Title: NullState Security™
Author: SalesPC
Published: <strong>October 9, 2026</strong>
Last modified: October 9, 2026

---

Search plugins

![](https://ps.w.org/nullstate-security/assets/icon-256x256.png?rev=3737250)

# NullState Security™

 By [SalesPC](https://profiles.wordpress.org/salespc/)

[Download](https://downloads.wordpress.org/plugin/nullstate-security.3.4.7.zip)

 * [Details](https://wordpress.org/plugins/nullstate-security/#description)
 * [Reviews](https://wordpress.org/plugins/nullstate-security/#reviews)
 *  [Installation](https://wordpress.org/plugins/nullstate-security/#installation)
 * [Development](https://wordpress.org/plugins/nullstate-security/#developers)

 [Support](https://wordpress.org/support/plugin/nullstate-security/)

## Description

NullState Security™ is a free WordPress security plugin with modular hardening, 
threat interception, forensic logging, a live traffic monitor (90-day retention),
two-factor authentication (TOTP), and a vulnerability scanner.

Key free features:

 * **Core hardening** – disables XML-RPC, hides version leaks, protects the uploads
   directory
 * **Brute-force protection** – automatic IP lockout after repeated failed logins
 * **IP blacklist** – block attackers manually or from the Live Traffic feed, with
   CSV import/export
 * **Request filtering** – blocks directory traversal, SQL injection, XSS, eval()
   and other attack payloads
 * **User-Agent Bouncer** – blocks known malicious scanners and bots (e.g. Nuclei,
   sqlmap)
 * **Emergency lockdown** – temporarily disable non-admin logins and block the site
 * **Session terminator** – end all other sessions with one click
 * **Cache & temp purge** – clear caches and kill memory-resident shells
 * **Admin creation lockdown** – detect and delete rogue administrator accounts
 * **Uploads shield** – block script execution in the uploads directory
 * **Forensic logging** – every security event recorded with full request context
 * **Live traffic monitor (90-day)** – real-time view of every request, classified
   as human, bot, or attack, with country flags and one-click IP blocking
 * **Two-factor authentication** – TOTP-based 2FA (Google Authenticator, Authy, …)
   with backup codes
 * **Vulnerability scanner** – checks plugins, themes and core for known vulnerabilities(
   optional free WPScan API token for detailed data)
 * **Manual malware sweeps** – C2 trojan cleanup, JS dropshell removal, trojanized
   CSS stripping, fake dependency removal, transient drop-shell cleanup
 * **Security scorecard** – 0–100 score with actionable recommendations

For advanced security solutions, enterprise-grade protection, and expert support,

visit [nullstatesecurity.net](https://nullstatesecurity.net/).

### External Services

This plugin connects to the following external services:

 1. **WPScan API (wpscan.com)** – Optional
 2.  * Purpose: Vulnerability database queries
     * Data sent: Plugin/theme/core version information
     * When: During vulnerability scans (user-initiated)
     * Terms: https://wpscan.com/terms
     * Privacy: https://automattic.com/privacy/
 3. **AbuseIPDB (abuseipdb.com)** – Optional
 4.  * Purpose: IP reputation and threat scoring
     * Data sent: Visitor IP addresses
     * When: When viewing IP details in Live Traffic
     * Terms: https://www.abuseipdb.com/legal
     * Privacy: https://www.abuseipdb.com/privacy
 5. **ip-api.com**
 6.  * Purpose: Geolocation, ISP, and location data
     * Data sent: Visitor IP addresses
     * When: For country flags and IP lookup details
     * Terms: https://ip-api.com/terms
     * Privacy: https://ip-api.com/privacy
 7. **WordPress.org API**
 8.  * Purpose: Checking for outdated plugins/themes/core
     * Data sent: Installed version numbers
     * When: During vulnerability scans
     * Terms: https://wordpress.org/about/privacy/

## Installation

 1. Upload the `nullstate-security` folder to `/wp-content/plugins/`
 2. Activate the plugin
 3. Go to NullState Security™  Settings to configure
 4. Enable features you want to use

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“NullState Security™” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ SalesPC ](https://profiles.wordpress.org/salespc/)

[Translate “NullState Security™” into your language.](https://translate.wordpress.org/projects/wp-plugins/nullstate-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/nullstate-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/nullstate-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/nullstate-security/)
by [RSS](https://plugins.trac.wordpress.org/log/nullstate-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 3.4.6

 * All code prefixes renamed to the nullstatesecurity_ / NULLSTATESECURITY_ / nullstatesecurity-
   convention (options, transients, user meta, hooks, classes, constants, handles,
   slugs, nonces, CSS classes)
 * Automatic one-time migration on activation/update moves existing settings, transients,
   user meta and log files to the new prefix
 * $_SERVER request data sanitized (esc_url_raw / sanitize_text_field) before use
   and logging
 * Various sanitization and hardening fixes

#### 3.4.5

 * No license keys, license checks, tiers or registration API – plugin runs fully
   without any activation
 * All shipped features are available to every user; no feature gating or upgrade
   prompts
 * Live Traffic retention fixed at 90 days for all installations
 * Removed the License admin page and license tracker
 * Removed all premium-feature promotion from the admin UI and readme
 * External services documented (WPScan, AbuseIPDB, ip-api.com, WordPress.org API)
 * Storage consolidated under wp-content/uploads/nullstate-security/ with direct-
   access protection
 * Various sanitization and hardening fixes

#### 3.4.0

 * NEW: Two-Factor Authentication (TOTP) – added as a free feature
 * NEW: Vulnerability Scanner – checks plugins, themes, and core for known vulnerabilities(
   free)

#### 3.3.0

 * IMPROVED: IP blacklist enforcement now works on all requests (including admin)
 * FIX: Brute-force lockout now correctly auto-blocks IPs
 * FIX: CSV export/import now works as expected

#### 3.2.2

 * NEW: Country flags in Live Traffic – see the origin country of each visitor
 * NEW: IP Lookup Tool – view ISP, location, and threat score for any IP in the 
   Live Traffic details modal
 * NEW: Bulk IP Import/Export – import and export IP blacklists via CSV
 * FIX: Local/private IPs are now excluded from IP blacklist and Live Traffic
 * IMPROVED: Dashboard redesign with security scorecard, charts, and recommendations
 * IMPROVED: Dark mode toggle in admin bar
 * IMPROVED: First-run onboarding wizard
 * IMPROVED: Tooltips with documentation links throughout the UI
 * IMPROVED: Notification center with bell icon and unread badge

#### 3.0.0

 * Rebranded from WP Sentinel Guard to NullState Security™
 * All code prefixes migrated: classes/constants (WPSG_  NSS_), functions and hooks(
   wpsg_  nss_), text domain (wp-sentinel-guard  nullstate-security)
 * Main plugin file renamed to nullstate-security.php; admin module files renamed
   to class-nss-*.php
 * All storage migrated from wpsg_* to nss_*: options, transients, user meta keys,
   JSON data files and data directories
 * Automatic one-time migration on activation – existing settings, fingerprints,
   logs, backups and scan history are preserved
 * Admin menu pages and URLs updated to the new naming

#### 2.5.0

 * NEW: Live Traffic Monitor – real-time view of every request to your site
 * Auto-refresh every 5 seconds with pause/resume (AJAX polling)
 * Filter by IP, method, status, URL and user agent + pagination (50 per page)
 * Block IP directly from the traffic table (adds to the IP blacklist)
 * Request details modal (headers, referer, size, response time, user ID, AJAX/REST
   flags)
 * Storage in JSON file capped at 10,000 entries (oldest 10% trimmed)
 * Skips admin-ajax, admin-post, wp-cron and login pages by default (filterable)
 * Exclude IPs and user agents from logging
 * Response time + final HTTP status patched in on shutdown

#### 2.0.0-2.0.5

 * Complete admin dashboard rebuild with 5 subpages
 * New UI with Tailwind CSS (dark mode ready)
 * Scan page with “Run All Scans” button and progress bar
 * Logs page with date filter, pagination, and per-page dropdown
 * Settings page with toggles for XML-RPC, User-Agent Bouncer, Login Error Hiding
 * Brute-force threshold and lockout duration settings
 * Emergency lockdown toggle on dashboard
 * Automatic .htaccess deployment on plugin activation
 * IP whitelist and trusted proxies settings

#### 1.5.3

 * Added “Run All Scans” button with progress bar
 * Redesigned logs page with date filter and pagination
 * Added settings page with toggles and thresholds
 * Fixed performance issues (moved sweeps to manual)
 * Fixed IP spoofing vulnerability
 * Fixed double-encoding bypass
 * Fixed admin-ajax false positives
 * Added IP whitelist and trusted proxies

#### 1.0.0

 * Initial release
 * Core hardening (XML-RPC disable, version hiding, uploads protection)
 * Brute-force protection with IP lockout
 * Forensic logging with JSON format
 * Request filtering and malware signature detection
 * Rogue script blocking
 * Header evaluation shield
 * XOR/Hex payload defender
 * C2 interceptor and spoofing defender
 * User-agent bouncer
 * Session terminator
 * Emergency lockdown mode
 * Uploads execution shield
 * Cache and temp purge
 * Admin creation lockdown

## Meta

 *  Version **3.4.7**
 *  Last updated **19 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.0 or higher **
 *  Tested up to **7.1.3**
 * Tags
 * [firewall](https://wordpress.org/plugins/tags/firewall/)[malware](https://wordpress.org/plugins/tags/malware/)
   [scanner](https://wordpress.org/plugins/tags/scanner/)[security](https://wordpress.org/plugins/tags/security/)
   [two factor](https://wordpress.org/plugins/tags/two-factor/)
 *  [Advanced View](https://wordpress.org/plugins/nullstate-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/nullstate-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/nullstate-security/reviews/)

## Contributors

 *   [ SalesPC ](https://profiles.wordpress.org/salespc/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/nullstate-security/)