{"id":334812,"date":"2026-07-31T07:32:18","date_gmt":"2026-07-31T07:32:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/brainwerk-security-suite\/"},"modified":"2026-08-05T12:52:34","modified_gmt":"2026-08-05T12:52:34","slug":"brainwerk-security-suite","status":"publish","type":"plugin","link":"https:\/\/es-mx.wordpress.org\/plugins\/brainwerk-security-suite\/","author":23503111,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.18.0","stable_tag":"0.18.0","tested":"7.0.3","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Brainwerk Security Suite","header_author":"Stefan Kogelgruber","header_description":"Privacy-first WordPress security suite, designed for EU compliance and Multisite installations. Lightweight, transparent, GDPR-ready.","assets_banners_color":"0d1c35","last_updated":"2026-08-05 12:52:34","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/brainwerk.at","rating":0,"author_block_rating":0,"active_installs":0,"downloads":172,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.14.4":{"tag":"0.14.4","author":"brainwerk","date":"2026-07-31 07:31:41"},"0.15.0":{"tag":"0.15.0","author":"brainwerk","date":"2026-07-31 16:31:20"},"0.16.0":{"tag":"0.16.0","author":"brainwerk","date":"2026-08-01 15:09:58"},"0.17.0":{"tag":"0.17.0","author":"brainwerk","date":"2026-08-01 17:36:13"},"0.18.0":{"tag":"0.18.0","author":"brainwerk","date":"2026-08-05 12:52:34"}},"upgrade_notice":{"1.0.0":"<p>First stable release. Documents the full module set (incl. WAF) and corrects the Free\/Pro boundary in docs. No breaking changes; internal class\/table names unchanged.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3629833,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3629833,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3629571,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3629571,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.14.4","0.15.0","0.16.0","0.17.0","0.18.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3629613,"resolution":"1","location":"assets","locale":"","width":1388,"height":1458},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3629613,"resolution":"10","location":"assets","locale":"","width":2560,"height":3552},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3629613,"resolution":"2","location":"assets","locale":"","width":2560,"height":4482},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3629613,"resolution":"3","location":"assets","locale":"","width":2560,"height":3200},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3629613,"resolution":"4","location":"assets","locale":"","width":2560,"height":1978},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3629613,"resolution":"5","location":"assets","locale":"","width":2560,"height":3386},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3629613,"resolution":"6","location":"assets","locale":"","width":2560,"height":4324},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3629613,"resolution":"7","location":"assets","locale":"","width":2560,"height":3424},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3629613,"resolution":"8","location":"assets","locale":"","width":2560,"height":5226},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3629613,"resolution":"9","location":"assets","locale":"","width":1524,"height":3424}},"screenshots":{"1":"Dashboard widget \u2014 threat-score header, action items, 24h stat grid with trend arrows, system-status strip, top attackers + targeted users, recent events.","2":"Scanner tab \u2014 file-integrity baseline status, run-now controls, findings table with re-baseline \/ whitelist actions, code-snippet preview for malware-pattern hits.","3":"Vulnerabilities tab \u2014 per-component listing of known CVEs, CVSS scores, fixed-in versions, links to CVE \/ EUVD advisories, active-vs-inactive flagging.","4":"2FA tab \u2014 module enable, force-by-role policy, per-user enrollment status with rescue-disable for lost-device recovery.","5":"Audit tab \u2014 who-changed-what timeline with per-event-type renderer, filter dropdown, 7-day distribution badges.","6":"Modules tab \u2014 WAF with paranoia levels + false-positive viewer, security headers, HaveIBeenPwned, trusted devices, live traffic, captcha, magic links, privacy dashboard.","7":"Hardening+ tab \u2014 custom login URL with live-preview + lockout-recovery hint, honeypot anti-bot toggles, per-header security toggles incl. CSP report-only mode.","8":"Anomaly tab \u2014 Z-score model, per-user baseline status, recent anomalies with explainable context.","9":"Logs tab \u2014 searchable activity log with quick block \/ unblock actions.","10":"Privacy \/ GDPR \u2014 anonymization, pseudonymization, retention, data map, Art. 15 \/ Art. 17 workflows, privacy-policy snippet generator."}},"plugin_section":[262246],"plugin_tags":[2439,1174,55021,600,9217],"plugin_category":[54],"plugin_contributors":[268198],"plugin_business_model":[],"class_list":["post-334812","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-firewall","plugin_tags-malware-scanner","plugin_tags-security","plugin_tags-two-factor","plugin_category-security-and-spam-protection","plugin_contributors-brainwerk","plugin_committers-brainwerk"],"banners":{"banner":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/banner-772x250.png?rev=3629571","banner_2x":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/banner-1544x500.png?rev=3629571","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/icon-128x128.png?rev=3629833","icon_2x":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/icon-256x256.png?rev=3629833","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-1.png?rev=3629613","caption":"Dashboard widget \u2014 threat-score header, action items, 24h stat grid with trend arrows, system-status strip, top attackers + targeted users, recent events."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-2.png?rev=3629613","caption":"Scanner tab \u2014 file-integrity baseline status, run-now controls, findings table with re-baseline \/ whitelist actions, code-snippet preview for malware-pattern hits."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-3.png?rev=3629613","caption":"Vulnerabilities tab \u2014 per-component listing of known CVEs, CVSS scores, fixed-in versions, links to CVE \/ EUVD advisories, active-vs-inactive flagging."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-4.png?rev=3629613","caption":"2FA tab \u2014 module enable, force-by-role policy, per-user enrollment status with rescue-disable for lost-device recovery."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-5.png?rev=3629613","caption":"Audit tab \u2014 who-changed-what timeline with per-event-type renderer, filter dropdown, 7-day distribution badges."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-6.png?rev=3629613","caption":"Modules tab \u2014 WAF with paranoia levels + false-positive viewer, security headers, HaveIBeenPwned, trusted devices, live traffic, captcha, magic links, privacy dashboard."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-7.png?rev=3629613","caption":"Hardening+ tab \u2014 custom login URL with live-preview + lockout-recovery hint, honeypot anti-bot toggles, per-header security toggles incl. CSP report-only mode."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-8.png?rev=3629613","caption":"Anomaly tab \u2014 Z-score model, per-user baseline status, recent anomalies with explainable context."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-9.png?rev=3629613","caption":"Logs tab \u2014 searchable activity log with quick block \/ unblock actions."},{"src":"https:\/\/ps.w.org\/brainwerk-security-suite\/assets\/screenshot-10.png?rev=3629613","caption":"Privacy \/ GDPR \u2014 anonymization, pseudonymization, retention, data map, Art. 15 \/ Art. 17 workflows, privacy-policy snippet generator."}],"raw_content":"<!--section=description-->\n<p>Brainwerk Security Suite is a modern, lightweight security plugin built for the European market. It treats privacy as a first-class feature, not an afterthought, and is designed for WordPress Multisite from day one.<\/p>\n\n<h4>Why another security plugin?<\/h4>\n\n<ul>\n<li><strong>Made in EU \/ GDPR-First<\/strong> \u2014 IP anonymization is on by default, retention is configurable, the data map is published in the admin so you can paste it straight into your privacy policy.<\/li>\n<li><strong>Multisite-aware<\/strong> \u2014 network-wide configuration with clean per-site overrides. (A cross-site <em>aggregate<\/em> dashboard is available in Pro.)<\/li>\n<li><strong>A full free feature set<\/strong> \u2014 a real Web Application Firewall, TOTP 2FA, plugin\/theme\/core vulnerability scanner, file-integrity monitor, malware-pattern scan, and audit log \u2014 all free.<\/li>\n<li><strong>No Google Fonts, no third-party cookies by default<\/strong> \u2014 the default anti-bot is a 100% local honeypot (no reCAPTCHA). An optional hCaptcha \/ Cloudflare Turnstile captcha is available if you choose to enable it.<\/li>\n<li><strong>Transparent about external calls<\/strong> \u2014 every outbound connection is documented in the <strong>External services<\/strong> section below. Out of the box the plugin makes <strong>no<\/strong> automatic outbound calls: the daily vulnerability lookup (EU-hosted, self-hostable) and every other integration are strictly opt-in and off by default.<\/li>\n<\/ul>\n\n<h4>Free features \u2014 defense in depth<\/h4>\n\n<p><strong>Login &amp; accounts<\/strong><\/p>\n\n<ul>\n<li>Login activity log (success \/ failure \/ blocked)<\/li>\n<li>Brute-force protection: IP-based AND account-based (botnet rotates IPs, account stays locked)<\/li>\n<li>IP whitelist (single IPs and CIDR)<\/li>\n<li>TOTP two-factor authentication (RFC 6238) \u2014 works with Google Authenticator, Microsoft Authenticator, Authy, 2FAS, FreeOTP, Aegis. 8 single-use recovery codes per user. Force-by-role.<\/li>\n<li>Magic login links \u2014 optional passwordless e-mail login: single-use, 15-minute, rate-limited links, with user-enumeration protection.<\/li>\n<li>Trusted devices \u2014 optional new-device e-mail warning (account-takeover early warning), device fingerprint from UA + IP-subnet + Accept-Language.<\/li>\n<li>Have I Been Pwned password check \u2014 optional, warns on breached passwords via k-anonymity (only a SHA-1 prefix is sent; the password never leaves your server).<\/li>\n<li>Honeypot anti-bot on login \/ register \/ comment forms \u2014 100% local, no reCAPTCHA, no Google data transfer.<\/li>\n<li>Optional hCaptcha \/ Cloudflare Turnstile captcha as an alternative to the honeypot (bring your own keys).<\/li>\n<li>Custom login URL \u2014 rewrite wp-login.php to a path of your choice; the original returns 404. Lockout-recovery via wp-config define.<\/li>\n<\/ul>\n\n<p><strong>Firewall &amp; rate limiting<\/strong><\/p>\n\n<ul>\n<li><strong>Web Application Firewall (WAF)<\/strong> \u2014 40+ curated regex signatures for SQLi, XSS, LFI, RCE, SSRF, XXE, command injection, WP user-enumeration and scanner user-agents. Three paranoia levels, admin allowlist, path allowlist, a false-positive viewer with one-click whitelisting, and optional 24h IP auto-block. Off by default \u2014 start at level 1.<\/li>\n<li>Crawler \/ request rate limiter to blunt aggressive scraping and enumeration bursts.<\/li>\n<\/ul>\n\n<p><strong>File integrity &amp; malware<\/strong><\/p>\n\n<ul>\n<li>SHA-256 file-integrity monitor over WP core, mu-plugins, plugins, and themes (default: ~10k files indexed). Daily wp-cron sweep detects added \/ changed \/ missing files.<\/li>\n<li>Pattern-based suspicious-code scan (16 rules) on every changed file: <code>eval(base64_decode(...))<\/code>, webshell signatures (c99\/r57\/WSO\/b374k), inline <code>wp_insert_user(role=admin)<\/code>, <code>preg_replace \/e<\/code>, remote include via URL \u2014 runs only against deltas, not full corpus, so it stays cheap.<\/li>\n<li>Core-file compare \u2014 verify every WordPress core file against the official wordpress.org MD5 manifest to find modified \/ missing \/ extra files. Local only, nothing uploaded.<\/li>\n<li>Repository-integrity check \u2014 detection-only comparison of installed plugins\/themes against the official wordpress.org packages; reports tampering and links you to the standard reinstall flow (never writes to your plugin\/theme files).<\/li>\n<\/ul>\n\n<p><strong>Vulnerability scanner<\/strong><\/p>\n\n<ul>\n<li>Opt-in daily check (off by default) of every installed plugin \/ theme \/ core version against an EU-hosted vulnerability API (default <code>shieldforge-intel.brainwerk.at<\/code>), which aggregates public sources (wpvulnerability.net, EUVD). No API key. The endpoint is configurable \u2014 point it at a self-hosted mirror. See <strong>External services<\/strong> below for exactly what is sent.<\/li>\n<li>CVE-IDs and CVSS scores with direct links; flagged ACTIVE vs INACTIVE so you know which to update first.<\/li>\n<\/ul>\n\n<p><strong>Hardening<\/strong><\/p>\n\n<ul>\n<li>One-click toggles: disable XML-RPC (and always strip the brute-force-amplifying <code>system.multicall<\/code>), hide WordPress version, block author enumeration, restrict REST API for anonymous visitors (users \/ comments \/ search \/ settings \/ themes \/ plugins endpoints).<\/li>\n<li>Security HTTP headers \u2014 per-header toggle: X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS, Cross-Origin-Opener-Policy (COOP), Cross-Origin-Resource-Policy (CORP).<\/li>\n<li>Content-Security-Policy with Report-Only mode for safe rollout \u2014 opt-in.<\/li>\n<li>Disable file editor in admin.<\/li>\n<\/ul>\n\n<p><strong>Detection &amp; response<\/strong><\/p>\n\n<ul>\n<li>404 probing tracker (<code>.env<\/code>, <code>wp-config.bak<\/code>, <code>xmlrpc.php<\/code> and friends).<\/li>\n<li><strong>Anomaly detection<\/strong> \u2014 explainable Z-score model on login_hour \/ IP family \/ user-agent class, per-user adaptive baseline, no cloud calls.<\/li>\n<li>Live-traffic monitor \u2014 optional ring buffer of the last ~1000 \"interesting\" requests (login, POST, admin, AJAX, XML-RPC) for forensics, auto-cleaned.<\/li>\n<li><strong>Incident Commander<\/strong> \u2014 post-incident forensics and one-click lockdown to contain an active compromise.<\/li>\n<li><strong>Audit trail<\/strong> \u2014 who changed what when: post edits, user changes, plugin\/theme\/core updates, security-sensitive option changes (siteurl, admin_email, users_can_register, default_role, network site_admins ...). Useful for incident response and DSGVO Art. 32 compliance.<\/li>\n<\/ul>\n\n<p><strong>Threat Network (opt-in)<\/strong><\/p>\n\n<ul>\n<li>Optional community threat-intelligence sensor: your site contributes fact-only, hashed attack telemetry and in return receives a signed feed of known-malicious IP indicators. Off by default; raw IPs never leave your server. See <strong>External services<\/strong> below.<\/li>\n<\/ul>\n\n<p><strong>Admin experience<\/strong><\/p>\n\n<ul>\n<li>WordPress dashboard widget with <strong>transparent threat score<\/strong> (0\u2013100), action items, system-status strip, top attackers, recent events.<\/li>\n<li>Daily digest email with threat score, 24h-vs-7d trend, ASCII heatmap, top targeted usernames, top probing patterns, vulnerable-active-components \u2014 pure ASCII so it renders identically through every mail pipeline (php mail \/ SMTP \/ OAuth-SMTP \/ Microsoft Graph).<\/li>\n<li><strong>Healthcheck banner<\/strong> \u2014 auto-detects setup issues (proxy IP masking, anonymization off, brute-force disabled) so admins can't ship a broken config.<\/li>\n<li>Quiet hours that critical alerts can override.<\/li>\n<\/ul>\n\n<p><strong>Privacy &amp; GDPR<\/strong><\/p>\n\n<ul>\n<li>IP anonymization (default on, \/24 for IPv4, \/64 for IPv6), username pseudonymization, configurable log retention with daily cleanup, retroactive anonymization helper.<\/li>\n<li>Privacy dashboard: published data map, one-click DSGVO Art. 15 (access) and Art. 17 (erasure) request workflows.<\/li>\n<li>Privacy-policy snippet generator (DE \/ EN).<\/li>\n<li>Multisite-aware: network-activate, per-site overrides.<\/li>\n<li><strong>Onboarding wizard in 6 languages<\/strong> \u2014 DE \/ EN \/ FR \/ IT \/ PL \/ ES, language picker as first step.<\/li>\n<\/ul>\n\n<h4>Pro features (separate companion plugin)<\/h4>\n\n<p>Brainwerk Security Suite Pro is an optional paid companion plugin. Details and pricing: https:\/\/security-suite.brainwerk.at<\/p>\n\n<ul>\n<li>WebAuthn \/ Passkeys (FIDO2) \u2014 phishing-resistant login alongside the free TOTP 2FA<\/li>\n<li>Geo-blocking with a regularly updated country database (allow\/deny on login, register, comment, REST)<\/li>\n<li>Cloud threat intelligence feed (EU-hosted, opt-in, Ed25519-signed)<\/li>\n<li>Slack \/ Discord \/ Mattermost \/ Telegram \/ MS Teams notifications<\/li>\n<li>Aggregate Multisite dashboard for agencies (cross-site attacker view, per-site scores, network-wide 2FA coverage)<\/li>\n<li>AI-assisted incident analysis (bring-your-own-key Mistral or self-hosted Ollama)<\/li>\n<li>Whitelabel mode<\/li>\n<li>Priority support<\/li>\n<\/ul>\n\n<h3>Privacy Policy<\/h3>\n\n<h4>Data stored in your WordPress database (never leaves the server)<\/h4>\n\n<ul>\n<li><strong>Login events<\/strong>: timestamp, event type (success \/ failure \/ blocked \/ 2FA required \/ 2FA passed \/ 2FA failed \/ logout), username (or hashed pseudonym if pseudonymization is on), IP address (or anonymized \/24 if IP anonymization is on \u2014 default), user-agent, request URI.<\/li>\n<li><strong>Brute-force blocks<\/strong>: blocked IP, reason, expiry timestamp.<\/li>\n<li><strong>WAF blocks<\/strong>: anonymized IP, request URI, matched rule name, timestamp.<\/li>\n<li><strong>Live-traffic buffer<\/strong> (if enabled): method, anonymized IP, request path, status code for the last ~1000 interesting requests.<\/li>\n<li><strong>Anomaly baselines<\/strong>: per-user statistical aggregates (mean and variance of login_hour, IP family, user-agent class). No raw login history is retained beyond the rolling log retention window (default 30 days).<\/li>\n<li><strong>File-integrity baseline<\/strong>: SHA-256 hash + size + mtime + tracked path of every PHP file under WP core \/ plugins \/ mu-plugins \/ themes. Used to detect added \/ changed \/ missing files. The file <em>contents<\/em> are never stored \u2014 only the hash.<\/li>\n<li><strong>2FA secrets<\/strong> (per user, if user enrolled): base32-encoded TOTP secret, sha256-hashed recovery codes (the plain codes are shown ONCE on enrollment and never persisted).<\/li>\n<li><strong>Trusted devices<\/strong> (if enabled): hashed device fingerprints per user.<\/li>\n<li><strong>Audit trail<\/strong>: who edited which post \/ user \/ option \/ theme \/ plugin, with field-level diffs (no post-content bodies, no password hashes \u2014 only <code>[changed]<\/code> markers for sensitive fields).<\/li>\n<li><strong>Site option<\/strong>: configuration values, last cron timestamps.<\/li>\n<\/ul>\n\n<h4>Data sent to external services<\/h4>\n\n<p>The plugin makes no automatic outbound calls until you opt in. The one you are most likely to enable is the vulnerability scanner, which \u2014 once switched on \u2014 queries an EU-hosted vulnerability API (default <code>https:\/\/shieldforge-intel.brainwerk.at\/<\/code>) once per day. It is off by default; the endpoint is configurable and the feature can be disabled again at any time.<\/p>\n\n<ul>\n<li><strong>What is sent<\/strong>: per HTTP GET, one slug + one version per installed component (plugin \/ theme \/ core). Example: <code>GET \/v1\/vulns\/plugin\/contact-form-7\/<\/code>.<\/li>\n<li><strong>What is NOT sent<\/strong>: site URL, domain, admin email, IP addresses, user information, content, settings.<\/li>\n<li><strong>Provider<\/strong>: <code>shieldforge-intel.brainwerk.at<\/code> is Brainwerk's own EU-hosted API that aggregates public vulnerability data (wpvulnerability.net, EUVD).<\/li>\n<li><strong>Enable \/ disable<\/strong>: Brainwerk Security Suite \u2192 Vulnerabilities \u2192 Settings \u2192 Enable scanner (off by default).<\/li>\n<li><strong>Self-host<\/strong>: point the endpoint setting at your own mirror to keep everything in your network.<\/li>\n<\/ul>\n\n<p>Several <strong>opt-in<\/strong> features contact external services only after you enable them \u2014 see the <strong>External services<\/strong> section below for the full list, the exact data sent, and how to turn each off.<\/p>\n\n<h4>Lifecycle<\/h4>\n\n<p>All Brainwerk Security Suite data is deleted on plugin uninstall (DB tables dropped, options removed, user-meta wiped, transients purged). The configurable log retention is enforced by a daily cron.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin can connect to the external services listed below. <strong>Every one of them is opt-in and off by default<\/strong> \u2014 out of the box the plugin contacts nothing. Each can be disabled again at any time, and the vulnerability endpoint can be re-pointed at a self-hosted mirror.<\/p>\n\n<p><strong>1. Brainwerk Vulnerability API \u2014 <code>https:\/\/shieldforge-intel.brainwerk.at\/<\/code> \u2014 OPT-IN, default OFF<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Daily vulnerability lookup for every plugin, theme and WordPress-core version installed on your site. Surfaces known CVEs, CVSS scores and fixed-in versions in the <em>Vulnerabilities<\/em> tab.<\/li>\n<li><strong>When data is sent:<\/strong> Never until you enable the scanner. Once enabled, once per day via WP-Cron (plus any manual \"Scan now\" you trigger).<\/li>\n<li><strong>What data is sent:<\/strong> One HTTP GET per installed component, with the component slug and version in the path (e.g. <code>GET \/v1\/vulns\/plugin\/contact-form-7\/<\/code>). No site URL, no domain, no admin email, no IP, no user data, no content, no settings.<\/li>\n<li><strong>How to disable:<\/strong> <em>Brainwerk Security Suite \u2192 Vulnerabilities \u2192 Settings \u2192 Enable scanner = off<\/em>.<\/li>\n<li><strong>Self-host \/ re-point:<\/strong> set the endpoint option to your own mirror to keep everything inside your network.<\/li>\n<li><strong>Provider:<\/strong> <code>shieldforge-intel.brainwerk.at<\/code> is Brainwerk's own EU-hosted API that aggregates public vulnerability data (wpvulnerability.net \u2014 a community mirror of WPScan \/ Patchstack \u2014 and the EU Vulnerability Database, EUVD). Operated by Brainwerk (EU). Privacy: <a href=\"https:\/\/brainwerk.at\/privacy\">https:\/\/brainwerk.at\/privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>2. Brainwerk Threat Network (sensor) \u2014 <code>https:\/\/shieldforge-intel.brainwerk.at\/<\/code> \u2014 OPT-IN, default OFF<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Optional community threat-intelligence network. Your site shares fact-only attack telemetry and in return receives a signed feed of known-malicious IP indicators.<\/li>\n<li><strong>When data is sent:<\/strong> Only after you give explicit consent AND the site registers with the network. Never before both steps are completed.<\/li>\n<li><strong>What data is sent:<\/strong> Batched, HMAC-signed events containing <strong>hashed, non-reversible IP indicators<\/strong> (raw IP addresses never leave your server), a hashed user-agent class, a request-path pattern, a country code and \u2014 when the User-Agent matches a known crawler (e.g. Googlebot, GPTBot, ClaudeBot) \u2014 the crawler's declared family name from a fixed, public allow-list. The raw User-Agent string itself never leaves your server; unrecognised User-Agents send no crawler-family field at all. No site URL owner data, no user identities, no content.<\/li>\n<li><strong>How to disable:<\/strong> <em>Brainwerk Security Suite \u2192 Threat Network \u2192 disable<\/em> (or simply never enable it). Off by default.<\/li>\n<li><strong>Provider:<\/strong> Brainwerk (EU-hosted), same operator and privacy policy as above.<\/li>\n<\/ul>\n\n<p><strong>3. Have I Been Pwned (Pwned Passwords) \u2014 <code>https:\/\/api.pwnedpasswords.com\/<\/code> \u2014 OPT-IN, default OFF<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Warns users whose password appears in known breach corpora, at login or password change.<\/li>\n<li><strong>What data is sent:<\/strong> Only the <strong>first 5 characters of the SHA-1 hash<\/strong> of the password (k-anonymity range query). The password itself and the full hash never leave your server.<\/li>\n<li><strong>How to disable:<\/strong> Off by default; enable under the login\/hardening settings only if you want it.<\/li>\n<li><strong>Provider:<\/strong> Have I Been Pwned, operated by Troy Hunt. <a href=\"https:\/\/haveibeenpwned.com\/Privacy\">https:\/\/haveibeenpwned.com\/Privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>4. hCaptcha \/ Cloudflare Turnstile (optional captcha) \u2014 <code>https:\/\/hcaptcha.com\/<\/code>, <code>https:\/\/challenges.cloudflare.com\/<\/code> \u2014 OPT-IN, default OFF<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Optional captcha on login \/ registration \/ comment forms as an alternative to the built-in local honeypot.<\/li>\n<li><strong>When it is active:<\/strong> Only if you enable the captcha module AND enter your own site\/secret keys. When enabled it loads the provider's JavaScript from their CDN in the browser and, on verification, sends the captcha token and the visitor's IP address to the provider.<\/li>\n<li><strong>How to disable:<\/strong> Off by default; the default anti-bot (honeypot) is 100% local and contacts nothing.<\/li>\n<li><strong>Providers:<\/strong> <a href=\"https:\/\/www.hcaptcha.com\/privacy\">hCaptcha privacy<\/a> \u00b7 <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">Cloudflare Turnstile privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>5. WordPress.org (core checksums &amp; repository integrity) \u2014 <code>https:\/\/api.wordpress.org\/<\/code>, <code>https:\/\/downloads.wordpress.org\/<\/code> \u2014 OPT-IN \/ on demand<\/strong><\/p>\n\n<ul>\n<li><strong>What it is used for:<\/strong> Verifying WordPress core files against official checksums (manual admin action) and, optionally, comparing installed plugins\/themes against the official wordpress.org checksums \/ release packages to detect tampering. The plugin only <strong>reads<\/strong> these to report differences \u2014 it never modifies your plugin or theme files.<\/li>\n<li><strong>What data is sent:<\/strong> The WordPress version + locale, and the slug\/version of the components being verified. No user data.<\/li>\n<li><strong>When:<\/strong> The core-checksum check runs only when you click it; the repository integrity check is off by default and, when enabled, runs via cron \/ on demand.<\/li>\n<li><strong>Provider:<\/strong> WordPress.org (the WordPress project's own infrastructure). <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">https:\/\/wordpress.org\/about\/privacy\/<\/a><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>brainwerk-security-suite<\/code> folder to <code>\/wp-content\/plugins\/<\/code> or install via the WordPress plugin uploader.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen (or <strong>Network Activate<\/strong> for Multisite).<\/li>\n<li>Open <strong>Brainwerk Security Suite<\/strong> in the admin sidebar and walk through the onboarding wizard.<\/li>\n<\/ol>\n\n<p>Brainwerk Security Suite ships with safe defaults \u2014 no configuration is required to get baseline protection, and out of the box it makes no outbound calls at all. The vulnerability scanner (the one feature that contacts an external API) is off by default; enable it under <strong>Vulnerabilities \u2192 Settings<\/strong> if you want daily CVE lookups.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20brainwerk%20security%20suite%20call%20any%20external%20service%3F\"><h3>Does Brainwerk Security Suite call any external service?<\/h3><\/dt>\n<dd><p>Not until you ask it to. Out of the box the plugin makes <strong>no<\/strong> automatic outbound calls. Every integration that can reach an external service is opt-in and off by default:<\/p>\n\n<ul>\n<li>The plugin\/theme\/core vulnerability scanner. Once you enable it, it queries an EU-hosted vulnerability API (default <code>https:\/\/shieldforge-intel.brainwerk.at\/<\/code>) once per day for the slug + version of each installed component. Nothing else (no site URL, no admin email, no IP, no user data) is sent, and you can point it at a self-hosted mirror under <strong>Brainwerk Security Suite \u2192 Vulnerabilities \u2192 Settings<\/strong>.<\/li>\n<li>The Threat Network sensor, the Have-I-Been-Pwned password check, an optional hCaptcha \/ Cloudflare Turnstile captcha, and the on-demand WordPress.org core-checksum \/ repository integrity checks.<\/li>\n<\/ul>\n\n<p>Each is documented in full in the <strong>External services<\/strong> section below.<\/p>\n\n<p>The core local features (WAF, file-integrity monitor, malware-pattern scan, brute-force protection, audit log, 2FA, honeypot, anomaly detection, security headers) make no outbound calls.<\/p><\/dd>\n<dt id=\"is%20the%20plugin%20gdpr-compliant%20out%20of%20the%20box%3F\"><h3>Is the plugin GDPR-compliant out of the box?<\/h3><\/dt>\n<dd><p>Yes \u2014 IP anonymization, configurable retention, and a published data map are on by default. The admin includes copy-paste ready text for your privacy policy.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on Multisite?<\/h3><\/dt>\n<dd><p>Yes. Network-activate it and configure once at the network level; per-site overrides are supported. A cross-site aggregate dashboard is a Pro feature.<\/p><\/dd>\n<dt id=\"i%20lost%20my%202fa%20device.%20how%20do%20i%20get%20back%20in%3F\"><h3>I lost my 2FA device. How do I get back in?<\/h3><\/dt>\n<dd><p>Use one of the 8 recovery codes generated when you enrolled. If you also lost those, an administrator with <code>manage_network_options<\/code> capability can disable 2FA for any user under <strong>Brainwerk Security Suite \u2192 2FA \u2192 Users with 2FA configured \u2192 Rescue: disable<\/strong>.<\/p><\/dd>\n<dt id=\"i%20enabled%20the%20custom%20login%20url%20and%20locked%20myself%20out.%20how%20do%20i%20recover%3F\"><h3>I enabled the custom login URL and locked myself out. How do I recover?<\/h3><\/dt>\n<dd><p>Add this line to <code>wp-config.php<\/code> (above the \"That's all\" comment):<\/p>\n\n<pre><code>define('SHIELDFORGE_LOGIN_RESCUE', 'choose-a-long-random-secret');\n<\/code><\/pre>\n\n<p>Then visit <code>https:\/\/your-site\/wp-login.php?shieldforge_rescue=choose-a-long-random-secret<\/code> to bypass the 404 and reach the standard login.<\/p><\/dd>\n<dt id=\"the%20waf%20blocked%20one%20of%20my%20own%20urls.%20what%20do%20i%20do%3F\"><h3>The WAF blocked one of my own URLs. What do I do?<\/h3><\/dt>\n<dd><p>Open <strong>Brainwerk Security Suite \u2192 Modules \u2192 WAF<\/strong>. The false-positive viewer lists the last 30 blocks; click \"Whitelist\" next to your legitimate path to add it to the WAF path allowlist. Start at paranoia level 1 and raise it only after watching the block log.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%3F\"><h3>Will it slow down my site?<\/h3><\/dt>\n<dd><p>It is designed to be lightweight. Hooks fire only where needed, the database tables are indexed, and old log rows are cleaned up daily. The file-integrity scanner runs at 03:30 in a 45-second time-budgeted cron sweep that resumes on the next tick if a single run can't finish.<\/p><\/dd>\n<dt id=\"my%20server%20runs%20behind%20a%20reverse%20proxy%20%2F%20cloudflare%20tunnel%20%2F%20sslh.%20will%20brainwerk%20security%20suite%20see%20real%20client%20ips%3F\"><h3>My server runs behind a reverse proxy \/ Cloudflare Tunnel \/ sslh. Will Brainwerk Security Suite see real client IPs?<\/h3><\/dt>\n<dd><p>Brainwerk Security Suite reads <code>$_SERVER['REMOTE_ADDR']<\/code> by default. If your nginx \/ Apache is configured to forward the original client IP (PROXY-protocol, X-Forwarded-For), that's what arrives in PHP and Brainwerk Security Suite uses it. The healthcheck card on every admin screen will warn you if all visitors arrive as 127.0.0.1 \u2014 that means the proxy chain is hiding the real client from PHP, which would silently disable IP-based brute-force protection. Fix it at the proxy \/ web-server layer (proxy-protocol-aware listener) before re-enabling brute-force protection.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.18.0 \u2014 2026-08-05<\/h4>\n\n<ul>\n<li><strong>Threat Network sensor now classifies known crawlers.<\/strong> When a request's User-Agent matches a known crawler (search engines plus major AI\/LLM crawlers such as GPTBot, ClaudeBot, PerplexityBot, Google-Extended), the sensor event sent to the opt-in Threat Network now includes the crawler's declared family name \u2014 never the raw User-Agent string, and omitted entirely for unrecognised User-Agents. This is the plugin-side half of the network's bot-reputation feature; verdicts require a minimum number of participating sites network-wide before they appear (k-anonymity floor), independent of any single site's traffic.<\/li>\n<li><strong>Security hardening (code-quality gate):<\/strong> every database query that consumes user input now uses <code>$wpdb-&gt;prepare()<\/code> with placeholders; all superglobal reads are unslashed and sanitized; all admin-view output is escaped at output time. Trusted internal table-name interpolation is explicitly documented in-code.<\/li>\n<li>Added a versioned PHPCS security ruleset (<code>phpcs.xml.dist<\/code>) enforcing <code>WordPress.Security<\/code>, prepared-SQL and direct-query rules \u2014 the plugin now passes it with <strong>zero errors<\/strong>.<\/li>\n<li>Fixed a TOTP base32 decoding bug that silently discarded lowercase characters from manually-entered authenticator secrets.<\/li>\n<\/ul>\n\n<h4>1.0.0 (geplant)<\/h4>\n\n<ul>\n<li>First stable release. Consolidates the full defense-in-depth module set and documents every feature honestly against the shipped code.<\/li>\n<li><strong>Web Application Firewall (WAF)<\/strong> \u2014 40+ regex signatures (SQLi\/XSS\/LFI\/RCE\/SSRF\/XXE\/cmdi\/enum), three paranoia levels, admin + path allowlists, false-positive viewer, optional IP auto-block.<\/li>\n<li><strong>Crawler \/ request rate limiter.<\/strong><\/li>\n<li><strong>Trusted devices<\/strong> (new-device e-mail warning), <strong>Have I Been Pwned<\/strong> password check, <strong>magic login links<\/strong> (passwordless), <strong>live-traffic monitor<\/strong>, <strong>core-file compare<\/strong> (wordpress.org MD5), <strong>repository-integrity<\/strong> detection, <strong>Incident Commander<\/strong> (post-incident forensics + lockdown).<\/li>\n<li><strong>Security headers<\/strong> extended with Cross-Origin-Opener-Policy (COOP) and Cross-Origin-Resource-Policy (CORP).<\/li>\n<li><strong>Privacy dashboard<\/strong> with published data map and one-click DSGVO Art. 15 \/ Art. 17 workflows.<\/li>\n<li>Documentation corrected: the cross-site <em>aggregate<\/em> Multisite dashboard is a Pro feature (the free build provides Multisite support with per-site overrides).<\/li>\n<li>Domains unified: product\/pricing\/docs \u2192 security-suite.brainwerk.at; company\/privacy \u2192 brainwerk.at.<\/li>\n<\/ul>\n\n<h4>0.14.4 \u2014 2026-07-29<\/h4>\n\n<ul>\n<li>Maintenance release: version bump only, no functional changes since 0.14.3.<\/li>\n<\/ul>\n\n<h4>0.14.3 \u2014 2026-07-17<\/h4>\n\n<ul>\n<li><strong>wp.org compliance<\/strong>: renamed all short-prefixed (<code>sf_<\/code>) transients to the unique <code>shieldforge_<\/code> prefix \u2014 <code>shieldforge_user_lock_<\/code>, <code>shieldforge_2fa_pending_<\/code>, <code>shieldforge_2fa_recovery_show_<\/code>, <code>shieldforge_2fa_attempts_<\/code> \u2014 to avoid collisions in the shared options\/transients space.<\/li>\n<li><strong>Metadata<\/strong>: removed the <code>Plugin URI<\/code> header (the previous value was not public); the public <code>Author URI<\/code> is retained.<\/li>\n<li><strong>Hardening<\/strong>: escape all remaining admin outputs at output time (audit table, scanner status, captcha widget, magic-link\/privacy <code>wp_die<\/code> messages) and document the trusted-table-name direct queries.<\/li>\n<\/ul>\n\n<h4>0.14.1 \u2014 2026-07-04<\/h4>\n\n<ul>\n<li><strong>Privacy<\/strong>: the plugin\/theme\/core vulnerability scanner is now <strong>opt-in and off by default<\/strong> \u2014 out of the box the plugin makes no automatic outbound calls at all. Enable it under <em>Vulnerabilities \u2192 Settings<\/em> to consent to the daily lookup.<\/li>\n<li><strong>wp.org compliance<\/strong>: all inline <code>&lt;script&gt;<\/code> \/ <code>&lt;style&gt;<\/code> blocks in admin views are now enqueued (<code>wp_add_inline_script<\/code> \/ bundled CSS \/ a static <code>assets\/js\/twofactor-profile.js<\/code>).<\/li>\n<li><strong>wp.org compliance<\/strong>: the repo-integrity checker is now detection-only \u2014 it reports tampered plugin\/theme files and links you to the standard WordPress reinstall flow instead of writing files into plugin\/theme folders.<\/li>\n<li><strong>wp.org compliance<\/strong>: removed the direct load of <code>wp-includes\/template-loader.php<\/code> in the login-URL 404 path; it now emits a self-contained 404.<\/li>\n<li><strong>Security<\/strong>: escape the WAF debug output and the 2FA \"last used\" column at output time.<\/li>\n<li><strong>Docs<\/strong>: readme reworded to drop comparative marketing claims and to reflect that every external service is opt-in and off by default.<\/li>\n<\/ul>\n\n<h4>0.14.0 \u2014 2026-05-21<\/h4>\n\n<ul>\n<li><strong>Rebranded<\/strong> to Brainwerk Security Suite (was: ShieldForge). Display name + text-domain + plugin filename + language files updated. Internal class prefix <code>Shieldforge_*<\/code> and DB tables <code>wp_shieldforge_*<\/code> kept stable for upgrade compatibility.<\/li>\n<li><strong>wp.org compliance<\/strong>: replaced both <code>&lt;&lt;&lt;TXT<\/code> heredocs in the privacy-policy generator with plain string concatenation.<\/li>\n<li><strong>Docs<\/strong>: readme now has a top-level <code>== External services ==<\/code> section documenting every outbound connection.<\/li>\n<\/ul>\n\n<h4>0.9.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>UX overhaul<\/strong>: tab navigation grouped into 5 logical sections; hero dashboard with color-coded threat-status banner; modern toggle switches; empty states with CTAs; Quick-Setup wizard (School \/ Agency \/ Shop \/ Blog); mobile-responsive admin; dark-mode support.<\/li>\n<\/ul>\n\n<h4>0.6.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>Custom login URL<\/strong>, <strong>honeypot anti-bot<\/strong>, <strong>Content-Security-Policy<\/strong> (Report-Only), <strong>per-header security toggles<\/strong>; new <strong>Hardening+<\/strong> tab.<\/li>\n<\/ul>\n\n<h4>0.5.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>User activity audit trail<\/strong> (11 lifecycle events), new <strong>Audit<\/strong> tab.<\/li>\n<\/ul>\n\n<h4>0.4.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>Plugin \/ theme \/ core vulnerability scanner<\/strong> (EU-hosted, no API key), new <strong>Vulnerabilities<\/strong> tab.<\/li>\n<\/ul>\n\n<h4>0.3.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>TOTP two-factor authentication<\/strong> (RFC 6238), recovery codes, force-by-role, new <strong>2FA<\/strong> tab.<\/li>\n<\/ul>\n\n<h4>0.2.0 \u2014 2026-05-10<\/h4>\n\n<ul>\n<li><strong>File-integrity monitor<\/strong> (SHA-256) + <strong>pattern-based malware scanner<\/strong> (16 rules), new <strong>Scanner<\/strong> tab.<\/li>\n<\/ul>\n\n<h4>0.1.0 \u2014 2026-05-07<\/h4>\n\n<ul>\n<li>Initial release: login activity log, brute-force protection, IP whitelist with CIDR, hardening toggles, 404 probing tracker, email notifications, daily digest with threat score, anomaly detection (beta), healthcheck banner, onboarding wizard in 6 languages, multisite-aware, GDPR controls, privacy-policy snippet generator.<\/li>\n<\/ul>","raw_excerpt":"Privacy-first WordPress security suite \u2014 built for EU compliance and Multisite. GDPR-ready by default, transparent about every byte that leaves your s &hellip;","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/334812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=334812"}],"author":[{"embeddable":true,"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/brainwerk"}],"wp:attachment":[{"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=334812"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=334812"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=334812"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=334812"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=334812"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es-mx.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=334812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}