{"id":326555,"date":"2026-07-31T11:47:53","date_gmt":"2026-07-31T11:47:53","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/locktura-security\/"},"modified":"2026-08-20T14:38:43","modified_gmt":"2026-08-20T14:38:43","slug":"locktura","status":"publish","type":"plugin","link":"https:\/\/lin.wordpress.org\/plugins\/locktura\/","author":23508383,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.4.4","stable_tag":"2.4.4","tested":"7.1","requires":"6.2","requires_php":"8.0","requires_plugins":null,"header_name":"Locktura Security","header_author":"Alain Lankers","header_description":"All-in-one WordPress security plugin to secure logins, block threats, harden your website, monitor activity, and reduce the need for multiple security plugins.","assets_banners_color":"01010f","last_updated":"2026-08-20 14:38:43","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/locktura\/","header_author_uri":"https:\/\/locktura.com","rating":0,"author_block_rating":0,"active_installs":10,"downloads":283,"num_ratings":0,"support_threads":1,"support_threads_resolved":1,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.3.7":{"tag":"2.3.7","author":"alainlankers","date":"2026-07-31 11:47:30"},"2.3.8":{"tag":"2.3.8","author":"alainlankers","date":"2026-07-31 11:59:01"},"2.3.9":{"tag":"2.3.9","author":"alainlankers","date":"2026-07-31 15:21:03"},"2.4.0":{"tag":"2.4.0","author":"alainlankers","date":"2026-08-02 12:01:41"},"2.4.2":{"tag":"2.4.2","author":"alainlankers","date":"2026-08-06 08:49:23"},"2.4.3":{"tag":"2.4.3","author":"alainlankers","date":"2026-08-13 10:47:33"},"2.4.4":{"tag":"2.4.4","author":"alainlankers","date":"2026-08-20 14:38:43"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3629932,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3629932,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3629932,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3629932,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3629932,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.3.7","2.3.8","2.3.9","2.4.0","2.4.2","2.4.3","2.4.4"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3644977,"resolution":"1","location":"assets","locale":"","width":1600,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3644977,"resolution":"2","location":"assets","locale":"","width":1600,"height":900},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3644977,"resolution":"3","location":"assets","locale":"","width":1600,"height":900},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3644977,"resolution":"4","location":"assets","locale":"","width":1600,"height":900},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3644977,"resolution":"5","location":"assets","locale":"","width":1600,"height":900},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3644977,"resolution":"6","location":"assets","locale":"","width":1600,"height":900},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3644977,"resolution":"7","location":"assets","locale":"","width":1600,"height":900}},"screenshots":{"1":"Security Overview with the protection score, security activity, blocked threats, scans, and blocked login attempts.","2":"Recent security alerts with the most active threat categories, threat distribution, and blocked countries.","3":"Traffic and blocked-login activity with an overview of installed Locktura security modules.","4":"Module management overview showing active protections and the current status of each module.","5":"Brute Force settings with protection controls, detection rules, security activity, and current status.","6":"Hardening settings for reducing common WordPress attack surfaces and protecting sensitive files and services.","7":"Firewall settings with request protection controls, rule configuration, and current protection status."}},"plugin_section":[262246],"plugin_tags":[2439,1174,31093,600,1909],"plugin_category":[54],"plugin_contributors":[274038],"plugin_business_model":[],"class_list":["post-326555","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-brute-force","plugin_tags-firewall","plugin_tags-hardening","plugin_tags-security","plugin_tags-two-factor-authentication","plugin_category-security-and-spam-protection","plugin_contributors-alainlankers","plugin_committers-alainlankers"],"banners":{"banner":"https:\/\/ps.w.org\/locktura\/assets\/banner-772x250.png?rev=3629932","banner_2x":"https:\/\/ps.w.org\/locktura\/assets\/banner-1544x500.png?rev=3629932","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/locktura\/assets\/icon.svg?rev=3629932","icon":"https:\/\/ps.w.org\/locktura\/assets\/icon.svg?rev=3629932","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/locktura\/assets\/screenshot-1.png?rev=3644977","caption":"Security Overview with the protection score, security activity, blocked threats, scans, and blocked login attempts."},{"src":"https:\/\/ps.w.org\/locktura\/assets\/screenshot-2.png?rev=3644977","caption":"Recent security alerts with the most active threat categories, threat distribution, and blocked countries."},{"src":"https:\/\/ps.w.org\/locktura\/assets\/screenshot-3.png?rev=3644977","caption":"Traffic and blocked-login activity with an overview of installed Locktura security modules."},{"src":"https:\/\/ps.w.org\/locktura\/assets\/screenshot-4.png?rev=3644977","caption":"Module management overview showing active protections and the current status of each module."},{"src":"https:\/\/ps.w.org\/locktura\/assets\/screenshot-5.png?rev=3644977","caption":"Brute Force settings with protection controls, detection rules, security activity, and current status."},{"src":"https:\/\/ps.w.org\/locktura\/assets\/screenshot-6.png?rev=3644977","caption":"Hardening settings for reducing common WordPress attack surfaces and protecting sensitive files and services."},{"src":"https:\/\/ps.w.org\/locktura\/assets\/screenshot-7.png?rev=3644977","caption":"Firewall settings with request protection controls, rule configuration, and current protection status."}],"raw_content":"<!--section=description-->\n<p>Locktura Security provides modular security tools for WordPress protection, monitoring, maintenance, and alerts. Most protection runs locally. Enable only the modules you need and manage them from one dashboard.<\/p>\n\n<h4>Included in this plugin<\/h4>\n\n<ul>\n<li><strong>Firewall<\/strong> - Attack filtering, cache-compatible protection modes, and diagnostics.<\/li>\n<li><strong>Brute Force Defense<\/strong> - Login limits, temporary bans, statistics, and unban controls.<\/li>\n<li><strong>Hardening<\/strong> - Configurable controls for common WordPress and server attack surfaces.<\/li>\n<li><strong>Update Manager<\/strong> - Update checks, installation, history, supported rollbacks, and extension cleanup.<\/li>\n<li><strong>Access Control<\/strong> - IP allowlists, blocklists, exclusions, automatic bans, and unban controls.<\/li>\n<li><strong>Geo Blocking<\/strong> - Country rules, trusted crawler verification, and geographic activity.<\/li>\n<li><strong>Hide Login<\/strong> - A custom login URL, default-route protection, and activity logging.<\/li>\n<li><strong>Anti-Spam Shield<\/strong> - Local CAPTCHA, form and comment protection, email and temporary IP blocking.<\/li>\n<li><strong>Usernames &amp; 2FA<\/strong> - Username audits and suggestions, TOTP authentication, one-time recovery codes, and 2FA status.<\/li>\n<li><strong>Password Manager<\/strong> - Password policies, forced resets, risk scans, and optional breach checks.<\/li>\n<li><strong>Email Alerts<\/strong> - Notifications for important protection, account, update, file, and SSL events.<\/li>\n<li><strong>Security Logs<\/strong> - Local events with filters, charts, geographic context, IP actions, and export.<\/li>\n<li><strong>Live Traffic<\/strong> - Request details, visitor and bot classification, blocking data, filters, and geolocation.<\/li>\n<li><strong>User Log<\/strong> - Login, content, account, extension, settings, media, editor, and update activity.<\/li>\n<li><strong>File Scanner<\/strong> - File and configuration checks, integrity monitoring, backup, fixes, quarantine, and restore.<\/li>\n<li><strong>File Permissions<\/strong> - Permission and ownership checks, hosting guidance, safe fixes, exceptions, and history.<\/li>\n<li><strong>SSL Control<\/strong> - HTTPS, certificate and proxy checks, redirects, backup, and rollback.<\/li>\n<li><strong>Email Encoder<\/strong> - Email inventory, entity encoding, JavaScript obfuscation, coverage, and activity.<\/li>\n<\/ul>\n\n<h4>Hardening options<\/h4>\n\n<ul>\n<li><strong>User Enumeration<\/strong> - Blocks author queries, guest user endpoints, author feeds, sitemap entries, and detailed login errors.<\/li>\n<li><strong>Disable Theme\/Plugin Editor<\/strong> - Removes editor menus and blocks direct editor access.<\/li>\n<li><strong>Privilege Escalation<\/strong> - Detects related exploit and credential-access patterns in requests.<\/li>\n<li><strong>XML-RPC Shield<\/strong> - Blocks direct XML-RPC access, multicall brute force, user queries, and pingback abuse.<\/li>\n<li><strong>Secure wp-admin, wp-includes &amp; wp-config.php<\/strong> - Protects sensitive WordPress and configuration paths.<\/li>\n<li><strong>Disable Directory Browsing<\/strong> - Prevents automatic directory listings.<\/li>\n<li><strong>Disable RSS Feeds<\/strong> - Disables public feeds and removes feed discovery links.<\/li>\n<li><strong>Prevent Image Hotlinking<\/strong> - Blocks unauthorized image embedding while supporting allowed sources.<\/li>\n<li><strong>Server Exposure Protection<\/strong> - Protects PHP uploads, environment files, debug logs, and configuration backups.<\/li>\n<\/ul>\n\n<p>Managed server rules are applied on supported Apache and LiteSpeed installations. Other servers receive configuration guidance.<\/p>\n\n<h4>Separate Premium plugin<\/h4>\n\n<p>Locktura Premium is separately distributed outside WordPress.org and is not included in this package. Every Free feature above works without a license.<\/p>\n\n<p>The separate Premium plugin adds:<\/p>\n\n<ul>\n<li><strong>Pattern Recognition<\/strong> - Signature detection, false-positive controls, activity, and signature management.<\/li>\n<li><strong>Behavior Analytics<\/strong> - Activity learning, risk scoring, thresholds, and verification.<\/li>\n<li><strong>Admin Lockdown<\/strong> - Access policies, schedules, trusted devices, verification, and recovery.<\/li>\n<li><strong>Virtual Patching<\/strong> - Temporary monitoring and blocking rules with scope and expiry.<\/li>\n<li><strong>Header Hardening<\/strong> - Security headers, browser policies, exposure controls, and previews.<\/li>\n<li><strong>API Guardian<\/strong> - REST, AJAX, endpoint, payload, request-limit, and JWT checks.<\/li>\n<li><strong>Neural Bot Suppressor<\/strong> - Bot detection, challenges, honeypots, crawler verification, and allowlists.<\/li>\n<li><strong>Network Reputation Control<\/strong> - Optional proxy, VPN, Tor, and hosting-network monitoring or blocking.<\/li>\n<li><strong>Malware Scanner &amp; Cleanup<\/strong> - File and database scans, quarantine, cleanup, backup, and restore.<\/li>\n<li><strong>Smart 404<\/strong> - Probe detection, thresholds, allowlists, temporary bans, activity, and unban controls.<\/li>\n<li><strong>Extra Hardening Tools<\/strong> - Table-prefix, security-salt, robots.txt, backup, and recovery tools.<\/li>\n<li><strong>Monthly Reports<\/strong> - Scheduled summaries, recipients, event details, and optional PDF reports.<\/li>\n<li><strong>Session Management<\/strong> - Session review, revocation, lifetime limits, and single-device controls.<\/li>\n<li><strong>Extra User Safety Tools<\/strong> - Administrator limits and automatic inactivity logout.<\/li>\n<li><strong>Premium Signature Pack<\/strong> - Maintained signatures, updates, inventory, cache rebuilding, and rollback.<\/li>\n<\/ul>\n\n<h3>Privacy<\/h3>\n\n<p>Locktura stores security data locally, including IP addresses, request and login details, usernames, events, alert settings, password-policy and 2FA settings (including hashed recovery codes), scan history, and update history. Optional geolocation and password-breach checks use the services below. Administrators control retention, recipients, lookups, and privacy settings.<\/p>\n\n<h3>External services<\/h3>\n\n<p>Locktura loads no scripts, styles, fonts, or images from third parties. It makes only the requests documented below when the related feature is enabled or used.<\/p>\n\n<h4>WordPress.org and extension update providers<\/h4>\n\n<p>Used for core, plugin, and theme update checks and downloads through WordPress.org and update endpoints declared by installed extensions. Requests occur during administrator-requested or scheduled checks and can contain the site URL, software versions, locale, and extension metadata. Update history is stored locally.<\/p>\n\n<p>Documentation: https:\/\/developer.wordpress.org\/apis\/handbook\/wordpress-org\/update-api\/\nPolicies: https:\/\/developer.wordpress.org\/plugins\/wordpress-org\/detailed-plugin-guidelines\/ and https:\/\/wordpress.org\/about\/license\/\nPrivacy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h4>Have I Been Pwned Pwned Passwords<\/h4>\n\n<p>Used for optional breach checks through <code>https:\/\/api.pwnedpasswords.com\/range\/{first5-sha1}<\/code>. Only the first five characters of the password's SHA-1 hash are sent, never the password or complete hash. Results can be cached locally, and stored status is discarded when the credential changes.<\/p>\n\n<p>Documentation: https:\/\/haveibeenpwned.com\/API\/v3#PwnedPasswords\nTerms: https:\/\/haveibeenpwned.com\/TermsOfUse\nPrivacy: https:\/\/haveibeenpwned.com\/Privacy<\/p>\n\n<h4>Geolocation providers<\/h4>\n\n<p>When enabled geolocation needs uncached data and no trusted country header exists, Locktura sends the public IP being looked up. Results can be cached locally for 24 hours. Providers are tried in this order:<\/p>\n\n<ul>\n<li>Country (<code>https:\/\/api.country.is\/{ip}<\/code>) - Primary provider. Service information and privacy: https:\/\/country.is\/ | Source and self-hosting: https:\/\/github.com\/lineofflight\/country<\/li>\n<li>IPWhois (<code>https:\/\/ipwho.is\/{ip}<\/code>) - First fallback. Documentation: https:\/\/ipwhois.io\/documentation | Terms: https:\/\/ipwhois.io\/terms | Privacy: https:\/\/ipwhois.io\/privacy<\/li>\n<li>ipapi.co (<code>https:\/\/ipapi.co\/{ip}\/json\/<\/code>) - Final fallback. Documentation: https:\/\/ipapi.co\/api\/ | Terms: https:\/\/ipapi.co\/terms\/ | Privacy: https:\/\/ipapi.co\/privacy\/<\/li>\n<\/ul>\n\n<h4>Own-site HTTPS and TLS checks<\/h4>\n\n<p>SSL Control checks the configured <code>home_url()<\/code> or <code>site_url()<\/code>. An administrator-requested HEAD request or TLS handshake sends ordinary network metadata and a Locktura user-agent to the site's own host. No security log is transmitted.<\/p>\n\n<h4>Site-configured email delivery<\/h4>\n\n<p>Enabled alerts and tests can contain the recipient, site URL, event type, timestamp, IP address, relevant context, and remediation links. WordPress uses the site's configured mail transport; Locktura selects no provider.<\/p>\n\n<h4>Locktura website links<\/h4>\n\n<p>Links to <code>https:\/\/locktura.com\/<\/code> open only after an administrator clicks them; there are no background calls.<\/p>\n\n<p>Terms: https:\/\/locktura.com\/terms-and-conditions\/\nPrivacy: https:\/\/locktura.com\/privacy-policy\/<\/p>\n\n<h3>Translations<\/h3>\n\n<p>Dutch translations are managed through translate.wordpress.org and delivered by WordPress when an approved package is available.<\/p>\n\n<h3>Bundled assets<\/h3>\n\n<p>Runtime assets are bundled locally. Flag Icons and QRCode for JavaScript use the MIT License; Inter and Bebas Neue use the SIL Open Font License 1.1. The modified Wikimedia Commons world map is public domain. Source and license details are included under <code>assets\/<\/code>. Locktura artwork is GPLv2 or later.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>locktura<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install it through the WordPress Plugins screen.<\/li>\n<li>Activate Locktura Security and open the Locktura dashboard.<\/li>\n<li>Review the modules, enable the protections you need, and save changed settings.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20the%20firewall%20included%3F\"><h3>Is the firewall included?<\/h3><\/dt>\n<dd><p>Yes. Locktura Security includes the firewall with bundled community rules.<\/p><\/dd>\n<dt id=\"do%20all%20listed%20free%20features%20work%20without%20a%20license%3F\"><h3>Do all listed Free features work without a license?<\/h3><\/dt>\n<dd><p>Yes. Every feature listed under Included in this plugin works without a license and has no time or usage restrictions. The separately distributed Premium plugin is not included in this package.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20cloud%20account%3F\"><h3>Do I need a cloud account?<\/h3><\/dt>\n<dd><p>No. Protection runs locally. Only the optional features documented under External services make network requests.<\/p><\/dd>\n<dt id=\"does%20locktura%20security%20store%20security%20logs%3F\"><h3>Does Locktura Security store security logs?<\/h3><\/dt>\n<dd><p>Yes. Security events are stored locally for administrator review.<\/p><\/dd>\n<dt id=\"can%20ip%20addresses%20be%20anonymized%3F\"><h3>Can IP addresses be anonymized?<\/h3><\/dt>\n<dd><p>Yes. An IP anonymization setting is available.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.4.4<\/h4>\n\n<ul>\n<li>Improved Security Logs pagination and dashboard grid layout.<\/li>\n<li>Fixed password-reset compatibility with Hide Login and improved Semantic Decode Shield event logging.<\/li>\n<li>Improved Geo Blocking IP handling and regional controls, plus File Scanner status and detection accuracy.<\/li>\n<\/ul>\n\n<h4>2.4.3<\/h4>\n\n<ul>\n<li>Improved dashboard and Live Traffic reporting with more consistent aggregation and country details.<\/li>\n<li>Improved password-strength checks and security-log timezone handling.<\/li>\n<li>Confirmed compatibility with WordPress 7.1 and refreshed public documentation.<\/li>\n<\/ul>\n\n<h4>2.4.2<\/h4>\n\n<ul>\n<li>Improved user and 2FA management with filtering, pagination, role-aware guidance, and session controls.<\/li>\n<li>Added hashed, one-time recovery codes for existing authenticator-app 2FA accounts.<\/li>\n<li>Improved file-permission guidance and support for approved hosting-specific permissions.<\/li>\n<\/ul>","raw_excerpt":"All-in-one WordPress security suite with local firewall, login protection, anti-spam controls, hardening, monitoring, and alerts.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/326555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=326555"}],"author":[{"embeddable":true,"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/alainlankers"}],"wp:attachment":[{"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=326555"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=326555"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=326555"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=326555"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=326555"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/lin.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=326555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}