Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Webboll Security

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Webboll Security

By muratkopar
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Webboll Security is an advanced security plugin that protects your WordPress site with a behavior-based approach. Instead of looking at individual requests, it reads attacker intent early by examining the visitor’s sequence of actions.

Free features:

  • Custom login URLs (hide wp-admin and wp-login.php)
  • Separate admin and member login gates
  • Brute-force protection with automatic IP blocking
  • Threat engine analyzing seven attack types with risk scoring
  • REST API and XML-RPC protection
  • Two-factor authentication (2FA) for admin and member logins
  • Honeypot bot traps
  • Activity log of all security events
  • Threat report with 24-hour and 7-day summaries
  • Bot detection with reverse-DNS verification of legitimate search engine bots
  • Panic mode for one-click lockdown
  • Email notifications
  • Multi-language support (7 languages)

Pro features:

  • Attack-Time Shield — verification gate for suspicious visitors during active attacks
  • Geo-Blocking — allow or block access by country
  • IP Reputation Databases — automatic blocking via AbuseIPDB, Spamhaus and other lists
  • Malware Scanner — scans files for malicious code using heuristics
  • File Integrity Monitoring — detects file changes with SHA-256 fingerprinting
  • Adaptive Learning Pool — learns attack patterns and quarantines new threats
  • IP Trajectory Analysis — tracks attacker movement across your site
  • Cloudflare Integration — real IP detection and blocking through Cloudflare
  • SMS Notifications — instant alerts for critical security events

External services

This plugin can connect to the following third-party services. Each one is optional and is only contacted when you enable and configure the corresponding feature. No data is sent to any of them unless you turn the feature on.

Cloudflare Turnstile (CAPTCHA) — Used to verify that a login/form submission is human when you select Turnstile as your CAPTCHA provider. When a protected form is submitted, the visitor’s Turnstile token and IP address are sent to Cloudflare for verification. The Turnstile script is also loaded on protected pages. Terms: https://www.cloudflare.com/terms/ — Privacy: https://www.cloudflare.com/privacypolicy/

hCaptcha (CAPTCHA) — Used to verify that a submission is human when you select hCaptcha as your CAPTCHA provider. On submission, the visitor’s hCaptcha token, secret key and IP address are sent to hCaptcha for verification, and the hCaptcha script is loaded on protected pages. Terms: https://www.hcaptcha.com/terms — Privacy: https://www.hcaptcha.com/privacy

Google reCAPTCHA (CAPTCHA) — Used to verify that a submission is human when you select reCAPTCHA as your CAPTCHA provider. On submission, the visitor’s reCAPTCHA token and IP address are sent to Google for verification, and the reCAPTCHA script is loaded on protected pages. Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy

ip-api.com (IP geolocation) — Used to look up the country and network information of an IP address shown in the IP management and threat screens. When you request details for an IP (or geo-blocking evaluates a visitor), that IP address is sent to ip-api.com. Terms & Privacy: https://ip-api.com/docs/legal

NetGSM (SMS) — Used to send SMS notifications and one-time codes if you enable SMS and enter your NetGSM credentials. When an SMS is triggered, the destination phone number, message text and your NetGSM credentials are sent to NetGSM. Terms & Privacy: https://www.netgsm.com.tr/sozlesme/

Twilio (SMS) — Alternative SMS provider. If you enable Twilio and enter your credentials, the destination phone number, message text and your Twilio credentials are sent to Twilio when an SMS is triggered. Terms: https://www.twilio.com/en-us/legal/tos — Privacy: https://www.twilio.com/en-us/legal/privacy

Screenshots

Installation

  1. Upload the plugin files to the /wp-content/plugins/webboll-security directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the “Plugins” screen in WordPress.
  3. Go to the WBS Security menu to configure your settings.
  4. Important: For custom login URLs to work, your WordPress Permalinks must not be set to “Plain” (Settings → Permalinks → choose “Post name”).

FAQ

Do custom login URLs work with any permalink setting?

No. WordPress cannot handle custom URL rewriting with the “Plain” permalink structure. Set Permalinks to any option other than “Plain” (recommended: Post name).

Does the free version provide real protection?

Yes. Brute-force protection, REST/XML-RPC protection, automatic IP blocking, the threat engine, 2FA, and more are all included in the free version.

Which languages are supported?

Turkish, English, Spanish, German, French, Portuguese (Brazil) and Italian.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Webboll Security” is open source software. The following people have contributed to this plugin.

Contributors
  • muratkopar
  • Freemius

Translate “Webboll Security” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

2.9.20

  • Raised the default Bot Detection auto-block score threshold from 8 to 15 to reduce false positives (a few quick page refreshes no longer risk an automatic block). Existing sites keep their configured value; the setting can still be changed under Bot Detection → Settings.

2.9.19

  • Lowered the minimum required WordPress version (“Requires at least”) from 7.0 to 6.5 so the plugin installs and activates on current WordPress 6.x sites.

2.9.18

  • Updated the Cloudflare Turnstile terms link in the External services section to the Cloudflare Self-Serve Subscription Agreement (https://www.cloudflare.com/terms/).

2.9.16

  • Updated the Plugin URI to https://webboll.com/webboll-security/.

2.9.15

  • Removed the “Tested up to” header from the main plugin file; compatibility is now declared only in readme.txt.
  • Step-up re-authentication is now bound to the current session token, so verifying in one session no longer authorizes the user’s other concurrent sessions.
  • Pending 2FA state is now keyed to a cryptographically random one-time token stored in an HttpOnly/Secure cookie instead of IP + User-Agent, preventing shared-IP collisions and spoofing of the pending login.

2.9.14

  • Database hardening: dynamic table names in all queries are now bound with the %i placeholder inside $wpdb->prepare(); table-creation (DDL) statements are annotated. No query interpolates a table name into a prepared string anymore.

2.9.13

  • Final prefix pass: removed the last short WBS references in comments and the admin menu label; everything now uses the WBSEC_/wbsec_ prefix consistently.

2.9.12

  • Every echoed value (including ternary class/style outputs) is now escaped at output with esc_attr/esc_html; no unescaped dynamic output remains.

2.9.11

  • Redirect targets from redirect_to are now validated with wp_validate_redirect at both input and output, fully closing any open-redirect path after login/2FA.

2.9.10

  • The shield/CAPTCHA widget now enqueues its script and uses progressive enhancement, removing the last inline

2.9.9

  • Security: login redirects now use wp_safe_redirect with wp_validate_redirect (prevents open redirect after 2FA).
  • All remaining icon/notice output is escaped with wp_kses at output; honeypot page styles are inline attributes (no style block).
  • Renamed the localized JS object from WBS to WBSEC_ADMIN to avoid a generic global name.

2.9.8

  • Added the PRO badge to the Behavior Engine status card so all Pro-only features are marked consistently on the dashboard.

2.9.7

  • Added the PRO badge to the Behavior Engine settings tab for consistency with the other Pro-only tabs.

2.9.6

  • Pro-only settings (behavior engine, trajectory, learning pool, shield, geo-blocking, reputation, file monitor, malware) are now shown as locked in the free version and their controls are hidden, so they can no longer appear enabled or be toggled where the feature is not present.

2.9.5

  • Completed the prefix rename in the bundled MaxMind reader library and the icon-manager script, fixing the geo reader class name and the icon AJAX object so they match again.

2.9.4

  • Fixed AJAX action and hook names that still used the old prefix, so admin buttons (IP lists, bot detection, panic mode, tests) work again. Also hardened remaining bot-detection queries.

2.9.3

  • Fixed the license-acceptance action hook that still used the old prefix, so the terms notice could not be dismissed.

2.9.2

  • Removed remaining Google Fonts references from admin and login stylesheets; the UI now uses the system font stack.

2.9.1

  • Fixed a fatal error on activation: class file names are now aligned with the wbsec prefix used by the loader.

2.9.0

  • Moved inline scripts and styles to enqueued asset files with wp_localize_script (login pages, IP manager, bot detection, file monitor, malware scan, trajectory, threat report, AI test).
  • Icon (SVG) output is escaped at every call site with a wp_kses allowlist.
  • Database table names in dynamic queries are bound with the %i placeholder.

2.8.8

  • Renamed all internal prefixes (classes, options, hooks, AJAX actions, CSS classes, page slugs and SVG asset IDs) to a unique WBSEC_/wbsec_/wbsec- prefix throughout PHP, CSS, JS and SVG.

2.8.7

  • Fixed: 2FA SMS is now sent through the selected SMS provider (Twilio or NetGSM); previously it always used NetGSM. The 2FA method label now reflects the active provider.

2.8.6

  • The plugin-language selector is now shown only when translation files are bundled; otherwise a short note explains that translations are delivered via WordPress.org. Prevents a non-functional language dropdown.

2.8.5

  • Security & compliance: SVG icons now sanitized via wp_kses allowlist; all $_SERVER inputs sanitized; removed external Google Fonts in favor of system fonts.

2.8.4

  • WordPress.org compliance round: documented all external services in the readme; moved AI analysis to Pro only; replaced HEREDOC email template with output buffering; removed runtime FORCE_SSL_ADMIN define; language files now ship with the Pro build and load conditionally; fixed plugin URI.

2.8.3

  • WordPress.org compliance: trajectory viewer queries now bind the table name with the %i placeholder and run inline through $wpdb->prepare, removing the intermediate SQL variable flagged by the scanner.

2.8.2

  • WordPress.org compliance: translation calls now use literal strings instead of variables (activity log templates, attack-type labels, icon labels); database queries in the trajectory viewer and audit pages are now always run through $wpdb->prepare.

2.8.1

  • WordPress.org compliance: replaced all short echo tags (<?=) with full <?php echo tags across the codebase, and fixed an interpolated variable inside a translation string.

2.8.0

  • Free version now shows ALL Pro features consistently: Trajectory Viewer and Learning Pool menus appear (locked with a PRO badge) just like File Monitoring and Malware Scan, instead of being hidden. Clicking them shows an upgrade notice — no fatal, no missing menus.

2.7.5

  • Aligned readme contributor with the WordPress.org account (muratkopar).

2.7.4

  • Fixed: logout entries in the activity log now translate in all languages, including sessions where the username was empty.

2.7.3

  • Activity log entries (auto-block reasons, attack type labels) now translate at display time across all languages, instead of showing raw Turkish.
  • REST audit “no user” label and remaining attack labels localized.
  • IP Management: fixed the “Reason” column layout — no longer squeezed vertically on narrow screens; tables now scroll horizontally when needed.

2.7.2

  • Fixed: selected language was lost on sub-menu pages (Activity Log, Blocked IPs, Trajectory, etc.). The locale override now covers all plugin admin pages, so the chosen language persists across every menu.

2.7.1

  • Comprehensive translation coverage: login/block screens, IP management, geo-blocking country names, menu icon labels, Pro-lock notices, and all admin AJAX messages now fully localized across 6 languages.
  • Default captcha/message values no longer hard-set in Turkish; translated at display time.

2.7.0

  • Text domain aligned with plugin slug (webboll-security) for wordpress.org translation compatibility.
  • Hardened input sanitization (POST/SERVER) and output escaping ahead of directory review.
  • Comprehensive interface translations across login, 2FA, and behavior pages.

2.6.8

  • Freemius integration, premium/free separation, user guide, support box, permalink warning, and updated version requirements.

Meta

  • Version 2.9.20
  • Last updated 21 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.5 or higher
  • Tested up to 7.1.3
  • PHP version 8.0 or higher
  • Tags
    Brute Forcefirewallloginsecuritytwo factor authentication
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • muratkopar
  • Freemius

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry