WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Guido Schad v0.4.2

Lockora Security Audit

Lockora Security Audit checks WordPress security posture, hardening, core integrity, vulnerabilities, and optional AI reports.

Lockora Security Audit

The facts

Rating
5★ from 4
Active installs
100+
Price
Free
Last updated
12 Aug 2026
Added
May 2026
Requires WP
6.0
Tested up to
WP 7.0.4
Requires PHP
7.4
Downloads
1,275

Our analysis

AI-assisted

Lockora Security Audit is a WordPress plugin designed to help site owners and agencies assess the security of their WordPress sites from the admin area. It identifies security weaknesses and integrates with the Who Changed It? plugin to connect security findings with user activity. The plugin offers features such as manual security scans, security score assessments, and various checks related to WordPress core files, authentication keys, and administrator accounts.

The plugin provides a range of security checks including file integrity, anomaly detection in the wp-content directory, and public exposure assessments. It also supports WP-CLI for command line operations and can connect to external services for enhanced functionality. This plugin is suitable for WordPress site administrators looking to improve their site's security posture and maintain compliance with best practices.

Best for: WordPress site administrators and agencies focused on enhancing site security.

What it does well

  • Identifies security weaknesses in WordPress sites
  • Integrates with Who Changed It? for activity logging
  • Offers manual security scans and weighted security scores
  • Includes checks for core file integrity and anomalies in uploads
  • Supports WP-CLI for command line operations

Where it falls short

  • Limited information on specific features and usability
  • No external data is sent during scans, but some data is sent to WordPress.org

Verdict

Lockora Security Audit provides a comprehensive set of tools for assessing and improving WordPress security. It is a useful resource for those serious about site protection.

From the developer

Guido Schad's own description of Lockora Security Audit, lightly tidied.

Lockora Security Audit helps site owners and agencies review a WordPress site’s security posture from the admin area.

Works well with Who Changed It?

Lockora finds security weaknesses. Who Changed It? – Activity Log shows what changed, who changed it, and when, with severity classification, field-level diffs, and alerts. Use both together to connect a security finding to the activity that caused it.

Current prototype features include:

  • Manual security scans.
  • Weighted security score out of 100.
  • Bounded scan history with current-versus-previous finding comparisons.
  • WordPress core file integrity checks using official checksums, with CSV and TXT exports.
  • Bounded wp-content anomaly scanning for executable uploads, unexpected PHP files outside standard code directories, runtime executables, and exposed backup or secret-like files, with CSV/TXT exports and clipboard copying.
  • WordPress authentication key and salt checks, with explicit actions to generate missing salts or rotate the keys stored in wp-config.php.
  • Must-use plugin directory presence checks.
  • PHP version status using WordPress.org Serve Happy data.
  • HTTPS and HTTP security header checks.
  • WordPress core, plugin, and theme update posture checks.
  • Administrator account posture checks for default usernames, excess admins, inactive admins, user ID 1 exposure, and an admin username/email inventory.
  • Public exposure checks: debug.log and readme.html reachability, uploads directory listing, PHP execution inside uploads, and author archive user enumeration.
  • SSL certificate expiry check, database table prefix check, automatic update posture check, and detection of login protection / two-factor plugins.
  • Site Health integration: scan summary plus key configuration checks appear under Tools > Site Health > Status.
  • WP-CLI support: wp lockora scan and wp lockora report, with --format=json and a --strict flag for CI pipelines.
  • Optional known vulnerability matching with a configured Wordfence Intelligence API key.
  • Optional AI client reports on WordPress 7.0+ when the site’s AI Connector is configured.
  • Reversible hardening toggles for XML-RPC, REST user routes, generator tag output, and basic security headers.
  • A lockora_scan_completed action for integrations that need scan scores and finding counts.

External Services

Lockora Security Audit may connect to external services only when the administrator runs a scan or generates an AI client report.

During a scan the plugin also sends HTTP requests to the site’s own public URL (loopback requests) to inspect response headers, debug.log and readme.html reachability, uploads directory behavior, and author archive redirects, and it opens a TLS connection to the site’s own hostname to read the SSL certificate expiry date. These requests stay within the site being scanned and send no data to third parties.

WordPress.org APIs:
* Used for WordPress core checksums, PHP version support status, and WordPress core/plugin/theme update data.
* Data sent: the site’s WordPress version and locale for core checksums and PHP compatibility; WordPress itself may send installed plugin and theme slugs/versions to WordPress.org when update data is refreshed.
* WordPress.org terms: https://wordpress.org/about/terms/
* WordPress.org privacy policy: https://wordpress.org/about/privacy/

Wordfence Intelligence:
* Optional.
* Used only when a Wordfence Intelligence API key is configured and an administrator runs a scan that includes vulnerability matching.
* Used to retrieve vulnerability data and match it locally against installed WordPress core, plugin, and theme versions.
* Data sent: the configured Wordfence Intelligence API key is sent in an Authorization header when requesting the vulnerability feed. Installed software details are not sent by this plugin to the Wordfence Intelligence endpoint; matching is performed locally after the feed is retrieved.
* Wordfence Intelligence terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
* Wordfence privacy policy: https://www.wordfence.com/privacy-policy/

WordPress AI Client / Connectors:
* Optional.
* Used only when the administrator clicks Generate Client Report.
* Data sent: sanitized scan findings, score, counts, and recommendations needed to generate a client-facing report. The plugin is designed not to send passwords, salts, API keys, raw logs, full user lists, or file contents.
* The configured AI provider is controlled by the site owner’s WordPress Connector settings.
* Terms and privacy policy: these depend on the AI provider configured by the site owner in WordPress. Site owners should review the selected provider’s terms and privacy policy before enabling AI reports.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)