Omega Web Apps Navigation
Omega Security Engine Pro — Features
Version 1.0.0 Omega Web Apps omegawebapps.com
Omega Security Engine Pro is an enterprise‑grade, early‑load WordPress security engine engineered for real production environments where uptime, privacy, and stability matter. It applies every security protection that a WordPress plugin can safely and universally apply — including optional, isolated .htaccess hardening for Apache servers.
1. Feature Overview
1.1 Early‑Load Firewall
Blocks malicious requests before WordPress loads, dramatically reducing attack surface. Includes:
- Pattern‑based request blocking
- SQLi/XSS/RFI/LFI signature detection
- Request sanitization
- Automatic IP blocking
- Bot and scraper blocking
- Suspicious user‑agent filtering
1.2 Malware Scanner
Local, zero‑cloud malware detection engine:
- Base64 injection detection
- eval/exec/passthru payload detection
- Obfuscated code detection
- Remote include detection
- Shell/backdoor signature detection
- Daily scheduled scans
- Manual on‑demand scans
1.3 Auto‑Heal Engine
Automatically restores modified core files and quarantines suspicious files without breaking the site.
1.4 Brute‑Force Login Protection
Tracks failed login attempts, blocks abusive IPs, enforces lockout windows, and logs username attempts. Includes:
- Login attempt throttling
- IP‑based lockouts
- Username enumeration blocking
- Hidden login URL support
1.5 File Integrity Monitor
Creates snapshots of your installation and detects:
- Modified files
- Added files
- Removed files
- Timestamp changes
1.6 Hardening Engine
Applies all safe, plugin‑level hardening rules.
When enabled, Omega can also apply optional .htaccess hardening for Apache servers:
- XML‑RPC disable
- REST API restriction
- User enumeration blocking
- Directory listing disable
- Sensitive file protection (wp‑config, .env, debug.log, etc.)
- Version exposure removal
- File editing disable
- File modifications disable
- Admin exposure protection
- Optional
.htaccessrules inside a dedicated Omega marker block - Automatic backup of original
.htaccess - One‑click removal of all Omega rules
- Never overwrites the WordPress core rewrite block
- No auto‑writes — user must enable hardening
1.7 Security Status & Fix Guide
A full breakdown of:
- What Omega Security Engine Pro fixed automatically
- What Omega Security Engine Pro cannot fix
- Why certain issues cannot be fixed by any plugin
- What requires manual developer action
- What requires server‑level configuration
- What requires CDN‑level configuration
- What requires Omega Web Metrics diagnostics
1.8 Developer‑Required Fix Categories
Issues that no WordPress plugin can fix automatically are clearly identified, including:
- HTTPS redirect
- HSTS header
- Advanced security headers (CSP, X‑Frame‑Options, etc.)
- Cookie flags (Secure, HttpOnly, SameSite)
- FORCE_SSL_ADMIN in wp-config.php
- WP_DEBUG in wp-config.php
- Database prefix changes
- Mixed content
- Nginx/LiteSpeed/Cloudflare header overrides
These require manual fixes by a developer or hosting provider.
1.9 IP Manager & Logs
Full visibility into security events:
- Firewall logs
- Login guard logs
- Blocked IPs
- Manual IP block/unblock
- Real‑time attack monitoring
1.10 Zero Cloud Dependency
All scanning, blocking, and analysis are performed locally.
No telemetry, no cloud lookups, no external APIs.
Note: Optional .htaccess hardening is also fully local and never depends on external services.
1.11 WooCommerce‑Safe
Fully compatible with WooCommerce, builders, and high‑traffic production environments.