CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan
Download CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan 1.0.2Description
At a glance
CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan v1.0.2 — free WordPress plugin download. Key facts: updated September 28, 2026 · requires WordPress 5.8+ & PHP 7.4+.
CenterShield is a WordPress security plugin built for Japanese site owners and the
agencies that maintain their sites.
It brings login protection, two-factor authentication, hardening, file protection and
malware scanning together in one place. Every setting explains what it protects and
what changes when you turn it on, so you can choose the measures your site needs
without security expertise.
The admin interface and all messages are in Japanese only.
Activating the plugin changes nothing on your site. Press “apply recommended settings”
to enable the recommended set in one step, or turn on each feature yourself.
Account and login protection
- Login attempt limiting (brute force protection)
- Username disclosure prevention
- Custom login URL
- HTTP Basic authentication on the login screen (written to .htaccess on Apache)
- reCAPTCHA v2 / v3
- Two-factor authentication (authenticator app, email, backup codes), with an optional grace period and a 30-day “remember this device” option
- XML-RPC disabling (signed Jetpack requests are still allowed)
- IP address restriction for the admin area
Disabling unused features and weak settings
- Pingback
- REST API restriction (well known plugins such as Contact Form 7, Jetpack and WooCommerce stay allowed)
- Author archive pages
- Theme and plugin file editor, application passwords
- Unneeded tags in wp_head, such as the WordPress version, the RSD link and emoji scripts
File and server protection
- Blocking direct access to wp-includes, wp-config.php, configuration and backup files
- Blocking PHP execution in the uploads folder
- Disabling directory listing
- Security headers such as X-Frame-Options
- Removing publicly readable files such as readme.html
- Permission review and correction
Ongoing protection
- Input filtering (lightweight WAF)
- Comment spam blocking (honeypot, rate limit, previous spam history)
- Detection of plugins and themes that have gone two years without an update or are not tested with your version of WordPress
Malware scanning
- Comparison against official checksums for WordPress core and plugins hosted on WordPress.org. Differences limited to comments or line endings are reported as informational
- Matching against a known vulnerability database
- Pattern matching against malware signatures bundled with the plugin and updated from the author’s server
- Change detection against the previous scan, for themes and plugins that are not on WordPress.org
- Database inspection of posts, widgets and administrator accounts
- Quarantine, restore from the official original, and difference display
External services
This plugin connects to the following external services. No site content, post data
or user data is transmitted to any of them, and every request identifies itself with a
fixed user agent rather than the WordPress default, which would carry your site address.
api.wpcenter.jp (WP Center, the plugin author)
Used to download malware signature definitions and known vulnerability data. The
request is sent when the plugin checks for definition updates and when a scan needs
vulnerability data. What is sent: the plugin version, and the metadata that any web
request carries, namely your server IP address and a fixed user agent string
(“WPCenterSecurity/” followed by the plugin version) that does not contain your site address. What is
received: signature definitions, their digital signature, and vulnerability records.
Your site address and the list of plugins and themes installed on your site are never
sent; matching is performed locally on your site.
Terms of service: https://wpcenter.jp/plugin-terms/
Privacy policy: https://wpcenter.jp/privacy/
The vulnerability records served from this endpoint originate from Wordfence
Intelligence, provided by Defiant, Inc., and include CVE records from the MITRE
Corporation. Copyright designations for both are shown with every record in the
scan results, and the Wordfence Intelligence terms are reproduced in
licenses/wordfence-intelligence-terms.txt inside this plugin. WP Center is not
affiliated with, endorsed by or sponsored by Wordfence or Defiant, Inc.
Wordfence Intelligence: https://www.wordfence.com/threat-intel/
Wordfence Intelligence terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
Wordfence privacy policy: https://www.wordfence.com/privacy-policy/
CVE terms of use: https://www.cve.org/Legal/TermsOfUse
api.wordpress.org and downloads.wordpress.org
Used to obtain official checksums during a scan. What is sent: the WordPress version
and locale, and the slug and version of each plugin being verified. What is received:
file checksums.
WordPress.org privacy policy: https://wordpress.org/about/privacy/
core.svn.wordpress.org and plugins.svn.wordpress.org
Used only when you press “compare with the original” or “restore the original” on a
scan result. What is sent: the version and file path of the file being retrieved.
What is received: that single original file, from the official WordPress.org
repository.
WordPress.org privacy policy: https://wordpress.org/about/privacy/
www.google.com (reCAPTCHA)
Used only if you enable reCAPTCHA and enter your own keys. The reCAPTCHA script is
then loaded on the forms you select, and the token is verified against Google. What
is sent: the reCAPTCHA token, your secret key and the visitor IP address.
Google terms: https://policies.google.com/terms
Google privacy policy: https://policies.google.com/privacy
Third-party resources
- Vulnerability data: Wordfence Intelligence Vulnerability Database (https://www.wordfence.com/threat-intel/). Copyright Defiant, Inc. CVE records copyright The MITRE Corporation. Redistributed under the Wordfence Intelligence Terms and Conditions, a copy of which is included in licenses/wordfence-intelligence-terms.txt. Each record displays its copyright designation in the scan results.
- Original file comparison: the public WordPress.org checksum API and SVN repositories.
- Part of the malware definitions: Linux Malware Detect (LMD) signatures, Copyright R-fx Networks, GNU GPL v2, https://github.com/rfxn/linux-malware-detect, incorporated under the terms of the GPL. Known malicious domains: URLhaus (abuse.ch, CC0, https://urlhaus.abuse.ch/).
- QR code generation: qrcode-generator v1.4.4, Copyright (c) 2009 Kazuhiko Arase, MIT License (assets/js/qrcode.min.js).
Frequently asked questions
What do I get when I download CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan?
CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan 1.0.2 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations.
Does CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan cost anything?
No. CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan 1.0.2 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.
How do I install CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan 1.0.2?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan?
CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan 1.0.2 requires WordPress 5.8 or higher and PHP 7.4 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan last updated?
Version 1.0.2 was last updated on September 28, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 1.0.2 |
|---|---|
| Last updated | September 28, 2026 |
| Requires WordPress | 5.8 or higher |
| Requires PHP | 7.4 or higher |
| Author | WPセンター |
| Tags | 2fa, firewall, login, malware, security |
Download CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan
Download CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan WP PluginNote: if the download does not start, disable your ad blocker and try again.