WordPress Security Detection & Response
WPAuditor is a WordPress security plugin that brings SOC-grade monitoring and an Active Defense System (ADS) directly into your dashboard. Detect threats, investigate quickly, and keep your sites resilient—without heavy overhead.
Track logins, plugin/theme changes, file edits, and suspicious HTTP with rich context (IP, method, URI, UA, severity, category) and MITRE/OWASP mapping.
Interactive charts, summaries, and a session correlator that groups by IP, User-Agent, and user—plus real-time auto-refresh.
Automatically detects abusive behavior (login sprays, scan storms, web attacks) and rate-limits or blocks IPs in real time.
Central view of critical alerts with severity filters and routing to email/SIEM so real incidents never get buried in noise.
Real-time inspection catches XSS, RCE, LFI, and SQLi patterns with severity-tagged, forensics-ready logs.
Find suspicious/sensitive/obfuscated PHP, verify core checksums against WordPress.org, and flag risky file permissions.
One-click quarantine, restore, or delete suspicious files directly from WP Admin. No FTP or file manager required..
IP blocklist (Cloudflare-friendly), disable XML-RPC/REST to reduce surface area, and check file permissions.
Safely simulate brute force, SQLi, XSS, and file uploads to validate detections and train your team.
Create verified full-site backups (files + database) and restore a single file, a plugin/theme, or the entire site from WP Admin.
Export CSV/JSON for audits, schedule auto-cleanup (e.g., <15 days), and filter/paginate for large sites.
Super lightweight and host-friendly. No extra database tables, no heavy UI frameworks, just fast monitoring and response that won’t slow your site.
Designed to feel like a built-in WordPress screen. Looks and behaves like core WordPress, with familiar tables, filters, badges, and clear navigation.
“Feels like having a SOC inside WordPress. We spot issues before they become incidents.”
“Lightweight, fast, and the signals are actually actionable. Exactly what we needed.”
“Easy to roll out across client sites. One license per domain keeps billing clean.”
“The incident workflow saved us hours during a brute-force swarm.”