Local Application Firewall
Inspects relevant request URI/payload signals early in WordPress bootstrap and can block configured malicious request patterns.
OMEGA SECURITY ENGINE PRO FEATURES · WordPress Plugin 2.0.0
Complete audited feature and capability reference for Omega Security Engine Pro WordPress Plugin 2.0.0, covering all meaningful customer-facing functions.
COMPLETE CAPABILITY REFERENCE
This reference describes the product capabilities exposed to customers and administrators. Internal helper methods are represented through the capability they implement rather than published as meaningless source-code function names.
Inspects relevant request URI/payload signals early in WordPress bootstrap and can block configured malicious request patterns.
Evaluates suspicious URI patterns used by common exploit/scanning requests.
Evaluates request payload signals for configured attack indicators.
Normalizes/validates IP addresses before applying allow/block/security logic.
Administrators can manually block validated IP addresses and later unblock them.
Administrators can allow trusted IPs and remove allow entries.
Proxy-derived client IP headers are ignored unless the administrator explicitly enables/trusts that model.
Tracks failed login attempts and applies temporary lockout behavior without permanently polluting the manual block list.
Updates login-protection state appropriately after successful authentication.
Scheduled cleanup removes expired temporary security state.
Calculates trusted hashes and reports file changes through manual integrity scanning.
Scans eligible PHP/site files for configured malware/signature indicators for administrator review.
Findings do not trigger automatic overwrite or deletion of site files.
Persistent state lives under wp-content/omega-security-engine-data rather than inside the plugin folder.
Security state uses locked/atomic file writes to reduce race/partial-write problems.
Can send configured hardening headers through WordPress when enabled.
HTTP Strict Transport Security remains off by default and requires deliberate activation.
Content Security Policy remains off by default because it must be tested against the site’s real resources.
Optional HTTPS enforcement/redirect behavior under administrator control.
Includes controls that can reduce XML-RPC/pingback exposure where appropriate.
Can block common author-enumeration request patterns.
REST restriction is off by default because many WordPress integrations depend on REST; it can be enabled deliberately.
Can install/remove managed WordPress-root hardening rules where supported.
Does not force WordPress file modification constants at runtime.
Does not override these site-level constants/settings at runtime.
Does not globally strip script/style version query strings, preserving cache invalidation semantics.
Maintains local security event history for dashboard review.
Includes notification support for configured security events/maintenance where applicable.
Registers recurring cleanup/scan maintenance tasks in addition to manual scans.
Administrative actions require appropriate WordPress capability checks and nonces.
Admin interface assets are limited to Omega Security screens.
The rebuilt dashboard organizes settings/scans/logs in accessible tabbed administration.
No cloud scanning subscription, telemetry stream or vulnerability-service API key is required.
No WordPress security plugin can guarantee prevention/detection of every attack. Server/WAF/CDN/hosting security remains part of the overall security model. CSP/HSTS/REST/proxy settings are environment-sensitive and must be tested before production use.
Review the complete public-facing capability specification, pricing and licence information for Omega Security Engine Pro.