CodeWP Shield Monitor adds a careful baseline of WordPress security controls without sending site data to third parties by default.
CodeWP Shield Monitor hashes IP addresses in its 30-day audit log. For failed-login lockout management, it may also store recent source IP addresses, attempt counts, lockout status, and last failed-login time so administrators can block or unlock those IPs. File contents and post body content are never stored.
CodeWP Shield Monitor can connect to the official WordPress.org checksum API when the administrator enables core checksum verification. The service is used to compare local WordPress core file hashes with official release hashes. It sends the installed WordPress version and site locale at most once every 12 hours; it does not send stored credentials, file contents, full database values, post body content, audit-log IP hashes, API tokens, or CAPTCHA tokens. WordPress.org provides this service under the WordPress.org Terms of Service and Privacy Policy.
Terms: https://wordpress.org/about/terms-of-service/
Privacy: https://wordpress.org/about/privacy/
CodeWP Shield Monitor can connect to Cloudflare Turnstile only when an administrator enables login CAPTCHA, selects Cloudflare Turnstile, and saves a Turnstile site key and secret key. The login page loads Cloudflare’s Turnstile JavaScript from challenges.cloudflare.com to display the challenge. During login, the plugin sends the Turnstile response token, configured secret key, and visitor IP address to Cloudflare’s siteverify endpoint to validate the challenge. This is required for the optional Turnstile CAPTCHA feature.
Terms: https://www.cloudflare.com/website-terms/
Privacy: https://www.cloudflare.com/privacypolicy/
CodeWP Shield Monitor can connect to Google reCAPTCHA only when an administrator enables login CAPTCHA, selects Google reCAPTCHA, and saves a reCAPTCHA site key and secret key. The login page loads Google’s reCAPTCHA JavaScript from google.com to display the challenge. During login, the plugin sends the reCAPTCHA response token, configured secret key, and visitor IP address to Google’s siteverify endpoint to validate the challenge. This is required for the optional Google reCAPTCHA feature.
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy