{"id":355610,"date":"2026-08-28T05:53:19","date_gmt":"2026-08-28T05:53:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/web-plura-security-center-login-protection-access-safety-local-checks\/"},"modified":"2026-09-28T12:18:27","modified_gmt":"2026-09-28T12:18:27","slug":"web-plura-security-center","status":"publish","type":"plugin","link":"https:\/\/bg.wordpress.org\/plugins\/web-plura-security-center\/","author":23509928,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.11","stable_tag":"0.1.11","tested":"7.1.2","requires":"5.8","requires_php":"8.1","requires_plugins":null,"header_name":"Web Plura Security Center \u2013 Security Scanner, Firewall, 2FA & Login Protection","header_author":"Web Plura","header_description":"Local login protection, access safety, malware checks, firewall controls, and admin security guidance for WordPress sites.","assets_banners_color":"333f56","last_updated":"2026-09-28 12:18:27","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":214,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.10":{"tag":"0.1.10","author":"wplura","date":"2026-08-28 05:53:00","revision":3669857},"0.1.11":{"tag":"0.1.11","author":"wplura","date":"2026-09-28 12:18:27","revision":3717138}},"upgrade_notice":{"0.1.11":"<p>Adds explicit WPlura legal, help, contact, and disclosure resource labels for WordPress.org release compliance.<\/p>","0.1.1":"<p>Adds free-owned extension slots so Security Center Pro can extend the local admin experience without replacing the free plugin shell.<\/p>","0.1.0":"<p>Initial public release of Web Plura Security Center with free local checks and WordPress-native security workflows.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3669857,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3669857,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3669857,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3669857,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.10","0.1.11"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3669857,"resolution":"1","location":"assets","locale":"","width":1440,"height":4696},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3669857,"resolution":"2","location":"assets","locale":"","width":1440,"height":11216},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3669857,"resolution":"3","location":"assets","locale":"","width":1440,"height":8239},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3669857,"resolution":"4","location":"assets","locale":"","width":1440,"height":2257},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3669857,"resolution":"5","location":"assets","locale":"","width":1440,"height":2023},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3669857,"resolution":"6","location":"assets","locale":"","width":1440,"height":9206},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3669857,"resolution":"7","location":"assets","locale":"","width":1440,"height":2851},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3669857,"resolution":"8","location":"assets","locale":"","width":1440,"height":3288}},"screenshots":{"1":"Security dashboard showing local protection status, scan context, and recommended review actions.","2":"Security Center setup guidance with checklist, score, and file-change baseline context.","3":"Security scanner page for local quick and full scans.","4":"Additional security advisor reviewing form, SMTP, update, and privacy-page signals.","5":"Security findings view with context and suggested review actions.","6":"Firewall controls for rate limiting, temporary blocking, and local request protection.","7":"User profile login-security controls for supported 2FA, passkeys, and backup codes.","8":"Settings for local security modules, notifications, SMTP delivery, and privacy controls."}},"plugin_section":[],"plugin_tags":[1174,1229,55021,600,1909],"plugin_category":[54],"plugin_contributors":[266029],"plugin_business_model":[],"class_list":["post-355610","plugin","type-plugin","status-publish","hentry","plugin_tags-firewall","plugin_tags-login-security","plugin_tags-malware-scanner","plugin_tags-security","plugin_tags-two-factor-authentication","plugin_category-security-and-spam-protection","plugin_contributors-wplura","plugin_committers-wplura"],"banners":{"banner":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/banner-772x250.png?rev=3669857","banner_2x":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/banner-1544x500.png?rev=3669857","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/icon-128x128.png?rev=3669857","icon_2x":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/icon-256x256.png?rev=3669857","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-1.png?rev=3669857","caption":"Security dashboard showing local protection status, scan context, and recommended review actions."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-2.png?rev=3669857","caption":"Security Center setup guidance with checklist, score, and file-change baseline context."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-3.png?rev=3669857","caption":"Security scanner page for local quick and full scans."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-4.png?rev=3669857","caption":"Additional security advisor reviewing form, SMTP, update, and privacy-page signals."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-5.png?rev=3669857","caption":"Security findings view with context and suggested review actions."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-6.png?rev=3669857","caption":"Firewall controls for rate limiting, temporary blocking, and local request protection."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-7.png?rev=3669857","caption":"User profile login-security controls for supported 2FA, passkeys, and backup codes."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-8.png?rev=3669857","caption":"Settings for local security modules, notifications, SMTP delivery, and privacy controls."}],"raw_content":"<!--section=description-->\n<p>Web Plura Security Center helps WordPress administrators investigate suspicious files, review security risks, strengthen login protection, monitor important file changes, and manage local firewall and hardening controls from the WordPress dashboard.<\/p>\n\n<p>The free WordPress.org plugin is built around local security work. Security scans, login protection, firewall\/rate-limiting controls, file-change review, hardening checks, reports, notifications, and privacy tools can be used without a Web Plura Cloud account, separate extension, subscription, license, or hosted service.<\/p>\n\n<p>Use it when you need a practical security review inside WordPress: scan for suspicious files and malware indicators, check risky configuration, review administrator and file-integrity signals, configure supported 2FA\/passkey login controls, and manage local request protection. Findings are advisory signals for investigation, not proof that every flagged item is malicious.<\/p>\n\n<h4>Key Security Features<\/h4>\n\n<ul>\n<li>Security scanning for suspicious files, malware indicators, and risky configuration<\/li>\n<li>File integrity checks and local file-change baseline review<\/li>\n<li>Firewall controls with rate limiting and temporary blocking<\/li>\n<li>Login protection with two-factor authentication, passkeys, backup codes, and optional CAPTCHA<\/li>\n<li>Plugin checksum verification against WordPress.org where supported<\/li>\n<li>Security hardening checks for headers, XML-RPC, debug exposure, file permissions, and related configuration<\/li>\n<li>Administrator\/user risk checks and file-integrity advisors<\/li>\n<li>Security findings, reports, email notifications, and local privacy tools<\/li>\n<\/ul>\n\n<h4>Security Scanner<\/h4>\n\n<p>Run local security scans to review suspicious files, malware indicators, risky configuration, and other findings that may need administrator attention.<\/p>\n\n<p>The scanner is designed to support investigation. It does not automatically treat every unusual file as malware, and administrators should review scan evidence before taking destructive action.<\/p>\n\n<h4>Suspicious Files and Malware Indicators<\/h4>\n\n<p>Unexpected files or file changes can sometimes indicate a compromised WordPress installation, but legitimate plugin updates, theme updates, administrators, hosting tools, and deployment processes can also modify files.<\/p>\n\n<p>Web Plura Security Center can help identify files and patterns that may require review. It does not claim to detect every compromise, confirm that every suspicious file is malicious, or fully clean hacked WordPress sites automatically.<\/p>\n\n<h4>Login Protection, 2FA and Passkeys<\/h4>\n\n<p>Account security is a common weak point on WordPress sites. Web Plura Security Center includes supported login-security controls such as:<\/p>\n\n<ul>\n<li>Two-factor authentication (2FA) using authenticator codes<\/li>\n<li>Passkey enrollment and passkey login where supported by the browser, device, and site configuration<\/li>\n<li>Backup authentication codes<\/li>\n<li>Trusted-device review and revocation<\/li>\n<li>Role or user force-logout controls<\/li>\n<li>Temporary lockout after repeated login failures<\/li>\n<li>Optional CAPTCHA protection for supported login surfaces<\/li>\n<\/ul>\n\n<p>These controls can reduce risk from reused passwords, repeated login attempts, and account-access problems. They do not guarantee account security.<\/p>\n\n<h4>Firewall and Rate Limiting<\/h4>\n\n<p>Web Plura Security Center includes local firewall controls designed to reduce repeated or abusive requests.<\/p>\n\n<p>Supported protections include request inspection, endpoint rate limiting, temporary blocking, local allowlist\/blocklist controls, and firewall audit events. These tools keep request protection under administrator control and can be disabled temporarily for troubleshooting.<\/p>\n\n<h4>File Integrity and File-Change Monitoring<\/h4>\n\n<p>Web Plura Security Center keeps local file-change and integrity context to help administrators review important changes.<\/p>\n\n<p>A changed file does not automatically mean a website has been compromised. File-change and baseline information is meant to help administrators compare expected changes, such as updates or deployments, with changes that deserve closer review.<\/p>\n\n<h4>Plugin Checksum Verification<\/h4>\n\n<p>Where supported, administrators can run checksum verification against the WordPress.org Plugin Checksums API.<\/p>\n\n<p>This can help identify differences between supported installed plugin files and the files expected for a known WordPress.org plugin release. Checksum verification is an integrity check, not guaranteed malware detection.<\/p>\n\n<h4>Security Hardening Checks<\/h4>\n\n<p>Web Plura Security Center includes local checks and controls that help administrators review common WordPress exposure points.<\/p>\n\n<p>Supported areas include security headers, XML-RPC exposure, API exposure notes, debug-log exposure, file permissions, executable files in uploads, public backup\/archive indicators, file editor exposure, administrator\/user risk, and update posture.<\/p>\n\n<p>These checks are intended to provide practical review context. They should be used with secure hosting, regular updates, strong credentials, reliable backups, and careful administrator review.<\/p>\n\n<h4>Admin\/User Risk and File Integrity Checks<\/h4>\n\n<p>The Admin\/User Risk &amp; File Integrity advisor reviews supported security conditions such as:<\/p>\n\n<ul>\n<li>administrator changes<\/li>\n<li>user-registration role exposure<\/li>\n<li>relevant file permissions<\/li>\n<li>executable files in upload locations<\/li>\n<li>exposed debug-log indicators<\/li>\n<li>publicly accessible archive indicators<\/li>\n<li>recent component changes<\/li>\n<\/ul>\n\n<p>These checks are advisory and read-only. They do not silently modify users, roles, files, or approved baselines.<\/p>\n\n<h4>Security Findings and Reports<\/h4>\n\n<p>Web Plura Security Center provides security findings, incident visibility, local reports, security history, and administrative guidance for supported local checks.<\/p>\n\n<p>Findings are intended to provide enough context for an administrator to decide what deserves investigation. Not every warning is a confirmed security breach.<\/p>\n\n<h4>Security Notifications<\/h4>\n\n<p>Where configured and supported by the current release, administrators can receive security-related email notifications.<\/p>\n\n<p>The free plugin does not claim SMS, push notifications, external monitoring, or continuous cloud monitoring.<\/p>\n\n<h4>Additional Security Advisors<\/h4>\n\n<p>Web Plura Security Center also includes secondary local advisors that can help administrators review related risk signals.<\/p>\n\n<p>The Form Abuse &amp; Lead Security advisor reviews supported local signals involving installed form plugins, likely lead pages, SMTP configuration, update status, privacy-page configuration, and risky form markers.<\/p>\n\n<p>These checks run locally according to the current plugin implementation. The advisor does not submit forms, capture leads for external analysis, analyze private lead content externally, or upload lead data to Web Plura.<\/p>\n\n<h4>Who Is This For?<\/h4>\n\n<p>Web Plura Security Center can be useful when you need to:<\/p>\n\n<ul>\n<li>investigate unexpected or suspicious files;<\/li>\n<li>scan for malware indicators and supported security risks;<\/li>\n<li>improve WordPress login security;<\/li>\n<li>enable two-factor authentication, passkeys, or backup codes;<\/li>\n<li>review file changes after plugin, theme, or deployment activity;<\/li>\n<li>check risky file permissions, debug-log exposure, public archives, and upload executable markers;<\/li>\n<li>inspect security headers, XML-RPC exposure, and common configuration issues;<\/li>\n<li>verify supported plugin files against WordPress.org checksums;<\/li>\n<li>reduce repeated abusive login or request attempts with local firewall controls;<\/li>\n<li>keep local security findings, reports, and privacy tools available inside WordPress.<\/li>\n<\/ul>\n\n<h4>Local-First Security and Privacy<\/h4>\n\n<p>The WordPress.org version is designed so that its included local security functionality can operate without requiring a Web Plura Cloud account.<\/p>\n\n<p>Local security functionality should be understood as local WordPress-site functionality. The free plugin stores plugin-owned security metadata in the site's WordPress database, including local settings, contact or notification email settings when configured, login-security metadata, audit events, hashed or prefix IP evidence, blocked IP records, file-baseline summaries, and local report or scan state.<\/p>\n\n<p>The free plugin does not automatically upload suspicious file samples, form-advisor data, administrator\/user-risk data, file-baseline history, setup-checklist information, or local security reports to Web Plura Cloud.<\/p>\n\n<p>The plugin registers applicable WordPress Privacy Tools exporter and eraser callbacks for plugin-owned security metadata. Uninstall removes applicable plugin options, scheduled hooks, and plugin-owned custom database tables.<\/p>\n\n<h4>Limitations and Important Notes<\/h4>\n\n<p>No WordPress security plugin can guarantee that every attack, malicious file, compromised account, vulnerability, or intrusion will always be detected.<\/p>\n\n<p>Web Plura Security Center provides security checks and administrative tools intended to help site owners identify and investigate supported security risks. Administrators should maintain secure hosting, strong credentials, current WordPress core, plugins and themes, reliable backups, and other appropriate security practices.<\/p>\n\n<p>Suspicious-file findings, checksum differences, file-change signals, administrator warnings, and hardening checks should be reviewed before action is taken. A finding indicates something worth reviewing; it does not automatically prove that the site has been compromised.<\/p>\n\n<p>Backup, restore, and disaster recovery workflows are handled by the standalone Web Plura Backup &amp; Restore Manager plugin.<\/p>\n\n<h3>Optional Web Plura Services<\/h3>\n\n<p>The WordPress.org package is fully functional for its included local security checks, login protection, firewall controls, file-integrity context, incident visibility, reports, administrator guidance, privacy tools, and plugin-owned data controls.<\/p>\n\n<p>Separately installed or hosted Web Plura services may provide additional account-backed services, hosted operations, or cross-site workflows.<\/p>\n\n<p>Those services are not required for the local functionality included in this WordPress.org plugin.<\/p>\n\n<p>The free plugin does not require Pro, Web Plura Cloud, account login, subscription, license, entitlement, checkout, or a hosted service for its included local controls.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This free plugin does not connect to Web Plura Cloud. It may contact these third-party services only when an administrator enables or runs the related local feature:<\/p>\n\n<p>Administrator consent is required before optional CAPTCHA checks or checksum verification checks use those external services.<\/p>\n\n<ul>\n<li>WordPress.org Plugin Checksums API: https:\/\/api.wordpress.org\/plugins\/checksums\/1.0\/\n\n<ul>\n<li>Purpose: verifies installed plugin files against WordPress.org checksums when an administrator runs checksum verification.<\/li>\n<li>Data sent: plugin slug and version identifiers needed for checksum lookup.<\/li>\n<li>Runs: only when checksum verification checks are run.<\/li>\n<li>Terms: https:\/\/wordpress.org\/about\/terms\/<\/li>\n<li>Privacy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul><\/li>\n<li>Cloudflare Turnstile: https:\/\/challenges.cloudflare.com\n\n<ul>\n<li>Purpose: loads the selected Turnstile challenge and verifies CAPTCHA responses when an administrator enables Cloudflare Turnstile for login protection.<\/li>\n<li>Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.<\/li>\n<li>Runs: only on configured login surfaces after the administrator enables Turnstile and saves Cloudflare keys.<\/li>\n<li>Terms: https:\/\/www.cloudflare.com\/website-terms\/<\/li>\n<li>Privacy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<li>Turnstile Privacy Addendum: https:\/\/www.cloudflare.com\/turnstile-privacy-policy\/<\/li>\n<\/ul><\/li>\n<li>hCaptcha: https:\/\/js.hcaptcha.com and https:\/\/hcaptcha.com\n\n<ul>\n<li>Purpose: loads the selected hCaptcha challenge and verifies CAPTCHA responses when an administrator enables hCaptcha for login protection.<\/li>\n<li>Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.<\/li>\n<li>Runs: only on configured login surfaces after the administrator enables hCaptcha and saves hCaptcha keys.<\/li>\n<li>Terms: https:\/\/www.hcaptcha.com\/terms<\/li>\n<li>Privacy: https:\/\/www.hcaptcha.com\/privacy<\/li>\n<\/ul><\/li>\n<li>Google reCAPTCHA: https:\/\/www.google.com\/recaptcha\/\n\n<ul>\n<li>Purpose: loads the selected reCAPTCHA challenge and verifies CAPTCHA responses when an administrator enables Google reCAPTCHA for login protection.<\/li>\n<li>Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.<\/li>\n<li>Runs: only on configured login surfaces after the administrator enables reCAPTCHA and saves Google reCAPTCHA keys.<\/li>\n<li>Terms: https:\/\/policies.google.com\/terms<\/li>\n<li>Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<p>Suspicious files, advisor data, admin\/user risk data, file baselines, and setup checklist data are not uploaded by the free plugin.<\/p>\n\n<p>No third-party executable PHP\/JS code is loaded except administrator-enabled CAPTCHA provider scripts. Plugin\/theme updates are not served from non-WordPress.org channels.<\/p>\n\n<p>Some payment, social, CDN, or static-hosting domains may appear in local scanner allowlists for false-positive reduction. They are detection references only and are not enqueued or executed by the free plugin.<\/p>\n\n<h3>Resources<\/h3>\n\n<ul>\n<li>Product page: https:\/\/wplura.com\/products\/web-plura-security-center<\/li>\n<li>Documentation: https:\/\/wplura.com\/docs<\/li>\n<li>Legal Center: https:\/\/wplura.com\/legal\nSupport: https:\/\/wplura.com\/support\nAbout: https:\/\/wplura.com\/about\nContact Us: https:\/\/wplura.com\/contact\nSecurity Disclosure: https:\/\/wplura.com\/security\nTerms of Service: https:\/\/wplura.com\/terms\nPrivacy Policy: https:\/\/wplura.com\/privacy<\/li>\n<li>Terms: https:\/\/wplura.com\/terms<\/li>\n<li>Privacy: https:\/\/wplura.com\/privacy\nCookie Policy: https:\/\/wplura.com\/cookie-policy\nAcceptable Use Policy: https:\/\/wplura.com\/acceptable-use\nData Processing Addendum (DPA): https:\/\/wplura.com\/data-processing-addendum\nService Level Agreement (SLA): https:\/\/wplura.com\/service-level-agreement<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Install Web Plura Security Center from the WordPress Plugin Directory, or upload the plugin ZIP through WordPress.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open Web Plura Security Center in wp-admin.<\/li>\n<li>Review the security dashboard and configure the local security features you want to use.<\/li>\n<li>Run an initial local security scan.<\/li>\n<li>Configure optional login-security or CAPTCHA functionality only if needed.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20web%20plura%20cloud%20account%3F\"><h3>Do I need a Web Plura Cloud account?<\/h3><\/dt>\n<dd><p>No. The included local security checks and core local administration workflows work without a Web Plura Cloud account.<\/p><\/dd>\n<dt id=\"can%20web%20plura%20security%20center%20scan%20for%20suspicious%20files%3F\"><h3>Can Web Plura Security Center scan for suspicious files?<\/h3><\/dt>\n<dd><p>Yes. The plugin includes local scanning for suspicious files, malware indicators, risky configuration, and supported security risks. Findings are intended to help administrators identify items that need investigation.<\/p><\/dd>\n<dt id=\"does%20it%20detect%20malware%3F\"><h3>Does it detect malware?<\/h3><\/dt>\n<dd><p>It can scan for suspicious files and malware indicators, but automated scanning cannot guarantee detection of every possible compromise. A finding should be reviewed as a security signal, not treated as automatic proof of malware.<\/p><\/dd>\n<dt id=\"can%20it%20tell%20me%20whether%20my%20wordpress%20site%20has%20been%20hacked%3F\"><h3>Can it tell me whether my WordPress site has been hacked?<\/h3><\/dt>\n<dd><p>The plugin can identify supported security signals such as suspicious files, malware indicators, unexpected file changes, and risky configuration. These findings may help investigate a suspected compromise, but a scan result alone cannot guarantee whether every intrusion has or has not occurred.<\/p><\/dd>\n<dt id=\"does%20it%20monitor%20file%20changes%3F\"><h3>Does it monitor file changes?<\/h3><\/dt>\n<dd><p>Yes. The plugin keeps local file-change and baseline context to help administrators review important changes. A changed file does not automatically mean the site has been compromised.<\/p><\/dd>\n<dt id=\"does%20it%20include%20firewall%20protection%3F\"><h3>Does it include firewall protection?<\/h3><\/dt>\n<dd><p>Yes. The plugin includes supported local firewall controls such as request inspection, rate limiting, temporary blocking, and local allowlist\/blocklist controls.<\/p><\/dd>\n<dt id=\"does%20it%20provide%20wordpress%20login%20protection%3F\"><h3>Does it provide WordPress login protection?<\/h3><\/dt>\n<dd><p>Yes. The plugin includes supported login-protection controls such as request rate limiting, temporary blocking, 2FA, passkeys, backup codes, and optional CAPTCHA protection.<\/p><\/dd>\n<dt id=\"does%20it%20support%20two-factor%20authentication%20or%20passkeys%3F\"><h3>Does it support two-factor authentication or passkeys?<\/h3><\/dt>\n<dd><p>Yes. Supported users can configure two-factor authentication, and passkey availability can depend on the browser, device, site configuration, and supported plugin implementation. Backup codes can be used where supported as a recovery method.<\/p><\/dd>\n<dt id=\"are%20suspicious%20files%20deleted%20automatically%3F\"><h3>Are suspicious files deleted automatically?<\/h3><\/dt>\n<dd><p>No. Security findings should be reviewed before potentially destructive actions are taken. The plugin provides findings and supported remediation context so administrators can investigate before acting.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20automatically%20upload%20suspicious%20files%3F\"><h3>Does the plugin automatically upload suspicious files?<\/h3><\/dt>\n<dd><p>No. Suspicious file sample upload is not part of the free local plugin.<\/p><\/dd>\n<dt id=\"does%20it%20compare%20plugin%20files%20with%20wordpress.org%20checksums%3F\"><h3>Does it compare plugin files with WordPress.org checksums?<\/h3><\/dt>\n<dd><p>Where supported, administrators can run checksum verification against the WordPress.org Plugin Checksums API. This is an integrity check and does not guarantee malware detection.<\/p><\/dd>\n<dt id=\"does%20it%20check%20wordpress%20file%20permissions%20and%20hardening%20risks%3F\"><h3>Does it check WordPress file permissions and hardening risks?<\/h3><\/dt>\n<dd><p>Yes. Supported hardening and admin\/user risk checks include file permission signals, executable files in upload locations, debug-log exposure, public archive indicators, security headers, XML-RPC exposure, and recent component changes.<\/p><\/dd>\n<dt id=\"does%20form%20abuse%20%26%20lead%20security%20send%20lead%20data%20anywhere%3F\"><h3>Does Form Abuse &amp; Lead Security send lead data anywhere?<\/h3><\/dt>\n<dd><p>No. The advisor performs supported local checks and does not submit forms or upload collected lead content to Web Plura.<\/p><\/dd>\n<dt id=\"does%20admin%2Fuser%20risk%20%26%20file%20integrity%20change%20my%20site%3F\"><h3>Does Admin\/User Risk &amp; File Integrity change my site?<\/h3><\/dt>\n<dd><p>No. The advisor is read-only and does not silently modify users, roles, files, or approved baselines.<\/p><\/dd>\n<dt id=\"what%20data%20leaves%20the%20wordpress%20site%3F\"><h3>What data leaves the WordPress site?<\/h3><\/dt>\n<dd><p>The free plugin does not send site security data to Web Plura Cloud by default. Optional external services may receive limited data only when the related feature is enabled or run by an administrator, such as checksum lookup requests to WordPress.org or CAPTCHA requests to the selected CAPTCHA provider.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20collect%20personal%20data%20by%20default%3F\"><h3>Does this plugin collect personal data by default?<\/h3><\/dt>\n<dd><p>The free plugin stores plugin-owned security metadata locally in WordPress. Depending on configuration and site activity, this may include contact or notification email settings, login-security metadata, audit events, hashed or prefix IP evidence, blocked IP records, file-baseline summaries, and local settings or report state.<\/p>\n\n<p>The free plugin does not send site security data to Web Plura Cloud by default. If an administrator enables a CAPTCHA provider, that provider may receive browser request metadata, a CAPTCHA verification token, and the requester IP address as described in the External Services section.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20support%20wordpress%20privacy%20tools%20exports%2Ferasures%3F\"><h3>Does this plugin support WordPress Privacy Tools exports\/erasures?<\/h3><\/dt>\n<dd><p>Yes. The plugin registers applicable WordPress Privacy Tools exporter and eraser callbacks for plugin-owned security metadata.<\/p><\/dd>\n<dt id=\"can%20i%20remove%20all%20plugin%20data%20on%20uninstall%3F\"><h3>Can I remove all plugin data on uninstall?<\/h3><\/dt>\n<dd><p>Yes. Uninstall removes applicable plugin options, scheduled hooks, and plugin-owned custom database tables.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.11<\/h4>\n\n<ul>\n<li>Added explicit WPlura legal, help, contact, and disclosure resource labels for WordPress.org release compliance.<\/li>\n<\/ul>\n\n<h4>0.1.10<\/h4>\n\n<ul>\n<li>Improved WordPress.org compliance for paths, nonces, input sanitization, escaping, local scripts, and remote asset disclosures.<\/li>\n<\/ul>\n\n<h4>0.1.9<\/h4>\n\n<ul>\n<li>Removed product-local Cloud connection, entitlement, dashboard, remote scan, policy sync, and signed transport workflows from the WordPress.org package.<\/li>\n<li>Kept local fixes, emergency review controls, firewall controls, login protection, and integrity checks available without Pro, Cloud, subscription, or entitlement checks.<\/li>\n<\/ul>\n\n<h4>0.1.8<\/h4>\n\n<p>Kept Free issue fixes, remediation-plan execution, and emergency action controls independent from Web Plura Cloud, Pro, subscription, and entitlement checks.<\/p>\n\n<h4>0.1.7<\/h4>\n\n<p>Renamed the public display title, added local-only integrity baselines, tightened nonce\/passkey handling, expanded external-service disclosure, downgraded unsafe filesystem cleanup to manual guidance, and removed unused public key files.<\/p>\n\n<h4>0.1.6<\/h4>\n\n<p>Improved external-service consent wording, Upgrade page presentation, and dormant cloud-service wording.<\/p>\n\n<h4>0.1.5<\/h4>\n\n<p>Added a Free-owned local scan evidence resolver so Free and Pro share canonical scanner report, summary, timestamp, and score fallback behavior.<\/p>\n\n<h4>0.1.4<\/h4>\n\n<p>Added a Free-owned reports extension surface.<\/p>\n\n<h4>0.1.3<\/h4>\n\n<p>Formalized the dashboard capability panel slot as a reversible Free-owned extension surface for Security Center Pro.<\/p>\n\n<h4>0.1.1<\/h4>\n\n<p>Added stable admin extension slots while keeping free features local-only.<\/p>\n\n<h4>0.1.0<\/h4>\n\n<p>Initial public release with local scans, login protection, firewall controls, setup guidance, advisor checks, privacy tooling, and bounded local data handling.<\/p>","raw_excerpt":"Scan for suspicious files and security risks, strengthen login protection with 2FA\/passkeys, and manage firewall and file-integrity controls.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/355610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=355610"}],"author":[{"embeddable":true,"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wplura"}],"wp:attachment":[{"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=355610"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=355610"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=355610"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=355610"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=355610"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bg.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=355610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}