Cerrojo Security Toolkit Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Cerrojo Security Toolkit adds focused security diagnostics and reversible, opt-in controls under Tools > Cerrojo Security Toolkit.
Current tools include:
- Security posture diagnostics with links to native WordPress Site Health.
- A file editor control that stores a plugin preference without editing wp-config.php.
- Best-effort login protection with temporary, progressive throttling.
- XML-RPC pingback protection that removes native inbound pingback methods and the WordPress-filtered X-Pingback header.
- Staged HTTP security header policies with baseline, optional groups, compatibility warnings, and rollback controls.
- Email alerts for supported plugin installation and activation events.
- Email alerts for supported administrator account lifecycle events.
- URL Change Alerts for supported successful local WordPress Address and Site Address updates.
- Selective REST API blocking by HTTP method and registered route template. Matching rules apply to all callers, including administrators and authenticated integrations.
Controls are designed to be reviewed, enabled, verified, and reversed individually. Coverage depends on the WordPress hooks and serving paths described in each tool. Login throttling is best-effort, email delivery depends on the site’s mail transport, and headers must be verified at every cache, proxy, CDN, and origin edge.
Cerrojo Security Toolkit is not a web application firewall or malware scanner. It does not certify a site or guarantee complete protection. Use it as one layer in a broader security and recovery plan.
Saved settings remain until you change them. Deactivation stops the plugin’s runtime behavior but preserves its settings, metrics, and temporary state. The plugin currently provides no uninstall cleanup routine.
Screenshots
No screenshots provided

