Descripción
Con Security Ninja Premium, es posible bloquear tráfico malicioso mediante firewall, ejecutar pruebas de seguridad, escanear archivos en busca de malware, comparar archivos del core con los originales de WordPress.org y registrar eventos del sitio en registros de auditoría. Atiende a administradores, agencias y dueños de tiendas que necesitan dar seguimiento a vulnerabilidades, intentos de inicio de sesión, cambios sospechosos y reglas de protección sin dispersar los controles entre varios plugins en el panel.
Principales características del Security Ninja Premium
- Firewall de protección
Filtra solicitudes sospechosas, IPs maliciosos e intentos automatizados. - Escáner de malware
Verifica archivos del sitio en busca de código sospechoso. - Pruebas de seguridad
Analiza permisos, configuraciones expuestas y puntos vulnerables de WordPress. - Protección de inicio de sesión
Restringe intentos repetidos y reduce ataques de fuerza bruta. - Registros de eventos
Registra acciones, accesos y cambios relevantes dentro del sitio.
Beneficios del Security Ninja Premium
- Respuesta más rápida
Alertas y registros ayudan a investigar incidentes con más contexto. - Menos exposición técnica
Correcciones guiadas reducen errores comunes de configuración en WordPress. - Control centralizado
Los recursos de firewall, escáner y auditoría permanecen en el mismo panel. - Rutina más predecible
Verificaciones programadas mantienen la seguridad monitoreada sin revisión manual constante.
¿Para quién está indicado Security Ninja Premium?
- Administradores de sitios WordPress que necesitan monitorear seguridad, malware e inicio de sesión.
- Agencias y freelancers que mantienen sitios de clientes bajo seguimiento recurrente.
- Tiendas, portales y proyectos con áreas administrativas sensibles o alto volumen de accesos.
Cómo descargar Security Ninja Premium
Security Ninja Premium está disponible para descargar aquí en Ultrapack. Después de descargar el archivo .zip, instálelo en Plugins > Añadir nuevo > Subir plugin, seleccione el .zip y actívelo. Después de la activación, configure los módulos de seguridad en el panel de WordPress.
Security Ninja Premium concentra capas importantes de protección en una rutina manejable: firewall, escaneo de malware, verificación de integridad, pruebas de seguridad y registro de eventos. Para quienes mantienen sitios WordPress en producción, esta combinación facilita detectar señales de intrusión, bloquear accesos no autorizados y monitorear cambios críticos antes de que pequeños problemas afecten la disponibilidad, la reputación o la operación.
Preguntas frecuentes
¿El plugin Security Ninja Premium es GPL?
Sí. Security Ninja Premium se distribuye bajo la licencia GPL (GNU General Public License). Puedes usarlo, modificarlo y redistribuirlo legalmente en todos los sitios que quieras.
¿Puedo usar el plugin Security Ninja Premium en más de un sitio?
Sí. Puedes instalar Security Ninja Premium en todos los sitios que quieras. Solo las actualizaciones automáticas con Ultrapack Auto Updater tienen límite: de 3 a 80 sitios, según el plan.
¿Cuánto cuesta el plugin Security Ninja Premium en Ultrapack?
Security Ninja Premium cuesta US$ 2,99 en la compra individual, y también está incluido en los planes de suscripción desde US$12/mes (VIP I).
¿El plugin Security Ninja Premium incluye actualizaciones?
Sí. La versión actual de Security Ninja Premium es la 5.303, publicada en Ultrapack el 09/09/2026. Los suscriptores actualizan directamente desde el panel de WordPress con UAU (Ultrapack Auto Updater).
¿Es seguro descargar e instalar el plugin Security Ninja Premium en mi WordPress?
Sí. Cada versión de Security Ninja Premium pasa por un análisis de malware (ClamAV y reglas YARA, en UltraHub) antes de publicarse.
¿Cuáles son los requisitos del plugin Security Ninja Premium?
Requiere WordPress 4.7 o superior y PHP 7.4 o superior. Probado hasta WordPress 7.1.
Qué cambió en esta versión
Versión 5.303
- 2026-09-08
- NEW: Visitor IP detection - Choose how the firewall reads the visitor IP: Automatic, Cloudflare, proxy headers, or REMOTE_ADDR. Automatic trusts Cloudflare ranges by default. For another load balancer or reverse proxy, add its IPs under Trusted proxy CIDRs. Free and Pro.
- IMPROVED: Vulnerability Scanner - Scheduled warning emails wait for a finished scan, skip plugins and themes that are gone or already patched, and do not repeat the same findings within 24 hours. Thank you Jamie.
- IMPROVED: Uninstall - Removing the plugin also clears module tables, settings, cached files, and related user metadata.
- IMPROVED: Events Logger - Administrator emails now cover new accounts and role promotions.
- IMPROVED: Events Logger - Speed improvement - When logging is off, event hooks and database writes are skipped. Broad REST API error logging stays off by default; turn it on in Events settings if you need those diagnostics.
- IMPROVED: Settings import/export and MainWP - Events REST logging and visitor IP settings, including trusted proxy CIDRs, are included when you copy settings between sites.
- IMPROVED: Malware Scanner - Removed the unused legacy scanner.
- IMPROVED: MainWP - Applying settings remotely now reschedules the scanner cron when the schedule changes, and applies the same wp-config updates as the Fixes page (file editor, debug, secure cookies).
- IMPROVED: MainWP - Remote settings now include WooCommerce rate-limit numbers, 2FA grace period and login copy, and satellite/ASN soft-mode lists.
- IMPROVED: Frontend - Speed improvement - Premium no longer loads unused Pro modules on public page views. Free modules are unchanged. Thank you Jose.
Versión 5.302
- 2026-09-01
- FIX: Firewall - Per-visitor reverse-DNS, ASN, and GeoIP caches no longer fill the WordPress options table with one row per IP. On busy sites without Redis/Memcached that could grow to hundreds of thousands of rows and cause intermittent downtime. After update, leftover rows are removed automatically in small batches. Thank you Davina.
- FIX: Firewall - Search-engine and crawler checks only run reverse-DNS when the User-Agent looks like a known crawler. Normal browser traffic no longer triggers a DNS lookup on every page view. AI crawlers (OpenAI, Perplexity, Claude) are checked against published IP ranges only.
- FIX: Firewall - Hostname-based "blocked hosts" matching (part of Filter Suspicious Queries) is off by default. URI, query string, user agent, and referrer rules still run. Developers can re-enable hostname checks with the secnin_cf_check_blocked_hosts filter.
- FIX: Firewall - Satellite/ASN softening (Pro) no longer calls the remote ASN API on every miss when the site has no object cache. With Redis or Memcached, results are cached there instead of in the database.
- FIX: Firewall - The list of remembered validated crawler IPs is limited to 200 entries so it cannot grow without bound.
- FIX: Fixes - Disable Username Enumeration now blocks anonymous REST user listing (/wp/v2/users and ?rest_route=), not only by removing the endpoint. The username enumeration security test checks that path as well. Thank you Elias.
Versión 5.301
- 2026-08-31
- FIX: Fixes - Saving Security Fixes with "Disable debug mode" off no longer forces WP_DEBUG to true in wp-config.php. Thank you Mike.
- IMPROVED: Vulnerability Scanner - Update notices now say we are tracking more known vulnerabilities in the database, not that vulnerabilities were "downloaded" to the site. Thank you Tom.
Versión 5.300
- 2026-08-25
- FIX: Firewall - Removed the blocked_kanagawa hostname rule again (Japanese prefecture / OCN false positives). Thank you Masahiro.
- IMPROVED: Firewall - Filter Suspicious Queries help text now states that it includes reverse-DNS hostname checks, separate from Cloud Firewall and Prevent Banned IPs.
- FIX: Scheduled Scanner - Security Testing emails no longer fire on message-only diffs or HTTP timeout Warning/Good flaps.
Versión 5.299
- 2026-08-24
- FIX: Vulnerability Scanner - Opening the Vulnerabilities tab no longer floods PHP warnings when a CVE reference is missing its display name (Undefined property stdClass::$name) or when strip-http helpers receive null (strpos deprecation on PHP 8+).
- NEW: Cloud Firewall - Claude / Anthropic crawlers (ClaudeBot, Claude-User, Claude-SearchBot) are verified against Anthropic's published IP ranges at claude.com/crawling/bots.json, same pattern as OpenAI and Perplexity. Thank you David.
- FIX: Security Tests - Local site detection no longer strips dots from 127.0.0.1 via sanitize_key (which broke TLS skip-verify). Self-checks against .local hosts and WP_ENVIRONMENT_TYPE=local work again, so tests like debug.log accessibility stop failing with a generic transport error on Local.
- FIX: Security Tests - REST API enabled check now skips TLS verify on local sites (same as other self-checks). Local installs with self-signed certs no longer get a false "Could not determine REST API accessibility" warning.
- FIX: Security Tests - PHP ini boolean checks (allow_url_include, expose_php, display_errors, register_globals, safe_mode) no longer treat the string Off as enabled.
- IMPROVED: Security Tests - expose_php test passes when the PHP version header is already hidden via Security Headers or server config (e.g. .htaccess), not only when php.ini is editable.
- FIX: Auto Fixer - Table prefix change requires an explicit prefix, shows the applied prefix on success, and handles long runs/timeouts more clearly.
Notas de versión publicadas por el desarrollador.
Cómo instalar
Actualización automática: este ítem se actualiza con el Ultrapack Auto Updater. Con él instalado, la versión nueva aparece en tu panel como cualquier otra actualización de WordPress (cómo configurarlo).
- Descarga el archivo
security-ninja-premium.zip. - En el panel de WordPress, ve a Plugins > Añadir nuevo > Subir plugin.
- Selecciona el archivo
security-ninja-premium.zipy haz clic en Instalar ahora. - Haz clic en Activar.
Requisitos: Requiere WordPress 4.7 o superior y PHP 7.4 o superior. Probado hasta WordPress 7.1.
¿Te trabaste en algún paso? Abre un ticket diciendo en cuál te detuviste.

UAU Ready