Sentinel Security for WordPress

One plugin to protect logins, requests, forms and files.

Sentinel adds a local WAF, Login Shield, antispam, malware scanning and integrity checks to your site. The panel centralises configuration, inventory and events; when available, the edge WAF adds a first layer before traffic reaches WordPress.

Local WAFForm antispamScanner & integrityCentral management

Compatible with WordPress 6.0+ and PHP 7.4+ · safe initial configuration in observation mode

On the site

Stops threats inside WordPress.

The plugin inspects requests, logins, comments, registrations, forms and files without requiring theme changes.

In the panel

Brings status and controls together.

Operating modes, inventory, version, last contact, reports and events are available in one console.

Before the site

Adds the edge layer when needed.

When the domain runs through the Sentinel WAF, edge protection filters traffic upstream and the plugin securely preserves the visitor's real address.

Multi-level defence

Three coordinated levels, with different roles.

The plugin is more than an admin screen: it enforces controls on the site and exchanges only the status, policies and events required for management with Sentinel.

01Optional

WAF Sentinel Edge

Stops hostile requests, application floods and disallowed traffic upstream, before they reach the WordPress server.

02On site

Sentinel Plugin

Understands WordPress and protects logins, XML-RPC, forms, comments and files through locally enforced rules.

03Control

Sentinel Panel

Collects inventory, status, modes, trends and authenticated events, maintaining a consistent view across all connected sites.

WordPress Protection

Protection that runs directly on the site.

Each module can begin in observation mode, allowing rules to be evaluated before active blocking is enabled.

WAF

Local application firewall

Inspects paths and GET and POST parameters to detect path traversal, XSS, SQL injection, command injection and PHP execution attempts.

  • Observe, balanced and aggressive modes
  • Explicit IP allowlists and blocklists
  • Configurable excluded paths
LOGIN

Login Shield

Counts failed attempts by source and applies a temporary block when the configured threshold is exceeded.

  • Adjustable attempts, window and duration
  • Allowlist for administrative access
  • Reset after successful login
SPAM

Antispam for forms and comments

Locally evaluates links, recurring terms, hidden HTML and anomalous patterns, and can request a reputation-based second opinion from the server.

  • WordPress comments and registrations
  • Contact Form 7 and Elementor Pro Forms
  • WPForms, with content sent only as a hash
XML

XML-RPC and user enumeration

Monitors or disables XML-RPC and stops user-enumeration attempts through author parameters and the users REST API.

  • Monitor or disabled mode
  • Events visible in reports
  • Blocking integrated with the firewall
SCAN

Non-destructive malware scanner

Finds web shells, obfuscated code, dangerous execution functions, remote includes and encoded payloads without automatically deleting files.

  • Scheduled daily scan
  • Manual start from WordPress
  • Time and file limits to protect server resources
FIM

Core, plugin and theme integrity

Compares WordPress core against official checksums and verifies plugins and themes against an administrator-created SHA-256 baseline.

  • Modified, missing or new files
  • Fallback checksums for WordPress core
  • Security score from 0 to 100
SAFE

Encrypted, reversible quarantine

A suspicious file can be manually moved to AES-256-GCM encrypted quarantine while retaining its hash, permissions and original path for verified restoration.

  • No automatic deletion
  • Integrity check before restoration
  • Protected quarantine directory
LOG

Security and audit events

Records the events needed to understand what happened: failed and successful logins, new users, activations, updates, XML-RPC calls and blocks.

  • Resilient local queue
  • Periodic batched delivery
  • Centralised history in the panel

Centralised control

Configure the site from the panel, without losing local control.

The website tab shows link health, plugin version, WordPress environment and actual configuration. Changes to the modes are delivered on the next heartbeat and remain visible in the plugin as well.

  • WAF: observe, balanced or aggressive.
  • Antispam: off, observe or block.
  • Login Shield: observe or protect.
  • XML-RPC: monitor or disabled.
  • Inventory: WordPress, PHP, language, multisite, active plugins and associated servers.
Real Sentinel Security plugin dashboard in WordPress showing connection status, security score and active protections
Plugin 0.9.3 dashboard · Real interface with demonstration data.

Scanner and integrity

The result explains what was found and why it matters.

The Scanner page separates malware, core integrity and extensions. Each finding includes its path, severity, reason, size and SHA-256 hash so the administrator can verify it before taking action.

  • Official core integrity check for modified or missing files.
  • Plugin and theme baseline created and verified on request.
  • Email alert notifies the administrator when threats or integrity issues are found.
  • Manual quarantine to avoid automatic irreversible actions.
Real Sentinel Security antivirus scanner page in WordPress showing scan results and integrity checks
Scanner and integrity · Real interface with demonstration data.

Report and visibility

From one website to the overall picture.

The plugin provides a local report; the panel brings together the events of the linked sites and shows protection volume, trends and distribution.

01

Dashboard in the plugin

Security score, WAF blocks, spam stopped, blocked access, queued events and charts of the last 14 days.

02

Site details in the panel

Online status, version, last contact, environment, active capabilities, configuration and event history of the individual site.

03

Aggregated reports

Intervals of 7, 30 or 90 days, trend compared to the previous period, distribution by type, most affected sites and recent events.

04

CSV export

The operational data for the period can be exported for verification, historical comparison and sharing with the technical contact person.

Connection and data

Authenticated connection with telemetry kept to what is essential.

The token generated in the panel is linked to the domain, is valid only once and expires after 24 hours. After activation the site receives a dedicated credential, encrypted locally with WordPress keys.

Mandatory HTTPSThe plugin only accepts encrypted Sentinel endpoints.
HMAC-SHA256 signatureHeartbeats and events use timestamp and nonce against replay and tampering.
No credentialsPasswords, cookies, tokens and usernames are not sent in telemetry.
Hashed antispam contentThe central second opinion receives the SHA-256 fingerprint, not the message text.
Verified updatesThe package is downloaded via HTTPS and installed only if the SHA-256 checksum coincides.
Fail-open antispamIf the central service does not respond, the site continues to use the local verdict.

Guided activation

From domain to initial protection in four steps.

Activation begins with safe defaults: first it connects and observes, then you choose the blocking modes suitable for the site.

01

Register the domain

In the panel, enter the exact address of the site, generate the one-time token and download the associated plugin.

02

Install and connect

Upload the package to WordPress, activate Sentinel and use the token on the connection page.

03

Observe and verify

Review events, reports, module compatibility and the first scan without aggressive blocking.

04

Activate policies

WAF, antispam, Login Shield and XML-RPC settings from the plugin or panel according to the website's profile.

Frequently asked questions

Essential answers on the plugin.

Does the plugin replace the edge WAF?

No. The plugin protects WordPress itself, while the optional edge WAF works before traffic reaches the server. Together they provide coordinated, two-layer protection.

Does it automatically delete suspicious files?

The scanner is non-destructive. Quarantine is a manual action, encrypted and reversible, with integrity checks before restoration.

What is enabled immediately after installation?

Protection starts with safe settings: WAF and antispam in observation mode, XML-RPC monitoring and scanning enabled. Active blocking must be deliberately selected.

Which contact forms does it protect?

In addition to WordPress comments and registrations, antispam integrates with Contact Form 7, Elementor Pro Forms and WPForms.

Can I manage it from the Sentinel panel?

Yes. You can view status, inventory, events and reports and change operating modes. Scans can be started from WordPress or run automatically every day.

How are updates delivered?

WordPress detects new versions through the authenticated Sentinel channel. The package is downloaded over HTTPS and its SHA-256 checksum must be valid before installation.

WordPress Security

Do you want to protect a site or an entire WordPress network?

Together we assess the hosting environment, plugins, public modules and risk level, then set an observable protection before activating the blocks.