NullState Security™

NullState Security™

Details
View on WordPress

NullState Security™ is a free WordPress security plugin with modular hardening, threat interception, forensic logging, a live traffic monitor (90-day retention), two-factor authentication (TOTP), and a vulnerability scanner.

Key free features:

  • Core hardening – disables XML-RPC, hides version leaks, protects the uploads directory
  • Brute-force protection – automatic IP lockout after repeated failed logins
  • IP blacklist – block attackers manually or from the Live Traffic feed, with CSV import/export
  • Request filtering – blocks directory traversal, SQL injection, XSS, eval() and other attack payloads
  • User-Agent Bouncer – blocks known malicious scanners and bots (e.g. Nuclei, sqlmap)
  • Emergency lockdown – temporarily disable non-admin logins and block the site
  • Session terminator – end all other sessions with one click
  • Cache & temp purge – clear caches and kill memory-resident shells
  • Admin creation lockdown – detect and delete rogue administrator accounts
  • Uploads shield – block script execution in the uploads directory
  • Forensic logging – every security event recorded with full request context
  • Live traffic monitor (90-day) – real-time view of every request, classified as human, bot, or attack, with country flags and one-click IP blocking
  • Two-factor authentication – TOTP-based 2FA (Google Authenticator, Authy, …) with backup codes
  • Vulnerability scanner – checks plugins, themes and core for known vulnerabilities (optional free WPScan API token for detailed data)
  • Manual malware sweeps – C2 trojan cleanup, JS dropshell removal, trojanized CSS stripping, fake dependency removal, transient drop-shell cleanup
  • Security scorecard – 0–100 score with actionable recommendations

For advanced security solutions, enterprise-grade protection, and expert support,
visit nullstatesecurity.net.

External Services

This plugin connects to the following external services:

  1. WPScan API (wpscan.com) – Optional

    • Purpose: Vulnerability database queries
    • Data sent: Plugin/theme/core version information
    • When: During vulnerability scans (user-initiated)
    • Terms: https://wpscan.com/terms
    • Privacy: https://automattic.com/privacy/
  2. AbuseIPDB (abuseipdb.com) – Optional

    • Purpose: IP reputation and threat scoring
    • Data sent: Visitor IP addresses
    • When: When viewing IP details in Live Traffic
    • Terms: https://www.abuseipdb.com/legal
    • Privacy: https://www.abuseipdb.com/privacy
  3. ip-api.com

    • Purpose: Geolocation, ISP, and location data
    • Data sent: Visitor IP addresses
    • When: For country flags and IP lookup details
    • Terms: https://ip-api.com/terms
    • Privacy: https://ip-api.com/privacy
  4. WordPress.org API

    • Purpose: Checking for outdated plugins/themes/core
    • Data sent: Installed version numbers
    • When: During vulnerability scans
    • Terms: https://wordpress.org/about/privacy/

Details

Plugin code:
nullstate-security
Plugin version:
3.4.7
Author:
Outdated:
No
WP version:
5.0 or higher
PHP version:
or higher
Test up to WP version:
7.1.3
Total installations:
0
Last updated:
2026-10-09
Rating:
Times rated:
0
firewall
malware
scanner
security
two-factor