[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fF47SXuxrZRwYMF7IEmDzv_WjYQSeVXdE8fgg4_mhfmU":3,"$fd4TG9N6S_ZZ0TnTASN33paYN_ItGrbUjo44uiws_xvA":117,"$f5VI0U7kAhBTHUFC_GxEJCf2Zt9WK6c6u4-Z-wxOHIjU":122},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"version-cloak","Version Cloak","1.0.4","nextdoorentertainment","https:\u002F\u002Fprofiles.wordpress.org\u002Fnextdoorentertainment\u002F","\u003Cp>Version Cloak is a hardening plugin that reduces the information opportunistic, automated scanners can read about your site. Version-matching bots fingerprint a site, look up known issues for the detected versions, and probe the easy targets first. This plugin shrinks that fingerprint.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Important:\u003C\u002Fstrong> this plugin obscures version and endpoint information. It does \u003Cstrong>not\u003C\u002Fstrong> patch vulnerable code. Keep your plugins, themes, and WordPress core updated — obscurity is a complement to patching, not a replacement for it.\u003C\u002Fp>\n\u003Ch4>Two version modes (per dropdown)\u003C\u002Fh4>\n\u003Cp>For \u003Cstrong>WordPress core\u003C\u002Fstrong> and for \u003Cstrong>plugins & themes\u003C\u002Fstrong>, choose one of:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Off\u003C\u002Fstrong> — leave the real version visible.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Obfuscate\u003C\u002Fstrong> — remove or block the version so it can’t be read.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Decoy\u003C\u002Fstrong> — report a plausible current version (auto-detected latest, or a value you set) so the site reads as up to date.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What it covers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>The WordPress \u003Ccode>\u003Cmeta name=\"generator\">\u003C\u002Fcode> tag, feed generators and the WLW manifest.\u003C\u002Fli>\n\u003Cli>Version query strings (\u003Ccode>?ver=\u003C\u002Fcode>) on enqueued CSS\u002FJS, and the same inside inline CSS.\u003C\u002Fli>\n\u003Cli>Version classes on the \u003Ccode>\u003Cbody>\u003C\u002Fcode> tag (e.g. page-builder version classes).\u003C\u002Fli>\n\u003Cli>Plugin-emitted \u003Ccode>\u003Cmeta name=\"generator\">\u003C\u002Fcode> tags.\u003C\u002Fli>\n\u003Cli>Plugin version strings in HTML comments (e.g. SEO plugins).\u003C\u002Fli>\n\u003Cli>Static version files served directly by the web server — \u003Ccode>readme.txt\u003C\u002Fcode>, \u003Ccode>changelog.txt\u003C\u002Fcode>, \u003Ccode>release_log.html\u003C\u002Fcode> — and version banner comments in CSS\u002FJS assets. In Obfuscate these are blocked (Apache\u002FLiteSpeed \u003Ccode>.htaccess\u003C\u002Fcode>, or an Nginx rule you add); in Decoy their version strings are rewritten and automatically reverted when you switch back.\u003C\u002Fli>\n\u003Cli>WordPress core \u003Ccode>readme.html\u003C\u002Fcode> \u002F \u003Ccode>license.txt\u003C\u002Fcode>, and the \u003Ccode>install.php\u003C\u002Fcode> \u002F \u003Ccode>upgrade.php\u003C\u002Fcode> setup pages (blocked for non-logged-in visitors so admins can still run updates).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Other hardening\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>XML-RPC\u003C\u002Fstrong> — disable and return 404, or keep it but remove pingback and \u003Ccode>system.multicall\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-Cron\u003C\u002Fstrong> — disable the HTTP pseudo-cron and block external hits to \u003Ccode>wp-cron.php\u003C\u002Fcode> (with an optional secret token for your system cron).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST user enumeration\u003C\u002Fstrong> — block the anonymous \u003Ccode>\u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode> endpoint.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Author enumeration\u003C\u002Fstrong> — block the \u003Ccode>?author=N\u003C\u002Fcode> redirect that leaks usernames.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Reversible\u003C\u002Fh4>\n\u003Cp>Setting a mode to \u003Cstrong>Off\u003C\u002Fstrong>, or deactivating the plugin, restores the real version strings and removes the \u003Ccode>.htaccess\u003C\u002Fcode> rules — the site returns to its normal state.\u003C\u002Fp>\n","Hide or decoy plugin, theme and core versions from scanners. Neutralize XML-RPC and lock down WP-Cron.",0,157,"2026-06-26T12:00:00.000Z","7.0.2","5.0","7.0",[18,19,20,21,22],"hardening","security","version","wp-cron","xml-rpc","https:\u002F\u002Fgithub.com\u002Fspiri439\u002Fwordpress_obfuscation","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fversion-cloak.1.0.4.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},2,30,94,"2026-08-28T23:30:23.965Z",[36,58,74,89,100],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":11,"num_ratings":11,"last_updated":46,"tested_up_to":47,"requires_at_least":48,"requires_php":49,"tags":50,"homepage":55,"download_link":56,"security_score":57,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"ab-wp-security","AB WP Security","1.51","abjelosevic","https:\u002F\u002Fprofiles.wordpress.org\u002Fabjelosevic\u002F","\u003Cp>Security plugin that stops User Enumeration in WordPress, removes WordPress Version Number, disable directory browsing and Disable XML-RPC\u003C\u002Fp>\n","Security plugin that stops User Enumeration in WordPress, removes WordPress Version Number, disable directory browsing and Disable XML-RPC",10,2743,"2017-06-18T19:17:00.000Z","4.8.28","3.8","",[51,52,53,54,19],"block","disable-xml-rpc","enumeration","remove-wordpress-version-number","http:\u002F\u002Faleksandar.bjelosevic.info\u002Fabwps","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fab-wp-security.1.51.zip",85,{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":44,"downloaded":66,"rating":25,"num_ratings":67,"last_updated":68,"tested_up_to":14,"requires_at_least":15,"requires_php":69,"tags":70,"homepage":49,"download_link":73,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"metadas-version-removal","Metadas Version Removal","1.1.1","metadas","https:\u002F\u002Fprofiles.wordpress.org\u002Fmetadas\u002F","\u003Cp>Metadas Version Removal is a fast, minimal, production ready plugin that strips WordPress version information from all common output locations. This helps reduce fingerprinting, hardens your site against automated scanners, and keeps your HTML clean.\u003C\u002Fp>\n\u003Cp>There is \u003Cstrong>no admin interface\u003C\u002Fstrong> and \u003Cstrong>no configuration required\u003C\u002Fstrong>. Activate the plugin and it immediately removes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress generator meta tag\u003C\u002Fli>\n\u003Cli>Version query strings from scripts and styles\u003C\u002Fli>\n\u003Cli>REST API discovery links\u003C\u002Fli>\n\u003Cli>oEmbed discovery links\u003C\u002Fli>\n\u003Cli>RSS generator tags\u003C\u002Fli>\n\u003Cli>Shortlink tags\u003C\u002Fli>\n\u003Cli>RSD (Really Simple Discovery) link\u003C\u002Fli>\n\u003Cli>Windows Live Writer manifest\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This plugin is intentionally small, efficient, and dependency free. It uses only core WordPress hooks and does not write to the database.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Removes all WordPress version output\u003C\u002Fli>\n\u003Cli>Zero configuration activate and you’re done\u003C\u002Fli>\n\u003Cli>Lightweight class based architecture\u003C\u002Fli>\n\u003Cli>No database usage\u003C\u002Fli>\n\u003Cli>No UI, no clutter\u003C\u002Fli>\n\u003Cli>Safe for caching and CDN setups\u003C\u002Fli>\n\u003Cli>Compatible with all themes and plugins\u003C\u002Fli>\n\u003C\u002Ful>\n","A lightweight, zero configuration plugin that removes all WordPress version output from your site for improved security and cleaner markup.",338,1,"2026-05-21T06:58:00.000Z","7.2",[71,18,72,19,20],"cleanup","remove-version","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmetadas-version-removal.1.1.1.zip",{"slug":75,"name":76,"version":77,"author":78,"author_profile":79,"description":80,"short_description":81,"active_installs":11,"downloaded":82,"rating":11,"num_ratings":11,"last_updated":83,"tested_up_to":14,"requires_at_least":15,"requires_php":84,"tags":85,"homepage":87,"download_link":88,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"janric-simple-attack-monitor","Janric Simple Attack Monitor","1.0.0","keithlunt","https:\u002F\u002Fprofiles.wordpress.org\u002Fkeithlunt\u002F","\u003Cp>Most security plugins try to do everything — firewall, blocking, malware scanning, email alerts — and end up bloated, slow, and full of upsells. Attack Monitor does one thing: it watches your site for common attack patterns and quietly logs them, so you always know what’s being thrown at your site.\u003Cbr \u002F>\nWhat it detects\u003C\u002Fp>\n\u003Cp>Brute force login attempts\u003Cbr \u002F>\nXML-RPC abuse (including system.multicall floods)\u003Cbr \u002F>\nUser enumeration via ?author= and the REST API\u003Cbr \u002F>\nAdmin area probing by unauthenticated visitors\u003Cbr \u002F>\nPath and plugin scanning (phpinfo.php, .env, phpmyadmin, wp-config.php and more)\u003Cbr \u002F>\nSQL injection attempts in URLs and POST data\u003Cbr \u002F>\nXSS attempts in URLs and POST data\u003Cbr \u002F>\nComment flooding\u003C\u002Fp>\n\u003Cp>What you get\u003C\u002Fp>\n\u003Cp>A dashboard widget showing this week’s attacks by category at a glance\u003Cbr \u002F>\nA full log page with day \u002F week \u002F 30-day \u002F all-time views\u003Cbr \u002F>\nA bar chart of attack volume over time\u003Cbr \u002F>\nTop attacking IPs ranked by hit count\u003Cbr \u002F>\nFilterable event log with timestamps, IPs, URLs and detail\u003Cbr \u002F>\nSafe IP whitelist — exclude your own monitoring tools, cron jobs or office IP ranges\u003Cbr \u002F>\nCIDR range support (e.g. 192.168.1.0\u002F24) for the whitelist\u003Cbr \u002F>\nA single lightweight database table — nothing else added to your WordPress installation\u003C\u002Fp>\n\u003Cp>Philosophy\u003Cbr \u002F>\nDetection and blocking are separate concerns. This plugin handles detection only, leaving you free to choose how you respond — whether that’s Fail2ban, Cloudflare, a companion blocking plugin, or simply reviewing the data. No firewall rules are added, no requests are blocked or slowed down, and no data is sent anywhere outside your own database.\u003Cbr \u002F>\nIdeal for developers, agencies and site owners who want visibility without handing over control to an all-in-one security suite.\u003C\u002Fp>\n","Lightweight attack detection for WordPress. Logs brute force, XML-RPC abuse, SQL injection, XSS attempts and more. No bloat, no blocking — just data.",87,"2026-06-15T16:11:00.000Z","7.4",[18,86,19,22],"rest-api","https:\u002F\u002Fjanricshield.com\u002Fjanric-attack-monitor.php","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fjanric-simple-attack-monitor.1.0.0.zip",{"slug":90,"name":91,"version":77,"author":78,"author_profile":79,"description":92,"short_description":93,"active_installs":11,"downloaded":94,"rating":11,"num_ratings":11,"last_updated":95,"tested_up_to":96,"requires_at_least":15,"requires_php":84,"tags":97,"homepage":98,"download_link":99,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"janric-simple-security-hardening","Janric Simple Security Hardening","\u003Cp>A lightweight plugin that disables XML-RPC, restricts the REST API to logged-in users, and hides the WordPress version number\u003C\u002Fp>\n","A lightweight plugin to disable XML-RPC, restrict the REST API, and hide the WordPress version.",118,"2026-05-20T14:01:00.000Z","6.9.5",[18,86,19,22],"https:\u002F\u002Fjanric.co.uk\u002Fjanric_simple_hardening.php","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fjanric-simple-security-hardening.1.0.0.zip",{"slug":101,"name":102,"version":77,"author":103,"author_profile":104,"description":105,"short_description":106,"active_installs":11,"downloaded":107,"rating":11,"num_ratings":11,"last_updated":108,"tested_up_to":109,"requires_at_least":110,"requires_php":84,"tags":111,"homepage":49,"download_link":114,"security_score":115,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":116},"pf-secure-toolkit","PF Secure Toolkit","Poet Farmer","https:\u002F\u002Fprofiles.wordpress.org\u002Fpoetfarmer\u002F","\u003Cp>PF Secure Toolkit helps you secure your site by turning off WordPress components you may not need or want exposed.\u003C\u002Fp>\n\u003Cp>Features include:\u003Cbr \u002F>\n* Disable Author Archives (301 redirect + remove users sitemap).\u003Cbr \u002F>\n* Disable Comments site-wide (removes UI, blocks REST, hides existing).\u003Cbr \u002F>\n* Disable WP Emojis (scripts, styles, TinyMCE, email\u002FRSS, CDN prefetch).\u003Cbr \u002F>\n* Disable XML-RPC (removes headers, blocks pingback methods).\u003Cbr \u002F>\n* Quick toggle settings in the admin panel.\u003C\u002Fp>\n","PF Secure Toolkit is a lightweight, modular plugin to harden WordPress by disabling unnecessary features.",297,"2025-08-27T10:54:00.000Z","6.8.5","5.6",[112,113,18,19,22],"comments","emojis","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpf-secure-toolkit.1.0.0.zip",92,"2026-04-16T10:56:18.058Z",{"error":118,"url":119,"statusCode":120,"statusMessage":121,"message":121},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fversion-cloak\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":123,"versions":124},4,[125,131,138,145],{"version":6,"download_url":24,"svn_tag_url":126,"released_at":26,"has_diff":127,"diff_files_changed":128,"diff_lines":26,"trac_diff_url":129,"vulnerabilities":130,"is_current":118},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fversion-cloak\u002Ftags\u002F1.0.4\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fversion-cloak%2Ftags%2F1.0.3&new_path=%2Fversion-cloak%2Ftags%2F1.0.4",[],{"version":132,"download_url":133,"svn_tag_url":134,"released_at":26,"has_diff":127,"diff_files_changed":135,"diff_lines":26,"trac_diff_url":136,"vulnerabilities":137,"is_current":127},"1.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fversion-cloak.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fversion-cloak\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fversion-cloak%2Ftags%2F1.0.2&new_path=%2Fversion-cloak%2Ftags%2F1.0.3",[],{"version":139,"download_url":140,"svn_tag_url":141,"released_at":26,"has_diff":127,"diff_files_changed":142,"diff_lines":26,"trac_diff_url":143,"vulnerabilities":144,"is_current":127},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fversion-cloak.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fversion-cloak\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fversion-cloak%2Ftags%2F1.0.1&new_path=%2Fversion-cloak%2Ftags%2F1.0.2",[],{"version":146,"download_url":147,"svn_tag_url":148,"released_at":26,"has_diff":127,"diff_files_changed":149,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":150,"is_current":127},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fversion-cloak.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fversion-cloak\u002Ftags\u002F1.0.1\u002F",[],[]]