Apaxon Security

Available nowFree

The hardening every site should have had on day one.

Sensible defaults applied without breaking the site, two-factor for the accounts that matter, and alerts that fire on the handful of events actually worth waking up for.

  • Free forever
  • No lockout risk
  • Alerts you can act on
Hardening
Monitoring
Two-factor
Alerts

What it does.

  • Hardening that does not break things

    File editing disabled, XML-RPC closed, author enumeration blocked, login attempts limited. Each is reversible and each says what it will affect before it applies.

  • Two-factor for the accounts that matter

    Required for administrators, optional below. An admin account behind a password alone is the whole site behind one credential.

  • Monitoring with a low false-positive rate

    Core file changes, new admin users, plugin installs. An alert that fires daily is one nobody reads, so the list is deliberately short.

  • Alerts that arrive

    Sent through Apaxon SMTP so a security notice is not the message that lands in spam because the host’s mail was never configured.

What it is not

Not a firewall, and honest about it.

A PHP plugin cannot block traffic before PHP runs, so any plugin claiming to be a firewall is doing its filtering after the request has already reached your application. Use Cloudflare or your host for that. This does the part a plugin genuinely can: configuration, credentials, visibility.

  • No traffic-blocking claims that a plugin cannot deliver
  • No performance cost from scanning every request
  • Pairs with a real WAF rather than pretending to be one

Requirements

Requires
Apaxon Core, WordPress 6.5+, PHP 8.1+
Two-factor
TOTP and recovery codes
Licence
GPLv2 or later
Standard
docs/SECURITY.md

Questions

Could this lock me out?

Two-factor enrolment issues recovery codes before it is enforced, and every hardening rule can be reversed from wp-config if the worst happens. Being locked out of your own site by a security plugin is a real risk we design against.

Do I still need a WAF?

Yes. This hardens the application; a WAF filters traffic before it arrives. They solve different halves and neither replaces the other.

Will it slow the site down?

No per-request scanning, so the overhead is close to nothing. Checks run on a schedule, not on every page view.

Ready to power your WordPress website the smart way?

Start with Apaxon Core — free, GPL, and with nothing to cancel. Add the plugins you need when you need them.