OOSOFT WAF Security is a WordPress plugin designed to protect websites with an advanced web application firewall. It specifically addresses threats such as SQL injection, cross-site scripting (XSS), malicious file uploads, brute-force login attempts, and suspicious requests, aiming to intercept these attacks before they can impact the site's content, plugins, or database.
The plugin incorporates six active protection modules within the WordPress request lifecycle. Its SQL Injection Protection scans every GET and POST parameter using 15 regex patterns to block injection payloads before they reach the database. The XSS Protection module detects script tags, event handlers, javascript: URIs, and encoded payloads in all request parameters. For file uploads, the Upload Security Scanner blocks dangerous extensions—including PHP, ASP, and shell scripts—detects double-extension attacks, and scans files for known malware signatures. Brute Force Protection tracks failed logins per IP address and blocks further attempts when a set threshold is reached. Security Event Logging records every blocked attack, capturing details such as IP address, request URI, user-agent, and payload in a dedicated database table with configurable retention. The plugin also offers an option to block all access to the XML-RPC endpoint, a common vector for brute-force and amplification attacks, via a single toggle setting.
OOSOFT WAF Security operates at a low level in WordPress, running at init priority 1 to intercept threats before the site loads content. Uploads are scanned prior to reaching the filesystem, and security headers are sent on every front-end response. The plugin has no external dependencies and does not require any third-party cloud services. It is developed according to WordPress Plugin Check standards and is designed to avoid unnecessary bloat or noise.
The plugin is free to install from the official WordPress Plugin Directory and does not require an account for use. It is intended for WordPress site administrators seeking to enhance website security directly within their hosting environment.
In the Infrastructure & Backend space, OOSOFT WAF Security takes a focused approach. It focuses on protecting WordPress sites from malicious requests, malware uploads, and common web attacks. OOSOFT WAF Security is a B2B product aimed at wordPress site administrators and developers. OOSOFT WAF Security costs nothing to use. It runs on the web.
oosoft builds and maintains OOSOFT WAF Security, and it first shipped in 2026. Among its 9 catalogued features are web application firewall, request filtering, and malware upload protection.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do