Your whole security posture on one screen.
Two grades, four protections, the certificate, last night's malware scan and eight live probes. Every reading here is one a configured site actually produces.
18,422 files scanned at 06:33 last night, and every night before it.
10 a minuteSign-in attempts allowed per visitor, on every site on the platform
25Known scanners and scrapers refused by name, before your site answers
2 yearsThe HTTPS-only instruction the server writes for you, subdomains included
GRADE SCALE A B C F
60/ 60 ptsA
SIX RESPONSE HEADERS, WEIGHTED
4 of 4 protections active
Renew now
RENEWS AUTOMATICALLY. NO ACTION NEEDED.
Clean: 18,422 files scanned
Scans run automatically every night.
content-security-policyWorth twenty points, more than any other header. Full marks need a policy that sets default-src or script-src and uses neither unsafe-inline nor unsafe-eval. A policy that allows both scores eight.
No exposed admin services or sensitive paths detected on brightwavestudio.co.nz.8 paths probed: phpMyAdmin, phpMyAdmin (alt), Adminer, .env file, WordPress login, Admin panel, cPanel, Webmail
File editor disabled (DISALLOW_FILE_EDIT)PASS
No PHP files in uploads folderPASS
XML-RPC blocked or restrictedPASS
WP_DEBUG disabledPASS
Security keys setPASS
Non-default table prefixPASS
readme.html removedPASS
Read from the live site
- Sixty of sixtySix response headers scored and weighted, not counted. A content security policy is worth twenty of them.
- Graded A, B, C or FTLS version, cipher suite and certificate expiry, graded together and rechecked daily.
- Eight paths probedphpMyAdmin, Adminer, a stray .env file and five more, checked from outside your site.
- Already onNightly malware scanning, and a sign-in limiter allowing ten attempts a minute per visitor, on every site.
The refusals happen at the web server, not in a plugin
A security plugin can only answer a request that has already reached PHP. Everything in this table runs in front of it, so a refused request never touches your site at all.
| Control | Where it runs | The unit it works in | What happens at the limit |
|---|---|---|---|
| Request rate | Web server, per site | Requests per period, per visitor address, per URL path, plus a burst | Refused with a too many requests answer (HTTP 429) |
| Sign-in attempts | Platform baseline, every site | Ten attempts a minute, per visitor | Refused before WordPress ever sees them |
| Firewall rules | Web server, per site | Nine match fields, eight operators, up to six clauses joined with and | Blocked outright, or logged and allowed through |
| Request ceiling | Web server, per site | About 5, 15 or 40 requests a second, with a matching connection cap | Dropped before your site runs any code |
| Crawlers | Reverse lookup, at request time | The address must reverse-resolve to the operator's own domain, and back again | Genuine crawlers pass. Twenty five known scrapers and scanners do not |
| Addresses | Web server, per site | Single addresses or CIDR ranges, version 4 and version 6 | Denied at your site's edge, with the reason kept |
Volumetric network floods are absorbed upstream of every row in this table and have no per site dial. There is no CAPTCHA and no browser check anywhere on the platform: a request is allowed, logged, or refused, and a visitor is never asked to prove they are a person.
What this does not do
A security page that lists only strengths is a brochure. Here are the edges, in the words a buyer would use to ask about them.
01Is this a security guarantee?
No, and the product's own help page says so in those words. It reduces the ways in, it watches the ones that get through, and it gives you a way back to a known good state. Nothing here promises you cannot be compromised, and you should not buy anything that does.
02Where is the firewall editor?
There is not one yet. Custom rules, per path rate limits, the request ceiling, address reputation and the crawler check are all real and all enforced at the web server today, but you set them by asking Kora rather than by filling in a form. The enforcement is no less real for it. The screens are on the list.
03Does it stop a denial of service attack?
The part of one that reaches the web server, yes: the request ceiling and the rate limiter shed floods of ordinary requests before they cost you anything. Volumetric network floods are absorbed upstream and have no per site setting, so no page here offers you a dial for them.
04Sixty points, not a hundred?
Sixty. The audit weights what matters rather than counting headers: a content security policy is worth twenty points and a referrer policy is worth five, because they are not worth the same thing. A score out of a hundred that treated them equally would be telling you less.
Every security change is written down
The site activity log records who did it, when, and from which address. These are the entries it writes.
Site Security Audit
One site, reviewed by an engineer, at a price published here rather than quoted after a call.
- A fixed price, shown in your currency, before you talk to anyone
- Charged once. It is not a subscription and it does not renew
- Runs the same checks the panel runs: transport grade, the sixty point header audit, the eight path probe and the WordPress checklist
- Kora answers immediately. A person is with you inside 4 business hours
Reducing the ways in is half of it
See your own posture, not ours
Every reading on this page is one the panel produces for a site it is already looking after. The fastest way to see yours is to put a site on it.
Kora answers immediately. A person is with you inside 4 business hours.