Watchdog Security Lite
Watchdog Security Lite is the free WordPress security edition powered by the Lumiverse Nexus ecosystem. It brings together active request protection, local malware scanning, vulnerability intelligence, official-file integrity checks, login protection and WooCommerce-aware controls in one security-focused dashboard. Watchdog Lite is designed to provide useful protection without turning every unusual request into an attack claim. Detection, observation and enforcement are kept distinct wherever possible so site owners can understand what the plugin actually saw and what it actually restricted. Core security features Traffic Shield Lite – conservative request-abuse protection for suspicious scanning, repeated hostile traffic and selected XML-RPC pressure. Login Guard – login abuse protection with lockout controls designed to avoid treating ordinary mistakes as attacks. Malware Scanner – local PHP/file scanning with high-confidence signatures, changed-file-first routine scanning and MU-plugin coverage. Vulnerability Watch Lite – checks installed WordPress, plugin and theme versions against Nexus vulnerability intelligence and provides severity plus update guidance. Official File Integrity – compares WordPress core and supported WordPress.org components with official checksums or packages. Safe Core Repair – manually restores verified modified or missing WordPress core files after creating a protected restore point. Optional administrator TOTP 2FA – authenticator-app protection and one-time recovery codes, configured separately by each administrator. Security Incident Inbox – groups related security activity into readable incidents. Site Change Watch Lite – records important administrator, plugin, theme and risky file changes. WP-Cron persistence checks – highlights high-confidence suspicious scheduled-task patterns and risky combinations. Watchdog Live Pulse – a real-data visual view of recent traffic, bots and protection activity. It does not invent attack events. Weekly Security Digest – optional once-weekly email summarizing protection activity, scan coverage and important security health signals. Nexus Threat Network Lite – optional shared threat intelligence with selected high-confidence signal contribution and privacy-preserving aggregate security telemetry. WooCommerce-aware protection WooCommerce stores receive cart, wishlist, catalog, checkout, AJAX and crawler traffic that should not all be treated as ordinary page requests. Watchdog Lite includes WooCommerce Bot Cart Guard Lite. When enabled, crawler-claimed and obvious automation may still access public pages while supported cart, wishlist or remove-item mutations are neutralized before they create unwanted shopping state. Normal shoppers, logged-in users and ordinary browser traffic are not handled by this crawler/automation rule. For business sites and stores that need earlier request containment, advanced WooCommerce resource protection, deeper incident investigation, richer Threat Network intelligence and recovery workflows, see Lumiverse Nexus PRO. Optional TOTP two-factor authentication TOTP 2FA is optional and configured separately by each administrator. It protects the standard WordPress administrator login; API, XML-RPC and application-password authentication remain separate controls. Watchdog Lite does not force 2FA after installation, after an update or when Recommended Local Protection is applied. The feature works with standard time-based authenticator applications, stores the secret locally and provides one-time recovery codes. Administrators should keep recovery codes in a secure location. Nexus Threat Network Lite Nexus Threat Network Lite is disabled by default. When an administrator enables Threat Intelligence Lite, the site joins the Nexus Threat Network participation model. While enabled, the site can: receive compact shared threat intelligence; contribute selected, high-confidence security signals used to strengthen network intelligence. Selected verified security signals are a separate part of Threat Network participation and may include the attacking public IP address together with limited security metadata such as event type, rule reference, confidence, request category, aggregated observation count, plugin version and a pseudonymous contributor credential. Disabling Threat Intelligence Lite stops Threat Network participation and discards unsent aggregate telemetry. Confirmed-match blocking remains a separate protection choice. Learn more at Nexus Threat Network. Lite and Nexus PRO Watchdog Security Lite provides practical security foundations for WordPress sites and WooCommerce stores. Lumiverse Nexus PRO adds the broader protection and investigation platform, including Early WAF / pre-WordPress protection, advanced WooCommerce resource defense, deeper Threat Network classifications, Security Twin, Threat Constellation, Incident Replay, Threat Continuum and Rescue Center workflows. Learn more at Lumiverse Nexus PRO. External Services Watchdog Security Lite performs routine malware/file scanning locally. Website files and file contents are not uploaded for routine malware scanning. Lumiverse Nexus services Watchdog Lite may communicate with services under: lumiversenexus.com These services provide malware-signature updates, vulnerability intelligence and Nexus Threat Network functions. Signature and vulnerability intelligence: requests may include normal HTTPS connection information and the public component information needed to retrieve the relevant intelligence. Installed component versions are evaluated locally. Website files, page content, usernames, passwords, customer data and order data are not uploaded for these checks. Threat Network participation: While enabled, selected high-confidence verified security signals may include an attacking public IP address plus limited security metadata such as event type, rule reference, confidence, request category, aggregated observation count, plugin version and a pseudonymous contributor credential. Threat Network registration does not require a customer name, email address, WordPress username, license key or site URL. Service information: Lumiverse Nexus Privacy Notice and Terms of Service.
Top keywords
- threat18×2.26%
- lite17×2.14%
- security17×2.14%
- nexus14×1.76%
- protection14×1.76%
- network13×1.63%
- threat network12×1.51%
- intelligence11×1.38%
- watchdog8×1.01%
- wordpress8×1.01%
- administrator6×0.75%
- lumiverse6×0.75%
Cloud Maestro – WAF Security Suite for Cloudflare
Cloud Maestro brings centralized Cloudflare Web Application Firewall (WAF) controls directly into WordPress. Why would I use a plugin when I can create rules in Cloudflare? If you manage multiple Cloudflare-connected sites, Cloud Maestro is a productivity tool that helps oversee several domains from a central dashboard using WordPress. If you only manage one domain in Cloudflare, you wouldn’t benefit from this plugin. It’s useful for someone managing: – Their own sites and client sites – Multiple businesses – Separate Cloudflare accounts People like using Cloud Maestro because configuring security rules one domain at a time is inefficient and error-prone. It allows you to configure WAF rules once and deploy them consistently across all domains in your Cloudflare account — instantly. The free version supports one Cloudflare account with multiple domains. An optional premium version is available for managing unlimited domains across multiple Cloudflare accounts at once. 🛡️ Why Use Cloud Maestro – WAF Security Suite for Cloudflare? Managing security rules across multiple Cloudflare domains is tedious and time-consuming. This plugin streamlines the process, allowing you to: Deploy in One Click – Apply comprehensive WAF rules to multiple domains simultaneously Save Time – No more manually configuring rules on each domain, one at a time Enterprise Security – Protect against bots, aggressive crawlers, malicious IPs, and common threats Reduce Mistakes – Maintain consistent security rules across domains ✅ Free Standard Features One Cloudflare account Multiple domains One-click WAF rule deployment Centralized Cloudflare controls Secure API credential storage (AES-256-CBC encryption) Plugin updates The free plugin does not require an upgrade. 🔥 What Gets Protected The plugin deploys 3 optimized trusted security rules (prior versions used 5) that work together to protect your sites: Good Bot Allowlist – Ensures legitimate bots (Google, Bing, monitoring tools) can access your site Managed Challenges for Suspicious Traffic – Automatically challenges requests from certain ASNs and non-US traffic Aggressive Crawler Protection – Blocks unauthorized crawlers and bots (Yandex, Semrush, Ahrefs, etc.) VPN & Login Protection – Adds extra challenges for VPN traffic and WordPress login attempts Block Known Threats – Automatically blocks web hosts, malicious IPs, TOR nodes, and attack vectors ✨ Premium Upgrade (Optional) For agencies and professionals managing multiple Cloudflare accounts, a Premium version is available with expanded functionality and tech support. Check out our free trial for these features: Multi-Account Management – Automatically manage domains across ALL your Cloudflare accounts Easy Bot Whitelisting – Built-in checkboxes for 50+ trusted services across 8 categories Custom User Agents – Add your own user agent strings to the Good Bot Rule Custom IP Whitelisting – Add trusted IP addresses to the Goot Bot Rule IP Rules management – View and edit Cloudflare’s IP Rules that block or allow access even before hitting WAF rules (and we are working on connecting to fail2ban and Wordfence blocks) Bulk DNS Management – Search and manage all Cloudflare DNS record types across all domains, bulk migrate exact old/new values with confirmation modals, and convert A records to CNAME with a single action DNS Manager Reliability – Full record visibility for MX/TXT and other record types, cleaner cache warm-up modal flow, and safer bulk migration previews that only list actual matches Priority Support – Get expert help when you need it Advanced Customization – Fine-tune rules to match your exact requirements Multi-Account Management – Centrally manage unlimited domains across all your Cloudflare accounts 📋 Important Information Rule Replacement: This plugin replaces existing custom WAF rules on targeted domains. Make sure to back up any custom rules you want to keep. Compatibility: Works with Cloudflare Free, Pro, and Business plans. Not compatible with Enterprise plans managed by hosting providers. Service Monitoring: These rules might challenge some monitoring or uptime services. Check Cloudflare’s Events log if services stop connecting, and add exceptions as needed.