=== Bearmor Security === Contributors: andeirz Tags: security, malware scanner, firewall, login security, two-factor authentication Requires at least: 5.8 Tested up to: 6.9 Requires PHP: 7.4 Stable tag: 1.0.1 License: GPLv2 or later License URI: https://www.gnu.org/licenses/gpl-2.0.html Lightweight, powerful WordPress security for small and medium businesses. Malware scanning, login protection, 2FA, hardening & more. == Description == # Bearmor Security Professional WordPress security plugin with comprehensive malware protection, file integrity monitoring, and login security. Almost entirely free, with optional PRO features for advanced needs. ## Core Features (100% Free) **Malware Scanner** - Deep file scanning for backdoors, web shells, and malicious code - Pattern matching and heuristic detection - One-click quarantine for threats - Whitelist false positives - Scans plugins, themes, uploads, and core files **File Integrity Monitoring** - Real-time tracking of all file changes - Detailed change logs showing what, when, and where - Instant quarantine for suspicious modifications - Mark legitimate changes as safe **Login Security** - Brute force protection with automatic IP blocking - Complete login activity log - Geographic tracking for login attempts - Two-factor authentication (2FA) via email **Security Hardening** - One-click hardening for common vulnerabilities - Disable XML-RPC, file editing, and directory browsing - Hide WordPress version and login errors - Enforce strong passwords - Simple toggle controls **Firewall** - Web application firewall blocks SQL injection, XSS, and command injection - Rate limiting to prevent DDoS attacks - Country blocking with geo-IP detection - Honeypot protection for forms **Activity Logging** - Track all administrative actions - Filter by user, action type, or date - Essential audit trail for multi-user sites **Security Dashboard** - Clear overview of security status - Letter-grade security score (A-F) - Threat alerts and recommendations - Clean, focused interface ## Optional PRO Features The free version provides complete security protection. PRO adds optional enhancements: - **Vulnerability Scanner** - Automated CVE checks for plugins and themes - **AI Security Analysis** - Plain-English explanations of security issues - **Uptime Monitoring** - 24/7 external monitoring with instant alerts [Learn more about PRO features](https://bearmor.eu/bearmor-security-plugin/) ## Why Bearmor? **Most Powerful Free Tier** Unlike competitors, Bearmor includes malware scanning, file monitoring, firewall, quarantine, and 2FA in the free version. Features other plugins lock behind paid plans are free here. **Performance Focused** Efficient scanning with minimal server impact. No bloat, no unnecessary features. **Professional Interface** Clean dashboard that shows what matters. No confusion, no clutter. **Privacy Respected** Free users only send basic registration data (URL + email). Security scan data stays on your server unless you enable PRO AI analysis. ## Quick Start 1. Install and activate Bearmor Security 2. Run your first malware scan from the dashboard 3. Enable recommended hardening options 4. Set up 2FA for your account No configuration required. Works immediately. ## External Services **Free Users:** - Bearmor API (bearmor.eu) - License verification and registration - WordPress.org API - Core file integrity checks - IP-API.com - Geographic data for login tracking **PRO Users (additional):** - Bearmor API - Uptime monitoring and vulnerability data - OpenAI API - AI security analysis All connections use HTTPS encryption. No security scan data leaves your server in the free version. [Privacy Policy](https://bearmor.eu/privacy) [Terms of Service](https://bearmor.eu/terms) ## Support - [Documentation](https://bearmor.eu/docs) - [Support Forum](https://wordpress.org/support/plugin/bearmor-security) - Email: security@bearmor.eu (PRO users receive priority support) ## Privacy & Data **Free Users:** - Site URL (installation identifier) - Admin email (security notifications) - Plugin version (update checks) **PRO Users (additional):** - Security scan results (AI analysis only) - Uptime monitoring data (ping responses) **We Never:** - Sell data to third parties - Track website visitors - Store passwords or sensitive user data - Share data without explicit consent Data is encrypted in transit, stored on EU servers, and automatically deleted after 90 days. Request data deletion anytime at security@bearmor.eu. [Full Privacy Policy](https://bearmor.eu/privacy)