Stalza Security

Përshkrim

Stalza Security protects your site without weighing it down. Instead of hundreds of generic warnings, it tells you what changed, why it matters, how confident the detection is, and what to do.

Detect Correlate Assess Risk Explain Protect Verify

Free features

  • File & WordPress integrity — core, plugin and theme checksums plus a local baseline for everything else.
  • Malware detection — heuristic analysis of PHP, JS and .htaccess files; no signature database needed.
  • Vulnerability detection — daily check of your installed components against known advisories (opt-in).
  • Brute-force protection — login, XML-RPC and REST user-enumeration limits with escalating lockouts.
  • Security hardening — one-click fixes and clear advisories for common misconfigurations.
  • Security events & reports — a single timeline of what happened, with a weekly digest.

Designed to be light

  • Zero frontend queries unless a login attempt is being evaluated.
  • Scans run in small resumable chunks with CPU and memory budgets.
  • No autoloaded option bigger than 50 KB. No bundled React runtime — uses the one WordPress already ships.

Premium

Stalza Security Pro extends the same engine with cloud threat intelligence, real-time protection, behavioral analysis, automatic remediation, IP reputation and advanced alerting.

External services

This plugin works fully offline by default. Nothing is sent anywhere until you opt in.

If you enable Vulnerability intelligence in Settings, the plugin sends the slugs and version numbers of your installed WordPress core, plugins and themes, plus your site URL, to https://stalza.com/api/stalza-security/v1/vulnerabilities/match once per day to receive matching security advisories. No user data, content or visitor information is included. See the Stalza privacy policy and terms.

Integrity checks fetch official checksums from WordPress.org (api.wordpress.org, downloads.wordpress.org), the same service WordPress core uses for updates.

Instalim

  1. Upload the plugin to /wp-content/plugins/stalza-security/ or install it from the Plugins screen.
  2. Activate it.
  3. Go to Stalza Security in the admin menu and run your first scan.

PBR

Does it slow down my site?

No. On the frontend the plugin does nothing unless a login, XML-RPC or user-listing request is being evaluated. Scans run in the background in small chunks.

Does it send data to Stalza?

Only if you enable vulnerability intelligence, and then only component names and versions. See “External services” above.

Is it compatible with other security plugins?

Yes, but running two brute-force limiters can double-count attempts. Disable one.

Shqyrtime

Për këtë shtojcë s’ka shqyrtime.

Kontribues & Zhvillues

“Stalza Security” është software me burim të hapur. Në këtë shtojcë kanë dhënë ndihmesë personat vijues.

Kontribues

Regjistër ndryshimesh

1.2.0

Features:

  • snapshot: add posture Collector with stable payload hash
  • snapshot: add Repository with retention prune
  • snapshot: add snapshots table and bump DB version to 3
  • snapshot: add structured Diff for posture payloads
  • snapshot: admin Snapshot tab, Dashboard card, and settings
  • snapshot: auto-capture on updates with cooldown and dedupe
  • snapshot: REST API and SnapshotModule registration
  • snapshot: settings defaults and REST allowlist

Bug Fixes:

  • snapshot: capture at bulk batch end; defer core marker until success
  • snapshot: lint-clean admin UI and use ConfirmDialog for delete
  • snapshot: stop list endpoint decoding full payloads; harden release build

1.1.1

Bug Fixes:

  • login: use site hostname as TOTP authenticator issuer

1.1.0

Features:

  • login: add free-tier two-factor authentication
  • login: free-tier two-factor authentication
  • vuln: allow filtering the live vulnerability match URL
  • vuln: live match URL filter + fixture fallback docs

Bug Fixes:

  • ci: satisfy prettier and PHPCS for live-vuln merge
  • ci: stylelint empty-line rules in style.scss
  • vuln: use offline label for fixture source

1.0.1

Fixes:

  • WordPress.org review prep: declare submitter as contributor; confirm Plugin URI and privacy/terms links on stalza.com
  • Admin list tables use shared DataTable + server pagination

1.0.0

Features:

  • admin: Settings, Dashboard, and Scan UX for v1 launch (Epic E7) (#9)
  • integrity: pause/resume/cancel scans; skip Hardening-removed core docs noise
  • malware: heuristic scan job + Scan-tab findings triage
  • vuln: opt-in match client with fixture fallback filtered to installed inventory
  • reports: weekly digest builder and cron
  • Free modules: Integrity M2, Login M2, Hardening, Malware, Vulnerabilities, Reports, Events

Bug Fixes:

  • vuln: do not surface fixture advisories for patched/absent components
  • integrity: silent-reseed own plugin baseline on version bump; keep same-version tamper
  • admin: hash navigation for TabPanel; Plugin Check ABSPATH on helpers
  • build: exclude .worktrees and agent dirs from release zips

Full history: https://stalza.com/docs/stalza-security/changelog