security v0.2.0

Arq Security

Scans the WordPress layer for real exposure — REST leaks, missing headers, sensitive files, default usernames — then lets you opt into runtime controls one at a time.

What it does

Audit-first hardening, never brick-risk.

  • Audit-only scanner: REST exposure, security headers, sensitive files, XML-RPC, default admin username, updates, salts, HTTPS config
  • Suggested protection profiles with individually adjustable presets
  • Opt-in runtime controls: REST user enumeration, HSTS, report-only CSP, REST discovery trimming
  • Copyable Apache/Nginx server-rule guidance (never writes server config directly)
  • Opt-in privacy-conscious traffic and crawler insights dashboard
  • Manual last-known-good policy rollback
  • Admin screens: Overview, Scan Results, Protection Settings, CSP Reports, Traffic, Activity Log

Activation is audit-only. Bypassable via ARQ_SECURITY_SAFE_MODE or ARQ_SECURITY_DISABLE. Never touches DNS, server config, or wp-config.php.