Adaptive form protection
Protects Contact Form 7 and native comments with signed time-limited tokens, timing checks, behavioral signals and compound risk scoring.

WordPress security · local first
SEDAJ Sentinel protects forms, logins, requests and file integrity directly inside WordPress—without collecting the content it is built to protect.
Read the security model →Current local release 2.3.2 · WordPress 6.1+ · PHP 7.4+
Protection layers
Sentinel combines focused application-layer controls instead of pretending that one generic blocklist can solve every problem.
Protects Contact Form 7 and native comments with signed time-limited tokens, timing checks, behavioral signals and compound risk scoring.
Blocks high-confidence traversal, injection, cross-site scripting and executable payload patterns before WordPress processes them further.
Limits brute-force attempts and password-reset abuse, masks revealing login errors and supports stronger privileged-account hygiene.
Checks WordPress core against official checksums and looks for executable uploads and high-confidence dangerous PHP signatures.
Reduces public username discovery through REST endpoints, author scans, oEmbed data and the WordPress user sitemap.
Shows anonymous outcomes, blocked reasons, trends and scan status without retaining submitted fields, names, messages or raw IP addresses.
Why Sentinel
Security belongs in the background. Sentinel adds local controls and useful operational visibility while keeping the public website clean and the data footprint deliberately small.
Protection works without changing the public design. Turnstile is optional and stays disabled until valid keys are configured.
Multiple independent signals are combined before a request is treated as suspicious, reducing dependence on one brittle rule.
Rules, scan results, anonymous activity and configuration remain in the WordPress administration environment.
The scanner reports findings but never repairs or deletes files automatically. Compatibility-sensitive controls stay configurable.
How it works
Form contents never need to leave the website for Sentinel to make a local protection decision.
Signed form tokens, request timing, behavior and local security signals are evaluated at the WordPress layer.
Adaptive scoring and configurable limits distinguish ordinary activity from high-confidence automated abuse.
Sentinel blocks or flags the request locally, before a rejected Contact Form 7 submission reaches mail delivery.
The dashboard records a reason, source, UTC time and salted one-way fingerprint—not the submitted content.
Integrity scanner
Scheduled and on-demand scans verify official WordPress core checksums, inspect the uploads area for executable PHP and detect high-confidence dangerous signatures in PHP code.
Product boundary
No future roadmap item is presented as part of the current plugin.
Form protection, firewall, login hardening, integrity scanning, anonymous local activity and configurable hardening controls.
Release and distribution status →A separately designed future service for signed, versioned security feeds. It will never be required for the essential local protection layer.
Read the cloud boundary →SEDAJ Sentinel 2.3.2
Explore the dedicated Sentinel website. Public purchasing and verified ZIP distribution through apps.sedaj.com are not active yet.
Open Sentinel website ↗Distribution coming after release verification