{"id":355610,"date":"2026-08-28T05:53:19","date_gmt":"2026-08-28T05:53:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/web-plura-security-center-login-protection-access-safety-local-checks\/"},"modified":"2026-08-28T05:53:00","modified_gmt":"2026-08-28T05:53:00","slug":"web-plura-security-center","status":"publish","type":"plugin","link":"https:\/\/dsb.wordpress.org\/plugins\/web-plura-security-center\/","author":23509928,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.10","stable_tag":"0.1.10","tested":"7.1","requires":"5.8","requires_php":"8.1","requires_plugins":null,"header_name":"Web Plura Security Center","header_author":"Web Plura","header_description":"Local login protection, access safety, malware checks, firewall controls, and admin security guidance for WordPress sites.","assets_banners_color":"333f56","last_updated":"2026-08-28 05:53:00","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":47,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.10":{"tag":"0.1.10","author":"wplura","date":"2026-08-28 05:53:00","revision":3669857}},"upgrade_notice":{"0.1.1":"<p>Adds free-owned extension slots so Security Center Pro can extend the local admin experience without replacing the free plugin shell.<\/p>","0.1.0":"<p>Initial public release of Web Plura Security Center with free local checks and WordPress-native security workflows.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3669857,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3669857,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3669857,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3669857,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.10"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3669857,"resolution":"1","location":"assets","locale":"","width":1440,"height":4696},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3669857,"resolution":"2","location":"assets","locale":"","width":1440,"height":11216},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3669857,"resolution":"3","location":"assets","locale":"","width":1440,"height":8239},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3669857,"resolution":"4","location":"assets","locale":"","width":1440,"height":2257},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3669857,"resolution":"5","location":"assets","locale":"","width":1440,"height":2023},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3669857,"resolution":"6","location":"assets","locale":"","width":1440,"height":9206},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3669857,"resolution":"7","location":"assets","locale":"","width":1440,"height":2851},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3669857,"resolution":"8","location":"assets","locale":"","width":1440,"height":3288}},"screenshots":{"1":"Security Dashboard overview with local protection and scan status.","2":"Security Center page with local setup templates, score checklist, and bounded file-change baseline summaries.","3":"Security Check page for quick and full local scans.","4":"Form Abuse &amp; Lead Security page for local lead capture exposure checks.","5":"Threat Alerts page listing suspicious findings and remediation context.","6":"Firewall controls for local request protection settings.","7":"User Profile Login Security controls for 2FA enrollment, passkeys, backup codes, and login availability notices.","8":"Settings page for local protection modules, notifications, SMTP delivery, and privacy\/data boundary status."}},"plugin_section":[],"plugin_tags":[1174,1184,5603,6464,600],"plugin_category":[54],"plugin_contributors":[266029],"plugin_business_model":[],"class_list":["post-355610","plugin","type-plugin","status-publish","hentry","plugin_tags-firewall","plugin_tags-malware","plugin_tags-monitoring","plugin_tags-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-wplura","plugin_committers-wplura"],"banners":{"banner":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/banner-772x250.png?rev=3669857","banner_2x":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/banner-1544x500.png?rev=3669857","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/icon-128x128.png?rev=3669857","icon_2x":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/icon-256x256.png?rev=3669857","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-1.png?rev=3669857","caption":"Security Dashboard overview with local protection and scan status."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-2.png?rev=3669857","caption":"Security Center page with local setup templates, score checklist, and bounded file-change baseline summaries."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-3.png?rev=3669857","caption":"Security Check page for quick and full local scans."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-4.png?rev=3669857","caption":"Form Abuse &amp; Lead Security page for local lead capture exposure checks."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-5.png?rev=3669857","caption":"Threat Alerts page listing suspicious findings and remediation context."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-6.png?rev=3669857","caption":"Firewall controls for local request protection settings."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-7.png?rev=3669857","caption":"User Profile Login Security controls for 2FA enrollment, passkeys, backup codes, and login availability notices."},{"src":"https:\/\/ps.w.org\/web-plura-security-center\/assets\/screenshot-8.png?rev=3669857","caption":"Settings page for local protection modules, notifications, SMTP delivery, and privacy\/data boundary status."}],"raw_content":"<!--section=description-->\n<p>Web Plura Security Center helps site owners and operations teams detect, track, and fix security issues.<\/p>\n\n<p>Product page: https:\/\/wplura.com\/products\/web-plura-security-center\nTerms: https:\/\/wplura.com\/terms\nPrivacy: https:\/\/wplura.com\/privacy\nSupport: https:\/\/wplura.com\/support\nMore: https:\/\/wplura.com\/about, https:\/\/wplura.com\/contact, https:\/\/wplura.com\/security, https:\/\/wplura.com\/docs, https:\/\/wplura.com\/legal, https:\/\/wplura.com\/cookie-policy, https:\/\/wplura.com\/acceptable-use, https:\/\/wplura.com\/data-processing-addendum, https:\/\/wplura.com\/service-level-agreement<\/p>\n\n<h3>Optional Web Plura Services<\/h3>\n\n<p>The WordPress.org package is fully functional for local security checks, login protection, firewall controls, incident visibility, reports, admin guidance, privacy tools, and plugin-owned data controls. Separately installed or hosted Web Plura services may offer account-backed support, hosted security operations, or cross-site workflows, but they are not required for the local features included here.<\/p>\n\n<p>Core capabilities:<\/p>\n\n<ul>\n<li>Local security scans for suspicious files, malware indicators, and risky configuration.<\/li>\n<li>Local setup templates, score checklist, and bounded file-change baseline summaries.<\/li>\n<li>Local Form Abuse &amp; Lead Security advisor for form plugins, lead pages, SMTP, privacy page, updates, and risky form markers.<\/li>\n<li>Local Admin\/User Risk &amp; File Integrity advisor for administrator drift, registration role exposure, permissions, upload executables, debug logs, public archives, and recent component changes.<\/li>\n<li>Firewall rules with rate limiting and temporary blocking controls.<\/li>\n<li>Incident tracking, audit visibility, and email notification support in wp-admin.<\/li>\n<\/ul>\n\n<p>Local advisors read only the WordPress data and bounded filesystem markers needed for their checks. They do not submit forms, collect lead content, change users or files, send telemetry, upload baseline history, or require Web Plura Cloud.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This free plugin does not connect to Web Plura Cloud. It may contact these third-party services only when an administrator enables the related local feature:<\/p>\n\n<p>Administrator consent is required before optional CAPTCHA checks or checksum verification checks use those external services.<\/p>\n\n<ul>\n<li>WordPress.org Plugin Checksums API: https:\/\/api.wordpress.org\/plugins\/checksums\/1.0\/\n\n<ul>\n<li>Purpose: verifies installed plugin files against WordPress.org checksums when an administrator runs checksum verification.<\/li>\n<li>Data sent: plugin slug and version identifiers needed for checksum lookup.<\/li>\n<li>Runs: only when checksum verification checks are run.<\/li>\n<li>Terms: https:\/\/wordpress.org\/about\/terms\/<\/li>\n<li>Privacy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul><\/li>\n<li>Cloudflare Turnstile: https:\/\/challenges.cloudflare.com\n\n<ul>\n<li>Purpose: loads the selected Turnstile challenge and verifies CAPTCHA responses when an administrator enables Cloudflare Turnstile for login protection.<\/li>\n<li>Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.<\/li>\n<li>Runs: only on configured login surfaces after the administrator enables Turnstile and saves Cloudflare keys.<\/li>\n<li>Terms: https:\/\/www.cloudflare.com\/website-terms\/<\/li>\n<li>Privacy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<li>Turnstile Privacy Addendum: https:\/\/www.cloudflare.com\/turnstile-privacy-policy\/<\/li>\n<\/ul><\/li>\n<li>hCaptcha: https:\/\/js.hcaptcha.com and https:\/\/hcaptcha.com\n\n<ul>\n<li>Purpose: loads the selected hCaptcha challenge and verifies CAPTCHA responses when an administrator enables hCaptcha for login protection.<\/li>\n<li>Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.<\/li>\n<li>Runs: only on configured login surfaces after the administrator enables hCaptcha and saves hCaptcha keys.<\/li>\n<li>Terms: https:\/\/www.hcaptcha.com\/terms<\/li>\n<li>Privacy: https:\/\/www.hcaptcha.com\/privacy<\/li>\n<\/ul><\/li>\n<li>Google reCAPTCHA: https:\/\/www.google.com\/recaptcha\/\n\n<ul>\n<li>Purpose: loads the selected reCAPTCHA challenge and verifies CAPTCHA responses when an administrator enables Google reCAPTCHA for login protection.<\/li>\n<li>Data sent: browser request metadata needed to load the challenge, the CAPTCHA verification token, and the requester IP address during verification.<\/li>\n<li>Runs: only on configured login surfaces after the administrator enables reCAPTCHA and saves Google reCAPTCHA keys.<\/li>\n<li>Terms: https:\/\/policies.google.com\/terms<\/li>\n<li>Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<p>Suspicious file samples, form-advisor data, admin\/user risk data, file baseline history, and setup checklist data are not uploaded by the free plugin.<\/p>\n\n<p>No third-party executable PHP\/JS code is loaded except the administrator-enabled CAPTCHA provider scripts documented above. Plugin\/theme updates are not served by this plugin from non-WordPress.org update channels.<\/p>\n\n<p>Some payment, social, CDN, or static-hosting domains may appear in local scanner signature allowlists so the plugin can avoid false positives while reviewing site files. Those strings are detection references only. The free plugin does not enqueue or execute Stripe, Facebook, jsDelivr, or gstatic assets.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>web-plura-security-center<\/code> folder to <code>\/wp-content\/plugins\/<\/code> (or install via ZIP in wp-admin).<\/li>\n<li>Activate the plugin through the <code>Plugins<\/code> screen in WordPress.<\/li>\n<li>Open <code>Web Plura Security Center<\/code> in wp-admin.<\/li>\n<li>Run an initial local scan from the security dashboard.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20cloud%20account%3F\"><h3>Do I need a cloud account?<\/h3><\/dt>\n<dd><p>No. Free local security checks and core admin workflows work without a cloud account.<\/p><\/dd>\n<dt id=\"what%20data%20is%20sent%20to%20the%20cloud%3F\"><h3>What data is sent to the cloud?<\/h3><\/dt>\n<dd><p>None. The free plugin does not send site security data to Web Plura Cloud.<\/p><\/dd>\n<dt id=\"does%20form%20abuse%20%26%20lead%20security%20send%20lead%20data%20anywhere%3F\"><h3>Does Form Abuse &amp; Lead Security send lead data anywhere?<\/h3><\/dt>\n<dd><p>No. It checks installed plugins, published page markers, SMTP signals, update metadata, and privacy policy configuration locally.<\/p><\/dd>\n<dt id=\"does%20admin%2Fuser%20risk%20%26%20file%20integrity%20change%20my%20site%3F\"><h3>Does Admin\/User Risk &amp; File Integrity change my site?<\/h3><\/dt>\n<dd><p>No. It is read-only and does not change users, roles, files, or baseline approvals.<\/p><\/dd>\n<dt id=\"are%20local%20file%20baseline%20details%20uploaded%3F\"><h3>Are local file baseline details uploaded?<\/h3><\/dt>\n<dd><p>No. File-change baseline summaries are stored locally with bounded retention.<\/p><\/dd>\n<dt id=\"are%20suspicious%20files%20uploaded%20automatically%3F\"><h3>Are suspicious files uploaded automatically?<\/h3><\/dt>\n<dd><p>No. Suspicious file sample upload is not part of the free plugin.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20collect%20personal%20data%20by%20default%3F\"><h3>Does this plugin collect personal data by default?<\/h3><\/dt>\n<dd><p>The free plugin does not send site security data to Web Plura Cloud by default.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20support%20wordpress%20privacy%20tools%20exports%2Ferasures%3F\"><h3>Does this plugin support WordPress Privacy Tools exports\/erasures?<\/h3><\/dt>\n<dd><p>Yes. The plugin registers WordPress Privacy Tools exporter and eraser callbacks so administrators can process personal data requests for plugin-owned security metadata.<\/p><\/dd>\n<dt id=\"can%20i%20remove%20all%20plugin%20data%20on%20uninstall%3F\"><h3>Can I remove all plugin data on uninstall?<\/h3><\/dt>\n<dd><p>Yes. Uninstall removes plugin options, scheduled hooks, and plugin custom database tables.<\/p><\/dd>\n<dt id=\"where%20can%20i%20get%20support%20or%20contact%20your%20team%3F\"><h3>Where can I get support or contact your team?<\/h3><\/dt>\n<dd><ul>\n<li>Support: https:\/\/wplura.com\/support<\/li>\n<li>Contact Us: https:\/\/wplura.com\/contact<\/li>\n<li>Security Disclosure: https:\/\/wplura.com\/security<\/li>\n<\/ul><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.10<\/h4>\n\n<ul>\n<li>Improved WordPress.org compliance for paths, nonces, input sanitization, escaping, local scripts, and remote asset disclosures.<\/li>\n<\/ul>\n\n<h4>0.1.9<\/h4>\n\n<ul>\n<li>Removed product-local Cloud connection, entitlement, dashboard, remote scan, policy sync, and signed transport workflows from the WordPress.org package.<\/li>\n<li>Kept local fixes, emergency review controls, firewall controls, login protection, and integrity checks available without Pro, Cloud, subscription, or entitlement checks.<\/li>\n<\/ul>\n\n<h4>0.1.8<\/h4>\n\n<p>Kept Free issue fixes, remediation-plan execution, and emergency action controls independent from Web Plura Cloud, Pro, subscription, and entitlement checks.<\/p>\n\n<h4>0.1.7<\/h4>\n\n<p>Renamed the public display title, added local-only integrity baselines, tightened nonce\/passkey handling, expanded external-service disclosure, downgraded unsafe filesystem cleanup to manual guidance, and removed unused public key files.<\/p>\n\n<h4>0.1.6<\/h4>\n\n<p>Improved external-service consent wording, Upgrade page presentation, and dormant cloud-service wording.<\/p>\n\n<h4>0.1.5<\/h4>\n\n<p>Added a Free-owned local scan evidence resolver so Free and Pro share canonical scanner report, summary, timestamp, and score fallback behavior.<\/p>\n\n<h4>0.1.4<\/h4>\n\n<p>Added a Free-owned reports extension surface.<\/p>\n\n<h4>0.1.3<\/h4>\n\n<p>Formalized the dashboard capability panel slot as a reversible Free-owned extension surface for Security Center Pro.<\/p>\n\n<h4>0.1.1<\/h4>\n\n<p>Added stable admin extension slots while keeping free features local-only.<\/p>\n\n<h4>0.1.0<\/h4>\n\n<p>Initial public release with local scans, login protection, firewall controls, setup guidance, advisor checks, privacy tooling, and bounded local data handling.<\/p>","raw_excerpt":"Free local security checks for WordPress sites.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/355610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=355610"}],"author":[{"embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wplura"}],"wp:attachment":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=355610"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=355610"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=355610"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=355610"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=355610"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=355610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}