Title: Vortix Web Security
Author: MohtamimNayeem
Published: <strong>1 ខែ​តុលា, 2026</strong>
Last modified: 3 ខែ​តុលា, 2026

---

ស្វែងរក កម្មវិធីបន្ថែម

![](https://ps.w.org/vortix-web-security/assets/icon-256x256.png?rev=3722599)

# Vortix Web Security

 By [MohtamimNayeem](https://profiles.wordpress.org/mohtamimnayeem/)

[Download](https://downloads.wordpress.org/plugin/vortix-web-security.2.2.0.zip)

 * [Details](https://km.wordpress.org/plugins/vortix-web-security/#description)
 * [Reviews](https://km.wordpress.org/plugins/vortix-web-security/#reviews)
 *  [Installation](https://km.wordpress.org/plugins/vortix-web-security/#installation)
 * [Development](https://km.wordpress.org/plugins/vortix-web-security/#developers)

 [Support](https://wordpress.org/support/plugin/vortix-web-security/)

## Description

Vortix Web Security provides practical WordPress hardening without accounts, license
keys, remote telemetry or a license server. The plugin is designed to be conservative:
new compatibility-sensitive protections are off by default, and .htaccess changes
are verified and reverted if the site’s own loopback probe reports an HTTP 500.

#### Free protection modules

 1.  **Basic Hardening** – generic login errors, public username-enumeration protection
     and MIME-sniffing protection.
 2.  **Login Protection** – temporary IP and username lockouts after repeated failed
     logins.
 3.  **Disable XML-RPC** – disables the XML-RPC interface and related discovery links.
 4.  **Bad Bot Blocker** – blocks requests from a small list of known scanner/exploit
     User-Agents.
 5.  **Upload Protection** – blocks execution of common script files in the uploads
     directory on Apache/LiteSpeed.
 6.  **Disable File Editor** – disables the WordPress plugin and theme code editors.
 7.  **Hide WP Version** – removes common WordPress version disclosures.
 8.  **Disable Directory Browsing** – adds a verified Options -Indexes rule on Apache/
     LiteSpeed.
 9.  **Strong Password Enforcement** – requires stronger passwords for users who can
     publish content.
 10. **Automatic Plugin Updates** – allows automatic updates for packages served by
     WordPress.org over HTTPS.
 11. **Automatic Theme Updates** – allows automatic theme updates for packages served
     by WordPress.org over HTTPS.
 12. **Pingback & Trackback Control** – disables legacy pingback/trackback publishing
     paths.
 13. **Safe Security Headers** – adds conservative X-Content-Type-Options and Referrer-
     Policy headers.
 14. **Sensitive File Protection** – blocks direct access to common deployment/configuration
     filenames and Git metadata directories.
 15. **Malicious Query Blocking** – blocks a small set of high-confidence XSS, traversal,
     null-byte, webshell and SQL injection signatures in the query string.

A **20-point Security Scan** provides local checks for HTTPS, XML-RPC state, debug
mode, file permissions, upload protection, version exposure, administrator username,
login protection, directory listing, user enumeration, REST user exposure, file 
editors, RSD/WLW links, outdated plugins, pingback/trackback control, security headers,
sensitive-file protection and malicious-query protection. Checks that cannot be 
verified are reported as unknown and excluded from the score.

Compatibility-sensitive modules remain **off by default**, including XML-RPC blocking,
bot blocking, .htaccess protections, automatic updates, pingback/trackback control
and malicious-query blocking. Existing installations keep their current choices 
when updating; newly introduced 2.2.0 modules are not enabled automatically.

### Login recovery

If Vortix Login Protection ever locks out an administrator, add this temporary line
to `wp-config.php`:

    ```
    define( 'VORTIX_DISABLE_LOGIN_PROTECTION', true );
    ```

Log in, remove the line, and then review the Login Protection settings. This bypass
affects only Vortix’s lockout module.

### Privacy

Blocked requests are logged locally in the site’s own database. The log contains
the client IP address, request path without the query string, event type and time.
Entries are automatically removed according to the configured retention period. 
Login-attempt counters use keyed hashes and expire automatically.

The plugin does not send telemetry, security logs, license data or scan results 
to the author or another server.

### External services

Vortix Web Security does not contact an external service.

 * Security Scan and .htaccess safety checks may make loopback requests to the site’s
   own URL.
 * Cloudflare mode only reads the `CF-Connecting-IP` request header and uses address
   ranges bundled with the plugin; it does not contact Cloudflare.
 * The optional Premium link is an ordinary user-initiated external link. No request
   is made by the plugin merely because the link is displayed.

## Installation

 1. Upload the plugin to `/wp-content/plugins/vortix-web-security/`, or install it 
    from Plugins.
 2. Activate **Vortix Web Security**.
 3. Open **Vortix Web Security** and review the protection modules.
 4. If the site is behind a CDN or reverse proxy, review **Settings > Trusted proxy**.

## FAQ

### Does it require a license or account?

No. The free plugin has no license key, trial, registration or remote licensing 
system.

### Will an update enable the new 2.2.0 protections automatically?

No. Existing installations keep their current module choices. New 2.2.0 modules 
start disabled so an update does not silently change site behaviour.

### Can Login Protection lock me out?

A temporary lockout can occur after repeated failures. If recovery is needed, use
the `VORTIX_DISABLE_LOGIN_PROTECTION` wp-config.php bypass described above.

### Can .htaccess features break my site?

The plugin uses marked rules and probes the site’s own URL after a write. If the
response indicates HTTP 500, the change is reverted. Hosts that do not support .
htaccess are not modified.

### Does Malicious Query Blocking inspect POST data?

No. It inspects only the query string and uses conservative, high-confidence signatures.
It is disabled by default because application-specific query formats vary.

### Does it work on Nginx?

Features that do not depend on .htaccess work on Nginx. Upload Protection, Disable
Directory Browsing and Sensitive File Protection require equivalent Nginx configuration
and will not claim to enforce those rules through .htaccess.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Vortix Web Security” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ MohtamimNayeem ](https://profiles.wordpress.org/mohtamimnayeem/)

[Translate “Vortix Web Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/vortix-web-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/vortix-web-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/vortix-web-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/vortix-web-security/)
by [RSS](https://plugins.trac.wordpress.org/log/vortix-web-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.2.0

 * Added Pingback & Trackback Control.
 * Added Safe Security Headers with conservative, compatibility-focused headers.
 * Added Sensitive File Protection with verified .htaccess changes.
 * Added conservative Malicious Query Blocking for high-confidence query-string 
   payloads.
 * Expanded Security Scan from 16 to 20 local checks.
 * Added a wp-config.php emergency bypass for Login Protection.
 * Added versioned migration on `plugins_loaded`; new 2.2.0 modules stay off for
   existing installations.
 * Removed unsupported premium marketing claims that were not represented by the
   separately distributed Pro codebase.
 * Kept the free plugin offline-first with no telemetry or remote license infrastructure.

#### 2.1.1

 * Refreshed admin design: colour-coded status, header banner, feature filter and
   score ring.

#### 2.1.0

 * First WordPress.org release of the free edition.
 * Added Basic Hardening and Disable XML-RPC.
 * Rebuilt the Modules screen and made compatibility-sensitive features opt-in.
 * Added verified .htaccess changes with loopback safety checks.
 * Added trusted proxy handling and local security logging.

## មេតា

 *  Version **2.2.0**
 *  Last updated **4 ថ្ងៃ មុន**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.0.7**
 *  PHP version ** 8.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/vortix-web-security/)
 * Tags
 * [Brute Force](https://km.wordpress.org/plugins/tags/brute-force/)[hardening](https://km.wordpress.org/plugins/tags/hardening/)
   [login security](https://km.wordpress.org/plugins/tags/login-security/)[security](https://km.wordpress.org/plugins/tags/security/)
   [xmlrpc](https://km.wordpress.org/plugins/tags/xmlrpc/)
 *  [Advanced View](https://km.wordpress.org/plugins/vortix-web-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/vortix-web-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/vortix-web-security/reviews/)

## Contributors

 *   [ MohtamimNayeem ](https://profiles.wordpress.org/mohtamimnayeem/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/vortix-web-security/)