Cerrojo Security Toolkit adds focused security diagnostics and reversible, opt-in controls under Tools > Cerrojo Security Toolkit.
Current tools include:
Controls are designed to be reviewed, enabled, verified, and reversed individually. Coverage depends on the WordPress hooks and serving paths described in each tool. Login throttling is best-effort, email delivery depends on the site’s mail transport, and headers must be verified at every cache, proxy, CDN, and origin edge.
Cerrojo Security Toolkit is not a web application firewall or malware scanner. It does not certify a site or guarantee complete protection. Use it as one layer in a broader security and recovery plan.
Saved settings remain until you change them. Deactivation stops the plugin’s runtime behavior but preserves its settings, metrics, and temporary state. The plugin currently provides no uninstall cleanup routine.