Title: Web Plura Security Center
Author: Web Plura
Published: <strong>August 28, 2026</strong>
Last modified: August 28, 2026

---

Search plugins

![](https://ps.w.org/web-plura-security-center/assets/banner-772x250.png?rev=3669857)

![](https://ps.w.org/web-plura-security-center/assets/icon-256x256.png?rev=3669857)

# Web Plura Security Center

 By [Web Plura](https://profiles.wordpress.org/wplura/)

[Download](https://downloads.wordpress.org/plugin/web-plura-security-center.0.1.10.zip)

 * [Details](https://wordpress.org/plugins/web-plura-security-center/#description)
 * [Reviews](https://wordpress.org/plugins/web-plura-security-center/#reviews)
 *  [Installation](https://wordpress.org/plugins/web-plura-security-center/#installation)
 * [Development](https://wordpress.org/plugins/web-plura-security-center/#developers)

 [Support](https://wordpress.org/support/plugin/web-plura-security-center/)

## Description

Web Plura Security Center helps site owners and operations teams detect, track, 
and fix security issues.

Product page: https://wplura.com/products/web-plura-security-center
 Terms: https://
wplura.com/terms Privacy: https://wplura.com/privacy Support: https://wplura.com/
support More: https://wplura.com/about, https://wplura.com/contact, https://wplura.
com/security, https://wplura.com/docs, https://wplura.com/legal, https://wplura.
com/cookie-policy, https://wplura.com/acceptable-use, https://wplura.com/data-processing-
addendum, https://wplura.com/service-level-agreement

### Optional Web Plura Services

The WordPress.org package is fully functional for local security checks, login protection,
firewall controls, incident visibility, reports, admin guidance, privacy tools, 
and plugin-owned data controls. Separately installed or hosted Web Plura services
may offer account-backed support, hosted security operations, or cross-site workflows,
but they are not required for the local features included here.

Core capabilities:

 * Local security scans for suspicious files, malware indicators, and risky configuration.
 * Local setup templates, score checklist, and bounded file-change baseline summaries.
 * Local Form Abuse & Lead Security advisor for form plugins, lead pages, SMTP, 
   privacy page, updates, and risky form markers.
 * Local Admin/User Risk & File Integrity advisor for administrator drift, registration
   role exposure, permissions, upload executables, debug logs, public archives, 
   and recent component changes.
 * Firewall rules with rate limiting and temporary blocking controls.
 * Incident tracking, audit visibility, and email notification support in wp-admin.

Local advisors read only the WordPress data and bounded filesystem markers needed
for their checks. They do not submit forms, collect lead content, change users or
files, send telemetry, upload baseline history, or require Web Plura Cloud.

### External Services

This free plugin does not connect to Web Plura Cloud. It may contact these third-
party services only when an administrator enables the related local feature:

Administrator consent is required before optional CAPTCHA checks or checksum verification
checks use those external services.

 * WordPress.org Plugin Checksums API: https://api.wordpress.org/plugins/checksums/
   1.0/
    - Purpose: verifies installed plugin files against WordPress.org checksums when
      an administrator runs checksum verification.
    - Data sent: plugin slug and version identifiers needed for checksum lookup.
    - Runs: only when checksum verification checks are run.
    - Terms: https://wordpress.org/about/terms/
    - Privacy: https://wordpress.org/about/privacy/
 * Cloudflare Turnstile: https://challenges.cloudflare.com
    - Purpose: loads the selected Turnstile challenge and verifies CAPTCHA responses
      when an administrator enables Cloudflare Turnstile for login protection.
    - Data sent: browser request metadata needed to load the challenge, the CAPTCHA
      verification token, and the requester IP address during verification.
    - Runs: only on configured login surfaces after the administrator enables Turnstile
      and saves Cloudflare keys.
    - Terms: https://www.cloudflare.com/website-terms/
    - Privacy: https://www.cloudflare.com/privacypolicy/
    - Turnstile Privacy Addendum: https://www.cloudflare.com/turnstile-privacy-policy/
 * hCaptcha: https://js.hcaptcha.com and https://hcaptcha.com
    - Purpose: loads the selected hCaptcha challenge and verifies CAPTCHA responses
      when an administrator enables hCaptcha for login protection.
    - Data sent: browser request metadata needed to load the challenge, the CAPTCHA
      verification token, and the requester IP address during verification.
    - Runs: only on configured login surfaces after the administrator enables hCaptcha
      and saves hCaptcha keys.
    - Terms: https://www.hcaptcha.com/terms
    - Privacy: https://www.hcaptcha.com/privacy
 * Google reCAPTCHA: https://www.google.com/recaptcha/
    - Purpose: loads the selected reCAPTCHA challenge and verifies CAPTCHA responses
      when an administrator enables Google reCAPTCHA for login protection.
    - Data sent: browser request metadata needed to load the challenge, the CAPTCHA
      verification token, and the requester IP address during verification.
    - Runs: only on configured login surfaces after the administrator enables reCAPTCHA
      and saves Google reCAPTCHA keys.
    - Terms: https://policies.google.com/terms
    - Privacy: https://policies.google.com/privacy

Suspicious file samples, form-advisor data, admin/user risk data, file baseline 
history, and setup checklist data are not uploaded by the free plugin.

No third-party executable PHP/JS code is loaded except the administrator-enabled
CAPTCHA provider scripts documented above. Plugin/theme updates are not served by
this plugin from non-WordPress.org update channels.

Some payment, social, CDN, or static-hosting domains may appear in local scanner
signature allowlists so the plugin can avoid false positives while reviewing site
files. Those strings are detection references only. The free plugin does not enqueue
or execute Stripe, Facebook, jsDelivr, or gstatic assets.

## Screenshots

[⌊Security Dashboard overview with local protection and scan status.⌉⌊Security Dashboard
overview with local protection and scan status.⌉[

Security Dashboard overview with local protection and scan status.

[⌊Security Center page with local setup templates, score checklist, and bounded 
file-change baseline summaries.⌉⌊Security Center page with local setup templates,
score checklist, and bounded file-change baseline summaries.⌉[

Security Center page with local setup templates, score checklist, and bounded file-
change baseline summaries.

[⌊Security Check page for quick and full local scans.⌉⌊Security Check page for quick
and full local scans.⌉[

Security Check page for quick and full local scans.

[⌊Form Abuse & Lead Security page for local lead capture exposure checks.⌉⌊Form 
Abuse & Lead Security page for local lead capture exposure checks.⌉[

Form Abuse & Lead Security page for local lead capture exposure checks.

[⌊Threat Alerts page listing suspicious findings and remediation context.⌉⌊Threat
Alerts page listing suspicious findings and remediation context.⌉[

Threat Alerts page listing suspicious findings and remediation context.

[⌊Firewall controls for local request protection settings.⌉⌊Firewall controls for
local request protection settings.⌉[

Firewall controls for local request protection settings.

[⌊User Profile Login Security controls for 2FA enrollment, passkeys, backup codes,
and login availability notices.⌉⌊User Profile Login Security controls for 2FA enrollment,
passkeys, backup codes, and login availability notices.⌉[

User Profile Login Security controls for 2FA enrollment, passkeys, backup codes,
and login availability notices.

[⌊Settings page for local protection modules, notifications, SMTP delivery, and 
privacy/data boundary status.⌉⌊Settings page for local protection modules, notifications,
SMTP delivery, and privacy/data boundary status.⌉[

Settings page for local protection modules, notifications, SMTP delivery, and privacy/
data boundary status.

## Installation

 1. Upload the `web-plura-security-center` folder to `/wp-content/plugins/` (or install
    via ZIP in wp-admin).
 2. Activate the plugin through the `Plugins` screen in WordPress.
 3. Open `Web Plura Security Center` in wp-admin.
 4. Run an initial local scan from the security dashboard.

## FAQ

### Do I need a cloud account?

No. Free local security checks and core admin workflows work without a cloud account.

### What data is sent to the cloud?

None. The free plugin does not send site security data to Web Plura Cloud.

### Does Form Abuse & Lead Security send lead data anywhere?

No. It checks installed plugins, published page markers, SMTP signals, update metadata,
and privacy policy configuration locally.

### Does Admin/User Risk & File Integrity change my site?

No. It is read-only and does not change users, roles, files, or baseline approvals.

### Are local file baseline details uploaded?

No. File-change baseline summaries are stored locally with bounded retention.

### Are suspicious files uploaded automatically?

No. Suspicious file sample upload is not part of the free plugin.

### Does this plugin collect personal data by default?

The free plugin does not send site security data to Web Plura Cloud by default.

### Does this plugin support WordPress Privacy Tools exports/erasures?

Yes. The plugin registers WordPress Privacy Tools exporter and eraser callbacks 
so administrators can process personal data requests for plugin-owned security metadata.

### Can I remove all plugin data on uninstall?

Yes. Uninstall removes plugin options, scheduled hooks, and plugin custom database
tables.

### Where can I get support or contact your team?

 * Support: https://wplura.com/support
 * Contact Us: https://wplura.com/contact
 * Security Disclosure: https://wplura.com/security

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Web Plura Security Center” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Web Plura ](https://profiles.wordpress.org/wplura/)

[Translate “Web Plura Security Center” into your language.](https://translate.wordpress.org/projects/wp-plugins/web-plura-security-center)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/web-plura-security-center/),
check out the [SVN repository](https://plugins.svn.wordpress.org/web-plura-security-center/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/web-plura-security-center/)
by [RSS](https://plugins.trac.wordpress.org/log/web-plura-security-center/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.1.10

 * Improved WordPress.org compliance for paths, nonces, input sanitization, escaping,
   local scripts, and remote asset disclosures.

#### 0.1.9

 * Removed product-local Cloud connection, entitlement, dashboard, remote scan, 
   policy sync, and signed transport workflows from the WordPress.org package.
 * Kept local fixes, emergency review controls, firewall controls, login protection,
   and integrity checks available without Pro, Cloud, subscription, or entitlement
   checks.

#### 0.1.8

Kept Free issue fixes, remediation-plan execution, and emergency action controls
independent from Web Plura Cloud, Pro, subscription, and entitlement checks.

#### 0.1.7

Renamed the public display title, added local-only integrity baselines, tightened
nonce/passkey handling, expanded external-service disclosure, downgraded unsafe 
filesystem cleanup to manual guidance, and removed unused public key files.

#### 0.1.6

Improved external-service consent wording, Upgrade page presentation, and dormant
cloud-service wording.

#### 0.1.5

Added a Free-owned local scan evidence resolver so Free and Pro share canonical 
scanner report, summary, timestamp, and score fallback behavior.

#### 0.1.4

Added a Free-owned reports extension surface.

#### 0.1.3

Formalized the dashboard capability panel slot as a reversible Free-owned extension
surface for Security Center Pro.

#### 0.1.1

Added stable admin extension slots while keeping free features local-only.

#### 0.1.0

Initial public release with local scans, login protection, firewall controls, setup
guidance, advisor checks, privacy tooling, and bounded local data handling.

## Meta

 *  Version **0.1.10**
 *  Last updated **3 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.8 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 8.1 or higher **
 * Tags
 * [firewall](https://wordpress.org/plugins/tags/firewall/)[malware](https://wordpress.org/plugins/tags/malware/)
   [monitoring](https://wordpress.org/plugins/tags/monitoring/)[scanner](https://wordpress.org/plugins/tags/scanner/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/web-plura-security-center/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/web-plura-security-center/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/web-plura-security-center/reviews/)

## Contributors

 *   [ Web Plura ](https://profiles.wordpress.org/wplura/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/web-plura-security-center/)