{"id":362240,"date":"2026-09-03T13:16:18","date_gmt":"2026-09-03T13:16:18","guid":{"rendered":"https:\/\/es.wordpress.org\/plugins\/seguridad-de-acceso-por-solutiontech\/"},"modified":"2026-09-15T18:09:32","modified_gmt":"2026-09-15T18:09:32","slug":"solutiontech-seguridad-de-acceso","status":"publish","type":"plugin","link":"https:\/\/de-ch.wordpress.org\/plugins\/solutiontech-seguridad-de-acceso\/","author":23558379,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.2.1","stable_tag":"2.2.1","tested":"7.1.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Solutiontech Seguridad de acceso","header_author":"solutiontechcl","header_description":"Protects WordPress access with a custom login URL, rate limiting, session controls, redirects, auditing, and optional content protection.","assets_banners_color":"184386","last_updated":"2026-09-15 18:09:32","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/solutiontech.cl\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":362,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.23.0":{"tag":"1.23.0","author":"solutiontechcl","date":"2026-09-03 13:15:47","revision":3679784},"1.23.1":{"tag":"1.23.1","author":"solutiontechcl","date":"2026-09-03 15:29:28","revision":3679981},"1.23.2":{"tag":"1.23.2","author":"solutiontechcl","date":"2026-09-03 17:40:21","revision":3680172},"1.24.0":{"tag":"1.24.0","author":"solutiontechcl","date":"2026-09-03 20:52:14","revision":3680402},"1.30.0":{"tag":"1.30.0","author":"solutiontechcl","date":"2026-09-04 17:40:30","revision":3681628},"1.40.0":{"tag":"1.40.0","author":"solutiontechcl","date":"2026-09-04 18:30:39","revision":3681671},"1.50.0":{"tag":"1.50.0","author":"solutiontechcl","date":"2026-09-04 20:56:12","revision":3681795},"1.50.1":{"tag":"1.50.1","author":"solutiontechcl","date":"2026-09-07 13:32:33","revision":3685013},"1.50.2":{"tag":"1.50.2","author":"solutiontechcl","date":"2026-09-08 12:32:00","revision":3686607},"2.0.0":{"tag":"2.0.0","author":"solutiontechcl","date":"2026-09-08 13:23:40","revision":3686713},"2.1.0":{"tag":"2.1.0","author":"solutiontechcl","date":"2026-09-15 13:51:23","revision":3697080},"2.2.0":{"tag":"2.2.0","author":"solutiontechcl","date":"2026-09-15 17:57:25","revision":3697500},"2.2.1":{"tag":"2.2.1","author":"solutiontechcl","date":"2026-09-15 18:09:32","revision":3697523}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3679784,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3679784,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3679784,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3679784,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3679784,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.23.0","1.23.1","1.23.2","1.24.0","1.30.0","1.40.0","1.50.0","1.50.1","1.50.2","2.0.0","2.1.0","2.2.0","2.2.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3680172,"resolution":"1","location":"assets","locale":"","width":1280,"height":820},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3680172,"resolution":"2","location":"assets","locale":"","width":1280,"height":820},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3680172,"resolution":"3","location":"assets","locale":"","width":1280,"height":820},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3680172,"resolution":"4","location":"assets","locale":"","width":1280,"height":820}},"screenshots":{"1":"Security Overview Dashboard with safety score gauge, protection indicators, and module matrix.","2":"Custom Login URL and Brute-Force Rate Limiting configuration.","3":"Micro-WAF (Web Application Firewall), IP Access Lists (Whitelist\/Blacklist), and Country Geolocation Filtering (GeoIP).","4":"Interactive Live Forensic Audit Log with instant search, category filtering, and CSV export."}},"plugin_section":[262246],"plugin_tags":[8534,2439,18193,602,600],"plugin_category":[38,54],"plugin_contributors":[279019],"plugin_business_model":[],"class_list":["post-362240","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-audit-log","plugin_tags-brute-force","plugin_tags-content-protection","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-solutiontechcl","plugin_committers-solutiontechcl"],"banners":{"banner":"https:\/\/ps.w.org\/solutiontech-seguridad-de-acceso\/assets\/banner-772x250.png?rev=3679784","banner_2x":"https:\/\/ps.w.org\/solutiontech-seguridad-de-acceso\/assets\/banner-1544x500.png?rev=3679784","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/solutiontech-seguridad-de-acceso\/assets\/icon.svg?rev=3679784","icon":"https:\/\/ps.w.org\/solutiontech-seguridad-de-acceso\/assets\/icon.svg?rev=3679784","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/solutiontech-seguridad-de-acceso\/assets\/screenshot-1.png?rev=3680172","caption":"Security Overview Dashboard with safety score gauge, protection indicators, and module matrix."},{"src":"https:\/\/ps.w.org\/solutiontech-seguridad-de-acceso\/assets\/screenshot-2.png?rev=3680172","caption":"Custom Login URL and Brute-Force Rate Limiting configuration."},{"src":"https:\/\/ps.w.org\/solutiontech-seguridad-de-acceso\/assets\/screenshot-3.png?rev=3680172","caption":"Micro-WAF (Web Application Firewall), IP Access Lists (Whitelist\/Blacklist), and Country Geolocation Filtering (GeoIP)."},{"src":"https:\/\/ps.w.org\/solutiontech-seguridad-de-acceso\/assets\/screenshot-4.png?rev=3680172","caption":"Interactive Live Forensic Audit Log with instant search, category filtering, and CSV export."}],"raw_content":"<!--section=description-->\n<p>Seguridad de acceso por Solutiontech protects WordPress access and reduces unnecessary public exposure without renaming core files or modifying .htaccess.<\/p>\n\n<p>Main features:<\/p>\n\n<ul>\n<li>Generador de Informes Ejecutivos de Seguridad para Clientes (PDF \/ HTML): Reportes corporativos listos para imprimir o descargar como HTML aut\u00f3nomo, con m\u00e9tricas ejecutivas, score de seguridad, resumen de vectores neutralizados y personalizaci\u00f3n con nombre de agencia.<\/li>\n<li>Motor de Reglas WAF Personalizadas (Custom Firewall Rules): Reglas a medida por URI, Query String, User-Agent o contenido POST con operadores de coincidencia y expresiones regulares protegidas contra ReDoS.<\/li>\n<li>Procedencia Geogr\u00e1fica de Amenazas en Tiempo Real: Monitoreo y agregaci\u00f3n de pa\u00edses de origen con banderas y porcentajes relativos en el Centro de Inteligencia de Amenazas.<\/li>\n<li>Breached Password Protection (HaveIBeenPwned k-Anonymity API): Validates new passwords against public breach databases using strict 5-character SHA-1 range queries with Add-Padding to guarantee zero password disclosure.<\/li>\n<li>Instant Lockout for Forbidden Dictionary Usernames: Immediately bans offending IPs on attempt #1 when attempting generic attacker usernames (admin, root, administrator, test, etc.) without waiting for standard retry limits.<\/li>\n<li>Global Session Kill-Switch \/ Panic Button: Emergency one-click button to revoke all active WordPress session tokens across the site in case of security incident or intrusion.<\/li>\n<li>Agency Threat Network &amp; Central Hub Mode: Connect to Solutiontech distributed threat intelligence network or operate as a central agency hub to synchronize IP blacklists and whitelists across client websites.<\/li>\n<li>2FA Emergency Backup Recovery Codes: Generates secure single-use recovery code sets in user profiles to prevent lockouts.<\/li>\n<li>Cloudflare Turnstile Anti-Bot Protection: Frictionless, privacy-first bot detection challenge across login, registration, and lost password forms.<\/li>\n<li>Malware Upload Shield (PHP File Scanner): Automatically scans \/wp-content\/uploads\/ for suspicious executable PHP scripts and backdoors.<\/li>\n<li>Interactive Audit Log Filter &amp; Live Search: Instant client-side search and category filtering across recorded security events.<\/li>\n<li>Authenticator App 2FA (TOTP - RFC 6238): Support for Google Authenticator, Microsoft Authenticator, and Authy with QR code pairing in user profiles.<\/li>\n<li>GeoIP Country Restriction: Allow or block access based on visitor country code from reverse proxies and Cloudflare.<\/li>\n<li>Security Email Alerts: Real-time HTML notifications with anti-flood rate limits for brute force, WAF blocks, and core discrepancies.<\/li>\n<li>WordPress Dashboard Widget: Overview widget with security score ring, status pills, and 24-hour threat metrics.<\/li>\n<li>Micro-WAF (Web Application Firewall): Early inspection and neutralisation of SQL Injections (SQLi), Cross-Site Scripting (XSS), Path Traversal (LFI), Remote Code Execution (RCE), and malicious security scanners.<\/li>\n<li>IP Whitelist &amp; Permanent Blacklist: Allows instant exclusion for trusted IPs and permanent 403 blocking for malicious IPs and CIDR ranges across the entire website.<\/li>\n<li>WordPress Core File Integrity Checker: Verifies local core files against official WordPress.org cryptographic MD5 checksums to detect modified or missing CMS files.<\/li>\n<li>Two-Factor Authentication (2FA via Email OTP): Delivers a 6-digit one-time code to authorized user emails to secure privileged logins.<\/li>\n<li>Strong Password Policies &amp; Expiration: Enforces 12+ character complexity and optional periodic password expiration reminders.<\/li>\n<li>Official Internationalization &amp; Translation Template: Standard .pot file included in languages\/ for seamless translation with Poedit, Loco Translate, or WordPress.org GlotPress.<\/li>\n<li>Invisible Honeypot Anti-Spam: Blocks automated bots across login, password recovery, registration, and comment forms without annoying CAPTCHAs.<\/li>\n<li>Pingback &amp; XML-RPC DDoS Protection: Strips X-Pingback headers and disables XML-RPC pingback reflection methods.<\/li>\n<li>WordPress Core Hardening: Hide WordPress version from headers\/feeds\/asset query strings, remove legacy discovery tags (RSD, WLWManifest, oEmbed), and disable built-in file editing.<\/li>\n<li>Background automated cleanup with WP-Cron for expired audit logs and 404 entries.<\/li>\n<li>Secure CSV export for Audit Log and 404 Monitor with Excel UTF-8 BOM and formula injection protection.<\/li>\n<li>Runtime in-memory caching for faster settings retrieval without redundant database queries.<\/li>\n<li>Google reCAPTCHA v3 invisible bot protection with score threshold on login and lost-password forms.<\/li>\n<li>HTTP Security Headers injection (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and HSTS).<\/li>\n<li>Progressive brute-force lockout with escalating lockout tiers for repeat offenders.<\/li>\n<li>Optional WooCommerce catalog mode, including controls for administrators and variable products.<\/li>\n<li>Security status dashboard with an informative score and links to each setting.<\/li>\n<li>Responsive sidebar navigation organized by security area.<\/li>\n<li>Session and device management based on native WordPress session tokens.<\/li>\n<li>Individual session revocation, single-session policy, and optional inactivity timeout.<\/li>\n<li>Optional alerts when a user signs in from a new device.<\/li>\n<li>404 monitor with retention, entry limits, and direct conversion to a redirect rule.<\/li>\n<li>Same-site redirect manager supporting 301, 302, 307, and 308 responses.<\/li>\n<li>Optional custom login URL and random URL regeneration.<\/li>\n<li>Protection against direct access to wp-login.php and wp-admin for visitors.<\/li>\n<li>Configurable login attempt limiting by IP address using WordPress transients.<\/li>\n<li>Generic login errors to reduce account enumeration.<\/li>\n<li>Optional author enumeration and public REST user endpoint protection.<\/li>\n<li>Optional XML-RPC restriction.<\/li>\n<li>Environment diagnostics for Multisite, subdirectories, proxy\/CDN setups, WooCommerce, and recovery flows.<\/li>\n<li>Optional deterrents for casual copying of images and text.<\/li>\n<li>Local audit log for relevant authentication and administration events.<\/li>\n<li>Configurable audit-log retention from 1 to 365 days, limited to 500 events.<\/li>\n<li>Independent controls for new comments and pingbacks on posts and pages.<\/li>\n<li>Optional email alerts when the login-attempt limit is reached.<\/li>\n<li>Configurable response for blocked login routes: 404, home page, or a custom URL.<\/li>\n<\/ul>\n\n<p>The plugin does not modify WordPress files. After deactivation, WordPress uses its standard login routes again.<\/p>\n\n<p>Developer website: https:\/\/solutiontech.cl\/<\/p>\n\n<h3>External Service and Privacy<\/h3>\n\n<p>This plugin can optionally connect to the following external services:<\/p>\n\n<ol>\n<li>Solutiontech Threat Intelligence Network (https:\/\/solutiontech.cl\/)<\/li>\n<\/ol>\n\n<p>* Purpose: Synchronizes distributed IP blacklists and whitelists to protect WordPress installations against emerging cyber threats and brute-force campaigns.\n* Data sent: Site URL, WordPress core version, and plugin version upon manual or scheduled sync. If anonymous threat reporting is enabled, the IP address and reason for blocked attacks intercepted by the local Micro-WAF are sent.\n* Service provider: Solutiontech (https:\/\/solutiontech.cl)\n* Privacy Policy: https:\/\/solutiontech.cl\/politica-de-privacidad\/\n* Terms of Service: https:\/\/solutiontech.cl\/terminos-y-condiciones\/\n* Note: This service is 100% OPT-IN and completely disabled by default until explicitly enabled by an administrator with a valid API key.<\/p>\n\n<ol>\n<li>WordPress.org Core API (https:\/\/api.wordpress.org\/)<\/li>\n<\/ol>\n\n<p>* Purpose: Verifies the integrity of WordPress core files by comparing local file hashes against official checksums.\n* Data sent: WordPress version and locale.\n* Service provider: WordPress Foundation\n* Privacy Policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<ol>\n<li>WPVulnerability API (https:\/\/www.wpvulnerability.net\/)<\/li>\n<\/ol>\n\n<p>* Purpose: Scans installed plugins, themes, and WordPress core against public vulnerability databases (CVEs).\n* Data sent: Slugs and installed version numbers of plugins\/themes (no personal or proprietary data).\n* Service provider: WPVulnerability\n* Privacy Policy: https:\/\/www.wpvulnerability.net\/privacy\/<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin can connect to the following third-party external services when explicitly configured and enabled by the site administrator:<\/p>\n\n<ul>\n<li><p><strong>Google reCAPTCHA v3<\/strong>:<\/p>\n\n<ul>\n<li><em>Purpose<\/em>: Protects authentication and password recovery forms against automated bots and credential-stuffing attacks.<\/li>\n<li><em>Data sent &amp; when<\/em>: When enabled with site administrator API credentials, user interaction tokens and visitor IP address are sent to <code>https:\/\/www.google.com\/recaptcha\/api\/siteverify<\/code> during form submission to obtain a risk confidence score.<\/li>\n<li><em>Service provider<\/em>: Google LLC.<\/li>\n<li><em>Terms of Service<\/em>: https:\/\/policies.google.com\/terms<\/li>\n<li><em>Privacy Policy<\/em>: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul><\/li>\n<li><p><strong>Cloudflare Turnstile<\/strong>:<\/p>\n\n<ul>\n<li><em>Purpose<\/em>: Provides frictionless, privacy-preserving smart anti-bot challenge validation on login, registration, and lost password forms.<\/li>\n<li><em>Data sent &amp; when<\/em>: When enabled with site administrator API credentials, the Turnstile response token and visitor IP address are sent to <code>https:\/\/challenges.cloudflare.com\/turnstile\/v0\/siteverify<\/code> during form submission.<\/li>\n<li><em>Service provider<\/em>: Cloudflare, Inc.<\/li>\n<li><em>Terms of Service<\/em>: https:\/\/www.cloudflare.com\/website-terms\/<\/li>\n<li><em>Privacy Policy<\/em>: https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<\/ul><\/li>\n<li><p><strong>WordPress.org Core Checksums API<\/strong>:<\/p>\n\n<ul>\n<li><em>Purpose<\/em>: Validates the integrity of local WordPress CMS files against official cryptographic checksums in the Diagnostics panel.<\/li>\n<li><em>Data sent &amp; when<\/em>: The current WordPress version and locale string (e.g., version and language code) are sent to <code>https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/code> only when an administrator clicks the \"Comprobar integridad del n\u00facleo\" button in the diagnostics dashboard. No user personal data is sent.<\/li>\n<li><em>Service provider<\/em>: WordPress Foundation \/ WordPress.org.<\/li>\n<li><em>Privacy Policy<\/em>: https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul><\/li>\n<li><p><strong>HaveIBeenPwned API (Pwned Passwords)<\/strong>:<\/p>\n\n<ul>\n<li><em>Purpose<\/em>: Validates user passwords during profile creation, profile updates, or password resets to prevent the use of passwords that have been publicly exposed in known data breaches.<\/li>\n<li><em>Data sent &amp; when<\/em>: When the breached password policy is enabled, only the first 5 characters of the uppercase SHA-1 hash of the password (k-Anonymity model) are sent via secure GET request to <code>https:\/\/api.pwnedpasswords.com\/range\/{prefix}<\/code> with the <code>Add-Padding: true<\/code> header. The plaintext password and remaining 35 hash characters are never transmitted over the network or stored.<\/li>\n<li><em>Service provider<\/em>: Troy Hunt \/ Have I Been Pwned.<\/li>\n<li><em>Terms of Service<\/em>: https:\/\/haveibeenpwned.com\/API\/v3<\/li>\n<li><em>Privacy Policy<\/em>: https:\/\/haveibeenpwned.com\/Privacy<\/li>\n<\/ul><\/li>\n<li><p><strong>Note on 2FA QR Codes<\/strong>: Two-Factor Authentication (TOTP) QR codes are generated 100% locally on your server in pure PHP as inline SVG. No secret keys or user data are ever sent to any external server or third-party service.<\/p><\/li>\n<\/ul>\n\n<h3>Privacy<\/h3>\n\n<p>The plugin does not send telemetry to Solutiontech. Optional security modules store their data locally in the WordPress database. Audit events may include complete IP addresses for forensic traceability, while the administration table displays masked addresses. WordPress session tokens may contain IP, browser, and date information. The 404 monitor does not store IP addresses or query parameters. If email alerts are enabled, the site sends the relevant information through its configured mail system. Site administrators are responsible for providing any required privacy notice and choosing an appropriate retention period.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to the <code>\/wp-content\/plugins\/solutiontech-seguridad-de-acceso<\/code> directory, or install the plugin through the WordPress plugins screen directly.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress.<\/li>\n<li>Use the 'Seguridad Solutiontech' screen to configure the plugin settings.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20happens%20if%20i%20forget%20the%20custom%20login%20url%3F\"><h3>What happens if I forget the custom login URL?<\/h3><\/dt>\n<dd><p>Use the emergency recovery URL shown on the plugin settings page. Keep a secure copy of this address. If you also lose that address, you can access your hosting panel or FTP client and temporarily rename the plugin folder in <code>\/wp-content\/plugins\/<\/code> to disable it and sign in through <code>\/wp-login.php<\/code>.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20modify%20.htaccess%20or%20web%20server%20configuration%20files%3F\"><h3>Does the plugin modify .htaccess or web server configuration files?<\/h3><\/dt>\n<dd><p>No. All protections, including login redirection, rate limiting, and session handling, are executed dynamically inside WordPress.<\/p><\/dd>\n<dt id=\"does%20rate%20limiting%20affect%20all%20users%3F\"><h3>Does rate limiting affect all users?<\/h3><\/dt>\n<dd><p>Rate limiting applies to any IP address attempting to sign in. The default allows 5 attempts, followed by a temporary lockout. Legitimate users can wait for the lockout period to expire or request an administrator to clear their IP address from the lockout pool.<\/p><\/dd>\n<dt id=\"can%20i%20use%20two-factor%20authentication%20with%20authenticator%20apps%3F\"><h3>Can I use Two-Factor Authentication with Authenticator Apps?<\/h3><\/dt>\n<dd><p>Yes. Version 1.22.0 introduces Authenticator App 2FA (TOTP RFC 6238) supporting Google Authenticator, Microsoft Authenticator, Authy, and 1Password with pure PHP offline SVG QR code pairing.<\/p><\/dd>\n<dt id=\"how%20does%20country%20geolocation%20%28geoip%29%20work%3F\"><h3>How does Country Geolocation (GeoIP) work?<\/h3><\/dt>\n<dd><p>GeoIP lets you restrict access based on visitor country code. It works out of the box with Cloudflare (CF-IPCountry) and reverse proxies (X-Country-Code). You can set it to allowlist or blocklist mode.<\/p><\/dd>\n<dt id=\"what%20does%20the%20micro-waf%20protect%20against%3F\"><h3>What does the Micro-WAF protect against?<\/h3><\/dt>\n<dd><p>The built-in Web Application Firewall inspects incoming HTTP requests to block SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion \/ Remote Code Execution (LFI\/RCE), and malicious penetration testing scanners (such as sqlmap, nikto, wpscan).<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20ip%20whitelist%20and%20permanent%20blacklist%3F\"><h3>What is the difference between IP Whitelist and Permanent Blacklist?<\/h3><\/dt>\n<dd><p>The IP Whitelist excludes trusted IPs and CIDR ranges from rate limiting and WAF blocking. The Permanent Blacklist immediately rejects all traffic from designated IPs and subnets with a 403 Forbidden response.<\/p><\/dd>\n<dt id=\"how%20does%20the%20wordpress%20core%20integrity%20checker%20work%3F\"><h3>How does the WordPress Core Integrity Checker work?<\/h3><\/dt>\n<dd><p>It fetches the official cryptographic MD5 checksums for your current WordPress version from WordPress.org and compares every local file in wp-admin, wp-includes, and the root directory to detect unauthorized modifications, malware injections, or missing files.<\/p><\/dd>\n<dt id=\"does%20disabling%20xml-rpc%20affect%20jetpack%20or%20the%20wordpress%20mobile%20app%3F\"><h3>Does disabling XML-RPC affect Jetpack or the WordPress Mobile App?<\/h3><\/dt>\n<dd><p>Disabling XML-RPC prevents automated brute force and pingback DDoS attacks. If you use Jetpack or the mobile app, you can keep XML-RPC enabled or use the dedicated toggle in the Sites Protection tab.<\/p><\/dd>\n<dt id=\"what%20does%20content%20protection%20do%3F\"><h3>What does content protection do?<\/h3><\/dt>\n<dd><p>It adds optional client-side controls that discourage casual visitors from right-clicking images, dragging images to their desktop, selecting and copying text, or using common copy shortcuts.<\/p><\/dd>\n<dt id=\"can%20i%20disable%20new%20user%20registration%20while%20keeping%20the%20site%20open%3F\"><h3>Can I disable new user registration while keeping the site open?<\/h3><\/dt>\n<dd><p>Yes. You can disable registration entirely or restrict new registrations to specific roles such as Subscriber or Customer.<\/p><\/dd>\n<dt id=\"can%20i%20disable%20comments%20on%20all%20posts%20or%20pages%20at%20once%3F\"><h3>Can I disable comments on all posts or pages at once?<\/h3><\/dt>\n<dd><p>Yes. The plugin includes toggles to disable comments across all published posts, all pages, or both.<\/p><\/dd>\n<dt id=\"does%20disabling%20comments%20delete%20existing%20comments%3F\"><h3>Does disabling comments delete existing comments?<\/h3><\/dt>\n<dd><p>New comments and pingbacks are prevented for the selected content type. Existing comments are not deleted.<\/p><\/dd>\n<dt id=\"can%20content%20protection%20completely%20prevent%20copying%3F\"><h3>Can content protection completely prevent copying?<\/h3><\/dt>\n<dd><p>No. These controls are deterrents. Content downloaded by a browser may still be obtained by other means or captured in a screenshot.<\/p><\/dd>\n<dt id=\"is%20the%20plugin%20compatible%20with%20multisite%2C%20subdirectory%20installations%2C%20and%20woocommerce%3F\"><h3>Is the plugin compatible with Multisite, subdirectory installations, and WooCommerce?<\/h3><\/dt>\n<dd><p>The plugin includes diagnostics and dedicated handling for these environments. On Multisite, settings are stored per site. After changing the login URL, test sign-in, sign-out, and password recovery in a private browser window.<\/p><\/dd>\n<dt id=\"which%20redirect%20types%20are%20supported%3F\"><h3>Which redirect types are supported?<\/h3><\/dt>\n<dd><p>The redirect manager supports 301, 302, 307, and 308. The source and destination must belong to the current site's domain. External hosts, duplicates, loops, and critical WordPress routes are rejected.<\/p><\/dd>\n<dt id=\"how%20does%20session%20management%20work%3F\"><h3>How does session management work?<\/h3><\/dt>\n<dd><p>The Sessions section uses native WordPress session tokens. Administrators can review devices, close an individual session, close other sessions for their own account, or revoke sessions for another accessible account. The current administrative session is protected against accidental revocation.<\/p><\/dd>\n<dt id=\"what%20information%20does%20the%20404%20monitor%20store%3F\"><h3>What information does the 404 monitor store?<\/h3><\/dt>\n<dd><p>It stores the requested path without query parameters, a referrer without query parameters, a general browser\/device description, first and last detection times, and a hit count. It does not store IP addresses and excludes administration, REST, AJAX, cron, critical routes, and request methods other than GET or HEAD.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.2.1<\/h4>\n\n<ul>\n<li>Informes Ejecutivos en Red de Agencia: Generaci\u00f3n de Informes Ejecutivos de Seguridad multi-sitio consolidados de la red de agencia y reportes individuales filtrados por cliente desde el panel central.<\/li>\n<li>Correcci\u00f3n de Error Cr\u00edtico en Generador de Reportes: Resuelve la excepci\u00f3n en la invocaci\u00f3n de la puntuaci\u00f3n de seguridad en la exportaci\u00f3n de informes ejecutivos.<\/li>\n<li>Integraci\u00f3n de Accesos Directos de Reportes: Nuevos botones de acceso en el Hub de Agencia y en la tabla de clientes para emitir informes ejecutivos en 1 clic.<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Generador de Informes Ejecutivos de Ciberseguridad para Clientes (PDF \/ HTML): Vista corporativa ejecutiva imprimible (@media print \/ window.print()) y descargable como HTML aut\u00f3nomo, con \u00edndice de seguridad, resumen de amenazas neutralizadas por vector de ataque, estado de salud del CMS, distribuci\u00f3n geogr\u00e1fica y recomendaciones t\u00e9cnicas personalizadas con el nombre de tu agencia.<\/li>\n<li>Motor de Reglas WAF Personalizadas (Custom Firewall Rules): Interfaz de creaci\u00f3n y gesti\u00f3n de reglas perimetrales personalizadas sobre URI, Query String, User-Agent y cuerpo POST con operadores contiene, igual, comienza con y expresiones regulares seguras (anti-ReDoS), con opciones de bloqueo inmediato (HTTP 403) o modo monitor\/registro forense.<\/li>\n<li>Procedencia Geogr\u00e1fica de Amenazas en Tiempo Real: Visualizaci\u00f3n gr\u00e1fica de procedencia geogr\u00e1fica de los ataques neutralizados por el Firewall y las defensas de acceso, con banderas Unicode, conteo exacto de incidentes y porcentajes relativos en el Centro de Inteligencia de Amenazas.<\/li>\n<li>Enriquecimiento Forense de Auditor\u00eda: Registro autom\u00e1tico del c\u00f3digo de pa\u00eds ISO en cada evento de auditor\u00eda para trazabilidad geogr\u00e1fica avanzada.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Protecci\u00f3n contra Contrase\u00f1as Filtradas (HaveIBeenPwned k-Anonymity API): Valida en tiempo real durante la creaci\u00f3n o cambio de clave que la contrase\u00f1a no haya aparecido en filtraciones masivas de datos p\u00fablicas, empleando k-Anonymity estricto donde solo se transmiten los primeros 5 caracteres del hash SHA-1 con encabezado Add-Padding.<\/li>\n<li>Bloqueo Instant\u00e1neo por Usuarios Prohibidos de Diccionario: Bloquea autom\u00e1ticamente en el 1er intento fallido a cualquier IP o bot que intente autenticarse con nombres gen\u00e9ricos de atacante (admin, administrator, root, test, guest, user, demo, etc.) sin esperar al agotamiento de reintentos.<\/li>\n<li>Bot\u00f3n de P\u00e1nico \/ Global Session Kill-Switch: Interruptor de emergencia en el panel de Dispositivos y Sesiones para invalidar masiva e instant\u00e1neamente todos los tokens de sesi\u00f3n activos en WordPress (con opci\u00f3n de preservar la sesi\u00f3n actual del administrador o revocar todo el sitio).<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Hardening Defensivo de Ciberseguridad: Auditor\u00eda integral de arquitectura con mitigaci\u00f3n proactiva contra vectores OWASP y CWE.<\/li>\n<li>Blindaje contra SSRF en Webhooks: Migraci\u00f3n al transporte seguro wp_safe_remote_post() para las alertas de seguridad instant\u00e1neas (Discord, Slack, Telegram y JSON), previniendo pivotes hacia subredes privadas o metadatos de computaci\u00f3n en la nube.<\/li>\n<li>Rate-Limiting por IP en Endpoints REST: Control estricto de tasa en la Red de Amenazas (\/hub\/threat-feed, \/hub\/report-threat y \/agency\/push-rule) con bloqueo temporal (HTTP 429) tras 10 intentos fallidos continuos de API Key.<\/li>\n<li>Micro-WAF con Inspecci\u00f3n de Cuerpos JSON: El Firewall analiza cargas \u00fatiles transmitidas en application\/json (php:\/\/input) en llamadas din\u00e1micas y APIs REST, filtrando SQLi, XSS y LFI\/RCE sin exponer contrase\u00f1as.<\/li>\n<li>Resistencia a Evasi\u00f3n por Doble Codificaci\u00f3n: Motor de decodificaci\u00f3n profunda multinivel (Multi-Pass URL Decoding) en el WAF para desarticular vectores con secuencias anidadas (%252e%252e%252f).<\/li>\n<li>Purga Total en Desinstalaci\u00f3n: Ciclo de vida robusto en uninstall.php que limpia exhaustivamente datos de la Red de Agencia, CVE Scanner, transitorios y tareas programadas en WP-Cron tanto en sitios individuales como en redes Multisite.<\/li>\n<\/ul>\n\n<h4>1.50.2<\/h4>\n\n<ul>\n<li>Telemetr\u00eda de Amenazas - Retenci\u00f3n de 120 D\u00edas: Historial de telemetr\u00eda de ataques conservado por al menos 120 d\u00edas con poda autom\u00e1tica diaria mediante WP-Cron.<\/li>\n<li>Telemetr\u00eda de Amenazas - Filtro por Fechas: Selector de rango de fechas (desde y hasta) para consultar incidentes hist\u00f3ricos neutralizados en el Hub.<\/li>\n<li>Telemetr\u00eda de Amenazas - Paginaci\u00f3n Numerada: Visualizaci\u00f3n paginada a 50 incidentes por vista con controles num\u00e9ricos (\u00ab Anterior, 1, 2, 3..., Siguiente \u00bb) y preservaci\u00f3n de navegaci\u00f3n fluida.<\/li>\n<li>Exportaci\u00f3n CSV de Red Filtrada: El reporte CSV de estad\u00edsticas de red respeta los filtros de fecha seleccionados en la pantalla.<\/li>\n<\/ul>\n\n<h4>1.50.1<\/h4>\n\n<ul>\n<li>Auditor\u00eda de Seguridad Integral: Correcci\u00f3n de hallazgos de seguridad (A-01 a A-04, M-01 a M-08, B-03, B-04, B-06).<\/li>\n<li>Red Agencia - Descarga de Estad\u00edsticas: Nueva funci\u00f3n para exportar informes completos en CSV con clientes autorizados, listas de IPs distribuidas y telemetr\u00eda de eventos neutralizados.<\/li>\n<li>Telemetr\u00eda de Amenazas en Vivo: Conexi\u00f3n autom\u00e1tica de bloqueos de auditor\u00eda y Micro-WAF al stream de telemetr\u00eda del Hub Central y nodos de la red.<\/li>\n<li>Hardening 2FA \/ TOTP: Aislamiento de c\u00f3digos QR y secretos por usuario, c\u00f3digos de respaldo de 40 bits de entrop\u00eda con random_bytes(), verificaci\u00f3n estricta de secrets antes de activaci\u00f3n y prevenci\u00f3n anti-replay RFC 6238.<\/li>\n<li>Verificaci\u00f3n GeoIP Segura: Restricci\u00f3n de encabezados Cloudflare CF-IPCountry mediante verificaci\u00f3n estricta de rangos IP CIDR oficiales de Cloudflare.<\/li>\n<li>Micro-WAF Anti-CSRF y Suspensi\u00f3n Temporal: Detecci\u00f3n de Sec-Fetch-Site para prevenir autobloqueos accidentales por CSRF cruzado y suspensi\u00f3n temporal de 24 horas para atacantes reincidentes.<\/li>\n<li>Enlaces Directos de Configuraci\u00f3n: Acceso directo en 1 clic a los paneles de control de Cloudflare Turnstile y Google reCAPTCHA v3.<\/li>\n<li>Limpieza de Interfaz: Remoci\u00f3n del pie de p\u00e1gina \"Gracias por crear con WordPress\" en las pantallas del plugin.<\/li>\n<\/ul>\n\n<h4>1.50.0<\/h4>\n\n<ul>\n<li>Modo Agencia y Red Global de Inteligencia de Amenazas (Threat Network): Conexi\u00f3n distribuida opcional para sincronizar listas negras y blancas de IPs en tiempo real con el servidor central de Solutiontech.<\/li>\n<li>Soporte de Rol Dual (Modo Nodo Cliente vs Modo Servidor Central Hub): Permite operar como sitio cliente receptor de directivas de seguridad o como servidor central Hub para agencias de desarrollo y mantenimiento web.<\/li>\n<li>Generador Criptogr\u00e1fico de Claves API de Clientes: Consola de administraci\u00f3n en modo Hub para emitir, copiar con 1 clic, revocar y eliminar credenciales API seguras (<code>st_net_...<\/code>) para sitios clientes conectados.<\/li>\n<li>Jerarqu\u00eda Estricta Anti-Autobloqueo: La lista blanca local del cliente mantiene prioridad absoluta (#1) sobre cualquier regla de red global para evitar autobloqueos accidentales, con banner de advertencia prominente en la interfaz.<\/li>\n<li>Endpoint REST API Seguro de Threat Feed y Telemetr\u00eda: Endpoints autenticados v\u00eda <code>X-ST-Agency-Key<\/code> para entrega instant\u00e1nea de feeds de ciberdefensa y stream de telemetr\u00eda de ataques en vivo.<\/li>\n<li>Cumplimiento Total de Directrices WordPress.org: M\u00f3dulo 100% opt-in desactivado por defecto y secci\u00f3n formal de declaraci\u00f3n de servicios externos en readme.txt.<\/li>\n<\/ul>\n\n<h4>1.40.0<\/h4>\n\n<ul>\n<li>Esc\u00e1ner de Vulnerabilidades Conocidas (CVE): Audita el n\u00facleo de WordPress, plugins y temas instalados contra la base de datos p\u00fablica global de CVEs (WPVulnerability Intelligence) con soporte para evaluaci\u00f3n de versiones afectadas, CVSS y enlaces oficiales.<\/li>\n<li>Nuevo Panel y Men\u00fa Lateral \"Esc\u00e1ner CVE\": Secci\u00f3n dedicada en la barra de navegaci\u00f3n del plugin con m\u00e9tricas de severidad (Cr\u00edtica, Alta, Media, Baja), bot\u00f3n de escaneo inmediato y tabla detallada con parches recomendados.<\/li>\n<li>Alertas Proactivas en WP-Cron: Escaneo diario en segundo plano con despacho autom\u00e1tico de notificaciones por Correo y Webhooks (Discord, Slack, Telegram, JSON) al detectar vulnerabilidades cr\u00edticas.<\/li>\n<li>Chequeo Oficial en Salud del Sitio: Integraci\u00f3n del 6\u00ba control de seguridad certificado en Herramientas &gt; Salud del sitio de WordPress.<\/li>\n<\/ul>\n\n<h4>1.30.0<\/h4>\n\n<ul>\n<li>Perfiles de Configuraci\u00f3n R\u00e1pida en 1 Clic (Presets): Permite aplicar perfiles preconfigurados (B\u00e1sico, Recomendado, Tienda \/ WooCommerce y Blindaje Total) directamente desde el panel de Resumen sin sobreescribir claves API ni datos sensibles.<\/li>\n<li>Webhooks de Notificaci\u00f3n Instant\u00e1nea: Despacho as\u00edncrono y en tiempo real de alertas de seguridad a canales de Discord (Embeds enriquecidos), Slack (Blocks interactivos), Telegram (Telegram Bot API con Chat ID) y Webhooks Gen\u00e9ricos (JSON REST) con bot\u00f3n de prueba en 1 clic.<\/li>\n<li>Integraci\u00f3n Oficial con Salud del Sitio (WP_Site_Health API): 5 chequeos certificados en la herramienta nativa Herramientas &gt; Salud del sitio de WordPress (Micro-WAF, 2FA, Integridad del Core, Blindaje de Uploads y Protecci\u00f3n de wp-login.php).<\/li>\n<\/ul>\n\n<h4>1.24.0<\/h4>\n\n<ul>\n<li>Threat Defense Center &amp; Forensic Reports: Dedicated intelligence and monitoring panel with live threat KPI cards, visual attack vector distribution, Top 5 recurring hostile IPs with 1-click blacklist action, and custom Date Range Forensic CSV Report Generator (filter by date from\/to, attack category, and severity).<\/li>\n<li>Automatic IP Blacklist on Critical Attacks: Automatically adds offending IPs to permanent blacklist upon intercepting SQL Injection, Path Traversal \/ LFI \/ RCE, or hostile scanning tools.<\/li>\n<li>WordPress Auto-Updates Manager: Centralized toggles in site protection to force automatic updates for WordPress core security releases, all installed plugins, and active themes.<\/li>\n<\/ul>\n\n<h4>1.23.2<\/h4>\n\n<ul>\n<li>Internationalization: Adds complete native translation packages for 12 locales: Spanish (Chile, Mexico, Argentina, Colombia, Peru, Spain), English (US), Brazilian Portuguese, European Portuguese, French, Italian, Russian, and Simplified Chinese.<\/li>\n<\/ul>\n\n<h4>1.23.1<\/h4>\n\n<ul>\n<li>Usability: Protected login URL is now disabled by default on initial activation to prevent unintended lockouts, allowing administrators to explicitly activate and customize their desired login route.<\/li>\n<\/ul>\n\n<h4>1.23.0<\/h4>\n\n<ul>\n<li>Adds 2FA Emergency Backup Recovery Codes (8 single-use codes) in user profiles with cryptographic hashing.<\/li>\n<li>Adds Cloudflare Turnstile anti-bot integration with support for login, registration, and lost-password forms.<\/li>\n<li>Adds Malware Upload Shield (suspicious executable PHP file scanner in \/wp-content\/uploads\/) in diagnostics panel.<\/li>\n<li>Adds interactive real-time search and category filtering in the Audit Log panel.<\/li>\n<\/ul>\n\n<h4>1.22.0<\/h4>\n\n<ul>\n<li>Adds Two-Factor Authentication via Authenticator Apps (TOTP - RFC 6238) with Google\/Microsoft Authenticator and QR code pairing in user profiles.<\/li>\n<li>Adds real-time Security Email Alerts with HTML formatting and anti-flood throttling for Brute Force lockouts, WAF attacks, and Core Integrity modifications.<\/li>\n<li>Adds Country Geolocation Filtering (GeoIP) with Allowlist\/Blocklist modes and Reverse Proxy \/ Cloudflare header detection.<\/li>\n<li>Adds WordPress Dashboard Security Widget with score gauge, protection indicators, and 24h threat summary.<\/li>\n<li>Fully compliant with WordPress.org Plugin Check validation and standards.<\/li>\n<\/ul>\n\n<h4>1.21.0<\/h4>\n\n<ul>\n<li>Adds Micro-WAF (Web Application Firewall) to detect and block SQL Injection, XSS, Path Traversal \/ LFI \/ RCE, and malicious scanner tools with forensic audit logging.<\/li>\n<li>Adds IP Whitelist and Permanent Blacklist management with support for IPv4, IPv6, and CIDR subnet notations.<\/li>\n<li>Adds WordPress Core File Integrity Checker comparing local core files against official WordPress.org cryptographic checksums with diagnostics dashboard integration.<\/li>\n<li>Integrates WAF, IP rules, and Core Integrity status into the security dashboard health score.<\/li>\n<\/ul>\n\n<h4>1.20.0<\/h4>\n\n<ul>\n<li>Adds Two-Factor Authentication (2FA via Email OTP) with 6-digit cryptographic verification code and brute-force attempt limits.<\/li>\n<li>Adds Strong Password Policies enforcing 12+ characters, uppercase, lowercase, numbers, and symbols during user creation and password resets.<\/li>\n<li>Adds optional periodic password expiration reminders for privileged user accounts.<\/li>\n<li>Integrates 2FA and password policy health checks into the security dashboard status score.<\/li>\n<\/ul>\n\n<h4>1.19.0<\/h4>\n\n<ul>\n<li>Adds official translation infrastructure with standard GNU gettext POT template (<code>languages\/solutiontech-seguridad-de-acceso.pot<\/code>).<\/li>\n<li>Declares <code>Domain Path: \/languages<\/code> in plugin headers for automatic native localization via WordPress Core.<\/li>\n<li>Fully compatible with Poedit, Loco Translate, WP-CLI, and WordPress.org GlotPress translation platform.<\/li>\n<\/ul>\n\n<h4>1.18.0<\/h4>\n\n<ul>\n<li>Adds Invisible Honeypot Anti-Spam protection across login, lost password, user registration, and comment forms to eliminate automated spam bot submissions.<\/li>\n<li>Adds Pingback protection: removes X-Pingback headers from server responses and disables XML-RPC pingback methods to mitigate DDoS amplification vectors.<\/li>\n<li>Adds optional Time-Gate submission speed filter to discard instant automated bot form submissions.<\/li>\n<li>Integrates anti-spam and honeypot indicators into the security dashboard score and administration panel.<\/li>\n<\/ul>\n\n<h4>1.17.0<\/h4>\n\n<ul>\n<li>Adds WordPress Core Hardening module: hides generator meta tags, RSS\/Atom version info, and removes ?ver= query strings matching the WordPress core version from public assets.<\/li>\n<li>Removes legacy and unnecessary discovery tags from HTML head (RSD link, WLWManifest link, and oEmbed discovery links).<\/li>\n<li>Adds theme and plugin file editor disabling (<code>DISALLOW_FILE_EDIT<\/code> enforcement and capability filtering) to prevent arbitrary PHP execution in case of account compromises.<\/li>\n<li>Integrates Core Hardening items into the security dashboard health score and environment diagnostics panel.<\/li>\n<\/ul>\n\n<h4>1.16.0<\/h4>\n\n<ul>\n<li>Adds daily scheduled WP-Cron task (<code>solutiontech_seguridad_acceso_daily_cleanup<\/code>) for automated asynchronous pruning of audit logs and 404 monitor entries.<\/li>\n<li>Adds secure CSV export functionality for Audit Log and 404 Monitor with UTF-8 BOM encoding for Excel compatibility and CSV formula injection protection.<\/li>\n<li>Implements runtime in-memory caching for settings retrieval to optimize database performance.<\/li>\n<\/ul>\n\n<h4>1.15.0<\/h4>\n\n<ul>\n<li>Adds Google reCAPTCHA v3 invisible protection for login and lost-password forms with customizable confidence score threshold.<\/li>\n<li>Adds HTTP Security Headers module (X-Frame-Options, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy, and HSTS).<\/li>\n<li>Adds Progressive Brute-Force Lockout feature with escalating penalty tiers for recurring attack IPs (1x base duration -&gt; 4x -&gt; 24 hours).<\/li>\n<li>Integrates new protection modules into the security status score and diagnostics dashboard.<\/li>\n<\/ul>\n\n<h4>1.14.4<\/h4>\n\n<ul>\n<li>Resolves Plugin Check update_modification_detected warning by removing core and plugin auto-update management to comply fully with WordPress.org guidelines.<\/li>\n<\/ul>\n\n<h4>1.14.3<\/h4>\n\n<ul>\n<li>Clearly distinguishes deleting a 404 history row from permanently resolving the missing URL.<\/li>\n<li>Renames the redirect action to Resolve permanently and uses a permanent 301 redirect by default.<\/li>\n<li>Removes the monitored 404 entry after its redirect is saved successfully.<\/li>\n<\/ul>\n\n<h4>1.14.2<\/h4>\n\n<ul>\n<li>Resolves the findings from Plugin Check concerning readme metadata, input handling, nonce analysis, and prefixed uninstall variables.<\/li>\n<li>Uses WordPress' native automatic-update preferences instead of filtering the plugin updater at runtime.<\/li>\n<li>Adds regression checks for packaging and WordPress.org compatibility metadata.<\/li>\n<\/ul>\n\n<h4>1.14.1<\/h4>\n\n<ul>\n<li>Fixes an interpolated translation string in the temporary lockout email.<\/li>\n<li>Adds regression coverage for static translatable strings and placeholder substitution.<\/li>\n<\/ul>\n\n<h4>1.14.0<\/h4>\n\n<ul>\n<li>Adds WooCommerce catalog mode under Content.<\/li>\n<li>Hides purchasing, cart, checkout, and optional variation controls.<\/li>\n<li>Can apply catalog mode to administrators while preserving existing order links.<\/li>\n<\/ul>\n\n<h4>1.13.5<\/h4>\n\n<ul>\n<li>Resolves internationalization findings reported by Plugin Check.<\/li>\n<li>Adds translator comments and ordered placeholders.<\/li>\n<\/ul>\n\n<h4>1.13.4<\/h4>\n\n<ul>\n<li>Prevents inactivity enforcement from intercepting REST requests used by the block editor.<\/li>\n<li>Masks IP addresses in the audit-log table.<\/li>\n<\/ul>\n\n<h4>1.13.3<\/h4>\n\n<ul>\n<li>Restricts redirect sources and destinations to the current domain.<\/li>\n<\/ul>\n\n<h4>1.13.2<\/h4>\n\n<ul>\n<li>Improves redirect normalization for omitted schemes and subdirectory installations.<\/li>\n<\/ul>\n\n<h4>1.13.1<\/h4>\n\n<ul>\n<li>Uses the full available width on desktop displays.<\/li>\n<\/ul>\n\n<h4>1.13.0<\/h4>\n\n<ul>\n<li>Adds individual session management for other accessible users.<\/li>\n<\/ul>\n\n<h4>1.12.5<\/h4>\n\n<ul>\n<li>Strengthens route, redirect, import, IPv6, and Multisite handling.<\/li>\n<\/ul>\n\n<h4>1.12.4<\/h4>\n\n<ul>\n<li>Improves diagnostic-card layout and responsive presentation.<\/li>\n<\/ul>\n\n<h4>1.12.3<\/h4>\n\n<ul>\n<li>Removes the promotional header from the administration panel.<\/li>\n<\/ul>\n\n<h4>1.12.2<\/h4>\n\n<ul>\n<li>Makes dashboard controls link directly to their related settings.<\/li>\n<\/ul>\n\n<h4>1.12.1<\/h4>\n\n<ul>\n<li>Improves the Copy URL button and renames technical hardening labels.<\/li>\n<\/ul>\n\n<h4>1.12.0<\/h4>\n\n<ul>\n<li>Adds the 404 monitor and refreshes the administration design.<\/li>\n<\/ul>\n\n<h4>1.11.0<\/h4>\n\n<ul>\n<li>Adds sessions, device alerts, single-session policy, and inactivity timeout.<\/li>\n<\/ul>\n\n<h4>1.10.0<\/h4>\n\n<ul>\n<li>Adds the same-site redirect manager.<\/li>\n<\/ul>\n\n<h4>1.9.0<\/h4>\n\n<ul>\n<li>Adds responsive sidebar navigation.<\/li>\n<\/ul>\n\n<h4>1.8.0<\/h4>\n\n<ul>\n<li>Adds emergency recovery, JSON import\/export, reset tools, and an IP allowlist.<\/li>\n<\/ul>","raw_excerpt":"Protects WordPress access with custom login URL, Micro-WAF, 2FA, IP control, brute force protection, core integrity, and local audit logs.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/362240","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=362240"}],"author":[{"embeddable":true,"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/solutiontechcl"}],"wp:attachment":[{"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=362240"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=362240"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=362240"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=362240"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=362240"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/de-ch.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=362240"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}