Skip to content

Releases: myguard-labs/wordpress-hardening-plugin

1.1.2

Choose a tag to compare

@eilandert eilandert released this 27 May 20:06
2e2c2a5

What's Changed

  • fix(9522200,9522315): chain-setvar bug causing silent anomaly score on legit traffic by @eilandert in #7
  • audit: correctness, perf, RFC, IPv6 + log-driven fixes by @eilandert in #8
  • audit: dedupe dead rules, drop noisy transforms, structural cleanup by @eilandert in #9

Full Changelog: 1.1.1...1.2.0

Wordpress Hardening Plugin 1.1.1

Choose a tag to compare

@eilandert eilandert released this 20 May 17:55

New Features

IP Whitelisting for Blocked Endpoints
Localhost and RFC 1918 private addresses are always allowed through the xmlrpc, REST API, and wp-cron gates. Additional CIDRs can be whitelisted per-endpoint via tx.wphard.whitelist_xmlrpc_ips, tx.wphard.whitelist_rest_api_ips, and tx.wphard.whitelist_wpcron_ips.

IP-Based Rate Limiting for wp-login.php (rules 9522400–9522410)
Locks out an IP after repeated failed login attempts. Defaults: 5 attempts per 60-second window. Configurable via tx.wphard.ratelimit_login_attempts, tx.wphard.ratelimit_login_window, and tx.wphard.ratelimit_login_whitelist_ips. Opt-out: set tx.wphard.ratelimit_login_enabled=0.

GeoIP-Based Login Access Control (rules 9522500–9522510)
Blocks /wp-login.php for countries not listed in plugins/wordpress-hardening-login-countries.data. Reads country from CF-IPCountry (Cloudflare) or X-GeoIP-Country header. Requires a trusted upstream proxy. Opt-in: tx.wphard.geoip_login_enabled=1.

IP Reputation Blocklist (rules 9522600–9522604)
Blocks all requests from IPs or CIDRs in plugins/wordpress-hardening-ip-reputation.data. Checks both X-Forwarded-For and REMOTE_ADDR. Loopback and RFC 1918 addresses are always exempt. Opt-in: tx.wphard.ip_reputation_enabled=1. Compatible with Emerging Threats, Spamhaus DROP, and Firehol feeds.

10 New Hardening Rules

Rule Feature Default
9522100 Block wp-admin theme/plugin editor ON
9522200 Block backup directories and archives ON
9522201 Block compressed database exports ON
9522202 Block directory traversal in uploads ON
9522300 Block null byte injection ON
9522305 Block known scanner user agents OFF
9522310 Block XDebug and debug endpoint probes ON
9522315 Block code injection in wp-login POST params ON
9522317 Block dangerous wp-admin endpoints (install/upgrade) OFF

New Data Files

  • plugins/wordpress-hardening-scanners.data — 55 known scanner/tool user agents
  • plugins/wordpress-hardening-ip-reputation.data — IP/CIDR blocklist (populate with your threat intel feeds)
  • plugins/wordpress-hardening-login-countries.data — GeoIP allowed-country list (ISO 3166-1 alpha-2 codes)

CI/CD

  • Full GitHub Actions integration test suite (nginx backend)
  • Lint workflow: validates rule ID ranges, detects duplicates, checks @pmFromFile references

Bug Fixes

  • Fixed REST API gate overlap between rules 9522107 and 9522207 (WHP-1)
  • Replaced @ipMatch with @ipMatchFromFile for file-backed IP lists (WHP-2)
  • Fixed @eq POST → @streq POST in integration tests (WHP-3)
  • Fixed chained rule skipAfter conflict in rate-limiting rule 9522410 (WHP-4)
  • Quoted all setvar values containing spaces (WHP-5)
  • Fixed msc_pyparser lint error (Expected ''') in logdata/msg strings (WHP-6)
  • Corrected URL-encoded user enumeration test cases (WHP-7)

Upgrade Notes

All new features are opt-in or on by default with safe fallbacks. No existing rule IDs or default behaviours have changed. To use IP reputation or GeoIP features, uncomment the relevant SecAction lines in wordpress-hardening-config.conf and populate the corresponding .data files

1.1.0

Choose a tag to compare

@eilandert eilandert released this 13 May 15:30

WordPress Hardening Plugin v1.1.0

Released: 2026-05-13


New Features

IP Whitelisting for Blocked Endpoints
Localhost and RFC 1918 private addresses are always allowed through the xmlrpc, REST API, and wp-cron gates. Additional CIDRs can be whitelisted per-endpoint via tx.wphard.whitelist_xmlrpc_ips, tx.wphard.whitelist_rest_api_ips, and tx.wphard.whitelist_wpcron_ips.

IP-Based Rate Limiting for wp-login.php (rules 9522400–9522410)
Locks out an IP after repeated failed login attempts. Defaults: 5 attempts per 60-second window. Configurable via tx.wphard.ratelimit_login_attempts, tx.wphard.ratelimit_login_window, and tx.wphard.ratelimit_login_whitelist_ips. Opt-out: set tx.wphard.ratelimit_login_enabled=0.

GeoIP-Based Login Access Control (rules 9522500–9522510)
Blocks /wp-login.php for countries not listed in plugins/wordpress-hardening-login-countries.data. Reads country from CF-IPCountry (Cloudflare) or X-GeoIP-Country header. Requires a trusted upstream proxy. Opt-in: tx.wphard.geoip_login_enabled=1.

IP Reputation Blocklist (rules 9522600–9522604)
Blocks all requests from IPs or CIDRs in plugins/wordpress-hardening-ip-reputation.data. Checks both X-Forwarded-For and REMOTE_ADDR. Loopback and RFC 1918 addresses are always exempt. Opt-in: tx.wphard.ip_reputation_enabled=1. Compatible with Emerging Threats, Spamhaus DROP, and Firehol feeds.

10 New Hardening Rules

Rule Feature Default
9522100 Block wp-admin theme/plugin editor ON
9522200 Block backup directories and archives ON
9522201 Block compressed database exports ON
9522202 Block directory traversal in uploads ON
9522300 Block null byte injection ON
9522305 Block known scanner user agents OFF
9522310 Block XDebug and debug endpoint probes ON
9522315 Block code injection in wp-login POST params ON
9522317 Block dangerous wp-admin endpoints (install/upgrade) OFF

New Data Files

  • plugins/wordpress-hardening-scanners.data — 55 known scanner/tool user agents
  • plugins/wordpress-hardening-ip-reputation.data — IP/CIDR blocklist (populate with your threat intel feeds)
  • plugins/wordpress-hardening-login-countries.data — GeoIP allowed-country list (ISO 3166-1 alpha-2 codes)

CI/CD

  • Full GitHub Actions integration test suite (nginx backend)
  • Lint workflow: validates rule ID ranges, detects duplicates, checks @pmFromFile references

Bug Fixes

  • Fixed REST API gate overlap between rules 9522107 and 9522207 (WHP-1)
  • Replaced @ipMatch with @ipMatchFromFile for file-backed IP lists (WHP-2)
  • Fixed @eq POST → @streq POST in integration tests (WHP-3)
  • Fixed chained rule skipAfter conflict in rate-limiting rule 9522410 (WHP-4)
  • Quoted all setvar values containing spaces (WHP-5)
  • Fixed msc_pyparser lint error (Expected ''') in logdata/msg strings (WHP-6)
  • Corrected URL-encoded user enumeration test cases (WHP-7)

Upgrade Notes

All new features are opt-in or on by default with safe fallbacks. No existing rule IDs or default behaviours have changed. To use IP reputation or GeoIP features, uncomment the relevant SecAction lines in wordpress-hardening-config.conf and populate the corresponding .data files.

1.0.0.3rc3

1.0.0.3rc3 Pre-release
Pre-release

Choose a tag to compare

@eilandert eilandert released this 16 Feb 00:31

Showstoppers for release 1.0.0:

  • Better formatting?
  • Review rules by someone else.
  • More production testing and input from users.

Prerelease 1.0.0rc3

  • modified regressiontests
  • no more fp's due to simplyfied rules
  • more OWASP formatting/compliance

Prerelease 1.0.0rc2

  • Fixed some rules
  • Squashed some rules
  • Added workflows and integrations.
  • All PL1 rules are now subject to the regression tests

Prerelease 1.0.0rc1

  • Block xmlrpc.php access (configurable, default: block) (PL1)
  • Block user enumeration (configurable, default: block) (PL1)
  • Block user "admin" logins (configurable, default: block) (PL1)
  • Block the wp-json restapi (configurable, default: non-block) (PL1)
  • Block wp-cron.php (configurable, default: non-block) (PL1)
  • Block direct php access in /wp-content/* and /wp-includes/* (PL1)
  • Block direct file access to some files in / and other files/directories (PL1)
  • Block other interpreters like .pl/.lua/.py/.sh (PL2)
  • Block nasty files in uploads/* (PL1)
  • Block access to sensitive files like .db/.orig/.sql/.log/.git (PL1)
  • Block access to "/wp-json" (exact match, the api still works) (PL1)