OMEGA SECURITY ENGINE PRO FEATURES · WordPress Plugin 2.0.0

Omega Security Engine Pro features

Complete audited feature and capability reference for Omega Security Engine Pro WordPress Plugin 2.0.0, covering all meaningful customer-facing functions.

COMPLETE CAPABILITY REFERENCE

33 meaningful customer-facing capabilities documented from the audited 2.0.0 engine

This reference describes the product capabilities exposed to customers and administrators. Internal helper methods are represented through the capability they implement rather than published as meaningless source-code function names.

Local Application Firewall

Inspects relevant request URI/payload signals early in WordPress bootstrap and can block configured malicious request patterns.

Malicious URI Detection

Evaluates suspicious URI patterns used by common exploit/scanning requests.

Malicious Payload Detection

Evaluates request payload signals for configured attack indicators.

Validated Client IP Handling

Normalizes/validates IP addresses before applying allow/block/security logic.

IP Block List

Administrators can manually block validated IP addresses and later unblock them.

IP Allow List

Administrators can allow trusted IPs and remove allow entries.

Safe Proxy Header Opt-In

Proxy-derived client IP headers are ignored unless the administrator explicitly enables/trusts that model.

Brute-Force / Login Guard

Tracks failed login attempts and applies temporary lockout behavior without permanently polluting the manual block list.

Successful Login Reset Logic

Updates login-protection state appropriately after successful authentication.

Expired Lockout Cleanup

Scheduled cleanup removes expired temporary security state.

File Integrity Baseline/Scan

Calculates trusted hashes and reports file changes through manual integrity scanning.

Manual Malware Scan

Scans eligible PHP/site files for configured malware/signature indicators for administrator review.

No Automatic File Healing

Findings do not trigger automatic overwrite or deletion of site files.

Protected Security Data Directory

Persistent state lives under wp-content/omega-security-engine-data rather than inside the plugin folder.

Atomic Locked JSON Storage

Security state uses locked/atomic file writes to reduce race/partial-write problems.

Optional Security Headers

Can send configured hardening headers through WordPress when enabled.

HSTS Opt-In

HTTP Strict Transport Security remains off by default and requires deliberate activation.

CSP Opt-In

Content Security Policy remains off by default because it must be tested against the site’s real resources.

HTTPS Redirect Option

Optional HTTPS enforcement/redirect behavior under administrator control.

XML-RPC / Pingback Controls

Includes controls that can reduce XML-RPC/pingback exposure where appropriate.

Author Enumeration Protection

Can block common author-enumeration request patterns.

Optional REST Restriction

REST restriction is off by default because many WordPress integrations depend on REST; it can be enabled deliberately.

Root .htaccess Hardening

Can install/remove managed WordPress-root hardening rules where supported.

No Forced DISALLOW_FILE_MODS

Does not force WordPress file modification constants at runtime.

No Forced FORCE_SSL_ADMIN/WP_DEBUG

Does not override these site-level constants/settings at runtime.

Asset Version Preservation

Does not globally strip script/style version query strings, preserving cache invalidation semantics.

Security Logs

Maintains local security event history for dashboard review.

Optional Security Email Notifications

Includes notification support for configured security events/maintenance where applicable.

Scheduled Maintenance

Registers recurring cleanup/scan maintenance tasks in addition to manual scans.

Capability & Nonce Protection

Administrative actions require appropriate WordPress capability checks and nonces.

Scoped Admin Assets

Admin interface assets are limited to Omega Security screens.

Accessible Dashboard Tabs

The rebuilt dashboard organizes settings/scans/logs in accessible tabbed administration.

Local-First Operation

No cloud scanning subscription, telemetry stream or vulnerability-service API key is required.

Safety and lifecycle controls

Published technical boundaries

No WordPress security plugin can guarantee prevention/detection of every attack. Server/WAF/CDN/hosting security remains part of the overall security model. CSP/HSTS/REST/proxy settings are environment-sensitive and must be tested before production use.

Product page and commercial specification

Review the complete public-facing capability specification, pricing and licence information for Omega Security Engine Pro.

View Omega Security Engine Pro