Manual
Product site My Page

Security / Speed

Watch daily for known vulnerabilities, security fixes, tampering and suspicious files, close entry points with two-factor authentication and more, and serve images as WebP for faster pages

The most common way in is a plugin that wasn't updated

"Sorabun > Security / Speed" watches and closes the ways a WordPress site gets taken over (Pro). The settings that make images lighter and pages faster also live here.

Most WordPress takeovers exploit weaknesses the developer has already fixed. After a fixed version is released, sites that haven't updated get targeted. But WordPress shows "update available" the same way for a new feature and for a security fix, so the urgent updates get buried.

This screen checks the following automatically every day, and notifies you when something urgent turns up:

  • Whether installed plugins, themes or core have a known vulnerability
  • Whether an available plugin update contains a security fix
  • Whether WordPress core and plugin files have been modified, or suspicious files have been placed

You don't need to sign up for any paid service or API key. It contacts WordPress.org and the Sorabun license server (for matching known vulnerabilities).

1. Known vulnerabilities

Installed plugins, themes and core are matched against a public vulnerability database (Wordfence Intelligence). The Sorabun license server imports the database every day.

ShownMeaning
SeverityCritical, High, Medium, Low (from the CVSS score)
Action "Update to x.x or later"A fixed version is out. Updating to it fixes the problem
Action "No fix yet"Not fixed yet. Updating can't fix it, so if you don't use it, consider deactivating or deleting it
  • Only plugin and theme names (slugs) are sent for matching. Installed versions and site contents are not sent. Versions are compared on your own site
  • Critical and High issues, and issues with no fix yet, are notified on the day they're found
  • License activation is required
Source

Vulnerability information comes from Wordfence Intelligence (free for personal and commercial use, and redistribution is permitted under its terms). The source, plus the copyright notices and licenses of the records shown (Wordfence/Defiant, MITRE for CVEs, etc.), appear at the bottom of the screen. Only Sorabun's server holds the Wordfence API key; your site never contacts Wordfence directly.

2. Updates that contain security fixes

For each plugin with an available update, it reads the changelog from your installed version up to the latest version from WordPress.org and checks whether a security fix is mentioned. Results are listed most urgent first.

VerdictMeaning
Update nowThe changelog clearly mentions a security fix, such as "vulnerability", "XSS", "SQL injection" or "CVE-". Update as soon as you can
Looks like a safety fixThe changelog mentions fixes that likely relate to safety, such as sanitizing input or permission checks
Can't check the changesThere is no changelog, or it can't be read (themes, plugins distributed outside WordPress.org, etc.)
Feature updateNo security fix was found in the changelog

A small update within the same WordPress release line (e.g. 6.8.1 → 6.8.2) is almost always security and bug fixes, so it's shown as "Update now".

While there's an "Update now" item, a red notice appears on every admin screen. It disappears once you update.

Keep updating even without "Update now"

Security fixes the developer doesn't write in the changelog can't be detected. "Update now" means at least do this one right away. Apply the other updates regularly too.

Apply only security fixes automatically

Turn on "Automatically apply only updates that contain security fixes" in "4. Close the entry points" to have WordPress's automatic updates (twice a day) apply only "Update now" items and plugins with a fixed version for a known vulnerability.

WordPress's automatic updates are all-or-nothing, but this applies only the urgent ones. It doesn't change the automatic update settings of other plugins. Applied updates are recorded on the screen.

3. Tampering and suspicious files

WordPress core

It compares WordPress core files (wp-admin and wp-includes) against the official list of correct files (checksums) published by WordPress.org. It finds three things:

  • Modified files: malicious code has been added to a core file
  • Missing files: a core file has been deleted
  • Unknown PHP inside the core folders: a common form of the "back door" left behind after a takeover

wp-content (themes, plugins, images) isn't compared, because its contents change with legitimate updates.

If differences turn up and you don't know why, use "Re-install version x.x.x" in "Dashboard > Updates" to put the official files back (your posts and settings are not deleted). Unknown PHP files aren't removed by re-installing, so check their contents in your server's file manager and delete them.

Development versions can't be checked

Development versions of WordPress, such as betas, have no official list, so the screen says the check isn't possible. That doesn't mean tampering was found.

Plugins and suspicious files

"Scan files" checks two things (it also runs automatically every day).

  1. Matching (reliable): plugins distributed on WordPress.org have an official list of correct files for each version. Installed files are compared against it to find modified files and PHP files that aren't in the original package
  2. Pattern check (a guide): files that can't be matched, such as themes, the uploads folder, and paid or custom plugins, are checked for patterns common in files planted during a takeover (running hidden code, running values sent from outside, PHP in the uploads folder, PHP disguised as an image, and so on)

Files that match the official list are not pattern-checked, so legitimate plugins are rarely flagged.

For anything found, "Ask AI to explain" has AI describe in plain words what the code does, whether it looks malicious, and what to do. Only 25 lines around the finding are sent to AI.

LevelMeaning
HighAlmost certainly malicious (notified on the day it's found)
GuideCommon in malicious code, but legitimate code uses it too. Check the contents
Not a replacement for a professional scan

The pattern check doesn't have the coverage of the large signature sets professional security companies maintain. "Nothing found" doesn't guarantee safety, so if you suspect a takeover, consult a professional.

4. Close the entry points

Every setting is off by default. Some of them stop features certain sites need, so read the description before turning one on.

SettingWhat it preventsKeep in mind
Automatic security fixesApplies urgent updates without waiting for someoneAn update can occasionally break the layout. Applied updates are recorded on the screen
Require two-factor authentication for administratorsEven if a password leaks, nobody can log in without the phoneWhen on, administrators who haven't set it up can't open other screens until they do. Set up your own first
Leaked passwordsStops people from using passwords that leaked from other sites and are circulating. They're refused when a password is set, and if a login uses one, a change is recommendedChecks use Have I Been Pwned. The password itself isn't sent: only the first 5 characters of its hash are sent, and matching happens on your site
Login brute forceAfter 5 failures in a row from the same connection, login is blocked for 15 minutes. Stops attacks that keep trying passwords by machineIf many people log in from the same network (an office, for example), one person's repeated typos can lock everyone out for a while
Username leaksHides the "?author=1" trick that reveals login IDs, and the user lists in the REST API and sitemap, from visitors who aren't logged inAuthor pages (/author/name/) still display
XML-RPCTurns off an old integration mechanism used for attacks that try many passwords at onceThe WordPress mobile app, Jetpack and some external posting tools will stop working
PHP in the uploads folderStops PHP from running in the uploads folder, against attacks that upload PHP disguised as an image and open itWorks on servers where .htaccess applies (Apache, LiteSpeed). On nginx, ask for the one line shown on the screen to be added to the server configuration

When a login is blocked, the date and time, the connection (partly masked) and the username that was tried stay on the screen. Blocking only uses connection information that can't be faked.

Firewall

Stops obvious attack requests inside WordPress.

  • SQL injection (peeking into the database), reading server files, running commands, injecting PHP, cross-site scripting
  • Probes for config and hidden files such as .env, wp-config.php.bak and .git/
  • Bursts of requests for pages that don't exist (30 within 5 minutes): robots hunting for vulnerable plugins are locked out for 30 minutes
ModeWhat it does
OffThe default
Log onlyRecords without blocking. Start here for a few days and check that no legitimate traffic shows up
BlockReturns "403" for matching requests

To avoid locking out legitimate users:

  • Requests from people who can write posts (logged-in editors and administrators) aren't checked (HTML and code in post content is normal)
  • Password fields aren't checked
  • For bursts of missing pages, search engines such as Google and Bing are verified by reverse DNS and excluded (their self-reported names can be faked, so they aren't trusted)
  • IPs and ranges listed in "Allowed connections" are never blocked. Adding your office's fixed IP is a good idea
What it can't do

It can't stop requests for files the server returns directly (existing images, files that don't go through WordPress), or floods of traffic (DDoS). Use a service such as Cloudflare alongside it if you need that.

Country blocking (login screen)

Enter two-letter country codes separated by commas (Japan is JP, the US is US) in "Countries allowed to log in", and the login screen and XML-RPC can only be opened from those countries. Admin logins are often attempted from abroad, so if your site is only used from Japan, setting just JP turns away most brute-force attempts at the door.

  • If the country can't be determined (a lookup failure, for example), access is allowed
  • It won't save if your current connection's country isn't included (so you don't lock yourself out the moment you save)
  • When logging in from a trip abroad, add your IP to "Allowed connections" or add the country
  • Countries are determined with DB-IP's list (IP Geolocation by DB-IP, CC BY 4.0), updated monthly. On sites behind Cloudflare, Cloudflare's determination is used

Sites behind Cloudflare

On sites behind Cloudflare, every request arrives from a Cloudflare IP. Left as is, everyone would look like the same person and a login lockout would lock everyone out. So the visitor IP that Cloudflare adds is used only when the request really comes from Cloudflare (the same header coming from anywhere else can be faked, so it isn't trusted).

Setting up two-factor authentication (each user's profile)

Each user sets up two-factor authentication under "Two-factor authentication" in "Users > Profile".

  1. Press "Set up" to show a QR code
  2. Scan it with an authenticator app on your phone (Google Authenticator, Microsoft Authenticator, 1Password, etc.)
  3. Enter the 6 digits shown in the app and press "Verify". It turns on and shows 10 backup codes. Each can be used once if you lose your phone, so print them or save them in a password manager

From then on, you're asked for the 6 digits after your password. You can get the 6 digits wrong up to 5 times; after that you start over from the password. The same 6 digits can't be used twice.

  • The QR code is created on the screen itself (the secret key isn't sent to any outside service). The secret key is stored encrypted, and backup codes are stored in a form that can't be reversed
  • If someone loses both their phone and backup codes, another administrator can press "Remove this user's two-factor authentication" on that user's profile, and they can log in with just the password
  • For XML-RPC, users with two-factor authentication can only log in with an application password

Passkeys (log in with fingerprint, face or PIN)

Press "Add a passkey" under "Passkeys" on your profile screen to log in with the fingerprint, face or PIN of the device you're using (phone or computer). From then on, just press "Log in with a passkey" on the login screen, with no password.

  • The site only stores half of the key pair (the public key), so a leak from the site can't be used
  • The key only responds to the site it was registered for, so it won't be used even if you're lured to a fake site (resistant to phishing)
  • It checks that you have the device and your fingerprint or PIN at the same time, so you aren't asked for the two-factor 6 digits when logging in with a passkey
  • Up to 10 per user. When you change devices, delete old ones from the list
  • Passkeys work on https sites (a browser rule)

Change the login URL, image CAPTCHA and login alerts

These are the same protections as SiteGuard WP Plugin. You'll find them in the "4. Close the entry points" table.

SettingWhat it preventsKeep in mind
Change the login URLMoves the login screen to https://your-site/any-name. wp-login.php, plus /wp-admin/, /login and /admin while logged out, return "Not Found", so bots hammering wp-login.php have nothing to tryUse 6 or more lowercase letters, digits, - or _. The new URL is also emailed to the person who changed it. Bookmark it. Password-protected posts, form submissions (admin-post.php) and Ajax keep working. Not available on multisite
Image CAPTCHAAsks for the 4 characters in an image on login, password reset and registration. Optionally also on comments from people who are not logged inThe image is drawn on your server, so no outside service is used (PHP GD is required). Easily confused characters (0, O, 1, I, L) are not used. Lowercase and full-width input are accepted
Login alertsEmails people who can write posts (Contributor and above) when they log in from an unfamiliar device (browser or network)Not sent for every login. The first login after turning it on only remembers that device. Up to 10 devices are remembered per person
If you lock yourself out

Add the line define( 'SORABUN_SECURITY_OFF', true ); to wp-config.php using your server's file manager. All settings in this section (two-factor authentication, login lockouts, the login URL change, the image CAPTCHA, etc.) stop. Monitoring and notifications continue. Remove the line once you can log in again. If you only forgot the login URL, define( 'SORABUN_LOGIN_URL_OFF', true ); stops just the login URL change (wp-login.php works again).

5. Lighter images for faster pages

Images are most of what slows a page down. Converting JPEG and PNG to WebP makes them a fraction of the size with almost no visible difference.

Turn on "Serve as WebP" to display article images from their WebP copy when one exists.

  • The original image isn't modified. A WebP copy is created next to it (photo.jpg.webp for photo.jpg) and swapped in only when displayed
  • Turning it off goes back to serving the original images immediately
  • Newly uploaded images get a copy right away
  • For existing images, use "Make existing images lighter in bulk". It works 15 images at a time and shows progress and how much was saved
  • Images that would get bigger as WebP (such as well-compressed PNGs) get no copy and are served as the original
  • Only images in this site's uploads folder are swapped. Images from other sites are left as they are
  • If you no longer need the copies, "Delete the WebP copies" removes them. The originals stay
Images made by AI are already saved lighter

Images Sorabun makes with AI, such as eyecatches and diagrams, are saved as WebP at a maximum width of 1600px. You can switch this with "Save AI-generated images lighter" in "Settings > Generation defaults". Slides for video stay PNG so video editing software can read them.

If the server's image processing (GD / Imagick) doesn't support WebP, copies can't be created. The screen tells you when that's the case; ask your hosting company about WebP support.