Сүрөттөө
Stalza Security protects your site without weighing it down. Instead of hundreds of generic warnings, it tells you what changed, why it matters, how confident the detection is, and what to do.
Detect Correlate Assess Risk Explain Protect Verify
Free features
- File & WordPress integrity — core, plugin and theme checksums plus a local baseline for everything else.
- Malware detection — heuristic analysis of PHP, JS and .htaccess files; no signature database needed.
- Vulnerability detection — daily check of your installed components against known advisories (opt-in).
- Brute-force protection — login, XML-RPC and REST user-enumeration limits with escalating lockouts.
- Security hardening — one-click fixes and clear advisories for common misconfigurations.
- Security events & reports — a single timeline of what happened, with a weekly digest.
Designed to be light
- Zero frontend queries unless a login attempt is being evaluated.
- Scans run in small resumable chunks with CPU and memory budgets.
- No autoloaded option bigger than 50 KB. No bundled React runtime — uses the one WordPress already ships.
Premium
Stalza Security Pro extends the same engine with cloud threat intelligence, real-time protection, behavioral analysis, automatic remediation, IP reputation and advanced alerting.
External services
This plugin works fully offline by default. Nothing is sent anywhere until you opt in.
If you enable Vulnerability intelligence in Settings, the plugin sends the slugs and version numbers of your installed WordPress core, plugins and themes, plus your site URL, to https://stalza.com/api/stalza-security/v1/vulnerabilities/match once per day to receive matching security advisories. No user data, content or visitor information is included. See the Stalza privacy policy and terms.
Integrity checks fetch official checksums from WordPress.org (api.wordpress.org, downloads.wordpress.org), the same service WordPress core uses for updates.
Орнотуу
- Upload the plugin to
/wp-content/plugins/stalza-security/or install it from the Plugins screen. - Activate it.
- Go to Stalza Security in the admin menu and run your first scan.
FAQ.KG
-
Does it slow down my site?
-
No. On the frontend the plugin does nothing unless a login, XML-RPC or user-listing request is being evaluated. Scans run in the background in small chunks.
-
Does it send data to Stalza?
-
Only if you enable vulnerability intelligence, and then only component names and versions. See “External services” above.
-
Is it compatible with other security plugins?
-
Yes, but running two brute-force limiters can double-count attempts. Disable one.
Сын-пикирлер
There are no reviews for this plugin.
Contributors & Developers
“Stalza Security” is open source software. The following people have contributed to this plugin.
МүчөлөрүTranslate “Stalza Security” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Өзгөртүүлөр
1.0.1
- WordPress.org review prep: declare submitter as contributor; confirm Plugin URI and privacy/terms links on stalza.com.
1.0.0
- First public free release: Integrity (core, plugins, baseline, uploads), Malware heuristics, opt-in Vulnerabilities (fixture until live API), Login Protection (wp-login, XML-RPC, enum), Hardening, Events timeline, weekly Reports, Settings / Dashboard / Scan admin UX.
- Vulnerability intelligence stays off until you opt in; offline fixture never invents matches for patched installs.
- Free zip excludes Premium code paths.
0.1.1
- Pre-release development builds (Events through Reports modules).
0.1.0
- Initial scaffold.
