Locktura Security
Locktura Security brings modular WordPress protection, monitoring, maintenance, and alerts into one dashboard. Most protection runs locally; enable only what your site needs.
Included modules
- Firewall – Attack filtering and cache-aware protection.
- Brute Force Defense – Login limits, bans, and unban controls.
- Hardening – User enumeration, editor, XML-RPC, feed, hotlink, and server-exposure controls.
- Update Manager – Updates, Software Health, rollback, and cleanup.
- Access Control – IP lists, exclusions, and automatic bans.
- Geo Blocking – Country rules and crawler verification.
- Hide Login – Custom login URL and route protection.
- Anti-Spam Shield – Local CAPTCHA and form or comment protection.
- Usernames & 2FA – Username audits, TOTP, passkeys, recovery codes, role rules, and least-privilege Locktura permissions.
- Password Manager – Policies, resets, risk scans, and breach checks.
- Email Alerts – Configurable security notifications.
- Security Logs – Tamper-evident local events, integrity checks, and export.
- Live Traffic – Requests, visitors, bots, filters, and geolocation.
- User Log – Tamper-evident account, content, and settings activity.
- File Scanner – File and configuration checks, official checksum verification, incremental integrity scans, deployment windows, quarantine, and restore.
- File Permissions – Permission checks, fixes, and history.
- SSL Control – HTTPS, certificate, proxy, backup, and rollback.
- Email Encoder – Email inventory and obfuscation.
Separate Premium plugin
Locktura Premium is separately distributed outside WordPress.org and is not included in this package. Every Free feature above works without a license.
The separate Premium plugin adds:
- Pattern Recognition
- Behavior Analytics
- Admin Lockdown
- Virtual Patching
- Header Hardening
- API Guardian
- Neural Bot Suppressor
- Network Reputation Control
- Domain Security
- Malware Scanner & Cleanup
- Smart 404
- Extra Hardening Tools
- Monthly Reports
- Session Management
- Extra User Safety Tools
- Premium Signature Pack
Privacy
Locktura stores security data locally, including IP addresses, request and login details, usernames, events, alert settings, password-policy and 2FA settings, encrypted TOTP secrets, public passkey credential data, hashed recovery codes, enrollment state, scan history, and update history. Passkey private keys remain on the user’s authenticator and are never stored by Locktura. Optional geolocation and password-breach checks use the services below. Administrators control retention, recipients, lookups, and privacy settings.
External services
Locktura loads no scripts, styles, fonts, or images from third parties. It makes only the requests documented below when the related feature is enabled or used.
WordPress.org and extension update providers
Used for core, plugin, and theme update checks and downloads through WordPress.org and update endpoints declared by installed extensions. Requests occur during administrator-requested or scheduled checks and can contain the site URL, software versions, locale, and extension metadata. A manual Software Health scan and enabled Trusted Integrity Scanner also request official WordPress.org core and plugin checksums; the Software Health scan can additionally request plugin last-update metadata. These checksum requests contain the installed version, locale, and plugin slug. Scan results, local baselines, integrity findings, and update history are stored locally. Local file contents are never sent to WordPress.org by the integrity scanner.
Documentation: https://developer.wordpress.org/apis/handbook/wordpress-org/update-api/ and https://developer.wordpress.org/cli/commands/plugin/verify-checksums/ Policies: https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/ and https://wordpress.org/about/license/ Privacy: https://wordpress.org/about/privacy/
Have I Been Pwned Pwned Passwords
Used for optional breach checks through https://api.pwnedpasswords.com/range/{first5-sha1}. Only the first five characters of the password’s SHA-1 hash are sent, never the password or complete hash. Results can be cached locally, and stored status is discarded when the credential changes.
Documentation: https://haveibeenpwned.com/API/v3#PwnedPasswords Terms: https://haveibeenpwned.com/TermsOfUse Privacy: https://haveibeenpwned.com/Privacy
Geolocation providers
When enabled geolocation needs uncached data and no trusted country header exists, Locktura sends the public IP being looked up. Results can be cached locally for 24 hours. Providers are tried in this order:
- Country (
https://api.country.is/{ip}) – Primary provider. Service information and privacy: https://country.is/ | Source and self-hosting: https://github.com/lineofflight/country - IPWhois (
https://ipwho.is/{ip}) – First fallback. Documentation: https://ipwhois.io/documentation | Terms: https://ipwhois.io/terms | Privacy: https://ipwhois.io/privacy - ipapi.co (
https://ipapi.co/{ip}/json/) – Final fallback. Documentation: https://ipapi.co/api/ | Terms: https://ipapi.co/terms/ | Privacy: https://ipapi.co/privacy/
Own-site HTTPS and TLS checks
SSL Control checks the configured home_url() or site_url(). An administrator-requested HEAD request or TLS handshake sends ordinary network metadata and a Locktura user-agent to the site’s own host. System Health also sends five small daily GET requests to the configured home_url(): one random missing path, three fixed sensitive paths, and the homepage. These requests check public exposure and unexpected external redirects. Response bodies and possible secrets are never stored; only status information is retained. No third-party endpoint is selected by Locktura.
Site-configured email delivery
Enabled alerts and tests can contain the recipient, site URL, event type, timestamp, IP address, relevant context, and remediation links. WordPress uses the site’s configured mail transport; Locktura selects no provider.
Locktura website links
Links to https://locktura.com/ open only after an administrator clicks them; there are no background calls.
Terms: https://locktura.com/terms-and-conditions/ Privacy: https://locktura.com/privacy-policy/
Translations
Dutch translations are managed through translate.wordpress.org and delivered by WordPress when an approved package is available.
Bundled assets
Runtime assets are bundled locally. Flag Icons, QRCode for JavaScript, and lbuchs/WebAuthn use the MIT License; Inter and Bebas Neue use the SIL Open Font License 1.1. The modified Wikimedia Commons world map is public domain. Source and license details are included under assets/ and vendor/lbuchs/. Locktura artwork is GPLv2 or later.
