
Seguridad de acceso por Solutiontech protects WordPress access and reduces unnecessary public exposure without renaming core files or modifying .htaccess.
Main features:
- Generador de Informes Ejecutivos de Seguridad para Clientes (PDF / HTML): Reportes corporativos listos para imprimir o descargar como HTML autónomo, con métricas ejecutivas, score de seguridad, resumen de vectores neutralizados y personalización con nombre de agencia.
- Motor de Reglas WAF Personalizadas (Custom Firewall Rules): Reglas a medida por URI, Query String, User-Agent o contenido POST con operadores de coincidencia y expresiones regulares protegidas contra ReDoS.
- Procedencia Geográfica de Amenazas en Tiempo Real: Monitoreo y agregación de países de origen con banderas y porcentajes relativos en el Centro de Inteligencia de Amenazas.
- Breached Password Protection (HaveIBeenPwned k-Anonymity API): Validates new passwords against public breach databases using strict 5-character SHA-1 range queries with Add-Padding to guarantee zero password disclosure.
- Instant Lockout for Forbidden Dictionary Usernames: Immediately bans offending IPs on attempt #1 when attempting generic attacker usernames (admin, root, administrator, test, etc.) without waiting for standard retry limits.
- Global Session Kill-Switch / Panic Button: Emergency one-click button to revoke all active WordPress session tokens across the site in case of security incident or intrusion.
- Agency Threat Network & Central Hub Mode: Connect to Solutiontech distributed threat intelligence network or operate as a central agency hub to synchronize IP blacklists and whitelists across client websites.
- 2FA Emergency Backup Recovery Codes: Generates secure single-use recovery code sets in user profiles to prevent lockouts.
- Cloudflare Turnstile Anti-Bot Protection: Frictionless, privacy-first bot detection challenge across login, registration, and lost password forms.
- Malware Upload Shield (PHP File Scanner): Automatically scans /wp-content/uploads/ for suspicious executable PHP scripts and backdoors.
- Interactive Audit Log Filter & Live Search: Instant client-side search and category filtering across recorded security events.
- Authenticator App 2FA (TOTP – RFC 6238): Support for Google Authenticator, Microsoft Authenticator, and Authy with QR code pairing in user profiles.
- GeoIP Country Restriction: Allow or block access based on visitor country code from reverse proxies and Cloudflare.
- Security Email Alerts: Real-time HTML notifications with anti-flood rate limits for brute force, WAF blocks, and core discrepancies.
- WordPress Dashboard Widget: Overview widget with security score ring, status pills, and 24-hour threat metrics.
- Micro-WAF (Web Application Firewall): Early inspection and neutralisation of SQL Injections (SQLi), Cross-Site Scripting (XSS), Path Traversal (LFI), Remote Code Execution (RCE), and malicious security scanners.
- IP Whitelist & Permanent Blacklist: Allows instant exclusion for trusted IPs and permanent 403 blocking for malicious IPs and CIDR ranges across the entire website.
- WordPress Core File Integrity Checker: Verifies local core files against official WordPress.org cryptographic MD5 checksums to detect modified or missing CMS files.
- Two-Factor Authentication (2FA via Email OTP): Delivers a 6-digit one-time code to authorized user emails to secure privileged logins.
- Strong Password Policies & Expiration: Enforces 12+ character complexity and optional periodic password expiration reminders.
- Official Internationalization & Translation Template: Standard .pot file included in languages/ for seamless translation with Poedit, Loco Translate, or WordPress.org GlotPress.
- Invisible Honeypot Anti-Spam: Blocks automated bots across login, password recovery, registration, and comment forms without annoying CAPTCHAs.
- Pingback & XML-RPC DDoS Protection: Strips X-Pingback headers and disables XML-RPC pingback reflection methods.
- WordPress Core Hardening: Hide WordPress version from headers/feeds/asset query strings, remove legacy discovery tags (RSD, WLWManifest, oEmbed), and disable built-in file editing.
- Background automated cleanup with WP-Cron for expired audit logs and 404 entries.
- Secure CSV export for Audit Log and 404 Monitor with Excel UTF-8 BOM and formula injection protection.
- Runtime in-memory caching for faster settings retrieval without redundant database queries.
- Google reCAPTCHA v3 invisible bot protection with score threshold on login and lost-password forms.
- HTTP Security Headers injection (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and HSTS).
- Progressive brute-force lockout with escalating lockout tiers for repeat offenders.
- Optional WooCommerce catalog mode, including controls for administrators and variable products.
- Security status dashboard with an informative score and links to each setting.
- Responsive sidebar navigation organized by security area.
- Session and device management based on native WordPress session tokens.
- Individual session revocation, single-session policy, and optional inactivity timeout.
- Optional alerts when a user signs in from a new device.
- 404 monitor with retention, entry limits, and direct conversion to a redirect rule.
- Same-site redirect manager supporting 301, 302, 307, and 308 responses.
- Optional custom login URL and random URL regeneration.
- Protection against direct access to wp-login.php and wp-admin for visitors.
- Configurable login attempt limiting by IP address using WordPress transients.
- Generic login errors to reduce account enumeration.
- Optional author enumeration and public REST user endpoint protection.
- Optional XML-RPC restriction.
- Environment diagnostics for Multisite, subdirectories, proxy/CDN setups, WooCommerce, and recovery flows.
- Optional deterrents for casual copying of images and text.
- Local audit log for relevant authentication and administration events.
- Configurable audit-log retention from 1 to 365 days, limited to 500 events.
- Independent controls for new comments and pingbacks on posts and pages.
- Optional email alerts when the login-attempt limit is reached.
- Configurable response for blocked login routes: 404, home page, or a custom URL.
The plugin does not modify WordPress files. After deactivation, WordPress uses its standard login routes again.
Developer website: https://solutiontech.cl/
External Service and Privacy
This plugin can optionally connect to the following external services:
- Solutiontech Threat Intelligence Network (https://solutiontech.cl/)
* Purpose: Synchronizes distributed IP blacklists and whitelists to protect WordPress installations against emerging cyber threats and brute-force campaigns.
* Data sent: Site URL, WordPress core version, and plugin version upon manual or scheduled sync. If anonymous threat reporting is enabled, the IP address and reason for blocked attacks intercepted by the local Micro-WAF are sent.
* Service provider: Solutiontech (https://solutiontech.cl)
* Privacy Policy: https://solutiontech.cl/politica-de-privacidad/
* Terms of Service: https://solutiontech.cl/terminos-y-condiciones/
* Note: This service is 100% OPT-IN and completely disabled by default until explicitly enabled by an administrator with a valid API key.
- WordPress.org Core API (https://api.wordpress.org/)
* Purpose: Verifies the integrity of WordPress core files by comparing local file hashes against official checksums.
* Data sent: WordPress version and locale.
* Service provider: WordPress Foundation
* Privacy Policy: https://wordpress.org/about/privacy/
- WPVulnerability API (https://www.wpvulnerability.net/)
* Purpose: Scans installed plugins, themes, and WordPress core against public vulnerability databases (CVEs).
* Data sent: Slugs and installed version numbers of plugins/themes (no personal or proprietary data).
* Service provider: WPVulnerability
* Privacy Policy: https://www.wpvulnerability.net/privacy/
External services
This plugin can connect to the following third-party external services when explicitly configured and enabled by the site administrator:
-
Google reCAPTCHA v3:
- Purpose: Protects authentication and password recovery forms against automated bots and credential-stuffing attacks.
- Data sent & when: When enabled with site administrator API credentials, user interaction tokens and visitor IP address are sent to
https://www.google.com/recaptcha/api/siteverifyduring form submission to obtain a risk confidence score. - Service provider: Google LLC.
- Terms of Service: https://policies.google.com/terms
- Privacy Policy: https://policies.google.com/privacy
-
Cloudflare Turnstile:
- Purpose: Provides frictionless, privacy-preserving smart anti-bot challenge validation on login, registration, and lost password forms.
- Data sent & when: When enabled with site administrator API credentials, the Turnstile response token and visitor IP address are sent to
https://challenges.cloudflare.com/turnstile/v0/siteverifyduring form submission. - Service provider: Cloudflare, Inc.
- Terms of Service: https://www.cloudflare.com/website-terms/
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
-
WordPress.org Core Checksums API:
- Purpose: Validates the integrity of local WordPress CMS files against official cryptographic checksums in the Diagnostics panel.
- Data sent & when: The current WordPress version and locale string (e.g., version and language code) are sent to
https://api.wordpress.org/core/checksums/1.0/only when an administrator clicks the “Comprobar integridad del núcleo” button in the diagnostics dashboard. No user personal data is sent. - Service provider: WordPress Foundation / WordPress.org.
- Privacy Policy: https://wordpress.org/about/privacy/
-
HaveIBeenPwned API (Pwned Passwords):
- Purpose: Validates user passwords during profile creation, profile updates, or password resets to prevent the use of passwords that have been publicly exposed in known data breaches.
- Data sent & when: When the breached password policy is enabled, only the first 5 characters of the uppercase SHA-1 hash of the password (k-Anonymity model) are sent via secure GET request to
https://api.pwnedpasswords.com/range/{prefix}with theAdd-Padding: trueheader. The plaintext password and remaining 35 hash characters are never transmitted over the network or stored. - Service provider: Troy Hunt / Have I Been Pwned.
- Terms of Service: https://haveibeenpwned.com/API/v3
- Privacy Policy: https://haveibeenpwned.com/Privacy
-
Note on 2FA QR Codes: Two-Factor Authentication (TOTP) QR codes are generated 100% locally on your server in pure PHP as inline SVG. No secret keys or user data are ever sent to any external server or third-party service.
Privacy
The plugin does not send telemetry to Solutiontech. Optional security modules store their data locally in the WordPress database. Audit events may include complete IP addresses for forensic traceability, while the administration table displays masked addresses. WordPress session tokens may contain IP, browser, and date information. The 404 monitor does not store IP addresses or query parameters. If email alerts are enabled, the site sends the relevant information through its configured mail system. Site administrators are responsible for providing any required privacy notice and choosing an appropriate retention period.
Screenshots

Security Overview Dashboard with safety score gauge, protection indicators, and module matrix.

Custom Login URL and Brute-Force Rate Limiting configuration.

Micro-WAF (Web Application Firewall), IP Access Lists (Whitelist/Blacklist), and Country Geolocation Filtering (GeoIP).

Interactive Live Forensic Audit Log with instant search, category filtering, and CSV export.