plugin-icon

Assist Security

Rotate your WordPress security keys and salts safely, with verified atomic writes, key health checks, and a full audit trail.
Version
0.1.2
Zuletzt aktualisiert
Aug 6, 2026

WordPress signs every login cookie and nonce with eight secret keys and salts stored in wp-config.php (AUTH_KEY through NONCE_SALT). If those secrets leak — through an old backup, a stolen config file, or a contractor who still has access — an attacker can forge valid authentication cookies for as long as the keys stay unchanged. Rotating them invalidates every existing session immediately.

Assist Security makes that rotation safe, automatic, and auditable.

🔑 Rotate Security Keys

  • One-click rotation from a clean, colorful settings screen
  • Locally generated keys using PHP’s cryptographically secure random number generator. No calls to any external API, no network dependency
  • Verified atomic writes. The new configuration is built in memory, written to a temporary file with restricted permissions, verified, atomically swapped in, then verified again — with automatic rollback if any step fails. The writer refuses to touch your file unless all eight keys are found, so a partial rotation is impossible
  • Key health checks for missing, weak, duplicated, or placeholder keys. Only the verdict is ever shown; your key values never leave the server
  • Audit log recording every attempt: timestamp, result, trigger, user, optional IP, duration, and how many sessions were signed out — with filtering, pagination, and CSV export
  • Failure alerts emailed to the site administrator if a rotation ever fails
  • Site Health test that flags key problems and keys older than 180 days
  • WP-CLI commandswp assist-security rotate and wp assist-security status
  • Custom config locations supported: wp-salt.php, a wp-config.php above the web root, or any path you choose with a filter

Built the right way

  • Beautiful, responsive settings screen with no page reloads and no build step
  • REST API under assist-security/v1; no admin-ajax
  • No bundled SDKs, no Composer dependencies, no external HTTP requests, no telemetry
  • Every input sanitized, every output escaped, every query prepared
  • Multisite aware: management is restricted to network administrators
  • Privacy-conscious: IP logging is optional and data removal on uninstall is opt-in
  • Settings import and export as JSON
  • Fully translatable, with a bundled POT file

Assist Security is built on a module architecture, so further protections can be added as self-contained modules in future releases.

Kostenlosmit kostenpflichtigen Tarifen
Mit deiner Installation stimmst du den Geschäftsbedingungen von WordPress.com sowie den Bedingungen für Drittanbieter-Plugins zu.
Getestet bis
WordPress 7.0.3
Dieses Plugin steht für deine -Website zum Download zur Verfügung.