Forge12 Security Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Forge12 Security is an all-in-one WordPress security plugin built by Forge12 Interactive GmbH. Every module can be switched on and off on its own, so a site runs only the parts it needs.
Every feature described below is included and fully functional. Nothing here is
limited by a licence key, a trial period or a usage quota.
What it does
- Web application firewall. Scores each request against a signature set and
refuses it when a category threshold is reached. A learning mode records what
matches without blocking, so the exceptions your own site needs can be created
from what actually happened. - Outbound traffic monitoring. Watches where this installation sends data
and to whom, learns which hosts are normal, and reports the new ones. Stolen
data has to leave the server somehow; this is where that shows. - Reinfection, not just infection. A file that was removed and came back is
proof of persistence. The scanner looks for what put it back — a scheduled
event, a must-use plugin, a drop-in — instead of deleting it again. - Behaviour rules. Judges a file by the sequence of things its code does
(create a user, hand it the administrator role, mark it to be found again),
not by how it is written. Obfuscation is free to change; the steps are not. - AI crawler detection with proof. Anyone can put “ClaudeBot” in a header.
Crawlers are checked against the address ranges their operators publish, so a
claim that cannot be verified is treated as unverified rather than as fact.
Each crawler, or each category of crawler, can be allowed, watched or refused. - Login protection and two-factor authentication. Rate limiting, lockouts,
TOTP with locally generated QR codes, and an optional custom login address.
Requirements
- WordPress 6.2 or higher
- PHP 8.1 or higher
- MySQL 5.7 / MariaDB 10.3 or higher
External Services
Everything this plugin does happens on your own server, with the exceptions
listed here. None of them runs unless the feature that needs it is switched on,
and the only one that is on out of the box talks to WordPress.org.
WPVulnerability — off by default
Looks up whether an installed plugin or theme has a published vulnerability.
The setup wizard asks before this is ever used; you can also switch it under
Security, Settings, Scanner (“Vulnerability Scan” and “Daily Vulnerability
Check”). While enabled it sends the slug and version number of each installed
plugin and theme to the API at www.wpvulnerability.net, once a day and during a
full scan. No address, no site content, nothing about your visitors.
Service: https://www.wpvulnerability.com/
Terms and licence: https://www.wpvulnerability.com/license/
Privacy policy: https://www.wpvulnerability.com/privacy/
WordPress.org — on by default
The file integrity, malware and update-guard scans compare your files against
the official checksums. Sends plugin and theme slugs, version numbers and file
hashes to api.wordpress.org, downloads.wordpress.org and core.svn.wordpress.org
while a scan runs. No personal data.
Service: https://wordpress.org/
Terms and licence: https://wordpress.org/about/license/
Privacy policy: https://wordpress.org/about/privacy/
Crawler operator IP ranges — off by default
The address lists ship with the plugin, and nothing is fetched unless you switch
this on under Security, Firewall, Bot Verification (“Refresh the published
address lists daily”). While it is off, this feature makes no outbound request
at all.
Switched on, the published IP range list of each crawler operator is fetched
once a day and cached, so that a real Googlebot can be told from something
calling itself Googlebot. The request carries this plugin’s user agent, which
contains your site address. Nothing else is sent, and nothing about your
visitors.
The lists are fetched from the operators themselves, at the addresses they
publish for this purpose: developers.google.com (Google), www.bing.com
(Microsoft), openai.com (OpenAI), claude.com (Anthropic), www.perplexity.ai
(Perplexity), duckduckgo.com (DuckDuckGo), search.developer.apple.com (Apple),
www.cloudflare.com (Cloudflare), uptimerobot.com (UptimeRobot) and jetpack.com
(Automattic). Security, Firewall, Bot Verification shows which address was used
for each and when. Each operator’s terms and privacy policy apply at their own
site; these are static range files, published by them for exactly this use.
Have I Been Pwned (Pwned Passwords) — off by default
Checks whether a chosen password appears in a known breach. Enabled under
Security, Hardening, “Breached password check”. Requests go to
api.pwnedpasswords.com and use the k-anonymity model: only the first five
characters of the password’s SHA-1 hash are sent, never the password and never
a username.
Service: https://haveibeenpwned.com/Passwords
Terms: https://haveibeenpwned.com/API/v3
Privacy policy: https://haveibeenpwned.com/Privacy
Telegram — off by default, needs a bot token
An alternative to e-mail for security alerts. Enabled under Security, Settings,
Notifications once you enter a bot token and a chat ID; nothing is sent before
that. While enabled, the text of each alert is sent to api.telegram.org, and
that text can name the address an attack came from. No other data is
transmitted, and Telegram is never contacted for anything else.
Service: https://core.telegram.org/bots/api
Terms: https://telegram.org/tos
Privacy policy: https://telegram.org/privacy
SilentShield — off by default, needs an API key
Tells a person filling in the login, registration or password reset form from a
script doing it. Enabled under Security, Hardening once you enter a key. This is
the only feature that loads a script into a visitor’s browser: the client is
served from api-eu.silentshield.io, and the visitor’s IP address reaches that
service. Submitted tokens are verified from your server. It is used on those
three forms only, never on the pages your visitors read. SilentShield is
operated by Forge12 Interactive GmbH from Germany.
Service: https://silentshield.io/
Terms: https://silentshield.io/terms/
Privacy policy: https://silentshield.io/privacy/
Forge12 signature service — off by default
Malware and firewall signatures age. Switched on, this fetches the current
signed rule set from api.forge12.com twice a day and applies it after checking
its signature; a set that fails the check is refused and the previous one stays
in place. The setup wizard asks before this is ever used; you can also switch it
under Security, Settings, Scanner. While it is off, the plugin keeps using the
rules it was shipped with and contacts nothing.
What is sent: the version of this plugin and the sequence number of the rule set
already held, so the server can answer “nothing new”. No site address, no file
contents, nothing about your visitors.
Which rule set you are served is decided by the service. Without a licence key
it answers with the set published 30 days ago; a Forge12 Security Pro key is
sent as a request header and is answered with the current one. Everything the
plugin does with the answer — fetching, verifying, applying — is identical in
both cases.
If you enter a licence key, that key and this site’s domain are additionally
sent to the same host to validate it. Without a key that never happens.
Service: https://www.forge12.com/
Terms: https://www.forge12.com/agb/
Privacy policy: https://www.forge12.com/datenschutz/
The plugin’s own Data Protection screen (Security, Privacy) lists the same
information for the configuration actually running on your site.= Key Features =
Web Application Firewall (WAF)
- Regex-based request filtering with customizable rules
- IP blocking with automatic expiration
- Bot detection with reverse DNS verification for Googlebot, Bingbot, Yandex, Baidu, DuckDuckBot
- Request validation (method, URL length, null byte detection)
- Predefined rule sets for common attack patterns (SQL injection, XSS, path traversal)
- WAF Learning Mode that records what the firewall would have blocked
- Automatic whitelist rule generation from learning mode results
Outbound Traffic Monitoring
- Watches where this installation sends data, and to whom
- Learns a baseline of the hosts your site normally talks to, then reports the ones that are new
- Refuses an outbound call before the connection is opened, so exfiltration and callbacks to a command server are stopped rather than logged after the fact
- The step every worthwhile attack has to take in the end — stolen data has to leave the server somehow
Vulnerability Shield
- Holds a known-vulnerable plugin shut until its update arrives
- The unauthenticated endpoints of a plugin with a published, unpatched vulnerability stop answering — the plugin’s own code is never touched
- Closes the window between disclosure and update: the weighted median from publication to mass exploitation is five hours, and 46 % of vulnerabilities are still unpatched on the day they are published
AI Crawler Detection
- Recognises crawlers operated by AI companies: OpenAI, Anthropic, Google, Perplexity, Meta, Apple, Amazon, Common Crawl, ByteDance and more
- Sorts them by what they do with your content: model training, assistant fetches on behalf of a user, AI search indexing
- Records which crawler requested what, and how often
- Allow, watch or block each crawler or whole category
- Matching robots.txt directives generated from your decisions
DDoS & Rate Limiting
- Configurable request rate limits per IP
- Separate rate limits for REST API endpoints
- 404 rate limiting to detect and block vulnerability scanners
- Automatic IP blocking on limit exceeded
- IP whitelist for trusted addresses
Login Protection
- Brute force prevention with automatic lockout (5 attempts / 15 min)
- Two-factor authentication (TOTP) with QR code setup
- Recovery codes for 2FA
- Login honeypot for bot detection
- Custom login URL to hide wp-login.php
- SilentShield bot check on the login, registration and password reset forms — Forge12’s own service, served from Germany, no Google script in your visitors’ browsers
- Login activity logging (success, failure, lockout)
Password Security
- Configurable strong password policy (minimum length, uppercase, numbers, special characters)
- Breached password detection via Have I Been Pwned API (k-Anonymity)
- 2FA enforcement per role, with a grace period for gradual rollout
File Integrity Monitoring
- SHA-256 checksum baseline of all WordPress core, plugin, and theme files
- Automatic scheduled scans with configurable intervals
- Repository verification against WordPress.org originals
- Automatic scheduled malware and integrity scans
- Quarantine and delete suspicious files
- Excluded paths: a page for the directories no file check should judge — a template cache a plugin fills with generated PHP, a staging clone, code you trust. It records which places your scans keep reporting and how many scans in a row, so excluding one is a button rather than a path typed from memory; entries can be switched off instead of deleted, and known candidates are offered as ticks, never applied on their own
Malware Signature Scanner
- Pattern-based malware detection with 283 built-in signatures
- Detects eval/base64 backdoors, shell uploads, code obfuscation, and remote includes
- Heuristic detection via entropy and structure analysis, beyond signature matching
- Three sensitivity levels: critical signatures only, critical and high, or everything including heuristics
- Files that still match the checksum their author published on WordPress.org are never flagged
- Mark a reviewed file as allowed — pinned to its content, so a later change brings it back into scope
- File Guard: an unexpected PHP file is reported the moment it is executed, not on the next scheduled scan. On its own this covers files that load WordPress, which is most of them, because a shell usually wants the database.
- Suspicious file flagging with threat identification
- Extensible signature database (JSON format)
Reinfection, Attack Surface and Supply Chain
- Persistence check: finds what puts a removed file back — a scheduled event, a must-use plugin, a drop-in — starting with the evidence that actually proves reinfection, a file that was taken away and is back
- Attack surface: records which REST routes and AJAX actions are reachable without logging in and which of those change something, and reports the door that newly appeared
- Update guard: verifies an installed update against the per-file checksum manifest WordPress.org publishes, so a package that is not what the author shipped is caught on arrival
- Known hashes: covers premium plugins, bespoke themes and this plugin itself, where wordpress.org publishes no original to compare against
- File inventory instead of modification times: a dropped file cannot make itself old with touch, and a plugin update no longer resets what counts as new
- Behaviour rules: judges a file by the sequence of things its code does — create a user, hand it the administrator role, mark it to be found again — not by how it is written
- Every finding says in plain words what it means and what to do about it, instead of naming the rule that fired
Database Integrity Monitoring
- Monitors wp_options, wp_posts, wp_postmeta, wp_users, wp_usermeta
- Detects unauthorized modifications, injected scripts and phishing URLs in posts, comments and options
WordPress Hardening
- Disable XML-RPC and pingbacks
- Disable file editor
- Force SSL for admin area
- Block PHP execution in uploads directory
- Prevent user enumeration
- Restrict REST API to authenticated users
- Disable application passwords
- Remove WordPress version info
- Configurable Content-Security-Policy header
- Full suite of security headers (HSTS, X-Frame-Options, X-Content-Type-Options, etc.)
- Limit post revisions
- Shorter session lifetimes
- Limit concurrent sessions per user
- Auto-update WordPress core
- Comment spam honeypot protection
- Strong password enforcement with configurable rules
- SilentShield bot protection for login, registration and password reset forms
Multi-Channel Notifications
- Alerts for critical and high severity events
- Findings collected and sent as one message, grouped and counted, instead of one email per finding
- Anything critical sent immediately, with whatever else has collected
- Unsubscribe link in every message, for people who no longer have an account on the site
- Weekly summary of what was blocked, attempted and found — sent whether or not anything went wrong
- Optional notifications for IP blocks
- Scan summary emails when changes are detected
- Configurable notification email address
- Test buttons for all notification channels
Live Traffic
- Watch requests as they arrive, with response code, request type and bot classification
- Block an IP straight from a traffic entry
- Records security-relevant requests (errors, blocks, login attempts) and keeps 24 hours
Security Logging
- Comprehensive event logging for all security actions
- Filterable by event type and severity
- Quick-filter for login activity
- CSV export
- Block IPs directly from log entries
- Configurable log retention (default: 90 days)
GDPR Compliance
- IP anonymization via HMAC-SHA256 (no plain IPs stored)
- Optional AES-256-CBC encrypted IP storage
- WordPress privacy exporter integration
- WordPress privacy eraser integration
Settings Management
- Import/export settings as JSON
- Security score with detailed breakdown
- Modern React-based admin interface
Screenshots
Dashboard: security score, a week of events, and every module on one switch each
Firewall: what was refused and why, split by kind, with the addresses currently blocked
Rate limiting: separate limits for pages, the REST API and missing files
Hardening: each measure on its own switch, the ones still off marked, and a watch-only position for the REST API
Scanner: every step of a run, what it checked, and what it found
Logs: filter by severity or event, and export as CSV
AI crawlers: who fetched your content and what for – decide by purpose, not by name
Data protection: what is stored, where, for how long, and what leaves the server
REST routes: which routes anonymous callers ask for, what was refused, and one click to open the ones you need
Excluded paths: the places your scans keep reporting, how many runs in a row, and one button to stop judging a directory a plugin generates

