=== Ultimate Security – Vulnerability Scanner, 2FA, and Login Protection ===
Contributors: wpultimatesecurity
Tags: security, login security, two factor authentication, vulnerability scanner, brute force
Requires at least: 5.6
Tested up to: 7.1.2
Requires PHP: 7.1
Stable tag: 1.0.40
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Protect your login, block bots and spam, and find unsafe plugins. Free, no coding, set up in 3 minutes.

== Description ==

**Stop hackers and bots from getting into your WordPress site.** Ultimate Security adds two-factor login, blocks password-guessing attacks, stops spam bots and warns you about plugins with known security holes. A setup wizard picks the right settings for your kind of site, so you don't have to understand every option.

[youtube https://www.youtube.com/watch?v=MU7KivId-cE]

= Why site owners choose it =

* **Free, with no account needed.** Install it and it works. No sign-up and no usage tracking.
* **Set up in about 3 minutes.** The wizard asks what kind of site you run, checks it, and shows every change before applying it. You can undo it all later.
* **Try before you enforce.** Test Mode shows what would have been blocked, without blocking anyone.
* **You can't lock yourself out for good.** The wizard gives you an emergency link that switches the plugin off from any browser.

= Protect your login =

**Two-factor login.** After the password, users confirm with a code sent by email or shown in an authenticator app (Google Authenticator, Authy, Microsoft Authenticator and similar). Choose which user roles need it. Works on the WordPress, WooCommerce and Ultimate Member login forms.

[youtube https://www.youtube.com/watch?v=iAEsiGlb_8M]

**Stop password-guessing bots.**

* Lock out anyone who gets the password wrong too many times. Repeat offenders wait longer each time.
* Permanently block addresses you never want to see again.
* An administrator can send a locked-out user a 15-minute recovery link.
* Works behind Cloudflare automatically. Site Health tells you if your host's setup needs one extra step.

[youtube https://www.youtube.com/watch?v=TkKENyFl33Y]

**Hide your login page.** Move `wp-login.php` to a private address so bots can't find it.

**Stronger passwords.**

* Set rules for length, letters, numbers and symbols, or pick a ready-made preset.
* Stop people reusing old passwords, and ask for a new one on first login or after a set time.
* Reject passwords that have appeared in known data leaks. The check never sends the password itself anywhere.

**Control who stays signed in.**

* Limit how many devices one account can use at once.
* Sign people out automatically after a period of inactivity.
* See who is signed in right now, and end any session with one click.

= Block spam and bots on your forms =

Add Google reCAPTCHA or Cloudflare Turnstile to your login, registration, password reset and comment forms, and to WooCommerce login, registration and checkout.

* Check that your keys work before going live.
* If the CAPTCHA service is down, your forms keep working.
* Won't clash with another CAPTCHA plugin on the same form.

[youtube https://www.youtube.com/watch?v=_9oKeDq2ZpQ]

= Find security problems before hackers do =

**Vulnerability scanner.** Checks WordPress, your plugins and your themes against a database of known security holes, and emails you when it finds one. It works without an API key; WPScan or Patchstack keys add extra coverage.

* Runs on a schedule in the background.
* Flags plugins that haven't been updated in a long time.
* Results show in the dashboard, Site Health and your plugins list.

[youtube https://www.youtube.com/watch?v=SsV6Dwn9tbY]

**Security score.** One number that tells you how well protected your site is, and which fix to do next.

**File check.** Compares your WordPress core files with the official copies, so changed or added files stand out.

**Safer updates.** Choose when WordPress, plugins and themes update automatically. Set update days and quiet periods, delay updates by a few days, and get an email when something changes.

= Advanced protection =

**Cloudflare firewall rules.** If your site uses Cloudflare, connect your account and turn on ready-made rules from wp-admin: let good bots through, block bad crawlers and risky traffic, and block attacks on known WordPress flaws before you've had a chance to update. You can preview every rule before it goes live.

[youtube https://www.youtube.com/watch?v=W2v08QaSCl4]

**Security keys (salts).** Change the secret keys in `wp-config.php` on demand or on a schedule, which signs everyone out and makes stolen login cookies useless. You get a warning before a scheduled change, and can restore a previous set.

= Test Mode =

Turn on your protections without blocking anyone, and review a log of what would have been blocked. Choose which user roles it covers. Visitors who aren't signed in are still held to the login limit, and Test Mode switches itself off after seven days, so a forgotten test never leaves your site unprotected.

= Moving from another plugin =

* Import your two-factor and login settings from Wordfence Login Security. Preview it first and undo it if you change your mind.
* Copy your settings to another site, or keep a backup, as a file.
* Detects WooCommerce, Ultimate Member, page builders, form, caching and SEO plugins, and warns you if another security plugin is already doing the same job.

= Privacy =

No usage tracking. The plugin contacts an outside service only when you switch on a feature that needs one, and each is listed under External Services below.

= For developers =

    wp ultimate-security template list
    wp ultimate-security template apply <template> [--dry-run]
    wp ultimate-security template undo
    wp ultimate-security export [--file=<path>]
    wp ultimate-security import <file> [--dry-run]
    wp ultimate-security status
    wp ultimate-security unlock <user> | --ip=<address> | --all
    wp ultimate-security 2fa disable <user>
    wp ultimate-security captcha off
    wp ultimate-security login-url reset

= Video guides =

* [Set up an authenticator app](https://www.youtube.com/watch?v=2hu-4C4RsqE)
* [Two-factor login by email](https://www.youtube.com/watch?v=oXF1IWAISTc)
* [Hide your login page](https://www.youtube.com/watch?v=O-h6rVUPSw4)
* [Set strong password rules](https://www.youtube.com/watch?v=2mTDSrdpMI0)
* [Limit login sessions](https://www.youtube.com/watch?v=qGdDc_loPyM)
* [Manage plugin and theme updates](https://www.youtube.com/watch?v=mlT0zbGP_wc)
* [Change your security keys after a breach](https://www.youtube.com/watch?v=9m85pe8JX8Q)
* [Spot changed WordPress files](https://www.youtube.com/watch?v=dOzK9pDmEZI)
* [Understand Site Health reports](https://www.youtube.com/watch?v=7h7eMOUucVA)
* [Dashboard walkthrough](https://www.youtube.com/watch?v=8UaUn7rgh6g)
* [Move your Wordfence two-factor settings](https://www.youtube.com/watch?v=6sw8FNnbTPU)

= Learn more =

* [Website](https://www.wpultimatesecurity.com) — features and articles.
* [Documentation](https://docs.wpultimatesecurity.com/) — setup guides, troubleshooting and how-tos.
* [YouTube](https://www.youtube.com/@wpultimatesecurity) — all video guides.

== Installation ==

**Requirements:** WordPress 5.6+ and PHP 7.1+. HTTPS is strongly recommended for 2FA and secure sessions.

= Install from your dashboard =

1. In WordPress, go to **Plugins → Add New** and search for "wpultimatesecurity".
2. Click **Install Now**, then **Activate**.
3. Follow the **Security Wizard** that appears — it scans your site, recommends settings, and shows you every change before applying it.

= Install manually =

1. Download the plugin ZIP.
2. Go to **Plugins → Add New → Upload Plugin**, choose the ZIP, and click **Install Now**.
3. Click **Activate**, then follow the Security Wizard.

Or with WP-CLI: `wp plugin install ultimate-security --activate`

= Your first 3 minutes =

1. Run the **Security Wizard** and apply the template that matches your site.
2. Save the **emergency link** the wizard shows you somewhere safe. It gets you back in if you ever lock yourself out.
3. Turn on **two-factor login** for every administrator.

== Frequently Asked Questions ==

= I locked myself out. How do I get back in? =
Open the **emergency link** the setup wizard gave you. It switches the plugin off so you can log in and fix the setting. If you didn't save it, ask your host to rename the folder `/wp-content/plugins/ultimate-security`, or run `wp plugin deactivate ultimate-security` over SSH.

= Will this slow down my site? =
No. Checks run only when someone logs in or submits a form, not on every page view. Scans run in the background on a schedule.

= Do I need any technical knowledge? =
No. The setup wizard picks settings for your kind of site and shows every change before applying it. You can undo all of it later.

= What is Test Mode? =
A safe way to try your settings. Your protections run, but nobody is blocked; instead you get a log of what would have been blocked. Once you are happy, switch it off to enforce the rules. It turns itself off after seven days, so a forgotten test never leaves your site unprotected.

= Can I undo what the wizard changed? =
Yes. The wizard shows every change before applying it, and you can undo them all later. Changes you made yourself afterwards are kept.

= Is it really free? =
Yes. Everything described on this page is included, with no account, trial or time limit.

= Do I need an API key for vulnerability scanning? =
No. The scanner works straight away with the free WPVulnerability database. WPScan and Patchstack keys are optional and only add extra coverage.

= Does it work with WooCommerce? =
Yes. CAPTCHA can protect the WooCommerce login, registration, password reset and checkout forms, two-factor login works on the WooCommerce login form, and the wizard has a WooCommerce template.

= Do I need a Cloudflare account? =
Only for the Cloudflare firewall rules. Every other feature works without one.

= I use Cloudflare or another CDN or proxy. Do I need to do anything? =
For Cloudflare, no: it is recognised automatically. For any other proxy or load balancer, add its address under Brute-force protection → Trusted proxies. Until you do, the plugin avoids locking out everyone at once, and Site Health tells you what to add.

= CAPTCHA is blocking every login. How do I recover? =
Add `define( 'ULTIMATE_SECURITY_DISABLE_CAPTCHA', true );` to `wp-config.php` to switch CAPTCHA off, log in, re-enter your Site Key and Secret Key, then remove the line. To turn off just one provider, use `ULTIMATE_SECURITY_DISABLE_TURNSTILE` or `ULTIMATE_SECURITY_DISABLE_RECAPTCHA`. Over SSH, `wp ultimate-security captcha off` does the same. Site Health warns you when a key stops working.

= Will it conflict with other security or CAPTCHA plugins? =
It can if two plugins do the same job. Use one plugin per job (one for two-factor, one for CAPTCHA, one for login limits) and switch the overlapping feature off in the other. Ultimate Security warns you when it spots an overlap.

= I already use another security plugin. Can I bring my settings across? =
You can import two-factor and login settings from Wordfence Login Security. You see exactly what will come across first, and can undo the import afterwards.

= Does the custom login URL work with caching and CDNs? =
Yes. Make sure your caching plugin doesn't cache the login page; most skip login and admin pages automatically.

= Does it work with Redis or Memcached? =
Yes. Give the cache enough memory so it doesn't drop entries early, or a lockout can end sooner than you set.

= Does it work on WordPress Multisite? =
It runs on Multisite, with settings per site. It has been tested less there than on single sites, so try it on a staging network first.

= Does the plugin track me or phone home? =
No. There is no usage tracking. It contacts an outside service only when you use a feature that needs one, and each is listed under External Services below.

= What does the plugin store about my visitors? =
IP addresses and browser details are kept in the session log so you can review sign-ins. Test Mode keeps its own log of what it would have blocked. Everything stays in your own database.

= Is it GDPR-friendly? =
Your data stays on your own server. Outside calls are limited to the services listed under External Services, and only for features you turn on.

= What happens to my data when I uninstall? =
By default your settings are kept, in case you reinstall. To remove everything, turn on "delete plugin data" in the plugin's advanced settings before uninstalling.

= How do I get support? =
Ask in the plugin's support forum on WordPress.org, or visit https://www.wpultimatesecurity.com.

== Screenshots ==

1. The dashboard tells you in plain words how safe your site is and what to fix next.
2. Answer a few questions and the setup wizard secures your site. You see every change first and can undo it later.
3. Stop bots that guess passwords. Repeat offenders are locked out for longer.
4. Test Mode shows what would have been blocked, without blocking anyone.
5. Add a second step to login with an email code or an authenticator app.
6. Hide your login page and require strong passwords.
7. Stop spam bots on your login, comment and WooCommerce forms with reCAPTCHA or Cloudflare Turnstile.
8. Find plugins, themes and WordPress versions with known security holes, automatically.
9. Turn on ready-made Cloudflare firewall rules without writing any code.
10. See who is signed in right now and sign anyone out with one click.
11. Switch each feature on or off. Your site stays fast.
12. Bring your settings over from Wordfence Login Security, or copy them to another site.

== External Services ==

This plugin connects to the following third-party services, and only when you use the related feature:

= Google reCAPTCHA =
* When: reCAPTCHA protection is enabled. The reCAPTCHA script is then loaded in your visitors' browsers on the protected forms.
* Data sent: the visitor's reCAPTCHA response token, your site secret key, and the visitor's IP address for verification.
* Endpoints: https://www.google.com/recaptcha/api.js (browser script, with a preconnect to https://www.gstatic.com) and https://www.google.com/recaptcha/api/siteverify (server-side verification).
* Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy

= Cloudflare Turnstile =
* When: Cloudflare Turnstile protection is enabled. The Turnstile script is then loaded in your visitors' browsers on the protected forms.
* Data sent: the visitor's Turnstile response token, your site secret key, and the visitor's IP address for verification.
* Endpoints: https://challenges.cloudflare.com/turnstile/v0/api.js (browser script) and https://challenges.cloudflare.com/turnstile/v0/siteverify (server-side verification).
* Terms: https://www.cloudflare.com/website-terms/ — Privacy: https://www.cloudflare.com/privacypolicy/

= WPVulnerability =
* When: the Vulnerability Scanner runs. This is the default vulnerability database and requires no API key.
* Data sent: your WordPress version and the slugs of your installed plugins and themes.
* Endpoint: https://www.wpvulnerability.net/
* Privacy: https://www.wpvulnerability.net/

= WPScan =
* When: the Vulnerability Scanner runs and you have configured a WPScan API key.
* Data sent: your WPScan API key, your WordPress version, and the slugs of your installed plugins and themes.
* Endpoint: https://wpscan.com/api/v3/
* Terms: https://wpscan.com/terms-of-service/ — Privacy: https://wpscan.com/privacy-policy/

= Patchstack =
* When: the Vulnerability Scanner runs and you have configured a Patchstack API key.
* Data sent: your Patchstack API key, your WordPress version, and the slugs of your installed plugins and themes.
* Endpoint: https://patchstack.com/database/api/v2/
* Terms: https://patchstack.com/terms-of-service/ — Privacy: https://patchstack.com/privacy-policy/

= WordPress.org Plugin and Theme Information API =
* When: the Vulnerability Scanner checks whether an extension has been abandoned, and when the Update Manager gathers update information.
* Data sent: the slugs of your installed plugins and themes (no user data).
* Endpoints: https://api.wordpress.org/plugins/info/1.2/ and https://api.wordpress.org/themes/info/1.2/
* Privacy: https://wordpress.org/about/privacy/

= WordPress.org Core Version Check =
* When: the Update Manager checks for available WordPress core updates.
* Data sent: a standard WordPress core version-check request (no user data).
* Endpoint: https://api.wordpress.org/core/version-check/1.7/
* Privacy: https://wordpress.org/about/privacy/

= WordPress.org Core Checksums =
* When: you run the WordPress core file-integrity check.
* Data sent: your WordPress version and locale, in order to retrieve the official file checksums for comparison.
* Endpoint: https://api.wordpress.org/core/checksums/1.0/
* Privacy: https://wordpress.org/about/privacy/

= WordPress.org Secret-Key (Salt) API =
* When: you rotate WordPress security keys and salts, on demand or on a schedule.
* Data sent: a request for randomly generated salt strings (no site or user data).
* Endpoint: https://api.wordpress.org/secret-key/1.1/salt/
* Privacy: https://wordpress.org/about/privacy/

= Cloudflare API =
* When: you connect Cloudflare or preview, deploy, remove or analyse WAF rules.
* Data sent: your Cloudflare credentials or API token, the selected zone and rule data, and the API requests needed for verification, deployment and analytics.
* Endpoint: https://api.cloudflare.com/client/v4/
* Terms: https://www.cloudflare.com/website-terms/ — Privacy: https://www.cloudflare.com/privacypolicy/

= Have I Been Pwned (Pwned Passwords) =
* When: the "refuse compromised passwords" password-policy option is enabled and a password is set or changed.
* Data sent: the first 5 characters of the SHA-1 hash of the password (a k-anonymity range query). The password itself is never sent.
* Endpoint: https://api.pwnedpasswords.com/range/
* Privacy: https://haveibeenpwned.com/Privacy

= Feedback and support email =
* When: only when an administrator explicitly submits contact, migration, or deactivation feedback. Choosing "Skip & Deactivate" sends nothing.
* Destination: support@wpultimatesecurity.com, delivered through the site's configured WordPress email service.
* Privacy: https://www.wpultimatesecurity.com/privacy-policy/

== Changelog ==

= 1.0.40 =
* Fix: Test Mode no longer locks out the accounts it covers when they reach the login limit. The attempt is recorded in the Test Mode log instead.
* Fix: On phones, the plugin's menu no longer makes pages scroll sideways or overlap other buttons.
* Improvement: Notifications on the email verification, two-factor and login settings pages now look and behave like the rest of the plugin.
* Improvement: Code optimized, so the plugin is a little lighter.

= 1.0.36 =
This update includes everything since 1.0.29; the versions in between were never released. It strengthens login security, adds new two-factor and lockout controls, fixes a long list of everyday problems and gives the plugin a cleaner, more consistent look. We recommend every site updates.

Security
* Stronger protection for sign-in, two-factor authentication and brute-force limits, following an internal security review. The details are kept private so sites that have not updated yet stay safe.

New
* Choose how many email two-factor codes can be requested every 15 minutes, and how long someone must wait before asking for another (Login → Two-Factor → Email Authentication).
* Set how many wrong two-factor codes are allowed, and how long the lockout lasts, for each method on the profile screen.
* The lockout message on the login page counts down and clears itself when the lockout ends.
* Brute-force protection now works in two stages: a few short lockouts first, then a longer one. You choose how many short lockouts come first, and you can switch the longer stage off.
* Site Health tells you when your site is behind Cloudflare but real visitor addresses are not reaching WordPress.
* On your first visit, a "Setting up your dashboard" window shows each check as it finishes instead of empty cards. The results are saved, so the dashboard opens with real numbers next time.

Improved
* A fresh, consistent look on every screen, including the setup wizard and the two-factor section on your profile page.
* Dark mode now covers every screen.
* Text is a little larger, and text boxes, dropdowns and switches have an outline you can actually see.
* Severity colours match everywhere: red for critical, amber for high.
* Settings pages show the page name above the form, like the dashboard.
* The unsaved-changes banner tells you which field needs attention.
* The brute-force settings are clearer: they are labelled Initial and Advanced, and the long lockout is set in minutes.
* Update Manager freeze periods need a start and an end date, and dates in the past are rejected.
* The two-factor lockout email is sent once per lockout instead of on every blocked attempt.
* API keys pasted with an extra space or line break are cleaned up when saved.

Changed
* The "Require authorization to reset 2FA" option added in 1.0.29 has been removed. It was off by default. If you had turned it on, users can once again reset their own two-factor method without re-entering their password.

Fixed
* Saving settings is more reliable: switches no longer flip back, a failed save shows the real reason instead of "No internet connection", and page caches are cleared after saving.
* The hidden login page shows the right address after you save.
* Cloudflare Turnstile and Google reCAPTCHA now protect the WooCommerce block checkout as well as the classic one.
* "Update all plugins" and "Update all themes" now run the updates.
* Password-reset links from WordPress or WooCommerce are no longer logged as attacks.
* "Clear all IP lockouts" no longer empties the whole site cache on sites that use Redis or Memcached.
* People on the block list see a clear "blocked" message instead of a countdown.
* Sites behind Cloudflare no longer risk locking out many visitors at once when Cloudflare's visitor-address header is missing.
* Authenticator app setups survive uninstalling and reinstalling the plugin when you choose to keep plugin data.
* Saved API keys stay readable after you change your site's security keys (salts).
* The Patchstack and WPScan vulnerability checks work again and catch more affected versions.
* Test Mode respects the "Always exclude administrators" and "Log simulated blocks" switches, and records the right user.
* Undoing a settings import in Backup & Restore works again, and the Copy button works on sites without HTTPS.
* The reCAPTCHA and Turnstile debug logs load again, the dashboard shows your PHP version straight away, and two messages that could crash on PHP 8 are fixed.

= Earlier versions =
See the full history at https://wpultimatesecurity.com/changelog/

== Upgrade Notice ==

= 1.0.36 =
Security and reliability update that includes everything since 1.0.29. Update as soon as you can. Your settings are kept.

= 1.0.29 =
Includes everything since 1.0.28; the internal builds in between never shipped. Security review fixes, plus lockout protection for sites behind a proxy or with a wrong CAPTCHA key. Update promptly.

= 1.0.28 =
Includes everything from 1.0.27, which was never released. Security hardening for bot protection and for what admin screens send to the browser, plus much faster admin pages. Update as soon as you can.

= 1.0.26 =
Settings and log screens load faster, old log rows are pruned after 90 days, and the plugin now runs on MariaDB and the SQLite used by WordPress Playground. No action needed after updating.
