PBJ SEO Is Now PBJ SEO & Security: Firewall, Malware Scanning, and Two-Factor Login — Built In
PBJ SEO 4.0.0 is out — and it has a new name: PBJ SEO & Security. Everything the plugin already did for your on-page SEO is still there, exactly as it was. What’s new is a whole second half: a firewall, a malware scanner, two-factor login, site hardening, and an activity log — the tools you’d normally bolt on with a second plugin, now first-party and in the same dashboard.
Nothing turns on by itself. Every security feature ships off. Upgrading changes nothing about how your site behaves until you flip a switch — so you can update today and turn on the pieces you want when you’re ready.
A firewall in front of WordPress
The new Web Application Firewall inspects anonymous requests before WordPress routes them and rejects the classic attack shapes — SQL injection, cross-site scripting, directory traversal, file inclusion, and PHP-injection probes. You get manual IP block and allow lists, header-based country blocking, and a “log only” dry-run mode so you can watch what it would block before you let it block anything. Logged-in users and your own API traffic are never inspected, so it can’t lock you out of your own site.
Malware scanning, with a one-click fix
Scan your core files against the official WordPress.org checksums to catch unauthorized edits, and sweep your plugins, themes, and uploads for backdoor and injected-spam signatures. Found a modified core file? Repair it in one click from the official copy (downloaded and checksum-verified first). Found something rogue? Quarantine it. Run scans on demand, or schedule them daily or weekly.
Lock down the front door
Rate-limit failed logins and lock out the IPs that keep guessing. Turn on two-factor authentication — an authenticator app like Google Authenticator, Authy, or 1Password, or a one-time code by email; no SMS gateway and no third-party service. Move your login screen to a secret URL so bots hammering /wp-login.php just get a 404. Enforce password length and complexity.
Close the doors you never use
One-switch hardening: disable the dashboard file editor, shut off XML-RPC, and hide your WordPress version from opportunistic scanners. And for the brave, an opt-in database-prefix rename — fully backed up and reversible with a single click.
Everything, in one log
A new Logs tab collects every security event in one place — scan findings, firewall blocks, login attempts and lockouts, and site activity — filterable by type and kept for 30 days. If something ever goes wrong, you’ll know exactly when, what, and from where.
Private by default
A few features can check an outside service — your core files against WordPress.org, or a visitor’s IP against a reputation list. None of them do anything unless you turn on both a master “Allow external services” switch and that specific feature, and each one spells out in plain language exactly what it sends and what comes back. Everything else runs entirely inside your own site.
And on the SEO side
Your 404 log now keeps not-found URLs for 30 days, and you can tick several at once and point them all at a single page — or dismiss them together — in one action.
Upgrading
Upload the new zip over the old plugin (or use the one-click update if your license key is saved) — the database migrates itself on first load, and all your settings and SEO data are preserved. The plugin’s name changes in your dashboard; the slug does not, so it’s a normal in-place update.
PBJ SEO 4.0.0 is out — and it has a new name: PBJ SEO & Security. Everything the plugin already did for your on-page SEO is still there, exactly as it was. What’s new is a whole second half: a firewall, a malware scanner, two-factor login, site hardening, and an activity log — the tools you’d normally bolt on with a second plugin, now first-party and in the same dashboard.
Nothing turns on by itself. Every security feature ships off. Upgrading changes nothing about how your site behaves until you flip a switch — so you can update today and turn on the pieces you want when you’re ready.
A firewall in front of WordPress
The new Web Application Firewall inspects anonymous requests before WordPress routes them and rejects the classic attack shapes — SQL injection, cross-site scripting, directory traversal, file inclusion, and PHP-injection probes. You get manual IP block and allow lists, header-based country blocking, and a “log only” dry-run mode so you can watch what it would block before you let it block anything. Logged-in users and your own API traffic are never inspected, so it can’t lock you out of your own site.
Malware scanning, with a one-click fix
Scan your core files against the official WordPress.org checksums to catch unauthorized edits, and sweep your plugins, themes, and uploads for backdoor and injected-spam signatures. Found a modified core file? Repair it in one click from the official copy (downloaded and checksum-verified first). Found something rogue? Quarantine it. Run scans on demand, or schedule them daily or weekly.
Lock down the front door
Rate-limit failed logins and lock out the IPs that keep guessing. Turn on two-factor authentication — an authenticator app like Google Authenticator, Authy, or 1Password, or a one-time code by email; no SMS gateway and no third-party service. Move your login screen to a secret URL so bots hammering /wp-login.php just get a 404. Enforce password length and complexity.
Close the doors you never use
One-switch hardening: disable the dashboard file editor, shut off XML-RPC, and hide your WordPress version from opportunistic scanners. And for the brave, an opt-in database-prefix rename — fully backed up and reversible with a single click.
Everything, in one log
A new Logs tab collects every security event in one place — scan findings, firewall blocks, login attempts and lockouts, and site activity — filterable by type and kept for 30 days. If something ever goes wrong, you’ll know exactly when, what, and from where.
Private by default
A few features can check an outside service — your core files against WordPress.org, or a visitor’s IP against a reputation list. None of them do anything unless you turn on both a master “Allow external services” switch and that specific feature, and each one spells out in plain language exactly what it sends and what comes back. Everything else runs entirely inside your own site.
And on the SEO side
Your 404 log now keeps not-found URLs for 30 days, and you can tick several at once and point them all at a single page — or dismiss them together — in one action.
Upgrading
Upload the new zip over the old plugin (or use the one-click update if your license key is saved) — the database migrates itself on first load, and all your settings and SEO data are preserved. The plugin’s name changes in your dashboard; the slug does not, so it’s a normal in-place update.