{"id":374999,"date":"2026-10-09T08:07:18","date_gmt":"2026-10-09T08:07:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/zeismo-security-firewall-malware-scanner-login-protection\/"},"modified":"2026-10-09T08:07:09","modified_gmt":"2026-10-09T08:07:09","slug":"zeismo-security","status":"publish","type":"plugin","link":"https:\/\/fon.wordpress.org\/plugins\/zeismo-security\/","author":23568106,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.3","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"ZEISMO Security \u2013 Firewall, Malware Scanner & Login Protection","header_author":"ZEISMO","header_description":"Local request monitoring, file scanning and security controls for WordPress. Review findings and choose when to enable blocking.","assets_banners_color":"395272","last_updated":"2026-10-09 08:07:09","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/zeismo-security\/","header_author_uri":"https:\/\/zeismo.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":67,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"zeismodev","date":"2026-10-09 08:07:09","revision":3736171}},"upgrade_notice":{"1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3736171,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3736171,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3736171,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3736171,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3736171,"resolution":"1","location":"assets","locale":"","width":1232,"height":1245},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3736171,"resolution":"2","location":"assets","locale":"","width":1232,"height":859},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3736171,"resolution":"3","location":"assets","locale":"","width":1232,"height":794},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3736171,"resolution":"4","location":"assets","locale":"","width":1232,"height":1273},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3736171,"resolution":"5","location":"assets","locale":"","width":1232,"height":1187},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3736171,"resolution":"6","location":"assets","locale":"","width":1232,"height":2340}},"screenshots":{"1":"Overview with the current posture, configuration score and measured activity.","2":"Local file scanner for supported files, pattern findings and baseline comparisons.","3":"Threat activity with local event evidence and filters.","4":"Firewall controls with monitor and blocking choices.","5":"Ban and allowlist management.","6":"Included security controls and their management links."}},"plugin_section":[],"plugin_tags":[1174,31093,1229,55021,600],"plugin_category":[54],"plugin_contributors":[281452],"plugin_business_model":[],"class_list":["post-374999","plugin","type-plugin","status-publish","hentry","plugin_tags-firewall","plugin_tags-hardening","plugin_tags-login-security","plugin_tags-malware-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-zeismodev","plugin_committers-zeismodev"],"banners":{"banner":"https:\/\/ps.w.org\/zeismo-security\/assets\/banner-772x250.png?rev=3736171","banner_2x":"https:\/\/ps.w.org\/zeismo-security\/assets\/banner-1544x500.png?rev=3736171","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/zeismo-security\/assets\/icon-128x128.png?rev=3736171","icon_2x":"https:\/\/ps.w.org\/zeismo-security\/assets\/icon-256x256.png?rev=3736171","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/zeismo-security\/assets\/screenshot-1.png?rev=3736171","caption":"Overview with the current posture, configuration score and measured activity."},{"src":"https:\/\/ps.w.org\/zeismo-security\/assets\/screenshot-2.png?rev=3736171","caption":"Local file scanner for supported files, pattern findings and baseline comparisons."},{"src":"https:\/\/ps.w.org\/zeismo-security\/assets\/screenshot-3.png?rev=3736171","caption":"Threat activity with local event evidence and filters."},{"src":"https:\/\/ps.w.org\/zeismo-security\/assets\/screenshot-4.png?rev=3736171","caption":"Firewall controls with monitor and blocking choices."},{"src":"https:\/\/ps.w.org\/zeismo-security\/assets\/screenshot-5.png?rev=3736171","caption":"Ban and allowlist management."},{"src":"https:\/\/ps.w.org\/zeismo-security\/assets\/screenshot-6.png?rev=3736171","caption":"Included security controls and their management links."}],"raw_content":"<!--section=description-->\n<p>ZEISMO Security combines a WordPress firewall, malware scanner, login protection and practical hardening in one local security console.<\/p>\n\n<p>The plugin starts in monitor mode. It inspects suspicious request patterns and records evidence without blocking visitors. After reviewing the activity on your own site, you can enable blocking by attack category.<\/p>\n\n<h4>Included controls<\/h4>\n\n<ul>\n<li>Request monitoring for SQL injection, cross-site scripting, path traversal, local and remote file inclusion, command injection and scanner patterns.<\/li>\n<li>A weighted risk score with monitor and block modes.<\/li>\n<li>Local file-integrity comparisons for supported files in core directories, plugins and themes.<\/li>\n<li>Local malware pattern scanning with bounded file coverage and scan-limit notices.<\/li>\n<li>Login attempt limiting and failed-login history.<\/li>\n<li>Temporary and permanent IP bans plus an allowlist.<\/li>\n<li>Optional XML-RPC blocking, neutral login errors, REST user-enumeration protection and reduced version exposure.<\/li>\n<li>Optional browser security headers and WordPress file-editor hardening.<\/li>\n<li>Local threat history, activity summaries and critical-event email alerts.<\/li>\n<li>A measured configuration score and WordPress toolbar status.<\/li>\n<\/ul>\n\n<h4>WordPress malware scanning and file integrity<\/h4>\n\n<p>Run a local scan to review suspicious PHP, JavaScript, iframe, redirect and spam patterns in supported files. Integrity checks compare file hashes with a locally recorded baseline to identify additions, modifications and removals. They do not compare every file against an official clean-copy database. Review the site before accepting a new baseline.<\/p>\n\n<p>Scans cover supported readable files in wp-admin, wp-includes, the plugins directory and the active theme root. Uploads, the database and root-level files are outside these scan roots. Files over 2 MB, unsupported extensions and symbolic links are excluded. A result with no findings is not proof that the entire website is clean.<\/p>\n\n<h4>A safer first-run flow<\/h4>\n\n<p>New installations begin in monitor mode so administrators can inspect real activity before deciding which categories to block. Review the measured local activity and scan coverage before changing settings.<\/p>\n\n<h4>Local by design<\/h4>\n\n<p>The WordPress.org edition runs its available security controls on your own WordPress site. No account, licence token or remote ZEISMO service is required. Local features in this edition are not restricted by a paid plan.<\/p>\n\n<p>Blocking is disabled by default. Logged-in editors are excluded from firewall enforcement, and the request filter fails open if it cannot evaluate a request. No security plugin can guarantee that a site will not be compromised.<\/p>\n\n<p><a href=\"https:\/\/zeismo.com\/docs\/security\/\">Read the complete user guide<\/a> | <a href=\"https:\/\/zeismo.com\/marketplace\/zeismo-security\/\">Product information<\/a><\/p>\n\n<h3>Privacy and data handling<\/h3>\n\n<p>This WordPress.org distribution performs its security analysis on the WordPress site where it is installed. It does not contact ZEISMO, load remote code, check a ZEISMO licence, send source files to ZEISMO or include a separate updater.<\/p>\n\n<p>The plugin stores security settings and local security records in the site's WordPress database. Records can include request paths, browser user-agent strings, usernames used in login attempts, pseudonymous IP hashes and, when enabled, raw IP addresses. Raw IP storage is enabled by default so administrators can investigate and block attacks. Administrators can disable raw IP storage or anonymise logged addresses in Settings.<\/p>\n\n<p>Security events follow the retention period selected by the administrator. Raw event IP addresses are removed after 90 days even when a longer event-retention period is selected. Optional critical alerts are sent with the site's configured WordPress mail system and are disabled by default.<\/p>\n\n<p>Deactivation feedback is optional, stays in the site's WordPress database and is not sent to ZEISMO. Deactivating or deleting the plugin preserves settings and security records so an administrator does not lose incident evidence. Site owners who want to remove that data can delete the <code>zeismo_security_settings<\/code>, <code>zeismo_sec_db_version<\/code>, <code>zeismo_sec_setup_complete<\/code> and <code>zeismo_sec_deactivation_feedback<\/code> options and the database tables whose names begin with their WordPress table prefix followed by <code>zeismo_sec_<\/code>.<\/p>\n\n<h3>Development and source code<\/h3>\n\n<p>All PHP, JavaScript and CSS source is included in this plugin package. The\nfiles in admin\/js\/ and admin\/css\/ are the actual readable source used by\nWordPress, including admin\/js\/deactivation.js, admin\/css\/deactivation.css\nand admin\/css\/toolbar.css. No compilation, minification, npm, Composer or\nother build step is required. Edit the bundled source files directly and\ntest on a development WordPress installation before distributing changes.\nThis package does not bundle compressed third-party JavaScript libraries.<\/p>\n\n<h3>Request inspection limits<\/h3>\n\n<p>Request-field inspection is capped at eight nested array levels, 256 visited entries across GET and POST, 4,000 bytes per value and 65,536 combined field-name\/value bytes. Field names longer than 128 bytes or combined paths longer than 256 bytes are skipped. The request URI has a separate 8,192-byte cap. Sensitive fields are excluded. Inputs beyond these inspection budgets are not examined; reaching a limit does not reject the request. These limits bound plugin inspection work, not PHP request parsing or all denial-of-service traffic.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Back up your site, then install the ZEISMO Security ZIP through Plugins &gt; Add New &gt; Upload Plugin and activate it.<\/li>\n<li>Open <strong>ZEISMO Security &gt; Setup<\/strong>.<\/li>\n<li>Keep monitor mode enabled while you review the first events and scanner results.<\/li>\n<li>Open <strong>Firewall<\/strong> when you are ready to enable blocking for selected attack categories.<\/li>\n<li>Review <strong>Settings<\/strong> for IP retention, trusted-proxy configuration, login protection, hardening and alerts.<\/li>\n<li>Test visitor login, forms and any checkout or REST integrations after each enforcement change. If legitimate traffic is affected, return to monitor mode and review the matching event.<\/li>\n<li>Review events and scan results regularly, keep WordPress updated and maintain independent backups.<\/li>\n<\/ol>\n\n<p>For sites behind a trusted reverse proxy, define <code>ZEISMO_SEC_TRUSTED_PROXIES<\/code> in <code>wp-config.php<\/code> with the actual proxy IP addresses or CIDR ranges before selecting a forwarded-address mode.<\/p>\n\n<p>Quarantine is available only when <code>ZEISMO_SEC_QUARANTINE_DIR<\/code> points to an existing private writable directory outside all public document roots. Review findings and keep backups before moving files.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20zeismo%20security%20block%20visitors%20immediately%3F\"><h3>Will ZEISMO Security block visitors immediately?<\/h3><\/dt>\n<dd><p>No. A new installation starts in monitor mode. Blocking must be enabled deliberately by an administrator.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20my%20files%20or%20traffic%20to%20zeismo%3F\"><h3>Does the plugin send my files or traffic to ZEISMO?<\/h3><\/dt>\n<dd><p>No. This WordPress.org distribution runs locally and does not contact ZEISMO.<\/p><\/dd>\n<dt id=\"is%20every%20scanner%20finding%20malware%3F\"><h3>Is every scanner finding malware?<\/h3><\/dt>\n<dd><p>No. A finding is a pattern match or an integrity change that needs review. Scan-limit and root traversal errors are reported. Unsupported file types, files over 2 MB, unreadable files and symbolic links are excluded; individual skipped files are not listed. Accepting an integrity baseline does not certify files as safe.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20account%20or%20paid%20plan%3F\"><h3>Do I need an account or paid plan?<\/h3><\/dt>\n<dd><p>No. The local controls in this WordPress.org edition work without a ZEISMO account, licence key or paid plan.<\/p><\/dd>\n<dt id=\"does%20this%20edition%20use%20cloud%20ai%20or%20automatically%20remove%20malware%3F\"><h3>Does this edition use cloud AI or automatically remove malware?<\/h3><\/dt>\n<dd><p>No. This edition uses local request rules, file patterns and baseline comparisons. It does not send files to a cloud AI service or provide automatic malware cleanup. Review findings before taking action.<\/p><\/dd>\n<dt id=\"will%20it%20replace%20hosting%20security%2C%20backups%20or%20a%20network%20firewall%3F\"><h3>Will it replace hosting security, backups or a network firewall?<\/h3><\/dt>\n<dd><p>No. It is a WordPress application-level tool. It does not filter traffic before it reaches your server, cover every attack or replace backups, updates and hosting-level protections.<\/p><\/dd>\n<dt id=\"does%20deleting%20the%20plugin%20delete%20security%20records%3F\"><h3>Does deleting the plugin delete security records?<\/h3><\/dt>\n<dd><p>No. Settings and records are preserved to avoid destroying incident evidence. The Privacy and data handling section identifies the options and table prefix for administrators who decide to remove them manually.<\/p><\/dd>\n<dt id=\"can%20i%20use%20forwarded%20client%20ip%20headers%3F\"><h3>Can I use forwarded client IP headers?<\/h3><\/dt>\n<dd><p>Yes, after a server administrator defines <code>ZEISMO_SEC_TRUSTED_PROXIES<\/code>. Merely selecting a proxy mode does not trust arbitrary forwarded headers.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial WordPress.org release.<\/li>\n<li>Added local request monitoring and optional category-based firewall blocking.<\/li>\n<li>Added integrity and malware pattern scanning.<\/li>\n<li>Added login protection, hardening, ban, allowlist, alert and local activity tools.<\/li>\n<li>Added measured configuration status and accessible administration workflows.<\/li>\n<\/ul>","raw_excerpt":"WordPress security with a monitor-first firewall, local malware pattern scanner, login protection and practical hardening controls.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/374999","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=374999"}],"author":[{"embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/zeismodev"}],"wp:attachment":[{"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=374999"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=374999"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=374999"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=374999"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=374999"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fon.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=374999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}