plugin-icon

PW Security and Backup

Security monitoring, login protection, file integrity checks, protected backups, and read-only comparison in one panel.
Versione
3.1.11
Ultimo aggiornamento
Aug 2, 2026

PW Security and Backup brings practical WordPress security and backup tools into one administration panel.

Main features:

  • Login attempt limiting and temporary IP bans.
  • Optional custom login path, additional password, and challenge question.
  • WordPress hardening controls with rollback support.
  • Suspicious-code scanning for WordPress files.
  • SHA-256 file integrity baselines and chunked site-directory monitoring.
  • Email notifications for administrator login, file changes, and IP bans.
  • WordPress site-file and database backups in ZIP format, excluding authentication secrets and environment configuration files.
  • Read-only backup comparison without overwriting or deleting WordPress core, theme, or plugin files.
  • Security logs, traffic records, and a security analysis report.
  • Translation-ready English source interface for translate.wordpress.org.

Login-path hiding and live traffic recording are disabled by default. They can be enabled after the administrator reviews the related settings and confirms that the hosting or proxy configuration is compatible.

The plugin does not require a license key, send telemetry, or load remote scripts. Email notifications are sent through the WordPress mail system to the configured address when enabled.

Important: WordPress scheduled events depend on site traffic unless the hosting provider runs a real server cron. FTP changes are reported after a complete scheduled integrity scan finishes.

Privacy

The plugin does not send telemetry, scan results, traffic records, credentials, or backup contents to PW Feed or another external service.

Security logs may store an IP address, WordPress username, event time, and event description. When live traffic recording is explicitly enabled, the plugin locally stores a limited rolling set of request paths, IP addresses, request methods, referrers, and user-agent strings. Administrators can clear these records from the plugin screens. The configured retention period applies to security logs.

Quarantined files and their local metadata are stored below the WordPress uploads directory in the plugin-specific pw-security-and-backup storage directory. The quarantine directory has a random component and access-blocking files. Quarantine data is not sent to an external service.

Email notifications are sent through the site’s WordPress mail configuration to the address selected by the administrator. Backups can contain personal and sensitive site data because they include site files and database tables. WordPress authentication configuration files, including wp-config.php and environment files, are excluded. Backup archives are placed below the WordPress uploads directory in the plugin-specific pw-security-and-backup storage directory with a random component and access-blocking files. Archives are downloaded through a capability- and nonce-protected administration action. Server-level access rules should also protect the uploads directory on hosting configurations that do not honor Apache or IIS access files.

More Information

For more information, documentation, and product updates, visit PW WordPress Plugin. Turkish-language information is available at PW WordPress Plugin Türkiye.

Gratuitosui piani a pagamento
Testato fino alla versione
WordPress 7.0.2
Questo plugin ora può essere scaricato per il tuo sito .