Title: Webboll Security
Author: muratkopar
Published: <strong>9, Ochobre de 2026</strong>
Last modified: 9, Ochobre de 2026

---

Guetar plugins

![](https://ps.w.org/webboll-security/assets/banner-772x250.png?rev=3736104)

![](https://ps.w.org/webboll-security/assets/icon-256x256.png?rev=3736104)

# Webboll Security

 By [muratkopar](https://profiles.wordpress.org/muratkopar/)

[Download](https://downloads.wordpress.org/plugin/webboll-security.2.9.20.zip)

 * [Details](https://ast.wordpress.org/plugins/webboll-security/#description)
 * [Reviews](https://ast.wordpress.org/plugins/webboll-security/#reviews)
 *  [Installation](https://ast.wordpress.org/plugins/webboll-security/#installation)
 * [Development](https://ast.wordpress.org/plugins/webboll-security/#developers)

 [Support](https://wordpress.org/support/plugin/webboll-security/)

## Description

Webboll Security is an advanced security plugin that protects your WordPress site
with a behavior-based approach. Instead of looking at individual requests, it reads
attacker intent early by examining the visitor’s sequence of actions.

**Free features:**

 * Custom login URLs (hide wp-admin and wp-login.php)
 * Separate admin and member login gates
 * Brute-force protection with automatic IP blocking
 * Threat engine analyzing seven attack types with risk scoring
 * REST API and XML-RPC protection
 * Two-factor authentication (2FA) for admin and member logins
 * Honeypot bot traps
 * Activity log of all security events
 * Threat report with 24-hour and 7-day summaries
 * Bot detection with reverse-DNS verification of legitimate search engine bots
 * Panic mode for one-click lockdown
 * Email notifications
 * Multi-language support (7 languages)

**Pro features:**

 * Attack-Time Shield — verification gate for suspicious visitors during active 
   attacks
 * Geo-Blocking — allow or block access by country
 * IP Reputation Databases — automatic blocking via AbuseIPDB, Spamhaus and other
   lists
 * Malware Scanner — scans files for malicious code using heuristics
 * File Integrity Monitoring — detects file changes with SHA-256 fingerprinting
 * Adaptive Learning Pool — learns attack patterns and quarantines new threats
 * IP Trajectory Analysis — tracks attacker movement across your site
 * Cloudflare Integration — real IP detection and blocking through Cloudflare
 * SMS Notifications — instant alerts for critical security events

### External services

This plugin can connect to the following third-party services. Each one is optional
and is only contacted when you enable and configure the corresponding feature. No
data is sent to any of them unless you turn the feature on.

**Cloudflare Turnstile (CAPTCHA)** — Used to verify that a login/form submission
is human when you select Turnstile as your CAPTCHA provider. When a protected form
is submitted, the visitor’s Turnstile token and IP address are sent to Cloudflare
for verification. The Turnstile script is also loaded on protected pages. Terms:
https://www.cloudflare.com/terms/ — Privacy: https://www.cloudflare.com/privacypolicy/

**hCaptcha (CAPTCHA)** — Used to verify that a submission is human when you select
hCaptcha as your CAPTCHA provider. On submission, the visitor’s hCaptcha token, 
secret key and IP address are sent to hCaptcha for verification, and the hCaptcha
script is loaded on protected pages. Terms: https://www.hcaptcha.com/terms — Privacy:
https://www.hcaptcha.com/privacy

**Google reCAPTCHA (CAPTCHA)** — Used to verify that a submission is human when 
you select reCAPTCHA as your CAPTCHA provider. On submission, the visitor’s reCAPTCHA
token and IP address are sent to Google for verification, and the reCAPTCHA script
is loaded on protected pages. Terms: https://policies.google.com/terms — Privacy:
https://policies.google.com/privacy

**ip-api.com (IP geolocation)** — Used to look up the country and network information
of an IP address shown in the IP management and threat screens. When you request
details for an IP (or geo-blocking evaluates a visitor), that IP address is sent
to ip-api.com. Terms & Privacy: https://ip-api.com/docs/legal

**NetGSM (SMS)** — Used to send SMS notifications and one-time codes if you enable
SMS and enter your NetGSM credentials. When an SMS is triggered, the destination
phone number, message text and your NetGSM credentials are sent to NetGSM. Terms&
Privacy: https://www.netgsm.com.tr/sozlesme/

**Twilio (SMS)** — Alternative SMS provider. If you enable Twilio and enter your
credentials, the destination phone number, message text and your Twilio credentials
are sent to Twilio when an SMS is triggered. Terms: https://www.twilio.com/en-us/
legal/tos — Privacy: https://www.twilio.com/en-us/legal/privacy

## Screenshots

[[

## Installation

 1. Upload the plugin files to the `/wp-content/plugins/webboll-security` directory,
    or install the plugin through the WordPress plugins screen directly.
 2. Activate the plugin through the “Plugins” screen in WordPress.
 3. Go to the WBS Security menu to configure your settings.
 4. Important: For custom login URLs to work, your WordPress Permalinks must not be
    set to “Plain” (Settings  Permalinks  choose “Post name”).

## FAQ

### Do custom login URLs work with any permalink setting?

No. WordPress cannot handle custom URL rewriting with the “Plain” permalink structure.
Set Permalinks to any option other than “Plain” (recommended: Post name).

### Does the free version provide real protection?

Yes. Brute-force protection, REST/XML-RPC protection, automatic IP blocking, the
threat engine, 2FA, and more are all included in the free version.

### Which languages are supported?

Turkish, English, Spanish, German, French, Portuguese (Brazil) and Italian.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Webboll Security” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ muratkopar ](https://profiles.wordpress.org/muratkopar/)
 *   [ Freemius ](https://profiles.wordpress.org/freemius/)

[Translate “Webboll Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/webboll-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/webboll-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/webboll-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/webboll-security/)
by [RSS](https://plugins.trac.wordpress.org/log/webboll-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.9.20

 * Raised the default Bot Detection auto-block score threshold from 8 to 15 to reduce
   false positives (a few quick page refreshes no longer risk an automatic block).
   Existing sites keep their configured value; the setting can still be changed 
   under Bot Detection  Settings.

#### 2.9.19

 * Lowered the minimum required WordPress version (“Requires at least”) from 7.0
   to 6.5 so the plugin installs and activates on current WordPress 6.x sites.

#### 2.9.18

 * Updated the Cloudflare Turnstile terms link in the External services section 
   to the Cloudflare Self-Serve Subscription Agreement (https://www.cloudflare.com/
   terms/).

#### 2.9.16

 * Updated the Plugin URI to https://webboll.com/webboll-security/.

#### 2.9.15

 * Removed the “Tested up to” header from the main plugin file; compatibility is
   now declared only in readme.txt.
 * Step-up re-authentication is now bound to the current session token, so verifying
   in one session no longer authorizes the user’s other concurrent sessions.
 * Pending 2FA state is now keyed to a cryptographically random one-time token stored
   in an HttpOnly/Secure cookie instead of IP + User-Agent, preventing shared-IP
   collisions and spoofing of the pending login.

#### 2.9.14

 * Database hardening: dynamic table names in all queries are now bound with the%
   i placeholder inside $wpdb->prepare(); table-creation (DDL) statements are annotated.
   No query interpolates a table name into a prepared string anymore.

#### 2.9.13

 * Final prefix pass: removed the last short WBS references in comments and the 
   admin menu label; everything now uses the WBSEC_/wbsec_ prefix consistently.

#### 2.9.12

 * Every echoed value (including ternary class/style outputs) is now escaped at 
   output with esc_attr/esc_html; no unescaped dynamic output remains.

#### 2.9.11

 * Redirect targets from redirect_to are now validated with wp_validate_redirect
   at both input and output, fully closing any open-redirect path after login/2FA.

#### 2.9.10

 * The shield/CAPTCHA widget now enqueues its script and uses progressive enhancement,
   removing the last inline

#### 2.9.9

 * Security: login redirects now use wp_safe_redirect with wp_validate_redirect (
   prevents open redirect after 2FA).
 * All remaining icon/notice output is escaped with wp_kses at output; honeypot 
   page styles are inline attributes (no style block).
 * Renamed the localized JS object from WBS to WBSEC_ADMIN to avoid a generic global
   name.

#### 2.9.8

 * Added the PRO badge to the Behavior Engine status card so all Pro-only features
   are marked consistently on the dashboard.

#### 2.9.7

 * Added the PRO badge to the Behavior Engine settings tab for consistency with 
   the other Pro-only tabs.

#### 2.9.6

 * Pro-only settings (behavior engine, trajectory, learning pool, shield, geo-blocking,
   reputation, file monitor, malware) are now shown as locked in the free version
   and their controls are hidden, so they can no longer appear enabled or be toggled
   where the feature is not present.

#### 2.9.5

 * Completed the prefix rename in the bundled MaxMind reader library and the icon-
   manager script, fixing the geo reader class name and the icon AJAX object so 
   they match again.

#### 2.9.4

 * Fixed AJAX action and hook names that still used the old prefix, so admin buttons(
   IP lists, bot detection, panic mode, tests) work again. Also hardened remaining
   bot-detection queries.

#### 2.9.3

 * Fixed the license-acceptance action hook that still used the old prefix, so the
   terms notice could not be dismissed.

#### 2.9.2

 * Removed remaining Google Fonts references from admin and login stylesheets; the
   UI now uses the system font stack.

#### 2.9.1

 * Fixed a fatal error on activation: class file names are now aligned with the 
   wbsec prefix used by the loader.

#### 2.9.0

 * Moved inline scripts and styles to enqueued asset files with wp_localize_script(
   login pages, IP manager, bot detection, file monitor, malware scan, trajectory,
   threat report, AI test).
 * Icon (SVG) output is escaped at every call site with a wp_kses allowlist.
 * Database table names in dynamic queries are bound with the %i placeholder.

#### 2.8.8

 * Renamed all internal prefixes (classes, options, hooks, AJAX actions, CSS classes,
   page slugs and SVG asset IDs) to a unique WBSEC_/wbsec_/wbsec- prefix throughout
   PHP, CSS, JS and SVG.

#### 2.8.7

 * Fixed: 2FA SMS is now sent through the selected SMS provider (Twilio or NetGSM);
   previously it always used NetGSM. The 2FA method label now reflects the active
   provider.

#### 2.8.6

 * The plugin-language selector is now shown only when translation files are bundled;
   otherwise a short note explains that translations are delivered via WordPress.
   org. Prevents a non-functional language dropdown.

#### 2.8.5

 * Security & compliance: SVG icons now sanitized via wp_kses allowlist; all $_SERVER
   inputs sanitized; removed external Google Fonts in favor of system fonts.

#### 2.8.4

 * WordPress.org compliance round: documented all external services in the readme;
   moved AI analysis to Pro only; replaced HEREDOC email template with output buffering;
   removed runtime FORCE_SSL_ADMIN define; language files now ship with the Pro 
   build and load conditionally; fixed plugin URI.

#### 2.8.3

 * WordPress.org compliance: trajectory viewer queries now bind the table name with
   the %i placeholder and run inline through $wpdb->prepare, removing the intermediate
   SQL variable flagged by the scanner.

#### 2.8.2

 * WordPress.org compliance: translation calls now use literal strings instead of
   variables (activity log templates, attack-type labels, icon labels); database
   queries in the trajectory viewer and audit pages are now always run through $
   wpdb->prepare.

#### 2.8.1

 * WordPress.org compliance: replaced all short echo tags (<?=) with full <?php 
   echo tags across the codebase, and fixed an interpolated variable inside a translation
   string.

#### 2.8.0

 * Free version now shows ALL Pro features consistently: Trajectory Viewer and Learning
   Pool menus appear (locked with a PRO badge) just like File Monitoring and Malware
   Scan, instead of being hidden. Clicking them shows an upgrade notice — no fatal,
   no missing menus.

#### 2.7.5

 * Aligned readme contributor with the WordPress.org account (muratkopar).

#### 2.7.4

 * Fixed: logout entries in the activity log now translate in all languages, including
   sessions where the username was empty.

#### 2.7.3

 * Activity log entries (auto-block reasons, attack type labels) now translate at
   display time across all languages, instead of showing raw Turkish.
 * REST audit “no user” label and remaining attack labels localized.
 * IP Management: fixed the “Reason” column layout — no longer squeezed vertically
   on narrow screens; tables now scroll horizontally when needed.

#### 2.7.2

 * Fixed: selected language was lost on sub-menu pages (Activity Log, Blocked IPs,
   Trajectory, etc.). The locale override now covers all plugin admin pages, so 
   the chosen language persists across every menu.

#### 2.7.1

 * Comprehensive translation coverage: login/block screens, IP management, geo-blocking
   country names, menu icon labels, Pro-lock notices, and all admin AJAX messages
   now fully localized across 6 languages.
 * Default captcha/message values no longer hard-set in Turkish; translated at display
   time.

#### 2.7.0

 * Text domain aligned with plugin slug (webboll-security) for wordpress.org translation
   compatibility.
 * Hardened input sanitization (POST/SERVER) and output escaping ahead of directory
   review.
 * Comprehensive interface translations across login, 2FA, and behavior pages.

#### 2.6.8

 * Freemius integration, premium/free separation, user guide, support box, permalink
   warning, and updated version requirements.

## Meta

 *  Version **2.9.20**
 *  Last updated **1 día ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.5 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 8.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/webboll-security/)
 * Tags
 * [Brute Force](https://ast.wordpress.org/plugins/tags/brute-force/)[firewall](https://ast.wordpress.org/plugins/tags/firewall/)
   [login](https://ast.wordpress.org/plugins/tags/login/)[security](https://ast.wordpress.org/plugins/tags/security/)
   [two factor authentication](https://ast.wordpress.org/plugins/tags/two-factor-authentication/)
 *  [Advanced View](https://ast.wordpress.org/plugins/webboll-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/webboll-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/webboll-security/reviews/)

## Contributors

 *   [ muratkopar ](https://profiles.wordpress.org/muratkopar/)
 *   [ Freemius ](https://profiles.wordpress.org/freemius/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/webboll-security/)