CloudAware Security Audit Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
This plugin adds auditing functionality to WordPress. It does this by adding extra
REST API endpoints. Using these endpoints it is possible to:
– see the version of core
– see whether there is an update available for core
– see what plugins are installed
– see whether these plugins have been actived
– see whether these plugins have autoupdate enabled
– see whether these plugins have updates
– see a list of vulnerabilities for these plugins
– see what themes are installed
For installations where the RESTAPI is disabled, the plugin can also push this information to an endpoint.
This will work for installations that are behind a geoblock or have no RESTAPI. To disable this, remove the
cronjob.
Dependancies
For getting vulnerabilities of WordPress components this plugin can use the WPVulnerability plugin
(https://wordpress.org/plugins/wpvulnerability/). If this plugin is installed, it will be used, otherwise this plugin
will work without the information from WPVulnerabilty plugin.
Without installing this dependancy no data is transferred to WPVulnerability. Please see https://www.wpvulnerability.com/privacy/
for more information.
Authentication
This plugin adds a new user cloudaware with a string, random password to the WordPress login. Additionally a new
role is added to the WordPress installation. This is done to limit the amount of authorisations this plugin uses.
After deinstalling the plugin the user and role are automatically removed from the system.
The password of this user is not known to CloudAware.
External services
In order to determine the latest version of installed software components this plugin uses the following
external services:
GitHub
Terms of Service: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service
Privacy Statement: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
– Releases list from ImageMagick github repository (https://api.github.com/repos/ImageMagick/ImageMagick/releases)
– Releases list from curl github repository (https://api.github.com/repos/curl/curl/releases)
Slider Revolution
Terms of Service: https://www.sliderrevolution.com/terms/
Privacy Statement: https://www.sliderrevolution.com/terms/privacy/
– Changelog documentation from Slider Revolution website (https://www.sliderrevolution.com/documentation/changelog/)
Apart from the usual headers (ip-address, UserAgent) used in a GET request no other information is send to these services.
Specifically no version information is transmitted to external services.
Screenshots
No screenshots provided

