SMEPlan Security Shield
Scheduled security scanning (files/DB/config), baseline/integrity checks, safe quarantine & rollback, and hardening for WordPress.
Solid choice
SMEPlan Security Shield is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 weeks ago, and scores 64/100 on our health check.
- Actively developed — last update 2 weeks ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where SMEPlan Security Shield stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| backdoor | #52 |
| firewall | >100 |
| hardening | >100 |
| malware scan | >100 |
| security | >100 |
About SMEPlan Security Shield
From the official readme · v0.7.39Description
SMEPlan Security Shield is a free, open-source security plugin built around a practical WordPress operations checklist: it watches the 3 most common attack surfaces (OWASP-class attacks plus WordPress-specific ones, persistence mechanisms, and entry vectors), detects issues with baseline/checksum + signature + thresholded heuristics, and remediates safely (quarantine instead of outright deletion; 1-click rollback).
Key features
- Batched, checkpointed file scanning: prioritizes
mu-plugins, drop-ins, the active theme/plugins, anduploads; never loads the whole file tree into RAM at once. - Safe database scanning: keyset pagination (no
OFFSET) overoptions,posts,postmeta,usermeta,comments,commentmetaandtermmeta; only flags a row when it decodes into an actually executable PHP/JS token, skipping image data URIs. - Configuration checks:
.htaccess/.user.inirules that map media extensions to PHP,auto_prepend_file, file/directory permissions, weak salts/keys, unusual cron entries. - Baseline/integrity: compares core files against WordPress.org’s official checksums; automatically builds a SHA-256 baseline for every plugin/theme on install/update; 1-click restore of any mismatched core file from a signature-verified WordPress.org package, with the current file quarantined first.
- Quarantine & rollback: moves suspicious files aside (never deletes), with a full transaction log and 1-click rollback.
- Per-component backups: a “last confirmed good” snapshot of each plugin/theme, refreshed on every trusted update, checksum-verified before every restore, with a best-effort local tamper-resistance layer.
- Maintenance mode with a TTL that turns on automatically when remediation touches a hot path or a large batch, and turns itself off once a health-check passes.
- Hardening: login rate-limit/lockout by IP + IP/username (real IP behind a CDN via trusted proxies), disables XML-RPC pingback + caps
system.multicall, security headers (HSTS/X-Frame-Options/CSP Report-Only), controlled auto-updates (low-traffic time window, skips VCS-managed sites, health-check after updating). - Multi-layer scan scheduling: WP-Cron + an internal watchdog + an HMAC-signed REST endpoint (for system cron/remote pings) + a WP-CLI command — the schedule keeps running even when WP-Cron is unreliable.
- Multisite: enumerates every site by
blog_id, scanning each site’s ownuploadsfolder and tables.
Two hardening behaviours worth knowing about before you enable them, because they change how the site answers requests that are not this plugin’s own:
- User-enumeration blocking is on by default. For visitors who are not signed in, the core
wp/v2/usersREST routes stop being served and?author=<id>links redirect to the home page. This is a deliberate part of the login-hardening layer, but it is a change to an API this plugin does not own — a headless front end, a mobile app or a third-party integration that reads the public user list will see it disappear. Turn it off under Hardening if something depends on it. (rc-47) wp smeplan-ss scan runexits 75 when a scan is already running. 75 isEX_TEMPFAIL— “temporary failure, try again” — rather than 0, so a wrapper running underset -ewill treat a busy lock as a failed command. Handle 75 explicitly if you schedule the command that way. (rc-49)
Not yet in this release (planned for later versions)
- 2FA (TOTP) and CAPTCHA for the login page.
- Anonymous telemetry (opt-in).
- Translations (every string is already wrapped in
__(), ready for translators via translate.wordpress.org — no translation is bundled with the plugin itself). - Action Scheduler integration for enterprise-grade durable queuing.
Privacy Policy
By default, this plugin does not send any data outside of the site it is installed on. Everything it collects (scan findings, logs, baseline data) stays in the local WordPress database and in a protected local storage folder inside the uploads directory (wp-content/uploads/smeplan-security-shield/, blocked from direct web access).
Two features send data off-site, and both are entirely opt-in — off unless the site admin explicitly sets them up:
- Alert email: if enabled, a summary of new findings is emailed to the site’s configured admin email address (
admin_email) using WordPress’s ownwp_mail(). - Alert webhook: if the admin enters a Webhook URL in Policies, a summary (site URL, alert subject, malicious/suspicious counts, timestamp — no personal or visitor data) is sent as JSON to that admin-provided URL whenever new findings are detected. Nothing is sent anywhere unless the admin fills in this field themselves.
That storage folder outlives the plugin on purpose: deleting the plugin removes its options, cron events and capabilities, but leaves the folder in place so a quarantined file is never destroyed by an uninstall performed mid-incident. See the FAQ entry “What is removed when I delete the plugin?” for the reasoning and for how to remove it yourself.
The plugin does not phone home to any SMEPlan-operated server, does not track usage/analytics, and does not include any third-party tracking or advertising code.
Installation
- Upload the plugin to
wp-content/plugins/or install it through the Plugins screen. - Activate the plugin.
- Go to Security Shield → Wizard to check WP-Cron/loopback and configure trusted proxies if the site sits behind a CDN.
- See Security Shield → Policies to turn hardening features on/off as needed.
Frequently asked questions
Does the plugin delete suspicious files automatically?
No. Files at the “malicious” level are moved into quarantine (wp-content/uploads/smeplan-security-shield/quarantine/) rather than deleted, and can be rolled back with 1 click. Files at the “suspicious” level are only recorded, waiting for manual review on the Findings page. Quarantined files are kept for a limited time: once a session is older than the retention period set under Policies (14 days by default), it is removed automatically to stop the quarantine folder growing without bound. Roll back anything you want to keep before that window closes, or raise the retention setting.
What is removed when I delete the plugin?
Deleting the plugin removes every option it created, its scheduled events, and the three custom capabilities it grants. It deliberately does not remove its storage folder at wp-content/uploads/smeplan-security-shield/, which holds the quarantine, the file baseline, the event log and any component backups. This is a deliberate choice, not an oversight. Quarantined files are moved, not copied — the folder holds the only remaining copy of anything the plugin took out of the site. Deleting a plugin is easy to do in the middle of handling an incident, or by someone who is not the person…
Does the plugin automatically edit database content or the .htaccess file?
No. Every finding in the database or in configuration files (.htaccess/.user.ini) is only reported, never auto-fixed, to avoid breaking a site’s legitimate functionality.
Does this plugin change how WordPress updates itself?
No. It never supplies its own update source: there is no bundled update checker, no third-party update server, no filtering of the plugin-information API, and nothing written to the transients core caches available updates in. Everything WordPress installs still comes from WordPress.org, fetched and verified by WordPress itself. What it does offer — off by default, and only if you switch it on in Policies — is control over when an update WordPress has already found and verified gets applied. Using core’s own public auto_update_core / auto_update_plugin / auto_update_theme filters, it can hold…
What environment does it need?
WordPress 6.1+, PHP 7.4+. Works best when WP-Cron runs normally; if the site has DISABLE_WP_CRON set or blocks loopback requests, use system cron/WP-CLI following the instructions on the Wizard page.
Changelog
Security release. Closes scanner blind spots (PHP under node_modules, PHP behind another extension, four database tables, handler files mapping arbitrary extensions to PHP), fixes a lock guard that let two scans run at once, and stops the scheduled purge from acting on unsigned metadata. Trusted components are re-scored once in the background after updating.
Newest release only — WordPress.org truncates this section at 5,000
characters. The full history is in changelog.txt, shipped with the plugin.
0.7.39
Security and reliability release. Works through the high-severity findings of the same full-codebase review that 0.7.38 began: answers that meant “checked, clean” when nothing had been checked, places the scanners never looked, and ways stored evidence could be lost. Detection changed, so trusted components are re-scored once after the update (three per minute, in the background).
Places that were never looked at. A PHP file under any folder named node_modules or .git was only token-matched; it now gets the full analysis. A file that opens with a PHP tag is reported whatever its extension (as suspicious — never auto-quarantined). A handler file mapping an arbitrary extension to PHP (AddType application/x-httpd-php .abc) matched no rule and now does; handler files are read to 1 MB, not 64 KB. The database scan covers usermeta, comments, commentmeta, termmeta and non-public post types, checks every base64 run in a value rather than the first, and inspects both ends of an oversized value. Executable files planted in this plugin’s own storage folder are reported. languages/ in a verified plugin is exempt for translation files only.
“Clean” that was not. An aborted package walk, a backup re-check with no temp folder, and an unreadable handler file each used to read as clean. The lock’s read-back guard could not fail (it read its own cached write), so two scan ticks could run at once. Maintenance was treated as active for 900 s although WordPress stops honouring it after 600 s.
Evidence and data. The scheduled purge acts only on metadata this site signed, has a time budget, and removes a session atomically. Reinstalling over a kept storage folder no longer purges old sessions on the first tick (a one-week grace; the Purge button is unaffected). Quarantine metadata is bound to its session id. Backups are verified and extracted from one private copy, written under unique temp names, and their metadata is swapped in only after the archive. Baselines are signed over what was written, not what is found after publishing; revoking trust removes the signature too.
Smaller fixes. REST /findings no longer returns file excerpts to review-only users and include_resolved is a true superset; the replay nonce is claimed atomically; a stale Policies tab can no longer overwrite newer settings; the self-signed-certificate loopback option has a checkbox again; package-controlled text in the update-blocked message is escaped; wp smeplan-ss scan run exits non-zero when the site does not exist; network activation no longer stalls when WP-Cron is disabled; uninstall only removes a maintenance file it can prove is its own.
Older releases: see changelog.txt, included with the plugin.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best SMEPlan Security Shield alternatives
All backdoor plugins →FAQ
SMEPlan Security Shield: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 3, 2026
Is SMEPlan Security Shield free?
Yes. SMEPlan Security Shield is free to download and use from the official WordPress.org plugin directory.
Is SMEPlan Security Shield safe to use in 2026?
SMEPlan Security Shield is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 weeks ago, and scores 64/100 on our health check.
How many websites use SMEPlan Security Shield?
SMEPlan Security Shield is active on <10 WordPress websites and has been downloaded 386 times since it launched in September 2026. It was downloaded 344 times in the last 30 days.
Does SMEPlan Security Shield work with WordPress 7.1?
Yes. The developer has tested SMEPlan Security Shield up to WordPress 7.1.2, the latest release. It requires WordPress 6.1 or newer.
What PHP version does SMEPlan Security Shield need?
SMEPlan Security Shield requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was SMEPlan Security Shield last updated?
The latest version, 0.7.39, was released on September 21, 2026 (2 weeks ago).
Who makes SMEPlan Security Shield?
SMEPlan Security Shield is developed and maintained by solotop.
What are the best alternatives to SMEPlan Security Shield?
The most popular alternatives to SMEPlan Security Shield are Cleverhog Malware Scanner (70+ installs), Deep Malware Cleaner (50+ installs) and Malroot Security (20+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card
