BaseCloud Shield
BaseCloud Shield is a lightweight yet powerful security plugin that enforces Two-Factor Authentication (2FA) on your WordPress login page. Unlike other bloat-heavy plugins, BaseCloud Shield focuses on reliability and flexibility in OTP delivery. Key Features: Plug & Play: Works immediately using standard WordPress email delivery. Multi-Recipient System: Send OTPs to the logging-in user, a manager email, or selected users. Multi-Channel Delivery: Choose multiple delivery methods simultaneously (Email, SendGrid, WhatsApp, SMS, Webhook). WhatsApp Integration: Send OTPs directly via WhatsApp using Twilio API. SMS Integration: Deliver OTPs via SMS using Twilio API. SendGrid API V3: Native integration for high-deliverability emails. Webhook Support: Connect to custom webhooks for advanced automation flows. Secure OTPs: 6-digit one-time passwords that expire automatically. Browser Trust: “Remember this device” functionality to reduce friction for authorized users. Advanced Attack Protection (v1.4.2): Credential stuffing detection, progressive delays, username enumeration protection. External Services This plugin may connect to external third-party services depending on your configuration. Below is a detailed explanation of what services are used, what data is sent, and when: SendGrid Email API (Optional) If you select “SendGrid API” as your delivery method in the plugin settings, this plugin will send data to SendGrid’s email service to deliver one-time password (OTP) codes. Service: SendGrid by Twilio What it’s used for: Sending two-factor authentication codes via email with improved deliverability When data is sent: Every time a user attempts to log in and 2FA is enabled Data sent: Recipient email address (user’s email or manager email if configured) Sender email address (configured in plugin settings) Site name Username attempting to log in 6-digit one-time password code Email subject and HTML body API Endpoint: https://api.sendgrid.com/v3/mail/send Terms of Service: https://www.twilio.com/legal/tos Privacy Policy: https://www.twilio.com/legal/privacy Important: You must have a SendGrid account and API key to use this feature. You are responsible for complying with SendGrid’s terms of service and ensuring proper data handling practices. Twilio API for WhatsApp & SMS (Optional) If you select “WhatsApp” or “SMS” as delivery methods, the plugin will send data to Twilio’s API to deliver one-time password codes. Service: Twilio What it’s used for: Sending two-factor authentication codes via WhatsApp and/or SMS When data is sent: Every time a user attempts to log in and 2FA is enabled with WhatsApp/SMS selected Data sent: Recipient phone number (from user meta field ‘billing_phone’) Sender phone number (WhatsApp number or SMS number configured in settings) Site name Username attempting to log in 6-digit one-time password code Message body API Endpoint: https://api.twilio.com/2010-04-01/Accounts/{AccountSid}/Messages.json Terms of Service: https://www.twilio.com/legal/tos Privacy Policy: https://www.twilio.com/legal/privacy Important: You must have a Twilio account with WhatsApp and/or SMS capabilities enabled. Phone numbers must be stored in user meta (field: ‘billing_phone’). You are responsible for complying with Twilio’s terms of service. Custom Webhook (Optional) If you select “Webhook” as a delivery method, the plugin will send login notification data to a webhook URL you configure. Service: Custom webhook endpoint (configured by you) What it’s used for: Sending login notifications to external systems for custom processing When data is sent: Every time a user attempts to log in and 2FA is enabled Data sent: Site name Username attempting to log in User email address 6-digit one-time password code Recipient information array Timestamp of login attempt Endpoint: User-configured webhook URL Important: When using the webhook option, you are responsible for the security and privacy compliance of the endpoint you configure. Ensure your webhook endpoint uses HTTPS and follows proper data protection practices. Standard WordPress Email (Default) By default, this plugin uses WordPress’s built-in wp_mail() function, which does not involve any external services unless your WordPress installation is configured to use a third-party SMTP service.
Top keywords
- email13×2.00%
- twilio13×2.00%
- api12×1.85%
- data12×1.85%
- sendgrid9×1.39%
- service9×1.39%
- sms9×1.39%
- webhook9×1.39%
- whatsapp9×1.39%
- user8×1.23%
- delivery7×1.08%
- https7×1.08%
Iron Security – WordPress Security Plugin
Iron Security is your WordPress security bodyguard. It shields your site from brute force attacks, unauthorized admin access, file injections, and common exploits like XML-RPC and REST API abuse. Whether you’re a solo creator or managing client sites, Iron Security delivers essential protection without the performance hit. 🔒 Don’t wait until your site is compromised. Secure it now — effortlessly. Iron Security includes real-time brute-force protection, custom login URLs, HTTP headers, session control, malware upload prevention, and much more. All from a single, easy-to-use plugin dashboard. Protects Against: – 🔐 Brute Force Attacks (Limit login attempts, 2FA) – 👮 Unauthorized Admin Access (Custom login URL, admin limit) – 👤 User Enumeration – 🎯 Admin Account Targeting (Admin ID & username protection) – 💣 XML-RPC & REST API Exploits – 🛡️ Code Injection & PHP Malware Uploads – 📂 Direct Access to Sensitive Files – 📛 MIME Sniffing & Content-Type Exploits – 🖼️ Clickjacking – 🧬 Cross-Site Scripting (XSS) – 🌐 Referrer Leakage 🔐 Key Features 🛠 General Hardening Disable XML-RPC & REST API Hide WordPress & WooCommerce versions Block AI & scraping bots Disable file editor Enable plugin & core auto-updates 🔍 Security Logs View detailed logs of login attempts and alerts Filter logs by IP, message, or date Audit suspicious activity easily 🔑 Login & Authentication Custom login/admin URL Limit login attempts with lockouts Session timeout for idle users Limit number of administrators Block user enumeration Change default Admin ID and Username Enable 2FA (Google Authenticator) 🗂 Files & Directory Protection Block PHP file uploads Prevent direct access to core/system files 📦 HTTP Security Headers X-Content-Type-Options X-Frame-Options X-XSS-Protection Strict-Transport-Security Referrer-Policy Content-Security-Policy Permissions-Policy Iron Security is built for creators who care about speed, simplicity, and security. If you’re not securing your site, you’re risking everything. Credits Developed and maintained by WPIron License This plugin is licensed under the GPLv2 or later.
Top keywords
- security8×2.89%
- admin7×2.53%
- login7×2.53%
- access4×1.44%