maca Sec

Swedish


WordPress powers millions of websites — and attracts attackers just as often. Brute-force login attempts, malicious bots, SQL injection, known CVE vulnerabilities, and unauthorized file changes are everyday threats that can take your site offline or compromise your data.

maca Sec is a security plugin developed by maca Development. It brings firewall (WAF), login protection, two-factor authentication, hardening, scanning, file monitoring, and logging together in one place. Every feature is included from day one — no premium tiers, no locked modules.

The plugin is open source (GPL) and runs on your own server. The admin interface is shown in Swedish when WordPress is set to a Swedish locale, and in English for all other locales. The user guide and legal documents are also available in both languages.


What’s new in the latest release

Collective threat intelligence

maca Sec can anonymously report new attacks to the maca Hub network and receive blocks that have already stopped threats on hundreds of other sites. Repeat attackers are stopped faster.

Filesystem Guard 2.0

Deep scanning of uploads and themes for new PHP files, webshell signatures, and suspicious code — eval, Base64, gzinflate, and more.

Security score

A holistic 0–100 score with a checklist on the dashboard: PHP version, HTTPS, 2FA, WAF, CVE status, and updates — all at a glance.

Live Attack Map

Real-time data on attacks per minute, countries, attack types, and recent exploits — shown in the maca Hub app when your site is connected.

AI bot protection

Per-bot policy (Allow / Block / Limit) for GPTBot, ClaudeBot, Bytespider, PerplexityBot, and Amazonbot.

Smart rate limiting

Behavioral weighting beyond plain IP blocking — burst, URL patterns, method, cookies, and referer — for fewer false positives and better bot protection.


Why maca Sec?

Everything included — Firewall, 2FA, captcha, CVE scanning, honeypot traps, file monitoring, supply chain protection, and security scanner — no paywall.

Built for WordPress — Clear dashboard with security score, logs, checklist, and step-by-step guide in wp-admin.

Protection early — The firewall analyzes traffic before WordPress processes dangerous requests.

You stay in control — Whitelist your IP, choose rules, block countries, and get email alerts. Logged-in administrators bypass the firewall in wp-admin.

Open and transparent — No cloud service required. Logs locally, uninstalls cleanly, telemetry can be disabled.

Swedish and English — Plugin UI, guide, and legal documents in both languages, matched to your WordPress locale.


Features

Firewall (WAF)

Blocks SQL injection, XSS, path traversal, and dangerous uploads. IP blocking, country filters, AI bot policies, and allowlists.

Rate limiting and Attack Shield

Per-IP limits for the whole site, wp-login, wp-admin, XML-RPC, and REST API. Smart rate limiting with behavioral signals. Temporary maintenance mode (HTTP 503) under extreme traffic.

Login protection and honeypot traps

Brute-force blocking, fake login/XML-RPC/REST paths for scanners, captcha (math, reCAPTCHA, or Cloudflare Turnstile), strong passwords, session management, and email alerts.

Two-factor authentication (2FA)

TOTP with Google Authenticator, Authy, or 1Password. QR codes and recovery codes per user.

WordPress hardening and HTTP headers

Close common security gaps and set security headers (X-Frame-Options, HSTS, CSP, etc.).

Security scanner, CVE table, and security score

0–100 score with checklist. Per-plugin CVE table with risk level and update recommendations (WPScan). Email alerts for new high-risk vulnerabilities.

File monitoring and Filesystem Guard 2.0

Monitors critical files and scans uploads and themes for new PHP files, webshell signatures, and suspicious code.

Supply chain protection and behavior analysis

Monitors plugin integrity, author changes, and WordPress.org checksums. 0–100 risk score for unusual REST and POST behavior.

Security log

All events in one place. Filter, search, and block suspicious IPs directly from the log.


maca Hub — in development

maca Hub is an iOS app that connects your WordPress sites with maca plugins. Through maca Sec you can get:

  • Security status and reports on your phone
  • Collective threat intelligence — shared attack patterns across the network
  • Live Attack Map with attacks per minute, countries, and attack types
  • Remote management and allowlist sync

maca Hub is under active development. The app is currently available for iOS only. We are looking for testers who want to try the integration between maca Sec and maca Hub — contact us via the contact form if you would like to join.

maca Hub is optional — maca Sec works fully on its own.


How it works

  1. Install the plugin in WordPress (requires WordPress 6.0+ and PHP 7.4+).
  2. Accept the Terms of Use and Privacy Policy on first activation.
  3. Open the dashboard under maca Sec in the admin menu.
  4. Run a security scan and fix critical issues.
  5. Whitelist your IP before enabling stricter rules.
  6. Enable 2FA on your administrator account.
  7. Review logs regularly — or let email alerts notify you of serious events.

Who is it for?

maca Sec is for anyone running a business site, blog, or webshop on WordPress who wants complete security without paying per feature — in Swedish or English.


Technical requirements

Requirement Version
WordPress 6.0 or later
PHP 7.4+ (8.1+ recommended)
Database MySQL or MariaDB
Languages Swedish and English

Your WordPress site deserves protection that does not charge extra for every new feature. maca Sec gives you that — free, open, and ready to install.

Download maca Sec