007AJ Security Scanner & Firewall Suite — Documentation

Guide to installing and using 007AJ Security Scanner & Firewall Suite (version 0.1.2). The Suite is standalone, so this page covers the whole plugin.

Contents

1. Installation and the free plugin

Requirements: WordPress 6.3 or newer and PHP 7.4 or newer.

  1. In WordPress go to Plugins → Add New → Upload Plugin, choose the 007aj-security-scanner-firewall-suite zip and click Install Now, or upload the folder to /wp-content/plugins/.
  2. Click Activate. A 007AJ Security menu appears with Dashboard, Settings, Integrity scan, File changes, Live traffic and Activity log.
  3. Open 007AJ Security → Settings and turn on the protections you want, one tab at a time.
The Suite is standalone and does not need the free 007AJ Security Scanner & Firewall plugin. If the free plugin is active, it pauses itself and shows a notice; you can deactivate it. If you deactivate the Suite, the free plugin resumes on its own. Settings are not copied between the two plugins.

No account or sign-up is needed. All features work as soon as the plugin is active.

2. Settings tabs

TabWhat it controls
LoginLogin lockout: attempts, window, lockout length, email alert.
FirewallOn/off, rule categories, form value checks, custom allow and block paths, XML-RPC switch.
Rate limitsLogin posts, all requests, REST requests, “not found” floods, and the length of temporary blocks.
IP rulesAllow list and block list.
ScansSchedule, plugin checksum checks, file change monitoring, email digest and recipient.
Live trafficOn/off, IP shortening, skip administrators.
HardeningFile editors, username discovery, version tag, application passwords.
Log and dataActivity log on/off, and whether to delete all data when the plugin is deleted.

Every protection is off after activation. Each tab is saved separately.

3. Login lockout and login rate limit

4. Firewall

The firewall checks the request path, the user agent, query string names and values, and form field names. Matching requests get a 403 page and, if the log is on, an activity log entry with the rule that matched.

Rule categories

Other options

Logged-in administrators and editors are not checked by the pattern rules, so normal editing keeps working.

The rules were written for this plugin and change only through plugin releases. They catch common probes; they are not a complete defence.

5. IP rules

Country blocking is not included. It would need a GeoIP database or an outside lookup service, and this plugin uses neither. Use CIDR ranges, or your host’s or CDN’s country rules instead.

6. Rate limits

LimitDefaultAnswer
Login posts to wp-login.php20 per 5 minutes429
All requests300 per minute429 with Retry-After
REST API requests120 per minute429
“Not found” pages30 per 5 minutestemporary block of the address on the whole site (default 15 minutes)

Each limit is off until you turn it on and its numbers can be changed. Logged-in administrators are exempt from most limits, and allowlisted addresses from all of them. Without a persistent object cache, the all-requests limit stores a counter in the database on each request, so set it with your traffic in mind.

7. Integrity scan

On Integrity scan, Run scan now compares every WordPress core file with the official WordPress.org checksums and lists modified, missing and unknown files (in wp-admin, wp-includes and the site root).

With Check plugins on (Scans tab, off by default), plugins installed in their own folder are also compared with the checksums WordPress.org publishes for that plugin and version. Plugins whose Update URI header points somewhere other than WordPress.org are skipped without a request. Custom and commercial plugins have no published checksums and are listed as not checked.

Themes cannot be checked: WordPress.org publishes no checksums for themes. Use file change monitoring for themes.

8. Repair and quarantine

Repair

Next to each modified or missing core file and WordPress.org plugin file, Repair downloads the official copy of that file for your exact version from WordPress.org’s source repositories. The file is written only if it matches the official checksum, and the current copy is saved in the quarantine first, so every repair can be undone. Repair all handles up to 50 files per click. Repair is refused if the scan result is out of date (for example after an update); run the scan again first.

Quarantine

Unknown files can be moved to the quarantine: a protected folder wp-content/uploads/ajsecs-quarantine-<random>/ with deny rules (.htaccess, web.config, index.php), where each file is stored under a random name ending in .bin so the web server will not run it. The quarantine list lets you Restore a file to its original place (never over a file that has since been put back) or Delete it permanently.

Nginx does not read .htaccess. The stored files cannot run, but if you want them unreachable over the web, add location ^~ /wp-content/uploads/ajsecs-quarantine- { deny all; } to your server block, then run nginx -t and reload.

Scans only read files. Repair and quarantine run only when you click their buttons.

9. Scheduled scans and email digest

On the Scans tab, set the schedule to Daily or Weekly (or Off (manual only)). Scheduled runs use WP-Cron. The email digest is plain text and goes to the address you enter, or the site admin address:

WP-Cron runs when your site gets visits, so on a quiet site a scheduled scan can be late. For exact timing, have your host call wp-cron.php from a real cron job. Emails are sent with wp_mail(); if your host does not deliver mail, use an SMTP plugin.

10. File change monitoring

With File change monitoring on (Scans tab), the plugin keeps a baseline of core, plugin and theme files (size, modification time and MD5) and checks it daily, or when you click Check now on the File changes screen. It reports files added, modified and removed until you click Accept, which sets a new baseline.

When WordPress, a plugin or a theme reports a new version, or is installed or removed, changes inside it are accepted automatically and listed separately, so updates do not flood the report. Uploads are not monitored.

Only one file check runs at a time. If you click Check now or Accept all changes while another check is running (for example the daily scheduled check), the screen says a check is already running and its result appears when it finishes; a scheduled check that finds one running simply skips. A new baseline only replaces the old one after it has been saved completely, so a check that is interrupted (a timeout or a server restart) leaves the previous baseline in use, and the next check cleans up after it.

11. Live traffic

With Live traffic on, the plugin keeps a short record of recent requests handled by WordPress: time, IP address (optionally shortened to /24 for IPv4 or /48 for IPv6), method, path without the query string, status, user ID, the protection that blocked it (if any) and the user agent. Only the newest 1,000 requests from the last 7 days are kept. Administrators are skipped by default. The Live traffic screen has a Block IP button per row and a Clear button.

Without a persistent object cache this adds one database write per recorded request.

12. Hardening and activity log

13. How IP addresses are read

The plugin reads the visitor address from REMOTE_ADDR only. Forwarded headers such as X-Forwarded-For can be forged by the visitor and are never trusted. If your site is behind a proxy or CDN that does not pass the real visitor address to PHP, every visitor may appear to have the same address, and lockouts or limits would then affect everyone. The Settings screen shows the address the server sees for you; check it before turning on lockouts, limits or blocks. Ask your host to restore the real visitor address at the server level if needed.

14. Privacy and personal data

Depending on the features you turn on, the plugin stores on your server:

The plugin adds suggested text to Settings → Privacy and registers a personal data exporter and eraser. They cover activity log entries (matched by user ID, username or email) and live traffic entries of registered users (matched by user ID). Traffic from visitors who are not logged in is identified only by IP address and expires after 7 days.

15. External services

The plugin connects only to WordPress.org services, and only for the features below. It sends nothing to 007AJ or any other third party and sends no visitor data. Requests use the user agent WordPress/<version>, so your site address is not sent. The plugin has no account system and makes no other remote checks.

ServiceWhenWhat is sent
WordPress.org core checksums
https://api.wordpress.org/core/checksums/1.0/
An integrity scan runs: Run scan now, or the daily/weekly schedule if you turned it on.Your WordPress version and site language.
WordPress.org plugin checksums
https://downloads.wordpress.org/plugin-checksums/<plugin>/<version>.json
An integrity scan runs and “Check plugins” is on (off by default).The folder name and version of each plugin installed in its own folder. Plugins whose Update URI points elsewhere are skipped without a request.
WordPress.org source repositories
https://core.svn.wordpress.org/ and https://plugins.svn.wordpress.org/
You click Repair or Repair all for a file listed by the last scan.The WordPress or plugin version and the path of the file requested.

Your server’s IP address is visible to WordPress.org, as with any web request. Provider: WordPress.org — Terms of use, Privacy policy.

Email digests are sent through your own site’s mail setup (wp_mail()) to the address you choose.

16. Deactivating, uninstalling and deleting data

Data removal cannot be undone. Restore any quarantined files you want to keep before deleting with data removal on.

17. Common questions

Can I lock myself out?

The plugin tries hard to prevent it: your current address cannot be added to the block list, block paths cannot cover wp-login.php or wp-admin, and administrators are exempt from the pattern rules and most limits. If it still happens, rename the plugin folder over FTP or your host’s file manager; deactivating also clears lockouts and temporary blocks.

Does repair change files without asking?

No. Scans only read files. Repair and quarantine run only when you click their buttons, and each keeps a copy you can restore.

Why are some core files refused for repair?

Repair writes a file only if the official download matches the official checksum. On some translated WordPress packages a file may not match, and repair is refused rather than writing a wrong file.

Multisite?

Not tested on multisite. Activate it per site.

18. Support

Email admin@007aj.com. Please include the plugin version (shown under Plugins), your WordPress and PHP versions, and what you expected to happen. Never send passwords.

19. Changelog

0.1.2

0.1.1

← Back to 007AJ Security Scanner & Firewall Suite

© 007AJ Security & Analytics · Home · Terms · Privacy