
Lunexia Security – .htaccess Shield, Firewall, Two Factor Authentication (2FA) & Malware Protection
by lunexiait
Lunexia Security & .htaccess Shield is an all-in-one WordPress security suite engineered to defend your website against attacks, malicious bots, unauthorized login attempts, and malware infections. Combining proven .htaccess server hardening, an intelligent Web Application Firewall (WAF), Two-Factor Authentication (2FA / OTP login protection), login brute force defense, and a deep malware scanner with 1-click quarantine, Lunexia provides comprehensive website security that is ultra-lightweight, safe, and fully compatible with WordPress 7.0 Modern admin and PHP 8+.
Whether you need rock-solid login protection, two-factor authentication, malware removal, or instant .htaccess security headers, Lunexia delivers enterprise-grade protection with zero bloat.
🛡️ Key Security Features:
- Two-Factor Authentication (2FA) & OTP Login Security: Add time-based one-time password (OTP) verification for Administrators, Editors, and custom roles. Protect your login forms from credential stuffing and unauthorized access.
- Login Brute Force Protection: Detect, limit, and automatically block malicious IP addresses attempting brute force login attacks.
- Web Application Firewall (WAF): Real-time inspection for SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion (LFI), and Remote Code Execution (RCE) attempts without breaking page builders like Elementor or Gutenberg.
- Malware Scanner & Threat Detection: Deep file integrity and heuristic scanner to detect webshells, backdoors, obfuscated base64 code, eval injections, and unauthorized core file modifications.
- 1-Click Quarantine & Cleanup: Instantly isolate infected files into a safe, non-executable quarantine vault with full 1-click restoration and permanent deletion controls.
- Automatic .htaccess Hardening: Safely apply proven Apache/LiteSpeed security rules with automatic timestamped backups before every change.
- Admin Approval Workflow: Require administrator approval for newly registered administrative and editor accounts before they can log in.
- Backend Access Control: Restrict access to
wp-adminandwp-login.phpexclusively to trusted, whitelisted IP addresses. - Security Headers Protection: Automatically enforce Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, and Referrer-Policy.
- Live Traffic Monitor & IP Reputation: Real-time traffic surveillance tracking visitor requests, malicious bots, automated crawlers, and blocked threat origins.
- Modern WordPress 7.0 Ready: Centered layout, high-DPI retina interface, and modern glassmorphic dashboard widgets.
🔒 Security Rules Included:
- Disable directory browsing and file listing (
Options -Indexes) - Protect
wp-config.phpdatabase credentials and.htaccessconfiguration files - Block direct web access to sensitive files (
.bak,.sql,.log,.ini,.sh,.env) - Disable XML-RPC (
xmlrpc.php) to block pingback DDoS and brute force amplifications - Prevent unauthorized PHP script execution in the
wp-content/uploads/directory - Block malicious query string injections, GLOBALS variable overrides, and script tags
- Block author enumeration attacks (
?author=1) to prevent username discovery - Enforce essential HTTP security headers (XSS Protection, No-Sniff, HSTS, Frame Guard)
⚡ Safe, Non-Destructive & Reliable:
- Automatically creates a backup before applying any file modifications.
- Uses native WordPress filesystem APIs for maximum server compatibility.
- All generated rules are cleanly encapsulated in custom markers for 1-click restore.
- Seamless compatibility with Elementor, Gutenberg, WooCommerce, and caching plugins.
External Services
This plugin connects to external services as follows:
Lunexia License Authority (api.lunexiait.com)
This plugin connects to the Lunexia central license server to validate commercial license authenticity, verify cryptographic Ed25519 tokens, and check domain bindings. This connection is used when activating, validating, or deactivating a license key in the plugin dashboard.
- Purpose: Validates license authenticity, cryptographic tokens, and domain licensing.
- When it’s used: When activating, validating, or deactivating an enterprise license.
- What data is sent: License key, website URL/domain, verification nonces, PHP and WordPress version numbers.
- Service provider: Lunexia IT (api.lunexiait.com)
- Terms of Service: https://lunexiait.com/terms/
- Privacy Policy: https://lunexiait.com/privacy/