FreelanceBo Sentra Control
FreelanceBo Sentra Control is a comprehensive WordPress security plugin that connects your site to the Sentra central console, providing enterprise-grade protection. Features Web Application Firewall (WAF) – Block malicious requests, SQL injection, XSS, and other common attacks Malware Scanner – Scan WordPress core files, themes, and plugins for known malware signatures Vulnerability Scanner – Check installed plugins and themes against known vulnerability databases Brute Force Protection – Limit login attempts and block attackers automatically File Integrity Monitoring – Detect unauthorized changes to WordPress core files IP Blocklist – Manage blocked IPs manually or automatically based on threat detection Security Events Log – Track all security events with detailed logging Central Console – Manage multiple WordPress sites from a single dashboard How It Works Install and activate the plugin on your WordPress site Connect to your Sentra central console by entering the server URL and API key in Settings The plugin automatically starts monitoring your site and reporting to the console View scan results, manage firewall rules, and review security events from either the WordPress admin panel or the central console Requirements WordPress 5.8 or higher PHP 7.4 or higher A Sentra central console account (available at freelancebo.it) External Services This plugin relies on the following external services: FreelanceBo Sentra Control Console This plugin connects to a self-hosted FreelanceBo Sentra Control central console for centralized security monitoring and management. This connection is essential for the plugin to function. What data is sent: * Site URL, WordPress version, PHP version, and installed plugins/themes list (during heartbeat and scans) * Security events (firewall blocks, failed login attempts, malware detections, file integrity changes) * Scan results (malware scan, vulnerability scan, integrity scan findings) When data is sent: * On plugin activation and periodically via heartbeat (every 5 minutes) * When security events occur (login attempts, firewall blocks) * When scans are triggered (manually or via scheduled cron) * When the admin manages firewall rules, blocklists, or settings Service provider: FreelanceBo Group S.r.l.s., Bologna, Italy * Service URL: https://sentra.freelancebo.it * Terms of Service: https://sentra.freelancebo.it/terms * Privacy Policy: https://sentra.freelancebo.it/privacy The console server URL is configurable by the user in the plugin settings. All data is transmitted over HTTPS. Data is stored on EU-based servers in compliance with GDPR. WordPress.org API The vulnerability scanner module uses the official WordPress.org API to retrieve information about installed plugins, themes, and WordPress core version. This is necessary to check for known vulnerabilities and outdated software. What data is sent: * Plugin slugs, theme slugs, and WordPress core version When data is sent: * When a vulnerability scan is triggered (manually or via scheduled cron) Service provider: WordPress.org * API endpoint: https://api.wordpress.org * Terms of Service: https://wordpress.org/about/privacy/ * Privacy Policy: https://wordpress.org/about/privacy/
Top keywords
- wordpress16×3.49%
- console9×1.96%
- sentra9×1.96%
- freelancebo8×1.74%
- https7×1.53%
- scan7×1.53%
- security7×1.53%
- central6×1.31%
- central console6×1.31%
- data6×1.31%
- org6×1.31%
- wordpress org6×1.31%
VulnTitan – Malware Scanner, Vulnerability Scanner & Security
VulnTitan is a WordPress security plugin focused on malware scanning and removal, vulnerability detection, file integrity monitoring, firewall protection, and anti-spam controls for comments and supported forms. Instantly scan your WordPress site for malware infections and known vulnerabilities, review detailed results, and clean or remove malware safely using a guided fix workflow with automatic backups. VulnTitan focuses on practical protection: vulnerability detection, malware scanning and removal, file integrity monitoring, firewall protection, anti-spam defense for comments and supported forms, hidden custom login access, and a weekly executive security digest every 7 days. Malware Scanner The WordPress malware scanner inspects your site files for suspicious code patterns and known malicious signatures. Detect malware infections in core, plugins, and themes Review problematic files with contextual code preview Safe-fix workflow with automatic backups Clear severity indicators and actionable recommendations Vulnerability Scanner The vulnerability scanner checks your installed WordPress core, plugins, and themes against a real-time vulnerability database powered by the VulnTitan API. Detect vulnerable plugins and themes Identify outdated components with known security risks Real-time vulnerability intelligence Clear risk explanations and remediation guidance File Integrity Scanner Monitor unauthorized file changes and unexpected modifications. Baseline comparison for WordPress files Queue-based processing for performance safety Visual status legends for fast review Actionable next steps for suspicious changes Firewall, Login, Comment & Form Protection VulnTitan includes firewall, WAF, login protection, and anti-spam controls to block common attack patterns and protect WordPress login, comment, and supported form submission surfaces. Early MU-plugin runtime request guards SQL injection (SQLi) payload protection Command injection detection Suspicious path traversal blocking Endpoint whitelisting controls Login lockout protection against brute-force attacks TOTP-based two-factor authentication for selected roles Recovery codes and trusted-device support for enrolled accounts CAPTCHA protection for WordPress login/registration, WooCommerce login/registration, WordPress lost-password, and optional comment forms XML-RPC allow, disable, or rate-limit policy controls with IP allowlisting Weak-password blocking during profile updates, password resets, and compatible registrations Comment Shield with honeypot, signed tokens, submit-time validation, duplicate detection, guest link limits, IP rate limiting, and moderation-aware logging Form Shield for Contact Form 7 and Fluent Forms with honeypot, signed submit tokens, link heuristics, repeated-domain detection, and IP rate limiting Form spam blocks are logged into the WAF/live feed with provider-aware source labels for easier review Suspicious comments can be held for moderation or blocked immediately REST comments can enforce signed anti-spam tokens and CAPTCHA when anonymous REST commenting is enabled elsewhere Configurable custom login slug so administrators can use a private login URL instead of the default wp-login.php Default wp-login.php and guest wp-admin access can be hidden behind a 404 response when custom login is enabled Weekly executive security report email with 7-day firewall, login abuse, WAF, form spam, and comment moderation statistics Security-First Architecture Secure storage and cleanup of scan queues and logs Hardened backup handling outside ABSPATH by default Hardened malware and integrity scan actions with stricter capability checks and in-root path validation Adaptive performance tuning for safe large-site scanning WP-CLI Support VulnTitan supports WP-CLI commands for malware, integrity, and vulnerability scans so administrators can run checks from the terminal, scripts, or server automation. wp vulntitan scan malware wp vulntitan scan integrity wp vulntitan scan vulnerability wp vulntitan scan all Optional flags: --scope=plugins, --format=json, --fail-on-findings External services This plugin connects to an external API at https://vulntitan.com/api/vulnerabilities to fetch up-to-date vulnerability data for WordPress core, plugins, and themes. This data is essential for detecting known vulnerabilities during scan operations. When a vulnerability scan is performed, the following data is sent to the VulnTitan API: – The slug and version of each plugin – The slug and version of each theme – The WordPress core version This data is transmitted only during scans initiated by the user or by scheduled scan settings. No personal, user-identifying, or sensitive site data is collected, transmitted, or stored. The external service is provided and operated by VulnTitan.com. Terms of Service: https://vulntitan.com/terms Privacy Policy: https://vulntitan.com/privacy