Title: Ensomedia Security powered by shieldwave.io
Author: shieldwave
Published: <strong>September 28, 2026</strong>
Last modified: September 28, 2026

---

Search plugins

![](https://ps.w.org/ensomedia-security/assets/banner-772x250.png?rev=3716337)

![](https://ps.w.org/ensomedia-security/assets/icon.svg?rev=3716310)

# Ensomedia Security powered by shieldwave.io

 By [shieldwave](https://profiles.wordpress.org/shieldwave/)

[Download](https://downloads.wordpress.org/plugin/ensomedia-security.1.0.0.zip)

 * [Details](https://li.wordpress.org/plugins/ensomedia-security/#description)
 * [Reviews](https://li.wordpress.org/plugins/ensomedia-security/#reviews)
 *  [Installation](https://li.wordpress.org/plugins/ensomedia-security/#installation)
 * [Development](https://li.wordpress.org/plugins/ensomedia-security/#developers)

 [Support](https://wordpress.org/support/plugin/ensomedia-security/)

## Description

Ensomedia Security, powered by shieldwave.io, scans your site from the inside and
tells you, in plain language, what is wrong and how to fix it. It is built around
one idea: **an alert has to be worth your attention**. Every check, the scheduled
scans and the email alerts are free, work without an account and have no limits.

#### Why owners switch to it

 * **Official checksums first.** Every WordPress core file, every plugin from the
   WordPress.org directory and every directory theme is compared with the exact 
   files WordPress.org published for your version. A file that matches is trusted
   and never “looks suspicious”. A file that differs is reported with the reason.
 * **Malware detection that needs real evidence.** One weak signal, such as base64
   in a file, is never a finding. The scanner looks for code that runs what a visitor
   sends, decodes and executes hidden payloads, hides function names, fetches remote
   code or creates hidden administrators. Findings ShieldWave is not sure about 
   are listed under “Ask your developer to check” and never send email.
 * **Change monitoring for everything WordPress.org cannot verify.** Premium plugins,
   custom themes, must-use plugins and drop-ins are recorded as a baseline. Changes
   that come with an update are accepted on their own; a new PHP file that appears
   without one is reported.
 * **Alerts that do not cry wolf.** One email per scan, only for problems that are
   new or got worse, never twice for the same one, at most four a day. A check that
   could not run (for example because WordPress.org did not answer) never sends 
   an email and never marks anything as fixed.
 * **Locks out password guessers.** Too many failed logins lock an address out for
   a while, and your user names stay private. New installs are protected out of 
   the box, and the address that turns it on is never locked out.
 * **A stolen password is not enough.** Turn on two-factor login and ShieldWave 
   asks for a one-time code from your authenticator app after the password. It is
   opt-in and per person, with recovery codes and a shell rescue, so you can never
   lock yourself out.
 * **Two common ways in, closed with one switch each.** Turn off the plugin and 
   theme file editor and XML-RPC in ShieldWave’s settings, without touching wp-config.
   php. The scan tells you when each one is worth it.
 * **Light on your server.** Scans never run while a visitor’s page loads: they 
   run in the background in short steps that fit hosts with a 30-second limit, and
   files that did not change since the last scan are not analyzed again.
 * **Never rewrites your site.** The plugin never edits, moves or deletes your files,
   users or settings. It explains each fix. The only things it ever refuses are 
   a bad login, a stranger asking for your user list, and the file editor and XML-
   RPC if you switch them off.

#### The checks

Malware and files:

 * **Malware and backdoors**: analyzes every PHP, JavaScript and .htaccess file 
   that WordPress.org cannot vouch for, with rules for web shells, request-to-execute
   code, decode-and-execute chains, obfuscated function names, remote code loaders,
   PHP hidden in images, spam mailers, hidden administrators, injected JavaScript
   and malicious redirects.
 * **WordPress core files**: every core file against the WordPress.org checksums
   for your version and language, plus PHP files in wp-admin, wp-includes or the
   site root that are not part of WordPress.
 * **Plugin files**: plugins from the WordPress.org directory against the checksums
   of the installed version, plus PHP files the release does not contain.
 * **Theme files**: themes from the WordPress.org directory against their release
   package.
 * **File changes**: new and changed files outside those releases (premium plugins,
   custom themes, must-use plugins, drop-ins, the site root) against the recorded
   baseline, and plugin or theme folders that appear without going through the WordPress
   installer.
 * **PHP files in uploads**: web shells, PHP files and .htaccess or .user.ini rules
   that make the server run uploads as PHP.

Vulnerabilities and software:

 * **Known vulnerabilities** (opt-in): plugins, themes and WordPress versions with
   published vulnerabilities, premium ones included, with the version that fixes
   each one. Uses the ShieldWave vulnerability lookup, which is free and needs no
   account; see External services.
 * **Closed and abandoned plugins**: plugins closed on WordPress.org (a security
   reason is flagged high) and plugins without an update for two years.
 * **Unused plugins and themes**: installed but switched off, so you can delete 
   what you do not need.
 * **WordPress, plugin and theme updates**, and **PHP version** support.

Live protection (all opt-in, all off until you turn them on):

 * **Live threat feed**: when ShieldWave publishes new malware rules or confirmed
   file signatures, your site picks them up within about three hours, verified by
   signature, so detection can improve between plugin updates. It sends nothing 
   about your site.
 * **AI second opinion**: for a file the local rules cannot judge, a redacted excerpt
   is sent for a language-model verdict in plain words. Site address, emails and
   anything key-like are removed first; wp-config.php is never sent. See External
   services.
 * **User list exposure** and **suspicious scheduled tasks**: whether the REST API
   hands your user names to anyone, and scheduled tasks that no plugin owns and 
   carry code or a web address.

Content and exposure:

 * **Injected content**: scripts, hidden iframes and spam links that attackers add
   to posts, widgets and options. Ordinary embeds and tracking codes are recognised
   and left alone.
 * **Exposed files**: readable copies of wp-config.php with the database password,
   database dumps, backup archives, .git folders, .env files and logs that your 
   web server hands out to anyone, confirmed by requesting them from your own site;
   leftover migration installers and database tools; folder listings.

Accounts and configuration:

 * **Administrator accounts**, **user registration**, **wp-config.php**, **debug
   output**, **file editor**, **XML-RPC** and **HTTPS**.

Each issue has a severity, what it means, how to fix it and the files, plugins or
settings involved. Problems of the same kind are grouped, so a site never faces 
hundreds of lines. You can ignore a problem; an ignored file comes back if it changes
again. The score starts at 100 and loses points for the most serious open issue 
of each check.

#### Login protection

 * **Stops brute-force logins**: after five failed logins from one address (you 
   choose), that address waits a cooldown you set. The lock is always temporary,
   and trusted addresses, including the one that turned the feature on, are never
   locked.
 * **Keeps user names private**: the login form stops confirming them, and visitors
   who are not logged in get none from the ?author=N trick, the REST API user list,
   embeds or the users sitemap. Logged-in requests work as before.
 * Every lockout goes to History and can raise an alert. On by default for new installs,
   off after an upgrade until you turn it on. It uses only the connection’s own 
   address, never a header a request can fake.

#### Two-factor login

 * **A second step at sign-in**: a one-time code from any authenticator app (Google
   Authenticator, Authy, 1Password and others) after the password, for each administrator
   who turns it on.
 * **No lock-outs**: the code is only required after you confirm your app makes 
   the right one; ten single-use recovery codes cover a lost phone, and `wp shieldwave
   two-factor disable <user>` rescues an account from the shell.
 * Every sign-in with the password asks for the code, from the login page or any
   other login form, such as a shop’s account page. Apps and integrations sign in
   with an application password; the plain password is refused over XML-RPC and 
   the REST API for an account with two-factor on. Codes cannot be replayed, and
   wrong codes are rate-limited.

#### Hardening

 * **Turn off the file editor**: the plugin and theme code editor leaves the dashboard,
   so a stolen administrator password cannot plant code through it. Updates keep
   working.
 * **Turn off XML-RPC**: xmlrpc.php stops offering WordPress methods, which closes
   bulk password guessing and pingback floods. ShieldWave warns you first if a plugin
   you use, such as Jetpack, needs it.
 * Both are off until you turn them on, and neither edits wp-config.php or any other
   file.

#### Alerts

 * After scheduled scans: new or more serious issues at or above your threshold (
   critical only, high and above, or medium and above).
 * In real time: when an account becomes administrator, naming who did it, and flagging
   it as urgent when nobody was signed in.
 * A weekly summary, if you want one.

#### ShieldWave dashboard (optional)

With a ShieldWave Pro or Enterprise account at [shieldwave.io](https://shieldwave.io)
you can connect the plugin with an API key: every connected site, its score and 
open issues in one list next to ShieldWave’s outside scan (TLS, security headers,
exposed files, email spoofing protection). The connection only sends results: the
dashboard cannot change a setting on the site or start anything there. A free account
can be connected too, but its results stay on your site. Without a connection, nothing
goes to ShieldWave except the opt-in features listed under External services.

#### What this plugin does not do

It is not a full web application firewall (it does not inspect and block every request),
and it does not remove malware for you. It finds, explains, alerts, stops brute-
force logins, adds two-factor login and can switch off the file editor and XML-RPC;
you, your developer or your host make the rest of the change. It adds nothing to
the pages visitors see.

#### Credits

The admin screens use the Inter typeface by The Inter Project Authors, licensed 
under the SIL Open Font License 1.1 (`assets/fonts/inter-license.txt`). It is loaded
from the plugin itself, only on the ShieldWave screens.

### External services

The plugin makes no outside requests when it is activated or when admin pages load.
Requests happen when a scan runs (by hand or on the schedule), when you use the 
account actions, and, with an account connected, in an hourly check-in. Requests
to WordPress.org and to your own site use the WordPress HTTP API’s default user 
agent, which includes your WordPress version and site address, exactly as WordPress
itself does for its update checks. Requests to ShieldWave send a neutral user agent(
ShieldWave-Security and the plugin version) and never your site address in their
headers. Like any web request, each one comes from your server’s IP address.

**WordPress.org core checksums** (api.wordpress.org/core/checksums/1.0/)
 Used by
the “WordPress core files” check. Sent: your WordPress version and package language.
Cached for a day.

**WordPress.org plugin checksums** (downloads.wordpress.org/plugin-checksums/)
 
Used by the “Plugin files” check. Sent: the folder name and version of each installed
plugin, one request per plugin. Cached for a week.

**WordPress.org theme packages** (downloads.wordpress.org/theme/)
 Used by the “
Theme files” check. The release package of each installed directory theme is downloaded
to a temporary file, hashed and deleted at once. Sent: the theme’s folder name and
version. The result is cached for a week.

**WordPress.org plugin information** (api.wordpress.org/plugins/info/1.2/)
 Used
by the “Closed and abandoned plugins” check. Sent: the folder name of each installed
plugin. Cached for a week.

All four are provided by WordPress.org: [privacy policy](https://wordpress.org/about/privacy/).

**Your own site**
 The XML-RPC, debug output and exposed files checks request a 
few URLs of your own site (xmlrpc.php, the debug.log URL, backup files found on 
disk, the uploads folder). While a scan runs, the plugin also calls your own admin-
ajax.php to continue the scan in the background.

**ShieldWave vulnerability lookup** (shieldwave.io, endpoint /api/plugin/vulnerabilities),
off until you turn it on
 Used by the “Known vulnerabilities” check. Sent when that
check runs: your WordPress version and the folder name, product name and version
of each installed plugin and theme, premium ones included. A premium plugin or theme
is matched to a vulnerability by its folder and product name. No site address, no
account, no personal data. The answer lists the vulnerabilities that apply to those
versions; the data comes from Wordfence Intelligence, and each result links to its
record with its copyright notice. Cached for a few hours.

**ShieldWave threat feed** (shieldwave.io, endpoint /api/plugin/intel), off until
you turn it on
 Used by the “Live threat feed” option. The plugin downloads a signed
file of extra malware rules and known-bad and known-good file signatures, roughly
every three hours, so detection improves between plugin updates. Sent: nothing about
your site; the only thing that leaves is your plugin version, which every request
already carries. The file is verified with a cryptographic signature before it is
used.

**ShieldWave AI second opinion** (shieldwave.io, endpoint /api/plugin/ai/review),
off until you turn it on
 Used by the “AI second opinion” option, and only for a
file the local rules cannot judge on their own. Sent: a short excerpt of that file(
the lines around the suspicious code), with your site address, email addresses and
anything that looks like a password, key or token removed first; configuration files
such as wp-config.php are never sent. ShieldWave asks a language model hosted by
Groq, Inc. and returns a plain-language verdict, which is cached by the file’s fingerprint
and shared across sites. No site address, no account, no personal data.

**ShieldWave account** (shieldwave.io), only after an administrator pastes an API
key under ShieldWave > Settings and presses Connect

 * When you connect, or press “Check account again”: the API key goes to the endpoint/
   api/license/verify on shieldwave.io to find the account and plan, and /api/plugin/
   connect receives this site’s id, address, and the plugin, WordPress and PHP versions.(
   These endpoints answer only a request that carries an API key; they are not pages.)
 * After each scan (if sending is on) or when you press “Send latest results”: the
   endpoint /api/plugin/sync receives the scan summary, the score, the open and 
   ignored issues (severity, title, message, fix, and the file, plugin or setting
   involved) and the list of installed plugins and themes with versions.
 * Hourly and after each scan, on Pro and Enterprise: the endpoint /api/plugin/heartbeat
   receives the scan status, the score and issue counts. Nothing in the answer changes
   the site: the plugin takes no settings and no commands from ShieldWave.
 * Never sent: posts, pages, comments, user names, email addresses or passwords.
   Issues about accounts are sent without the account names.
 * For a free account ShieldWave answers that the plan does not include the dashboard,
   stores nothing, and the plugin pauses these calls for 12 hours.

ShieldWave [terms of service](https://shieldwave.io/legal/en/terms-of-service) and
[privacy policy](https://shieldwave.io/legal/en/privacy-policy).

## Screenshots

[⌊Overview: whether the site is safe, what to do next, and what protects it.⌉⌊Overview:
whether the site is safe, what to do next, and what protects it.⌉[

Overview: whether the site is safe, what to do next, and what protects it.

[⌊A problem opened: what was found, how to fix it, and a button to the right WordPress
screen.⌉⌊A problem opened: what was found, how to fix it, and a button to the right
WordPress screen.⌉[

A problem opened: what was found, how to fix it, and a button to the right WordPress
screen.

[⌊Signs of a break-in: what to do now, and the file, rule and code that matched.⌉⌊
Signs of a break-in: what to do now, and the file, rule and code that matched.⌉[

Signs of a break-in: what to do now, and the file, rule and code that matched.

[⌊A scan running in the background.⌉⌊A scan running in the background.⌉[

A scan running in the background.

[⌊History: every scan and every change that matters, in plain sentences.⌉⌊History:
every scan and every change that matters, in plain sentences.⌉[

History: every scan and every change that matters, in plain sentences.

[⌊Settings: automatic scans, email alerts, extra checks and the optional ShieldWave
account.⌉⌊Settings: automatic scans, email alerts, extra checks and the optional
ShieldWave account.⌉[

Settings: automatic scans, email alerts, extra checks and the optional ShieldWave
account.

## Installation

 1. Install the plugin from Plugins > Add New, or upload the `ensomedia-security` folder
    to `/wp-content/plugins/`.
 2. Activate it.
 3. Open **ShieldWave** and press **Scan now**. The first scan records the baseline
    and usually takes a few minutes; later scans are faster.
 4. Scheduled scans run daily at 03:00 (site time). Change that, the alerts and the
    options under **ShieldWave > Settings**.
 5. Optional: turn on the known-vulnerability lookup under **ShieldWave > Settings 
    > Extra checks**.
 6. Optional: to use the ShieldWave dashboard, create an API key under API keys in 
    your ShieldWave account and paste it under **ShieldWave > Settings**.

## FAQ

### Do I need a ShieldWave account?

No. All 23 checks, scheduled scans, email alerts and the vulnerability lookup work
without one, with no limits.

### Can I hide ShieldWave from the toolbar?

Yes. Under ShieldWave > Settings > Toolbar, turn off “Show ShieldWave in the toolbar”.
The choice is per administrator. Visitors never see it.

### How is this different from other security scanners?

It trusts the files WordPress.org can vouch for, needs real evidence before it calls
something malware, and emails only about problems that are new or got worse. The
goal is that every alert you get is one you would want.

### What does “Ask your developer to check” mean?

The scanner found something unusual that is often harmless: for example a new PHP
file in a premium plugin without an update. It is listed so someone who knows the
site can look at it, it lowers the score a little, and it never sends an email on
its own. Problems under “Fix now” are the ones with clear evidence.

### A finding is about a file I changed on purpose.

Press “Mark as safe”. The file is left alone until it changes again. For a whole
setting, “Ignore” keeps it out of the score and the alerts. Ignored issues stay 
visible under Issues > Ignored.

### Will it slow my site down?

No. Scans never run while a visitor’s page loads: they work in the background in
steps of a few seconds, and later scans skip files that were clean and did not change.
On a busy shared host you can choose the low scan speed in Settings.

### Which outside requests does it make?

Only when scans run: to WordPress.org for checksums, theme packages and plugin information,
and to your own site. With the vulnerability lookup, live threat feed or AI second
opinion on: to shieldwave.io. With an account connected: to shieldwave.io. Each 
of those is off until you turn it on, and the External services section below lists
exactly what is sent.

### Why does the plugin register a public AJAX action?

The AJAX action `shieldwave_worker` lets a running scan continue in the background;
it does nothing without the random token of the running scan. The plugin’s REST 
routes answer administrators only.

### My headless front end reads authors from the REST API.

With login protection on, the REST API user list answers only logged-in requests,
so an anonymous request for an author gets an error. To keep the list public, add`
add_filter( 'shieldwave_hide_user_list', '__return_false' );` to a small plugin 
or to your theme’s functions.php. The same filter also brings back the author fields
in embeds and the users sitemap.

### Does it work on multisite?

Yes, network-wide. Scanning, the schedule, alerts, the settings screens and the 
optional ShieldWave account all live on the main site, in the Network Admin, for
network administrators only. Every other site of the network enforces the same choice
made there: when login protection, two-factor or a hardening switch is on, it is
on for that site too, with no separate settings screen to set up. A lockout after
failed logins is shared by the whole network, not counted per site, so an address
cannot dodge the limit by trying a different site.

### Does it work without WP-Cron?

Yes. If WP-Cron is disabled or loopback requests are blocked, scans still run while
the ShieldWave screen is open, and scheduled scans run whenever your server cron
calls wp-cron.php.

### How is the score calculated?

It starts at 100. For each check, the most serious open issue takes off points: 
critical 30, high 15, medium 8, low 3. Ignored issues, hints and checks that could
not run take nothing off.

### I think a finding is wrong.

Open a topic in this plugin’s support forum with the check name and what you see.
False positives are treated as bugs.

### How do I report a security problem in the plugin?

Follow https://shieldwave.io/legal/en/vulnerability-disclosure. Please do not post
it in the public support forum.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Ensomedia Security powered by shieldwave.io” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ shieldwave ](https://profiles.wordpress.org/shieldwave/)

[Translate “Ensomedia Security powered by shieldwave.io” into your language.](https://translate.wordpress.org/projects/wp-plugins/ensomedia-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/ensomedia-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/ensomedia-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/ensomedia-security/)
by [RSS](https://plugins.trac.wordpress.org/log/ensomedia-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * First release in the WordPress.org directory.
 * Builds downloaded earlier from shieldwave.io were numbered up to 3.6.6. To switch,
   deactivate and delete that copy, then install this one; the first scan starts
   the file history again.

## Meta

 *  Version **1.0.0**
 *  Last updated **17 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/ensomedia-security/)
 * Tags
 * [File Integrity](https://li.wordpress.org/plugins/tags/file-integrity/)[hardening](https://li.wordpress.org/plugins/tags/hardening/)
   [malware scanner](https://li.wordpress.org/plugins/tags/malware-scanner/)[security](https://li.wordpress.org/plugins/tags/security/)
   [vulnerability scanner](https://li.wordpress.org/plugins/tags/vulnerability-scanner/)
 *  [Advanced View](https://li.wordpress.org/plugins/ensomedia-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/ensomedia-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/ensomedia-security/reviews/)

## Contributors

 *   [ shieldwave ](https://profiles.wordpress.org/shieldwave/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/ensomedia-security/)