Title: Locktura Security
Author: Alain Lankers
Published: <strong>Gortheren 31, 2026</strong>
Last modified: Est 29, 2026

---

Search plugins

![](https://ps.w.org/locktura/assets/banner-772x250.png?rev=3629932)

![](https://ps.w.org/locktura/assets/icon.svg?rev=3629932)

# Locktura Security

 By [Alain Lankers](https://profiles.wordpress.org/alainlankers/)

[Download](https://downloads.wordpress.org/plugin/locktura.2.5.1.zip)

 * [Details](https://cor.wordpress.org/plugins/locktura/#description)
 * [Reviews](https://cor.wordpress.org/plugins/locktura/#reviews)
 *  [Installation](https://cor.wordpress.org/plugins/locktura/#installation)
 * [Development](https://cor.wordpress.org/plugins/locktura/#developers)

 [Support](https://wordpress.org/support/plugin/locktura/)

## Description

Locktura Security brings modular WordPress protection, monitoring, maintenance, 
and alerts into one dashboard. Most protection runs locally; enable only what your
site needs.

#### Included modules

 * **Firewall** – Attack filtering and cache-aware protection.
 * **Brute Force Defense** – Login limits, bans, and unban controls.
 * **Hardening** – User enumeration, editor, XML-RPC, feed, hotlink, and server-
   exposure controls.
 * **Update Manager** – Updates, Software Health, rollback, and cleanup.
 * **Access Control** – IP lists, exclusions, and automatic bans.
 * **Geo Blocking** – Country rules and crawler verification.
 * **Hide Login** – Custom login URL and route protection.
 * **Anti-Spam Shield** – Local CAPTCHA and form or comment protection.
 * **Usernames & 2FA** – Username audits, TOTP, passkeys, recovery codes, role rules,
   and least-privilege Locktura permissions.
 * **Password Manager** – Policies, resets, risk scans, and breach checks.
 * **Email Alerts** – Configurable security notifications.
 * **Security Logs** – Tamper-evident local events, integrity checks, and export.
 * **Live Traffic** – Requests, visitors, bots, filters, and geolocation.
 * **User Log** – Tamper-evident account, content, and settings activity.
 * **File Scanner** – File and configuration checks, official checksum verification,
   incremental integrity scans, deployment windows, quarantine, and restore.
 * **File Permissions** – Permission checks, fixes, and history.
 * **SSL Control** – HTTPS, certificate, proxy, backup, and rollback.
 * **Email Encoder** – Email inventory and obfuscation.

#### Separate Premium plugin

Locktura Premium is separately distributed outside WordPress.org and is not included
in this package. Every Free feature above works without a license.

The separate Premium plugin adds:

 * **Pattern Recognition**
 * **Behavior Analytics**
 * **Admin Lockdown**
 * **Virtual Patching**
 * **Header Hardening**
 * **API Guardian**
 * **Neural Bot Suppressor**
 * **Network Reputation Control**
 * **Domain Security**
 * **Malware Scanner & Cleanup**
 * **Smart 404**
 * **Extra Hardening Tools**
 * **Monthly Reports**
 * **Session Management**
 * **Extra User Safety Tools**
 * **Premium Signature Pack**

### Privacy

Locktura stores security data locally, including IP addresses, request and login
details, usernames, events, alert settings, password-policy and 2FA settings, encrypted
TOTP secrets, public passkey credential data, hashed recovery codes, enrollment 
state, scan history, and update history. Passkey private keys remain on the user’s
authenticator and are never stored by Locktura. Optional geolocation and password-
breach checks use the services below. Administrators control retention, recipients,
lookups, and privacy settings.

### External services

Locktura loads no scripts, styles, fonts, or images from third parties. It makes
only the requests documented below when the related feature is enabled or used.

#### WordPress.org and extension update providers

Used for core, plugin, and theme update checks and downloads through WordPress.org
and update endpoints declared by installed extensions. Requests occur during administrator-
requested or scheduled checks and can contain the site URL, software versions, locale,
and extension metadata. A manual Software Health scan and enabled Trusted Integrity
Scanner also request official WordPress.org core and plugin checksums; the Software
Health scan can additionally request plugin last-update metadata. These checksum
requests contain the installed version, locale, and plugin slug. Scan results, local
baselines, integrity findings, and update history are stored locally. Local file
contents are never sent to WordPress.org by the integrity scanner.

Documentation: https://developer.wordpress.org/apis/handbook/wordpress-org/update-
api/ and https://developer.wordpress.org/cli/commands/plugin/verify-checksums/
 
Policies: https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-
guidelines/ and https://wordpress.org/about/license/ Privacy: https://wordpress.
org/about/privacy/

#### Have I Been Pwned Pwned Passwords

Used for optional breach checks through `https://api.pwnedpasswords.com/range/{first5-
sha1}`. Only the first five characters of the password’s SHA-1 hash are sent, never
the password or complete hash. Results can be cached locally, and stored status 
is discarded when the credential changes.

Documentation: https://haveibeenpwned.com/API/v3#PwnedPasswords
 Terms: https://
haveibeenpwned.com/TermsOfUse Privacy: https://haveibeenpwned.com/Privacy

#### Geolocation providers

When enabled geolocation needs uncached data and no trusted country header exists,
Locktura sends the public IP being looked up. Results can be cached locally for 
24 hours. Providers are tried in this order:

 * Country (`https://api.country.is/{ip}`) – Primary provider. Service information
   and privacy: https://country.is/ | Source and self-hosting: https://github.com/
   lineofflight/country
 * IPWhois (`https://ipwho.is/{ip}`) – First fallback. Documentation: https://ipwhois.
   io/documentation | Terms: https://ipwhois.io/terms | Privacy: https://ipwhois.
   io/privacy
 * ipapi.co (`https://ipapi.co/{ip}/json/`) – Final fallback. Documentation: https://
   ipapi.co/api/ | Terms: https://ipapi.co/terms/ | Privacy: https://ipapi.co/privacy/

#### Own-site HTTPS and TLS checks

SSL Control checks the configured `home_url()` or `site_url()`. An administrator-
requested HEAD request or TLS handshake sends ordinary network metadata and a Locktura
user-agent to the site’s own host. System Health also sends five small daily GET
requests to the configured `home_url()`: one random missing path, three fixed sensitive
paths, and the homepage. These requests check public exposure and unexpected external
redirects. Response bodies and possible secrets are never stored; only status information
is retained. No third-party endpoint is selected by Locktura.

#### Site-configured email delivery

Enabled alerts and tests can contain the recipient, site URL, event type, timestamp,
IP address, relevant context, and remediation links. WordPress uses the site’s configured
mail transport; Locktura selects no provider.

#### Locktura website links

Links to `https://locktura.com/` open only after an administrator clicks them; there
are no background calls.

Terms: https://locktura.com/terms-and-conditions/
 Privacy: https://locktura.com/
privacy-policy/

### Translations

Dutch translations are managed through translate.wordpress.org and delivered by 
WordPress when an approved package is available.

### Bundled assets

Runtime assets are bundled locally. Flag Icons, QRCode for JavaScript, and lbuchs/
WebAuthn use the MIT License; Inter and Bebas Neue use the SIL Open Font License
1.1. The modified Wikimedia Commons world map is public domain. Source and license
details are included under `assets/` and `vendor/lbuchs/`. Locktura artwork is GPLv2
or later.

## Screenshots

[⌊Security Overview with the protection score, security activity, blocked threats,
scans, and blocked login attempts.⌉⌊Security Overview with the protection score,
security activity, blocked threats, scans, and blocked login attempts.⌉[

Security Overview with the protection score, security activity, blocked threats,
scans, and blocked login attempts.

[⌊Recent security alerts with the most active threat categories, threat distribution,
and blocked countries.⌉⌊Recent security alerts with the most active threat categories,
threat distribution, and blocked countries.⌉[

Recent security alerts with the most active threat categories, threat distribution,
and blocked countries.

[⌊Traffic and blocked-login activity with an overview of installed Locktura security
modules.⌉⌊Traffic and blocked-login activity with an overview of installed Locktura
security modules.⌉[

Traffic and blocked-login activity with an overview of installed Locktura security
modules.

[⌊Module management overview showing active protections and the current status of
each module.⌉⌊Module management overview showing active protections and the current
status of each module.⌉[

Module management overview showing active protections and the current status of 
each module.

[⌊Brute Force settings with protection controls, detection rules, security activity,
and current status.⌉⌊Brute Force settings with protection controls, detection rules,
security activity, and current status.⌉[

Brute Force settings with protection controls, detection rules, security activity,
and current status.

[⌊Hardening settings for reducing common WordPress attack surfaces and protecting
sensitive files and services.⌉⌊Hardening settings for reducing common WordPress 
attack surfaces and protecting sensitive files and services.⌉[

Hardening settings for reducing common WordPress attack surfaces and protecting 
sensitive files and services.

[⌊Firewall settings with request protection controls, rule configuration, and current
protection status.⌉⌊Firewall settings with request protection controls, rule configuration,
and current protection status.⌉[

Firewall settings with request protection controls, rule configuration, and current
protection status.

## Installation

 1. Upload the `locktura` folder to `/wp-content/plugins/`, or install it through the
    WordPress Plugins screen.
 2. Activate Locktura Security and open the Locktura dashboard.
 3. Review the modules, enable the protections you need, and save changed settings.

## FAQ

### Is the firewall included?

Yes. Locktura Security includes the firewall with bundled community rules.

### Do all listed Free features work without a license?

Yes. Every feature listed under Included in this plugin works without a license 
and has no time or usage restrictions. The separately distributed Premium plugin
is not included in this package.

### Do I need a cloud account?

No. Protection runs locally. Only the optional features documented under External
services make network requests.

### Does Locktura Security store security logs?

Yes. Security events are stored locally for administrator review. New records are
linked and signed so unexpected changes or missing records can be detected. Existing
records remain available as legacy logs after upgrading.

### Can IP addresses be anonymized?

Yes. An IP anonymization setting is available.

### Do users need a passkey?

No. Passkeys and physical security keys are optional. Existing authenticator-app
2FA keeps working without re-enrollment, and the familiar 2FA screen remains the
default after password login.

### Where do users manage 2FA?

Users manage their own authenticator app, passkeys, and recovery codes under Users
> Profile. Administrators can require 2FA by role, set a grace period, review enrollment
status, and reset 2FA without seeing user secrets.

### What does the Permissions tab control?

It separates Locktura access into viewing security, managing blocks, running scans,
repairing files, managing policy, and clearing logs. Administrators retain full 
access; other roles or individual users receive only the permissions you assign.
Permission changes require a fresh 2FA verification.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Locktura Security” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Alain Lankers ](https://profiles.wordpress.org/alainlankers/)

“Locktura Security” has been translated into 1 locale. Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/locktura/contributors)
for their contributions.

[Translate “Locktura Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/locktura)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/locktura/), check out
the [SVN repository](https://plugins.svn.wordpress.org/locktura/), or subscribe 
to the [development log](https://plugins.trac.wordpress.org/log/locktura/) by [RSS](https://plugins.trac.wordpress.org/log/locktura/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.5.1

 * Improved File Integrity Monitoring with faster adaptive background scans and 
   more accurate file-based progress.
 * Improved deployment-aware integrity checks and grouped FIM security logging.

#### 2.5.0

 * Added System Health and Public Exposure checks, and expanded Software Health 
   reporting.
 * Expanded MFA policy, step-up protection, account permissions, and unsafe-username
   controls.
 * Added Firewall Block and Monitor Only modes, WooCommerce Safe mode, and improved
   Cache Guard behavior.
 * Improved Security Logs, User Logs, and File Integrity Monitoring workflows and
   reporting.
 * Improved Access Control, Password Manager, File Scanner, and SSL Control navigation.
 * Improved request sanitization and translation metadata across Free security modules.

#### 2.4.4

 * Added Free Identity Security with optional passkeys, self-service 2FA, role-based
   grace periods, encrypted TOTP storage, and configurable step-up protection for
   critical actions while preserving existing 2FA enrollments.
 * Added a Free Permissions tab with separate Locktura capabilities for viewing,
   blocks, scans, file repair, policy changes, and log clearing, assignable by WordPress
   role or user.
 * Added Free Software Health checks for abandoned plugins, update sources, and 
   official WordPress.org file checksums.
 * Added Free Security Logs integrity protection with a hash chain, signed checkpoints,
   background verification, local retention, and a separate log-deletion capability.
 * Added the Free Trusted Integrity Scanner with official Core and WordPress.org
   plugin checksums, full local baselines, incremental background scans, deployment
   windows, and automatic update rescans.
 * Improved Security Logs pagination and dashboard grid layout.
 * Fixed password-reset compatibility with Hide Login and improved Semantic Decode
   Shield event logging.
 * Improved Geo Blocking IP handling and regional controls, plus File Scanner status
   and detection accuracy.

#### 2.4.3

 * Improved dashboard and Live Traffic reporting with more consistent aggregation
   and country details.
 * Improved password-strength checks and security-log timezone handling.
 * Confirmed compatibility with WordPress 7.1 and refreshed public documentation.

#### 2.4.2

 * Improved user and 2FA management with filtering, pagination, role-aware guidance,
   and session controls.
 * Added hashed, one-time recovery codes for existing authenticator-app 2FA accounts.
 * Improved file-permission guidance and support for approved hosting-specific permissions.

## Meta

 *  Version **2.5.1**
 *  Last updated **13 our ago**
 *  Active installations **10+**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 8.0 or higher **
 *  Languages
 * [Dutch](https://nl.wordpress.org/plugins/locktura/) and [English (US)](https://wordpress.org/plugins/locktura/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/locktura)
 * Tags
 * [Brute Force](https://cor.wordpress.org/plugins/tags/brute-force/)[firewall](https://cor.wordpress.org/plugins/tags/firewall/)
   [hardening](https://cor.wordpress.org/plugins/tags/hardening/)[security](https://cor.wordpress.org/plugins/tags/security/)
   [two factor authentication](https://cor.wordpress.org/plugins/tags/two-factor-authentication/)
 *  [Advanced View](https://cor.wordpress.org/plugins/locktura/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/locktura/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/locktura/reviews/)

## Contributors

 *   [ Alain Lankers ](https://profiles.wordpress.org/alainlankers/)

## Support

Issues resolved in last two months:

     1 out of 1

 [View support forum](https://wordpress.org/support/plugin/locktura/)