=== Fuerte-WP === Contributors: tcattd Tags: security, login, protection, admin, brute-force, GDPR, privacy, access-control, multisite Stable tag: 1.7.2 Requires at least: 6.0 Tested up to: 6.9 Requires PHP: 8.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.txt Fortify your WordPress site with military-grade security. Stop brute-force attacks, hide your login URL, and control admin access like never before. == Description == πŸ›‘οΈ **ULTIMATE WORDPRESS SECURITY SOLUTION** Is your WordPress site vulnerable to attacks? Every day, thousands of sites get compromised through weak login security, unrestricted admin access, and exposed login URLs. Fuerte-WP is your fortress against these threats. **⚠️ STARTLING FACT:** - 90% of hacked WordPress sites are compromised through brute-force attacks on wp-login.php - Most WordPress security breaches happen from within - by administrator accounts with too much power - Your default wp-login.php URL is a public invitation to attackers **πŸ”₯ WHY FUERTE-WP IS DIFFERENT:** Most security plugins just alert you AFTER an attack. Fuerte-WP PREVENTS attacks before they happen, combining multiple layers of protection that work together seamlessly. **🚨 BRUTE-FORTRESSβ„’ ATTACK PREVENTION** - **Intelligent Rate Limiting**: Configurable thresholds (default: 5 attempts in 15 minutes) - **Progressive Lockouts**: Smart lockouts that get longer with repeated attempts - **IP & Username Blacklisting**: Automatic blocking of suspicious IPs and usernames - **Real-Time Threat Detection**: Live dashboard showing current attacks and active lockouts **πŸ‘‘ ADMINISTRATOR CONTROL SYSTEM** - **Super User Access**: Designate who has full access (YOU) while restricting others - **Role-Based Permissions**: Granular control over what different admin roles can do - **Plugin & Theme Protection**: Prevent other admins from installing, deleting, or modifying critical files - **Menu Management**: Hide sensitive WordPress menu items from restricted users - **User Account Shielding**: Protect super user accounts from being edited or deleted **πŸ“Š SECURITY COMMAND CENTER** - **Live Attack Monitoring**: Real-time AJAX dashboard shows login attempts as they happen - **Detailed Forensic Logs**: Comprehensive logging with timestamps, IPs, and user agents - **Export Security Data**: Download logs for analysis or compliance reporting - **Smart Notifications**: Get alerted about security events and lockouts - **One-Click Management**: Instantly unblock IPs, clear logs, or reset lockouts **πŸ‡ͺπŸ‡Ί GDPR COMPLIANCE MADE EASY** - **Privacy Notice Builder**: Customizable GDPR compliance messages for login/registration forms - **Built-in Legal Templates**: Professional default privacy messages if you don't customize - **Non-Intrusive Design**: Compliance that doesn't hurt user experience - **Audit Trail**: Logging that helps with GDPR compliance requirements **βš™οΈ ADVANCED WORDPRESS HARDENING** - **Auto-Update Management**: Automated updates for core, plugins, themes, and translations - **API Security Shield**: Disable XML-RPC, Application Passwords, and restrict REST API - **Email Protection**: Customize WordPress recovery and sender emails - **Security Hardening**: Force strong passwords, disable file editors, block weak passwords - **Performance Optimized**: Background updates that don't slow down your site **πŸ” OPTIONAL: LOGIN URL OBSCURITY** *For users who want additional obscurity layers* - **Invisible Login URL**: Replace default `wp-login.php` with custom URLs - **Smart Redirection**: Send attackers away from your site (404 page or custom URL) - **WP-Admin Fortress**: Block direct `/wp-admin/` access to unauthorized users - **Hidden Field Protection**: Advanced CSRF protection against automated attacks *Note: This feature is disabled by default because true security comes from strong authentication, not hiding URLs.* **πŸ”’ WHY CHOOSE FUERTE-WP?** βœ… **PROACTIVE PROTECTION** - Stops attacks BEFORE they succeed βœ… **INTELLIGENT RATE LIMITING** - Real-time attack detection and prevention βœ… **ADMIN INSIDER THREAT PROTECTION** - Controls what other administrators can do βœ… **GDPR READY** - Built-in privacy compliance features βœ… **PERFORMANCE OPTIMIZED** - Won't slow down your website βœ… **MULTISITE COMPATIBLE** - Works on single sites and WordPress networks βœ… **SELF-PROTECTING** - Cannot be disabled by non-super users βœ… **DEVELOPER FRIENDLY** - File-based configuration for mass deployment βœ… **SMART SECURITY APPROACH** - Focuses on real protection over security by obscurity **🎯 PERFECT FOR:** - Multi-author blogs and news sites - Client websites built by agencies - E-commerce stores with multiple administrators - Educational institutions with WordPress installations - Enterprise WordPress deployments - Anyone serious about WordPress security **⚑ INSTALL IN SECONDS, PROTECT FOR YEARS** Don't wait for your site to get hacked. Install Fuerte-WP today and join thousands of smart WordPress administrators who sleep better at night knowing their sites are fortified. == Installation == 1. Click "Install Now" or search for "Fuerte-WP" in your WordPress dashboard 2. Activate the plugin 3. Visit Settings > Fuerte-WP to configure your security fortress 4. **CRITICAL**: Add your email as a Super User to maintain full access 5. Setup your custom login URL (takes 30 seconds) 6. Review and customize your security restrictions 7. Congratulations! Your WordPress site is now fortified. 🚨 **IMPORTANT**: After activation, immediately add your email address to the Super Users list to ensure you maintain full administrative access. == Frequently Asked Questions == = Where is the FAQ? = You can [read the full FAQ at GitHub](https://github.com/EstebanForge/Fuerte-WP/blob/master/FAQ.md). = Suggestions, Support? = Please, open [a discussion](https://github.com/EstebanForge/Fuerte-WP/discussions). = Found a Bug or Error? = Please, open [an issue](https://github.com/EstebanForge/Fuerte-WP/issues). == Screenshots == 1. Main options page. 2. Emails configuration. 3. Restrictions. 4. Advanced restrictions. == Changelog == [Check the changelog at GitHub](https://github.com/EstebanForge/Fuerte-WP/blob/master/CHANGELOG.md).