Advanced WordPress security plugin for HTTP Security Headers, CSP management, Smart CSP discovery, deep scanning, and WordPress hardening — developed by Ebrahim Shafiei (EbraSha).
-
Updated
Sep 1, 2026 - PHP
Advanced WordPress security plugin for HTTP Security Headers, CSP management, Smart CSP discovery, deep scanning, and WordPress hardening — developed by Ebrahim Shafiei (EbraSha).
CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test. For authorized testing only.
WordPress plugin providing security functionality, plays nicely with Fail2ban and Cloudflare. Verified with WordPress 5.5+/6.6.x and PHP 7.4, 8.1, 8.2, 8.3, and 8.4
Simple Security for preventing comment spam and brute force attacks.
A minimal WordPress plugin that disables XML-RPC
The native WordPress $wpdb->prepare() method is not a true prepared statement implementation like those provided by PDO. It uses a sprintf-like substitution mechanism to escape inputs, which does not fully separate the query structure from user data. In contrast, our secure approach leverages genuine PDO prepared statements, ensuring that parameter
WordPress Secure Private Login Access. Plugin extension for WordPress-IP-Geo-Block.
Check your WordPress website for headers that are common for security purposes.
Plugin Extension for "IP Location Block" WordPress plugin (https://github.com/gdarko/ip-location-block), selective allowing administrators by dynamic/static DNS domain, country, intenet provider or IP
Security focused WordPress plugin
To associate your repository with the wordpress-security-plugin topic, visit your repo's landing page and select "manage topics."