{"id":278927,"date":"2026-03-05T19:06:49","date_gmt":"2026-03-05T19:06:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/security-kit\/"},"modified":"2026-08-25T19:42:42","modified_gmt":"2026-08-25T19:42:42","slug":"srworks-armorlite","status":"publish","type":"plugin","link":"https:\/\/lv.wordpress.org\/plugins\/srworks-armorlite\/","author":23444628,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.30","stable_tag":"1.0.30","tested":"6.9.7","requires":"5.3","requires_php":"7.4","requires_plugins":null,"header_name":"SRWorks ArmorPro","header_author":"SRWorks LLC","header_description":"Free WordPress security with firewall, brute force protection, bot detection, security headers, IP whitelist, and login monitoring. Lightweight, no bloat.","assets_banners_color":"316656","last_updated":"2026-08-25 19:42:42","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/srworks-armorlite\/","header_author_uri":"https:\/\/srworks.co","rating":0,"author_block_rating":0,"active_installs":0,"downloads":521,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"srworks","date":"2026-03-05 19:07:05"},"1.0.25":{"tag":"1.0.25","author":"srworks","date":"2026-04-08 20:47:02"},"1.0.27":{"tag":"1.0.27","author":"srworks","date":"2026-06-27 17:36:43"},"1.0.28":{"tag":"1.0.28","author":"srworks","date":"2026-06-27 17:53:57"},"1.0.30":{"tag":"1.0.30","author":"srworks","date":"2026-08-25 19:42:42"}},"upgrade_notice":{"1.0.30":"<p>Security release. Passkey logins now enforce your configured user verification level, the post-login redirect is restricted to your own site, and admin log rendering is hardened. Settings import no longer drops protections. Recommended for all users.<\/p>","1.0.29":"<p>Every feature is now free and unlimited, including the WAF engine, two-factor authentication, and passkeys. New features arrive switched off, so upgrading does not change how you log in. Visitor IPs are no longer sent to third-party geolocation services.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3475861,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3475861,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3475861,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3475861,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3475861,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner.svg":{"filename":"banner.svg","revision":3475861,"resolution":false,"location":"assets","locale":false}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.25","1.0.27","1.0.28","1.0.30"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Security dashboard with real-time stats, protection status, and blocks over time","2":"Brute force protection with login activity log and lockout settings","3":"Firewall with 600+ patterns, per-pattern toggles, and hit counts","4":"Access control with IP whitelist, blacklist, and country blocking","5":"Two-factor authentication and passkey setup","6":"Settings with security headers and configuration","7":"Tools and diagnostics with health checks and database repair"}},"plugin_section":[262246],"plugin_tags":[2439,1174,602,600,1909],"plugin_category":[54],"plugin_contributors":[257201],"plugin_business_model":[],"class_list":["post-278927","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-firewall","plugin_tags-login","plugin_tags-security","plugin_tags-two-factor-authentication","plugin_category-security-and-spam-protection","plugin_contributors-srworks","plugin_committers-srworks"],"banners":{"banner":"https:\/\/ps.w.org\/srworks-armorlite\/assets\/banner-772x250.png?rev=3475861","banner_2x":"https:\/\/ps.w.org\/srworks-armorlite\/assets\/banner-1544x500.png?rev=3475861","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/srworks-armorlite\/assets\/icon.svg?rev=3475861","icon":"https:\/\/ps.w.org\/srworks-armorlite\/assets\/icon.svg?rev=3475861","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>ArmorPro<\/strong> protects WordPress with a full security stack that runs before your site does. Every feature is free and unlimited. There is no premium tier, no locked panels, and no upgrade prompts.<\/p>\n\n<p>Attacks get blocked at the PHP engine level, roughly a millisecond into the request, before WordPress loads a single file.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>WAF Engine<\/strong> \u2014 Runs before WordPress loads via PHP's auto_prepend_file, adding roughly 1ms of overhead. Blocks malicious requests at the PHP engine level before any WordPress code executes. Detects and configures Apache, NGINX, and LiteSpeed automatically, and falls back to the standard firewall when enhanced mode is unavailable. Enable it from the Firewall tab with one click.<\/li>\n<li><strong>Firewall<\/strong> \u2014 600+ built-in patterns covering SQL injection, XSS, path traversal, and shell access, matched across five categories (Request URI, Query String, User Agent, Referrer, IP Address) in three modes: contains, ends-with, and path-only. Pattern manager with per-pattern toggles, hit counts, and your own custom patterns. Pure PHP, so it works on any server without .htaccess.<\/li>\n<li><strong>Brute Force Protection<\/strong> \u2014 Session-based login tracking with automatic lockouts after a configurable number of failures. Repeat offenders can be auto-blacklisted with an optional expiry. Login activity log records IP, country, status, and the usernames tried.<\/li>\n<li><strong>Two-Factor Authentication<\/strong> \u2014 TOTP for Google Authenticator, Authy, 1Password, and any compatible app. QR code setup, ten backup recovery codes, and role-based enforcement with a grace period.<\/li>\n<li><strong>Passkey Authentication<\/strong> \u2014 Passwordless login with Face ID, Touch ID, Windows Hello, or a hardware security key (WebAuthn\/FIDO2). Multiple passkeys per user with friendly names and clone detection.<\/li>\n<li><strong>Bot Protection<\/strong> \u2014 Honeypot fields, timestamp validation, and JavaScript token verification on login, registration, and password reset forms. Bots are stopped before they can attempt a single password.<\/li>\n<li><strong>Access Control<\/strong> \u2014 IP whitelist and blacklist with inline notes. Country blocking in allow or block mode, backed by a locally stored MaxMind GeoLite2 database.<\/li>\n<li><strong>Custom Login URL<\/strong> \u2014 Move wp-login.php to any slug you choose. The default login returns a 404.<\/li>\n<li><strong>Security Headers<\/strong> \u2014 Seven managed headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, X-XSS-Protection, HSTS, Content-Security-Policy, Permissions-Policy) delivered via PHP and optionally .htaccess, with a header probe that avoids duplicating what your server already sends.<\/li>\n<li><strong>Email Notifications<\/strong> \u2014 Daily and weekly security digests, plus event alerts for blocks, blacklists, firewall hits, and admin logins.<\/li>\n<li><strong>Privacy Hardening<\/strong> \u2014 Author slug randomization to stop user enumeration, and email obfuscation to keep addresses away from scrapers. XML-RPC and REST API protection included.<\/li>\n<li><strong>Dashboard<\/strong> \u2014 Real-time stats, a blocks-over-time chart, protection status cards, and a WordPress dashboard widget.<\/li>\n<li><strong>Tools<\/strong> \u2014 Health checks with database integrity verification, one-click table repair, settings export and import, CSV log export, and debug mode.<\/li>\n<\/ul>\n\n<h4>Privacy by default<\/h4>\n\n<p>Visitor IP addresses never leave your server. Geolocation is resolved against a MaxMind GeoLite2 database stored locally on your own site, not by calling a third-party lookup API. Anonymous usage statistics are off unless you turn them on.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>ArmorPro connects to srworks.co in the situations below. Visitor IP addresses are never sent to any external service.<\/p>\n\n<h4>GeoIP Database Download<\/h4>\n\n<p>To show the country for logged IPs and to power country blocking, ArmorPro downloads a MaxMind GeoLite2 country database and stores it on your server. All lookups then happen locally.<\/p>\n\n<ul>\n<li>When: once when the database is missing, checked on an admin page load at most once per day, then weekly for updates<\/li>\n<li>Data sent: your site URL and the plugin version<\/li>\n<li>Service: https:\/\/api.srworks.co, which returns a link to the database file hosted on SRWorks infrastructure<\/li>\n<li>Database: GeoLite2 Country by MaxMind, https:\/\/www.maxmind.com<\/li>\n<li>Terms: https:\/\/srworks.co\/terms \u2014 Privacy: https:\/\/srworks.co\/privacy<\/li>\n<\/ul>\n\n<p>Individual IP addresses are never sent to this or any other service. Only the database file is transferred, and every lookup runs locally against it.<\/p>\n\n<h4>Anonymous Usage Statistics (Optional, Off by Default)<\/h4>\n\n<p>ArmorPro can share anonymous statistics to help guide development. This is disabled until you explicitly opt in from the Settings page, and can be turned off again at any time.<\/p>\n\n<ul>\n<li>When: on activation and once daily, only after you opt in<\/li>\n<li>Data sent: a one-way hash of your site URL, WordPress version, PHP version, plugin version, and which features are enabled<\/li>\n<li>Service: https:\/\/api.srworks.co<\/li>\n<li>Terms: https:\/\/srworks.co\/terms \u2014 Privacy: https:\/\/srworks.co\/privacy<\/li>\n<\/ul>\n\n<p>No personal data, visitor data, or log contents are included.<\/p>\n\n<h4>License Validation (Unused in This Version)<\/h4>\n\n<p>ArmorPro contains a license client reserved for future AI-powered features, which will carry a per-request cost. No feature in this version is gated behind it, the admin interface has no field for entering a license key, and the AJAX endpoints that would trigger validation are not registered. This client makes no network requests.<\/p>\n\n<ul>\n<li>When: never, in this version<\/li>\n<li>Service: https:\/\/api.srworks.co<\/li>\n<li>Terms: https:\/\/srworks.co\/terms \u2014 Privacy: https:\/\/srworks.co\/privacy<\/li>\n<\/ul>\n\n<h3>Privacy Policy<\/h3>\n\n<p>ArmorPro stores the following in your WordPress database:<\/p>\n\n<ul>\n<li>IP addresses of visitors who trigger a security rule or attempt to log in<\/li>\n<li>Timestamps of security events<\/li>\n<li>Usernames used in login attempts<\/li>\n<li>Country codes resolved locally from the GeoLite2 database<\/li>\n<\/ul>\n\n<p>Clear all logs at any time from the Tools tab. Log retention is 90 days and old entries are pruned daily. Uninstalling the plugin deletes all of it, along with the WAF bootstrap file and any .htaccess or .user.ini directives ArmorPro added.<\/p>\n\n<p>Visitor IP addresses are never transmitted off your server.<\/p>\n\n<h3>Support<\/h3>\n\n<p>Questions, bug reports, and feature requests: https:\/\/srworks.co\/contact<\/p>\n\n<h3>Credits<\/h3>\n\n<p>Firewall patterns inspired by the work of Jeff Starr at Perishable Press (https:\/\/perishablepress.com), used under GPLv2.<\/p>\n\n<p>Charts by Chart.js (https:\/\/www.chartjs.org), MIT License.\nTooltips by Tippy.js (https:\/\/atomiks.github.io\/tippyjs) and Popper (https:\/\/popper.js.org), MIT License.\nQR codes by jquery-qrcode (https:\/\/larsjung.de\/jquery-qrcode\/), MIT License.<\/p>\n\n<p>This product includes GeoLite2 data created by MaxMind, available from https:\/\/www.maxmind.com.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install through Plugins &gt; Add New, or upload the plugin folder to \/wp-content\/plugins\/<\/li>\n<li>Activate the plugin through the Plugins menu in WordPress<\/li>\n<li>Open ArmorPro in your admin menu<\/li>\n<li>Turn on the features you want<\/li>\n<\/ol>\n\n<p>The firewall, brute force protection, and bot protection begin working immediately. The WAF engine, two-factor authentication, passkeys, and custom login URL are opt-in, so nothing changes how you log in until you choose it.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20anything%20paid%20or%20limited%3F\"><h3>Is anything paid or limited?<\/h3><\/dt>\n<dd><p>No. Every feature is free and unlimited, with no premium tier and no upgrade prompts.<\/p><\/dd>\n<dt id=\"does%20armorpro%20work%20with%20nginx%3F\"><h3>Does ArmorPro work with NGINX?<\/h3><\/dt>\n<dd><p>Yes. It runs on Apache, NGINX, LiteSpeed, and others. The standard firewall is pure PHP and needs no server configuration. The WAF engine detects your server type and configures itself.<\/p><\/dd>\n<dt id=\"what%20is%20the%20waf%20engine%3F\"><h3>What is the WAF Engine?<\/h3><\/dt>\n<dd><p>It runs at the PHP engine level, before WordPress begins loading, using PHP's auto_prepend_file directive to intercept malicious requests in roughly a millisecond. It reads from cached flat files for speed and fails open, allowing requests through, if anything goes wrong.<\/p>\n\n<p>Enabling it writes a small bootstrap file to your site root and adds an auto_prepend_file directive to .user.ini or .htaccess, depending on your server. Both are removed when you disable it or uninstall the plugin.<\/p><\/dd>\n<dt id=\"will%20this%20slow%20down%20my%20website%3F\"><h3>Will this slow down my website?<\/h3><\/dt>\n<dd><p>No. The WAF engine adds roughly 1ms. The standard firewall uses fast string matching early in the WordPress load. Blocked requests stop before WordPress finishes loading, which reduces server load during an attack.<\/p><\/dd>\n<dt id=\"how%20does%20brute%20force%20protection%20work%3F\"><h3>How does brute force protection work?<\/h3><\/dt>\n<dd><p>Failed logins are tracked per IP address. After a configurable number of failures the IP is locked out for a configurable duration. Repeat offenders can be auto-blacklisted after a set number of blocks, with an optional expiry so entries clear themselves.<\/p><\/dd>\n<dt id=\"can%20i%20use%20this%20alongside%20another%20security%20plugin%3F\"><h3>Can I use this alongside another security plugin?<\/h3><\/dt>\n<dd><p>Yes, though features may overlap. Test before relying on both. Running two WAFs or two custom login URLs at once is not recommended.<\/p><\/dd>\n<dt id=\"how%20do%20i%20whitelist%20my%20ip%20address%3F\"><h3>How do I whitelist my IP address?<\/h3><\/dt>\n<dd><p>Go to ArmorPro &gt; Access Control and add it to the whitelist. Whitelisted IPs bypass every security check, including brute force lockouts and firewall blocking.<\/p><\/dd>\n<dt id=\"i%20locked%20myself%20out.%20what%20now%3F\"><h3>I locked myself out. What now?<\/h3><\/dt>\n<dd><p>Add <code>define('ARMOR_DISABLE', true);<\/code> to wp-config.php to bypass all protection, or create a file named <code>.emergency-bypass<\/code> in the plugin directory. Either one restores access so you can fix the setting and remove the bypass.<\/p><\/dd>\n<dt id=\"what%20data%20does%20armorpro%20collect%3F\"><h3>What data does ArmorPro collect?<\/h3><\/dt>\n<dd><p>Security logs are stored locally in your WordPress database: IP addresses that trigger a rule or attempt a login, timestamps, and attempted usernames. Visitor data is never sent to a third party. Anonymous usage statistics are optional and off by default. See External Services below for every outbound connection the plugin can make.<\/p><\/dd>\n<dt id=\"what%20does%20the%20bot%20protection%20do%3F\"><h3>What does the bot protection do?<\/h3><\/dt>\n<dd><p>Bot protection adds invisible honeypot fields, timestamp validation, and JavaScript token verification to login, registration, and password reset forms. Automated bots that submit forms without rendering JavaScript or that submit too quickly are blocked before they can attempt brute force attacks.<\/p><\/dd>\n<dt id=\"can%20i%20block%20specific%20countries%20from%20accessing%20my%20site%3F\"><h3>Can I block specific countries from accessing my site?<\/h3><\/dt>\n<dd><p>Yes. Country blocking lets you allow only specific countries (whitelist mode) or block specific countries (blacklist mode) from accessing your login page. Uses MaxMind GeoLite2 database stored locally for fast, unlimited lookups. Note: country blocking currently applies to login page access; the firewall provides separate protection for all other requests.<\/p><\/dd>\n<dt id=\"how%20do%20i%20protect%20my%20wordpress%20login%20page%3F\"><h3>How do I protect my WordPress login page?<\/h3><\/dt>\n<dd><p>ArmorPro offers multiple login protection features: brute force protection with automatic lockouts, bot detection, two-factor authentication, passkey login, REST API protection to block enumeration, author slug obfuscation to hide usernames, and a custom login URL to hide wp-login.php entirely.<\/p><\/dd>\n<dt id=\"does%20armorpro%20support%20two-factor%20authentication%3F\"><h3>Does ArmorPro support two-factor authentication?<\/h3><\/dt>\n<dd><p>Yes! ArmorPro includes built-in two-factor authentication (2FA) using TOTP (Time-based One-Time Password). Users can set up any authenticator app like Google Authenticator, Authy, or 1Password. Backup codes are also provided in case you lose access to your device. Passkey authentication (Face ID, Touch ID, Windows Hello) is also supported as an alternative.<\/p><\/dd>\n<dt id=\"does%20armorpro%20protect%20against%20malware%3F\"><h3>Does ArmorPro protect against malware?<\/h3><\/dt>\n<dd><p>ArmorPro focuses on prevention: stopping attacks before they compromise your site. The firewall blocks SQL injection, XSS, and other common attack vectors. For malware scanning and removal, we recommend pairing with a dedicated malware scanner.<\/p><\/dd>\n<dt id=\"how%20do%20i%20block%20bad%20bots%20and%20scrapers%3F\"><h3>How do I block bad bots and scrapers?<\/h3><\/dt>\n<dd><p>ArmorPro blocks malicious request patterns via the firewall and includes Bad User Agent blocking with a curated list of known malicious bots, scrapers, and vulnerability scanners that's regularly updated. Bot protection adds additional automated detection on login forms.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20an%20ip%20is%20blocked%3F\"><h3>What happens when an IP is blocked?<\/h3><\/dt>\n<dd><p>Blocked visitors see a professional \"Access Blocked\" page with a 403 status code. The page is clean and branded, informing them to contact the site administrator if they believe it's an error.<\/p><\/dd>\n<dt id=\"can%20i%20export%20security%20logs%3F\"><h3>Can I export security logs?<\/h3><\/dt>\n<dd><p>Yes. You can export login activity, firewall blocks, and blacklist data to CSV files for analysis or compliance reporting.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20caching%20plugins%3F\"><h3>Is it compatible with caching plugins?<\/h3><\/dt>\n<dd><p>Yes, including WP Rocket, W3 Total Cache, LiteSpeed Cache, and WP Super Cache. The firewall runs ahead of caching layers and sets appropriate cache-control headers.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.30<\/h4>\n\n<ul>\n<li>Security: passkey logins now enforce the configured user verification level. When set to \"Required\", the server verifies that the authenticator actually performed PIN or biometric verification instead of accepting possession of the key alone. Applies to both passkey registration and login.<\/li>\n<li>Security: the redirect target after a passkey login is now restricted to your own site, falling back to the dashboard.<\/li>\n<li>Security: hardened HTML escaping in admin tables so logged request data cannot inject markup attributes when viewing the Firewall log.<\/li>\n<li>Fixed: settings import now merges over defaults instead of replacing them, so importing a partial or older export can no longer switch protections off. Bot protection is now included in import\/export.<\/li>\n<li>Fixed: unlock request rate limiting is now per visitor. Previously a handful of requests from any one client could block the recovery route for every administrator.<\/li>\n<li>Deployment tooling now verifies the release host's SSH key.<\/li>\n<\/ul>\n\n<h4>1.0.29<\/h4>\n\n<ul>\n<li><strong>ArmorPro is now completely free.<\/strong> Every feature that previously required a license is unlocked for everyone, with no limits: WAF engine, two-factor authentication, passkey login, custom login URL, IP blacklist, country blocking, HSTS, Content-Security-Policy, Permissions-Policy, email notifications, custom firewall patterns, and settings export\/import.<\/li>\n<li>Your existing settings, firewall patterns, IP lists and logs are carried over automatically on update. Protection stays on throughout; nothing needs reconfiguring.<\/li>\n<li>Log retention increased from 7 to 90 days for all installs.<\/li>\n<li><strong>New features arrive switched off.<\/strong> Upgrading changes nothing about how you or your users log in. The WAF engine, two-factor authentication, passkeys, and custom login URL are all opt-in, and none of them touch your site until you enable them.<\/li>\n<li>Removed: activating the plugin no longer writes to your site's root .htaccess. Security headers are delivered over PHP from the first request, and .htaccess is only written when you save settings.<\/li>\n<li>Privacy: removed third-party geolocation lookups. Visitor IP addresses are no longer sent to any external service. Country data is now resolved entirely from the local GeoLite2 database.<\/li>\n<li>Anonymous usage statistics now default to off for every install and require explicit opt-in.<\/li>\n<li>Removed all upgrade prompts and the license activation screen.<\/li>\n<\/ul>\n\n<h4>1.0.28<\/h4>\n\n<ul>\n<li>Fixed: Firewall false positive that could 403 legitimate requests carrying a URL in a query parameter (OAuth redirect_uri, social share links, payment return URLs, callbacks). Removed the over-broad http(s)\/ftp(s) protocol-in-query rules; PHP stream wrapper signatures (php:\/\/, phps:\/\/) are unchanged. Existing installs are cleaned up automatically on update.<\/li>\n<\/ul>\n\n<h4>1.0.27<\/h4>\n\n<ul>\n<li>Fixed: Firewall false positive that could 403 legitimate requests containing array or JSON style query parameters (e.g. Fluent Forms entry filters, WooCommerce faceted filters, REST list endpoints). Removed the over-broad bare [ ] { } ? query string rules; targeted bracket attack signatures (GLOBALS[, REQUEST[, etc.) are unchanged. Existing installs are cleaned up automatically on update.<\/li>\n<\/ul>\n\n<h4>1.0.26<\/h4>\n\n<ul>\n<li>Fixed: Enhanced WAF verification incorrectly reported 'not active' on sites using page caching (fastcgi_cache, Cloudflare, Varnish, LiteSpeed, WP Super Cache, WP Rocket, BoostPro). The check now uses a cache-immune heartbeat and probes a URL that page caches always bypass.<\/li>\n<\/ul>\n\n<h4>1.0.25<\/h4>\n\n<ul>\n<li>Bug fixes and improvements<\/li>\n<\/ul>\n\n<h4>1.0.24<\/h4>\n\n<ul>\n<li>Bug fixes and improvements<\/li>\n<\/ul>\n\n<h4>1.0.23<\/h4>\n\n<ul>\n<li>Bug fixes and improvements<\/li>\n<\/ul>\n\n<h4>1.0.22<\/h4>\n\n<ul>\n<li>Remove bundle license auto-activation (per-plugin keys now)<\/li>\n<\/ul>\n\n<h4>1.0.21<\/h4>\n\n<ul>\n<li>Switch file extension firewall patterns to contains_path match mode<\/li>\n<\/ul>\n\n<h4>1.0.20<\/h4>\n\n<ul>\n<li>Fix false positives on file extension patterns matching query string URLs<\/li>\n<li>Widen match_mode column to support contains_path value<\/li>\n<\/ul>\n\n<h4>1.0.19<\/h4>\n\n<ul>\n<li>Add input normalization pipeline to firewall, misc fixes<\/li>\n<\/ul>\n\n<h4>1.0.18<\/h4>\n\n<ul>\n<li>Bug fixes and improvements<\/li>\n<\/ul>\n\n<h4>1.0.17<\/h4>\n\n<ul>\n<li>Redesign firewall block pages with ASCII art branding<\/li>\n<li>Add email unlock recovery and emergency bypass file for lockout prevention<\/li>\n<li>Add email unlock recovery, branded HTML block page, and email template system<\/li>\n<\/ul>\n\n<h4>1.0.16<\/h4>\n\n<ul>\n<li>Auto-update WAF engine on plugin upgrade<\/li>\n<li>Add REST API protection compatibility warning<\/li>\n<\/ul>\n\n<h4>1.0.15<\/h4>\n\n<ul>\n<li>Fix WAF false positives on wp-login redirect URLs<\/li>\n<li>Plain text block pages with dynamic reasons<\/li>\n<li>Fix notification init order and per-IP rate limiting<\/li>\n<\/ul>\n\n<h4>1.0.14<\/h4>\n\n<ul>\n<li>Bug fixes and stability improvements<\/li>\n<\/ul>\n\n<h4>1.0.13<\/h4>\n\n<ul>\n<li>Replace partner SDK with lightweight telemetry<\/li>\n<li>Code cleanup and UI refinements<\/li>\n<\/ul>\n\n<h4>1.0.12<\/h4>\n\n<ul>\n<li>Add standalone WAF engine with enhanced firewall patterns and endswith matching<\/li>\n<li>Remove login from reserved slugs for custom login URL<\/li>\n<li>Security hardening, dead code removal, and PHPCS compliance<\/li>\n<li>UI refinements and admin JS cleanup<\/li>\n<\/ul>\n\n<h4>1.0.11<\/h4>\n\n<ul>\n<li>Allow 'login' as custom login slug<\/li>\n<\/ul>\n\n<h4>1.0.10<\/h4>\n\n<ul>\n<li>Add authentication enforcement with grace period<\/li>\n<li>Suppress passkey nudge when enforcement is active<\/li>\n<\/ul>\n\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>Update readme.txt with high-level feature descriptions and vendor credits<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Remove all Pro\/free tier distinctions from readme.txt<\/li>\n<li>Fix duplicate changelog entries in readme.txt<\/li>\n<li>Fix activation crash, security headers UI, and cleanup completeness<\/li>\n<li>Add license secret comment, RUJS firewall bypass, and uninstall completeness<\/li>\n<li>Unify toast notifications, fix firewall and TOTP improvements<\/li>\n<li>Audit fixes: firewall execution, pattern matching, XSS hardening, dead code removal<\/li>\n<li>Increment hit counts for all matching patterns, not just the first<\/li>\n<li>Switch firewall from regex to string matching for improved performance<\/li>\n<li>Admin UI improvements, database hardening, passkeys and firewall updates<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Admin UI refinements: card header font size, toggle colors, remove rule ID column<\/li>\n<li>Remove all Pro\/free tier distinctions from readme.txt<\/li>\n<li>Split bundled firewall rules into individual toggles, remove cookies from rule manager<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>Replace Space Grotesk with Inter for headings, remove unused font files<\/li>\n<li>Hide third-party admin notices on ArmorPro settings page<\/li>\n<li>Add security headers management, admin UI enhancements, and deploy script updates<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Bug fixes and improvements<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Bug fixes and improvements<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Bug fixes and enhancements<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Bug fixes and stability improvements<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>Brute force protection with configurable thresholds<\/li>\n<li>PHP firewall with SQL injection and XSS protection<\/li>\n<li>Security headers (X-Content-Type, X-Frame-Options, Referrer-Policy, X-XSS-Protection, HSTS, CSP, Permissions Policy)<\/li>\n<li>XML-RPC and REST API protection<\/li>\n<li>Author slug and email obfuscation<\/li>\n<li>IP whitelist and temporary blocking<\/li>\n<li>Geolocation with MaxMind GeoLite2<\/li>\n<li>Two-factor authentication (TOTP) with backup codes<\/li>\n<li>Country blocking, custom login URL, permanent blacklist<\/li>\n<li>Auto-blacklist repeat offenders<\/li>\n<li>Email notifications and security digests<\/li>\n<li>Extended logging and CSV export<\/li>\n<\/ul>","raw_excerpt":"Free WordPress security: WAF, firewall, brute force protection, two-factor authentication, passkeys, country blocking, and security headers.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/278927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=278927"}],"author":[{"embeddable":true,"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/srworks"}],"wp:attachment":[{"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=278927"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=278927"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=278927"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=278927"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=278927"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/lv.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=278927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}