WordPress Security Plugin

OOSOFT WAF Security

Protect your WordPress website with advanced Web Application Firewall protection. OOSOFT WAF Security blocks SQL injection, XSS, malicious uploads, brute-force attempts, and suspicious requests before they can affect your site.

Free on WordPress.org v1.0.0 · PHP 7.4+
Protection Modules

Everything You Need to Secure WordPress

Six layers of active protection built directly into the WordPress request lifecycle.

SQL Injection Protection

Scans every GET and POST parameter against 15 battle-tested regex patterns to detect and block SQL injection payloads before they reach the database.

XSS Protection

Detects cross-site scripting patterns including script tags, event handlers, javascript: URIs, and encoded payloads across all request parameters.

Upload Security Scanner

Blocks uploads of dangerous extensions (PHP, ASP, shell scripts), detects double-extension attacks, and scans file content against known malware signatures.

Brute Force Protection

Tracks failed login attempts per IP using WordPress transients and automatically blocks further attempts once the configured threshold is reached.

Security Event Logging

Records every blocked attack with IP address, request URI, user-agent, and payload in a dedicated database table with configurable retention.

XML-RPC Protection

Optionally blocks all access to the XML-RPC endpoint — a common brute-force and amplification attack vector — with a single setting toggle.

Security at Every Layer

OOSOFT WAF Security hooks into WordPress at the lowest possible level — running before page rendering begins — so threats are intercepted before they can touch your theme, plugins, or database.

  • Firewall runs at init priority 1 — before WordPress loads your content
  • Uploads scanned before they reach the filesystem
  • Security headers sent on every front-end response
  • Zero external dependencies — no third-party cloud required
  • Built to WordPress Plugin Check standards — no bloat, no noise
By the Numbers

Built Specifically for WordPress

15+ SQL injection patterns detected
30+ Dangerous file extensions blocked
20+ Known malicious user-agents blocked

Start Protecting Your WordPress Site

Free to install. No account required. Available on the official WordPress Plugin Directory.

OOSOFT Technology develops secure and reliable solutions for websites and server environments. Visit oosoft.co.in to learn more about our services.