Web Plura Security Center

Wopisanje

Web Plura Security Center helps site owners and operations teams detect, track, and fix security issues.

Product page: https://wplura.com/products/web-plura-security-center
Terms: https://wplura.com/terms
Privacy: https://wplura.com/privacy
Support: https://wplura.com/support
More: https://wplura.com/about, https://wplura.com/contact, https://wplura.com/security, https://wplura.com/docs, https://wplura.com/legal, https://wplura.com/cookie-policy, https://wplura.com/acceptable-use, https://wplura.com/data-processing-addendum, https://wplura.com/service-level-agreement

Optional Web Plura Services

The WordPress.org package is fully functional for local security checks, login protection, firewall controls, incident visibility, reports, admin guidance, privacy tools, and plugin-owned data controls. Separately installed or hosted Web Plura services may offer account-backed support, hosted security operations, or cross-site workflows, but they are not required for the local features included here.

Core capabilities:

  • Local security scans for suspicious files, malware indicators, and risky configuration.
  • Local setup templates, score checklist, and bounded file-change baseline summaries.
  • Local Form Abuse & Lead Security advisor for form plugins, lead pages, SMTP, privacy page, updates, and risky form markers.
  • Local Admin/User Risk & File Integrity advisor for administrator drift, registration role exposure, permissions, upload executables, debug logs, public archives, and recent component changes.
  • Firewall rules with rate limiting and temporary blocking controls.
  • Incident tracking, audit visibility, and email notification support in wp-admin.

Local advisors read only the WordPress data and bounded filesystem markers needed for their checks. They do not submit forms, collect lead content, change users or files, send telemetry, upload baseline history, or require Web Plura Cloud.

External Services

This free plugin does not connect to Web Plura Cloud. It may contact these third-party services only when an administrator enables the related local feature:

Administrator consent is required before optional CAPTCHA checks or checksum verification checks use those external services.

  • WordPress.org Plugin Checksums API: https://api.wordpress.org/plugins/checksums/1.0/
    • Purpose: verifies installed plugin files against WordPress.org checksums when an administrator runs checksum verification.
    • Data sent: plugin slug and version identifiers needed for checksum lookup.
    • Runs: only when checksum verification checks are run.
    • Terms: https://wordpress.org/about/terms/
    • Privacy: https://wordpress.org/about/privacy/
  • Cloudflare Turnstile: https://challenges.cloudflare.com
    • Purpose: loads the selected Turnstile challenge and verifies CAPTCHA responses when an administrator enables Cloudflare Turnstile for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables Turnstile and saves Cloudflare keys.
    • Terms: https://www.cloudflare.com/website-terms/
    • Privacy: https://www.cloudflare.com/privacypolicy/
    • Turnstile Privacy Addendum: https://www.cloudflare.com/turnstile-privacy-policy/
  • hCaptcha: https://js.hcaptcha.com and https://hcaptcha.com
    • Purpose: loads the selected hCaptcha challenge and verifies CAPTCHA responses when an administrator enables hCaptcha for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables hCaptcha and saves hCaptcha keys.
    • Terms: https://www.hcaptcha.com/terms
    • Privacy: https://www.hcaptcha.com/privacy
  • Google reCAPTCHA: https://www.google.com/recaptcha/
    • Purpose: loads the selected reCAPTCHA challenge and verifies CAPTCHA responses when an administrator enables Google reCAPTCHA for login protection.
    • Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.
    • Runs: only on configured login surfaces after the administrator enables reCAPTCHA and saves Google reCAPTCHA keys.
    • Terms: https://policies.google.com/terms
    • Privacy: https://policies.google.com/privacy

Suspicious file samples, form-advisor data, admin/user risk data, file baseline history, and setup checklist data are not uploaded by the free plugin.

No third-party executable PHP/JS code is loaded except the administrator-enabled CAPTCHA provider scripts documented above. Plugin/theme updates are not served by this plugin from non-WordPress.org update channels.

Some payment, social, CDN, or static-hosting domains may appear in local scanner signature allowlists so the plugin can avoid false positives while reviewing site files. Those strings are detection references only. The free plugin does not enqueue or execute Stripe, Facebook, jsDelivr, or gstatic assets.

Screenshots

Instalacija

  1. Upload the web-plura-security-center folder to /wp-content/plugins/ (or install via ZIP in wp-admin).
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Open Web Plura Security Center in wp-admin.
  4. Run an initial local scan from the security dashboard.

FAQ

Do I need a cloud account?

No. Free local security checks and core admin workflows work without a cloud account.

What data is sent to the cloud?

None. The free plugin does not send site security data to Web Plura Cloud.

Does Form Abuse & Lead Security send lead data anywhere?

No. It checks installed plugins, published page markers, SMTP signals, update metadata, and privacy policy configuration locally.

Does Admin/User Risk & File Integrity change my site?

No. It is read-only and does not change users, roles, files, or baseline approvals.

Are local file baseline details uploaded?

No. File-change baseline summaries are stored locally with bounded retention.

Are suspicious files uploaded automatically?

No. Suspicious file sample upload is not part of the free plugin.

Does this plugin collect personal data by default?

The free plugin does not send site security data to Web Plura Cloud by default.

Does this plugin support WordPress Privacy Tools exports/erasures?

Yes. The plugin registers WordPress Privacy Tools exporter and eraser callbacks so administrators can process personal data requests for plugin-owned security metadata.

Can I remove all plugin data on uninstall?

Yes. Uninstall removes plugin options, scheduled hooks, and plugin custom database tables.

Where can I get support or contact your team?

  • Support: https://wplura.com/support
  • Contact Us: https://wplura.com/contact
  • Security Disclosure: https://wplura.com/security

Reviews

There are no reviews for this plugin.

Sobustatkujuce a wuwijarje

„Web Plura Security Center“ jo software wótwórjonego žrědła. Slědujuce luźe su pśinosowali k toś tomu tykacoju.

Sobustatkujuce

Changelog

0.1.10

  • Improved WordPress.org compliance for paths, nonces, input sanitization, escaping, local scripts, and remote asset disclosures.

0.1.9

  • Removed product-local Cloud connection, entitlement, dashboard, remote scan, policy sync, and signed transport workflows from the WordPress.org package.
  • Kept local fixes, emergency review controls, firewall controls, login protection, and integrity checks available without Pro, Cloud, subscription, or entitlement checks.

0.1.8

Kept Free issue fixes, remediation-plan execution, and emergency action controls independent from Web Plura Cloud, Pro, subscription, and entitlement checks.

0.1.7

Renamed the public display title, added local-only integrity baselines, tightened nonce/passkey handling, expanded external-service disclosure, downgraded unsafe filesystem cleanup to manual guidance, and removed unused public key files.

0.1.6

Improved external-service consent wording, Upgrade page presentation, and dormant cloud-service wording.

0.1.5

Added a Free-owned local scan evidence resolver so Free and Pro share canonical scanner report, summary, timestamp, and score fallback behavior.

0.1.4

Added a Free-owned reports extension surface.

0.1.3

Formalized the dashboard capability panel slot as a reversible Free-owned extension surface for Security Center Pro.

0.1.1

Added stable admin extension slots while keeping free features local-only.

0.1.0

Initial public release with local scans, login protection, firewall controls, setup guidance, advisor checks, privacy tooling, and bounded local data handling.