Support
Log in Sign up

Hardening score and the public badge (Free)

What it does: Scores the installation out of a hundred from twenty-one checks of the site itself, and lists every one with what it is worth, what that weight defends against, and a link to the screen that changes it. How to access: GuardForge > Hardening score. Recomputed when settings change, once a day by cron, and on demand. Free/PRO: Free. With Pro installed and licensed one more row joins the same list at the top weight — installed plugins and themes with a published advisory — and the shares are worked out again around it. Without the add-on that row does not exist and nothing on the screen mentions it. Notes:
  • Every check reads this installation and the score makes no external request of any kind, which is also why it cannot verify a header by fetching the homepage. That promise is worth more than the extra check, and a unit test holds the score’s source to it.
  • A check that cannot apply — the two .htaccess checks on nginx — leaves the sum rather than scoring zero, and the remaining checks grow to fill the hundred, so a correctly configured nginx site can still reach 100.
  • Four weight buckets only (12 / 8 / 5 / 2). The whole table is published in readme.txt and a test compares it with the code, because a score nobody can audit is a score nobody should believe.
  • The score is recorded once a day and kept for a year.
  • The public badge is off until switched on. It publishes a letter grade and the month it was worked out, computed only from the eleven checks a stranger could already run against the site with curl. The numeric score, two-factor coverage, brute-force thresholds, integrity results, pending updates and vulnerable components are never published. The link carries a 32-hex token, can be reissued or revoked, logs nothing, is refused if the site’s host name no longer matches the one it was issued for, and does not exist as a route at all until it is switched on.
Forge AI Assistant Online

Hi! I'm the Guard Forge AI assistant. Ask me anything about the plugin — setup, features, troubleshooting, or development.

Just now
Powered by Forge AI · Browse docs