{"id":222131,"date":"2025-03-22T19:00:05","date_gmt":"2025-03-22T19:00:05","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ultimate-security\/"},"modified":"2026-09-02T17:58:05","modified_gmt":"2026-09-02T17:58:05","slug":"ultimate-security","status":"publish","type":"plugin","link":"https:\/\/en-za.wordpress.org\/plugins\/ultimate-security\/","author":23331565,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.25","stable_tag":"1.0.25","tested":"7.1","requires":"5.6","requires_php":"7.0","requires_plugins":null,"header_name":"Ultimate Security","header_author":"wpultimatesecurity","header_description":"Ultimate Security plugin for Your Site","assets_banners_color":"80689e","last_updated":"2026-09-02 17:58:05","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.wpultimatesecurity.com","header_plugin_uri":"https:\/\/www.wpultimatesecurity.com","header_author_uri":"https:\/\/www.wpultimatesecurity.com\/","rating":0,"author_block_rating":0,"active_installs":10,"downloads":3136,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"programmelab","date":"2025-05-12 18:41:17","revision":3292101},"1.0.1":{"tag":"1.0.1","author":"programmelab","date":"2025-07-24 07:38:15","revision":3333334},"1.0.10":{"tag":"1.0.10","author":"wpultimatesecurity","date":"2025-09-08 12:52:29","revision":3357913},"1.0.11":{"tag":"1.0.11","author":"wpultimatesecurity","date":"2025-09-10 20:22:17","revision":3359434},"1.0.12":{"tag":"1.0.12","author":"wpultimatesecurity","date":"2025-09-16 11:06:42","revision":3362445},"1.0.13":{"tag":"1.0.13","author":"wpultimatesecurity","date":"2025-11-17 14:00:45","revision":3397281},"1.0.14":{"tag":"1.0.14","author":"wpultimatesecurity","date":"2025-11-24 20:56:38","revision":3402080},"1.0.15":{"tag":"1.0.15","author":"wpultimatesecurity","date":"2025-12-08 17:28:06","revision":3414585},"1.0.16":{"tag":"1.0.16","author":"wpultimatesecurity","date":"2025-12-22 18:32:32","revision":3425581},"1.0.17":{"tag":"1.0.17","author":"wpultimatesecurity","date":"2026-02-18 10:05:50","revision":3464168},"1.0.18":{"tag":"1.0.18","author":"wpultimatesecurity","date":"2026-06-29 22:05:35","revision":3590652},"1.0.19":{"tag":"1.0.19","author":"wpultimatesecurity","date":"2026-06-29 22:05:35","revision":3590652},"1.0.2":{"tag":"1.0.2","author":"programmelab","date":"2025-07-29 07:46:25","revision":3335727},"1.0.20":{"tag":"1.0.20","author":"wpultimatesecurity","date":"2026-06-29 22:05:35","revision":3590652},"1.0.21":{"tag":"1.0.21","author":"wpultimatesecurity","date":"2026-06-29 22:05:35","revision":3590652},"1.0.22":{"tag":"1.0.22","author":"wpultimatesecurity","date":"2026-06-29 22:05:35","revision":3590652},"1.0.23":{"tag":"1.0.23","author":"wpultimatesecurity","date":"2026-08-18 11:20:36","revision":3652660},"1.0.24":{"tag":"1.0.24","author":"wpultimatesecurity","date":"2026-09-02 13:51:14","revision":3678113},"1.0.25":{"tag":"1.0.25","author":"wpultimatesecurity","date":"2026-09-02 17:58:05","revision":3678497},"1.0.3":{"tag":"1.0.3","author":"programmelab","date":"2025-07-30 12:37:08","revision":3336637},"1.0.4":{"tag":"1.0.4","author":"programmelab","date":"2025-08-11 18:46:22","revision":3343092},"1.0.5":{"tag":"1.0.5","author":"programmelab","date":"2025-08-14 09:01:05","revision":3344476},"1.0.6":{"tag":"1.0.6","author":"programmelab","date":"2025-08-18 19:38:10","revision":3346626},"1.0.7":{"tag":"1.0.7","author":"wpultimatesecurity","date":"2025-08-25 19:11:42","revision":3349912},"1.0.8":{"tag":"1.0.8","author":"wpultimatesecurity","date":"2025-09-01 19:15:34","revision":3354213},"1.0.9":{"tag":"1.0.9","author":"wpultimatesecurity","date":"2025-09-02 09:22:37","revision":3354493}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.gif":{"filename":"icon-128x128.gif","revision":3678713,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.gif":{"filename":"icon-256x256.gif","revision":3678713,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3678713,"resolution":"1544x500","location":"assets","locale":"","width":3088,"height":1000},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3678713,"resolution":"772x250","location":"assets","locale":"","width":1544,"height":500}},"assets_blueprints":{"blueprint.json":{"filename":"blueprint.json","revision":3678726,"resolution":false,"location":"assets","locale":"","contents":"{\"$schema\":\"https:\\\/\\\/playground.wordpress.net\\\/blueprint-schema.json\",\"meta\":{\"title\":\"Ultimate Security live preview\",\"description\":\"Try Ultimate Security in a throwaway WordPress: the three-minute setup wizard, then the dashboard, Test Mode, two-factor and login protection screens.\",\"author\":\"WP Ultimate Security\",\"categories\":[\"security\",\"plugin\"]},\"landingPage\":\"\\\/wp-admin\\\/admin.php?page=ultimate-security#\\\/wizard\",\"preferredVersions\":{\"php\":\"latest\",\"wp\":\"latest\"},\"features\":{\"networking\":true},\"steps\":[{\"step\":\"login\",\"username\":\"admin\",\"password\":\"password\",\"progress\":{\"weight\":1,\"caption\":\"Signing in as admin\"}},{\"step\":\"setSiteOptions\",\"options\":{\"blogname\":\"Ultimate Security demo\",\"blogdescription\":\"A throwaway site for trying the plugin\",\"permalink_structure\":\"\\\/%postname%\\\/\",\"timezone_string\":\"UTC\"},\"progress\":{\"weight\":1,\"caption\":\"Naming the demo site\"}},{\"step\":\"installPlugin\",\"pluginData\":{\"resource\":\"wordpress.org\\\/plugins\",\"slug\":\"ultimate-security\"},\"options\":{\"activate\":true},\"ifAlreadyInstalled\":\"skip\",\"progress\":{\"weight\":4,\"caption\":\"Installing Ultimate Security\"}},{\"step\":\"writeFile\",\"path\":\"\\\/wordpress\\\/wp-content\\\/mu-plugins\\\/ultimate-security-preview-notice.php\",\"data\":\"<?php\\n\\\/**\\n * Plugin Name: Ultimate Security preview notice\\n * Description: Marks this site as a throwaway WordPress Playground preview.\\n *\\\/\\nadd_action( 'all_admin_notices', function () {\\n\\techo '<div class=\\\"notice notice-info is-dismissible\\\"><p>'\\n\\t\\t. 'You are looking at a WordPress Playground preview of <strong>Ultimate Security<\\\/strong>. '\\n\\t\\t. 'Everything here is temporary and nothing is saved. '\\n\\t\\t. '<a href=\\\"https:\\\/\\\/wordpress.org\\\/plugins\\\/ultimate-security\\\/\\\" target=\\\"_blank\\\" rel=\\\"noopener\\\">Plugin page<\\\/a>'\\n\\t\\t. '<\\\/p><\\\/div>';\\n} );\\n\",\"progress\":{\"weight\":1,\"caption\":\"Adding the preview notice\"}},{\"step\":\"runPHP\",\"code\":\"<?php\\nrequire '\\\/wordpress\\\/wp-load.php';\\n\\n\\\/\\\/ 1. We land on the wizard explicitly; stop the plugin's one-shot activation bounce.\\ndelete_option( 'ultimate_security_do_activation_redirect' );\\n\\n\\\/\\\/ 2. Hide developer \\\/ housekeeping banners so screens match the listing screenshots.\\nforeach ( array(\\n\\t'ultimate_security_modules_dev_notice_banner_hide',\\n\\t'ultimate_security_file_integrity_last_scan_banner_hide',\\n\\t'ultimate_security_file_integrity_significant_file_changes_detected_banner_hide',\\n\\t'ultimate_security_incident_detail_banner_hide',\\n\\t'ultimate_security_activity_logs_security_incidents_critical_incidents_banner_hide',\\n) as $flag ) {\\n\\tupdate_option( $flag, '1' );\\n}\\nupdate_option( 'ultimate_security_score_has_scanned', 1 );\\nupdate_option( 'ultimate_security_feedback_dismissed_permanently', 1 );\\n\\n\\\/\\\/ 3. Two demo accounts so sessions and 2FA user lists are not empty. Passwords are random and never shown.\\nforeach ( array(\\n\\tarray( 'michael_brown', 'editor', 'Michael', 'Brown', 'michael.brown@example.com' ),\\n\\tarray( 'sarah_lee', 'author', 'Sarah', 'Lee', 'sarah.lee@example.com' ),\\n) as $u ) {\\n\\tif ( ! username_exists( $u[0] ) ) {\\n\\t\\twp_insert_user( array(\\n\\t\\t\\t'user_login'   => $u[0],\\n\\t\\t\\t'user_pass'    => wp_generate_password( 24 ),\\n\\t\\t\\t'role'         => $u[1],\\n\\t\\t\\t'first_name'   => $u[2],\\n\\t\\t\\t'last_name'    => $u[3],\\n\\t\\t\\t'display_name' => $u[2] . ' ' . $u[3],\\n\\t\\t\\t'user_email'   => $u[4],\\n\\t\\t) );\\n\\t}\\n}\\n\\n\\\/\\\/ 4. Test Mode on for every role, so visitors can see simulated blocks instead of real lockouts.\\n$utils = '\\\\\\\\WPUltimateSecurity\\\\\\\\UltimateSecurity\\\\\\\\Support\\\\\\\\Helpers\\\\\\\\Utils';\\nif ( class_exists( $utils ) ) {\\n\\ttry {\\n\\t\\t$options = $utils::ultimate_security_get_option( true );\\n\\t\\tif ( is_array( $options ) ) {\\n\\t\\t\\t$options['test_mode'] = array_merge(\\n\\t\\t\\t\\tisset( $options['test_mode'] ) && is_array( $options['test_mode'] ) ? $options['test_mode'] : array(),\\n\\t\\t\\t\\tarray(\\n\\t\\t\\t\\t\\t'enabled'               => '1',\\n\\t\\t\\t\\t\\t'exclude_admins'        => '0',\\n\\t\\t\\t\\t\\t'affected_roles'        => array( 'administrator', 'editor', 'author', 'contributor', 'subscriber' ),\\n\\t\\t\\t\\t\\t'log_simulations'       => '1',\\n\\t\\t\\t\\t\\t'show_dashboard_notice' => '1',\\n\\t\\t\\t\\t)\\n\\t\\t\\t);\\n\\t\\t\\t$utils::ultimate_security_update_option( $options );\\n\\t\\t}\\n\\t} catch ( \\\\Throwable $e ) {\\n\\t\\t\\\/\\\/ Seeding must never break the preview.\\n\\t}\\n}\\n\\n\\\/\\\/ 5. A few failed sign-ins from bot-style usernames. Distinct names stay under the lockout threshold.\\nforeach ( array( 'admin1', 'wpadmin', 'test', 'administrator' ) as $bot ) {\\n\\ttry {\\n\\t\\tdo_action( 'wp_login_failed', $bot, new WP_Error( 'invalid_username', 'Unknown username.' ) );\\n\\t} catch ( \\\\Throwable $e ) {\\n\\t}\\n}\\n\\ndelete_transient( 'ultimate_security_score_cache' );\\nwp_cache_flush();\\n\",\"progress\":{\"weight\":2,\"caption\":\"Seeding demo users and sign-in history\"}}]}"}},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.2","1.0.20","1.0.21","1.0.22","1.0.23","1.0.24","1.0.25","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3678713,"resolution":"1","location":"assets","locale":"","width":1600,"height":1000},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3678713,"resolution":"10","location":"assets","locale":"","width":1600,"height":1000},"screenshot-11.png":{"filename":"screenshot-11.png","revision":3678713,"resolution":"11","location":"assets","locale":"","width":1600,"height":1000},"screenshot-12.png":{"filename":"screenshot-12.png","revision":3678713,"resolution":"12","location":"assets","locale":"","width":1600,"height":1000},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3678713,"resolution":"2","location":"assets","locale":"","width":1600,"height":1000},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3678713,"resolution":"3","location":"assets","locale":"","width":1600,"height":1000},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3678713,"resolution":"4","location":"assets","locale":"","width":1600,"height":1000},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3678713,"resolution":"5","location":"assets","locale":"","width":1600,"height":1000},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3678713,"resolution":"6","location":"assets","locale":"","width":1600,"height":1000},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3678713,"resolution":"7","location":"assets","locale":"","width":1600,"height":1000},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3678713,"resolution":"8","location":"assets","locale":"","width":1600,"height":1000},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3678713,"resolution":"9","location":"assets","locale":"","width":1600,"height":1000}},"screenshots":[]},"plugin_section":[262246],"plugin_tags":[2439,362,1229,600,1909],"plugin_category":[54],"plugin_contributors":[246206],"plugin_business_model":[],"class_list":["post-222131","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-captcha","plugin_tags-login-security","plugin_tags-security","plugin_tags-two-factor-authentication","plugin_category-security-and-spam-protection","plugin_contributors-wpultimatesecurity","plugin_committers-wpultimatesecurity"],"banners":{"banner":"https:\/\/ps.w.org\/ultimate-security\/assets\/banner-772x250.png?rev=3678713","banner_2x":"https:\/\/ps.w.org\/ultimate-security\/assets\/banner-1544x500.png?rev=3678713","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ultimate-security\/assets\/icon-128x128.gif?rev=3678713","icon_2x":"https:\/\/ps.w.org\/ultimate-security\/assets\/icon-256x256.gif?rev=3678713","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-1.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-2.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-3.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-4.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-5.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-6.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-7.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-8.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-9.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-10.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-11.png?rev=3678713","caption":""},{"src":"https:\/\/ps.w.org\/ultimate-security\/assets\/screenshot-12.png?rev=3678713","caption":""}],"raw_content":"<!--section=description-->\n<p>Ultimate Security handles the traffic that actually reaches a WordPress site: automated login attempts, brute-force runs, comment and form spam, and probes at well-known paths. It covers two-factor authentication, login lockouts, CAPTCHA, a movable login URL, session controls, vulnerability scanning, and Cloudflare edge rules \u2014 set up from one admin screen, without editing files or writing firewall rules by hand.<\/p>\n\n<p>[youtube https:\/\/www.youtube.com\/watch?v=wip2sejhJkQ]<\/p>\n\n<p>There is no usage tracking and nothing phones home. The plugin contacts an outside service only when you switch on a feature that needs one, and each is listed under External Services below. Features that belong to the Pro add-on are labelled as such.<\/p>\n\n<h4>Setup wizard<\/h4>\n\n<p>The first run is a five-step wizard. You answer a few questions about the site, it runs a quick scan, and you pick one of seven starting templates: basic, moderate, strict, agency, blog, membership, or WooCommerce. Before it changes anything it shows you a full diff, and you can undo everything it did later without losing edits you made yourself. It also gives you an emergency access link \u2014 keep it somewhere safe, and you can switch the plugin off from a browser if you ever lock yourself out.<\/p>\n\n<h4>Two-factor authentication<\/h4>\n\n<ul>\n<li>Email one-time codes, no app required, for any user.<\/li>\n<li>Authenticator apps (TOTP and HOTP) with QR enrolment \u2014 Google Authenticator, Authy, Microsoft Authenticator and similar.<\/li>\n<li>Per-role configuration: pick which roles use email codes and which use an app.<\/li>\n<li>Rate limiting on code entry, with a configurable attempt limit and lockout.<\/li>\n<li>Optional 2FA event logging.<\/li>\n<li>Covers the WordPress, WooCommerce and Ultimate Member login forms, with a separate setting for XML-RPC.<\/li>\n<\/ul>\n\n<h4>Login access control<\/h4>\n\n<ul>\n<li>Move <code>wp-login.php<\/code> to a secret URL so bots can't find it, with a configurable post-login redirect.<\/li>\n<li>HTTP Basic Authentication in front of <code>wp-login.php<\/code> and <code>wp-admin<\/code>, no <code>.htaccess<\/code> editing. The password is stored hashed, repeated failures trigger a lockout, and you can let trusted IPs through.<\/li>\n<li>Show your own consent or policy text on the login form.<\/li>\n<\/ul>\n\n<h4>Password policies<\/h4>\n\n<ul>\n<li>Require a minimum length, mixed case, numbers and special characters, or start from a preset.<\/li>\n<li>Expiry with advance warning, a grace period, and email notification.<\/li>\n<li>Password history, so old passwords can't be reused.<\/li>\n<li>Force a password change on first login.<\/li>\n<li>Reject compromised passwords, checked against the Have I Been Pwned range API by k-anonymity \u2014 the password itself never leaves the site.<\/li>\n<li>Optionally turn off self-service password reset and point people at your own process instead.<\/li>\n<\/ul>\n\n<h4>Brute-force protection<\/h4>\n\n<ul>\n<li>Limit failed logins and lock offenders out automatically.<\/li>\n<li>Progressive lockouts, so repeat offenders wait longer each time.<\/li>\n<li>Configurable retry-reset window, plus a permanent block list.<\/li>\n<li>A one-time recovery link, so a lockout doesn't strand you.<\/li>\n<\/ul>\n\n<h4>Session management<\/h4>\n\n<ul>\n<li>Limit concurrent logins per user; block the new login or end the oldest session.<\/li>\n<li>Idle timeout for inactive sessions.<\/li>\n<li>HttpOnly, Secure and SameSite flags on auth cookies.<\/li>\n<li>Optionally bind a session to its IP and\/or browser to catch hijacking.<\/li>\n<\/ul>\n\n<h4>CAPTCHA and spam<\/h4>\n\n<ul>\n<li>Google reCAPTCHA v2 and v3, with a v3 score threshold, IP and user-agent allowlists, a bypass for logged-in users, and a verification log.<\/li>\n<li>Cloudflare Turnstile, with theme, size, language and appearance options, deferred loading, custom failure messages, and its own log.<\/li>\n<li>Both cover the WordPress login, registration, lost-password and comment forms, and the WooCommerce login, registration, lost-password and checkout forms.<\/li>\n<li>No-conflict mode and provider priority keep two CAPTCHAs off the same form.<\/li>\n<li>Validate your site and secret keys from the settings page before going live.<\/li>\n<li>If the provider is unreachable, forms keep working.<\/li>\n<\/ul>\n\n<h4>Vulnerability scanning<\/h4>\n\n<ul>\n<li>Scans WordPress core, plugins and themes for known vulnerabilities.<\/li>\n<li>No API key needed \u2014 it uses the keyless WPVulnerability database by default.<\/li>\n<li>Add a WPScan or Patchstack key for more coverage, with automatic failover between providers.<\/li>\n<li>Scheduled scans and email alerts, filtered by severity.<\/li>\n<li>Flags plugins that haven't been updated in a long time.<\/li>\n<li>Scan history, run-to-run comparison, and an ignore list for findings you've accepted.<\/li>\n<li>Results show up in Site Health, the dashboard widget, the plugins list, and menu counters.<\/li>\n<\/ul>\n\n<h4>Cloudflare WAF rules<\/h4>\n\n<p>Connect your own Cloudflare account and manage edge rules from wp-admin.<\/p>\n\n<p>[youtube https:\/\/www.youtube.com\/watch?v=LCuXzebRGj4]<\/p>\n\n<ul>\n<li>Let verified search, monitoring, backup, SEO and social crawlers through.<\/li>\n<li>Block aggressive crawlers and sensitive WordPress paths.<\/li>\n<li>Block data-center hosts and TOR exit nodes.<\/li>\n<li>Challenge large cloud providers and specific countries.<\/li>\n<li>Challenge VPN traffic and requests to <code>wp-login.php<\/code>.<\/li>\n<li>Virtual patches that block requests exploiting known core CVEs at the edge until you can update.<\/li>\n<li>Preview the generated expressions before deploying, review the live rules on your zone, and read request, threat and bandwidth analytics.<\/li>\n<\/ul>\n\n<h4>Security keys (salts)<\/h4>\n\n<ul>\n<li>Rotate the keys and salts in <code>wp-config.php<\/code> on demand or on a schedule \u2014 daily, weekly, monthly, quarterly, or twice a year.<\/li>\n<li>Advance notice before a scheduled rotation, so the forced re-login isn't a surprise.<\/li>\n<li>Quiet hours, plus pause and skip-next controls.<\/li>\n<li>Rotation history, with the option to restore a previous set.<\/li>\n<\/ul>\n\n<h4>Update manager<\/h4>\n\n<ul>\n<li>Set auto-update policy for core, plugins and themes, with per-plugin and per-theme overrides.<\/li>\n<li>Update windows, allowed days, and freeze periods for when you don't want changes.<\/li>\n<li>Delay updates by a set number of days to let others hit the bugs first.<\/li>\n<li>Optional maintenance mode during updates, and detection of version-controlled installs.<\/li>\n<li>Email notifications and a daily digest.<\/li>\n<\/ul>\n\n<h4>Monitoring, security score and logs<\/h4>\n\n<ul>\n<li>A security score with a per-check breakdown of what's pulling it down.<\/li>\n<li>Activity log for logins, logouts, lockouts, and 2FA and password events, with a retention period you set.<\/li>\n<li>Session log for session events and anomalies.<\/li>\n<li>A \"who's online\" view of currently active users.<\/li>\n<li>Core file-integrity check against the official WordPress.org checksums.<\/li>\n<li>Site Health entries covering plugin, server, database, filesystem, theme and WordPress diagnostics.<\/li>\n<li>A dashboard widget summarising failed logins, issues found, outdated plugins and the current score.<\/li>\n<\/ul>\n\n<h4>Test mode<\/h4>\n\n<p>Run your rules without blocking anyone and review a log of what would have been blocked before you enforce it. Choose which roles it applies to, keep admins excluded, and an admin-bar marker plus a dashboard notice remind you it's on.<\/p>\n\n<h4>Tools, migration and backup<\/h4>\n\n<ul>\n<li>Import from Wordfence Login Security \u2014 preview what comes across, run it, and roll it back if you change your mind.<\/li>\n<li>Export and import settings as JSON for staging-to-production moves or recovery.<\/li>\n<li>Reset all settings to defaults, and clear the plugin cache.<\/li>\n<li>Diagnostics for REST API, cron (with a manual run trigger), and server status.<\/li>\n<li>An emergency deactivation URL that switches the plugin off if you're locked out.<\/li>\n<\/ul>\n\n<h4>Works with what you already run<\/h4>\n\n<p>Ultimate Security detects and adapts to WooCommerce, Ultimate Member, common page builders, form plugins, caching plugins and SEO plugins, and warns you when another security plugin is already doing the same job.<\/p>\n\n<h4>WP-CLI<\/h4>\n\n<pre><code>wp ultimate-security template list\nwp ultimate-security template apply &lt;template&gt; [--dry-run]\nwp ultimate-security template undo\nwp ultimate-security export [--file=&lt;path&gt;]\nwp ultimate-security import &lt;file&gt; [--dry-run]\nwp ultimate-security status\n<\/code><\/pre>\n\n<h4>Learn more<\/h4>\n\n<ul>\n<li><a href=\"https:\/\/www.wpultimatesecurity.com\">Website<\/a> \u2014 features and articles.<\/li>\n<li><a href=\"https:\/\/docs.wpultimatesecurity.com\/\">Documentation<\/a> \u2014 setup guides, troubleshooting and how-tos.<\/li>\n<li><a href=\"https:\/\/www.youtube.com\/@wpultimatesecurity\">YouTube<\/a> \u2014 walkthroughs and tutorials.<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to the following third-party services, and only when you use the related feature:<\/p>\n\n<h4>Google reCAPTCHA<\/h4>\n\n<ul>\n<li>When: reCAPTCHA protection is enabled. The reCAPTCHA script is then loaded in your visitors' browsers on the protected forms.<\/li>\n<li>Data sent: the visitor's reCAPTCHA response token, your site secret key, and the visitor's IP address for verification.<\/li>\n<li>Endpoints: https:\/\/www.google.com\/recaptcha\/api.js (browser script, with a preconnect to https:\/\/www.gstatic.com) and https:\/\/www.google.com\/recaptcha\/api\/siteverify (server-side verification).<\/li>\n<li>Terms: https:\/\/policies.google.com\/terms \u2014 Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<h4>Cloudflare Turnstile<\/h4>\n\n<ul>\n<li>When: Cloudflare Turnstile protection is enabled. The Turnstile script is then loaded in your visitors' browsers on the protected forms.<\/li>\n<li>Data sent: the visitor's Turnstile response token, your site secret key, and the visitor's IP address for verification.<\/li>\n<li>Endpoints: https:\/\/challenges.cloudflare.com\/turnstile\/v0\/api.js (browser script) and https:\/\/challenges.cloudflare.com\/turnstile\/v0\/siteverify (server-side verification).<\/li>\n<li>Terms: https:\/\/www.cloudflare.com\/website-terms\/ \u2014 Privacy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<\/ul>\n\n<h4>WPVulnerability<\/h4>\n\n<ul>\n<li>When: the Vulnerability Scanner runs. This is the default vulnerability database and requires no API key.<\/li>\n<li>Data sent: your WordPress version and the slugs of your installed plugins and themes.<\/li>\n<li>Endpoint: https:\/\/www.wpvulnerability.net\/<\/li>\n<li>Privacy: https:\/\/www.wpvulnerability.net\/<\/li>\n<\/ul>\n\n<h4>WPScan<\/h4>\n\n<ul>\n<li>When: the Vulnerability Scanner runs and you have configured a WPScan API key.<\/li>\n<li>Data sent: your WPScan API key, your WordPress version, and the slugs of your installed plugins and themes.<\/li>\n<li>Endpoint: https:\/\/wpscan.com\/api\/v3\/<\/li>\n<li>Terms: https:\/\/wpscan.com\/terms-of-service\/ \u2014 Privacy: https:\/\/wpscan.com\/privacy-policy\/<\/li>\n<\/ul>\n\n<h4>Patchstack<\/h4>\n\n<ul>\n<li>When: the Vulnerability Scanner runs and you have configured a Patchstack API key.<\/li>\n<li>Data sent: your Patchstack API key, your WordPress version, and the slugs of your installed plugins and themes.<\/li>\n<li>Endpoint: https:\/\/patchstack.com\/database\/api\/v2\/<\/li>\n<li>Terms: https:\/\/patchstack.com\/terms-of-service\/ \u2014 Privacy: https:\/\/patchstack.com\/privacy-policy\/<\/li>\n<\/ul>\n\n<h4>WordPress.org Plugin and Theme Information API<\/h4>\n\n<ul>\n<li>When: the Vulnerability Scanner checks whether an extension has been abandoned, and when the Update Manager gathers update information.<\/li>\n<li>Data sent: the slugs of your installed plugins and themes (no user data).<\/li>\n<li>Endpoints: https:\/\/api.wordpress.org\/plugins\/info\/1.2\/ and https:\/\/api.wordpress.org\/themes\/info\/1.2\/<\/li>\n<li>Privacy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul>\n\n<h4>WordPress.org Core Version Check<\/h4>\n\n<ul>\n<li>When: the Update Manager checks for available WordPress core updates.<\/li>\n<li>Data sent: a standard WordPress core version-check request (no user data).<\/li>\n<li>Endpoint: https:\/\/api.wordpress.org\/core\/version-check\/1.7\/<\/li>\n<li>Privacy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul>\n\n<h4>WordPress.org Core Checksums<\/h4>\n\n<ul>\n<li>When: you run the WordPress core file-integrity check.<\/li>\n<li>Data sent: your WordPress version and locale, in order to retrieve the official file checksums for comparison.<\/li>\n<li>Endpoint: https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/li>\n<li>Privacy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul>\n\n<h4>WordPress.org Secret-Key (Salt) API<\/h4>\n\n<ul>\n<li>When: you rotate WordPress security keys and salts, on demand or on a schedule.<\/li>\n<li>Data sent: a request for randomly generated salt strings (no site or user data).<\/li>\n<li>Endpoint: https:\/\/api.wordpress.org\/secret-key\/1.1\/salt\/<\/li>\n<li>Privacy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul>\n\n<h4>Cloudflare API<\/h4>\n\n<ul>\n<li>When: you connect Cloudflare or preview, deploy, remove or analyse WAF rules.<\/li>\n<li>Data sent: your Cloudflare credentials or API token, the selected zone and rule data, and the API requests needed for verification, deployment and analytics.<\/li>\n<li>Endpoint: https:\/\/api.cloudflare.com\/client\/v4\/<\/li>\n<li>Terms: https:\/\/www.cloudflare.com\/website-terms\/ \u2014 Privacy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<\/ul>\n\n<h4>Have I Been Pwned (Pwned Passwords)<\/h4>\n\n<ul>\n<li>When: the \"refuse compromised passwords\" password-policy option is enabled and a password is set or changed.<\/li>\n<li>Data sent: the first 5 characters of the SHA-1 hash of the password (a k-anonymity range query). The password itself is never sent.<\/li>\n<li>Endpoint: https:\/\/api.pwnedpasswords.com\/range\/<\/li>\n<li>Privacy: https:\/\/haveibeenpwned.com\/Privacy<\/li>\n<\/ul>\n\n<h4>Feedback and support email<\/h4>\n\n<ul>\n<li>When: only when an administrator explicitly submits contact, migration, or deactivation feedback. Choosing \"Skip &amp; Deactivate\" sends nothing.<\/li>\n<li>Data sent: the submitted message or deactivation reason and optional notes. Contact and migration requests also include diagnostic details shown with the form, such as the site URL, WordPress\/PHP versions, active theme and plugin count, administrator profile, IP address, user agent, and referrer.<\/li>\n<li>Destination: support@wpultimatesecurity.com, delivered through the site's configured WordPress email service.<\/li>\n<li>Privacy: https:\/\/www.wpultimatesecurity.com\/privacy-policy\/<\/li>\n<\/ul>\n\n<!--section=installation-->\n<p><strong>Requirements:<\/strong> WordPress 5.6+ and PHP 7.0+. HTTPS is strongly recommended for 2FA and secure sessions.<\/p>\n\n<p>\ud83d\udcd8 Full setup walkthrough: <a href=\"https:\/\/docs.wpultimatesecurity.com\/\">Documentation<\/a> \u00b7 <a href=\"https:\/\/www.youtube.com\/@wpultimatesecurity\">Video tutorials<\/a><\/p>\n\n<h4>Install from your dashboard<\/h4>\n\n<ol>\n<li>In WordPress, go to <strong>Plugins \u2192 Add New<\/strong> and search for \"wpultimatesecurity\".<\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<li>Follow the <strong>Security Wizard<\/strong> that appears \u2014 it scans your site, recommends settings, and shows you every change before applying it.<\/li>\n<\/ol>\n\n<h4>Install manually<\/h4>\n\n<ol>\n<li>Download the plugin ZIP.<\/li>\n<li>Go to <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>, choose the ZIP, and click <strong>Install Now<\/strong>.<\/li>\n<li>Click <strong>Activate<\/strong>, then follow the Security Wizard.<\/li>\n<\/ol>\n\n<p>Or with WP-CLI: <code>wp plugin install ultimate-security --activate<\/code><\/p>\n\n<h4>Recommended first 5 minutes<\/h4>\n\n<ol>\n<li>Run the <strong>Security Wizard<\/strong> and apply a template that matches your site.<\/li>\n<li>Enable <strong>2FA<\/strong> for all administrator accounts.<\/li>\n<li>Set <strong>login attempt limits<\/strong> and a lockout duration.<\/li>\n<li>Add <strong>CAPTCHA<\/strong> (reCAPTCHA or Cloudflare Turnstile) to your login, registration and comment forms.<\/li>\n<li>Set a <strong>custom login URL<\/strong>, save it somewhere safe, and store the emergency access link the wizard showed you.<\/li>\n<li>Run a <strong>vulnerability scan<\/strong>, then review the <strong>Security Score<\/strong> and <strong>Site Health<\/strong> before enabling stricter rules.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20slow%20down%20my%20site%3F\"><h3>Will this slow down my site?<\/h3><\/dt>\n<dd><p>It is built to stay lightweight \u2014 security checks run on login and form submission, not on every page view. Vulnerability scans run on a schedule in the background, not during visitor requests.<\/p><\/dd>\n<dt id=\"do%20i%20need%20any%20technical%20or%20coding%20knowledge%3F\"><h3>Do I need any technical or coding knowledge?<\/h3><\/dt>\n<dd><p>No. The setup wizard scans your site, recommends settings, and shows you every change before it is applied \u2014 and you can undo all of it. Every setting is in plain English.<\/p><\/dd>\n<dt id=\"i%20enabled%202fa%20or%20a%20custom%20login%20url%20and%20locked%20myself%20out.%20how%20do%20i%20get%20back%20in%3F\"><h3>I enabled 2FA or a custom login URL and locked myself out. How do I get back in?<\/h3><\/dt>\n<dd><p>Use the <strong>emergency deactivation URL<\/strong> the setup wizard showed you \u2014 open it in a browser and the plugin switches itself off. If you did not save it, deactivate the plugin manually: over FTP\/SFTP rename the folder <code>\/wp-content\/plugins\/ultimate-security<\/code>, or over SSH run <code>wp plugin deactivate ultimate-security<\/code>. Then log in and reconfigure.<\/p><\/dd>\n<dt id=\"turnstile%20is%20blocking%20every%20login%20%28for%20example%20after%20changing%20my%20security%20keys%29.%20how%20do%20i%20recover%3F\"><h3>Turnstile is blocking every login (for example after changing my security keys). How do I recover?<\/h3><\/dt>\n<dd><p>Add <code>define( 'ULTIMATE_SECURITY_DISABLE_TURNSTILE', true );<\/code> to <code>wp-config.php<\/code>. This fully disables Turnstile rendering and verification so you can log in. Then re-enter your Turnstile Site Key and Secret Key in the plugin settings (rotating WordPress security keys\/salts makes previously saved keys unreadable \u2014 Site Health and an admin notice will tell you when this has happened) and remove the constant. The constant requires server access, so it is never a public bypass.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20api%20key%20for%20vulnerability%20scanning%3F\"><h3>Do I need an API key for vulnerability scanning?<\/h3><\/dt>\n<dd><p>No. The scanner works out of the box using the keyless WPVulnerability database. WPScan and Patchstack API keys are optional and only add extra coverage.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. Both reCAPTCHA and Cloudflare Turnstile can protect WooCommerce login, registration, lost-password and checkout forms, and there is a WooCommerce setup template in the wizard.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20cloudflare%20account%20to%20use%20this%20plugin%3F\"><h3>Do I need a Cloudflare account to use this plugin?<\/h3><\/dt>\n<dd><p>Only for the WAF Rules section. Those rules are deployed to your own Cloudflare zone, so they need a Cloudflare account and an API token. Every other feature works without one.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20wordpress%20multisite%3F\"><h3>Does it work on WordPress Multisite?<\/h3><\/dt>\n<dd><p>The plugin activates and runs on Multisite, and its uninstall routine is network-aware. It has not been tested as extensively on Multisite as on single-site installs, so validate on a staging network first and configure settings per site.<\/p><\/dd>\n<dt id=\"does%20the%20custom%20login%20url%20work%20with%20caching%20and%20cdns%3F\"><h3>Does the custom login URL work with caching and CDNs?<\/h3><\/dt>\n<dd><p>Yes. Exclude the login path from full-page caching (most caching plugins do this for login and admin pages automatically) so the secret URL is never served from cache.<\/p><\/dd>\n<dt id=\"will%20it%20conflict%20with%20other%20security%20or%20captcha%20plugins%3F\"><h3>Will it conflict with other security or CAPTCHA plugins?<\/h3><\/dt>\n<dd><p>It can if two plugins do the same job. Pick one plugin per function (one 2FA, one CAPTCHA, one login limiter) and disable the overlapping feature in the other. Ultimate Security detects common security plugins and warns you.<\/p><\/dd>\n<dt id=\"i%20already%20use%20another%20security%20plugin.%20can%20i%20bring%20my%20settings%20across%3F\"><h3>I already use another security plugin. Can I bring my settings across?<\/h3><\/dt>\n<dd><p>Settings can be imported from Wordfence Login Security. You get a preview of exactly what will be imported before anything is applied, and you can roll the import back afterwards.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20track%20me%20or%20phone%20home%3F\"><h3>Does the plugin track me or phone home?<\/h3><\/dt>\n<dd><p>No. Ultimate Security does not collect product-usage telemetry. It contacts third-party services only when you use a feature that requires one, and every one of those is listed under External Services below.<\/p><\/dd>\n<dt id=\"what%20does%20the%20plugin%20store%20about%20my%20visitors%3F\"><h3>What does the plugin store about my visitors?<\/h3><\/dt>\n<dd><p>IP addresses and user agents are recorded in the activity and session logs so you can investigate login attempts, with a retention period you control (30 days by default). Test Mode keeps its own log of what would have been blocked. \"Who's online\" rows expire after 60 seconds. Nothing is sent off your site except through the services listed below.<\/p><\/dd>\n<dt id=\"is%20it%20gdpr-friendly%3F\"><h3>Is it GDPR-friendly?<\/h3><\/dt>\n<dd><p>The plugin is self-hosted and stores its data in your own database. Outbound calls are limited to the feature-specific services listed under External Services, such as reCAPTCHA, Turnstile, the vulnerability databases and WordPress.org APIs.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20data%20when%20i%20uninstall%3F\"><h3>What happens to my data when I uninstall?<\/h3><\/dt>\n<dd><p>By default the plugin leaves its data in place. If you enable the \"delete plugin data\" option in the plugin's advanced settings before uninstalling, its database tables, options and user meta are removed on uninstall.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20free%20and%20pro%3F\"><h3>What is the difference between Free and Pro?<\/h3><\/dt>\n<dd><p>Everything described on this page is in the free plugin: the setup wizard, email and app-based 2FA, brute-force lockout, custom login URL, HTTP Basic Auth, password policies, session management, reCAPTCHA and Turnstile, vulnerability scanning, Cloudflare WAF rules, security-key rotation (on demand and scheduled), the Update Manager, Security Score, activity logs, core file-integrity checking, Site Health, Test Mode, Wordfence migration, and settings backup and restore. Ultimate Security Pro is a separate add-on that requires this free plugin and adds further authentication, monitoring, automation and maintenance features not included here.<\/p><\/dd>\n<dt id=\"how%20do%20i%20get%20support%3F\"><h3>How do I get support?<\/h3><\/dt>\n<dd><p>Use the plugin support forum on WordPress.org, or visit https:\/\/www.wpultimatesecurity.com.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.25<\/h4>\n\n<ul>\n<li>Fixed: Session cookie hardening (SameSite, Secure) was overridden by WordPress core and never applied.<\/li>\n<li>Fixed: Dashboard hijack and idle-timeout counters read the wrong table and always showed 0.<\/li>\n<li>Fixed: Ending a session from Active Sessions could fail with a fatal error instead of a clear message.<\/li>\n<li>Fixed: Header search listed Active Sessions as Pro and Session Automations as free.<\/li>\n<li>Security: Ending a session from Active Sessions is now a POST request and is recorded in the activity log.<\/li>\n<li>Performance: Active Sessions only queries users who actually hold a session.<\/li>\n<\/ul>\n\n<h4>1.0.24<\/h4>\n\n<ul>\n<li>New: The redesigned admin interface is now the default for everyone \u2014 a cleaner dashboard, settings, and reporting, with light and dark modes that follow your system preference.<\/li>\n<li>Fix: Scheduled security-key (salt) rotation is a free feature, but the setup wizard displayed it as Pro and the Maximum Security template withheld its settings from free installs. Both corrected \u2014 applying that template now enables scheduled rotation.<\/li>\n<li>Fix: Security headers and XML-RPC protection are Pro features and are no longer labelled as free in the setup wizard.<\/li>\n<li>Docs: The readme now documents the complete free feature set and discloses every third-party service the plugin contacts.<\/li>\n<li>Maintenance: Removed unreachable code \u2014 an unused salt-change extension, a duplicate session route registrar, an unscheduled cron entry, an unused settings group, and unused Pro-feature permission helpers.<\/li>\n<li>Fix: The maintenance file written during plugin and theme updates was not valid PHP. On sites using that option it printed stray text at the top of every page, which broke logins and the plugin's own admin screens, and it could be left behind if an update failed part way through. Maintenance mode itself never actually engaged.<\/li>\n<li>Fix: Changing your security keys and salts now verifies the new wp-config.php before replacing the old one. Previously a bad network response could be written into the file, leaving the site unable to start.<\/li>\n<li>Fix: Saved API keys (reCAPTCHA, Turnstile, WPScan, Patchstack, Twilio) survive a key and salt change. They were previously left unreadable, so those integrations stopped working with no explanation.<\/li>\n<li>Fix: Turning off automatic updates no longer stops WordPress from checking for updates or slows down the admin area. Update notices, including security releases, keep working.<\/li>\n<li>Security: The two-factor code screen is now tied to the browser that signed in. It could previously be shown to another visitor who requested the login page at the right moment.<\/li>\n<li>Security: Two-factor authentication is now required over XML-RPC and for application passwords, which previously bypassed it.<\/li>\n<li>Security: Login attempt limits now count by IP address as well as username, so attempts spread across many usernames are limited and one account can no longer be locked out on demand. Lockout messages no longer reveal whether an account exists.<\/li>\n<li>Security: CAPTCHA can no longer be skipped by sending an authorization header with the login request.<\/li>\n<li>Security: The plugin deactivation link is now confirmed with a form submission instead of acting on a plain link, its secret is kept encrypted, and it changes after each use.<\/li>\n<li>Security: The compromised-password check is rate limited. It could previously be called repeatedly by anyone to exhaust the server.<\/li>\n<li>Security: HTTP authentication now also covers xmlrpc.php, and no longer alters the submitted password before checking it, which could reject valid passwords.<\/li>\n<li>Security: The login recovery link is kept out of settings exports and support reports, and credentials are removed on uninstall even when settings are kept.<\/li>\n<li>Performance: Scan results and CAPTCHA debug logs are no longer loaded on every page request, and settings are read later in the load order.<\/li>\n<li>Performance: Front-end assets now load only where a plugin feature is actually on the page \u2014 a page with no forms, widgets, or CAPTCHA loads no plugin CSS\/JS and no jQuery.<\/li>\n<li>Improvement: Reworked the Vulnerability Scanner scan-history view \u2014 full-width results table and a corrected trend chart.<\/li>\n<li>Maintenance: Removed the previous interface and its opt-in switch, the now-unused styles behind it, and dead IP-switch AJAX handlers.<\/li>\n<\/ul>\n\n<h4>1.0.23<\/h4>\n\n<ul>\n<li>Privacy: Removed unpublished product-usage analytics code and dependencies before release.<\/li>\n<li>Privacy: Removed automatic dashboard blog-feed and remote country-flag requests.<\/li>\n<li>Fix: Free mode no longer requests Pro-only blocklist routes or mounts Pro-only settings screens.<\/li>\n<li>Compatibility: Restored the documented WordPress 5.6 and PHP 7.0 runtime floor without changing the database schema.<\/li>\n<li>Maintenance: Removed repository GitHub Actions while preserving local release checks.<\/li>\n<\/ul>\n\n<h4>1.0.22<\/h4>\n\n<ul>\n<li>Improvement: Added localized passkey login feedback supplied by Ultimate Security Pro.<\/li>\n<li>Security: Render passkey login errors as text instead of interpolating error content into HTML.<\/li>\n<\/ul>\n\n<h4>1.0.21<\/h4>\n\n<ul>\n<li>New: WordPress Salt keys rotation option. Now you can schedule, skip and more when rotating keys.<\/li>\n<li>New: Now you can see the reCaptcha Logs directly from the plugin's setting page.<\/li>\n<li>Improvement: Both reCaptcha and Cloudflare Turnstile follow a similar settings structure for consistency.<\/li>\n<li>Fix: Cloudflare Turnstile and reCAPTCHA whitelist option was not working properly.<\/li>\n<\/ul>\n\n<h4>1.0.20<\/h4>\n\n<ul>\n<li>New: Improved Session Management settings including concurrent login limits, session cookie hardening and more,<\/li>\n<li>New: Cloudflare Turnstile and reCAPTCHA CAPTCHA verifcation when applying their respective keys.<\/li>\n<li>Improvement: Cloudflare WAF rules function improvement.<\/li>\n<li>Improvement: Code optimization and performance improvements.<\/li>\n<\/ul>\n\n<h4>1.0.19<\/h4>\n\n<ul>\n<li>Fix: 2FA User role was not working properly.<\/li>\n<li>Fix: Login activity dashboard modal was showing wrong agent.<\/li>\n<li>Improvement: Better user friendly Server Protection Card Design<\/li>\n<li>Improvement: Code cleanup and optimization.<\/li>\n<\/ul>\n\n<h4>1.0.18<\/h4>\n\n<ul>\n<li>New: One-click Cloudflare WAF rules apply<\/li>\n<li>New: New Modal for Login activity with detailed information.<\/li>\n<li>Improvement: Code cleanup and optimization<\/li>\n<li>Fix: Login redirected URL was showing exisiting login for password reset<\/li>\n<\/ul>\n\n<h4>1.0.17<\/h4>\n\n<ul>\n<li>Fix: Minor bug fixes and stability improvements<\/li>\n<li>Improvement: Code cleanup and optimization<\/li>\n<\/ul>\n\n<h4>1.0.16<\/h4>\n\n<ul>\n<li>Improvement: Code improvements to the ovearll plugin making it snappier.<\/li>\n<\/ul>\n\n<h4>1.0.15<\/h4>\n\n<ul>\n<li>Improvement: Conflict management between applied settings.<\/li>\n<li>Improvement: UI improvements to existing settings pages. Making it more intuitive to use.<\/li>\n<li>Fix: Multiple bug fixes to dashboard. You should get more accurate results now.<\/li>\n<li>Fix: New deactivation URL was not saving after deactiviting-activating plugin.<\/li>\n<\/ul>\n\n<h4>1.0.14<\/h4>\n\n<ul>\n<li>Fix: Email 2FA codes were not being sent properly<\/li>\n<li>Fix: 2FA code page flickering effect after login<\/li>\n<\/ul>\n\n<h4>1.0.13<\/h4>\n\n<ul>\n<li>New: Completely redesigned user interface for better usability<\/li>\n<\/ul>\n\n<h4>1.0.12<\/h4>\n\n<ul>\n<li>New: Security Score meter to track your site's security level<\/li>\n<li>Improvement: Enhanced modal design for better UI\/UX<\/li>\n<\/ul>\n\n<h4>1.0.11<\/h4>\n\n<ul>\n<li>Fix: Minor UI bug fixes<\/li>\n<\/ul>\n\n<h4>1.0.10<\/h4>\n\n<ul>\n<li>Security: Removed unauthenticated AJAX actions<\/li>\n<li>Security: REST routes now require admin permission<\/li>\n<\/ul>\n\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>Fix: Dashboard emergency deactivation URL display issue<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Improvement: Human-readable values in activity log<\/li>\n<li>Improvement: Reduced plugin size with optimized code<\/li>\n<li>Fix: 2FA reset issue for users<\/li>\n<li>Fix: Password policy not applying to new users<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>New: Activity Log feature<\/li>\n<li>New: Improved dashboard design<\/li>\n<li>Fix: Nonce validation issues<\/li>\n<li>Fix: Turnstile not showing on comment forms<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>Fix: Custom login setup issues<\/li>\n<li>Fix: Email 2FA asking for OTP twice<\/li>\n<li>Fix: Feedback form email delivery<\/li>\n<li>Improvement: Reorganized menu navigation<\/li>\n<li>Improvement: Performance optimizations<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Fix: Request logs page display issue<\/li>\n<li>Fix: URL Guard SQL query display<\/li>\n<li>Improvement: Performance optimizations<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Redesigned settings page interface<\/li>\n<\/ul>","raw_excerpt":"Complete WordPress security \u2014 2FA, brute-force blocking, CAPTCHA, Cloudflare WAF rules, vulnerability scanning and guided 3-minute setup.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/222131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=222131"}],"author":[{"embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wpultimatesecurity"}],"wp:attachment":[{"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=222131"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=222131"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=222131"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=222131"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=222131"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/en-za.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=222131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}