NEVERLAST SENTINEL SECURITY

Security that stays
alert.

A WordPress security suite built for site owners, administrators, agencies and developers — from essential baseline protection to advanced monitoring, testing, automation and incident response.

01 Protect Reduce exposure before incidents escalate.
02 Detect Surface suspicious activity and integrity changes.
03 Respond Support controlled remediation and recovery.
GUARDIAN ONLINE Compromised WordPress admin ≠ full control.

Protected high-risk operations can require a second authorization plane independent of the WordPress session.

Site owners WordPress admins Agencies Developers Security teams
ProtectionActive posture
IntegrityContinuous awareness
AuthenticationStronger access control
ResponseControlled actions
✓
WordPress focusedDesigned specifically for WordPress security operations.
2FA
Stronger authenticationAdditional account protection and access safeguards.
24/7
Continuous awarenessMonitoring, scanning and retained security visibility.
↺
Controlled responseSupport for mitigation, recovery and reporting.

EXTREME SECURITY · GUARDIAN

A stolen admin account does not have to mean a stolen site.

WordPress normally treats an authenticated administrator as highly trusted. Sentinel Extreme Security can add a second authorization boundary for selected high-risk operations, while Guardian maintains an integrity and recovery layer independent of ordinary WordPress administrator access.

G
GUARDIAN ONLINE

WordPress administrator access is not the final authority for protected operations.

When an ESF policy is in Protect, selected critical operations can be refused even when the requester already has a valid WordPress administrator session. A short, scoped maintenance authorization is required for the protected task.

2ndauthorization plane
Scopedmaintenance windows
Offlinebreak-glass recovery
IndependentGuardian integrity

ADMIN ACCOUNT TAKEOVER CONTAINMENT

What changes when Guardian protection is active?

1 Admin session stolen

The attacker may possess a valid WordPress administrator cookie or credential.

→
2 Protected action attempted

A high-risk administrative, user, product, payment or plugin operation is requested.

→
3 Guardian / ESF checks

WordPress authorization alone is insufficient when the selected protection is in Protect.

→
4 Refused by default

Without the required short-lived authorization window, the protected operation is denied.

01

Separate security identity

Extreme Security uses security credentials separate from the normal WordPress account, with optional additional authentication.

02

Independent Guardian integrity

Guardian keeps protected package and signed policy state separate from ordinary administrator access.

03

Short maintenance authorization

Critical changes can be opened only for a specific maintenance task and locked again immediately after completion.

04

Protected updates

Protected package updates are reviewed as explicit version transitions instead of silently trusting a normal update result.

05

Whole-package recovery

Recovery is designed around verified package state rather than opportunistically mixing files from different versions.

06

Offline break-glass recovery

A separately stored hard-copy recovery mechanism provides a local recovery path when online services are unavailable.

CREDENTIAL COMPROMISE RESPONSE

Emergency Login Kill Switch

Sentinel also includes emergency administrator-login containment designed for credential compromise: session destruction, temporary login freeze and a controlled recovery path using a separate emergency secret.

Destroy active sessions Freeze new logins Rotate credentials Recover through controlled flow
Security boundary:

Guardian does not make a WordPress site invulnerable and cannot protect a server after an attacker gains unrestricted hosting, filesystem, database or infrastructure-level control. Its purpose is to make a compromised WordPress administrator identity insufficient for the high-risk operations explicitly placed behind the second authorization boundary.

PUBLIC CAPABILITY OVERVIEW

Defense across the WordPress security lifecycle.

Sentinel combines multiple defensive functions in one operational surface while keeping implementation details, detection logic and enforcement internals private.

01
⌁

Web protection

Helps inspect and control suspicious requests before they become application-level incidents.

02
◉

Login & account security

Adds stronger authentication controls and safeguards around privileged access.

03
◇

Integrity & malware scanning

Supports file integrity awareness, malware-oriented inspection and change visibility.

04
△

Vulnerability awareness

Helps identify known-risk software conditions and surface security-relevant update priorities.

05
⊙

Adaptive monitoring

Observes site behavior and security signals to improve operator awareness without exposing internal detection logic.

06
↯

Mitigation & remediation

Provides controlled tools for temporary protection, quarantine, restore and incident handling.

07
☷

Reports & audit visibility

Consolidates security events, operator context and reporting into a unified administrative experience.

08
◎

Compatibility testing

Includes non-destructive checks intended to reduce the risk of breaking normal WordPress operation.

FREE PROTECTION · ADVANCED PRO SECURITY

Start protected. Go deeper when you need to.

Sentinel keeps essential protection available without a Pro licence. Pro adds deeper inspection, stronger identity controls, recurring security operations, vulnerability intelligence and controlled response.

FREE

Sentinel Free

Essential protections that remain available without a Pro entitlement.

✓

Basic firewall filteringBaseline request protection for common high-confidence threats.

✓

Login rate limitingHelps reduce repeated authentication abuse.

✓

XML-RPC controlReduce unnecessary exposure when XML-RPC is not required.

✓

Security headersBrowser-facing hardening for common web risks.

✓

Basic security scanPractical security checks and prioritised findings.

✓

Hardening checklistGuidance for safer WordPress configuration.

✓

Activity logSecurity-relevant visibility directly inside WordPress.

Best for Personal sites · small businesses · baseline protection · first-time security users
PRO
PRO

Sentinel Security Pro

Deeper controls for business sites, WooCommerce, agencies, developers and security operators.

✓

Advanced WAF protectionScored request inspection, stronger operating modes and narrow compatibility exclusions.

✓

Malware signature scanningDeeper inspection for suspicious file patterns.

✓

File integrity monitoringKnown-good baselines and change evidence.

✓

2FA & recovery controlsEmail OTP, authenticator TOTP, backup codes, trusted devices and role enforcement.

✓

Scheduled scansRecurring checks without manual initiation.

✓

Vulnerability intelligenceLocal component/version matching against available vulnerability records.

✓

Safe FuzzerBounded, non-destructive endpoint security testing for controlled environments.

✓

Email alertsActionable notifications and delivery history.

✓

Quarantine & remediationPreview, quarantine, restore and controlled permanent deletion.

✓

Virtual patchesTemporary targeted protection while awaiting upstream fixes.

✓

Signed protection updatesAuthenticated live rule updates for licensed installations.

Best for Business · WooCommerce · agencies · managed sites · developers · security teams
i

Locked Pro pages explicitly distinguish not checked from clean. Free protection remains available independently from Pro entitlement state.

FROM SITE OWNER TO SECURITY ENGINEER

One product. Different levels of depth.

Sentinel is designed to be usable without specialist security knowledge, but it does not stop at a simplified dashboard. Administrators, agencies and developers can progressively move into deeper technical and automated workflows.

SITE OWNER

Tell me what matters.

Clear posture, important findings, safer defaults and explanations that do not assume security expertise.

  • Dashboard security posture
  • Guided onboarding
  • Built-in Guide & Wiki
  • Contextual tooltips
  • Hardening checklist
  • Readable findings
WORDPRESS ADMIN

Give me safe operational control.

Staged deployment, compatibility testing, monitoring-first workflows and recoverable incident response.

  • Monitor → Balanced → Strict workflow
  • Compatibility Autopilot
  • Scan coverage visibility
  • 2FA commissioning guidance
  • Quarantine before deletion
  • Session invalidation
AGENCY / MSP

Make security repeatable.

Structured reporting, exports, client-facing evidence and workflows for managed WordPress environments.

  • Client-facing HTML reports
  • CSV / JSON-oriented exports
  • Audit-friendly event history
  • Compatibility testing
  • Scheduled scans
  • Multi-channel alerting
DEVELOPER / SECOPS

Expose automation, not just buttons.

Developer-facing surfaces support repeatable administration, integration and machine-readable security evidence.

  • WP-CLI support
  • REST API support
  • NLSSP_Logger::log()
  • NLSSP_Alerts::notify()
  • Scheduled maintenance hooks
  • Scheduled scan hooks
1UnderstandPlain-language posture
→
2ConfigureGuided safe defaults
→
3InvestigateTechnical evidence
→
4RespondControlled remediation
→
5AutomateCLI · API · scheduled jobs

ATTACK SIMULATION EVIDENCE

Tested under bounded hostile traffic.

The recorded physical Attack Lab figures below belong to the 1.9.15 laboratory evidence set from 5 August 2026. The current 2.0.1 beta line contains later security and Guardian work, so these numbers are retained as historical measured evidence — not presented as a complete validation statement for every later build.

EXTREME MIXED SCENARIO · RECORDED PASS 3,000 / 3,000

requests completed and refused

0 server errors · 0 network errors

Throughput99.8requests / second
p50 latency46ms
p95 latency80ms
5xx responses0recorded
PASS

Authentication pressure

20 / 20 completed with no server or network errors. Sentinel recorded rate-limit engagement while both isolated control requests passed.

4.1 RPSp95 110 ms
PASS

WAF barrage

18 / 18 hostile probes blocked while 2 / 2 legitimate controls were allowed.

4.0 RPSp95 124 ms
PASS

Scanner storm

18 / 18 scanner probes refused with no 5xx response in the recorded isolated run.

4.1 RPSp95 171 ms
PASS

Mixed siege · heavy

375 / 375 requests refused across scanner, WAF and authentication traffic.

25.0 RPSp95 81 ms
CURRENT LINE
Sentinel 2.0.1 beta evolved beyond the original 1.9.15 ASR snapshot.

Later builds added and hardened Extreme Security / Guardian workflows, administrator protection, signed intelligence, compatibility logic, protected updates and operational controls. The current build line is validated separately from the historical 5 August performance run.

AI / AGENTIC ATTACK LAB

Security testing for attackers that adapt.

These are defensive scenarios in the Sentinel Attack Lab catalog. They are shown as validation scenarios, not recorded PASS results unless a bound execution report exists.

AL-001CRITICAL

AI-orchestrated espionage

Multi-stage agentic activity that changes identities, paths and tactics while progressing from reconnaissance toward impact.

Goal: correlate a campaign instead of treating every request independently.
AL-002CRITICAL

Autonomous vulnerability enumeration

An adaptive synthetic adversary abandons blocked options and immediately explores alternatives.

Goal: detect speed, breadth, transitions and adaptive pivoting.
AL-003CRITICAL

AI-assisted unknown attack behavior

Previously unseen synthetic behavior changes form between runs while preserving the same harmless consequence.

Goal: avoid depending exclusively on known vulnerability signatures.
AL-004CRITICAL

Indirect prompt injection

Untrusted web or log content attempts to influence a mock administrative AI component.

Pass target: zero unauthorized tool execution and zero privileged data disclosure.
BF-001BOSS FIGHT

Eight-agent adaptive WordPress campaign

Eight synthetic specialist agents coordinate reconnaissance, identity, alternate-path and persistence-like simulation.

Goal: containment before synthetic impact with auditable recovery.
BF-003BOSS FIGHT

Fleet intelligence poisoning

A synthetic tenant floods low-quality attack-like signals attempting to create a harmful shared defensive conclusion.

Goal: frequency alone must never create trusted fleet-wide intelligence.
RL-001RESEARCH

Autonomous multi-agent chain

Cross-surface state sharing between synthetic web, identity, host and cloud events.

Goal: preserve campaign context across security surfaces.
RL-002RESEARCH

Multi-agent prompt propagation

Inert malicious instructions attempt to move between collaborating mock agents.

Goal: permissions and policy must be rechecked at every hop.
Tdetect

Time to first detection

Tcorrelate

Time to campaign linkage

Tdecide

Time to defensive decision

Tcontain

Time to effective containment

Trecover

Time to verified recovery

LAB

Attack Lab scenarios use isolated systems, synthetic identities/data, inert fixtures and controlled event generators. Scenario design distinguishes blocked, detected, contained, recovered and missed outcomes rather than reducing security to a single block flag.

VALIDATED BUILD QUALITY

Security software must survive its own validation.

Build validation and Attack Lab evidence are shown separately. Neither is presented as proof that any security product can prevent every possible attack.

PHP source validation 61 / 61 files pass syntax validation
Focused regression harness PASS current beta validation
Bootstrap audit PASS current beta validation
Final package re-check PASS re-extraction + lint

PLATFORM COMPATIBILITY

Built for current WordPress environments.

The current product metadata targets modern WordPress installations and requires a contemporary PHP runtime.

Tested up toWordPress 7.0
RequiresPHP 8.1+
Current line2.0.1 beta
i

Static and focused regression checks are not substitutes for staging and production-runtime verification. Sentinel treats compatibility and security validation as separate gates.

SECURITY PRINCIPLES

Built to protect without hiding the limits.

The public site intentionally avoids publishing sensitive implementation details that could reduce the effectiveness of defensive controls.

01

Defense in depth

Multiple layers of protection instead of relying on one defensive control.

02

Fail safely

Security-sensitive actions should remain controlled when confidence or compatibility is insufficient.

03

Operator visibility

Make meaningful security state and events understandable without exposing unnecessary internals.

04

Compatibility matters

Protection is useful only if legitimate WordPress operation remains reliable.

FUTURE DIRECTION

Harder to bypass. Easier to operate.

1

Broaden validation

Expand staging and real-environment compatibility testing across more WordPress configurations.

2

Improve intelligence

Strengthen the quality and usefulness of security-relevant software and risk information.

3

Reduce noise

Improve prioritization so operators can focus on events that require action.

4

Harden recovery

Continue improving controlled remediation, recovery and operational resilience.

5

Expand integrations

Build broader reporting and operational interoperability without weakening security boundaries.

CONTACT NEVERLAST

Interested in Sentinel?

For evaluation, Free/Pro questions, security discussions, developer integration, deployment, partnerships or testing opportunities, contact the NeverLast Sentinel Security team directly at nss@neverlast.ro.

01 Evaluation

Discuss WordPress security requirements and product evaluation.

nss@neverlast.ro →
02 Testing

Explore compatibility, Attack Lab or controlled testing on different WordPress environments.

Contact testing team →