Title: Lockora Security Audit
Author: Guido Schad
Published: <strong>Май 20, 2026-ж.</strong>
Last modified: Август 5, 2026-ж.

---

Плагиндерди издөө

![](https://ps.w.org/lockora-security-audit/assets/icon-256x256.png?rev=3540179)

# Lockora Security Audit

 Автору [Guido Schad](https://profiles.wordpress.org/cmdgw/)

[Жүктөө](https://downloads.wordpress.org/plugin/lockora-security-audit.0.3.0.zip)

 * [Кенен маалымат](https://ky.wordpress.org/plugins/lockora-security-audit/#description)
 * [Сын-пикирлер](https://ky.wordpress.org/plugins/lockora-security-audit/#reviews)
 *  [Орнотуу](https://ky.wordpress.org/plugins/lockora-security-audit/#installation)
 * [Development](https://ky.wordpress.org/plugins/lockora-security-audit/#developers)

 [Колдоо](https://wordpress.org/support/plugin/lockora-security-audit/)

## Сүрөттөө

Lockora Security Audit helps site owners and agencies review a WordPress site’s 
security posture from the admin area.

### Works well with Who Changed It?

Lockora finds security weaknesses. [Who Changed It? – Activity Log](https://wordpress.org/plugins/who-changed-it/)
shows what changed, who changed it, and when, with severity classification, field-
level diffs, and alerts. Use both together to connect a security finding to the 
activity that caused it.

Current prototype features include:

 * Manual security scans.
 * Weighted security score out of 100.
 * Bounded scan history with current-versus-previous finding comparisons.
 * WordPress core file integrity checks using official checksums.
 * WordPress authentication key and salt checks, with an explicit action to generate
   missing salts.
 * Must-use plugin directory presence checks.
 * PHP version status using WordPress.org Serve Happy data.
 * HTTPS and HTTP security header checks.
 * WordPress core, plugin, and theme update posture checks.
 * Administrator account posture checks for default usernames, excess admins, inactive
   admins, user ID 1 exposure, and an admin username/email inventory.
 * Public exposure checks: debug.log and readme.html reachability, uploads directory
   listing, PHP execution inside uploads, and author archive user enumeration.
 * SSL certificate expiry check, database table prefix check, automatic update posture
   check, and detection of login protection / two-factor plugins.
 * Site Health integration: scan summary plus key configuration checks appear under
   Tools > Site Health > Status.
 * WP-CLI support: `wp lockora scan` and `wp lockora report`, with `--format=json`
   and a `--strict` flag for CI pipelines.
 * Optional known vulnerability matching with a configured Wordfence Intelligence
   API key.
 * Optional AI client reports on WordPress 7.0+ when the site’s AI Connector is 
   configured.
 * Reversible hardening toggles for XML-RPC, REST user routes, generator tag output,
   and basic security headers.
 * A `lockora_scan_completed` action for integrations that need scan scores and 
   finding counts.

### External Services

Lockora Security Audit may connect to external services only when the administrator
runs a scan or generates an AI client report.

During a scan the plugin also sends HTTP requests to the site’s own public URL (
loopback requests) to inspect response headers, debug.log and readme.html reachability,
uploads directory behavior, and author archive redirects, and it opens a TLS connection
to the site’s own hostname to read the SSL certificate expiry date. These requests
stay within the site being scanned and send no data to third parties.

WordPress.org APIs:
 * Used for WordPress core checksums, PHP version support status,
and WordPress core/plugin/theme update data. * Data sent: the site’s WordPress version
and locale for core checksums and PHP compatibility; WordPress itself may send installed
plugin and theme slugs/versions to WordPress.org when update data is refreshed. *
WordPress.org terms: https://wordpress.org/about/terms/ * WordPress.org privacy 
policy: https://wordpress.org/about/privacy/

Wordfence Intelligence:
 * Optional. * Used only when a Wordfence Intelligence API
key is configured and an administrator runs a scan that includes vulnerability matching.*
Used to retrieve vulnerability data and match it locally against installed WordPress
core, plugin, and theme versions. * Data sent: the configured Wordfence Intelligence
API key is sent in an Authorization header when requesting the vulnerability feed.
Installed software details are not sent by this plugin to the Wordfence Intelligence
endpoint; matching is performed locally after the feed is retrieved. * Wordfence
Intelligence terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/*
Wordfence privacy policy: https://www.wordfence.com/privacy-policy/

WordPress AI Client / Connectors:
 * Optional. * Used only when the administrator
clicks Generate Client Report. * Data sent: sanitized scan findings, score, counts,
and recommendations needed to generate a client-facing report. The plugin is designed
not to send passwords, salts, API keys, raw logs, full user lists, or file contents.*
The configured AI provider is controlled by the site owner’s WordPress Connector
settings. * Terms and privacy policy: these depend on the AI provider configured
by the site owner in WordPress. Site owners should review the selected provider’s
terms and privacy policy before enabling AI reports.

## Орнотуу

 1. Upload the `lockora-security-audit` folder to `/wp-content/plugins/`.
 2. Activate Lockora Security Audit from the Plugins screen.
 3. Go to Tools > Lockora Security Audit.
 4. Click Run Scan.

## FAQ.KG

### Does Lockora Security Audit fix every issue automatically?

No. It provides reversible hardening toggles for selected low-risk settings. Other
findings should be reviewed by an administrator, developer, or host.

### Does Lockora Security Audit require AI?

No. The scanner works without AI on WordPress 6.0 and newer. AI client reports are
optional and require WordPress 7.0 or newer with AI Client support plus a configured
AI Connector.

### Does Lockora Security Audit include a vulnerability database?

No. It can optionally use a configured Wordfence Intelligence API key for known 
vulnerability matching.

### Does Lockora Security Audit send secrets to AI providers?

The plugin is designed to send sanitized scan findings only. It does not intentionally
send passwords, salts, API keys, raw logs, user lists, or file contents.

## Сын-пикирлер

![](https://secure.gravatar.com/avatar/cf25fe7bd528afc7b32607caeac4c7b2c0d7374511284d675fc7d92b6e3075b7?
s=60&d=retro&r=g)

### 󠀁[Clear, practical, and impressively thorough](https://wordpress.org/support/topic/clear-practical-and-impressively-thorough/)󠁿

 [marschadgc](https://profiles.wordpress.org/marschadgc/) Июль 30, 2026-ж.

Lockora Security Audit makes reviewing WordPress security refreshingly straightforward.
The security score gives you an immediate overview, while the detailed findings 
explain what needs attention without burying you in jargon. I especially appreciate
the core integrity and public-exposure feature which shows which files do not belong
into wp core, very very useful!! The interface is clean, scans are quick, and the
recommendations feel practical and actionable. Site Health integration and the optional
AI-generated client reports are excellent additions. A polished, lightweight security
tool that provides real value…highly recommended!

![](https://secure.gravatar.com/avatar/2bfb85ba19f74018a1e2294210bad5d938a7138a6d46af7fb76623e8536bf828?
s=60&d=retro&r=g)

### 󠀁[Excellent Security Plugin](https://wordpress.org/support/topic/excellent-security-plugin-53/)󠁿

 [ttpainos](https://profiles.wordpress.org/princecalaf/) Июль 1, 2026-ж.

Lockora has quickly become one of my favorites. The security audit is detailed without
being overwhelming, and it identified several configuration issues and hardening
opportunities that had gone unnoticed by other tools I had previously used. What
impressed me most is the Claude AI integration. Instead of searching through documentation
or trying to interpret technical findings on my own, I can simply ask the AI what
a particular issue means, whether it’s a real risk, and how to fix it. The responses
are accurate, practical, and save a tremendous amount of time. The plugin is lightweight,
scans complete quickly, and the interface is clean and easy to navigate. If website
security is important to you, Lockora is definitely worth installing.

![](https://secure.gravatar.com/avatar/6fc3b62319f5ba421e69fa3d0f52499a6b5b3efa6fad7410d488cd9e5ce194a3?
s=60&d=retro&r=g)

### 󠀁[Best security plugin I’ve used in years — flawless Claude AI integration](https://wordpress.org/support/topic/best-security-plugin-ive-used-in-years-flawless-claude-ai-integration/)󠁿

 [callaf](https://profiles.wordpress.org/callaf/) Май 30, 2026-ж.

I’ve tested a lot of WordPress security plugins over the years, and Lockora Security
Audit is genuinely the best I’ve seen in a long time. The audit engine is thorough,
fast, and easy to understand even if you’re not a security expert. It flagged a 
few hardening issues on my site that other tools completely missed, and the recommendations
were clear and actionable. What really sets it apart is the AI connection to Claude.
It works perfectly … I can ask questions about scan results in plain language and
get smart, contextual explanations and fixes right inside the dashboard. It turns
a normally tedious security review into something quick and almost enjoyable. Setup
was painless, performance impact is negligible, and it just works. Highly recommended
for anyone who takes their site security seriously. Five stars!

![](https://secure.gravatar.com/avatar/01ca6885f4ee9e50021cd307793981c73288bec8c0e1ddc8364a2df8b6e09110?
s=60&d=retro&r=g)

### 󠀁[Top WordPress Security Plugin for WP 7](https://wordpress.org/support/topic/top-wordpress-security-plugin-for-wp-7/)󠁿

 [michaelseri](https://profiles.wordpress.org/michaelseri/) Май 21, 2026-ж.

Lockora is I think the first WordPress security audit which can implement AI into
your security audit automatically and it works beautifully. Not a real malware scanner
but shows within seconds if your system has been altered and which steps you need
to take to harden your installation. 5/5 !!

 [ Read all 4 reviews ](https://wordpress.org/support/plugin/lockora-security-audit/reviews/)

## Contributors & Developers

“Lockora Security Audit” is open source software. The following people have contributed
to this plugin.

Мүчөлөрү

 *   [ Guido Schad ](https://profiles.wordpress.org/cmdgw/)

[Translate “Lockora Security Audit” into your language.](https://translate.wordpress.org/projects/wp-plugins/lockora-security-audit)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/lockora-security-audit/),
check out the [SVN repository](https://plugins.svn.wordpress.org/lockora-security-audit/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/lockora-security-audit/)
by [RSS](https://plugins.trac.wordpress.org/log/lockora-security-audit/?limit=100&mode=stop_on_copy&format=rss).

## Өзгөртүүлөр

#### 0.3.0

 * Added bounded scan history and current-versus-previous finding comparisons.
 * Added contextual links from findings to Who Changed It? or its WordPress.org 
   listing.
 * Added the `lockora_scan_completed` action for scan-result integrations.

#### 0.2.2

 * Added: style altered WordPress core files list items and heading in red color(#
   b32d2e) for enhanced visibility.

#### 0.2.1

 * Fixed: core integrity checks now show the full list of altered/missing/extra 
   files through an interactive collapsible UI details panel when there are more
   than 5 files.
 * Added: auto-trigger scan update when loading the admin dashboard after plugin
   upgrade, ensuring the detailed file lists are populated immediately without manual
   intervention.

#### 0.2.0

 * Fixed: wp-config.php can now be found one directory above the WordPress root,
   matching core behavior.
 * Fixed: authentication salt checks now use runtime constants, so salts defined
   outside wp-config.php (for example Bedrock-style configs) are no longer reported
   as missing and can no longer receive duplicate defines.
 * Fixed: generated salts can no longer be corrupted by regex replacement characters,
   and wp-config.php writes are now verified and rolled back if the written file
   does not match.
 * Fixed: admin notices are stored server-side instead of being read from the URL,
   removing a notice spoofing vector.
 * Fixed: network-activated plugins are no longer reported as inactive on multisite.
 * Fixed: the inactive administrator check now uses recorded last-login times instead
   of short-lived session tokens, removing false positives.
 * Fixed: the security header check falls back to GET when a server rejects HEAD
   requests, and the default fallback theme now follows WP_DEFAULT_THEME.
 * Added: public exposure checks for debug.log, readme.html, uploads directory listing,
   PHP execution in uploads, and author enumeration.
 * Added: SSL certificate expiry, database table prefix, automatic update posture,
   and login protection plugin checks.
 * Added: Site Health integration with a scan summary and key configuration tests.
 * Added: WP-CLI commands `wp lockora scan` and `wp lockora report` with JSON output
   and a –strict flag for CI.
 * Added: uninstall cleanup that removes all plugin options, transients, and user
   meta on deletion.
 * Hardened: AI report generation now uses a lock against concurrent requests, sanitizes
   finding text before prompting, and instructs the model to treat finding text 
   as untrusted data.

#### 0.1.2

 * Lowered the required WordPress version to 6.0 for non-AI security scanning and
   hardening checks.
 * Kept AI client reports disabled unless WordPress 7.0+ AI Client support is available.

#### 0.1.1

 * Fixed HTTP security header scanning when a server returns duplicate headers as
   arrays.

#### 0.1.0

 * Initial prototype with manual scans, hardening checks, core integrity checks,
   PHP version checks, vulnerability posture checks, optional Wordfence feed matching,
   and optional client-ready AI reports.

## Мета

 *  Нуска **0.3.0**
 *  Акыркы жаңыртуу **7 саат мурун**
 *  Активдүү орнотуулар **100+**
 *  WordPress нускасы ** 6.0 же андан жогору **
 *  Tested up to **7.0.2**
 *  PHP нускасы ** 7.4 же андан жогору **
 *  Тил
 * [English (US)](https://wordpress.org/plugins/lockora-security-audit/)
 * Тег:
 * [AI](https://ky.wordpress.org/plugins/tags/ai/)[hardening](https://ky.wordpress.org/plugins/tags/hardening/)
   [security](https://ky.wordpress.org/plugins/tags/security/)[site health](https://ky.wordpress.org/plugins/tags/site-health/)
   [vulnerability scanner](https://ky.wordpress.org/plugins/tags/vulnerability-scanner/)
 *  [Advanced View](https://ky.wordpress.org/plugins/lockora-security-audit/advanced/)

## Рейтинг

 5 out of 5 stars.

 *  [  4 5-star reviews     ](https://wordpress.org/support/plugin/lockora-security-audit/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/lockora-security-audit/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/lockora-security-audit/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/lockora-security-audit/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/lockora-security-audit/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/lockora-security-audit/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/lockora-security-audit/reviews/)

## Мүчөлөрү

 *   [ Guido Schad ](https://profiles.wordpress.org/cmdgw/)

## Колдоо

Комментарийлер барбы? Жардам керекпи?

 [Колдоо форумун көрүү](https://wordpress.org/support/plugin/lockora-security-audit/)