Nexura Docs

Documentation

Learn how to configure Nexura Security to protect your WordPress site from modern threats without slowing it down.

Getting Started

Nexura Security is built with a "Zero Configuration" philosophy. The moment you activate the plugin, your website is immediately secured against 90% of common automated attacks.

The Golden Rule: You do not need to be a security expert to use Nexura. Simply turn on the features you need, and our AI-driven systems will handle the backend complexity silently.

General Security

Disable File Execution

Why you need it: Attackers often look for vulnerable forms on your website to upload malicious files (like backdoors or shells). If they succeed, they can take full control of your site.

How it protects you: Turning this on puts a strict lock on your Uploads, Themes, and Plugins directories. Even if an attacker sneaks a malicious file onto your server, the server will completely refuse to execute it, rendering the attack useless.

Malware Scanner

Automated Deep Scanning

Why you need it: Malware can sit silently in your core files or database, redirecting your visitors or stealing data without you knowing.

How it protects you: Nexura continuously scans your files and database against millions of known malware signatures. If a file is modified illegally, the scanner will alert you immediately.

PRO Feature Pro users get background Scheduled Scanning (Daily/Weekly) and Automated Healing.

Edge Firewall (WAF)

Cloudflare Integration

Why you need it: Handling massive bot attacks directly on your web server consumes CPU and memory, which can crash your site (DDoS).

How it protects you: By linking your Cloudflare API, Nexura pushes security blocks directly to the "Edge" of the internet. Hackers are stopped by Cloudflare's massive servers before they even reach your website, ensuring your site remains lightning fast.

Geo-Blocking PRO

If you are receiving highly targeted attacks from specific regions where you do no business, you can use Geo-Blocking. Toggling a country will instantly drop all traffic from that region at the Firewall level.

Intrusion Detection (IDS)

Smart User Screening

Why you need it: Spammers love to create thousands of fake user accounts on WordPress sites to post spam or look for privileges.

How it protects you: The IDS system acts like a silent bouncer. When a new user registers, it analyzes their username and email patterns. If it looks like a bot (e.g., weird names with lots of numbers), the account is immediately locked in a "Pending" state. You can safely review or delete them from the IDS Approvals page.

Anti-Spam System

Invisible Bot Traps

Why you need it: Traditional CAPTCHAs annoy real human users.

How it protects you: Nexura uses invisible traps. If a form is submitted with "superhuman speed" or an invisible trap field is filled out by an automated script, the comment is rejected instantly. Furthermore, new commenters are strictly forbidden from posting external links.

Aggressive Spam Cleaner PRO

Why you need it: You might have thousands of pending spam comments sitting in your database from before you installed Nexura.

How it protects you: Turn this on in the settings, and Nexura runs a daily automated sweep in the background. It finds all unapproved comments containing shady links and permanently deletes them without touching real human comments. It keeps your database perfectly clean automatically.

Login Security (2FA)

Two-Factor Authentication

Why you need it: Passwords can be stolen, leaked, or guessed through automated brute-force attacks.

How it protects you: 2FA adds a mandatory second layer. Even if a hacker has your exact password, they cannot log into your dashboard without the time-sensitive code generated on your personal mobile device (via Google Authenticator or Authy).