[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzlqZ8nYA-GkI-LrJb5M9I-ng6ZgBJdtF3itsUBR1skg":3,"$fVb-rOd_fgwAJ4EDFokyadTrVt_x5gR0QZJYi1Zz1Bc8":122,"$f56U7q6E8URuMZSbq8UZCF9Udj7ORFQjyH0U6Yaglbf4":127},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":36,"analysis":26,"fingerprints":26},"treder-security-snapshot","Treder Security Snapshot","1.0.0","Ben Treder","https:\u002F\u002Fprofiles.wordpress.org\u002Fbdtreder\u002F","\u003Cp>Treder Security Snapshot gives WordPress site owners a simple local security health report.\u003C\u002Fp>\n\u003Cp>It is not a firewall, malware removal tool, or all-in-one security suite. It focuses on clear visibility, practical recommendations, and easy reporting.\u003C\u002Fp>\n\u003Cp>The plugin checks common WordPress security basics and gives you a security score from 0 to 100.\u003C\u002Fp>\n\u003Ch4>Included Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Security score from 0 to 100\u003C\u002Fli>\n\u003Cli>Dashboard tab\u003C\u002Fli>\n\u003Cli>Detailed audit tab\u003C\u002Fli>\n\u003Cli>Scan history tab\u003C\u002Fli>\n\u003Cli>WordPress dashboard widget\u003C\u002Fli>\n\u003Cli>Beginner-friendly explanations\u003C\u002Fli>\n\u003Cli>Suggested fixes\u003C\u002Fli>\n\u003Cli>Local scan history\u003C\u002Fli>\n\u003Cli>Local HTML report download\u003C\u002Fli>\n\u003Cli>Email latest report to a chosen address\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security Checks\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress core update status\u003C\u002Fli>\n\u003Cli>Plugin update status\u003C\u002Fli>\n\u003Cli>Theme update status\u003C\u002Fli>\n\u003Cli>Default admin usernames\u003C\u002Fli>\n\u003Cli>User enumeration risk\u003C\u002Fli>\n\u003Cli>XML-RPC status\u003C\u002Fli>\n\u003Cli>File editing status\u003C\u002Fli>\n\u003Cli>Debug mode status\u003C\u002Fli>\n\u003Cli>Directory browsing indicators\u003C\u002Fli>\n\u003Cli>HTTPS and SSL status\u003C\u002Fli>\n\u003Cli>Database prefix check\u003C\u002Fli>\n\u003Cli>WordPress version visibility\u003C\u002Fli>\n\u003Cli>Public registration status\u003C\u002Fli>\n\u003Cli>Inactive plugins\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Separate Pro Companion\u003C\u002Fh4>\n\u003Cp>A separate Pro companion plugin is available from the author’s website for users who want additional tools such as advanced checks, scheduled reports, file integrity monitoring, white-label reporting, and AI-assisted fix plans.\u003C\u002Fp>\n\u003Cp>The WordPress.org plugin includes all functionality described in this readme.\u003C\u002Fp>\n","A lightweight WordPress security health report with a simple score, clear findings, local reports, and beginner-friendly suggested fixes.",0,81,"2026-06-15T13:32:00.000Z","7.0.2","6.0","7.4",[18,19,20,21,22],"admin","audit","hardening","report","security","https:\u002F\u002Fbentreder.com\u002Fplugins\u002Ftreder-security-snapshot","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftreder-security-snapshot.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},"bdtreder",6,30,94,"2026-08-25T02:27:37.635Z",[37,53,69,85,109],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":11,"downloaded":45,"rating":11,"num_ratings":11,"last_updated":46,"tested_up_to":47,"requires_at_least":48,"requires_php":16,"tags":49,"homepage":51,"download_link":52,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"anonindo-security-advisor","Anonindo Security Advisor","1.1.1","Akshay Vasoya","https:\u002F\u002Fprofiles.wordpress.org\u002Fanonymoustech\u002F","\u003Cp>Anonindo Security Advisor helps site owners understand and improve their WordPress security posture without acting like a full firewall suite.\u003C\u002Fp>\n\u003Cp>The plugin follows a simple workflow:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Scan for common WordPress security issues and misconfigurations\u003C\u002Fli>\n\u003Cli>Explain what each issue means in beginner-friendly language\u003C\u002Fli>\n\u003Cli>Show practical guidance and safer best practices\u003C\u002Fli>\n\u003Cli>Offer safe auto-fix actions for selected hardening steps\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is designed to be lightweight, educational, and operationally safe.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Detects debug mode enabled in production\u003C\u002Fli>\n\u003Cli>Detects dashboard file editing enabled\u003C\u002Fli>\n\u003Cli>Detects XML-RPC exposure\u003C\u002Fli>\n\u003Cli>Detects weak file permissions on common paths\u003C\u002Fli>\n\u003Cli>Detects potentially exposed \u003Ccode>wp-config.php\u003C\u002Fcode> backup patterns\u003C\u002Fli>\n\u003Cli>Detects outdated plugins and themes\u003C\u002Fli>\n\u003Cli>Detects suspicious administrator account patterns\u003C\u002Fli>\n\u003Cli>Detects REST API user enumeration exposure\u003C\u002Fli>\n\u003Cli>Heuristically scans active theme and plugin PHP files for basic SQL injection and XSS risk patterns\u003C\u002Fli>\n\u003Cli>Scans selected database content for suspicious script-like patterns\u003C\u002Fli>\n\u003Cli>Provides a security score and prioritized recommendations\u003C\u002Fli>\n\u003Cli>Includes an activity log for meaningful security-related site events\u003C\u002Fli>\n\u003Cli>Supports safe auto-fixes for selected hardening improvements\u003C\u002Fli>\n\u003C\u002Ful>\n","Lightweight WordPress security coach for scanning risks, explaining issues clearly, and guiding safer site improvements.",143,"2026-05-14T11:13:00.000Z","6.9.5","6.4",[18,19,20,50,22],"scanner","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanonindo-security-advisor.1.1.1.zip",{"slug":54,"name":55,"version":56,"author":57,"author_profile":58,"description":59,"short_description":60,"active_installs":25,"downloaded":61,"rating":11,"num_ratings":11,"last_updated":62,"tested_up_to":14,"requires_at_least":63,"requires_php":16,"tags":64,"homepage":67,"download_link":68,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"aipatch-security-scanner","Aipatch Security Scanner","2.0.2","Esteban","https:\u002F\u002Fprofiles.wordpress.org\u002Festebandezafra\u002F","\u003Cp>\u003Cstrong>Aipatch Security Scanner\u003C\u002Fstrong> is a modular security audit engine built for site owners, developers, and AI-powered agents who need deep visibility into WordPress security posture — without the bloat of all-in-one security suites.\u003C\u002Fp>\n\u003Ch4>Why Aipatch Security Scanner?\u003C\u002Fh4>\n\u003Cp>Most WordPress security plugins are either too simple to be useful or too heavy to be practical. Aipatch takes a different approach:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Audit-first architecture.\u003C\u002Fstrong> Every check is a standalone, testable module that returns structured findings with severity, confidence, evidence, and fingerprints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built for automation.\u003C\u002Fstrong> 23 MCP abilities expose the full audit, scanning, and remediation surface to external AI agents — making Aipatch the first WordPress security plugin designed for agentic workflows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero external dependencies.\u003C\u002Fstrong> Everything runs locally. No accounts, no cloud services, no API keys required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reversible by design.\u003C\u002Fstrong> Every automated remediation stores rollback data so you can undo any change with one click.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Core Capabilities\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>36-Point Security Audit\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Aipatch runs 36 automated checks across 8 categories — core, plugins, themes, users, configuration, server, access control, and malware surface:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Outdated WordPress core, plugins, and themes\u003C\u002Fli>\n\u003Cli>Default admin username, excessive admin accounts, inactive admin users, user ID 1 exposure\u003C\u002Fli>\n\u003Cli>XML-RPC, file editor, debug mode, debug log, REST API exposure, directory listing\u003C\u002Fli>\n\u003Cli>PHP version, HTTPS, file permissions, security headers (X-Frame-Options, CSP, etc.)\u003C\u002Fli>\n\u003Cli>Database prefix, sensitive files, PHP execution in uploads, auto-update configuration\u003C\u002Fli>\n\u003Cli>Salt key strength, cron health, cookie security flags, CORS, application passwords\u003C\u002Fli>\n\u003Cli>Exposed backup files, phpinfo files, uploads directory indexing, default login URL\u003C\u002Fli>\n\u003Cli>Database credential security, file installation permissions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Every finding includes a severity (critical \u002F high \u002F medium \u002F low \u002F info), confidence score, human-readable explanation, and actionable recommendation.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Weighted Security Score (0–100)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A logarithmic scoring engine computes an overall security score and per-area breakdown across six risk dimensions: software, access control, configuration, infrastructure, malware surface, and vulnerability exposure. Severity weights and confidence multipliers ensure the score reflects actual risk, not just issue count.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Multi-Layer Malware File Scanner\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A three-layer file scanner (content 55%, context 25%, integrity 20%) with 27 detection signatures, Shannon entropy analysis, and malware family classification detects:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Code execution patterns: eval(), assert(), create_function(), preg_replace \u002Fe\u003C\u002Fli>\n\u003Cli>System command functions: shell_exec, exec, passthru, backtick operators\u003C\u002Fli>\n\u003Cli>Obfuscation techniques: base64 encoding, hex encoding, str_rot13, gzinflate chains, chr() concatenation, variable variables, suspiciously long lines\u003C\u002Fli>\n\u003Cli>Network\u002Fexfiltration: cURL execution, fsockopen, remote file_get_contents\u003C\u002Fli>\n\u003Cli>Known backdoor signatures: c99, r57, WSO, b374k, weevely, FilesMan\u003C\u002Fli>\n\u003Cli>WordPress-specific threats: unauthorized admin creation, critical option injection, security function removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Scanning runs in batches via an async job system with configurable batch sizes — safe for shared hosting.\u003C\u002Fp>\n\u003Cp>Files are classified into 11 malware families (web shell, obfuscated loader, dropper, persistence backdoor, cloaked PHP, code injector, and more) with confidence scores and remediation hints.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Core Integrity Verification\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Verifies every core file against official checksums from api.wordpress.org. Detects modified core files (checksum mismatch), missing core files, and unexpected files planted in wp-admin\u002F or wp-includes\u002F. Core tampering findings are automatically escalated to critical severity with zero false-positive likelihood.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>File Integrity Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Build a known-good hash baseline of all PHP files in your installation. Diff against it at any time to detect modified, deleted, or newly added files. Origin detection distinguishes core, plugin, theme, and upload files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Vulnerability Intelligence\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A local knowledge base of known plugin, theme, and core vulnerabilities with a database-backed caching layer for fast lookups. Provider architecture allows extending with external feeds.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One-Click Remediation with Rollback\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Apply fixes directly from findings — change WordPress options, delete suspicious files, rename files, patch file contents, or add .htaccess rules. Every automated action stores a full rollback payload so you can reverse any change. Manual remediations can be logged for audit trails.\u003C\u002Fp>\n\u003Cp>Six supported action types: \u003Ccode>wp_option\u003C\u002Fcode>, \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>rename_file\u003C\u002Fcode>, \u003Ccode>file_patch\u003C\u002Fcode>, \u003Ccode>htaccess_rule\u003C\u002Fcode>, \u003Ccode>manual\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hardening Module\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Five toggleable hardening rules with clear explanations and compatibility warnings:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable XML-RPC — blocks external XML-RPC requests and removes X-Pingback header\u003C\u002Fli>\n\u003Cli>Hide WordPress Version — removes version leaks from source, RSS feeds, scripts, and styles\u003C\u002Fli>\n\u003Cli>Restrict REST API — limits sensitive endpoints to authenticated users\u003C\u002Fli>\n\u003Cli>Block Author Scanning — prevents user enumeration via author archives\u003C\u002Fli>\n\u003Cli>Login Brute-Force Protection — rate-limits login attempts per IP with configurable thresholds and lockout duration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Persistent Findings Store\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>All audit findings persist in a dedicated database table with automatic deduplication by fingerprint. Track findings over time — dismissed findings stay dismissed across scans; resolved findings reopen if the issue reappears.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security Event Logging\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Every scan, hardening change, remediation, and significant event is logged to a dedicated table. Logs are filterable by severity and exportable as CSV.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WordPress Site Health Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Adds 6 security tests to the built-in Site Health screen: file editor, debug mode, XML-RPC, admin username, SSL, and overall security score.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Performance Diagnostics\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Built-in performance profiling to identify slow queries, high memory usage, and resource bottlenecks related to security operations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>REST API\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>10 authenticated endpoints under the \u003Ccode>aipatch-security-scanner\u002Fv1\u003C\u002Fcode> namespace for triggering scans, retrieving summaries, toggling hardening, exporting logs, and running performance diagnostics.\u003C\u002Fp>\n\u003Ch4>MCP Surface for AI Agents (23 Abilities)\u003C\u002Fh4>\n\u003Cp>Aipatch exposes 23 structured abilities via the WordPress Abilities API — making your site’s security surface fully accessible to external AI agents, coding assistants, and orchestration tools:\u003C\u002Fp>\n\u003Cp>By default, only \u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> is enabled. You can enable additional abilities from \u003Cstrong>Aipatch Security Scanner -> Settings -> MCP Abilities\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-site\u003C\u002Fstrong> — Run a full 36-check security audit with scored findings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Faudit-suspicious\u003C\u002Fstrong> — Quick heuristic scan for suspicious files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fstart-file-scan\u003C\u002Fstrong> — Launch an async multi-layer malware scan job\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fprocess-file-scan-batch\u003C\u002Fstrong> — Process next batch of files in a running scan\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-progress\u003C\u002Fstrong> — Check file scan progress\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffile-scan-results\u003C\u002Fstrong> — Retrieve enriched scan results with family, reasons, layer scores\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-scan-summary\u003C\u002Fstrong> — Comprehensive latest scan summary with classification breakdown\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-suspicious-files\u003C\u002Fstrong> — List suspicious files from latest scan (no job_id needed)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Integrity & Baseline\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fverify-core-integrity\u003C\u002Fstrong> — Verify WP core files against official api.wordpress.org checksums\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-build\u003C\u002Fstrong> — Build or refresh the known-good file hash baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-diff\u003C\u002Fstrong> — Compare current filesystem against stored baseline\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fbaseline-stats\u003C\u002Fstrong> — Baseline statistics by origin type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-baseline-drift\u003C\u002Fstrong> — Combined baseline drift + core integrity report\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Findings & Monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-findings\u003C\u002Fstrong> — Query persistent findings with status\u002Fseverity\u002Fcategory filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-stats\u003C\u002Fstrong> — Aggregate finding statistics\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Ffindings-diff\u003C\u002Fstrong> — New and resolved findings since a point in time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-file-finding-detail\u003C\u002Fstrong> — Single finding with decoded metadata, layer scores, family\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fdismiss-finding\u003C\u002Fstrong> — Dismiss a finding as accepted risk\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Remediation\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Fapply-remediation\u003C\u002Fstrong> — Apply a security fix with rollback support\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Frollback-remediation\u003C\u002Fstrong> — Undo a previously applied fix\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-remediations\u003C\u002Fstrong> — List remediation history with filters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Jobs & Status\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>aipatch\u002Flist-jobs\u003C\u002Fstrong> — List scan\u002Faudit jobs with filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>aipatch\u002Fget-async-job-status\u003C\u002Fstrong> — Check async job status and retrieve results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>20 abilities are read-only; only 3 (dismiss, apply-remediation, rollback) modify site state. All abilities include typed input\u002Foutput schemas, permission checks (\u003Ccode>manage_options\u003C\u002Fcode>), and structured error responses.\u003C\u002Fp>\n\u003Ch4>What Aipatch Does NOT Do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>It is NOT a firewall or WAF — it does not filter incoming traffic.\u003C\u002Fli>\n\u003Cli>It does NOT intercept frontend requests or affect page load performance.\u003C\u002Fli>\n\u003Cli>It does NOT phone home, require an account, or send data externally.\u003C\u002Fli>\n\u003Cli>It does NOT inject ads, upsells, or nag notices.\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress security scanner with 36 checks, malware scanning, core integrity verification, remediation, and 23 MCP abilities.",477,"2026-05-03T09:18:00.000Z","6.5",[19,20,65,22,66],"malware-scanner","vulnerability","https:\u002F\u002Fgithub.com\u002Festebanstifli\u002Faipatch-security-scanner","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faipatch-security-scanner.2.0.2.zip",{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":33,"downloaded":77,"rating":11,"num_ratings":11,"last_updated":78,"tested_up_to":14,"requires_at_least":48,"requires_php":16,"tags":79,"homepage":83,"download_link":84,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"codewp-shield-monitor","CodeWP Shield Monitor","1.4.1","CodeWP","https:\u002F\u002Fprofiles.wordpress.org\u002Fvithanhlam\u002F","\u003Cp>CodeWP Shield Monitor (ShieldPress) adds a careful baseline of WordPress security controls without sending site data to third parties by default.\u003C\u002Fp>\n\u003Cp>Monitor your website health anywhere — visit \u003Ca href=\"https:\u002F\u002Fshieldpress.net\" rel=\"nofollow ugc\">shieldpress.net\u003C\u002Fa> or download the ShieldPress app on \u003Ca href=\"https:\u002F\u002Fapps.apple.com\u002Fapp\u002Fshieldpress\" rel=\"nofollow ugc\">iOS\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fplay.google.com\u002Fstore\u002Fapps\u002Fdetails?id=net.shieldpress.app\" rel=\"nofollow ugc\">Android\u003C\u002Fa> to keep track of your site’s security status, receive real-time alerts, and manage protection settings on the go.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Security & Hardening\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Rate limits repeated failed logins by hashed IP address.\u003C\u002Fli>\n\u003Cli>Restricts public user enumeration.\u003C\u002Fli>\n\u003Cli>Adds conservative browser security headers.\u003C\u002Fli>\n\u003Cli>Optionally disables XML-RPC.\u003C\u002Fli>\n\u003Cli>Disables dashboard file editing.\u003C\u002Fli>\n\u003Cli>Hides the default login\u002Fadmin paths behind a custom login slug when enabled.\u003C\u002Fli>\n\u003Cli>Shows failed-login IPs with manual block and unlock controls.\u003C\u002Fli>\n\u003Cli>Adds honeypot fields to login, registration, and comment forms to silently block automated bots.\u003C\u002Fli>\n\u003Cli>Blocks PHP execution inside the uploads directory and prevents uploading dangerous file types.\u003C\u002Fli>\n\u003Cli>Supports comment and registration rate limiting per IP with optional math CAPTCHA challenges.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Monitoring & Scanning\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records a local security audit log with configurable retention (30 days default).\u003C\u002Fli>\n\u003Cli>Monitors important WordPress files every five minutes using SHA-256 hashes.\u003C\u002Fli>\n\u003Cli>Runs lightweight suspicious-code and database scans with severity-based findings.\u003C\u002Fli>\n\u003Cli>Adds threat intelligence checks for admin anomalies, executable uploads, suspicious options, cron hooks, MU plugins, fake CAPTCHA content, external scripts, cloaking signals, and hardening gaps.\u003C\u002Fli>\n\u003Cli>Ships 38 built-in threat detection patterns covering web shells, backdoors, obfuscation techniques, credit card skimmers, SEO spam, PHP object injection, SQL injection, SSRF, and more — based on real-world CVEs and active malware campaigns (Balada Injector, Sign1, SocGholish, mu-plugins backdoors).\u003C\u002Fli>\n\u003Cli>Skips previously clean malware-scan files while their SHA-256 hash is unchanged.\u003C\u002Fli>\n\u003Cli>Flags external JavaScript and URLs outside the current site domain in source or database content.\u003C\u002Fli>\n\u003Cli>Lets administrators run manual scans or schedule scans daily, weekly, or monthly.\u003C\u002Fli>\n\u003Cli>Emails alerts for administrator logins, blocked login attacks, file changes, and suspicious scan findings.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Firewall & Threat Patterns\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Includes a Web Application Firewall (WAF) to block SQL injection, XSS, path traversal, PHP object injection, SSRF, CRLF injection, and other common attack patterns.\u003C\u002Fli>\n\u003Cli>Provides an extensible threat pattern engine for custom malware signatures, WAF rules, and database content patterns with import\u002Fexport support.\u003C\u002Fli>\n\u003Cli>Rate-limits audit log events to prevent database flooding during brute-force attacks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Activity & Notifications\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records recent public content create\u002Fupdate activity and new administrator access.\u003C\u002Fli>\n\u003Cli>Records WordPress core, plugin, and theme update events.\u003C\u002Fli>\n\u003Cli>Records plugin and theme lifecycle events, including activation, deactivation, installs, and updates.\u003C\u002Fli>\n\u003Cli>Pushes Contact Form 7 submissions, WooCommerce orders, and selected custom post type creations to the authenticated events API.\u003C\u002Fli>\n\u003Cli>Provides an incident-response summary with prioritized findings and next review steps.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>App & API Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Displays basic WordPress security and update status in wp-admin.\u003C\u002Fli>\n\u003Cli>Provides token-authenticated REST endpoints for the ShieldPress App and Web dashboard.\u003C\u002Fli>\n\u003Cli>Pairs the App using a local QR code and a short-lived, one-time exchange code.\u003C\u002Fli>\n\u003Cli>Creates scoped, one-time quick-login URLs for paired App\u002FWeb clients when enabled.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Tools\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Provides database cleanup tools for spam, revisions, orphaned data, expired transients, and inactive subscriber accounts.\u003C\u002Fli>\n\u003Cli>Offers media optimization with optional thumbnail generation control and automatic WebP conversion on upload.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>CodeWP Shield Monitor hashes IP addresses in its 30-day audit log. For failed-login lockout management, it may also store recent source IP addresses, attempt counts, lockout status, and last failed-login time so administrators can block or unlock those IPs. File contents and post body content are never stored.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>CodeWP Shield Monitor can connect to the official WordPress.org checksum API when the administrator enables core checksum verification. The service is used to compare local WordPress core file hashes with official release hashes. It sends the installed WordPress version and site locale at most once every 12 hours; it does not send stored credentials, file contents, full database values, post body content, audit-log IP hashes, API tokens, or CAPTCHA tokens. WordPress.org provides this service under the WordPress.org Terms of Service and Privacy Policy.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fterms-of-service\u002F\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Cp>CodeWP Shield Monitor can connect to Cloudflare Turnstile only when an administrator enables CAPTCHA challenges, selects Cloudflare Turnstile, saves a Turnstile site key and secret key, and chooses the forms to protect. Public pages that may contain selected login, registration, or WooCommerce checkout forms can load Cloudflare’s Turnstile JavaScript from challenges.cloudflare.com to display the challenge. During protected form submissions, the plugin sends the Turnstile response token, configured secret key, and visitor IP address to Cloudflare’s siteverify endpoint to validate the challenge. This is required for the optional Turnstile CAPTCHA feature.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fwww.cloudflare.com\u002Fwebsite-terms\u002F\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\u003C\u002Fp>\n\u003Cp>CodeWP Shield Monitor can connect to Google reCAPTCHA only when an administrator enables CAPTCHA challenges, selects Google reCAPTCHA v2 or v3, saves a reCAPTCHA site key and secret key, and chooses the forms to protect. Public pages that may contain selected login, registration, or WooCommerce checkout forms can load Google’s reCAPTCHA JavaScript from google.com to display or run the challenge. During protected form submissions, the plugin sends the reCAPTCHA response token, configured secret key, and visitor IP address to Google’s siteverify endpoint to validate the challenge. When Google reCAPTCHA v3 is selected, the plugin also checks the returned score against the configured threshold, which defaults to 0.1. This is required for the optional Google reCAPTCHA feature.\u003C\u002Fp>\n\u003Cp>Terms: https:\u002F\u002Fpolicies.google.com\u002Fterms\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fp>\n","Privacy-first WordPress security hardening, login protection, and local audit logging.",200,"2026-07-15T09:48:00.000Z",[80,20,81,82,22],"audit-log","login","privacy","https:\u002F\u002Fshieldpress.net","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcodewp-shield-monitor.zip",{"slug":86,"name":87,"version":88,"author":89,"author_profile":90,"description":91,"short_description":92,"active_installs":93,"downloaded":94,"rating":25,"num_ratings":95,"last_updated":96,"tested_up_to":97,"requires_at_least":98,"requires_php":99,"tags":100,"homepage":51,"download_link":106,"security_score":107,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":108},"audit-charitable-donations","Audit Charitable Donations Plugin","1.0.1","Himani Lotia","https:\u002F\u002Fprofiles.wordpress.org\u002Fimani3011\u002F","\u003Cp>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcharitable\u002F\" rel=\"ugc\">Charitable\u003C\u002Fa>\u003C\u002Fstrong> plugin of the WordPress allows non-profits and developers to create powerful fundraising platforms on their own website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit Charitable Donations\u003C\u002Fstrong> provides an ability to maintain the transparency with Donors and gain more trust by giving an overview of how and where their donations are being utilized by your fundraising platform.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Add your expenses made from the fund raised\u003C\u002Fli>\n\u003Cli>See all the expenses in WP Admin Dashboard Audit Donations Page\u003C\u002Fli>\n\u003Cli>Display the Audit data seggregated by Charitable Campaigns, anywhere on the website with the help of a shortcode [charitable_audit]\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>For any issue with the plugin, or if you have any suggestions, email me at himani.lotia@gmail.com\u003C\u002Fli>\n\u003C\u002Ful>\n","Are you looking for gainning more trust among your donors? You are at the right place. This plugin allows an admin to audit the received donations and &hellip;",20,1645,1,"2019-05-27T04:35:00.000Z","5.2.24","4.1","5.6",[101,102,103,104,105],"audit-received-donations","charitable","charitable-addon","display-admin-report","donors-transparency","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faudit-charitable-donations.1.0.1.zip",85,"2026-04-16T10:56:18.058Z",{"slug":110,"name":111,"version":112,"author":113,"author_profile":114,"description":115,"short_description":116,"active_installs":93,"downloaded":117,"rating":11,"num_ratings":11,"last_updated":118,"tested_up_to":47,"requires_at_least":48,"requires_php":119,"tags":120,"homepage":51,"download_link":121,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"steel-security","Steel Security & Hardening – Site Audit Tools","1.0.4","sweetwatermedia","https:\u002F\u002Fprofiles.wordpress.org\u002Fsweetwatermedia\u002F","\u003Cp>Steel Security & Hardening – Site Audit Tools focuses on practical security hygiene for WordPress administrators.\u003C\u002Fp>\n\u003Cp>The free plugin provides:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>on-demand security scans\u003C\u002Fli>\n\u003Cli>risk summaries grouped by severity and category\u003C\u002Fli>\n\u003Cli>checks for common WordPress hardening gaps\u003C\u002Fli>\n\u003Cli>checks for exposed root-level artifacts such as \u003Ccode>.env\u003C\u002Fcode>, SQL dumps, \u003Ccode>phpinfo\u003C\u002Fcode> files, and backup archives\u003C\u002Fli>\n\u003Cli>a quarantine vault for operator-reviewed file isolation\u003C\u002Fli>\n\u003Cli>uploads PHP execution blocking on supported server environments\u003C\u002Fli>\n\u003Cli>manual guidance when automatic server hardening is not safely supported\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is positioned as an auditing and hardening tool. It helps surface risk and apply selected preventive controls, but it does not promise malware removal, incident response, or complete server protection.\u003C\u002Fp>\n\u003Ch4>Included checks\u003C\u002Fh4>\n\u003Cp>The scan currently looks for items such as:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP error display exposure\u003C\u002Fli>\n\u003Cli>\u003Ccode>WP_DEBUG\u003C\u002Fcode> and \u003Ccode>debug.log\u003C\u002Fcode> exposure\u003C\u002Fli>\n\u003Cli>XML-RPC availability\u003C\u002Fli>\n\u003Cli>author and REST user enumeration exposure\u003C\u002Fli>\n\u003Cli>theme\u002Fplugin file editor availability\u003C\u002Fli>\n\u003Cli>WordPress generator meta output\u003C\u002Fli>\n\u003Cli>comments enabled by default\u003C\u002Fli>\n\u003Cli>uploads PHP execution hardening status\u003C\u002Fli>\n\u003Cli>root-level sensitive files and archives\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Server-aware behavior\u003C\u002Fh4>\n\u003Cp>This plugin only auto-applies server config changes where it can do so in a scoped and reversible way.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Apache and LiteSpeed: uploads PHP blocking is managed through a Steel Security-marked \u003Ccode>.htaccess\u003C\u002Fcode> block\u003C\u002Fli>\n\u003Cli>IIS: uploads PHP blocking is managed through a Steel Security-marked \u003Ccode>web.config\u003C\u002Fcode> section\u003C\u002Fli>\n\u003Cli>Nginx and unsupported environments: Steel Security provides manual guidance instead of claiming automatic protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro companion\u003C\u002Fh4>\n\u003Cp>This plugin can work with a separate Pro companion plugin that adds features such as scheduled scans, scan history, reports, and managed server-level controls such as directory listing protection and baseline security headers. The free plugin remains usable on its own.\u003C\u002Fp>\n","High-signal WordPress security auditing and hardening with practical site audit tools for administrators.",218,"2026-04-28T22:21:00.000Z","8.0",[19,20,50,22],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsteel-security.1.0.4.zip",{"error":123,"url":124,"statusCode":125,"statusMessage":126,"message":126},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Ftreder-security-snapshot\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":95,"versions":128},[129],{"version":6,"download_url":24,"svn_tag_url":130,"released_at":26,"has_diff":131,"diff_files_changed":132,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":133,"is_current":123},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftreder-security-snapshot\u002Ftags\u002F1.0.0\u002F",false,[],[]]