Plugin screenshot thumbnail 1/8
Plugin screenshot thumbnail 2/8
Plugin screenshot thumbnail 3/8
Plugin screenshot thumbnail 4/8
Plugin screenshot thumbnail 5/8
Plugin screenshot thumbnail 6/8
Plugin screenshot thumbnail 7/8
Plugin screenshot thumbnail 8/8
FeatureLite (Free)Pro
Security scanner (14 checks)✓✓
CMS config / headers / CSP checks✓✓
Login brute-force protection✓✓
Audit logging30 days365 days
Console commands✓✓
Scan historyLast 10Unlimited
Scheduled scans (queue-based)—✓
CP alerts on failed scan—✓
Email notifications—✓
Slack / Discord / Webhook—✓
IP restriction (CP + frontend, CIDR)—✓
HTTP Basic Auth—✓
File integrity monitoring—✓
REST API—✓
Multi-site scans—✓
Rate limiting—✓
WAF / request filtering—✓
Geo-blocking—✓
Dashboard analytics + trends—✓
Risk score trending—✓
Auto-remediation suggestions—✓

Modules

Scanner

Runs 14 security checks against your site and produces a risk score (0–100):

  • CMS Configuration — dev mode, admin changes, test email, session duration, GraphQL origins
  • HTTPS — verifies site is served over TLS
  • CSRF Protection — confirms CSRF tokens are enabled
  • File Permissions — checks .env, config/, web/index.php for unsafe permissions
  • PHP Version — flags EOL or soon-to-expire PHP versions
  • HTTP Headers — X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
  • Content Security Policy — checks for CSP header presence and configuration
  • CORS — validates cross-origin resource sharing settings
  • CMS Version — flags outdated Craft CMS installations
  • Plugin Versions — checks for plugins with available updates
  • Database Security — table prefix usage, default credentials
  • Admin Accounts — flags accounts using weak or default usernames
  • SSL Certificate — checks certificate expiry
  • File Permissions (detailed) — world-readable/writable sensitive paths

Risk score weights: Critical (+25), High (+15), Medium (+8), Low (+3), Warning (+1).

Shield

Active request-level protection. Checks run on every request, ordered cheapest to most expensive:

  1. IP blocklist — in-memory cached lookup → 403
  2. Login lockout — brute-force threshold check → 403
  3. IP allowlist — optional restrict-to-list mode → 403
  4. Geo-blocking (Pro) — country-based blocking → 403
  5. Rate limiting — cache-based atomic increments → 429
  6. WAF rules (Pro) — compiled regex patterns for SQL injection, XSS, path traversal, user-agent filtering → 403

Sentinel

Monitoring and audit trail:

  • Audit log — tracks logins, logouts, failed logins, element saves/deletes, plugin installs, project config changes, user events
  • File integrity (Plus+) — SHA-256 baselines stored in the database; detects modified, added, or deleted files in monitored paths

Default monitored paths: vendor/craftcms/cms/src/, config/, .env, web/index.php.

Beacon

Multi-channel notifications (Pro+):

  • Email — via Craft's built-in mailer
  • Slack — webhook URL
  • Discord — webhook URL
  • Webhook — generic POST with JSON payload

Triggers: scan failure, threat detection, login lockout.

Lite

Pro

Plus $79/year after one year.

Installation Instructions

To install this plugin, copy the command above to your terminal.

Reviews

This plugin doesn't have any reviews.

Active Installs
11
Version
5.1.6
License
Craft
Compatibility
Craft 5
Last release
August 19, 2026
Activity (30 days)
0
Closed Issues
0
Open Issues
0
Merged PRs
0
Open PRs