plugin-icon

WordSec – Malware Scanner & Removal, Web Application Firewall (WAF), and 2FA

Door WordSec·
WordPress security plugin with firewall, malware scanner, and login protection. Block attacks and scan for malware from one dashboard.
Beoordelingen
5
Versie
1.1.0
Laatst bijgewerkt
Aug 1, 2026
WordSec – Malware Scanner & Removal, Web Application Firewall (WAF), and 2FA

WordSec is a complete WordPress security plugin. Eight modules cover the firewall, malware scanner, login security, live traffic, IP and country blocking, supply-chain intelligence, audit log and alerts, so you block attacks and harden your site from one dashboard instead of installing eight plugins.

If your site gets hacked you do not just lose the site. You lose customer trust, your search rankings, and days of work restoring backups. WordSec is built to stop that before it happens, and to help you recover if it already has: the scanner finds the malware, quarantine takes it out of the way, and modified core, plugin and theme files are repaired from their original copies.

Free, and no license key to enter. WAF firewall rules, malware and file-integrity scanning, brute force protection, two factor authentication, IP and country blocking, the audit log and one-click hardening all run locally on your own server.

Web Application Firewall (WAF)

  • Custom rule builder with regex and wildcard matching
  • Built-in rules for SQL injection, XSS, path traversal, PHP and command injection
  • Learning and active modes, bot blocking, security headers, rate limiting
  • 25+ hardening toggles for wp-config access, author enumeration and REST API
  • Optional Extended Protection: pre-WordPress request inspection (opt-in, fully reversible)

Malware Scanner and Removal

  • Malware detection rules across files, the database and scheduled tasks
  • Core, plugin and theme file-integrity verification via the WordPress.org API
  • Scheduled scans, one-click quarantine and restore
  • Malware removal on a hacked site: quarantine a finding, or repair a modified core, plugin or theme file from its original copy

Login Security, Two-Factor Authentication (2FA) and Brute Force Protection

  • Role-based two-factor authentication (RFC 6238 TOTP)
  • reCAPTCHA, hCaptcha and Cloudflare Turnstile, plus a built-in math CAPTCHA
  • Brute-force protection with progressive lockout, honeypot and login URL rename
  • Leaked-password checking, session management, custom login page

Live verkeer

  • Real-time request logging with bot detection and CSV export
  • Exclusion filtering by role, IP, country or URI

IP and Country Blocking

  • Country and continent allow or block lists
  • IP and CIDR blocking, temporary or permanent, with allow-list support

Supply Chain and Threat Intelligence

  • Reputation scoring and abandoned-plugin detection
  • Known-vulnerability alerts for core, plugins, themes and PHP
  • Update-integrity verification with backups and an SBOM inventory

Audit Log

  • Activity tracking across 11 object types and 14 actions

Alarms

  • 36 alert event types delivered by Email, Telegram or Slack

Every feature runs locally with no license key. Optionally, the WordSec service at wordsec.net supplies threat-intelligence data that cannot be produced locally: managed WAF rule sets, the malware signature feed, IP-reputation lists, the GeoIP database and vulnerability records. Connecting is optional and every external service is documented in “External services” below.

Externe diensten

WordSec is designed to run locally, and with no license key it makes no outbound requests to the WordSec service. Core request filtering and file scanning run on your server. The services listed below are contacted only for the specific features described, and most of them only when you explicitly enable that feature (or, for the WordSec API, only after you activate a license key). This section documents every third-party service the plugin can connect to and the data each one receives.

WordSec API (api.wordsec.net)

WordSec runs free without a license, in which case it does not contact this service at all. A free license is available to everyone; once you activate a key the plugin communicates with the WordSec service for two distinct purposes:

  1. Required service calls (only while a license key is active): license activation and validation, and threat-data updates (firewall rules, malware signatures, IP reputation lists, GeoIP data, the disposable-email domain list and known-vulnerability data). These enable the cloud-backed features and cannot be performed locally; with no key, none of these calls are made. The local enforcement code for these features (the WAF engine, the malware scanner, the IP-blocking filters and the signup-restriction filter) is always present and active; without an up-to-date feed it simply has no threat-intelligence data to check requests against.

* When: on activation/validation and on scheduled threat-data update checks. * Data sent: your site URL and license key (used to authenticate you and bind the license to this site) and, for update checks, the current versions of your installed threat-data feeds.

  1. Optional usage/environment telemetry (OPT-IN, OFF by default): an anonymous once-daily snapshot used to improve WordSec. It is only sent after you explicitly enable “Share usage & environment data” (at license activation or in Settings Advanced Usage Data) and can be turned off again at any time.

* Wanneer: eenmaal per dag, alleen zolang de opt-in is ingeschakeld. * Verzonden gegevens: een niet-persoonlijke momentopname van de siteomgeving (server-, WordPress-, PHP- en databaseversies, de lijst met actieve plugins en thema’s) en geaggregeerde statistieken over WordSec-functiegebruik en beveiliging. Er worden nooit wachtwoorden, databasegegevens, geheime sleutels of e-mailadressen verzonden.

  • Dienstvoorwaarden: https://wordsec.net/terms
  • Privacybeleid: https://wordsec.net/privacy

Have I Been Pawned (api.pwnedpasswords.com)

Used by the optional leaked-password check to detect whether a password appears in known data breaches, using k-anonymity. * When: when a user sets or submits a password and the leaked-password check is enabled. * Data sent: only the first 5 characters of the SHA-1 hash of the password. The password itself and its full hash never leave your site. * Terms & Privacy: https://haveibeenpwned.com/Privacy

WordPress.org API (api.wordpress.org, downloads.wordpress.org, wordpress.org, core.svn.wordpress.org, plugins.svn.wordpress.org, themes.svn.wordpress.org)

Used to verify WordPress core, plugin and theme file integrity, to look up public plugin/theme information (plugins_api/themes_api) for the supply-chain reputation scores and update-integrity checks, to download WordSec’s own translation language pack from translate.wordpress.org when you pick a Display Language that is not installed yet (the same mechanism WordPress itself uses when the site language changes), and — only when you click “Repair” on a scanner finding — to download the original copy of a modified core/plugin/theme file so it can be restored. Repair downloads fetch single original files from plugins.svn.wordpress.org / themes.svn.wordpress.org / core.svn.wordpress.org, falling back to full packages from downloads.wordpress.org (plugin/theme zips) and wordpress.org (core release zips). * When: during malware/integrity scans and supply-chain reputation checks, on an explicit repair action, and when you save a Display Language whose translation is not installed yet. * Data sent: the WordPress core version, site locale, and the slugs/versions of the plugins/themes being checked; for a language download, the plugin slug/version and the chosen locale. * Terms & Privacy: https://wordpress.org/about/privacy/

RDAP (rdap.org)

Used by the WHOIS/RDAP lookup tool on the Tools page to show ownership information for an IP address or domain you inspect. * When: only when you run the WHOIS/RDAP lookup tool. * Data sent: the IP address or domain you chose to look up. * Terms & Privacy: https://about.rdap.org/

ipify (api.ipify.org)

Used by the Tools page blacklist checker and the server-info tool to determine your server’s own public IP address. * When: only when you run the “Blacklist Check” or “Server IPs” tool. * Data sent: a plain request from your server; no site data is included (the service simply echoes the requesting IP). * Terms & Privacy: https://www.ipify.org/

DNS-blokkeerlijstaanbieders (Blokkeerlijst controle tool)

The Tools page “Blacklist Check” queries DNS-based blocklists (DNSBLs) to tell you whether your server’s public IPv4 address is listed. Each provider receives a standard DNS query containing your server’s IP address in reversed form. Five providers are queried: * Spamhaus ZEN (zen.spamhaus.org) – https://www.spamhaus.org/privacy-notice/ * SpamCop (bl.spamcop.net), operated by Cisco – https://www.cisco.com/c/en/us/about/legal/privacy-full.html * Barracuda Reputation Block List (b.barracudacentral.org) – https://www.barracuda.com/company/legal/privacy-policy * UCEPROTECT Level 1 (dnsbl-1.uceprotect.net) – https://www.uceprotect.net/en/index.php * PSBL (psbl.surriel.com) – https://psbl.org/ Details: * When: only when you click “Blacklist Check” on the Tools page. * Data sent: your server’s public IPv4 address, embedded in each DNS blocklist query.

Telegram Bot API (api.telegram.org)

Optional alarm delivery channel. Active only when you configure your own Telegram bot token and chat ID. * When: when a security alarm you enabled fires and Telegram delivery is configured. * Data sent: the alarm message text (event type, site name, relevant IP/user context) to the bot/chat you configured. * Terms of Service: https://telegram.org/tos * Privacy Policy: https://telegram.org/privacy

Slack Incoming Webhooks (hooks.slack.com)

Optional alarm delivery channel. Active only when you configure your own Slack incoming-webhook URL. * When: when a security alarm you enabled fires and Slack delivery is configured. * Data sent: the alarm message text (event type, site name, relevant IP/user context) to the webhook you configured. * Terms of Service: https://slack.com/terms-of-service * Privacy Policy: https://slack.com/privacy-policy

Google reCAPTCHA (www.google.com, www.gstatic.com)

Optional login/registration CAPTCHA. Active only when you select reCAPTCHA and provide your own keys. * When: on login and registration forms while enabled. * Loaded remotely: reCAPTCHA requires its widget script (www.google.com/recaptcha/api.js, served with assets from www.gstatic.com) to be loaded from Google in the visitor’s browser; it is enqueued only on those forms and only while reCAPTCHA is the selected provider. Token verification is a server-side call from your site to www.google.com. * Data sent: the CAPTCHA response token, your public site key, and the visitor’s IP address. * Terms of Service: https://policies.google.com/terms * Privacy Policy: https://policies.google.com/privacy

hCaptcha (hcaptcha.com, js.hcaptcha.com)

Optional login/registration CAPTCHA. Active only when you select hCaptcha and provide your own keys. * When: on login and registration forms while enabled. * Loaded remotely: hCaptcha requires its widget script (js.hcaptcha.com/1/api.js) to be loaded from hCaptcha in the visitor’s browser; it is enqueued only on those forms and only while hCaptcha is the selected provider. Token verification is a server-side call from your site to hcaptcha.com. * Data sent: the CAPTCHA response token, your public site key, and the visitor’s IP address. * Terms of Service: https://www.hcaptcha.com/terms * Privacy Policy: https://www.hcaptcha.com/privacy

Cloudflare Turnstile (challenges.cloudflare.com)

Optional login/registration CAPTCHA. Active only when you select Turnstile and provide your own keys. * When: on login and registration forms while enabled. * Loaded remotely: Turnstile requires its widget script (challenges.cloudflare.com/turnstile/v0/api.js) to be loaded from Cloudflare in the visitor’s browser; it is enqueued only on those forms and only while Turnstile is the selected provider. Token verification is a server-side call from your site to challenges.cloudflare.com. * Data sent: the CAPTCHA response token, your public site key, and the visitor’s IP address. * Terms of Service: https://www.cloudflare.com/website-terms/ * Privacy Policy: https://www.cloudflare.com/privacypolicy/

ipwhois.io (ipwho.is)

Optional IP details service, disabled by default. All requests go over HTTPS with certificate verification, and none are made until you enable “External IP Lookup Service” in WordSec Settings (Visitor IP Handling section). It is used for exactly one thing: the “IP details” lookup in Live Traffic (country, region, city, ISP, organization, ASN). Traffic logging never contacts this service; country resolution during logging uses only the local GeoIP database. * When: only while the External IP Lookup Service opt-in is enabled, and only on your click in the IP details lookup. * Data sent: the IP address you chose to inspect. * Terms of Service: https://ipwhois.io/terms * Privacy Policy: https://ipwhois.io/privacy

VirusTotal (virustotal.com)

Not contacted automatically. The scanner shows a “Check on VirusTotal” link you can click to open VirusTotal in your browser for a given file. * When: only when you click the link. * Data sent: the file hash contained in the link URL. * Terms & Privacy: https://docs.virustotal.com/docs/privacy-policy

Qualys SSL Labs (ssllabs.com)

Not contacted automatically. The Tools page “Check SSL Health” test runs entirely on your own server (it opens a TLS connection to your own domain and reads the certificate). Next to it, a “Deep Scan (SSL Labs)” link opens the Qualys SSL Labs test in a new browser tab; SSL Labs then connects to your site from the outside and grades its TLS configuration. The link carries the “hide results” flag, so the report is not published on the SSL Labs public board. * When: only when you click the “Deep Scan (SSL Labs)” link. * Data sent: your site’s domain name, contained in the link URL. * Terms: https://www.ssllabs.com/about/terms.html * Privacy: https://www.qualys.com/company/privacy/

Credits

WordSec bevat de hieronder genoemde bibliotheken van derden. Elke bibliotheek wordt gedistribueerd onder een licentie die compatibel is met de eigen “GPLv2 or later” licentie van WordSec. Elke meegeleverde bibliotheek behoudt zijn licentiebanner in het bestand en/of zijn upstream licentiebestand, en de volledige oorspronkelijke (niet-verkleinde) broncode van elke bibliotheek is beschikbaar bij het gelinkte project en de gelinkte versie.

PHP-bibliotheken (`vendor/`)

TCPDF 6.11.3 * Licentie: LGPL-3.0-or-later * Auteursrecht: Nicola Asuni, Tecnick.com LTD * Bron: https://github.com/tecnickcom/TCPDF * Licentiebestand: vendor/tecnickcom/tcpdf/LICENSE.TXT * Gebruikt voor: genereren van PDF-rapporten/export

SimpleXLSXGen 1.5.x * Licentie: MIT * Auteursrecht: (c) 2020-2022 Sergey Shuchkin * Bron: https://github.com/shuchkin/simplexlsxgen * Licentiebestand: vendor/shuchkin/simplexlsxgen/LICENSE * Gebruikt voor: XLSX (Excel)-export

JavaScript / CSS-bibliotheken (`assets/*/vendor/`)

Select2 4.1.0-rc.0 * Licentie: MIT * Auteursrecht: Kevin Brown, Igor Vaynberg en de Select2-bijdragers * Bron: https://github.com/select2/select2 * Licentietekst: https://github.com/select2/select2/blob/master/LICENSE.md * Meegeleverde bestanden: assets/js/vendor/select2.min.js, assets/css/vendor/select2.min.css

ApexCharts 5.16.0 * Licentie: MIT * Auteursrecht: (c) 2018-2026 ApexCharts * Bron: https://github.com/apexcharts/apexcharts.js * Licentietekst: https://github.com/apexcharts/apexcharts.js/blob/main/LICENSE * Meegeleverde bestanden: assets/js/vendor/apexcharts.min.js

jsVectorMap 1.7.0 * Licentie: MIT * Auteursrecht: (c) Mustafa Omar en de jsVectorMap-bijdragers * Bron: https://github.com/themustafaomar/jsvectormap * Licentietekst: https://github.com/themustafaomar/jsvectormap/blob/master/LICENSE * Meegeleverde bestanden: assets/js/vendor/jsvectormap.min.js, assets/css/vendor/jsvectormap.min.css * Gebruikt voor: wereldkaartvisualisaties (Live verkeer / Blokkeren / Firewall)

Wereldkaartgegevens (world_mill), geregistreerd als de jsVectorMap kaart “world” * Licentie: MIT * Auteursrecht: jvectormap-content-bijdragers; kaartgeometrie afgeleid van Natural Earth (public domain) * Bron: https://www.npmjs.com/package/jvectormap-content * Meegeleverde bestanden: assets/js/vendor/world.js * Gebruikt voor: de landgeometrie die door de bovenstaande wereldkaartvisualisaties wordt weergegeven

qrcode-generator 1.4.4 * Licentie: MIT * Auteursrecht: Kazuhiko Arase * Bron: https://github.com/kazuhikoarase/qrcode-generator * Licentietekst: https://github.com/kazuhikoarase/qrcode-generator/blob/master/LICENSE * Meegeleverde bestanden: assets/js/vendor/qrcode.min.js

Iconen / assets

flag-icons (country flag SVGs) * License: MIT (SVG markup); the flag designs themselves are in the public domain * Copyright: (c) 2013 Panayiotis Lipiridis * Source: https://github.com/lipis/flag-icons * License text: https://github.com/lipis/flag-icons/blob/main/LICENSE * Bundled files: assets/images/flags/*.svg (country flags, 4×3 viewBox="0 0 640 480")

Gratisvoor betaalde abonnementen
Door te installeren, ga je akkoord met de Servicevoorwaarden van WordPress.com en de voorwaarden voor plugins van derden.
Getest tot
WordPress 7.0.2
Deze plugin kan worden gedownload, zodat je hem op je kan gebruiken.