Real plugin admin demo: this is the installed plugin interface. The demo guard disables saving, actions, credentials, licenses, and all unlisted WordPress administration screens.
artistpro Security: Please enter your license key to receive updates. Enter License Key
Tip: Generate an emergency access URL in case you lock yourself out. Generate Now
apSecurity Setup
A guided setup path for local protection, edge blocking, scanning, and reviewable cleanup.
Beginner Path
- Whitelist your own admin IP.
- Activate the paid license through artistprowp.com.
- Use Cloudflare only if the website is proxied through Cloudflare.
- Run a manual scan before turning on stronger settings.
Advanced Path
- Connect Cloudflare or AWS WAF with least-privilege credentials.
- Enable virtual patching and confirm normal traffic still works.
- Run a background scan and review noisy medium findings.
- Export an incident package before destructive cleanup actions.
1. License
Use the apLicense service on artistprowp.com for activation, update checks, and license status. apSecurity uses one paid license, not separate feature tiers.
2. Edge Provider
Connect Cloudflare or AWS WAF from the Edge Providers page. Environment variables are preferred for credentials.
Cloudflare: not_configured
AWS WAF: not_configured
3. Scanner
Run a manual scan first, then use the background scan on larger sites.
Threat feed: error
Bundled fallback rules are active. Signed remote rule updates are not active until a feed public key and verified feed are configured.
4. Virtual Patching
Status: enabled
- waf-upload-php-execution: Block PHP execution from uploads and upgrade folders
- waf-request-php-payload: Block request-delivered PHP payload probes
- waf-wp-user-creation-probe: Block request-controlled WordPress admin creation probes
- waf-lfi-path-traversal: Block local-file inclusion and traversal probes
- waf-sql-injection-probe: Block common SQL injection probes
- waf-template-injection-probe: Block template/server-side injection probes
- waf-plugin-file-upload-probe: Block suspicious plugin upload endpoint payloads