Stalza Security

Description

Stalza Security protects your site without weighing it down. Instead of hundreds of generic warnings, it tells you what changed, why it matters, how confident the detection is, and what to do.

Detect Correlate Assess Risk Explain Protect Verify

Free features

  • File & WordPress integrity — official core and repository plugin checksums plus a local baseline for other files.
  • Malware detection — heuristic analysis of PHP, JS and .htaccess files; no signature database needed.
  • Vulnerability detection — daily check of your installed components against known advisories (opt-in).
  • Brute-force protection — login, XML-RPC and REST user-enumeration limits with escalating lockouts.
  • Security hardening — one-click fixes and clear advisories for common misconfigurations.
  • Security events & reports — a single timeline of what happened, with a weekly digest.

Designed to be light

  • Resumable background scans and bounded protection checks on applicable requests.
  • Scans run in small resumable chunks with CPU and memory budgets.
  • No autoloaded option bigger than 50 KB. No bundled React runtime — uses the one WordPress already ships.

Premium

Stalza Security Pro adds manual quarantine and guarded recovery, license management and signed updates. Guided Safe Repair is in development and is not yet a customer release. Real-time protection, automatic remediation and other future capabilities are not included in the current release.

External services

Vulnerability matching is opt-in. Integrity checks contact WordPress.org for official checksums and packages; the plugin is not entirely offline.

If you enable Vulnerability intelligence in Settings, the plugin sends the slugs and version numbers of your installed WordPress core, plugins and themes, plus your site URL, to https://stalza.com/api/stalza-security/v1/vulnerabilities/match once per day to receive matching security advisories. No user data, content or visitor information is included. See the Stalza privacy policy and terms.

Integrity checks fetch official checksums from WordPress.org (api.wordpress.org, downloads.wordpress.org), the same service WordPress core uses for updates.

Installation

  1. Upload the plugin to /wp-content/plugins/stalza-security/ or install it from the Plugins screen.
  2. Activate it.
  3. Go to Stalza Security in the admin menu and run your first scan.

FAQ

Does it slow down my site?

Scans run in background chunks to limit server pressure. Login, XML-RPC and user-listing protection performs bounded work when applicable. Performance depends on your site and host.

Does it send data to Stalza?

Opt-in vulnerability matching sends component slugs, versions and your site URL to Stalza. Integrity checks contact WordPress.org. See “External services” above.

Is it compatible with other security plugins?

Yes, but running two brute-force limiters can double-count attempts. Disable one.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Stalza Security” is open source software. The following people have contributed to this plugin.

Contributors

Translate “Stalza Security” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.3.0

Features:

  • Shared checksum-backed official-file preparation, guarded atomic replacement and exact finding compare-and-set for Pro manual Safe Repair.
  • Integrity findings expose the separately licensed manual repair preview and recovery flow when Pro is active.

Security and fixes:

  • Preserve recovery keys and journal on Free removal instead of orphaning originals.
  • Load WordPress file helpers for unattended cron downloads.
  • Correct Pro availability and external-service disclosures.

1.2.1

Bug Fixes:

  • core: drop all plugin tables on uninstall; correct feature matrix versions
  • integrity: skip content-verified silence index.php in uploads

1.2.0

Features:

  • snapshot: add posture Collector with stable payload hash
  • snapshot: add Repository with retention prune
  • snapshot: add snapshots table and bump DB version to 3
  • snapshot: add structured Diff for posture payloads
  • snapshot: admin Snapshot tab, Dashboard card, and settings
  • snapshot: auto-capture on updates with cooldown and dedupe
  • snapshot: REST API and SnapshotModule registration
  • snapshot: settings defaults and REST allowlist

Bug Fixes:

  • snapshot: capture at bulk batch end; defer core marker until success
  • snapshot: lint-clean admin UI and use ConfirmDialog for delete
  • snapshot: stop list endpoint decoding full payloads; harden release build

1.1.1

Bug Fixes:

  • login: use site hostname as TOTP authenticator issuer

1.1.0

Features:

  • login: add free-tier two-factor authentication
  • login: free-tier two-factor authentication
  • vuln: allow filtering the live vulnerability match URL
  • vuln: live match URL filter + fixture fallback docs

Bug Fixes:

  • ci: satisfy prettier and PHPCS for live-vuln merge
  • ci: stylelint empty-line rules in style.scss
  • vuln: use offline label for fixture source

Full history: https://stalza.com/docs/stalza-security/changelog