Real plugin admin demo: this is the installed plugin interface. The demo guard disables saving, actions, credentials, licenses, and all unlisted WordPress administration screens.

artistpro Security: Please enter your license key to receive updates. Enter License Key

Tip: Generate an emergency access URL in case you lock yourself out. Generate Now

apSecurity Setup

A guided setup path for local protection, edge blocking, scanning, and reviewable cleanup.

apSecurity setup overview

Beginner Path

  1. Whitelist your own admin IP.
  2. Activate the paid license through artistprowp.com.
  3. Use Cloudflare only if the website is proxied through Cloudflare.
  4. Run a manual scan before turning on stronger settings.

Advanced Path

  1. Connect Cloudflare or AWS WAF with least-privilege credentials.
  2. Enable virtual patching and confirm normal traffic still works.
  3. Run a background scan and review noisy medium findings.
  4. Export an incident package before destructive cleanup actions.

1. License

Use the apLicense service on artistprowp.com for activation, update checks, and license status. apSecurity uses one paid license, not separate feature tiers.

License type: Paid

Status: unlicensed

Authority: https://artistprowp.com/wp-json/artistpro-license/v1/

Purchase License Find My License

2. Edge Provider

Connect Cloudflare or AWS WAF from the Edge Providers page. Environment variables are preferred for credentials.

Cloudflare: not_configured

AWS WAF: not_configured

Open Edge Settings

3. Scanner

Run a manual scan first, then use the background scan on larger sites.

Threat feed: error

Bundled fallback rules are active. Signed remote rule updates are not active until a feed public key and verified feed are configured.

Scanner results preview

Open Scanner

4. Virtual Patching

Status: enabled

  • waf-upload-php-execution: Block PHP execution from uploads and upgrade folders
  • waf-request-php-payload: Block request-delivered PHP payload probes
  • waf-wp-user-creation-probe: Block request-controlled WordPress admin creation probes
  • waf-lfi-path-traversal: Block local-file inclusion and traversal probes
  • waf-sql-injection-probe: Block common SQL injection probes
  • waf-template-injection-probe: Block template/server-side injection probes
  • waf-plugin-file-upload-probe: Block suspicious plugin upload endpoint payloads