Description
Anonindo Security Advisor helps site owners understand and improve their WordPress security posture without acting like a full firewall suite.
The plugin follows a simple workflow:
- Scan for common WordPress security issues and misconfigurations
- Explain what each issue means in beginner-friendly language
- Show practical guidance and safer best practices
- Offer safe auto-fix actions for selected hardening steps
This plugin is designed to be lightweight, educational, and operationally safe.
Features
- Detects debug mode enabled in production
- Detects dashboard file editing enabled
- Detects XML-RPC exposure
- Detects weak file permissions on common paths
- Detects potentially exposed
wp-config.phpbackup patterns - Detects outdated plugins and themes
- Detects suspicious administrator account patterns
- Detects REST API user enumeration exposure
- Heuristically scans active theme and plugin PHP files for basic SQL injection and XSS risk patterns
- Scans selected database content for suspicious script-like patterns
- Provides a security score and prioritized recommendations
- Includes an activity log for meaningful security-related site events
- Supports safe auto-fixes for selected hardening improvements
Screenshots

Dashboard with security score, scan summary, and recommended improvements. 
Vulnerability cards with plain-language explanations and guided actions. 
Security Improvements tab with manual guidance and safe auto-fix actions. 
Activity Log showing meaningful security-related events. 
Settings screen for module and scan preferences.
Installation
- Upload the
anonindo-security-advisorfolder to the/wp-content/plugins/directory. - Activate the plugin through the
Pluginsscreen in WordPress. - Open
Anonindo Security Advisorin the WordPress admin menu. - Run a security scan and review the recommendations.
FAQ
-
Does this replace a firewall or malware scanner?
-
No. This plugin focuses on lightweight auditing, explanation, guided improvements, and selected safe fixes.
-
Does the plugin make automatic changes?
-
Only selected hardening actions support auto-fix, and they require explicit administrator confirmation.
-
Will this plugin impact performance?
-
The plugin is designed to avoid heavy frontend overhead. Scans are run manually or on schedule, and the most expensive checks are intentionally bounded.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Anonindo Security Advisor” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Anonindo Security Advisor” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Change log
1.1.1
- Renamed the plugin to Anonindo Security Advisor and updated the submission metadata and slug.
1.0.0
- Initial MVP release.
