{
  "version": "1.0",
  "schema": "https://entitymap.org/spec/v1.0",
  "publisher": {
    "name": "Larsik Corp",
    "url": "https://wpsecurityninja.com/",
    "sameAs": "https://larsik.com/"
  },
  "generated": "2026-08-06T13:32:18.239Z",
  "profile": "core",
  "verificationStatus": "self-declared",
  "entities": [
    {
      "entityId": "e_001",
      "@type": "Organization",
      "name": "Larsik Corp",
      "description": "Larsik Corp maintains, supports, and sells WP Security Ninja, a WordPress security plugin used by site owners, freelancers, and agencies.",
      "hasChunks": [
        {
          "chunkId": "c_001",
          "text": "Larsik Corp maintains, supports, and sells WP Security Ninja, a WordPress security plugin used by site owners, freelancers, and agencies.",
          "sourceUrl": "https://wpsecurityninja.com/about/",
          "pageTitle": "About, history & future of Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_002",
          "text": "A practical WordPress security plugin, built for people who want protection without the drama.",
          "sourceUrl": "https://wpsecurityninja.com/about/",
          "pageTitle": "About, history & future of Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        },
        {
          "chunkId": "c_003",
          "text": "The install wizard gets the basics on, and import/export helps if you manage more than one site. Prefer reading first? There are 150+ docs, including help from inside the plugin.",
          "sourceUrl": "https://wpsecurityninja.com/about/",
          "pageTitle": "About, history & future of Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://larsik.com/",
      "relations": [
        {
          "predicate": "OFFERS",
          "targetId": "e_002",
          "targetName": "WP Security Ninja"
        },
        {
          "predicate": "OFFERS",
          "targetId": "e_024",
          "targetName": "Security Cleanup and Review"
        }
      ]
    },
    {
      "entityId": "e_023",
      "@type": "Person",
      "name": "Lars Koudal",
      "description": "Lars Koudal develops and supports WP Security Ninja day to day for Larsik Corp.",
      "hasChunks": [
        {
          "chunkId": "c_004",
          "text": "Lars Koudal develops and supports WP Security Ninja day to day for Larsik Corp.",
          "sourceUrl": "https://wpsecurityninja.com/about/",
          "pageTitle": "About, history & future of Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_005",
          "text": "A practical WordPress security plugin, built for people who want protection without the drama.",
          "sourceUrl": "https://wpsecurityninja.com/about/",
          "pageTitle": "About, history & future of Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        },
        {
          "chunkId": "c_006",
          "text": "The install wizard gets the basics on, and import/export helps if you manage more than one site. Prefer reading first? There are 150+ docs, including help from inside the plugin.",
          "sourceUrl": "https://wpsecurityninja.com/about/",
          "pageTitle": "About, history & future of Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "audienceType": "general",
      "relations": [
        {
          "predicate": "AFFILIATED_WITH",
          "targetId": "e_001",
          "targetName": "Larsik Corp"
        }
      ]
    },
    {
      "entityId": "e_002",
      "@type": "SoftwareProduct",
      "name": "WP Security Ninja",
      "description": "WP Security Ninja is an all-in-one WordPress security plugin with malware scanning, a cloud firewall, login hardening, security tests, and vulnerability checks.",
      "hasChunks": [
        {
          "chunkId": "c_007",
          "text": "WP Security Ninja is an all-in-one WordPress security plugin with malware scanning, a cloud firewall, login hardening, security tests, and vulnerability checks.",
          "sourceUrl": "https://wpsecurityninja.com/",
          "pageTitle": "WordPress Security Features That Protect Your Site",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_008",
          "text": "Block bad traffic, harden logins, find malware and vulnerabilities, and get clear alerts. Start free, unlock full protection with Pro.",
          "sourceUrl": "https://wpsecurityninja.com/",
          "pageTitle": "WordPress Security Features That Protect Your Site",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "alternateName": "Security Ninja",
      "sameAs": "https://wordpress.org/plugins/security-ninja/",
      "relations": [
        {
          "predicate": "INCLUDES",
          "targetId": "e_003",
          "targetName": "Cloud Firewall"
        },
        {
          "predicate": "INCLUDES",
          "targetId": "e_004",
          "targetName": "Malware Scanner"
        },
        {
          "predicate": "INCLUDES",
          "targetId": "e_005",
          "targetName": "Login Protection"
        },
        {
          "predicate": "INCLUDES",
          "targetId": "e_006",
          "targetName": "Security Tests"
        },
        {
          "predicate": "INCLUDES",
          "targetId": "e_007",
          "targetName": "Vulnerability Scanner"
        },
        {
          "predicate": "INCLUDES",
          "targetId": "e_008",
          "targetName": "404 Guard"
        },
        {
          "predicate": "INCLUDES",
          "targetId": "e_009",
          "targetName": "AI Security Advisor"
        },
        {
          "predicate": "INCLUDES",
          "targetId": "e_010",
          "targetName": "White Label"
        },
        {
          "predicate": "DESCRIBED_BY",
          "targetId": "e_022",
          "targetName": "Features Overview"
        },
        {
          "predicate": "DESCRIBED_BY",
          "targetId": "e_017",
          "targetName": "Documentation"
        },
        {
          "predicate": "DESCRIBED_BY",
          "targetId": "e_020",
          "targetName": "WordPress Security Guide 2026"
        }
      ]
    },
    {
      "entityId": "e_024",
      "@type": "Service",
      "name": "Security Cleanup and Review",
      "description": "Hands-on WordPress malware cleanup and security review services offered by Larsik Corp for compromised or at-risk sites.",
      "hasChunks": [
        {
          "chunkId": "c_009",
          "text": "Hands-on WordPress malware cleanup and security review services offered by Larsik Corp for compromised or at-risk sites.",
          "sourceUrl": "https://wpsecurityninja.com/consultation/",
          "pageTitle": "Hire us - WordPress security review & malware cleanup",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_010",
          "text": "Fixed-price WordPress security review ($229) or malware cleanup ($449 / $649 rush). Pay securely with Stripe.",
          "sourceUrl": "https://wpsecurityninja.com/consultation/",
          "pageTitle": "Hire us - WordPress security review & malware cleanup",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        },
        {
          "chunkId": "c_011",
          "text": "<!-- Rendered by src/pages/consultation.astro (dedicated Stripe hire route). --",
          "sourceUrl": "https://wpsecurityninja.com/consultation/",
          "pageTitle": "Hire us - WordPress security review & malware cleanup",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "audienceType": "general",
      "relations": [
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_002",
          "targetName": "WP Security Ninja"
        }
      ]
    },
    {
      "entityId": "e_003",
      "@type": "ProprietaryTerm",
      "name": "Cloud Firewall",
      "description": "Cloud Firewall filters malicious requests and known bad IPs before they reach WordPress, reducing exploit noise and login abuse.",
      "hasChunks": [
        {
          "chunkId": "c_012",
          "text": "Cloud Firewall filters malicious requests and known bad IPs before they reach WordPress, reducing exploit noise and login abuse.",
          "sourceUrl": "https://wpsecurityninja.com/cloud-firewall/",
          "pageTitle": "WordPress Cloud Firewall",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_013",
          "text": "Cloud Firewall filters bad requests, blocks a living list of known bad IPs, and lets you ban countries or custom ranges, so most attacks never become a WordPress problem.",
          "sourceUrl": "https://wpsecurityninja.com/cloud-firewall/",
          "pageTitle": "WordPress Cloud Firewall",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "maturityStatus": "established",
      "audienceType": "technical",
      "relations": [
        {
          "predicate": "ENABLES",
          "targetId": "e_012",
          "targetName": "WAF"
        },
        {
          "predicate": "DESCRIBED_BY",
          "targetId": "e_018",
          "targetName": "Firewall Documentation"
        },
        {
          "predicate": "PREVENTS",
          "targetId": "e_014",
          "targetName": "SQL Injection"
        }
      ]
    },
    {
      "entityId": "e_004",
      "@type": "ProprietaryTerm",
      "name": "Malware Scanner",
      "description": "The Malware Scanner finds malicious code on WordPress sites and supports cleanup with integrity checks for plugins and themes.",
      "hasChunks": [
        {
          "chunkId": "c_014",
          "text": "The Malware Scanner finds malicious code on WordPress sites and supports cleanup with integrity checks for plugins and themes.",
          "sourceUrl": "https://wpsecurityninja.com/malware-scanner/",
          "pageTitle": "WordPress Malware Scanner",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_015",
          "text": "Scan for suspicious files, review clear findings, clean or whitelist with confidence, and verify WordPress.org plugins have not been tampered with.",
          "sourceUrl": "https://wpsecurityninja.com/malware-scanner/",
          "pageTitle": "WordPress Malware Scanner",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "maturityStatus": "established",
      "audienceType": "technical",
      "relations": [
        {
          "predicate": "TARGETS",
          "targetId": "e_013",
          "targetName": "Malware",
          "confidence": "declared"
        }
      ]
    },
    {
      "entityId": "e_005",
      "@type": "ProprietaryTerm",
      "name": "Login Protection",
      "description": "Login Protection hardens wp-login with failed-login limits, custom login URLs, and two-factor authentication.",
      "hasChunks": [
        {
          "chunkId": "c_016",
          "text": "Login Protection hardens wp-login with failed-login limits, custom login URLs, and two-factor authentication.",
          "sourceUrl": "https://wpsecurityninja.com/login-protection/",
          "pageTitle": "WordPress Login Protection",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_017",
          "text": "Limit failed logins, hide the default login URL, and add 2FA so stolen passwords and credential stuffing are much harder to abuse.",
          "sourceUrl": "https://wpsecurityninja.com/login-protection/",
          "pageTitle": "WordPress Login Protection",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "maturityStatus": "established",
      "audienceType": "technical",
      "relations": [
        {
          "predicate": "PREVENTS",
          "targetId": "e_011",
          "targetName": "Brute Force"
        },
        {
          "predicate": "ENABLES",
          "targetId": "e_015",
          "targetName": "Two-Factor Authentication"
        },
        {
          "predicate": "DESCRIBED_BY",
          "targetId": "e_018",
          "targetName": "Firewall Documentation"
        }
      ]
    },
    {
      "entityId": "e_006",
      "@type": "ProprietaryTerm",
      "name": "Security Tests",
      "description": "Security Tests run 50+ practical WordPress hardening checks with clear guidance on what to fix.",
      "hasChunks": [
        {
          "chunkId": "c_018",
          "text": "Security Tests run 50+ practical WordPress hardening checks with clear guidance on what to fix.",
          "sourceUrl": "https://wpsecurityninja.com/security-tests/",
          "pageTitle": "WordPress Security Tests",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_019",
          "text": "Security Tests check 50+ common hardening gaps, from outdated plugins to exposed config files. You get a weighted score, clear pass and fail counts, and fix guidance on every result.",
          "sourceUrl": "https://wpsecurityninja.com/security-tests/",
          "pageTitle": "WordPress Security Tests",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "maturityStatus": "established",
      "audienceType": "general",
      "relations": [
        {
          "predicate": "ENABLES",
          "targetId": "e_009",
          "targetName": "AI Security Advisor"
        }
      ]
    },
    {
      "entityId": "e_007",
      "@type": "ProprietaryTerm",
      "name": "Vulnerability Scanner",
      "description": "The Vulnerability Scanner checks installed plugins, themes, and WordPress core against known CVEs so you can patch before attackers exploit outdated software.",
      "hasChunks": [
        {
          "chunkId": "c_020",
          "text": "The Vulnerability Scanner checks installed plugins, themes, and WordPress core against known CVEs so you can patch before attackers exploit outdated software.",
          "sourceUrl": "https://wpsecurityninja.com/vulnerabilities/",
          "pageTitle": "WordPress Vulnerability Scanner",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_021",
          "text": "Security Ninja’s free WordPress vulnerability scanner checks your installed software against known CVEs and security issues, included on every free and Pro install.",
          "sourceUrl": "https://wpsecurityninja.com/vulnerabilities/",
          "pageTitle": "WordPress Vulnerability Scanner",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "maturityStatus": "established",
      "audienceType": "technical",
      "relations": [
        {
          "predicate": "TARGETS",
          "targetId": "e_014",
          "targetName": "SQL Injection",
          "confidence": "declared"
        },
        {
          "predicate": "ENABLES",
          "targetId": "e_009",
          "targetName": "AI Security Advisor"
        }
      ]
    },
    {
      "entityId": "e_008",
      "@type": "ProprietaryTerm",
      "name": "404 Guard",
      "description": "404 Guard detects bots that hammer missing URLs and blocks aggressive scanners without hurting real visitors or SEO crawlers.",
      "hasChunks": [
        {
          "chunkId": "c_022",
          "text": "404 Guard detects bots that hammer missing URLs and blocks aggressive scanners without hurting real visitors or SEO crawlers.",
          "sourceUrl": "https://wpsecurityninja.com/404-guard/",
          "pageTitle": "404 Guard for WordPress",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_023",
          "text": "Bots love guessing URLs: backups, old plugin folders, config files. Each wrong guess can still load WordPress. 404 Guard spots the pattern and blocks the IP before it keeps burning CPU on pages that never existed.",
          "sourceUrl": "https://wpsecurityninja.com/404-guard/",
          "pageTitle": "404 Guard for WordPress",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "maturityStatus": "established",
      "audienceType": "technical",
      "relations": [
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_003",
          "targetName": "Cloud Firewall"
        }
      ]
    },
    {
      "entityId": "e_009",
      "@type": "ProprietaryTerm",
      "name": "AI Security Advisor",
      "description": "AI Security Advisor turns Security Ninja scan results into a ranked security audit with guided follow-ups on WordPress 7.",
      "hasChunks": [
        {
          "chunkId": "c_024",
          "text": "AI Security Advisor turns Security Ninja scan results into a ranked security audit with guided follow-ups on WordPress 7.",
          "sourceUrl": "https://wpsecurityninja.com/ai-security-advisor/",
          "pageTitle": "AI Security Advisor for WordPress",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_025",
          "text": "AI Security Advisor turns your Security Ninja tests, vulnerabilities, core findings, and recent activity into a saved audit with ranked next steps and guided follow-up questions.",
          "sourceUrl": "https://wpsecurityninja.com/ai-security-advisor/",
          "pageTitle": "AI Security Advisor for WordPress",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "maturityStatus": "established",
      "audienceType": "general",
      "relations": [
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_006",
          "targetName": "Security Tests"
        }
      ]
    },
    {
      "entityId": "e_010",
      "@type": "ProprietaryTerm",
      "name": "White Label",
      "description": "White Label lets agencies rebrand Security Ninja with their own name and icon on Pro licenses with 25 or more sites.",
      "hasChunks": [
        {
          "chunkId": "c_026",
          "text": "White Label lets agencies rebrand Security Ninja with their own name and icon on Pro licenses with 25 or more sites.",
          "sourceUrl": "https://wpsecurityninja.com/whitelabel/",
          "pageTitle": "White Label WordPress Security",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_027",
          "text": "White label lets you rename Security Ninja, swap icons, and present security as part of your care plan. Included on agency-scale Pro licenses.",
          "sourceUrl": "https://wpsecurityninja.com/whitelabel/",
          "pageTitle": "White Label WordPress Security",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "maturityStatus": "established",
      "audienceType": "executive",
      "relations": [
        {
          "predicate": "SUITED_FOR",
          "targetId": "e_021",
          "targetName": "WordPress Security for Agencies",
          "confidence": "declared"
        }
      ]
    },
    {
      "entityId": "e_dict_404-scanning",
      "@type": "Concept",
      "name": "404 scanning",
      "description": "404 scanning is automated probing of missing URLs to find leftovers, backups, and known vulnerable paths.",
      "hasChunks": [
        {
          "chunkId": "c_028",
          "text": "404 scanning is automated probing of missing URLs to find leftovers, backups, and known vulnerable paths.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/404-scanning/",
          "pageTitle": "404 scanning",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_029",
          "text": "Bots do not only hit the homepage. They request thousands of paths that never existed: old plugin folders, .env backups, wp-config.php.bak , known exploit URLs. Each miss is a 404 that still costs PHP or server work. On cheap hosting, that noise shows up as slow sites and higher bills.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/404-scanning/",
          "pageTitle": "404 scanning",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q18947",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_account-takeover",
      "@type": "Concept",
      "name": "Account takeover",
      "description": "Account takeover is when an attacker gains control of a legitimate user account and can act as that user.",
      "hasChunks": [
        {
          "chunkId": "c_030",
          "text": "Account takeover is when an attacker gains control of a legitimate user account and can act as that user.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/account-takeover/",
          "pageTitle": "Account takeover",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_031",
          "text": "If an Administrator account is taken over, the attacker can install plugins, create more admins, and plant backdoors. Takeover often starts with a reused password, a phishing page, or a session theft, not a clever zero-day.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/account-takeover/",
          "pageTitle": "Account takeover",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q30680574",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_application-passwords",
      "@type": "Concept",
      "name": "Application passwords",
      "description": "Application passwords are per-app credentials WordPress can issue so integrations authenticate without using your main password.",
      "hasChunks": [
        {
          "chunkId": "c_032",
          "text": "Application passwords are per-app credentials WordPress can issue so integrations authenticate without using your main password.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/application-passwords/",
          "pageTitle": "Application passwords",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_033",
          "text": "Mobile apps, CLI tools, and automations often need API access. Application passwords give them a revocable secret instead of storing the real admin password in a third-party service. They still carry the user’s capabilities. An app password on an Administrator is still administrator-level power if it leaks.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/application-passwords/",
          "pageTitle": "Application passwords",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://developer.wordpress.org/rest-api/using-the-rest-api/authentication/#application-passwords",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_assume-breach",
      "@type": "Concept",
      "name": "Assume breach",
      "description": "Assume breach means designing as if an attacker may already have a foothold, so detection and recovery matter as much as prevention.",
      "hasChunks": [
        {
          "chunkId": "c_034",
          "text": "Assume breach means designing as if an attacker may already have a foothold, so detection and recovery matter as much as prevention.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/assume-breach/",
          "pageTitle": "Assume breach",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_035",
          "text": "Perfect prevention fails eventually: a zero-day plugin hole, a phished editor, a vendor compromise. Teams that only “lock the door” freeze when something slips through. Assume breach means you can still answer what changed, restore cleanly, and hunt persistence.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/assume-breach/",
          "pageTitle": "Assume breach",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q105081284",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_backdoor",
      "@type": "Concept",
      "name": "Backdoor",
      "description": "A backdoor is hidden access an attacker leaves so they can return without the original vulnerability.",
      "hasChunks": [
        {
          "chunkId": "c_036",
          "text": "A backdoor is hidden access an attacker leaves so they can return without the original vulnerability.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/backdoor/",
          "pageTitle": "Backdoor",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_037",
          "text": "Cleaning “the obvious malware file” while leaving a backdoor means reinfection days later. Backdoors hide in themes, mu-plugins, uploads with double extensions, or database options that eval code on every request.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/backdoor/",
          "pageTitle": "Backdoor",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q797494",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_011",
      "@type": "Concept",
      "name": "Brute Force",
      "description": "A brute-force attack tries many passwords or tokens until one works, usually against the login form.",
      "hasChunks": [
        {
          "chunkId": "c_038",
          "text": "A brute-force attack tries many passwords or tokens until one works, usually against the login form.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/brute-force/",
          "pageTitle": "Brute force",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_039",
          "text": "WordPress exposes a public login URL on most sites. Bots can hit wp-login.php and xmlrpc.php all day with guessed passwords. One weak Administrator password is enough for a full takeover.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/brute-force/",
          "pageTitle": "Brute force",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q869370",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_core-file-integrity",
      "@type": "Concept",
      "name": "Core file integrity",
      "description": "Core file integrity is the assurance that WordPress core files match known-good versions and have not been tampered with.",
      "hasChunks": [
        {
          "chunkId": "c_040",
          "text": "Core file integrity is the assurance that WordPress core files match known-good versions and have not been tampered with.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/core-file-integrity/",
          "pageTitle": "Core file integrity",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_041",
          "text": "Attackers sometimes patch a core file so their backdoor loads on every request. The site can look fine in wp-admin while wp-includes is no longer stock WordPress. Comparing core to official hashes catches that class of persistence even when malware signatures miss it.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/core-file-integrity/",
          "pageTitle": "Core file integrity",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q5447195",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_credential-stuffing",
      "@type": "Concept",
      "name": "Credential stuffing",
      "description": "Credential stuffing replays usernames and passwords stolen from other breaches against your login.",
      "hasChunks": [
        {
          "chunkId": "c_042",
          "text": "Credential stuffing replays usernames and passwords stolen from other breaches against your login.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/credential-stuffing/",
          "pageTitle": "Credential stuffing",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_043",
          "text": "People reuse passwords. When another site leaks a list, attackers try those same pairs on WordPress. They are not guessing letter by letter. They are checking whether your users recycled a password from a breach dump.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/credential-stuffing/",
          "pageTitle": "Credential stuffing",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q30680574",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_csrf",
      "@type": "Concept",
      "name": "CSRF",
      "description": "CSRF tricks a logged-in browser into sending a request the user did not mean to send.",
      "hasChunks": [
        {
          "chunkId": "c_044",
          "text": "CSRF tricks a logged-in browser into sending a request the user did not mean to send.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/csrf/",
          "pageTitle": "CSRF",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_045",
          "text": "If an Administrator is logged in and visits a malicious page, that page can try to submit forms to wp-admin as the admin. WordPress core uses nonces to stop most of this. Custom plugins that skip nonce and capability checks stay risky.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/csrf/",
          "pageTitle": "CSRF",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q1128340",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_cve",
      "@type": "Concept",
      "name": "CVE",
      "description": "A CVE is a public identifier for a known cybersecurity vulnerability tracked in shared databases.",
      "hasChunks": [
        {
          "chunkId": "c_046",
          "text": "A CVE is a public identifier for a known cybersecurity vulnerability tracked in shared databases.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/cve/",
          "pageTitle": "CVE",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_047",
          "text": "When a plugin hole goes public, it usually gets a CVE ID (and sometimes several related IDs). Scanners, hosts, and news posts use that ID so everyone means the same bug. Your job is not to memorize CVSS charts. It is to see whether your installed version is affected and whether a fixed release exists.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/cve/",
          "pageTitle": "CVE",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q506244",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_ddos",
      "@type": "Concept",
      "name": "DDoS",
      "description": "A DDoS attack floods a site or its infrastructure with traffic so legitimate visitors cannot get through.",
      "hasChunks": [
        {
          "chunkId": "c_048",
          "text": "A DDoS attack floods a site or its infrastructure with traffic so legitimate visitors cannot get through.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/ddos/",
          "pageTitle": "DDoS",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_049",
          "text": "Even a cheap flood can knock shared hosting offline. Application-layer floods aim at login, search, XML-RPC, or heavy plugin endpoints so a little traffic does a lot of damage. A security plugin alone cannot absorb a large network flood; that belongs at the CDN or host edge.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/ddos/",
          "pageTitle": "DDoS",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q18947",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_defense-in-depth",
      "@type": "Concept",
      "name": "Defense in depth",
      "description": "Defense in depth stacks multiple controls so one missed update or weak password is less likely to end in disaster.",
      "hasChunks": [
        {
          "chunkId": "c_050",
          "text": "Defense in depth stacks multiple controls so one missed update or weak password is less likely to end in disaster.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/defense-in-depth/",
          "pageTitle": "Defense in depth",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_051",
          "text": "There is no single “secure plugin” checkbox. Updates, backups, 2FA, a WAF, monitoring, and least privilege each catch different failures. Layers turn brittle security into something that survives a bad week.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/defense-in-depth/",
          "pageTitle": "Defense in depth",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q1182453",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_event-logging",
      "@type": "Concept",
      "name": "Event logging",
      "description": "Event logging records security-relevant actions so you can see what changed and when.",
      "hasChunks": [
        {
          "chunkId": "c_052",
          "text": "Event logging records security-relevant actions so you can see what changed and when.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/event-logging/",
          "pageTitle": "Event logging",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_053",
          "text": "When something goes wrong, memory is a bad forensic tool. A timeline of logins, plugin installs, option changes, and new users answers “who did that?” without guessing from a backup dump.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/event-logging/",
          "pageTitle": "Event logging",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q11046",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_false-negative",
      "@type": "Concept",
      "name": "False negative",
      "description": "A false negative is a real security problem that a tool or process failed to detect.",
      "hasChunks": [
        {
          "chunkId": "c_054",
          "text": "A false negative is a real security problem that a tool or process failed to detect.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/false-negative/",
          "pageTitle": "False negative",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_055",
          "text": "A green “no malware found” badge feels great. It is not proof the site is clean. New backdoors, clever obfuscation, and database-only injections get missed. Pair scanners with integrity checks, logs, and human review when symptoms disagree with the report.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/false-negative/",
          "pageTitle": "False negative",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q5430288",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_false-positive",
      "@type": "Concept",
      "name": "False positive",
      "description": "A false positive is an alert that looks like a problem but turns out to be benign after review.",
      "hasChunks": [
        {
          "chunkId": "c_056",
          "text": "A false positive is an alert that looks like a problem but turns out to be benign after review.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/false-positive/",
          "pageTitle": "False positive",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_057",
          "text": "Scanners and WAFs err on the side of caution. Treating every flag as malware wastes hours. Ignoring every flag because “tools cry wolf” is how real infections linger. The skill is verification, not blind trust or blind dismissal.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/false-positive/",
          "pageTitle": "False positive",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q5430284",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_file-integrity-monitoring",
      "@type": "Concept",
      "name": "File integrity monitoring",
      "description": "File integrity monitoring checks whether important files changed compared with a known-good baseline.",
      "hasChunks": [
        {
          "chunkId": "c_058",
          "text": "File integrity monitoring checks whether important files changed compared with a known-good baseline.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/file-integrity-monitoring/",
          "pageTitle": "File integrity monitoring",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_059",
          "text": "Attackers often tweak a core file, drop PHP under uploads/ , or quietly edit wp-config.php . Integrity checks catch those edits even when a signature scanner has never seen that exact payload.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/file-integrity-monitoring/",
          "pageTitle": "File integrity monitoring",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q5447195",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_file-upload-vulnerability",
      "@type": "Concept",
      "name": "File upload vulnerability",
      "description": "A file upload vulnerability lets an attacker place a dangerous file on the server, often leading to a webshell.",
      "hasChunks": [
        {
          "chunkId": "c_060",
          "text": "A file upload vulnerability lets an attacker place a dangerous file on the server, often leading to a webshell.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/file-upload-vulnerability/",
          "pageTitle": "File upload vulnerability",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_061",
          "text": "WordPress sites upload media all day. When a form or plugin fails to validate type, size, or path, attackers upload .php (or double extensions) and browse to it. That is one of the most common ways webshells land.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/file-upload-vulnerability/",
          "pageTitle": "File upload vulnerability",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q183980",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_incident-response",
      "@type": "Concept",
      "name": "Incident response",
      "description": "Incident response is the structured process of detecting, containing, cleaning, and learning from a security incident.",
      "hasChunks": [
        {
          "chunkId": "c_062",
          "text": "Incident response is the structured process of detecting, containing, cleaning, and learning from a security incident.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/incident-response/",
          "pageTitle": "Incident response",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_063",
          "text": "When a site is hacked, random clicking makes things worse. A simple response order protects visitors, preserves evidence, removes persistence, and closes the door. You do not need a Fortune 500 playbook. You need a one-page checklist you will actually follow.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/incident-response/",
          "pageTitle": "Incident response",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q5157563",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_least-privilege",
      "@type": "Concept",
      "name": "Least privilege",
      "description": "Least privilege means each user and integration gets only the access required for their job, nothing more.",
      "hasChunks": [
        {
          "chunkId": "c_064",
          "text": "Least privilege means each user and integration gets only the access required for their job, nothing more.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/least-privilege/",
          "pageTitle": "Least privilege",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_065",
          "text": "Every Administrator account is full keys to the kingdom. Freelancers, interns, and old agency logins with admin rights turn a small phishing win into a full takeover. Least privilege shrinks that blast radius before anything goes wrong.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/least-privilege/",
          "pageTitle": "Least privilege",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q17082516",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_login-protection",
      "@type": "Concept",
      "name": "Login protection",
      "description": "Login protection is the set of controls that harden the WordPress login against bots and credential attacks.",
      "hasChunks": [
        {
          "chunkId": "c_066",
          "text": "Login protection is the set of controls that harden the WordPress login against bots and credential attacks.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/login-protection/",
          "pageTitle": "Login protection",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_067",
          "text": "wp-login.php is the front door on almost every site. Bots do not care how small your blog is. Real protection is rate limits, lockouts, 2FA, and watching successes after failure spikes. Renaming the login URL alone is security theater.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/login-protection/",
          "pageTitle": "Login protection",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://wordpress.org/documentation/article/hardening-wordpress/",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_013",
      "@type": "Concept",
      "name": "Malware",
      "description": "Malware on WordPress is unwanted code that steals data, spam-sends, redirects visitors, or keeps a backdoor open.",
      "hasChunks": [
        {
          "chunkId": "c_068",
          "text": "Malware on WordPress is unwanted code that steals data, spam-sends, redirects visitors, or keeps a backdoor open.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/malware/",
          "pageTitle": "Malware",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_069",
          "text": "Infected sites lose trust, trip Safe Browsing warnings, and can hurt visitors. Deleting the one ugly PHP file often fails because a backdoor, cron job, or database option puts it back. That “it returned overnight” pattern is common.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/malware/",
          "pageTitle": "Malware",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q14001",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_nulled-plugin",
      "@type": "Concept",
      "name": "Nulled plugin",
      "description": "A nulled plugin is an unauthorized, usually modified copy of a paid plugin that often includes malware or backdoors.",
      "hasChunks": [
        {
          "chunkId": "c_070",
          "text": "A nulled plugin is an unauthorized, usually modified copy of a paid plugin that often includes malware or backdoors.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/nulled-plugin/",
          "pageTitle": "Nulled plugin",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_071",
          "text": "“Free Pro download” sites do not remove the license check out of kindness. They often add webshells, spam injectors, or phone-home code. You trade a license fee for a persistent compromise that can outlive the plugin you thought you wanted.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/nulled-plugin/",
          "pageTitle": "Nulled plugin",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://wordpress.org/about/security/",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_phishing",
      "@type": "Concept",
      "name": "Phishing",
      "description": "Phishing tricks people into handing over credentials or installing malware by impersonating a trusted party.",
      "hasChunks": [
        {
          "chunkId": "c_072",
          "text": "Phishing tricks people into handing over credentials or installing malware by impersonating a trusted party.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/phishing/",
          "pageTitle": "Phishing",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_073",
          "text": "Attackers email “your site is hacked, log in here” or “WordPress needs urgent verification.” The fake page captures the password. 2FA helps a lot, but rush and fear still win when people click before they think.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/phishing/",
          "pageTitle": "Phishing",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q185789",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_plugin-supply-chain",
      "@type": "Concept",
      "name": "Plugin supply chain",
      "description": "Plugin supply-chain risk is when trusted plugin code or updates become a path for attackers.",
      "hasChunks": [
        {
          "chunkId": "c_074",
          "text": "Plugin supply-chain risk is when trusted plugin code or updates become a path for attackers.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/plugin-supply-chain/",
          "pageTitle": "Plugin supply chain",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_075",
          "text": "You inherit the security of every plugin author you install. Abandoned plugins, stolen publisher accounts, and pirated “nulled” packages keep showing up in incident reports. The update you clicked can be the delivery path.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/plugin-supply-chain/",
          "pageTitle": "Plugin supply chain",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q4118473",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_privilege-escalation",
      "@type": "Concept",
      "name": "Privilege escalation",
      "description": "Privilege escalation is gaining higher access than intended, such as a subscriber becoming an administrator.",
      "hasChunks": [
        {
          "chunkId": "c_076",
          "text": "Privilege escalation is gaining higher access than intended, such as a subscriber becoming an administrator.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/privilege-escalation/",
          "pageTitle": "Privilege escalation",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_077",
          "text": "A bug that lets a Subscriber update options or upload PHP is effectively a full site takeover. Many plugin CVEs are labeled “authenticated privilege escalation.” Spam registrations plus one of those bugs is a common combo.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/privilege-escalation/",
          "pageTitle": "Privilege escalation",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q2518167",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_rate-limiting",
      "@type": "Concept",
      "name": "Rate limiting",
      "description": "Rate limiting caps how often an action can happen from an IP or account, which slows automated abuse.",
      "hasChunks": [
        {
          "chunkId": "c_078",
          "text": "Rate limiting caps how often an action can happen from an IP or account, which slows automated abuse.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/rate-limiting/",
          "pageTitle": "Rate limiting",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_079",
          "text": "Without limits, bots can try thousands of passwords per hour against wp-login.php and xmlrpc.php . That burns server resources and raises the odds that a weak password eventually works. Soft limits turn the spray into a slow, noisy process you can detect and block.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/rate-limiting/",
          "pageTitle": "Rate limiting",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q7295691",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_remote-code-execution",
      "@type": "Concept",
      "name": "Remote code execution",
      "description": "Remote code execution is a vulnerability that lets an attacker run attacker-controlled code on the server.",
      "hasChunks": [
        {
          "chunkId": "c_080",
          "text": "Remote code execution is a vulnerability that lets an attacker run attacker-controlled code on the server.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/remote-code-execution/",
          "pageTitle": "Remote code execution",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_081",
          "text": "RCE is near the top of the severity ladder. If a plugin or theme flaw lets someone execute PHP or shell commands, they can drop a webshell, read wp-config.php , or pivot further. Public RCE CVEs get scanned quickly. Treat them as drop-everything updates.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/remote-code-execution/",
          "pageTitle": "Remote code execution",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q4781490",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_rest-api",
      "@type": "Concept",
      "name": "REST API",
      "description": "The WordPress REST API is an HTTP JSON interface at /wp-json/ used by the editor, apps, and many plugins.",
      "hasChunks": [
        {
          "chunkId": "c_082",
          "text": "The WordPress REST API is an HTTP JSON interface at /wp-json/ used by the editor, apps, and many plugins.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/rest-api/",
          "pageTitle": "REST API",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_083",
          "text": "/wp-json/ is how the block editor and countless plugins talk to WordPress. It is also a discovery surface: user enumeration, authenticated routes, and plugin endpoints that forget capability checks. Killing the entire REST API often breaks Gutenberg. The job is to understand what you expose, not to yank the fuse blindly.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/rest-api/",
          "pageTitle": "REST API",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q749047",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_scheduled-scanning",
      "@type": "Concept",
      "name": "Scheduled scanning",
      "description": "Scheduled scanning runs security checks automatically on a repeating timetable and can alert you to new findings.",
      "hasChunks": [
        {
          "chunkId": "c_084",
          "text": "Scheduled scanning runs security checks automatically on a repeating timetable and can alert you to new findings.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/scheduled-scanning/",
          "pageTitle": "Scheduled scanning",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_085",
          "text": "Manual scans only happen when someone remembers. Attackers and new CVEs do not wait for your Monday checklist. A schedule turns scanning into a habit: malware, vulnerabilities, or integrity drift show up in email or the dashboard while you are busy elsewhere.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/scheduled-scanning/",
          "pageTitle": "Scheduled scanning",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q5447195",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_security-audit",
      "@type": "Concept",
      "name": "Security audit",
      "description": "A security audit is a structured review of a site’s risks, misconfigurations, and recommended fixes.",
      "hasChunks": [
        {
          "chunkId": "c_086",
          "text": "A security audit is a structured review of a site’s risks, misconfigurations, and recommended fixes.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/security-audit/",
          "pageTitle": "Security audit",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_087",
          "text": "Gut feel is not a plan. An audit turns “we should be more secure” into ordered work: outdated plugins, leftover admins, missing backups, open XML-RPC, weak login controls. Agencies use the same pass before launch or after a scare.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/security-audit/",
          "pageTitle": "Security audit",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q6031434",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_security-hardening",
      "@type": "Concept",
      "name": "Security hardening",
      "description": "Hardening is the set of configuration and process changes that make a site harder to abuse.",
      "hasChunks": [
        {
          "chunkId": "c_088",
          "text": "Hardening is the set of configuration and process changes that make a site harder to abuse.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/security-hardening/",
          "pageTitle": "Security hardening",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_089",
          "text": "Default WordPress is usable, not maximally strict. Hardening shrinks what attackers can touch: fewer plugins, tighter roles, locked file editing, current software, tested backups. It is different from security theater (rename the login URL and call it done).",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/security-hardening/",
          "pageTitle": "Security hardening",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q5656205",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_security-headers",
      "@type": "Concept",
      "name": "Security headers",
      "description": "Security headers are HTTP response headers that tell browsers how to treat your pages for safer defaults.",
      "hasChunks": [
        {
          "chunkId": "c_090",
          "text": "Security headers are HTTP response headers that tell browsers how to treat your pages for safer defaults.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/security-headers/",
          "pageTitle": "Security headers",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_091",
          "text": "Headers will not patch a vulnerable plugin. They still reduce common browser-side risks: forcing HTTPS (HSTS), blocking easy clickjacking, tightening what scripts can run when you use CSP carefully. Many hosts and CDNs can send them without a plugin pile-on.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/security-headers/",
          "pageTitle": "Security headers",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_security-theater",
      "@type": "Concept",
      "name": "Security theater",
      "description": "Security theater is activity that feels protective but does not meaningfully reduce real risk.",
      "hasChunks": [
        {
          "chunkId": "c_092",
          "text": "Security theater is activity that feels protective but does not meaningfully reduce real risk.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/security-theater/",
          "pageTitle": "Security theater",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_093",
          "text": "Renaming wp-login.php , hiding the generator meta tag, or stacking five overlapping “security” plugins can feel productive while admin passwords stay weak and backups stay untested. Attackers automate the boring holes. They do not need your version string.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/security-theater/",
          "pageTitle": "Security theater",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q2266747",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_session-hijacking",
      "@type": "Concept",
      "name": "Session hijacking",
      "description": "Session hijacking steals or guesses a valid session so the attacker acts as the logged-in user.",
      "hasChunks": [
        {
          "chunkId": "c_094",
          "text": "Session hijacking steals or guesses a valid session so the attacker acts as the logged-in user.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/session-hijacking/",
          "pageTitle": "Session hijacking",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_095",
          "text": "Admin cookies are powerful. XSS, malware on a workstation, or cleartext HTTP can expose them. After a hijack, the attacker does not need the password until the session ends. That is why HTTPS, XSS patching, and salt rotation after incidents matter together.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/session-hijacking/",
          "pageTitle": "Session hijacking",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q1137396",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_014",
      "@type": "Concept",
      "name": "SQL Injection",
      "description": "SQL injection tricks a database query into running attacker-controlled SQL, often through unsafe input handling.",
      "hasChunks": [
        {
          "chunkId": "c_096",
          "text": "SQL injection tricks a database query into running attacker-controlled SQL, often through unsafe input handling.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/sql-injection/",
          "pageTitle": "SQL injection",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_097",
          "text": "Plugins and custom code that build SQL with raw request data can expose posts, users, or the whole database. On WordPress, that usually means a vulnerable extension, not core itself. Public CVEs get automated fast.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/sql-injection/",
          "pageTitle": "SQL injection",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "alternateName": "SQLi",
      "sameAs": "https://www.wikidata.org/wiki/Q506059",
      "maturityStatus": "established",
      "audienceType": "technical"
    },
    {
      "entityId": "e_dict_ssl-tls",
      "@type": "Concept",
      "name": "SSL/TLS",
      "description": "SSL/TLS encrypts traffic between browsers and your server so passwords and cookies are harder to sniff.",
      "hasChunks": [
        {
          "chunkId": "c_098",
          "text": "SSL/TLS encrypts traffic between browsers and your server so passwords and cookies are harder to sniff.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/ssl-tls/",
          "pageTitle": "SSL/TLS",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_099",
          "text": "Login forms, cookies, and customer data should never ride cleartext HTTP. Browsers mark non-HTTPS sites as insecure, which hurts trust and SEO. HTTPS protects the pipe. It does not fix an outdated plugin with a public CVE.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/ssl-tls/",
          "pageTitle": "SSL/TLS",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q206123",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_015",
      "@type": "Concept",
      "name": "Two-Factor Authentication",
      "description": "Two-factor authentication (2FA) requires a second proof of identity after the password, such as an app code.",
      "hasChunks": [
        {
          "chunkId": "c_100",
          "text": "Two-factor authentication (2FA) requires a second proof of identity after the password, such as an app code.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/two-factor-authentication/",
          "pageTitle": "Two-factor authentication (2FA)",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_101",
          "text": "Passwords leak from other sites, phishing, and shared agency logins. 2FA means the password alone should not open wp-admin . For site owners and agencies, it is one of the highest-value controls you can turn on in an afternoon.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/two-factor-authentication/",
          "pageTitle": "Two-factor authentication (2FA)",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "alternateName": "2FA",
      "sameAs": "https://www.wikidata.org/wiki/Q17086335",
      "maturityStatus": "established",
      "audienceType": "general",
      "relations": [
        {
          "predicate": "PREVENTS",
          "targetId": "e_011",
          "targetName": "Brute Force"
        }
      ]
    },
    {
      "entityId": "e_dict_vulnerability",
      "@type": "Concept",
      "name": "Vulnerability",
      "description": "A vulnerability is a weakness in software that attackers can abuse to break confidentiality, integrity, or availability.",
      "hasChunks": [
        {
          "chunkId": "c_102",
          "text": "A vulnerability is a weakness in software that attackers can abuse to break confidentiality, integrity, or availability.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/vulnerability/",
          "pageTitle": "Vulnerability",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_103",
          "text": "Most breaches start with a known vulnerable plugin or theme, not a brand-new zero-day against core. Automated scanners look for unpatched versions within hours of a public advisory. Severity and fixed-version notes tell you whether to update today or tonight.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/vulnerability/",
          "pageTitle": "Vulnerability",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q183980",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_012",
      "@type": "Concept",
      "name": "WAF",
      "description": "A WAF filters HTTP traffic to block common web attacks before they reach WordPress.",
      "hasChunks": [
        {
          "chunkId": "c_104",
          "text": "A WAF filters HTTP traffic to block common web attacks before they reach WordPress.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/waf/",
          "pageTitle": "WordPress WAF",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_105",
          "text": "A WordPress-oriented WAF sits at the edge or in the app and stops noisy exploit probes, bad bots, and known attack shapes. It is not a substitute for updates. It buys time and cuts drive-by noise while you patch.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/waf/",
          "pageTitle": "WordPress WAF",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "alternateName": "Web Application Firewall",
      "sameAs": "https://www.wikidata.org/wiki/Q25348457",
      "maturityStatus": "established",
      "audienceType": "technical",
      "relations": [
        {
          "predicate": "PREVENTS",
          "targetId": "e_014",
          "targetName": "SQL Injection"
        }
      ]
    },
    {
      "entityId": "e_dict_webshell",
      "@type": "Concept",
      "name": "Webshell",
      "description": "A webshell is a small script uploaded to the server that lets an attacker run commands through the browser.",
      "hasChunks": [
        {
          "chunkId": "c_106",
          "text": "A webshell is a small script uploaded to the server that lets an attacker run commands through the browser.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/webshell/",
          "pageTitle": "Webshell",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_107",
          "text": "One PHP file in uploads or a theme can give filesystem and database access. Attackers use webshells to plant more malware, steal dumps, or pivot to other sites on shared hosting. Cleanup that misses the shell (or the upload hole) invites reinfection.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/webshell/",
          "pageTitle": "Webshell",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q2553703",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_wordpress-nonce",
      "@type": "Concept",
      "name": "WordPress nonce",
      "description": "A WordPress nonce is a short-lived token used to verify that a request was intentional, mainly to reduce CSRF risk.",
      "hasChunks": [
        {
          "chunkId": "c_108",
          "text": "A WordPress nonce is a short-lived token used to verify that a request was intentional, mainly to reduce CSRF risk.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/wordpress-nonce/",
          "pageTitle": "WordPress nonce",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_109",
          "text": "Core and well-built plugins attach nonces to admin forms and AJAX calls so a random third-party page cannot easily forge those actions while you are logged in. A missing or unchecked nonce shows up in CVE write-ups constantly. A nonce is not encryption, and it is not a substitute for capability checks.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/wordpress-nonce/",
          "pageTitle": "WordPress nonce",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://developer.wordpress.org/apis/security/nonces/",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_wordpress-salts",
      "@type": "Concept",
      "name": "WordPress salts",
      "description": "WordPress salts are secret keys in wp-config.php that help secure cookies, nonces, and related cryptographic operations.",
      "hasChunks": [
        {
          "chunkId": "c_110",
          "text": "WordPress salts are secret keys in wp-config.php that help secure cookies, nonces, and related cryptographic operations.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/wordpress-salts/",
          "pageTitle": "WordPress salts",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_111",
          "text": "AUTH KEY , SECURE AUTH KEY , and the other salts in wp-config.php make session cookies and nonces harder to forge. If those secrets leak (or you inherited a site with keys copied from a tutorial), attackers have an easier time with stolen cookies. Regenerating salts invalidates existing sessions. That is often what you want after a breach.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/wordpress-salts/",
          "pageTitle": "WordPress salts",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://developer.wordpress.org/apis/security/authentication/#salts",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_wordpress-user-roles",
      "@type": "Concept",
      "name": "WordPress user roles",
      "description": "User roles group capabilities that decide what each account can do in WordPress, from reading to full admin.",
      "hasChunks": [
        {
          "chunkId": "c_112",
          "text": "User roles group capabilities that decide what each account can do in WordPress, from reading to full admin.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/wordpress-user-roles/",
          "pageTitle": "WordPress user roles",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_113",
          "text": "Roles are how WordPress encodes trust. Misassigned roles are a common root cause of “someone changed the site and we do not know who.” Administrator can install plugins and edit code paths; Editor usually should not.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/wordpress-user-roles/",
          "pageTitle": "WordPress user roles",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://wordpress.org/documentation/article/roles-and-capabilities/",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_wp-config",
      "@type": "Concept",
      "name": "wp-config.php",
      "description": "wp-config.php holds database credentials, keys, and core WordPress settings for the site.",
      "hasChunks": [
        {
          "chunkId": "c_114",
          "text": "wp-config.php holds database credentials, keys, and core WordPress settings for the site.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/wp-config/",
          "pageTitle": "wp-config.php",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_115",
          "text": "If wp-config.php leaks, attackers get database access and authentication salts. Malware also loves to inject PHP here because the file loads on every request. One quiet edit can persist long after you delete an obvious webshell.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/wp-config/",
          "pageTitle": "wp-config.php",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://developer.wordpress.org/advanced-administration/wordpress/wp-config/",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_xml-rpc",
      "@type": "Concept",
      "name": "XML-RPC",
      "description": "XML-RPC is an older WordPress API endpoint attackers often abuse for brute force and amplification.",
      "hasChunks": [
        {
          "chunkId": "c_116",
          "text": "XML-RPC is an older WordPress API endpoint attackers often abuse for brute force and amplification.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/xml-rpc/",
          "pageTitle": "XML-RPC",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_117",
          "text": "xmlrpc.php can allow many password attempts in one HTTP request (multicall) and has been used in pingback-based floods. Plenty of modern sites do not need it. Leaving it open without limits is free attack surface.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/xml-rpc/",
          "pageTitle": "XML-RPC",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q726183",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_xss",
      "@type": "Concept",
      "name": "Cross-site scripting (XSS)",
      "description": "Cross-site scripting (XSS) injects malicious JavaScript into pages that other users’ browsers will run.",
      "hasChunks": [
        {
          "chunkId": "c_118",
          "text": "Cross-site scripting (XSS) injects malicious JavaScript into pages that other users’ browsers will run.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/xss/",
          "pageTitle": "Cross-site scripting (XSS)",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_119",
          "text": "Stored XSS in a comment, page builder field, or admin notice can run in another user’s browser. For admins, that can mean stolen cookies, forced actions, or malware shown to visitors. Reflected XSS often rides on crafted URLs in plugins.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/xss/",
          "pageTitle": "Cross-site scripting (XSS)",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q1135824",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_dict_zero-trust",
      "@type": "Concept",
      "name": "Zero trust",
      "description": "Zero trust treats every request as untrusted until verified, and limits what any one identity can reach.",
      "hasChunks": [
        {
          "chunkId": "c_120",
          "text": "Zero trust treats every request as untrusted until verified, and limits what any one identity can reach.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/zero-trust/",
          "pageTitle": "Zero trust",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_121",
          "text": "“We are on the office VPN so we are safe” does not match remote teams and cloud hosts. For WordPress, zero trust looks like strong identity checks, least privilege, and less surprise when a laptop or freelancer account goes missing.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/zero-trust/",
          "pageTitle": "Zero trust",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "sameAs": "https://www.wikidata.org/wiki/Q105081284",
      "maturityStatus": "established",
      "audienceType": "general"
    },
    {
      "entityId": "e_016",
      "@type": "Taxonomy",
      "name": "WordPress Security Dictionary",
      "description": "A curated set of short WordPress security definitions that hand off to deeper feature and guide pages.",
      "hasChunks": [
        {
          "chunkId": "c_122",
          "text": "A curated set of short WordPress security definitions that hand off to deeper feature and guide pages.",
          "sourceUrl": "https://wpsecurityninja.com/dictionary/",
          "pageTitle": "WordPress Security Dictionary",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        }
      ],
      "relations": [
        {
          "predicate": "COVERS",
          "targetId": "e_dict_404-scanning",
          "targetName": "404 scanning"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_account-takeover",
          "targetName": "Account takeover"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_application-passwords",
          "targetName": "Application passwords"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_assume-breach",
          "targetName": "Assume breach"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_backdoor",
          "targetName": "Backdoor"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_011",
          "targetName": "Brute Force"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_core-file-integrity",
          "targetName": "Core file integrity"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_credential-stuffing",
          "targetName": "Credential stuffing"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_csrf",
          "targetName": "CSRF"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_cve",
          "targetName": "CVE"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_ddos",
          "targetName": "DDoS"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_defense-in-depth",
          "targetName": "Defense in depth"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_event-logging",
          "targetName": "Event logging"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_false-negative",
          "targetName": "False negative"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_false-positive",
          "targetName": "False positive"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_file-integrity-monitoring",
          "targetName": "File integrity monitoring"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_file-upload-vulnerability",
          "targetName": "File upload vulnerability"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_incident-response",
          "targetName": "Incident response"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_least-privilege",
          "targetName": "Least privilege"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_login-protection",
          "targetName": "Login protection"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_013",
          "targetName": "Malware"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_nulled-plugin",
          "targetName": "Nulled plugin"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_phishing",
          "targetName": "Phishing"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_plugin-supply-chain",
          "targetName": "Plugin supply chain"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_privilege-escalation",
          "targetName": "Privilege escalation"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_rate-limiting",
          "targetName": "Rate limiting"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_remote-code-execution",
          "targetName": "Remote code execution"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_rest-api",
          "targetName": "REST API"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_scheduled-scanning",
          "targetName": "Scheduled scanning"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_security-audit",
          "targetName": "Security audit"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_security-hardening",
          "targetName": "Security hardening"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_security-headers",
          "targetName": "Security headers"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_security-theater",
          "targetName": "Security theater"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_session-hijacking",
          "targetName": "Session hijacking"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_014",
          "targetName": "SQL Injection"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_ssl-tls",
          "targetName": "SSL/TLS"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_015",
          "targetName": "Two-Factor Authentication"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_vulnerability",
          "targetName": "Vulnerability"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_012",
          "targetName": "WAF"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_webshell",
          "targetName": "Webshell"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_wordpress-nonce",
          "targetName": "WordPress nonce"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_wordpress-salts",
          "targetName": "WordPress salts"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_wordpress-user-roles",
          "targetName": "WordPress user roles"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_wp-config",
          "targetName": "wp-config.php"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_xml-rpc",
          "targetName": "XML-RPC"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_xss",
          "targetName": "Cross-site scripting (XSS)"
        },
        {
          "predicate": "COVERS",
          "targetId": "e_dict_zero-trust",
          "targetName": "Zero trust"
        }
      ]
    },
    {
      "entityId": "e_017",
      "@type": "larsik:Guide",
      "name": "Documentation",
      "description": "Official WP Security Ninja documentation covering install, firewall, scanners, security tests, and Pro features.",
      "hasChunks": [
        {
          "chunkId": "c_123",
          "text": "Official WP Security Ninja documentation covering install, firewall, scanners, security tests, and Pro features.",
          "sourceUrl": "https://wpsecurityninja.com/docs/",
          "pageTitle": "WP Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_124",
          "text": "Getting started with WP Security Ninja: install, configure security tests, and find docs for firewall, scanners, and Pro features.",
          "sourceUrl": "https://wpsecurityninja.com/docs/",
          "pageTitle": "WP Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        },
        {
          "chunkId": "c_125",
          "text": "Welcome to WP Security Ninja Documentation",
          "sourceUrl": "https://wpsecurityninja.com/docs/",
          "pageTitle": "WP Security Ninja",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "relations": [
        {
          "predicate": "INCLUDES",
          "targetId": "e_018",
          "targetName": "Firewall Documentation"
        },
        {
          "predicate": "INCLUDES",
          "targetId": "e_019",
          "targetName": "Install Guide"
        },
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_016",
          "targetName": "WordPress Security Dictionary"
        },
        {
          "predicate": "AUTHORED_BY",
          "targetId": "e_023",
          "targetName": "Lars Koudal"
        }
      ]
    },
    {
      "entityId": "e_018",
      "@type": "larsik:Guide",
      "name": "Firewall Documentation",
      "description": "Guides for the free 8G request firewall, Pro Cloud Firewall, login protection, country blocking, and 2FA.",
      "hasChunks": [
        {
          "chunkId": "c_126",
          "text": "Guides for the free 8G request firewall, Pro Cloud Firewall, login protection, country blocking, and 2FA.",
          "sourceUrl": "https://wpsecurityninja.com/docs/firewall/",
          "pageTitle": "Firewall",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_127",
          "text": "Firewall, login protection, 2FA, and related Security Ninja guides.",
          "sourceUrl": "https://wpsecurityninja.com/docs/firewall/",
          "pageTitle": "Firewall",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        },
        {
          "chunkId": "c_128",
          "text": "Guides for the free 8G request firewall, Pro Cloud Firewall (600M+ bad IPs), login protection, country blocking, and 2FA.",
          "sourceUrl": "https://wpsecurityninja.com/docs/firewall/",
          "pageTitle": "Firewall",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "relations": [
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_003",
          "targetName": "Cloud Firewall"
        },
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_005",
          "targetName": "Login Protection"
        }
      ]
    },
    {
      "entityId": "e_019",
      "@type": "larsik:Guide",
      "name": "Install Guide",
      "description": "Step-by-step install for WP Security Ninja via WordPress admin or FTP.",
      "hasChunks": [
        {
          "chunkId": "c_129",
          "text": "Step-by-step install for WP Security Ninja via WordPress admin or FTP.",
          "sourceUrl": "https://wpsecurityninja.com/docs/installation-and-usage/install/",
          "pageTitle": "Install: Quick Start Guide",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_130",
          "text": "Easily install WP Security Ninja on your WordPress site. Follow our step-by-step guide for plugin installation via the WordPress admin or FTP for enhanced security.",
          "sourceUrl": "https://wpsecurityninja.com/docs/installation-and-usage/install/",
          "pageTitle": "Install: Quick Start Guide",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        },
        {
          "chunkId": "c_131",
          "text": "To install the free plugin from inside WordPress admin. the easiest way",
          "sourceUrl": "https://wpsecurityninja.com/docs/installation-and-usage/install/",
          "pageTitle": "Install: Quick Start Guide",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "relations": [
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_002",
          "targetName": "WP Security Ninja"
        }
      ]
    },
    {
      "entityId": "e_020",
      "@type": "larsik:Guide",
      "name": "WordPress Security Guide 2026",
      "description": "A practical WordPress security hub for 2026: ordered path from checklist and hardening to login, firewall, scanners, malware recovery, and WooCommerce.",
      "hasChunks": [
        {
          "chunkId": "c_132",
          "text": "A practical WordPress security hub for 2026: ordered path from checklist and hardening to login, firewall, scanners, malware recovery, and WooCommerce.",
          "sourceUrl": "https://wpsecurityninja.com/wordpress-security-guide/",
          "pageTitle": "WordPress Security Guide 2026: Where to Start",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_133",
          "text": "A practical WordPress security hub for 2026: ordered path from checklist and hardening to login, firewall, scanners, malware recovery, WooCommerce, and Free vs Pro.",
          "sourceUrl": "https://wpsecurityninja.com/wordpress-security-guide/",
          "pageTitle": "WordPress Security Guide 2026: Where to Start",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        },
        {
          "chunkId": "c_134",
          "text": "You do not need another 15,000-word “ultimate” guide that repeats the same advice five times. You need a clear order of work and links to guides that already go deep. Use this page as the map.",
          "sourceUrl": "https://wpsecurityninja.com/wordpress-security-guide/",
          "pageTitle": "WordPress Security Guide 2026: Where to Start",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.85,
          "contentType": "evidence"
        }
      ],
      "relations": [
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_016",
          "targetName": "WordPress Security Dictionary"
        },
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_002",
          "targetName": "WP Security Ninja"
        },
        {
          "predicate": "AUTHORED_BY",
          "targetId": "e_023",
          "targetName": "Lars Koudal"
        }
      ]
    },
    {
      "entityId": "e_021",
      "@type": "larsik:Guide",
      "name": "WordPress Security for Agencies",
      "description": "Agency packs with bulk licenses, white label, MainWP workflows, and webhook alerts so agencies can protect client sites at scale.",
      "hasChunks": [
        {
          "chunkId": "c_135",
          "text": "Agency packs with bulk licenses, white label, MainWP workflows, and webhook alerts so agencies can protect client sites at scale.",
          "sourceUrl": "https://wpsecurityninja.com/agencies/",
          "pageTitle": "WordPress Security for Agencies",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_136",
          "text": "Agency packs for 25 to 500 sites, white label included, MainWP workflows, and alerts in Slack or Discord. Security that scales with your portfolio.",
          "sourceUrl": "https://wpsecurityninja.com/agencies/",
          "pageTitle": "WordPress Security for Agencies",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "relations": [
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_010",
          "targetName": "White Label"
        },
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_002",
          "targetName": "WP Security Ninja"
        }
      ]
    },
    {
      "entityId": "e_022",
      "@type": "larsik:Guide",
      "name": "Features Overview",
      "description": "Overview of WP Security Ninja features: firewall, malware scanning, login hardening, vulnerability checks, and install wizard.",
      "hasChunks": [
        {
          "chunkId": "c_137",
          "text": "Overview of WP Security Ninja features: firewall, malware scanning, login hardening, vulnerability checks, and install wizard.",
          "sourceUrl": "https://wpsecurityninja.com/features/",
          "pageTitle": "WordPress Security Features That Protect Your Site",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.95,
          "contentType": "definition"
        },
        {
          "chunkId": "c_138",
          "text": "Block bad traffic, harden logins, find malware and vulnerabilities, and get clear alerts. Start free, unlock full protection with Pro.",
          "sourceUrl": "https://wpsecurityninja.com/features/",
          "pageTitle": "WordPress Security Features That Protect Your Site",
          "publisher": "Larsik Corp",
          "retrieved": "2026-08-06T13:32:18.239Z",
          "relevanceScore": 0.9,
          "contentType": "evidence"
        }
      ],
      "relations": [
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_002",
          "targetName": "WP Security Ninja"
        },
        {
          "predicate": "DEPENDS_ON",
          "targetId": "e_016",
          "targetName": "WordPress Security Dictionary"
        }
      ]
    }
  ]
}
