NEVERLAST SENTINEL SECURITY
Security that stays
alert.
A WordPress security suite built for site owners, administrators, agencies and developers — from essential baseline protection to advanced monitoring, testing, automation and incident response.
Protected high-risk operations can require a second authorization plane independent of the WordPress session.
EXTREME SECURITY · GUARDIAN
A stolen admin account does not have to mean a stolen site.
WordPress normally treats an authenticated administrator as highly trusted. Sentinel Extreme Security can add a second authorization boundary for selected high-risk operations, while Guardian maintains an integrity and recovery layer independent of ordinary WordPress administrator access.
WordPress administrator access is not the final authority for protected operations.
When an ESF policy is in Protect, selected critical operations can be refused even when the requester already has a valid WordPress administrator session. A short, scoped maintenance authorization is required for the protected task.
ADMIN ACCOUNT TAKEOVER CONTAINMENT
What changes when Guardian protection is active?
The attacker may possess a valid WordPress administrator cookie or credential.
A high-risk administrative, user, product, payment or plugin operation is requested.
WordPress authorization alone is insufficient when the selected protection is in Protect.
Without the required short-lived authorization window, the protected operation is denied.
Separate security identity
Extreme Security uses security credentials separate from the normal WordPress account, with optional additional authentication.
Independent Guardian integrity
Guardian keeps protected package and signed policy state separate from ordinary administrator access.
Short maintenance authorization
Critical changes can be opened only for a specific maintenance task and locked again immediately after completion.
Protected updates
Protected package updates are reviewed as explicit version transitions instead of silently trusting a normal update result.
Whole-package recovery
Recovery is designed around verified package state rather than opportunistically mixing files from different versions.
Offline break-glass recovery
A separately stored hard-copy recovery mechanism provides a local recovery path when online services are unavailable.
CREDENTIAL COMPROMISE RESPONSE
Emergency Login Kill Switch
Sentinel also includes emergency administrator-login containment designed for credential compromise: session destruction, temporary login freeze and a controlled recovery path using a separate emergency secret.
Guardian does not make a WordPress site invulnerable and cannot protect a server after an attacker gains unrestricted hosting, filesystem, database or infrastructure-level control. Its purpose is to make a compromised WordPress administrator identity insufficient for the high-risk operations explicitly placed behind the second authorization boundary.
PUBLIC CAPABILITY OVERVIEW
Defense across the WordPress security lifecycle.
Sentinel combines multiple defensive functions in one operational surface while keeping implementation details, detection logic and enforcement internals private.
Web protection
Helps inspect and control suspicious requests before they become application-level incidents.
Login & account security
Adds stronger authentication controls and safeguards around privileged access.
Integrity & malware scanning
Supports file integrity awareness, malware-oriented inspection and change visibility.
Vulnerability awareness
Helps identify known-risk software conditions and surface security-relevant update priorities.
Adaptive monitoring
Observes site behavior and security signals to improve operator awareness without exposing internal detection logic.
Mitigation & remediation
Provides controlled tools for temporary protection, quarantine, restore and incident handling.
Reports & audit visibility
Consolidates security events, operator context and reporting into a unified administrative experience.
Compatibility testing
Includes non-destructive checks intended to reduce the risk of breaking normal WordPress operation.
FREE PROTECTION · ADVANCED PRO SECURITY
Start protected. Go deeper when you need to.
Sentinel keeps essential protection available without a Pro licence. Pro adds deeper inspection, stronger identity controls, recurring security operations, vulnerability intelligence and controlled response.
Sentinel Free
Essential protections that remain available without a Pro entitlement.
Basic firewall filteringBaseline request protection for common high-confidence threats.
Login rate limitingHelps reduce repeated authentication abuse.
XML-RPC controlReduce unnecessary exposure when XML-RPC is not required.
Security headersBrowser-facing hardening for common web risks.
Basic security scanPractical security checks and prioritised findings.
Hardening checklistGuidance for safer WordPress configuration.
Activity logSecurity-relevant visibility directly inside WordPress.
Sentinel Security Pro
Deeper controls for business sites, WooCommerce, agencies, developers and security operators.
Advanced WAF protectionScored request inspection, stronger operating modes and narrow compatibility exclusions.
Malware signature scanningDeeper inspection for suspicious file patterns.
File integrity monitoringKnown-good baselines and change evidence.
2FA & recovery controlsEmail OTP, authenticator TOTP, backup codes, trusted devices and role enforcement.
Scheduled scansRecurring checks without manual initiation.
Vulnerability intelligenceLocal component/version matching against available vulnerability records.
Safe FuzzerBounded, non-destructive endpoint security testing for controlled environments.
Email alertsActionable notifications and delivery history.
Quarantine & remediationPreview, quarantine, restore and controlled permanent deletion.
Virtual patchesTemporary targeted protection while awaiting upstream fixes.
Signed protection updatesAuthenticated live rule updates for licensed installations.
Locked Pro pages explicitly distinguish not checked from clean. Free protection remains available independently from Pro entitlement state.
FROM SITE OWNER TO SECURITY ENGINEER
One product. Different levels of depth.
Sentinel is designed to be usable without specialist security knowledge, but it does not stop at a simplified dashboard. Administrators, agencies and developers can progressively move into deeper technical and automated workflows.
Tell me what matters.
Clear posture, important findings, safer defaults and explanations that do not assume security expertise.
- Dashboard security posture
- Guided onboarding
- Built-in Guide & Wiki
- Contextual tooltips
- Hardening checklist
- Readable findings
Give me safe operational control.
Staged deployment, compatibility testing, monitoring-first workflows and recoverable incident response.
- Monitor → Balanced → Strict workflow
- Compatibility Autopilot
- Scan coverage visibility
- 2FA commissioning guidance
- Quarantine before deletion
- Session invalidation
Make security repeatable.
Structured reporting, exports, client-facing evidence and workflows for managed WordPress environments.
- Client-facing HTML reports
- CSV / JSON-oriented exports
- Audit-friendly event history
- Compatibility testing
- Scheduled scans
- Multi-channel alerting
Expose automation, not just buttons.
Developer-facing surfaces support repeatable administration, integration and machine-readable security evidence.
- WP-CLI support
- REST API support
NLSSP_Logger::log()NLSSP_Alerts::notify()- Scheduled maintenance hooks
- Scheduled scan hooks
ATTACK SIMULATION EVIDENCE
Tested under bounded hostile traffic.
The recorded physical Attack Lab figures below belong to the 1.9.15 laboratory evidence set from 5 August 2026. The current 2.0.1 beta line contains later security and Guardian work, so these numbers are retained as historical measured evidence — not presented as a complete validation statement for every later build.
requests completed and refused
0 server errors · 0 network errors
Authentication pressure
20 / 20 completed with no server or network errors. Sentinel recorded rate-limit engagement while both isolated control requests passed.
WAF barrage
18 / 18 hostile probes blocked while 2 / 2 legitimate controls were allowed.
Scanner storm
18 / 18 scanner probes refused with no 5xx response in the recorded isolated run.
Mixed siege · heavy
375 / 375 requests refused across scanner, WAF and authentication traffic.
Later builds added and hardened Extreme Security / Guardian workflows, administrator protection, signed intelligence, compatibility logic, protected updates and operational controls. The current build line is validated separately from the historical 5 August performance run.
AI / AGENTIC ATTACK LAB
Security testing for attackers that adapt.
These are defensive scenarios in the Sentinel Attack Lab catalog. They are shown as validation scenarios, not recorded PASS results unless a bound execution report exists.
AI-orchestrated espionage
Multi-stage agentic activity that changes identities, paths and tactics while progressing from reconnaissance toward impact.
Goal: correlate a campaign instead of treating every request independently.Autonomous vulnerability enumeration
An adaptive synthetic adversary abandons blocked options and immediately explores alternatives.
Goal: detect speed, breadth, transitions and adaptive pivoting.AI-assisted unknown attack behavior
Previously unseen synthetic behavior changes form between runs while preserving the same harmless consequence.
Goal: avoid depending exclusively on known vulnerability signatures.Indirect prompt injection
Untrusted web or log content attempts to influence a mock administrative AI component.
Pass target: zero unauthorized tool execution and zero privileged data disclosure.Eight-agent adaptive WordPress campaign
Eight synthetic specialist agents coordinate reconnaissance, identity, alternate-path and persistence-like simulation.
Goal: containment before synthetic impact with auditable recovery.Fleet intelligence poisoning
A synthetic tenant floods low-quality attack-like signals attempting to create a harmful shared defensive conclusion.
Goal: frequency alone must never create trusted fleet-wide intelligence.Autonomous multi-agent chain
Cross-surface state sharing between synthetic web, identity, host and cloud events.
Goal: preserve campaign context across security surfaces.Multi-agent prompt propagation
Inert malicious instructions attempt to move between collaborating mock agents.
Goal: permissions and policy must be rechecked at every hop.Time to first detection
Time to campaign linkage
Time to defensive decision
Time to effective containment
Time to verified recovery
Attack Lab scenarios use isolated systems, synthetic identities/data, inert fixtures and controlled event generators. Scenario design distinguishes blocked, detected, contained, recovered and missed outcomes rather than reducing security to a single block flag.
VALIDATED BUILD QUALITY
Security software must survive its own validation.
Build validation and Attack Lab evidence are shown separately. Neither is presented as proof that any security product can prevent every possible attack.
PLATFORM COMPATIBILITY
Built for current WordPress environments.
The current product metadata targets modern WordPress installations and requires a contemporary PHP runtime.
Static and focused regression checks are not substitutes for staging and production-runtime verification. Sentinel treats compatibility and security validation as separate gates.
SECURITY PRINCIPLES
Built to protect without hiding the limits.
The public site intentionally avoids publishing sensitive implementation details that could reduce the effectiveness of defensive controls.
Defense in depth
Multiple layers of protection instead of relying on one defensive control.
Fail safely
Security-sensitive actions should remain controlled when confidence or compatibility is insufficient.
Operator visibility
Make meaningful security state and events understandable without exposing unnecessary internals.
Compatibility matters
Protection is useful only if legitimate WordPress operation remains reliable.
FUTURE DIRECTION
Harder to bypass. Easier to operate.
Broaden validation
Expand staging and real-environment compatibility testing across more WordPress configurations.
Improve intelligence
Strengthen the quality and usefulness of security-relevant software and risk information.
Reduce noise
Improve prioritization so operators can focus on events that require action.
Harden recovery
Continue improving controlled remediation, recovery and operational resilience.
Expand integrations
Build broader reporting and operational interoperability without weakening security boundaries.
CONTACT NEVERLAST
Interested in Sentinel?
For evaluation, Free/Pro questions, security discussions, developer integration, deployment, partnerships or testing opportunities, contact the NeverLast Sentinel Security team directly at nss@neverlast.ro.
Discuss WordPress security requirements and product evaluation.
nss@neverlast.ro →Explore compatibility, Attack Lab or controlled testing on different WordPress environments.
Contact testing team →Discuss hosting, managed-service or technical collaboration opportunities.
Start a conversation →