Title: Trufend
Author: shewa
Published: <strong>September 20, 2026</strong>
Last modified: September 20, 2026

---

Search plugins

![](https://ps.w.org/trufend/assets/banner-772x250.png?rev=3703916)

![](https://ps.w.org/trufend/assets/icon.svg?rev=3703916)

# Trufend

 By [shewa](https://profiles.wordpress.org/shewa/)

[Download](https://downloads.wordpress.org/plugin/trufend.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/trufend/#description)
 * [Reviews](https://wordpress.org/plugins/trufend/#reviews)
 *  [Installation](https://wordpress.org/plugins/trufend/#installation)
 * [Development](https://wordpress.org/plugins/trufend/#developers)

 [Support](https://wordpress.org/support/plugin/trufend/)

## Description

Trufend helps you protect a WordPress site with practical security controls that
stay out of your way until you need them. Enable only the modules you want, review
activity from a single dashboard, and keep common attack paths closed.

#### Free features

 * **IP Lock** — Limit failed login attempts, block abusive IP addresses, and unblock
   them from the settings page.
 * **Login Security** — Hide login hints, optional custom login URL, and email-based
   two-factor authentication.
 * **Admin User Protection** — Enforce stronger administrator passwords and surface
   important account changes.
 * **Security Headers** — Send common HTTP security headers such as `X-Frame-Options`
   and `Referrer-Policy`.
 * **XML-RPC Protection** — Disable XML-RPC when it is not needed.
 * **User Enumeration Protection** — Block common author-scanning techniques.
 * **REST API Protection** — Restrict anonymous REST API access when configured.
 * **Comment Protection** — Add a lightweight honeypot to comment forms.
 * **User Activity Log** — Review recent security-related activity in the dashboard.
 * **Malware Scanner** — Scan individual files for suspicious PHP patterns.
 * **Backups** — Create manual database or site file backups in the background.
 * **File Permissions** — Browse file and folder permissions from the WordPress 
   admin.

#### External libraries

Trufend bundles the following library with its distribution:

 * [shewa/wp-job-queue](https://packagist.org/packages/shewa/wp-job-queue) — GPL-
   2.0-or-later — Background job processing for scans and backups.

## Screenshots

[⌊Security dashboard with module overview⌉⌊Security dashboard with module overview⌉[

Security dashboard with module overview

[⌊Module settings with enable toggle and options⌉⌊Module settings with enable toggle
and options⌉[

Module settings with enable toggle and options

[⌊File permissions browser⌉⌊File permissions browser⌉[

File permissions browser

[⌊Malware scanner results⌉⌊Malware scanner results⌉[

Malware scanner results

[⌊Backup manager⌉⌊Backup manager⌉[

Backup manager

[[

## Installation

 1. Upload the plugin files to `/wp-content/plugins/trufend`, or install the plugin
    through the WordPress Plugins screen.
 2. Activate the plugin through the **Plugins** screen in WordPress.
 3. Open **Trufend** in the admin menu to review the dashboard and enable the modules
    you need.

If you install from source, run `composer install --no-dev` in the plugin directory
before activation so bundled dependencies are available.

## FAQ

### Does this plugin phone home or collect analytics?

No. Trufend does not send site data to external services by default. Optional Pro
upgrade links can be changed with the `trufend_pro_upgrade_url` filter.

### Will uninstalling remove my data?

Yes. When you delete the plugin, Trufend removes its database tables, settings, 
scheduled events, and stored backup archives by default. Use the `trufend_uninstall_delete_backups`
filter if you want to keep backup files.

### Does the plugin modify wp-config.php?

Only when Pro is active and you enable the file editor protection toggle. Trufend
adds a managed `DISALLOW_FILE_EDIT` constant and removes it on uninstall when possible.

### Can I use this on multisite?

Yes. When network-activated, settings can be managed network-wide and per-site tables
are cleaned up on uninstall.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Trufend” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ shewa ](https://profiles.wordpress.org/shewa/)

[Translate “Trufend” into your language.](https://translate.wordpress.org/projects/wp-plugins/trufend)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/trufend/), check out
the [SVN repository](https://plugins.svn.wordpress.org/trufend/), or subscribe to
the [development log](https://plugins.trac.wordpress.org/log/trufend/) by [RSS](https://plugins.trac.wordpress.org/log/trufend/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release with core security modules.

## Meta

 *  Version **1.0.0**
 *  Last updated **3 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [backup](https://wordpress.org/plugins/tags/backup/)[firewall](https://wordpress.org/plugins/tags/firewall/)
   [login](https://wordpress.org/plugins/tags/login/)[malware](https://wordpress.org/plugins/tags/malware/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/trufend/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/trufend/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/trufend/reviews/)

## Contributors

 *   [ shewa ](https://profiles.wordpress.org/shewa/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/trufend/)