Title: PowerSEC
Author: CinderEye LLC
Published: <strong>16.09.2026</strong>
Last modified: 16.09.2026

---

Поиск плагинов

![](https://ps.w.org/powersec/assets/banner-772x250.png?rev=3699113)

![](https://ps.w.org/powersec/assets/icon.svg?rev=3699113)

# PowerSEC

 Автор: [CinderEye LLC](https://profiles.wordpress.org/amoomj/)

[Скачать](https://downloads.wordpress.org/plugin/powersec.1.4.230.zip)

 * [Детали](https://ru.wordpress.org/plugins/powersec/#description)
 * [Отзывы](https://ru.wordpress.org/plugins/powersec/#reviews)
 *  [Установка](https://ru.wordpress.org/plugins/powersec/#installation)
 * [Разработка](https://ru.wordpress.org/plugins/powersec/#developers)

 [Поддержка](https://wordpress.org/support/plugin/powersec/)

## Описание

Local security, no account: firewall/WAF; brute-force lockouts, 2FA, CAPTCHA, magic-
link, bot/honeypot; IP blocklist/allowlist and country blocks; malware and file-
change scanning; WordPress, database and session hardening; on-site backups with
1-click restore; tamper-evident audit log.

PowerSEC can connect to PowerSEC Central (https://powersec.io) for multi-site management
and vulnerability scanning (plugins, themes and core), **off by default** — see 
External services (1). If connected, it can switch WordPress’s own plugin and theme
auto-update settings on or off. It never changes how core updates itself.

### External services

Each service below is contacted **only** when its feature is on; every third-party
service is **off by default**, and Central is off until an administrator connects
the site. Out of the box the only request PowerSEC makes on its own is to the first-
party WordPress.org checksum API (5); an alert channel’s «Send test» is the one 
exception, contacting the destination you typed at once. IPs and usernames may be
personal data — disclose the services you enable in your own policy. The User-Agent
is `PowerSEC/<version>` alone; see each service below.

**1. PowerSEC Central — https://powersec.io** — dashboard for multi-site management,
cloud backups, alerting, incident response. _Trigger:_ only when an administrator
connects the site. _Default:_ off.
 _Sent:_ site URL, identifiers and API keys; 
WordPress/PHP/MySQL versions; plugin and theme inventory (name, slug, version, author,
active state); site icon URL; disk, memory and database size; up to 14 days of pageview
counts; scan summaries, security event metadata and backup status; IPs of blocked
or attacking clients; administrator usernames, last login, and their email addresses(
only while two-factor is on or this server cannot send mail). If a message this 
site sends fails, its subject and body go to Central to deliver — to your own administrators
only. With two-factor on and connected, the one-time code and recipient email go
to Central to deliver (otherwise wp_mail() is used and nothing leaves the site).
Database-scan findings carry a short redacted excerpt plus its table and key; whole
posts, option values and page output never are. _Cloud backup (paid):_ archives 
on Wasabi (`*.wasabisys.com`); restores use short-lived signed URLs from `*.wasabisys.
com`, `*.amazonaws.com` or `powersec.io`. Wasabi https://wasabi.com/legal/ , https://
wasabi.com/legal/privacy-policy/ — AWS https://aws.amazon.com/service-terms/ , https://
aws.amazon.com/privacy/ _Terms_ https://powersec.io/terms — _Privacy_ https://powersec.
io/privacy

**2. Google Gemini — https://ai.google.dev** (via Central) — an AI second opinion
on a file the scanner **already flagged**.
 _Trigger:_ (a) manual — an administrator
clicks to explain one flagged file; that click is the authorisation. (b) automated—**
off by default**, needing an explicit local opt-in by an administrator of this site
under PowerSEC > Central Connection. Connecting to Central, your plan and Central’s
settings do **not** enable it; switching it off stops future sharing. _Sent:_ only
a bounded, redacted excerpt of that flagged file (size-capped, secrets redacted),
plus its path, size, hash and the matching rule. Whole files, whole sites, databases
and files that may hold credentials (`wp-config.php`, `.env`, key/certificate files)
are never sent. Advisory only: it never changes scan results, malware counts or 
your score, and never removes, quarantines or repairs a file. _Terms_ https://ai.
google.dev/gemini-api/terms — _Privacy_ https://policies.google.com/privacy

**3. GeoJS — https://get.geojs.io** — IP geolocation. _Trigger:_ only when country
blocking is enabled. _Default:_ off. _Sent:_ the visitor’s IP, to resolve its country;
cached 24h, and behind Cloudflare the country comes from Cloudflare’s header with
no external call.
 _Terms_ https://www.geojs.io/tos/ — _Privacy_ https://www.geojs.
io/privacy/

**4. Tor Project exit list — https://check.torproject.org** — the public exit-node
list. _Trigger:_ only when Tor blocking is enabled. _Default:_ off. _Sent:_ nothing;
the request carries no visitor information.
 _Privacy_ https://www.torproject.org/
about/privacy_policy/ (a public file served without an account, so no separate terms)

**5. WordPress.org — https://api.wordpress.org , https://downloads.wordpress.org**—
the official checksum APIs core itself uses. _Trigger:_ file-integrity monitoring(**
on by default**) and malware scans. _Sent:_ your WordPress version and locale for
core checksums; each plugin’s slug and version for plugin checksums. No personal
data.
 _Privacy_ https://wordpress.org/about/privacy/

**6. Alerting / SIEM destinations** — security events sent where you choose. _Trigger:_
only when you configure and enable a channel. _Default:_ off; on every plan. Kinds:
webhook URLs you supply (Slack, Discord, Splunk HEC, custom); fixed endpoints (PagerDuty`
events.pagerduty.com`, Datadog `http-intake.logs.datadoghq.com` or its regional 
host); raw syslog/CEF over UDP/TCP to a host you supply.
 _Sent:_ per event — type,
severity, message, the WordPress username involved (on a failed login this is visitor-
supplied text), client IP, timestamp, your site name and URL. Custom-webhook and
Splunk formats also include event metadata, which for a login can contain the request
path and user-agent; the others do not. _Terms/privacy:_ https://slack.com/terms-
of-service , https://slack.com/trust/privacy/privacy-policy , https://discord.com/
terms , https://discord.com/privacy , https://www.splunk.com/en_us/legal/terms.html,
https://www.splunk.com/en_us/legal/privacy-policy.html , https://www.pagerduty.com/
terms-of-service/ , https://www.pagerduty.com/privacy-policy/ , https://www.datadoghq.
com/legal/terms/ , https://www.datadoghq.com/legal/privacy/ . A webhook, Splunk 
HEC or syslog collector you supply is your own server, so its terms are yours.

**7. Your own site (loopback)** — not a third party. Long backups and scans continue
by calling your site’s own `admin-ajax.php`; nothing leaves your server.

### Privacy

Recorded locally: login attempts (attempted username, IP, time), audit log (action,
user, IP), sessions (user, IP, user-agent, times), and firewall/WAF/IP-blocking 
records (IP, path, method, user-agent). Findings describe files, not people. Retention:
audit log and login attempts about 90 days (configurable), firewall/WAF/sessions
about 30 days, remote requests about 7 days.

Blocked IPs follow their own rules, not the schedule above: a temporary block ends
by itself when it expires; a permanent block PowerSEC created automatically is removed
after about a year (configurable); one an administrator added by hand is kept until
an administrator removes it.

**Deleting the plugin keeps your data by default.** That site’s PowerSEC tables,
settings and connection details stay, so a reinstall resumes where it left off. 
Running `wp option update powersec_delete_data_on_uninstall 1` first (no screen 
for it) also drops those tables and removes PowerSEC settings, stored keys, connection
details, transients, per-account data and scheduled tasks, plus the firewall folder.
Backup and quarantine folders remain, as do the uploads PHP-execution guards. One
secret-free pending-revocation marker remains when a Central release is unconfirmed,
never reported as done. wp-admin deletion cannot notify Central, so disconnect first.

WordPress export and erasure requests are answered for records tied to a WordPress
account. IP-only records cannot reliably be linked to an email address, so they 
are not exported or erased. Where erasure would break the tamper-evident audit chain,
identifying fields are anonymised instead of deleted, and the response says so.

### Files and directories this plugin writes

Everything is written inside your uploads directory (`wp_upload_dir()`): `powersec-
backups/` (archives; deny-all `.htaccess`), `powersec-quarantine/` (detected files
kept for inspection), `powersec/` (firewall rules), `powersec-config-backups/` (
wp-config.php copies; removed on data deletion), plus guards stopping PHP executing
in uploads. Two things write outside uploads: the prefix change edits `wp-config.
php` after backing it up, and a restore adds `.maintenance` to the site root, removed
when it ends. **Restoring overwrites site files.**

### Credits

Chart.js v4.5.1, @kurkle/color v0.3.2 (MIT; texts in `licenses/`). https://github.
com/chartjs/Chart.js , https://github.com/kurkle/color

## Скриншоты

[[

[[

[[

[[

[[

[[

## Установка

 1. Install from the Plugins screen, or upload the ZIP.
 2. Activate it, then open **PowerSEC > Dashboard** to scan.
 3. (Optional) Open **PowerSEC > Central Connection** and choose **Connect automatically**.

**Multisite:** PowerSEC supports multisite through per-site activation only. Network
activation is intentionally refused, because each site keeps its own data and connection.
Activate PowerSEC separately on each site where you need it. Data deletion removes
per-user data network-wide.

## Часто задаваемые вопросы

### Is PowerSEC Central free?

Central has a free tier: connect sites and use the fleet dashboard free. Paid plans
add cloud backups, scheduling, AI review and alerting. Every local feature works
on every plan. Automatic AI review stays off until an administrator turns it on —
see External services (2).

## Отзывы

Нет отзывов об этом плагине.

## Участники и разработчики

«PowerSEC» — проект с открытым исходным кодом. В развитие плагина внесли свой вклад
следующие участники:

Участники

 *   [ CinderEye LLC ](https://profiles.wordpress.org/amoomj/)

[Перевести «PowerSEC» на ваш язык.](https://translate.wordpress.org/projects/wp-plugins/powersec)

### Заинтересованы в разработке?

[Посмотрите код](https://plugins.trac.wordpress.org/browser/powersec/), проверьте
[SVN репозиторий](https://plugins.svn.wordpress.org/powersec/), или подпишитесь 
на [журнал разработки](https://plugins.trac.wordpress.org/log/powersec/) по [RSS](https://plugins.trac.wordpress.org/log/powersec/?limit=100&mode=stop_on_copy&format=rss).

## Журнал изменений

Full history ships in `changelog.txt`.

#### 1.4.230

 * Fix: a scan interrupted by the 1.4.229 update now restarts instead of resuming,
   so no finding is misread.

#### 1.4.228

 * PowerSEC no longer changes how WordPress core auto-updates; subdirectory installs
   fixed.

## Мета

 *  Версия **1.4.230**
 *  Обновление: **2 дня назад**
 *  Активных установок: **Менее 10**
 *  Версия WordPress ** 5.8 или выше **
 *  Совместим вплоть до: **7.1.1**
 *  Версия PHP ** 7.4 или выше **
 *  Язык
 * [English (US)](https://wordpress.org/plugins/powersec/)
 * Метки:
 * [backup](https://ru.wordpress.org/plugins/tags/backup/)[firewall](https://ru.wordpress.org/plugins/tags/firewall/)
   [login security](https://ru.wordpress.org/plugins/tags/login-security/)[malware scanner](https://ru.wordpress.org/plugins/tags/malware-scanner/)
   [security](https://ru.wordpress.org/plugins/tags/security/)
 *  [Дополнительно](https://ru.wordpress.org/plugins/powersec/advanced/)

## Оценки

Пока что нет ни одного отзыва.

[Ваш отзыв](https://wordpress.org/support/plugin/powersec/reviews/#new-post)

[Посмотреть всеотзывы](https://wordpress.org/support/plugin/powersec/reviews/)

## Участники

 *   [ CinderEye LLC ](https://profiles.wordpress.org/amoomj/)

## Поддержка

Есть что сказать? Нужна помощь?

 [Перейти в форум поддержки](https://wordpress.org/support/plugin/powersec/)