NullState Security™ Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
NullState Security™ is a free WordPress security plugin with modular hardening, threat interception, forensic logging, a live traffic monitor (90-day retention), two-factor authentication (TOTP), and a vulnerability scanner.
Key free features:
- Core hardening – disables XML-RPC, hides version leaks, protects the uploads directory
- Brute-force protection – automatic IP lockout after repeated failed logins
- IP blacklist – block attackers manually or from the Live Traffic feed, with CSV import/export
- Request filtering – blocks directory traversal, SQL injection, XSS, eval() and other attack payloads
- User-Agent Bouncer – blocks known malicious scanners and bots (e.g. Nuclei, sqlmap)
- Emergency lockdown – temporarily disable non-admin logins and block the site
- Session terminator – end all other sessions with one click
- Cache & temp purge – clear caches and kill memory-resident shells
- Admin creation lockdown – detect and delete rogue administrator accounts
- Uploads shield – block script execution in the uploads directory
- Forensic logging – every security event recorded with full request context
- Live traffic monitor (90-day) – real-time view of every request, classified as human, bot, or attack, with country flags and one-click IP blocking
- Two-factor authentication – TOTP-based 2FA (Google Authenticator, Authy, …) with backup codes
- Vulnerability scanner – checks plugins, themes and core for known vulnerabilities (optional free WPScan API token for detailed data)
- Manual malware sweeps – C2 trojan cleanup, JS dropshell removal, trojanized CSS stripping, fake dependency removal, transient drop-shell cleanup
- Security scorecard – 0–100 score with actionable recommendations
For advanced security solutions, enterprise-grade protection, and expert support,
visit nullstatesecurity.net.
External Services
This plugin connects to the following external services:
-
WPScan API (wpscan.com) – Optional
- Purpose: Vulnerability database queries
- Data sent: Plugin/theme/core version information
- When: During vulnerability scans (user-initiated)
- Terms: https://wpscan.com/terms
- Privacy: https://automattic.com/privacy/
-
AbuseIPDB (abuseipdb.com) – Optional
- Purpose: IP reputation and threat scoring
- Data sent: Visitor IP addresses
- When: When viewing IP details in Live Traffic
- Terms: https://www.abuseipdb.com/legal
- Privacy: https://www.abuseipdb.com/privacy
-
ip-api.com
- Purpose: Geolocation, ISP, and location data
- Data sent: Visitor IP addresses
- When: For country flags and IP lookup details
- Terms: https://ip-api.com/terms
- Privacy: https://ip-api.com/privacy
-
WordPress.org API
- Purpose: Checking for outdated plugins/themes/core
- Data sent: Installed version numbers
- When: During vulnerability scans
- Terms: https://wordpress.org/about/privacy/
Screenshots
No screenshots provided

