Title: Ensomedia Security powered by shieldwave.io
Author: shieldwave
Published: <strong>28 setembre 2026</strong>
Last modified: 10 octobre 2026

---

Search plugins

![](https://ps.w.org/ensomedia-security/assets/banner-772x250.png?rev=3716337)

![](https://ps.w.org/ensomedia-security/assets/icon.svg?rev=3716310)

# Ensomedia Security powered by shieldwave.io

 Per [shieldwave](https://profiles.wordpress.org/shieldwave/)

[Download](https://downloads.wordpress.org/plugin/ensomedia-security.1.1.13.zip)

 * [Details](https://oci.wordpress.org/plugins/ensomedia-security/#description)
 * [Reviews](https://oci.wordpress.org/plugins/ensomedia-security/#reviews)
 *  [Installation](https://oci.wordpress.org/plugins/ensomedia-security/#installation)
 * [Development](https://oci.wordpress.org/plugins/ensomedia-security/#developers)

 [Support](https://wordpress.org/support/plugin/ensomedia-security/)

## Descripcion

[shieldwave.io](https://shieldwave.io/?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme)
by [ensomedia.dev](https://ensomedia.dev)

Ensomedia Security, powered by shieldwave.io, scans your site from the inside and
tells you, in plain language, what is wrong and how to fix it. It is built around
one idea: **an alert has to be worth your attention**. Every check, the scheduled
scans and the email alerts are free, work without an account and have no limits.

#### Why owners switch to it

 * **Official checksums first.** WordPress core, directory plugins and directory
   themes are compared with the files WordPress.org published for your version. 
   A matching file is trusted; a file that differs is reported with the reason.
 * **Malware detection that needs real evidence.** One weak signal, such as base64
   in a file, is never a finding. The scanner looks for code that runs what a visitor
   sends, executes hidden payloads, fetches remote code or creates hidden administrators.
   Findings it is not sure about go under « Ask your developer to check » and never
   send email.
 * **Change monitoring for what WordPress.org cannot verify.** Premium plugins, 
   custom themes, must-use plugins and drop-ins get a baseline. Changes that come
   with an update are accepted; a new PHP file that appears without one is reported.
 * **Alerts that do not cry wolf.** One email per scan, only for problems that are
   new or got worse, at most four a day. A check that could not run never sends 
   email and never marks anything as fixed.
 * **Light on your server.** Scans run in the background in short steps that fit
   hosts with a 30-second limit, and files that did not change are not analyzed 
   again.
 * **Never rewrites your site on its own.** The plugin changes files, users or settings
   only when you press a button or turn on a switch: delete an unused plugin, move
   a file into quarantine, turn off the file editor or XML-RPC, block PHP in uploads,
   send security headers.

#### The checks

 * **Malware and backdoors** in PHP, JavaScript and .htaccess files that WordPress.
   org cannot vouch for: web shells, decode-and-execute chains, obfuscated code,
   remote code loaders, PHP hidden in images, spam mailers, hidden administrators,
   injected JavaScript and malicious redirects.
 * **Core, plugin and theme files** against the WordPress.org checksums or release
   packages of your versions, plus PHP files those releases do not contain.
 * **File changes** against the recorded baseline, and plugin or theme folders that
   appear without going through the WordPress installer.
 * **PHP files in uploads**, and .htaccess or .user.ini rules that make the server
   run uploads as PHP.
 * **Known vulnerabilities** (opt-in) in plugins, themes and WordPress, premium 
   ones included, with the version that fixes each one.
 * **Closed, abandoned and unused plugins and themes**, **updates** and **PHP version**
   support.
 * **Injected content**: scripts, hidden iframes and spam links in posts, widgets
   and options. Ordinary embeds and tracking codes are left alone.
 * **Exposed files** that your web server hands out to anyone (copies of wp-config.
   php, database dumps, backups, .git folders, .env files, logs), confirmed by requesting
   them from your own site; leftover installers and database tools; folder listings.
 * **Accounts and configuration**: administrators, user registration, wp-config.
   php, debug output, file editor, XML-RPC, HTTPS, user list exposure and suspicious
   scheduled tasks.

Each issue has a severity, what it means, how to fix it and the files, plugins or
settings involved. Problems of the same kind are grouped, so a site never faces 
hundreds of lines. An ignored file comes back if it changes again.

Live protection (three features, all opt-in):

 * **Known vulnerabilities**: the lookup above.
 * **Live threat feed**: new malware rules and file signatures from ShieldWave reach
   your site within about an hour, verified by signature. It sends nothing about
   your site.
 * **AI second opinion**: for a file the local rules cannot judge, a redacted excerpt
   gets a verdict in plain words. Configuration, credential, backup and log files
   are never sent.

All three are off until you turn them on and run from WP-Cron once an hour, whether
or not a scan is running. See External services.

#### Login protection

 * Failed logins are limited per address (five by default, then a cooldown you set)
   and per user name across all addresses (20 an hour by default, any number from
   1 to 500, 0 turns it off). Password reset requests are limited per address, 5
   an hour by default. A lock is always temporary, and trusted addresses are never
   locked.
 * Only the connection’s own address counts, never a header a request can fake. 
   Behind a proxy or CDN, list its addresses or CIDR ranges (a range of /8 or narrower,
   up to 20 entries) under trusted proxies and choose the header that carries the
   visitor’s address.
 * User names stay private: the login form, the ?author=N trick, the REST API user
   list, embeds and the users sitemap stop giving them to visitors who are not logged
   in.
 * An email goes out when the user name of an administrator gets locked.
 * Login protection is on by default for new installs and off after an upgrade until
   you turn it on.

#### Two-factor login, passkeys and sessions

 * Turn two-factor login on for the site, and each administrator sets up an authenticator
   app under ShieldWave > Settings. Ten recovery codes and `wp shieldwave two-factor
   disable <user>` make sure nobody is locked out. Apps sign in with an application
   password.
 * **Required for roles.** Choose the roles that must use two-factor login and give
   them 0 to 30 days (7 by default) to set it up. After that, signing in leads to
   a set-up screen on the login page.
 * **Passkeys** (WebAuthn) work as the second step after the password, never instead
   of it. They need a site that loads over HTTPS and the OpenSSL extension in PHP.
 * **Sessions.** See where your account is signed in, sign out everywhere else or
   sign out every user, and set how long an administrator’s session lasts.

#### Hardening

 * Turn off the plugin and theme file editor and XML-RPC with one switch each, without
   editing wp-config.php. ShieldWave warns you first if a plugin you use, such as
   Jetpack, needs XML-RPC.
 * **PHP in uploads.** On Apache and LiteSpeed one switch writes a block into the.
   htaccess file in uploads that stops PHP, Perl, Python, CGI and server-side include
   files. On nginx and IIS, Settings shows the rule to add. Check now tests whether
   PHP still runs there.
 * **Security headers.** One switch sends nosniff, Referrer-Policy, Permissions-
   Policy, Cross-Origin-Opener-Policy and protection against framing; Strict-Transport-
   Security has its own switch and goes out only over HTTPS. A header that your 
   server, CDN or another plugin already sends is left as it is.

All of them are off until you turn them on.

#### Quarantine

A finding of medium severity or higher about one file can move that file into quarantine.
The file is stored encoded, so it cannot run, in a folder the web server refuses,
and Restore puts back the same bytes with their date and permissions. wp-config.
php, the main .htaccess, WordPress’s own files and files the site loads on every
request are never moved, and if the site stops working after a move, the file goes
back. Nothing is moved unless you press the button.

#### Activity log and privacy

History is kept in its own database table. Each entry carries a hash, keyed with
a secret from wp-config.php, that includes the hash of the entry before it, so Check
history integrity tells whether an entry was edited or deleted outside ShieldWave.
Entries are kept for 7 to 730 days (90 by default) and can be exported as CSV.

When logins are paused after too many failed attempts, the plugin records the IP
address and the typed user name (the name only when the account exists). After a
successful login it sets a cookie whose name starts with shieldwave_kd_. It holds
only a random identifier, lets that browser keep signing in while someone else guesses
the password for the same account, expires after 90 days and stops working when 
the password changes. The plugin adds a suggested text to Settings > Privacy and
takes part in the WordPress personal data export and erasure tools.

#### Alerts

Email after scheduled scans for new or more serious issues at or above your threshold,
at once when an account becomes administrator or the user name of an administrator
gets locked, and a weekly summary if you want one.

#### ShieldWave dashboard (optional)

Press **Connect with shieldwave.io** under ShieldWave > Settings and the site shows
up in your dashboard at [shieldwave.io](https://shieldwave.io/?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme)
with its score and open issues, next to ShieldWave’s outside scan. A free account
shows one site; Pro and Enterprise show every site. The dashboard cannot change 
anything on the site. See External services.

#### What this plugin does not do

It is not a full web application firewall and it does not clean malware out of files
for you. It finds, explains, alerts, stops brute-force logins and applies the hardening
you switch on; you, your developer or your host make the rest of the change. Visitors
see nothing of it.

#### Who builds it

[shieldwave.io](https://shieldwave.io/?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme)
by [ensomedia.dev](https://ensomedia.dev). Ensomedia Security is designed, built
and maintained by ENSOMEDIA, the web and software practice of Radosław Fedorczuk
in Wrocław, Poland, which also runs the shieldwave.io outside scanner and dashboard
this plugin can connect to.

#### Credits

The admin screens use the Inter typeface by The Inter Project Authors, licensed 
under the SIL Open Font License 1.1 (`assets/fonts/inter-license.txt`). It is loaded
from the plugin itself, only on the ShieldWave screens.

### External services

The plugin makes no outside requests when it is activated or when admin pages load.
Requests happen when a scan runs (by hand or on the schedule), when you use the 
account actions, and, from WP-Cron once an hour, for the live protection features
you turned on and for the check-in of a connected account. Requests to WordPress.
org and to your own site use the WordPress HTTP API’s default user agent, which 
includes your WordPress version and site address, exactly as WordPress itself does
for its update checks. Requests to ShieldWave send a neutral user agent (ShieldWave-
Security and the plugin version) and never your site address in their headers. Like
any web request, each one comes from your server’s IP address.

**WordPress.org core checksums** (api.wordpress.org/core/checksums/1.0/)
 Used by
the « WordPress core files » check. Sent: your WordPress version and package language.
Cached for a day.

**WordPress.org release list** (api.wordpress.org/core/stable-check/1.0/)
 Used 
by the « WordPress core files » check to know which older releases to compare with.
Sent: nothing about your site; it is a plain request for the public list. Cached
for a day.

**WordPress.org plugin checksums** (downloads.wordpress.org/plugin-checksums/)
 
Used by the « Plugin files » check. Sent: the folder name and version of each installed
plugin, one request per plugin. Cached for a week, or for a day when no list was
available.

**WordPress.org theme packages** (downloads.wordpress.org/theme/)
 Used by the «
Theme files » check. The release package of each installed directory theme is downloaded
to a temporary file, hashed and deleted at once. Sent: the theme’s folder name and
version. The result is cached for a week.

**WordPress.org plugin information** (api.wordpress.org/plugins/info/1.2/)
 Used
by the « Closed and abandoned plugins » check. Sent: the folder name of each installed
plugin. Cached for a day.

**WordPress.org theme information** (api.wordpress.org/themes/info/1.2/)
 Used by
the « Theme files » check to learn which installed themes come from the directory
and in which version. Sent: the folder name of each installed theme. Cached for 
a day.

All six are provided by WordPress.org: [privacy policy](https://wordpress.org/about/privacy/),
[terms](https://wordpress.org/about/privacy/).

**Your own site**
 The XML-RPC, debug output and exposed files checks request a 
few URLs of your own site (xmlrpc.php, the debug.log URL, backup files found on 
disk, the uploads folder). The HTTPS check asks for the home page over http and 
https, the security headers check asks for the home page once, « Check now » for
PHP in uploads writes two harmless test files into the uploads folder, asks for 
them and deletes them, and after a file is moved to quarantine the plugin asks for
the home page and the login page to see that the site still answers. While a scan
runs, the plugin also calls your own admin-ajax.php to continue the scan in the 
background.

**ShieldWave vulnerability lookup** (shieldwave.io, endpoint /api/plugin/vulnerabilities),
off until you turn it on
 Used by the « Known vulnerabilities » check. Sent when
that check runs: your WordPress version and the folder name and version of each 
installed plugin and theme, premium ones included. A premium plugin’s product name
is compared on your site, never sent. No site address, no account, no personal data.
The answer lists the vulnerabilities that apply to those versions; the data comes
from Wordfence Intelligence, and each result links to its record with its copyright
notice. The link is shown only for a short list of vulnerability databases (Wordfence,
NVD, CVE.org, WPScan, Patchstack, shieldwave.io, WordPress.org and the GitHub advisory
database). Runs with the scan and once an hour from WP-Cron; cached for a few hours.

**ShieldWave threat feed** (shieldwave.io, endpoint /api/plugin/intel), off until
you turn it on
 Used by the « Live threat feed » option. The plugin downloads a 
signed file of extra malware rules and known-bad and known-good file signatures,
once an hour from WP-Cron, so detection improves between plugin updates. Sent: nothing
about your site; the only thing that leaves is your plugin version, which every 
request already carries. The file is verified with a cryptographic signature before
it is used.

**ShieldWave AI second opinion** (shieldwave.io, endpoint /api/plugin/ai/review),
off until you turn it on
 Used by the « AI second opinion » option, and only for
a file the local rules cannot judge on their own. Sent: an excerpt of up to 6,000
characters around the suspicious code, plus the file’s SHA-256 and MD5 fingerprints
and size, its kind (PHP, JavaScript or a server configuration file), where it sits(
a plugin, a theme, the uploads folder and so on) and the folder name of its plugin
or theme, the local verdict, the matched rule identifiers, the site language, the
plugin version and a salted hash of the site. Before it is sent, the plugin removes
your site address, email addresses, IPv4 and IPv6 addresses, the server path of 
WordPress and of home folders (replaced by a neutral path), every DB_ constant and
the arguments of database connections, constants and values named like a password,
key, salt, secret or token (from 6 characters), and long random tokens. Other web
addresses stay. For PHP found inside an image, the excerpt starts at the first PHP
tag, not at the picture data. Files named wp-config*, .env*, .htpasswd, .user.ini,
php.ini or auth.json, backup copies (.bak, .old, .orig, .save, .swp, names ending
in ~), database dumps (.sql), logs and .ini files are never read. If the redaction
fails, nothing is sent. shieldwave.io passes the excerpt to an AI provider of shieldwave.
io, described in the ShieldWave privacy policy; the verdict is kept by …

## Screenshots

[⌊Overview: whether the site is safe, what to do next, and what protects it.⌉⌊Overview:
whether the site is safe, what to do next, and what protects it.⌉[

Overview: whether the site is safe, what to do next, and what protects it.

[⌊A problem opened: what was found, how to fix it, and a button to the right WordPress
screen.⌉⌊A problem opened: what was found, how to fix it, and a button to the right
WordPress screen.⌉[

A problem opened: what was found, how to fix it, and a button to the right WordPress
screen.

[⌊Signs of a break-in: what to do now, and the file, rule and code that matched.⌉⌊
Signs of a break-in: what to do now, and the file, rule and code that matched.⌉[

Signs of a break-in: what to do now, and the file, rule and code that matched.

[⌊A scan running in the background.⌉⌊A scan running in the background.⌉[

A scan running in the background.

[⌊History: every scan and every change that matters, in plain sentences.⌉⌊History:
every scan and every change that matters, in plain sentences.⌉[

History: every scan and every change that matters, in plain sentences.

[⌊Settings: automatic scans, email alerts, extra checks and the optional ShieldWave
account.⌉⌊Settings: automatic scans, email alerts, extra checks and the optional
ShieldWave account.⌉[

Settings: automatic scans, email alerts, extra checks and the optional ShieldWave
account.

[⌊The optional ShieldWave account: connect the site to shieldwave.io with one click,
or with an API key.⌉⌊The optional ShieldWave account: connect the site to shieldwave.
io with one click, or with an API key.⌉[

The optional ShieldWave account: connect the site to shieldwave.io with one click,
or with an API key.

## Installacion

 1. Install the plugin from Plugins > Add Plugin, or upload the `ensomedia-security`
    folder to `/wp-content/plugins/`.
 2. Activate it.
 3. Open **ShieldWave** and press **Scan now**. The first scan records the baseline
    and usually takes a few minutes; later scans are faster.
 4. Scheduled scans run daily at 03:00 (site time). Change that, the alerts and the
    options under **ShieldWave > Settings**.
 5. Optional: turn on the known-vulnerability lookup under **ShieldWave > Settings 
    > Live protection**.
 6. Optional: to see the site in the ShieldWave dashboard, press **Connect with shieldwave.
    io** under **ShieldWave > Settings > ShieldWave account**.

## FAQ

### Do I need a ShieldWave account?

No. All 23 checks, scheduled scans, email alerts and the vulnerability lookup work
without one, with no limits.

### Can I hide ShieldWave from the toolbar?

Yes. Under ShieldWave > Settings > Toolbar, turn off « Show ShieldWave in the toolbar».
The choice is per administrator. Visitors never see it.

### How is this different from other security scanners?

It trusts the files WordPress.org can vouch for, needs real evidence before it calls
something malware, and emails only about problems that are new or got worse. The
goal is that every alert you get is one you would want.

### What does « Ask your developer to check » mean?

The scanner found something unusual that is often harmless: for example a new PHP
file in a premium plugin without an update. It is listed so someone who knows the
site can look at it, and it never sends an email on its own. Problems under « Fix
now » are the ones with clear evidence.

### A finding is about a file I changed on purpose.

Open the item and press « Ignore ». It stays out of the score and the alerts, and
an ignored file comes back by itself if it changes again. Ignored items stay under
the « Ignored » link below the to-do list, where « Restore » brings one back.

### Will it slow my site down?

No. Scans never run while a visitor’s page loads: they work in the background in
steps of a few seconds, and later scans skip files that were clean and did not change.
On a busy shared host you can choose the low scan speed in Settings.

### What happens to the scheduled scan when the clocks change?

It stays on the hour you chose, in the time zone set under Settings > General, and
it follows a change of that time zone at once. On the one day a year the clocks 
skip the chosen hour, the scan runs right after the skipped hour. On the day an 
hour happens twice, it runs once, the first time the clock shows it.

### Which outside requests does it make?

Only when scans run: to WordPress.org for checksums, theme packages, plugin information
and the list of WordPress releases, and to your own site. With the vulnerability
lookup, live threat feed or AI second opinion on: to shieldwave.io, once an hour
from WP-Cron and after scans. With an account connected: to shieldwave.io, also 
once an hour. Each of those is off until you turn it on, and the External services
section below lists exactly what is sent.

### Why does the plugin register a public AJAX action?

The AJAX action `shieldwave_worker` lets a running scan continue in the background;
it does nothing without the random token of the running scan. The plugin’s REST 
routes answer administrators only.

### My headless front end reads authors from the REST API.

With login protection on, the REST API user list answers only logged-in requests,
so an anonymous request for an author gets an error. To keep the list public, add`
add_filter( 'shieldwave_hide_user_list', '__return_false' );` to a small plugin 
or to your theme’s functions.php. The same filter also brings back the author fields
in embeds and the users sitemap.

### Does it work on multisite?

Yes, network-wide. It is activated for the whole network (Network Activate): two-
factor login and login protection need that, because one sign-in works on every 
site. Scanning, the schedule, alerts, the settings screens and the optional ShieldWave
account all live on the main site, in the Network Admin, for network administrators
only. Every other site of the network enforces the same choice made there: when 
login protection, two-factor or a hardening switch is on, it is on for that site
too, with no separate settings screen to set up. A lockout after failed logins is
shared by the whole network, not counted per site, so an address cannot dodge the
limit by trying a different site.

### Does it work without WP-Cron?

Yes. If WP-Cron is disabled or loopback requests are blocked, scans still run while
the ShieldWave screen is open, and scheduled scans run whenever your server cron
calls wp-cron.php.

### How is the score calculated?

It starts at 100. For each check, the most serious open issue takes off points: 
critical 30, high 15, medium 8, low 3. Ignored issues, hints and checks that could
not run take nothing off.

### Which languages does it speak?

English, Arabic, Chinese (Simplified), Dutch, French, German, Indonesian, Italian,
Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Swedish, Turkish
and Vietnamese. The screens, the login protection and the alert emails follow the
language of your WordPress admin, and Arabic gets a right-to-left layout. Regional
variants such as Spanish (Mexico), German (Switzerland) or French (Canada) use the
main language. For these languages the plugin’s own translation is used, and a translate.
wordpress.org pack fills only what it lacks; other languages use the pack from translate.
wordpress.org once one is complete.

### The old ShieldWave Security from shieldwave.io is installed too.

Builds downloaded from shieldwave.io before the directory listing were called ShieldWave
Security, numbered up to 3.6.6, and live in the folder shieldwave-security. They
cannot update themselves to this plugin. Keep Ensomedia Security active, deactivate
ShieldWave Security, then delete it on the Plugins screen: the settings, results
and two-factor set-ups carry over, because Ensomedia Security keeps them while the
old copy’s clean-up runs. The Plugins screen shows a notice while an old copy is
installed.

### Can I undo a quarantine?

Yes. Restore puts the file back where it was. Quarantined files are kept in a folder
inside wp-content that is removed, with the files the plugin put there, when the
plugin is deleted, so restore what you want to keep before you delete the plugin.

### What happens to my data when I delete the plugin?

The plugin removes its settings, results, tables, scheduled tasks, user settings,
two-factor and passkey data, the quarantine folder and its block in the uploads .
htaccess file. If the site is connected to shieldwave.io, it first asks shieldwave.
io to remove the site and its results.

### What does connecting to shieldwave.io do?

It shows the site in your shieldwave.io dashboard with its score and open problems,
next to the outside scan of shieldwave.io, and confirms that the domain is yours,
which the full outside scan needs. A free account shows one site. Everything in 
the plugin works the same without it.

### I think a finding is wrong.

Open a topic in this plugin’s support forum with the check name and what you see.
False positives are treated as bugs.

### How do I report a security problem in the plugin?

Follow https://shieldwave.io/legal/en/vulnerability-disclosure?utm_source=wordpress&
utm_medium=plugin&utm_campaign=readme. Please do not post it in the public support
forum.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Ensomedia Security powered by shieldwave.io” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ shieldwave ](https://profiles.wordpress.org/shieldwave/)

“Ensomedia Security powered by shieldwave.io” has been translated into 3 locales.
Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/ensomedia-security/contributors)
for their contributions.

[Translate “Ensomedia Security powered by shieldwave.io” into your language.](https://translate.wordpress.org/projects/wp-plugins/ensomedia-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/ensomedia-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/ensomedia-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/ensomedia-security/)
by [RSS](https://plugins.trac.wordpress.org/log/ensomedia-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.13

 * No more false alarms right after an update. The file changes check finishes again(
   from 1.1.10 to 1.1.12 it stopped with an error, so its findings never closed),
   a file that matches its release keeps its official mark through the walk that
   follows an update, and a plugin or theme whose every code file matches WordPress.
   org is never « changed without an update », even when the update left no record,
   as automatic updates of this plugin do.
 * The malware check no longer calls a plugin’s own admin code malicious when request
   input reaches eval or include behind a nonce and capability check that ends the
   request, and an include path chosen from a fixed table by a request key is not
   request input. Dummy checks and checks on one side of an « or » are still caught.
 * A file of a WordPress.org plugin is judged more strictly only when it stands 
   out: it differs from the release, is not part of it, or the rest of the plugin
   matched while it carries no mark. Until now, when the marks were gone after an
   update or WordPress.org had no checksums for the version, every file of the plugin
   was read that way and one weak sign was enough to report it (WP Mail SMTP’s e-
   mail summary template).
 * Six rules were narrowed after a sweep of 147,858 files from the 200 most popular
   WordPress.org plugins: a login form that checks the password it was sent, the
   WordPress importer and the copies themes bundle, assert used as a type check,
   a stylesheet printed inside a style tag, a variable named $include, and a shipped
   build script that writes PHP from its own text are no longer reported. The backdoors
   they resembled still are, each with a sample in the release tests.
 * Drafts of code snippets (Simple Custom CSS and JS, WPCode) are not injected content;
   published snippets are still checked.
 * A large script that is not PHP in a node_modules, vendor or bower_components 
   folder of a plugin or theme gets no « too large to analyze » note of its own;
   both ends are still analyzed.
 * The Overview headline says the site needs some tidying, in amber, when the score
   is under 60 or five or more things are open with nothing urgent. It no longer
   says « Your site looks good » over a failing score.
 * The live threat feed card says « nothing new beyond the built-in rules » instead
   of « 0 rules, 0 known-bad files ».
 * A theme that loads its front-end CSS in wp-admin no longer draws a line across
   the ShieldWave header.
 * A security review of the whole plugin (admin screens, REST and the scan worker,
   the connection to shieldwave.io, login and two-factor, passkeys, sessions, quarantine,
   every check and the rules engine). What it found is fixed here. For a site updated
   from 1.1.x with a trusted proxy, the visitor address header is no longer picked
   up from a header a visitor could have added; only X-Forwarded-For is adopted 
   on its own. A live login lockout is no longer lifted by a sign-in finished later
   on the two-factor screen. Turning the scan schedule or the alerts off, raising
   the alert threshold, adding an alert recipient, excluding files and starting 
   the file history over now ask for your password, as turning a protection off 
   does. Serialized objects inside the posts, widgets and builder data the content
   check reads are never created. A post of many megabytes no longer holds the scan.
   A server rule that runs images as PHP through mod_rewrite, a redirect to another
   site inside a caching plugin’s block, a page or redirect saved as a « placeholder»
   in uploads, and a firewall bootstrap that only names the firewall’s folder in
   a comment are reported. File names are shown and quarantined exactly as stored,
   including a leading space or a marker inside the name. Paths longer than 1,024
   characters are stored whole. Findings whose severity depends on the state of 
   the site (an exposed backup, an available update, a known-bad scheduled task)
   come back after an ignore when that state gets worse. The history log refuses
   to seal over a change made outside the plugin, notices the deletion of its oldest
   entries and uses a lock name of its own per install; the personal data eraser
   also removes the address. Freshly issued recovery codes are stored encrypted.
   The excerpt sent to the AI second opinion also loses bearer tokens, positional
   random tokens and password values. Answers from shieldwave.io and WordPress.org
   have size limits, feed rules are tested for cost before use, and the detection
   of encoded files keeps to the time budget.
 * The readme says more precisely what the sync, the AI second opinion and the checks
   send and to whom, names the theme information service, and says which translation
   is used for the shipped languages.
 * Before release, the plugin went through a scan of a test site with the 200 most
   popular WordPress.org plugins and the plugins of five real sites, an update of
   a WordPress.org plugin, a premium plugin, a theme and WordPress core by FTP and
   through WordPress, and every check had to finish.

#### 1.1.12

 * Quarantine with restore for findings of the malware, PHP in uploads, core, file
   changes, plugin and theme checks. The file is stored encoded so it cannot run,
   and Restore puts back the same bytes.
 * Block PHP execution in the uploads folder and send security headers, each with
   its own switch, off by default. On nginx and IIS, Settings shows the rule to 
   add.
 * Two-factor login can be required for chosen roles, with 0 to 30 days to set it
   up. Passkeys (WebAuthn) work as the second step. Sessions can be listed and ended
   everywhere, and an administrator’s session length can be set.
 * The suggested privacy text now describes what two-factor login and passkeys store
   for an account.
 * Deleting the plugin also removes the quarantine folder, the passkey data and 
   the uploads .htaccess block.
 * Setting up an authenticator app asks for your password, and the owner gets an
   email for every new app. An account whose time to set up two-factor is over gets
   a code by email before the set-up screen.
 * Changes that lower protection (higher login limits, a trusted proxy, the file
   editor back on, a longer session) ask for your password, wherever they are made.
 * On a multisite network the plugin is network activated, so two-factor and login
   protection cover every site.
 * Quarantine refuses files the site loads on every request, checks the site still
   works after a move, and puts the file back if it does not.

#### 1.1.10

 * Login protection: a limit per user name, a limit on password reset requests, 
   trusted proxies as a list of addresses or CIDR ranges with a choice of header,
   and an email when an administrator’s user name is locked.
 * The activity log has its own table, its ordinary entries form a hash chain whose
   newest entry is recorded apart, so edited, deleted and cut-off entries are found,
   the retention is set in days and the log can be exported as CSV.
 * Privacy: a suggested text for Settings > Privacy, and the WordPress personal 
   data export and erasure tools cover the failed login records.
 * The AI second opinion redacts more before anything is sent (IP addresses, paths,
   all DB_ constants, database connection arguments, secrets from 6 characters),
   never reads configuration, credential, backup, dump, log and ini files, and starts
   the excerpt of PHP in an image at the PHP tag.
 * The banner that offers live protection now says that the AI second opinion sends
   redacted excerpts to shieldwave.io and its AI provider.
 * The API key is stored encrypted when the server allows it.
 * Deleting the plugin asks shieldwave.io to remove a connected site, and removes
   the tables, scheduled task and user settings this version adds.
 * A record link in a vulnerability finding is shown only for known vulnerability
   databases.
 * The readme describes what is sent and how often as the code does it: the threat
   feed and the lookups run every hour from WP-Cron, live protection has three features.
 * Malware detection follows request input more precisely and no longer flags legitimate
   code. On a test site with 35 popular plugins, 5 themes and WordPress core (52,800
   files) it flags nothing, and no file takes more than a fraction of a second. 
   Large PHP files are analysed within a time and memory budget.
 * File checks: a file that differs from its release only in line endings matches
   it, a change made by a recorded update is explained, and a real change stays 
   reported until it is reviewed. Links to other sites and odd file names are one
   finding per place.
 * Known vulnerabilities: when a fixed version exists but WordPress does not offer
   the update (a plugin closed on WordPress.org, a premium plugin, or an update 
   source that has no newer version), the finding says so and gives the steps for
   that case.
 * HTTPS: when the site address starts with http but every http address redirects
   to https, this is information, not a problem.
 * Login and two-factor: turning two-factor off for the whole site needs the password
   or a code, a changed or reset password forgets the remembered browsers, wp shieldwave
   unlock lifts a two-factor lock, and ?author= requests in any form no longer reveal
   a login name.
 * Alerts, notices and log entries use calmer, more precise wording.
 * Findings that name user accounts reach a connected shieldwave.io account without
   the names.
 * Every text was reviewed again for natural wording in all 16 languages, and 23
   unclear English texts were rewritten.

#### 1.1.9

 * Unused plugins can be deleted from their finding: tick the ones to remove (all
   are ticked) and confirm. It works like Delete on the Plugins screen, so each 
   plugin’s own uninstall runs. Only plugins in use nowhere are listed, never ShieldWave
   itself, and only for users who may delete plugins on a server where WordPress
   can write the files.
 * On a multisite network, a plugin switched on for one site only is no longer reported
   as unused.
 * Files that an older WordPress release left behind after an update are no longer
   reported as unknown PHP. Each one matches the checksums of the release it comes
   from; the check’s summary counts them and nothing needs to be done. A PHP file
   that no release explains is still reported.
 * Fewer false alarms on premium plugins: the storage index files All-in-One WP 
   Migration writes itself, the html2canvas library in Elementor Pro, a base64 image
   saved with wp_upload_bits(), and $GLOBALS read with a fixed key as in BerlinDB(
   WP Rocket and others) and ACF Pro.
 * An empty debug.log is not reported. A debug log the server refuses to hand out
   is a low note instead of a high finding; only a log that can really be downloaded
   stays high.
 * A site that works over HTTPS but has http:// in Settings > General gets a low
   note instead of « Login and dashboard are not served over HTTPS ».
 * With TranslatePress active, findings no longer show its #!trpst# markers, and
   texts follow the language of the admin instead of the site.
 * A new rule finds the cmd.exec remote-control backdoor family as critical, also
   outside the uploads folder. Every file is analysed again under the new rules.
 * In the network admin the texts say « network » where a single site says « site».
 * More room in the layout: a wider side margin, a calmer header with smaller tabs,
   a smaller headline and more space between sections. WordPress notices above the
   plugin are readable in dark mode.

#### 1.1.8

 * A scan no longer stops with an error on hosting whose PHP is built without the
   tokenizer extension (rare; it is on by default almost everywhere). Without it
   the malware rules match the raw text, as before 1.1.7.

#### 1.1.7

 * A finding about files now says where they are: « in the plugin X 2.3.0 (inactive)»,«
   in the theme Y », « in WordPress’s own files » or « in the uploads folder », 
   and the advice fits that place. An inactive plugin is to be deleted, a plugin
   from WordPress.org reinstalled, a premium one replaced with a fresh copy from
   its author, a WordPress file reinstalled from Dashboard > Updates. The same goes
   into the email alert and into « Copy for your developer ».
 * Every finding has « Read more »: a fuller explanation for a developer, where 
   the file comes from, the steps with WP-CLI commands and how to check the fix 
   worked, with a button that copies all of it. The plain message above stays as
   it was.
 * An old copy of ShieldWave Security (2.x or 3.x) left in the plugins folder is
   no longer reported as malware. Its scanner lists the names of known webshells
   as text to look for, which read like a webshell. Code-pattern rules now count
   only where the pattern is code, not inside a string or a translated sentence;
   real backdoors are still found.
 * After a scan, the Overview asks once whether to turn on live protection, with
   a link to what is sent. « Not now » hides it for 30 days. Nothing is turned on
   without the click.
 * Translations shipped with the plugin now win over an older language pack from
   translate.wordpress.org, which only fills what the plugin lacks. On Polish sites
   some sentences showed in English and corrected wording never appeared.
 * An empty threat feed says that it has nothing beyond the built-in rules yet, 
   instead of showing three zeros.
 * Many screen fixes: the layout is centred on wide screens, titles wrap instead
   of being cut off, form fields and the selected option read clearly in dark mode,
   notices above the plugin follow its theme, commands and settings fit a phone,
   the settings section list stays in view and marks the right section, changed 
   settings that are not saved yet are marked and leaving asks first, no glow under
   buttons, and one-letter words no longer end a Polish line.
 * The link to this site on shieldwave.io opens « My sites ».

#### 1.1.6

 * On a multisite network the ShieldWave screens are styled again. In the network
   admin WordPress names the screen differently from a single site, so the plugin
   did not recognise its own screens there: the stylesheet did not apply (plain 
   lists, tiny text), History and Settings opened as the Overview, and the footer
   line was missing.
 * WordPress itself is no longer reported as vulnerable for two old records that
   match every version and that WordPress has never fixed (a blind server-side request
   through pingbacks and activation keys stored in plain text). An up-to-date site
   was told « WordPress has 2 known vulnerabilities » and to wait for a fix that
   is not coming. A real vulnerability in WordPress is still reported with the release
   that fixes it.
 * A WordPress release that WordPress.org marks as insecure is reported with the
   secure release of its branch, even before the vulnerability databases have a 
   record for the fix.
 * A vulnerability in WordPress itself with no fixed release no longer offers the
   Plugins screen.

#### 1.1.5

 * The site and shieldwave.io agree on a language. When the site connects, the plugin
   tells shieldwave.io the site’s language; an account that has not chosen one yet
   takes it over, so the emails, reports and dashboard of shieldwave.io come in 
   the language the site already uses. The account’s language is shown next to the
   account under Settings and follows a change made in the dashboard within the 
   hour.

#### 1.1.4

 * Known-vulnerability checks and the threat feed now run every hour instead of 
   every three, so a vulnerability disclosed for one of your plugins or themes is
   reported, and emailed if alerts are on, within the hour. The lookups are cached
   on shieldwave.io, so the extra runs cost your site almost nothing. An existing
   schedule is moved to the new rhythm on update.

#### 1.1.3

 * A plain image in the uploads folder is no longer reported as an unknown PHP file.
   With « Images » switched on in Extra checks, every picture was listed as a high
   finding (a shop with 200 product photos saw all 200), and the email alert went
   out for them. An image is now reported only when ShieldWave actually finds PHP
   code inside it, which it still does.

#### 1.1.2

 * The screens keep the size of the WordPress admin on large monitors. Since 1.0.3
   the whole plugin was enlarged on windows wider than 1920 pixels (a third bigger
   at 2560); now a wider window gives the lists more room instead of bigger letters.
   Only a 4K window at 100% scaling gets one small step up.
 * The header, the status band, the lists and the footer share one left and right
   edge, and the light under the current tab sits exactly on the header’s bottom
   line.
 * A tidier header: a slightly lower headline, the theme switch and Scan now in 
   the same rounded shape.
 * More bot traffic in the simulation on the planet, most of it aimed at your site,
   also when the system asks for less motion.

#### 1.1.1

 * The automatic scan stays on the hour you chose. It kept its old clock time after
   the clocks changed or after you picked another time zone under Settings > General,
   so « At 03:00 » could sit beside « Next scan at 02:00 ». Every run now plans 
   the next one from your site’s own time. On the one day the clocks skip the chosen
   hour, the scan runs right after it; when an hour happens twice, it runs once,
   the first time.
 * The update replaces the schedule of 1.1.0 at once, and nothing is scheduled twice.
 * The weekly summary follows your site’s clock in the same way.
 * The hours in the list under « At » use your site’s time format, the same as «
   Next scan », and « today » and « tomorrow » are right on the days the clocks 
   change.
 * « See plans » opens the pricing page with the Pro plan selected.
 * After a scan, the Overview shows one plain line about the free outside check 
   at shieldwave.io, with your domain filled in. There is nothing to dismiss, and
   nothing is sent unless you click it.
 * Every link from the plugin to shieldwave.io carries the tags utm_source=wordpress,
   utm_medium=plugin and utm_campaign=(the screen the link is on), which tell shieldwave.
   io only which link a visit came from.

#### 1.1.0

 * Connect with shieldwave.io in one click, from Settings or the Overview: sign 
   in or create a free account there, press « Connect this site » and you are back.
   Pasting an API key still works, under « Use an API key instead ».
 * A free shieldwave.io account shows one site in the dashboard, with its score 
   and open problems.
 * While connected, shieldwave.io confirms that the domain is yours from an invisible
   tag on the home page, so its full outside scan can run on the site.
 * Disconnecting removes the site and its results from shieldwave.io, and a copy
   of the site at another address (a staging copy) shows as a site of its own.
 * The dashboard shows the AI second opinion on a file, and problems you ignored
   as ignored.
 * Known vulnerabilities: plugins whose folder name has capital letters are matched
   again, and one plugin the lookup cannot read no longer stops the check for all
   the others.
 * The old ShieldWave Security from shieldwave.io and this plugin can be installed
   side by side without losing anything: deactivating or deleting one leaves the
   settings, results, schedule and two-factor set-ups of the other alone, and a 
   notice says how to remove the old copy.
 * Problems about administrator accounts are sent to the dashboard without the account
   names, and the texts about what is sent say exactly that.
 * « Turn all of it on » beside Live protection on the Overview works without JavaScript
   too.

#### 1.0.3

 * A clearer Overview: every group of problems has its own heading above its list,
   a row shows the name of the problem, and everything else opens with a click.
 * The tabs in the header are easier to see, and the Settings tab shows how many
   protections are still off.
 * The look of shieldwave.io: its colours, and its planet beside the status of your
   site. The planet marks where your site is and shows a simulation of typical bot
   traffic; a button beside it stops the motion.
 * The screens grow with the window on large monitors, and buttons are easier to
   hit on phones.
 * « New » marks a problem only when some problems are new and others are not.
 * When a problem has no WordPress screen to open, « Copy for your developer » is
   the main button.
 * No request for a review while something urgent is open.
 * « Turn on » beside Known vulnerabilities opens the right part of Settings, and
   the time of an AI second opinion no longer says « ago » twice.
 * In the dark theme the hour of the automatic scan stays readable while its list
   is open, and switches that are off have a visible edge.

#### 1.0.2

 * Emails display correctly in Outlook on Windows: the button keeps its padding,
   the fonts stay the same in every part of the message, and a long file path wraps
   instead of widening the message.
 * The ShieldWave mark in emails is in the brand colour, so it shows in Outlook’s
   dark mode too.

#### 1.0.1

 * Translated into Arabic, Chinese (Simplified), Dutch, French, German, Indonesian,
   Italian, Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Swedish,
   Turkish and Vietnamese.
 * Right-to-left layout for Arabic and other right-to-left admin languages.
 * The ShieldWave mark in the plugin’s header and admin menu, the same as on shieldwave.
   io.
 * Alert emails carry the ShieldWave mark (embedded in the email, nothing is loaded
   from outside), a clearer layout and a right-to-left layout for Arabic.
 * After a few scans, the Overview asks once whether you would review the plugin
   on WordPress.org. « Later » and « Do not ask again » are remembered per administrator.

#### 1.0.0

 * First release in the WordPress.org directory.
 * Builds downloaded earlier from shieldwave.io were numbered up to 3.6.6. To switch,
   deactivate and delete that copy, then install this one; the first scan starts
   the file history again.

## Mèta

 *  Version **1.1.13**
 *  Last updated **2 oras ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 *  Languages
 * [English (US)](https://wordpress.org/plugins/ensomedia-security/), [Polish](https://pl.wordpress.org/plugins/ensomedia-security/),
   [Russian](https://ru.wordpress.org/plugins/ensomedia-security/) e .[Swedish](https://sv.wordpress.org/plugins/ensomedia-security/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/ensomedia-security)
 * Tags
 * [File Integrity](https://oci.wordpress.org/plugins/tags/file-integrity/)[hardening](https://oci.wordpress.org/plugins/tags/hardening/)
   [malware scanner](https://oci.wordpress.org/plugins/tags/malware-scanner/)[security](https://oci.wordpress.org/plugins/tags/security/)
   [vulnerability scanner](https://oci.wordpress.org/plugins/tags/vulnerability-scanner/)
 *  [Advanced View](https://oci.wordpress.org/plugins/ensomedia-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/ensomedia-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/ensomedia-security/reviews/)

## Contributors

 *   [ shieldwave ](https://profiles.wordpress.org/shieldwave/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/ensomedia-security/)