Locktura Security
Locktura Security helps WordPress administrators manage core site protection from one plugin. This WordPress.org package includes 18 modules for firewall rules, login protection, anti-spam, hardening, update visibility, file checks, traffic review, logging, alerts, and privacy controls.
Most protection runs locally inside WordPress. Enable only the modules you need, review local events, and manage common security tasks from one dashboard.
Included in this plugin
- Firewall – Blocks suspicious requests with bundled community rules and request analysis.
- Page Cache Compatibility – Provides Strict protection or Cache-compatible public caching, with detection for commonly used cache plugins.
- Brute Force Defense – Limits repeated failed login attempts and manages temporary bans.
- Hardening – Reduces common WordPress attack surfaces such as enumeration, file editing, XML-RPC abuse, and direct exposure of sensitive server files.
- Update Manager – Reviews WordPress core, plugin, and theme updates and stores local update history.
- Access Control – Manages allowed, excluded, and blocked IP access controls.
- Geo Block – Blocks configured countries using geolocation data for public IP addresses.
- Hide Login – Replaces default login and admin entry points with a custom slug.
- Anti-Spam Shield – Combines CAPTCHA challenges with spam-prevention controls for login, comments, and custom forms.
- Usernames & 2FA – Reviews unsafe usernames, recent users, and per-user 2FA status.
- Password Manager – Adds password policy checks, forced reset workflows, and password risk visibility.
- Email Alerts – Sends security notifications for important events.
- Security Logs – Stores local security events and firewall activity for review.
- Live Traffic – Shows recent request activity with optional geolocation details.
- User Log – Tracks user activity for audit and review.
- File Scanner – Scans files for suspicious patterns and includes file integrity monitoring.
- File Permissions – Checks risky file and directory permissions.
- SSL Control – Helps enforce HTTPS and SSL-related protection.
- Email Encoder – Obfuscates public email addresses against scraping.
Hardening module options
- User Enumeration
- Disable Theme/Plugin Editor
- Privilege Escalation
- XML-RPC Shield
- Secure wp-admin, wp-includes & wp-config.php
- Disable Directory Browsing
- Disable RSS Feeds
- Prevent Image Hotlinking
- Server Exposure Protection
Separate Premium plugin
Locktura Premium is a separately distributed plugin and is not included in this WordPress.org package. All functionality described above is included in this WordPress.org plugin.
The separate Premium plugin adds these additional modules:
- Pattern Recognition
- Behavior Analytics
- Admin Lockdown
- Virtual Patching
- Header Hardening
- API Guardian
- Neural Bot Suppressor
- Malware Scanner & Cleanup
- Smart 404
- Extra Hardening Tools
- Monthly Reports
- Extra User Safety Tools
- Premium Signature Pack
Privacy
Locktura Security stores security data locally, including IP addresses, request and login details, usernames, events, alert settings, password-policy and 2FA status, scan history, and update history. Optional Geo-IP and password-breach checks use the services documented below. Administrators control retention, recipients, lookup use, and privacy settings.
External services
Locktura Security loads no scripts, styles, fonts, or images from third parties. It makes only the requests documented below when the related feature is enabled or used.
WordPress.org and extension update providers
Used for core, plugin, and theme update checks and downloads through api.wordpress.org, downloads.wordpress.org, plugins.svn.wordpress.org, themes.svn.wordpress.org, and update endpoints declared by installed extensions. Requests occur when an administrator uses Update Manager or WordPress performs scheduled checks. WordPress can send the site URL, core/PHP/MySQL versions, locale, and installed extension metadata. Completed update history is stored locally.
Documentation: https://developer.wordpress.org/apis/handbook/wordpress-org/update-api/ Policies: https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/ and https://wordpress.org/about/license/ Privacy: https://wordpress.org/about/privacy/
Have I Been Pwned Pwned Passwords
Used for optional password-breach checks through https://api.pwnedpasswords.com/range/{first5-sha1}. When enabled and a password is evaluated, Locktura sends only the first five characters of its SHA-1 hash, never the password or complete hash. Responses are cached locally for 24 hours.
Documentation: https://haveibeenpwned.com/API/v3#PwnedPasswords Terms: https://haveibeenpwned.com/TermsOfUse Privacy: https://haveibeenpwned.com/Privacy
Country / country.is
Used as the primary country lookup at https://api.country.is/{ip}. When an enabled geolocation feature needs uncached data and no trusted country header exists, Locktura sends the public IP being looked up. Results can be cached locally for 24 hours. Country states that it does not log requests.
Documentation, terms, and privacy: https://country.is/ Source and self-hosting information: https://github.com/lineofflight/country
IPWhois / ipwho.is
Used at https://ipwho.is/{ip} as a geolocation fallback when Country returns no usable data. When an enabled feature needs uncached location data, Locktura sends the public IP being looked up. Results can be cached locally for 24 hours.
Documentation: https://ipwhois.io/documentation Terms: https://ipwhois.io/terms Privacy: https://ipwhois.io/privacy
ipapi.co
Used at https://ipapi.co/{ip}/json/ as the final geolocation fallback when Country and IPWhois return no usable data. When an enabled feature needs uncached location data, Locktura sends the public IP being looked up. Results can be cached locally for 24 hours.
Documentation: https://ipapi.co/api/ Terms: https://ipapi.co/terms/ Privacy: https://ipapi.co/privacy/
Own-site HTTPS and TLS checks
Used to verify the HTTPS response and certificate of the site’s configured home_url() or site_url(). When an administrator runs SSL Control, a HEAD request or TLS handshake sends ordinary network metadata and a Locktura user-agent to the site’s own host. No security log is sent. The site’s and hosting provider’s terms and privacy policies apply; Locktura selects no third party.
Site-configured email delivery
Used for enabled security alerts and administrator-requested tests. Messages can contain the recipient, site URL, event type, timestamp, IP address, relevant request or account context, and remediation links. WordPress uses the site’s configured mail transport. Any mail provider processes messages under the site owner’s agreement and policies; Locktura selects no provider. Related events can remain in local Security Logs.
Locktura website links
Links under https://locktura.com/ provide documentation, plugin and Premium information, and support. They open only after an administrator clicks them; there are no background calls. The browser sends ordinary IP address, user-agent, and referrer data. Locktura appends no logs, settings, or license data.
Terms: https://locktura.com/terms-and-conditions/ Privacy: https://locktura.com/privacy-policy/
Translations
Locktura Security includes a Dutch translation (nl_NL).
Bundled assets
All assets are bundled locally. Flag Icons and QRCode for JavaScript use the MIT License; Inter and Bebas Neue use the SIL Open Font License 1.1. Their license files are included under assets/. The modified Wikimedia Commons world map is public domain with details in assets/images/world-map.SOURCE.txt. Locktura artwork uses the plugin’s GPLv2-or-later license.
