Guide to installing and using 007AJ Security Scanner & Firewall Suite (version 0.1.2). The Suite is standalone, so this page covers the whole plugin.
Requirements: WordPress 6.3 or newer and PHP 7.4 or newer.
007aj-security-scanner-firewall-suite zip and click Install Now, or upload the folder to /wp-content/plugins/.No account or sign-up is needed. All features work as soon as the plugin is active.
| Tab | What it controls |
|---|---|
| Login | Login lockout: attempts, window, lockout length, email alert. |
| Firewall | On/off, rule categories, form value checks, custom allow and block paths, XML-RPC switch. |
| Rate limits | Login posts, all requests, REST requests, “not found” floods, and the length of temporary blocks. |
| IP rules | Allow list and block list. |
| Scans | Schedule, plugin checksum checks, file change monitoring, email digest and recipient. |
| Live traffic | On/off, IP shortening, skip administrators. |
| Hardening | File editors, username discovery, version tag, application passwords. |
| Log and data | Activity log on/off, and whether to delete all data when the plugin is deleted. |
Every protection is off after activation. Each tab is saved separately.
wp-login.php per IP address (default 20 in 5 minutes); extra requests get HTTP 429.The firewall checks the request path, the user agent, query string names and values, and form field names. Matching requests get a 403 page and, if the log is on, an activity log entry with the rule that matched.
UNION SELECT, tautologies, time-based probes.javascript: links.../, /etc/passwd, PHP stream wrappers..env, .git, database dumps, backup archives, wp-config backups and known web shell names.wp-login.php or wp-admin are refused when you save.xmlrpc.php requests and turn off pingbacks.Logged-in administrators and editors are not checked by the pattern rules, so normal editing keeps working.
203.0.113.7, 198.51.100.0/24, 2001:db8::/32). Allowlisted addresses skip the firewall, rate limits, temporary blocks and login lockout.| Limit | Default | Answer |
|---|---|---|
| Login posts to wp-login.php | 20 per 5 minutes | 429 |
| All requests | 300 per minute | 429 with Retry-After |
| REST API requests | 120 per minute | 429 |
| “Not found” pages | 30 per 5 minutes | temporary block of the address on the whole site (default 15 minutes) |
Each limit is off until you turn it on and its numbers can be changed. Logged-in administrators are exempt from most limits, and allowlisted addresses from all of them. Without a persistent object cache, the all-requests limit stores a counter in the database on each request, so set it with your traffic in mind.
On Integrity scan, Run scan now compares every WordPress core file with the official WordPress.org checksums and lists modified, missing and unknown files (in wp-admin, wp-includes and the site root).
With Check plugins on (Scans tab, off by default), plugins installed in their own folder are also compared with the checksums WordPress.org publishes for that plugin and version. Plugins whose Update URI header points somewhere other than WordPress.org are skipped without a request. Custom and commercial plugins have no published checksums and are listed as not checked.
Themes cannot be checked: WordPress.org publishes no checksums for themes. Use file change monitoring for themes.
Next to each modified or missing core file and WordPress.org plugin file, Repair downloads the official copy of that file for your exact version from WordPress.org’s source repositories. The file is written only if it matches the official checksum, and the current copy is saved in the quarantine first, so every repair can be undone. Repair all handles up to 50 files per click. Repair is refused if the scan result is out of date (for example after an update); run the scan again first.
Unknown files can be moved to the quarantine: a protected folder wp-content/uploads/ajsecs-quarantine-<random>/ with deny rules (.htaccess, web.config, index.php), where each file is stored under a random name ending in .bin so the web server will not run it. The quarantine list lets you Restore a file to its original place (never over a file that has since been put back) or Delete it permanently.
.htaccess. The stored files cannot run, but if you want them unreachable over the web, add location ^~ /wp-content/uploads/ajsecs-quarantine- { deny all; } to your server block, then run nginx -t and reload.Scans only read files. Repair and quarantine run only when you click their buttons.
On the Scans tab, set the schedule to Daily or Weekly (or Off (manual only)). Scheduled runs use WP-Cron. The email digest is plain text and goes to the address you enter, or the site admin address:
wp-cron.php from a real cron job. Emails are sent with wp_mail(); if your host does not deliver mail, use an SMTP plugin.With File change monitoring on (Scans tab), the plugin keeps a baseline of core, plugin and theme files (size, modification time and MD5) and checks it daily, or when you click Check now on the File changes screen. It reports files added, modified and removed until you click Accept, which sets a new baseline.
When WordPress, a plugin or a theme reports a new version, or is installed or removed, changes inside it are accepted automatically and listed separately, so updates do not flood the report. Uploads are not monitored.
Only one file check runs at a time. If you click Check now or Accept all changes while another check is running (for example the daily scheduled check), the screen says a check is already running and its result appears when it finishes; a scheduled check that finds one running simply skips. A new baseline only replaces the old one after it has been saved completely, so a check that is interrupted (a timeout or a server restart) leaves the previous baseline in use, and the next check cleans up after it.
With Live traffic on, the plugin keeps a short record of recent requests handled by WordPress: time, IP address (optionally shortened to /24 for IPv4 or /48 for IPv6), method, path without the query string, status, user ID, the protection that blocked it (if any) and the user agent. Only the newest 1,000 requests from the last 7 days are kept. Administrators are skipped by default. The Live traffic screen has a Block IP button per row and a Clear button.
Without a persistent object cache this adds one database write per recorded request.
DISALLOW_FILE_EDIT), limit username discovery for visitors, hide the version tag, turn off application passwords.The plugin reads the visitor address from REMOTE_ADDR only. Forwarded headers such as X-Forwarded-For can be forged by the visitor and are never trusted. If your site is behind a proxy or CDN that does not pass the real visitor address to PHP, every visitor may appear to have the same address, and lockouts or limits would then affect everyone. The Settings screen shows the address the server sees for you; check it before turning on lockouts, limits or blocks. Ask your host to restore the real visitor address at the server level if needed.
Depending on the features you turn on, the plugin stores on your server:
The plugin adds suggested text to Settings → Privacy and registers a personal data exporter and eraser. They cover activity log entries (matched by user ID, username or email) and live traffic entries of registered users (matched by user ID). Traffic from visitors who are not logged in is identified only by IP address and expires after 7 days.
The plugin connects only to WordPress.org services, and only for the features below. It sends nothing to 007AJ or any other third party and sends no visitor data. Requests use the user agent WordPress/<version>, so your site address is not sent. The plugin has no account system and makes no other remote checks.
| Service | When | What is sent |
|---|---|---|
WordPress.org core checksumshttps://api.wordpress.org/core/checksums/1.0/ | An integrity scan runs: Run scan now, or the daily/weekly schedule if you turned it on. | Your WordPress version and site language. |
WordPress.org plugin checksumshttps://downloads.wordpress.org/plugin-checksums/<plugin>/<version>.json | An integrity scan runs and “Check plugins” is on (off by default). | The folder name and version of each plugin installed in its own folder. Plugins whose Update URI points elsewhere are skipped without a request. |
WordPress.org source repositorieshttps://core.svn.wordpress.org/ and https://plugins.svn.wordpress.org/ | You click Repair or Repair all for a file listed by the last scan. | The WordPress or plugin version and the path of the file requested. |
Your server’s IP address is visible to WordPress.org, as with any web request. Provider: WordPress.org — Terms of use, Privacy policy.
Email digests are sent through your own site’s mail setup (wp_mail()) to the address you choose.
The plugin tries hard to prevent it: your current address cannot be added to the block list, block paths cannot cover wp-login.php or wp-admin, and administrators are exempt from the pattern rules and most limits. If it still happens, rename the plugin folder over FTP or your host’s file manager; deactivating also clears lockouts and temporary blocks.
No. Scans only read files. Repair and quarantine run only when you click their buttons, and each keeps a copy you can restore.
Repair writes a file only if the official download matches the official checksum. On some translated WordPress packages a file may not match, and repair is refused rather than writing a wrong file.
Not tested on multisite. Activate it per site.
Email admin@007aj.com. Please include the plugin version (shown under Plugins), your WordPress and PHP versions, and what you expected to happen. Never send passwords.