{"id":366863,"date":"2026-10-01T06:13:48","date_gmt":"2026-10-01T06:13:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/pb4-shield\/"},"modified":"2026-10-01T06:45:09","modified_gmt":"2026-10-01T06:45:09","slug":"pb4host-security","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/pb4host-security\/","author":10489306,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.5","stable_tag":"1.0.5","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"PB4Host Security","header_author":"PB4Host","header_description":"Enterprise-grade WordPress Security Suite: Web Application Firewall (WAF), active malware scanning, brute-force defense, Two-Factor Authentication (2FA), and system hardening.","assets_banners_color":"1d4060","last_updated":"2026-10-01 06:45:09","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.pb4host.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":38,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.5":{"tag":"1.0.5","author":"pb.krishna@gmail.com","date":"2026-10-01 06:45:09","revision":3722511},"1.0.6":{"tag":"1.0.6","author":"pb.krishna@gmail.com","date":"2026-10-01 06:13:36","revision":3722475}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3722475,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3722475,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3722475,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3722475,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.5","1.0.6"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[9211,1174,55021,600,214603],"plugin_category":[54],"plugin_contributors":[283826],"plugin_business_model":[],"class_list":["post-366863","plugin","type-plugin","status-publish","hentry","plugin_tags-2fa","plugin_tags-firewall","plugin_tags-malware-scanner","plugin_tags-security","plugin_tags-turnstile","plugin_category-security-and-spam-protection","plugin_contributors-pbkrishnagmailcom","plugin_committers-pbkrishnagmailcom"],"banners":{"banner":"https:\/\/ps.w.org\/pb4host-security\/assets\/banner-772x250.png?rev=3722475","banner_2x":"https:\/\/ps.w.org\/pb4host-security\/assets\/banner-1544x500.png?rev=3722475","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/pb4host-security\/assets\/icon-128x128.png?rev=3722475","icon_2x":"https:\/\/ps.w.org\/pb4host-security\/assets\/icon-256x256.png?rev=3722475","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>PB4Host Security<\/strong> is an enterprise-grade, all-in-one Security &amp; Protection suite engineered specifically for WordPress. Built to safeguard your website from cyber threats, brute force attacks, malicious payloads, and backdoors with minimal performance impact.<\/p>\n\n<p>Featuring an early Web Application Firewall (WAF), active heuristic malware scanner, native Two-Factor Authentication (2FA\/TOTP), intelligent brute-force lockout defense, system hardening, and zero-day virtual patching.<\/p>\n\n<p>Key Highlights:\n* High-Performance Web Application Firewall (WAF) running at early priority before plugins execute.\n* Active Malware &amp; Heuristic Scanner with quarantined vault isolation and 1-click restoration.\n* Native Two-Factor Authentication (2FA \/ TOTP) compatible with Google Authenticator, Authy, and Microsoft Authenticator.\n* Intelligent Brute-Force Login Defense with honeypot traps and custom login slugs.\n* Comprehensive System Hardening (XML-RPC disabler, user enumeration guard, uploads PHP execution blocker).\n* Privacy-first architecture: Threat intelligence feeds, disposable email lists, and trackback verification run 100% offline with zero external tracking.<\/p>\n\n<h3>Features<\/h3>\n\n<h3>\ud83d\udee1\ufe0f Complete Enterprise Security Engines:<\/h3>\n\n<ol>\n<li><p><strong>Web Application Firewall (WAF)<\/strong>:<\/p>\n\n<ul>\n<li><strong>Early Packet Inspection<\/strong>: Runs before theme and plugin execution to intercept malicious requests.<\/li>\n<li><strong>Deep Threat Detection<\/strong>: Protects against SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion (LFI), and Remote Code Execution (RCE).<\/li>\n<li><strong>Scanner &amp; Bot Defense<\/strong>: Blocks automated vulnerability scanners (sqlmap, nikto, wpscan, nmap).<\/li>\n<li><strong>Rate Limiting &amp; IP Set<\/strong>: Protects against velocity surges and supports full CIDR IP white\/blacklisting.<\/li>\n<\/ul><\/li>\n<li><p><strong>Active Malware &amp; File Integrity Scanner<\/strong>:<\/p>\n\n<ul>\n<li><strong>Heuristic Signature Engine<\/strong>: Detects webshells, obfuscated base64 execution, and dynamic backdoors.<\/li>\n<li><strong>Uploads Directory Guard<\/strong>: Flags and prevents executable scripts inside uploads directories.<\/li>\n<li><strong>Quarantine Vault<\/strong>: Safely isolates infected files with 1-click restore and permanent delete options.<\/li>\n<\/ul><\/li>\n<li><p><strong>Login Security &amp; Brute-Force Defense<\/strong>:<\/p>\n\n<ul>\n<li><strong>Intelligent IP Lockout<\/strong>: Automatically locks out IP addresses exceeding maximum failed login attempts.<\/li>\n<li><strong>Honeypot Traps<\/strong>: Immediate lockout upon login attempts with reserved usernames (<code>admin<\/code>, <code>root<\/code>).<\/li>\n<li><strong>Custom Login Slug<\/strong>: Conceals <code>wp-login.php<\/code> behind a custom URL with 403 Forbidden on direct requests.<\/li>\n<li><strong>Masked Errors<\/strong>: Neutralizes login hints to prevent username enumeration.<\/li>\n<\/ul><\/li>\n<li><p><strong>Native Two-Factor Authentication (2FA \/ TOTP)<\/strong>:<\/p>\n\n<ul>\n<li><strong>RFC 6238 Standard<\/strong>: Fully compatible with Google Authenticator, Authy, Microsoft Authenticator, and 1Password.<\/li>\n<li><strong>Offline &amp; Privacy-First<\/strong>: Zero external tracking or third-party API dependencies.<\/li>\n<li><strong>Role Enforcement &amp; Backup Codes<\/strong>: Enforce mandatory 2FA on admin\/editor roles, with emergency recovery codes.<\/li>\n<\/ul><\/li>\n<li><p><strong>WordPress &amp; System Hardening<\/strong>:<\/p>\n\n<ul>\n<li><strong>Surface Reduction<\/strong>: Disables XML-RPC and unauthenticated REST API user enumeration.<\/li>\n<li><strong>File Protection<\/strong>: Disables administrative file editing and secures uploads folder via <code>.htaccess<\/code>.<\/li>\n<li><strong>HTTP Security Headers<\/strong>: Enforces <code>X-Frame-Options<\/code>, <code>X-Content-Type-Options: nosniff<\/code>, and <code>Referrer-Policy<\/code>.<\/li>\n<\/ul><\/li>\n<li><p><strong>Live Security Audit Log<\/strong>:<\/p>\n\n<ul>\n<li>Real-time stream of security events: WAF blocks, failed logins, lockouts, 2FA, and file changes.<\/li>\n<li>Filterable by severity with automated 30-day log rotation and 1-click CSV export.<\/li>\n<\/ul><\/li>\n<li><p><strong>Frictionless Bot Defense (Turnstile &amp; reCAPTCHA)<\/strong>:<\/p>\n\n<ul>\n<li>Protects login, registration, lost password, and comment forms against automated abuse.<\/li>\n<li>Fail-open network resilience prevents user lockouts during upstream API hiccups.<\/li>\n<\/ul><\/li>\n<li><p><strong>Known CVE Vulnerability Scanner<\/strong>:<\/p>\n\n<ul>\n<li>Audits core, plugins, and themes against known CVE vulnerabilities and CVSS scores.<\/li>\n<li>1-click direct update links to patch vulnerable extensions quickly.<\/li>\n<\/ul><\/li>\n<li><p><strong>Compromised Password Checking &amp; Password Policy<\/strong>:<\/p>\n\n<ul>\n<li>Optional HaveIBeenPwned check using privacy-preserving k-anonymity (5-char SHA-1 prefix only).<\/li>\n<li>Enforces configurable password strength, mixed case, and personal data restrictions.<\/li>\n<\/ul><\/li>\n<li><p><strong>GeoIP &amp; Country Access Control<\/strong>:<\/p>\n\n<ul>\n<li>Granular country allowlisting and denylisting for the whole site or login screens.<\/li>\n<li>Uses fast edge server headers (Cloudflare <code>CF-IPCountry<\/code>) or cached fallback lookups.<\/li>\n<\/ul><\/li>\n<li><p><strong>User Session Manager<\/strong>:<\/p>\n\n<ul>\n<li>Real-time visibility into all active user sessions and device fingerprints.<\/li>\n<li>Enforces idle auto-logout and concurrent session caps with 1-click remote session revocation.<\/li>\n<\/ul><\/li>\n<li><p><strong>Curated Threat Intelligence &amp; IP Set<\/strong>:<\/p>\n\n<ul>\n<li>Bundled local threat intelligence and suspicious IP rules block bad actors before execution.<\/li>\n<li>100% offline local processing ensures zero external latency or privacy leaks.<\/li>\n<\/ul><\/li>\n<li><p><strong>Official WordPress.org Checksum Verifier<\/strong>:<\/p>\n\n<ul>\n<li>Verifies core and plugin files against official WordPress.org cryptographic hashes.<\/li>\n<li>Detects rogue or extraneous files within core directories.<\/li>\n<\/ul><\/li>\n<li><p><strong>File Integrity Monitoring (FIM)<\/strong>:<\/p>\n\n<ul>\n<li>Takes cryptographic SHA-256 baselines of site files and detects additions, alterations, or deletions.<\/li>\n<li>Smart exclusion filters ignore cache files and media uploads.<\/li>\n<\/ul><\/li>\n<li><p><strong>Targeted Virtual Patching (vPatch)<\/strong>:<\/p>\n\n<ul>\n<li>Intercepts critical exploit vectors for known high-impact WordPress vulnerabilities before plugin code runs.<\/li>\n<li>Proactive micro-rules protect sites even before vendor security updates are installed.<\/li>\n<\/ul><\/li>\n<li><p><strong>Real-Time Multi-Channel Security Alerts<\/strong>:<\/p>\n\n<ul>\n<li>Dispatches instant security incident notifications via Slack, Discord, Email, or SIEM webhooks.<\/li>\n<li>Anti-flood rate limiting prevents alert fatigue while ensuring critical alerts pass through.<\/li>\n<\/ul><\/li>\n<li><p><strong>Security Fleet Profile Export &amp; Import<\/strong>:<\/p>\n\n<ul>\n<li>Standardize security policies across client and staging sites using portable JSON profiles.<\/li>\n<li>Automatic pre-import rollback snapshots protect against configuration errors.<\/li>\n<\/ul><\/li>\n<li><p><strong>Database Security Hardening &amp; Hygiene<\/strong>:<\/p>\n\n<ul>\n<li>Audits user accounts for rogue administrators and disposable email domains.<\/li>\n<li>Scans database tables for obfuscated payloads, script injections, and unhygienic transient overhead.<\/li>\n<\/ul><\/li>\n<\/ol>\n\n<h3>Shortcodes<\/h3>\n\n<ul>\n<li><code>[pb4host_security_2fa_status]<\/code> - Optional shortcode to display current 2FA activation status to logged-in users.<\/li>\n<\/ul>\n\n<h3>WP-CLI Commands<\/h3>\n\n<ul>\n<li><code>wp pb4host-security scan [--scope=&lt;all|core|plugins|themes|uploads&gt;]<\/code> - Run automated malware scan.<\/li>\n<li><code>wp pb4host-security waf-status [--mode=&lt;protect|monitor&gt;]<\/code> - View or update WAF settings.<\/li>\n<li><code>wp pb4host-security block-ip &lt;ip&gt;<\/code> - Add IP to WAF blacklist.<\/li>\n<li><code>wp pb4host-security unblock-ip &lt;ip&gt;<\/code> - Remove IP from blacklist and release active lockouts.<\/li>\n<li><code>wp pb4host-security lockouts [--clear]<\/code> - List or clear active login lockouts.<\/li>\n<li><code>wp pb4host-security audit-log [--limit=20] [--event=&lt;event&gt;]<\/code> - View recent audit logs.<\/li>\n<li><code>wp pb4host-security vuln-scan [--format=&lt;table|json|csv&gt;]<\/code> - Inspect core, plugins, and themes for known CVE vulnerabilities.<\/li>\n<li><code>wp pb4host-security sessions &lt;list|revoke|force-logout-all&gt; [--user=&lt;user&gt;]<\/code> - Inspect or remotely terminate user sessions.<\/li>\n<li><code>wp pb4host-security checksums &lt;core|plugins|rogue&gt; [&lt;plugin&gt;]<\/code> - Verify core &amp; plugin files against official WordPress.org checksums.<\/li>\n<li><code>wp pb4host-security fim &lt;status|check|accept&gt;<\/code> - Manage File Integrity Monitoring baseline snapshots and differential audits.<\/li>\n<li><code>wp pb4host-security vpatch &lt;status|list|toggle&gt; [&lt;patch_id&gt;] [--enable|--disable]<\/code> - Manage Targeted Virtual Patching (vPatch) micro-rules and exploit shields.<\/li>\n<li><code>wp pb4host-security alerts &lt;status|test|configure&gt; [--channel=&lt;all|email|slack|discord|webhook&gt;]<\/code> - Manage multi-channel security alerts, test notification channels, and configure SIEM webhooks.<\/li>\n<li><code>wp pb4host-security config &lt;presets|apply-preset|export|import|backups&gt; [...]<\/code> - Export\/import fleet configurations, deploy preset profiles, and manage rollback snapshots.<\/li>\n<li><code>wp pb4host-security db &lt;posture|check-admins|trust-admin|demote-admin|scan|clean-threat&gt; [...]<\/code> - Database security hardening, rogue administrator auditing, and payload disinfection.<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>PB4Host Security may optionally connect to third-party external services only when explicitly enabled and configured by the website administrator. Under WordPress.org Privacy Guidelines 7 &amp; 9, all remote service calls are strictly optional, turned OFF by default, and never phone home without explicit administrator opt-in consent:<\/p>\n\n<ul>\n<li><p><strong>Offline Privacy Notice<\/strong>:<\/p>\n\n<ul>\n<li>The Community Threat Intelligence IP list, Disposable Email Domain blocker, and Pingback\/Trackback verification operate 100% offline using locally bundled curated databases. They make zero external HTTP requests, phone home to no remote servers, and transmit no data whatsoever.<\/li>\n<\/ul><\/li>\n<li><p><strong>WPVulnerability API<\/strong><\/p>\n\n<ul>\n<li>Service URL: https:\/\/www.wpvulnerability.net<\/li>\n<li>Purpose: Checks installed WordPress core, plugins, and themes against known CVE security advisories and CVSS vulnerability scores.<\/li>\n<li>What Data is Sent and When: Transmits only plugin and theme directory slugs and installed version numbers (e.g. <code>plugin\/woocommerce<\/code>, <code>9.0.0<\/code>). No site URLs, visitor data, IP addresses, or personal information are ever transmitted.<\/li>\n<li>Opt-In Requirement: 100% optional and disabled by default (<code>vuln_scanner_remote_api = 0<\/code>). Only executes when an administrator explicitly opts in via settings or manually triggers a vulnerability scan.<\/li>\n<li>Terms of Service: https:\/\/www.wpvulnerability.com\/license\/<\/li>\n<li>Legal Notice: https:\/\/www.robotstxt.es\/legal\/<\/li>\n<li>Privacy Policy: https:\/\/www.wpvulnerability.com\/privacy\/<\/li>\n<\/ul><\/li>\n<li><p><strong>Country.is Geolocation API<\/strong><\/p>\n\n<ul>\n<li>Service URL: https:\/\/api.country.is<\/li>\n<li>Purpose: Resolves client IP addresses to 2-letter ISO country codes for GeoIP and country-based firewall blocking when native web server \/ reverse-proxy headers (such as Cloudflare <code>CF-IPCountry<\/code>, Cloudfront, or Fastly) are unavailable.<\/li>\n<li>What Data is Sent and When: Transmits the client IP address to resolve country code. Results are cached locally in WordPress transients for 7 days to eliminate redundant lookups.<\/li>\n<li>Opt-In Requirement: 100% optional and disabled by default (<code>geoip_enabled = 0<\/code>). Only queries Country.is if the administrator enables GeoIP blocking in settings.<\/li>\n<li>Terms of Service &amp; Privacy Policy: https:\/\/country.is\/<\/li>\n<\/ul><\/li>\n<li><p><strong>Cloudflare Turnstile<\/strong><\/p>\n\n<ul>\n<li>Service URL: https:\/\/challenges.cloudflare.com<\/li>\n<li>Purpose: Frictionless bot mitigation and human verification for login, registration, lost password, and comment forms.<\/li>\n<li>What Data is Sent and When: Client IP address, browser User-Agent, and the client-side challenge token are sent to Cloudflare during form submission for cryptographic token verification.<\/li>\n<li>Opt-In Requirement: 100% optional and disabled by default. Requires the site administrator to obtain and configure Turnstile API Site Key and Secret Key.<\/li>\n<li>Terms of Service: https:\/\/www.cloudflare.com\/terms\/<\/li>\n<li>Privacy Policy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<\/ul><\/li>\n<li><p><strong>Google reCAPTCHA (v2 \/ v3)<\/strong><\/p>\n\n<ul>\n<li>Service URL: https:\/\/www.google.com\/recaptcha\/api\/siteverify<\/li>\n<li>Purpose: Bot defense and human verification on public forms.<\/li>\n<li>What Data is Sent and When: Client IP address, browser User-Agent, and response token are transmitted to Google upon form submission for verification.<\/li>\n<li>Opt-In Requirement: 100% optional and disabled by default. Requires the site administrator to configure reCAPTCHA Site Key and Secret Key.<\/li>\n<li>Terms of Service: https:\/\/policies.google.com\/terms<\/li>\n<li>Privacy Policy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul><\/li>\n<li><p><strong>HaveIBeenPwned API (Troy Hunt)<\/strong><\/p>\n\n<ul>\n<li>Service URL: https:\/\/haveibeenpwned.com<\/li>\n<li>Purpose: Checking candidate passwords during user registration or password reset against known breached credential dumps.<\/li>\n<li>What Data is Sent and When: Utilizes a privacy-preserving k-Anonymity mathematical model. Transmits ONLY the first 5 characters of the SHA-1 hash of the candidate password. Raw passwords, usernames, site URLs, and user accounts are never sent over the network.<\/li>\n<li>Opt-In Requirement: 100% optional and disabled by default (<code>pw_check_hibp = 0<\/code>). Only executed if an administrator explicitly enables \"Check candidate passwords against HaveIBeenPwned\" in Login Security settings.<\/li>\n<li>Terms of Service: https:\/\/haveibeenpwned.com\/API\/v3#AcceptableUse<\/li>\n<li>Privacy Policy: https:\/\/haveibeenpwned.com\/Privacy<\/li>\n<\/ul><\/li>\n<li><p><strong>WordPress.org Checksums &amp; SVN API<\/strong><\/p>\n\n<ul>\n<li>Service URL: https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/li>\n<li>Purpose: Compares local WordPress core and repository plugin files against official cryptographic hashes published by WordPress.org to detect altered files or backdoors.<\/li>\n<li>What Data is Sent and When: WordPress core version and installed plugin slugs\/versions. Runs only when an administrator manually triggers core or plugin checksum verification.<\/li>\n<li>Privacy Policy: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul><\/li>\n<li><p><strong>External Notification Webhooks (Slack, Discord, Custom SIEM)<\/strong><\/p>\n\n<ul>\n<li>Service URL: Configured by administrator (e.g., https:\/\/hooks.slack.com, https:\/\/discord.com, or custom SIEM HTTPS endpoint).<\/li>\n<li>Purpose: Dispatches real-time security incident alerts to the administrator's chosen notification channel.<\/li>\n<li>What Data is Sent and When: Incident event title, severity level, timestamp, site URL, and incident description. Runs only when configured and enabled by the site administrator.<\/li>\n<\/ul><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>pb4host-security<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install via the WordPress Plugins screen.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress.<\/li>\n<li>Navigate to <strong>PB4Host Security<\/strong> in the WordPress admin menu to review your security score and configure your firewall rules.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20pb4host%20security%20slow%20down%20my%20website%3F\"><h3>Does PB4Host Security slow down my website?<\/h3><\/dt>\n<dd><p>No. PB4Host Security is designed to be lightweight, utilizing compiled regex patterns, transient caching, and memory-safe chunked scanning to minimize performance impact on your website.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20get%20locked%20out%3F\"><h3>What happens if I get locked out?<\/h3><\/dt>\n<dd><p>If your IP is locked out due to failed attempts, you can wait for the lockout duration (default 30 mins) or run <code>wp pb4host-security lockouts --clear<\/code> via SSH \/ WP-CLI.<\/p><\/dd>\n<dt id=\"does%20the%20two-factor%20authentication%20require%20internet%20connectivity%3F\"><h3>Does the Two-Factor Authentication require internet connectivity?<\/h3><\/dt>\n<dd><p>No. The TOTP algorithm runs completely offline on your server using standard math and time calculations.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Feature: Added Live Threat IP Activity &amp; Real-Time Intelligence Stream to Security Analytics dashboard.<\/li>\n<li>Performance: Zero-CPU Server Conservation Mode automatically halts background polling when tabs are inactive or when polling is disabled.<\/li>\n<li>Improvement: Resilient in-place Settings &amp; CPU panel toggle with instant inline script fallback, active chevron feedback, and direct Hardening settings link.<\/li>\n<li>Fix: Add default variable initialization in Scheduled WP-Cron Tasks &amp; Backdoor Hunter.<\/li>\n<li>Fix: Removed inline scripts and ensured all assets adhere to standard wp_enqueue_script and wp_enqueue_style APIs.<\/li>\n<li>Fix: Harmonized all internal symbols, REST routes, CLI commands, and hooks to canonical 'pb4host_' prefixes (&gt;= 4 characters) to resolve WordPress.org review requirements.<\/li>\n<li>Fix: Updated Author URI and License URI to ensure robust availability during automated checks.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Release: Standardized plugin directory naming and text domain across all components to 'pb4host-security'.<\/li>\n<li>Performance: Enhanced WAF fast-drop Nginx compilation and pre-bootstrap early cache sync.<\/li>\n<li>Packaging: Resolved WordPress.org Plugin Check validations and cleaned production archive structures.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Fix: Ensure all external third-party calls (WPVulnerability API, HaveIBeenPwned) are disabled by default and require explicit administrator opt-in consent per Guidelines 7 &amp; 9.<\/li>\n<li>Fix: Converted Community Threat Intelligence Feed, Disposable Email Domain blocking, and Pingback\/Trackback verification to 100% local offline processing, removing all undocumented network requests.<\/li>\n<li>Fix: Standardize text domain to 'pb4host-security' matching the approved WordPress.org plugin directory slug.<\/li>\n<li>Fix: Removed waf-bootstrap.php to eliminate inline CSS styles and ensure proper script\/style enqueuing.<\/li>\n<li>Fix: Resolve filesystem locations strictly using WordPress directory API helpers (get_home_path(), plugin_dir_path(), wp_upload_dir()) avoiding hardcoded paths.<\/li>\n<li>Fix: Restrict WP-CLI configuration exports strictly to the plugin's uploads directory.<\/li>\n<li>Fix: Enforce nonce verification on WAF self-unblock actions.<\/li>\n<li>Fix: Ensure all function, class, transient, option, and hook prefixes meet or exceed the 4-character requirement (pb4host_ \/ pb4host_security_).<\/li>\n<li>Fix: Add explicit direct-access checks (defined('ABSPATH') || exit) across all PHP files.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Fix: Standardize all internal translation text domains to 'pb4host-security' in compliance with WordPress Plugin Guidelines.<\/li>\n<li>Fix: Add missing translator context comments for localized strings containing format placeholders.<\/li>\n<li>Fix: Ensure strict output escaping on dynamic parameters in two-factor administrative screens and database audit logs.<\/li>\n<li>Fix: Sanitize and unslash administrative navigation input variables.<\/li>\n<li>Improvement: Modernize translation loading in accordance with WordPress 4.6+ automatic core language pack standard.<\/li>\n<li>Hardening: Strengthen input sanitization and unslashing on trusted device cookies.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Security and performance hardening patch.<\/li>\n<li>Added multi-tier GeoIP resolution and country-level filtering.<\/li>\n<li>Enhanced WAF pre-execution packet gating.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release of PB4Host Security.<\/li>\n<li>Web Application Firewall (WAF) with SQLi, XSS, LFI, RCE, and bad bot threat inspection.<\/li>\n<li>Active heuristic malware scanner with uploads folder enforcement and quarantine vault.<\/li>\n<li>Brute force defense with IP lockouts and honeypot username traps.<\/li>\n<li>RFC 6238 Two-Factor Authentication (2FA \/ TOTP) with role enforcement.<\/li>\n<li>System hardening: XML-RPC disabler, REST API user enumeration lock, uploads execution guard, and security HTTP headers.<\/li>\n<li>Real-time security audit log with 30-day auto-prune and CSV export.<\/li>\n<li>Frictionless Bot Defense Engine supporting Cloudflare Turnstile &amp; Google reCAPTCHA v3\/v2 with fail-open network resilience.<\/li>\n<li>Known Plugin, Theme &amp; Core CVE Vulnerability Scanner with dual-layer offline\/online intelligence.<\/li>\n<li>Compromised Passwords (HaveIBeenPwned k-Anonymity API) &amp; Password Policy Engine.<\/li>\n<li>GeoIP &amp; Country Blocking Extension with multi-tier resolution, whitelist\/blacklist modes, and fail-safe private IP immunity.<\/li>\n<li>User Session Manager &amp; Remote Device Termination with idle auto-logout, concurrent session caps, and emergency containment.<\/li>\n<li>Automated Community Threat Intelligence IP Feed with dynamic WP-Cron sync, offline seed defense, and fast O(1) pre-execution packet gating.<\/li>\n<li>Official WordPress.org Core &amp; Plugin Checksum Integrity Verification engine.<\/li>\n<li>File Integrity Monitoring (FIM) &amp; Filesystem Snapshot Engine with SHA-256 differential auditing.<\/li>\n<li>Targeted Virtual Patching (vPatch) Engine with early WAF interception (priority 4), curated high-impact CVE micro-rules, and dual auto\/proactive modes.<\/li>\n<li>Multi-Channel Real-Time Security Alerts &amp; Webhook Notifications Engine (Slack Block Kit, Discord Embeds, HTML Email, and SIEM HMAC-SHA256 Webhooks).<\/li>\n<li>Security Fleet Profile Export\/Import &amp; Hosting Standardization Engine with SHA-256 integrity verification, secret scrubbing, automatic rollback snapshots, and curated profiles (High Security, WooCommerce, VPS).<\/li>\n<li>Database Security Hardening &amp; Rogue Admin Audit Engine with covert administrator account detection, disposable email flagging, options\/posts malware payload scanning, MySQL privilege audit, and 1-click remediation.<\/li>\n<li>Complete WP-CLI CLI command suite.<\/li>\n<\/ul>","raw_excerpt":"Enterprise Security Suite for WordPress: Web Application Firewall (WAF), Active Malware Scanner, Brute-Force Defense, 2FA, and System Hardening.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/366863","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=366863"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/pbkrishnagmailcom"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=366863"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=366863"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=366863"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=366863"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=366863"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=366863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}