H3SEC Guard – Security Hardening
·
Lightweight WordPress security plugin focused on hardening, explainable risk scoring, activity logging, and a lightweight malware/integrity scan.
H3SEC Guard is built for site owners who want practical security controls without enabling a heavy, opaque security suite. Project contact: h3st4k3r@h3sec.com
Main capabilities:
- Hardening controls (XML-RPC, file editor, author enumeration, security headers)
- Login protection (attempt limit + temporary IP lockout + optional admin whitelist)
- Activity logging for critical site changes
- Core integrity scan using official WordPress checksums
- Lightweight suspicious PHP scanner with context-aware severity
- Finding-level hashes (MD5/SHA256), full path visibility, and recommendations
- Risk panel (low / medium / high / critical score)
- On-screen findings tables (not only downloads) for suspicious files, core mismatches, and permissions
- Response mode actions (close sessions, force password reset, maintenance, forensic export)
- Default blocking for known malicious probe paths with temporary IP lockout
- Weekly mitigation report with detailed activity counters
- Tracking for attempts with non-existent usernames
- Paginated activity log with expandable event context
- Configurable log retention with automatic daily cleanup
- Local security assistant with explainable next-step guidance
- Branded HTML weekly reports and security alerts
- No hidden telemetry or mandatory third-party APIs
H3SEC Guard is designed as an explainable security plugin. Each control explains:
- what it does;
- what risk it reduces;
- what it may break;
- how to revert it.