Assist Security
·
Rotate your WordPress security keys and salts safely, with verified atomic writes, key health checks, and a full audit trail.
WordPress signs every login cookie and nonce with eight secret keys and salts stored in wp-config.php (AUTH_KEY through NONCE_SALT). If those secrets leak — through an old backup, a stolen config file, or a contractor who still has access — an attacker can forge valid authentication cookies for as long as the keys stay unchanged. Rotating them invalidates every existing session immediately.
Assist Security makes that rotation safe, automatic, and auditable.
🔑 Rotate Security Keys
- One-click rotation from a clean, colorful settings screen
- Locally generated keys using PHP’s cryptographically secure random number generator. No calls to any external API, no network dependency
- Verified atomic writes. The new configuration is built in memory, written to a temporary file with restricted permissions, verified, atomically swapped in, then verified again — with automatic rollback if any step fails. The writer refuses to touch your file unless all eight keys are found, so a partial rotation is impossible
- Key health checks for missing, weak, duplicated, or placeholder keys. Only the verdict is ever shown; your key values never leave the server
- Audit log recording every attempt: timestamp, result, trigger, user, optional IP, duration, and how many sessions were signed out — with filtering, pagination, and CSV export
- Failure alerts emailed to the site administrator if a rotation ever fails
- Site Health test that flags key problems and keys older than 180 days
- WP-CLI commands —
wp assist-security rotateandwp assist-security status - Custom config locations supported:
wp-salt.php, awp-config.phpabove the web root, or any path you choose with a filter
Built the right way
- Beautiful, responsive settings screen with no page reloads and no build step
- REST API under
assist-security/v1; no admin-ajax - No bundled SDKs, no Composer dependencies, no external HTTP requests, no telemetry
- Every input sanitized, every output escaped, every query prepared
- Multisite aware: management is restricted to network administrators
- Privacy-conscious: IP logging is optional and data removal on uninstall is opt-in
- Settings import and export as JSON
- Fully translatable, with a bundled POT file
Assist Security is built on a module architecture, so further protections can be added as self-contained modules in future releases.