{"id":313440,"date":"2026-07-21T08:44:49","date_gmt":"2026-07-21T08:44:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/securyn\/"},"modified":"2026-07-21T08:54:03","modified_gmt":"2026-07-21T08:54:03","slug":"securyn","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/securyn\/","author":9259846,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.0.2","requires":"6.8","requires_php":"7.4","requires_plugins":null,"header_name":"Securyn","header_author":"WisdmLabs","header_description":"AI-native WordPress security operations platform.","assets_banners_color":"0b182d","last_updated":"2026-07-21 08:54:03","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/securyn.wisdmlabs.net\/","header_author_uri":"https:\/\/wisdmlabs.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":51,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"WisdmLabs","date":"2026-07-21 08:54:03"}},"upgrade_notice":{"1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3616719,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3616719,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3616719,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3616719,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3616719,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner.svg":{"filename":"banner.svg","revision":3616719,"resolution":false,"location":"assets","locale":false}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3616719,"resolution":"1","location":"assets","locale":"","width":1852,"height":994},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3616719,"resolution":"2","location":"assets","locale":"","width":1852,"height":994},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3616719,"resolution":"3","location":"assets","locale":"","width":1852,"height":994},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3616719,"resolution":"4","location":"assets","locale":"","width":1852,"height":994},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3616719,"resolution":"5","location":"assets","locale":"","width":1852,"height":994},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3616719,"resolution":"6","location":"assets","locale":"","width":1852,"height":994},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3616719,"resolution":"7","location":"assets","locale":"","width":1852,"height":994},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3616719,"resolution":"8","location":"assets","locale":"","width":1852,"height":994}},"screenshots":{"1":"Unified security dashboard \u2014 posture score, per-module status, live protection, and a prioritized action queue.","2":"Runtime firewall in block mode \u2014 blocked attacks grouped by rule, each with a plain-language \"why blocked\" explanation.","3":"Hardening audit \u2014 posture across configuration surfaces with AI-prioritized, step-by-step remediation guidance.","4":"Identity &amp; access \u2014 privilege-drift detection, account posture (MFA, dormant admins), and live sessions and blocked IPs.","5":"File and code integrity \u2014 triage of integrity findings, including AI-analyzed malware-signature detection.","6":"Vulnerability scanner \u2014 installed plugins matched against the CVE feed, grouped per plugin with fix guidance.","7":"Findings \u2014 every finding across modules in one place, filterable by severity and module, with AI analysis.","8":"Audit log \u2014 tamper-evident activity trail of security-relevant events with user and IP attribution."}},"plugin_section":[],"plugin_tags":[2353,1174,1184,600,6460],"plugin_category":[54],"plugin_contributors":[79685],"plugin_business_model":[],"class_list":["post-313440","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-firewall","plugin_tags-malware","plugin_tags-security","plugin_tags-vulnerability","plugin_category-security-and-spam-protection","plugin_contributors-wisdmlabs","plugin_committers-wisdmlabs"],"banners":{"banner":"https:\/\/ps.w.org\/securyn\/assets\/banner-772x250.png?rev=3616719","banner_2x":"https:\/\/ps.w.org\/securyn\/assets\/banner-1544x500.png?rev=3616719","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/securyn\/assets\/icon.svg?rev=3616719","icon":"https:\/\/ps.w.org\/securyn\/assets\/icon.svg?rev=3616719","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/securyn\/assets\/screenshot-1.png?rev=3616719","caption":"Unified security dashboard \u2014 posture score, per-module status, live protection, and a prioritized action queue."},{"src":"https:\/\/ps.w.org\/securyn\/assets\/screenshot-2.png?rev=3616719","caption":"Runtime firewall in block mode \u2014 blocked attacks grouped by rule, each with a plain-language \"why blocked\" explanation."},{"src":"https:\/\/ps.w.org\/securyn\/assets\/screenshot-3.png?rev=3616719","caption":"Hardening audit \u2014 posture across configuration surfaces with AI-prioritized, step-by-step remediation guidance."},{"src":"https:\/\/ps.w.org\/securyn\/assets\/screenshot-4.png?rev=3616719","caption":"Identity &amp; access \u2014 privilege-drift detection, account posture (MFA, dormant admins), and live sessions and blocked IPs."},{"src":"https:\/\/ps.w.org\/securyn\/assets\/screenshot-5.png?rev=3616719","caption":"File and code integrity \u2014 triage of integrity findings, including AI-analyzed malware-signature detection."},{"src":"https:\/\/ps.w.org\/securyn\/assets\/screenshot-6.png?rev=3616719","caption":"Vulnerability scanner \u2014 installed plugins matched against the CVE feed, grouped per plugin with fix guidance."},{"src":"https:\/\/ps.w.org\/securyn\/assets\/screenshot-7.png?rev=3616719","caption":"Findings \u2014 every finding across modules in one place, filterable by severity and module, with AI analysis."},{"src":"https:\/\/ps.w.org\/securyn\/assets\/screenshot-8.png?rev=3616719","caption":"Audit log \u2014 tamper-evident activity trail of security-relevant events with user and IP attribution."}],"raw_content":"<!--section=description-->\n<p>Most WordPress security plugins report a problem. They do not explain it. You get an alert that a file changed, a login failed, or a plugin is vulnerable. You do not get the reason, the risk, or the next step.<\/p>\n\n<p>Securyn is different. Securyn watches your site, finds the security problems, and explains each one in plain language. For each finding, Securyn tells you three things: what happened, why it is a risk, and the WordPress screen to open to correct it.<\/p>\n\n<p>Securyn is a detect-and-guide plugin. Securyn does not change your plugins, themes, core files, or configuration for you. You stay in control of every change. Securyn shows you the problem and the correct screen. You decide when to act.<\/p>\n\n<p>Securyn combines six security tools in one dashboard:<\/p>\n\n<ul>\n<li>Firewall \u2014 a request-time firewall with an OWASP Top 5 ruleset, rate limits, and an automatic blocklist for repeat attackers.<\/li>\n<li>Vulnerability scanner \u2014 a check of your installed plugins and themes against a known-vulnerability feed. Securyn uses wpvulnerability.net by default. Securyn uses the Wordfence Intelligence v3 feed when you add a free Wordfence key.<\/li>\n<li>Identity \u2014 login risk checks, session monitors, and privilege-drift alerts.<\/li>\n<li>File integrity \u2014 a baseline and a drift check for core and plugin files, verified against official WordPress.org checksums.<\/li>\n<li>Hardening \u2014 configuration checks with step-by-step guidance and an optional AI advisor.<\/li>\n<li>Audit log \u2014 a tamper-evident record of security events, with automatic retention cleanup.<\/li>\n<\/ul>\n\n<h4>Plain-language alerts<\/h4>\n\n<p>Each finding includes a short, human-readable explanation. You do not need to be a developer to understand what happened or what to do next. Securyn writes the alert in plain English and links you to the correct WordPress screen, such as Plugins or Updates.<\/p>\n\n<h4>AI features are optional<\/h4>\n\n<p>AI narratives use a Bring-Your-Own-Key model. You supply your own key from OpenAI, Anthropic, or Google Gemini. No request goes through a Securyn server. If you add no key, every non-AI tool continues to work. Only the AI narratives and the AI triage turn off.<\/p>\n\n<h3>Third-Party Services<\/h3>\n\n<p>This plugin connects to the following external services under specific conditions. No data is sent unless the described trigger occurs.<\/p>\n\n<h4>WordPress.org APIs<\/h4>\n\n<p>The file-integrity module fetches official checksums and package metadata from WordPress.org to verify that core files, plugins, and themes have not been tampered with. Only the component slug and version are transmitted; no site or user data is sent.<\/p>\n\n<p>Data sent: WordPress version and locale (core checksums), plugin slug and version (plugin checksums), theme slug (theme info).\nWhen: during a file-integrity scan, or when a component is checked against its official checksums.<\/p>\n\n<p>The vulnerability module also queries api.wordpress.org\/plugins\/info\/1.2\/ (via the WordPress core plugins_api() function) to check whether each installed plugin slug is still listed in the official plugin directory. Only the plugin slug is transmitted.<\/p>\n\n<p>Data sent: plugin slug.\nWhen: on the scheduled vulnerability sync (every 4 days by default) and when manually triggered.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/wordpress.org\/\">WordPress.org<\/a><\/li>\n<li>License: <a href=\"https:\/\/wordpress.org\/about\/license\/\">https:\/\/wordpress.org\/about\/license\/<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">https:\/\/wordpress.org\/about\/privacy\/<\/a><\/li>\n<\/ul>\n\n<h4>Wordfence Intelligence v3<\/h4>\n\n<p>The vulnerability scanner fetches CVE data from the Wordfence Intelligence v3 feed to check installed plugins and themes against known vulnerabilities. Requests are made on a scheduled basis (daily by default) and cached locally. A free Wordfence API key is required; you can obtain one at wordfence.com.<\/p>\n\n<p>Data sent: an HTTP GET request containing the plugin's user-agent string and the Wordfence API key (as a Bearer token in the Authorization header). No site URLs, user data, or other site-specific information is transmitted.\nWhen: on the scheduled vulnerability sync and when manually triggered from the Securyn dashboard.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/www.wordfence.com\/threat-intel\/\">Wordfence Intelligence<\/a><\/li>\n<li>Terms and Conditions: <a href=\"https:\/\/www.wordfence.com\/wordfence-intelligence-terms-and-conditions\/\">https:\/\/www.wordfence.com\/wordfence-intelligence-terms-and-conditions\/<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/www.wordfence.com\/privacy-policy\/\">https:\/\/www.wordfence.com\/privacy-policy\/<\/a><\/li>\n<\/ul>\n\n<h4>WPVulnerability<\/h4>\n\n<p>The vulnerability scanner queries the wpvulnerability.net API for CVE data. This is the default vulnerability source when no Wordfence API key is configured, and serves as a fallback if the Wordfence feed is unreachable.<\/p>\n\n<p>Data sent: plugin\/theme slug or WordPress version in the URL path. No site-specific or user-specific data is transmitted.\nWhen: during a scheduled or manual vulnerability sync, whenever wpvulnerability.net is the active source.<\/p>\n\n<p>Note: the project runs its API on the wpvulnerability.net domain (the endpoint this plugin queries), while its website, documentation, Terms of Use, and Privacy Policy are hosted on wpvulnerability.com.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/www.wpvulnerability.com\/\">WPVulnerability<\/a><\/li>\n<li>Terms of Use: <a href=\"https:\/\/www.wpvulnerability.com\/license\/\">https:\/\/www.wpvulnerability.com\/license\/<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/www.wpvulnerability.com\/privacy\">https:\/\/www.wpvulnerability.com\/privacy<\/a><\/li>\n<\/ul>\n\n<h4>OpenAI API (optional)<\/h4>\n\n<p>If you configure an OpenAI API key under Securyn &gt; Settings, the plugin sends security finding summaries to the OpenAI API for AI-assisted narratives and triage.<\/p>\n\n<p>Data sent: security finding summaries (vulnerability descriptions, hardening check results). No credentials, user data, or site URLs are included in the payload.\nWhen: only when an API key is configured and a user views a finding detail or triggers AI triage.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/openai.com\/\">OpenAI<\/a><\/li>\n<li>Terms of Use: <a href=\"https:\/\/openai.com\/policies\/terms-of-use\/\">https:\/\/openai.com\/policies\/terms-of-use\/<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/openai.com\/policies\/privacy-policy\/\">https:\/\/openai.com\/policies\/privacy-policy\/<\/a><\/li>\n<\/ul>\n\n<h4>Anthropic API (optional)<\/h4>\n\n<p>If you configure an Anthropic API key under Securyn &gt; Settings, the plugin sends security finding summaries to the Anthropic API for AI-assisted narratives and triage.<\/p>\n\n<p>Data sent: security finding summaries (vulnerability descriptions, hardening check results). No credentials, user data, or site URLs are included in the payload.\nWhen: only when an API key is configured and a user views a finding detail or triggers AI triage.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/www.anthropic.com\/\">Anthropic<\/a><\/li>\n<li>Terms of Service: <a href=\"https:\/\/www.anthropic.com\/legal\/commercial-terms\">https:\/\/www.anthropic.com\/legal\/commercial-terms<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/www.anthropic.com\/legal\/privacy\">https:\/\/www.anthropic.com\/legal\/privacy<\/a><\/li>\n<\/ul>\n\n<h4>Google Gemini API (optional)<\/h4>\n\n<p>If you configure a Google Gemini API key under Securyn &gt; Settings, the plugin sends security finding summaries to the Google Generative Language API for AI-assisted narratives and triage.<\/p>\n\n<p>Data sent: security finding summaries (vulnerability descriptions, hardening check results). No credentials, user data, or site URLs are included in the payload.\nWhen: only when an API key is configured and a user views a finding detail or triggers AI triage.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/ai.google.dev\/\">Google Gemini<\/a><\/li>\n<li>Terms of Use: <a href=\"https:\/\/ai.google.dev\/gemini-api\/terms\">https:\/\/ai.google.dev\/gemini-api\/terms<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/policies.google.com\/privacy\">https:\/\/policies.google.com\/privacy<\/a><\/li>\n<\/ul>\n\n<h4>WordPress Core AI Client (WordPress 7.0+, optional)<\/h4>\n\n<p>On WordPress 7.0 and later, Securyn can delegate AI requests to the built-in WordPress AI Client via the Connectors API. The external provider contacted depends on the connector the site administrator has configured in WordPress settings. Securyn sends the same security finding summaries described above; no additional data is transmitted.<\/p>\n\n<p>When: only when WordPress 7.0+ is detected, the core AI Client connector is active, and no BYOK API key is configured for another provider.<\/p>\n\n<ul>\n<li>Service: Determined by the site's WordPress Connectors configuration<\/li>\n<li>Terms of Use: Depend on the configured connector provider<\/li>\n<li>Privacy Policy: Depend on the configured connector provider<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>securyn<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory. Or install the plugin from the Plugins screen.<\/li>\n<li>Activate the plugin from the Plugins screen in WordPress.<\/li>\n<li>Open the Securyn menu in the admin sidebar. Run the initial setup.<\/li>\n<li>Optional: add your OpenAI, Anthropic, or Google Gemini API key under Securyn &gt; Settings to turn on AI narratives.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20securyn%20fix%20hacked%20files%20automatically%3F\"><h3>Does Securyn fix hacked files automatically?<\/h3><\/dt>\n<dd><p>No. Securyn does not change your files for you. Securyn shows you what changed and why it is a risk. Then Securyn links you to the correct WordPress screen, so you make the change yourself. You stay in control of every action.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20securyn%20and%20wordfence%3F\"><h3>What is the difference between Securyn and Wordfence?<\/h3><\/dt>\n<dd><p>Wordfence and similar plugins report a problem, but they do not always explain it. Securyn explains each finding in plain language. Securyn tells you what happened, why it is a risk, and the exact screen to open to correct it. Securyn also combines a firewall, a vulnerability scanner, identity checks, file-integrity checks, hardening checks, and an audit log in one dashboard. Securyn can also use the Wordfence Intelligence v3 feed for vulnerability data when you add a free Wordfence key.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20developer%20to%20clean%20up%20a%20wordpress%20security%20problem%3F\"><h3>Do I need a developer to clean up a WordPress security problem?<\/h3><\/dt>\n<dd><p>No. Securyn writes each alert in plain language. Securyn links you to the WordPress screen where you make the change, such as Plugins or Updates. You do not need to read technical logs or edit code to understand the problem.<\/p><\/dd>\n<dt id=\"does%20securyn%20need%20an%20api%20key%3F\"><h3>Does Securyn need an API key?<\/h3><\/dt>\n<dd><p>No. All non-AI tools work without a key. The AI narratives and the AI triage turn on only when you add a key.<\/p><\/dd>\n<dt id=\"where%20does%20the%20vulnerability%20data%20come%20from%3F\"><h3>Where does the vulnerability data come from?<\/h3><\/dt>\n<dd><p>Securyn uses the wpvulnerability.net feed by default. If you add a free Wordfence API key, Securyn uses the Wordfence Intelligence v3 feed and keeps wpvulnerability.net as a fallback. Securyn caches the results on your site.<\/p><\/dd>\n<dt id=\"can%20agencies%20use%20securyn%20on%20many%20sites%3F\"><h3>Can agencies use Securyn on many sites?<\/h3><\/dt>\n<dd><p>Yes. Securyn works on any single WordPress site. An agency can install Securyn on each site it manages. Each site keeps its own findings, firewall rules, and audit log.<\/p><\/dd>\n<dt id=\"does%20securyn%20modify%20my%20plugins%2C%20themes%2C%20or%20core%20files%3F\"><h3>Does Securyn modify my plugins, themes, or core files?<\/h3><\/dt>\n<dd><p>No. Securyn does not write to your plugins, themes, core files, or wp-config. When Securyn finds a problem, it links you to the correct WordPress screen \u2014 Plugins, Updates, or a settings page. You make the change and stay in control. Manual controls, such as ending a suspicious login session, act only when you start them.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<p>Initial release.<\/p>\n\n<ul>\n<li>Runtime firewall with an OWASP Top 5 ruleset, rate limits, and an automatic blocklist.<\/li>\n<li>Vulnerability scanner that checks installed plugins and themes against the wpvulnerability.net feed, with an optional Wordfence Intelligence v3 feed.<\/li>\n<li>Identity module with login risk checks, session monitors, and privilege-drift alerts.<\/li>\n<li>File-integrity baseline and drift detection, verified against official WordPress.org checksums.<\/li>\n<li>Hardening checks with step-by-step guidance and an optional AI advisor.<\/li>\n<li>Tamper-evident audit log with automatic retention cleanup.<\/li>\n<li>Plain-language explanations for every finding, each linked to the correct WordPress screen.<\/li>\n<li>Optional AI narratives with a Bring-Your-Own-Key model (OpenAI, Anthropic, or Google Gemini).<\/li>\n<\/ul>","raw_excerpt":"Securyn is a WordPress security operations plugin. It explains every finding in plain English and shows you where to fix it.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/313440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=313440"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wisdmlabs"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=313440"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=313440"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=313440"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=313440"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=313440"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=313440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}