{"id":360803,"date":"2026-10-09T19:27:19","date_gmt":"2026-10-09T19:27:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/nullstate-security\/"},"modified":"2026-10-09T19:26:50","modified_gmt":"2026-10-09T19:26:50","slug":"nullstate-security","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/nullstate-security\/","author":7718974,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.4.7","stable_tag":"3.4.7","tested":"7.1.3","requires":"5.0","requires_php":"","requires_plugins":null,"header_name":"NullState Security\u2122","header_author":"NullState Security","header_description":"NullState Security\u2122 \u2013 modular security hardening, threat interception, forensic logging, live traffic monitoring, two-factor authentication, and vulnerability scanning for WordPress.","assets_banners_color":"","last_updated":"2026-10-09 19:26:50","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/nullstatesecurity.net","rating":0,"author_block_rating":0,"active_installs":0,"downloads":52,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"3.4.7":{"tag":"3.4.7","author":"salespc","date":"2026-10-09 19:26:50","revision":3737247}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3737250,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3737250,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["3.4.7"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[1174,1184,6464,600,9217],"plugin_category":[54],"plugin_contributors":[285436],"plugin_business_model":[],"class_list":["post-360803","plugin","type-plugin","status-publish","hentry","plugin_tags-firewall","plugin_tags-malware","plugin_tags-scanner","plugin_tags-security","plugin_tags-two-factor","plugin_category-security-and-spam-protection","plugin_contributors-salespc","plugin_committers-salespc"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/nullstate-security\/assets\/icon-128x128.png?rev=3737250","icon_2x":"https:\/\/ps.w.org\/nullstate-security\/assets\/icon-256x256.png?rev=3737250","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>NullState Security\u2122 is a free WordPress security plugin with modular hardening, threat interception, forensic logging, a live traffic monitor (90-day retention), two-factor authentication (TOTP), and a vulnerability scanner.<\/p>\n\n<p>Key free features:<\/p>\n\n<ul>\n<li><strong>Core hardening<\/strong> \u2013 disables XML-RPC, hides version leaks, protects the uploads directory<\/li>\n<li><strong>Brute-force protection<\/strong> \u2013 automatic IP lockout after repeated failed logins<\/li>\n<li><strong>IP blacklist<\/strong> \u2013 block attackers manually or from the Live Traffic feed, with CSV import\/export<\/li>\n<li><strong>Request filtering<\/strong> \u2013 blocks directory traversal, SQL injection, XSS, eval() and other attack payloads<\/li>\n<li><strong>User-Agent Bouncer<\/strong> \u2013 blocks known malicious scanners and bots (e.g. Nuclei, sqlmap)<\/li>\n<li><strong>Emergency lockdown<\/strong> \u2013 temporarily disable non-admin logins and block the site<\/li>\n<li><strong>Session terminator<\/strong> \u2013 end all other sessions with one click<\/li>\n<li><strong>Cache &amp; temp purge<\/strong> \u2013 clear caches and kill memory-resident shells<\/li>\n<li><strong>Admin creation lockdown<\/strong> \u2013 detect and delete rogue administrator accounts<\/li>\n<li><strong>Uploads shield<\/strong> \u2013 block script execution in the uploads directory<\/li>\n<li><strong>Forensic logging<\/strong> \u2013 every security event recorded with full request context<\/li>\n<li><strong>Live traffic monitor (90-day)<\/strong> \u2013 real-time view of every request, classified as human, bot, or attack, with country flags and one-click IP blocking<\/li>\n<li><strong>Two-factor authentication<\/strong> \u2013 TOTP-based 2FA (Google Authenticator, Authy, \u2026) with backup codes<\/li>\n<li><strong>Vulnerability scanner<\/strong> \u2013 checks plugins, themes and core for known vulnerabilities (optional free WPScan API token for detailed data)<\/li>\n<li><strong>Manual malware sweeps<\/strong> \u2013 C2 trojan cleanup, JS dropshell removal, trojanized CSS stripping, fake dependency removal, transient drop-shell cleanup<\/li>\n<li><strong>Security scorecard<\/strong> \u2013 0\u2013100 score with actionable recommendations<\/li>\n<\/ul>\n\n<p>For advanced security solutions, enterprise-grade protection, and expert support,\nvisit <a href=\"https:\/\/nullstatesecurity.net\/\">nullstatesecurity.net<\/a>.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to the following external services:<\/p>\n\n<ol>\n<li><p><strong>WPScan API (wpscan.com)<\/strong> \u2013 Optional<\/p>\n\n<ul>\n<li>Purpose: Vulnerability database queries<\/li>\n<li>Data sent: Plugin\/theme\/core version information<\/li>\n<li>When: During vulnerability scans (user-initiated)<\/li>\n<li>Terms: https:\/\/wpscan.com\/terms<\/li>\n<li>Privacy: https:\/\/automattic.com\/privacy\/<\/li>\n<\/ul><\/li>\n<li><p><strong>AbuseIPDB (abuseipdb.com)<\/strong> \u2013 Optional<\/p>\n\n<ul>\n<li>Purpose: IP reputation and threat scoring<\/li>\n<li>Data sent: Visitor IP addresses<\/li>\n<li>When: When viewing IP details in Live Traffic<\/li>\n<li>Terms: https:\/\/www.abuseipdb.com\/legal<\/li>\n<li>Privacy: https:\/\/www.abuseipdb.com\/privacy<\/li>\n<\/ul><\/li>\n<li><p><strong>ip-api.com<\/strong><\/p>\n\n<ul>\n<li>Purpose: Geolocation, ISP, and location data<\/li>\n<li>Data sent: Visitor IP addresses<\/li>\n<li>When: For country flags and IP lookup details<\/li>\n<li>Terms: https:\/\/ip-api.com\/terms<\/li>\n<li>Privacy: https:\/\/ip-api.com\/privacy<\/li>\n<\/ul><\/li>\n<li><p><strong>WordPress.org API<\/strong><\/p>\n\n<ul>\n<li>Purpose: Checking for outdated plugins\/themes\/core<\/li>\n<li>Data sent: Installed version numbers<\/li>\n<li>When: During vulnerability scans<\/li>\n<li>Terms: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul><\/li>\n<\/ol>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>nullstate-security<\/code> folder to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin<\/li>\n<li>Go to NullState Security\u2122 \u2192 Settings to configure<\/li>\n<li>Enable features you want to use<\/li>\n<\/ol>\n\n<!--section=changelog-->\n<h4>3.4.6<\/h4>\n\n<ul>\n<li>All code prefixes renamed to the nullstatesecurity_ \/ NULLSTATESECURITY_ \/ nullstatesecurity- convention (options, transients, user meta, hooks, classes, constants, handles, slugs, nonces, CSS classes)<\/li>\n<li>Automatic one-time migration on activation\/update moves existing settings, transients, user meta and log files to the new prefix<\/li>\n<li>$_SERVER request data sanitized (esc_url_raw \/ sanitize_text_field) before use and logging<\/li>\n<li>Various sanitization and hardening fixes<\/li>\n<\/ul>\n\n<h4>3.4.5<\/h4>\n\n<ul>\n<li>No license keys, license checks, tiers or registration API \u2013 plugin runs fully without any activation<\/li>\n<li>All shipped features are available to every user; no feature gating or upgrade prompts<\/li>\n<li>Live Traffic retention fixed at 90 days for all installations<\/li>\n<li>Removed the License admin page and license tracker<\/li>\n<li>Removed all premium-feature promotion from the admin UI and readme<\/li>\n<li>External services documented (WPScan, AbuseIPDB, ip-api.com, WordPress.org API)<\/li>\n<li>Storage consolidated under wp-content\/uploads\/nullstate-security\/ with direct-access protection<\/li>\n<li>Various sanitization and hardening fixes<\/li>\n<\/ul>\n\n<h4>3.4.0<\/h4>\n\n<ul>\n<li>NEW: Two-Factor Authentication (TOTP) \u2013 added as a free feature<\/li>\n<li>NEW: Vulnerability Scanner \u2013 checks plugins, themes, and core for known vulnerabilities (free)<\/li>\n<\/ul>\n\n<h4>3.3.0<\/h4>\n\n<ul>\n<li>IMPROVED: IP blacklist enforcement now works on all requests (including admin)<\/li>\n<li>FIX: Brute-force lockout now correctly auto-blocks IPs<\/li>\n<li>FIX: CSV export\/import now works as expected<\/li>\n<\/ul>\n\n<h4>3.2.2<\/h4>\n\n<ul>\n<li>NEW: Country flags in Live Traffic \u2013 see the origin country of each visitor<\/li>\n<li>NEW: IP Lookup Tool \u2013 view ISP, location, and threat score for any IP in the Live Traffic details modal<\/li>\n<li>NEW: Bulk IP Import\/Export \u2013 import and export IP blacklists via CSV<\/li>\n<li>FIX: Local\/private IPs are now excluded from IP blacklist and Live Traffic<\/li>\n<li>IMPROVED: Dashboard redesign with security scorecard, charts, and recommendations<\/li>\n<li>IMPROVED: Dark mode toggle in admin bar<\/li>\n<li>IMPROVED: First-run onboarding wizard<\/li>\n<li>IMPROVED: Tooltips with documentation links throughout the UI<\/li>\n<li>IMPROVED: Notification center with bell icon and unread badge<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>Rebranded from WP Sentinel Guard to NullState Security\u2122<\/li>\n<li>All code prefixes migrated: classes\/constants (WPSG_ \u2192 NSS_), functions and hooks (wpsg_ \u2192 nss_), text domain (wp-sentinel-guard \u2192 nullstate-security)<\/li>\n<li>Main plugin file renamed to nullstate-security.php; admin module files renamed to class-nss-*.php<\/li>\n<li>All storage migrated from wpsg_* to nss_*: options, transients, user meta keys, JSON data files and data directories<\/li>\n<li>Automatic one-time migration on activation \u2013 existing settings, fingerprints, logs, backups and scan history are preserved<\/li>\n<li>Admin menu pages and URLs updated to the new naming<\/li>\n<\/ul>\n\n<h4>2.5.0<\/h4>\n\n<ul>\n<li>NEW: Live Traffic Monitor \u2013 real-time view of every request to your site<\/li>\n<li>Auto-refresh every 5 seconds with pause\/resume (AJAX polling)<\/li>\n<li>Filter by IP, method, status, URL and user agent + pagination (50 per page)<\/li>\n<li>Block IP directly from the traffic table (adds to the IP blacklist)<\/li>\n<li>Request details modal (headers, referer, size, response time, user ID, AJAX\/REST flags)<\/li>\n<li>Storage in JSON file capped at 10,000 entries (oldest 10% trimmed)<\/li>\n<li>Skips admin-ajax, admin-post, wp-cron and login pages by default (filterable)<\/li>\n<li>Exclude IPs and user agents from logging<\/li>\n<li>Response time + final HTTP status patched in on shutdown<\/li>\n<\/ul>\n\n<h4>2.0.0-2.0.5<\/h4>\n\n<ul>\n<li>Complete admin dashboard rebuild with 5 subpages<\/li>\n<li>New UI with Tailwind CSS (dark mode ready)<\/li>\n<li>Scan page with \"Run All Scans\" button and progress bar<\/li>\n<li>Logs page with date filter, pagination, and per-page dropdown<\/li>\n<li>Settings page with toggles for XML-RPC, User-Agent Bouncer, Login Error Hiding<\/li>\n<li>Brute-force threshold and lockout duration settings<\/li>\n<li>Emergency lockdown toggle on dashboard<\/li>\n<li>Automatic .htaccess deployment on plugin activation<\/li>\n<li>IP whitelist and trusted proxies settings<\/li>\n<\/ul>\n\n<h4>1.5.3<\/h4>\n\n<ul>\n<li>Added \"Run All Scans\" button with progress bar<\/li>\n<li>Redesigned logs page with date filter and pagination<\/li>\n<li>Added settings page with toggles and thresholds<\/li>\n<li>Fixed performance issues (moved sweeps to manual)<\/li>\n<li>Fixed IP spoofing vulnerability<\/li>\n<li>Fixed double-encoding bypass<\/li>\n<li>Fixed admin-ajax false positives<\/li>\n<li>Added IP whitelist and trusted proxies<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>Core hardening (XML-RPC disable, version hiding, uploads protection)<\/li>\n<li>Brute-force protection with IP lockout<\/li>\n<li>Forensic logging with JSON format<\/li>\n<li>Request filtering and malware signature detection<\/li>\n<li>Rogue script blocking<\/li>\n<li>Header evaluation shield<\/li>\n<li>XOR\/Hex payload defender<\/li>\n<li>C2 interceptor and spoofing defender<\/li>\n<li>User-agent bouncer<\/li>\n<li>Session terminator<\/li>\n<li>Emergency lockdown mode<\/li>\n<li>Uploads execution shield<\/li>\n<li>Cache and temp purge<\/li>\n<li>Admin creation lockdown<\/li>\n<\/ul>","raw_excerpt":"Short Description: Free WordPress security plugin \u2013 malware scanning, brute-force protection, two-factor authentication, and more.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/360803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=360803"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/salespc"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=360803"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=360803"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=360803"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=360803"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=360803"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=360803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}