[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fp_cE5-uoJgfgOwp5mJwCRFzK44Smie78vN-y_E8pZ_0":3,"$fYx_uZJaNBHhxU_0LI30yGkQ3q1L5hy5Q_dRyMkCwcno":249,"$fdh8Iqr0OFptgth2EPX_ZiViBp9fwftga4HeQBGbm4xc":253},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":36,"analysis":144,"fingerprints":229},"turbo-rate-limiter","Turbo Rate Limiter","1.0.2","ahriad","https:\u002F\u002Fprofiles.wordpress.org\u002Fahriad\u002F","\u003Cp>Turbo Rate Limiter is a powerful yet easy-to-use security plugin that helps protect your WordPress site from various types of abuse by limiting the rate at which visitors can make requests.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>URI-based filtering\u003C\u002Fstrong> – Set rate limits for specific URLs, paths, or patterns\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multiple match types\u003C\u002Fstrong> – Exact match, contains, starts with, ends with, or regex\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible time windows\u003C\u002Fstrong> – Configure rate limits per second, minute, or hour\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multiple actions\u003C\u002Fstrong> – Return HTTP 429, redirect to URL, or redirect to page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Test mode\u003C\u002Fstrong> – Preview rate limiting behavior without blocking visitors\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Debug panel\u003C\u002Fstrong> – Visual debug panel for administrators\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare support\u003C\u002Fstrong> – Full IPv4 and IPv6 proxy detection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Localization ready\u003C\u002Fstrong> – Translations available for multiple languages\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Use Cases\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>API protection\u003C\u002Fstrong> – Limit API calls to prevent abuse\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login protection\u003C\u002Fstrong> – Prevent brute force attacks on login pages\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Form spam prevention\u003C\u002Fstrong> – Limit form submission rates\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Resource protection\u003C\u002Fstrong> – Protect heavy database queries\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CDN compatibility\u003C\u002Fstrong> – Works with Cloudflare and other proxies\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Arbitrary section\u003C\u002Fh3>\n\u003Ch3>Developer API\u003C\u002Fh3>\n\u003Cp>Turbo Rate Limiter provides hooks and filters for developers:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>\u002F\u002F Add trusted proxy IPs\nadd_filter('turbo_rate_limiter_trusted_proxies', function() {\n    return [\n        '173.245.48.0\u002F20',\n        '2400:cb00::\u002F32',\n        \u002F\u002F More ranges...\n    ];\n});\n\n\u002F\u002F Access rate limiter instance\n$rate_limiter = TURBORL_Rate_Limiter::get_instance();\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For full API documentation, see docs\u002Fdeveloper-api.md.\u003C\u002Fp>\n","Protect your WordPress site from brute force attacks, API abuse, and DDoS attacks with customizable rate limiting rules.",40,383,0,"2026-03-26T04:25:00.000Z","6.9.5","5.0","7.4",[19,20,21,22,23],"api","ddos","rate-limit","security","spam-protection","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fturbo-rate-limiter.1.0.2.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},2,30,94,"2026-08-29T04:06:08.398Z",[37,58,76,101,124],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":26,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":24,"download_link":57,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"anti-browser-ddos-protection","Anti Browser DDoS Protection","2.28","sourcecode347","https:\u002F\u002Fprofiles.wordpress.org\u002Fsourcecode347\u002F","\u003Cp>The \u003Cstrong>Anti Browser DDoS Protection\u003C\u002Fstrong> plugin provides robust protection against denial-of-service (DoS) attacks on your WordPress site. It implements IP-based rate limiting, with configurable settings for subscribers, non-logged-in users, and verified bots, while excluding administrators and other non-subscriber roles. It features advanced bot detection to identify and limit suspicious bots, immediate blocking of malicious bots by User Agent, and supports Cloudflare for accurate client IP detection. Static assets (e.g., CSS, JS, images) are excluded to maintain site performance. An intuitive admin panel allows you to configure rate limits, bot exclusions, trusted bot IP ranges (with automatic duplicate removal), blocked bots by User Agent, log expiration settings, and view logs for blocked IPs, banned IPs, and high traffic bots with auto-refresh every 30 seconds, all with User Agent details and timestamps. You can export \u003Cstrong>Excluded Bots\u003C\u002Fstrong>, \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong>, and \u003Cstrong>Blocked Bots\u003C\u002Fstrong> lists to .txt files and import new entries to append to existing lists without duplicates. Daily bar charts for Blocked IPs, Banned IPs, and High Traffic Bots are displayed above the logs for quick visual insights.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Rate limiting based on IP for subscribers and non-logged-in users, with configurable maximum requests and time window.\u003C\u002Fli>\n\u003Cli>Excludes non-subscriber logged-in users (e.g., administrators, editors) from rate limiting.\u003C\u002Fli>\n\u003Cli>Advanced bot detection to identify suspicious bots (bots using trusted User Agents but from unverified IPs).\u003C\u002Fli>\n\u003Cli>Suspicious bots are subject to the same rate limiting as regular users and logged with User Agent in the Blocked IPs Log.\u003C\u002Fli>\n\u003Cli>Immediate blocking of malicious bots by User Agent (e.g., MJ12bot, SemrushBot, DotBot by default) with customizable settings and logging.\u003C\u002Fli>\n\u003Cli>Configurable rate limiting for verified excluded bots (default: 100 requests per minute), with logging for bots exceeding this limit.\u003C\u002Fli>\n\u003Cli>High Traffic Excluded Bots Log to track verified bots with excessive requests, including IP, User Agent, and timestamp.\u003C\u002Fli>\n\u003Cli>Admin panel to configure maximum requests, time window, excluded bots, trusted bot IP ranges, blocked bots (User Agents), blocks before ban, ban duration, high traffic bot limits, and log expiration (days).\u003C\u002Fli>\n\u003Cli>Export \u003Cstrong>Excluded Bots\u003C\u002Fstrong>, \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong>, and \u003Cstrong>Blocked Bots\u003C\u002Fstrong> lists to .txt files for backup or transfer.\u003C\u002Fli>\n\u003Cli>Import .txt files for \u003Cstrong>Excluded Bots\u003C\u002Fstrong>, \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong>, and \u003Cstrong>Blocked Bots\u003C\u002Fstrong> to append new entries to existing lists, with automatic duplicate removal.\u003C\u002Fli>\n\u003Cli>Automatic removal of duplicate IP ranges in the \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong> field on save, keeping the first occurrence.\u003C\u002Fli>\n\u003Cli>Support for Cloudflare real IP detection using \u003Ccode>CF-Connecting-IP\u003C\u002Fcode> and \u003Ccode>X-Forwarded-For\u003C\u002Fcode> headers.\u003C\u002Fli>\n\u003Cli>Excludes static assets (CSS, JS, images, fonts, etc.) from rate limiting to optimize performance.\u003C\u002Fli>\n\u003Cli>Logs blocked IPs, banned IPs, and high traffic bots with IP, User Agent, and timestamps using the WordPress timezone, viewable in the admin panel with options to clear logs and auto-refresh every 30 seconds.\u003C\u002Fli>\n\u003Cli>Daily bar charts for Blocked IPs, Banned IPs, and High Traffic Bots displayed above the logs in the admin panel for visual statistics.\u003C\u002Fli>\n\u003Cli>Automatic log expiration (Blocked IPs, Banned IPs, High Traffic Bots) after a configurable number of days (default: 5 days), with hourly cleanup via WordPress Scheduler.\u003C\u002Fli>\n\u003Cli>All error messages and logs prefixed with “Anti Browser DDoS Protection: ” for clarity.\u003C\u002Fli>\n\u003Cli>Donate link in the admin panel to support the project.\u003C\u002Fli>\n\u003Cli>Automatic cleanup of transients, blocked IPs, banned IPs, high traffic bots, blocked bots, bot IP ranges, and log expiration settings on plugin deactivation to prevent database bloat.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Ideal for WordPress sites seeking enhanced security against automated attacks, with seamless integration for Cloudflare users, advanced bot management, efficient log management, visual charts for statistics, and easy export\u002Fimport for bot lists.\u003C\u002Fp>\n\u003Ch3>Plugin Assets img\u002F\u003C\u002Fh3>\n\u003Ch3>Icon Image\u003C\u002Fh3>\n\u003Cp>Normal: icon-128×128.png\u003Cbr \u002F>\nHigh-DPI (Retina): icon-256×256.png\u003C\u002Fp>\n\u003Ch3>Bugs\u003C\u002Fh3>\n\u003Cp>Caching plugins such as WP Super Cache, W3 Total Cache, and others may bypass the DDoS protection provided by Anti Browser DDoS Protection, serving cached pages without triggering the plugin’s checks for blocked bots, rate limiting, or banned IPs.\u003Cbr \u002F>\n– \u003Cstrong>Solution\u003C\u002Fstrong>: Disable all WordPress caching plugins to ensure full DDoS protection. Instead, enable Browser Caching using a service like Cloudflare to improve performance without compromising security.\u003Cbr \u002F>\n   Enable standard type Caching and Configure Cloudflare Browser Cache TTL (e.g., 8 days) via \u003Cstrong>Caching > Configuration\u003C\u002Fstrong> in the Cloudflare dashboard.- \u003Cstrong>Cloudflare Compatibility\u003C\u002Fstrong>: Ensure Cloudflare is configured to pass \u003Ccode>CF-Connecting-IP\u003C\u002Fcode> headers for accurate IP detection. Check your Cloudflare dashboard if logged IPs are incorrect.\u003Cbr \u002F>\n– \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong>: Update the \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong> field every 6 months (next update: March 2026) using official sources (e.g., Google, Bing, Yandex documentation). Duplicate ranges are automatically removed on save. Export to .txt for backup or import from .txt to append new ranges.\u003Cbr \u002F>\n– \u003Cstrong>Blocked Bots\u003C\u002Fstrong>: Add malicious bots to the \u003Cstrong>Blocked Bots (User Agents)\u003C\u002Fstrong> field (e.g., MJ12bot, SemrushBot, DotBot) to block them immediately. Blocked bots are logged with their IP and User Agent. Export to .txt for backup or import from .txt to append new entries.\u003Cbr \u002F>\n– \u003Cstrong>Excluded Bots\u003C\u002Fstrong>: Add trusted bots (e.g., Googlebot, Bingbot) to the \u003Cstrong>Excluded Bots\u003C\u002Fstrong> field to exempt them from regular rate limiting (if from verified IPs). Export to .txt for backup or import from .txt to append new entries.\u003Cbr \u002F>\n– \u003Cstrong>High Traffic Bots\u003C\u002Fstrong>: Verified bots exceeding the configured limit (default: 100 requests per minute) are logged for monitoring but not blocked. Check the High Traffic Excluded Bots Log regularly.\u003Cbr \u002F>\n– \u003Cstrong>Log Expiration\u003C\u002Fstrong>: Set the \u003Cstrong>Log Expires (Days)\u003C\u002Fstrong> setting to control how long logs are retained (default: 5 days). Cleanup runs hourly via WordPress Scheduler. Logs older than the specified days are automatically deleted.\u003Cbr \u002F>\n– \u003Cstrong>Timezone\u003C\u002Fstrong>: Set the WordPress timezone correctly (e.g., \u003Ccode>Europe\u002FAthens\u003C\u002Fcode> for Greece) in Settings > General > Timezone to ensure accurate timestamp display in logs and charts.\u003Cbr \u002F>\n– \u003Cstrong>Performance\u003C\u002Fstrong>: For high-traffic sites, clear the Blocked IPs Log, Banned IPs Log, and High Traffic Excluded Bots Log regularly, or set a lower \u003Cstrong>Log Expires (Days)\u003C\u002Fstrong> value to prevent database growth.\u003Cbr \u002F>\n– \u003Cstrong>Customization\u003C\u002Fstrong>: Contact the author for additional features like custom error pages, email notifications for high traffic bots, or advanced logging.\u003Cbr \u002F>\n– \u003Cstrong>Support the Project\u003C\u002Fstrong>: If you find this plugin useful, consider supporting its development via the \u003Ca href=\"https:\u002F\u002Fbuy.stripe.com\u002FbIY5o70SSfam8Qo7ss\" rel=\"nofollow ugc\">donation link\u003C\u002Fa> in the admin panel or plugin page.\u003C\u002Fp>\n","Protects WordPress from DDoS with rate limiting, bot detection, blocking, Cloudflare support, logs, charts, and bot list export\u002Fimport.",70,1020,1,"2026-06-22T07:51:00.000Z","7.0.2","6.0","8.5",[53,54,55,56,22],"bot-blocking","ddos-protection","ip-blocking","rate-limiting","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanti-browser-ddos-protection.2.28.zip",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":13,"downloaded":66,"rating":13,"num_ratings":13,"last_updated":67,"tested_up_to":68,"requires_at_least":69,"requires_php":70,"tags":71,"homepage":24,"download_link":74,"security_score":75,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"defendium-checker","Defendium Checker","1.1.2","defendium","https:\u002F\u002Fprofiles.wordpress.org\u002Fdefendium\u002F","\u003Cp>Defendium-Checker is an innovative WordPress plugin designed to safeguard your website’s comment section from spam. By utilizing the robust Defendium API, this plugin meticulously scans incoming comments, effectively identifying and blocking spam. It’s a must-have tool for website owners seeking to maintain the integrity and cleanliness of their comment areas.\u003C\u002Fp>\n","Defendium is a powerful spam checker plugin for WordPress, integrating with the Defendium API to scrutinize incoming comments for spam.",1278,"2024-08-29T20:50:00.000Z","6.5.8","5.9","8.1",[19,72,22,73,23],"comments","spam","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdefendium-checker.1.1.2.zip",92,{"slug":77,"name":78,"version":79,"author":80,"author_profile":81,"description":82,"short_description":83,"active_installs":84,"downloaded":85,"rating":86,"num_ratings":87,"last_updated":88,"tested_up_to":89,"requires_at_least":90,"requires_php":91,"tags":92,"homepage":24,"download_link":97,"security_score":98,"vuln_count":99,"unpatched_count":13,"last_vuln_date":100,"fetched_at":28},"advanced-access-manager","Advanced Access Manager – Access Governance for WordPress","7.1.2","AAM Plugin","https:\u002F\u002Fprofiles.wordpress.org\u002Fvasyltech\u002F","\u003Cp>\u003Cstrong>Advanced Access Manager (AAM)\u003C\u002Fstrong> introduces \u003Cstrong>Access Governance for WordPress\u003C\u002Fstrong> – a systematic approach to securing your site by controlling who can access what, when, and why.\u003C\u002Fp>\n\u003Cp>Most WordPress security plugins focus on external threats like malware, firewalls, and brute-force attacks. AAM addresses the \u003Cstrong>root cause of the #1 WordPress security risk: broken access controls, excessive privileges, and misconfigured roles\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Instead of reacting to attacks, AAM helps you \u003Cstrong>design security into your WordPress site\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch4>What Access Governance means in practice\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Mitigate Broken Access Controls\u003C\u002Fstrong>. Ensure roles, users, and permissions are correctly configured to prevent unauthorized actions and privilege escalation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Eliminate Excessive Privileges\u003C\u002Fstrong>. Identify overpowered users and reduce access to critical functionality, admin areas, and APIs.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure Content by Design\u003C\u002Fstrong>. Control who can view, edit, publish, or delete posts, pages, media, taxonomies, and custom content types.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Govern Access with Policy\u003C\u002Fstrong>. Define access rules using JSON Access Policies — portable, auditable, and automation-friendly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Build Custom Security Logic\u003C\u002Fstrong>. Use the AAM PHP Framework to create advanced, programmatic access controls tailored to your application.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Security Audit\u003C\u002Fstrong>. Detect risky role assignments, misconfigurations, and compromised accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Granular Access Control\u003C\u002Fstrong>. Manage permissions for any user, role, or visitor with precision.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Role & Capability Management\u003C\u002Fstrong>. Customize WordPress roles and capabilities beyond defaults.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin & Menu Control\u003C\u002Fstrong>. Restrict dashboard areas and tailor the admin experience per user or role.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>API & Endpoint Protection\u003C\u002Fstrong>. Secure REST and XML-RPC access with fine-grained controls.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Modern Authentication Options\u003C\u002Fstrong>. Support passwordless and secure login flows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer-Ready Framework\u003C\u002Fstrong>. Extend WordPress security using AAM’s powerful SDK.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ad-Free & Transparent\u003C\u002Fstrong>. – No ads, no tracking, no bloat.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Built for Security-Conscious WordPress Users\u003C\u002Fh4>\n\u003Cp>AAM is trusted by \u003Cstrong>150,000+ websites\u003C\u002Fstrong> to deliver enterprise-grade access control without unnecessary complexity. Whether you’re a site owner, agency, developer, or security professional, AAM gives you \u003Cstrong>full control over WordPress access — by design\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Most core features are free. Advanced capabilities are available via premium add-ons.\u003C\u002Fp>\n\u003Cp>No hidden tracking. No data collection. No unwanted changes.\u003Cbr \u002F>\nJust \u003Cstrong>security you can reason about, audit, and trust\u003C\u002Fstrong>.\u003C\u002Fp>\n","Access Governance for WordPress. Control roles, users, content, admin areas, and APIs to prevent broken access controls and excessive privileges.",100000,7557401,84,420,"2026-05-25T19:32:00.000Z","7.0.0","5.8.0","5.6.0",[93,94,95,22,96],"access-governance","api-security","restricted-content","user-roles","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadvanced-access-manager.7.1.2.zip",82,12,"2026-05-14 00:00:00",{"slug":102,"name":103,"version":104,"author":105,"author_profile":106,"description":107,"short_description":108,"active_installs":109,"downloaded":110,"rating":111,"num_ratings":112,"last_updated":113,"tested_up_to":49,"requires_at_least":114,"requires_php":17,"tags":115,"homepage":119,"download_link":120,"security_score":121,"vuln_count":122,"unpatched_count":13,"last_vuln_date":123,"fetched_at":28},"anti-spam","Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter","7.5.2","Themeisle","https:\u002F\u002Fprofiles.wordpress.org\u002Fthemeisle\u002F","\u003Cp>Titan Anti-Spam & Security is a complete protection solution designed to secure your website against spam, login attacks, and unauthorized access.\u003C\u002Fp>\n\u003Cp>Websites are constantly targeted by automated spam bots, brute force login attempts, and malicious access patterns. Titan helps you block spam comments, protect your login page, enforce strong authentication, and apply essential security hardening rules from a single dashboard.\u003C\u002Fp>\n\u003Cp>Whether you run a blog, business site, WooCommerce store, membership platform, or agency network, Titan helps you:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Stop comment spam automatically\u003C\u002Fli>\n\u003Cli>Protect your login area from brute force attacks\u003C\u002Fli>\n\u003Cli>Limit login attempts and lock suspicious activity\u003C\u002Fli>\n\u003Cli>Monitor login activity and security events\u003C\u002Fli>\n\u003Cli>Apply security hardening best practices\u003C\u002Fli>\n\u003Cli>Enable two-factor authentication for stronger account security in \u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=2fa\" rel=\"nofollow ugc\">Pro\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Create backups with advanced storage options in \u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=backup\" rel=\"nofollow ugc\">Pro\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Titan is designed to reduce risk without affecting legitimate visitors or requiring captcha challenges.\u003C\u002Fp>\n\u003Ch3>Quick links\u003C\u002Fh3>\n\u003Cp>📘 \u003Ca href=\"https:\u002F\u002Fdocs.themeisle.com\u002Ftitan-anti-spam-security\u002F\" rel=\"nofollow ugc\">Documentation\u003C\u002Fa> – Complete setup and configuration guide\u003Cbr \u002F>\n💬 \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fanti-spam\u002F\" rel=\"ugc\">Support Forum\u003C\u002Fa> – Get help with spam protection, login security, and plugin settings from the community and support team.\u003Cbr \u002F>\n⭐ \u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=quicklinks\" rel=\"nofollow ugc\">Go Pro\u003C\u002Fa> – Unlock Machine Learning spam detection, two-factor authentication, backups, and priority support.\u003C\u002Fp>\n\u003Ch3>Anti Spam Protection\u003C\u002Fh3>\n\u003Cp>Spam comments can damage your SEO, clutter your database, and waste moderation time. Titan provides automated spam protection that works in the background without interrupting real users.\u003C\u002Fp>\n\u003Cp>Every comment is checked against a global spam database and evaluated using intelligent filtering rules. Suspicious comments are automatically marked as spam and hidden from public view.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Automatic spam comment blocking:\u003C\u002Fstrong> Blocks spam comments in real time using a global spam database and intelligent filtering rules. Suspicious submissions are automatically marked as spam before they appear publicly.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Block spam comments without captcha:\u003C\u002Fstrong> Protect your site from comment spam without forcing visitors to solve captcha challenges. Real users experience a smooth commenting process.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Save spam comments for review:\u003C\u002Fstrong> Optionally store filtered spam comments in the moderation area so you can verify filtering accuracy and review blocked content.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detailed spam processing logs:\u003C\u002Fstrong> View logs of processed comments to understand how spam filtering works and monitor spam activity trends.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy policy link integration:\u003C\u002Fstrong> Display a privacy policy notice under comment forms to help with transparency and compliance requirements.\u003C\u002Fp>\n\u003Cp>This ensures real visitors can interact freely while bots are filtered automatically.\u003C\u002Fp>\n\u003Ch3>Security Hardening Tools\u003C\u002Fh3>\n\u003Cp>Titan includes built-in security hardening options that reduce publicly exposed information and protect your website from common automated attacks.\u003C\u002Fp>\n\u003Cp>Many bots scan websites looking for version numbers, exposed login patterns, weak passwords, or XML-RPC endpoints. Titan helps minimize those risks with configurable hardening controls that strengthen overall site security.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Strong Password Enforcement:\u003C\u002Fstrong> Force users to create strong passwords based on the WordPress password strength meter. Weak passwords are a leading cause of account compromise. Enforcing strong credentials significantly improves login security and reduces unauthorized** access risks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hide Author Login:\u003C\u002Fstrong> Attackers can attempt to discover usernames using author archive URLs. Titan prevents user enumeration by restricting access patterns that reveal valid login names. This reduces the effectiveness of targeted brute force login attacks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Disable XML-RPC:\u003C\u002Fstrong> XML-RPC can be abused for automated login attacks and pingback spam. Disabling XML-RPC reduces exposure to remote brute force attempts and limits unnecessary resource usage.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Hide Version Information:\u003C\u002Fstrong> WordPress core and plugins sometimes expose version numbers in the source code. Attackers use this information to target known vulnerabilities. Titan removes version references to reduce fingerprinting risks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Remove Version Query Strings:\u003C\u002Fstrong> JavaScript and CSS files often include version query parameters. Removing these prevents attackers from identifying the exact WordPress or plugin version running on your site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Remove Meta Generator Tag:\u003C\u002Fstrong> The generator meta tag can reveal your CMS version. Titan removes it to reduce publicly visible system information and lower exposure.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Remove HTML Comments:\u003C\u002Fstrong> Some themes and plugins output HTML comments that may expose structural details. Titan can remove these comments to limit unnecessary information disclosure.\u003C\u002Fp>\n\u003Cp>Together, these security hardening options reduce your attack surface and strengthen your website without affecting normal functionality.\u003C\u002Fp>\n\u003Ch3>Activity Monitoring and Logs\u003C\u002Fh3>\n\u003Cp>Security is not only about blocking attacks. It is also about visibility and awareness.\u003C\u002Fp>\n\u003Cp>Titan includes built-in monitoring tools that help you understand login behavior and security activity on your website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Login Attempts Log:\u003C\u002Fstrong> Track failed login attempts in real time. See which IP addresses are attempting access, how many retries were made, and when lockouts were triggered. This helps you evaluate brute force protection effectiveness.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Activity Logger:\u003C\u002Fstrong> Monitor security-related events across your site, including login activity and system actions. Identify suspicious patterns before they escalate.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Error Log Viewer:\u003C\u002Fstrong> View plugin-related errors directly from the dashboard. Diagnose configuration issues quickly without accessing server files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Debug Information Export:\u003C\u002Fstrong> Export diagnostic information when contacting support. This reduces troubleshooting time and speeds up issue resolution.\u003C\u002Fp>\n\u003Cp>With proper monitoring and logging, you are not only blocking attacks but also gaining insight into how your website is being targeted.\u003C\u002Fp>\n\u003Ch3>PRO Anti Spam Features\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Machine Learning spam detection:\u003C\u002Fstrong> Advanced spam filtering powered by Machine Learning improves detection accuracy by analyzing behavioral patterns across large datasets.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scan existing comments for spam:\u003C\u002Fstrong> Identify previously approved spam comments and clean up your database.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scan registered users for spam accounts:\u003C\u002Fstrong> Detect and flag suspicious user accounts that may have been created by spam bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhanced background spam analysis:\u003C\u002Fstrong> Apply additional invisible tests that improve spam protection without affecting legitimate visitors.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=antispam\" rel=\"nofollow ugc\">Upgrade to unlock\u003C\u002Fa> advanced anti-spam capabilities.\u003C\u002Fp>\n\u003Ch3>PRO Two Factor Authentication\u003C\u002Fh3>\n\u003Cp>Two-factor authentication adds an additional verification step beyond a password. Even if a password is compromised, attackers cannot access the account without the second authentication factor.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>QR Code Setup:\u003C\u002Fstrong> Scan a QR code with an authenticator app to activate two-factor authentication quickly and securely.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manual Secret Key Configuration:\u003C\u002Fstrong> Set up two-factor authentication manually if QR code scanning is unavailable.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Per User 2FA Management:\u003C\u002Fstrong> Enable or manage two-factor authentication individually for specific users or roles.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Compatible with TOTP Apps:\u003C\u002Fstrong> Works with popular authenticator apps such as Google Authenticator and other TOTP-compatible applications.\u003C\u002Fp>\n\u003Cp>Two-factor authentication significantly strengthens login security for administrators and users.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=2fa\" rel=\"nofollow ugc\">Upgrade to Titan Pro\u003C\u002Fa> to enable Two Factor Authentication and advanced account protection.\u003C\u002Fp>\n\u003Ch3>PRO Backup and Recovery\u003C\u002Fh3>\n\u003Cp>Regular backups are essential for website security and recovery planning. If something goes wrong, having a recent backup allows you to restore your site quickly.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scheduled Automatic Backups:\u003C\u002Fstrong> Automatically create backups at defined intervals to ensure recent recovery points are always available.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manual Backup Creation:\u003C\u002Fstrong> Generate a backup instantly before making major changes to your website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>FTP Storage Support:\u003C\u002Fstrong> Store backups on a remote FTP server for additional protection and redundancy.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Dropbox Storage Integration:\u003C\u002Fstrong> Save backups to Dropbox for secure off-site storage.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Automatic Archive Cleanup:\u003C\u002Fstrong> Remove older backup files automatically to manage storage usage efficiently.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Adjustable Backup Performance:\u003C\u002Fstrong> Control backup speed to balance performance and server resource usage.\u003C\u002Fp>\n\u003Cp>Backups can be managed directly from the Titan dashboard for centralized control.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ftitansitescanner.com\u002F?utm_source=wordpressorg&utm_medium=readme&utm_campaign=backup\" rel=\"nofollow ugc\">Upgrade to Titan Pro\u003C\u002Fa> to unlock scheduled backups and external storage options.\u003C\u002Fp>\n\u003Ch3>Use Cases\u003C\u002Fh3>\n\u003Cp>Titan is suitable for:\u003C\u002Fp>\n\u003Cp>• Blogs receiving large volumes of comment spam\u003Cbr \u002F>\n• WooCommerce stores protecting customer login pages\u003Cbr \u002F>\n• Membership websites securing user accounts\u003Cbr \u002F>\n• Agencies managing multiple client websites\u003Cbr \u002F>\n• Educational platforms enforcing stronger authentication\u003Cbr \u002F>\n• Website owners looking for anti-spam and login security in one plugin\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>Need help? Open a new thread in the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fanti-spam\u002F\" rel=\"ugc\">Support Forum\u003C\u002Fa>, and we’ll be happy to assist.\u003C\u002Fp>\n\u003Ch3>Documentation\u003C\u002Fh3>\n\u003Cp>Discover how to make the most of Robin with our detailed and user-friendly \u003Ca href=\"https:\u002F\u002Fdocs.themeisle.com\u002F\" rel=\"nofollow ugc\">documentation\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Titan is backed by Themeisle, trusted by over 1 million WordPress users worldwide.\u003C\u002Fp>\n","Block spam comments, defend against login attacks, strengthen site security. Anti-spam, brute-force protection & two-factor authentication built in.",50000,3499574,90,369,"2026-05-19T11:25:00.000Z","5.6",[116,117,22,23,118],"antispam","brute-force-protection","two-factor-authentication","http:\u002F\u002Fwordpress.org\u002Fplugins\u002Fanti-spam\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanti-spam.7.5.2.zip",99,3,"2024-07-11 00:00:00",{"slug":125,"name":126,"version":127,"author":128,"author_profile":129,"description":130,"short_description":131,"active_installs":132,"downloaded":133,"rating":134,"num_ratings":135,"last_updated":136,"tested_up_to":49,"requires_at_least":16,"requires_php":16,"tags":137,"homepage":139,"download_link":140,"security_score":141,"vuln_count":142,"unpatched_count":13,"last_vuln_date":143,"fetched_at":28},"stop-spammer-registrations-plugin","Stop Spammers Classic","2026.6","Web Guy","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebguyio\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwebguyio\u002Fdam-spam\u002Fissues\" rel=\"nofollow ugc\">💬 Ask Question\u003C\u002Fa> | \u003Ca href=\"mailto:webguywork@gmail.com\" rel=\"nofollow ugc\">📧 Email Me\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Stop Spammers is now \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fdam-spam\u002F\" rel=\"ugc\">Dam Spam\u003C\u002Fa>. Switching is easy. All of your settings migrate over automatically in the background.\u003C\u002Fp>\n\u003Cp>Stop Spammers Classic is legacy code that will receive security patches only moving forward.\u003C\u002Fp>\n\u003Cp>🥪 \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fsponsors\u002Fwebguyio\" rel=\"nofollow ugc\">Buy me a sandwich\u003C\u002Fa> to help preserve Stop Spammers Classic or further project development in Dam Spam if you rely on either of them.\u003C\u002Fp>\n","A simplified, restored, and preserved version of the original Stop Spammers plugin.",30000,2647705,88,243,"2026-07-18T01:38:00.000Z",[102,138,22,73,23],"no-spam","https:\u002F\u002Fdamspam.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstop-spammer-registrations-plugin.zip",86,9,"2026-06-01 00:00:00",{"attackSurface":145,"codeSignals":215,"taintFlows":224,"riskAssessment":225,"analyzedAt":228},{"hooks":146,"ajaxHandlers":206,"restRoutes":212,"shortcodes":213,"cronEvents":214,"entryPointCount":47,"unprotectedCount":13},[147,153,157,160,165,169,173,177,181,185,189,194,198,202],{"type":148,"name":149,"callback":150,"file":151,"line":152},"action","admin_menu","add_admin_menu","admin\u002Fclass-admin-page.php",64,{"type":148,"name":154,"callback":155,"file":151,"line":156},"admin_init","register_settings",67,{"type":148,"name":158,"callback":159,"file":151,"line":45},"admin_enqueue_scripts","enqueue_assets",{"type":148,"name":161,"callback":162,"priority":163,"file":151,"line":164},"admin_bar_menu","add_admin_bar_menu",999,73,{"type":148,"name":166,"callback":167,"file":151,"line":168},"admin_post_turbo_rate_limiter_add_filter","handle_add_filter",76,{"type":148,"name":170,"callback":171,"file":151,"line":172},"admin_post_turbo_rate_limiter_update_filter","handle_update_filter",77,{"type":148,"name":174,"callback":175,"file":151,"line":176},"admin_post_turbo_rate_limiter_delete_filter","handle_delete_filter",78,{"type":148,"name":178,"callback":179,"file":151,"line":180},"admin_post_turbo_rate_limiter_toggle_filter","handle_toggle_filter",79,{"type":148,"name":182,"callback":183,"file":151,"line":184},"admin_post_turbo_rate_limiter_toggle_test_mode","handle_toggle_test_mode",80,{"type":148,"name":186,"callback":187,"file":151,"line":188},"admin_post_turbo_rate_limiter_clear_test_info","handle_clear_test_info",81,{"type":148,"name":190,"callback":191,"priority":47,"file":192,"line":193},"init","check_request","includes\u002Fclass-rate-limiter.php",121,{"type":148,"name":195,"callback":196,"file":192,"line":197},"wp_enqueue_scripts","enqueue_debug_assets",124,{"type":148,"name":199,"callback":200,"priority":163,"file":192,"line":201},"wp_footer","output_debug_panel",127,{"type":148,"name":203,"callback":204,"file":205,"line":141},"plugins_loaded","turborl_init","turbo-rate-limiter.php",[207],{"action":208,"nopriv":209,"callback":210,"hasNonce":211,"hasCapCheck":211,"file":151,"line":86},"turbo_rate_limiter_toggle_filter",false,"ajax_toggle_filter",true,[],[],[],{"dangerousFunctions":216,"sqlUsage":217,"outputEscaping":219,"fileOperations":13,"externalRequests":13,"nonceChecks":222,"capabilityChecks":99,"bundledLibraries":223},[],{"prepared":47,"raw":13,"locations":218},[],{"escaped":220,"rawEcho":13,"locations":221},264,[],8,[],[],{"summary":226,"deductions":227},"The 'turbo-rate-limiter' plugin, version 1.0.2, exhibits a strong security posture based on the provided static analysis. The code demonstrates excellent adherence to security best practices, with all SQL queries utilizing prepared statements and all output being properly escaped.  The plugin also implements a healthy number of nonce and capability checks, and crucially, has no external HTTP requests or file operations, significantly reducing its attack surface. The absence of any recorded vulnerabilities, critical or otherwise, in its history further bolsters this positive assessment.  The taint analysis showing zero unsanitized paths is a significant strength.  While the plugin has a single AJAX entry point, it is reported as being protected, which is a good indicator.  Overall, this plugin appears to be well-developed from a security perspective, with no immediate, evidence-backed concerns arising from the static analysis or vulnerability history. Its strengths lie in robust input validation and output sanitization, coupled with a clean vulnerability record.",[],"2026-04-16T13:07:59.694Z",{"wat":230,"direct":239},{"assetPaths":231,"generatorPatterns":234,"scriptPaths":235,"versionParams":236},[232,233],"\u002Fwp-content\u002Fplugins\u002Fturbo-rate-limiter\u002Fadmin\u002Fcss\u002Fadmin-styles.css","\u002Fwp-content\u002Fplugins\u002Fturbo-rate-limiter\u002Fadmin\u002Fjs\u002Fadmin-scripts.js",[],[233],[237,238],"turbo-rate-limiter\u002Fadmin\u002Fcss\u002Fadmin-styles.css?ver=","turbo-rate-limiter\u002Fadmin\u002Fjs\u002Fadmin-scripts.js?ver=",{"cssClasses":240,"htmlComments":241,"htmlAttributes":242,"restEndpoints":245,"jsGlobals":246,"shortcodeOutput":248},[],[],[243,244],"data-turborl-filter-id","data-turborl-filter-status",[],[247],"wpApiSettings",[],{"error":211,"url":250,"statusCode":251,"statusMessage":252,"message":252},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fturbo-rate-limiter\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":122,"versions":254},[255,260,267],{"version":6,"download_url":25,"svn_tag_url":256,"released_at":27,"has_diff":209,"diff_files_changed":257,"diff_lines":27,"trac_diff_url":258,"vulnerabilities":259,"is_current":211},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fturbo-rate-limiter\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fturbo-rate-limiter%2Ftags%2F1.0.1&new_path=%2Fturbo-rate-limiter%2Ftags%2F1.0.2",[],{"version":261,"download_url":262,"svn_tag_url":263,"released_at":27,"has_diff":209,"diff_files_changed":264,"diff_lines":27,"trac_diff_url":265,"vulnerabilities":266,"is_current":209},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fturbo-rate-limiter.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fturbo-rate-limiter\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fturbo-rate-limiter%2Ftags%2F1.0.0&new_path=%2Fturbo-rate-limiter%2Ftags%2F1.0.1",[],{"version":268,"download_url":269,"svn_tag_url":270,"released_at":27,"has_diff":209,"diff_files_changed":271,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":272,"is_current":209},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fturbo-rate-limiter.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fturbo-rate-limiter\u002Ftags\u002F1.0.0\u002F",[],[]]