[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgNHYfsGnKZ5NkhNiD-jFsztjsJFyaNG3CmDSLfYKBYw":3,"$fLFH5CCbrzdLKZNbY7v6T0vZ7-qsvYHo6H-8Szk_S1Ks":124,"$f4YLeO8_-8A13FYG31hSFdaGwk6Wk4BWEkuIebeRsGK4":129},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"visitor-sentinel","Visitor Sentinel","2.1.1","byot","https:\u002F\u002Fprofiles.wordpress.org\u002Fbyot\u002F","\u003Cp>Visitor Sentinel is a security and traffic analysis plugin for WordPress. It combines real-time attack detection with an active deception layer, so an attacker is not just noticed — they are lured into giving themselves away.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Records site visits (IP, page visited, user-agent, device\u002Fbrowser, account type).\u003C\u002Fli>\n\u003Cli>Analyzes every request in real time using multiple heuristics: unusual request rate, user-agent associated with scanning\u002Fattack tools, requests to sensitive resources (wp-config.php, .env, .git, etc.), repeated failed logins, credential-stuffing patterns, XML-RPC abuse, invisible honeypot fields on login\u002Fcomment forms, submission-timing checks, and scanning of non-existent pages (404).\u003C\u002Fli>\n\u003Cli>Calculates a risk score per IP address and permanently blocks it once the score exceeds the configured threshold — sheer browsing volume alone never triggers a block, only genuine attack\u002Fbot\u002Fspam signals do.\u003C\u002Fli>\n\u003Cli>Blocks are permanent by design and apply everywhere on the site (the full-page cache, if any, is purged automatically on every block). Lifting one requires a signed declaration, kept permanently in History.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Deception layer (honeypots & honeytokens)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A decoy backup file (honeyfile) at a random, unlinked URL — any access to it is conclusive proof of directory scanning.\u003C\u002Fli>\n\u003Cli>A decoy admin username that was never a real account — any login attempt against it is an instant, certain block.\u003C\u002Fli>\n\u003Cli>A decoy REST endpoint that hands out a fake API key — using that key anywhere is what triggers the block, not merely finding it.\u003C\u002Fli>\n\u003Cli>A hidden spam-trap email address planted only where scrapers read markup — if it ever comes back in a submitted form, that visitor harvested this exact site.\u003C\u002Fli>\n\u003Cli>Every one of these bypasses the normal scoring threshold entirely: interacting with any of them is treated as certain malicious intent, not a “maybe.”\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Management & visibility\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Optional email alerts whenever an IP is blocked or escalated, and one-click CSV export of the blocked IPs list.\u003C\u002Fli>\n\u003Cli>A complete control panel: a live dashboard, an auto-refreshing visitor log, a list of blocked IPs with details about the block reason, and options to unblock, extend, or change the block type (temporary\u002Fpermanent).\u003C\u002Fli>\n\u003Cli>Displays, to logged-in users and optionally guests, a discreet badge showing how many people are on the site right now, updating live in the browser without a page reload.\u003C\u002Fli>\n\u003Cli>Fully responsive admin panel, usable on desktop, tablet, and phone.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All text is translation-ready. The plugin loads no external resources (CDN) and does not enable any third-party tracking. The only optional external call is described in the FAQ below, and it is off by default.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to one third-party service, and only for a single, optional, off-by-default feature:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP-to-country lookup (ip-api.com)\u003C\u002Fstrong> — used only if you explicitly enable “Show country flags next to IPs” in Settings. When enabled, and only then, each new IP address seen by the plugin is sent to ip-api.com so it can look up which country it belongs to. Nothing else about the visitor (no page content, no personal data, no credentials) is sent. Results are cached locally for 30 days so the same IP is never looked up twice. If you never enable this setting, the plugin makes no external requests at all.\u003C\u002Fp>\n\u003Cp>Service provided by ip-api.com: \u003Ca href=\"https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n","Monitors your site's visitors, automatically detects bots and attackers, plants decoy honeypots, and blocks problematic IPs.",0,185,"2026-07-16T14:46:00.000Z","7.0.2","5.8","7.4",[18,19,20,21,22],"ban-ip","bot-protection","firewall","honeypot","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fvisitor-sentinel\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.2.1.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},1,30,94,"2026-08-29T07:14:53.625Z",[36,54,75,91,106],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":25,"num_ratings":46,"last_updated":47,"tested_up_to":14,"requires_at_least":48,"requires_php":16,"tags":49,"homepage":52,"download_link":53,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"waf-security-suite-for-cloudflare","Cloud Maestro – WAF Security Suite for Cloudflare","1.4","5 Star Plugins (Rob)","https:\u002F\u002Fprofiles.wordpress.org\u002F5starplugins\u002F","\u003Cp>Cloud Maestro brings centralized Cloudflare Web Application Firewall (WAF) controls directly into WordPress.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why would I use a plugin when I can create rules in Cloudflare?\u003C\u002Fstrong>\u003Cbr \u002F>\nIf you manage multiple Cloudflare-connected sites, Cloud Maestro is a productivity tool that helps oversee several domains from a central dashboard using WordPress. If you only manage one domain in Cloudflare, you wouldn’t benefit from this plugin.\u003C\u002Fp>\n\u003Cp>It’s useful for someone managing:\u003Cbr \u002F>\n– Their own sites and client sites\u003Cbr \u002F>\n– Multiple businesses\u003Cbr \u002F>\n– Separate Cloudflare accounts\u003C\u002Fp>\n\u003Cp>People like using Cloud Maestro because configuring security rules one domain at a time is inefficient and error-prone. It allows you to configure WAF rules once and deploy them consistently across all domains in your Cloudflare account — instantly.\u003C\u002Fp>\n\u003Cp>The free version supports one Cloudflare account with multiple domains.\u003C\u002Fp>\n\u003Cp>An optional premium version is available for managing unlimited domains across multiple Cloudflare accounts at once.\u003C\u002Fp>\n\u003Ch3>🛡️ Why Use Cloud Maestro – WAF Security Suite for Cloudflare?\u003C\u002Fh3>\n\u003Cp>Managing security rules across multiple Cloudflare domains is tedious and time-consuming. This plugin streamlines the process, allowing you to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Deploy in One Click\u003C\u002Fstrong> – Apply comprehensive WAF rules to multiple domains simultaneously\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Save Time\u003C\u002Fstrong> – No more manually configuring rules on each domain, one at a time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enterprise Security\u003C\u002Fstrong> – Protect against bots, aggressive crawlers, malicious IPs, and common threats\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reduce Mistakes\u003C\u002Fstrong> – Maintain consistent security rules across domains\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>✅ Free Standard Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>One Cloudflare account\u003C\u002Fli>\n\u003Cli>Multiple domains\u003C\u002Fli>\n\u003Cli>One-click WAF rule deployment\u003C\u002Fli>\n\u003Cli>Centralized Cloudflare controls\u003C\u002Fli>\n\u003Cli>Secure API credential storage (AES-256-CBC encryption)\u003C\u002Fli>\n\u003Cli>Plugin updates\u003Cbr \u002F>\nThe free plugin does not require an upgrade.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔥 What Gets Protected\u003C\u002Fh3>\n\u003Cp>The plugin deploys \u003Cstrong>3 optimized trusted security rules\u003C\u002Fstrong> (prior versions used 5) that work together to protect your sites:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Good Bot Allowlist\u003C\u002Fstrong> – Ensures legitimate bots (Google, Bing, monitoring tools) can access your site\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Managed Challenges for Suspicious Traffic\u003C\u002Fstrong> – Automatically challenges requests from certain ASNs and non-US traffic\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Aggressive Crawler Protection\u003C\u002Fstrong> – Blocks unauthorized crawlers and bots (Yandex, Semrush, Ahrefs, etc.)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>VPN & Login Protection\u003C\u002Fstrong> – Adds extra challenges for VPN traffic and WordPress login attempts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block Known Threats\u003C\u002Fstrong> – Automatically blocks web hosts, malicious IPs, TOR nodes, and attack vectors\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>✨ Premium Upgrade (Optional)\u003C\u002Fh3>\n\u003Cp>For agencies and professionals managing multiple Cloudflare accounts, a Premium version is available with expanded functionality and tech support. \u003Cstrong>\u003Ca href=\"https:\u002F\u002F5starplugins.com\u002Fcloud-maestro-cloudflare-waf-rules\u002F\" rel=\"nofollow ugc\">Check out our free trial\u003C\u002Fa>\u003C\u002Fstrong> for these features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Multi-Account Management\u003C\u002Fstrong> – Automatically manage domains across ALL your Cloudflare accounts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Easy Bot Whitelisting\u003C\u002Fstrong> – Built-in checkboxes for 50+ trusted services across 8 categories\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom User Agents\u003C\u002Fstrong> – Add your own user agent strings to the Good Bot Rule\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom IP Whitelisting\u003C\u002Fstrong> – Add trusted IP addresses to the Goot Bot Rule\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Rules management\u003C\u002Fstrong> – View and edit Cloudflare’s IP Rules that block or allow access even before hitting WAF rules (and we are working on connecting to fail2ban and Wordfence blocks)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk DNS Management\u003C\u002Fstrong> – Search and manage DNS records across all domains, bulk migrate IP addresses, CNAME targets, and convert A records to CNAME with a single action\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Priority Support\u003C\u002Fstrong> – Get expert help when you need it\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Customization\u003C\u002Fstrong> – Fine-tune rules to match your exact requirements\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Account Management\u003C\u002Fstrong> – Centrally manage unlimited domains across all your Cloudflare accounts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📋 Important Information\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Rule Replacement:\u003C\u002Fstrong> This plugin replaces existing custom WAF rules on targeted domains. Make sure to back up any custom rules you want to keep.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Compatibility:\u003C\u002Fstrong> Works with Cloudflare Free, Pro, and Business plans. Not compatible with Enterprise plans managed by hosting providers.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Service Monitoring:\u003C\u002Fstrong> These rules might challenge some monitoring or uptime services. Check Cloudflare’s Events log if services stop connecting, and add exceptions as needed.\u003C\u002Fp>\n","Bulk deploy powerful WAF security rules to multiple Cloudflare domains with one click. Protect your sites from bots, malicious traffic, and threats.",50,1445,4,"2026-06-23T04:57:00.000Z","6.0",[19,50,20,22,51],"cloudflare","waf-rules","https:\u002F\u002F5starplugins.com\u002Fcloud-maestro-cloudflare-waf-rules\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwaf-security-suite-for-cloudflare.1.4.zip",{"slug":55,"name":56,"version":57,"author":58,"author_profile":59,"description":60,"short_description":61,"active_installs":62,"downloaded":63,"rating":25,"num_ratings":64,"last_updated":65,"tested_up_to":66,"requires_at_least":67,"requires_php":68,"tags":69,"homepage":68,"download_link":72,"security_score":73,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":74},"botfirewall","BotFirewall | Stop Spam Bots & Secure Login","2.3.5","SafeWeb","https:\u002F\u002Fprofiles.wordpress.org\u002Fhallemmit3\u002F","\u003Cp>\u003Cstrong>BotFirewall\u003C\u002Fstrong> is a powerful and modern plugin designed to protect your WordPress site from malicious bots, spam, and DDoS attacks. Using advanced JavaScript verification and encrypted cookies, BotFirewall ensures robust security without disrupting the experience of real users.\u003C\u002Fp>\n\u003Ch3>Why Do You Need BotFirewall?\u003C\u002Fh3>\n\u003Cp>In today’s internet landscape, bots make up a significant portion of web traffic, and many of them are malicious. They can attack your site, send spam, scrape content, or attempt to hack login pages like \u003Ccode>wp-login.php\u003C\u002Fcode>. BotFirewall addresses these threats by providing \u003Cstrong>smart and flexible protection\u003C\u002Fstrong> that:\u003Cbr \u002F>\n– \u003Cstrong>Blocks bots\u003C\u002Fstrong> with seamless JavaScript verification that most bots cannot pass.\u003Cbr \u002F>\n– \u003Cstrong>Secures key pages\u003C\u002Fstrong> like \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-signup.php\u003C\u002Fcode> from unauthorized access.\u003Cbr \u002F>\n– \u003Cstrong>Uses encrypted cookies\u003C\u002Fstrong> to ensure only verified users gain access.\u003Cbr \u002F>\n– \u003Cstrong>Offers customizable settings\u003C\u002Fstrong> through an intuitive interface in the WordPress admin panel.\u003C\u002Fp>\n\u003Ch3>Key Features of BotFirewall\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>JavaScript Verification\u003C\u002Fstrong>: Ensures visitors can execute JavaScript, effectively filtering out most bots.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Encrypted Cookies\u003C\u002Fstrong>: Cookies are tied to IP and User-Agent for enhanced security against spoofing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Page Protection\u003C\u002Fstrong>: Enable or disable protection for \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-signup.php\u003C\u002Fcode> pages via settings.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Whitelist and Blacklist\u003C\u002Fstrong>: Configure lists of allowed bots (e.g., Googlebot) and IPs, and block known malicious IPs, including subnet support (e.g., 192.168.0.0\u002F24).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Exclude URLs\u003C\u002Fstrong>: Specify URLs to bypass bot protection entirely (e.g., for APIs or specific pages).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time Statistics\u003C\u002Fstrong>: Monitor bot activity with detailed stats – filter by time periods (Last 24 hours, Last Week, Last Month).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action Logging\u003C\u002Fstrong>: Logs blocks and successful verifications with URL details, keeping data for the last 30 days.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allowed Bots Tab\u003C\u002Fstrong>: Easily select known bots to allow without verification, with quick filters for bot types.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recent Activity\u003C\u002Fstrong>: View the latest 10 logged sessions with details like IP, URL, and status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight and Fast\u003C\u002Fstrong>: Optimized for minimal impact on site performance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Clean Uninstall\u003C\u002Fstrong>: Removes all data, including logs and settings, upon deactivation and deletion.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable Verification Page\u003C\u002Fstrong>: Tailor the text (title, description, countdown), CSS styling, and logo of the verification page to match your site’s design.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhanced Support\u003C\u002Fstrong>: Get assistance directly through Live Chat in the Support tab for quick resolution of issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How Does BotFirewall Work?\u003C\u002Fh3>\n\u003Cp>BotFirewall employs a multi-layered protection system:\u003Cbr \u002F>\n1. \u003Cstrong>Cookie Check\u003C\u002Fstrong>: If a visitor has a valid cookie, they bypass additional checks.\u003Cbr \u002F>\n2. \u003Cstrong>Whitelist\u003C\u002Fstrong>: Known “good” bots (e.g., search engine crawlers) are automatically allowed.\u003Cbr \u002F>\n3. \u003Cstrong>JavaScript Verification\u003C\u002Fstrong>: If no cookie is present, the visitor is redirected to a verification page where they must execute a JavaScript request. Bots unable to run JavaScript are blocked.\u003Cbr \u002F>\n4. \u003Cstrong>Login Page Protection\u003C\u002Fstrong>: Optionally protect \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-signup.php\u003C\u002Fcode> to prevent brute-force attacks.\u003Cbr \u002F>\n5. \u003Cstrong>Post-Verification Redirect\u003C\u002Fstrong>: After successful verification, the user is redirected to their original page, and a cookie is set for future visits.\u003C\u002Fp>\n\u003Ch3>Why BotFirewall is a Must-Have for Your Site\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Spam and DDoS Protection\u003C\u002Fstrong>: Effectively blocks bots that attempt to spam or overload your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login Security\u003C\u002Fstrong>: Safeguards \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>wp-signup.php\u003C\u002Fcode> from unauthorized access and brute-force attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexibility\u003C\u002Fstrong>: Customize protection with whitelists, blacklists, cookie lifetime settings, and verification page styling.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Transparency\u003C\u002Fstrong>: Detailed statistics and logs let you monitor bot activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ease of Use\u003C\u002Fstrong>: A user-friendly interface in the WordPress admin panel makes configuration a breeze.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Professional Look\u003C\u002Fstrong>: Customize the verification page with your own text, styles, logo, and a modern font (Roboto) for a polished appearance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reliable Support\u003C\u002Fstrong>: Access our support team via Live Chat for help with any technical or security issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>BotFirewall is an \u003Cstrong>essential tool\u003C\u002Fstrong> for WordPress site owners who want to protect their content, users, and server from malicious bots. Install BotFirewall today and secure your site with confidence!\u003C\u002Fp>\n","BotFirewall is a powerful and modern plugin designed to protect your WordPress site from malicious bots, spam, and DDoS attacks.",20,738,2,"2025-06-05T14:29:00.000Z","6.8.5","5.0","",[70,19,20,71,22],"anti-bot","login-protection","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbotfirewall.2.3.5.zip",92,"2026-03-15T15:16:48.613Z",{"slug":76,"name":77,"version":78,"author":79,"author_profile":80,"description":81,"short_description":82,"active_installs":11,"downloaded":83,"rating":25,"num_ratings":31,"last_updated":84,"tested_up_to":14,"requires_at_least":85,"requires_php":86,"tags":87,"homepage":89,"download_link":90,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"botfend-anti-bot-firewall","BotFend Anti-Bot Firewall","4.9.1","Omajemite Don","https:\u002F\u002Fprofiles.wordpress.org\u002Fejesgist\u002F","\u003Cp>BotFend Anti-Bot Firewall is a professional-grade WordPress security suite designed to stop automated attacks, malicious bots, and brute-force attempts before they consume your server resources. Built with a high-performance V4 architecture, it features a smart aggregation engine and an early-loading Web Application Firewall (WAF) that neutralizes threats at the server level.\u003C\u002Fp>\n\u003Cp>Developed by Omajemite Don, BotFend protects your site without slowing it down.\u003C\u002Fp>\n\u003Ch3>Core Features:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Advanced Web Application Firewall (WAF):\u003C\u002Fstrong> Uses \u003Ccode>auto_prepend_file\u003C\u002Fcode> via \u003Ccode>.htaccess\u003C\u002Fcode> or \u003Ccode>.user.ini\u003C\u002Fcode> to block attacks before WordPress even loads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Intelligent Bot Detection:\u003C\u002Fstrong> Identifies and blocks malicious bots, crawlers, and scrapers using advanced signature detection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Behavioral Analysis:\u003C\u002Fstrong> Monitors visitor behavior patterns to detect and block automated threats that mimic human activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Browser Fingerprinting:\u003C\u002Fstrong> Generates unique browser fingerprints to track and identify persistent attackers across sessions and IP changes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced 404 Detection:\u003C\u002Fstrong> Detects and blocks malicious path scanning, vulnerability probing, and excessive 404 abuse patterns.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress Protection:\u003C\u002Fstrong> Comprehensive protection against XML-RPC attacks, REST API abuse, author scanning, and WordPress-specific vulnerabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Signature Detection:\u003C\u002Fstrong> Real-time pattern matching against known attack signatures and malicious payloads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Log Aggregation:\u003C\u002Fstrong> High-performance database architecture that centralizes logging to prevent database bloat and memory crashes, even under heavy attack.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Perpetual Offender Tracking:\u003C\u002Fstrong> Automatically upgrades temporary bans to permanent blocks for IPs that repeatedly attack your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time Threat Intelligence:\u003C\u002Fstrong> Integrates with external databases to verify IP reputations on the fly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tor Node Blocking:\u003C\u002Fstrong> Automatically detects and blocks malicious traffic originating from the Tor anonymity network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comprehensive UI:\u003C\u002Fstrong> Clean, intuitive WordPress admin interface with bulk actions, detailed threat analysis timelines, and visual statistics.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Pro Features (Available with License):\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Full Firewall Auto Prepend:\u003C\u002Fstrong> Execute firewall protection at the earliest possible stage of WordPress execution\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare Integration:\u003C\u002Fstrong> Synchronize blocked IPs to Cloudflare firewall rules at the edge, blocking attacks before they reach your server\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>IMPORTANT: All external services are DISABLED BY DEFAULT. You must explicitly enable each service in the plugin settings before any data is sent.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin can connect to the following external services to provide enhanced threat protection. No data is sent unless you explicitly enable these features.\u003C\u002Fp>\n\u003Ch3>1. AbuseIPDB API\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Checks the reputation of suspicious IP addresses against a global database of reported abusers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> The IP address of the visitor being checked\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When AbuseIPDB integration is enabled AND an IP address needs verification (cached for 24 hours)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable AbuseIPDB” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fwww.abuseipdb.com\u002Flegal\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fwww.abuseipdb.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>2. IPHub API\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Detects VPNs, proxies, and non-residential IP addresses\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> The IP address of the visitor being checked\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When IPHub integration is enabled (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable IPHub” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fiphub.info\u002Flegal\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fiphub.info\u002Flegal\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>3. IP Geolocation Services\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Determine the country of origin for IP addresses to apply geographic blocking rules\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> The IP address of the visitor being geolocated\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When geolocation is enabled (default: OFF) AND an IP needs geolocation (results cached)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable IP Geolocation” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Services used:\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>ip-api.com\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Primary geolocation service\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fip-api.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fip-api.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>ipapi.co\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Fallback geolocation service\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fipapi.co\u002Fterms\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fipapi.co\u002Fprivacy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>ipwhois.io\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Secondary fallback geolocation service\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fipwhois.io\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fipwhois.io\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>4. Tor Project Exit List\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Downloads the official list of active Tor exit nodes to block anonymous attacks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> None (only downloads a public list)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> Every 6 hours when Tor blocking is enabled (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable Tor Blocking” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fcheck.torproject.org\u002Ftorbulkexitlist\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Use:\u003C\u002Fstrong> https:\u002F\u002Fwww.torproject.org\u002Fabout\u002Ftrademark\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fwww.torproject.org\u002Fabout\u002Fprivacy_policy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>5. dan.me.uk Tor List (Alternative Source)\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Alternative source for Tor exit node list when primary source is unavailable\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> None (only downloads a public list)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> Only used as fallback when primary Tor list fails and Tor blocking is enabled\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Disable Tor blocking in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fwww.dan.me.uk\u002Ftorlist\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms\u002FPrivacy:\u003C\u002Fstrong> This is a public service with no formal terms or privacy policy. Use is governed by standard HTTP protocol.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>6. Threat Intelligence Feeds\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Download curated lists of known malicious IP addresses\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> None (only downloads public blocklists)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When threat intelligence is enabled (default: OFF) and feeds need refreshing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set “Enable Threat Intelligence” to OFF in plugin settings (default: OFF)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Feeds used:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>\u003Cstrong>FireHOL:\u003C\u002Fstrong> https:\u002F\u002Ffirehol.org\u002F (Public domain blocklists)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocklist.de:\u003C\u002Fstrong> https:\u002F\u002Fwww.blocklist.de\u002F (Terms: https:\u002F\u002Fwww.blocklist.de\u002Fen\u002Fterms.html)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Emerging Threats (Proofpoint):\u003C\u002Fstrong> Real-time threat intelligence feeds\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms:\u003C\u002Fstrong> https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Flegal\u002Flicense\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy:\u003C\u002Fstrong> https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Flegal\u002Fprivacy-policy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>7. Google reCAPTCHA\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Provides bot verification on login, registration, and comment forms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> Browser interaction data sent to Google’s servers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> When reCAPTCHA is enabled AND a user interacts with a protected form\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Set reCAPTCHA site key and secret key to empty in plugin settings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>8. Cloudflare API Integration (PRO VERSION)\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> Synchronize blocked IPs to Cloudflare firewall rules at the edge, blocking attacks before they reach your server\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data sent:\u003C\u002Fstrong> IP addresses, threat scores, authentication credentials, and configuration parameters during API calls\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When:\u003C\u002Fstrong> During manual sync operations, scheduled automatic syncs, and license validation\u003C\u002Fli>\n\u003Cli>\u003Cstrong>How to disable:\u003C\u002Fstrong> Available only in Pro version with valid license\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> https:\u002F\u002Fwww.cloudflare.com\u002Fterms\u002F\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fwww.cloudflare.com\u002Fprivacypolicy\u002F\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Data Handling Summary\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>No data is sent to any external service unless you explicitly enable that feature\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>All API results are cached\u003C\u002Fstrong> to minimize external requests\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Regular visitor IPs are never sent\u003C\u002Fstrong> – only suspicious or attacking IPs trigger external lookups\u003C\u002Fli>\n\u003Cli>\u003Cstrong>You can disable ALL external services\u003C\u002Fstrong> in the plugin settings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin works perfectly with all external services disabled\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin respects user privacy:\u003Cbr \u002F>\n– No tracking of regular site visitors\u003Cbr \u002F>\n– No analytics or usage data collected\u003Cbr \u002F>\n– All external services are opt-in (disabled by default)\u003Cbr \u002F>\n– Full transparency: All external service calls are documented above\u003C\u002Fp>\n","Professional security plugin protecting WordPress from malicious bots, spam, and server attacks using an advanced Web Application Firewall.",276,"2026-05-21T16:41:00.000Z","6.4","8.0",[19,20,22,88],"spam-protection","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbotfend-anti-bot-firewall\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbotfend-anti-bot-firewall.4.9.1.zip",{"slug":92,"name":93,"version":94,"author":95,"author_profile":96,"description":97,"short_description":98,"active_installs":11,"downloaded":99,"rating":11,"num_ratings":11,"last_updated":100,"tested_up_to":101,"requires_at_least":67,"requires_php":16,"tags":102,"homepage":68,"download_link":105,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"bunkr-solution","Bunkr Solution","1.0.0","Bunkr","https:\u002F\u002Fprofiles.wordpress.org\u002Fyfel\u002F","\u003Cp>Bunkr Solution provides enterprise-grade bot protection for your WordPress site through sophisticated server-side analysis.\u003C\u002Fp>\n\u003Cp>Key Features:\u003Cbr \u002F>\n* Real-time behavioral analysis\u003Cbr \u002F>\n* Advanced bot detection\u003Cbr \u002F>\n* Seamless user experience for legitimate visitors\u003Cbr \u002F>\n* Enterprise-grade protection\u003Cbr \u002F>\n* Easy integration with WordPress\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the Bunkr API service to analyze website traffic and provide bot protection. Here’s what you need to know:\u003C\u002Fp>\n\u003Ch4>Service Information\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service\u003C\u002Fstrong>: Bunkr Bot Protection API (https:\u002F\u002Fwpde.bunkr-solution.com)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Real-time analysis of website requests to identify and block malicious bot traffic\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Provider\u003C\u002Fstrong>: Bunkr Solution (https:\u002F\u002Fbunkr-solution.com)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Data Transmission\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>When data is sent\u003C\u002Fstrong>: Every time a non-admin user visits your website (excluding AJAX requests)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent\u003C\u002Fstrong>:\u003Cbr \u002F>\n* Request metadata: URL, HTTP method, referrer, timestamp\u003Cbr \u002F>\n* Server headers: User-Agent, Accept headers, security headers (Sec-* headers)\u003Cbr \u002F>\n* Network information: IP address, domain name\u003Cbr \u002F>\n* Browser context: Mobile detection, HTTPS status\u003Cbr \u002F>\n* Cookie analysis: Count and types of cookies (WordPress, session, persistent)\u003Cbr \u002F>\n* Request identifier: Unique request identifier\u003C\u002Fp>\n\u003Cp>\u003Cstrong>No sensitive data\u003C\u002Fstrong>: The plugin does not send form data, post content, user credentials, or personal information.\u003C\u002Fp>\n\u003Ch4>Legal Information\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Terms of Service\u003C\u002Fstrong>: https:\u002F\u002Fbunkr-solution.com\u002Fterms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy\u003C\u002Fstrong>: https:\u002F\u002Fbunkr-solution.com\u002Fprivacy\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>User Consent\u003C\u002Fh4>\n\u003Cp>By installing and activating this plugin, you acknowledge that:\u003Cbr \u002F>\n1. Request data will be sent to Bunkr’s servers for analysis\u003Cbr \u002F>\n2. This data transmission is necessary for the plugin’s bot protection functionality\u003Cbr \u002F>\n3. You have reviewed Bunkr’s terms of service and privacy policy\u003Cbr \u002F>\n4. You are responsible for informing your website users about this data processing if required by applicable privacy laws\u003C\u002Fp>\n","Advanced bot protection for WordPress using real-time behavioral analysis. Blocks malicious traffic while allowing legitimate users seamless access.",973,"2025-10-10T13:14:00.000Z","6.8.6",[103,19,104,20,22],"anti-spam","click-fraud","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbunkr-solution.1.0.2.zip",{"slug":107,"name":108,"version":109,"author":110,"author_profile":111,"description":112,"short_description":113,"active_installs":11,"downloaded":114,"rating":11,"num_ratings":11,"last_updated":115,"tested_up_to":116,"requires_at_least":117,"requires_php":16,"tags":118,"homepage":122,"download_link":123,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"esherpa-login-guard","eSherpa Login Guard","3.0.0","Ralf Naumann","https:\u002F\u002Fprofiles.wordpress.org\u002Fr2d3\u002F","\u003Cp>\u003Cstrong>eSherpa Login Guard\u003C\u002Fstrong> effectively and intelligently protects your WordPress site from brute-force attacks – Swiss precision, completely without external dependencies.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Honeypot-first bot defense\u003C\u002Fstrong>: JavaScript Honeypot detects non-browser bots and triggers immediate lockout logic.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Protected username trap\u003C\u002Fstrong>: Immediate lockout for defined usernames (e.g., “admin”, “test”), independent of the regular counter.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Proactive User-Agent blocking\u003C\u002Fstrong>: Block known bot signatures before login processing (exact match or substring mode).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Blocked User-Agent attempt log\u003C\u002Fstrong>: Separate log table for blocked User-Agent requests including matching pattern.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress hardening options\u003C\u002Fstrong>: Disable XML-RPC (with fake-user honeypot response), hide REST user endpoint, and block author archive enumeration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optional bot password capture\u003C\u002Fstrong>: Store attempted passwords from detected JS-honeypot bots for incident analysis.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Neutral login error option\u003C\u002Fstrong>: Hide username enumeration by using neutral WordPress login error responses.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Live security visibility\u003C\u002Fstrong>: Live alarm in admin, lockout badge in menu, and detailed failed-attempt logs with IP\u002FUser-Agent filters.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Progressive lockout durations\u003C\u002Fstrong>: Lockout time increases on repeat offenses (e.g., 15 \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> 30 \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> 60 \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> 120 minutes).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Login page guidance\u003C\u002Fstrong>: Clear countdown and “X attempts remaining” notice for transparent lock state.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy-compliant\u003C\u002Fstrong>: IPs stored only as anonymized hashes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic cleanup\u003C\u002Fstrong> of old failed attempts (configurable).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mobile-friendly admin tables\u003C\u002Fstrong>: Horizontal scrolling for wide security tables on small screens, including swipe hint.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email notification\u003C\u002Fstrong> to admin on attacks against existing users.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Developed in Switzerland – fast, clean, performant, and multilingual ready.\u003C\u002Fp>\n\u003Cp>Compatible with WordPress 6.9 and tested up to PHP 8.5.3.\u003C\u002Fp>\n","Intelligent login protection with honeypot detection, WordPress hardening, and a clear security admin overview.",384,"2026-03-03T08:32:00.000Z","6.9.5","5.6",[19,119,21,120,121],"brute-force-protection","login-security","wordpress-hardening","https:\u002F\u002Fesherpa.ch\u002Flogin-guard","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fesherpa-login-guard.3.0.0.zip",{"error":125,"url":126,"statusCode":127,"statusMessage":128,"message":128},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fvisitor-sentinel\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":130,"versions":131},16,[132,138,145,152,159,166,173,180,187,194,201,208,215,222,229,236],{"version":6,"download_url":24,"svn_tag_url":133,"released_at":26,"has_diff":134,"diff_files_changed":135,"diff_lines":26,"trac_diff_url":136,"vulnerabilities":137,"is_current":125},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F2.1.1\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F2.1.0&new_path=%2Fvisitor-sentinel%2Ftags%2F2.1.1",[],{"version":139,"download_url":140,"svn_tag_url":141,"released_at":26,"has_diff":134,"diff_files_changed":142,"diff_lines":26,"trac_diff_url":143,"vulnerabilities":144,"is_current":134},"2.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.2.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F2.1.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F2.0.0&new_path=%2Fvisitor-sentinel%2Ftags%2F2.1.0",[],{"version":146,"download_url":147,"svn_tag_url":148,"released_at":26,"has_diff":134,"diff_files_changed":149,"diff_lines":26,"trac_diff_url":150,"vulnerabilities":151,"is_current":134},"2.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.2.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F2.0.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.9.4&new_path=%2Fvisitor-sentinel%2Ftags%2F2.0.0",[],{"version":153,"download_url":154,"svn_tag_url":155,"released_at":26,"has_diff":134,"diff_files_changed":156,"diff_lines":26,"trac_diff_url":157,"vulnerabilities":158,"is_current":134},"1.9.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.9.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.9.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.8.2&new_path=%2Fvisitor-sentinel%2Ftags%2F1.9.4",[],{"version":160,"download_url":161,"svn_tag_url":162,"released_at":26,"has_diff":134,"diff_files_changed":163,"diff_lines":26,"trac_diff_url":164,"vulnerabilities":165,"is_current":134},"1.8.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.8.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.8.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.8.1&new_path=%2Fvisitor-sentinel%2Ftags%2F1.8.2",[],{"version":167,"download_url":168,"svn_tag_url":169,"released_at":26,"has_diff":134,"diff_files_changed":170,"diff_lines":26,"trac_diff_url":171,"vulnerabilities":172,"is_current":134},"1.8.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.8.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.8.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.8.0&new_path=%2Fvisitor-sentinel%2Ftags%2F1.8.1",[],{"version":174,"download_url":175,"svn_tag_url":176,"released_at":26,"has_diff":134,"diff_files_changed":177,"diff_lines":26,"trac_diff_url":178,"vulnerabilities":179,"is_current":134},"1.8.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.8.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.8.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.7.5&new_path=%2Fvisitor-sentinel%2Ftags%2F1.8.0",[],{"version":181,"download_url":182,"svn_tag_url":183,"released_at":26,"has_diff":134,"diff_files_changed":184,"diff_lines":26,"trac_diff_url":185,"vulnerabilities":186,"is_current":134},"1.7.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.7.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.7.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.7.4&new_path=%2Fvisitor-sentinel%2Ftags%2F1.7.5",[],{"version":188,"download_url":189,"svn_tag_url":190,"released_at":26,"has_diff":134,"diff_files_changed":191,"diff_lines":26,"trac_diff_url":192,"vulnerabilities":193,"is_current":134},"1.7.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.7.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.7.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.7.3&new_path=%2Fvisitor-sentinel%2Ftags%2F1.7.4",[],{"version":195,"download_url":196,"svn_tag_url":197,"released_at":26,"has_diff":134,"diff_files_changed":198,"diff_lines":26,"trac_diff_url":199,"vulnerabilities":200,"is_current":134},"1.7.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.7.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.7.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.7.2&new_path=%2Fvisitor-sentinel%2Ftags%2F1.7.3",[],{"version":202,"download_url":203,"svn_tag_url":204,"released_at":26,"has_diff":134,"diff_files_changed":205,"diff_lines":26,"trac_diff_url":206,"vulnerabilities":207,"is_current":134},"1.7.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.7.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.7.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.7.1&new_path=%2Fvisitor-sentinel%2Ftags%2F1.7.2",[],{"version":209,"download_url":210,"svn_tag_url":211,"released_at":26,"has_diff":134,"diff_files_changed":212,"diff_lines":26,"trac_diff_url":213,"vulnerabilities":214,"is_current":134},"1.7.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.7.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.7.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.7.0&new_path=%2Fvisitor-sentinel%2Ftags%2F1.7.1",[],{"version":216,"download_url":217,"svn_tag_url":218,"released_at":26,"has_diff":134,"diff_files_changed":219,"diff_lines":26,"trac_diff_url":220,"vulnerabilities":221,"is_current":134},"1.7.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.7.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.7.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.6.2&new_path=%2Fvisitor-sentinel%2Ftags%2F1.7.0",[],{"version":223,"download_url":224,"svn_tag_url":225,"released_at":26,"has_diff":134,"diff_files_changed":226,"diff_lines":26,"trac_diff_url":227,"vulnerabilities":228,"is_current":134},"1.6.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.6.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.6.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.6.1&new_path=%2Fvisitor-sentinel%2Ftags%2F1.6.2",[],{"version":230,"download_url":231,"svn_tag_url":232,"released_at":26,"has_diff":134,"diff_files_changed":233,"diff_lines":26,"trac_diff_url":234,"vulnerabilities":235,"is_current":134},"1.6.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.6.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.6.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fvisitor-sentinel%2Ftags%2F1.6.0&new_path=%2Fvisitor-sentinel%2Ftags%2F1.6.1",[],{"version":237,"download_url":238,"svn_tag_url":239,"released_at":26,"has_diff":134,"diff_files_changed":240,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":241,"is_current":134},"1.6.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvisitor-sentinel.1.6.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fvisitor-sentinel\u002Ftags\u002F1.6.0\u002F",[],[]]