{"id":334812,"date":"2026-07-31T07:32:18","date_gmt":"2026-07-31T07:32:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/brainwerk-security-suite\/"},"modified":"2026-07-31T07:31:41","modified_gmt":"2026-07-31T07:31:41","slug":"brainwerk-security-suite","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/brainwerk-security-suite\/","author":23503111,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.14.4","stable_tag":"0.14.4","tested":"7.0.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Brainwerk Security Suite","header_author":"Stefan Kogelgruber","header_description":"Privacy-first WordPress security suite, designed for EU compliance and Multisite installations. Lightweight, transparent, GDPR-ready.","assets_banners_color":"0d1c35","last_updated":"2026-07-31 07:31:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/brainwerk.at","rating":0,"author_block_rating":0,"active_installs":0,"downloads":26,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.14.4":{"tag":"0.14.4","author":"brainwerk","date":"2026-07-31 07:31:41"}},"upgrade_notice":{"0.14.4":"<p>Housekeeping release: privacy-first EU positioning in the readme, no functional changes. Out of the box the plugin still makes no outbound calls \u2014 every external service stays opt-in and off by default.<\/p>","0.6.0":"<p>Adds custom login URL, honeypot anti-bot, and CSP support. Read the FAQ on lockout-recovery before enabling the custom login URL.<\/p>","0.5.0":"<p>Adds full user-activity audit trail. Old log entries are unaffected; new events start being recorded immediately after upgrade.<\/p>","0.4.0":"<p>Adds the plugin\/theme\/core vulnerability scanner. ONE outbound HTTP call per installed component per day, to Brainwerk&#039;s EU vulnerability API (shieldforge-intel.brainwerk.at). Disable in Settings if you require fully air-gapped operation.<\/p>","0.3.0":"<p>Adds TOTP two-factor authentication. Existing users keep working unchanged; admins can opt into 2FA on their profile page.<\/p>","0.2.0":"<p>Adds the file-integrity monitor and malware-pattern scanner. The first baseline build runs at the next scheduled cron (03:30) or on demand from the Scanner tab.<\/p>","0.1.0":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3629833,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3629833,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3629571,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3629571,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.14.4"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3629613,"resolution":"1","location":"assets","locale":"","width":1388,"height":1458},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3629613,"resolution":"10","location":"assets","locale":"","width":2560,"height":3552},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3629613,"resolution":"2","location":"assets","locale":"","width":2560,"height":4482},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3629613,"resolution":"3","location":"assets","locale":"","width":2560,"height":3200},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3629613,"resolution":"4","location":"assets","locale":"","width":2560,"height":1978},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3629613,"resolution":"5","location":"assets","locale":"","width":2560,"height":3386},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3629613,"resolution":"6","location":"assets","locale":"","width":2560,"height":4324},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3629613,"resolution":"7","location":"assets","locale":"","width":2560,"height":3424},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3629613,"resolution":"8","location":"assets","locale":"","width":2560,"height":5226},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3629613,"resolution":"9","location":"assets","locale":"","width":1524,"height":3424}},"screenshots":{"1":"Dashboard widget \u2014 threat-score header, action items, 24h stat grid with trend arrows, system-status strip, top attackers + targeted users, recent events.","2":"Scanner tab \u2014 file-integrity baseline status, run-now controls, findings table with re-baseline \/ whitelist actions, code-snippet preview for malware-pattern hits.","3":"Vulnerabilities tab \u2014 per-component listing of known CVEs, CVSS scores, fixed-in versions, links to CVE \/ EUVD advisories, active-vs-inactive flagging.","4":"2FA tab \u2014 module enable, force-by-role policy, per-user enrollment status with rescue-disable for lost-device recovery.","5":"Audit tab \u2014 who-changed-what timeline with per-event-type renderer, filter dropdown, 7-day distribution badges.","6":"Hardening+ tab \u2014 custom login URL with live-preview + lockout-recovery hint, honeypot anti-bot toggles, per-header security toggles incl. CSP report-only mode.","7":"Anomaly tab \u2014 Z-score model, per-user baseline status, recent anomalies with explainable context.","8":"Logs tab \u2014 searchable activity log with quick block \/ unblock actions.","9":"Notifications \u2014 daily digest preview with threat score and ASCII heatmap.","10":"Privacy \/ GDPR \u2014 anonymization, pseudonymization, retention, privacy-policy snippet generator."}},"plugin_section":[262246],"plugin_tags":[2439,55021,600,9217,139069],"plugin_category":[54],"plugin_contributors":[268198],"plugin_business_model":[],"class_list":["post-334812","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-malware-scanner","plugin_tags-security","plugin_tags-two-factor","plugin_tags-vulnerability-scanner","plugin_category-security-and-spam-protection","plugin_contributors-brainwerk","plugin_committers-brainwerk"],"banners":{"banner":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/banner-772x250.png?rev=3629571","banner_2x":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/banner-1544x500.png?rev=3629571","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/icon-128x128.png?rev=3629833","icon_2x":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/icon-256x256.png?rev=3629833","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-1.png?rev=3629613","caption":"Dashboard widget \u2014 threat-score header, action items, 24h stat grid with trend arrows, system-status strip, top attackers + targeted users, recent events."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-2.png?rev=3629613","caption":"Scanner tab \u2014 file-integrity baseline status, run-now controls, findings table with re-baseline \/ whitelist actions, code-snippet preview for malware-pattern hits."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-3.png?rev=3629613","caption":"Vulnerabilities tab \u2014 per-component listing of known CVEs, CVSS scores, fixed-in versions, links to CVE \/ EUVD advisories, active-vs-inactive flagging."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-4.png?rev=3629613","caption":"2FA tab \u2014 module enable, force-by-role policy, per-user enrollment status with rescue-disable for lost-device recovery."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-5.png?rev=3629613","caption":"Audit tab \u2014 who-changed-what timeline with per-event-type renderer, filter dropdown, 7-day distribution badges."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-6.png?rev=3629613","caption":"Hardening+ tab \u2014 custom login URL with live-preview + lockout-recovery hint, honeypot anti-bot toggles, per-header security toggles incl. CSP report-only mode."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-7.png?rev=3629613","caption":"Anomaly tab \u2014 Z-score model, per-user baseline status, recent anomalies with explainable context."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-8.png?rev=3629613","caption":"Logs tab \u2014 searchable activity log with quick block \/ unblock actions."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-9.png?rev=3629613","caption":"Notifications \u2014 daily digest preview with threat score and ASCII heatmap."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-10.png?rev=3629613","caption":"Privacy \/ GDPR \u2014 anonymization, pseudonymization, retention, privacy-policy snippet generator."}],"raw_content":"<!--section=description-->\n<p><strong>WordPress security that protects your site \u2014 without selling out you or your visitors.<\/strong><\/p>\n\n<p>Brainwerk Security Suite is a modern, lightweight security plugin that keeps <strong>100 % of your security data on your own server<\/strong>. No third-party cookies. No Google reCAPTCHA. No silent phone-home. Just clear, honest protection \u2014 2FA, brute-force defense, file-integrity monitoring, a vulnerability scanner and a full audit trail \u2014 with privacy treated as a first-class feature, not an afterthought, and Multisite supported from day one.<\/p>\n\n<h4>\ud83c\uddea\ud83c\uddfa Made in Europe. Made for Europe.<\/h4>\n\n<p><strong>Brainwerk Security Suite is the European answer for privacy-first WordPress security \u2014 the solution built in the EU, for the EU.<\/strong><\/p>\n\n<p>Engineered in the EU, to EU standards, with <strong>privacy-by-design built into every log line<\/strong> \u2014 never bolted on afterwards. Out of the box the plugin makes <strong>no<\/strong> outbound calls at all, so your security data never leaves your infrastructure and you stay in control of your users' trust.<\/p>\n\n<ul>\n<li><strong>Privacy-focused by default<\/strong> \u2014 IP anonymisation on by default (\/24 for IPv4, \/64 for IPv6), username pseudonymisation, configurable retention, one-click erasure, and a published data map you can paste straight into your privacy policy. These are technical data-minimisation measures; whether a consent banner is required depends on your configuration and jurisdiction and should be legally reviewed.<\/li>\n<li><strong>Built for NIS2-era governance<\/strong> \u2014 everything self-hosted, auditable and under your control, with an audit trail to support your GDPR (Art. 32) and NIS2 data-governance obligations.<\/li>\n<li><strong>No phone-home, ever, unless you ask<\/strong> \u2014 every external service is opt-in and off by default, and each is documented byte-for-byte in the <strong>External services<\/strong> section below. The default anti-bot is a 100 % local honeypot \u2014 no reCAPTCHA, no Google data transfer.<\/li>\n<li><strong>High-tech under the hood<\/strong> \u2014 a SHA-256 integrity baseline over ~10k files, time-budgeted resumable cron sweeps, an explainable Z-score anomaly model with a per-user baseline, indexed tables and a transparent 0\u2013100 threat score \u2014 all computed locally, no cloud.<\/li>\n<\/ul>\n\n<h4>Free features \u2014 defense in depth<\/h4>\n\n<p><strong>Login &amp; accounts<\/strong><\/p>\n\n<ul>\n<li>Login activity log (success \/ failure \/ blocked)<\/li>\n<li>Brute-force protection: IP-based AND account-based (botnet rotates IPs, account stays locked)<\/li>\n<li>IP whitelist (single IPs and CIDR)<\/li>\n<li>TOTP two-factor authentication (RFC 6238) \u2014 works with Google Authenticator, Microsoft Authenticator, Authy, 2FAS, FreeOTP, Aegis. 8 single-use recovery codes per user. Force-by-role.<\/li>\n<li>Honeypot anti-bot on login \/ register \/ comment forms \u2014 100% local, no reCAPTCHA, no Google data transfer.<\/li>\n<li>Custom login URL \u2014 rewrite wp-login.php to a path of your choice; the original returns 404. Lockout-recovery via wp-config define.<\/li>\n<\/ul>\n\n<p><strong>File integrity &amp; malware<\/strong><\/p>\n\n<ul>\n<li>SHA-256 file-integrity monitor over WP core, mu-plugins, plugins, and themes (default: ~10k files indexed). Daily wp-cron sweep detects added \/ changed \/ missing files.<\/li>\n<li>Pattern-based suspicious-code scan (16 rules) on every changed file: <code>eval(base64_decode(...))<\/code>, webshell signatures (c99\/r57\/WSO\/b374k), inline <code>wp_insert_user(role=admin)<\/code>, <code>preg_replace \/e<\/code>, remote include via URL \u2014 runs only against deltas, not full corpus, so it stays cheap.<\/li>\n<\/ul>\n\n<p><strong>Vulnerability scanner<\/strong><\/p>\n\n<ul>\n<li>Opt-in daily check (off by default) of every installed plugin \/ theme \/ core version against an EU-hosted vulnerability API (default <code>shieldforge-intel.brainwerk.at<\/code>), which aggregates public sources (wpvulnerability.net, EUVD). No API key. The endpoint is configurable \u2014 point it at a self-hosted mirror. See <strong>External services<\/strong> below for exactly what is sent.<\/li>\n<li>CVE-IDs and CVSS scores with direct links; flagged ACTIVE vs INACTIVE so you know which to update first.<\/li>\n<\/ul>\n\n<p><strong>Hardening<\/strong><\/p>\n\n<ul>\n<li>One-click toggles: disable XML-RPC, hide WordPress version, block author enumeration, restrict REST API for anonymous visitors (users \/ comments \/ search \/ settings \/ themes \/ plugins endpoints).<\/li>\n<li>Security HTTP headers \u2014 per-header toggle: X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS.<\/li>\n<li>Content-Security-Policy with Report-Only mode for safe rollout \u2014 opt-in.<\/li>\n<li>Disable file editor in admin.<\/li>\n<\/ul>\n\n<p><strong>Detection<\/strong><\/p>\n\n<ul>\n<li>404 probing tracker (<code>.env<\/code>, <code>wp-config.bak<\/code>, <code>xmlrpc.php<\/code> and friends).<\/li>\n<li><strong>Anomaly detection<\/strong> \u2014 explainable Z-score model on login_hour \/ IP family \/ user-agent class, per-user adaptive baseline, no cloud calls.<\/li>\n<li><strong>Audit trail<\/strong> \u2014 who changed what when: post edits, user changes, plugin\/theme\/core updates, security-sensitive option changes (siteurl, admin_email, users_can_register, default_role, network site_admins ...). Useful for incident response and DSGVO Art. 32 compliance.<\/li>\n<\/ul>\n\n<p><strong>Admin experience<\/strong><\/p>\n\n<ul>\n<li>WordPress dashboard widget with <strong>transparent threat score<\/strong> (0\u2013100), action items, system-status strip, top attackers, recent events.<\/li>\n<li>Daily digest email with threat score, 24h-vs-7d trend, ASCII heatmap, top targeted usernames, top probing patterns, vulnerable-active-components \u2014 pure ASCII so it renders identically through every mail pipeline (php mail \/ SMTP \/ OAuth-SMTP \/ Microsoft Graph).<\/li>\n<li><strong>Healthcheck banner<\/strong> \u2014 auto-detects setup issues (proxy IP masking, anonymization off, brute-force disabled) so admins can't ship a broken config.<\/li>\n<li>Quiet hours that critical alerts can override.<\/li>\n<\/ul>\n\n<p><strong>Privacy &amp; GDPR<\/strong><\/p>\n\n<ul>\n<li>IP anonymization (default on, \/24 for IPv4, \/64 for IPv6), username pseudonymization, configurable log retention with daily cleanup, retroactive anonymization helper.<\/li>\n<li>Privacy-policy snippet generator (DE \/ EN).<\/li>\n<li>Multisite-aware: network-activate, per-site overrides, aggregate dashboard.<\/li>\n<li><strong>Onboarding wizard in 6 languages<\/strong> \u2014 DE \/ EN \/ FR \/ IT \/ PL \/ ES, language picker as first step.<\/li>\n<\/ul>\n\n<h4>Go Pro<\/h4>\n\n<p>The Pro tier (a separate companion plugin) adds:<\/p>\n\n<ul>\n<li>WebAuthn \/ Passkeys (FIDO2)<\/li>\n<li>Geo-blocking with a regularly updated database<\/li>\n<li>Cloud threat-intelligence feed (EU-hosted, opt-in)<\/li>\n<li>Slack \/ Discord \/ Mattermost \/ Telegram \/ MS Teams notifications<\/li>\n<li>Aggregate Multisite dashboard for agencies<\/li>\n<li>Whitelabel mode and priority support<\/li>\n<\/ul>\n\n<h4>\ud83c\uddea\ud83c\uddfa Auf Deutsch \u2014 kurz &amp; knapp<\/h4>\n\n<p><strong>Die europ\u00e4ische Antwort f\u00fcr datenschutzfreundliche WordPress-Security \u2014 die L\u00f6sung aus der EU f\u00fcr die EU.<\/strong><\/p>\n\n<p>Brainwerk Security Suite ist die schlanke, moderne Security-Suite f\u00fcr WordPress, die <strong>100 % deiner Security-Daten auf deinem eigenen Server<\/strong> beh\u00e4lt. Keine Tracking-Cookies, kein Google reCAPTCHA, kein stilles Phone-Home \u2014 nur ehrlicher Schutz und volle Kontrolle. Datenschutz ist Kernfunktion, nicht nachtr\u00e4gliches Extra, und Multisite ist von Anfang an mitgedacht.<\/p>\n\n<ul>\n<li><strong>Made in Europe, made for Europe<\/strong> \u2014 in der EU nach EU-Standards entwickelt, Privacy-by-Design in jeder Logzeile<\/li>\n<li><strong>DSGVO-ready ab Werk<\/strong> \u2014 IP-Anonymisierung standardm\u00e4\u00dfig an, Pseudonymisierung, konfigurierbare Aufbewahrung, Ein-Klick-L\u00f6schung, ver\u00f6ffentlichte Data-Map. Ob ein Consent-Banner n\u00f6tig ist, h\u00e4ngt von deiner Konfiguration und Rechtslage ab und ist rechtlich zu pr\u00fcfen.<\/li>\n<li><strong>F\u00fcr die NIS2-\u00c4ra gebaut<\/strong> \u2014 alles selbst gehostet, auditierbar, mit Audit-Trail f\u00fcr DSGVO Art. 32<\/li>\n<li><strong>Kein Phone-Home ab Werk<\/strong> \u2014 jede externe Verbindung ist opt-in und standardm\u00e4\u00dfig aus, und im Abschnitt <strong>External services<\/strong> Byte f\u00fcr Byte dokumentiert<\/li>\n<li><strong>Login-Schutz<\/strong> \u2014 TOTP-2FA, IP- <em>und<\/em> accountbasierter Brute-Force-Schutz, lokaler Honeypot (kein reCAPTCHA), eigene Login-URL<\/li>\n<li><strong>Datei-Integrit\u00e4t &amp; Malware<\/strong> \u2014 SHA-256-Baseline \u00fcber ~10.000 Dateien, Pattern-Scanner mit 16 Regeln, nur auf Deltas<\/li>\n<li><strong>Schwachstellen-Scanner<\/strong> \u2014 opt-in, t\u00e4glicher Abgleich gegen eine EU-gehostete API (self-hostbar), CVE\/CVSS<\/li>\n<li><strong>H\u00e4rtung &amp; Erkennung<\/strong> \u2014 XML-RPC aus, Security-Header, CSP, 404-Probing-Tracker, erkl\u00e4rbare Anomalieerkennung (lokal)<\/li>\n<li><strong>Multisite-First<\/strong> \u2014 netzwerkweit konfigurieren, Per-Site-Overrides, Onboarding-Wizard in 6 Sprachen (DE\/EN\/FR\/IT\/PL\/ES)<\/li>\n<\/ul>\n\n<h3>Privacy Policy<\/h3>\n\n<h4>Data stored in your WordPress database (never leaves the server)<\/h4>\n\n<ul>\n<li><strong>Login events<\/strong>: timestamp, event type (success \/ failure \/ blocked \/ 2FA required \/ 2FA passed \/ 2FA failed \/ logout), username (or hashed pseudonym if pseudonymization is on), IP address (or anonymized \/24 if IP anonymization is on \u2014 default), user-agent, request URI.<\/li>\n<li><strong>Brute-force blocks<\/strong>: blocked IP, reason, expiry timestamp.<\/li>\n<li><strong>Anomaly baselines<\/strong>: per-user statistical aggregates (mean and variance of login_hour, IP family, user-agent class). No raw login history is retained beyond the rolling log retention window (default 30 days).<\/li>\n<li><strong>File-integrity baseline<\/strong>: SHA-256 hash + size + mtime + tracked path of every PHP file under WP core \/ plugins \/ mu-plugins \/ themes. Used to detect added \/ changed \/ missing files. The file <em>contents<\/em> are never stored \u2014 only the hash.<\/li>\n<li><strong>2FA secrets<\/strong> (per user, if user enrolled): base32-encoded TOTP secret, sha256-hashed recovery codes (the plain codes are shown ONCE on enrollment and never persisted).<\/li>\n<li><strong>Audit trail<\/strong>: who edited which post \/ user \/ option \/ theme \/ plugin, with field-level diffs (no post-content bodies, no password hashes \u2014 only <code>[changed]<\/code> markers for sensitive fields).<\/li>\n<li><strong>Site option<\/strong>: configuration values, last cron timestamps.<\/li>\n<\/ul>\n\n<h4>Data sent to external services<\/h4>\n\n<p>The plugin makes no automatic outbound calls until you opt in. The one you are most likely to enable is the vulnerability scanner, which \u2014 once switched on \u2014 queries an EU-hosted vulnerability API (default <code>https:\/\/shieldforge-intel.brainwerk.at\/<\/code>) once per day. It is off by default; the endpoint is configurable and the feature can be disabled again at any time.<\/p>\n\n<ul>\n<li><strong>What is sent<\/strong>: per HTTP GET, one slug + one version per installed component (plugin \/ theme \/ core). Example: <code>GET \/v1\/vulns\/plugin\/contact-form-7\/<\/code>.<\/li>\n<li><strong>What is NOT sent<\/strong>: site URL, domain, admin email, IP addresses, user information, content, settings.<\/li>\n<li><strong>Provider<\/strong>: <code>shieldforge-intel.brainwerk.at<\/code> is Brainwerk's own EU-hosted API that aggregates public vulnerability data (wpvulnerability.net, EUVD).<\/li>\n<li><strong>Enable \/ disable<\/strong>: Brainwerk Security Suite \u2192 Vulnerabilities \u2192 Settings \u2192 Enable scanner (off by default).<\/li>\n<li><strong>Self-host<\/strong>: point the endpoint setting at your own mirror to keep everything in your network.<\/li>\n<\/ul>\n\n<p>Several <strong>opt-in<\/strong> features contact external services only after you enable them \u2014 see the <strong>External services<\/strong> section below for the full list, the exact data sent, and how to turn each off.<\/p>\n\n<h4>Lifecycle<\/h4>\n\n<p>All Brainwerk Security Suite data is deleted on plugin uninstall (DB tables dropped, options removed, user-meta wiped, transients purged). The configurable log retention is enforced by a daily cron.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin can connect to the external services listed below. <strong>Every one of them is opt-in and off by default<\/strong> \u2014 out of the box the plugin contacts nothing. Each can be disabled again at any time, and the vulnerability endpoint can be re-pointed at a self-hosted mirror.<\/p>\n\n<p><strong>1. Brainwerk Vulnerability API \u2014 <code>https:\/\/shieldforge-intel.brainwerk.at\/<\/code> \u2014 OPT-IN, default OFF<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Daily vulnerability lookup for every plugin, theme and WordPress-core version installed on your site. Surfaces known CVEs, CVSS scores and fixed-in versions in the <em>Vulnerabilities<\/em> tab.<\/li>\n<li><strong>When data is sent:<\/strong> Never until you enable the scanner. Once enabled, once per day via WP-Cron (plus any manual \"Scan now\" you trigger).<\/li>\n<li><strong>What data is sent:<\/strong> One HTTP GET per installed component, with the component slug and version in the path (e.g. <code>GET \/v1\/vulns\/plugin\/contact-form-7\/<\/code>). No site URL, no domain, no admin email, no IP, no user data, no content, no settings.<\/li>\n<li><strong>How to disable:<\/strong> <em>Brainwerk Security Suite \u2192 Vulnerabilities \u2192 Settings \u2192 Enable scanner = off<\/em>.<\/li>\n<li><strong>Self-host \/ re-point:<\/strong> set the endpoint option to your own mirror to keep everything inside your network.<\/li>\n<li><strong>Provider:<\/strong> <code>shieldforge-intel.brainwerk.at<\/code> is Brainwerk's own EU-hosted API that aggregates public vulnerability data (wpvulnerability.net \u2014 a community mirror of WPScan \/ Patchstack \u2014 and the EU Vulnerability Database, EUVD). Operated by Stefan Kogelgruber \/ Brainwerk (EU). Privacy: <a href=\"https:\/\/brainwerk.at\/privacy\">https:\/\/brainwerk.at\/privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>2. Brainwerk Threat Network (sensor) \u2014 <code>https:\/\/shieldforge-intel.brainwerk.at\/<\/code> \u2014 OPT-IN, default OFF<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Optional community threat-intelligence network. Your site shares fact-only attack telemetry and in return receives a signed feed of known-malicious IP indicators.<\/li>\n<li><strong>When data is sent:<\/strong> Only after you give explicit consent AND the site registers with the network. Never before both steps are completed.<\/li>\n<li><strong>What data is sent:<\/strong> Batched, HMAC-signed events containing <strong>hashed, non-reversible IP indicators<\/strong> (raw IP addresses never leave your server), a hashed user-agent class, a request-path pattern and a country code. No site URL owner data, no user identities, no content.<\/li>\n<li><strong>How to disable:<\/strong> <em>Brainwerk Security Suite \u2192 Threat Network \u2192 disable<\/em> (or simply never enable it). Off by default.<\/li>\n<li><strong>Provider:<\/strong> Brainwerk (EU-hosted), same operator and privacy policy as above.<\/li>\n<\/ul>\n\n<p><strong>3. Have I Been Pwned (Pwned Passwords) \u2014 <code>https:\/\/api.pwnedpasswords.com\/<\/code> \u2014 OPT-IN, default OFF<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Warns users whose password appears in known breach corpora, at login or password change.<\/li>\n<li><strong>What data is sent:<\/strong> Only the <strong>first 5 characters of the SHA-1 hash<\/strong> of the password (k-anonymity range query). The password itself and the full hash never leave your server.<\/li>\n<li><strong>How to disable:<\/strong> Off by default; enable under the login\/hardening settings only if you want it.<\/li>\n<li><strong>Provider:<\/strong> Have I Been Pwned, operated by Troy Hunt. <a href=\"https:\/\/haveibeenpwned.com\/Privacy\">https:\/\/haveibeenpwned.com\/Privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>4. hCaptcha \/ Cloudflare Turnstile (optional captcha) \u2014 <code>https:\/\/hcaptcha.com\/<\/code>, <code>https:\/\/challenges.cloudflare.com\/<\/code> \u2014 OPT-IN, default OFF<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Optional captcha on login \/ registration \/ comment forms as an alternative to the built-in local honeypot.<\/li>\n<li><strong>When it is active:<\/strong> Only if you enable the captcha module AND enter your own site\/secret keys. When enabled it loads the provider's JavaScript from their CDN in the browser and, on verification, sends the captcha token and the visitor's IP address to the provider.<\/li>\n<li><strong>How to disable:<\/strong> Off by default; the default anti-bot (honeypot) is 100% local and contacts nothing.<\/li>\n<li><strong>Providers:<\/strong> <a href=\"https:\/\/www.hcaptcha.com\/privacy\">hCaptcha privacy<\/a> \u00b7 <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">Cloudflare Turnstile privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>5. WordPress.org (core checksums &amp; repository integrity) \u2014 <code>https:\/\/api.wordpress.org\/<\/code>, <code>https:\/\/downloads.wordpress.org\/<\/code> \u2014 OPT-IN \/ on demand<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Verifying WordPress core files against official checksums (manual admin action) and, optionally, comparing installed plugins\/themes against the official wordpress.org checksums \/ release packages to detect tampering. The plugin only <strong>reads<\/strong> these to report differences \u2014 it never modifies your plugin or theme files.<\/li>\n<li><strong>What data is sent:<\/strong> The WordPress version + locale, and the slug\/version of the components being verified. No user data.<\/li>\n<li><strong>When:<\/strong> The core-checksum check runs only when you click it; the repository integrity check is off by default and, when enabled, runs via cron \/ on demand.<\/li>\n<li><strong>Provider:<\/strong> WordPress.org (the WordPress project's own infrastructure). <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">https:\/\/wordpress.org\/about\/privacy\/<\/a><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>brainwerk-security-suite<\/code> folder to <code>\/wp-content\/plugins\/<\/code> or install via the WordPress plugin uploader.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen (or <strong>Network Activate<\/strong> for Multisite).<\/li>\n<li>Open <strong>Brainwerk Security Suite<\/strong> in the admin sidebar and walk through the onboarding wizard.<\/li>\n<\/ol>\n\n<p>Brainwerk Security Suite ships with safe defaults \u2014 no configuration is required to get baseline protection, and out of the box it makes no outbound calls at all. The vulnerability scanner (the one feature that contacts an external API) is off by default; enable it under <strong>Vulnerabilities \u2192 Settings<\/strong> if you want daily CVE lookups.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20brainwerk%20security%20suite%20call%20any%20external%20service%3F\"><h3>Does Brainwerk Security Suite call any external service?<\/h3><\/dt>\n<dd><p>Not until you ask it to. Out of the box the plugin makes <strong>no<\/strong> automatic outbound calls. Every integration that can reach an external service is opt-in and off by default:<\/p>\n\n<ul>\n<li>The plugin\/theme\/core vulnerability scanner. Once you enable it, it queries an EU-hosted vulnerability API (default <code>https:\/\/shieldforge-intel.brainwerk.at\/<\/code>) once per day for the slug + version of each installed component. Nothing else (no site URL, no admin email, no IP, no user data) is sent, and you can point it at a self-hosted mirror under <strong>Brainwerk Security Suite \u2192 Vulnerabilities \u2192 Settings<\/strong>.<\/li>\n<li>The Threat Network sensor, the Have-I-Been-Pwned password check, an optional hCaptcha \/ Cloudflare Turnstile captcha, and the on-demand WordPress.org core-checksum \/ repository integrity checks.<\/li>\n<\/ul>\n\n<p>Each is documented in full in the <strong>External services<\/strong> section below.<\/p>\n\n<p>The core local features (file-integrity monitor, malware-pattern scan, brute-force protection, audit log, 2FA, honeypot, anomaly detection, security headers) make no outbound calls.<\/p><\/dd>\n<dt id=\"is%20the%20plugin%20gdpr-compliant%20out%20of%20the%20box%3F\"><h3>Is the plugin GDPR-compliant out of the box?<\/h3><\/dt>\n<dd><p>It is built to support your GDPR obligations: IP anonymization, configurable retention, and a published data map are on by default, and the admin includes copy-paste-ready text for your privacy policy. Full legal compliance always depends on how you run your whole site, so treat these as strong technical building blocks rather than legal advice.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on Multisite?<\/h3><\/dt>\n<dd><p>Yes. Network-activate it and configure once at the network level; per-site overrides are supported.<\/p><\/dd>\n<dt id=\"i%20lost%20my%202fa%20device.%20how%20do%20i%20get%20back%20in%3F\"><h3>I lost my 2FA device. How do I get back in?<\/h3><\/dt>\n<dd><p>Use one of the 8 recovery codes generated when you enrolled. If you also lost those, an administrator with <code>manage_network_options<\/code> capability can disable 2FA for any user under <strong>Brainwerk Security Suite \u2192 2FA \u2192 Users with 2FA configured \u2192 Rescue: disable<\/strong>.<\/p><\/dd>\n<dt id=\"i%20enabled%20the%20custom%20login%20url%20and%20locked%20myself%20out.%20how%20do%20i%20recover%3F\"><h3>I enabled the custom login URL and locked myself out. How do I recover?<\/h3><\/dt>\n<dd><p>Add this line to <code>wp-config.php<\/code> (above the \"That's all\" comment):<\/p>\n\n<pre><code>define('SHIELDFORGE_LOGIN_RESCUE', 'choose-a-long-random-secret');\n<\/code><\/pre>\n\n<p>Then visit <code>https:\/\/your-site\/wp-login.php?shieldforge_rescue=choose-a-long-random-secret<\/code> to bypass the 404 and reach the standard login.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%3F\"><h3>Will it slow down my site?<\/h3><\/dt>\n<dd><p>It is designed to be lightweight. Hooks fire only where needed, the database tables are indexed, and old log rows are cleaned up daily. The file-integrity scanner runs at 03:30 in a 45-second time-budgeted cron sweep that resumes on the next tick if a single run can't finish.<\/p><\/dd>\n<dt id=\"my%20server%20runs%20behind%20a%20reverse%20proxy%20%2F%20cloudflare%20tunnel%20%2F%20sslh.%20will%20brainwerk%20security%20suite%20see%20real%20client%20ips%3F\"><h3>My server runs behind a reverse proxy \/ Cloudflare Tunnel \/ sslh. Will Brainwerk Security Suite see real client IPs?<\/h3><\/dt>\n<dd><p>Brainwerk Security Suite reads <code>$_SERVER['REMOTE_ADDR']<\/code> by default. If your nginx \/ Apache is configured to forward the original client IP (PROXY-protocol, X-Forwarded-For), that's what arrives in PHP and Brainwerk Security Suite uses it. The healthcheck card on every admin screen will warn you if all visitors arrive as 127.0.0.1 \u2014 that means the proxy chain is hiding the real client from PHP, which would silently disable IP-based brute-force protection. Fix it at the proxy \/ web-server layer (proxy-protocol-aware listener) before re-enabling brute-force protection.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.14.4 \u2014 2026-07-29<\/h4>\n\n<ul>\n<li>Maintenance release: version bump only, no functional changes since 0.14.3.<\/li>\n<\/ul>\n\n<h4>0.14.3 \u2014 2026-07-17<\/h4>\n\n<ul>\n<li><strong>wp.org compliance<\/strong>: renamed all short-prefixed (<code>sf_<\/code>) transients to the unique <code>shieldforge_<\/code> prefix \u2014 <code>shieldforge_user_lock_<\/code>, <code>shieldforge_2fa_pending_<\/code>, <code>shieldforge_2fa_recovery_show_<\/code>, <code>shieldforge_2fa_attempts_<\/code> \u2014 to avoid collisions in the shared options\/transients space.<\/li>\n<li><strong>Metadata<\/strong>: removed the <code>Plugin URI<\/code> header (the previous value was not public); the public <code>Author URI<\/code> is retained.<\/li>\n<li><strong>Hardening<\/strong>: escape all remaining admin outputs at output time (audit table, scanner status, captcha widget, magic-link\/privacy <code>wp_die<\/code> messages) and document the trusted-table-name direct queries.<\/li>\n<\/ul>\n\n<h4>0.14.1 \u2014 2026-07-04<\/h4>\n\n<ul>\n<li><strong>Privacy<\/strong>: the plugin\/theme\/core vulnerability scanner is now <strong>opt-in and off by default<\/strong> \u2014 out of the box the plugin makes no automatic outbound calls at all. Enable it under <em>Vulnerabilities \u2192 Settings<\/em> to consent to the daily lookup.<\/li>\n<li><strong>wp.org compliance<\/strong>: all inline <code>&lt;script&gt;<\/code> \/ <code>&lt;style&gt;<\/code> blocks in admin views are now enqueued (<code>wp_add_inline_script<\/code> \/ bundled CSS \/ a static <code>assets\/js\/twofactor-profile.js<\/code>).<\/li>\n<li><strong>wp.org compliance<\/strong>: the repo-integrity checker is now detection-only \u2014 it reports tampered plugin\/theme files and links you to the standard WordPress reinstall flow instead of writing files into plugin\/theme folders.<\/li>\n<li><strong>wp.org compliance<\/strong>: removed the direct load of <code>wp-includes\/template-loader.php<\/code> in the login-URL 404 path; it now emits a self-contained 404.<\/li>\n<li><strong>wp.org compliance<\/strong>: removed the redundant <code>load_plugin_textdomain()<\/code> call (WordPress 4.6+ auto-loads bundled translations by slug).<\/li>\n<li><strong>Security<\/strong>: escape the WAF debug output and the 2FA \"last used\" column at output time.<\/li>\n<li><strong>Docs<\/strong>: readme reworded to drop comparative marketing claims and to reflect that every external service is opt-in and off by default.<\/li>\n<\/ul>\n\n<h4>0.14.0 \u2014 2026-05-21<\/h4>\n\n<ul>\n<li><strong>Rebranded<\/strong> to Brainwerk Security Suite (was: ShieldForge). Display name + text-domain + plugin filename + language files updated. Internal class prefix <code>Shieldforge_*<\/code> and DB tables <code>wp_shieldforge_*<\/code> kept stable for upgrade compatibility.<\/li>\n<li><strong>Security<\/strong>: nonce in the magic-link form now goes through <code>sanitize_text_field( wp_unslash() )<\/code> (pluggable-function hardening).<\/li>\n<li><strong>Security<\/strong>: <code>$_COOKIE<\/code> reads in the 2FA grace-period token now sanitize_text_field + wp_unslash before the alphanum hex-filter.<\/li>\n<li><strong>Security<\/strong>: all <code>$_SERVER<\/code> reads (<code>HTTP_USER_AGENT<\/code>, <code>HTTP_REFERER<\/code>, <code>HTTP_ACCEPT_LANGUAGE<\/code>, <code>REQUEST_METHOD<\/code>, <code>REQUEST_URI<\/code>, <code>REMOTE_ADDR<\/code>, trusted-proxy header loop) now use <code>sanitize_text_field( wp_unslash() )<\/code> (URLs use <code>esc_url_raw( wp_unslash() )<\/code>).<\/li>\n<li><strong>wp.org compliance<\/strong>: replaced both <code>&lt;&lt;&lt;TXT<\/code> heredocs in the privacy-policy generator with plain string concatenation (wp.org pre-scan blocks heredocs).<\/li>\n<li><strong>wp.org compliance<\/strong>: removed <code>load_plugin_textdomain()<\/code> \u2014 WordPress 4.6+ auto-loads translations for plugins hosted on wp.org by slug. The de_AT \/ de_CH \/ de_DE_formal fallback filter stays.<\/li>\n<li><strong>Docs<\/strong>: readme now has a top-level <code>== External services ==<\/code> section documenting every outbound connection \u2014 the default vulnerability API (<code>shieldforge-intel.brainwerk.at<\/code>) plus the opt-in Threat Network sensor, Pwned-Passwords check, optional hCaptcha\/Turnstile captcha, and WordPress.org checksum\/repository checks (what is sent, when, how to disable, self-host option, provider links).<\/li>\n<li><strong>Docs<\/strong>: added <code>brainwerk<\/code> as primary contributor in readme alongside <code>stefankogelgruber<\/code>.<\/li>\n<\/ul>\n\n<h4>0.9.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>UX overhaul<\/strong>: tab navigation now grouped into 5 logical sections (Operations \/ Setup &amp; Hardening \/ Detection &amp; Response \/ Records &amp; Alerts \/ System) \u2014 easier to find your way around 16 tabs.<\/li>\n<li><strong>Hero dashboard<\/strong>: big color-coded threat-status banner at the top, action-items as prominent clickable cards, status pop visible in 1 second.<\/li>\n<li><strong>Modern toggle switches<\/strong> (iOS-style sliders) replace stock checkboxes throughout settings forms.<\/li>\n<li><strong>Empty states with CTAs<\/strong>: Vulnerabilities \/ Scanner \/ Audit \/ Firewall now show inviting empty-state cards with one-click actions instead of a flat \"no findings yet\".<\/li>\n<li><strong>Quick-Setup wizard<\/strong>: pick a site profile (School \/ Agency \/ Shop \/ Blog) \u2192 all relevant settings batch-applied with sensible defaults.<\/li>\n<li><strong>Mobile-responsive admin<\/strong> \u2014 tab nav adapts, hero stacks vertically on small screens.<\/li>\n<li><strong>Dark-mode<\/strong> support for the WP \"Midnight\" \/ \"Ectoplasm\" \/ \"Ocean\" admin color schemes.<\/li>\n<li><strong>Tooltip bubbles<\/strong> via <code>[data-sf-tip]<\/code> attribute pattern for inline setting hints.<\/li>\n<li>Pro plugin now has its own <code>bin\/bump-version.ps1<\/code> (was Free-only).<\/li>\n<li>Both bump-version scripts now also sync the <code>Project-Id-Version<\/code> header in <code>.po<\/code> translation files.<\/li>\n<\/ul>\n\n<h4>0.6.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>Custom login URL<\/strong>: rewrite wp-login.php to a configurable path; original returns 404. Lockout-recovery via <code>SHIELDFORGE_LOGIN_RESCUE<\/code> wp-config define.<\/li>\n<li><strong>Honeypot anti-bot<\/strong> on login \/ register \/ comment forms \u2014 100% local, no reCAPTCHA. Per-surface toggles.<\/li>\n<li><strong>Content-Security-Policy<\/strong> support with Report-Only mode for safe rollout.<\/li>\n<li><strong>Per-header security toggles<\/strong> for X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS \u2014 set only if your nginx\/Apache doesn't already send them.<\/li>\n<li>New <strong>Hardening+<\/strong> admin tab.<\/li>\n<\/ul>\n\n<h4>0.5.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>User activity audit trail<\/strong>: hooks 11 WordPress lifecycle events (post_updated \/ wp_trash_post \/ before_delete_post \/ profile_update \/ deleted_user \/ wpmu_delete_user \/ wp_logout \/ upgrader_process_complete \/ updated_option \/ update_site_option). Per-group toggles, post-type skip-list, security-sensitive option-key whitelist, password \/ hash redaction.<\/li>\n<li>New <strong>Audit<\/strong> admin tab with filter dropdown, paginated event list, 7-day distribution badges.<\/li>\n<li>9 new event types: logout, post_updated\/trashed\/deleted, user_deleted, user_profile_updated, plugin_updated, theme_updated, core_updated.<\/li>\n<\/ul>\n\n<h4>0.4.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>Plugin \/ theme \/ core vulnerability scanner<\/strong> \u2014 daily check against wpvulnerability.net (free, EU-hosted, no API key). CVE-IDs, CVSS scores, fixed-in versions, active-vs-inactive flagging.<\/li>\n<li>New <strong>Vulnerabilities<\/strong> admin tab.<\/li>\n<li>Dashboard action-item nag and daily-digest section for active critical vulns.<\/li>\n<li>Cron staggering: scanner 03:30 \/ vulnscan 04:30 \/ digest 07:00 to spread DB load.<\/li>\n<li>Dedup state: each vuln is logged once per slug+version+uuid, re-logged after 7 days.<\/li>\n<\/ul>\n\n<h4>0.3.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>TOTP two-factor authentication<\/strong> (RFC 6238, pure PHP, no external dependencies). Compatible with Google Authenticator, Microsoft Authenticator, Authy, 2FAS, FreeOTP, Aegis.<\/li>\n<li>8 single-use recovery codes per user, sha256-hashed, normalized matcher.<\/li>\n<li>Force-by-role policy.<\/li>\n<li>Interstitial login flow (<code>wp-login.php?action=sf_2fa<\/code>) preserves the WordPress login styling.<\/li>\n<li>Application-password authentication bypasses 2FA correctly (per WordPress 5.6+ guidelines).<\/li>\n<li>New <strong>2FA<\/strong> admin tab.<\/li>\n<\/ul>\n\n<h4>0.2.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>File-integrity monitor<\/strong>: SHA-256 hash baseline of every PHP file under WP core \/ plugins \/ mu-plugins \/ themes. Daily cron diffs against the baseline.<\/li>\n<li><strong>Pattern-based suspicious-code scanner<\/strong> (16 rules) on every added or changed file: <code>eval(base64_decode(...))<\/code>, <code>eval(gzinflate(...))<\/code>, <code>assert(base64_decode(...))<\/code>, <code>preg_replace \/e<\/code>, webshell signatures (c99 \/ r57 \/ WSO \/ b374k), remote include via URL, inline <code>wp_insert_user(role=administrator)<\/code>, <code>wp_set_auth_cookie(literal-id)<\/code> and more.<\/li>\n<li>Time-budgeted cron run (45 s soft cap, resumes on next tick).<\/li>\n<li>New <strong>Scanner<\/strong> admin tab with re-baseline \/ whitelist quick actions.<\/li>\n<li>DB schema upgrade to v2 (adds <code>shieldforge_files<\/code> table).<\/li>\n<\/ul>\n\n<h4>0.1.1 \u2014 2026-05-07<\/h4>\n\n<ul>\n<li>Hardening: account-based brute-force lockout in addition to IP-based.<\/li>\n<li>REST API anonymous-restriction extended to comments \/ search \/ settings \/ themes \/ plugins endpoints.<\/li>\n<li>Probing-hook moved from <code>template_redirect<\/code> to <code>wp<\/code> action priority 1 for compatibility with custom 404 themes \/ SEO plugins.<\/li>\n<li>nginx-hardening: install.php and *.log explicitly blocked.<\/li>\n<li>IP anonymization re-enabled by default; one-time retroactive anonymization helper.<\/li>\n<li>IP-form-mismatch fix in BF counter (anonymized vs raw).<\/li>\n<li>Internal: versioning framework with idempotent migrations + bash\/PowerShell bump-version helpers.<\/li>\n<li>Pro companion plugin scaffolding with first feature (Slack\/Discord\/Mattermost webhook).<\/li>\n<li>Dashboard widget aggregated upgrade: action-items block, system-status strip, trend arrows vs 7-day average, top-targeted-usernames column.<\/li>\n<\/ul>\n\n<h4>0.1.0 \u2014 2026-05-07<\/h4>\n\n<ul>\n<li>Initial release: login activity log, brute-force protection, IP whitelist with CIDR, hardening toggles, 404 probing tracker, email notifications, daily digest with transparent threat score, anomaly detection (beta), healthcheck banner, onboarding wizard in 6 languages, multisite-aware, GDPR controls (IP anonymization, username pseudonymization, log retention), privacy-policy snippet generator, License management against Lemon Squeezy License API.<\/li>\n<\/ul>","raw_excerpt":"The European answer for privacy-first WordPress security \u2014 from the EU, for the EU. GDPR-ready, Multisite-first, no outbound calls by default.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/334812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=334812"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/brainwerk"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=334812"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=334812"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=334812"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=334812"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=334812"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=334812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}