{"id":273886,"date":"2026-01-29T17:56:28","date_gmt":"2026-01-29T17:56:28","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/security-watchdog-lite\/"},"modified":"2026-09-19T18:25:45","modified_gmt":"2026-09-19T18:25:45","slug":"lumiverse-security-watchdog-lite","status":"publish","type":"plugin","link":"https:\/\/fi.wordpress.org\/plugins\/lumiverse-security-watchdog-lite\/","author":13133672,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"4.2.0","stable_tag":"4.2.0","tested":"7.1.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Watchdog Security Lite \u2014 Powered by Lumiverse Nexus","header_author":"Lumiverse Dynamic","header_description":"Modular background scanner: tracks new plugins, new admin users and scans changed .js files for malware signatures. Sends email alerts. Options to harden your installation.","assets_banners_color":"47628e","last_updated":"2026-09-19 18:25:45","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/lumiversenexus.com\/lite\/","header_author_uri":"https:\/\/lumiversenexus.com\/","rating":5,"author_block_rating":0,"active_installs":70,"downloads":1231,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.3":{"tag":"1.1.3","author":"bestseogr","date":"2026-01-29 17:58:48","revision":3449891},"3.0.0":{"tag":"3.0.0","author":"bestseogr","date":"2026-04-24 11:14:46","revision":3514548},"3.0.1":{"tag":"3.0.1","author":"bestseogr","date":"2026-04-24 17:24:43","revision":3514817},"3.0.3":{"tag":"3.0.3","author":"bestseogr","date":"2026-04-24 19:12:11","revision":3514879},"3.0.4":{"tag":"3.0.4","author":"bestseogr","date":"2026-05-20 18:58:01","revision":3539897},"3.5.6":{"tag":"3.5.6","author":"bestseogr","date":"2026-06-13 09:14:19","revision":3570881},"3.6.7":{"tag":"3.6.7","author":"bestseogr","date":"2026-07-02 07:21:48","revision":3593508},"3.8.2":{"tag":"3.8.2","author":"bestseogr","date":"2026-07-24 04:06:55","revision":3620731},"3.8.3":{"tag":"3.8.3","author":"bestseogr","date":"2026-07-24 06:30:23","revision":3620847},"4.0.15":{"tag":"4.0.15","author":"bestseogr","date":"2026-09-07 19:58:38","revision":3685514},"4.1.0":{"tag":"4.1.0","author":"bestseogr","date":"2026-09-10 17:22:59","revision":3690260},"4.2.0":{"tag":"4.2.0","author":"bestseogr","date":"2026-09-19 18:25:45","revision":3703545}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3514546,"resolution":"128x128","location":"assets","locale":"","width":250,"height":250}},"assets_banners":{"banner-772x250.png":{"filename":"banner-772x250.png","revision":3514538,"resolution":"772x250","location":"assets","locale":"","width":2149,"height":732}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.3","3.0.0","3.0.1","3.0.3","3.0.4","3.5.6","3.6.7","3.8.2","3.8.3","4.0.15","4.1.0","4.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3685504,"resolution":"1","location":"assets","locale":"","width":1657,"height":794},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3685502,"resolution":"2","location":"assets","locale":"","width":1648,"height":779},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3685501,"resolution":"3","location":"assets","locale":"","width":1650,"height":629},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3685499,"resolution":"4","location":"assets","locale":"","width":1654,"height":576},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3685511,"resolution":"5","location":"assets","locale":"","width":1646,"height":788},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3685510,"resolution":"6","location":"assets","locale":"","width":1342,"height":766},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3685509,"resolution":"7","location":"assets","locale":"","width":1647,"height":822},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3685508,"resolution":"8","location":"assets","locale":"","width":1644,"height":752}},"screenshots":{"1":"Watchdog Lite dashboard with Live Pulse and protection overview.","2":"Vulnerability Watch Lite with severity and update guidance.","3":"Integrity Center with core and repository comparisons.","4":"Optional administrator TOTP 2FA setup.","5":"Real Time Activity.","6":"Malware scanner and MU-plugin coverage.","7":"Traffic Shield.","8":"Nexus Threat Network Lite controls."}},"plugin_section":[],"plugin_tags":[1174,55021,600,1909,227904],"plugin_category":[54],"plugin_contributors":[84570],"plugin_business_model":[],"class_list":["post-273886","plugin","type-plugin","status-publish","hentry","plugin_tags-firewall","plugin_tags-malware-scanner","plugin_tags-security","plugin_tags-two-factor-authentication","plugin_tags-woocommerce-security","plugin_category-security-and-spam-protection","plugin_contributors-bestseogr","plugin_committers-bestseogr"],"banners":{"banner":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/banner-772x250.png?rev=3514538","banner_2x":false,"banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/icon-128x128.png?rev=3514546","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/screenshot-1.png?rev=3685504","caption":"Watchdog Lite dashboard with Live Pulse and protection overview."},{"src":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/screenshot-2.png?rev=3685502","caption":"Vulnerability Watch Lite with severity and update guidance."},{"src":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/screenshot-3.png?rev=3685501","caption":"Integrity Center with core and repository comparisons."},{"src":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/screenshot-4.png?rev=3685499","caption":"Optional administrator TOTP 2FA setup."},{"src":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/screenshot-5.png?rev=3685511","caption":"Real Time Activity."},{"src":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/screenshot-6.png?rev=3685510","caption":"Malware scanner and MU-plugin coverage."},{"src":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/screenshot-7.png?rev=3685509","caption":"Traffic Shield."},{"src":"https:\/\/ps.w.org\/lumiverse-security-watchdog-lite\/assets\/screenshot-8.png?rev=3685508","caption":"Nexus Threat Network Lite controls."}],"raw_content":"<!--section=description-->\n<p><strong>Watchdog Security Lite<\/strong> is the free WordPress security edition powered by <strong>Lumiverse Nexus<\/strong>.<\/p>\n\n<p>It combines practical local protection with a fast, visual security dashboard designed to answer three simple questions:<\/p>\n\n<ul>\n<li><strong>What is happening on my website?<\/strong><\/li>\n<li><strong>What is Watchdog protecting?<\/strong><\/li>\n<li><strong>What may still need my attention?<\/strong><\/li>\n<\/ul>\n\n<p>Watchdog Lite is built with performance in mind. Heavy work is kept away from normal visitor requests wherever possible, and the dashboard avoids turning every unusual request into an attack claim.<\/p>\n\n<h4>Highlights<\/h4>\n\n<ul>\n<li><strong>Traffic Shield Lite<\/strong> - conservative protection against suspicious request pressure, probes and selected XML-RPC abuse.<\/li>\n<li><strong>Login Guard<\/strong> - protects WordPress login from repeated failed attempts and obvious abuse.<\/li>\n<li><strong>Malware Scanner<\/strong> - local file scanning with change-aware coverage and MU-plugin support.<\/li>\n<li><strong>Vulnerability Watch Lite<\/strong> - checks installed WordPress components against Nexus vulnerability intelligence.<\/li>\n<li><strong>Official File Integrity<\/strong> - compares WordPress core and supported WordPress.org components with trusted sources.<\/li>\n<li><strong>Safe Core Repair<\/strong> - manually restores verified WordPress core files with a protected restore point.<\/li>\n<li><strong>Security &amp; Exposure Check<\/strong> - reviews local protection and highlights practical attack-surface items that may deserve attention.<\/li>\n<li><strong>Attack Stories<\/strong> - groups related protection events into readable activity sequences instead of repetitive log noise.<\/li>\n<li><strong>Watchdog Live Pulse<\/strong> - a real-data visual view of recent traffic, bots and protection activity.<\/li>\n<li><strong>Site Change Watch Lite<\/strong> - records important administrator, plugin, theme and risky file changes.<\/li>\n<li><strong>Optional administrator TOTP 2FA<\/strong> - authenticator-app protection with one-time recovery codes.<\/li>\n<li><strong>WooCommerce Bot Cart Guard Lite<\/strong> - helps stop obvious automation from creating unwanted cart or wishlist state.<\/li>\n<li><strong>Weekly Security Digest<\/strong> - optional weekly email with useful protection and security-health signals.<\/li>\n<li><strong>Nexus Threat Network Lite<\/strong> - optional shared security intelligence and contributor participation.<\/li>\n<\/ul>\n\n<h4>Security you can understand<\/h4>\n\n<p>Watchdog Lite does more than display raw logs.<\/p>\n\n<p><strong>Security &amp; Exposure Check<\/strong> reviews practical configuration and attack-surface signals, while <strong>Attack Stories<\/strong> groups related Traffic Shield and Login Guard events into a readable sequence. The goal is to help site owners understand what Watchdog actually observed and what it actually restricted.<\/p>\n\n<p>Watchdog does not invent attack events for visual effect.<\/p>\n\n<h4>WooCommerce-aware protection<\/h4>\n\n<p>WooCommerce stores receive cart, wishlist, checkout, AJAX, crawler and catalog traffic that should not all be treated the same way.<\/p>\n\n<p>Watchdog Lite includes store-aware request protection and <strong>WooCommerce Bot Cart Guard Lite<\/strong>, which can neutralize supported cart and wishlist mutations from crawler-claimed or obvious automation while leaving public pages available.<\/p>\n\n<h4>Optional TOTP two-factor authentication<\/h4>\n\n<p>TOTP 2FA is optional and configured separately by each administrator. It protects the standard WordPress administrator login and provides one-time recovery codes.<\/p>\n\n<p>Watchdog Lite does not force 2FA after installation or when Recommended Local Protection is applied.<\/p>\n\n<h4>Nexus Threat Network Lite<\/h4>\n\n<p>Nexus Threat Network Lite is <strong>disabled by default<\/strong>.<\/p>\n\n<p>When an administrator enables Threat Intelligence Lite, the site can receive compact shared security intelligence and contribute selected high-confidence security signals.<\/p>\n\n<p>The participating site URL\/domain is included with the authenticated contributor record so the Nexus Network operator can identify the connected installation. Selected verified security signals may include an attacking public IP address and limited security metadata needed for network intelligence.<\/p>\n\n<p>Threat Network participation does not send passwords, cookies, form contents, customer\/order data or page content.<\/p>\n\n<p>Learn more at <a href=\"https:\/\/lumiversenexus.com\/threat-network\/\">Nexus Threat Network<\/a>.<\/p>\n\n<h4>Watchdog Lite and Nexus PRO<\/h4>\n\n<p>Watchdog Lite provides a strong free security foundation inside WordPress.<\/p>\n\n<p>The dashboard also includes a <strong>Protection Horizon<\/strong> that shows where Lite protection ends and what <strong>Lumiverse Nexus PRO<\/strong> adds for sites that need more:<\/p>\n\n<ul>\n<li>earlier request containment before WordPress fully processes eligible hostile pressure;<\/li>\n<li>deception-based hostile activity observation;<\/li>\n<li>adaptive defense that can learn from repeated hostile behavior;<\/li>\n<li>richer investigation and recovery workflows;<\/li>\n<li>distributed Nexus intelligence across connected sites;<\/li>\n<li>Nexus Fleet for agency and multi-site operational visibility.<\/li>\n<\/ul>\n\n<p>Learn more at <a href=\"https:\/\/lumiversenexus.com\/pro\/\">Lumiverse Nexus PRO<\/a>.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>Watchdog Security Lite performs routine malware\/file scanning locally. Website files and file contents are not uploaded for routine malware scanning.<\/p>\n\n<p>Watchdog Lite may communicate with services under <strong>lumiversenexus.com<\/strong> for malware signatures, vulnerability intelligence and optional Nexus Threat Network functions.<\/p>\n\n<p>When Threat Intelligence Lite is enabled, the participating site URL\/domain is included with its authenticated contributor identity so the Nexus Network operator can identify the connected installation. Selected verified security signals may include an attacking public IP address plus limited security metadata. Aggregate telemetry contains security-event counts and contributor\/site attribution, but does not include raw attacking IP addresses in telemetry buckets, request URLs, usernames, cookies, request bodies, passwords, page content, or WooCommerce customer\/order data.<\/p>\n\n<p>Service information: <a href=\"https:\/\/lumiversenexus.com\/privacy\/\">Lumiverse Nexus Privacy Notice<\/a> and <a href=\"https:\/\/lumiversenexus.com\/terms\/\">Terms of Service<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Go to WordPress Dashboard -&gt; Plugins -&gt; Add New.<\/li>\n<li>Search for \"Watchdog Security Lite\".<\/li>\n<li>Install and activate the plugin.<\/li>\n<li>Open <strong>Watchdog Lite<\/strong> from the WordPress admin menu.<\/li>\n<li>Review the dashboard and choose the protection settings appropriate for your site.<\/li>\n<\/ol>\n\n<p>Threat Intelligence Lite, Weekly Security Digest and administrator TOTP 2FA remain optional.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20watchdog%20security%20lite%20slow%20down%20my%20website%3F\"><h3>Will Watchdog Security Lite slow down my website?<\/h3><\/dt>\n<dd><p>Watchdog Lite is designed to keep heavy work away from normal visitor requests wherever possible. Scanning, reporting and network work are separated from the normal page-delivery path where practical.<\/p><\/dd>\n<dt id=\"what%20is%20security%20%26%20exposure%20check%3F\"><h3>What is Security &amp; Exposure Check?<\/h3><\/dt>\n<dd><p>It is a fast local review of Watchdog protection plus practical WordPress attack-surface signals, such as risky public artifacts, PHP files in upload-like locations and selected configuration choices that may deserve review.<\/p>\n\n<p>It reports what it can verify locally and avoids claiming that a file or feature is publicly exploitable when server-level access cannot be confirmed.<\/p><\/dd>\n<dt id=\"what%20are%20attack%20stories%3F\"><h3>What are Attack Stories?<\/h3><\/dt>\n<dd><p>Attack Stories group related Traffic Shield and Login Guard activity from the same source into a readable sequence. They are built from real events already recorded by Watchdog Lite and do not generate simulated attacks.<\/p><\/dd>\n<dt id=\"is%20administrator%202fa%20mandatory%3F\"><h3>Is administrator 2FA mandatory?<\/h3><\/dt>\n<dd><p>No. TOTP 2FA is optional and configured separately by each administrator.<\/p><\/dd>\n<dt id=\"what%20does%20threat%20intelligence%20lite%20share%3F\"><h3>What does Threat Intelligence Lite share?<\/h3><\/dt>\n<dd><p>Threat Intelligence Lite is disabled by default. When enabled, the participating site URL\/domain is registered with the authenticated contributor identity. Selected verified security signals may include an attacking public IP address and limited security metadata. Aggregate telemetry contains event counts and contributor\/site attribution.<\/p>\n\n<p>Passwords, cookies, form contents, customer\/order data and page content are not shared through Threat Network participation.<\/p><\/dd>\n<dt id=\"does%20the%20scanner%20upload%20my%20website%20files%3F\"><h3>Does the scanner upload my website files?<\/h3><\/dt>\n<dd><p>No. Routine malware\/file scanning is performed locally.<\/p><\/dd>\n<dt id=\"does%20the%20scanner%20include%20mu-plugins%3F\"><h3>Does the scanner include MU-plugins?<\/h3><\/dt>\n<dd><p>Yes. Malware scanning can include the WordPress MU-plugin directory, and Live Watch can monitor it when enabled.<\/p><\/dd>\n<dt id=\"does%20safe%20core%20repair%20change%20plugins%2C%20themes%20or%20wp-content%3F\"><h3>Does Safe Core Repair change plugins, themes or wp-content?<\/h3><\/dt>\n<dd><p>No. Lite Safe Core Repair restores only verified WordPress core files represented in the official checksum set. It excludes <code>wp-content<\/code>, <code>wp-config.php<\/code> and server configuration files, and creates a protected restore point first.<\/p><\/dd>\n<dt id=\"what%20is%20watchdog%20live%20pulse%3F\"><h3>What is Watchdog Live Pulse?<\/h3><\/dt>\n<dd><p>It is a lightweight visual view of real activity already observed by Watchdog Lite, including recent requests, bots and protection events. It does not generate simulated attack events.<\/p><\/dd>\n<dt id=\"is%20watchdog%20lite%20suitable%20for%20woocommerce%3F\"><h3>Is Watchdog Lite suitable for WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. It includes store-aware traffic protection and optional bot cart-action neutralization. Nexus PRO adds broader WooCommerce resource-defense, adaptive protection and investigation layers for higher-pressure business stores.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>4.2.0<\/h4>\n\n<ul>\n<li>Added Security &amp; Exposure Check with a clearer view of practical WordPress attack-surface signals.<\/li>\n<li>Added Attack Stories to turn related protection activity into readable security sequences.<\/li>\n<li>Added the cinematic Protection Horizon to show current Lite protection and the additional layers available in Nexus PRO.<\/li>\n<li>Refined Threat Network contributor identification and dashboard presentation.<\/li>\n<\/ul>\n\n<h4>4.1.1<\/h4>\n\n<ul>\n<li>Improved Nexus Threat Network contributor identification for connected Lite installations.<\/li>\n<\/ul>\n\n<h4>4.1.0<\/h4>\n\n<ul>\n<li>Added the optional Weekly Security Digest and clearer protection, scan-coverage and WooCommerce pressure summaries.<\/li>\n<\/ul>\n\n<h4>4.0.16<\/h4>\n\n<ul>\n<li>Improved Integrity Center presentation and managed-host compatibility.<\/li>\n<\/ul>","raw_excerpt":"Fast WordPress and WooCommerce security with malware scanning, vulnerability intelligence, integrity checks, login protection, attack stories and Nexu &hellip;","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/273886","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=273886"}],"author":[{"embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/bestseogr"}],"wp:attachment":[{"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=273886"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=273886"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=273886"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=273886"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=273886"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=273886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}