BACK TO DIRECTORY
Rooted Dev Studio Security Toolkit provides a transparent baseline for protecting a WordPress website without hiding important behavior behind vague scores or destructive automatic fixes.
Features include:
- Configurable failed-login limiting with short, per-login-and-IP temporary lockouts.
- Administrator controls for reviewing and clearing active Rooted Dev Studio Security Toolkit lockouts.
- Time-based two-factor authentication with single-use recovery codes.
- A local Security Timeline for important authentication, administration, hardening, and file events.
- Hashed origin records without storing raw IP addresses in security events.
- Baseline browser security headers.
- Reversible theme and plugin editor protection.
- Optional XML-RPC authentication restriction.
- Optional public REST user endpoint restriction.
- Security configuration checks for HTTPS, updates, debug display, administrator access, WordPress salts, and PHP.
- Read-only file fingerprinting with expected and unexplained change review.
- A bounded, manual suspicious-code scan for selected high-risk PHP patterns.
- Email alerts for important software and administrator changes and repeated-login lockouts.
- Local retention controls and automatic cleanup.
Rooted Dev Studio Security Toolkit does not transmit site data to Rooted Dev Studio or any third party. It does not execute, edit, quarantine, restore, or delete scanned files. A clean scan is not a guarantee that a website is free of malicious code. Rooted Dev Studio Security Toolkit does not replace secure hosting, backups, software updates, or professional incident response.
Plugin Details
Active Installs
0Total Downloads
61Version
0.2.1Requires WP
6.5Requires PHP
7.4Tested Up To
7.1Added
2026-08-29Last Updated
2026-08-29 8:01pm GMTRatings
5
0
4
0
3
0
2
0
1
0