Opis
Forge12 Security is an all-in-one WordPress security plugin built by Forge12 Interactive GmbH in Germany. Firewall, malware and file scanner, login protection with two-factor authentication, hardening and AI crawler control — every module can be switched on and off on its own, so a site runs only the parts it needs.
It is built for sites that have to answer for their visitors’ data: IP addresses are stored as hashes, the admin loads no fonts, scripts or images from anybody else, and nothing contacts a third party unless you switch the feature on.
Every feature described below is included and fully functional. Nothing here is
limited by a licence key, a trial period or a usage quota.
Forge12 Security Pro
For agencies and business sites, Forge12 Security Pro adds what the plugin directory does not allow a free plugin to do, and what saves time when you look after many sites:
- Repair with one click — put the original back over a modified WordPress, plugin or theme file, one at a time or all at once, and restore files from quarantine
- Firewall before WordPress — requests are checked before WordPress and every other plugin load
- Same-day signatures — malware signatures and firewall rules the day they are published; the free plugin receives the same rule set 30 days later
- Country blocking and IP ranges — allow or block by country, and by IPv4/IPv6 range
- Tamper-proof audit trail, Slack and Telegram alerts, daily digest
- Remote monitoring, WP-CLI and multisite network management for looking after many sites
- Database snapshots with restore, Google Safe Browsing, and automatic repair and quarantine instead of a report
Pro is an add-on: it needs this plugin installed and active, and keeps all of its settings. Compare Free and Pro.
What it does
- Web application firewall. Scores each request against a signature set and
refuses it when a category threshold is reached. A learning mode records what
matches without blocking, so the exceptions your own site needs can be created
from what actually happened. - Outbound traffic monitoring. Watches where this installation sends data
and to whom, learns which hosts are normal, and reports the new ones. Stolen
data has to leave the server somehow; this is where that shows. - Reinfection, not just infection. A file that was removed and came back is
proof of persistence. The scanner looks for what put it back — a scheduled
event, a must-use plugin, a drop-in — instead of deleting it again. - Behaviour rules. Judges a file by the sequence of things its code does
(create a user, hand it the administrator role, mark it to be found again),
not by how it is written. Obfuscation is free to change; the steps are not. - AI crawler detection with proof. Anyone can put “ClaudeBot” in a header.
Crawlers are checked against the address ranges their operators publish, so a
claim that cannot be verified is treated as unverified rather than as fact.
Each crawler, or each category of crawler, can be allowed, watched or refused. - Login protection and two-factor authentication. Rate limiting, lockouts,
TOTP with locally generated QR codes, and an optional custom login address.
Requirements
- WordPress 6.2 or higher
- PHP 8.1 or higher
- MySQL 5.7 / MariaDB 10.3 or higher
External Services
Everything this plugin does happens on your own server, with the exceptions
below. None of them runs unless the feature that needs it is switched on; the
only one that is on out of the box talks to WordPress.org. The plugin’s Data
Protection screen (Security, Privacy) shows which of them are active on your
site.
WordPress.org — on by default
File integrity, malware and update checks compare your files with the official
checksums. Sent while a scan runs: plugin and theme slugs, version numbers and
file hashes. No personal data.
Terms: https://wordpress.org/about/license/
Privacy policy: https://wordpress.org/about/privacy/
WPVulnerability — off by default
Looks up whether an installed plugin or theme has a published vulnerability.
The setup wizard asks first. Sent once a day and during a full scan: the slug
and version of each installed plugin and theme. Nothing about your site or your
visitors.
Terms: https://www.wpvulnerability.com/license/
Privacy policy: https://www.wpvulnerability.com/privacy/
Have I Been Pwned (Pwned Passwords) — off by default
Checks whether a new password appears in a known breach. Only the first five
characters of the password’s SHA-1 hash are sent (k-anonymity), never the
password and never a username.
Terms: https://haveibeenpwned.com/API/v3
Privacy policy: https://haveibeenpwned.com/Privacy
SilentShield — off by default, needs an API key
A behaviour check on the login, registration and password reset forms, and the
only feature that loads a script into a visitor’s browser — on those three forms
only. The visitor’s IP address reaches the service. Operated by Forge12
Interactive GmbH from Germany.
Terms: https://silentshield.io/terms/
Privacy policy: https://silentshield.io/privacy/
Forge12 signature service — off by default
Fetches the current signed malware and firewall rule set twice a day and applies
it only after its signature checks out. The setup wizard asks first. Sent: the
plugin version and the number of the rule set already held. If you enter a
licence key, the key and this site’s domain are sent to validate it. Operated by
Forge12 Interactive GmbH from Germany.
Terms: https://www.forge12.com/agb/
Privacy policy: https://www.forge12.com/datenschutz/
Crawler operators’ published address lists — off by default
Switched on, the list each crawler operator publishes of its own addresses is
fetched once a day, so that a real crawler can be told from an impostor. The
lists come from the operators themselves: Google, Microsoft Bing, OpenAI,
Anthropic, Perplexity, DuckDuckGo, Apple, Cloudflare, UptimeRobot and Jetpack.
The request carries the plugin’s user agent, which names your site; nothing
else is sent. While it is off, the lists shipped with the plugin are used and
nothing is fetched. Each operator’s own terms and privacy policy apply.= Key Features =
Web Application Firewall (WAF)
- Regex-based request filtering with customizable rules
- IP blocking with automatic expiration
- Bot detection with reverse DNS verification for Googlebot, Bingbot, Yandex, Baidu, DuckDuckBot
- Request validation (method, URL length, null byte detection)
- Predefined rule sets for common attack patterns (SQL injection, XSS, path traversal)
- WAF Learning Mode that records what the firewall would have blocked
- Automatic whitelist rule generation from learning mode results
Outbound Traffic Monitoring
- Watches where this installation sends data, and to whom
- Learns a baseline of the hosts your site normally talks to, then reports the ones that are new
- Refuses an outbound call before the connection is opened, so exfiltration and callbacks to a command server are stopped rather than logged after the fact
- The step every worthwhile attack has to take in the end — stolen data has to leave the server somehow
Vulnerability Shield
- Holds a known-vulnerable plugin shut until its update arrives
- The unauthenticated endpoints of a plugin with a published, unpatched vulnerability stop answering — the plugin’s own code is never touched
- Closes the window between disclosure and update: the weighted median from publication to mass exploitation is five hours, and 46 % of vulnerabilities are still unpatched on the day they are published
AI Crawler Detection
- Recognises crawlers operated by AI companies: OpenAI, Anthropic, Google, Perplexity, Meta, Apple, Amazon, Common Crawl, ByteDance and more
- Sorts them by what they do with your content: model training, assistant fetches on behalf of a user, AI search indexing
- Records which crawler requested what, and how often
- Allow, watch or block each crawler or whole category
- Matching robots.txt directives generated from your decisions
DDoS & Rate Limiting
- Configurable request rate limits per IP
- Separate rate limits for REST API endpoints
- 404 rate limiting to detect and block vulnerability scanners
- Automatic IP blocking on limit exceeded
- IP whitelist for trusted addresses
Login Protection
- Brute force prevention with automatic lockout (5 attempts / 15 min)
- Two-factor authentication (TOTP) with QR code setup
- Recovery codes for 2FA
- Login honeypot for bot detection
- Custom login URL to hide wp-login.php
- SilentShield bot check on the login, registration and password reset forms — Forge12’s own service, served from Germany, no Google script in your visitors’ browsers
- Login activity logging (success, failure, lockout)
Password Security
- Configurable strong password policy (minimum length, uppercase, numbers, special characters)
- Breached password detection via Have I Been Pwned API (k-Anonymity)
- 2FA enforcement per role, with a grace period for gradual rollout
File Integrity Monitoring
- SHA-256 checksum baseline of all WordPress core, plugin, and theme files
- Automatic scheduled scans with configurable intervals
- Repository verification against WordPress.org originals
- Automatic scheduled malware and integrity scans
- Quarantine and delete suspicious files
- Excluded paths: a page for the directories no file check should judge — a template cache a plugin fills with generated PHP, a staging clone, code you trust. It records which places your scans keep reporting and how many scans in a row, so excluding one is a button rather than a path typed from memory; entries can be switched off instead of deleted, and known candidates are offered as ticks, never applied on their own
Malware Signature Scanner
- Pattern-based malware detection with 283 built-in signatures
- Detects eval/base64 backdoors, shell uploads, code obfuscation, and remote includes
- Heuristic detection via entropy and structure analysis, beyond signature matching
- Three sensitivity levels: critical signatures only, critical and high, or everything including heuristics
- Files that still match the checksum their author published on WordPress.org are never flagged
- Mark a reviewed file as allowed — pinned to its content, so a later change brings it back into scope
- File Guard: an unexpected PHP file is reported the moment it is executed, not on the next scheduled scan. On its own this covers files that load WordPress, which is most of them, because a shell usually wants the database.
- Suspicious file flagging with threat identification
- Extensible signature database (JSON format)
Reinfection, Attack Surface and Supply Chain
- Persistence check: finds what puts a removed file back — a scheduled event, a must-use plugin, a drop-in — starting with the evidence that actually proves reinfection, a file that was taken away and is back
- Attack surface: records which REST routes and AJAX actions are reachable without logging in and which of those change something, and reports the door that newly appeared
- Update guard: verifies an installed update against the per-file checksum manifest WordPress.org publishes, so a package that is not what the author shipped is caught on arrival
- Known hashes: covers premium plugins, bespoke themes and this plugin itself, where wordpress.org publishes no original to compare against
- File inventory instead of modification times: a dropped file cannot make itself old with touch, and a plugin update no longer resets what counts as new
- Behaviour rules: judges a file by the sequence of things its code does — create a user, hand it the administrator role, mark it to be found again — not by how it is written
- Every finding says in plain words what it means and what to do about it, instead of naming the rule that fired
Database Integrity Monitoring
- Monitors wp_options, wp_posts, wp_postmeta, wp_users, wp_usermeta
- Detects unauthorized modifications, injected scripts and phishing URLs in posts, comments and options
WordPress Hardening
- Disable XML-RPC and pingbacks
- Disable file editor
- Force SSL for admin area
- Block PHP execution in uploads directory
- Prevent user enumeration
- Restrict REST API to authenticated users
- Disable application passwords
- Remove WordPress version info
- Configurable Content-Security-Policy header
- Full suite of security headers (HSTS, X-Frame-Options, X-Content-Type-Options, etc.)
- Limit post revisions
- Shorter session lifetimes
- Limit concurrent sessions per user
- Auto-update WordPress core
- Comment spam honeypot protection
- Strong password enforcement with configurable rules
- SilentShield bot protection for login, registration and password reset forms
Email Notifications
- Alerts for critical and high severity events
- Findings collected and sent as one message, grouped and counted, instead of one email per finding
- Anything critical sent immediately, with whatever else has collected
- Unsubscribe link in every message, for people who no longer have an account on the site
- Weekly summary of what was blocked, attempted and found — sent whether or not anything went wrong
- Optional notifications for IP blocks
- Scan summary emails when changes are detected
- Configurable notification email address
- A test button to check delivery
- Slack and Telegram alerts and a daily digest are part of Forge12 Security Pro
Live Traffic
- Watch requests as they arrive, with response code, request type and bot classification
- Block an IP straight from a traffic entry
- Records security-relevant requests (errors, blocks, login attempts) and keeps 24 hours
Security Logging
- Comprehensive event logging for all security actions
- Filterable by event type and severity
- Quick-filter for login activity
- CSV export
- Block IPs directly from log entries
- Configurable log retention (default: 90 days)
Data Protection
- IP anonymization via HMAC-SHA256 (no plain IPs stored)
- Optional AES-256-CBC encrypted IP storage
- WordPress privacy exporter integration
- WordPress privacy eraser integration
Settings Management
- Import/export settings as JSON
- Security score with detailed breakdown
- Modern React-based admin interface
Snimke zaslona










Instalacija
- Upload the
forge12-securityfolder to the/wp-content/plugins/directory - Activate the plugin through the ‘Plugins’ menu in WordPress
- Navigate to the Forge12 Security menu in the admin sidebar
- Review the Dashboard and enable/disable modules as needed
- Configure individual module settings through the respective pages
First Steps After Installation
- Check the Dashboard – Review your security score and enable recommended modules
- Run a File Scan – Go to File Integrity and create a baseline
- Review Hardening – Enable hardening options that suit your site
- Set Up Notifications – Configure your notification email in Settings
- Enable 2FA – Activate two-factor authentication for admin accounts
Pitanja i odgovori
-
What is the difference between Forge12 Security and Forge12 Security Pro?
-
Everything described on this page is free and stays free, without a trial period or a limit. Forge12 Security Pro is an add-on for sites that want problems fixed rather than reported: one-click repair of modified files and restore from quarantine, a firewall stage that runs before WordPress, same-day malware signatures and firewall rules, country blocking, a tamper-proof audit trail, Slack and Telegram alerts, and remote monitoring for many sites.
-
Do I need this plugin to use Forge12 Security Pro?
-
Yes. Pro extends this plugin and needs it installed and active. Removing Pro leaves this plugin and all of its settings as they were.
-
Does this plugin work with caching plugins?
-
Yes. Forge12 Security operates at the PHP level and is compatible with all major caching plugins. Rate limiting and firewall checks happen before page caching kicks in.
-
Will the custom login URL break my site?
-
No. If you forget the custom login URL, you can deactivate the plugin via FTP/file manager and the standard wp-login.php will work again. Password-protected post forms (action=postpass) continue to work normally.
-
Does this plugin store IP addresses?
-
By default, IP addresses are hashed using HMAC-SHA256 and never stored in plain text. Optionally, you can enable AES-256-CBC encrypted storage if you need to identify specific IPs. These options help minimize stored personal data; they do not guarantee GDPR compliance.
-
Can I use this with other security plugins?
-
While possible, we recommend using only one comprehensive security plugin to avoid conflicts. If you need specific features from another plugin, you can disable overlapping modules in Forge12 Security.
-
What happens when the malware scanner finds something?
-
Suspicious files are flagged with the detected signature name. You can review the file, move it to encrypted quarantine, or permanently delete it after a separate confirmation. Modified WordPress, plugin and theme files are compared with their published version; to replace one, reinstall or update it from the dashboard. Confirmed false positives can be ignored or excluded.
-
How does the honeypot work?
-
The honeypot adds an invisible form field to login and comment forms. Real users never see or fill it. Bots that automatically fill all form fields trigger the honeypot and are blocked. The field name rotates every 6 hours to prevent bot adaptation.
-
How does the SilentShield bot check work?
-
A small client is loaded on your login, registration and password reset forms. It watches how the form is filled in and leaves a token on it; on submission the plugin asks the SilentShield API what that token was worth, and you set the threshold below which a submission is refused. It replaced the Google reCAPTCHA integration in 3.3.44, because that one loaded Google’s script into the browser of everybody who opened your login page, handing Google their address and setting Google’s cookies for a form only your own staff ever use. SilentShield is Forge12’s own service and answers from a German host with no CDN in front of it, so the transfer is one you can put in a contract. What has not changed: it is still a third-party script in the visitor’s browser, and the visitor’s address still reaches somebody else. Like the check it replaced it fails open by default — an outage at the API must never be the reason nobody can log in — and a filter is there for sites that would rather be locked out than let a bot through.
-
Does the breached password check send my passwords to an external service?
-
No. The HIBP check uses k-Anonymity: only the first 5 characters of the SHA-1 hash of the password are sent to the API. The full password never leaves your server. Results are cached for 24 hours.
-
Where do I require two-factor authentication for a role?
-
Under Two-Factor Auth, above the user list. Switch on the roles that must carry a second factor, set the grace period beside them, and save. The roles offered are the ones your site actually has, including any a plugin adds.
-
What is the 2FA grace period?
-
It is how long somebody may go on working before the requirement takes effect: 0 to 90 days, counted from that account’s first sign-in after you switch the requirement on. Nobody is ever locked out by it. The sign-in itself succeeds either way; once the period is up, the account is taken to the setup screen and stays there until a second factor is in place, and during the period it sees a notice with the days remaining. A grace period of zero days means the setup screen appears at the next sign-in.
-
How does 404 rate limiting work?
-
404 rate limiting monitors how many “Page Not Found” errors a single IP generates within a time window. Vulnerability scanners typically probe hundreds of known paths rapidly, generating many 404s. When the threshold is exceeded, the IP is automatically blocked.
-
How does bot detection work?
-
Bot detection identifies fake search engine crawlers. When a visitor claims to be Googlebot (via User-Agent), the plugin performs a reverse DNS lookup to verify that the IP actually belongs to Google. If the reverse DNS check fails, the bot is flagged as fake and optionally blocked. Results are cached for 24 hours.
-
What is WAF Learning Mode?
-
Learning Mode records normal request patterns (URLs, methods, parameter names) over a configurable period (default: 7 days). After the learning period, you can generate whitelist rules from the observed traffic. These whitelist rules ensure that known-good requests bypass WAF checks, reducing false positives.
-
Why can this plugin not repair files or run the firewall before WordPress?
-
Both write into places the WordPress plugin directory does not allow this plugin to write to: code into files, and files into the WordPress, plugin and theme folders or the site’s root folder. Those features are part of Forge12 Security Pro, which is not distributed through the directory. This plugin still finds, explains and compares every modified file, and quarantines or deletes suspicious ones.
-
Can I export my settings to another site?
-
Yes. Go to Settings > Import / Export. You can export all settings as a JSON file and import them on another WordPress installation.
Recenzije
Nema recenzija za ovaj dodatak.
Suradnici i Programeri
“Forge12 Security – Firewall, Malware Scanner, 2FA & Login Security” je softver otvorenog koda. Sljedeće osobe su doprinijele ovom dodatku.
SuradniciPrevedite “Forge12 Security – Firewall, Malware Scanner, 2FA & Login Security” na svoj jezik.
Zainteresirani ste za razvoj?
Pregledajte kôd, pogledajte SVN spremišteili se pretplatite na dnevnik razvoja od RSS.
Dnevnik promjena
Only the most recent releases are listed here. The full history is in
changelog.txt, which ships with the plugin.
3.7.16
A server set to write files over FTP without the FTP extension no longer takes the site down.
- Where WordPress was configured to write files over FTP but PHP has no FTP support, every request ended with a fatal error as soon as the plugin wrote a protection file. The plugin now recognises a file system that could not be set up and leaves the write out.
3.7.15
Forge12 Security is now distributed through WordPress.org, and installations that received their updates from forge12.com switch over by themselves.
- An installation that received updates from forge12.com replaces itself with the WordPress.org copy on the next visit to the dashboard. Settings, records and findings are kept, and automatic updates stay switched on if they were.
- If a server does not allow the switch, for example because plugins cannot be installed from the dashboard, a notice explains how to do it by hand and offers to try again.
- Deleting one of two installed copies of the plugin no longer removes the settings and records the other copy still uses.
- The WordPress.org package includes the German translation.
3.7.14
Settings that went back to their old value after saving now stay, and a finding is emailed once instead of on every check.
- The scan steps “Unpublished Files” and “Persistence”, and “Seconds per Scan Request”, were confirmed as saved but showed their previous value on the next load. They are now saved.
- Saving on one screen could undo settings changed on another screen during the same visit, for example a hardening switch after “Save all Settings”. Each screen now saves only what was changed on it.
- The audit log switch reported success without changing anything. It now switches audit logging on and off.
- “Not listed on WordPress.org, so it cannot be checked there” is information for the log and is no longer sent by email.
- An outdated or abandoned plugin or theme, and a known vulnerability, are emailed when they are first found, not again on every check. The log still records them each time. A new version, a new vulnerability or a change of state is emailed again.
- Plugins listed on WordPress.org were missing from the vulnerability overview, because their last-update date did not fit the database field. They are now listed.
- The setup wizard showed brute-force protection as a switch that could be turned off. The protection is always on, and the wizard now shows it that way.
- “Custom Login URL” on the Hardening screen looked like a switch but only shows whether a login address is set. It no longer reacts to clicks.
- The plugin’s own menu, the test email and the footer of alert emails now use the plugin’s name, Forge12 Security, instead of the old short form.
3.7.13
An expired license from before 26 September 2026 keeps its Pro features, and an unreachable license server no longer switches anything off.
- A license whose term began before 26 September 2026 keeps the Pro features of the installed version after it expires. Updates and support end with the term.
- A license whose term begins on or after 26 September 2026 pauses the Pro features when it expires. All settings and data are kept, and a new license resumes them at once.
- If the license server cannot be reached, the last known license status stays in force. A license that expires during such an outage keeps its Pro features for another 14 days, in case it has already been renewed.
- If the license server has not been reachable for more than seven days, a notice on the plugin’s screens says so. Nothing is switched off.
- A suspended or revoked license switches the Pro features off, whatever its model.
- A license renewed on the same key keeps, once its new term has expired, the Pro features up to the Forge12 Security Pro version its earlier term covered.
- A license is valid until the end of its last day, German time, as the license server counts it. Dates are judged by the license server’s clock, so a wrong clock on the web server neither ends a license early nor keeps it running.
- The license page says which of these applies.
