Releases: myguard-labs/wordpress-hardening-plugin
Release list
1.1.2
What's Changed
- fix(9522200,9522315): chain-setvar bug causing silent anomaly score on legit traffic by @eilandert in #7
- audit: correctness, perf, RFC, IPv6 + log-driven fixes by @eilandert in #8
- audit: dedupe dead rules, drop noisy transforms, structural cleanup by @eilandert in #9
Full Changelog: 1.1.1...1.2.0
Wordpress Hardening Plugin 1.1.1
New Features
IP Whitelisting for Blocked Endpoints
Localhost and RFC 1918 private addresses are always allowed through the
xmlrpc, REST API, and wp-cron gates. Additional CIDRs can be whitelisted
per-endpoint via tx.wphard.whitelist_xmlrpc_ips, tx.wphard.whitelist_rest_api_ips, and tx.wphard.whitelist_wpcron_ips.
IP-Based Rate Limiting for wp-login.php (rules 9522400–9522410)
Locks out an IP after repeated failed login attempts. Defaults: 5 attempts per 60-second window. Configurable via tx.wphard.ratelimit_login_attempts, tx.wphard.ratelimit_login_window, and tx.wphard.ratelimit_login_whitelist_ips. Opt-out: set tx.wphard.ratelimit_login_enabled=0.
GeoIP-Based Login Access Control (rules 9522500–9522510)
Blocks /wp-login.php for countries not listed in plugins/wordpress-hardening-login-countries.data. Reads country from CF-IPCountry (Cloudflare) or X-GeoIP-Country header. Requires a trusted upstream proxy. Opt-in: tx.wphard.geoip_login_enabled=1.
IP Reputation Blocklist (rules 9522600–9522604)
Blocks all requests from IPs or CIDRs in plugins/wordpress-hardening-ip-reputation.data. Checks both X-Forwarded-For and REMOTE_ADDR. Loopback and RFC 1918 addresses are always exempt. Opt-in: tx.wphard.ip_reputation_enabled=1. Compatible with Emerging Threats, Spamhaus DROP, and Firehol feeds.
10 New Hardening Rules
| Rule | Feature | Default |
|---|---|---|
| 9522100 | Block wp-admin theme/plugin editor | ON |
| 9522200 | Block backup directories and archives | ON |
| 9522201 | Block compressed database exports | ON |
| 9522202 | Block directory traversal in uploads | ON |
| 9522300 | Block null byte injection | ON |
| 9522305 | Block known scanner user agents | OFF |
| 9522310 | Block XDebug and debug endpoint probes | ON |
| 9522315 | Block code injection in wp-login POST params | ON |
| 9522317 | Block dangerous wp-admin endpoints (install/upgrade) | OFF |
New Data Files
plugins/wordpress-hardening-scanners.data— 55 known scanner/tool user agentsplugins/wordpress-hardening-ip-reputation.data— IP/CIDR blocklist (populate with your threat intel feeds)plugins/wordpress-hardening-login-countries.data— GeoIP allowed-country list (ISO 3166-1 alpha-2 codes)
CI/CD
- Full GitHub Actions integration test suite (nginx backend)
- Lint workflow: validates rule ID ranges, detects duplicates, checks
@pmFromFilereferences
Bug Fixes
- Fixed REST API gate overlap between rules 9522107 and 9522207 (WHP-1)
- Replaced
@ipMatchwith@ipMatchFromFilefor file-backed IP lists (WHP-2) - Fixed
@eq POST→@streq POSTin integration tests (WHP-3) - Fixed chained rule
skipAfterconflict in rate-limiting rule 9522410 (WHP-4) - Quoted all
setvarvalues containing spaces (WHP-5) - Fixed
msc_pyparserlint error (Expected ''') inlogdata/msgstrings (WHP-6) - Corrected URL-encoded user enumeration test cases (WHP-7)
Upgrade Notes
All new features are opt-in or on by default with safe fallbacks. No
existing rule IDs or default behaviours have changed. To use IP
reputation or GeoIP features, uncomment the relevant SecAction lines in wordpress-hardening-config.conf and populate the corresponding .data files
1.1.0
WordPress Hardening Plugin v1.1.0
Released: 2026-05-13
New Features
IP Whitelisting for Blocked Endpoints
Localhost and RFC 1918 private addresses are always allowed through the xmlrpc, REST API, and wp-cron gates. Additional CIDRs can be whitelisted per-endpoint via tx.wphard.whitelist_xmlrpc_ips, tx.wphard.whitelist_rest_api_ips, and tx.wphard.whitelist_wpcron_ips.
IP-Based Rate Limiting for wp-login.php (rules 9522400–9522410)
Locks out an IP after repeated failed login attempts. Defaults: 5 attempts per 60-second window. Configurable via tx.wphard.ratelimit_login_attempts, tx.wphard.ratelimit_login_window, and tx.wphard.ratelimit_login_whitelist_ips. Opt-out: set tx.wphard.ratelimit_login_enabled=0.
GeoIP-Based Login Access Control (rules 9522500–9522510)
Blocks /wp-login.php for countries not listed in plugins/wordpress-hardening-login-countries.data. Reads country from CF-IPCountry (Cloudflare) or X-GeoIP-Country header. Requires a trusted upstream proxy. Opt-in: tx.wphard.geoip_login_enabled=1.
IP Reputation Blocklist (rules 9522600–9522604)
Blocks all requests from IPs or CIDRs in plugins/wordpress-hardening-ip-reputation.data. Checks both X-Forwarded-For and REMOTE_ADDR. Loopback and RFC 1918 addresses are always exempt. Opt-in: tx.wphard.ip_reputation_enabled=1. Compatible with Emerging Threats, Spamhaus DROP, and Firehol feeds.
10 New Hardening Rules
| Rule | Feature | Default |
|---|---|---|
| 9522100 | Block wp-admin theme/plugin editor | ON |
| 9522200 | Block backup directories and archives | ON |
| 9522201 | Block compressed database exports | ON |
| 9522202 | Block directory traversal in uploads | ON |
| 9522300 | Block null byte injection | ON |
| 9522305 | Block known scanner user agents | OFF |
| 9522310 | Block XDebug and debug endpoint probes | ON |
| 9522315 | Block code injection in wp-login POST params | ON |
| 9522317 | Block dangerous wp-admin endpoints (install/upgrade) | OFF |
New Data Files
plugins/wordpress-hardening-scanners.data— 55 known scanner/tool user agentsplugins/wordpress-hardening-ip-reputation.data— IP/CIDR blocklist (populate with your threat intel feeds)plugins/wordpress-hardening-login-countries.data— GeoIP allowed-country list (ISO 3166-1 alpha-2 codes)
CI/CD
- Full GitHub Actions integration test suite (nginx backend)
- Lint workflow: validates rule ID ranges, detects duplicates, checks
@pmFromFilereferences
Bug Fixes
- Fixed REST API gate overlap between rules 9522107 and 9522207 (WHP-1)
- Replaced
@ipMatchwith@ipMatchFromFilefor file-backed IP lists (WHP-2) - Fixed
@eq POST→@streq POSTin integration tests (WHP-3) - Fixed chained rule
skipAfterconflict in rate-limiting rule 9522410 (WHP-4) - Quoted all
setvarvalues containing spaces (WHP-5) - Fixed
msc_pyparserlint error (Expected ''') inlogdata/msgstrings (WHP-6) - Corrected URL-encoded user enumeration test cases (WHP-7)
Upgrade Notes
All new features are opt-in or on by default with safe fallbacks. No existing rule IDs or default behaviours have changed. To use IP reputation or GeoIP features, uncomment the relevant SecAction lines in wordpress-hardening-config.conf and populate the corresponding .data files.
1.0.0.3rc3
Showstoppers for release 1.0.0:
- Better formatting?
- Review rules by someone else.
- More production testing and input from users.
Prerelease 1.0.0rc3
- modified regressiontests
- no more fp's due to simplyfied rules
- more OWASP formatting/compliance
Prerelease 1.0.0rc2
- Fixed some rules
- Squashed some rules
- Added workflows and integrations.
- All PL1 rules are now subject to the regression tests
Prerelease 1.0.0rc1
- Block xmlrpc.php access (configurable, default: block) (PL1)
- Block user enumeration (configurable, default: block) (PL1)
- Block user "admin" logins (configurable, default: block) (PL1)
- Block the wp-json restapi (configurable, default: non-block) (PL1)
- Block wp-cron.php (configurable, default: non-block) (PL1)
- Block direct php access in /wp-content/* and /wp-includes/* (PL1)
- Block direct file access to some files in / and other files/directories (PL1)
- Block other interpreters like .pl/.lua/.py/.sh (PL2)
- Block nasty files in uploads/* (PL1)
- Block access to sensitive files like .db/.orig/.sql/.log/.git (PL1)
- Block access to "/wp-json" (exact match, the api still works) (PL1)