{"id":308922,"date":"2026-09-29T19:36:50","date_gmt":"2026-09-29T19:36:50","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ux3-security\/"},"modified":"2026-09-29T22:09:42","modified_gmt":"2026-09-29T22:09:42","slug":"ux3-security","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ux3-security\/","author":23493836,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.2","requires":"5.0","requires_php":"7.4","requires_plugins":null,"header_name":"UX3 Security","header_author":"UX3 Security","header_description":"Cloud-managed firewall, bot protection, and threat monitoring for WordPress. Protect your site from SQL injection, XSS, malicious bots, spam, and more \u2014 managed centrally from the UX3 Security dashboard.","assets_banners_color":"215150","last_updated":"2026-09-29 22:09:42","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/central.ux3security.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":62,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"ux3security","date":"2026-09-29 22:09:42","revision":3719923}},"upgrade_notice":{"1.0.0":"<p>First release \u2014 install and configure your API credentials to enable protection.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3719907,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3719907,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3719907,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":550},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3719907,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3719917,"resolution":"1","location":"assets","locale":"","width":1919,"height":943},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3719917,"resolution":"2","location":"assets","locale":"","width":1903,"height":769},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3719917,"resolution":"3","location":"assets","locale":"","width":1902,"height":938},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3719917,"resolution":"4","location":"assets","locale":"","width":1903,"height":940},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3719917,"resolution":"5","location":"assets","locale":"","width":1900,"height":909},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3719917,"resolution":"6","location":"assets","locale":"","width":1899,"height":936},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3719917,"resolution":"7","location":"assets","locale":"","width":1907,"height":913},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3719917,"resolution":"8","location":"assets","locale":"","width":1906,"height":934}},"screenshots":{"1":"Secure sign-in \u2014 access your UX3 Security dashboard with multi-site management and 24\/7 monitoring built in.","2":"Admin Dashboard \u2014 see every protected site at a glance: total sites, live connection state, disk, database and platform storage in one view.","3":"Site Overview \u2014 real numbers for each site: visitors, unique visits, bots, proxies, blocked requests, spam and SQL-injection attempts, plus full server info.","4":"Traffic snapshot \u2014 live traffic chart, threats by country, and device \/ browser \/ OS breakdowns, with one-click access to bots, threats, protection and whitelist.","5":"Live Traffic \u2014 active visitors right now, humans vs bots, blocked attempts, hourly trend, top pages and top countries in real time.","6":"Visitors by Country \u2014 see where your legitimate traffic comes from on an interactive world map, ranked by share.","7":"Traffic Graph \u2014 humans vs bots over any date range, so you can spot attack spikes and traffic patterns instantly.","8":"Threats by Country \u2014 an interactive threat-origins map with a ranked list of every country attacking your site, updated live."}},"plugin_section":[],"plugin_tags":[2359,1174,600,599,18199],"plugin_category":[54],"plugin_contributors":[283479],"plugin_business_model":[],"class_list":["post-308922","plugin","type-plugin","status-publish","hentry","plugin_tags-bot","plugin_tags-firewall","plugin_tags-security","plugin_tags-spam","plugin_tags-waf","plugin_category-security-and-spam-protection","plugin_contributors-ux3security","plugin_committers-ux3security"],"banners":{"banner":"https:\/\/ps.w.org\/ux3-security\/assets\/banner-772x250.png?rev=3719907","banner_2x":"https:\/\/ps.w.org\/ux3-security\/assets\/banner-1544x500.png?rev=3719907","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ux3-security\/assets\/icon-128x128.png?rev=3719907","icon_2x":"https:\/\/ps.w.org\/ux3-security\/assets\/icon-256x256.png?rev=3719907","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ux3-security\/assets\/screenshot-1.png?rev=3719917","caption":"Secure sign-in \u2014 access your UX3 Security dashboard with multi-site management and 24\/7 monitoring built in."},{"src":"https:\/\/ps.w.org\/ux3-security\/assets\/screenshot-2.png?rev=3719917","caption":"Admin Dashboard \u2014 see every protected site at a glance: total sites, live connection state, disk, database and platform storage in one view."},{"src":"https:\/\/ps.w.org\/ux3-security\/assets\/screenshot-3.png?rev=3719917","caption":"Site Overview \u2014 real numbers for each site: visitors, unique visits, bots, proxies, blocked requests, spam and SQL-injection attempts, plus full server info."},{"src":"https:\/\/ps.w.org\/ux3-security\/assets\/screenshot-4.png?rev=3719917","caption":"Traffic snapshot \u2014 live traffic chart, threats by country, and device \/ browser \/ OS breakdowns, with one-click access to bots, threats, protection and whitelist."},{"src":"https:\/\/ps.w.org\/ux3-security\/assets\/screenshot-5.png?rev=3719917","caption":"Live Traffic \u2014 active visitors right now, humans vs bots, blocked attempts, hourly trend, top pages and top countries in real time."},{"src":"https:\/\/ps.w.org\/ux3-security\/assets\/screenshot-6.png?rev=3719917","caption":"Visitors by Country \u2014 see where your legitimate traffic comes from on an interactive world map, ranked by share."},{"src":"https:\/\/ps.w.org\/ux3-security\/assets\/screenshot-7.png?rev=3719917","caption":"Traffic Graph \u2014 humans vs bots over any date range, so you can spot attack spikes and traffic patterns instantly."},{"src":"https:\/\/ps.w.org\/ux3-security\/assets\/screenshot-8.png?rev=3719917","caption":"Threats by Country \u2014 an interactive threat-origins map with a ranked list of every country attacking your site, updated live."}],"raw_content":"<!--section=description-->\n<p><strong>UX3 Security<\/strong> connects your WordPress site to the UX3 Security cloud dashboard for centralized firewall management. Block SQL injection attempts, XSS attacks, malicious bots, spam submissions, and more \u2014 with rules managed from a single place across all your sites.<\/p>\n\n<h4>Key features<\/h4>\n\n<ul>\n<li><strong>Web Application Firewall<\/strong> \u2014 blocks SQLi, XSS, and other common attack patterns<\/li>\n<li><strong>Bot protection<\/strong> \u2014 detects and blocks bad bots, fake search-engine crawlers, anonymous bot traffic<\/li>\n<li><strong>Spam protection<\/strong> \u2014 honeypot + content-based detection for forms<\/li>\n<li><strong>Word filter<\/strong> \u2014 block requests matching custom keyword lists<\/li>\n<li><strong>Geo-blocking<\/strong> \u2014 block traffic from specific countries<\/li>\n<li><strong>Rate limiting<\/strong> \u2014 prevents brute-force and scraping<\/li>\n<li><strong>Smart filter<\/strong> \u2014 one-click allow-list for false positives<\/li>\n<li><strong>Centralized dashboard<\/strong> \u2014 all your sites in one place at central.ux3security.com<\/li>\n<li><strong>Real-time alerts<\/strong> \u2014 email notifications for attacks, disconnections, disk warnings, etc.<\/li>\n<\/ul>\n\n<h4>How it works<\/h4>\n\n<ol>\n<li>Sign up at <a href=\"https:\/\/central.ux3security.com\/\">central.ux3security.com<\/a> and add your site<\/li>\n<li>Copy the API URL and token from your dashboard<\/li>\n<li>Install this plugin and paste them into Settings \u2192 UX3 Security<\/li>\n<li>Enable protection \u2014 done. Manage rules from the dashboard.<\/li>\n<\/ol>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to two external services in order to function. Each is described below in line with WordPress.org's third-party service disclosure guideline.<\/p>\n\n<h4>1. UX3 Security API<\/h4>\n\n<p>What it is and what it is used for: The cloud dashboard at central.ux3security.com is the central management plane for the plugin. It distributes firewall rules to the agent, receives logs of blocked attacks, and tracks site connection status.<\/p>\n\n<p>When and what data is sent:<\/p>\n\n<ul>\n<li>On every blocked request: visitor IP, country (resolved server-side), request URL and method, user-agent, attack type that triggered the block, timestamp.<\/li>\n<li>On every approximately 5 minutes: a rules-version check (lightweight) and an agent heartbeat with site identifier.<\/li>\n<li>On every approximately 60 minutes: server diagnostics (PHP version, server software, OS, disk usage, OpenSSL version, cURL version, memory peak, platform\/install-method detection).<\/li>\n<\/ul>\n\n<p>What is NOT sent: post or page content, user names, passwords, email addresses, database content, file content.<\/p>\n\n<p>Service URL: the URL you configure in Settings -&gt; UX3 Security (typically https:\/\/central.ux3security.com\/api\/v1).\nProvider: UX3 Security.\nTerms of service: https:\/\/central.ux3security.com\/terms\nPrivacy policy: https:\/\/central.ux3security.com\/privacy<\/p>\n\n<h4>2. ip-api.com<\/h4>\n\n<p>What it is and what it is used for: ip-api.com is a third-party IP geolocation service. The plugin queries it to resolve the country, city, ISP, and approximate latitude\/longitude of visitor IPs. Geo data is used for country-based blocking rules, the geographic view of attack traffic on the dashboard, and proxy\/hosting detection.<\/p>\n\n<p>When and what data is sent: only the visitor's IP address, when a request hits the firewall and the IP has not been resolved within the last 24 hours. The IP is the only piece of data transmitted in the request URL. ip-api.com does not receive any other request details, headers, or content.<\/p>\n\n<p>Service URL: http:\/\/ip-api.com\/json\/{ip} (free tier: 45 requests per minute, no API key required).\nProvider: ip-api.com.\nTerms of service: https:\/\/members.ip-api.com\/legal\nPrivacy policy: https:\/\/ip-api.com\/docs\/legal<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/ux3-security\/<\/code>, or install via the Plugins screen in WordPress<\/li>\n<li>Activate the plugin through the 'Plugins' screen<\/li>\n<li>Visit Settings \u2192 UX3 Security<\/li>\n<li><strong>Review the Data Processing Consent section<\/strong> \u2014 this explains exactly what data the plugin sends to the UX3 Security API and to ip-api.com. Tick the consent checkbox only if you agree.<\/li>\n<li>Paste your API URL and API Token (from your UX3 Security dashboard)<\/li>\n<li>Tick \"Enable UX3 Security protection\" and Save<\/li>\n<\/ol>\n\n<p>The plugin ships with protection <strong>disabled by default<\/strong> and will not send any data to external services until you have both given consent and enabled protection.<\/p>\n\n<p>For maximum protection on supported hosts, you can additionally configure <code>auto_prepend_file<\/code> in your php.ini \u2014 see the Settings page for the exact directive.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20account%20on%20central.ux3security.com%3F\"><h3>Do I need an account on central.ux3security.com?<\/h3><\/dt>\n<dd><p>Yes. The plugin is the agent \u2014 it works in conjunction with the central dashboard where you create accounts, add sites, and configure rules.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20my%20site%20can%27t%20reach%20the%20api%3F\"><h3>What happens if my site can't reach the API?<\/h3><\/dt>\n<dd><p>The agent caches firewall rules locally for 5 minutes. If the API is unreachable, it continues using the cached rules \u2014 your site stays protected even during brief network blips. After cache expiry, the agent skips silently rather than break your site.<\/p><\/dd>\n<dt id=\"will%20this%20plugin%20slow%20down%20my%20site%3F\"><h3>Will this plugin slow down my site?<\/h3><\/dt>\n<dd><p>The agent is highly optimized \u2014 typical overhead is 1-3ms per request. Rules are cached on disk so most requests don't even need a database lookup.<\/p><\/dd>\n<dt id=\"can%20i%20temporarily%20disable%20protection%3F\"><h3>Can I temporarily disable protection?<\/h3><\/dt>\n<dd><p>Yes \u2014 uncheck \"Enable UX3 Security protection\" on the settings page. No need to deactivate the plugin.<\/p><\/dd>\n<dt id=\"how%20do%20i%20withdraw%20consent%3F\"><h3>How do I withdraw consent?<\/h3><\/dt>\n<dd><p>Uncheck the consent checkbox on Settings \u2192 UX3 Security and save. The agent stops making outbound requests immediately.<\/p><\/dd>\n<dt id=\"how%20does%20the%20plugin%20display%20warning%20pages%20when%20a%20request%20is%20blocked%3F\"><h3>How does the plugin display warning pages when a request is blocked?<\/h3><\/dt>\n<dd><p>Blocked visitors see a warning page served in an iframe from central.ux3security.com. The plugin does not cache warning-page HTML in your WordPress database or filesystem \u2014 the styled page is served live from Central each time.<\/p><\/dd>\n<dt id=\"where%20are%20my%20settings%20stored%3F\"><h3>Where are my settings stored?<\/h3><\/dt>\n<dd><p>In the WordPress options table \u2014 same place as other plugin settings. They're cleaned up automatically if you delete (not just deactivate) the plugin.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>WordPress wrapper for the UX3 Security agent (v1.1.0)<\/li>\n<li>Settings page for API URL \/ token \/ enable toggle<\/li>\n<li>Auto-detect existing auto_prepend_file config and recommend if not set<\/li>\n<li>Reports install_method = 'wp_plugin' to the dashboard<\/li>\n<\/ul>","raw_excerpt":"Cloud-managed firewall, bot protection, and threat monitoring. Manage rules, bans, and allow-lists from a central dashboard.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/308922","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=308922"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ux3security"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=308922"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=308922"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=308922"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=308922"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=308922"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=308922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}