Thessley Security Hardening is a modular security plugin. Each feature is a self-contained module you can enable, configure, and put into log-only or enforcing mode independently — nothing is all-or-nothing.
Perimeter
Request inspection
Detection
Hardening
Overview
Ops
This plugin connects to third-party services to power its blocking, geolocation, vulnerability-lookup and alerting features. Activating the plugin makes no external request. Every service below is contacted only after the site admin acts on the module that owns it: saving that module’s settings, clicking its refresh/test button, or entering credentials for it. The one exception is WordPress.org’s own API (api.wordpress.org), which File Integrity and Vulnerability Scan query on their scheduled scans.
For every service the entry says what it is, which server is contacted, whether an account is needed, what is sent and when, and links its Terms and Privacy Policy.
How requests identify themselves. Requests to the feed, Jetpack, trusted-networks, unwantedip, WPScan and Telegram servers are sent with the User-Agent wp-thessley/<version> (or wp-thessley) so this site’s address is not leaked in WordPress’ default User-Agent. The DB-IP download and the api.wordpress.org calls use WordPress’ standard User-Agent, which includes the site address, exactly as WordPress core’s own update checks do.
Plain-text lists of malicious IP addresses and ranges. The plugin downloads the chosen lists once a day (and when you click Refresh) and compiles them into a local blocklist that is checked on each request. Each is a single anonymous HTTP GET for a public text file. No account is needed, and nothing about this site or its visitors is sent. All feeds are opt-in: the source list starts empty and is only populated when you save the IP Blocklist settings.
cinsscore.com (https://cinsscore.com/list/ci-badguys.txt), operated by Sentinel IPS / Nomic Networks. Terms: https://sentinelips.com/terms — Privacy: https://sentinelips.com/privacyfeeds.dshield.org (https://feeds.dshield.org/block.txt), operated by the SANS Internet Storm Center. About: https://www.dshield.org/about.html — Privacy: https://www.dshield.org/privacy.htmlwww.spamhaus.org (https://www.spamhaus.org/drop/drop.txt). Fair Use Policy: https://www.spamhaus.org/blocklists/drop-fair-use-policy/ — Terms: https://www.spamhaus.org/terms-conditions/ — Privacy: https://www.spamhaus.org/privacy-notice/raw.githubusercontent.com (path /firehol/blocklist-ipsets/master/, three files). These are the FireHOL project’s own published data lists, distributed from GitHub. Each is a plain-text list of IP addresses and CIDR ranges: no scripts, stylesheets, images or other code. They are downloaded server-side, parsed as text into a local range table, and never executed or loaded by a visitor’s browser. GitHub Terms: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service — Privacy: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statementA self-hosted IP-reputation tracker run by this plugin’s author. Server: unwantedip.eagleeye-intelligence.com. It is used in three ways, all opt-in:
https://unwantedip.eagleeye-intelligence.com/api/v1/feed/wordpress is a read-only GET of the list of WordPress-targeting IPs. It requires the same API key, which is sent as a request header; nothing else is sent.https://unwantedip.eagleeye-intelligence.com/ip/<ip> in a new tab. Nothing is sent unless an admin clicks the link.Terms: https://unwantedip.eagleeye-intelligence.com/terms.html — Privacy: https://unwantedip.eagleeye-intelligence.com/privacy-policy.html
A service run by this plugin’s author that publishes crawler-nets.conf, a plain-text list of the IP ranges used by legitimate search-engine, AI and monitoring crawlers (Google, Bing, DuckDuckGo, OpenAI and others), updated automatically from those operators’ own published ranges. The Whitelist module uses it so genuine crawlers are not blocked by the other modules.
wp-opsec.eagleeye-intelligence.com, one file: https://wp-opsec.eagleeye-intelligence.com/wp-content/uploads/wp-opsec/crawler-nets.confwp-thessley/<version> User-Agent. Nothing about this site, its users or its visitors is sent. The server’s standard web-server access log records the requesting IP address and time.A compiled IP-to-country dataset. Server: download.db-ip.com (https://download.db-ip.com/free/dbip-country-lite-YYYY-MM.csv.gz). It is downloaded when you first save the Geo Blocker settings or click its Refresh button (Geo Login uses the same dataset), then refreshed weekly, and looked up locally, so no visitor IP address is ever sent to DB-IP. No account is needed. Nothing is sent beyond the download request itself. Source: https://db-ip.com — Privacy: https://db-ip.com/privacy.php — Dataset licensed CC BY 4.0: https://creativecommons.org/licenses/by/4.0/
WordPress.org’s own API. No account is needed.
https://api.wordpress.org/core/checksums/1.0/ to compare against this site’s core files. It sends this site’s WordPress version and locale, the same two values core itself sends for its own update checks.https://api.wordpress.org/plugins/info/1.0/<slug>.json for each installed plugin to see whether it is still listed, closed or long unmaintained. It sends the slug of each installed plugin being checked, and nothing else about this site.Terms/Privacy: https://wordpress.org/about/privacy/
Opt-in, only when XML-RPC blocking is enabled. Fetches Automattic’s published Jetpack IP range list (https://jetpack.com/ips-v4.txt, server jetpack.com) so xmlrpc.php requests genuinely coming from Jetpack’s own servers can be exempted. No account is needed and nothing is sent beyond the request for the list. Terms: https://automattic.com/tos/ — Privacy: https://automattic.com/privacy/
Opt-in. Adds known-CVE data for installed plugins and themes. Server: wpscan.com (https://wpscan.com/api/v3/). An account is needed: a free WPScan API token that you obtain yourself at https://wpscan.com/api and enter on the Vulnerability Scan page. Sent: the slug of each installed plugin/theme being checked and your API token, once per plugin/theme per 24 hours (results are cached). No other site data is sent. Terms: https://wpscan.com/terms/ — Privacy: https://automattic.com/privacy/
Opt-in. Sends a message to a Telegram chat you control when a security event exceeds the severity threshold you configure. Server: api.telegram.org. An account is needed: a Telegram bot token (from @BotFather) and a chat ID that you provide. Sent, only when a qualifying event fires (or when you press “Send test”): the site name and domain, the module and event name, the action taken, the offending IP address, a short detail string and a timestamp. Terms: https://telegram.org/tos — Privacy: https://telegram.org/privacy
Opt-in. Uses this site’s own mail system, not a third-party service, so nothing is sent to any server listed here.