Descrição
Com o Security Ninja Premium, é possível bloquear tráfego malicioso por firewall, executar testes de segurança, escanear arquivos em busca de malware, comparar arquivos do core com originais do WordPress.org e registrar eventos do site em logs de auditoria. Ele atende administradores, agências e lojistas que precisam acompanhar vulnerabilidades, tentativas de login, alterações suspeitas e regras de proteção sem espalhar controles por vários plugins no painel.
Principais Características do Security Ninja Premium
- Firewall de proteção
Filtra requisições suspeitas, IPs maliciosos e tentativas automatizadas. - Scanner de malware
Verifica arquivos do site em busca de código suspeito. - Testes de segurança
Analisa permissões, configurações expostas e pontos vulneráveis do WordPress. - Proteção de login
Restringe tentativas repetidas e reduz ataques de força bruta. - Logs de eventos
Registra ações, acessos e alterações relevantes dentro do site.
Benefícios do Security Ninja Premium
- Resposta mais rápida
Alertas e registros ajudam a investigar incidentes com mais contexto. - Menos exposição técnica
Correções guiadas reduzem falhas comuns de configuração no WordPress. - Controle centralizado
Recursos de firewall, scanner e auditoria ficam no mesmo painel. - Rotina mais previsível
Verificações programadas mantêm a segurança acompanhada sem revisão manual constante.
Para Quem o Security Ninja Premium é Indicado?
- Administradores de sites WordPress que precisam monitorar segurança, malware e login.
- Agências e freelancers que mantêm sites de clientes sob acompanhamento recorrente.
- Lojas, portais e projetos com áreas administrativas sensíveis ou alto volume de acessos.
Como Baixar o Security Ninja Premium
O Security Ninja Premium está disponível para download aqui no Ultrapack. Após baixar o arquivo .zip, instale em Plugins > Adicionar Novo > Enviar plugin, selecione o .zip e ative. Depois da ativação, configure os módulos de segurança no painel do WordPress.
O Security Ninja Premium concentra camadas importantes de proteção em uma rotina administrável: firewall, varredura de malware, checagem de integridade, testes de segurança e registro de eventos. Para quem mantém sites WordPress em produção, essa combinação facilita detectar sinais de invasão, bloquear acessos indevidos e acompanhar alterações críticas antes que pequenos problemas afetem disponibilidade, reputação ou operação.
Perguntas Frequentes
O plugin Security Ninja Premium é GPL?
Sim. O Security Ninja Premium é distribuído sob a licença GPL (GNU General Public License). Você pode usar, modificar e redistribuir legalmente, em quantos sites quiser.
Posso usar o plugin Security Ninja Premium em mais de um site?
Sim. Você pode instalar o Security Ninja Premium em quantos sites quiser. Só as atualizações automáticas pelo Ultrapack Auto Updater têm limite: de 3 a 80 sites, conforme o plano.
Quanto custa o plugin Security Ninja Premium no Ultrapack?
O Security Ninja Premium sai por R$ 14,90 na compra avulsa, e também está incluído nos planos de assinatura a partir de R$59/mês (VIP I).
O plugin Security Ninja Premium inclui atualizações?
Sim. A versão atual do Security Ninja Premium é a 5.303, publicada no Ultrapack em 09/09/2026. Assinantes atualizam direto do painel do WordPress com o UAU (Ultrapack Auto Updater).
O plugin Security Ninja Premium é seguro para baixar e instalar no meu WordPress?
Sim. Cada versão do Security Ninja Premium passa por varredura de malware (ClamAV e regras YARA, no UltraHub) antes de ser publicada.
Quais são os requisitos do plugin Security Ninja Premium?
Requer WordPress 4.7 ou superior e PHP 7.4 ou superior. Testado até o WordPress 7.1.
O que mudou nesta versão
Versão 5.303
- 2026-09-08
- NEW: Visitor IP detection - Choose how the firewall reads the visitor IP: Automatic, Cloudflare, proxy headers, or REMOTE_ADDR. Automatic trusts Cloudflare ranges by default. For another load balancer or reverse proxy, add its IPs under Trusted proxy CIDRs. Free and Pro.
- IMPROVED: Vulnerability Scanner - Scheduled warning emails wait for a finished scan, skip plugins and themes that are gone or already patched, and do not repeat the same findings within 24 hours. Thank you Jamie.
- IMPROVED: Uninstall - Removing the plugin also clears module tables, settings, cached files, and related user metadata.
- IMPROVED: Events Logger - Administrator emails now cover new accounts and role promotions.
- IMPROVED: Events Logger - Speed improvement - When logging is off, event hooks and database writes are skipped. Broad REST API error logging stays off by default; turn it on in Events settings if you need those diagnostics.
- IMPROVED: Settings import/export and MainWP - Events REST logging and visitor IP settings, including trusted proxy CIDRs, are included when you copy settings between sites.
- IMPROVED: Malware Scanner - Removed the unused legacy scanner.
- IMPROVED: MainWP - Applying settings remotely now reschedules the scanner cron when the schedule changes, and applies the same wp-config updates as the Fixes page (file editor, debug, secure cookies).
- IMPROVED: MainWP - Remote settings now include WooCommerce rate-limit numbers, 2FA grace period and login copy, and satellite/ASN soft-mode lists.
- IMPROVED: Frontend - Speed improvement - Premium no longer loads unused Pro modules on public page views. Free modules are unchanged. Thank you Jose.
Versão 5.302
- 2026-09-01
- FIX: Firewall - Per-visitor reverse-DNS, ASN, and GeoIP caches no longer fill the WordPress options table with one row per IP. On busy sites without Redis/Memcached that could grow to hundreds of thousands of rows and cause intermittent downtime. After update, leftover rows are removed automatically in small batches. Thank you Davina.
- FIX: Firewall - Search-engine and crawler checks only run reverse-DNS when the User-Agent looks like a known crawler. Normal browser traffic no longer triggers a DNS lookup on every page view. AI crawlers (OpenAI, Perplexity, Claude) are checked against published IP ranges only.
- FIX: Firewall - Hostname-based "blocked hosts" matching (part of Filter Suspicious Queries) is off by default. URI, query string, user agent, and referrer rules still run. Developers can re-enable hostname checks with the secnin_cf_check_blocked_hosts filter.
- FIX: Firewall - Satellite/ASN softening (Pro) no longer calls the remote ASN API on every miss when the site has no object cache. With Redis or Memcached, results are cached there instead of in the database.
- FIX: Firewall - The list of remembered validated crawler IPs is limited to 200 entries so it cannot grow without bound.
- FIX: Fixes - Disable Username Enumeration now blocks anonymous REST user listing (/wp/v2/users and ?rest_route=), not only by removing the endpoint. The username enumeration security test checks that path as well. Thank you Elias.
Versão 5.301
- 2026-08-31
- FIX: Fixes - Saving Security Fixes with "Disable debug mode" off no longer forces WP_DEBUG to true in wp-config.php. Thank you Mike.
- IMPROVED: Vulnerability Scanner - Update notices now say we are tracking more known vulnerabilities in the database, not that vulnerabilities were "downloaded" to the site. Thank you Tom.
Versão 5.300
- 2026-08-25
- FIX: Firewall - Removed the blocked_kanagawa hostname rule again (Japanese prefecture / OCN false positives). Thank you Masahiro.
- IMPROVED: Firewall - Filter Suspicious Queries help text now states that it includes reverse-DNS hostname checks, separate from Cloud Firewall and Prevent Banned IPs.
- FIX: Scheduled Scanner - Security Testing emails no longer fire on message-only diffs or HTTP timeout Warning/Good flaps.
Versão 5.299
- 2026-08-24
- FIX: Vulnerability Scanner - Opening the Vulnerabilities tab no longer floods PHP warnings when a CVE reference is missing its display name (Undefined property stdClass::$name) or when strip-http helpers receive null (strpos deprecation on PHP 8+).
- NEW: Cloud Firewall - Claude / Anthropic crawlers (ClaudeBot, Claude-User, Claude-SearchBot) are verified against Anthropic's published IP ranges at claude.com/crawling/bots.json, same pattern as OpenAI and Perplexity. Thank you David.
- FIX: Security Tests - Local site detection no longer strips dots from 127.0.0.1 via sanitize_key (which broke TLS skip-verify). Self-checks against .local hosts and WP_ENVIRONMENT_TYPE=local work again, so tests like debug.log accessibility stop failing with a generic transport error on Local.
- FIX: Security Tests - REST API enabled check now skips TLS verify on local sites (same as other self-checks). Local installs with self-signed certs no longer get a false "Could not determine REST API accessibility" warning.
- FIX: Security Tests - PHP ini boolean checks (allow_url_include, expose_php, display_errors, register_globals, safe_mode) no longer treat the string Off as enabled.
- IMPROVED: Security Tests - expose_php test passes when the PHP version header is already hidden via Security Headers or server config (e.g. .htaccess), not only when php.ini is editable.
- FIX: Auto Fixer - Table prefix change requires an explicit prefix, shows the applied prefix on success, and handles long runs/timeouts more clearly.
Notas de versão publicadas pelo desenvolvedor.
Como instalar
Atualização automática: este item é atualizado pelo Ultrapack Auto Updater. Com ele instalado, a versão nova aparece no seu painel como qualquer outra atualização do WordPress (como configurar).
- Baixe o arquivo
security-ninja-premium.zip. - No painel do WordPress, vá em Plugins > Adicionar novo > Enviar plugin.
- Selecione o arquivo
security-ninja-premium.zipe clique em Instalar agora. - Clique em Ativar.
Requisitos: Requer WordPress 4.7 ou superior e PHP 7.4 ou superior. Testado até o WordPress 7.1.
Travou em algum passo? Abra um chamado dizendo em qual deles parou.

UAU Ready