security
v0.2.0
Arq Security
Scans the WordPress layer for real exposure — REST leaks, missing headers, sensitive files, default usernames — then lets you opt into runtime controls one at a time.
What it does
Audit-first hardening, never brick-risk.
- Audit-only scanner: REST exposure, security headers, sensitive files, XML-RPC, default admin username, updates, salts, HTTPS config
- Suggested protection profiles with individually adjustable presets
- Opt-in runtime controls: REST user enumeration, HSTS, report-only CSP, REST discovery trimming
- Copyable Apache/Nginx server-rule guidance (never writes server config directly)
- Opt-in privacy-conscious traffic and crawler insights dashboard
- Manual last-known-good policy rollback
- Admin screens: Overview, Scan Results, Protection Settings, CSP Reports, Traffic, Activity Log
Activation is audit-only. Bypassable via ARQ_SECURITY_SAFE_MODE or ARQ_SECURITY_DISABLE. Never touches DNS, server config, or wp-config.php.