Slotbaas – Security, Scanner & Firewall
Slotbaas is de lichte totaaloplossing voor een WordPress-website die goed op slot zit. Eén overzichtelijke plugin combineert een firewall, brute-force- en wachtwoordresetbescherming, malware- en integriteitsscans…
Solid choice
Slotbaas is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 month ago, and scores 62/100 on our health check.
- Tested with the latest WordPress (7.1)
- Small user base (10+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Slotbaas stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| auto updates | >100 |
| firewall | >100 |
| login security | >100 |
| malware scanner | #83 |
| security | >100 |
Version adoption
Share of active sites per release.
About Slotbaas – Security, Scanner & Firewall
From the official readme · v1.6.9Description
Slotbaas is de lichte totaaloplossing voor een WordPress-website die goed op slot zit. Eén overzichtelijke plugin combineert een firewall, brute-force- en wachtwoordresetbescherming, malware- en integriteitsscans, beheerderscontrole en automatische updates.
Geen onnodige verzameling zware beveiligingsplugins, maar één complete beveiligingslaag die aanvallen helpt blokkeren, verdachte wijzigingen zichtbaar maakt en beheerders zelf de controle laat houden. Slotbaas is ontworpen om terughoudend met servercapaciteit om te gaan: scans draaien in kleine, gespreide stappen en de firewall blijft fail-open als een interne controle onverwacht niet kan worden uitgevoerd.
Slotbaas is ontwikkeld naar aanleiding van een echte website-inbraak die drie maanden onopgemerkt bleef. Elke detectieregel is gebaseerd op iets wat daadwerkelijk op een besmette website is aangetroffen.
De plugin beschermt de website op vier belangrijke onderdelen.
1. Nieuwe beheerders moeten worden goedgekeurd
Een ongewenst beheerdersaccount kan ervoor zorgen dat een aanvaller ook na een schoonmaak toegang houdt. Zodra een account beheerdersrechten krijgt, parkeert Slotbaas het account daarom eerst:
- De oorspronkelijke rollen en rechten worden veilig opgeslagen.
- Het account krijgt tijdelijk een rol zonder bevoegdheden.
- Inloggen wordt geblokkeerd en bestaande sessies worden beëindigd.
- De beheerder ontvangt een e-mail met gebruikersnaam, e-mailadres, IP-adres, tijdstip en de manier waarop het account is ontstaan.
De e-mail bevat afzonderlijke links om het account goed te keuren of te weigeren. Deze beveiligde links verlopen na 48 uur, werken één keer en vragen altijd om een extra bevestiging. Een geweigerd account wordt geblokkeerd maar niet automatisch verwijderd, zodat het eerst onderzocht kan worden.
2. Beveiligingsscanner
De scanner controleert onder meer op:
- PHP-bestanden in
wp-content/uploads/, waar normaal alleen media en documenten thuishoren. - Onbekende bestanden in
wp-content/mu-plugins/, die automatisch bij iedere paginaweergave worden geladen. - Verdachte pluginmappen met willekeurige achtervoegsels, zoals die bij verborgen nepplugins worden gebruikt.
- Verdachte code in drop-ins zoals
object-cache.php,advanced-cache.phpendb.php. De inhoud wordt beoordeeld, niet alleen de bestandsnaam, zodat legitieme cachebestanden worden herkend. - Aangepaste WordPress-kernbestanden, vergeleken met de officiële checksums van WordPress.org.
- Afwijkende bestandsdatums die kunnen wijzen op kunstmatig teruggezette wijzigingsdatums, met correcties voor verhuizingen, back-ups en normale updates.
- Meerdere pluginheaders in één map, een techniek waarmee schadelijke code zich als meerdere normale plugins kan presenteren.
- Oude WordPress-installaties in submappen, die bereikbaar kunnen blijven zonder nog beveiligingsupdates te ontvangen.
De scanner werkt in kleine batches met een beperkt tijdsbudget. Websites krijgen verschillende, vaste scanmomenten en een drukke server stelt scanwerk automatisch uit. Na de eerste scan wordt alleen opnieuw onderzocht wat werkelijk is veranderd. Slotbaas maakt daarbij geen terugkerende HTTP-verzoeken naar de eigen website.
Iedere bevinding toont het pad, de bestandsgrootte, relevante datums, een uitleg in gewone taal, de eerste regels van het bestand en de functie van het bestand binnen WordPress, een plugin of het actieve thema.
3. Firewall en brute-forcebescherming
De firewall controleert verzoeken voordat WordPress deze volledig verwerkt. De bescherming omvat onder andere verdachte REST-verzoeken, gebruikersopsomming, SQL-injectiepatronen, directe toegang tot PHP-bestanden in uploads, XML-RPC, auteursopsomming en misbruik van wp-login.php, admin-ajax.php en wachtwoordherstel.
IP-adressen kunnen afzonderlijk of als CIDR-bereik worden toegestaan of geblokkeerd. De optionele strenge modus kan een adres na herhaald misbruik permanent blokkeren. Vertrouwde adressen worden nooit automatisch op de blokkadelijst gezet.
De firewall werkt fail-open. Als een interne controle onverwacht niet kan worden uitgevoerd, blijft de website bereikbaar. Bij een normale paginaweergave gebruikt de firewall één reeds automatisch geladen instelling en enkele snelle tekenreekscontroles, zonder extra databasequery, bestandsbewerking of extern HTTP-verzoek.
Proxyheaders worden alleen vertrouwd wanneer de beheerder dit expliciet inschakelt en de eigen proxyadressen opgeeft. Zo kan een aanvaller de IP-controle niet omzeilen met een vervalste X-Forwarded-For-header.
4. Automatische updates
Verouderde plugins en thema’s vormen een belangrijk beveiligingsrisico. Slotbaas schakelt de gewone automatische updates van WordPress in en houdt nieuwe plugins en thema’s eveneens bij. De zichtbare schakelaars in wp-admin blijven daarbij leidend.
Zet een beheerder een automatische update handmatig uit, dan voegt Slotbaas dit onderdeel toe aan de uitzonderingslijst. Kernupdates zijn standaard beperkt tot beveiligings- en onderhoudsversies; grote versie-upgrades zijn een expliciete keuze.
Veilige, rapporterende scanner
Slotbaas wijzigt, verplaatst, herstelt of verwijdert geen aangetroffen bestanden. De scanner geeft het pad, de reden en voldoende context om een bevinding te beoordelen. Herstel WordPress-kernbestanden via Dashboard → Updates → Opnieuw installeren en behandel bevestigde malware via het bestandsbeheer van uw hosting of met hulp van een deskundige.
Taal
De beheeromgeving is volledig vertaalbaar via translate.wordpress.org. Nederlands is momenteel de brontaal.
Externe diensten
Slotbaas benadert WordPress.org uitsluitend voor de scanner:
https://api.wordpress.org/core/checksums/1.0/levert de officiële checksums voor de controle van kernbestanden. Hierbij worden de geïnstalleerde WordPress-versie en taalcode verstuurd. Deze controle kan in de instellingen worden uitgeschakeld.
Deze diensten worden beheerd door het WordPress-project. De voorwaarden staan ophttps://wordpress.org/about/terms-of-service/en het privacybeleid ophttps://wordpress.org/about/privacy/.
Slotbaas stuurt geen gegevens over de website, gebruikers of bezoekers naar HV Media. De plugin bevat geen licentiecontrole, registratie, telemetrie of analytics.
Installation
- Upload the
slotbaasfolder to/wp-content/plugins/, or install the ZIP through Plugins → Add New → Upload Plugin. - Activate the plugin through the Plugins menu.
- Go to Slotbaas → Settings and fill in the email address that should receive security notifications. This is required: until it is set, notifications fall back to the site’s admin email address and a reminder is shown.
- Add your own office IP to Firewall → Always allow so you cannot lock yourself out.
- Start a first scan at Slotbaas → File scan. It builds the baseline, which makes later scans much faster.
On activation the plugin creates its own tables, registers a capability-free role for parked accounts, records every administrator that already exists (they are never locked out), and schedules its cron events.
Emergency switches
If anything goes wrong, these constants in wp-config.php work even when you cannot log in:
define( 'HVSEC_DISABLE_ALL', true );
define( 'HVSEC_DISABLE_FIREWALL', true );
define( 'HVSEC_DISABLE_USER_GUARD', true );
define( 'HVSEC_DISABLE_SCANNER', true );
define( 'HVSEC_DISABLE_AUTO_UPDATES', true );
define( 'HVSEC_ALLOW_IP', '203.0.113.4' );
define( 'HVSEC_NOTIFY_EMAIL', 'you@example.com' );
An active emergency switch is shown as a warning on the overview screen, so a temporary measure does not silently stay in place for months.
Frequently asked questions
The scanner reported a core file, but the file looks completely normal.
Use Re-evaluate findings on the scan page. Version 1.1.0 compares core files against both your site locale and the en_US package; a site installed in English and later switched to another language used to trigger a false alarm on wp-includes/version.php.
I get lots of “back-dated modification time” findings.
That was a weakness in version 1.0.0. On a site that has been migrated or restored, every file gets a fresh inode date while keeping its original modification date. Version 1.1.0 only reports a file whose date stands out from the other files in the same directory. Press Re-evaluate findings to clear the old ones.
The scanner reports dozens of “back-dated modification time” findings about an archive folder.
Update to 1.2.0 and press Re-evaluate findings. Those findings are withdrawn automatically. What remains is one finding about the archive folder itself, which is the thing that actually needs your attention: an old WordPress installation in the web root is reachable over the internet and never updated.
Kan Slotbaas de gevonden bestanden verwijderen?
Nee. De openbare versie is bewust rapporterend en schrijft niet naar WordPress-kernmappen, pluginmappen, themamappen, de site-root of een quarantainemap. Herstel de WordPress-kern via het updatescherm en verwijder bevestigde malware via uw hostingbeheer of een deskundige.
The scan does not progress.
WP-Cron is not running. Use the Scan a bit further now button on the scan page, or set up a system cron job that calls wp-cron.php. The plugin never makes loopback requests to your own site, so DISABLE_WP_CRON with a system cron job is fully supported and is the recommended setup on a busy shared server.
I am not receiving any email.
Check whether the site can send mail at all. On shared hosting wp_mail() often does not arrive without an SMTP plugin. Until mail works, a new administrator account simply stays disabled — safe, but you will not notice it.
Does blocking `?author=N` break my author archives?
Only if your theme links to authors in that form. With pretty permalinks (/author/name/) nothing changes. The rule can be switched off.
Does blocking xmlrpc.php break anything?
It breaks the WordPress mobile app, Jetpack and pingbacks. There is a setting to allow it again.
Will automatic updates overwrite my manual choices?
No. If you switch a plugin’s auto-update off in wp-admin, Slotbaas adds it to its exclusion list and leaves it alone from then on. You can also maintain that list yourself in the settings.
Does it work on multisite?
The plugin activates and runs, and auto-update options are written as network options. It has been built and tested for single-site installations; multisite is not officially supported yet.
Changelog
Restricts all automatic scan work to a distributed local night window and supports PHP 7.4.
1.6.9
- WordPress.org compliance: file and directory locations are resolved through WordPress APIs, including
plugin_dir_path(),wp_get_upload_dir(),get_theme_root(),WPMU_PLUGIN_DIRandget_home_path(). - The public scanner is report-only and no longer moves, restores, replaces or deletes files.
- Removed writes to WordPress core directories, the site root,
.htaccess,wp-contentandmu-plugins. - Core findings now direct administrators to WordPress’ own reinstall workflow.
1.6.8
- Branding: renamed to Slotbaas – Security, Scanner & Firewall, with the matching
slotbaasslug and text domain. - WordPress.org compliance: all included quarantine, deletion and checksum-verified core-repair features are free and fully functional; no remediation code is intentionally locked.
- Safety: remediation remains administrator-initiated, nonce-protected and limited by per-file impact checks.
- WordPress.org compliance: the plugin no longer defines
DISABLE_WP_CRONor writes a rule that disableswp-cron.php; system-cron configuration remains the site owner’s or host’s responsibility. - Transparency: every WordPress.org endpoint used for checksum detection and explicit core repair is documented with the data sent, Terms of Service and Privacy Policy.
1.6.7
- Performance: unchanged scanner baselines are now marked with one bulk database update per batch instead of one write per file.
- Performance: scan batches process at most 250 files by default and wait a randomized 5–15 minutes before continuing.
- Performance: reports, update-setting synchronization and log cleanup receive stable per-site time slots to avoid server-wide synchronization spikes.
1.6.6
- New: administrators see a nonce-protected prompt to add their current trusted IP address to the firewall allowlist.
- Privacy and security: optional HV Media management IP access is explicit, disclosed and disabled by default; disabling it removes those addresses from the allowlist.
1.6.5
- Fixed: the automatic overload circuit breaker no longer blocks wp-login.php; login and password-reset rate limits continue to protect the endpoint.
- Compatibility: Axios is no longer blocked by default because legitimate webhook and booking integrations commonly use it.
1.6.4
- WordPress.org-compliance: requestgegevens worden vroeg gesaneerd en publieke CSS wordt via de enqueue-API geladen.
- Beheermeldingen zijn beperkt tot de eigen Slotbaas-schermen.
- De scanner is detectiegericht en schrijft niet meer naar kern-, plugin- of themamappen.
- Vertalingen worden via translate.wordpress.org geleverd.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Slotbaas alternatives
All auto updates plugins →FAQ
Slotbaas: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 6, 2026
Is Slotbaas free?
Yes. Slotbaas is free to download and use from the official WordPress.org plugin directory.
Is Slotbaas safe to use in 2026?
Slotbaas is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 month ago, and scores 62/100 on our health check.
How many websites use Slotbaas?
Slotbaas is active on 10+ WordPress websites and has been downloaded 140 times since it launched in September 2026. It was downloaded 82 times in the last 30 days.
Does Slotbaas work with WordPress 7.1?
Yes. The developer has tested Slotbaas up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.
What PHP version does Slotbaas need?
Slotbaas requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Slotbaas last updated?
The latest version, 1.6.9, was released on September 3, 2026 (1 month ago).
Who makes Slotbaas?
Slotbaas is developed and maintained by hvmediabv.
What are the best alternatives to Slotbaas?
The most popular alternatives to Slotbaas are Backup and Staging by WP Ti… (10K+ installs), Fuerte-WP (100+ installs) and Automatic Updates Enabled (<10 installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card