{"id":355017,"date":"2026-09-15T23:22:17","date_gmt":"2026-09-15T23:22:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/securizer\/"},"modified":"2026-09-15T23:22:07","modified_gmt":"2026-09-15T23:22:07","slug":"securizer","status":"publish","type":"plugin","link":"https:\/\/su.wordpress.org\/plugins\/securizer\/","author":23550695,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.4","stable_tag":"1.0.4","tested":"7.1.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Securizer","header_author":"WP Podrska","header_description":"Practical WordPress security, hardening, integrity checks and login protection without a firewall or cloud dependency.","assets_banners_color":"3e352f","last_updated":"2026-09-15 23:22:07","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/wppodrska.com\/","rating":5,"author_block_rating":0,"active_installs":0,"downloads":70,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.4":{"tag":"1.0.4","author":"wppodrska","date":"2026-09-15 23:22:07","revision":3697780}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3697780,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3697780,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3697780,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3697780,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.4"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3697780,"resolution":"1","location":"assets","locale":"","width":1200,"height":711},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3697780,"resolution":"2","location":"assets","locale":"","width":971,"height":891},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3697780,"resolution":"3","location":"assets","locale":"","width":963,"height":807},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3697780,"resolution":"4","location":"assets","locale":"","width":960,"height":855},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3697780,"resolution":"5","location":"assets","locale":"","width":964,"height":495},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3697780,"resolution":"6","location":"assets","locale":"","width":961,"height":885}},"screenshots":{"1":"Dashboard with protection status, recent activity, Action Center, compatibility checks and security overview.","2":"Login Protection with IP handling, targeted-account monitoring, active lockouts and Safe Login URL.","3":"Hardening controls for exposure reduction, remote access and browser security headers.","4":"Administrative hardening, Authentication Keys &amp; Salts rotation, and Safe File Protection.","5":"Core Integrity verification against official WordPress checksums.","6":"Diagnostics \/ Self Test with update hygiene and security configuration checks."}},"plugin_section":[262246],"plugin_tags":[2439,31093,173015,602,600],"plugin_category":[38,54],"plugin_contributors":[280966],"plugin_business_model":[],"class_list":["post-355017","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-hardening","plugin_tags-integrity","plugin_tags-login","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-wppodrska","plugin_committers-wppodrska"],"banners":{"banner":"https:\/\/ps.w.org\/securizer\/assets\/banner-772x250.png?rev=3697780","banner_2x":"https:\/\/ps.w.org\/securizer\/assets\/banner-1544x500.png?rev=3697780","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/securizer\/assets\/icon-128x128.png?rev=3697780","icon_2x":"https:\/\/ps.w.org\/securizer\/assets\/icon-256x256.png?rev=3697780","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/securizer\/assets\/screenshot-1.png?rev=3697780","caption":"Dashboard with protection status, recent activity, Action Center, compatibility checks and security overview."},{"src":"https:\/\/ps.w.org\/securizer\/assets\/screenshot-2.png?rev=3697780","caption":"Login Protection with IP handling, targeted-account monitoring, active lockouts and Safe Login URL."},{"src":"https:\/\/ps.w.org\/securizer\/assets\/screenshot-3.png?rev=3697780","caption":"Hardening controls for exposure reduction, remote access and browser security headers."},{"src":"https:\/\/ps.w.org\/securizer\/assets\/screenshot-4.png?rev=3697780","caption":"Administrative hardening, Authentication Keys &amp; Salts rotation, and Safe File Protection."},{"src":"https:\/\/ps.w.org\/securizer\/assets\/screenshot-5.png?rev=3697780","caption":"Core Integrity verification against official WordPress checksums."},{"src":"https:\/\/ps.w.org\/securizer\/assets\/screenshot-6.png?rev=3697780","caption":"Diagnostics \/ Self Test with update hygiene and security configuration checks."}],"raw_content":"<!--section=description-->\n<p>Securizer is a lightweight WordPress security and diagnostics plugin focused on local protection, verification and reporting. It provides login protection, hardening, core integrity, Safe Repair, diagnostics and account hygiene without a Securizer cloud service.<\/p>\n\n<p>Read-only checks do not repair files. Disruptive actions require administrator confirmation; safety-sensitive workflows use verification and rollback.<\/p>\n\n<h4>Login Protection<\/h4>\n\n<ul>\n<li>Progressive IP lockouts for repeated failed login attempts<\/li>\n<li>Targeted-account activity detection<\/li>\n<li>Exact-IP whitelist and blacklist<\/li>\n<li>Active lockout management and manual unlock<\/li>\n<li>Security event logging<\/li>\n<li>Configurable client IP detection, including Cloudflare support<\/li>\n<li>Compatibility warnings for overlapping login-protection plugins<\/li>\n<\/ul>\n\n<h4>Safe Login URL<\/h4>\n\n<p>Securizer can provide a custom login path and hide normal anonymous access to wp-login.php and wp-admin. The new route is verified before the default route is hidden, and the previous configuration is restored if verification fails. An emergency recovery constant is available if access problems occur.<\/p>\n\n<h4>WordPress Hardening<\/h4>\n\n<p>Hardening controls cover XML-RPC and pingbacks, generator exposure, author enumeration, REST API user exposure, the file editor, Application Passwords, security headers, directory listing and public access to PHP-like files inside uploads. Potentially incompatible server-level changes are not forced automatically.<\/p>\n\n<h4>Core Integrity and Safe Repair<\/h4>\n\n<p>Core Integrity compares WordPress core files with official checksums and identifies modified files, missing official files and unexpected files inside wp-admin and wp-includes.<\/p>\n\n<p>Scanning is read-only. For selected modified or missing files, Safe Repair downloads the matching official WordPress package, reads only selected files into memory, verifies checksums, writes them through the WordPress Filesystem API and scans again. Pre-repair contents remain in memory for rollback if verification fails. Unexpected files are reported and not deleted.<\/p>\n\n<h4>Diagnostics and Safe File Protection<\/h4>\n\n<p>Diagnostics checks security configuration, public exposure, HTTPS\/SSL behavior, headers, file\/directory protection and WordPress configuration. Some checks request the site's public URLs to verify effective behavior.<\/p>\n\n<p>Safe File Protection can verify directory listing and denial of PHP-like requests in uploads. Its uploads test requests a randomized, non-existent PHP-like URL and creates no probe file. Where supported, Securizer can apply its own marked rules, verify the result immediately and roll back a newly applied rule when it cannot confirm a safe and effective change.<\/p>\n\n<h4>Account Hygiene, Salts and Logs<\/h4>\n\n<p>Account Hygiene reviews administrator usernames, active sessions and Application Passwords, and includes a controlled administrator login-name change workflow. Securizer also audits the eight WordPress authentication keys and salts without displaying or storing their values; explicit rotation includes verification and rollback.<\/p>\n\n<p>Security events are stored locally and can include IP address, attempted username, event type, timestamp and limited event context. Passwords and authentication secrets are never logged. Logs can be reviewed in WordPress administration and exported as CSV.<\/p>\n\n<h4>What Securizer is not<\/h4>\n\n<p>Securizer is not a WAF, cloud malware scanner or vulnerability-intelligence service. It does not replace secure hosting, backups, updates or a dedicated firewall where required.<\/p>\n\n<h3>External services and network requests<\/h3>\n\n<p>Securizer has no product telemetry and does not require a Securizer cloud account.<\/p>\n\n<h4>WordPress.org services<\/h4>\n\n<p>Core Integrity requests official checksums from WordPress.org. When an administrator explicitly runs Safe Repair, Securizer also downloads the matching official WordPress release package and reads only selected repair files from the archive in memory.<\/p>\n\n<p>These requests send the WordPress core version and locale needed for checksum verification or package selection.<\/p>\n\n<p>WordPress.org: https:\/\/wordpress.org\/\nWordPress.org Privacy Policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h4>Requests to the site's own public URLs<\/h4>\n\n<p>Diagnostics, Safe Login URL verification and Safe File Protection can request URLs belonging to the same site to verify redirects, login-route behavior, headers, public exposure and file protection. No Securizer cloud service is involved.<\/p>\n\n<h4>RIPEstat<\/h4>\n\n<p>Security Logs can display a manual Lookup link for eligible public IP addresses. An IP address is opened on RIPEstat only when an administrator explicitly clicks the link.<\/p>\n\n<p>RIPEstat: https:\/\/stat.ripe.net\/\nRIPE NCC Privacy Statement: https:\/\/www.ripe.net\/about-us\/legal\/ripe-ncc-privacy-statement\/<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Securizer stores settings, scan results and security logs locally in the WordPress installation. It does not include product telemetry or send Securizer usage statistics to the developer.<\/p>\n\n<p>Security logs may contain IP addresses and attempted usernames because they are required for login protection and security-event analysis. Securizer provides suggested text in the WordPress Privacy Policy Guide describing its local logging and relevant network behavior.<\/p>\n\n<p>Site administrators are responsible for retained security logs under applicable privacy requirements.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install Securizer through the WordPress plugin installer or upload the plugin ZIP.<\/li>\n<li>Activate Securizer.<\/li>\n<li>Open Securizer from the WordPress administration menu.<\/li>\n<li>Review the initial Diagnostics and Core Integrity baseline.<\/li>\n<li>Review Login Protection and Hardening settings and adjust them if needed.<\/li>\n<\/ol>\n\n<p>A new installation stores conservative defaults and schedules a read-only Diagnostics and Core Integrity baseline. It does not repair files, rotate authentication salts, change the login URL or apply server-level file-protection rules.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20securizer%20include%20a%20firewall%3F\"><h3>Does Securizer include a firewall?<\/h3><\/dt>\n<dd><p>No. Securizer does not include a WAF or replace a server, CDN or dedicated firewall.<\/p><\/dd>\n<dt id=\"does%20securizer%20scan%20for%20malware%3F\"><h3>Does Securizer scan for malware?<\/h3><\/dt>\n<dd><p>Securizer verifies WordPress core integrity against official checksums and can identify unexpected files in core directories. It is not a general-purpose malware scanner.<\/p><\/dd>\n<dt id=\"does%20securizer%20send%20site%20data%20to%20a%20securizer%20server%3F\"><h3>Does Securizer send site data to a Securizer server?<\/h3><\/dt>\n<dd><p>No. Securizer has no product telemetry or Securizer cloud service. Some features use official WordPress.org services, and some diagnostics request the site's own public URLs as documented above.<\/p><\/dd>\n<dt id=\"can%20securizer%20lock%20me%20out%20after%20changing%20the%20login%20url%3F\"><h3>Can Securizer lock me out after changing the login URL?<\/h3><\/dt>\n<dd><p>Safe Login URL verifies the new route before hiding normal anonymous login access, restores the previous configuration if verification fails, and provides an emergency recovery bypass.<\/p><\/dd>\n<dt id=\"how%20do%20i%20enable%20emergency%20recovery%3F\"><h3>How do I enable emergency recovery?<\/h3><\/dt>\n<dd><p>Add this line to wp-config.php:<\/p>\n\n<pre><code>define( 'WPPS_SECURITY_BYPASS', true );\n<\/code><\/pre>\n\n<p>This disables active Securizer protection modules while keeping the administration interface available. Remove the line after resolving the problem.<\/p><\/dd>\n<dt id=\"does%20securizer%20automatically%20repair%20or%20delete%20wordpress%20core%20files%3F\"><h3>Does Securizer automatically repair or delete WordPress core files?<\/h3><\/dt>\n<dd><p>No. Core Integrity scanning is read-only. An administrator can explicitly select modified or missing official core files and run Safe Repair; Securizer validates the matching official WordPress package and re-verifies checksums after replacement. Unexpected files are reported rather than deleted.<\/p><\/dd>\n<dt id=\"will%20securizer%20disable%20another%20security%20plugin%3F\"><h3>Will Securizer disable another security plugin?<\/h3><\/dt>\n<dd><p>No. Securizer can detect known overlapping login-protection functionality and display a compatibility recommendation, but it does not automatically disable or reconfigure another plugin.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20securizer%20is%20deactivated%20or%20deleted%3F\"><h3>What happens when Securizer is deactivated or deleted?<\/h3><\/dt>\n<dd><p>Deactivation preserves Securizer settings, logs and managed file-protection rules. By default, uninstall also preserves stored data; administrators can explicitly enable database cleanup.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Corrected Core Integrity locale selection. When only en_US fallback checksums are available, verification is partial and Safe Repair is blocked for that result.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Hardened Cloudflare client-IP detection.<\/li>\n<li>Prevented Diagnostics warnings with repeated security headers.<\/li>\n<li>Prevented event logging errors when WordPress temporarily uses a database prefix without the Securizer event table.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>WordPress.org review-compliance fixes for safer salt rotation, Safe Login URL styling, Safe Core Repair, uploads protection verification and runtime path compatibility.<\/li>\n<\/ul>","raw_excerpt":"Lightweight WordPress security, login protection, hardening, integrity and diagnostics without a firewall or cloud service.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/355017","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=355017"}],"author":[{"embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wppodrska"}],"wp:attachment":[{"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=355017"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=355017"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=355017"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=355017"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=355017"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/su.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=355017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}