Tag
#Security
Drafts tagged Security — vote on the plugins and apps you want built.
Store API Guard
Rate-limit cart and checkout abuse without breaking shoppers.
Form Firewall
Apply sensible submission limits to forms you already use.
Activity Trace
Keep a useful record of meaningful WordPress admin actions.
Client Lock
Give a client the editor, not the plugin screen.
Magic Link Gate
Let members sign in from an email link instead of a password they will forget.
SVG Gate
Allow SVG uploads only after they are sanitized.
Plugin Stale Watch
Warn when an installed plugin has not had an upstream update in 30 days.
Login After Path
Send each role to a different page after they sign in.
Comment Off Switch
Turn comments off for a post type without a 40-module suite.
XML-RPC Gate
Close xmlrpc.php unless you still need Jetpack or the mobile app.
Probe 404 Log
See which missing URLs bots and people hit, without auto-banning anyone.
Last Login Column
Show when each user last signed in, on the users list.
Login Fail Pad
Log failed logins so you can see a brute-force attempt without installing a WAF.
Session Kick Desk
See who is signed in and end a session from the users screen.
App Password Audit
List WordPress application passwords and revoke the ones that should be dead.
User Enum Gate
Stop user slugs and REST user lists from leaking logins.
File Editor Lock
Turn off the plugin and theme file editors on production.