SEDAJ Sentinel geometric shield on a navy and teal cybersecurity network

WordPress security · local first

Less abuse.
More control.

SEDAJ Sentinel protects forms, logins, requests and file integrity directly inside WordPress—without collecting the content it is built to protect.

Read the security model →

Current local release 2.3.2 · WordPress 6.1+ · PHP 7.4+

Sentinel localACTIVE
Protection foundationLOCALIndependent of cloud availability
FFormsAdaptive scoringON
WFirewallApplication layerON
LLoginBrute-force limitsON
SScannerIntegrity checksLOCAL
0form fields stored
0raw IP addresses stored
4local protection areas
2.3.2current release

Protection layers

Security that understands WordPress.

Sentinel combines focused application-layer controls instead of pretending that one generic blocklist can solve every problem.

01

Adaptive form protection

Protects Contact Form 7 and native comments with signed time-limited tokens, timing checks, behavioral signals and compound risk scoring.

02

Application firewall

Blocks high-confidence traversal, injection, cross-site scripting and executable payload patterns before WordPress processes them further.

03

Login hardening

Limits brute-force attempts and password-reset abuse, masks revealing login errors and supports stronger privileged-account hygiene.

04

Integrity scanner

Checks WordPress core against official checksums and looks for executable uploads and high-confidence dangerous PHP signatures.

05

User-enumeration protection

Reduces public username discovery through REST endpoints, author scans, oEmbed data and the WordPress user sitemap.

06

Privacy-safe visibility

Shows anonymous outcomes, blocked reasons, trends and scan status without retaining submitted fields, names, messages or raw IP addresses.

Why Sentinel

Protection without punishing real visitors.

Security belongs in the background. Sentinel adds local controls and useful operational visibility while keeping the public website clean and the data footprint deliberately small.

Invisible to legitimate visitors

Protection works without changing the public design. Turnstile is optional and stays disabled until valid keys are configured.

Useful signals, less noise

Multiple independent signals are combined before a request is treated as suspicious, reducing dependence on one brittle rule.

Local control

Rules, scan results, anonymous activity and configuration remain in the WordPress administration environment.

Safe operational choices

The scanner reports findings but never repairs or deletes files automatically. Compatibility-sensitive controls stay configurable.

How it works

From signal to decision—locally.

Form contents never need to leave the website for Sentinel to make a local protection decision.

01

Observe

Signed form tokens, request timing, behavior and local security signals are evaluated at the WordPress layer.

02

Decide

Adaptive scoring and configurable limits distinguish ordinary activity from high-confidence automated abuse.

03

Act

Sentinel blocks or flags the request locally, before a rejected Contact Form 7 submission reaches mail delivery.

04

Explain

The dashboard records a reason, source, UTC time and salted one-way fingerprint—not the submitted content.

Integrity scanner

Know what changed. Keep the decision.

Scheduled and on-demand scans verify official WordPress core checksums, inspect the uploads area for executable PHP and detect high-confidence dangerous signatures in PHP code.

  • Staged scan progress with checked-file and finding counts
  • Optional e-mail only when findings change or the site returns clean
  • No automatic repair, quarantine or deletion
Integrity scanREAD ONLY
Transparent by defaultFindings require administrator review
Core checksumsUpload safetyPHP signatures

Product boundary

Local is available. Cloud is separate.

No future roadmap item is presented as part of the current plugin.

AVAILABLE NOW

Sentinel Local 2.3.2

Form protection, firewall, login hardening, integrity scanning, anonymous local activity and configurable hardening controls.

Release and distribution status →
NOT LAUNCHED

Sentinel Cloud

A separately designed future service for signed, versioned security feeds. It will never be required for the essential local protection layer.

Read the cloud boundary →

SEDAJ Sentinel 2.3.2

Local protection.
Clear responsibility.

Explore the dedicated Sentinel website. Public purchasing and verified ZIP distribution through apps.sedaj.com are not active yet.

Open Sentinel website Distribution coming after release verification