Kapsule Protect / Site security

Your whole security posture on one screen.

Two grades, four protections, the certificate, last night's malware scan and eight live probes. Every reading here is one a configured site actually produces.

18,422 files scanned at 06:33 last night, and every night before it.

10 a minuteSign-in attempts allowed per visitor, on every site on the platform

25Known scanners and scrapers refused by name, before your site answers

2 yearsThe HTTPS-only instruction the server writes for you, subdomains included

kpanel.kapsulehost.com/websites/brightwavestudio.co.nz/securityActive
Connection (TLS)
ATLS 1.3AEAD cipher suite, certificate valid

GRADE SCALE A B C F

Security headers audit

60/ 60 ptsA

SIX RESPONSE HEADERS, WEIGHTED

WordPress security

4 of 4 protections active

SSL certificateNo malware detectedLogin protectionNo vulnerabilities
HSTS (Strict-Transport-Security)Force browsers to always use HTTPS for this domain: protects against downgrade and stripping attacks.
OCSP staplingFaster, more private TLS handshakes: the server staples the certificate revocation status.
SSL Certificate62d remaining
Subjectbrightwavestudio.co.nzExpires12 Oct 2026Domains coveredbrightwavestudio.co.nz, www.brightwavestudio.co.nz

Renew now

RENEWS AUTOMATICALLY. NO ACTION NEEDED.

Malware scan10 Aug, 06:33 pm

Clean: 18,422 files scanned

Scans run automatically every night.

Response headersselect one

content-security-policyWorth twenty points, more than any other header. Full marks need a policy that sets default-src or script-src and uses neither unsafe-inline nor unsafe-eval. A policy that allows both scores eight.

Live posture

No exposed admin services or sensitive paths detected on brightwavestudio.co.nz.8 paths probed: phpMyAdmin, phpMyAdmin (alt), Adminer, .env file, WordPress login, Admin panel, cPanel, Webmail

Security checklist7 of 7

File editor disabled (DISALLOW_FILE_EDIT)PASS

No PHP files in uploads folderPASS

XML-RPC blocked or restrictedPASS

WP_DEBUG disabledPASS

Security keys setPASS

Non-default table prefixPASS

readme.html removedPASS

Read from the live site

  • Sixty of sixtySix response headers scored and weighted, not counted. A content security policy is worth twenty of them.
  • Graded A, B, C or FTLS version, cipher suite and certificate expiry, graded together and rechecked daily.
  • Eight paths probedphpMyAdmin, Adminer, a stray .env file and five more, checked from outside your site.
  • Already onNightly malware scanning, and a sign-in limiter allowing ten attempts a minute per visitor, on every site.
Enforcement

The refusals happen at the web server, not in a plugin

A security plugin can only answer a request that has already reached PHP. Everything in this table runs in front of it, so a refused request never touches your site at all.

ControlWhere it runsThe unit it works inWhat happens at the limit
Request rateWeb server, per siteRequests per period, per visitor address, per URL path, plus a burstRefused with a too many requests answer (HTTP 429)
Sign-in attemptsPlatform baseline, every siteTen attempts a minute, per visitorRefused before WordPress ever sees them
Firewall rulesWeb server, per siteNine match fields, eight operators, up to six clauses joined with andBlocked outright, or logged and allowed through
Request ceilingWeb server, per siteAbout 5, 15 or 40 requests a second, with a matching connection capDropped before your site runs any code
CrawlersReverse lookup, at request timeThe address must reverse-resolve to the operator's own domain, and back againGenuine crawlers pass. Twenty five known scrapers and scanners do not
AddressesWeb server, per siteSingle addresses or CIDR ranges, version 4 and version 6Denied at your site's edge, with the reason kept

Volumetric network floods are absorbed upstream of every row in this table and have no per site dial. There is no CAPTCHA and no browser check anywhere on the platform: a request is allowed, logged, or refused, and a visitor is never asked to prove they are a person.

The honest part

What this does not do

A security page that lists only strengths is a brochure. Here are the edges, in the words a buyer would use to ask about them.

01Is this a security guarantee?

No, and the product's own help page says so in those words. It reduces the ways in, it watches the ones that get through, and it gives you a way back to a known good state. Nothing here promises you cannot be compromised, and you should not buy anything that does.

02Where is the firewall editor?

There is not one yet. Custom rules, per path rate limits, the request ceiling, address reputation and the crawler check are all real and all enforced at the web server today, but you set them by asking Kora rather than by filling in a form. The enforcement is no less real for it. The screens are on the list.

03Does it stop a denial of service attack?

The part of one that reaches the web server, yes: the request ceiling and the rate limiter shed floods of ordinary requests before they cost you anything. Volumetric network floods are absorbed upstream and have no per site setting, so no page here offers you a dial for them.

04Sixty points, not a hundred?

Sixty. The audit weights what matters rather than counting headers: a content security policy is worth twenty points and a referrer policy is worth five, because they are not worth the same thing. A score out of a hundred that treated them equally would be telling you less.

The trail

Every security change is written down

The site activity log records who did it, when, and from which address. These are the entries it writes.

SSL certificate renewedMalware scan startedIP address blockedSecurity headers updatedLogin lockout enabledREST API restrictedApplication password createdWP 2FA enabledIP block removed
Professional services

Site Security Audit

One site, reviewed by an engineer, at a price published here rather than quoted after a call.

  • A fixed price, shown in your currency, before you talk to anyone
  • Charged once. It is not a subscription and it does not renew
  • Runs the same checks the panel runs: transport grade, the sixty point header audit, the eight path probe and the WordPress checklist
  • Kora answers immediately. A person is with you inside 4 business hours
US$240Charged onceBook the auditNo call required to see the price.

See your own posture, not ours

Every reading on this page is one the panel produces for a site it is already looking after. The fastest way to see yours is to put a site on it.

Kora answers immediately. A person is with you inside 4 business hours.