Title: Forge12 Security – Firewall, Malware Scanner, 2FA &amp; Login Security
Author: Forge12 Interactive GmbH
Published: <strong>September 30, 2026</strong>
Last modified: September 30, 2026

---

Search plugins

![](https://ps.w.org/forge12-security/assets/banner-772x250.png?rev=3720713)

![](https://ps.w.org/forge12-security/assets/icon-256x256.png?rev=3720713)

# Forge12 Security – Firewall, Malware Scanner, 2FA & Login Security

 By [Forge12 Interactive GmbH](https://profiles.wordpress.org/forge12/)

[Download](https://downloads.wordpress.org/plugin/forge12-security.3.7.16.zip)

 * [Details](https://wordpress.org/plugins/forge12-security/#description)
 * [Reviews](https://wordpress.org/plugins/forge12-security/#reviews)
 *  [Installation](https://wordpress.org/plugins/forge12-security/#installation)
 * [Development](https://wordpress.org/plugins/forge12-security/#developers)

 [Support](https://wordpress.org/support/plugin/forge12-security/)

## Description

**Forge12 Security** is an all-in-one WordPress security plugin built by Forge12
Interactive GmbH in Germany. Firewall, malware and file scanner, login protection
with two-factor authentication, hardening and AI crawler control — every module 
can be switched on and off on its own, so a site runs only the parts it needs.

It is built for sites that have to answer for their visitors’ data: IP addresses
are stored as hashes, the admin loads no fonts, scripts or images from anybody else,
and nothing contacts a third party unless you switch the feature on.

Every feature described below is included and fully functional. Nothing here is

limited by a licence key, a trial period or a usage quota.

#### Forge12 Security Pro

For agencies and business sites, [Forge12 Security Pro](https://www.forge12.com/en/shop/f12-security)
adds what the plugin directory does not allow a free plugin to do, and what saves
time when you look after many sites:

 * **Repair with one click** — put the original back over a modified WordPress, 
   plugin or theme file, one at a time or all at once, and restore files from quarantine
 * **Firewall before WordPress** — requests are checked before WordPress and every
   other plugin load
 * **Same-day signatures** — malware signatures and firewall rules the day they 
   are published; the free plugin receives the same rule set 30 days later
 * **Country blocking and IP ranges** — allow or block by country, and by IPv4/IPv6
   range
 * **Tamper-proof audit trail, Slack and Telegram alerts, daily digest**
 * **Remote monitoring, WP-CLI and multisite network management** for looking after
   many sites
 * **Database snapshots with restore, Google Safe Browsing**, and automatic repair
   and quarantine instead of a report

Pro is an add-on: it needs this plugin installed and active, and keeps all of its
settings. [Compare Free and Pro](https://www.forge12.com/en/shop/f12-security).

#### What it does

 * **Web application firewall.** Scores each request against a signature set and
   
   refuses it when a category threshold is reached. A learning mode records what
   matches without blocking, so the exceptions your own site needs can be created
   from what actually happened.
 * **Outbound traffic monitoring.** Watches where this installation sends data
    
   and to whom, learns which hosts are normal, and reports the new ones. Stolen 
   data has to leave the server somehow; this is where that shows.
 * **Reinfection, not just infection.** A file that was removed and came back is
   
   proof of persistence. The scanner looks for what put it back — a scheduled event,
   a must-use plugin, a drop-in — instead of deleting it again.
 * **Behaviour rules.** Judges a file by the sequence of things its code does
    (
   create a user, hand it the administrator role, mark it to be found again), not
   by how it is written. Obfuscation is free to change; the steps are not.
 * **AI crawler detection with proof.** Anyone can put “ClaudeBot” in a header.
   
   Crawlers are checked against the address ranges their operators publish, so a
   claim that cannot be verified is treated as unverified rather than as fact. Each
   crawler, or each category of crawler, can be allowed, watched or refused.
 * **Login protection and two-factor authentication.** Rate limiting, lockouts,
   
   TOTP with locally generated QR codes, and an optional custom login address.

#### Requirements

 * WordPress 6.2 or higher
 * PHP 8.1 or higher
 * MySQL 5.7 / MariaDB 10.3 or higher

### External Services

Everything this plugin does happens on your own server, with the exceptions
 below.
None of them runs unless the feature that needs it is switched on; the only one 
that is on out of the box talks to WordPress.org. The plugin’s Data Protection screen(
Security, Privacy) shows which of them are active on your site.

**WordPress.org** — on by default

File integrity, malware and update checks compare your files with the official
 
checksums. Sent while a scan runs: plugin and theme slugs, version numbers and file
hashes. No personal data. Terms: https://wordpress.org/about/license/ Privacy policy:
https://wordpress.org/about/privacy/

**WPVulnerability** — off by default

Looks up whether an installed plugin or theme has a published vulnerability.
 The
setup wizard asks first. Sent once a day and during a full scan: the slug and version
of each installed plugin and theme. Nothing about your site or your visitors. Terms:
https://www.wpvulnerability.com/license/ Privacy policy: https://www.wpvulnerability.
com/privacy/

**Have I Been Pwned (Pwned Passwords)** — off by default

Checks whether a new password appears in a known breach. Only the first five
 characters
of the password’s SHA-1 hash are sent (k-anonymity), never the password and never
a username. Terms: https://haveibeenpwned.com/API/v3 Privacy policy: https://haveibeenpwned.
com/Privacy

**SilentShield** — off by default, needs an API key

A behaviour check on the login, registration and password reset forms, and the
 
only feature that loads a script into a visitor’s browser — on those three forms
only. The visitor’s IP address reaches the service. Operated by Forge12 Interactive
GmbH from Germany. Terms: https://silentshield.io/terms/ Privacy policy: https://
silentshield.io/privacy/

**Forge12 signature service** — off by default

Fetches the current signed malware and firewall rule set twice a day and applies

it only after its signature checks out. The setup wizard asks first. Sent: the plugin
version and the number of the rule set already held. If you enter a licence key,
the key and this site’s domain are sent to validate it. Operated by Forge12 Interactive
GmbH from Germany. Terms: https://www.forge12.com/agb/ Privacy policy: https://www.
forge12.com/datenschutz/

**Crawler operators’ published address lists** — off by default

Switched on, the list each crawler operator publishes of its own addresses is
 fetched
once a day, so that a real crawler can be told from an impostor. The lists come 
from the operators themselves: Google, Microsoft Bing, OpenAI, Anthropic, Perplexity,
DuckDuckGo, Apple, Cloudflare, UptimeRobot and Jetpack. The request carries the 
plugin’s user agent, which names your site; nothing else is sent. While it is off,
the lists shipped with the plugin are used and nothing is fetched. Each operator’s
own terms and privacy policy apply.= Key Features =

**Web Application Firewall (WAF)**

 * Regex-based request filtering with customizable rules
 * IP blocking with automatic expiration
 * Bot detection with reverse DNS verification for Googlebot, Bingbot, Yandex, Baidu,
   DuckDuckBot
 * Request validation (method, URL length, null byte detection)
 * Predefined rule sets for common attack patterns (SQL injection, XSS, path traversal)
 * WAF Learning Mode that records what the firewall would have blocked
 * Automatic whitelist rule generation from learning mode results

**Outbound Traffic Monitoring**

 * Watches where this installation sends data, and to whom
 * Learns a baseline of the hosts your site normally talks to, then reports the 
   ones that are new
 * Refuses an outbound call before the connection is opened, so exfiltration and
   callbacks to a command server are stopped rather than logged after the fact
 * The step every worthwhile attack has to take in the end — stolen data has to 
   leave the server somehow

**Vulnerability Shield**

 * Holds a known-vulnerable plugin shut until its update arrives
 * The unauthenticated endpoints of a plugin with a published, unpatched vulnerability
   stop answering — the plugin’s own code is never touched
 * Closes the window between disclosure and update: the weighted median from publication
   to mass exploitation is five hours, and 46 % of vulnerabilities are still unpatched
   on the day they are published

**AI Crawler Detection**

 * Recognises crawlers operated by AI companies: OpenAI, Anthropic, Google, Perplexity,
   Meta, Apple, Amazon, Common Crawl, ByteDance and more
 * Sorts them by what they do with your content: model training, assistant fetches
   on behalf of a user, AI search indexing
 * Records which crawler requested what, and how often
 * Allow, watch or block each crawler or whole category
 * Matching robots.txt directives generated from your decisions

**DDoS & Rate Limiting**

 * Configurable request rate limits per IP
 * Separate rate limits for REST API endpoints
 * 404 rate limiting to detect and block vulnerability scanners
 * Automatic IP blocking on limit exceeded
 * IP whitelist for trusted addresses

**Login Protection**

 * Brute force prevention with automatic lockout (5 attempts / 15 min)
 * Two-factor authentication (TOTP) with QR code setup
 * Recovery codes for 2FA
 * Login honeypot for bot detection
 * Custom login URL to hide wp-login.php
 * SilentShield bot check on the login, registration and password reset forms — 
   Forge12’s own service, served from Germany, no Google script in your visitors’
   browsers
 * Login activity logging (success, failure, lockout)

**Password Security**

 * Configurable strong password policy (minimum length, uppercase, numbers, special
   characters)
 * Breached password detection via Have I Been Pwned API (k-Anonymity)
 * 2FA enforcement per role, with a grace period for gradual rollout

**File Integrity Monitoring**

 * SHA-256 checksum baseline of all WordPress core, plugin, and theme files
 * Automatic scheduled scans with configurable intervals
 * Repository verification against WordPress.org originals
 * Automatic scheduled malware and integrity scans
 * Quarantine and delete suspicious files
 * Excluded paths: a page for the directories no file check should judge — a template
   cache a plugin fills with generated PHP, a staging clone, code you trust. It 
   records which places your scans keep reporting and how many scans in a row, so
   excluding one is a button rather than a path typed from memory; entries can be
   switched off instead of deleted, and known candidates are offered as ticks, never
   applied on their own

**Malware Signature Scanner**

 * Pattern-based malware detection with 283 built-in signatures
 * Detects eval/base64 backdoors, shell uploads, code obfuscation, and remote includes
 * Heuristic detection via entropy and structure analysis, beyond signature matching
 * Three sensitivity levels: critical signatures only, critical and high, or everything
   including heuristics
 * Files that still match the checksum their author published on WordPress.org are
   never flagged
 * Mark a reviewed file as allowed — pinned to its content, so a later change brings
   it back into scope
 * File Guard: an unexpected PHP file is reported the moment it is executed, not
   on the next scheduled scan. On its own this covers files that load WordPress,
   which is most of them, because a shell usually wants the database.
 * Suspicious file flagging with threat identification
 * Extensible signature database (JSON format)

**Reinfection, Attack Surface and Supply Chain**

 * Persistence check: finds what puts a removed file back — a scheduled event, a
   must-use plugin, a drop-in — starting with the evidence that actually proves 
   reinfection, a file that was taken away and is back
 * Attack surface: records which REST routes and AJAX actions are reachable without
   logging in and which of those change something, and reports the door that newly
   appeared
 * Update guard: verifies an installed update against the per-file checksum manifest
   WordPress.org publishes, so a package that is not what the author shipped is 
   caught on arrival
 * Known hashes: covers premium plugins, bespoke themes and this plugin itself, 
   where wordpress.org publishes no original to compare against
 * File inventory instead of modification times: a dropped file cannot make itself
   old with touch, and a plugin update no longer resets what counts as new
 * Behaviour rules: judges a file by the sequence of things its code does — create
   a user, hand it the administrator role, mark it to be found again — not by how
   it is written
 * Every finding says in plain words what it means and what to do about it, instead
   of naming the rule that fired

**Database Integrity Monitoring**

 * Monitors wp_options, wp_posts, wp_postmeta, wp_users, wp_usermeta
 * Detects unauthorized modifications, injected scripts and phishing URLs in posts,
   comments and options

**WordPress Hardening**

 * Disable XML-RPC and pingbacks
 * Disable file editor
 * Force SSL for admin area
 * Block PHP execution in uploads directory
 * Prevent user enumeration
 * Restrict REST API to authenticated users
 * Disable application passwords
 * Remove WordPress version info
 * Configurable Content-Security-Policy header
 * Full suite of security headers (HSTS, X-Frame-Options, X-Content-Type-Options,
   etc.)
 * Limit post revisions
 * Shorter session lifetimes
 * Limit concurrent sessions per user
 * Auto-update WordPress core
 * Comment spam honeypot protection
 * Strong password enforcement with configurable rules
 * SilentShield bot protection for login, registration and password reset forms

**Email Notifications**

 * Alerts for critical and high severity events
 * Findings collected and sent as one message, grouped and counted, instead of one
   email per finding
 * Anything critical sent immediately, with whatever else has collected
 * Unsubscribe link in every message, for people who no longer have an account on
   the site
 * Weekly summary of what was blocked, attempted and found — sent whether or not
   anything went wrong
 * Optional notifications for IP blocks
 * Scan summary emails when changes are detected
 * Configurable notification email address
 * A test button to check delivery
 * Slack and Telegram alerts and a daily digest are part of Forge12 Security Pro

**Live Traffic**

 * Watch requests as they arrive, with response code, request type and bot classification
 * Block an IP straight from a traffic entry
 * Records security-relevant requests (errors, blocks, login attempts) and keeps
   24 hours

**Security Logging**

 * Comprehensive event logging for all security actions
 * Filterable by event type and severity
 * Quick-filter for login activity
 * CSV export
 * Block IPs directly from log entries
 * Configurable log retention (default: 90 days)

**Data Protection**

 * IP anonymization via HMAC-SHA256 (no plain IPs stored)
 * Optional AES-256-CBC encrypted IP storage
 * WordPress privacy exporter integration
 * WordPress privacy eraser integration

**Settings Management**

 * Import/export settings as JSON
 * Security score with detailed breakdown
 * Modern React-based admin interface

## Screenshots

[⌊Dashboard: security score, a week of events, and every module on one switch each⌉⌊
Dashboard: security score, a week of events, and every module on one switch each⌉[

Dashboard: security score, a week of events, and every module on one switch each

[⌊Firewall: what was refused and why, split by kind, with the addresses currently
blocked⌉⌊Firewall: what was refused and why, split by kind, with the addresses currently
blocked⌉[

Firewall: what was refused and why, split by kind, with the addresses currently 
blocked

[⌊Rate limiting: separate limits for pages, the REST API and missing files⌉⌊Rate
limiting: separate limits for pages, the REST API and missing files⌉[

Rate limiting: separate limits for pages, the REST API and missing files

[⌊Hardening: each measure on its own switch, the ones still off marked, and a watch-
only position for the REST API⌉⌊Hardening: each measure on its own switch, the ones
still off marked, and a watch-only position for the REST API⌉[

Hardening: each measure on its own switch, the ones still off marked, and a watch-
only position for the REST API

[⌊Scanner: every step of a run, what it checked, and what it found⌉⌊Scanner: every
step of a run, what it checked, and what it found⌉[

Scanner: every step of a run, what it checked, and what it found

[⌊Logs: filter by severity or event, and export as CSV⌉⌊Logs: filter by severity
or event, and export as CSV⌉[

Logs: filter by severity or event, and export as CSV

[⌊AI crawlers: who fetched your content and what for - decide by purpose, not by
name⌉⌊AI crawlers: who fetched your content and what for - decide by purpose, not
by name⌉[

AI crawlers: who fetched your content and what for – decide by purpose, not by name

[⌊Data protection: what is stored, where, for how long, and what leaves the server⌉⌊
Data protection: what is stored, where, for how long, and what leaves the server⌉[

Data protection: what is stored, where, for how long, and what leaves the server

[⌊REST routes: which routes anonymous callers ask for, what was refused, and one
click to open the ones you need⌉⌊REST routes: which routes anonymous callers ask
for, what was refused, and one click to open the ones you need⌉[

REST routes: which routes anonymous callers ask for, what was refused, and one click
to open the ones you need

[⌊Excluded paths: the places your scans keep reporting, how many runs in a row, 
and one button to stop judging a directory a plugin generates⌉⌊Excluded paths: the
places your scans keep reporting, how many runs in a row, and one button to stop
judging a directory a plugin generates⌉[

Excluded paths: the places your scans keep reporting, how many runs in a row, and
one button to stop judging a directory a plugin generates

## Installation

 1. Upload the `forge12-security` folder to the `/wp-content/plugins/` directory
 2. Activate the plugin through the ‘Plugins’ menu in WordPress
 3. Navigate to the Forge12 Security menu in the admin sidebar
 4. Review the Dashboard and enable/disable modules as needed
 5. Configure individual module settings through the respective pages

#### First Steps After Installation

 1. **Check the Dashboard** – Review your security score and enable recommended modules
 2. **Run a File Scan** – Go to File Integrity and create a baseline
 3. **Review Hardening** – Enable hardening options that suit your site
 4. **Set Up Notifications** – Configure your notification email in Settings
 5. **Enable 2FA** – Activate two-factor authentication for admin accounts

## FAQ

### What is the difference between Forge12 Security and Forge12 Security Pro?

Everything described on this page is free and stays free, without a trial period
or a limit. [Forge12 Security Pro](https://www.forge12.com/en/shop/f12-security)
is an add-on for sites that want problems fixed rather than reported: one-click 
repair of modified files and restore from quarantine, a firewall stage that runs
before WordPress, same-day malware signatures and firewall rules, country blocking,
a tamper-proof audit trail, Slack and Telegram alerts, and remote monitoring for
many sites.

### Do I need this plugin to use Forge12 Security Pro?

Yes. Pro extends this plugin and needs it installed and active. Removing Pro leaves
this plugin and all of its settings as they were.

### Does this plugin work with caching plugins?

Yes. Forge12 Security operates at the PHP level and is compatible with all major
caching plugins. Rate limiting and firewall checks happen before page caching kicks
in.

### Will the custom login URL break my site?

No. If you forget the custom login URL, you can deactivate the plugin via FTP/file
manager and the standard wp-login.php will work again. Password-protected post forms(
action=postpass) continue to work normally.

### Does this plugin store IP addresses?

By default, IP addresses are hashed using HMAC-SHA256 and never stored in plain 
text. Optionally, you can enable AES-256-CBC encrypted storage if you need to identify
specific IPs. These options help minimize stored personal data; they do not guarantee
GDPR compliance.

### Can I use this with other security plugins?

While possible, we recommend using only one comprehensive security plugin to avoid
conflicts. If you need specific features from another plugin, you can disable overlapping
modules in Forge12 Security.

### What happens when the malware scanner finds something?

Suspicious files are flagged with the detected signature name. You can review the
file, move it to encrypted quarantine, or permanently delete it after a separate
confirmation. Modified WordPress, plugin and theme files are compared with their
published version; to replace one, reinstall or update it from the dashboard. Confirmed
false positives can be ignored or excluded.

### How does the honeypot work?

The honeypot adds an invisible form field to login and comment forms. Real users
never see or fill it. Bots that automatically fill all form fields trigger the honeypot
and are blocked. The field name rotates every 6 hours to prevent bot adaptation.

### How does the SilentShield bot check work?

A small client is loaded on your login, registration and password reset forms. It
watches how the form is filled in and leaves a token on it; on submission the plugin
asks the SilentShield API what that token was worth, and you set the threshold below
which a submission is refused. It replaced the Google reCAPTCHA integration in 3.3.44,
because that one loaded Google’s script into the browser of everybody who opened
your login page, handing Google their address and setting Google’s cookies for a
form only your own staff ever use. SilentShield is Forge12’s own service and answers
from a German host with no CDN in front of it, so the transfer is one you can put
in a contract. What has not changed: it is still a third-party script in the visitor’s
browser, and the visitor’s address still reaches somebody else. Like the check it
replaced it fails open by default — an outage at the API must never be the reason
nobody can log in — and a filter is there for sites that would rather be locked 
out than let a bot through.

### Does the breached password check send my passwords to an external service?

No. The HIBP check uses k-Anonymity: only the first 5 characters of the SHA-1 hash
of the password are sent to the API. The full password never leaves your server.
Results are cached for 24 hours.

### Where do I require two-factor authentication for a role?

Under Two-Factor Auth, above the user list. Switch on the roles that must carry 
a second factor, set the grace period beside them, and save. The roles offered are
the ones your site actually has, including any a plugin adds.

### What is the 2FA grace period?

It is how long somebody may go on working before the requirement takes effect: 0
to 90 days, counted from that account’s first sign-in after you switch the requirement
on. Nobody is ever locked out by it. The sign-in itself succeeds either way; once
the period is up, the account is taken to the setup screen and stays there until
a second factor is in place, and during the period it sees a notice with the days
remaining. A grace period of zero days means the setup screen appears at the next
sign-in.

### How does 404 rate limiting work?

404 rate limiting monitors how many “Page Not Found” errors a single IP generates
within a time window. Vulnerability scanners typically probe hundreds of known paths
rapidly, generating many 404s. When the threshold is exceeded, the IP is automatically
blocked.

### How does bot detection work?

Bot detection identifies fake search engine crawlers. When a visitor claims to be
Googlebot (via User-Agent), the plugin performs a reverse DNS lookup to verify that
the IP actually belongs to Google. If the reverse DNS check fails, the bot is flagged
as fake and optionally blocked. Results are cached for 24 hours.

### What is WAF Learning Mode?

Learning Mode records normal request patterns (URLs, methods, parameter names) over
a configurable period (default: 7 days). After the learning period, you can generate
whitelist rules from the observed traffic. These whitelist rules ensure that known-
good requests bypass WAF checks, reducing false positives.

### Why can this plugin not repair files or run the firewall before WordPress?

Both write into places the WordPress plugin directory does not allow this plugin
to write to: code into files, and files into the WordPress, plugin and theme folders
or the site’s root folder. Those features are part of [Forge12 Security Pro](https://www.forge12.com/en/shop/f12-security),
which is not distributed through the directory. This plugin still finds, explains
and compares every modified file, and quarantines or deletes suspicious ones.

### Can I export my settings to another site?

Yes. Go to Settings > Import / Export. You can export all settings as a JSON file
and import them on another WordPress installation.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Forge12 Security – Firewall, Malware Scanner, 2FA & Login Security” is open source
software. The following people have contributed to this plugin.

Contributors

 *   [ Forge12 Interactive GmbH ](https://profiles.wordpress.org/forge12/)

[Translate “Forge12 Security – Firewall, Malware Scanner, 2FA & Login Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/forge12-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/forge12-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/forge12-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/forge12-security/)
by [RSS](https://plugins.trac.wordpress.org/log/forge12-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

Only the most recent releases are listed here. The full history is in
 changelog.
txt, which ships with the plugin.

#### 3.7.16

A server set to write files over FTP without the FTP extension no longer takes the
site down.

 * Where WordPress was configured to write files over FTP but PHP has no FTP support,
   every request ended with a fatal error as soon as the plugin wrote a protection
   file. The plugin now recognises a file system that could not be set up and leaves
   the write out.

#### 3.7.15

Forge12 Security is now distributed through WordPress.org, and installations that
received their updates from forge12.com switch over by themselves.

 * An installation that received updates from forge12.com replaces itself with the
   WordPress.org copy on the next visit to the dashboard. Settings, records and 
   findings are kept, and automatic updates stay switched on if they were.
 * If a server does not allow the switch, for example because plugins cannot be 
   installed from the dashboard, a notice explains how to do it by hand and offers
   to try again.
 * Deleting one of two installed copies of the plugin no longer removes the settings
   and records the other copy still uses.
 * The WordPress.org package includes the German translation.

#### 3.7.14

Settings that went back to their old value after saving now stay, and a finding 
is emailed once instead of on every check.

 * The scan steps “Unpublished Files” and “Persistence”, and “Seconds per Scan Request”,
   were confirmed as saved but showed their previous value on the next load. They
   are now saved.
 * Saving on one screen could undo settings changed on another screen during the
   same visit, for example a hardening switch after “Save all Settings”. Each screen
   now saves only what was changed on it.
 * The audit log switch reported success without changing anything. It now switches
   audit logging on and off.
 * “Not listed on WordPress.org, so it cannot be checked there” is information for
   the log and is no longer sent by email.
 * An outdated or abandoned plugin or theme, and a known vulnerability, are emailed
   when they are first found, not again on every check. The log still records them
   each time. A new version, a new vulnerability or a change of state is emailed
   again.
 * Plugins listed on WordPress.org were missing from the vulnerability overview,
   because their last-update date did not fit the database field. They are now listed.
 * The setup wizard showed brute-force protection as a switch that could be turned
   off. The protection is always on, and the wizard now shows it that way.
 * “Custom Login URL” on the Hardening screen looked like a switch but only shows
   whether a login address is set. It no longer reacts to clicks.
 * The plugin’s own menu, the test email and the footer of alert emails now use 
   the plugin’s name, Forge12 Security, instead of the old short form.

#### 3.7.13

An expired license from before 26 September 2026 keeps its Pro features, and an 
unreachable license server no longer switches anything off.

 * A license whose term began before 26 September 2026 keeps the Pro features of
   the installed version after it expires. Updates and support end with the term.
 * A license whose term begins on or after 26 September 2026 pauses the Pro features
   when it expires. All settings and data are kept, and a new license resumes them
   at once.
 * If the license server cannot be reached, the last known license status stays 
   in force. A license that expires during such an outage keeps its Pro features
   for another 14 days, in case it has already been renewed.
 * If the license server has not been reachable for more than seven days, a notice
   on the plugin’s screens says so. Nothing is switched off.
 * A suspended or revoked license switches the Pro features off, whatever its model.
 * A license renewed on the same key keeps, once its new term has expired, the Pro
   features up to the Forge12 Security Pro version its earlier term covered.
 * A license is valid until the end of its last day, German time, as the license
   server counts it. Dates are judged by the license server’s clock, so a wrong 
   clock on the web server neither ends a license early nor keeps it running.
 * The license page says which of these applies.

## Meta

 *  Version **3.7.16**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 8.1 or higher **
 * Tags
 * [2FA](https://wordpress.org/plugins/tags/2fa/)[firewall](https://wordpress.org/plugins/tags/firewall/)
   [login security](https://wordpress.org/plugins/tags/login-security/)[malware scanner](https://wordpress.org/plugins/tags/malware-scanner/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/forge12-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/forge12-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/forge12-security/reviews/)

## Contributors

 *   [ Forge12 Interactive GmbH ](https://profiles.wordpress.org/forge12/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/forge12-security/)