S
by SiMULA 0 (0 reviews)

Simula Security Telemetry for Wordfence

Export Wordfence-generated telemetry into a node_exporter textfile collector .prom file and append incidents detected by Wordfence to a local log file …

Simula Security Telemetry for Wordfence ranks #20,218 among WordPress.org plugins with 50+ active installations, is #1,551 of 4,566 in the Security category, and was last updated Aug 22, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.6 (Current: 7.1.2)
v3.2.3 Current Version v3.2.3
Updated 1 month ago Last Update on 22 Aug, 2026
Refreshed 8 hours ago Last Refreshed on
#1,551 of 4,566 in Security Top 50% by installs
View on WordPress.org
Rank
#20,218
No change
Active Installs
50+
+212.5%
KW Avg Position
68
45 worse
Downloads
720
+1 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 60

Total Progress 40%
50+ 60+
4,133
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 6 more installs to reach 60+

Rank Changes

19,929 20,087 20,246 20,405 20,563 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
19,929 20,087 20,246 20,405 20,563 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #20,218
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 20 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Simula Security Telemetry for Wordfence

No. It writes metrics to a local file for node_exporter to collect, and it can append blocked incidents to a local log file.
Yes. The plugin reads Wordfence data from the WordPress database. If required Wordfence tables or columns are unavailable, the exporter writes failure-state metrics instead of silently doing nothing.
The plugin schedules fast exports with WP-Cron. The default fast interval is every 15 minutes, and the admin UI also supports every 5 minutes, every 30 minutes, and hourly. Slow posture and scan metrics refresh hourly by default and can be set to hourly, twice daily, or daily. On low-traffic sites, WP-Cron may not run exactly on schedule unless you trigger WordPress cron processing through a system cron job or WP-CLI.
With the default metric prefix of wordpress_wordfence, the plugin can export: wordpress_wordfence_export_success wordpress_wordfence_plugin_info wordpress_wordfence_last_export_timestamp_seconds wordpress_wordfence_next_export_timestamp_seconds wordpress_wordfence_next_slow_export_timestamp_seconds wordpress_wordfence_enabled wordpress_wordfence_error_info wordpress_wordfence_blocked_events_total wordpress_wordfence_blocked_events_window wordpress_wordfence_blocked_hit_rows_total wordpress_wordfence_blocked_hit_rows_window wordpress_wordfence_firewall_blocks_window wordpress_wordfence_firewall_blocks_available wordpress_wordfence_firewall_blocks_collection_success wordpress_wordfence_firewall_blocks_source_info wordpress_wordfence_firewall_blocks_latest_timestamp_seconds wordpress_wordfence_blocked_events_by_status_24h wordpress_wordfence_failed_login_attempts_window wordpress_wordfence_authentication_failures_window wordpress_wordfence_rate_limited_events_window wordpress_wordfence_brute_force_events_window wordpress_wordfence_top_attack_sources_24h wordpress_wordfence_locked_out_total wordpress_wordfence_two_factor_enabled wordpress_wordfence_two_factor_protected_users_total wordpress_wordfence_passkey_enabled wordpress_wordfence_passkey_protected_users_total wordpress_wordfence_login_protected_users_total wordpress_wordfence_scan_issues_by_severity wordpress_wordfence_scan_findings_total wordpress_wordfence_vulnerability_findings_total wordpress_wordfence_latest_hit_timestamp_seconds wordpress_wordfence_latest_blocked_hit_timestamp_seconds wordpress_wordfence_latest_scan_timestamp_seconds wordpress_wordfence_scan_age_seconds wordpress_wordfence_scan_issue_update_age_seconds wordpress_wordfence_installed wordpress_wordfence_version_info wordpress_wordfence_firewall_enabled wordpress_wordfence_firewall_optimized wordpress_wordfence_live_traffic_enabled wordpress_wordfence_scan_enabled wordpress_wordfence_license_type wordpress_wordfence_wordpress_version_info wordpress_wordfence_core_update_available wordpress_wordfence_plugin_update_available_total wordpress_wordfence_plugins_installed_total wordpress_wordfence_plugins_active_total wordpress_wordfence_plugins_inactive_total wordpress_wordfence_plugins_network_active_total wordpress_wordfence_plugin_inventory_info wordpress_wordfence_theme_update_available_total wordpress_wordfence_admin_users_total wordpress_wordfence_admin_users_without_2fa_total wordpress_wordfence_admin_users_without_passkey_total wordpress_wordfence_admin_users_without_login_protection_total wordpress_wordfence_admin_user_info wordpress_wordfence_users_total wordpress_wordfence_users_created_window wordpress_wordfence_admin_users_created_window wordpress_wordfence_admin_users_modified_window wordpress_wordfence_roles_total wordpress_wordfence_role_capabilities_total wordpress_wordfence_unexpected_admin_capabilities_total wordpress_wordfence_users_can_register_enabled wordpress_wordfence_default_role_info wordpress_wordfence_file_edit_allowed wordpress_wordfence_file_mods_allowed wordpress_wordfence_debug_enabled wordpress_wordfence_debug_display_enabled wordpress_wordfence_xmlrpc_enabled wordpress_wordfence_rest_api_enabled wordpress_wordfence_search_engine_visibility_enabled wordpress_wordfence_home_url_info wordpress_wordfence_site_url_info wordpress_wordfence_plugins_added_window wordpress_wordfence_plugins_removed_window wordpress_wordfence_plugins_activated_window wordpress_wordfence_plugins_deactivated_window wordpress_wordfence_mu_plugins_total wordpress_wordfence_dropins_total wordpress_wordfence_active_theme_info wordpress_wordfence_themes_installed_total wordpress_wordfence_themes_update_available_total wordpress_wordfence_successful_logins_window wordpress_wordfence_password_resets_window wordpress_wordfence_user_email_changes_window wordpress_wordfence_application_passwords_total wordpress_wordfence_admin_application_passwords_total wordpress_wordfence_sessions_total wordpress_wordfence_cron_events_total wordpress_wordfence_cron_hooks_total wordpress_wordfence_cron_new_hooks_window wordpress_wordfence_cron_scheduled_events_total wordpress_wordfence_cron_suspicious_hooks_total wordpress_wordfence_options_total wordpress_wordfence_autoload_options_total wordpress_wordfence_autoload_options_bytes wordpress_wordfence_options_changed_window wordpress_wordfence_new_autoload_options_window wordpress_wordfence_sensitive_options_changed_window wordpress_wordfence_posts_modified_window wordpress_wordfence_pages_modified_window wordpress_wordfence_posts_with_script_tags_total wordpress_wordfence_posts_with_iframe_tags_total wordpress_wordfence_posts_with_suspicious_redirects_total wordpress_wordfence_recent_admin_post_edits_window wordpress_wordfence_upload_php_files_total wordpress_wordfence_upload_executable_files_total wordpress_wordfence_recent_upload_php_files_window wordpress_wordfence_plugin_files_modified_window wordpress_wordfence_theme_files_modified_window wordpress_wordfence_wp_content_recently_modified_files_total Each metric family can be enabled or disabled independently from the settings screen. Per-plugin inventory and per-admin inventory are disabled by default because plugin names, versions, active state, and administrator identities can expose sensitive operational details. Admin inventory uses hashed identity labels by default when enabled. blocked_events_total and blocked_events_window are deprecated ambiguous aliases for hit/live-traffic row counts. blocked_hit_rows_total and blocked_hit_rows_window are the explicit names for that same low-level data model. firewall_blocks_window derives aggregate firewall block counts from the locally stored wfBlockedIPLog/wfblockediplog table when the required fields are available. It uses locally available day-bucket, block-type, and block-count data, groups recognized block types into the bounded categories complex, brute_force, and blocklist, and groups all other values under other. This metric has different source and retention semantics from blocked_hit_rows_* and should not be expected to match retained hit-row counts. If the aggregate source is unavailable, firewall_blocks_available is 0 and category/window series are omitted rather than fabricated. The two_factor_* and admin_users_without_2fa_total metrics remain strict Wordfence TOTP/2FA metrics. Wordfence 9.0.0 passkeys are exported through passkey_enabled, passkey_protected_users_total, admin_users_without_passkey_total, admin_users_without_login_protection_total, and login_protected_users_total. For Wordfence 9.0.0+ login-protection alerts, prefer admin_users_without_login_protection_total overloading the 2FA-only admin metric. failed_login_attempts_window remains the aggregate failed-login metric and counts Wordfence wfLogins rows where fail is greater than 0, including passkey-related failures in Wordfence 9.0.0. authentication_failures_window adds bounded method labels for password, passkey, passkey_required, two_factor, and other failures. brute_force_events_window username values use password-classified login failures when wfLogins is available, so passkey-required policy blocks are not counted as password brute force.
It appends newly observed blocked Wordfence hits to a local .log or .jsonl path. The default text format preserves the original plain-text log line. The JSON Lines format emits one structured JSON object per blocked event for Loki, ELK, OpenSearch, and similar tooling. The exported incident timestamp is taken from the Wordfence hit row, falling back across known timestamp columns before using export time. The exporter tracks the last processed hit ID, and you can reset the incident cursor from the admin UI or WP-CLI to backfill retained history up to the configured per-run limit. For Loki, configure your log collector to parse the text prefix or the JSON Lines timestamp field if you want Grafana to display the original Wordfence event time instead of the collector ingestion time. Incident privacy controls can keep full IPs, truncate IPv4 to /24 and IPv6 to /64, hash IPs with the site salt, drop IP fields, drop query strings from URL and referer fields, drop referers, drop user agents, skip private/internal source IP ranges, and append an optional retention note to emitted events.
If WP-CLI is available, the plugin registers: wp simula-security-telemetry export wp simula-security-telemetry export --metrics-only wp simula-security-telemetry export --metrics-only --scope=fast wp simula-security-telemetry export --metrics-only --scope=slow wp simula-security-telemetry export --incidents-only wp simula-security-telemetry reset-cursor wp simula-security-telemetry status
Yes. The source repository provides repository-only examples under examples/grafana/ and examples/prometheus/. They are intentionally not included in the WordPress.org plugin zip. The dashboard includes exporter health, activity, scan posture, WordPress version, plugin posture, opt-in plugin inventory, opt-in admin inventory, administrator login-protection coverage, and incident logs. Inventory-based alert examples require the matching opt-in inventory metric to be enabled.
The directory that will contain the .prom file must already exist and be writable by the PHP process running WordPress. If incident export is enabled, the incident log directory must also already exist and be writable by PHP. node_exporter must be able to read the resulting .prom file.

Sign In / Register

You need to sign in or register to use this feature.