VMP Fence Security
Advanced WordPress security plugin with comprehensive malware scanner, vulnerability detection, and multi-layer protection system.
Plugin info
Maintenance & Compatibility
Maintenance score
Actively maintained • Last updated 62 days ago
Is VMP Fence Security abandoned?
Likely maintained (last update 62 days ago).
Compatibility
Similar & Alternatives
Explore plugins with similar tags, and compare key metrics like downloads, ratings, updates, support, and WP/PHP compatibility.
Description
COMPREHENSIVE WORDPRESS SECURITY SCANNER
VMP Fence Security provides protection for WordPress websites through an advanced multi-scanner architecture. Our plugin features 11 specialized security scanners that work together to detect malware, vulnerabilities, suspicious activities, and security threats.
VMP Fence Security includes malware detection, file integrity monitoring, vulnerability scanning, user security analysis, and comprehensive threat protection.
🛡️ MULTI-SCANNER SECURITY ARCHITECTURE
- Server State Scanner monitors server configuration and security settings
- File Changes Scanner detects unauthorized modifications to WordPress core, themes, and plugins
- User Security Scanner identifies suspicious user accounts, risky usernames, and admin enumeration
- Content Safety Scanner analyzes posts and comments for malicious content and URLs
- Public Files Scanner checks for exposed configuration files and sensitive data
- User Audit Scanner monitors user activities and permission changes
- Vulnerability Scanner identifies known security vulnerabilities in installed plugins and themes
- Malware Scanner detects malicious code, backdoors, and infected files
- Domain Blocklist Scanner checks against known malicious domains and reputation databases
- Spamvertising Scanner identifies spam content injection and SEO spam attacks
- IP Spam Scanner monitors for suspicious IP addresses and bot activity
🔍 MALWARE DETECTION & FILE SCANNING
- Advanced malware signatures with pattern-based detection for backdoors and trojans
- File integrity monitoring compares files against WordPress.org repository versions
- Binary file scanning detects malicious code in images and executables
- WordPress core verification ensures core files haven’t been tampered with
- Plugin and theme scanning identifies modified or infected extensions
- Unknown file detection flags suspicious files that don’t belong to WordPress
🚨 VULNERABILITY & THREAT DETECTION
- Plugin vulnerability scanning checks for known security issues in installed plugins
- Theme vulnerability detection identifies security flaws in active themes
- WordPress core vulnerabilities monitors for outdated WordPress installations
- Google Safe Browsing integration checks URLs against Google’s malware database
- Suspicious admin detection identifies potentially compromised administrator accounts
- Password security analysis detects weak or compromised passwords
⚙️ SCAN CONFIGURATION & MANAGEMENT
- Multiple scan types: Limited (quick), Standard (balanced), High Sensitivity (comprehensive), Custom (configurable)
- Scheduled scanning with flexible timing options (hourly, daily, weekly)
- Scan monitoring system with automatic recovery from interrupted scans
- Performance optimization with memory management and resource controls
- File exclusion patterns to customize scanning scope and reduce false positives
- Progress tracking with real-time status updates and detailed logging
📊 ADMIN INTERFACE & REPORTING
- Dashboard overview showing security status and recent scan results
- Detailed scan results with issue classification and remediation guidance
- Audit logging tracks all security events and user activities
- Scan result reporting with detailed security issue analysis and remediation guidance
- Activity logs accessible via “Show Log” and “See Full Log” interface buttons
- Issue management with options to ignore detected threats or repair infected files
🔧 ADVANCED FEATURES
- API integrations including Google Safe Browsing for URL reputation checking
- Background processing prevents timeouts during large site scans
- Resource management with configurable memory limits and execution timeouts
- IPv4/IPv6 support with option to force IPv4-only scanning
- Multi-site compatibility works with WordPress multisite installations
- Flexible configuration with comprehensive options and settings management
Privacy and Data Collection
VMP Fence respects your privacy and follows WordPress.org guidelines for external service usage. This plugin may collect and transmit data to external services for security analysis:
Google Safe Browsing API: When URL reputation checking is enabled, URLs found in your content, posts, comments, and uploaded files are sent to Google’s Safe Browsing service to check against databases of malicious websites, phishing sites, and malware distribution points. This helps protect your site from security threats.
Data sent to Google includes:
– URLs extracted from posts, pages, comments, and file content
– Website URLs being analyzed for reputation
– No personal information, user data, or site content is transmitted beyond the URLs themselves
Data NOT sent to Google:
– User personal information or login credentials
– Post content, comment text, or page content
– Database information or configuration details
– User behavior or analytics data
Your Privacy Rights:
– In the current version (1.0.0), Google Safe Browsing integration is enabled by default for security protection
– Future plugin updates will include user settings to disable external service usage
– No data is collected or stored by VMP Fence itself beyond standard WordPress security logs
Third-Party Privacy Policies:
– Google Safe Browsing API: https://developers.google.com/safe-browsing/v4/usage-limits
– Google Privacy Policy: https://policies.google.com/privacy
Data Retention:
VMP Fence caches URL reputation results locally for up to 1 hour to improve performance and reduce external API calls. These cached results are stored only on your server and are automatically purged.
Current Limitation:
In version 1.0.0, Google Safe Browsing integration is automatically enabled for URL scanning. Future versions will include user settings to control external service usage. If you prefer not to use external services, please contact the plugin developer or wait for the next update which will include privacy controls.
GitHub WordPress Repository (File Comparison/Diff Viewer)
Service Purpose:
VMP Fence connects to GitHub’s raw content service to download original WordPress core files for displaying file differences/comparisons in the admin interface.
Service URLs:
– Primary: https://raw.githubusercontent.com/WordPress/
– Fallback: https://core.svn.wordpress.org/
When This Service Is Called:
– Only when user clicks “View Differences” button on a scan result
– Used to show side-by-side comparison of current file vs original WordPress core file
– NOT called during regular scanning operations or automated processes
Data Sent to GitHub:
– WordPress version number (e.g., “6.8”)
– File path relative to WordPress root (e.g., “wp-admin/index.php”)
– HTTP User-Agent header: “VMPFence Security Scanner”
– NO personal data, user information, site content, or configuration details are sent
Data Received from GitHub:
– Original WordPress core file content for comparison and repair
– Public repository data only (no tracking or analytics)
Privacy Implications:
– GitHub may log standard web server access logs (IP address, user agent, timestamp)
– No authentication required – all accessed files are public WordPress core files
– No data is collected or stored by VMP Fence beyond the file content used for verification
Required:
– Optional feature – viewing file differences can be skipped
– Internet connection required only when viewing file comparisons
– Regular security scanning does not require this service
Third-Party Privacy Policy:
– GitHub Privacy Statement: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement
User Control:
– This feature is only activated when user manually clicks “View Differences” button
– No automatic background requests are made
– Users can review scan results without using this feature
Installation
Secure your website with VMP Fence in just a few steps:
- Install VMP Fence through the WordPress plugin directory or upload the ZIP file
- Activate VMP Fence through the ‘Plugins’ menu in WordPress
- Navigate to VMP Fence > Dashboard to access the security interface
- Configure your scan preferences using the scan configuration options
- Run your first security scan from VMP Fence > Scan
- Review and address any security issues found in the scan results
- Set up scheduled scans for ongoing automated protection
Frequently Asked Questions
VMP Fence detects a comprehensive range of security threats including malware, backdoors, trojans, suspicious file changes, plugin/theme vulnerabilities, compromised user accounts, spam content injection, malicious URLs, exposed configuration files, and various forms of code injection attacks.
VMP Fence uses 11 specialized scanners that each focus on specific security aspects. The Server State Scanner checks configuration, File Changes Scanner monitors file integrity, Malware Scanner detects malicious code, Vulnerability Scanner identifies security flaws, and so on. This modular approach provides comprehensive coverage while maintaining performance.
VMP Fence offers four scan types:
– Limited: Quick scan focusing on critical security checks and core files
– Standard: Balanced scan covering most security aspects with good performance
– High Sensitivity: Deep comprehensive scan with maximum threat detection
– Custom: Fully configurable scan where you can enable/disable individual scanner modules
VMP Fence focuses on detection and detailed reporting of security issues. While it identifies infected files and provides comprehensive analysis, VMP Fence offers repair options that you can execute manually for infected files. The plugin provides safe file restoration capabilities, but repairs require user confirmation to ensure complete and safe remediation.
VMP Fence integrates with Google’s Safe Browsing API to check URLs found in your content, posts, and comments against Google’s database of known malicious websites, phishing sites, and malware distribution points. This helps identify compromised content early.
No. VMP Fence is designed for optimal performance with background scanning, intelligent resource management, and optimized algorithms. Scans run independently without affecting your website’s front-end performance or user experience.
VMP Fence can scan PHP files, JavaScript, CSS, WordPress core files, theme files, plugin files, configuration files, and optionally binary files including images and executables for embedded threats.
VMP Fence includes a flexible scheduling system that can run automatic scans at specified intervals (daily, twice daily, weekdays, weekends, or custom schedules). The scan monitor system ensures scans complete successfully and can automatically recover from interrupted scans.
Yes. VMP Fence provides flexible exclusion options allowing you to exclude specific files, directories, or file patterns from scanning. This is useful for large media directories, custom code, or known safe files that might trigger false positives.
When security issues are detected, VMP Fence provides detailed reports with issue classification, severity ratings, affected files, and remediation recommendations. You can choose to ignore false positives, repair infected files, or take manual action based on the findings.
Yes. VMP Fence is fully compatible with WordPress multisite (network) installations and can scan all sites in your network while providing centralized management and reporting.
VMP Fence provides comprehensive security reporting and activity logging for all scan results and security events. The plugin tracks scan completion, threat discoveries, and security activities through detailed logs accessible via the admin interface.
Review feed
Screenshots

Security Dashboard with firewall status, scan status, and notifications overview

Comprehensive Scan Interface showing real-time scan progress and security statistics

Comprehensive Scan Interface showing completed scan results with details and appropriate actions.

Scan options including Scan Scheduling, Scan Type, General, Performance, Advanced scan options.
Changelog
1.0.0 – September 29, 2025
- Initial release of VMP Fence Security
- Implemented 11 specialized security scanner modules
- Added comprehensive malware detection with advanced pattern matching
- Integrated Google Safe Browsing API for URL reputation checking
- Created multi-scan type support (Limited, Standard, High Sensitivity, Custom)
- Implemented file integrity monitoring against WordPress.org repository
- Added vulnerability scanning for plugins, themes, and WordPress core
- Created user security analysis and suspicious admin detection
- Implemented content safety scanning for posts and comments
- Added public files scanner for exposed configuration detection
- Created scheduled scanning with automatic recovery system
- Implemented performance optimization and resource management
- Added comprehensive audit logging and security event tracking
- Created flexible file exclusion system for false positive management
- Added email notification system for security alerts and scan completion
- Implemented dashboard interface with detailed security reporting
- Created comprehensive configuration system with advanced options management