This is an info Alert.
xpay
  • Product
    • Become Agent-Ready
      • Merchants
        Agentic Commerce — list your store across ChatGPT, Gemini, Claude & Perplexity
      • Publishers
        Monetize your content when AI agents read, cite, or train on it
      • SaaS Companies
        Treat AI agents as first-class customers with agent-priced checkout
    • Monetize
      • Monetize MCP Server
        Charge per call on any MCP server in 2 minutes
      • Monetize AI Agents
        Turn n8n, Zapier, Activepieces workflows into revenue
  • Resources
    • xpay Ecosystem
      • xpay✦ Tools
        1,000+ pay-per-use tools for your AI agents
      • Agent-Ready SaaS Index
        25,481 SaaS scored on agent-buyability
      • SaaS Pricing Database
        Pricing pages indexed across 1,000+ categories
      • Shopify Apps Directory
        Every Shopify app, with its full review history
      • WooCommerce Plugins Directory
        Every WooCommerce plugin, scored on how well it is maintained
      • GitHub
        Open source repositories
    • Agent Building
      • Agent Frameworks
        AI frameworks for building multi-agent systems
      • x402 Integration
        AI frameworks with x402 payment integration
      • Networks
        Blockchain networks supporting x402
    • Company
      • About xpay✦
        Our mission, products, and protocols
      • Blog
        Latest insights and updates
      • Docs
        Complete xpay documentation
  • Pricing
  • Blog
  • Docs
Get Started
  1. xpay✦ Commerce

  2. Directory

  3. WooCommerce plugins

  4. Open24 Security

Open24 Security

Security hardening for WordPress and WooCommerce: lock down the REST API, protect the login, hide version info and add security headers.

10+ active installs
5.0
(1 ratings)
Free on WordPress.org
View on WordPress.orgSupport forum
Will this break my store?

What the WordPress.org registry says about keeping Open24 Security running.

WordPress compatibility
Tested to 7.0.5 — 1 branch behind 7.1
Tested against the WordPress branch in use today.
Last updated
1 month ago
Requires PHP
7.4
Your host must be running at least this version.
Requires WordPress
5.5
Contributors
1
A single maintainer. Worth knowing if the plugin is load-bearing for your store.

10+ active installsWordPress.org reports installs in bands, not exact counts.
Maintenance & trust

Scored on how Open24 Security is looked after — not on how many stores run it.

Well maintained
Not enough public feedback to put a confident number on this one. Little public feedback — score rests mostly on release activity. What we can see is below.

Maintenance
35 / 35
Updated 42 days ago.
WordPress compatibility
20 / 20
Tested to WP 7.0.5 (current).
Support responsiveness
Not enough data
Only 0 support thread(s) — not enough to judge.
Merchant satisfaction
10 / 15
5.0/5 across 1 rating(s).
Listing transparency
6 / 10
Provides: description, homepage
1 of 5 measures had too little evidence to score. They are left out of the total rather than counted as zero — otherwise a plugin would be marked down for being small rather than for being poorly kept.Measured 2026-09-20 from the WordPress.org plugin registry.
Ratings

5.0

1 rating
5★1
4★0
3★0
2★0
1★0
Every rating WordPress.org holds for this plugin, not a sample. Written reviews live in the plugin's WordPress.org reviews forum.

Open24 Security applies a set of well-known hardening measures to WordPress and WooCommerce sites from a single settings screen. Every option is off by default and can be switched on individually, so you decide exactly how much you want to restrict.

The plugin does not phone home, does not require an account and does not send any data to external services. The only outbound request it makes is to the official WordPress.org API, and only when you explicitly rotate your security keys.

Features

WordPress REST API

  • Hide the /wp-json/wp/v2/users endpoint
  • Require authentication on sensitive endpoints
  • Disable the /wp-json/ index

Login

  • Custom login URL (replace wp-login.php with your own slug)
  • Limit login attempts per IP address
  • Block common usernames such as admin or root
  • Hide error hints that reveal whether a username exists

Protocols

  • Disable XML-RPC
  • Block external access to wp-cron.php
  • Block user enumeration via ?author=N

Information disclosure

  • Hide the WordPress version from the generator meta tag and RSS feeds

HTTP security headers

  • X-Frame-Options, X-Content-Type-Options, Referrer-Policy
  • Permissions-Policy, X-XSS-Protection
  • Optional HSTS

WooCommerce

  • Reject anonymous requests to the /wc/v3/ and /wc/v2/ REST routes
  • Hide WooCommerce headers on the storefront

Tools

  • Log out all users: rotates the WordPress security keys and salts, which invalidates every session cookie and immediately signs out all logged-in users. Useful after a suspected compromise or when an employee leaves.
  • Change log: records which settings were changed and when.

Agency signature

  • Adds an Open24 signature in the document head so the site can be identified as maintained by the agency by crawlers such as BuiltWith. This can be turned off.

About the security keys feature

Rotating the WordPress security keys requires updating the corresponding constants in wp-config.php. The plugin does this through the official WP_Filesystem API, writes to a temporary file with restrictive permissions and then moves it over the original in a single atomic operation, preserving the original file permissions. No backup copy is left anywhere on the server, and if any step fails, wp-config.php is left untouched.

If wp-config.php is not writable, the feature reports it and makes no changes.

Will this break my site?

Every option is off by default. The ones that need the most care are the custom login URL and the REST API restrictions, because some themes and plugins rely on those endpoints. Enable them one at a time and check your site afterwards.

I enabled the custom login URL and now I am locked out. What do I do?

Rename or delete the open24-security folder in /wp-content/plugins/ over FTP or your hosting file manager. The plugin will be deactivated and wp-login.php will work again.

Does this plugin work without WooCommerce?

Yes. The WooCommerce options only appear when WooCommerce is active.

Does the plugin send data anywhere?

No. The only outbound request is to the official WordPress.org key generator API, and only when you choose to log out all users.

I am behind Cloudflare and every visitor looks like the same IP

Under Login, set “Visitor IP read from” to the header your proxy sets. The screen shows the IP the plugin currently sees for you, so you can confirm the setting is right. Leave it on the direct connection unless there really is a proxy in front of the site: those headers are sent by the client, so trusting them without a proxy lets an attacker send a different IP on every login attempt and never get locked out.

Why does logging out all users modify wp-config.php?

Because that is where WordPress stores the security keys and salts, as PHP constants. Changing them is what invalidates every session cookie. See the Description for details on how the file is written safely.

Categories
Accounts & CRMWorkflow automationSecurity & spam
Plugin details
Version1.1.1
Last updated2026-08-09 4:45am GMT
Added2026-08-03
Requires WordPress5.5
Tested up to7.0.5
Requires PHP7.4

Tags on WordPress.org
hardening
login
rest-api
security
woocommerce
Alternatives
Other plugins in the same categories.
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
30K+ installs
4.3(152)
Login & Register Customizer – Forms, Popup, Profile & WooCommerce
40K+ installs
4.8(254)
Object Data Sync for Salesforce Integration with WP, Woo, Gravity, WPForms, Ninja, CF7 & more
100+ installs
4.9(22)
Add Customer for WooCommerce
1K+ installs
5.0(12)
Sky Login Redirect
2K+ installs
4.7(24)
OTP Login & Register Woocommerce
1K+ installs
4.6(44)
xpay

The agent-readiness stack for the AI shopping era — helping merchants, publishers and SaaS companies get discovered, cited and transacted with by ChatGPT, Perplexity, Claude, Gemini and the custom shopping agents underneath them.

CompanyAgentically Inc. (d/b/a xpay✦)1875 Mission St, Ste 103San Francisco, CA 94103, United Stateslegal@xpay.sh · privacy@xpay.sh
or ask your AI app
Company
About xpayAgency PartnersGitHubDiscordllms.txt
DevelopersDocumentationAPI ReferenceSDKs & LibrariesQuickstart GuideOpenAPI Spec
Stay Updated
Occasional product updates and agent-readiness playbooks from xpay (Agentically Inc.) — typically a couple of emails a month. Double opt-in: we email you a link to confirm before sending anything, and every email has one-click unsubscribe.
Social
  • For Publishers
    • News
    • Finance
    • Dev / Tech
    • Travel
    • View all verticals
  • Agent-Ready Index
    • SaaS Pricing Database
    • Agent-Ready SaaS Index
    • Verified band
    • AI & ML
    • Sales & CRM
  • Products
    • Pricing Widget
    • Monetize MCP Server
    • Paywall
    • Smart Proxy
    • Monetize AI Agents
    • xpay x402 Facilitator
  • Agentic Economy
    • Timeline
    • Resources
    • Manifesto
    • Stack
  • Agentic Commerce
    • Get listed
    • ChatGPT Ads
    • How ChatGPT Ads work
    • ChatGPT Ads · Apparel
    • ChatGPT Ads · Health & Beauty
    • xpay Listings · Amazon + Google
    • Pricing
    • Free audit
    • Shopify
    • WooCommerce
    • Apparel & Accessories
    • Health & Beauty
    • Overview
  • Commerce Index
    • Shopify apps directory
    • Agentic Commerce Ready Index
    • Methodology
    • Pet brands · WooCommerce
    • Pet brands · Shopify
  • Marketplace
    • 🛍️ xpay.deals — agentic storefront for deals
  • Protocols
    • Overview
    • x402
    • MPP
    • UCP
    • ACP
    • AP2
    • TAP
    • A2A
  • Agent Frameworks
    • Overview
    • LangChain
    • CrewAI
    • Claude MCP
    • AutoGPT
    • LangChain vs Mastra
    • LangGraph vs Pydantic AI
  • Company
    • About xpay
    • Blog
    • Docs
    • GitHub
  • Free prompts
    • Ecommerce prompts
    • Email marketing prompts
    • Product description prompts
    • Facebook ad prompts
    • Skincare prompts
    • Supplement prompts
    • Wine prompts
    • Electronics prompts

© 2025 Agentically Inc. All rights reserved.
Privacy PolicyTerms of UseAcceptable Use Policy