Title: Webro Security
Author: webro
Published: <strong>ସେପ୍ଟେମ୍ବର 1, 2026</strong>
Last modified: ଅକ୍ଟୋବର 5, 2026

---

Search plugins

![](https://ps.w.org/webro-security/assets/banner-772x250.png?rev=3675560)

![](https://ps.w.org/webro-security/assets/icon-256x256.png?rev=3675560)

# Webro Security

 By [webro](https://profiles.wordpress.org/webrodk/)

[Download](https://downloads.wordpress.org/plugin/webro-security.1.0.4.zip)

 * [Details](https://ory.wordpress.org/plugins/webro-security/#description)
 * [Reviews](https://ory.wordpress.org/plugins/webro-security/#reviews)
 *  [Installation](https://ory.wordpress.org/plugins/webro-security/#installation)
 * [Development](https://ory.wordpress.org/plugins/webro-security/#developers)

 [Support](https://wordpress.org/support/plugin/webro-security/)

## Description

A WordPress plugin that adds security headers, CSP, login protection, SMTP, spam
protection and more. Functionality is continuously being expanded to cover more 
ground.

#### Features

 * Adds security headers, including configurable HSTS, X-Frame-Options, COOP and
   CORP
 * Supports Content Security Policy (CSP), editable from the admin UI and validated
   against unrecognized directives
 * Protects login with rate-limiting
 * Blocks weak passwords, with an exemption list for individual users
 * Blocks common/guessable usernames
 * Validates protected brand names against required domains — self-registration 
   blocks a brand-impersonating email outright
 * Locks file editing, with a temporary admin-bar toggle that automatically relocks
   after a period of inactivity
 * Honeypot spam protection (CF7, Elementor, WPForms, Forminator, lost password)
 * Custom SMTP sending, with a test-email button
 * Central security log with automatic retention, including new user account creation
 * Removes certain default WordPress traces from `<head>`
 * Blocks usernames from leaking through author URLs, the REST API and embedded 
   author data
 * English, with community translations available via translate.wordpress.org

#### What does it protect against?

 * Basic login attacks
 * Some forms of user enumeration
 * Unwanted WordPress metadata
 * Missing security headers

**Important:** it does not protect against vulnerabilities in other plugins or themes,
poor server configuration, or missing updates.

#### Compatibility

Some security headers can affect elements such as iframes, embeds and third-party
scripts. Some of the CSP directives may be too strict and might need loosening depending
on your needs — this is done from the admin UI’s CSP field (administrator role).

### Support

Contact webro with questions or bug reports at len@webro.dk

## Screenshots

[[

[[

[[

[[

[[

[[

## Installation

 1. Upload the plugin to `wp-content/plugins/`
 2. Activate it via the WordPress admin panel

#### Uninstallation

 * Removes the plugin’s saved options
 * Removes the plugin’s transients
 * Cleans up its own settings on uninstall

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Webro Security” is open source software. The following people have contributed 
to this plugin.

Contributors

 *   [ webro ](https://profiles.wordpress.org/webrodk/)
 *   [ Lasse Enggaard ](https://profiles.wordpress.org/lasseenggaard/)
 *   [ Rikke Rasmussen ](https://profiles.wordpress.org/rirasmussen/)

[Translate “Webro Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/webro-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/webro-security/), check
out the [SVN repository](https://plugins.svn.wordpress.org/webro-security/), or 
subscribe to the [development log](https://plugins.trac.wordpress.org/log/webro-security/)
by [RSS](https://plugins.trac.wordpress.org/log/webro-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.4

 * Fixed the security headers blocking the block editor when adding a new page/post:
   blob: is now allowed in the frame-src and connect-src directives of the default
   CSP
 * wp-admin and wp-login are now excluded from the .htaccess security headers without
   depending on the mod_setenvif Apache module, also on sites installed in a subdirectory
 * The PHP fallback for the security headers no longer applies to wp-admin and wp-
   login
 * After an update, the plugin now rewrites its .htaccess security headers itself
   and drops an outdated saved default CSP, so the settings no longer have to be
   re-saved by hand
 * Hardened the honeypot: the timing check is now signed by the server, and the 
   way the honeypot field is hidden varies between page loads
 * Expanded the list of blocked usernames
 * The author name and author URL are no longer exposed in oEmbed responses, and
   WordPress’ built-in users sitemap is turned off, since both revealed usernames
   to visitors who are not logged in

#### 1.0.0

 * First version

## Meta

 *  Version **1.0.4**
 *  Last updated **2 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 8.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/webro-security/)
 * Tags
 * [csp](https://ory.wordpress.org/plugins/tags/csp/)[login protection](https://ory.wordpress.org/plugins/tags/login-protection/)
   [security](https://ory.wordpress.org/plugins/tags/security/)[smtp](https://ory.wordpress.org/plugins/tags/smtp/)
   [spam protection](https://ory.wordpress.org/plugins/tags/spam-protection/)
 *  [Advanced View](https://ory.wordpress.org/plugins/webro-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/webro-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/webro-security/reviews/)

## Contributors

 *   [ webro ](https://profiles.wordpress.org/webrodk/)
 *   [ Lasse Enggaard ](https://profiles.wordpress.org/lasseenggaard/)
 *   [ Rikke Rasmussen ](https://profiles.wordpress.org/rirasmussen/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/webro-security/)