Description
NullState Security™ is a free WordPress security plugin with modular hardening, threat interception, forensic logging, a live traffic monitor (90-day retention), two-factor authentication (TOTP), and a vulnerability scanner.
Key free features:
- Core hardening – disables XML-RPC, hides version leaks, protects the uploads directory
- Brute-force protection – automatic IP lockout after repeated failed logins
- IP blacklist – block attackers manually or from the Live Traffic feed, with CSV import/export
- Request filtering – blocks directory traversal, SQL injection, XSS, eval() and other attack payloads
- User-Agent Bouncer – blocks known malicious scanners and bots (e.g. Nuclei, sqlmap)
- Emergency lockdown – temporarily disable non-admin logins and block the site
- Session terminator – end all other sessions with one click
- Cache & temp purge – clear caches and kill memory-resident shells
- Admin creation lockdown – detect and delete rogue administrator accounts
- Uploads shield – block script execution in the uploads directory
- Forensic logging – every security event recorded with full request context
- Live traffic monitor (90-day) – real-time view of every request, classified as human, bot, or attack, with country flags and one-click IP blocking
- Two-factor authentication – TOTP-based 2FA (Google Authenticator, Authy, …) with backup codes
- Vulnerability scanner – checks plugins, themes and core for known vulnerabilities (optional free WPScan API token for detailed data)
- Manual malware sweeps – C2 trojan cleanup, JS dropshell removal, trojanized CSS stripping, fake dependency removal, transient drop-shell cleanup
- Security scorecard – 0–100 score with actionable recommendations
For advanced security solutions, enterprise-grade protection, and expert support,
visit nullstatesecurity.net.
External Services
This plugin connects to the following external services:
-
WPScan API (wpscan.com) – Optional
- Purpose: Vulnerability database queries
- Data sent: Plugin/theme/core version information
- When: During vulnerability scans (user-initiated)
- Terms: https://wpscan.com/terms
- Privacy: https://automattic.com/privacy/
-
AbuseIPDB (abuseipdb.com) – Optional
- Purpose: IP reputation and threat scoring
- Data sent: Visitor IP addresses
- When: When viewing IP details in Live Traffic
- Terms: https://www.abuseipdb.com/legal
- Privacy: https://www.abuseipdb.com/privacy
-
ip-api.com
- Purpose: Geolocation, ISP, and location data
- Data sent: Visitor IP addresses
- When: For country flags and IP lookup details
- Terms: https://ip-api.com/terms
- Privacy: https://ip-api.com/privacy
-
WordPress.org API
- Purpose: Checking for outdated plugins/themes/core
- Data sent: Installed version numbers
- When: During vulnerability scans
- Terms: https://wordpress.org/about/privacy/
Installation
- Upload the
nullstate-securityfolder to/wp-content/plugins/ - Activate the plugin
- Go to NullState Security™ Settings to configure
- Enable features you want to use
Reviews
There are no reviews for this plugin.
Contributors & Developers
“NullState Security™” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “NullState Security™” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
3.4.6
- All code prefixes renamed to the nullstatesecurity_ / NULLSTATESECURITY_ / nullstatesecurity- convention (options, transients, user meta, hooks, classes, constants, handles, slugs, nonces, CSS classes)
- Automatic one-time migration on activation/update moves existing settings, transients, user meta and log files to the new prefix
- $_SERVER request data sanitized (esc_url_raw / sanitize_text_field) before use and logging
- Various sanitization and hardening fixes
3.4.5
- No license keys, license checks, tiers or registration API – plugin runs fully without any activation
- All shipped features are available to every user; no feature gating or upgrade prompts
- Live Traffic retention fixed at 90 days for all installations
- Removed the License admin page and license tracker
- Removed all premium-feature promotion from the admin UI and readme
- External services documented (WPScan, AbuseIPDB, ip-api.com, WordPress.org API)
- Storage consolidated under wp-content/uploads/nullstate-security/ with direct-access protection
- Various sanitization and hardening fixes
3.4.0
- NEW: Two-Factor Authentication (TOTP) – added as a free feature
- NEW: Vulnerability Scanner – checks plugins, themes, and core for known vulnerabilities (free)
3.3.0
- IMPROVED: IP blacklist enforcement now works on all requests (including admin)
- FIX: Brute-force lockout now correctly auto-blocks IPs
- FIX: CSV export/import now works as expected
3.2.2
- NEW: Country flags in Live Traffic – see the origin country of each visitor
- NEW: IP Lookup Tool – view ISP, location, and threat score for any IP in the Live Traffic details modal
- NEW: Bulk IP Import/Export – import and export IP blacklists via CSV
- FIX: Local/private IPs are now excluded from IP blacklist and Live Traffic
- IMPROVED: Dashboard redesign with security scorecard, charts, and recommendations
- IMPROVED: Dark mode toggle in admin bar
- IMPROVED: First-run onboarding wizard
- IMPROVED: Tooltips with documentation links throughout the UI
- IMPROVED: Notification center with bell icon and unread badge
3.0.0
- Rebranded from WP Sentinel Guard to NullState Security™
- All code prefixes migrated: classes/constants (WPSG_ NSS_), functions and hooks (wpsg_ nss_), text domain (wp-sentinel-guard nullstate-security)
- Main plugin file renamed to nullstate-security.php; admin module files renamed to class-nss-*.php
- All storage migrated from wpsg_* to nss_*: options, transients, user meta keys, JSON data files and data directories
- Automatic one-time migration on activation – existing settings, fingerprints, logs, backups and scan history are preserved
- Admin menu pages and URLs updated to the new naming
2.5.0
- NEW: Live Traffic Monitor – real-time view of every request to your site
- Auto-refresh every 5 seconds with pause/resume (AJAX polling)
- Filter by IP, method, status, URL and user agent + pagination (50 per page)
- Block IP directly from the traffic table (adds to the IP blacklist)
- Request details modal (headers, referer, size, response time, user ID, AJAX/REST flags)
- Storage in JSON file capped at 10,000 entries (oldest 10% trimmed)
- Skips admin-ajax, admin-post, wp-cron and login pages by default (filterable)
- Exclude IPs and user agents from logging
- Response time + final HTTP status patched in on shutdown
2.0.0-2.0.5
- Complete admin dashboard rebuild with 5 subpages
- New UI with Tailwind CSS (dark mode ready)
- Scan page with “Run All Scans” button and progress bar
- Logs page with date filter, pagination, and per-page dropdown
- Settings page with toggles for XML-RPC, User-Agent Bouncer, Login Error Hiding
- Brute-force threshold and lockout duration settings
- Emergency lockdown toggle on dashboard
- Automatic .htaccess deployment on plugin activation
- IP whitelist and trusted proxies settings
1.5.3
- Added “Run All Scans” button with progress bar
- Redesigned logs page with date filter and pagination
- Added settings page with toggles and thresholds
- Fixed performance issues (moved sweeps to manual)
- Fixed IP spoofing vulnerability
- Fixed double-encoding bypass
- Fixed admin-ajax false positives
- Added IP whitelist and trusted proxies
1.0.0
- Initial release
- Core hardening (XML-RPC disable, version hiding, uploads protection)
- Brute-force protection with IP lockout
- Forensic logging with JSON format
- Request filtering and malware signature detection
- Rogue script blocking
- Header evaluation shield
- XOR/Hex payload defender
- C2 interceptor and spoofing defender
- User-agent bouncer
- Session terminator
- Emergency lockdown mode
- Uploads execution shield
- Cache and temp purge
- Admin creation lockdown