Controla helps you monitor and improve the security posture of your WordPress installation.
The plugin securely sends essential system metadata to your Controla dashboard so you can identify risks, outdated software, missing configurations, and general site health issues.
Data sent to Controla includes:
- Site and home URLs
- WordPress version, locale, multisite status, and automatic plugin update status
- Installed plugin names, file paths, versions, activation status, and update availability
- Basic server information
- WordPress user IDs, names, email addresses, roles, and two-factor authentication provider status (if configured)
- The plugin's security-hardening settings and generated server security recommendations
The plugin does NOT collect passwords, site content, or session data.
Separately, the plugin stores a local security audit log in the WordPress database. Audit entries can contain usernames, WordPress user IDs, IP addresses, event details, and timestamps. These entries are not included in the data sent to Controla and are retained until the site owner deletes them.
A free Controla account is recommended to make the most out of this plugin.
1.0.2
Document the Controla external service, improve PHP 7.4 compatibility, tighten the recommended-plugin installer, and exclude directory screenshots from release packages.
1.0.1
Support WordPress 7, raise the minimum supported PHP version to 7.4 and WordPress version to 5.9.
1.0.0
Initial release.