{"id":376323,"date":"2026-09-29T01:03:09","date_gmt":"2026-09-29T01:03:09","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/stalza-security\/"},"modified":"2026-09-30T06:43:09","modified_gmt":"2026-09-30T06:43:09","slug":"stalza-security","status":"publish","type":"plugin","link":"https:\/\/ky.wordpress.org\/plugins\/stalza-security\/","author":20735312,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Stalza Security","header_author":"Stalza","header_description":"Smart WordPress security without the bloat. File integrity, malware detection, vulnerability intelligence, brute-force protection and hardening \u2014 explained, prioritized, actionable.","assets_banners_color":"70969b","last_updated":"2026-09-30 06:43:09","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/stalza.com\/stalza-security","header_author_uri":"https:\/\/stalza.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":85,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"fuadkm","date":"2026-09-29 01:02:42","revision":3718101},"1.1.0":{"tag":"1.1.0","author":"fuadkm","date":"2026-09-30 06:43:09","revision":3720469}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3718101,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3718101,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3718101,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3718101,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1","1.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Dashboard","2":"Scan results with risk and confidence","3":"Hardening checklist"}},"plugin_section":[],"plugin_tags":[2439,1174,173015,1184,600],"plugin_category":[54],"plugin_contributors":[283307],"plugin_business_model":[],"class_list":["post-376323","plugin","type-plugin","status-publish","hentry","plugin_tags-brute-force","plugin_tags-firewall","plugin_tags-integrity","plugin_tags-malware","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-fuadkm","plugin_committers-fuadkm"],"banners":{"banner":"https:\/\/ps.w.org\/stalza-security\/assets\/banner-772x250.jpg?rev=3718101","banner_2x":"https:\/\/ps.w.org\/stalza-security\/assets\/banner-1544x500.jpg?rev=3718101","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/stalza-security\/assets\/icon-128x128.png?rev=3718101","icon_2x":"https:\/\/ps.w.org\/stalza-security\/assets\/icon-256x256.png?rev=3718101","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Stalza Security protects your site without weighing it down. Instead of hundreds of generic warnings, it tells you <strong>what changed, why it matters, how confident the detection is, and what to do<\/strong>.<\/p>\n\n<p><strong>Detect \u2192 Correlate \u2192 Assess Risk \u2192 Explain \u2192 Protect \u2192 Verify<\/strong><\/p>\n\n<h4>Free features<\/h4>\n\n<ul>\n<li><strong>File &amp; WordPress integrity<\/strong> \u2014 core, plugin and theme checksums plus a local baseline for everything else.<\/li>\n<li><strong>Malware detection<\/strong> \u2014 heuristic analysis of PHP, JS and .htaccess files; no signature database needed.<\/li>\n<li><strong>Vulnerability detection<\/strong> \u2014 daily check of your installed components against known advisories (opt-in).<\/li>\n<li><strong>Brute-force protection<\/strong> \u2014 login, XML-RPC and REST user-enumeration limits with escalating lockouts.<\/li>\n<li><strong>Security hardening<\/strong> \u2014 one-click fixes and clear advisories for common misconfigurations.<\/li>\n<li><strong>Security events &amp; reports<\/strong> \u2014 a single timeline of what happened, with a weekly digest.<\/li>\n<\/ul>\n\n<h4>Designed to be light<\/h4>\n\n<ul>\n<li>Zero frontend queries unless a login attempt is being evaluated.<\/li>\n<li>Scans run in small resumable chunks with CPU and memory budgets.<\/li>\n<li>No autoloaded option bigger than 50 KB. No bundled React runtime \u2014 uses the one WordPress already ships.<\/li>\n<\/ul>\n\n<h4>Premium<\/h4>\n\n<p><a href=\"https:\/\/stalza.com\/stalza-security\">Stalza Security Pro<\/a> extends the same engine with cloud threat intelligence, real-time protection, behavioral analysis, automatic remediation, IP reputation and advanced alerting.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin works fully offline by default. <strong>Nothing is sent anywhere until you opt in.<\/strong><\/p>\n\n<p>If you enable <em>Vulnerability intelligence<\/em> in Settings, the plugin sends the slugs and version numbers of your installed WordPress core, plugins and themes, plus your site URL, to <code>https:\/\/stalza.com\/api\/stalza-security\/v1\/vulnerabilities\/match<\/code> once per day to receive matching security advisories. No user data, content or visitor information is included. See the <a href=\"https:\/\/stalza.com\/privacy\">Stalza privacy policy<\/a> and <a href=\"https:\/\/stalza.com\/terms\">terms<\/a>.<\/p>\n\n<p>Integrity checks fetch official checksums from WordPress.org (<code>api.wordpress.org<\/code>, <code>downloads.wordpress.org<\/code>), the same service WordPress core uses for updates.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/stalza-security\/<\/code> or install it from the Plugins screen.<\/li>\n<li>Activate it.<\/li>\n<li>Go to <strong>Stalza Security<\/strong> in the admin menu and run your first scan.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20slow%20down%20my%20site%3F\"><h3>Does it slow down my site?<\/h3><\/dt>\n<dd><p>No. On the frontend the plugin does nothing unless a login, XML-RPC or user-listing request is being evaluated. Scans run in the background in small chunks.<\/p><\/dd>\n<dt id=\"does%20it%20send%20data%20to%20stalza%3F\"><h3>Does it send data to Stalza?<\/h3><\/dt>\n<dd><p>Only if you enable vulnerability intelligence, and then only component names and versions. See \"External services\" above.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20other%20security%20plugins%3F\"><h3>Is it compatible with other security plugins?<\/h3><\/dt>\n<dd><p>Yes, but running two brute-force limiters can double-count attempts. Disable one.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<p>Features:<\/p>\n\n<ul>\n<li>login: add free-tier two-factor authentication<\/li>\n<li>login: free-tier two-factor authentication<\/li>\n<li>vuln: allow filtering the live vulnerability match URL<\/li>\n<li>vuln: live match URL filter + fixture fallback docs<\/li>\n<\/ul>\n\n<p>Bug Fixes:<\/p>\n\n<ul>\n<li>ci: satisfy prettier and PHPCS for live-vuln merge<\/li>\n<li>ci: stylelint empty-line rules in style.scss<\/li>\n<li>vuln: use offline label for fixture source<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<p>Fixes:<\/p>\n\n<ul>\n<li>WordPress.org review prep: declare submitter as contributor; confirm Plugin URI and privacy\/terms links on stalza.com<\/li>\n<li>Admin list tables use shared DataTable + server pagination<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<p>Features:<\/p>\n\n<ul>\n<li>admin: Settings, Dashboard, and Scan UX for v1 launch (Epic E7) (#9)<\/li>\n<li>integrity: pause\/resume\/cancel scans; skip Hardening-removed core docs noise<\/li>\n<li>malware: heuristic scan job + Scan-tab findings triage<\/li>\n<li>vuln: opt-in match client with fixture fallback filtered to installed inventory<\/li>\n<li>reports: weekly digest builder and cron<\/li>\n<li>Free modules: Integrity M2, Login M2, Hardening, Malware, Vulnerabilities, Reports, Events<\/li>\n<\/ul>\n\n<p>Bug Fixes:<\/p>\n\n<ul>\n<li>vuln: do not surface fixture advisories for patched\/absent components<\/li>\n<li>integrity: silent-reseed own plugin baseline on version bump; keep same-version tamper<\/li>\n<li>admin: hash navigation for TabPanel; Plugin Check ABSPATH on helpers<\/li>\n<li>build: exclude <code>.worktrees<\/code> and agent dirs from release zips<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<p>Features:<\/p>\n\n<ul>\n<li>admin: add Events tab with filters, table, and context drawer<\/li>\n<li>admin: add Login Protection tab with allowlist and unlock<\/li>\n<li>core: add Settings helper for nested plugin options<\/li>\n<li>core: scaffold plugin kernel, admin shell, build pipeline and CI<\/li>\n<li>core: seed login protection settings defaults<\/li>\n<li>events: add Repository, Recorder, and retention Pruner<\/li>\n<li>events: add Severity map and TypeRegistry allowlist<\/li>\n<li>events: register the module, REST list, and upgrade hook after boot<\/li>\n<li>hardening: Epic E3 Hardening module (#2)<\/li>\n<li>integrity: Integrity M2 \u2014 plugins, baseline, uploads, Accept (#4)<\/li>\n<li>integrity: ship M1 Queue, Findings, core scan, REST, and admin tab<\/li>\n<li>login: add Guard for lockout policy and events<\/li>\n<li>login: add lockouts repository with window and escalate helpers<\/li>\n<li>login: add login status, allowlist, and unlock REST endpoints<\/li>\n<li>login: Login Protection M2 \u2014 proxies, enum blocks, editable thresholds (#3)<\/li>\n<li>login: register LoginProtectionModule and login event types<\/li>\n<li>support: add Fs, Hashing, Http, and Budget helpers<\/li>\n<li>support: add Ip helper (REMOTE_ADDR + pack\/unpack)<\/li>\n<\/ul>\n\n<p>Bug Fixes:<\/p>\n\n<ul>\n<li>admin: clear login refresh error after successful retry<\/li>\n<li>admin: separate login unlock errors from list refresh<\/li>\n<li>core: rename reserved-word column scans.cursor to cursor_state<\/li>\n<li>integrity: ignore wp-content paths in core checksum scan<\/li>\n<li>integrity: keep dotted scan types; record deactivate events<\/li>\n<li>login: avoid null lockout row offsets<\/li>\n<li>login: harden lockout persistence<\/li>\n<li>login: ignore failures while IP already locked<\/li>\n<\/ul>\n\n<p>Performance:<\/p>\n\n<ul>\n<li>core: autoload db_version option so upgrade check costs no query<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<p>Features:<\/p>\n\n<ul>\n<li>core: plugin kernel, container, module contract, feature flags, schema installer<\/li>\n<li>admin: single-page React admin shell with dashboard and status endpoint<\/li>\n<\/ul>\n\n<p>Full history: https:\/\/stalza.com\/docs\/stalza-security\/changelog<\/p>","raw_excerpt":"Smart WordPress security without the bloat: integrity, malware, vulnerability and brute-force protection, explained and prioritized.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/376323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=376323"}],"author":[{"embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/fuadkm"}],"wp:attachment":[{"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=376323"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=376323"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=376323"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=376323"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=376323"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=376323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}