{"id":318093,"date":"2026-06-01T12:41:17","date_gmt":"2026-06-01T12:41:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/simula-wordfence-grafana-integration\/"},"modified":"2026-08-05T22:54:30","modified_gmt":"2026-08-05T22:54:30","slug":"simula-security-telemetry-for-wordfence","status":"publish","type":"plugin","link":"https:\/\/azb.wordpress.org\/plugins\/simula-security-telemetry-for-wordfence\/","author":20131485,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.1.2","stable_tag":"3.1.2","tested":"7.0.3","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Simula Security Telemetry for Wordfence","header_author":"Simula","header_description":"Export metrics and incidents from WordPress and Wordfence into a node_exporter textfile collector .prom file, and .log file","assets_banners_color":"","last_updated":"2026-08-05 22:54:30","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/simulalab.org","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/simula-security-telemetry-for-wordfence","header_author_uri":"https:\/\/simulalab.org","rating":0,"author_block_rating":0,"active_installs":50,"downloads":419,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.2.2":{"tag":"2.2.2","author":"simulalab","date":"2026-06-01 14:22:33"},"2.3.3":{"tag":"2.3.3","author":"simulalab","date":"2026-07-07 19:36:18"},"3.0.0":{"tag":"3.0.0","author":"simulalab","date":"2026-07-27 18:01:30"},"3.1.2":{"tag":"3.1.2","author":"simulalab","date":"2026-08-05 22:54:30"}},"upgrade_notice":{"3.1.2":"<p>Uses Wordfence&#039;s wfLogins table for failed-login and username brute-force windows when available, preserving older hit\/live-traffic fallback behavior.<\/p>","3.1.0":"<p>Adds Wordfence Firewall Summary-compatible aggregate block metrics and explicit blocked_hit_rows aliases. Existing blocked_events metrics remain available but are now documented as deprecated hit\/live-traffic row aliases, not Wordfence Firewall Summary totals.<\/p>","2.3.3":"<p>Improves scan finding classification so malware counts follow Wordfence issue types more closely, avoids false positives from descriptive text, and makes stale exports easier to diagnose.<\/p>","2.2.2":"<p>Fixes incident log event timestamps, adds incident log levels and instance_name dashboard filtering, and renames the plugin storage prefix from <code>wfne<\/code> to <code>sstfw<\/code>. The WP-CLI command is now <code>wp simula-security-telemetry<\/code>.<\/p>","2.1.0":"<p>Adds incident privacy controls for sensitive IP, URL, referer, user-agent, private\/internal IP, and retention-note handling.<\/p>","2.0.0":"<p>Adds ops-ready dashboard, alert, WP-CLI, JSON Lines incident, freshness, and posture capabilities while preserving the node_exporter textfile collection model.<\/p>","1.0.0":"<p>Adds configurable metric export coverage and optional blocked-incident log export for Wordfence operators.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.2.2","2.3.3","3.0.0","3.1.2"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Settings screen showing Prometheus metric controls, incident log settings, manual actions, and current exporter state."}},"plugin_section":[],"plugin_tags":[211254,3283,5603,600,14385],"plugin_category":[54],"plugin_contributors":[223827],"plugin_business_model":[],"class_list":["post-318093","plugin","type-plugin","status-publish","hentry","plugin_tags-grafana","plugin_tags-metrics","plugin_tags-monitoring","plugin_tags-security","plugin_tags-wordfence","plugin_category-security-and-spam-protection","plugin_contributors-simulalab","plugin_committers-simulalab"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/simula-security-telemetry-for-wordfence.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Simula Security Telemetry for Wordfence exports Wordfence security telemetry in two forms:<\/p>\n\n<ul>\n<li>Prometheus metrics for the node_exporter textfile collector that can be scraped by Prometheus<\/li>\n<li>A local incident log containing blocked Wordfence requests that can be shipped with Grafana-Alloy<\/li>\n<\/ul>\n\n<p>This plugin is intended for WordPress sites that already use Wordfence and Prometheus-based infrastructure. Instead of exposing a public metrics endpoint from WordPress, the plugin writes local files that node_exporter and log-based tooling can consume.<\/p>\n\n<p>By default, the plugin runs a fast collector every 15 minutes and a slow collector hourly using WP-Cron. It supports:<\/p>\n\n<ul>\n<li>Exporter health and plugin metadata metrics<\/li>\n<li>Configurable cron interval<\/li>\n<li>Separate fast and slow collector intervals<\/li>\n<li>Per-metric-family enable or disable controls<\/li>\n<li>Wordfence Firewall Summary-compatible aggregate block counts<\/li>\n<li>Blocked hit-row counters and recent activity windows<\/li>\n<li>Blocked event counts by HTTP status code over the last 24 hours<\/li>\n<li>Failed login, rate-limited, and brute-force activity windows<\/li>\n<li>Current lockout counts for IPs and users<\/li>\n<li>Wordfence two-factor status and protected user counts<\/li>\n<li>Scan issue counts by severity<\/li>\n<li>Malware, file change, and vulnerable component findings<\/li>\n<li>Top blocked attack sources by country and normalized IP range<\/li>\n<li>Incident log export for newly observed blocked requests<\/li>\n<li>Incident privacy controls for IPs, URLs, referers, user agents, and internal traffic<\/li>\n<li>Manual export and incident cursor reset from the admin UI<\/li>\n<li>Current exporter and incident state visibility in the admin UI<\/li>\n<li>Optional JSON Lines incident output<\/li>\n<li>WP-CLI exports for system cron<\/li>\n<li>Source freshness and WordPress\/Wordfence posture metrics<\/li>\n<li>A ready-to-import Grafana dashboard and sample Prometheus alert rules<\/li>\n<\/ul>\n\n<p>Simula exposes two distinct Wordfence blocking measurements. blocked_hit_rows_* counts retained hit\/live-traffic records matching a blocked-request predicate. firewall_blocks_* reports Wordfence's aggregate Firewall Summary counts by category. The values are not expected to be equal because they have different sources, units, retention behavior, and categorization.<\/p>\n\n<p>The legacy blocked_events_* names are deprecated aliases for the hit\/live-traffic row model. They are still emitted for compatibility, but they must not be treated as the Wordfence Firewall Summary \"Attacks Blocked\" statistic.<\/p>\n\n<p>Blocked hit rows are currently identified from the Wordfence hits table where:<\/p>\n\n<ul>\n<li>action matches blocked:*<\/li>\n<li>or the HTTP status code is 403 or 503<\/li>\n<\/ul>\n\n<p>The plugin includes an admin settings screen under Settings &gt; Security Telemetry, where you can:<\/p>\n\n<ul>\n<li>Enable or disable the exporter master switch<\/li>\n<li>Choose the export cron interval<\/li>\n<li>Choose the slow collector interval<\/li>\n<li>Set the .prom output path<\/li>\n<li>Set a custom metric prefix<\/li>\n<li>Set a custom site label<\/li>\n<li>Enable or disable individual metric families<\/li>\n<li>Enable or disable incident log export<\/li>\n<li>Set the incident log path<\/li>\n<li>Choose text or JSON Lines incident output<\/li>\n<li>Limit the number of incidents appended per run<\/li>\n<li>Configure incident IP privacy and field-dropping filters<\/li>\n<li>Add an optional retention note to emitted incident events<\/li>\n<li>Trigger a manual export<\/li>\n<li>Reset the incident cursor for backfill<\/li>\n<li>Review current exporter and incident state<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to the \/wp-content\/plugins\/ directory, or install it using your preferred deployment process.<\/li>\n<li>Activate the plugin through the Plugins screen in WordPress.<\/li>\n<li>Go to Settings &gt; Security Telemetry.<\/li>\n<li>Set the Prometheus output file path. The default is \/var\/lib\/node_exporter\/textfile_collector\/wordfence.prom.<\/li>\n<li>Ensure the target directory already exists and is writable by the PHP process.<\/li>\n<li>If incident export is enabled, set the incident log path. The default is \/var\/log\/wordpress-wordfence-incidents.log.<\/li>\n<li>Ensure the incident log directory already exists and is writable by the PHP process.<\/li>\n<li>Ensure node_exporter is configured with the textfile collector and can read the generated .prom file.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20expose%20a%20public%20metrics%20endpoint%3F\"><h3>Does this plugin expose a public metrics endpoint?<\/h3><\/dt>\n<dd><p>No. It writes metrics to a local file for node_exporter to collect, and it can append blocked incidents to a local log file.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20require%20wordfence%3F\"><h3>Does this plugin require Wordfence?<\/h3><\/dt>\n<dd><p>Yes. The plugin reads Wordfence data from the WordPress database. If required Wordfence tables or columns are unavailable, the exporter writes failure-state metrics instead of silently doing nothing.<\/p><\/dd>\n<dt id=\"how%20often%20are%20metrics%20exported%3F\"><h3>How often are metrics exported?<\/h3><\/dt>\n<dd><p>The plugin schedules fast exports with WP-Cron. The default fast interval is every 15 minutes, and the admin UI also supports every 5 minutes, every 30 minutes, and hourly. Slow posture and scan metrics refresh hourly by default and can be set to hourly, twice daily, or daily. On low-traffic sites, WP-Cron may not run exactly on schedule unless you trigger WordPress cron processing through a system cron job or WP-CLI.<\/p><\/dd>\n<dt id=\"what%20metrics%20does%20the%20plugin%20export%3F\"><h3>What metrics does the plugin export?<\/h3><\/dt>\n<dd><p>With the default metric prefix of wordpress_wordfence, the plugin can export:<\/p>\n\n<ul>\n<li>wordpress_wordfence_export_success<\/li>\n<li>wordpress_wordfence_plugin_info<\/li>\n<li>wordpress_wordfence_last_export_timestamp_seconds<\/li>\n<li>wordpress_wordfence_next_export_timestamp_seconds<\/li>\n<li>wordpress_wordfence_next_slow_export_timestamp_seconds<\/li>\n<li>wordpress_wordfence_enabled<\/li>\n<li>wordpress_wordfence_error_info<\/li>\n<li>wordpress_wordfence_blocked_events_total<\/li>\n<li>wordpress_wordfence_blocked_events_window<\/li>\n<li>wordpress_wordfence_blocked_hit_rows_total<\/li>\n<li>wordpress_wordfence_blocked_hit_rows_window<\/li>\n<li>wordpress_wordfence_firewall_blocks_window<\/li>\n<li>wordpress_wordfence_firewall_blocks_available<\/li>\n<li>wordpress_wordfence_firewall_blocks_collection_success<\/li>\n<li>wordpress_wordfence_firewall_blocks_source_info<\/li>\n<li>wordpress_wordfence_firewall_blocks_latest_timestamp_seconds<\/li>\n<li>wordpress_wordfence_blocked_events_by_status_24h<\/li>\n<li>wordpress_wordfence_failed_login_attempts_window<\/li>\n<li>wordpress_wordfence_rate_limited_events_window<\/li>\n<li>wordpress_wordfence_brute_force_events_window<\/li>\n<li>wordpress_wordfence_top_attack_sources_24h<\/li>\n<li>wordpress_wordfence_locked_out_total<\/li>\n<li>wordpress_wordfence_two_factor_enabled<\/li>\n<li>wordpress_wordfence_two_factor_protected_users_total<\/li>\n<li>wordpress_wordfence_scan_issues_by_severity<\/li>\n<li>wordpress_wordfence_scan_findings_total<\/li>\n<li>wordpress_wordfence_vulnerability_findings_total<\/li>\n<li>wordpress_wordfence_latest_hit_timestamp_seconds<\/li>\n<li>wordpress_wordfence_latest_blocked_hit_timestamp_seconds<\/li>\n<li>wordpress_wordfence_latest_scan_timestamp_seconds<\/li>\n<li>wordpress_wordfence_scan_age_seconds<\/li>\n<li>wordpress_wordfence_installed<\/li>\n<li>wordpress_wordfence_version_info<\/li>\n<li>wordpress_wordfence_firewall_enabled<\/li>\n<li>wordpress_wordfence_firewall_optimized<\/li>\n<li>wordpress_wordfence_live_traffic_enabled<\/li>\n<li>wordpress_wordfence_scan_enabled<\/li>\n<li>wordpress_wordfence_license_type<\/li>\n<li>wordpress_wordfence_wordpress_version_info<\/li>\n<li>wordpress_wordfence_core_update_available<\/li>\n<li>wordpress_wordfence_plugin_update_available_total<\/li>\n<li>wordpress_wordfence_plugins_installed_total<\/li>\n<li>wordpress_wordfence_plugins_active_total<\/li>\n<li>wordpress_wordfence_plugins_inactive_total<\/li>\n<li>wordpress_wordfence_plugins_network_active_total<\/li>\n<li>wordpress_wordfence_plugin_inventory_info<\/li>\n<li>wordpress_wordfence_theme_update_available_total<\/li>\n<li>wordpress_wordfence_admin_users_total<\/li>\n<li>wordpress_wordfence_admin_users_without_2fa_total<\/li>\n<li>wordpress_wordfence_admin_user_info<\/li>\n<li>wordpress_wordfence_users_total<\/li>\n<li>wordpress_wordfence_users_created_window<\/li>\n<li>wordpress_wordfence_admin_users_created_window<\/li>\n<li>wordpress_wordfence_admin_users_modified_window<\/li>\n<li>wordpress_wordfence_roles_total<\/li>\n<li>wordpress_wordfence_role_capabilities_total<\/li>\n<li>wordpress_wordfence_unexpected_admin_capabilities_total<\/li>\n<li>wordpress_wordfence_users_can_register_enabled<\/li>\n<li>wordpress_wordfence_default_role_info<\/li>\n<li>wordpress_wordfence_file_edit_allowed<\/li>\n<li>wordpress_wordfence_file_mods_allowed<\/li>\n<li>wordpress_wordfence_debug_enabled<\/li>\n<li>wordpress_wordfence_debug_display_enabled<\/li>\n<li>wordpress_wordfence_xmlrpc_enabled<\/li>\n<li>wordpress_wordfence_rest_api_enabled<\/li>\n<li>wordpress_wordfence_search_engine_visibility_enabled<\/li>\n<li>wordpress_wordfence_home_url_info<\/li>\n<li>wordpress_wordfence_site_url_info<\/li>\n<li>wordpress_wordfence_plugins_added_window<\/li>\n<li>wordpress_wordfence_plugins_removed_window<\/li>\n<li>wordpress_wordfence_plugins_activated_window<\/li>\n<li>wordpress_wordfence_plugins_deactivated_window<\/li>\n<li>wordpress_wordfence_mu_plugins_total<\/li>\n<li>wordpress_wordfence_dropins_total<\/li>\n<li>wordpress_wordfence_active_theme_info<\/li>\n<li>wordpress_wordfence_themes_installed_total<\/li>\n<li>wordpress_wordfence_themes_update_available_total<\/li>\n<li>wordpress_wordfence_successful_logins_window<\/li>\n<li>wordpress_wordfence_password_resets_window<\/li>\n<li>wordpress_wordfence_user_email_changes_window<\/li>\n<li>wordpress_wordfence_application_passwords_total<\/li>\n<li>wordpress_wordfence_admin_application_passwords_total<\/li>\n<li>wordpress_wordfence_sessions_total<\/li>\n<li>wordpress_wordfence_cron_events_total<\/li>\n<li>wordpress_wordfence_cron_hooks_total<\/li>\n<li>wordpress_wordfence_cron_new_hooks_window<\/li>\n<li>wordpress_wordfence_cron_scheduled_events_total<\/li>\n<li>wordpress_wordfence_cron_suspicious_hooks_total<\/li>\n<li>wordpress_wordfence_options_total<\/li>\n<li>wordpress_wordfence_autoload_options_total<\/li>\n<li>wordpress_wordfence_autoload_options_bytes<\/li>\n<li>wordpress_wordfence_options_changed_window<\/li>\n<li>wordpress_wordfence_new_autoload_options_window<\/li>\n<li>wordpress_wordfence_sensitive_options_changed_window<\/li>\n<li>wordpress_wordfence_posts_modified_window<\/li>\n<li>wordpress_wordfence_pages_modified_window<\/li>\n<li>wordpress_wordfence_posts_with_script_tags_total<\/li>\n<li>wordpress_wordfence_posts_with_iframe_tags_total<\/li>\n<li>wordpress_wordfence_posts_with_suspicious_redirects_total<\/li>\n<li>wordpress_wordfence_recent_admin_post_edits_window<\/li>\n<li>wordpress_wordfence_upload_php_files_total<\/li>\n<li>wordpress_wordfence_upload_executable_files_total<\/li>\n<li>wordpress_wordfence_recent_upload_php_files_window<\/li>\n<li>wordpress_wordfence_plugin_files_modified_window<\/li>\n<li>wordpress_wordfence_theme_files_modified_window<\/li>\n<li>wordpress_wordfence_wp_content_recently_modified_files_total<\/li>\n<\/ul>\n\n<p>Each metric family can be enabled or disabled independently from the settings screen. Per-plugin inventory and per-admin inventory are disabled by default because plugin names, versions, active state, and administrator identities can expose sensitive operational details. Admin inventory uses hashed identity labels by default when enabled.<\/p>\n\n<p>blocked_events_total and blocked_events_window are deprecated ambiguous aliases for hit\/live-traffic row counts. blocked_hit_rows_total and blocked_hit_rows_window are the explicit names for that same low-level data model. firewall_blocks_window is the Wordfence Firewall Summary-compatible aggregate metric; it reads wfBlockedIPLog\/wfblockediplog with unixday, blockType, and SUM(blockCount), maps known block types to complex, brute_force, and blocklist, and bounds all other values to other. If the aggregate source is unavailable, the availability metric is 0 and category\/window series are omitted instead of fabricated.<\/p><\/dd>\n<dt id=\"what%20does%20the%20incident%20log%20export%20do%3F\"><h3>What does the incident log export do?<\/h3><\/dt>\n<dd><p>It appends newly observed blocked Wordfence hits to a local .log or .jsonl path. The default text format preserves the original plain-text log line. The JSON Lines format emits one structured JSON object per blocked event for Loki, ELK, OpenSearch, and similar tooling. The exported incident timestamp is taken from the Wordfence hit row, falling back across known timestamp columns before using export time. The exporter tracks the last processed hit ID, and you can reset the incident cursor from the admin UI or WP-CLI to backfill retained history up to the configured per-run limit.<\/p>\n\n<p>For Loki, configure your log collector to parse the text prefix or the JSON Lines timestamp field if you want Grafana to display the original Wordfence event time instead of the collector ingestion time.<\/p>\n\n<p>Incident privacy controls can keep full IPs, truncate IPv4 to \/24 and IPv6 to \/64, hash IPs with the site salt, drop IP fields, drop query strings from URL and referer fields, drop referers, drop user agents, skip private\/internal source IP ranges, and append an optional retention note to emitted events.<\/p><\/dd>\n<dt id=\"what%20wp-cli%20commands%20are%20available%3F\"><h3>What WP-CLI commands are available?<\/h3><\/dt>\n<dd><p>If WP-CLI is available, the plugin registers:<\/p>\n\n<ul>\n<li>wp simula-security-telemetry export<\/li>\n<li>wp simula-security-telemetry export --metrics-only<\/li>\n<li>wp simula-security-telemetry export --metrics-only --scope=fast<\/li>\n<li>wp simula-security-telemetry export --metrics-only --scope=slow<\/li>\n<li>wp simula-security-telemetry export --incidents-only<\/li>\n<li>wp simula-security-telemetry reset-cursor<\/li>\n<li>wp simula-security-telemetry status<\/li>\n<\/ul><\/dd>\n<dt id=\"does%20the%20project%20provide%20grafana%20and%20prometheus%20examples%3F\"><h3>Does the project provide Grafana and Prometheus examples?<\/h3><\/dt>\n<dd><p>Yes. The source repository provides repository-only examples under examples\/grafana\/ and examples\/prometheus\/. They are intentionally not included in the WordPress.org plugin zip. The dashboard includes exporter health, activity, scan posture, WordPress version, plugin posture, opt-in plugin inventory, opt-in admin inventory, administrator 2FA coverage, and incident logs. Inventory-based alert examples require the matching opt-in inventory metric to be enabled.<\/p><\/dd>\n<dt id=\"what%20permissions%20are%20required%3F\"><h3>What permissions are required?<\/h3><\/dt>\n<dd><p>The directory that will contain the .prom file must already exist and be writable by the PHP process running WordPress. If incident export is enabled, the incident log directory must also already exist and be writable by PHP. node_exporter must be able to read the resulting .prom file.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.1.2<\/h4>\n\n<ul>\n<li>Added Wordfence Firewall Summary-compatible aggregate block metrics by category and 24h, 7d, and 30d reporting window.<\/li>\n<li>Added explicit blocked_hit_rows aliases for the existing hit\/live-traffic row metrics while keeping blocked_events metrics for compatibility.<\/li>\n<li>Added Firewall Summary source availability, collection-success, source-info, and latest-bucket diagnostics.<\/li>\n<li>Updated admin and WP-CLI status output to distinguish hit-row metrics from aggregate Firewall Summary metrics.<\/li>\n<li>Updated Prometheus rules, Grafana dashboard examples, Docker fixtures, and documentation for source-model comparison and migration.<\/li>\n<li>Marked ambiguous blocked_events metric names as deprecated aliases in documentation.<\/li>\n<li>Count failed-login windows from Wordfence's wfLogins table when available, with the previous hit\/live-traffic text heuristic retained as a fallback.<\/li>\n<li>Count brute_force_events_window{vector=\"username\"} from failed wfLogins rows when available. The xmlrpc vector remains hit\/live-traffic based.<\/li>\n<li>Document rate-limited windows as retained hit\/live-traffic heuristics.<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>Split the plugin implementation into explicit include classes for configuration, settings, admin UI, WP-CLI, metrics rendering, Wordfence schema detection, collection, output, incidents, and utilities.<\/li>\n<li>Added disposable Docker test harnesses for local fixture, publisher integration, and release zip install validation.<\/li>\n<li>Added dependency-free PHP unit tests, bootstrap smoke checks, Prometheus output validators, and coverage tooling for environments with Xdebug or PCOV.<\/li>\n<li>Added WordPress core version metadata through wordpress_wordfence_wordpress_version_info.<\/li>\n<li>Added installed plugin aggregate metrics for installed, active, inactive, and network-active plugin totals.<\/li>\n<li>Added opt-in per-plugin inventory metrics with plugin file, name, version, active state, and update availability labels.<\/li>\n<li>Added opt-in administrator inventory metrics with hashed identity labels by default and per-admin Wordfence two-factor status.<\/li>\n<li>Added WordPress settings, role\/user, plugin\/theme drift, account event, cron\/option persistence, content injection, and uploads\/file IoC metric families.<\/li>\n<li>Added administrator identity label modes for hashed, ID-only, and counts-only operation.<\/li>\n<li>Updated WP-CLI and admin status output to show plugin inventory, admin inventory, and admin identity mode settings.<\/li>\n<li>Updated Grafana dashboard and Prometheus alert examples for WordPress version, plugin posture, plugin inventory, admin inventory, core updates, plugin updates, inactive Wordfence inventory, and administrator 2FA coverage.<\/li>\n<li>Added release asset validation for README\/readme metric coverage, Grafana JSON, and Prometheus alert examples.<\/li>\n<li>Updated the Docker smoke test to install and activate the current official Wordfence plugin before activating this plugin.<\/li>\n<li>Updated documentation for the new WordPress version, plugin inventory, and administrator inventory metric families.<\/li>\n<\/ul>\n\n<h4>2.3.3<\/h4>\n\n<ul>\n<li>Added clearer stale-export diagnostics through next scheduled fast and slow export timestamps plus richer admin and WP-CLI freshness status output.<\/li>\n<li>Fixed scan finding classification so malware counts prefer structured Wordfence issue types instead of broad message text matches.<\/li>\n<li>Reduced false malware positives for non-malware scan issues such as skipped scan paths and unknown files.<\/li>\n<\/ul>\n\n<h4>2.2.2<\/h4>\n\n<ul>\n<li>Fixed incident log timestamps to prefer the original Wordfence hit timestamp over the export run time.<\/li>\n<li>Added bounded INFO, WARN, and CRITICAL levels to Wordfence incident log events.<\/li>\n<li>Added dashboard filtering by instance_name across metrics and incident logs.<\/li>\n<li>Renamed the plugin, admin page slug, option keys, cron hooks, and WP-CLI command to the Simula Security Telemetry naming.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Added incident privacy controls for IPs, URL and referer query strings, referers, user agents, private\/internal IP ranges, and retention notes.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Changed the default fast export interval to 15 minutes.<\/li>\n<li>Added a slow collector for scan, two-factor, WordPress posture, and Wordfence posture metrics.<\/li>\n<li>Added WP-CLI export, status, and incident cursor commands.<\/li>\n<li>Added optional JSON Lines incident output.<\/li>\n<li>Added source freshness, Wordfence posture, and WordPress posture metrics.<\/li>\n<li>Replaced unbounded error message labels with bounded error type labels.<\/li>\n<li>Added a Grafana dashboard and sample Prometheus alert rules.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Added configurable WP-Cron export intervals.<\/li>\n<li>Added per-metric-family enable and disable controls.<\/li>\n<li>Added incident log export for blocked Wordfence requests.<\/li>\n<li>Added incident cursor tracking and manual cursor reset for backfill.<\/li>\n<li>Added current exporter and incident state visibility in the admin UI.<\/li>\n<li>Added expanded Wordfence telemetry including failed logins, rate limiting, brute force activity, lockouts, two-factor coverage, scan findings, and top attack sources.<\/li>\n<\/ul>","raw_excerpt":"Export metrics from Wordfence into a node_exporter textfile collector .prom file and append incidents detected by wordfence to a local log file.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/318093","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=318093"}],"author":[{"embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/simulalab"}],"wp:attachment":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=318093"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=318093"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=318093"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=318093"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=318093"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=318093"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}