{"id":145700,"date":"2021-08-27T19:22:35","date_gmt":"2021-08-27T19:22:35","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/fuerte-wp\/"},"modified":"2026-08-05T01:54:48","modified_gmt":"2026-08-05T01:54:48","slug":"fuerte-wp","status":"publish","type":"plugin","link":"https:\/\/sah.wordpress.org\/plugins\/fuerte-wp\/","author":14388663,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.11.1","stable_tag":"1.11.1","tested":"7.0.2","requires":"6.5","requires_php":"8.2","requires_plugins":null,"header_name":"Fuerte-WP","header_author":"Esteban Cuevas","header_description":"Stronger WP. Limit access to critical WordPress areas, even other for admins.","assets_banners_color":"15619a","last_updated":"2026-08-05 01:54:48","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/EstebanForge\/Fuerte-WP","header_author_uri":"https:\/\/actitud.xyz","rating":0,"author_block_rating":0,"active_installs":100,"downloads":7752,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.10.0":{"tag":"1.10.0","author":"TCattd","date":"2026-07-17 00:47:50"},"1.11.0":{"tag":"1.11.0","author":"TCattd","date":"2026-07-30 23:30:22"},"1.11.1":{"tag":"1.11.1","author":"TCattd","date":"2026-08-05 01:54:48"},"1.3.1":{"tag":"1.3.1","author":"TCattd","date":"2021-08-27 19:23:02"},"1.3.10":{"tag":"1.3.10","author":"TCattd","date":"2022-01-06 14:21:25"},"1.3.11":{"tag":"1.3.11","author":"TCattd","date":"2022-01-11 16:58:01"},"1.3.2":{"tag":"1.3.2","author":"TCattd","date":"2021-09-13 17:48:45"},"1.3.3":{"tag":"1.3.3","author":"TCattd","date":"2021-09-13 17:53:59"},"1.3.4":{"tag":"1.3.4","author":"TCattd","date":"2021-09-13 17:59:48"},"1.3.5":{"tag":"1.3.5","author":"TCattd","date":"2021-09-13 18:19:26"},"1.3.6":{"tag":"1.3.6","author":"TCattd","date":"2021-10-08 19:35:05"},"1.3.7":{"tag":"1.3.7","author":"TCattd","date":"2021-10-08 19:38:33"},"1.3.8":{"tag":"1.3.8","author":"TCattd","date":"2021-11-03 19:42:22"},"1.3.9":{"tag":"1.3.9","author":"TCattd","date":"2022-01-06 14:17:15"},"1.4.0":{"tag":"1.4.0","author":"TCattd","date":"2022-07-22 18:39:44"},"1.4.1":{"tag":"1.4.1","author":"TCattd","date":"2022-07-22 18:59:16"},"1.4.10":{"tag":"1.4.10","author":"TCattd","date":"2023-11-06 16:51:43"},"1.4.11":{"tag":"1.4.11","author":"TCattd","date":"2023-11-06 17:04:32"},"1.4.12":{"tag":"1.4.12","author":"TCattd","date":"2023-11-06 20:56:54"},"1.4.2":{"tag":"1.4.2","author":"TCattd","date":"2022-08-12 15:24:30"},"1.4.3":{"tag":"1.4.3","author":"TCattd","date":"2022-11-28 14:08:20"},"1.4.4":{"tag":"1.4.4","author":"TCattd","date":"2023-02-20 15:21:13"},"1.4.5":{"tag":"1.4.5","author":"TCattd","date":"2023-11-06 16:16:15"},"1.4.6":{"tag":"1.4.6","author":"TCattd","date":"2023-11-06 16:23:09"},"1.4.7":{"tag":"1.4.7","author":"TCattd","date":"2023-11-06 16:28:13"},"1.4.8":{"tag":"1.4.8","author":"TCattd","date":"2023-11-06 16:34:37"},"1.4.9":{"tag":"1.4.9","author":"TCattd","date":"2023-11-06 16:49:58"},"1.5.0":{"tag":"1.5.0","author":"TCattd","date":"2024-07-25 15:38:15"},"1.5.1":{"tag":"1.5.1","author":"TCattd","date":"2024-07-25 16:01:33"},"1.6.1":{"tag":"1.6.1","author":"TCattd","date":"2025-09-20 23:44:44"},"1.7.0":{"tag":"1.7.0","author":"TCattd","date":"2025-11-13 22:01:46"},"1.7.1":{"tag":"1.7.1","author":"TCattd","date":"2025-11-13 22:53:10"},"1.7.2":{"tag":"1.7.2","author":"TCattd","date":"2025-11-13 23:49:18"},"1.7.3":{"tag":"1.7.3","author":"TCattd","date":"2025-11-14 02:44:37"},"1.7.4":{"tag":"1.7.4","author":"TCattd","date":"2025-11-14 13:09:43"},"1.7.5":{"tag":"1.7.5","author":"TCattd","date":"2025-11-19 02:46:42"},"1.8.0":{"tag":"1.8.0","author":"TCattd","date":"2026-03-23 13:19:34"},"1.8.1":{"tag":"1.8.1","author":"TCattd","date":"2026-04-14 00:07:38"},"1.9.0":{"tag":"1.9.0","author":"TCattd","date":"2026-04-24 21:16:42"},"1.9.1":{"tag":"1.9.1","author":"TCattd","date":"2026-04-25 00:52:18"},"1.9.2":{"tag":"1.9.2","author":"TCattd","date":"2026-04-25 02:50:03"},"1.9.3":{"tag":"1.9.3","author":"TCattd","date":"2026-04-29 04:25:37"},"1.9.4":{"tag":"1.9.4","author":"TCattd","date":"2026-05-08 23:27:51"},"1.9.5":{"tag":"1.9.5","author":"TCattd","date":"2026-06-02 13:33:15"}},"upgrade_notice":{"1.11.0":"<p>Advanced Restrictions now actually apply, and admin menu management is searchable. Review your Restrictions tab after upgrading; sensible defaults are enabled for non-super users.<\/p>","1.10.0":"<p>Adds bundled Two-Factor authentication with admin enforcement. If you already run the standalone Two-Factor plugin, Fuerte-WP detects it and steps aside automatically.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":2589990,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-2048x2048.png":{"filename":"icon-2048x2048.png","revision":2589990,"resolution":"2048x2048","location":"assets","locale":"","width":2048,"height":2048},"icon-256x256.png":{"filename":"icon-256x256.png","revision":2589990,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":2589990,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":2589990,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.10.0","1.11.0","1.11.1","1.3.1","1.3.10","1.3.11","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.1","1.4.10","1.4.11","1.4.12","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5.0","1.5.1","1.6.1","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.8.0","1.8.1","1.9.0","1.9.1","1.9.2","1.9.3","1.9.4","1.9.5"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":2589990,"resolution":"1","location":"assets","locale":"","width":2556,"height":1967},"screenshot-2.png":{"filename":"screenshot-2.png","revision":2589990,"resolution":"2","location":"assets","locale":"","width":2556,"height":1967},"screenshot-3.png":{"filename":"screenshot-3.png","revision":2589990,"resolution":"3","location":"assets","locale":"","width":2556,"height":1967},"screenshot-4.png":{"filename":"screenshot-4.png","revision":2589990,"resolution":"4","location":"assets","locale":"","width":2556,"height":1967}},"screenshots":{"1":"Main settings page with super user configuration","2":"Auto-update management with scheduling options","3":"Deferred and Blocked Updates configuration","4":"Two-Factor and Login Security dashboard with real-time monitoring","5":"Discovery-driven admin menu and access control management"}},"plugin_section":[],"plugin_tags":[37376,1229,732,600,9217],"plugin_category":[54],"plugin_contributors":[85358],"plugin_business_model":[],"class_list":["post-145700","plugin","type-plugin","status-publish","hentry","plugin_tags-auto-updates","plugin_tags-login-security","plugin_tags-maintenance","plugin_tags-security","plugin_tags-two-factor","plugin_category-security-and-spam-protection","plugin_contributors-tcattd","plugin_committers-tcattd"],"banners":{"banner":"https:\/\/ps.w.org\/fuerte-wp\/assets\/banner-772x250.png?rev=2589990","banner_2x":"https:\/\/ps.w.org\/fuerte-wp\/assets\/banner-1544x500.png?rev=2589990","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/fuerte-wp\/assets\/icon-128x128.png?rev=2589990","icon_2x":"https:\/\/ps.w.org\/fuerte-wp\/assets\/icon-256x256.png?rev=2589990","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/fuerte-wp\/assets\/screenshot-1.png?rev=2589990","caption":"Main settings page with super user configuration"},{"src":"https:\/\/ps.w.org\/fuerte-wp\/assets\/screenshot-2.png?rev=2589990","caption":"Auto-update management with scheduling options"},{"src":"https:\/\/ps.w.org\/fuerte-wp\/assets\/screenshot-3.png?rev=2589990","caption":"Deferred and Blocked Updates configuration"},{"src":"https:\/\/ps.w.org\/fuerte-wp\/assets\/screenshot-4.png?rev=2589990","caption":"Two-Factor and Login Security dashboard with real-time monitoring"}],"raw_content":"<!--section=description-->\n<p>\ud83d\udee1\ufe0f <strong>WordPress Security and Maintenance That Prevents Problems Before They Happen<\/strong><\/p>\n\n<p>Every day, WordPress sites are compromised through supply chain attacks. A trustworthy plugin developer has their account hacked, malicious code ships as an \"update\", and thousands of sites auto-install it within hours. Fuerte-WP protects your site when developers cannot protect their own update systems.<\/p>\n\n<p>Fuerte-WP combines four defenses in one lightweight plugin: <strong>update management<\/strong>, <strong>admin oversight<\/strong>, <strong>login security<\/strong>, and <strong>two-factor authentication<\/strong>. It is built for agencies, e-commerce stores, and anyone who manages WordPress sites and needs to sleep at night.<\/p>\n\n<p><strong>\ud83d\udea8 CRITICAL: SUPPLY CHAIN ATTACK AND MALICIOUS UPDATE PROTECTION<\/strong><\/p>\n\n<p>A supply chain attack happens when an attacker compromises a developer account and pushes a malicious update that thousands of sites auto-install before anyone notices. When you learn an attack is in progress, you need to act in minutes, not days.<\/p>\n\n<p>Fuerte-WP gives you three update modes so you can react correctly:<\/p>\n\n<ul>\n<li><strong>Scheduled Updates<\/strong>: choose how often WordPress checks for and applies updates. Options are 6, 12, 24, or 48 hours. Slower cycles give you a review window. Faster cycles keep client sites current.<\/li>\n<li><strong>Deferred Updates<\/strong>: keep a plugin out of auto-updates while still letting you update it manually. Useful when you want to test a release on staging before it reaches production.<\/li>\n<li><strong>Blocked Updates<\/strong>: completely freeze a plugin or theme. Neither WordPress nor manual clicks can update it. This is the supply chain defense. When a developer account is compromised, you block the plugin at its last known safe version and wait until the all-clear.<\/li>\n<\/ul>\n\n<p>This is not a generic \"disable updates\" toggle. Deferred and Blocked are separate, intentional controls, so you can hold one compromised plugin back while the rest of the site keeps updating normally.<\/p>\n\n<p><strong>\u26a1 AUTO-UPDATE MANAGEMENT FOR CORE, PLUGINS, THEMES, AND TRANSLATIONS<\/strong><\/p>\n\n<p>Granular control over every update channel:<\/p>\n\n<ul>\n<li><strong>WordPress core<\/strong> auto-updates (on or off)<\/li>\n<li><strong>Plugin<\/strong> auto-updates (on or off, with per-plugin defer and block)<\/li>\n<li><strong>Theme<\/strong> auto-updates (on or off, with per-theme defer and block)<\/li>\n<li><strong>Translation<\/strong> auto-updates (on or off)<\/li>\n<li><strong>Update check frequency<\/strong>: 6, 12, 24, or 48 hours<\/li>\n<li><strong>Zero performance impact<\/strong>: all checks run in the background through a dedicated cron event. Page load times are unaffected.<\/li>\n<\/ul>\n\n<p>You can configure this once on your main site and reuse the same file-based configuration across every site you manage.<\/p>\n\n<p><strong>\ud83d\udc51 ADMINISTRATOR OVERSIGHT AND ACCESS CONTROL<\/strong><\/p>\n\n<p>Most WordPress security plugins assume the administrator is the threat. Fuerte-WP assumes the administrator is trusted but busy, and that you want to protect them from themselves and from each other.<\/p>\n\n<ul>\n<li><strong>Super User Access<\/strong>: designate one or more super users by email. Super users bypass every restriction and are the only accounts that can change Fuerte-WP settings or disable the plugin.<\/li>\n<li><strong>Restrict Other Administrators<\/strong>: prevent non-super administrators from installing unstable plugins, editing theme and plugin code, changing permalinks, or touching sensitive WordPress settings.<\/li>\n<li><strong>Hide and Block Admin Menus<\/strong>: a searchable, discovery-driven interface lists every registered admin menu, submenu, and admin-bar node on your site. You select what to hide. Hide and block are unified: hiding a page also blocks direct URL access to it. A manual textarea stays available as a precision escape hatch for slugs the discovery scan does not surface.<\/li>\n<li><strong>Smart Block Targeting<\/strong>: the block engine avoids over-blocking. Shared scripts like <code>edit.php<\/code> (Posts, Pages, and custom post types) and <code>index.php<\/code> are hide-only so you never strand a non-super user on a blank screen. Single-purpose core scripts (<code>themes.php<\/code>, <code>tools.php<\/code>, <code>plugins.php<\/code>) block by <code>$pagenow<\/code>. Plugin pages block by their <code>?page=<\/code> query argument.<\/li>\n<li><strong>Account Protection<\/strong>: protect your own admin account from being modified or deleted by another administrator.<\/li>\n<\/ul>\n\n<p><strong>\ud83d\udd12 LOGIN SECURITY (OPTIONAL, ON BY DEFAULT)<\/strong><\/p>\n\n<p>Brute force attacks against <code>wp-login.php<\/code> and XML-RPC are the most common way WordPress sites are compromised. Fuerte-WP ships with a full login hardening suite:<\/p>\n\n<ul>\n<li><strong>Rate Limiting and Brute Force Protection<\/strong>: block an IP address after too many failed login attempts. Progressive penalties apply to repeat offenders.<\/li>\n<li><strong>Lockout Protection<\/strong>: escalating lockout windows for repeated security violations.<\/li>\n<li><strong>Hide Login URL \/ Custom Login URL<\/strong>: move your login page away from the default <code>wp-login.php<\/code> and <code>wp-admin<\/code> paths so automated bots that scan for those endpoints find nothing. Your real login URL is whatever you choose.<\/li>\n<li><strong>Real-Time Monitoring<\/strong>: a live dashboard shows login attempts, lockouts, and security events.<\/li>\n<li><strong>Registration Protection<\/strong>: control who can register and from which IP ranges.<\/li>\n<\/ul>\n\n<p><strong>\ud83d\udd10 TWO-FACTOR AUTHENTICATION (2FA) FOR ADMINS<\/strong><\/p>\n\n<p>Since version 1.10.0, Fuerte-WP bundles the official WordPress Two-Factor library and enforces a safe provider policy:<\/p>\n\n<ul>\n<li><strong>Email codes<\/strong> (default for enforced admins)<\/li>\n<li><strong>Authenticator app \/ TOTP<\/strong> (Time-based One-Time Password, Google Authenticator, Authy, 1Password, etc.)<\/li>\n<li><strong>Recovery \/ backup codes<\/strong><\/li>\n<li>The insecure <strong>Dummy Method<\/strong> is stripped site-wide, even under <code>WP_DEBUG<\/code>.<\/li>\n<\/ul>\n\n<p><strong>Enforce 2FA for Administrators<\/strong> is on by default. Administrators and Super Admins are challenged with an emailed code at login even before they set up an authenticator app. Each admin can switch to TOTP from their own profile page. Enforcement is read-only: it never writes to user meta, so unchecking the box releases admins immediately. Fuerte super users always bypass enforcement.<\/p>\n\n<p>Crash-safe coexistence: if you already run the standalone Two-Factor plugin, Fuerte-WP detects it and steps aside. No class-redeclare fatal, no duplicate provider screens.<\/p>\n\n<p>Operator escape hatch: define <code>FUERTEWP_DISABLE_2FA<\/code> in <code>wp-config.php<\/code> to skip the bundled library entirely.<\/p>\n\n<p><strong>\ud83d\udee0 REST API, XML-RPC, AND APP PASSWORD HARDENING<\/strong><\/p>\n\n<p>Modern WordPress exposes several attack surfaces beyond the login form:<\/p>\n\n<ul>\n<li><strong>Disable Application Passwords<\/strong> site-wide (on by default)<\/li>\n<li><strong>Disable the XML-RPC API<\/strong> (on by default), removing the pingback vector and brute force amplification<\/li>\n<li><strong>Disable weak passwords<\/strong> during user creation and password reset<\/li>\n<li>REST API and authentication filters centralized so you can lock down application access without editing code<\/li>\n<\/ul>\n\n<p><strong>\ud83d\udce7 EMAIL CONTROLS AND RECOVERY<\/strong><\/p>\n\n<p>WordPress sends a lot of email. Fuerte-WP lets you redirect and silence it:<\/p>\n\n<ul>\n<li>Rewrite the sender address and name on every outgoing <code>wp_mail()<\/code> (falls back to <code>no-reply@&lt;your-domain&gt;<\/code> when left empty)<\/li>\n<li>Redirect <strong>Recovery Mode<\/strong> and fatal-error emails to a monitored address<\/li>\n<li>Toggle individual notifications: fatal errors, automatic updates, comment moderation, comment publication, password resets, personal-data export requests, new-user creation<\/li>\n<\/ul>\n\n<p><strong>\ud83c\udf10 MULTISITE, PERFORMANCE, AND DEVELOPER FRIENDLINESS<\/strong><\/p>\n\n<ul>\n<li><strong>Multisite compatible<\/strong>: network-activate for centralized management across every site on the network<\/li>\n<li><strong>Self-protecting<\/strong>: non-super users cannot disable Fuerte-WP or change its settings<\/li>\n<li><strong>Performance optimized<\/strong>: background cron processing, no per-request overhead<\/li>\n<li><strong>File-based configuration<\/strong>: define <code>$fuertewp<\/code> in <code>wp-config-fuerte.php<\/code> for mass deployment. File config wins over the database, so the same settings ship to every site without touching the admin UI<\/li>\n<li><strong>Translation ready<\/strong>: ships with Spanish (es_CL \/ es_ES); contribute more via translate.wordpress.org<\/li>\n<\/ul>\n\n<p><strong>\ud83d\udd27 HOW FUERTE-WP WORKS<\/strong><\/p>\n\n<p>Fuerte-WP follows a single-source-of-truth model. Configuration lives in one normalized array and is read the same way everywhere:<\/p>\n\n<ol>\n<li><strong>Load<\/strong>: a transient-cached config loader checks a <code>wp-config-fuerte.php<\/code> file first, then falls back to the database option saved by the admin UI. File always wins.<\/li>\n<li><strong>Enforce<\/strong>: a singleton enforcer applies every restriction, login rule, and update policy from that normalized array.<\/li>\n<li><strong>Recover<\/strong>: super users (matched by email, case-insensitive) bypass restrictions. Define <code>FUERTEWP_FORCE<\/code> to enforce even on super users, or <code>FUERTEWP_DISABLE<\/code> to switch the whole plugin off without uninstalling.<\/li>\n<\/ol>\n\n<p>Because the enforcer reads one normalized array, there is no drift between what the admin UI shows and what the site enforces. After editing config logic in code, bust the transient with <code>delete_transient('fuertewp_config')<\/code> so the new rules take effect.<\/p>\n\n<p><strong>\ud83d\udcc1 FILE-BASED CONFIGURATION FOR MASS DEPLOYMENT<\/strong><\/p>\n\n<p>For agencies and platform teams, Fuerte-WP can be configured entirely from a file, with no admin UI clicks. Drop a <code>wp-config-fuerte.php<\/code> file in your <code>ABSPATH<\/code> directory defining a <code>$fuertewp<\/code> array:<\/p>\n\n<pre><code>`\n<\/code><\/pre>\n\n<p>&lt;?php\n$fuertewp = array(\n    'general'      =&gt; array( 'sender_email_enable' =&gt; true ),\n    'super_users'  =&gt; array( 'you@agency.com' ),\n    'auto_updates' =&gt; array(\n        'core' =&gt; true, 'plugins' =&gt; true, 'themes' =&gt; true,\n        'translations' =&gt; true, 'frequency' =&gt; '12h',\n    ),\n    'restrictions' =&gt; array(\n        'disable_theme_editor'  =&gt; true,\n        'disable_plugin_editor' =&gt; true,\n        'restapi_disable_app_passwords' =&gt; true,\n        'disable_xmlrpc'        =&gt; true,\n    ),\n    'login_security' =&gt; array( 'login_security_enable' =&gt; true, 'two_factor_enable' =&gt; true ),\n);\n    `<\/p>\n\n<p>Commit this file to your deployment pipeline and every site in your fleet ships the same security baseline. The admin UI still renders for inspection, but saved values never override the file. This is the recommended path for WordPress multisite networks and managed-hosting platforms.<\/p>\n\n<p><strong>\ud83d\udccb SECURITY HARDENING CHECKLIST<\/strong><\/p>\n\n<p>Fuerte-WP ships with safe defaults so a fresh install is already hardened. The following are on by default and can be toggled on the Restrictions and Login Security tabs:<\/p>\n\n<ul>\n<li>Disable the Theme Editor and Plugin Editor (prevents code injection from the admin)<\/li>\n<li>Disable Theme Install and Plugin Install (prevents untrusted uploads)<\/li>\n<li>Disable the Customizer CSS Editor<\/li>\n<li>Restrict access to Permalinks and Advanced Custom Fields<\/li>\n<li>Disable Application Passwords and the XML-RPC API<\/li>\n<li>Disable weak passwords<\/li>\n<li>Enable login security, brute force protection, and registration protection<\/li>\n<li>Enforce two-factor authentication for administrators<\/li>\n<li>Send fatal-error and recovery-mode emails to a monitored address<\/li>\n<\/ul>\n\n<p>Review the Restrictions tab after your first install and adjust to your workflow.<\/p>\n\n<p><strong>\ud83c\udfaf PERFECT FOR:<\/strong><\/p>\n\n<ul>\n<li>Agencies managing many client WordPress websites<\/li>\n<li>E-commerce and WooCommerce stores that require maximum uptime<\/li>\n<li>Educational institutions and universities running WordPress multisite networks<\/li>\n<li>Enterprise and government deployments needing strict maintenance and change-control policies<\/li>\n<li>Developers who want a reproducible, file-driven security baseline<\/li>\n<li>Anyone serious about WordPress security, login protection, and update reliability<\/li>\n<\/ul>\n\n<p><strong>\u26a1 INSTALL IN SECONDS, PROTECT FOR YEARS<\/strong><\/p>\n\n<ol>\n<li>Install and activate Fuerte-WP<\/li>\n<li>Add yourself as a super user (by email)<\/li>\n<li>Configure your auto-update preferences and login security<\/li>\n<li>Your site is now protected from supply chain attacks, brute force login attempts, and accidental admin changes<\/li>\n<\/ol>\n\n<!--section=installation-->\n<ol>\n<li>Install Fuerte-WP from the WordPress plugin directory (Plugins &gt; Add New &gt; search \"Fuerte-WP\" or \"WordPress security auto-updates\").<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to Settings &gt; Fuerte-WP.<\/li>\n<li>Add your email as a super user. Super users bypass all restrictions.<\/li>\n<li>Set your auto-update preferences (core, plugins, themes, translations, frequency).<\/li>\n<li>Optionally enable login security, hide your login URL, and enforce 2FA for administrators.<\/li>\n<li>You are protected.<\/li>\n<\/ol>\n\n<p>For mass deployment, drop a <code>wp-config-fuerte.php<\/code> file in your <code>ABSPATH<\/code> directory defining a <code>$fuertewp<\/code> array. File configuration wins over the database. See the sample in <code>config-sample\/<\/code>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20does%20supply%20chain%20attack%20protection%20work%3F\"><h3>How does supply chain attack protection work?<\/h3><\/dt>\n<dd><p>When you learn that a plugin developer's account has been compromised and malicious updates are being distributed, open Fuerte-WP and block that plugin under Blocked Updates. This freezes the plugin at its last safe version and prevents your site from auto-installing malicious code, even while thousands of other sites are being compromised. Once the developer publishes a verified clean release, remove the block.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20deferred%20and%20blocked%20updates%3F\"><h3>What is the difference between Deferred and Blocked updates?<\/h3><\/dt>\n<dd><p><strong>Deferred Updates<\/strong>: the plugin will not auto-update, but you can still update it manually when you are ready. Good for testing a release on staging before it reaches production.<\/p>\n\n<p><strong>Blocked Updates<\/strong>: the plugin cannot update at all, neither automatically nor manually. Essential during a supply chain attack when any update could contain malicious code.<\/p><\/dd>\n<dt id=\"does%20fuerte-wp%20include%20two-factor%20authentication%20%282fa%29%3F\"><h3>Does Fuerte-WP include two-factor authentication (2FA)?<\/h3><\/dt>\n<dd><p>Yes. Since 1.10.0, Fuerte-WP bundles the official WordPress Two-Factor library. Administrators can use Email codes, an Authenticator App (TOTP, compatible with Google Authenticator, Authy, 1Password), and Recovery Codes. \"Enforce 2FA for Admins\" is on by default. If you already run the standalone Two-Factor plugin, Fuerte-WP detects it and steps aside.<\/p><\/dd>\n<dt id=\"can%20other%20administrators%20disable%20fuerte-wp%3F\"><h3>Can other administrators disable Fuerte-WP?<\/h3><\/dt>\n<dd><p>No. Only super users can modify Fuerte-WP settings or disable the plugin. Other administrators are restricted from making changes that could compromise your site's security. This makes Fuerte-WP self-protecting.<\/p><\/dd>\n<dt id=\"how%20does%20the%20hide%20login%20url%20%2F%20custom%20login%20url%20feature%20work%3F\"><h3>How does the hide login URL \/ custom login URL feature work?<\/h3><\/dt>\n<dd><p>You set a secret login slug. Fuerte-WP redirects the default <code>wp-login.php<\/code> and <code>wp-admin<\/code> paths away from unauthenticated visitors, so bots that scan for those endpoints find nothing. You and your team log in at your custom URL instead. Brute force attacks against the default login form stop almost entirely.<\/p><\/dd>\n<dt id=\"can%20i%20disable%20xml-rpc%20and%20application%20passwords%3F\"><h3>Can I disable XML-RPC and Application Passwords?<\/h3><\/dt>\n<dd><p>Yes, both are one-click toggles and both are on by default. Disabling XML-RPC removes the pingback vector and brute force amplification. Disabling Application Passwords prevents leaked credentials from being used against the REST API.<\/p><\/dd>\n<dt id=\"will%20this%20slow%20down%20my%20website%3F\"><h3>Will this slow down my website?<\/h3><\/dt>\n<dd><p>No. All maintenance and update checks run in the background through a dedicated cron event. Page load times are unaffected. Fuerte-WP is performance optimized.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20wordpress%20multisite%3F\"><h3>Does this work with WordPress multisite?<\/h3><\/dt>\n<dd><p>Yes. Fuerte-WP is fully compatible with WordPress multisite and can be network-activated for centralized management across every site on the network.<\/p><\/dd>\n<dt id=\"can%20i%20configure%20fuerte-wp%20without%20the%20admin%20ui%3F\"><h3>Can I configure Fuerte-WP without the admin UI?<\/h3><\/dt>\n<dd><p>Yes. Define a <code>$fuertewp<\/code> array in <code>wp-config-fuerte.php<\/code> inside your <code>ABSPATH<\/code> directory. File configuration wins over the database, so the same baseline ships to every site you manage. See <code>config-sample\/wp-config-fuerte.php<\/code> for the full shape.<\/p><\/dd>\n<dt id=\"where%20can%20i%20find%20more%20documentation%3F\"><h3>Where can I find more documentation?<\/h3><\/dt>\n<dd><p><a href=\"https:\/\/github.com\/EstebanForge\/Fuerte-WP\/blob\/master\/README.md\">Full documentation is on GitHub<\/a>.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.11.0 \/ 2026-07-30<\/h4>\n\n<ul>\n<li><strong>New Feature<\/strong>: Discovery-driven admin menu, submenu, and admin-bar visibility. The old manual textareas are replaced by searchable multiselects populated from the live menu tree. Hide and block are now unified: hiding a page also blocks direct URL access. A collapsed manual textarea remains as a precision escape hatch.<\/li>\n<li><strong>Bug Fix<\/strong>: Five Advanced Restrictions settings (removed menus, submenus, admin-bar nodes, restricted scripts, restricted pages) were silently dead since the 1.7.0 HyperFields migration. They now reach the enforcer correctly.<\/li>\n<li><strong>Bug Fix<\/strong>: The \"Disable Application Passwords\" restriction was a no-op due to a wrong config key. Application passwords are now actually disabled site-wide.<\/li>\n<li><strong>Bug Fix<\/strong>: App Passwords and XML-RPC restriction hooks were registered at the wrong filter priority. Fixed.<\/li>\n<li><strong>Changed<\/strong>: Bundled HyperFields library updated to 1.5.0, adding automatic cache invalidation on settings saves.<\/li>\n<\/ul>\n\n<h4>1.10.0 \/ 2026-07-10<\/h4>\n\n<ul>\n<li><strong>New Feature<\/strong>: Bundled the official WordPress Two-Factor plugin as a library, with a site-enforced provider policy (Email, TOTP Authenticator App, Recovery Codes) and crash-safe coexistence with the standalone plugin.<\/li>\n<li><strong>New Feature<\/strong>: \"Enable 2FA\" and \"Enforce 2FA for Admins\" checkboxes on the Login Security tab (both default ON). Admins are challenged with an emailed code at login; each admin can switch to TOTP. Super users always bypass enforcement.<\/li>\n<li><strong>New Feature<\/strong>: <code>FUERTEWP_DISABLE_2FA<\/code> constant as a higher-priority off switch for operators.<\/li>\n<li><strong>Changed<\/strong>: Auto-update settings moved from the Main tab to a dedicated Updates tab.<\/li>\n<\/ul>\n\n<h4>1.9.6 \/ 2026-06-06<\/h4>\n\n<ul>\n<li><strong>New Feature<\/strong>: Disable Comments site-wide with a single toggle. Closes comments and pings on all post types, removes the Comments admin menu and dashboard widget, blocks comment feeds and REST API comment endpoints, blocks XML-RPC comment methods and pingback, and removes the X-Pingback header.<\/li>\n<\/ul>\n\n<h4>1.9.5 \/ 2026-06-02<\/h4>\n\n<ul>\n<li><strong>Bug Fix<\/strong>: Super-users were incorrectly affected by restrictions meant only for non-super-users (Permalinks, ACF, Theme\/Plugin Editor, Theme\/Plugin Install, Customizer CSS). Added a single source of truth for super-user checks and fixed a case-sensitivity bug in email matching.<\/li>\n<\/ul>\n\n<h4>1.9.4 \/ 2026-05-08<\/h4>\n\n<ul>\n<li><strong>Bug Fix<\/strong>: Fixed WooCommerce Action Scheduler async runner being blocked by the Login URL Hider. AJAX and cron requests now bypass the login redirect.<\/li>\n<\/ul>\n\n<p><a href=\"https:\/\/github.com\/EstebanForge\/Fuerte-WP\/blob\/master\/CHANGELOG.md\">See the complete changelog on GitHub<\/a><\/p>","raw_excerpt":"WordPress security and maintenance plugin: schedule auto-updates, block malicious updates during supply chain attacks, enforce two-factor authenticati &hellip;","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/145700","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=145700"}],"author":[{"embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/tcattd"}],"wp:attachment":[{"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=145700"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=145700"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=145700"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=145700"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=145700"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=145700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}