Watchdog Security Lite — Powered by Lumiverse Nexus

Watchdog Security Lite — Powered by Lumiverse Nexus

5/5 (1 ratings) 70 active installs Updated Sep 22, 2026
Watchdog Lite dashboard with Live Pulse and protection overview.

Watchdog Lite dashboard with Live Pulse and protection overview.

Watchdog Security Lite is the free WordPress security edition powered by Lumiverse Nexus.

It combines practical local protection with a fast, visual security dashboard designed to answer three simple questions:

  • What is happening on my website?
  • What is Watchdog protecting?
  • What may still need my attention?

Watchdog Lite is built with performance in mind. Heavy work is kept away from normal visitor requests wherever possible, and the dashboard avoids turning every unusual request into an attack claim.

Highlights

  • Exploit Shield Lite – blocks a conservative set of high-confidence exploit payloads using local and already-cached rules in the normal WordPress request path.
  • Traffic Shield Lite – conservative protection against suspicious request pressure, probes and selected XML-RPC abuse.
  • Login Guard – protects WordPress login from repeated failed attempts and obvious abuse.
  • Malware Scanner – local file scanning with change-aware coverage and MU-plugin support.
  • Database Threat Scan – bounded, incremental inspection of high-risk WordPress database content for high-confidence malicious code, redirects and persistence indicators.
  • Vulnerability Watch Lite – checks installed WordPress components against Nexus vulnerability intelligence.
  • Official File Integrity – compares WordPress core and supported WordPress.org components with trusted sources.
  • Safe Core Repair – manually restores verified WordPress core files with a protected restore point.
  • Security & Exposure Check – reviews local protection and highlights practical attack-surface items that may deserve attention.
  • Attack Stories – groups related protection events into readable activity sequences instead of repetitive log noise.
  • Watchdog Live Pulse – a real-data visual view of recent traffic, bots and protection activity.
  • Site Change Watch Lite – records important administrator, plugin, theme and risky file changes.
  • Optional administrator TOTP 2FA – authenticator-app protection with one-time recovery codes.
  • WooCommerce Bot Cart Guard Lite – helps stop obvious automation from creating unwanted cart or wishlist state.
  • Weekly Security Digest – optional weekly email with useful protection and security-health signals.
  • Nexus Threat Network Lite – optional shared security intelligence and contributor participation.

Exploit Shield Lite

Exploit Shield Lite blocks a compact, conservative set of high-confidence request payloads such as SQL injection, script injection, path traversal, dangerous PHP stream wrappers and executable upload attempts.

It runs inside the normal WordPress plugin lifecycle. It does not configure auto_prepend_file, and it does not make a remote decision call while serving a visitor request. Nexus PRO remains the earlier pre-WordPress protection tier through its Early WAF architecture.

Database Threat Scan

When enabled, scheduled malware scans also inspect bounded high-risk database content. Watchdog checks selected options plus rotating batches of posts and post metadata for high-confidence malicious code, hidden redirects, obfuscated JavaScript and persistence indicators.

Large content tables are scanned incrementally rather than swept in one expensive pass.

Security you can understand

Watchdog Lite does more than display raw logs.

Security & Exposure Check reviews practical configuration and attack-surface signals, while Attack Stories groups related Traffic Shield and Login Guard events into a readable sequence. The goal is to help site owners understand what Watchdog actually observed and what it actually restricted.

Watchdog does not invent attack events for visual effect.

WooCommerce-aware protection

WooCommerce stores receive cart, wishlist, checkout, AJAX, crawler and catalog traffic that should not all be treated the same way.

Watchdog Lite includes store-aware request protection and WooCommerce Bot Cart Guard Lite, which can neutralize supported cart and wishlist mutations from crawler-claimed or obvious automation while leaving public pages available.

Watchdog Lite and Nexus PRO

Watchdog Lite provides a strong free security foundation inside WordPress.

The dashboard also includes a Protection Horizon that shows where Lite protection ends and what Lumiverse Nexus PRO adds for sites that need more:

  • earlier request containment before WordPress fully processes eligible hostile pressure;
  • deception-based hostile activity observation;
  • adaptive defense that can learn from repeated hostile behavior;
  • richer investigation and recovery workflows;
  • distributed Nexus intelligence across connected sites;
  • Nexus Fleet for agency and multi-site operational visibility.

Learn more at Lumiverse Nexus PRO.

Nexus Threat Network Lite

Nexus Threat Network Lite is disabled by default.

When an administrator enables Threat Intelligence Lite, the site can receive compact shared security intelligence and contribute selected high-confidence security signals.

The participating site URL/domain is included with the authenticated contributor record so the Nexus Network operator can identify the connected installation. Selected verified security signals may include an attacking public IP address and limited security metadata needed for network intelligence.

Threat Network participation does not send passwords, cookies, form contents, customer/order data or page content.

Learn more at Nexus Threat Network.

External Services

Watchdog Security Lite performs routine file and enabled Database Threat scanning locally. Website files, database content and file contents are not uploaded for routine malware scanning.

Watchdog Lite may communicate with services under lumiversenexus.com for malware signatures, vulnerability intelligence and optional Nexus Threat Network functions.

When Threat Intelligence Lite is enabled, the participating site URL/domain is included with its authenticated contributor identity so the Nexus Network operator can identify the connected installation. Selected verified security signals may include an attacking public IP address plus limited security metadata. Aggregate telemetry contains security-event counts and contributor/site attribution, but does not include raw attacking IP addresses in telemetry buckets, request URLs, usernames, cookies, request bodies, passwords, page content, or WooCommerce customer/order data.

Service information: Lumiverse Nexus Privacy Notice and Terms of Service.