Description
UX3 Security connects your WordPress site to the UX3 Security cloud dashboard for centralized firewall management. Block SQL injection attempts, XSS attacks, malicious bots, spam submissions, and more — with rules managed from a single place across all your sites.
Key features
- Web Application Firewall — blocks SQLi, XSS, and other common attack patterns
- Bot protection — detects and blocks bad bots, fake search-engine crawlers, anonymous bot traffic
- Spam protection — honeypot + content-based detection for forms
- Word filter — block requests matching custom keyword lists
- Geo-blocking — block traffic from specific countries
- Rate limiting — prevents brute-force and scraping
- Smart filter — one-click allow-list for false positives
- Centralized dashboard — all your sites in one place at central.ux3security.com
- Real-time alerts — email notifications for attacks, disconnections, disk warnings, etc.
How it works
- Sign up at central.ux3security.com and add your site
- Copy the API URL and token from your dashboard
- Install this plugin and paste them into Settings UX3 Security
- Enable protection — done. Manage rules from the dashboard.
External services
This plugin connects to two external services in order to function. Each is described below in line with WordPress.org’s third-party service disclosure guideline.
1. UX3 Security API
What it is and what it is used for: The cloud dashboard at central.ux3security.com is the central management plane for the plugin. It distributes firewall rules to the agent, receives logs of blocked attacks, and tracks site connection status.
When and what data is sent:
- On every blocked request: visitor IP, country (resolved server-side), request URL and method, user-agent, attack type that triggered the block, timestamp.
- On every approximately 5 minutes: a rules-version check (lightweight) and an agent heartbeat with site identifier.
- On every approximately 60 minutes: server diagnostics (PHP version, server software, OS, disk usage, OpenSSL version, cURL version, memory peak, platform/install-method detection).
What is NOT sent: post or page content, user names, passwords, email addresses, database content, file content.
Service URL: the URL you configure in Settings -> UX3 Security (typically https://central.ux3security.com/api/v1).
Provider: UX3 Security.
Terms of service: https://central.ux3security.com/terms
Privacy policy: https://central.ux3security.com/privacy
2. ip-api.com
What it is and what it is used for: ip-api.com is a third-party IP geolocation service. The plugin queries it to resolve the country, city, ISP, and approximate latitude/longitude of visitor IPs. Geo data is used for country-based blocking rules, the geographic view of attack traffic on the dashboard, and proxy/hosting detection.
When and what data is sent: only the visitor’s IP address, when a request hits the firewall and the IP has not been resolved within the last 24 hours. The IP is the only piece of data transmitted in the request URL. ip-api.com does not receive any other request details, headers, or content.
Service URL: http://ip-api.com/json/{ip} (free tier: 45 requests per minute, no API key required).
Provider: ip-api.com.
Terms of service: https://members.ip-api.com/legal
Privacy policy: https://ip-api.com/docs/legal
Screenshots








Installation
- Upload the plugin files to
/wp-content/plugins/ux3-security/, or install via the Plugins screen in WordPress - Activate the plugin through the ‘Plugins’ screen
- Visit Settings UX3 Security
- Review the Data Processing Consent section — this explains exactly what data the plugin sends to the UX3 Security API and to ip-api.com. Tick the consent checkbox only if you agree.
- Paste your API URL and API Token (from your UX3 Security dashboard)
- Tick “Enable UX3 Security protection” and Save
The plugin ships with protection disabled by default and will not send any data to external services until you have both given consent and enabled protection.
For maximum protection on supported hosts, you can additionally configure auto_prepend_file in your php.ini — see the Settings page for the exact directive.
FAQ
-
Do I need an account on central.ux3security.com?
-
Yes. The plugin is the agent — it works in conjunction with the central dashboard where you create accounts, add sites, and configure rules.
-
What happens if my site can’t reach the API?
-
The agent caches firewall rules locally for 5 minutes. If the API is unreachable, it continues using the cached rules — your site stays protected even during brief network blips. After cache expiry, the agent skips silently rather than break your site.
-
Will this plugin slow down my site?
-
The agent is highly optimized — typical overhead is 1-3ms per request. Rules are cached on disk so most requests don’t even need a database lookup.
-
Can I temporarily disable protection?
-
Yes — uncheck “Enable UX3 Security protection” on the settings page. No need to deactivate the plugin.
-
How do I withdraw consent?
-
Uncheck the consent checkbox on Settings UX3 Security and save. The agent stops making outbound requests immediately.
-
How does the plugin display warning pages when a request is blocked?
-
Blocked visitors see a warning page served in an iframe from central.ux3security.com. The plugin does not cache warning-page HTML in your WordPress database or filesystem — the styled page is served live from Central each time.
-
Where are my settings stored?
-
In the WordPress options table — same place as other plugin settings. They’re cleaned up automatically if you delete (not just deactivate) the plugin.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“UX3 Security” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “UX3 Security” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.0
- Initial release
- WordPress wrapper for the UX3 Security agent (v1.1.0)
- Settings page for API URL / token / enable toggle
- Auto-detect existing auto_prepend_file config and recommend if not set
- Reports install_method = ‘wp_plugin’ to the dashboard
