Locktura Security

Description

Locktura Security provides modular security tools for WordPress protection, monitoring, maintenance, and alerts. Most protection runs locally. Enable only the modules you need and manage them from one dashboard.

Included in this plugin

  • Firewall – Attack filtering, cache-compatible protection modes, and diagnostics.
  • Brute Force Defense – Login limits, temporary bans, statistics, and unban controls.
  • Hardening – Configurable controls for common WordPress and server attack surfaces.
  • Update Manager – Update checks, installation, history, supported rollbacks, and extension cleanup.
  • Access Control – IP allowlists, blocklists, exclusions, automatic bans, and unban controls.
  • Geo Blocking – Country rules, trusted crawler verification, and geographic activity.
  • Hide Login – A custom login URL, default-route protection, and activity logging.
  • Anti-Spam Shield – Local CAPTCHA, form and comment protection, email and temporary IP blocking.
  • Usernames & 2FA – Username audits and suggestions, TOTP authentication, one-time recovery codes, and 2FA status.
  • Password Manager – Password policies, forced resets, risk scans, and optional breach checks.
  • Email Alerts – Notifications for important protection, account, update, file, and SSL events.
  • Security Logs – Local events with filters, charts, geographic context, IP actions, and export.
  • Live Traffic – Request details, visitor and bot classification, blocking data, filters, and geolocation.
  • User Log – Login, content, account, extension, settings, media, editor, and update activity.
  • File Scanner – File and configuration checks, integrity monitoring, backup, fixes, quarantine, and restore.
  • File Permissions – Permission and ownership checks, hosting guidance, safe fixes, exceptions, and history.
  • SSL Control – HTTPS, certificate and proxy checks, redirects, backup, and rollback.
  • Email Encoder – Email inventory, entity encoding, JavaScript obfuscation, coverage, and activity.

Hardening options

  • User Enumeration – Blocks author queries, guest user endpoints, author feeds, sitemap entries, and detailed login errors.
  • Disable Theme/Plugin Editor – Removes editor menus and blocks direct editor access.
  • Privilege Escalation – Detects related exploit and credential-access patterns in requests.
  • XML-RPC Shield – Blocks direct XML-RPC access, multicall brute force, user queries, and pingback abuse.
  • Secure wp-admin, wp-includes & wp-config.php – Protects sensitive WordPress and configuration paths.
  • Disable Directory Browsing – Prevents automatic directory listings.
  • Disable RSS Feeds – Disables public feeds and removes feed discovery links.
  • Prevent Image Hotlinking – Blocks unauthorized image embedding while supporting allowed sources.
  • Server Exposure Protection – Protects PHP uploads, environment files, debug logs, and configuration backups.

Managed server rules are applied on supported Apache and LiteSpeed installations. Other servers receive configuration guidance.

Separate Premium plugin

Locktura Premium is separately distributed outside WordPress.org and is not included in this package. Every Free feature above works without a license.

The separate Premium plugin adds:

  • Pattern Recognition – Signature detection, false-positive controls, activity, and signature management.
  • Behavior Analytics – Activity learning, risk scoring, thresholds, and verification.
  • Admin Lockdown – Access policies, schedules, trusted devices, verification, and recovery.
  • Virtual Patching – Temporary monitoring and blocking rules with scope and expiry.
  • Header Hardening – Security headers, browser policies, exposure controls, and previews.
  • API Guardian – REST, AJAX, endpoint, payload, request-limit, and JWT checks.
  • Neural Bot Suppressor – Bot detection, challenges, honeypots, crawler verification, and allowlists.
  • Network Reputation Control – Optional proxy, VPN, Tor, and hosting-network monitoring or blocking.
  • Malware Scanner & Cleanup – File and database scans, quarantine, cleanup, backup, and restore.
  • Smart 404 – Probe detection, thresholds, allowlists, temporary bans, activity, and unban controls.
  • Extra Hardening Tools – Table-prefix, security-salt, robots.txt, backup, and recovery tools.
  • Monthly Reports – Scheduled summaries, recipients, event details, and optional PDF reports.
  • Session Management – Session review, revocation, lifetime limits, and single-device controls.
  • Extra User Safety Tools – Administrator limits and automatic inactivity logout.
  • Premium Signature Pack – Maintained signatures, updates, inventory, cache rebuilding, and rollback.

Privacy

Locktura stores security data locally, including IP addresses, request and login details, usernames, events, alert settings, password-policy and 2FA settings (including hashed recovery codes), scan history, and update history. Optional geolocation and password-breach checks use the services below. Administrators control retention, recipients, lookups, and privacy settings.

External services

Locktura loads no scripts, styles, fonts, or images from third parties. It makes only the requests documented below when the related feature is enabled or used.

WordPress.org and extension update providers

Used for core, plugin, and theme update checks and downloads through WordPress.org and update endpoints declared by installed extensions. Requests occur during administrator-requested or scheduled checks and can contain the site URL, software versions, locale, and extension metadata. Update history is stored locally.

Documentation: https://developer.wordpress.org/apis/handbook/wordpress-org/update-api/
Policies: https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/ and https://wordpress.org/about/license/
Privacy: https://wordpress.org/about/privacy/

Have I Been Pwned Pwned Passwords

Used for optional breach checks through https://api.pwnedpasswords.com/range/{first5-sha1}. Only the first five characters of the password’s SHA-1 hash are sent, never the password or complete hash. Results can be cached locally, and stored status is discarded when the credential changes.

Documentation: https://haveibeenpwned.com/API/v3#PwnedPasswords
Terms: https://haveibeenpwned.com/TermsOfUse
Privacy: https://haveibeenpwned.com/Privacy

Geolocation providers

When enabled geolocation needs uncached data and no trusted country header exists, Locktura sends the public IP being looked up. Results can be cached locally for 24 hours. Providers are tried in this order:

  • Country (https://api.country.is/{ip}) – Primary provider. Service information and privacy: https://country.is/ | Source and self-hosting: https://github.com/lineofflight/country
  • IPWhois (https://ipwho.is/{ip}) – First fallback. Documentation: https://ipwhois.io/documentation | Terms: https://ipwhois.io/terms | Privacy: https://ipwhois.io/privacy
  • ipapi.co (https://ipapi.co/{ip}/json/) – Final fallback. Documentation: https://ipapi.co/api/ | Terms: https://ipapi.co/terms/ | Privacy: https://ipapi.co/privacy/

Own-site HTTPS and TLS checks

SSL Control checks the configured home_url() or site_url(). An administrator-requested HEAD request or TLS handshake sends ordinary network metadata and a Locktura user-agent to the site’s own host. No security log is transmitted.

Site-configured email delivery

Enabled alerts and tests can contain the recipient, site URL, event type, timestamp, IP address, relevant context, and remediation links. WordPress uses the site’s configured mail transport; Locktura selects no provider.

Locktura website links

Links to https://locktura.com/ open only after an administrator clicks them; there are no background calls.

Terms: https://locktura.com/terms-and-conditions/
Privacy: https://locktura.com/privacy-policy/

Translations

Dutch translations are managed through translate.wordpress.org and delivered by WordPress when an approved package is available.

Bundled assets

Runtime assets are bundled locally. Flag Icons and QRCode for JavaScript use the MIT License; Inter and Bebas Neue use the SIL Open Font License 1.1. The modified Wikimedia Commons world map is public domain. Source and license details are included under assets/. Locktura artwork is GPLv2 or later.

Screenshots

Installation

  1. Upload the locktura folder to /wp-content/plugins/, or install it through the WordPress Plugins screen.
  2. Activate Locktura Security and open the Locktura dashboard.
  3. Review the modules, enable the protections you need, and save changed settings.

FAQ

Is the firewall included?

Yes. Locktura Security includes the firewall with bundled community rules.

Do all listed Free features work without a license?

Yes. Every feature listed under Included in this plugin works without a license and has no time or usage restrictions. The separately distributed Premium plugin is not included in this package.

Do I need a cloud account?

No. Protection runs locally. Only the optional features documented under External services make network requests.

Does Locktura Security store security logs?

Yes. Security events are stored locally for administrator review.

Can IP addresses be anonymized?

Yes. An IP anonymization setting is available.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Locktura Security” is open source software. The following people have contributed to this plugin.

Contributors

“Locktura Security” has been translated into 1 locale. Thank you to the translators for their contributions.

Translate “Locktura Security” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

2.4.4

  • Improved Security Logs pagination and dashboard grid layout.
  • Fixed password-reset compatibility with Hide Login and improved Semantic Decode Shield event logging.
  • Improved Geo Blocking IP handling and regional controls, plus File Scanner status and detection accuracy.

2.4.3

  • Improved dashboard and Live Traffic reporting with more consistent aggregation and country details.
  • Improved password-strength checks and security-log timezone handling.
  • Confirmed compatibility with WordPress 7.1 and refreshed public documentation.

2.4.2

  • Improved user and 2FA management with filtering, pagination, role-aware guidance, and session controls.
  • Added hashed, one-time recovery codes for existing authenticator-app 2FA accounts.
  • Improved file-permission guidance and support for approved hosting-specific permissions.