NullState Security™

Description

NullState Security™ is a free WordPress security plugin with modular hardening, threat interception, forensic logging, a live traffic monitor (90-day retention), two-factor authentication (TOTP), and a vulnerability scanner.

Key free features:

  • Core hardening – disables XML-RPC, hides version leaks, protects the uploads directory
  • Brute-force protection – automatic IP lockout after repeated failed logins
  • IP blacklist – block attackers manually or from the Live Traffic feed, with CSV import/export
  • Request filtering – blocks directory traversal, SQL injection, XSS, eval() and other attack payloads
  • User-Agent Bouncer – blocks known malicious scanners and bots (e.g. Nuclei, sqlmap)
  • Emergency lockdown – temporarily disable non-admin logins and block the site
  • Session terminator – end all other sessions with one click
  • Cache & temp purge – clear caches and kill memory-resident shells
  • Admin creation lockdown – detect and delete rogue administrator accounts
  • Uploads shield – block script execution in the uploads directory
  • Forensic logging – every security event recorded with full request context
  • Live traffic monitor (90-day) – real-time view of every request, classified as human, bot, or attack, with country flags and one-click IP blocking
  • Two-factor authentication – TOTP-based 2FA (Google Authenticator, Authy, …) with backup codes
  • Vulnerability scanner – checks plugins, themes and core for known vulnerabilities (optional free WPScan API token for detailed data)
  • Manual malware sweeps – C2 trojan cleanup, JS dropshell removal, trojanized CSS stripping, fake dependency removal, transient drop-shell cleanup
  • Security scorecard – 0–100 score with actionable recommendations

For advanced security solutions, enterprise-grade protection, and expert support,
visit nullstatesecurity.net.

External Services

This plugin connects to the following external services:

  1. WPScan API (wpscan.com) – Optional

    • Purpose: Vulnerability database queries
    • Data sent: Plugin/theme/core version information
    • When: During vulnerability scans (user-initiated)
    • Terms: https://wpscan.com/terms
    • Privacy: https://automattic.com/privacy/
  2. AbuseIPDB (abuseipdb.com) – Optional

    • Purpose: IP reputation and threat scoring
    • Data sent: Visitor IP addresses
    • When: When viewing IP details in Live Traffic
    • Terms: https://www.abuseipdb.com/legal
    • Privacy: https://www.abuseipdb.com/privacy
  3. ip-api.com

    • Purpose: Geolocation, ISP, and location data
    • Data sent: Visitor IP addresses
    • When: For country flags and IP lookup details
    • Terms: https://ip-api.com/terms
    • Privacy: https://ip-api.com/privacy
  4. WordPress.org API

    • Purpose: Checking for outdated plugins/themes/core
    • Data sent: Installed version numbers
    • When: During vulnerability scans
    • Terms: https://wordpress.org/about/privacy/

Installation

  1. Upload the nullstate-security folder to /wp-content/plugins/
  2. Activate the plugin
  3. Go to NullState Security™ Settings to configure
  4. Enable features you want to use

Reviews

There are no reviews for this plugin.

Contributors & Developers

“NullState Security™” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

3.4.6

  • All code prefixes renamed to the nullstatesecurity_ / NULLSTATESECURITY_ / nullstatesecurity- convention (options, transients, user meta, hooks, classes, constants, handles, slugs, nonces, CSS classes)
  • Automatic one-time migration on activation/update moves existing settings, transients, user meta and log files to the new prefix
  • $_SERVER request data sanitized (esc_url_raw / sanitize_text_field) before use and logging
  • Various sanitization and hardening fixes

3.4.5

  • No license keys, license checks, tiers or registration API – plugin runs fully without any activation
  • All shipped features are available to every user; no feature gating or upgrade prompts
  • Live Traffic retention fixed at 90 days for all installations
  • Removed the License admin page and license tracker
  • Removed all premium-feature promotion from the admin UI and readme
  • External services documented (WPScan, AbuseIPDB, ip-api.com, WordPress.org API)
  • Storage consolidated under wp-content/uploads/nullstate-security/ with direct-access protection
  • Various sanitization and hardening fixes

3.4.0

  • NEW: Two-Factor Authentication (TOTP) – added as a free feature
  • NEW: Vulnerability Scanner – checks plugins, themes, and core for known vulnerabilities (free)

3.3.0

  • IMPROVED: IP blacklist enforcement now works on all requests (including admin)
  • FIX: Brute-force lockout now correctly auto-blocks IPs
  • FIX: CSV export/import now works as expected

3.2.2

  • NEW: Country flags in Live Traffic – see the origin country of each visitor
  • NEW: IP Lookup Tool – view ISP, location, and threat score for any IP in the Live Traffic details modal
  • NEW: Bulk IP Import/Export – import and export IP blacklists via CSV
  • FIX: Local/private IPs are now excluded from IP blacklist and Live Traffic
  • IMPROVED: Dashboard redesign with security scorecard, charts, and recommendations
  • IMPROVED: Dark mode toggle in admin bar
  • IMPROVED: First-run onboarding wizard
  • IMPROVED: Tooltips with documentation links throughout the UI
  • IMPROVED: Notification center with bell icon and unread badge

3.0.0

  • Rebranded from WP Sentinel Guard to NullState Security™
  • All code prefixes migrated: classes/constants (WPSG_ NSS_), functions and hooks (wpsg_ nss_), text domain (wp-sentinel-guard nullstate-security)
  • Main plugin file renamed to nullstate-security.php; admin module files renamed to class-nss-*.php
  • All storage migrated from wpsg_* to nss_*: options, transients, user meta keys, JSON data files and data directories
  • Automatic one-time migration on activation – existing settings, fingerprints, logs, backups and scan history are preserved
  • Admin menu pages and URLs updated to the new naming

2.5.0

  • NEW: Live Traffic Monitor – real-time view of every request to your site
  • Auto-refresh every 5 seconds with pause/resume (AJAX polling)
  • Filter by IP, method, status, URL and user agent + pagination (50 per page)
  • Block IP directly from the traffic table (adds to the IP blacklist)
  • Request details modal (headers, referer, size, response time, user ID, AJAX/REST flags)
  • Storage in JSON file capped at 10,000 entries (oldest 10% trimmed)
  • Skips admin-ajax, admin-post, wp-cron and login pages by default (filterable)
  • Exclude IPs and user agents from logging
  • Response time + final HTTP status patched in on shutdown

2.0.0-2.0.5

  • Complete admin dashboard rebuild with 5 subpages
  • New UI with Tailwind CSS (dark mode ready)
  • Scan page with “Run All Scans” button and progress bar
  • Logs page with date filter, pagination, and per-page dropdown
  • Settings page with toggles for XML-RPC, User-Agent Bouncer, Login Error Hiding
  • Brute-force threshold and lockout duration settings
  • Emergency lockdown toggle on dashboard
  • Automatic .htaccess deployment on plugin activation
  • IP whitelist and trusted proxies settings

1.5.3

  • Added “Run All Scans” button with progress bar
  • Redesigned logs page with date filter and pagination
  • Added settings page with toggles and thresholds
  • Fixed performance issues (moved sweeps to manual)
  • Fixed IP spoofing vulnerability
  • Fixed double-encoding bypass
  • Fixed admin-ajax false positives
  • Added IP whitelist and trusted proxies

1.0.0

  • Initial release
  • Core hardening (XML-RPC disable, version hiding, uploads protection)
  • Brute-force protection with IP lockout
  • Forensic logging with JSON format
  • Request filtering and malware signature detection
  • Rogue script blocking
  • Header evaluation shield
  • XOR/Hex payload defender
  • C2 interceptor and spoofing defender
  • User-agent bouncer
  • Session terminator
  • Emergency lockdown mode
  • Uploads execution shield
  • Cache and temp purge
  • Admin creation lockdown