Watchdog Security Lite — Powered by Lumiverse Nexus

Description

Watchdog Security Lite is the free WordPress security edition powered by Lumiverse Nexus.

It combines practical local protection with a fast, visual security dashboard designed to answer three simple questions:

  • What is happening on my website?
  • What is Watchdog protecting?
  • What may still need my attention?

Watchdog Lite is built with performance in mind. Heavy work is kept away from normal visitor requests wherever possible, and the dashboard avoids turning every unusual request into an attack claim.

Highlights

  • Exploit Shield Lite – blocks a conservative set of high-confidence exploit payloads using local and already-cached rules in the normal WordPress request path.
  • Traffic Shield Lite – conservative protection against suspicious request pressure, probes and selected XML-RPC abuse.
  • Login Guard – protects WordPress login from repeated failed attempts and obvious abuse.
  • Malware Scanner – local file scanning with change-aware coverage and MU-plugin support.
  • Database Threat Scan – bounded, incremental inspection of high-risk WordPress database content for high-confidence malicious code, redirects and persistence indicators.
  • Vulnerability Watch Lite – checks installed WordPress components against Nexus vulnerability intelligence.
  • Official File Integrity – compares WordPress core and supported WordPress.org components with trusted sources.
  • Safe Core Repair – manually restores verified WordPress core files with a protected restore point.
  • Security & Exposure Check – reviews local protection and highlights practical attack-surface items that may deserve attention.
  • Attack Stories – groups related protection events into readable activity sequences instead of repetitive log noise.
  • Watchdog Live Pulse – a real-data visual view of recent traffic, bots and protection activity.
  • Site Change Watch Lite – records important administrator, plugin, theme and risky file changes.
  • Optional administrator TOTP 2FA – authenticator-app protection with one-time recovery codes.
  • WooCommerce Bot Cart Guard Lite – helps stop obvious automation from creating unwanted cart or wishlist state.
  • Weekly Security Digest – optional weekly email with useful protection and security-health signals.
  • Nexus Threat Network Lite – optional shared security intelligence and contributor participation.

Exploit Shield Lite

Exploit Shield Lite blocks a compact, conservative set of high-confidence request payloads such as SQL injection, script injection, path traversal, dangerous PHP stream wrappers and executable upload attempts.

It runs inside the normal WordPress plugin lifecycle. It does not configure auto_prepend_file, and it does not make a remote decision call while serving a visitor request. Nexus PRO remains the earlier pre-WordPress protection tier through its Early WAF architecture.

Database Threat Scan

When enabled, scheduled malware scans also inspect bounded high-risk database content. Watchdog checks selected options plus rotating batches of posts and post metadata for high-confidence malicious code, hidden redirects, obfuscated JavaScript and persistence indicators.

Large content tables are scanned incrementally rather than swept in one expensive pass.

Security you can understand

Watchdog Lite does more than display raw logs.

Security & Exposure Check reviews practical configuration and attack-surface signals, while Attack Stories groups related Traffic Shield and Login Guard events into a readable sequence. The goal is to help site owners understand what Watchdog actually observed and what it actually restricted.

Watchdog does not invent attack events for visual effect.

WooCommerce-aware protection

WooCommerce stores receive cart, wishlist, checkout, AJAX, crawler and catalog traffic that should not all be treated the same way.

Watchdog Lite includes store-aware request protection and WooCommerce Bot Cart Guard Lite, which can neutralize supported cart and wishlist mutations from crawler-claimed or obvious automation while leaving public pages available.

Watchdog Lite and Nexus PRO

Watchdog Lite provides a strong free security foundation inside WordPress.

The dashboard also includes a Protection Horizon that shows where Lite protection ends and what Lumiverse Nexus PRO adds for sites that need more:

  • earlier request containment before WordPress fully processes eligible hostile pressure;
  • deception-based hostile activity observation;
  • adaptive defense that can learn from repeated hostile behavior;
  • richer investigation and recovery workflows;
  • distributed Nexus intelligence across connected sites;
  • Nexus Fleet for agency and multi-site operational visibility.

Learn more at Lumiverse Nexus PRO.

Nexus Threat Network Lite

Nexus Threat Network Lite is disabled by default.

When an administrator enables Threat Intelligence Lite, the site can receive compact shared security intelligence and contribute selected high-confidence security signals.

The participating site URL/domain is included with the authenticated contributor record so the Nexus Network operator can identify the connected installation. Selected verified security signals may include an attacking public IP address and limited security metadata needed for network intelligence.

Threat Network participation does not send passwords, cookies, form contents, customer/order data or page content.

Learn more at Nexus Threat Network.

External Services

Watchdog Security Lite performs routine file and enabled Database Threat scanning locally. Website files, database content and file contents are not uploaded for routine malware scanning.

Watchdog Lite may communicate with services under lumiversenexus.com for malware signatures, vulnerability intelligence and optional Nexus Threat Network functions.

When Threat Intelligence Lite is enabled, the participating site URL/domain is included with its authenticated contributor identity so the Nexus Network operator can identify the connected installation. Selected verified security signals may include an attacking public IP address plus limited security metadata. Aggregate telemetry contains security-event counts and contributor/site attribution, but does not include raw attacking IP addresses in telemetry buckets, request URLs, usernames, cookies, request bodies, passwords, page content, or WooCommerce customer/order data.

Service information: Lumiverse Nexus Privacy Notice and Terms of Service.

Screenshots

Installation

  1. Go to WordPress Dashboard -> Plugins -> Add New.
  2. Search for “Watchdog Security Lite”.
  3. Install and activate the plugin.
  4. Open Watchdog Lite from the WordPress admin menu.
  5. Review the dashboard and choose the protection settings appropriate for your site.

FAQ

Will Watchdog Security Lite slow down my website?

Watchdog Lite is designed to keep heavy work away from normal visitor requests wherever possible. Scanning, reporting and network work are separated from the normal page-delivery path where practical.

What is Security & Exposure Check?

It is a fast local review of Watchdog protection plus practical WordPress attack-surface signals, such as risky public artifacts, PHP files in upload-like locations and selected configuration choices that may deserve review.

It reports what it can verify locally and avoids claiming that a file or feature is publicly exploitable when server-level access cannot be confirmed.

What are Attack Stories?

Attack Stories group related Traffic Shield and Login Guard activity from the same source into a readable sequence. They are built from real events already recorded by Watchdog Lite and do not generate simulated attacks.

Does Database Threat Scan read my entire database on every scan?

No. It inspects selected high-risk options and bounded rotating batches of content tables so large WordPress and WooCommerce databases are covered over time without a full-table sweep on every scheduled scan.

Is administrator 2FA mandatory?

No. TOTP 2FA is optional and configured separately by each administrator.

What does Threat Intelligence Lite share?

Threat Intelligence Lite is disabled by default. When enabled, the participating site URL/domain is registered with the authenticated contributor identity. Selected verified security signals may include an attacking public IP address and limited security metadata. Aggregate telemetry contains event counts and contributor/site attribution.

Passwords, cookies, form contents, customer/order data and page content are not shared through Threat Network participation.

Does the scanner upload my website files?

No. Routine file and enabled database threat scanning is performed locally.

Does the scanner include MU-plugins?

Yes. Malware scanning can include the WordPress MU-plugin directory, and Live Watch can monitor it when enabled.

Does Safe Core Repair change plugins, themes or wp-content?

No. Lite Safe Core Repair restores only verified WordPress core files represented in the official checksum set. It excludes wp-content, wp-config.php and server configuration files, and creates a protected restore point first.

What is Watchdog Live Pulse?

It is a lightweight visual view of real activity already observed by Watchdog Lite, including recent requests, bots and protection events. It does not generate simulated attack events.

Is Watchdog Lite suitable for WooCommerce?

Yes. It includes store-aware traffic protection and optional bot cart-action neutralization. Nexus PRO adds broader WooCommerce resource-defense, adaptive protection and investigation layers for higher-pressure business stores.

Reviews

4 มิถุนายน 2026
I installed the plugin on a few WordPress websites to test it and was pleasantly surprised. The plugin is lightweight, easy to configure and provides useful security monitoring features without affecting site performance. I especially like the file change monitoring and security checks, which can help identify problems before they become serious. Looking forward to future updates. Great work by the developer.
Read all 1 review

Contributors & Developers

“Watchdog Security Lite — Powered by Lumiverse Nexus” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

4.3.0

  • Added Exploit Shield Lite with conservative, local high-confidence request protection for common exploit payload classes in the normal WordPress request path.
  • Added a flagship Exploit Shield dashboard with real blocked-request metrics, attack classes, a seven-day pressure view and a sanitized recent-interventions feed.
  • Integrated Exploit Shield interventions directly into Watchdog Live Pulse, including the live radar, event highlights and combined blocked-today counter.
  • Added Database Threat Scan with bounded, incremental inspection of high-risk WordPress database content for malicious code, redirects and persistence indicators.
  • Integrated both protections into Recommended Local Protection, dashboard status and Security & Exposure Check.
  • Kept WooCommerce protection prominent while preserving optional 2FA and optional Threat Network participation.

4.2.1

  • Refined first-run guidance so Watchdog proves local value before optional services or upgrades are emphasized.
  • Made WooCommerce protection a more prominent dashboard experience with clear store-aware monitoring and commerce-pressure visibility.
  • Improved Security & Exposure Check presentation for WooCommerce stores and clarified quiet/empty monitoring states.
  • Includes reliability hardening for settings persistence and background option updates.

4.2.0

  • Added Security & Exposure Check with a clearer view of practical WordPress attack-surface signals.
  • Added Attack Stories to turn related protection activity into readable security sequences.
  • Added the cinematic Protection Horizon to show current Lite protection and the additional layers available in Nexus PRO.
  • Refined Threat Network contributor identification and dashboard presentation.

4.1.1

  • Improved Nexus Threat Network contributor identification for connected Lite installations.

4.1.0

  • Added the optional Weekly Security Digest and clearer protection, scan-coverage and WooCommerce pressure summaries.

4.0.16

  • Improved Integrity Center presentation and managed-host compatibility.