Перейти к содержимому
WordPress.org

Русский

  • Темы
  • Плагины
  • Новости
    • Документация
    • Форумы
  • О WordPress
  • Сообщество
  • Скачать WordPress
Скачать WordPress
WordPress.org

Plugin Directory

Web Plura Security Center – Security Scanner, Firewall, 2FA & Login Protection

  • Отправить плагин
  • Мои избранные
  • Войти
  • Отправить плагин
  • Мои избранные
  • Войти

Web Plura Security Center – Security Scanner, Firewall, 2FA & Login Protection

Автор: Web Plura
Скачать
  • Детали
  • Отзывы
  • Установка
  • Разработка
Поддержка

Описание

Web Plura Security Center helps WordPress administrators investigate suspicious files, review security risks, strengthen login protection, monitor important file changes, and manage local firewall and hardening controls from the WordPress dashboard.

The free WordPress.org plugin is built around local security work. Security scans, login protection, firewall/rate-limiting controls, file-change review, hardening checks, reports, notifications, and privacy tools can be used without a Web Plura Cloud account, separate extension, subscription, license, or hosted service.

Use it when you need a practical security review inside WordPress: scan for suspicious files and malware indicators, check risky configuration, review administrator and file-integrity signals, configure supported 2FA/passkey login controls, and manage local request protection. Findings are advisory signals for investigation, not proof that every flagged item is malicious.

Key Security Features

  • Security scanning for suspicious files, malware indicators, and risky configuration
  • File integrity checks and local file-change baseline review
  • Firewall controls with rate limiting and temporary blocking
  • Login protection with two-factor authentication, passkeys, backup codes, and optional CAPTCHA
  • Plugin checksum verification against WordPress.org where supported
  • Security hardening checks for headers, XML-RPC, debug exposure, file permissions, and related configuration
  • Administrator/user risk checks and file-integrity advisors
  • Security findings, reports, email notifications, and local privacy tools

Security Scanner

Run local security scans to review suspicious files, malware indicators, risky configuration, and other findings that may need administrator attention.

The scanner is designed to support investigation. It does not automatically treat every unusual file as malware, and administrators should review scan evidence before taking destructive action.

Suspicious Files and Malware Indicators

Unexpected files or file changes can sometimes indicate a compromised WordPress installation, but legitimate plugin updates, theme updates, administrators, hosting tools, and deployment processes can also modify files.

Web Plura Security Center can help identify files and patterns that may require review. It does not claim to detect every compromise, confirm that every suspicious file is malicious, or fully clean hacked WordPress sites automatically.

Login Protection, 2FA and Passkeys

Account security is a common weak point on WordPress sites. Web Plura Security Center includes supported login-security controls such as:

  • Two-factor authentication (2FA) using authenticator codes
  • Passkey enrollment and passkey login where supported by the browser, device, and site configuration
  • Backup authentication codes
  • Trusted-device review and revocation
  • Role or user force-logout controls
  • Temporary lockout after repeated login failures
  • Optional CAPTCHA protection for supported login surfaces

These controls can reduce risk from reused passwords, repeated login attempts, and account-access problems. They do not guarantee account security.

Firewall and Rate Limiting

Web Plura Security Center includes local firewall controls designed to reduce repeated or abusive requests.

Supported protections include request inspection, endpoint rate limiting, temporary blocking, local allowlist/blocklist controls, and firewall audit events. These tools keep request protection under administrator control and can be disabled temporarily for troubleshooting.

File Integrity and File-Change Monitoring

Web Plura Security Center keeps local file-change and integrity context to help administrators review important changes.

A changed file does not automatically mean a website has been compromised. File-change and baseline information is meant to help administrators compare expected changes, such as updates or deployments, with changes that deserve closer review.

Plugin Checksum Verification

Where supported, administrators can run checksum verification against the WordPress.org Plugin Checksums API.

This can help identify differences between supported installed plugin files and the files expected for a known WordPress.org plugin release. Checksum verification is an integrity check, not guaranteed malware detection.

Security Hardening Checks

Web Plura Security Center includes local checks and controls that help administrators review common WordPress exposure points.

Supported areas include security headers, XML-RPC exposure, API exposure notes, debug-log exposure, file permissions, executable files in uploads, public backup/archive indicators, file editor exposure, administrator/user risk, and update posture.

These checks are intended to provide practical review context. They should be used with secure hosting, regular updates, strong credentials, reliable backups, and careful administrator review.

Admin/User Risk and File Integrity Checks

The Admin/User Risk & File Integrity advisor reviews supported security conditions such as:

  • administrator changes
  • user-registration role exposure
  • relevant file permissions
  • executable files in upload locations
  • exposed debug-log indicators
  • publicly accessible archive indicators
  • recent component changes

These checks are advisory and read-only. They do not silently modify users, roles, files, or approved baselines.

Security Findings and Reports

Web Plura Security Center provides security findings, incident visibility, local reports, security history, and administrative guidance for supported local checks.

Findings are intended to provide enough context for an administrator to decide what deserves investigation. Not every warning is a confirmed security breach.

Security Notifications

Where configured and supported by the current release, administrators can receive security-related email notifications.

The free plugin does not claim SMS, push notifications, external monitoring, or continuous cloud monitoring.

Additional Security Advisors

Web Plura Security Center also includes secondary local advisors that can help administrators review related risk signals.

The Form Abuse & Lead Security advisor reviews supported local signals involving installed form plugins, likely lead pages, SMTP configuration, update status, privacy-page configuration, and risky form markers.

These checks run locally according to the current plugin implementation. The advisor does not submit forms, capture leads for external analysis, analyze private lead content externally, or upload lead data to Web Plura.

Who Is This For?

Web Plura Security Center can be useful when you need to:

  • investigate unexpected or suspicious files;
  • scan for malware indicators and supported security risks;
  • improve WordPress login security;
  • enable two-factor authentication, passkeys, or backup codes;
  • review file changes after plugin, theme, or deployment activity;
  • check risky file permissions, debug-log exposure, public archives, and upload executable markers;
  • inspect security headers, XML-RPC exposure, and common configuration issues;
  • verify supported plugin files against WordPress.org checksums;
  • reduce repeated abusive login or request attempts with local firewall controls;
  • keep local security findings, reports, and privacy tools available inside WordPress.

Local-First Security and Privacy

The WordPress.org version is designed so that its included local security functionality can operate without requiring a Web Plura Cloud account.

Local security functionality should be understood as local WordPress-site functionality. The free plugin stores plugin-owned security metadata in the site’s WordPress database, including local settings, contact or notification email settings when configured, login-security metadata, audit events, hashed or prefix IP evidence, blocked IP records, file-baseline summaries, and local report or scan state.

The free plugin does not automatically upload suspicious file samples, form-advisor data, administrator/user-risk data, file-baseline history, setup-checklist information, or local security reports to Web Plura Cloud.

The plugin registers applicable WordPress Privacy Tools exporter and eraser callbacks for plugin-owned security metadata. Uninstall removes applicable plugin options, scheduled hooks, and plugin-owned custom database tables.

Limitations and Important Notes

No WordPress security plugin can guarantee that every attack, malicious file, compromised account, vulnerability, or intrusion will always be detected.

Web Plura Security Center provides security checks and administrative tools intended to help site owners identify and investigate supported security risks. Administrators should maintain secure hosting, strong credentials, current WordPress core, plugins and themes, reliable backups, and other appropriate security practices.

Suspicious-file findings, checksum differences, file-change signals, administrator warnings, and hardening checks should be reviewed before action is taken. A finding indicates something worth reviewing; it does not automatically prove that the site has been compromised.

Backup, restore, and disaster recovery workflows are handled by the standalone Web Plura Backup & Restore Manager plugin.

Optional Web Plura Services

The WordPress.org package is fully functional for its included local security checks, login protection, firewall controls, file-integrity context, incident visibility, reports, administrator guidance, privacy tools, and plugin-owned data controls.

Separately installed or hosted Web Plura services may provide additional account-backed services, hosted operations, or cross-site workflows.

Those services are not required for the local functionality included in this WordPress.org plugin.

The free plugin does not require Pro, Web Plura Cloud, account login, subscription, license, entitlement, checkout, or a hosted service for its included local controls.

External Services

This free plugin does not connect to Web Plura Cloud. It may contact these third-party services only when an administrator enables or runs the related local feature:

Administrator consent is required before optional CAPTCHA checks or checksum verification checks use those external services.

  • WordPress.org Plugin Checksums API: https://api.wordpress.org/plugins/checksums/1.0/
    • Purpose: verifies installed plugin files against WordPress.org checksums when an administrator runs checksum verification.
    • Data sent: plugin slug and version identifiers needed for checksum lookup.
    • Runs: only when checksum verification checks are run.
    • Terms: https://wordpress.org/about/terms/
    • Privacy: https://wordpress.org/about/privacy/
  • Cloudflare Turnstile: https://challenges.cloudflare.com
    • Purpose: loads the selected Turnstile challenge and verifies CAPTCHA responses when an administrator enables Cloudflare Turnstile for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables Turnstile and saves Cloudflare keys.
    • Terms: https://www.cloudflare.com/website-terms/
    • Privacy: https://www.cloudflare.com/privacypolicy/
    • Turnstile Privacy Addendum: https://www.cloudflare.com/turnstile-privacy-policy/
  • hCaptcha: https://js.hcaptcha.com and https://hcaptcha.com
    • Purpose: loads the selected hCaptcha challenge and verifies CAPTCHA responses when an administrator enables hCaptcha for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables hCaptcha and saves hCaptcha keys.
    • Terms: https://www.hcaptcha.com/terms
    • Privacy: https://www.hcaptcha.com/privacy
  • Google reCAPTCHA: https://www.google.com/recaptcha/
    • Purpose: loads the selected reCAPTCHA challenge and verifies CAPTCHA responses when an administrator enables Google reCAPTCHA for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables reCAPTCHA and saves Google reCAPTCHA keys.
    • Terms: https://policies.google.com/terms
    • Privacy: https://policies.google.com/privacy

Suspicious files, advisor data, admin/user risk data, file baselines, and setup checklist data are not uploaded by the free plugin.

No third-party executable PHP/JS code is loaded except administrator-enabled CAPTCHA provider scripts. Plugin/theme updates are not served from non-WordPress.org channels.

Some payment, social, CDN, or static-hosting domains may appear in local scanner allowlists for false-positive reduction. They are detection references only and are not enqueued or executed by the free plugin.

Resources

  • Product page: https://wplura.com/products/web-plura-security-center
  • Documentation: https://wplura.com/docs
  • Legal Center: https://wplura.com/legal
    Support: https://wplura.com/support
    About: https://wplura.com/about
    Contact Us: https://wplura.com/contact
    Security Disclosure: https://wplura.com/security
    Terms of Service: https://wplura.com/terms
    Privacy Policy: https://wplura.com/privacy
  • Terms: https://wplura.com/terms
  • Privacy: https://wplura.com/privacy
    Cookie Policy: https://wplura.com/cookie-policy
    Acceptable Use Policy: https://wplura.com/acceptable-use
    Data Processing Addendum (DPA): https://wplura.com/data-processing-addendum
    Service Level Agreement (SLA): https://wplura.com/service-level-agreement

Скриншоты

Security dashboard showing local protection status, scan context, and recommended review actions.
Security dashboard showing local protection status, scan context, and recommended review actions.
Security Center setup guidance with checklist, score, and file-change baseline context.
Security Center setup guidance with checklist, score, and file-change baseline context.
Security scanner page for local quick and full scans.
Security scanner page for local quick and full scans.
Additional security advisor reviewing form, SMTP, update, and privacy-page signals.
Additional security advisor reviewing form, SMTP, update, and privacy-page signals.
Security findings view with context and suggested review actions.
Security findings view with context and suggested review actions.
Firewall controls for rate limiting, temporary blocking, and local request protection.
Firewall controls for rate limiting, temporary blocking, and local request protection.
User profile login-security controls for supported 2FA, passkeys, and backup codes.
User profile login-security controls for supported 2FA, passkeys, and backup codes.
Settings for local security modules, notifications, SMTP delivery, and privacy controls.
Settings for local security modules, notifications, SMTP delivery, and privacy controls.

Установка

  1. Install Web Plura Security Center from the WordPress Plugin Directory, or upload the plugin ZIP through WordPress.
  2. Activate the plugin.
  3. Open Web Plura Security Center in wp-admin.
  4. Review the security dashboard and configure the local security features you want to use.
  5. Run an initial local security scan.
  6. Configure optional login-security or CAPTCHA functionality only if needed.

Часто задаваемые вопросы

Do I need a Web Plura Cloud account?

No. The included local security checks and core local administration workflows work without a Web Plura Cloud account.

Can Web Plura Security Center scan for suspicious files?

Yes. The plugin includes local scanning for suspicious files, malware indicators, risky configuration, and supported security risks. Findings are intended to help administrators identify items that need investigation.

Does it detect malware?

It can scan for suspicious files and malware indicators, but automated scanning cannot guarantee detection of every possible compromise. A finding should be reviewed as a security signal, not treated as automatic proof of malware.

Can it tell me whether my WordPress site has been hacked?

The plugin can identify supported security signals such as suspicious files, malware indicators, unexpected file changes, and risky configuration. These findings may help investigate a suspected compromise, but a scan result alone cannot guarantee whether every intrusion has or has not occurred.

Does it monitor file changes?

Yes. The plugin keeps local file-change and baseline context to help administrators review important changes. A changed file does not automatically mean the site has been compromised.

Does it include firewall protection?

Yes. The plugin includes supported local firewall controls such as request inspection, rate limiting, temporary blocking, and local allowlist/blocklist controls.

Does it provide WordPress login protection?

Yes. The plugin includes supported login-protection controls such as request rate limiting, temporary blocking, 2FA, passkeys, backup codes, and optional CAPTCHA protection.

Does it support two-factor authentication or passkeys?

Yes. Supported users can configure two-factor authentication, and passkey availability can depend on the browser, device, site configuration, and supported plugin implementation. Backup codes can be used where supported as a recovery method.

Are suspicious files deleted automatically?

No. Security findings should be reviewed before potentially destructive actions are taken. The plugin provides findings and supported remediation context so administrators can investigate before acting.

Does the plugin automatically upload suspicious files?

No. Suspicious file sample upload is not part of the free local plugin.

Does it compare plugin files with WordPress.org checksums?

Where supported, administrators can run checksum verification against the WordPress.org Plugin Checksums API. This is an integrity check and does not guarantee malware detection.

Does it check WordPress file permissions and hardening risks?

Yes. Supported hardening and admin/user risk checks include file permission signals, executable files in upload locations, debug-log exposure, public archive indicators, security headers, XML-RPC exposure, and recent component changes.

Does Form Abuse & Lead Security send lead data anywhere?

No. The advisor performs supported local checks and does not submit forms or upload collected lead content to Web Plura.

Does Admin/User Risk & File Integrity change my site?

No. The advisor is read-only and does not silently modify users, roles, files, or approved baselines.

What data leaves the WordPress site?

The free plugin does not send site security data to Web Plura Cloud by default. Optional external services may receive limited data only when the related feature is enabled or run by an administrator, such as checksum lookup requests to WordPress.org or CAPTCHA requests to the selected CAPTCHA provider.

Does this plugin collect personal data by default?

The free plugin stores plugin-owned security metadata locally in WordPress. Depending on configuration and site activity, this may include contact or notification email settings, login-security metadata, audit events, hashed or prefix IP evidence, blocked IP records, file-baseline summaries, and local settings or report state.

The free plugin does not send site security data to Web Plura Cloud by default. If an administrator enables a CAPTCHA provider, that provider may receive browser request metadata, a CAPTCHA verification token, and the requester IP address as described in the External Services section.

Does this plugin support WordPress Privacy Tools exports/erasures?

Yes. The plugin registers applicable WordPress Privacy Tools exporter and eraser callbacks for plugin-owned security metadata.

Can I remove all plugin data on uninstall?

Yes. Uninstall removes applicable plugin options, scheduled hooks, and plugin-owned custom database tables.

Отзывы

Нет отзывов об этом плагине.

Участники и разработчики

«Web Plura Security Center – Security Scanner, Firewall, 2FA & Login Protection» — проект с открытым исходным кодом. В развитие плагина внесли свой вклад следующие участники:

Участники
  • Web Plura

Перевести «Web Plura Security Center – Security Scanner, Firewall, 2FA & Login Protection» на ваш язык.

Заинтересованы в разработке?

Посмотрите код, проверьте SVN репозиторий, или подпишитесь на журнал разработки по RSS.

Журнал изменений

0.1.11

  • Added explicit WPlura legal, help, contact, and disclosure resource labels for WordPress.org release compliance.

0.1.10

  • Improved WordPress.org compliance for paths, nonces, input sanitization, escaping, local scripts, and remote asset disclosures.

0.1.9

  • Removed product-local Cloud connection, entitlement, dashboard, remote scan, policy sync, and signed transport workflows from the WordPress.org package.
  • Kept local fixes, emergency review controls, firewall controls, login protection, and integrity checks available without Pro, Cloud, subscription, or entitlement checks.

0.1.8

Kept Free issue fixes, remediation-plan execution, and emergency action controls independent from Web Plura Cloud, Pro, subscription, and entitlement checks.

0.1.7

Renamed the public display title, added local-only integrity baselines, tightened nonce/passkey handling, expanded external-service disclosure, downgraded unsafe filesystem cleanup to manual guidance, and removed unused public key files.

0.1.6

Improved external-service consent wording, Upgrade page presentation, and dormant cloud-service wording.

0.1.5

Added a Free-owned local scan evidence resolver so Free and Pro share canonical scanner report, summary, timestamp, and score fallback behavior.

0.1.4

Added a Free-owned reports extension surface.

0.1.3

Formalized the dashboard capability panel slot as a reversible Free-owned extension surface for Security Center Pro.

0.1.1

Added stable admin extension slots while keeping free features local-only.

0.1.0

Initial public release with local scans, login protection, firewall controls, setup guidance, advisor checks, privacy tooling, and bounded local data handling.

Мета

  • Версия 0.1.11
  • Обновление: 6 часов назад
  • Активных установок: Менее 10
  • Версия WordPress 5.8 или выше
  • Совместим вплоть до: 7.1.2
  • Версия PHP 8.1 или выше
  • Язык
    English (US)
  • Метки:
    firewalllogin securitymalware scannersecuritytwo factor authentication
  • Дополнительно

Оценки

Пока что нет ни одного отзыва.

Ваш отзыв

Посмотреть всеотзывы

Участники

  • Web Plura

Поддержка

Есть что сказать? Нужна помощь?

Перейти в форум поддержки

  • О нас
  • Новости
  • Хостинг
  • Приватность
  • Витрина
  • Темы
  • Плагины
  • Паттерны
  • Обучение
  • Поддержка
  • Разработчики
  • WordPress.TV ↗
  • Присоединиться
  • События
  • Поддержать ↗
  • Сувениры ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Русский

  • Посетите нас в X (ранее Twitter)
  • Посетите нашу учётную запись в Bluesky
  • Посетите нашу ленту в Mastodon
  • Посетите нашу учётную запись в Threads
  • Посетите нашу страницу на Facebook
  • Посетите наш Instagram
  • Посетите нашу страницу в LinkedIn
  • Посетите нашу учётную запись в TikTok
  • Посетите наш канал YouTube
  • Посетите нашу учётную запись в Tumblr
Код — это поэзия.
The WordPress® trademark is the intellectual property of the WordPress Foundation.