Assist Security
Assist Security
Description
WordPress signs every login cookie and nonce with eight secret keys and salts stored in wp-config.php (AUTH_KEY through NONCE_SALT). If those secrets leak — through an old backup, a stolen config file, or a contractor who still has access — an attacker can forge valid authentication cookies for as long as the keys stay unchanged. Rotating them invalidates every existing session immediately.
Assist Security makes that rotation safe, automatic, and auditable.
🔑 Rotate Security Keys
- One-click rotation from a clean, colorful settings screen
- Locally generated keys using PHP’s cryptographically secure random number generator. No calls to any external API, no network dependency
- Verified atomic writes. The new configuration is built in memory, written to a temporary file with restricted permissions, verified, atomically swapped in, then verified again — with automatic rollback if any step fails. The writer refuses to touch your file unless all eight keys are found, so a partial rotation is impossible
- Key health checks for missing, weak, duplicated, or placeholder keys. Only the verdict is ever shown; your key values never leave the server
- Audit log recording every attempt: timestamp, result, trigger, user, optional IP, duration, and how many sessions were signed out — with filtering, pagination, and CSV export
- Failure alerts emailed to the site administrator if a rotation ever fails
- Site Health test that flags key problems and keys older than 180 days
- WP-CLI commands —
wp assist-security rotateandwp assist-security status - Custom config locations supported:
wp-salt.php, awp-config.phpabove the web root, or any path you choose with a filter
Built the right way
- Beautiful, responsive settings screen with no page reloads and no build step
- REST API under
assist-security/v1; no admin-ajax - No bundled SDKs, no Composer dependencies, no external HTTP requests, no telemetry
- Every input sanitized, every output escaped, every query prepared
- Multisite aware: management is restricted to network administrators
- Privacy-conscious: IP logging is optional and data removal on uninstall is opt-in
- Settings import and export as JSON
- Fully translatable, with a bundled POT file
Assist Security is built on a module architecture, so further protections can be added as self-contained modules in future releases.
Installation
- Upload the
assist-securityfolder to/wp-content/plugins/, or install it through Plugins Add New. - Activate Assist Security from the Plugins screen.
- Open the new Assist Security menu in your admin sidebar.
- Check your key health on the Security Keys tab and rotate whenever you need to.
Note: rotating the keys signs out every user, including you. The plugin warns you first and sends you to the login screen afterwards.
For rotation to work, wp-config.php (or your custom salt file) must be writable by PHP. The Security Keys tab and Site Health both report this.
Faq
No. The writer refuses to modify your configuration file unless all eight keys are found, verifies the result before and after an atomic swap, and rolls back automatically if anything is wrong. If a rotation cannot complete safely, your original file is left untouched.
That is the point. Invalidating existing cookies is what makes rotation a security measure. Session tokens are cleared as well.
They are generated on your own server with PHP’s cryptographically secure random number generator. The plugin makes no external requests.
No. Key values are never displayed, logged, exported, or transmitted. The health check reads each constant only long enough to decide whether it is missing, weak, or duplicated, and reports that verdict alone.
Yes. The plugin checks wp-salt.php, wp-config.php, and the parent directory automatically. You can also point it anywhere:
add_filter( 'assist_security_config_file', function () { return '/path/to/wp-salt.php'; } );
Yes. On multisite, only network administrators (manage_network_options) can manage the plugin.
Every one to three months suits most sites. Rotate immediately if you suspect a leak, after removing an administrator, or after restoring from a backup of unknown origin. The Site Health test reminds you once your keys pass 180 days.
Settings in a single option, and rotation records in its own database table. IP addresses are recorded only if you enable that option. Everything is removed on uninstall only if you opt in first, on the Tools tab.
Reviews
Changelog
0.1
- Initial release.