Web Plura Security Center

Popis

Web Plura Security Center

Web Plura Security Center helps WordPress site owners, developers, and administrators identify security problems, review suspicious activity, strengthen login security, monitor important file changes, and manage local security controls from the WordPress dashboard.

The free plugin is designed around local security checks. Core security scans, firewall controls, login protection, security advisors, reports, incident visibility, and privacy controls do not require a Web Plura Cloud account.

What You Can Review

Web Plura Security Center helps administrators review:

  • suspicious WordPress files and malware indicators
  • firewall and rate-limiting controls
  • login security, 2FA, passkeys, and backup codes
  • file-change baseline summaries
  • admin/user risk and file integrity checks
  • form abuse and lead security checks
  • security reports and privacy tools

WordPress Security Scanner

Run local security checks to identify suspicious files, malware indicators, risky configuration, and other security findings that may need investigation.

The scanner helps administrators review potential security problems without automatically treating every unusual file as malware. Use the scan results and available remediation context to investigate findings before making potentially destructive changes.

Suspicious Files and Malware Indicators

Unexpected files or file changes can sometimes indicate a compromised WordPress installation, but legitimate plugin updates, theme updates, administrators, hosting tools, and deployment processes can also modify files.

Web Plura Security Center helps identify suspicious files and malware indicators so administrators can review them with appropriate context. The plugin does not claim that every suspicious file is malicious or that automated scanning can detect every possible compromise.

WordPress Firewall Controls

Web Plura Security Center includes local firewall controls designed to help reduce repeated or abusive requests.

Available protections include supported rate-limiting and temporary-blocking controls. These tools can add another layer of protection for WordPress installations while keeping firewall configuration under administrator control.

WordPress Security Hardening Checks

Web Plura Security Center includes supported hardening checks and controls that help administrators review common WordPress exposure points.

Supported areas include security headers, XML-RPC exposure, API exposure notes, debug-log exposure, file permissions, executable files in upload locations, public archive indicators, file editor exposure, and update posture.

These checks are designed to provide practical context for administrator review. They should be used alongside secure hosting, regular updates, strong credentials, and reliable backups.

WordPress Login Security

Account security is an important part of protecting a WordPress website. Web Plura Security Center includes supported login-security controls such as:

  • Two-factor authentication (2FA)
  • Passkeys
  • Backup authentication codes
  • Login-protection controls
  • Request rate limiting
  • Temporary blocking
  • Optional CAPTCHA protection

Two-Factor Authentication

Supported users can configure two-factor authentication to add another verification step to WordPress login.

Two-factor authentication can help reduce the risk associated with compromised or reused passwords. It does not guarantee account security.

Passkeys

Where supported by the user’s browser, device, WordPress environment, and current plugin implementation, passkeys can provide another authentication option for WordPress accounts.

Users can manage passkey enrollment through the controls provided by the plugin. Passkey availability depends on the browser, device, site configuration, and supported plugin implementation.

Optional CAPTCHA Login Protection

Administrators can optionally configure supported CAPTCHA providers for applicable login protection.

CAPTCHA functionality is not required for the plugin’s core local security checks. External CAPTCHA services are contacted only when the related feature is enabled and configured by an administrator.

File Integrity and File-Change Monitoring

Web Plura Security Center provides bounded local file-change baseline information to help administrators identify important changes that deserve investigation.

A changed file does not automatically mean a website has been compromised. The feature is intended to provide additional security context when investigating unexpected changes. Baseline information remains local according to the plugin’s documented data-handling behavior.

Plugin Checksum Verification

Where supported, administrators can run checksum verification against the WordPress.org Plugin Checksums API.

This can help identify differences between supported installed plugin files and the files expected for a known WordPress.org plugin release. Checksum verification is an integrity check, not guaranteed malware detection.

Admin/User Risk and File Integrity Checks

The Admin/User Risk & File Integrity advisor reviews supported security conditions such as:

  • administrator changes
  • user-registration role exposure
  • relevant file permissions
  • executable files in upload locations
  • exposed debug-log indicators
  • publicly accessible archive indicators
  • recent component changes

These checks are advisory and read-only. They do not silently modify users, roles, files, or approved baselines.

Form Abuse and Lead Security Checks

The Form Abuse & Lead Security advisor reviews supported local security signals involving areas such as:

  • installed form plugins
  • relevant lead pages
  • SMTP configuration
  • update status
  • privacy-page configuration
  • risky form markers

These checks run locally according to the current plugin implementation. The advisor does not submit forms, capture leads for external analysis, analyze private lead content externally, or upload lead data to Web Plura.

Threat Alerts and Security Findings

Web Plura Security Center provides security findings, threat alerts, incident visibility, reports, and administrative guidance for supported local checks.

Findings are intended to provide enough context for an administrator to decide what deserves investigation. Not every warning is a confirmed security breach.

Security Notifications

Where configured and supported by the current release, administrators can receive security-related email notifications.

The free plugin does not claim SMS, push notifications, external monitoring, or continuous cloud monitoring.

Local-First Security

The WordPress.org version is designed so that its included local security functionality can operate without requiring a Web Plura Cloud account.

Core local functions include supported:

  • security scans
  • suspicious-file checks
  • malware-indicator checks
  • firewall controls
  • login protection
  • security advisors
  • file-change baseline information
  • incident visibility
  • security reports
  • privacy controls

Privacy and Data Control

Local security functionality should be understood as local WordPress-site functionality. The free plugin stores plugin-owned security metadata in the site’s WordPress database, including local settings, contact or notification email settings when configured, login-security metadata, audit events, hashed or prefix IP evidence, blocked IP records, file-baseline summaries, and local report or scan state.

The free plugin does not automatically upload suspicious file samples, form-advisor data, administrator/user-risk data, file-baseline history, setup-checklist information, or local security reports to Web Plura Cloud.

The plugin registers applicable WordPress Privacy Tools exporter and eraser callbacks for plugin-owned security metadata. Uninstall removes applicable plugin options, scheduled hooks, and plugin-owned custom database tables.

Who Is Web Plura Security Center For?

Web Plura Security Center can be useful for:

  • WordPress site owners
  • developers
  • administrators
  • agencies
  • website maintenance teams
  • operations teams

Typical use cases include investigating suspicious WordPress files, reviewing security configuration, strengthening login security, monitoring unexpected file changes, reviewing administrator-related risks, and managing supported firewall controls.

What the Plugin Does Not Promise

No WordPress security plugin can guarantee that every attack, malicious file, compromised account, vulnerability, or intrusion will always be detected.

Web Plura Security Center provides security checks and administrative tools intended to help site owners identify and investigate supported security risks. Administrators should maintain secure hosting, strong credentials, current WordPress core, plugins and themes, reliable backups, and other appropriate security practices.

Optional Web Plura Services

The WordPress.org package is fully functional for its included local security checks, login protection, firewall controls, incident visibility, reports, administrator guidance, privacy tools, and plugin-owned data controls.

Separately installed or hosted Web Plura services may provide additional account-backed services, hosted operations, or cross-site workflows.

Those services are not required for the local functionality included in this WordPress.org plugin.

External Services

This free plugin does not connect to Web Plura Cloud. It may contact these third-party services only when an administrator enables or runs the related local feature:

Administrator consent is required before optional CAPTCHA checks or checksum verification checks use those external services.

  • WordPress.org Plugin Checksums API: https://api.wordpress.org/plugins/checksums/1.0/
    • Purpose: verifies installed plugin files against WordPress.org checksums when an administrator runs checksum verification.
    • Data sent: plugin slug and version identifiers needed for checksum lookup.
    • Runs: only when checksum verification checks are run.
    • Terms: https://wordpress.org/about/terms/
    • Privacy: https://wordpress.org/about/privacy/
  • Cloudflare Turnstile: https://challenges.cloudflare.com
    • Purpose: loads the selected Turnstile challenge and verifies CAPTCHA responses when an administrator enables Cloudflare Turnstile for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables Turnstile and saves Cloudflare keys.
    • Terms: https://www.cloudflare.com/website-terms/
    • Privacy: https://www.cloudflare.com/privacypolicy/
    • Turnstile Privacy Addendum: https://www.cloudflare.com/turnstile-privacy-policy/
  • hCaptcha: https://js.hcaptcha.com and https://hcaptcha.com
    • Purpose: loads the selected hCaptcha challenge and verifies CAPTCHA responses when an administrator enables hCaptcha for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables hCaptcha and saves hCaptcha keys.
    • Terms: https://www.hcaptcha.com/terms
    • Privacy: https://www.hcaptcha.com/privacy
  • Google reCAPTCHA: https://www.google.com/recaptcha/
    • Purpose: loads the selected reCAPTCHA challenge and verifies CAPTCHA responses when an administrator enables Google reCAPTCHA for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables reCAPTCHA and saves Google reCAPTCHA keys.
    • Terms: https://policies.google.com/terms
    • Privacy: https://policies.google.com/privacy

Suspicious files, advisor data, admin/user risk data, file baselines, and setup checklist data are not uploaded by the free plugin.

No third-party executable PHP/JS code is loaded except administrator-enabled CAPTCHA provider scripts. Plugin/theme updates are not served from non-WordPress.org channels.

Some payment, social, CDN, or static-hosting domains may appear in local scanner allowlists for false-positive reduction. They are detection references only and are not enqueued or executed by the free plugin.

Resources

  • Product page: https://wplura.com/products/web-plura-security-center
  • Documentation: https://wplura.com/docs
  • Legal Center: https://wplura.com/legal
  • Support: https://wplura.com/support
    About: https://wplura.com/about
    Contact Us: https://wplura.com/contact
    Security Disclosure: https://wplura.com/security
    Terms: https://wplura.com/terms
    Privacy: https://wplura.com/privacy
    Cookie Policy: https://wplura.com/cookie-policy
    Acceptable Use Policy: https://wplura.com/acceptable-use
    Data Processing Addendum (DPA): https://wplura.com/data-processing-addendum
    Service Level Agreement (SLA): https://wplura.com/service-level-agreement

Snímky obrazovky

Instalace

  1. Install Web Plura Security Center from the WordPress Plugin Directory, or upload the plugin ZIP through WordPress.
  2. Activate the plugin.
  3. Open Web Plura Security Center in wp-admin.
  4. Review the security dashboard and configure the local security features you want to use.
  5. Run an initial local security scan.
  6. Configure optional login-security or CAPTCHA functionality only if needed.

Nejčastější dotazy

Do I need a Web Plura Cloud account?

No. The included local security checks and core local administration workflows work without a Web Plura Cloud account.

Is Web Plura Security Center a malware scanner?

It includes local scanning for suspicious files, malware indicators, and supported security risks. Findings are intended to help administrators identify items that need investigation. Automated scanning cannot guarantee detection of every possible compromise.

Can it tell me whether my WordPress site has been hacked?

The plugin can identify supported security signals such as suspicious files, malware indicators, unexpected file changes, and risky configuration. These findings may help investigate a suspected compromise, but a scan result alone cannot guarantee whether every intrusion has or has not occurred.

Does it include firewall protection?

Yes. The plugin includes supported local firewall controls such as rate limiting and temporary blocking.

Does it help with brute-force login protection?

Yes. The plugin includes supported login-protection controls such as request rate limiting, temporary blocking, 2FA, passkeys, backup codes, and optional CAPTCHA protection.

Does it protect WordPress login?

The plugin includes supported login-security functionality such as 2FA, passkeys, backup codes, rate limiting, temporary blocking, and optional CAPTCHA protection.

Does it support two-factor authentication?

Yes. Supported users can configure two-factor authentication as an additional login-security measure.

Does it support passkeys?

Yes. Passkey availability can depend on the browser, device, site configuration, and supported plugin implementation.

Are suspicious files deleted automatically?

No. Security findings should be reviewed before potentially destructive actions are taken. The plugin provides findings and supported remediation context so administrators can investigate before acting.

Does the plugin automatically upload suspicious files?

No. Suspicious file sample upload is not part of the free local plugin.

Does Form Abuse & Lead Security send lead data anywhere?

No. The advisor performs supported local checks and does not submit forms or upload collected lead content to Web Plura.

Does Admin/User Risk & File Integrity change my site?

No. The advisor is read-only and does not silently modify users, roles, files, or approved baselines.

Are local file baseline details uploaded?

No. File-change baseline summaries are stored locally with bounded retention.

Does it check WordPress file permissions?

Yes. Supported admin/user risk and file integrity checks include relevant file permission signals, executable files in upload locations, debug-log exposure, public archive indicators, and recent component changes.

Does it include security headers controls?

Yes. The plugin includes supported security headers controls and local review context for administrators.

Does it detect suspicious administrator changes?

The Admin/User Risk & File Integrity advisor reviews supported administrator-change signals and local drift context so administrators can investigate account-related risk.

Does it compare plugin files with WordPress.org checksums?

Where supported, administrators can run checksum verification against the WordPress.org Plugin Checksums API. This is an integrity check and does not guarantee malware detection.

Does this plugin collect personal data by default?

The free plugin stores plugin-owned security metadata locally in WordPress. Depending on configuration and site activity, this may include contact or notification email settings, login-security metadata, audit events, hashed or prefix IP evidence, blocked IP records, file-baseline summaries, and local settings or report state.

The free plugin does not send site security data to Web Plura Cloud by default. If an administrator enables a CAPTCHA provider, that provider may receive browser request metadata, a CAPTCHA verification token, and the requester IP address as described in the External Services section.

Does this plugin support WordPress Privacy Tools exports/erasures?

Yes. The plugin registers applicable WordPress Privacy Tools exporter and eraser callbacks for plugin-owned security metadata.

Can I remove all plugin data on uninstall?

Yes. Uninstall removes applicable plugin options, scheduled hooks, and plugin-owned custom database tables.

Where can I get support or contact your team?

  • Support: https://wplura.com/support
  • Documentation: https://wplura.com/docs
  • Security disclosure: https://wplura.com/security

Recenze

Pro tento plugin nejsou žádné recenze.

Autoři

Web Plura Security Center je otevřený software. Následující lidé přispěli k vývoji tohoto pluginu.

Spolupracovníci

Přehled změn

0.1.11

  • Added explicit WPlura legal, help, contact, and disclosure resource labels for WordPress.org release compliance.

0.1.10

  • Improved WordPress.org compliance for paths, nonces, input sanitization, escaping, local scripts, and remote asset disclosures.

0.1.9

  • Removed product-local Cloud connection, entitlement, dashboard, remote scan, policy sync, and signed transport workflows from the WordPress.org package.
  • Kept local fixes, emergency review controls, firewall controls, login protection, and integrity checks available without Pro, Cloud, subscription, or entitlement checks.

0.1.8

Kept Free issue fixes, remediation-plan execution, and emergency action controls independent from Web Plura Cloud, Pro, subscription, and entitlement checks.

0.1.7

Renamed the public display title, added local-only integrity baselines, tightened nonce/passkey handling, expanded external-service disclosure, downgraded unsafe filesystem cleanup to manual guidance, and removed unused public key files.

0.1.6

Improved external-service consent wording, Upgrade page presentation, and dormant cloud-service wording.

0.1.5

Added a Free-owned local scan evidence resolver so Free and Pro share canonical scanner report, summary, timestamp, and score fallback behavior.

0.1.4

Added a Free-owned reports extension surface.

0.1.3

Formalized the dashboard capability panel slot as a reversible Free-owned extension surface for Security Center Pro.

0.1.1

Added stable admin extension slots while keeping free features local-only.

0.1.0

Initial public release with local scans, login protection, firewall controls, setup guidance, advisor checks, privacy tooling, and bounded local data handling.