[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqKEsg99YJwiF5fqGZ3eQN-EOY2z_d_JOxoemBDMWPUU":3,"$fquzJGr6ps1f5x7K5uG4sIgHC1itSzsZA7LJUt7qI-Vg":125,"$famHSUYyDqng0w10jzlh_M7_PVrNb2UGhOXRYKoOTNYk":130},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"traffic-origin-guard","Traffic Origin Guard","1.0.0","jasond727","https:\u002F\u002Fprofiles.wordpress.org\u002Fjasond727\u002F","\u003Cp>Traffic Origin Guard helps protect your origin server from direct traffic by requiring a secret header value on every request.\u003C\u002Fp>\n\u003Cp>Use case:\u003Cbr \u002F>\n– Your site is behind Cloudflare or another reverse proxy.\u003Cbr \u002F>\n– You want only proxy-originated requests to reach WordPress.\u003Cbr \u002F>\n– You want automatic Apache rule management.\u003C\u002Fp>\n\u003Cp>How it works:\u003Cbr \u002F>\n– You set one token in plugin settings.\u003Cbr \u002F>\n– The plugin writes Apache rules into .htaccess using a managed block.\u003Cbr \u002F>\n– Requests missing the expected X-Origin-Secret header are blocked with HTTP 403.\u003C\u002Fp>\n\u003Cp>Features:\u003Cbr \u002F>\n– Apache .htaccess rule writer with managed BEGIN\u002FEND markers.\u003Cbr \u002F>\n– Header validation status visibility on the settings page.\u003Cbr \u002F>\n– One-click token utilities in admin (generate, copy, and “Use as token”).\u003Cbr \u002F>\n– In-page Cloudflare setup guide with step-by-step instructions.\u003Cbr \u002F>\n– Lockout recovery instructions displayed directly in the settings page.\u003Cbr \u002F>\n– View details link on the Plugins list page.\u003Cbr \u002F>\n– Automatic cleanup on plugin deactivation and uninstall.\u003C\u002Fp>\n","Protect your WordPress origin by requiring a secret request header and blocking direct access with Apache .htaccess rules.",0,85,"2026-06-19T04:53:00.000Z","7.0.2","7.0","8.3",[18,19,20,21,22],"apache","cloudflare","hardening","headers","security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftraffic-origin-guard.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},1,30,94,"2026-08-29T03:11:58.908Z",[36,54,73,91,107],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":11,"num_ratings":11,"last_updated":46,"tested_up_to":14,"requires_at_least":47,"requires_php":48,"tags":49,"homepage":52,"download_link":53,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"security-hardener","Security Hardener","2.4.4","Marc Armengou","https:\u002F\u002Fprofiles.wordpress.org\u002Fmarc4\u002F","\u003Cp>\u003Cstrong>Security Hardener\u003C\u002Fstrong> applies WordPress security best practices based on the \u003Ca href=\"https:\u002F\u002Fdeveloper.wordpress.org\u002Fadvanced-administration\u002Fsecurity\u002Fhardening\u002F\" rel=\"nofollow ugc\">WordPress Advanced Administration \u002F Security \u002F Hardening\u003C\u002Fa> documentation and widely accepted hardening measures. It uses WordPress core functions and follows best practices without modifying core files.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>File Security:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Disable file editor in WordPress admin\u003Cbr \u002F>\n* Optionally disable all file modifications\u003C\u002Fp>\n\u003Cp>\u003Cstrong>XML-RPC Protection:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Disable XML-RPC completely\u003Cbr \u002F>\n* Remove pingback methods when XML-RPC is enabled\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Pingback Protection:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Disable self-pingbacks\u003Cbr \u002F>\n* Remove X-Pingback header\u003Cbr \u002F>\n* Block incoming pingbacks\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Enumeration Protection:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Block \u003Ccode>\u002F?author=N\u003C\u002Fcode> queries (returns 404)\u003Cbr \u002F>\n* Secure REST API user endpoints (require authentication)\u003Cbr \u002F>\n* Remove users from XML sitemaps\u003Cbr \u002F>\n* Prevent canonical redirects that expose usernames\u003Cbr \u002F>\n* Optionally block author feed pages (\u003Ccode>\u002Fauthor\u002Fusername\u002Ffeed\u002F\u003C\u002Fcode>)\u003Cbr \u002F>\n* Optionally anonymize the author name in oEmbed responses\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Security:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Generic error messages (no username\u002Fpassword hints)\u003Cbr \u002F>\n* Login honeypot\u003Cbr \u002F>\n* Block unsafe usernames\u003Cbr \u002F>\n* Application Passwords disabled by default\u003Cbr \u002F>\n* IP-based rate limiting with configurable thresholds\u003Cbr \u002F>\n* Security event logging\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Headers:\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Ccode>X-Frame-Options: SAMEORIGIN\u003C\u002Fcode> (clickjacking protection)\u003Cbr \u002F>\n* \u003Ccode>X-Content-Type-Options: nosniff\u003C\u002Fcode> (MIME sniffing protection)\u003Cbr \u002F>\n* \u003Ccode>Referrer-Policy: strict-origin-when-cross-origin\u003C\u002Fcode>\u003Cbr \u002F>\n* \u003Ccode>Permissions-Policy\u003C\u002Fcode> (restricts geolocation, microphone, camera)\u003Cbr \u002F>\n* Optional HSTS (HTTP Strict Transport Security) for HTTPS sites — max-age set to 1 year\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Additional Hardening:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Hide WordPress version (meta generator tag and asset query strings)\u003Cbr \u002F>\n* Remove obsolete wp_head items (RSD, WLW manifest, shortlink, emoji scripts)\u003Cbr \u002F>\n* System Status — monitors file permissions, WP_DEBUG, user registration, PHP version, administrator accounts, and database version\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>⚠️ \u003Cstrong>Important:\u003C\u002Fstrong> Always test security settings in a staging environment first. Some features may affect third-party integrations or plugins.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong> This plugin does not send data to external services and does not create custom database tables. It stores plugin settings and a security event log in the WordPress options table, and uses transients for temporary login attempt tracking. All data is preserved on uninstall by default and only deleted if the “Delete all data on uninstall” option is explicitly enabled.\u003C\u002Fp>\n","Basic hardening: secure headers, login honeypot, user enumeration blocking, generic login errors, rate limiting, and more.",200,1779,"2026-06-13T18:25:00.000Z","6.9","8.2",[50,20,21,51,22],"brute-force","login-protection","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsecurity-hardener\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecurity-hardener.2.4.4.zip",{"slug":55,"name":56,"version":57,"author":58,"author_profile":59,"description":60,"short_description":61,"active_installs":25,"downloaded":62,"rating":63,"num_ratings":64,"last_updated":65,"tested_up_to":66,"requires_at_least":67,"requires_php":68,"tags":69,"homepage":71,"download_link":72,"security_score":12,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"secure-http-headers","Secure HTTP Headers","1.0","shasha310","https:\u002F\u002Fprofiles.wordpress.org\u002Fshasha310\u002F","\u003Cp>Harden your web applications.\u003C\u002Fp>\n\u003Cp>HTTP header fields are components of the header section of request and response messages. The headers define the operating parameters of an HTTP transaction.\u003C\u002Fp>\n\u003Cp>Securing HTTP headers will improve the resilience of your web application against many common attacks including those that are on the OWASP top 10 list.\u003C\u002Fp>\n\u003Cp>Securing headers can also improve your SEO rank and in addition to preventing websites from being marked as dangerous by browsers and antivirus applications.\u003C\u002Fp>\n\u003Cp>Protect sensitive user information and be compliant with privacy regulations. Defend users from stealing private data by protecting website cookies. Use the proper directive such as “secure”, “httponly” and “samesite”, all of those will be applied automatically by “Secure HTTP Headers” plugin.\u003C\u002Fp>\n\u003Cp>Secure HTTP Headers will automatically analyze any website and will build up secure headers directives, by the latest best practice.\u003C\u002Fp>\n\u003Cp>In addition, Secure HTTP Headers offers fully configurable options, apply or skip any header directive as needed.\u003C\u002Fp>\n\u003Cp>Install and activate Secure HTTP Headers with full confidence, the deactivation of this plugin will return your website header directives to their original state.\u003C\u002Fp>\n\u003Ch3>Main plugin functionality\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\n\u003Cp>HTTP Strict Transport Security – helps to protect websites against man-in-the-middle attacks and cookie hijacking\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>X-Frame-Options – helps to protect users against ClickJacking attacks\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>X-Content-Type-Options  – helps to prevent the browser from MIME-sniffing\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Referrer-Policy – helps to control how much referrer information should be included with requests\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Clear-Site-Data – helps to ensure that data is deleted from the browser if the user logs out\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>X-Download-Options – helps to control how IE 8 will handle downloaded HTML files\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Access-Control-Allow-Origin – helps to ensure whether the response can be shared with requesting code from the given origin\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Cross-Origin-Embedder-Policy – helps to prevent a document from loading any cross-origin resources that don’t explicitly grant the document permission\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Permissions-Policy – helps to allow and deny the use of browser features in its own frame, and in content within any iframe elements in the document\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Cross-Origin-Opener-Policy – helps to protect websites against a set of cross-origin attacks dubbed XS-Leaks\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Cross-Origin-Resource-Policy – helps to protect websites against speculative side-channel attacks, like Spectre, as well as Cross-Site Script Inclusion attacks\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>X-Permitted-Cross-Domain-Policies – helps to control how cross-domain requests from Flash and PDF documents are handled\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Cookie Http-Only flag – helps to protect websites against Cross-Site Scripting, or XSS attacks\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Cookie Secure flag – helps to ensure that cookie is sent over a secure connection\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Cookie Samesite Lax flag – helps to protect websites against CSRF and XSSI attacks\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Expect-CT – helps to prevent the use of misissued certificates for a website. Note: The Expect-CT will likely become obsolete in June 2021\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>What are the optional extras?\u003C\u002Fh3>\n\u003Cp>Magnisec is offering “Secure HTTP Headers enhanced”\u003C\u002Fp>\n\u003Cp>A plugin that contains, in addition, an engine that watches and builds in any website changes a CSP – Content Security Policy that is best practice and recommended by all professional securities experts, that mitigate XSS -Cross site Scripting, one of the most common and destructive attacks.\u003C\u002Fp>\n\u003Cp>Price: 50$ \u002Fyear for a domain.\u003C\u002Fp>\n\u003Cp>More details and installation \u003Ca href=\"https:\u002F\u002Fmagnisec.com\" rel=\"nofollow ugc\">here\u003C\u002Fa>\u003C\u002Fp>\n","Secure HTTP headers - Essential, and easy.",2741,60,2,"2021-04-13T08:27:00.000Z","5.7.15","5.3","7.2",[70,20,21,22],"cookies","https:\u002F\u002Fmagnisec.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-http-headers.1.0.zip",{"slug":74,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":81,"downloaded":82,"rating":25,"num_ratings":64,"last_updated":83,"tested_up_to":84,"requires_at_least":85,"requires_php":86,"tags":87,"homepage":23,"download_link":90,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"basecloud-security-manager","BaseCloud Security Manager","1.0.26","BaseCloud","https:\u002F\u002Fprofiles.wordpress.org\u002Fbasecloud\u002F","\u003Cp>\u003Cstrong>Transform your WordPress site into a security fortress in under 2 minutes.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>BaseCloud Security Manager delivers enterprise-level security protection through advanced HTTP security headers – the same technology used by Fortune 500 companies to protect their websites. No technical expertise required.\u003C\u002Fp>\n\u003Cp>🎯 \u003Cstrong>Why Security Headers Matter:\u003C\u002Fstrong>\u003Cbr \u002F>\nSecurity headers are your website’s first line of defense, instructing browsers on how to handle your content safely. Without them, your site is vulnerable to:\u003Cbr \u002F>\n• Cross-Site Scripting (XSS) attacks – \u003Cstrong>87% of websites are vulnerable\u003C\u002Fstrong>\u003Cbr \u002F>\n• Clickjacking attacks that steal user credentials\u003Cbr \u002F>\n• Data theft through insecure connections\u003Cbr \u002F>\n• Privacy violations through referrer leaks\u003Cbr \u002F>\n• Malicious code injection\u003C\u002Fp>\n\u003Cp>✨ \u003Cstrong>What Makes BaseCloud Different:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>🚀 \u003Cstrong>One-Click Protection\u003C\u002Fstrong> – Enable military-grade security with a single click\u003Cbr \u002F>\n🔒 \u003Cstrong>Zero Configuration Required\u003C\u002Fstrong> – Smart defaults protect you instantly\u003Cbr \u002F>\n⚡ \u003Cstrong>Lightning Fast\u003C\u002Fstrong> – No performance impact on your site\u003Cbr \u002F>\n🎛️ \u003Cstrong>Full Control\u003C\u002Fstrong> – Advanced users can customize every setting\u003Cbr \u002F>\n🛠️ \u003Cstrong>Developer Friendly\u003C\u002Fstrong> – Clean, well-documented code\u003Cbr \u002F>\n🔧 \u003Cstrong>No Server Changes\u003C\u002Fstrong> – Works on any hosting provider\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🛡️ Complete Security Arsenal:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🎯 Master Security Switch\u003C\u002Fstrong>\u003Cbr \u002F>\nEnable all protections instantly – perfect for non-technical users who want maximum security without complexity.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔐 Force SSL\u002FHTTPS Everywhere\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically redirect all HTTP traffic to HTTPS, ensuring all data transmission is encrypted. Protects against man-in-the-middle attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🛡️ Content Security Policy (CSP)\u003C\u002Fstrong>\u003Cbr \u002F>\nThe gold standard of XSS protection. Controls exactly which scripts, styles, and resources can run on your site. Includes smart defaults that work with 99% of WordPress themes and plugins.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔒 HTTP Strict Transport Security (HSTS)\u003C\u002Fstrong>\u003Cbr \u002F>\nForces browsers to communicate exclusively over HTTPS, preventing SSL stripping attacks. Includes preload support for maximum protection.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🕵️ Advanced Referrer Policy\u003C\u002Fstrong>\u003Cbr \u002F>\nProtects user privacy by controlling what information is shared when visitors click links, preventing data leaks to third parties.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🎤 Permissions Policy (Feature Policy)\u003C\u002Fstrong>\u003Cbr \u002F>\nBlock unauthorized access to sensitive browser features like camera, microphone, geolocation, and payment APIs – preventing malicious sites from accessing these features.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🍪 Secure Cookie Protection\u003C\u002Fstrong>\u003Cbr \u002F>\nAutomatically applies HttpOnly and Secure flags to session cookies, preventing JavaScript access and ensuring cookies are only sent over HTTPS.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>👻 Server Fingerprinting Protection\u003C\u002Fstrong>\u003Cbr \u002F>\nRemoves server signatures and version information that hackers use to identify vulnerabilities in your hosting setup.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⚡ Essential Security Headers Included:\u003C\u002Fstrong>\u003Cbr \u002F>\n• X-Frame-Options: SAMEORIGIN (prevents clickjacking)\u003Cbr \u002F>\n• X-Content-Type-Options: nosniff (prevents MIME-type confusion attacks)\u003Cbr \u002F>\n• X-XSS-Protection: 1; mode=block (legacy XSS protection for older browsers)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>💼 Perfect For:\u003C\u002Fstrong>\u003Cbr \u002F>\n• Business owners who want enterprise security without technical complexity\u003Cbr \u002F>\n• Developers building secure WordPress applications\u003Cbr \u002F>\n• Agencies managing multiple client sites\u003Cbr \u002F>\n• Anyone serious about website security\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🎯 Use Cases:\u003C\u002Fstrong>\u003Cbr \u002F>\n• E-commerce sites handling sensitive customer data\u003Cbr \u002F>\n• Membership sites with user logins\u003Cbr \u002F>\n• Business websites with contact forms\u003Cbr \u002F>\n• Blogs that want to protect visitor privacy\u003Cbr \u002F>\n• Development sites that need security during testing\u003C\u002Fp>\n\u003Cp>BaseCloud Security Manager is lightweight, efficient, and designed to integrate seamlessly into your WordPress admin experience without clutter or intrusive advertising.\u003C\u002Fp>\n\u003Ch3>Additional Information\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>🎯 Why Choose BaseCloud Security Manager?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>✅ \u003Cstrong>Instant Protection\u003C\u002Fstrong> – Works immediately after activation\u003Cbr \u002F>\n✅ \u003Cstrong>Zero Learning Curve\u003C\u002Fstrong> – No technical knowledge required\u003Cbr \u002F>\n✅ \u003Cstrong>Enterprise Grade\u003C\u002Fstrong> – Same technology used by Fortune 500 companies\u003Cbr \u002F>\n✅ \u003Cstrong>Fully Customizable\u003C\u002Fstrong> – Advanced users have complete control\u003Cbr \u002F>\n✅ \u003Cstrong>Regular Updates\u003C\u002Fstrong> – Stay protected against emerging threats\u003Cbr \u002F>\n✅ \u003Cstrong>Expert Support\u003C\u002Fstrong> – Professional team ready to help\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔗 Useful Links:\u003C\u002Fstrong>\u003Cbr \u002F>\n• \u003Cstrong>Documentation:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwww.basecloudglobal.com\u002Fsecurity-manager-docs\" rel=\"nofollow ugc\">BaseCloud Security Docs\u003C\u002Fa>\u003Cbr \u002F>\n• \u003Cstrong>Support:\u003C\u002Fstrong> support@basecloudglobal.com\u003Cbr \u002F>\n• \u003Cstrong>Security Testing:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fobservatory.mozilla.org\" rel=\"nofollow ugc\">Mozilla Observatory\u003C\u002Fa>\u003Cbr \u002F>\n• \u003Cstrong>Header Verification:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fsecurityheaders.com\" rel=\"nofollow ugc\">SecurityHeaders.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🤝 Join Our Community:\u003C\u002Fstrong>\u003Cbr \u002F>\nConnect with other security-conscious WordPress users, get tips, and stay updated on the latest security trends.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⭐ Love BaseCloud Security Manager?\u003C\u002Fstrong>\u003Cbr \u002F>\nHelp others discover enterprise-grade security by leaving a review. Your feedback helps us improve and helps other users make informed decisions about their website security.\u003C\u002Fp>\n\u003Cp>\u003Cem>Made with ❤️ by the BaseCloud Team – Securing WordPress sites worldwide since 2024\u003C\u002Fem>\u003C\u002Fp>\n","🛡️ Enterprise-grade WordPress security made simple. Implement military-standard HTTP security headers with zero technical knowledge required.",20,1193,"2026-02-25T14:45:00.000Z","6.8.6","5.8","7.4",[20,21,88,22,89],"hsts","xss","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbasecloud-security-manager.1.0.26.zip",{"slug":92,"name":93,"version":94,"author":95,"author_profile":96,"description":97,"short_description":98,"active_installs":11,"downloaded":99,"rating":11,"num_ratings":11,"last_updated":100,"tested_up_to":101,"requires_at_least":102,"requires_php":86,"tags":103,"homepage":23,"download_link":105,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":106},"headershield","HeaderShield","1.0.14","Vishwa","https:\u002F\u002Fprofiles.wordpress.org\u002Fsbvi1122\u002F","\u003Cp>HeaderShield adds a conservative set of security headers that improve browser protection without breaking most sites. It also provides optional strict cross-origin protections for sites that are ready for them.\u003C\u002Fp>\n\u003Cp>Default headers include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>X-Frame-Options\u003C\u002Fli>\n\u003Cli>X-Content-Type-Options\u003C\u002Fli>\n\u003Cli>X-XSS-Protection (legacy)\u003C\u002Fli>\n\u003Cli>Referrer-Policy\u003C\u002Fli>\n\u003Cli>Permissions-Policy\u003C\u002Fli>\n\u003Cli>Content-Security-Policy (upgrade-insecure-requests)\u003C\u002Fli>\n\u003Cli>Strict-Transport-Security (HTTPS only)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Strict Mode can additionally enable COEP, COOP, and CORP for stronger isolation, but may break third‑party scripts or embeds. Use with care and test on staging first.\u003C\u002Fp>\n\u003Ch4>Source code for third-party assets\u003C\u002Fh4>\n\u003Cp>The admin UI uses SlimSelect for the multi-select dropdown. Human-readable source is included in the plugin:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>JavaScript: \u003Ccode>assets\u002Fjs\u002Fslimselect.js\u003C\u002Fcode> (minified build: \u003Ccode>assets\u002Fjs\u002Fslimselect.min.js\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>CSS: \u003Ccode>assets\u002Fcss\u002Fslimselect.css\u003C\u002Fcode> (minified build: \u003Ccode>assets\u002Fcss\u002Fslimselect.min.css\u003C\u002Fcode>)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Upstream project: https:\u002F\u002Fgithub.com\u002Fbrianvoe\u002Fslim-select (MIT). This plugin does not use a custom build process; the included files are from the published release.\u003C\u002Fp>\n","Add safe, modern HTTP security headers with optional strict cross-origin protections and a simple admin UI.",84,"2026-03-20T10:25:00.000Z","6.9.4","5.0",[104,20,21,88,22],"csp","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fheadershield.1.0.14.zip","2026-04-06T09:54:40.288Z",{"slug":108,"name":109,"version":110,"author":111,"author_profile":112,"description":113,"short_description":114,"active_installs":11,"downloaded":115,"rating":11,"num_ratings":11,"last_updated":116,"tested_up_to":14,"requires_at_least":117,"requires_php":118,"tags":119,"homepage":123,"download_link":124,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"zen-site-security","Zen Site Security","1.13.1","Guram Zhgamadze","https:\u002F\u002Fprofiles.wordpress.org\u002Fguramzhgamadze\u002F","\u003Cp>Zen Site Security migrates your WordPress site to HTTPS safely and keeps it there.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-click activation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The plugin first verifies that a valid SSL certificate is actually installed for your domain — activation is blocked until one is found, so you can never lock yourself out by accident. Activation then:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>switches your WordPress Address and Site Address to https,\u003C\u002Fli>\n\u003Cli>301-redirects every HTTP request (pages, REST API) to HTTPS,\u003C\u002Fli>\n\u003Cli>fixes mixed content on your pages on the fly.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>HTTP to HTTPS redirect, your way\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>PHP 301 redirect\u003C\u002Fstrong> (default) — works on every server and disappears automatically when the plugin is deactivated.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>.htaccess 301 redirect\u003C\u002Fstrong> (advanced, Apache\u002FLiteSpeed) — redirects at server level before WordPress loads, with the PHP redirect kept as a safety net. The rules are placed above the WordPress block, wrapped in clear markers, and removed on deactivation.\u003C\u002Fli>\n\u003Cli>On nginx the plugin shows you the exact server snippet to copy instead.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Mixed content fixer\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Insecure \u003Ccode>http:\u002F\u002F\u003C\u002Fcode> references to your own site (including www\u002Fnon-www variants and JSON-escaped URLs), plus common \u003Ccode>src\u003C\u002Fcode>, \u003Ccode>href\u003C\u002Fcode>, \u003Ccode>action\u003C\u002Fcode>, \u003Ccode>og:image\u003C\u002Fcode>, \u003Ccode>url()\u003C\u002Fcode> and \u003Ccode>srcset\u003C\u002Fcode> patterns, are rewritten to \u003Ccode>https:\u002F\u002F\u003C\u002Fcode> just before the page is sent to the browser. Feeds, sitemaps and JSON responses are left untouched. An optional fixer for the WordPress admin is available too.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Certificate monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The dashboard shows the certificate issuer, expiry date, and whether it covers your domain (wildcards included). When SSL is active and the certificate is about to expire (or already has), administrators see a warning.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>HTTP Strict Transport Security (HSTS) — opt-in\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Once your site runs reliably on https, you can send the \u003Ccode>Strict-Transport-Security\u003C\u002Fcode> header. Max-age starts at one day for safe testing; the preload-eligible configuration (1 year + includeSubDomains) requires explicit opt-in, because it is hard to undo.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security hardening — XSS, CSRF, and injection defense in depth (all opt-in)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security headers\u003C\u002Fstrong>: \u003Ccode>X-Content-Type-Options: nosniff\u003C\u002Fcode>, \u003Ccode>X-Frame-Options\u003C\u002Fcode> (clickjacking), \u003Ccode>Referrer-Policy\u003C\u002Fcode> (keeps tokens out of cross-site referrers), a conservative \u003Ccode>Permissions-Policy\u003C\u002Fcode>, and CSP \u003Ccode>upgrade-insecure-requests\u003C\u002Fcode>. Every header stands down automatically if another plugin already sends it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SameSite login cookies\u003C\u002Fstrong>: the WordPress auth cookies are re-issued with an explicit \u003Ccode>SameSite=Lax\u003C\u002Fcode> attribute, so CSRF protection no longer depends on browser defaults — a second layer next to WordPress nonces.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Attack-surface reduction\u003C\u002Fstrong>: disable the wp-admin file editors (\u003Ccode>DISALLOW_FILE_EDIT\u003C\u002Fcode>), block PHP execution in the uploads directory (an uploaded webshell becomes a dead file), deny web access to sensitive files (logs, database dumps, backup copies, wp-config variants), disable directory listings, disable XML-RPC and pingbacks, and hide the WordPress version and PHP \u003Ccode>X-Powered-By\u003C\u002Fcode> header.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Built to pair with Zen Login & Authentication\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The two Zen plugins split the work cleanly: Zen Login & Authentication owns identity security (login forms, brute-force protection, 2FA, passkeys, user enumeration, XML-RPC), while this plugin owns transport and platform security (HTTPS, headers, cookies, file-system attack surface). When both are active, each control has exactly one owner — for example, this plugin’s XML-RPC switch automatically defers to its sibling. Each plugin is fully standalone; neither requires the other.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Web cache deception protection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>When a CDN or page cache sits in front of your site, an attacker can try to trick it into storing a victim’s private page under a URL they control (for example by appending a fake \u003Ccode>.css\u003C\u002Fcode> to an account page). This plugin marks logged-in pages and authenticated REST responses as \u003Ccode>Cache-Control: no-store, private\u003C\u002Fcode>, and refuses to let a dynamic response be cached under a static-looking URL — the origin-side defense recommended by OWASP and PortSwigger.\u003C\u002Fp>\n\u003Cp>Honest scope: these features reduce attack surface and blunt common exploit paths. They are defense in depth — they cannot fix an injection, XSS or XXE vulnerability inside another plugin’s or theme’s code, and no plugin can. Server-side injection (SQL\u002FNoSQL), XML external entity (XXE) and web LLM\u002Fprompt-injection flaws are fixed in the application code that has the bug; keep WordPress, plugins and themes updated, and use security headers here as a second layer.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Locked out? Built-in emergency recovery\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If anything goes wrong, add one line to wp-config.php:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>define( 'ZENSS_DISABLE_SSL', true );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>On the next visit the plugin reverts your site to http, disables the redirect, and removes its .htaccess rules.\u003C\u002Fp>\n","SSL in one click plus security hardening: 301 HTTPS redirect, mixed content fixer, HSTS, security headers, SameSite cookies, attack-surface hardening.",32,"2026-07-20T16:54:00.000Z","6.5","8.0",[20,88,120,121,122],"https","security-headers","ssl","https:\u002F\u002Fgithub.com\u002Fguramzhgamadze\u002Fzen-site-security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fzen-site-security.1.13.1.zip",{"error":126,"url":127,"statusCode":128,"statusMessage":129,"message":129},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Ftraffic-origin-guard\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":31,"versions":131},[132],{"version":6,"download_url":24,"svn_tag_url":133,"released_at":26,"has_diff":134,"diff_files_changed":135,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":136,"is_current":126},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftraffic-origin-guard\u002Ftags\u002F1.0.0\u002F",false,[],[]]