Blueternal BOLT Security Toolkit
by jfgamsby 0 (0 reviews)

Blueternal BOLT Security Toolkit

WordPress and hosting security scanner with plain-English findings, safe hardening actions, reports, and Pro AI summaries.

Blueternal BOLT Security Toolkit ranks #61,028 among WordPress.org plugins with 0+ active installations, is #3,514 of 4,596 in the Security category, and was last updated May 17, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 6.9.9 (Current: 7.1.2)
v0.6.9 Current Version v0.6.9
Updated 4 months ago Last Update on 17 May, 2026
Refreshed 7 hours ago Last Refreshed on
#3,514 of 4,596 in Security
View on WordPress.org
Rank
#61,028
No change
Active Installs
0+
No change
KW Avg Position
163
33 worse
Downloads
222
+1 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 10

Total Progress 10%
0+ 10+
41,288
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 10+

Rank Changes

47,195 53,296 59,397 65,498 71,599 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
47,195 53,296 59,397 65,498 71,599 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #61,028
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Blueternal BOLT Security Toolkit

No. BOLT works entirely through PHP and the WordPress filesystem API — the same permissions your site already runs under.
No. BOLT can detect many server and WordPress security issues, automate some changes that are reachable from plugin context, and guide the rest. It cannot honestly replace root or sudo from inside WordPress. Some fixes are always one-click, some are host-dependent, some are manual only, and some would require a future companion agent or external integration.
The free tier covers 31 checks across PHP and database versions, PHP resource limits, local PHP override effectiveness, OPcache, dangerous PHP functions, directory listing, loopback request health, WP-Cron health, uploads permissions and executable files, WP_DEBUG, wp-config.php permissions, DISALLOW_FILE_EDIT, database prefix, XML-RPC, REST API, application passwords, user registration, default admin username, administrator account sprawl, debug log exposure, readme file exposure, public backup or dump artifact exposure, HTTPS, HSTS, and core/plugin/theme update status. Pro adds server-side domain/IP reputation scanning, WordPress core file integrity monitoring, suspicious PHP malware-pattern detection, and vulnerability intelligence for WordPress core, plugins, and themes. Free displays vulnerability status and CVE IDs when advisory findings are present; Pro shows the full advisory detail.
BOLT separates chained risk into three layers. Attack Paths are realistic compromise chains where multiple findings combine into a practical risk. Near Misses are partial chains where one important condition exists, but another required condition is missing. Amplifiers are findings that do not create an attack path by themselves, but increase the impact of a real path. For example, writable wp-config.php is not treated as remote compromise by itself. Alone, it appears as a near miss because it could support persistence if a write-capable foothold appears later. Combined with a real write-capable compromise path, it appears as a persistence amplifier.
BOLT Pro can verify WordPress core files against official checksum data and detect unexpected files inside wp-admin and wp-includes. If the checksum service is temporarily unavailable, the integrity checks fall back to a warning instead of failing the whole scan.
BOLT Pro can scan PHP files in plugins, themes, mu-plugins, and uploads for suspicious combinations of malware-like patterns such as obfuscation, hidden iframe payloads, encoded blobs, and dangerous execution chains. The scan is heuristic and should be treated as an investigation starting point rather than definitive malware attribution.
BOLT Pro can query a configurable advisory feed and compare installed WordPress core, plugin, and theme versions against known affected version ranges. Successful responses are cached locally for 6 hours, and the last good cache is reused if the endpoint is temporarily unavailable.
Auto-fixes write the correct configuration change directly where WordPress has a safe capability path, such as wp-config.php, .htaccess, or an mu-plugin. BOLT logs fix metadata in the database, but it does not store backup copies of config or code files. Undo is available only for files BOLT creates itself, such as its XML-RPC and REST API mu-plugin files. Changes to existing files should be reviewed before applying and rolled back through your host backup or version control if needed. BOLT distinguishes between fixes that are verified immediately, fixes that are pending the next request, and fixes that are manual only on the current host. BOLT does not auto-write disable_functions; PHP treats that as system-level configuration that must be changed in php.ini, PHP-FPM pool config, LiteSpeed/PHP selector, or a hosting control panel. Uploads execution blocking is one-click only when the current stack is Apache/LiteSpeed-style and can use an uploads .htaccess rule. REST API restriction uses an mu-plugin instead of a blanket web-server block so logged-in WordPress requests and detected routes selected in the allowlist manager can keep working. Developers can also extend the allowlist with bolt_rest_api_allowed_public_routes. Nginx/PHP-FPM and FastCGI-only stacks receive manual server-rule guidance where server rules are required.
BOLT does not store rollback copies of config files, code files, public artifacts, or executable uploads. It stores fix history metadata in the WordPress database and relies on your normal host backup, staging workflow, or version control for rollback of existing files.
Yes, when PDF attachment is enabled. Free reports use BOLT branding and one recipient. BOLT uses dompdf if WordPress already loads it; otherwise it attaches a built-in plain PDF report. BOLT Pro adds multiple recipients and custom report branding.

Sign In / Register

You need to sign in or register to use this feature.