The security visibility layer for WordPress.
Open-source activity logging, request threat detection, core file integrity, file forensics, quarantine, and access hardening for WordPress.
Website · Documentation · Download Free · Get Pro · Security policy
This repository contains WPAuditor Free, the open-source WordPress security plugin. It helps administrators understand what is happening on a site by recording important activity locally, highlighting suspicious requests, verifying WordPress core files, investigating potentially unsafe files, and providing controlled response and hardening tools.
WPAuditor Free works without an account, license key, telemetry service, or external security dashboard. WPAuditor Pro is available separately for users who need the additional capabilities described on the plans page. The Free and Pro editions cannot run at the same time; deactivate one edition before activating the other.
| Area | Included capabilities |
|---|---|
| Security dashboard | Event, severity, source-address, threat-category, and targeted-endpoint summaries with time and severity filters. |
| Activity and audit log | Successful and failed logins, user and role changes, content and media activity, plugin activation or deactivation, and theme changes. |
| Request threat detection | Indicators associated with SQL injection, cross-site scripting, command injection, remote code execution, file inclusion and path traversal, PHP object injection, XXE, suspicious uploads, sensitive-file probes, reconnaissance, and encoded payloads. |
| Core file integrity | Administrator-initiated comparison of WordPress core files with official WordPress.org checksums. |
| File Forensics | Inspects files for suspicious characteristics and presents risk, confidence, evidence, hashes, file types, and modification context when available. |
| Quarantine Manager | Isolates reviewed files and supports controlled restoration or permanent deletion. |
| Access hardening | Optional Custom Login, XML-RPC blocking, REST API restrictions, and public-user-endpoint controls. |
| Log management | Log health, downloads, manual cleanup, and configurable automatic retention from 30 to 180 days. |
Important
WPAuditor reports indicators for administrator review. A detection is not proof of compromise, and the free edition does not automatically block attacking IP addresses. Back up your site and verify recovery access before quarantining files or enabling hardening controls.
| Security Events | WordPress Core File Integrity |
|---|---|
![]() |
![]() |
| File Forensics | Quarantine Manager |
|---|---|
![]() |
![]() |
| Custom Login | API Access Control |
|---|---|
![]() |
![]() |
- WordPress 6.0 or later
- PHP 8.0 or later
- Write access to the WordPress content and uploads locations used for protected log and quarantine storage
- Working WordPress scheduled events for automatic log retention
- Outbound HTTPS access to WordPress.org for administrator-initiated core checksum scans
- Outbound HTTPS access to GitHub for release checks and plugin updates
- Open the latest release.
- Download the attached
wpauditor.zippackage. Do not use GitHub's automatically generated source archive as the WordPress installer package. - In WordPress, open Plugins → Add New Plugin → Upload Plugin.
- Select
wpauditor.zip, install it, and activate WPAuditor. - Open WPAuditor → Settings and verify logging, retention, and timezone preferences.
- Review the dashboard and run File Forensics and Core Integrity before enabling optional hardening controls.
Starting with version 1.0.1, the GitHub-distributed edition checks WPAuditor's latest stable GitHub release and shows a normal WordPress update notice when a newer version and an attached wpauditor.zip are available. Site administrators can update from the Plugins screen or enable WordPress automatic updates. GitHub's generated source archives are not used for plugin updates.
Version 1.0.0 does not contain this updater. Sites running 1.0.0 must install version 1.0.1 once using the ZIP upload steps above. Future releases must include a wpauditor.zip whose root is wpauditor/ and whose wpauditor.php version matches the release tag.
WPAuditor records supported WordPress authentication, account, role, content, media, plugin, and theme events. It also analyzes supported request components for suspicious patterns and provides severity, confidence, HTTP, OWASP, and MITRE ATT&CK context where available.
The free edition observes and records supported suspicious activity for review. It does not automatically block source IP addresses. Detection results can include false positives and should be investigated alongside server logs, account activity, file changes, and the actual request outcome.
Events are stored locally in protected storage within the WordPress content area. WPAuditor Free does not send event logs to WPAuditor. Logs can contain personal or confidential information, so administrators should use appropriate retention periods and protect exported copies.
Recognized password-like URL parameters, tokens, nonces, API keys, secrets, and Custom Login recovery values are redacted before logging. Arbitrary application data may still contain sensitive information and should be reviewed before sharing.
WPAuditor contacts the official WordPress.org Core Checksum API only when an authorized administrator starts a Core File Integrity scan. The request contains the installed WordPress version and locale. Site content, WPAuditor logs, and user data are not included.
- Service:
https://api.wordpress.org/core/checksums/1.0/ - WordPress.org privacy policy
The GitHub-distributed edition also requests the latest public release information from https://api.github.com/repos/WPAuditor/WPAuditor/releases/latest during WordPress update checks. When an update is installed, WordPress downloads the attached ZIP from GitHub. GitHub receives ordinary connection information such as the server IP address and HTTP headers. WPAuditor does not send event logs, scan findings, license keys, or account data with these requests.
The free edition does not include analytics, telemetry, advertising, license callbacks, AI-provider connections, or Cloudflare synchronization.
- Confirm findings before deleting or quarantining files.
- Keep tested off-site backups and a working recovery path.
- Test Custom Login and API restrictions on staging or in a private browser session before signing out.
- Restrict WPAuditor access to trusted administrators.
- Review and redact exported logs before sharing them.
Please do not disclose suspected vulnerabilities in a public issue. Follow the private reporting process in SECURITY.md.
Use GitHub Issues for reproducible bugs and feature requests that do not contain sensitive security information. Include the WPAuditor version, WordPress version, PHP version, relevant steps, and sanitized diagnostic details.
Contributions should be focused, documented, and compatible with the WordPress coding and security practices used by the project. A dedicated contribution guide may be added as the public development workflow grows.
- Chart.js 4.5.1, distributed under the MIT License.
- Country flag images from Flagpedia, published for commercial and non-commercial use as public-domain material according to the source.
WPAuditor is licensed under the GNU General Public License v2.0 or later.
WPAuditor is independently developed and is not affiliated with or endorsed by WordPress, WordPress.org, Automattic, or the WordPress Foundation. WordPress is a registered trademark of the WordPress Foundation.







