{"id":270051,"date":"2026-01-09T19:39:59","date_gmt":"2026-01-09T19:39:59","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/x-security\/"},"modified":"2026-08-04T14:13:08","modified_gmt":"2026-08-04T14:13:08","slug":"liveupx-security","status":"publish","type":"plugin","link":"https:\/\/af.wordpress.org\/plugins\/liveupx-security\/","author":20884552,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"4.0.2","stable_tag":"4.0.2","tested":"6.9.5","requires":"5.0","requires_php":"7.4","requires_plugins":null,"header_name":"Liveupx Security","header_author":"Liveupx","header_description":"Complete WordPress security solution - Login protection, firewall, brute force protection, IP blocking, activity logging, and more. Developed by Liveupx.com","assets_banners_color":"9899f6","last_updated":"2026-08-04 14:13:08","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/liveupx.com\/liveupx-security","header_author_uri":"https:\/\/liveupx.com","rating":0,"author_block_rating":0,"active_installs":20,"downloads":666,"num_ratings":0,"support_threads":1,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.5.1":{"tag":"1.5.1","author":"liveupx","date":"2026-01-09 19:56:57"},"1.5.2":{"tag":"1.5.2","author":"liveupx","date":"2026-01-09 19:58:11"},"2.0.0":{"tag":"2.0.0","author":"liveupx","date":"2026-03-19 18:28:09"},"3.0.0":{"tag":"3.0.0","author":"liveupx","date":"2026-03-19 19:04:32"},"4.0.0":{"tag":"4.0.0","author":"liveupx","date":"2026-03-21 19:01:19"},"4.0.1":{"tag":"4.0.1","author":"liveupx","date":"2026-04-09 18:41:05"},"4.0.2":{"tag":"4.0.2","author":"liveupx","date":"2026-08-04 14:13:08"}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":0},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3447278,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3447278,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3447278,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3447278,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3447278,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.5.1","1.5.2","2.0.0","3.0.0","4.0.0","4.0.1","4.0.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3447278,"resolution":"1","location":"assets","locale":"","width":2000,"height":968},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3447278,"resolution":"2","location":"assets","locale":"","width":2000,"height":1143},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3447278,"resolution":"3","location":"assets","locale":"","width":2000,"height":684},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3447278,"resolution":"4","location":"assets","locale":"","width":2000,"height":764},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3447278,"resolution":"5","location":"assets","locale":"","width":2000,"height":912},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3447278,"resolution":"6","location":"assets","locale":"","width":2000,"height":714}},"screenshots":[]},"plugin_section":[],"plugin_tags":[9211,1174,15756,55021,600],"plugin_category":[54],"plugin_contributors":[253678],"plugin_business_model":[],"class_list":["post-270051","plugin","type-plugin","status-publish","hentry","plugin_tags-2fa","plugin_tags-firewall","plugin_tags-login-protection","plugin_tags-malware-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-liveupx","plugin_committers-liveupx"],"banners":{"banner":"https:\/\/ps.w.org\/liveupx-security\/assets\/banner-772x250.png?rev=3447278","banner_2x":"https:\/\/ps.w.org\/liveupx-security\/assets\/banner-1544x500.png?rev=3447278","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/liveupx-security\/assets\/icon.svg?rev=3447278","icon":"https:\/\/ps.w.org\/liveupx-security\/assets\/icon.svg?rev=3447278","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/liveupx-security\/assets\/screenshot-1.png?rev=3447278","caption":""},{"src":"https:\/\/ps.w.org\/liveupx-security\/assets\/screenshot-2.png?rev=3447278","caption":""},{"src":"https:\/\/ps.w.org\/liveupx-security\/assets\/screenshot-3.png?rev=3447278","caption":""},{"src":"https:\/\/ps.w.org\/liveupx-security\/assets\/screenshot-4.png?rev=3447278","caption":""},{"src":"https:\/\/ps.w.org\/liveupx-security\/assets\/screenshot-5.png?rev=3447278","caption":""},{"src":"https:\/\/ps.w.org\/liveupx-security\/assets\/screenshot-6.png?rev=3447278","caption":""}],"raw_content":"<!--section=description-->\n<p>Liveupx Security is a complete, 100% free WordPress security plugin that rivals paid solutions. No paywalls, ever.<\/p>\n\n<h4>Core Features<\/h4>\n\n<p><strong>Login Security<\/strong>\n* Brute force protection with progressive lockouts (1st\/2nd\/3rd+ strikes escalate automatically)\n* Multi-provider CAPTCHA: Math, Google reCAPTCHA v3, hCaptcha, Cloudflare Turnstile\n* Honeypot bot detection (wp-login.php + WooCommerce)\n* Passwordless magic link login\n* Two-factor authentication: TOTP (Google Authenticator) + Email OTP\n* Trusted device (30-day bypass cookie)\n* Geolocation login alerts \u2014 notify when login comes from a new country\n* Subnet auto-blocking (repeated attacks from \/24 range)\n* Custom login URL (hide wp-login.php)<\/p>\n\n<p><strong>Firewall \/ WAF<\/strong>\n* PHP-based Web Application Firewall running at priority 1\n* Remote WAF rule feed (auto-updated from liveupx.com)\n* Admin-defined custom firewall rules\n* Per-endpoint rate limiting (REST API, checkout, search, etc.)\n* REST API security controls (block guests, hide \/users endpoint)\n* Country\/geo blocking with API fallback chain\n* Bad bot blocking with verified bot allowlist (Google, Bing, etc.)\n* Referrer blocking with spam referrer presets\n* Bad query\/XSS\/SQL injection blocking\n* .htaccess security rules<\/p>\n\n<p><strong>Malware Scanner<\/strong>\n* Chunked AJAX scanner \u2014 scans plugins, themes, uploads, mu-plugins\n* 30+ malware patterns including backdoors, crypto miners, shell injections\n* Heuristic risk scoring (0\u2013100) per suspicious file\n* Auto-quarantine critical findings during scan\n* Scan diff \u2014 shows new threats vs last scan\n* Database malware scanner (posts, options, comments, users)\n* File quarantine and permanent delete<\/p>\n\n<p><strong>Vulnerability Scanner<\/strong>\n* Powered by WPScan API (free tier)\n* Scans all active plugins and active theme for known CVEs\n* CVSS severity scoring (Critical\/High\/Medium\/Low)\n* Dashboard widget showing unresolved critical\/high count\n* Dedicated Vulnerabilities admin page<\/p>\n\n<p><strong>File Integrity<\/strong>\n* WordPress core file integrity check (vs WordPress.org checksums API)\n* Plugin &amp; theme checksum verification (vs WordPress.org checksums)\n* wp-config.php and .htaccess tampering detection\n* Unknown PHP file detection in core directories<\/p>\n\n<p><strong>Core File Repair<\/strong>\n* Downloads clean copies from WordPress.org SVN\n* MD5 verification before writing\n* Single file or bulk repair<\/p>\n\n<p><strong>Security Headers<\/strong>\n* X-Frame-Options, X-Content-Type-Options, X-XSS-Protection\n* Referrer-Policy, Permissions-Policy (per-feature builder)\n* HSTS with preload support\n* Content-Security-Policy with visual builder\n* CSP violation reporting endpoint (REST API)\n* A\u2013F letter grade for your header configuration<\/p>\n\n<p><strong>User Security<\/strong>\n* User enumeration protection (?author= + REST API)\n* Strong password enforcement\n* Block dangerous usernames (admin, root, etc.)\n* Inactive user auto-lock (configurable threshold)\n* Admin action audit trail\n* Active session manager (view &amp; revoke)\n* GDPR IP anonymization<\/p>\n\n<p><strong>Post-Hack Recovery<\/strong>\n* Lock PHP execution in uploads and wp-includes\n* Log out all users instantly\n* Force password reset for all users\n* Reinstall free plugins from WordPress.org\n* Delete version-revealing files (readme.html, etc.)\n* Weekly security summary email report<\/p>\n\n<p><strong>Monitoring &amp; Notifications<\/strong>\n* Activity log (filterable, paginated, CSV export, configurable retention)\n* HTML branded email alerts\n* Slack\/webhook notifications (compatible with Make.com, Zapier, Discord)\n* Real-time dashboard stats (auto-refresh every 30s)\n* 7-day login attempt chart<\/p>\n\n<p><strong>Developer Tools<\/strong>\n* WP-CLI commands (wp xsec status|scan|block-ip|unblock-ip|2fa-reset|export-settings|import-settings)\n* Settings import\/export (JSON)\n* Security score with category breakdown<\/p>\n\n<p>Developed by <a href=\"https:\/\/liveupx.com\">Liveupx.com<\/a>\nCloud hosting partner: <a href=\"https:\/\/xhost.live\">xHost<\/a> \u2014 by Liveupx.com\n<a href=\"https:\/\/justhunt.co\/startups\/x-security\">Featured on JustHunt.co<\/a><\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/liveupx-security<\/code><\/li>\n<li>Activate the plugin through the 'Plugins' screen<\/li>\n<li>Navigate to <strong>Liveupx Security<\/strong> in the admin menu<\/li>\n<li>Review your security score and enable recommended features<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20plugin%20really%20100%25%20free%3F\"><h3>Is this plugin really 100% free?<\/h3><\/dt>\n<dd><p>Yes. All features are free forever. No premium tier, no feature paywalls, no upsells.<\/p><\/dd>\n<dt id=\"will%20it%20conflict%20with%20other%20security%20plugins%3F\"><h3>Will it conflict with other security plugins?<\/h3><\/dt>\n<dd><p>It's designed to work standalone. Deactivate conflicting security plugins (Wordfence, iThemes) before using.<\/p><\/dd>\n<dt id=\"does%20it%20support%20woocommerce%3F\"><h3>Does it support WooCommerce?<\/h3><\/dt>\n<dd><p>Yes \u2014 honeypot and CAPTCHA protection apply to WooCommerce login forms.<\/p><\/dd>\n<dt id=\"does%20it%20support%20multisite%3F\"><h3>Does it support multisite?<\/h3><\/dt>\n<dd><p>Basic multisite support in v4.0.0. Network-wide management is planned for v5.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>4.0.2<\/h4>\n\n<ul>\n<li>FIX: Malware scanner no longer scans its own plugin directory \u2014 the signature list itself was being matched, so the scanner reported its own files as a critical backdoor<\/li>\n<li>FIX: Detection signatures are no longer stored as plain literals, so other security plugins stop flagging Liveupx Security as malware<\/li>\n<li>NEW: Whitelist \u2014 \"Mark as safe\" on any scan result. Entries are bound to a SHA-256 hash, so a whitelisted file that is later modified is scanned again automatically<\/li>\n<li>NEW: \"Files Marked as Safe\" management table on the Malware Scanner page<\/li>\n<li>NEW: Excluded paths setting (one glob per line, relative to wp-content)<\/li>\n<li>NEW: Configurable reporting threshold (10-100, default 50)<\/li>\n<li>ENHANCE: Confidence-based reporting. Patterns are now classified as definitive (known backdoor signatures \u2014 always reported) or suspicious (legitimate code uses them too \u2014 reported only when the combined score passes the threshold)<\/li>\n<li>ENHANCE: Iframe patterns now only apply inside uploads\/. They were matching every legitimate YouTube, Google Maps and payment-gateway embed in themes and plugins<\/li>\n<li>ENHANCE: \"PHP in uploads\" no longer fires on empty \"silence is golden\" index.php stubs<\/li>\n<li>ENHANCE: New \"Needs Review\" section for low-confidence matches \u2014 no email alert, never auto-quarantined<\/li>\n<li>ENHANCE: Auto-quarantine now requires a definitive signature AND a score of 70+, and refuses to touch the plugin's own files<\/li>\n<li>FIX: Quarantine and Delete now refuse any path inside the plugin directory (previously could fatal the site)<\/li>\n<li>FIX: Scan progress now reports the infected count correctly \u2014 results no longer required a manual page reload<\/li>\n<li>FIX: One-click \"Enable Now\" in the security scan modal reset every other setting to 0<\/li>\n<li>FIX: Saving one settings section no longer resets custom firewall rules and CSP builder data<\/li>\n<\/ul>\n\n<p>Database scanner (same false-positive rework):<\/p>\n\n<ul>\n<li>FIX: iframes in posts, pages and comments are checked against an allowlist of ~60 known embed hosts (YouTube, Vimeo, Maps, Spotify, Calendly, Stripe, your own domain...). Ordinary embedded content is no longer reported as an injection<\/li>\n<li>FIX: Patterns are now scoped to the column they make sense in \u2014 a post about php.ini no longer matches the auto_prepend_file rule<\/li>\n<li>FIX: The wp_options sweep reported every row whose value merely contained \"shell_exec\", which flagged the stored settings of security and code-snippet plugins, including this one. Values must now match an actual code pattern, and the plugin's own options and transients are excluded<\/li>\n<li>FIX: \"Recently created administrator\" compared a string user ID with an integer, so the logged-in admin was flagged on every scan. It is now an advisory review item, never an alert<\/li>\n<li>FIX: Chunked post\/comment scans had no ORDER BY, so paging could skip or repeat rows<\/li>\n<li>FIX: The admin-user-creation pattern looked for add_user(), a function that does not exist in WordPress<\/li>\n<li>NEW: \"Mark as safe\" on any database finding, bound to a hash of the content \u2014 editing the item re-opens the finding<\/li>\n<li>ENHANCE: Findings show a confidence score and split into threats vs \"needs review\" <\/li>\n<\/ul>\n\n<h4>4.0.1<\/h4>\n\n<ul>\n<li>FIX: Custom Login URL feature now correctly serves the login page at the custom slug<\/li>\n<li>FIX: Direct wp-login.php access now properly returns 404 for non-authenticated visitors<\/li>\n<li>FIX: Password reset, logout, and other core WordPress actions no longer blocked by custom login URL<\/li>\n<li>FIX: Logged-in administrators can still access wp-login.php directly<\/li>\n<li>FIX: Replaced PHP parse_url() with WordPress wp_parse_url() for coding standards compliance<\/li>\n<\/ul>\n\n<h4>4.0.0<\/h4>\n\n<ul>\n<li>NEW: Multi-provider CAPTCHA (reCAPTCHA v3, hCaptcha, Cloudflare Turnstile)<\/li>\n<li>NEW: Magic link \/ passwordless login<\/li>\n<li>NEW: Progressive lockouts (escalating duration per IP)<\/li>\n<li>NEW: Trusted device (30-day 2FA bypass cookie)<\/li>\n<li>NEW: Geolocation login alerts with one-click account lock<\/li>\n<li>NEW: Subnet auto-blocking<\/li>\n<li>NEW: Remote WAF rule feed<\/li>\n<li>NEW: Admin-defined custom firewall rules<\/li>\n<li>NEW: Per-endpoint rate limiting<\/li>\n<li>NEW: REST API security controls<\/li>\n<li>NEW: Verified bot allowlist (Google, Bing, etc.)<\/li>\n<li>NEW: Referrer blocking with spam presets<\/li>\n<li>NEW: Vulnerability Scanner (WPScan API)<\/li>\n<li>NEW: Database malware scanner<\/li>\n<li>NEW: Plugin\/theme checksum verification<\/li>\n<li>NEW: wp-config.php and .htaccess integrity check<\/li>\n<li>NEW: Heuristic risk scoring (0\u2013100) for malware<\/li>\n<li>NEW: Auto-quarantine on scan<\/li>\n<li>NEW: Scan diff (new vs cleared threats)<\/li>\n<li>NEW: HTML email templates for all alerts<\/li>\n<li>NEW: Webhook\/Slack notifications<\/li>\n<li>NEW: Real-time dashboard stats<\/li>\n<li>NEW: 7-day login attempt chart<\/li>\n<li>NEW: Security score breakdown by category<\/li>\n<li>NEW: Inactive user auto-lock<\/li>\n<li>NEW: Admin action audit trail<\/li>\n<li>NEW: Active session manager<\/li>\n<li>NEW: GDPR IP anonymization<\/li>\n<li>NEW: WP-CLI commands<\/li>\n<li>NEW: Settings import\/export (JSON)<\/li>\n<li>NEW: Configurable log retention<\/li>\n<li>NEW: CSP visual builder<\/li>\n<li>NEW: CSP violation reporting endpoint<\/li>\n<li>NEW: Permissions-Policy per-feature builder<\/li>\n<li>NEW: Security header A\u2013F grade<\/li>\n<li>NEW: Vulnerabilities admin page<\/li>\n<li>FIX: TOTP user_id detection on Edit User page<\/li>\n<li>FIX: DISALLOW_FILE_MODS now properly wired<\/li>\n<li>FIX: RSS toggle uses AJAX save (not fragile hidden form)<\/li>\n<li>FIX: WooCommerce login honeypot and CAPTCHA support<\/li>\n<li>FIX: Geo API fallback chain (ip-api.com \u2192 ipapi.co \u2192 skip)<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>TOTP 2FA (Google Authenticator), email OTP fallback, backup codes<\/li>\n<li>Core file repair (download from WordPress.org SVN with checksum verification)<\/li>\n<li>Post-Hack recovery tools<\/li>\n<li>Malware quarantine and permanent delete<\/li>\n<\/ul>","raw_excerpt":"Complete WordPress security \u2014 Firewall, 2FA, Malware Scanner, Vulnerability Scanner, Login Protection, Security Headers. 100% free.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/270051","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=270051"}],"author":[{"embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/liveupx"}],"wp:attachment":[{"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=270051"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=270051"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=270051"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=270051"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=270051"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=270051"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}