Uncompromising Protection for Modern WordPress
We believe security should be transparent, verifiable, and deeply integrated. Attributes WP provides absolute oversight of your ecosystem through meticulous logging and hardened access controls.
Comprehensive Audit Trails
Password Policies
Enforce zero-trust principles across your user base with highly configurable password requirements designed to thwart automated attacks.
- check Minimum length enforcement (up to 128 chars)
- check Required character class complexity
- check Password history & aging rules
- check Real-time breach dictionary checking
What the plugin does itself
Attributes runs inside your WordPress, on your own infrastructure. These are the protections it brings with it.
- verified_user Authenticator secrets encrypted at rest (AES-256-GCM)
- verified_user Sign-in throttled by account and by IP address
- verified_user Every sign-in, lockout and setting change logged
- verified_user Your data stays on your servers — we never receive it
Found something? Tell us first
Report it to security@attributeswp.com, or through the contact form. Please give us a reasonable period to release a fix before saying anything publicly.
We will keep you informed while we work on it, credit you in the release notes unless you would rather we did not, and we will not pursue legal action over research carried out in good faith under this policy.
In scope
- check The free and Pro plugins
- check This website
Out of scope
- remove Findings that need an already-compromised WordPress
- remove Scanner output with no demonstrated impact
- remove Denial of service
Machine-readable: /.well-known/security.txt
Join Our Affiliates
Partner with the most secure WordPress ecosystem toolkit. We offer competitive revenue sharing for agencies and security professionals who recommend Attributes WP.
Learn More About Affiliates arrow_forward