Description
Stalza Security protects your site without weighing it down. Instead of hundreds of generic warnings, it tells you what changed, why it matters, how confident the detection is, and what to do.
Detect Correlate Assess Risk Explain Protect Verify
Free features
- File & WordPress integrity — core, plugin and theme checksums plus a local baseline for everything else.
- Malware detection — heuristic analysis of PHP, JS and .htaccess files; no signature database needed.
- Vulnerability detection — daily check of your installed components against known advisories (opt-in).
- Brute-force protection — login, XML-RPC and REST user-enumeration limits with escalating lockouts.
- Security hardening — one-click fixes and clear advisories for common misconfigurations.
- Security events & reports — a single timeline of what happened, with a weekly digest.
Designed to be light
- Zero frontend queries unless a login attempt is being evaluated.
- Scans run in small resumable chunks with CPU and memory budgets.
- No autoloaded option bigger than 50 KB. No bundled React runtime — uses the one WordPress already ships.
Premium
Stalza Security Pro extends the same engine with cloud threat intelligence, real-time protection, behavioral analysis, automatic remediation, IP reputation and advanced alerting.
External services
This plugin works fully offline by default. Nothing is sent anywhere until you opt in.
If you enable Vulnerability intelligence in Settings, the plugin sends the slugs and version numbers of your installed WordPress core, plugins and themes, plus your site URL, to https://stalza.com/api/stalza-security/v1/vulnerabilities/match once per day to receive matching security advisories. No user data, content or visitor information is included. See the Stalza privacy policy and terms.
Integrity checks fetch official checksums from WordPress.org (api.wordpress.org, downloads.wordpress.org), the same service WordPress core uses for updates.
Installation
- Upload the plugin to
/wp-content/plugins/stalza-security/or install it from the Plugins screen. - Activate it.
- Go to Stalza Security in the admin menu and run your first scan.
FAQ
-
Does it slow down my site?
-
No. On the frontend the plugin does nothing unless a login, XML-RPC or user-listing request is being evaluated. Scans run in the background in small chunks.
-
Does it send data to Stalza?
-
Only if you enable vulnerability intelligence, and then only component names and versions. See “External services” above.
-
Is it compatible with other security plugins?
-
Yes, but running two brute-force limiters can double-count attempts. Disable one.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Stalza Security” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Stalza Security” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.1.0
Features:
- login: add free-tier two-factor authentication
- login: free-tier two-factor authentication
- vuln: allow filtering the live vulnerability match URL
- vuln: live match URL filter + fixture fallback docs
Bug Fixes:
- ci: satisfy prettier and PHPCS for live-vuln merge
- ci: stylelint empty-line rules in style.scss
- vuln: use offline label for fixture source
1.0.1
Fixes:
- WordPress.org review prep: declare submitter as contributor; confirm Plugin URI and privacy/terms links on stalza.com
- Admin list tables use shared DataTable + server pagination
1.0.0
Features:
- admin: Settings, Dashboard, and Scan UX for v1 launch (Epic E7) (#9)
- integrity: pause/resume/cancel scans; skip Hardening-removed core docs noise
- malware: heuristic scan job + Scan-tab findings triage
- vuln: opt-in match client with fixture fallback filtered to installed inventory
- reports: weekly digest builder and cron
- Free modules: Integrity M2, Login M2, Hardening, Malware, Vulnerabilities, Reports, Events
Bug Fixes:
- vuln: do not surface fixture advisories for patched/absent components
- integrity: silent-reseed own plugin baseline on version bump; keep same-version tamper
- admin: hash navigation for TabPanel; Plugin Check ABSPATH on helpers
- build: exclude
.worktreesand agent dirs from release zips
0.1.1
Features:
- admin: add Events tab with filters, table, and context drawer
- admin: add Login Protection tab with allowlist and unlock
- core: add Settings helper for nested plugin options
- core: scaffold plugin kernel, admin shell, build pipeline and CI
- core: seed login protection settings defaults
- events: add Repository, Recorder, and retention Pruner
- events: add Severity map and TypeRegistry allowlist
- events: register the module, REST list, and upgrade hook after boot
- hardening: Epic E3 Hardening module (#2)
- integrity: Integrity M2 — plugins, baseline, uploads, Accept (#4)
- integrity: ship M1 Queue, Findings, core scan, REST, and admin tab
- login: add Guard for lockout policy and events
- login: add lockouts repository with window and escalate helpers
- login: add login status, allowlist, and unlock REST endpoints
- login: Login Protection M2 — proxies, enum blocks, editable thresholds (#3)
- login: register LoginProtectionModule and login event types
- support: add Fs, Hashing, Http, and Budget helpers
- support: add Ip helper (REMOTE_ADDR + pack/unpack)
Bug Fixes:
- admin: clear login refresh error after successful retry
- admin: separate login unlock errors from list refresh
- core: rename reserved-word column scans.cursor to cursor_state
- integrity: ignore wp-content paths in core checksum scan
- integrity: keep dotted scan types; record deactivate events
- login: avoid null lockout row offsets
- login: harden lockout persistence
- login: ignore failures while IP already locked
Performance:
- core: autoload db_version option so upgrade check costs no query
0.1.0
Features:
- core: plugin kernel, container, module contract, feature flags, schema installer
- admin: single-page React admin shell with dashboard and status endpoint
Full history: https://stalza.com/docs/stalza-security/changelog
