WordPress plugin profile

Solutiontech Seguridad de acceso

Protects WordPress access with custom login URL, Micro-WAF, 2FA, IP control, brute force protection, core integrity, and local audit logs.

Updated 1h ago·New active installs·★ 0.0
Version1.23.0
Tested toWP 7.1
Requires WP6.2
Requires PHP7.4
Overview

About this plugin

Seguridad de acceso por Solutiontech protects WordPress access and reduces unnecessary public exposure without renaming core files or modifying .htaccess. Main features: 2FA Emergency Backup Recovery Codes: Generates secure single-use recovery code sets in user profiles to prevent lockouts. Cloudflare Turnstile Anti-Bot Protection: Frictionless, privacy-first bot detection challenge across login, registration, and lost password forms. Malware Upload Shield (PHP File Scanner): Automatically scans /wp-content/uploads/ for suspicious executable PHP scripts and backdoors. Interactive Audit Log Filter & Live Search: Instant client-side search and category filtering across recorded security events. Authenticator App 2FA (TOTP – RFC 6238): Support for Google Authenticator, Microsoft Authenticator, and Authy with QR code pairing in user profiles. GeoIP Country Restriction: Allow or block access based on visitor country code from reverse proxies and Cloudflare. Security Email Alerts: Real-time HTML notifications with anti-flood rate limits for brute force, WAF blocks, and core discrepancies. WordPress Dashboard Widget: Overview widget with security score ring, status pills, and 24-hour threat metrics. Micro-WAF (Web Application Firewall): Early inspection and neutralisation of SQL Injections (SQLi), Cross-Site Scripting (XSS), Path Traversal (LFI), Remote Code Execution (RCE), and malicious security scanners. IP Whitelist & Permanent Blacklist: Allows instant exclusion for trusted IPs and permanent 403 blocking for malicious IPs and CIDR ranges across the entire website. WordPress Core File Integrity Checker: Verifies local core files against official WordPress.org cryptographic MD5 checksums to detect modified or missing CMS files. Two-Factor Authentication (2FA via Email OTP): Delivers a 6-digit one-time code to authorized user emails to secure privileged logins. Strong Password Policies & Expiration: Enforces 12+ character complexity and optional periodic password expiration reminders. Official Internationalization & Translation Template: Standard .pot file included in languages/ for seamless translation with Poedit, Loco Translate, or WordPress.org GlotPress. Invisible Honeypot Anti-Spam: Blocks automated bots across login, password recovery, registration, and comment forms without annoying CAPTCHAs. Pingback & XML-RPC DDoS Protection: Strips X-Pingback headers and disables XML-RPC pingback reflection methods. WordPress Core Hardening: Hide WordPress version from headers/feeds/asset query strings, remove legacy discovery tags (RSD, WLWManifest, oEmbed), and disable built-in file editing. Background automated cleanup with WP-Cron for expired audit logs and 404 entries. Secure CSV export for Audit Log and 404 Monitor with Excel UTF-8 BOM and formula injection protection. Runtime in-memory caching for faster settings retrieval without redundant database queries. Google reCAPTCHA v3 invisible bot protection with score threshold on login and lost-password forms. HTTP Security Headers injection (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and HSTS). Progressive brute-force lockout with escalating lockout tiers for repeat offenders. Optional WooCommerce catalog mode, including controls for administrators and variable products. Security status dashboard with an informative score and links to each setting. Responsive sidebar navigation organized by security area. Session and device management based on native WordPress session tokens. Individual session revocation, single-session policy, and optional inactivity timeout. Optional alerts when a user signs in from a new device. 404 monitor with retention, entry limits, and direct conversion to a redirect rule. Same-site redirect manager supporting 301, 302, 307, and 308 responses. Optional custom login URL and random URL regeneration. Protection against direct access to wp-login.php and wp-admin for visitors. Configurable login attempt limiting by IP address using WordPress transients. Generic login errors to reduce account enumeration. Optional author enumeration and public REST user endpoint protection. Optional XML-RPC restriction. Environment diagnostics for Multisite, subdirectories, proxy/CDN setups, WooCommerce, and recovery flows. Optional deterrents for casual copying of images and text. Local audit log for relevant authentication and administration events. Configurable audit-log retention from 1 to 365 days, limited to 500 events. Independent controls for new comments and pingbacks on posts and pages. Optional email alerts when the login-attempt limit is reached. Configurable response for blocked login routes: 404, home page, or a custom URL. The plugin does not modify WordPress files. After deactivation, WordPress uses its standard login routes again. Developer website: https://solutiontech.cl/ External services This plugin can connect to the following third-party external services when explicitly configured and enabled by the site administrator: Google reCAPTCHA v3 : Purpose : Protects authentication and password recovery forms against automated bots and credential-stuffing attacks. Data sent & when : When enabled with site administrator API credentials, user interaction tokens and visitor IP address are sent to https://www.google.com/recaptcha/api/siteverify during form submission to obtain a risk confidence score. Service provider : Google LLC. Terms of Service : https://policies.google.com/terms Privacy Policy : https://policies.google.com/privacy Cloudflare Turnstile : Purpose : Provides frictionless, privacy-preserving smart anti-bot challenge validation on login, registration, and lost password forms. Data sent & when : When enabled with site administrator API credentials, the Turnstile response token and visitor IP address are sent to https://challenges.cloudflare.com/turnstile/v0/siteverify during form submission. Service provider : Cloudflare, Inc. Terms of Service : https://www.cloudflare.com/website-terms/ Privacy Policy : https://www.cloudflare.com/privacypolicy/ WordPress.org Core Checksums API : Purpose : Validates the integrity of local WordPress CMS files against official cryptographic checksums in the Diagnostics panel. Data sent & when : The current WordPress version and locale string (e.g., version and language code) are sent to https://api.wordpress.org/core/checksums/1.0/ only when an administrator clicks the “Comprobar integridad del núcleo” button in the diagnostics dashboard. No user personal data is sent. Service provider : WordPress Foundation / WordPress.org. Privacy Policy : https://wordpress.org/about/privacy/ Note on 2FA QR Codes : Two-Factor Authentication (TOTP) QR codes are generated 100% locally on your server in pure PHP as inline SVG. No secret keys or user data are ever sent to any external server or third-party service. Privacy The plugin does not send telemetry to Solutiontech. Optional security modules store their data locally in the WordPress database. Audit events may include complete IP addresses for forensic traceability, while the administration table displays masked addresses. WordPress session tokens may contain IP, browser, and date information. The 404 monitor does not store IP addresses or query parameters. If email alerts are enabled, the site sends the relevant information through its configured mail system. Site administrators are responsible for providing any required privacy notice and choosing an appropriate retention period.