FreelanceBo Sentra Control
FreelanceBo Sentra Control is a comprehensive WordPress security plugin that connects your site to the Sentra central console, providing enterprise-grade protection. Features Web Application Firewall (WAF) – Block malicious requests, SQL injection, XSS, and other common attacks Malware Scanner – Scan WordPress core files, themes, and plugins for known malware signatures Vulnerability Scanner – Check installed plugins and themes against known vulnerability databases Brute Force Protection – Limit login attempts and block attackers automatically File Integrity Monitoring – Detect unauthorized changes to WordPress core files IP Blocklist – Manage blocked IPs manually or automatically based on threat detection Security Events Log – Track all security events with detailed logging Central Console – Manage multiple WordPress sites from a single dashboard How It Works Install and activate the plugin on your WordPress site Connect to your Sentra central console by entering the server URL and API key in Settings The plugin automatically starts monitoring your site and reporting to the console View scan results, manage firewall rules, and review security events from either the WordPress admin panel or the central console Requirements WordPress 5.8 or higher PHP 7.4 or higher A Sentra central console account (available at freelancebo.it) External Services This plugin relies on the following external services: FreelanceBo Sentra Control Console This plugin connects to a self-hosted FreelanceBo Sentra Control central console for centralized security monitoring and management. This connection is essential for the plugin to function. What data is sent: * Site URL, WordPress version, PHP version, and installed plugins/themes list (during heartbeat and scans) * Security events (firewall blocks, failed login attempts, malware detections, file integrity changes) * Scan results (malware scan, vulnerability scan, integrity scan findings) When data is sent: * On plugin activation and periodically via heartbeat (every 5 minutes) * When security events occur (login attempts, firewall blocks) * When scans are triggered (manually or via scheduled cron) * When the admin manages firewall rules, blocklists, or settings Service provider: FreelanceBo Group S.r.l.s., Bologna, Italy * Service URL: https://sentra.freelancebo.it * Terms of Service: https://sentra.freelancebo.it/terms * Privacy Policy: https://sentra.freelancebo.it/privacy The console server URL is configurable by the user in the plugin settings. All data is transmitted over HTTPS. Data is stored on EU-based servers in compliance with GDPR. WordPress.org API The vulnerability scanner module uses the official WordPress.org API to retrieve information about installed plugins, themes, and WordPress core version. This is necessary to check for known vulnerabilities and outdated software. What data is sent: * Plugin slugs, theme slugs, and WordPress core version When data is sent: * When a vulnerability scan is triggered (manually or via scheduled cron) Service provider: WordPress.org * API endpoint: https://api.wordpress.org * Terms of Service: https://wordpress.org/about/privacy/ * Privacy Policy: https://wordpress.org/about/privacy/
Top keywords
- wordpress16×3.49%
- console9×1.96%
- sentra9×1.96%
- freelancebo8×1.74%
- https7×1.53%
- scan7×1.53%
- security7×1.53%
- central6×1.31%
- central console6×1.31%
- data6×1.31%
- org6×1.31%
- wordpress org6×1.31%
Web-Art Login Shield with reCAPTCHA
Web-Art Login Shield with reCAPTCHA protects WordPress authentication, Elementor Login widgets and Elementor Forms. It provides optional Google reCAPTCHA v2/v3, IP lockouts, Advanced login URL protection, IP blocking and REST/XML-RPC protection. It preserves WordPress core authentication logic. No ads, author telemetry or external dashboard. All modules are opt-in and disabled by default. Key Features reCAPTCHA v2/v3 selectable v2 checkbox or v3 score-based verification protection for wp-login.php, Elementor Login and Elementor Forms server-side token, action, score and hostname validation where applicable configurable v3 score threshold one active type at a time configuration verification before activation Elementor support protection for Elementor Login and Elementor Pro Forms native Elementor reCAPTCHA fields are skipped to avoid duplication v2 alignment controls login errors and lockouts remain inside the Login widget dynamic content and Elementor popup support Login Protect per-IP failed-attempt counting and temporary lockouts safe concurrent-request handling active-lockout countdown local security event log with bounded retention optional REST API, Application Password and XML-RPC protection independent operation with or without reCAPTCHA Advanced login URL optional custom login endpoint protection of default login routes while preserving required public actions logout and password-link compatibility emergency wp-config.php recovery constant IP allowlists and blocking separate reCAPTCHA allowlist and Login Protect trusted IP list permanent IP blocking for public site requests with HTTP 403 optional IP | reason notes XML-RPC hardening Optional blocking of: pingback.ping pingback.extensions.getPingbacks system.multicall Security Model Protected flows use fail-closed handling. If an enabled check cannot be completed safely, the request is rejected instead of bypassing protection. Login Protect preserves active lockouts and safely handles concurrent requests. Setting Maximum login attempts or Lockout duration to 0 disables lockout enforcement. All modules remain disabled until enabled. Recovery constants are available in wp-config.php for selected modules. External Services This plugin integrates with Google reCAPTCHA v2 and v3, services provided by Google LLC. reCAPTCHA is disabled by default. Google scripts or verification requests are used only after an administrator enables reCAPTCHA or runs a settings-page verification test. Google’s reCAPTCHA JavaScript (https://www.google.com/recaptcha/api.js) may load on protected wp-login.php requests, pages containing protected Elementor widgets or forms, and the settings page during a verification test. Allowlisted visitors bypass frontend loading where applicable. When reCAPTCHA runs, the visitor’s browser connects directly to Google. Google may process browser, device and interaction information and may set the necessary _GRECAPTCHA cookie under its policies. For server-side verification, the plugin sends the token, configured Secret Key and visitor IP address when available to Google’s siteverify endpoint. It does not include usernames, passwords, email addresses or form contents in that request. The plugin sends no telemetry, analytics or usage data to its author. Google policies: https://policies.google.com/privacy https://policies.google.com/terms Privacy Locally stored security data may include: IP addresses, failed-attempt counts and lockout timestamps a username or email associated with an IP lockout recent events containing an IP address, username or email, source, type and timestamp the latest reCAPTCHA configuration or transport error used for diagnostics permanent IP blocklist entries and optional notes Inactive Login Protect entries become eligible for deletion after seven days. Active lockouts remain until expiry. The event log is limited to 30 entries and 30 days. WordPress privacy tools export or erase records matched to the requested email address or associated account. Unmatched IP-only records remain subject to retention and administrator cleanup. Permanent blocklist entries remain until removed by an administrator. Plugin data can be removed during uninstall when uninstall cleanup is enabled. Legal reCAPTCHA is a trademark of Google LLC. Elementor is a trademark of Elementor Ltd. This plugin is not affiliated with, endorsed by, or sponsored by Google LLC or Elementor Ltd.