plugin-icon

Scudo Security

Totaliweb yazdı·
Environment-aware security: firewall, malware & integrity scan, brute-force protection and 2FA — safety-first, with previews and rollback.
Sürüm
1.1.2
Son güncellenme
Jul 26, 2026
Scudo Security

Scudo Security is designed to harden your site without breaking it. It detects your exact hosting environment and only offers controls that can actually work there — disabling the rest with a clear explanation and a fallback. Every change is previewed, applied reversibly, verified, and rolled back automatically if the verification fails. If you are ever locked out, three independent recovery routes get you back in.

Honest scope. On shared PHP hosting there is no always-on antivirus daemon. Real, continuous protection comes from per-request firewalling, scheduled scans, file-change detection, and access monitoring — not a resident process. Scudo Security is built around prevention and hardening, with reversible quarantine instead of destructive cleanup.

Included for free

  • Web Application Firewall — inspects every request as WordPress boots and blocks SQL-injection, cross-site-scripting, path-traversal and command-injection patterns. Conservative by design, and it always stands down in Safe Mode so it can never be the reason you are locked out.
  • Malware & integrity scan — chunked, resumable scans that compare your WordPress core files against the official WordPress.org checksums and your installed plugins and themes against their official packages, plus a database scan for injected scripts, rogue administrator accounts and malicious scheduled tasks. Self-optimising: the scan automatically right-sizes its workload to your host’s memory and time limits, so it never times out on small hosting and runs faster on powerful servers.
  • Reversible clean-up — quarantine a suspicious file instead of deleting it, or restore a tampered core file from the official WordPress source after a checksum match.
  • Brute-force protection — login-attempt limiting with automatic IP lockouts, plus an invisible CAPTCHA that stops password-guessing bots, and a manual IP block list.
  • Two-factor authentication (TOTP) — self-enrolment with an authenticator app and backup codes.
  • Hardening baseline — applied automatically on activation and fully reversible: the WordPress version is hidden, user enumeration is blocked, the built-in file editor is disabled, the basic security headers are sent, and PHP execution is denied inside your uploads folder. Each change takes a restore point first, verifies itself, and rolls itself back if the verification fails.
  • Security headers (report-only first) and an HTTPS/HSTS check.
  • Security score + dashboard — a transparent, explainable score with real per-day activity charts.
  • Activity log — every sensitive operation and security block, with search and filters.
  • Hide the admin bar for non-administrators.
  • Safe Mode / recovery — three DB-less escape routes if anything goes wrong.

Scudo Security Pro

Pro adds an advanced layer for sites that need more:

  • Custom firewall rules — write your own allow and block rules on top of the built-in engine.
  • GeoIP country blocking (verified against the CDN’s published IP ranges) and advanced per-IP rate limiting.
  • Hide the login page behind a secret URL with bot redirection, and keep non-administrators out of wp-admin entirely.
  • Two-factor enforcement by role — require two-factor for the roles you choose, instead of leaving it to each user.
  • Compromised-password blocking — a k-anonymity check that rejects passwords found in known breaches, sending only the first five characters of a hash.
  • Content-Security-Policy builder — compose and ship a CSP without hand-editing headers.
  • Email alerts and a weekly security report — an administrator-login notice and a weekly digest.
  • Activity-log CSV export — download the filtered log for reporting or an audit.
  • Configuration export and import — move a tuned setup from one site to the next.
  • The optional AI security advisor — reviews your posture and proposes prioritised, validated fixes. Proposals only; nothing is ever applied automatically. Off by default, bring your own API key, with consent and redaction.

The free version is fully functional on its own — Pro only ever adds capability; it never takes protection away, and a lapsed licence never disables the firewall.

External services

Scudo Security contacts external services only for the features below. Each is used solely to deliver that feature; no data is ever sold or shared, and no analytics or tracking SDK is bundled.

WordPress.org core checksums (api.wordpress.org)

What it does: fetches the official WordPress core file checksums. Why: the malware & integrity scan compares your core files against the official checksums to detect tampering. When: when a scan runs (manual or scheduled). Data sent: your WordPress version. No personal data is transmitted. Service terms: https://wordpress.org/about/ — Privacy policy: https://wordpress.org/about/privacy/

Official WordPress.org source (core.svn.wordpress.org)

What it does: downloads pristine copies of WordPress core files from the official WordPress.org source repository (the core Subversion tree). Why: the “repair from official source” action restores a tampered core file to its original, verified content. The response is treated strictly as data (written to disk only after a checksum match); nothing from it is ever executed. When: only when you explicitly repair a flagged core file. Data sent: the core file path and version requested. No personal data is transmitted. Service terms: https://wordpress.org/about/ — Privacy policy: https://wordpress.org/about/privacy/

WordPress.org plugin and theme packages (downloads.wordpress.org)

What it does: downloads the official package (ZIP) of an installed plugin or theme from the WordPress.org repository. Why: the integrity scan compares the files of your installed plugins and themes against the official published release, so it can tell a tampered file apart from a legitimate one. WordPress.org publishes no checksum API for plugins and themes, so the official package itself is the reference. When: during a plugin/theme integrity scan, and only for items that come from the WordPress.org repository. Data sent: the slug and version of the plugin or theme being verified. No personal data is transmitted. Service terms: https://wordpress.org/about/ — Privacy policy: https://wordpress.org/about/privacy/

Freemius (api.freemius.com)

What it does: handles the optional Pro licence activation and — only if you opt in — anonymous usage diagnostics. This free version is updated by WordPress.org; Freemius does not deliver or gate its updates. Why: Scudo Security uses the Freemius platform so users who choose the separate Pro version can activate their licence, and — with your consent — to collect anonymous data that helps improve the plugin. When: only if you activate a Pro licence, and (opt-in only) for the diagnostics you consented to. No Freemius request is made to check for updates of this free version — updates come from WordPress.org. Data sent: your site URL and, only after you opt in, anonymous environment/usage data. Service terms: https://freemius.com/terms/ — Privacy policy: https://freemius.com/privacy/

Vulnerability advisory feed (optional; you choose the URL)

What it does: fetches a JSON vulnerability feed that is overlaid on the bundled baseline advisories. Why: lets you keep vulnerability advisories continuously up to date. The feed is provider-agnostic — no vendor is hardcoded, and nothing is fetched until you set a feed URL. When: only after you enter a feed URL, during advisory scans. Data sent: an HTTP GET to the URL you configured. No site data is placed in the request. Service terms/privacy: governed by the operator of whichever feed URL you choose.

Scudo Security Pro (a separate plugin, not this free version) additionally uses the Have I Been Pwned range API for the optional compromised-password check — sending only the first five characters of a password’s SHA-1 hash, never the password — and, if you enable the optional AI security advisor, the Anthropic Claude API with your own API key.

Ücretsiz(ücretli paketlerde)
Kurulum işlemini tamamlayarak, WordPress.com'un Hizmet Şartları ile Üçüncü Taraf Eklenti Şartlarını kabul etmiş olursunuz.
Test edilen son sürüm
WordPress 7.0.2
Bu eklenti, sitenizde kullanılmak üzere indirilebilir.