Thessley Security Hardening
Download Thessley Security Hardening 1.0.21Description
At a glance
Thessley Security Hardening v1.0.21 is a free WordPress plugin with updated September 27, 2026, requires WordPress 6.0+ & PHP 7.4+. Download the latest GPL version below — free, with live demo included.
Thessley Security Hardening is a modular security plugin. Each feature is a self-contained module you can enable, configure, and put into log-only or enforcing mode independently — nothing is all-or-nothing.
Perimeter
- IP Blocklist — blocks traffic from public IP-reputation feeds (CINS, DShield, Spamhaus DROP, FireHOL), merged and compiled into a single range list, plus a local list other modules can escalate into.
- Geo Blocker — blocks or allows traffic by country, using a compiled IP-to-country dataset (DB-IP Country Lite) checked before WordPress finishes loading.
- Geo Login — restricts wp-login.php specifically to an allow-list of countries, independent of the site-wide Geo Blocker.
- Rate Limiter — throttles requests per IP site-wide, escalating sustained floods into the shared local blocklist.
Request inspection
- Query Guard — inspects query strings and request bodies for SQL injection, XSS, path traversal, command injection, and obfuscated-payload signatures.
- Login Guard — rate-limits failed logins per IP, with a configurable lockout window.
Detection
- File Integrity — verifies core files against WordPress.org’s published checksums, and plugins/themes against a local baseline you take yourself.
- Malware Scanner — scans plugin, theme, and upload files for webshell markers, obfuscated eval/assert chains, and injected-spam patterns.
- Vulnerability Scan — flags outdated, removed, and unmaintained plugins/themes.
- User Watchdog — watches privileged accounts for the changes a backdoor actually makes: new admin accounts, role escalation, hidden users.
Hardening
- Security Headers — standard hardening response headers, including opt-in HSTS for sites behind a TLS-terminating proxy.
- User Enumeration — blocks anonymous username harvesting via author-scan URLs and the REST users endpoint.
- Hardening — disables the file editor, blocks PHP execution in uploads, and flags hidden/disguised plugins.
Overview
- Event Log — a filterable, searchable record of everything every module has seen, with a 1–20 severity score per event.
- Event Map — blocked/logged events tinted on a world map by country.
- Activity Log — the mundane admin audit trail: who published, deleted, installed, or changed what.
Ops
- Auto Updates — per-plugin auto-update control, including a “flagged only” mode driven by the Vulnerability Scan’s findings.
- Alerts — a real-time Telegram message and/or email when an event crosses a severity threshold you set, independently per channel.
Bundled third-party assets
- World map outline used by the Event Map module: flekschas/simple-world-map, CC BY-SA 3.0.
External services
This plugin connects to third-party services to power its blocking, geolocation, vulnerability-lookup and alerting features. Activating the plugin makes no external request. Every service below is contacted only after the site admin acts on the module that owns it: saving that module’s settings, clicking its refresh/test button, or entering credentials for it. The one exception is WordPress.org’s own API (api.wordpress.org), which File Integrity and Vulnerability Scan query on their scheduled scans.
For every service the entry says what it is, which server is contacted, whether an account is needed, what is sent and when, and links its Terms and Privacy Policy.
How requests identify themselves. Requests to the feed, Jetpack, trusted-networks, unwantedip, WPScan and Telegram servers are sent with the User-Agent wp-thessley/<version> (or wp-thessley) so this site’s address is not leaked in WordPress’ default User-Agent. The DB-IP download and the api.wordpress.org calls use WordPress’ standard User-Agent, which includes the site address, exactly as WordPress core’s own update checks do.
IP-reputation feeds (IP Blocklist module)
Plain-text lists of malicious IP addresses and ranges. The plugin downloads the chosen lists once a day (and when you click Refresh) and compiles them into a local blocklist that is checked on each request. Each is a single anonymous HTTP GET for a public text file. No account is needed, and nothing about this site or its visitors is sent. All feeds are opt-in: the source list starts empty and is only populated when you save the IP Blocklist settings.
- CINS Army list — server
cinsscore.com(https://cinsscore.com/list/ci-badguys.txt), operated by Sentinel IPS / Nomic Networks. Terms: https://sentinelips.com/terms — Privacy: https://sentinelips.com/privacy - SANS DShield block list — server
feeds.dshield.org(https://feeds.dshield.org/block.txt), operated by the SANS Internet Storm Center. About: https://www.dshield.org/about.html — Privacy: https://www.dshield.org/privacy.html - Spamhaus DROP — server
www.spamhaus.org(https://www.spamhaus.org/drop/drop.txt). Fair Use Policy: https://www.spamhaus.org/blocklists/drop-fair-use-policy/ — Terms: https://www.spamhaus.org/terms-conditions/ — Privacy: https://www.spamhaus.org/privacy-notice/ - FireHOL blocklist-ipsets (levels 1 and 2) and the ET Tor exit-node list — server
raw.githubusercontent.com(path/firehol/blocklist-ipsets/master/, three files). These are the FireHOL project’s own published data lists, distributed from GitHub. Each is a plain-text list of IP addresses and CIDR ranges: no scripts, stylesheets, images or other code. They are downloaded server-side, parsed as text into a local range table, and never executed or loaded by a visitor’s browser. GitHub Terms: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service — Privacy: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement
unwantedip.eagleeye-intelligence.com (IP Sharing module and IP Blocklist feed)
A self-hosted IP-reputation tracker run by this plugin’s author. Server: unwantedip.eagleeye-intelligence.com. It is used in three ways, all opt-in:
- IP Sharing requires an API key. An account is needed, but it collects nothing personal: clicking “Sign up for an API key” on the IP Sharing page creates one automatically from the IP address the request comes from (no name, email, site name or domain is asked for or sent). Once enabled, each time this site actually blocks a request it sends the blocked IP address, a short category (for example “WordPress Login Brute Force Attempt”) and a severity label, with your API key, at most once per IP per hour. Nothing about this site, its domain, its users or its visitors’ other activity is sent. Reported IPs are public by design: each reported address gets a public page on unwantedip, so only enable sharing if you are comfortable with that. The service’s Privacy Policy explains this in full.
- Feed (optional source in IP Blocklist):
https://unwantedip.eagleeye-intelligence.com/api/v1/feed/wordpressis a read-only GET of the list of WordPress-targeting IPs. It requires the same API key, which is sent as a request header; nothing else is sent. - Links: the IP column of the Event Log and Bot Log links to
https://unwantedip.eagleeye-intelligence.com/ip/<ip>in a new tab. Nothing is sent unless an admin clicks the link.
Terms: https://unwantedip.eagleeye-intelligence.com/terms.html — Privacy: https://unwantedip.eagleeye-intelligence.com/privacy-policy.html
wp-opsec.eagleeye-intelligence.com (Whitelist module: trusted-networks list)
A service run by this plugin’s author that publishes crawler-nets.conf, a plain-text list of the IP ranges used by legitimate search-engine, AI and monitoring crawlers (Google, Bing, DuckDuckGo, OpenAI and others), updated automatically from those operators’ own published ranges. The Whitelist module uses it so genuine crawlers are not blocked by the other modules.
- Server contacted:
wp-opsec.eagleeye-intelligence.com, one file:https://wp-opsec.eagleeye-intelligence.com/wp-content/uploads/wp-opsec/crawler-nets.conf - Account needed: No.
- When: opt-in. The Whitelist page pre-fills the URL field with this address as a suggestion only; nothing is fetched until you save the page. It is then refreshed daily and when you click Refresh. Clear the field to turn remote fetching off, or replace it with your own URL.
- Data sent: none. It is a single anonymous GET request for a static file, with the
wp-thessley/<version>User-Agent. Nothing about this site, its users or its visitors is sent. The server’s standard web-server access log records the requesting IP address and time. - Terms / Privacy: the file is static and no account or personal data is collected, so there is no separate policy page. Contact for any question or removal request: [email protected]
DB-IP Country Lite (Geo Blocker and Geo Login modules)
A compiled IP-to-country dataset. Server: download.db-ip.com (https://download.db-ip.com/free/dbip-country-lite-YYYY-MM.csv.gz). It is downloaded when you first save the Geo Blocker settings or click its Refresh button (Geo Login uses the same dataset), then refreshed weekly, and looked up locally, so no visitor IP address is ever sent to DB-IP. No account is needed. Nothing is sent beyond the download request itself. Source: https://db-ip.com — Privacy: https://db-ip.com/privacy.php — Dataset licensed CC BY 4.0: https://creativecommons.org/licenses/by/4.0/
api.wordpress.org (File Integrity and Vulnerability Scan modules)
WordPress.org’s own API. No account is needed.
- File Integrity fetches WordPress core’s official checksums from
https://api.wordpress.org/core/checksums/1.0/to compare against this site’s core files. It sends this site’s WordPress version and locale, the same two values core itself sends for its own update checks. - Vulnerability Scan queries
https://api.wordpress.org/plugins/info/1.0/<slug>.jsonfor each installed plugin to see whether it is still listed, closed or long unmaintained. It sends the slug of each installed plugin being checked, and nothing else about this site.
Terms/Privacy: https://wordpress.org/about/privacy/
Jetpack IP list (Query Guard module)
Opt-in, only when XML-RPC blocking is enabled. Fetches Automattic’s published Jetpack IP range list (https://jetpack.com/ips-v4.txt, server jetpack.com) so xmlrpc.php requests genuinely coming from Jetpack’s own servers can be exempted. No account is needed and nothing is sent beyond the request for the list. Terms: https://automattic.com/tos/ — Privacy: https://automattic.com/privacy/
WPScan API (Vulnerability Scan module)
Opt-in. Adds known-CVE data for installed plugins and themes. Server: wpscan.com (https://wpscan.com/api/v3/). An account is needed: a free WPScan API token that you obtain yourself at https://wpscan.com/api and enter on the Vulnerability Scan page. Sent: the slug of each installed plugin/theme being checked and your API token, once per plugin/theme per 24 hours (results are cached). No other site data is sent. Terms: https://wpscan.com/terms/ — Privacy: https://automattic.com/privacy/
Telegram Bot API (Alerts module)
Opt-in. Sends a message to a Telegram chat you control when a security event exceeds the severity threshold you configure. Server: api.telegram.org. An account is needed: a Telegram bot token (from @BotFather) and a chat ID that you provide. Sent, only when a qualifying event fires (or when you press “Send test”): the site name and domain, the module and event name, the action taken, the offending IP address, a short detail string and a timestamp. Terms: https://telegram.org/tos — Privacy: https://telegram.org/privacy
Email alerts (Alerts module)
Opt-in. Uses this site’s own mail system, not a third-party service, so nothing is sent to any server listed here.
Frequently asked questions
What is Thessley Security Hardening?
Thessley Security Hardening is a free WordPress plugin available under the GPL license. The current version is 1.0.21.
Is Thessley Security Hardening free to download?
Yes — Thessley Security Hardening 1.0.21 is a free GPL download with no hidden fees, no account needed, and no feature locked behind a paywall in this package.
How do I install Thessley Security Hardening 1.0.21?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for Thessley Security Hardening?
Thessley Security Hardening 1.0.21 requires WordPress 6.0 or higher and PHP 7.4 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was Thessley Security Hardening last updated?
Version 1.0.21 was last updated on September 27, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the Thessley Security Hardening download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 1.0.21 |
|---|---|
| Last updated | September 27, 2026 |
| Requires WordPress | 6.0 or higher |
| Requires PHP | 7.4 or higher |
| Author | thessleysecurity |
| Tags | brute-force, firewall, geo-blocking, malware, security |
Download Thessley Security Hardening
Download Thessley Security Hardening WP PluginNote: if the download does not start, disable your ad blocker and try again.