Attackers find the fake door first.
DecoyNest plants convincing decoys across your site — a fake admin login, a fake vulnerable plugin file, a watched XML-RPC endpoint. Every probe is recorded. Nothing real is touched.
Free and open source · No account required · Works alongside your existing firewall
↖ Try the login form. It is a decoy — this is what it records.
Three steps, then it runs itself.
Activate
Decoys go live the moment you activate the plugin. No setup wizard, no API key, nothing to configure. Your real admin login is untouched.
Attackers take the bait
Bots probe the fake admin path, request readme files from plugins you do not have, and hammer XML-RPC. Real visitors never see any of it.
You read the evidence
Every probe is logged with source IP, request path, payload, and a classification. Export it, or stream it into your SIEM.
Ten modules. Most of them free.
The free tier is deliberately generous. Every install is a sensor, and a bigger sensor network makes detection better for everyone using it.
Honeypot sensors
FreeFake admin login, fake plugin files, and XML-RPC monitoring. Logged locally to your own database.
Two-factor auth
FreeTOTP with any authenticator app. Backup codes, per-role enforcement, and a grace period for rollout.
Single sign-on
FreeMicrosoft 365, Google Workspace, and GitHub. Verified identities only, scoped to your tenant, and it still goes through two-factor.
Firewall rules
FreeIP allow and block lists with CIDR, country blocking, login rate limiting, and REST API restrictions.
Vulnerability scanner
FreeChecks your core, plugin, and theme versions against known vulnerabilities. CSV export included.
Hardening score
FreeTwenty checks, one score, and a specific fix for each failure. No vague advice.
Audit log
FreeWho created that administrator, who changed the site URL, who edited a theme file — with IP and timestamp.
Security headers
FreeCSP with report-only mode, HSTS, frame options, and referrer policy. Applied through WordPress, not .htaccess.
Encrypted backup
ProScheduled database and file backups, encrypted before they leave the site. Stored locally or in your own Drive, OneDrive or Dropbox — never with us.
Microsoft Sentinel
ProStream honeypot events and audit entries straight into your Log Analytics workspace.
Your WordPress estate, in the console you already watch.
No other WordPress security plugin writes to Microsoft Sentinel. DecoyNest sends events through the Azure Monitor Logs Ingestion API into a custom table, so WordPress attacks correlate with your identity and network telemetry instead of sitting in a separate dashboard nobody opens.
- Custom DecoyNestEvents_CL table with a defined schema
- Service principal auth, scoped to a single data collection rule
- Sample analytics rules and a workbook to start from
- CEF and Syslog export for Splunk, QRadar, and others
// Brute force against WordPress decoys DecoyNestEvents_CL | where TimeGenerated > ago(1h) | where AttackCategory == "brute_force" | summarize Attempts = count() by SourceIPAddress, SiteUrl, bin(TimeGenerated, 5m) | where Attempts > 10 | project TimeGenerated, SourceIPAddress, SiteUrl, Attempts
What this is, and what it is not.
It does
- Detect and record attack attempts through decoys
- Harden the parts of WordPress that are commonly left open
- Add modern authentication your organisation already uses
- Hand the evidence to your SIEM in a usable shape
It does not
- Claim to block every attack — no plugin can
- Replace a WAF at the edge, if you run one
- Load third-party scripts or send your content anywhere
- Share any data unless you explicitly opt in
Find out what is already knocking.
Most sites are probed within hours of going live. Install DecoyNest and read the log for a week — the results are usually surprising.