{"id":352362,"date":"2026-08-22T19:33:18","date_gmt":"2026-08-22T19:33:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/wpsecureops-connector\/"},"modified":"2026-08-22T19:33:00","modified_gmt":"2026-08-22T19:33:00","slug":"wpsecureops-connector","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/wpsecureops-connector\/","author":21069844,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"WPSecureOps Connector","header_author":"Guido Schad","header_description":"Sends redacted Wordfence scan findings to your WPSecureOps dashboard, so one team can triage alerts across every site it looks after.","assets_banners_color":"","last_updated":"2026-08-22 19:33:00","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/wpserverguard.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":40,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"cmdgw","date":"2026-08-22 19:33:00"}},"upgrade_notice":{"1.0.0":"<p>Forwarding is automatic for connected sites. If you had deliberately left the old\n&quot;Enable forwarding&quot; checkbox off while staying connected, press Disconnect\ninstead \u2014 that checkbox no longer exists.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[5590,1110,1184,5603,600],"plugin_category":[54],"plugin_contributors":[263741],"plugin_business_model":[],"class_list":["post-352362","plugin","type-plugin","status-publish","hentry","plugin_tags-agency","plugin_tags-alerts","plugin_tags-malware","plugin_tags-monitoring","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-cmdgw","plugin_committers-cmdgw"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/wpsecureops-connector.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>If you look after more than a handful of WordPress sites, Wordfence findings\narrive as one email per site per scan, in as many inboxes as you have sites.\nThis connector sends each completed scan to a single WPSecureOps dashboard\ninstead, where findings from every site queue up in one place, keep their\nhistory, and can be acknowledged or ignored once rather than again on every\nre-scan.<\/p>\n\n<p>The plugin does not scan anything itself and does not change how Wordfence\nbehaves. It reads the results of scans Wordfence has already finished.<\/p>\n\n<p><strong>Setup is one click.<\/strong> Activate the plugin, open Settings &rarr; WPSecureOps,\npress <strong>Connect now<\/strong>. The site registers itself, an operator approves it in the\ndashboard, and it collects its own key. There is nothing to copy or paste and no\nswitch to remember to turn on: once a site is connected, every completed scan is\nforwarded automatically. Pressing <strong>Disconnect<\/strong> is how you stop it.<\/p>\n\n<h4>What is sent<\/h4>\n\n<ul>\n<li>Site name, public URL, and the WordPress, Wordfence and connector versions.<\/li>\n<li>Scan completion time, and whether the scan succeeded or failed.<\/li>\n<li>For each finding: issue type, severity, and a redacted title and description.<\/li>\n<li>A check-in every 30 minutes carrying the versions above, whether Wordfence is\nstill active and scanning, and how many reports are waiting in the local\nqueue. This is what lets the dashboard tell \"no findings\" apart from \"this\nsite stopped talking to us\" \u2014 silence otherwise looks identical to health.<\/li>\n<\/ul>\n\n<h4>What is not sent<\/h4>\n\n<p>Usernames, passwords, API credentials, file contents, database contents, visitor\ndata and the raw Wordfence issue structure never leave the site. Absolute server\npaths are rewritten to <code>[site-root]\/<\/code> before a report is queued, so a finding\ncannot leak your directory layout.<\/p>\n\n<h4>Reliability<\/h4>\n\n<p>Reports go into a queue in your own database and are delivered by WP-Cron with\nexponential backoff, so a dashboard outage or a network blip cannot lose a scan.\nEvery report carries a deterministic id derived from the installation and the\nscan, so a retry can never create a duplicate entry in the dashboard. A report\nthat can never be delivered is dropped at the end of the retry ladder rather\nthan growing the queue forever.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to the WPSecureOps API at <code>https:\/\/wpsecureops.com<\/code> \u2014 the\nservice the plugin exists to talk to, and the only external service it contacts.<\/p>\n\n<p>It sends data at these points, and no others:<\/p>\n\n<ul>\n<li><strong>When you press \"Connect now\"<\/strong> \u2014 the site name, home URL, WordPress and\nWordfence versions, a locally generated installation id, and the hash of a\nlocally generated claim secret. Nothing is sent before you press it: installing\nand activating the plugin contacts nothing at all.<\/li>\n<li><strong>As part of that registration<\/strong>, WPSecureOps fetches your home URL once to\nconfirm you control it, and the plugin answers with a one-time nonce.<\/li>\n<li><strong>After a Wordfence scan completes<\/strong>, one report as described under \"What is\nsent\" above.<\/li>\n<li><strong>Every 30 minutes while connected<\/strong>, one check-in as described above. The\ndashboard may change this rate; the plugin clamps whatever it is told to a\nrange between 5 minutes and 6 hours.<\/li>\n<\/ul>\n\n<p>Nothing is sent once you press Disconnect, and nothing is sent by a site that has\nnever been connected.<\/p>\n\n<p>Privacy policy: https:\/\/wpsecureops.com\/privacy<\/p>\n\n<p>Self-hosters can point the connector at their own install with the\n    wpso_connector_endpoint filter or the advanced field on the settings screen.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>Created by <a href=\"https:\/\/wpserverguard.com\/\">Guido Schad<\/a>, author of\n<a href=\"https:\/\/wordpress.org\/plugins\/lockora-security-audit\/\">Lockora Security Audit<\/a>\nand <a href=\"https:\/\/wordpress.org\/plugins\/who-changed-it\/\">Who Changed It? \u2013 Activity Log &amp; Audit Trail<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate Wordfence, if it is not already running.<\/li>\n<li>Install and activate WPSecureOps Connector.<\/li>\n<li>Open <strong>Settings &rarr; WPSecureOps<\/strong> and press <strong>Connect now<\/strong>. If whoever\nruns your dashboard gave you a connect code, paste it first so the site lands\nin their account automatically.<\/li>\n<li>Approve the site in the WPSecureOps dashboard. The plugin finishes connecting\non its own, usually within five minutes.<\/li>\n<\/ol>\n\n<p>WP-Cron must be able to run. On a low-traffic site, have your host call\n    wp-cron.php on a schedule.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20wordfence%3F\"><h3>Do I need Wordfence?<\/h3><\/dt>\n<dd><p>Yes. This plugin reports what Wordfence finds; on its own it has nothing to\nreport.<\/p><\/dd>\n<dt id=\"does%20it%20modify%20or%20slow%20down%20wordfence%3F\"><h3>Does it modify or slow down Wordfence?<\/h3><\/dt>\n<dd><p>No. It reads Wordfence's completed-scan timestamp and issue list after a scan\nhas finished, never while one is running.<\/p><\/dd>\n<dt id=\"how%20do%20i%20stop%20it%20sending%3F\"><h3>How do I stop it sending?<\/h3><\/dt>\n<dd><p>Press <strong>Disconnect<\/strong> on the settings screen, or deactivate the plugin. Both stop\ndelivery immediately; Disconnect also discards this site's key.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20dashboard%20is%20offline%3F\"><h3>What happens if the dashboard is offline?<\/h3><\/dt>\n<dd><p>The report waits in a queue in your database and retries with exponential\nbackoff. Nothing is lost and nothing is duplicated.<\/p><\/dd>\n<dt id=\"can%20one%20api%20key%20be%20used%20on%20several%20sites%3F\"><h3>Can one API key be used on several sites?<\/h3><\/dt>\n<dd><p>No. The API binds a key to the first WordPress installation that uses it, and\nrefuses it everywhere else.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>It runs per site, and each site connects separately. It is not network-activated.<\/p><\/dd>\n<dt id=\"where%20is%20my%20data%20stored%3F\"><h3>Where is my data stored?<\/h3><\/dt>\n<dd><p>Findings are stored in the WPSecureOps dashboard your site is connected to. The\nplugin itself stores only its queue table, its own options, and its key \u2014 all of\nwhich are removed when you uninstall it.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Forwarding is now automatic. A connected site sends every completed scan \u2014 the\n\"Enable forwarding\" checkbox is gone, along with the state where a site looked\nconnected but had been left switched off and silently sent nothing. Connect and\nDisconnect are the only controls.<\/li>\n<li>The settings screen no longer repeats the endpoint it sends to; it reports\nwhether forwarding is active instead.<\/li>\n<li>Says plainly when Wordfence is not installed, rather than reporting \"Not\ndetected\" and leaving you to work out what that means.<\/li>\n<li>Uninstalling now removes the queue table and every option the plugin created.<\/li>\n<li>First release prepared for the WordPress plugin directory.<\/li>\n<\/ul>\n\n<h4>0.7.0<\/h4>\n\n<ul>\n<li>Scheduled check-in every 30 minutes, so the dashboard can tell a healthy quiet\nsite apart from one that has stopped reporting.<\/li>\n<\/ul>\n\n<h4>0.6.0<\/h4>\n\n<ul>\n<li>Optional connect code on the Connect screen. Paste the code your WPSecureOps\ncontact gave you and this site is assigned to their account automatically.\nLeave it blank and an administrator assigns the site instead.<\/li>\n<\/ul>\n\n<h4>0.5.0<\/h4>\n\n<ul>\n<li>Domain-control verification. The dashboard issues a nonce at registration and\nfetches this site to see it echoed back before any key is handed over, so a\nregistration can only succeed for a URL you actually control.<\/li>\n<li>Re-registering an existing site no longer changes anything until that check\npasses, so nobody can rewrite a connected site's record by knowing its URL.<\/li>\n<\/ul>\n\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>One-click connect. The plugin ships with no credentials at all: install it,\npress \"Connect now\" on the settings screen, and the site registers itself with\nthe dashboard and collects its own API key. Nothing to copy or paste.<\/li>\n<li>New sites arrive in the dashboard as pending and cannot deliver a finding\nuntil an operator approves them; the site then finishes connecting on its own.\nOperators can switch on auto-approval for a bulk rollout.<\/li>\n<li>Replaces the 0.3.0 fleet-token build, which required baking a shared secret\ninto the plugin.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Fleet install: a connector built with an enrollment token can be installed\nunchanged on any number of sites. Each site registers itself on activation and\nreceives its own per-site API key \u2014 nothing to configure per site.<\/li>\n<li>Single-site builds can also ship their key, so activating the plugin is the\nentire setup.<\/li>\n<li>Reports that can never be delivered are dropped after the full retry ladder\ninstead of retrying forever.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>The dashboard endpoint is now built in \u2014 you only paste an API key. The\nendpoint field moved to an optional \"Advanced\" section for self-hosters.<\/li>\n<li>Fixed: a scheme-less or http:\/\/ endpoint was silently discarded, leaving the\nsetting empty so nothing was ever sent and no error was recorded. Entries are\nnow upgraded to https instead of thrown away, and anything genuinely invalid\nsays so instead of failing quietly.<\/li>\n<li>Test connection no longer requires an endpoint to be entered first.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial private MVP.<\/li>\n<\/ul>","raw_excerpt":"Forward completed Wordfence scan findings to your WPSecureOps dashboard, so one team can triage alerts across every site it looks after.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/352362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=352362"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/cmdgw"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=352362"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=352362"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=352362"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=352362"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=352362"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=352362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}