TrustSig Security
TrustSig Security stops scripted bots and brute-force attacks on WordPress forms and API endpoints. There are no puzzles to solve and no “I am not a robot” checkboxes to tick, and you do not have to sign up for anything before it starts working. What exactly gets checked depends on the protection mode you pick, described below. Why TrustSig Covers the forms that matter out of the box: login, registration, comments, password reset, WooCommerce checkout, BuddyPress signup, Easy Digital Downloads, Elementor Pro forms, WPForms (including the Mesmerize and Materialis contact form), Contact Form 7, SureForms, plus any custom form via a shortcode. Locks out brute-force login attempts after repeated failures. Real visitors never notice it. The browser check runs on its own and finishes in about a second, with no images to click. Three protection modes: Monitor logs and never blocks, Challenge (the default) shows a short interstitial and retries, Enforce blocks outright. Nothing to configure. Activate the plugin and protection is live. The anonymous free tier needs no account. Works with caching plugins, WPML, multisite and most themes, because forms are signed server-side with a per-site secret. A developer API: the PHP helper trustsig_verify(), the REST endpoint /wp-json/trustsig/v1/verify, and filters and actions for custom forms. An optional guard for admin-ajax and the REST API on sites that need it. An optional scan-on-submit mode that runs the browser check only when a visitor actually uses a form, not on every page view. GPLv2, fully open source. How it works TrustSig loads a small browser SDK, signs every rendered form with a per-site secret, and checks submissions against the TrustSig Edge service. A real visitor passes the check in about a second without doing anything. A scripted client that never runs JavaScript produces no token and gets stopped. When a request arrives without a valid token, the plugin does not quietly wave it through. Depending on the mode, it either serves a short “please wait” page that re-verifies the browser and then continues the original request, or blocks it. No account and no API keys are needed; the anonymous free tier is the default. Connecting a TrustSig dashboard account is optional and only adds analytics and higher limits. Protection modes Monitor: verify and log only, never block. Good for a safe rollout. Upgrades also pin existing sites here, so behaviour never changes silently on update. Challenge (default for new installs): a missing or invalid token triggers the interstitial, which then continues or blocks. Enforce: a missing or invalid token is blocked immediately. What it protects Browser forms are covered automatically, no code needed: WordPress core: login, registration, comments, lost and reset password WooCommerce: login, registration, checkout, pay order, lost password BuddyPress: registration Easy Digital Downloads: login, registration Elementor Pro forms WPForms: contact and other forms, on by default (this also covers the Mesmerize and Materialis contact section) Contact Form 7: feedback submissions, on by default, guarded on the REST endpoint CF7 submits to SureForms: form submissions, on by default, guarded on the REST submit-form endpoint Anything else via the site-wide “protect all forms” option, the [trustsig_form] shortcode, or a hidden trustsig-response input On top of that there is an optional brute-force lockout for repeated failed logins, an opt-in guard for admin-ajax and the REST API, and a verification API for developers. For developers PHP: trustsig_verify( array( ‘token’ => $t, ‘action’ => ‘my_form’ ) ) returns pass, fail or challenge. Filters: trustsig_pre_verify, trustsig_result. Action: trustsig_blocked. REST: POST /wp-json/trustsig/v1/verify with { “token”: “…” }. Known limitations XML-RPC (xmlrpc.php) is deliberately out of scope and is not verified. If your site does not use XML-RPC, disable it separately. admin-ajax and the REST API are only guarded when you enable that in Settings. This is on purpose, so third-party integrations do not break the moment you install the plugin. File uploads and AJAX submissions cannot show the interstitial. In Challenge or Enforce mode a missing token on those is blocked. It is never silently allowed. External services This plugin relies on the TrustSig Edge service to decide whether a request comes from a human or an automated client. That verdict cannot be produced locally, so the service is required for the plugin to do its job. Service provider: TrustSig, https://trustsig.eu Remote script loaded in the browser: https://edge.trustsig.eu/trustsig.js loads on pages that contain a protected form, on the login screen, and on the verification interstitial. It runs the non-interactive browser check and produces a verification token. Data sent from the visitor’s browser or your server to https://edge.trustsig.eu/verify: the TrustSig verification token generated by the SDK in the visitor’s browser; your site’s host name (for example example.com) on the anonymous free tier, or the secret key you entered if you connect a dashboard account; as with any HTTPS request, the visitor’s IP address and standard request metadata such as the user agent are visible to the service. When data is sent: when the SDK loads on a protected page, when a protected form is submitted, and once per browser when the optional verified-session cookie is bootstrapped. Data stored locally on your site: TrustSig writes a verification log to your own WordPress database (custom tables) with visitor IP addresses, the action attempted, and the verdict. This log is not sent to TrustSig, and you can clear it at any time under Settings, TrustSig, Tools. By installing and activating this plugin you, the site administrator, consent to this data being sent to TrustSig so that requests can be verified. Inform your own visitors as your local privacy obligations require. Terms of Service: https://trustsig.eu/terms-of-service/ Privacy Policy: https://trustsig.eu/privacy
Top keywords
- trustsig26×2.72%
- form11×1.15%
- browser10×1.04%
- forms9×0.94%
- token9×0.94%
- api7×0.73%
- rest7×0.73%
- verify7×0.73%
- default6×0.63%
- https6×0.63%
- login6×0.63%
- never6×0.63%
Cloud Maestro – WAF Security Suite for Cloudflare
Cloud Maestro brings centralized Cloudflare Web Application Firewall (WAF) controls directly into WordPress. Why would I use a plugin when I can create rules in Cloudflare? If you manage multiple Cloudflare-connected sites, Cloud Maestro is a productivity tool that helps oversee several domains from a central dashboard using WordPress. If you only manage one domain in Cloudflare, you wouldn’t benefit from this plugin. It’s useful for someone managing: – Their own sites and client sites – Multiple businesses – Separate Cloudflare accounts People like using Cloud Maestro because configuring security rules one domain at a time is inefficient and error-prone. It allows you to configure WAF rules once and deploy them consistently across all domains in your Cloudflare account — instantly. The free version supports one Cloudflare account with multiple domains. An optional premium version is available for managing unlimited domains across multiple Cloudflare accounts at once. 🛡️ Why Use Cloud Maestro – WAF Security Suite for Cloudflare? Managing security rules across multiple Cloudflare domains is tedious and time-consuming. This plugin streamlines the process, allowing you to: Deploy in One Click – Apply comprehensive WAF rules to multiple domains simultaneously Save Time – No more manually configuring rules on each domain, one at a time Enterprise Security – Protect against bots, aggressive crawlers, malicious IPs, and common threats Reduce Mistakes – Maintain consistent security rules across domains ✅ Free Standard Features One Cloudflare account Multiple domains One-click WAF rule deployment Centralized Cloudflare controls Secure API credential storage (AES-256-CBC encryption) Plugin updates The free plugin does not require an upgrade. 🔥 What Gets Protected The plugin deploys 3 optimized trusted security rules (prior versions used 5) that work together to protect your sites: Good Bot Allowlist – Ensures legitimate bots (Google, Bing, monitoring tools) can access your site Managed Challenges for Suspicious Traffic – Automatically challenges requests from certain ASNs and non-US traffic Aggressive Crawler Protection – Blocks unauthorized crawlers and bots (Yandex, Semrush, Ahrefs, etc.) VPN & Login Protection – Adds extra challenges for VPN traffic and WordPress login attempts Block Known Threats – Automatically blocks web hosts, malicious IPs, TOR nodes, and attack vectors ✨ Premium Upgrade (Optional) For agencies and professionals managing multiple Cloudflare accounts, a Premium version is available with expanded functionality and tech support. Check out our free trial for these features: Multi-Account Management – Automatically manage domains across ALL your Cloudflare accounts Easy Bot Whitelisting – Built-in checkboxes for 50+ trusted services across 8 categories Custom User Agents – Add your own user agent strings to the Good Bot Rule Custom IP Whitelisting – Add trusted IP addresses to the Goot Bot Rule IP Rules management – View and edit Cloudflare’s IP Rules that block or allow access even before hitting WAF rules (and we are working on connecting to fail2ban and Wordfence blocks) Bulk DNS Management – Search and manage all Cloudflare DNS record types across all domains, bulk migrate exact old/new values with confirmation modals, and convert A records to CNAME with a single action DNS Manager Reliability – Full record visibility for MX/TXT and other record types, cleaner cache warm-up modal flow, and safer bulk migration previews that only list actual matches Priority Support – Get expert help when you need it Advanced Customization – Fine-tune rules to match your exact requirements Multi-Account Management – Centrally manage unlimited domains across all your Cloudflare accounts 📋 Important Information Rule Replacement: This plugin replaces existing custom WAF rules on targeted domains. Make sure to back up any custom rules you want to keep. Compatibility: Works with Cloudflare Free, Pro, and Business plans. Not compatible with Enterprise plans managed by hosting providers. Service Monitoring: These rules might challenge some monitoring or uptime services. Check Cloudflare’s Events log if services stop connecting, and add exceptions as needed.