{"id":355203,"date":"2026-09-01T07:41:18","date_gmt":"2026-09-01T07:41:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/webro-security\/"},"modified":"2026-10-05T09:05:58","modified_gmt":"2026-10-05T09:05:58","slug":"webro-security","status":"publish","type":"plugin","link":"https:\/\/ory.wordpress.org\/plugins\/webro-security\/","author":23550845,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.4","stable_tag":"1.0.4","tested":"7.1.2","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"Webro Security","header_author":"webro.dk","header_description":"Improves WordPress security with security headers, CSP, login protection, SMTP and spam protection.","assets_banners_color":"ced1d7","last_updated":"2026-10-05 09:05:58","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/webro.dk\/wordpress-plugins\/webro-security\/","header_author_uri":"https:\/\/webro.dk","rating":0,"author_block_rating":0,"active_installs":0,"downloads":138,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"webrodk","date":"2026-09-01 07:40:51","revision":3675561},"1.0.4":{"tag":"1.0.4","author":"webrodk","date":"2026-10-05 09:05:58","revision":3728477}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3675560,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3675560,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3675560,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3675560,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.4"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3675560,"resolution":"1","location":"assets","locale":"","width":1756,"height":848},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3675560,"resolution":"2","location":"assets","locale":"","width":1748,"height":786},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3675560,"resolution":"3","location":"assets","locale":"","width":1745,"height":579},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3675560,"resolution":"4","location":"assets","locale":"","width":1766,"height":798},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3675560,"resolution":"5","location":"assets","locale":"","width":989,"height":429},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3675560,"resolution":"6","location":"assets","locale":"","width":987,"height":373}},"screenshots":[]},"plugin_section":[],"plugin_tags":[19966,15756,600,6696,2419],"plugin_category":[41,54],"plugin_contributors":[273391,278614,278613],"plugin_business_model":[],"class_list":["post-355203","plugin","type-plugin","status-publish","hentry","plugin_tags-csp","plugin_tags-login-protection","plugin_tags-security","plugin_tags-smtp","plugin_tags-spam-protection","plugin_category-communication","plugin_category-security-and-spam-protection","plugin_contributors-lasseenggaard","plugin_contributors-rirasmussen","plugin_contributors-webrodk","plugin_committers-webrodk"],"banners":{"banner":"https:\/\/ps.w.org\/webro-security\/assets\/banner-772x250.png?rev=3675560","banner_2x":"https:\/\/ps.w.org\/webro-security\/assets\/banner-1544x500.png?rev=3675560","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/webro-security\/assets\/icon-128x128.png?rev=3675560","icon_2x":"https:\/\/ps.w.org\/webro-security\/assets\/icon-256x256.png?rev=3675560","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/webro-security\/assets\/screenshot-1.png?rev=3675560","caption":""},{"src":"https:\/\/ps.w.org\/webro-security\/assets\/screenshot-2.png?rev=3675560","caption":""},{"src":"https:\/\/ps.w.org\/webro-security\/assets\/screenshot-3.png?rev=3675560","caption":""},{"src":"https:\/\/ps.w.org\/webro-security\/assets\/screenshot-4.png?rev=3675560","caption":""},{"src":"https:\/\/ps.w.org\/webro-security\/assets\/screenshot-5.png?rev=3675560","caption":""},{"src":"https:\/\/ps.w.org\/webro-security\/assets\/screenshot-6.png?rev=3675560","caption":""}],"raw_content":"<!--section=description-->\n<p>A WordPress plugin that adds security headers, CSP, login protection, SMTP, spam protection and more. Functionality is continuously being expanded to cover more ground.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li>Adds security headers, including configurable HSTS, X-Frame-Options, COOP and CORP<\/li>\n<li>Supports Content Security Policy (CSP), editable from the admin UI and validated against unrecognized directives<\/li>\n<li>Protects login with rate-limiting<\/li>\n<li>Blocks weak passwords, with an exemption list for individual users<\/li>\n<li>Blocks common\/guessable usernames<\/li>\n<li>Validates protected brand names against required domains \u2014 self-registration blocks a brand-impersonating email outright<\/li>\n<li>Locks file editing, with a temporary admin-bar toggle that automatically relocks after a period of inactivity<\/li>\n<li>Honeypot spam protection (CF7, Elementor, WPForms, Forminator, lost password)<\/li>\n<li>Custom SMTP sending, with a test-email button<\/li>\n<li>Central security log with automatic retention, including new user account creation<\/li>\n<li>Removes certain default WordPress traces from <code>&lt;head&gt;<\/code><\/li>\n<li>Blocks usernames from leaking through author URLs, the REST API and embedded author data<\/li>\n<li>English, with community translations available via translate.wordpress.org<\/li>\n<\/ul>\n\n<h4>What does it protect against?<\/h4>\n\n<ul>\n<li>Basic login attacks<\/li>\n<li>Some forms of user enumeration<\/li>\n<li>Unwanted WordPress metadata<\/li>\n<li>Missing security headers<\/li>\n<\/ul>\n\n<p><strong>Important:<\/strong> it does not protect against vulnerabilities in other plugins or themes, poor server configuration, or missing updates.<\/p>\n\n<h4>Compatibility<\/h4>\n\n<p>Some security headers can affect elements such as iframes, embeds and third-party scripts. Some of the CSP directives may be too strict and might need loosening depending on your needs \u2014 this is done from the admin UI's CSP field (administrator role).<\/p>\n\n<h3>Support<\/h3>\n\n<p>Contact webro with questions or bug reports at len@webro.dk<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>wp-content\/plugins\/<\/code><\/li>\n<li>Activate it via the WordPress admin panel<\/li>\n<\/ol>\n\n<h4>Uninstallation<\/h4>\n\n<ul>\n<li>Removes the plugin's saved options<\/li>\n<li>Removes the plugin's transients<\/li>\n<li>Cleans up its own settings on uninstall<\/li>\n<\/ul>\n\n<!--section=changelog-->\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Fixed the security headers blocking the block editor when adding a new page\/post: blob: is now allowed in the frame-src and connect-src directives of the default CSP<\/li>\n<li>wp-admin and wp-login are now excluded from the .htaccess security headers without depending on the mod_setenvif Apache module, also on sites installed in a subdirectory<\/li>\n<li>The PHP fallback for the security headers no longer applies to wp-admin and wp-login<\/li>\n<li>After an update, the plugin now rewrites its .htaccess security headers itself and drops an outdated saved default CSP, so the settings no longer have to be re-saved by hand<\/li>\n<li>Hardened the honeypot: the timing check is now signed by the server, and the way the honeypot field is hidden varies between page loads<\/li>\n<li>Expanded the list of blocked usernames<\/li>\n<li>The author name and author URL are no longer exposed in oEmbed responses, and WordPress' built-in users sitemap is turned off, since both revealed usernames to visitors who are not logged in<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First version<\/li>\n<\/ul>","raw_excerpt":"Adds security headers, CSP, login protection, SMTP configuration and spam protection to harden your WordPress site.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/355203","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=355203"}],"author":[{"embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/webrodk"}],"wp:attachment":[{"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=355203"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=355203"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=355203"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=355203"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=355203"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ory.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=355203"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}