{"id":358961,"date":"2026-08-29T20:01:18","date_gmt":"2026-08-29T20:01:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/rooted-security\/"},"modified":"2026-08-29T20:01:03","modified_gmt":"2026-08-29T20:01:03","slug":"rooted-dev-studio-security-toolkit","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/rooted-dev-studio-security-toolkit\/","author":23548336,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.2.1","stable_tag":"0.2.1","tested":"7.1","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"Rooted Dev Studio Security Toolkit","header_author":"Rooted Dev Studio","header_description":"Practical WordPress hardening, login protection, activity logging, and security health checks with clear, reversible controls.","assets_banners_color":"08131b","last_updated":"2026-08-29 20:01:03","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/rooteddevstudio.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":28,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.2.1":{"tag":"0.2.1","author":"bigdawgdad2185","date":"2026-08-29 20:01:03","revision":3671852}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3671852,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3671852,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.2.1"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[262246],"plugin_tags":[8531,31093,1229,600,153786],"plugin_category":[54],"plugin_contributors":[277122],"plugin_business_model":[],"class_list":["post-358961","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-activity-log","plugin_tags-hardening","plugin_tags-login-security","plugin_tags-security","plugin_tags-security-headers","plugin_category-security-and-spam-protection","plugin_contributors-bigdawgdad2185","plugin_committers-bigdawgdad2185"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/rooted-dev-studio-security-toolkit\/assets\/icon-256x256.png?rev=3671852","icon_2x":"https:\/\/ps.w.org\/rooted-dev-studio-security-toolkit\/assets\/icon-256x256.png?rev=3671852","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Rooted Dev Studio Security Toolkit provides a transparent baseline for protecting a WordPress website without hiding important behavior behind vague scores or destructive automatic fixes.<\/p>\n\n<p>Features include:<\/p>\n\n<ul>\n<li>Configurable failed-login limiting with short, per-login-and-IP temporary lockouts.<\/li>\n<li>Administrator controls for reviewing and clearing active Rooted Dev Studio Security Toolkit lockouts.<\/li>\n<li>Time-based two-factor authentication with single-use recovery codes.<\/li>\n<li>A local Security Timeline for important authentication, administration, hardening, and file events.<\/li>\n<li>Hashed origin records without storing raw IP addresses in security events.<\/li>\n<li>Baseline browser security headers.<\/li>\n<li>Reversible theme and plugin editor protection.<\/li>\n<li>Optional XML-RPC authentication restriction.<\/li>\n<li>Optional public REST user endpoint restriction.<\/li>\n<li>Security configuration checks for HTTPS, updates, debug display, administrator access, WordPress salts, and PHP.<\/li>\n<li>Read-only file fingerprinting with expected and unexplained change review.<\/li>\n<li>A bounded, manual suspicious-code scan for selected high-risk PHP patterns.<\/li>\n<li>Email alerts for important software and administrator changes and repeated-login lockouts.<\/li>\n<li>Local retention controls and automatic cleanup.<\/li>\n<\/ul>\n\n<p>Rooted Dev Studio Security Toolkit does not transmit site data to Rooted Dev Studio or any third party. It does not execute, edit, quarantine, restore, or delete scanned files. A clean scan is not a guarantee that a website is free of malicious code. Rooted Dev Studio Security Toolkit does not replace secure hosting, backups, software updates, or professional incident response.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>rooted-security<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP through Plugins &gt; Add New &gt; Upload Plugin.<\/li>\n<li>Activate Rooted Dev Studio Security Toolkit.<\/li>\n<li>Open Rooted Dev Studio Security Toolkit &gt; Dashboard.<\/li>\n<li>Review Rooted Dev Studio Security Toolkit &gt; Settings before enabling compatibility-sensitive options.<\/li>\n<li>Configure two-factor authentication from each administrator's WordPress profile and store recovery codes securely.<\/li>\n<li>Create a file-monitor baseline only after confirming the website is in a known-good state.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20rooted%20dev%20studio%20security%20toolkit%20send%20my%20site%20data%20anywhere%3F\"><h3>Does Rooted Dev Studio Security Toolkit send my site data anywhere?<\/h3><\/dt>\n<dd><p>No. Rooted Dev Studio Security Toolkit Free has no telemetry, remote API, account requirement, or external service connection.<\/p><\/dd>\n<dt id=\"does%20the%20suspicious-code%20scan%20prove%20my%20website%20is%20clean%3F\"><h3>Does the suspicious-code scan prove my website is clean?<\/h3><\/dt>\n<dd><p>No. The bounded, read-only scanner looks for selected high-risk PHP patterns in active themes and plugins. Findings require review, and a clean result cannot detect every malware family or hidden compromise.<\/p><\/dd>\n<dt id=\"why%20are%20xml-rpc%20and%20rest%20user%20restrictions%20disabled%20by%20default%3F\"><h3>Why are XML-RPC and REST user restrictions disabled by default?<\/h3><\/dt>\n<dd><p>Those options can affect mobile apps, publishing tools, and integrations. Rooted Dev Studio Security Toolkit keeps compatibility-sensitive controls opt-in.<\/p><\/dd>\n<dt id=\"are%20ip%20addresses%20stored%3F\"><h3>Are IP addresses stored?<\/h3><\/dt>\n<dd><p>Raw IP addresses are not written to the activity table. Rooted Dev Studio Security Toolkit stores a keyed hash so repeated events can be correlated without retaining the original address.<\/p><\/dd>\n<dt id=\"can%20login%20protection%20lock%20every%20visitor%20out%20of%20an%20account%3F\"><h3>Can login protection lock every visitor out of an account?<\/h3><\/dt>\n<dd><p>No. Temporary lockouts are tied to the matching login value and the server-observed IP address. Password-reset access remains available, active administrators can clear Rooted Dev Studio Security Toolkit lockouts, and a file-access recovery constant is documented on the Login Protection screen.<\/p><\/dd>\n<dt id=\"does%20rooted%20dev%20studio%20security%20toolkit%20automatically%20change%20or%20delete%20suspicious%20files%3F\"><h3>Does Rooted Dev Studio Security Toolkit automatically change or delete suspicious files?<\/h3><\/dt>\n<dd><p>No. File monitoring and suspicious-code scanning are review tools. Rooted Dev Studio Security Toolkit does not automatically modify, quarantine, restore, or delete files.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.2.1<\/h4>\n\n<ul>\n<li>Renamed the plugin for a distinctive WordPress.org identity.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Added local two-factor authentication and single-use recovery codes.<\/li>\n<li>Added the local Security Timeline and dashboard summary.<\/li>\n<li>Added reversible hardening controls and review history.<\/li>\n<li>Added read-only file fingerprinting and expected-change review.<\/li>\n<li>Added a bounded manual suspicious-code scanner with PHP comment filtering.<\/li>\n<li>Added windowed login limiting, administrator lockout recovery, timeline events, and anti-flood email alerts.<\/li>\n<li>Expanded privacy, safety-scope, and uninstall cleanup documentation.<\/li>\n<li>Addressed WordPress Plugin Check translation, request-validation, package, and database-query findings.<\/li>\n<li>Corrected translator-comment placement in administrative templates.<\/li>\n<li>Normalized production source-file line endings.<\/li>\n<\/ul>","raw_excerpt":"Practical WordPress hardening, two-factor authentication, login protection, file monitoring, and transparent security checks.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/358961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=358961"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/bigdawgdad2185"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=358961"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=358961"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=358961"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=358961"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=358961"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=358961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}