong> — Check file scan progress\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-results\u003C\u002Fstrong> — Retrieve enriched scan results with family, reasons, layer scores\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-scan-summary\u003C\u002Fstrong> — Comprehensive latest scan summary with classification breakdown\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-suspicious-files\u003C\u002Fstrong> — List suspicious files from latest scan (no job_id needed)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Integrity & Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fverify-core-integrity\u003C\u002Fstrong> — Verify WP core files against official api.wordpress.org checksums\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-build\u003C\u002Fstrong> — Build or refresh the known-good file hash baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-diff\u003C\u002Fstrong> — Compare current filesystem against stored baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-stats\u003C\u002Fstrong> — Baseline statistics by origin type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-baseline-drift\u003C\u002Fstrong> — Combined baseline drift + core integrity report\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Findings & Monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-findings\u003C\u002Fstrong> — Query persistent findings with status\u002Fseverity\u002Fcategory filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-stats\u003C\u002Fstrong> — Aggregate finding statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-diff\u003C\u002Fstrong> — New and resolved findings since a point in time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-file-finding-detail\u003C\u002Fstrong> — Single finding with decoded metadata, layer scores, family\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fdismiss-finding\u003C\u002Fstrong> — Dismiss a finding as accepted risk\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Remediation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fapply-remediation\u003C\u002Fstrong> — Apply a security fix with rollback support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Frollback-remediation\u003C\u002Fstrong> — Undo a previously applied fix\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-remediations\u003C\u002Fstrong> — List remediation history with filters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Jobs & Status\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-jobs\u003C\u002Fstrong> — List scan\u002Faudit jobs with filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-async-job-status\u003C\u002Fstrong> — Check async job status and retrieve results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>20 abilities are read-only; only 3 (dismiss, apply-remediation, rollback) modify site state. All abilities include typed input\u002Foutput schemas, permission checks (\u003Ccode>manage_options\u003C\u002Fcode>), and structured error responses.\u003C\u002Fp>\n\u003Ch4>What Aipatch Does NOT Do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>It is NOT a firewall or WAF — it does not filter incoming traffic.\u003C\u002Fli>\n\u003Cli>It does NOT intercept frontend requests or affect page load performance.\u003C\u002Fli>\n\u003Cli>It does NOT phone home, require an account, or send data externally.\u003C\u002Fli>\n\u003Cli>It does NOT inject ads, upsells, or nag notices.\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress security scanner with 36 checks, malware scanning, core integrity verification, remediation, and 23 MCP abilities.",477,"2026-05-03T09:18:00.000Z","6.5",[18,19,49,22,50],"malware-scanner","vulnerability","https:\u002F\u002Fgithub.com\u002Festebanstifli\u002Faipatch-security-scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.2.0.2.zip",{"slug":54,"name":55,"version":56,"author":57,"author_profile":58,"description":59,"short_description":60,"active_installs":61,"downloaded":62,"rating":11,"num_ratings":11,"last_updated":63,"tested_up_to":64,"requires_at_least":65,"requires_php":66,"tags":67,"homepage":68,"download_link":69,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"steel-security","Steel Security & Hardening – Site Audit Tools","1.0.4","sweetwatermedia","https:\u002F\u002Fprofiles.wordpress.org\u002Fsweetwatermedia\u002F","\u003Cp>Steel Security & Hardening – Site Audit Tools focuses on practical security hygiene for WordPress administrators.\u003C\u002Fp>\n\u003Cp>The free plugin provides:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>on-demand security scans\u003C\u002Fli>\n\u003Cli>risk summaries grouped by severity and category\u003C\u002Fli>\n\u003Cli>checks for common WordPress hardening gaps\u003C\u002Fli>\n\u003Cli>checks for exposed root-level artifacts such as \u003Ccode>.env\u003C\u002Fcode>, SQL dumps, \u003Ccode>phpinfo\u003C\u002Fcode> files, and backup archives\u003C\u002Fli>\n\u003Cli>a quarantine vault for operator-reviewed file isolation\u003C\u002Fli>\n\u003Cli>uploads PHP execution blocking on supported server environments\u003C\u002Fli>\n\u003Cli>manual guidance when automatic server hardening is not safely supported\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is positioned as an auditing and hardening tool. It helps surface risk and apply selected preventive controls, but it does not promise malware removal, incident response, or complete server protection.\u003C\u002Fp>\n\u003Ch4>Included checks\u003C\u002Fh4>\n\u003Cp>The scan currently looks for items such as:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP error display exposure\u003C\u002Fli>\n\u003Cli>\u003Ccode>WP_DEBUG\u003C\u002Fcode> and \u003Ccode>debug.log\u003C\u002Fcode> exposure\u003C\u002Fli>\n\u003Cli>XML-RPC availability\u003C\u002Fli>\n\u003Cli>author and REST user enumeration exposure\u003C\u002Fli>\n\u003Cli>theme\u002Fplugin file editor availability\u003C\u002Fli>\n\u003Cli>WordPress generator meta output\u003C\u002Fli>\n\u003Cli>comments enabled by default\u003C\u002Fli>\n\u003Cli>uploads PHP execution hardening status\u003C\u002Fli>\n\u003Cli>root-level sensitive files and archives\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Server-aware behavior\u003C\u002Fh4>\n\u003Cp>This plugin only auto-applies server config changes where it can do so in a scoped and reversible way.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Apache and LiteSpeed: uploads PHP blocking is managed through a Steel Security-marked \u003Ccode>.htaccess\u003C\u002Fcode> block\u003C\u002Fli>\n\u003Cli>IIS: uploads PHP blocking is managed through a Steel Security-marked \u003Ccode>web.config\u003C\u002Fcode> section\u003C\u002Fli>\n\u003Cli>Nginx and unsupported environments: Steel Security provides manual guidance instead of claiming automatic protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro companion\u003C\u002Fh4>\n\u003Cp>This plugin can work with a separate Pro companion plugin that adds features such as scheduled scans, scan history, reports, and managed server-level controls such as directory listing protection and baseline security headers. The free plugin remains usable on its own.\u003C\u002Fp>\n","High-signal WordPress security auditing and hardening with practical site audit tools for administrators.",20,218,"2026-04-28T22:21:00.000Z","6.9.5","6.4","8.0",[18,19,21,22],"","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsteel-security.1.0.4.zip",{"slug":71,"name":72,"version":73,"author":74,"author_profile":75,"description":76,"short_description":77,"active_installs":11,"downloaded":78,"rating":11,"num_ratings":11,"last_updated":79,"tested_up_to":64,"requires_at_least":65,"requires_php":16,"tags":80,"homepage":68,"download_link":82,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"anonindo-security-advisor","Anonindo Security Advisor","1.1.1","Akshay Vasoya","https:\u002F\u002Fprofiles.wordpress.org\u002Fanonymoustech\u002F","\u003Cp>Anonindo Security Advisor helps site owners understand and improve their WordPress security posture without acting like a full firewall suite.\u003C\u002Fp>\n\u003Cp>The plugin follows a simple workflow:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Scan for common WordPress security issues and misconfigurations\u003C\u002Fli>\n\u003Cli>Explain what each issue means in beginner-friendly language\u003C\u002Fli>\n\u003Cli>Show practical guidance and safer best practices\u003C\u002Fli>\n\u003Cli>Offer safe auto-fix actions for selected hardening steps\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is designed to be lightweight, educational, and operationally safe.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Detects debug mode enabled in production\u003C\u002Fli>\n\u003Cli>Detects dashboard file editing enabled\u003C\u002Fli>\n\u003Cli>Detects XML-RPC exposure\u003C\u002Fli>\n\u003Cli>Detects weak file permissions on common paths\u003C\u002Fli>\n\u003Cli>Detects potentially exposed \u003Ccode>wp-config.php\u003C\u002Fcode> backup patterns\u003C\u002Fli>\n\u003Cli>Detects outdated plugins and themes\u003C\u002Fli>\n\u003Cli>Detects suspicious administrator account patterns\u003C\u002Fli>\n\u003Cli>Detects REST API user enumeration exposure\u003C\u002Fli>\n\u003Cli>Heuristically scans active theme and plugin PHP files for basic SQL injection and XSS risk patterns\u003C\u002Fli>\n\u003Cli>Scans selected database content for suspicious script-like patterns\u003C\u002Fli>\n\u003Cli>Provides a security score and prioritized recommendations\u003C\u002Fli>\n\u003Cli>Includes an activity log for meaningful security-related site events\u003C\u002Fli>\n\u003Cli>Supports safe auto-fixes for selected hardening improvements\u003C\u002Fli>\n\u003C\u002Ful>\n","Lightweight WordPress security coach for scanning risks, explaining issues clearly, and guiding safer site improvements.",143,"2026-05-14T11:13:00.000Z",[81,18,19,21,22],"admin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanonindo-security-advisor.1.1.1.zip",{"slug":84,"name":85,"version":86,"author":87,"author_profile":88,"description":89,"short_description":90,"active_installs":11,"downloaded":91,"rating":11,"num_ratings":11,"last_updated":92,"tested_up_to":14,"requires_at_least":15,"requires_php":68,"tags":93,"homepage":96,"download_link":97,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"apta-shield","Apta Shield","1.1.3","Lorenzo Romero","https:\u002F\u002Fprofiles.wordpress.org\u002Fmegapattern\u002F","\u003Cp>Apta Shield is a comprehensive, lightweight, and robust security engine designed to keep your WordPress site safe from modern threats.\u003C\u002Fp>\n\u003Cp>Key Features:\u003Cbr \u002F>\n* \u003Cstrong>Web Application Firewall (WAF)\u003C\u002Fstrong>: Active traffic inspection targeting SQLi, XSS, RCE, and LFI.\u003Cbr \u002F>\n* \u003Cstrong>Brute Force Protection\u003C\u002Fstrong>: Automatic detection and temporary lockout of suspicious IP addresses.\u003Cbr \u002F>\n* \u003Cstrong>URL Obfuscation\u003C\u002Fstrong>: Hide wp-login.php and wp-admin behind a custom secret slug.\u003Cbr \u002F>\n* \u003Cstrong>Security Hardening\u003C\u002Fstrong>: Disable XML-RPC, native code editors, author enumeration, and hide WordPress version.\u003Cbr \u002F>\n* \u003Cstrong>Malware & Integrity Scanner\u003C\u002Fstrong>: Compares local PHP files against official WordPress checksums and scans for heuristic malware signatures.\u003Cbr \u002F>\n* \u003Cstrong>Core Reinstallation\u003C\u002Fstrong>: Reinstall clean core files from WordPress.org in one click if corruption or modifications are found.\u003Cbr \u002F>\n* \u003Cstrong>Audit Log\u003C\u002Fstrong>: Keep track of user activity, login failures, profile updates, and settings modifications.\u003Cbr \u002F>\n* \u003Cstrong>Alert Notifications\u003C\u002Fstrong>: Immediate email alerts for critical security events.\u003C\u002Fp>\n","Premium WordPress security with WAF, brute force block, URL obfuscation, malware scanning, and core reinstallation.",197,"2026-06-24T22:43:00.000Z",[94,95,19,49,22],"brute-force","firewall","https:\u002F\u002Fgithub.com\u002Florenrocu\u002Fapta-shield","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fapta-shield.1.1.3.zip",{"slug":99,"name":100,"version":101,"author":102,"author_profile":103,"description":104,"short_description":105,"active_installs":11,"downloaded":106,"rating":11,"num_ratings":11,"last_updated":107,"tested_up_to":14,"requires_at_least":47,"requires_php":16,"tags":108,"homepage":109,"download_link":110,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"compatshield-site-auditor","CompatShield WP Site Auditor","0.1.0","CompatShield","https:\u002F\u002Fprofiles.wordpress.org\u002Fcompatshield\u002F","\u003Cp>CompatShield Site Auditor gives WordPress site owners and agencies a full picture of their site’s security posture in one scan. Unlike basic security plugins, it audits every layer — environment, plugins, themes, users, files, and database — and produces a single weighted score out of 100 with a per-category breakdown.\u003C\u002Fp>\n\u003Ch4>What it checks\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Environment & Hardening\u003C\u002Fstrong>\u003Cbr \u002F>\n* PHP version (flags below 8.2)\u003Cbr \u002F>\n* WordPress core version\u003Cbr \u002F>\n* WP_DEBUG exposure\u003Cbr \u002F>\n* XML-RPC enabled\u003Cbr \u002F>\n* wp-config.php file permissions\u003Cbr \u002F>\n* Database table prefix (flags default wp_)\u003Cbr \u002F>\n* Directory listing enabled\u003Cbr \u002F>\n* .htaccess integrity\u003Cbr \u002F>\n* HTTPS enforcement\u003Cbr \u002F>\n* readme.html \u002F license.txt version leakage\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Plugin & Theme Intelligence\u003C\u002Fstrong>\u003Cbr \u002F>\n* Lists all installed plugins (active and inactive)\u003Cbr \u002F>\n* Hits WordPress.org API for last updated date and install count\u003Cbr \u002F>\n* Flags plugins not updated in 6, 12, or 24 months\u003Cbr \u002F>\n* Flags plugins removed from the WordPress.org directory\u003Cbr \u002F>\n* Flags abandoned themes\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User & Access Audit\u003C\u002Fstrong>\u003Cbr \u002F>\n* Lists all administrator accounts\u003Cbr \u002F>\n* Flags the default “admin” username still in use\u003Cbr \u002F>\n* Detects dormant admin accounts (no login in 90+ days)\u003Cbr \u002F>\n* Checks for two-factor authentication plugins\u003Cbr \u002F>\n* Flags non-admin users with elevated capabilities (manage_options, install_plugins, etc.)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity & Backdoor Detection\u003C\u002Fstrong>\u003Cbr \u002F>\n* Hashes WordPress core files against official checksums\u003Cbr \u002F>\n* Flags modified core files\u003Cbr \u002F>\n* Scans theme and plugin files for dangerous PHP patterns: eval(base64_decode), gzinflate, str_rot13, shell_exec, exec, system, preg_replace with \u002Fe modifier\u003Cbr \u002F>\n* Flags PHP files inside \u002Fuploads\u002F directory\u003Cbr \u002F>\n* Flags .git directory exposure\u003Cbr \u002F>\n* Detects suspicious WordPress cron jobs\u003Cbr \u002F>\n* Flags PHP files modified in the last 7 or 30 days\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Database Security\u003C\u002Fstrong>\u003Cbr \u002F>\n* Checks for publicly accessible phpMyAdmin\u003Cbr \u002F>\n* Scans published posts for injected content (hidden links, base64 blobs, external iframes)\u003Cbr \u002F>\n* Scans wp_options autoloaded data for malicious PHP patterns and oversized entries\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Score\u003C\u002Fstrong>\u003Cbr \u002F>\n* Weighted score out of 100 (Environment 25, Plugins 20, Headers 20, Users 15, Database 10, Themes 10)\u003Cbr \u002F>\n* Per-category score breakdown with issue count\u003Cbr \u002F>\n* Historical score tracking with week-over-week change\u003C\u002Fp>\n\u003Ch4>Who is this for?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress site owners who want to know their security posture\u003C\u002Fli>\n\u003Cli>Freelancers and developers managing client sites\u003C\u002Fli>\n\u003Cli>Agencies auditing multiple client sites\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All of the scanning and reporting features described above are fully\u003Cbr \u002F>\nincluded in this free plugin — nothing here is time-limited or\u003Cbr \u002F>\nfeature-gated. CompatShield may offer separate, optional products in\u003Cbr \u002F>\nthe future (such as a multi-site management dashboard); any such\u003Cbr \u002F>\nproduct would be a distinct, separately-installed plugin or service,\u003Cbr \u002F>\nnot a restriction on this one.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>This plugin makes outbound requests to:\u003Cbr \u002F>\n* \u003Cstrong>WordPress.org API\u003C\u002Fstrong> (api.wordpress.org) — to retrieve plugin and theme metadata\u003Cbr \u002F>\n* \u003Cstrong>Your own site’s URL\u003C\u002Fstrong> — to check phpMyAdmin exposure and security headers\u003C\u002Fp>\n\u003Cp>No data is sent to third-party servers by the free version.\u003C\u002Fp>\n","Comprehensive WordPress security auditor. Scans for vulnerabilities, misconfigurations and threats — scored report with actionable fix steps.",91,"2026-06-26T10:10:00.000Z",[18,19,20,22,50],"https:\u002F\u002Fcompatshield.com\u002Fcompatshield-site-auditor","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcompatshield-site-auditor.zip",{"error":112,"url":113,"statusCode":114,"statusMessage":115,"message":115},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fshieldscope-site-security-scanner\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":117,"versions":118},2,[119,125],{"version":6,"download_url":24,"svn_tag_url":120,"released_at":26,"has_diff":121,"diff_files_changed":122,"diff_lines":26,"trac_diff_url":123,"vulnerabilities":124,"is_current":112},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fshieldscope-site-security-scanner\u002Ftags\u002F1.3.1\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fshieldscope-site-security-scanner%2Ftags%2F1.3.0&new_path=%2Fshieldscope-site-security-scanner%2Ftags%2F1.3.1",[],{"version":126,"download_url":127,"svn_tag_url":128,"released_at":26,"has_diff":121,"diff_files_changed":129,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":130,"is_current":121},"1.3.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshieldscope-site-security-scanner.1.3.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fshieldscope-site-security-scanner\u002Ftags\u002F1.3.0\u002F",[],[]]