Описание
WordPress security that protects your site — without selling out you or your visitors.
Brainwerk Security Suite is a modern, lightweight security plugin that keeps 100 % of your security data on your own server. No third-party cookies. No Google reCAPTCHA. No silent phone-home. Just clear, honest protection — 2FA, brute-force defense, file-integrity monitoring, a vulnerability scanner and a full audit trail — with privacy treated as a first-class feature, not an afterthought, and Multisite supported from day one.
🇪🇺 Made in Europe. Made for Europe.
Brainwerk Security Suite is the European answer for privacy-first WordPress security — the solution built in the EU, for the EU.
Engineered in the EU, to EU standards, with privacy-by-design built into every log line — never bolted on afterwards. Out of the box the plugin makes no outbound calls at all, so your security data never leaves your infrastructure and you stay in control of your users’ trust.
- Privacy-focused by default — IP anonymisation on by default (/24 for IPv4, /64 for IPv6), username pseudonymisation, configurable retention, one-click erasure, and a published data map you can paste straight into your privacy policy. These are technical data-minimisation measures; whether a consent banner is required depends on your configuration and jurisdiction and should be legally reviewed.
- Built for NIS2-era governance — everything self-hosted, auditable and under your control, with an audit trail to support your GDPR (Art. 32) and NIS2 data-governance obligations.
- No phone-home, ever, unless you ask — every external service is opt-in and off by default, and each is documented byte-for-byte in the External services section below. The default anti-bot is a 100 % local honeypot — no reCAPTCHA, no Google data transfer.
- High-tech under the hood — a SHA-256 integrity baseline over ~10k files, time-budgeted resumable cron sweeps, an explainable Z-score anomaly model with a per-user baseline, indexed tables and a transparent 0–100 threat score — all computed locally, no cloud.
Free features — defense in depth
Login & accounts
- Login activity log (success / failure / blocked)
- Brute-force protection: IP-based AND account-based (botnet rotates IPs, account stays locked)
- IP whitelist (single IPs and CIDR)
- TOTP two-factor authentication (RFC 6238) — works with Google Authenticator, Microsoft Authenticator, Authy, 2FAS, FreeOTP, Aegis. 8 single-use recovery codes per user. Force-by-role.
- Honeypot anti-bot on login / register / comment forms — 100% local, no reCAPTCHA, no Google data transfer.
- Custom login URL — rewrite wp-login.php to a path of your choice; the original returns 404. Lockout-recovery via wp-config define.
File integrity & malware
- SHA-256 file-integrity monitor over WP core, mu-plugins, plugins, and themes (default: ~10k files indexed). Daily wp-cron sweep detects added / changed / missing files.
- Pattern-based suspicious-code scan (16 rules) on every changed file:
eval(base64_decode(...)), webshell signatures (c99/r57/WSO/b374k), inlinewp_insert_user(role=admin),preg_replace /e, remote include via URL — runs only against deltas, not full corpus, so it stays cheap.
Vulnerability scanner
- Opt-in daily check (off by default) of every installed plugin / theme / core version against an EU-hosted vulnerability API (default
shieldforge-intel.brainwerk.at), which aggregates public sources (wpvulnerability.net, EUVD). No API key. The endpoint is configurable — point it at a self-hosted mirror. See External services below for exactly what is sent. - CVE-IDs and CVSS scores with direct links; flagged ACTIVE vs INACTIVE so you know which to update first.
Hardening
- One-click toggles: disable XML-RPC, hide WordPress version, block author enumeration, restrict REST API for anonymous visitors (users / comments / search / settings / themes / plugins endpoints).
- Security HTTP headers — per-header toggle: X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS.
- Content-Security-Policy with Report-Only mode for safe rollout — opt-in.
- Disable file editor in admin.
Detection
- 404 probing tracker (
.env,wp-config.bak,xmlrpc.phpand friends). - Anomaly detection — explainable Z-score model on login_hour / IP family / user-agent class, per-user adaptive baseline, no cloud calls.
- Audit trail — who changed what when: post edits, user changes, plugin/theme/core updates, security-sensitive option changes (siteurl, admin_email, users_can_register, default_role, network site_admins …). Useful for incident response and DSGVO Art. 32 compliance.
Admin experience
- WordPress dashboard widget with transparent threat score (0–100), action items, system-status strip, top attackers, recent events.
- Daily digest email with threat score, 24h-vs-7d trend, ASCII heatmap, top targeted usernames, top probing patterns, vulnerable-active-components — pure ASCII so it renders identically through every mail pipeline (php mail / SMTP / OAuth-SMTP / Microsoft Graph).
- Healthcheck banner — auto-detects setup issues (proxy IP masking, anonymization off, brute-force disabled) so admins can’t ship a broken config.
- Quiet hours that critical alerts can override.
Privacy & GDPR
- IP anonymization (default on, /24 for IPv4, /64 for IPv6), username pseudonymization, configurable log retention with daily cleanup, retroactive anonymization helper.
- Privacy-policy snippet generator (DE / EN).
- Multisite-aware: network-activate, per-site overrides, aggregate dashboard.
- Onboarding wizard in 6 languages — DE / EN / FR / IT / PL / ES, language picker as first step.
Go Pro
The Pro tier (a separate companion plugin) adds:
- WebAuthn / Passkeys (FIDO2)
- Geo-blocking with a regularly updated database
- Cloud threat-intelligence feed (EU-hosted, opt-in)
- Slack / Discord / Mattermost / Telegram / MS Teams notifications
- Aggregate Multisite dashboard for agencies
- Whitelabel mode and priority support
🇪🇺 Auf Deutsch — kurz & knapp
Die europäische Antwort für datenschutzfreundliche WordPress-Security — die Lösung aus der EU für die EU.
Brainwerk Security Suite ist die schlanke, moderne Security-Suite für WordPress, die 100 % deiner Security-Daten auf deinem eigenen Server behält. Keine Tracking-Cookies, kein Google reCAPTCHA, kein stilles Phone-Home — nur ehrlicher Schutz und volle Kontrolle. Datenschutz ist Kernfunktion, nicht nachträgliches Extra, und Multisite ist von Anfang an mitgedacht.
- Made in Europe, made for Europe — in der EU nach EU-Standards entwickelt, Privacy-by-Design in jeder Logzeile
- DSGVO-ready ab Werk — IP-Anonymisierung standardmäßig an, Pseudonymisierung, konfigurierbare Aufbewahrung, Ein-Klick-Löschung, veröffentlichte Data-Map. Ob ein Consent-Banner nötig ist, hängt von deiner Konfiguration und Rechtslage ab und ist rechtlich zu prüfen.
- Für die NIS2-Ära gebaut — alles selbst gehostet, auditierbar, mit Audit-Trail für DSGVO Art. 32
- Kein Phone-Home ab Werk — jede externe Verbindung ist opt-in und standardmäßig aus, und im Abschnitt External services Byte für Byte dokumentiert
- Login-Schutz — TOTP-2FA, IP- und accountbasierter Brute-Force-Schutz, lokaler Honeypot (kein reCAPTCHA), eigene Login-URL
- Datei-Integrität & Malware — SHA-256-Baseline über ~10.000 Dateien, Pattern-Scanner mit 16 Regeln, nur auf Deltas
- Schwachstellen-Scanner — opt-in, täglicher Abgleich gegen eine EU-gehostete API (self-hostbar), CVE/CVSS
- Härtung & Erkennung — XML-RPC aus, Security-Header, CSP, 404-Probing-Tracker, erklärbare Anomalieerkennung (lokal)
- Multisite-First — netzwerkweit konfigurieren, Per-Site-Overrides, Onboarding-Wizard in 6 Sprachen (DE/EN/FR/IT/PL/ES)
Privacy Policy
Data stored in your WordPress database (never leaves the server)
- Login events: timestamp, event type (success / failure / blocked / 2FA required / 2FA passed / 2FA failed / logout), username (or hashed pseudonym if pseudonymization is on), IP address (or anonymized /24 if IP anonymization is on — default), user-agent, request URI.
- Brute-force blocks: blocked IP, reason, expiry timestamp.
- Anomaly baselines: per-user statistical aggregates (mean and variance of login_hour, IP family, user-agent class). No raw login history is retained beyond the rolling log retention window (default 30 days).
- File-integrity baseline: SHA-256 hash + size + mtime + tracked path of every PHP file under WP core / plugins / mu-plugins / themes. Used to detect added / changed / missing files. The file contents are never stored — only the hash.
- 2FA secrets (per user, if user enrolled): base32-encoded TOTP secret, sha256-hashed recovery codes (the plain codes are shown ONCE on enrollment and never persisted).
- Audit trail: who edited which post / user / option / theme / plugin, with field-level diffs (no post-content bodies, no password hashes — only
[changed]markers for sensitive fields). - Site option: configuration values, last cron timestamps.
Data sent to external services
The plugin makes no automatic outbound calls until you opt in. The one you are most likely to enable is the vulnerability scanner, which — once switched on — queries an EU-hosted vulnerability API (default https://shieldforge-intel.brainwerk.at/) once per day. It is off by default; the endpoint is configurable and the feature can be disabled again at any time.
- What is sent: per HTTP GET, one slug + one version per installed component (plugin / theme / core). Example:
GET /v1/vulns/plugin/contact-form-7/. - What is NOT sent: site URL, domain, admin email, IP addresses, user information, content, settings.
- Provider:
shieldforge-intel.brainwerk.atis Brainwerk’s own EU-hosted API that aggregates public vulnerability data (wpvulnerability.net, EUVD). - Enable / disable: Brainwerk Security Suite Vulnerabilities Settings Enable scanner (off by default).
- Self-host: point the endpoint setting at your own mirror to keep everything in your network.
Several opt-in features contact external services only after you enable them — see the External services section below for the full list, the exact data sent, and how to turn each off.
Lifecycle
All Brainwerk Security Suite data is deleted on plugin uninstall (DB tables dropped, options removed, user-meta wiped, transients purged). The configurable log retention is enforced by a daily cron.
External services
This plugin can connect to the external services listed below. Every one of them is opt-in and off by default — out of the box the plugin contacts nothing. Each can be disabled again at any time, and the vulnerability endpoint can be re-pointed at a self-hosted mirror.
1. Brainwerk Vulnerability API — https://shieldforge-intel.brainwerk.at/ — OPT-IN, default OFF
- What it is used for: Daily vulnerability lookup for every plugin, theme and WordPress-core version installed on your site. Surfaces known CVEs, CVSS scores and fixed-in versions in the Vulnerabilities tab.
- When data is sent: Never until you enable the scanner. Once enabled, once per day via WP-Cron (plus any manual «Scan now» you trigger).
- What data is sent: One HTTP GET per installed component, with the component slug and version in the path (e.g.
GET /v1/vulns/plugin/contact-form-7/). No site URL, no domain, no admin email, no IP, no user data, no content, no settings. - How to disable: Brainwerk Security Suite Vulnerabilities Settings Enable scanner = off.
- Self-host / re-point: set the endpoint option to your own mirror to keep everything inside your network.
- Provider:
shieldforge-intel.brainwerk.atis Brainwerk’s own EU-hosted API that aggregates public vulnerability data (wpvulnerability.net — a community mirror of WPScan / Patchstack — and the EU Vulnerability Database, EUVD). Operated by Stefan Kogelgruber / Brainwerk (EU). Privacy: https://brainwerk.at/privacy
2. Brainwerk Threat Network (sensor) — https://shieldforge-intel.brainwerk.at/ — OPT-IN, default OFF
- What it is used for: Optional community threat-intelligence network. Your site shares fact-only attack telemetry and in return receives a signed feed of known-malicious IP indicators.
- When data is sent: Only after you give explicit consent AND the site registers with the network. Never before both steps are completed.
- What data is sent: Batched, HMAC-signed events containing hashed, non-reversible IP indicators (raw IP addresses never leave your server), a hashed user-agent class, a request-path pattern and a country code. No site URL owner data, no user identities, no content.
- How to disable: Brainwerk Security Suite Threat Network disable (or simply never enable it). Off by default.
- Provider: Brainwerk (EU-hosted), same operator and privacy policy as above.
3. Have I Been Pwned (Pwned Passwords) — https://api.pwnedpasswords.com/ — OPT-IN, default OFF
- What it is used for: Warns users whose password appears in known breach corpora, at login or password change.
- What data is sent: Only the first 5 characters of the SHA-1 hash of the password (k-anonymity range query). The password itself and the full hash never leave your server.
- How to disable: Off by default; enable under the login/hardening settings only if you want it.
- Provider: Have I Been Pwned, operated by Troy Hunt. https://haveibeenpwned.com/Privacy
4. hCaptcha / Cloudflare Turnstile (optional captcha) — https://hcaptcha.com/, https://challenges.cloudflare.com/ — OPT-IN, default OFF
- What it is used for: Optional captcha on login / registration / comment forms as an alternative to the built-in local honeypot.
- When it is active: Only if you enable the captcha module AND enter your own site/secret keys. When enabled it loads the provider’s JavaScript from their CDN in the browser and, on verification, sends the captcha token and the visitor’s IP address to the provider.
- How to disable: Off by default; the default anti-bot (honeypot) is 100% local and contacts nothing.
- Providers: hCaptcha privacy · Cloudflare Turnstile privacy
5. WordPress.org (core checksums & repository integrity) — https://api.wordpress.org/, https://downloads.wordpress.org/ — OPT-IN / on demand
- What it is used for: Verifying WordPress core files against official checksums (manual admin action) and, optionally, comparing installed plugins/themes against the official wordpress.org checksums / release packages to detect tampering. The plugin only reads these to report differences — it never modifies your plugin or theme files.
- What data is sent: The WordPress version + locale, and the slug/version of the components being verified. No user data.
- When: The core-checksum check runs only when you click it; the repository integrity check is off by default and, when enabled, runs via cron / on demand.
- Provider: WordPress.org (the WordPress project’s own infrastructure). https://wordpress.org/about/privacy/
Скриншоты










Установка
- Upload the
brainwerk-security-suitefolder to/wp-content/plugins/or install via the WordPress plugin uploader. - Activate the plugin through the Plugins screen (or Network Activate for Multisite).
- Open Brainwerk Security Suite in the admin sidebar and walk through the onboarding wizard.
Brainwerk Security Suite ships with safe defaults — no configuration is required to get baseline protection, and out of the box it makes no outbound calls at all. The vulnerability scanner (the one feature that contacts an external API) is off by default; enable it under Vulnerabilities Settings if you want daily CVE lookups.
Часто задаваемые вопросы
-
Does Brainwerk Security Suite call any external service?
-
Not until you ask it to. Out of the box the plugin makes no automatic outbound calls. Every integration that can reach an external service is opt-in and off by default:
- The plugin/theme/core vulnerability scanner. Once you enable it, it queries an EU-hosted vulnerability API (default
https://shieldforge-intel.brainwerk.at/) once per day for the slug + version of each installed component. Nothing else (no site URL, no admin email, no IP, no user data) is sent, and you can point it at a self-hosted mirror under Brainwerk Security Suite Vulnerabilities Settings. - The Threat Network sensor, the Have-I-Been-Pwned password check, an optional hCaptcha / Cloudflare Turnstile captcha, and the on-demand WordPress.org core-checksum / repository integrity checks.
Each is documented in full in the External services section below.
The core local features (file-integrity monitor, malware-pattern scan, brute-force protection, audit log, 2FA, honeypot, anomaly detection, security headers) make no outbound calls.
- The plugin/theme/core vulnerability scanner. Once you enable it, it queries an EU-hosted vulnerability API (default
-
Is the plugin GDPR-compliant out of the box?
-
It is built to support your GDPR obligations: IP anonymization, configurable retention, and a published data map are on by default, and the admin includes copy-paste-ready text for your privacy policy. Full legal compliance always depends on how you run your whole site, so treat these as strong technical building blocks rather than legal advice.
-
Does it work on Multisite?
-
Yes. Network-activate it and configure once at the network level; per-site overrides are supported.
-
I lost my 2FA device. How do I get back in?
-
Use one of the 8 recovery codes generated when you enrolled. If you also lost those, an administrator with
manage_network_optionscapability can disable 2FA for any user under Brainwerk Security Suite 2FA Users with 2FA configured Rescue: disable. -
I enabled the custom login URL and locked myself out. How do I recover?
-
Add this line to
wp-config.php(above the «That’s all» comment):define('SHIELDFORGE_LOGIN_RESCUE', 'choose-a-long-random-secret');Then visit
https://your-site/wp-login.php?shieldforge_rescue=choose-a-long-random-secretto bypass the 404 and reach the standard login. -
Will it slow down my site?
-
It is designed to be lightweight. Hooks fire only where needed, the database tables are indexed, and old log rows are cleaned up daily. The file-integrity scanner runs at 03:30 in a 45-second time-budgeted cron sweep that resumes on the next tick if a single run can’t finish.
-
My server runs behind a reverse proxy / Cloudflare Tunnel / sslh. Will Brainwerk Security Suite see real client IPs?
-
Brainwerk Security Suite reads
$_SERVER['REMOTE_ADDR']by default. If your nginx / Apache is configured to forward the original client IP (PROXY-protocol, X-Forwarded-For), that’s what arrives in PHP and Brainwerk Security Suite uses it. The healthcheck card on every admin screen will warn you if all visitors arrive as 127.0.0.1 — that means the proxy chain is hiding the real client from PHP, which would silently disable IP-based brute-force protection. Fix it at the proxy / web-server layer (proxy-protocol-aware listener) before re-enabling brute-force protection.
Отзывы
Нет отзывов об этом плагине.
Участники и разработчики
«Brainwerk Security Suite» — проект с открытым исходным кодом. В развитие плагина внесли свой вклад следующие участники:
УчастникиПеревести «Brainwerk Security Suite» на ваш язык.
Заинтересованы в разработке?
Посмотрите код, проверьте SVN репозиторий, или подпишитесь на журнал разработки по RSS.
Журнал изменений
0.14.4 — 2026-07-29
- Maintenance release: version bump only, no functional changes since 0.14.3.
0.14.3 — 2026-07-17
- wp.org compliance: renamed all short-prefixed (
sf_) transients to the uniqueshieldforge_prefix —shieldforge_user_lock_,shieldforge_2fa_pending_,shieldforge_2fa_recovery_show_,shieldforge_2fa_attempts_— to avoid collisions in the shared options/transients space. - Metadata: removed the
Plugin URIheader (the previous value was not public); the publicAuthor URIis retained. - Hardening: escape all remaining admin outputs at output time (audit table, scanner status, captcha widget, magic-link/privacy
wp_diemessages) and document the trusted-table-name direct queries.
0.14.1 — 2026-07-04
- Privacy: the plugin/theme/core vulnerability scanner is now opt-in and off by default — out of the box the plugin makes no automatic outbound calls at all. Enable it under Vulnerabilities Settings to consent to the daily lookup.
- wp.org compliance: all inline
<script>/<style>blocks in admin views are now enqueued (wp_add_inline_script/ bundled CSS / a staticassets/js/twofactor-profile.js). - wp.org compliance: the repo-integrity checker is now detection-only — it reports tampered plugin/theme files and links you to the standard WordPress reinstall flow instead of writing files into plugin/theme folders.
- wp.org compliance: removed the direct load of
wp-includes/template-loader.phpin the login-URL 404 path; it now emits a self-contained 404. - wp.org compliance: removed the redundant
load_plugin_textdomain()call (WordPress 4.6+ auto-loads bundled translations by slug). - Security: escape the WAF debug output and the 2FA «last used» column at output time.
- Docs: readme reworded to drop comparative marketing claims and to reflect that every external service is opt-in and off by default.
0.14.0 — 2026-05-21
- Rebranded to Brainwerk Security Suite (was: ShieldForge). Display name + text-domain + plugin filename + language files updated. Internal class prefix
Shieldforge_*and DB tableswp_shieldforge_*kept stable for upgrade compatibility. - Security: nonce in the magic-link form now goes through
sanitize_text_field( wp_unslash() )(pluggable-function hardening). - Security:
$_COOKIEreads in the 2FA grace-period token now sanitize_text_field + wp_unslash before the alphanum hex-filter. - Security: all
$_SERVERreads (HTTP_USER_AGENT,HTTP_REFERER,HTTP_ACCEPT_LANGUAGE,REQUEST_METHOD,REQUEST_URI,REMOTE_ADDR, trusted-proxy header loop) now usesanitize_text_field( wp_unslash() )(URLs useesc_url_raw( wp_unslash() )). - wp.org compliance: replaced both
<<<TXTheredocs in the privacy-policy generator with plain string concatenation (wp.org pre-scan blocks heredocs). - wp.org compliance: removed
load_plugin_textdomain()— WordPress 4.6+ auto-loads translations for plugins hosted on wp.org by slug. The de_AT / de_CH / de_DE_formal fallback filter stays. - Docs: readme now has a top-level
== External services ==section documenting every outbound connection — the default vulnerability API (shieldforge-intel.brainwerk.at) plus the opt-in Threat Network sensor, Pwned-Passwords check, optional hCaptcha/Turnstile captcha, and WordPress.org checksum/repository checks (what is sent, when, how to disable, self-host option, provider links). - Docs: added
brainwerkas primary contributor in readme alongsidestefankogelgruber.
0.9.0 — 2026-05-10
- UX overhaul: tab navigation now grouped into 5 logical sections (Operations / Setup & Hardening / Detection & Response / Records & Alerts / System) — easier to find your way around 16 tabs.
- Hero dashboard: big color-coded threat-status banner at the top, action-items as prominent clickable cards, status pop visible in 1 second.
- Modern toggle switches (iOS-style sliders) replace stock checkboxes throughout settings forms.
- Empty states with CTAs: Vulnerabilities / Scanner / Audit / Firewall now show inviting empty-state cards with one-click actions instead of a flat «no findings yet».
- Quick-Setup wizard: pick a site profile (School / Agency / Shop / Blog) all relevant settings batch-applied with sensible defaults.
- Mobile-responsive admin — tab nav adapts, hero stacks vertically on small screens.
- Dark-mode support for the WP «Midnight» / «Ectoplasm» / «Ocean» admin color schemes.
- Tooltip bubbles via
[data-sf-tip]attribute pattern for inline setting hints. - Pro plugin now has its own
bin/bump-version.ps1(was Free-only). - Both bump-version scripts now also sync the
Project-Id-Versionheader in.potranslation files.
0.6.0 — 2026-05-10
- Custom login URL: rewrite wp-login.php to a configurable path; original returns 404. Lockout-recovery via
SHIELDFORGE_LOGIN_RESCUEwp-config define. - Honeypot anti-bot on login / register / comment forms — 100% local, no reCAPTCHA. Per-surface toggles.
- Content-Security-Policy support with Report-Only mode for safe rollout.
- Per-header security toggles for X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS — set only if your nginx/Apache doesn’t already send them.
- New Hardening+ admin tab.
0.5.0 — 2026-05-10
- User activity audit trail: hooks 11 WordPress lifecycle events (post_updated / wp_trash_post / before_delete_post / profile_update / deleted_user / wpmu_delete_user / wp_logout / upgrader_process_complete / updated_option / update_site_option). Per-group toggles, post-type skip-list, security-sensitive option-key whitelist, password / hash redaction.
- New Audit admin tab with filter dropdown, paginated event list, 7-day distribution badges.
- 9 new event types: logout, post_updated/trashed/deleted, user_deleted, user_profile_updated, plugin_updated, theme_updated, core_updated.
0.4.0 — 2026-05-10
- Plugin / theme / core vulnerability scanner — daily check against wpvulnerability.net (free, EU-hosted, no API key). CVE-IDs, CVSS scores, fixed-in versions, active-vs-inactive flagging.
- New Vulnerabilities admin tab.
- Dashboard action-item nag and daily-digest section for active critical vulns.
- Cron staggering: scanner 03:30 / vulnscan 04:30 / digest 07:00 to spread DB load.
- Dedup state: each vuln is logged once per slug+version+uuid, re-logged after 7 days.
0.3.0 — 2026-05-10
- TOTP two-factor authentication (RFC 6238, pure PHP, no external dependencies). Compatible with Google Authenticator, Microsoft Authenticator, Authy, 2FAS, FreeOTP, Aegis.
- 8 single-use recovery codes per user, sha256-hashed, normalized matcher.
- Force-by-role policy.
- Interstitial login flow (
wp-login.php?action=sf_2fa) preserves the WordPress login styling. - Application-password authentication bypasses 2FA correctly (per WordPress 5.6+ guidelines).
- New 2FA admin tab.
0.2.0 — 2026-05-10
- File-integrity monitor: SHA-256 hash baseline of every PHP file under WP core / plugins / mu-plugins / themes. Daily cron diffs against the baseline.
- Pattern-based suspicious-code scanner (16 rules) on every added or changed file:
eval(base64_decode(...)),eval(gzinflate(...)),assert(base64_decode(...)),preg_replace /e, webshell signatures (c99 / r57 / WSO / b374k), remote include via URL, inlinewp_insert_user(role=administrator),wp_set_auth_cookie(literal-id)and more. - Time-budgeted cron run (45 s soft cap, resumes on next tick).
- New Scanner admin tab with re-baseline / whitelist quick actions.
- DB schema upgrade to v2 (adds
shieldforge_filestable).
0.1.1 — 2026-05-07
- Hardening: account-based brute-force lockout in addition to IP-based.
- REST API anonymous-restriction extended to comments / search / settings / themes / plugins endpoints.
- Probing-hook moved from
template_redirecttowpaction priority 1 for compatibility with custom 404 themes / SEO plugins. - nginx-hardening: install.php and *.log explicitly blocked.
- IP anonymization re-enabled by default; one-time retroactive anonymization helper.
- IP-form-mismatch fix in BF counter (anonymized vs raw).
- Internal: versioning framework with idempotent migrations + bash/PowerShell bump-version helpers.
- Pro companion plugin scaffolding with first feature (Slack/Discord/Mattermost webhook).
- Dashboard widget aggregated upgrade: action-items block, system-status strip, trend arrows vs 7-day average, top-targeted-usernames column.
0.1.0 — 2026-05-07
- Initial release: login activity log, brute-force protection, IP whitelist with CIDR, hardening toggles, 404 probing tracker, email notifications, daily digest with transparent threat score, anomaly detection (beta), healthcheck banner, onboarding wizard in 6 languages, multisite-aware, GDPR controls (IP anonymization, username pseudonymization, log retention), privacy-policy snippet generator, License management against Lemon Squeezy License API.
