DIGITER.ORG · DOCUMENTATION
Digiter Security Ultimate Documentation
Focused, release-aligned setup, workflow, licensing, compatibility, recovery and support guidance for this product.Effective date: September 8, 2026 · Version 2.4.0Digiter Security Ultimate 3.6.47
Always-on WordPress protection connected to Digiter's global Threat Database, with DTD-first malware intelligence, persistence monitoring, quarantine and recovery.
Product overview
Digiter Security Ultimate is built as a security operations suite rather than a single on/off firewall switch. It combines request protection, anti-bot controls, login hardening, malware and integrity analysis, persistence and supply-chain monitoring, quarantine, two-factor authentication, attack intelligence, diagnostics and recovery-oriented functions so administrators can investigate and respond from one coordinated interface.
Digiter operates its own global Digiter Threat Database (DTD). It continuously collects, verifies and normalizes threat information from worldwide intelligence sources so participating Security Ultimate installations can benefit from current reputation, malware and vulnerability context instead of relying only on signatures bundled months earlier. Every legal customer with an authentic Security Ultimate license is entitled to the licensed DTD services included with that product plan; the owner-only DTD Control plugin is not required on customer websites.
The current DTD-first scanner combines WordPress-aware Digiter behavior and integrity analysis with central exact-hash reputation and managed ClamAV/YARA capability where available. Important critical defenses are deliberately independent from premium licensing: the Critical Shield continues to protect the site even when a license is missing, invalid, wrong-domain or expired. Exact signatures, scoring weights, source-selection logic, service credentials and defensive thresholds remain confidential because publishing them would weaken the protection model.
Demo, purchase, delivery and activation
- The Shop product card provides the reviewed complete license-gated ZIP only after Customer Account login and email confirmation. No license is needed for the product's declared minimal Demo function.
- For a downloadable commercial plan, Digiter Shop waits for verified PayPal confirmation, issues the domain-bound signed license and sends the protected full-package download and license key to the checkout email.
- The Demo and commercial delivery use the same complete license-gated product version. Activating a valid key unlocks the full installed capacity without reinstallation; the paid email link remains available for a clean copy or recovery.
- Eligible Account purchases also expose current protected downloads while update access remains active. Download counts, expiry, domain and plan terms remain those recorded for the order.
- Private signed releases integrate with the standard WordPress Plugins and Dashboard Updates screens. Update eligibility follows the purchased update period and does not change the permanent-use term of a Lifetime license.
Current release highlights
- Security Ultimate 3.6.47 corrects attack-map projection so high and critical source markers align with their actual geographic coordinates across all three map styles.
- DTD-first diagnostics now report the actual availability of central ClamAV and YARA capability instead of presenting unrelated host binaries as the normal active engine.
- Administrators can retain identified high and critical map attacks for seven days or one month, with automatic expiry enforced independently from optional general cleanup.
- The full WordPress installation can be scanned in resumable, server-safe batches with visible current file, progress, speed, coverage, findings and estimated completion time.
- When a reviewed license-gated Demo is available, a confirmed Customer Account can download it from the Shop product card.
Why this product stands apart
- Unlike many license-gated security products, Digiter does not turn off the most critical protection when a commercial key is absent or expired; Critical Shield remains active.
- Digiter combines WordPress-specific behavior analysis, integrity verification, global DTD intelligence and managed multi-engine scanning instead of relying on one generic signature source.
- Findings are separated into confirmed malware, manual review, integrity changes and trusted exact hashes, giving administrators more context than an unexplained red warning.
- Persistence, database-trigger, scheduled-task, rendered-content and install-time supply-chain checks extend protection beyond ordinary file scanning.
- Local privacy-first anti-spam, Cloudflare-aware visitor identification, Plesk-oriented host defense and reversible recovery provide unusually broad operational coverage in one WordPress suite.
Core capabilities
- Apply an application-layer firewall, mandatory anti-bot controls, adaptive flood protection, secure upload rules, session controls and security hardening while preserving supported WordPress workflows.
- Protect login and API authentication with throttling, generic failure responses, encrypted TOTP two-factor authentication, recovery codes and session-lifetime/concurrency controls.
- Scan the complete WordPress installation for suspicious behavior, integrity problems, disguised executable content, unknown executable core files and large-script indicators.
- Compare supported WordPress core and public plugin files with official integrity information, while treating modifications as integrity evidence rather than automatically labeling every difference as malware.
- Use DTD exact-hash reputation, vulnerability context and central scan capability as part of a layered result; an unavailable optional source does not prevent the local scanner from continuing.
- Monitor critical file changes, selected persistence mechanisms, scheduled tasks and suspicious content/outbound-link changes without blindly deleting findings.
- Use protected quarantine and SHA-256-verified restore workflows so a reviewed suspicious file is not simply destroyed without a recovery path.
- Protect comments and common forms with explainable local signals and native WordPress quarantine without transmitting comment text to a third-party anti-spam service.
- Present events, alerts, IP intelligence, three attack-map styles, 7/30-day retention, vulnerability information and diagnostics in an administrator-focused interface.
- Integrate signed private updates, package integrity verification and authorized rollback so maintenance remains part of the same commercial lifecycle.
Protection, integrity and recovery model
- Critical Shield keeps the request firewall, anti-bot protection, login throttling, existing TOTP enforcement, upload protection, session controls, local blocks and critical hardening active without a valid premium license.
- A YARA-only or otherwise inconclusive signal remains Manual Review by design; it is not silently promoted to confirmed malware.
- Quarantine and restore validate file identity and expected location, and reviewed trust follows the exact file hash so later file changes are scanned again.
- Optional intelligence failures use bounded timeouts and fail-safe behavior so one unavailable service does not stall every file or invent a vulnerability result.
- Customer documentation and support output exclude service secrets, license material, private detection rules and other information that could be repurposed to bypass protection.
- Account-gated Demo packages must be verified to keep only the declared minimal runtime available until a valid signed license is activated. Customer data, credentials, signing material and internal release records must never be included.
- A downloaded WordPress ZIP remains technically inspectable. Confirmed-Account access, encryption at rest, user-bound expiring links, integrity checks, request limiting and crawler controls protect storage and delivery but do not claim impossible post-download DRM.
Administration and visibility
- Live dashboard status for firewall, scanner, anti-spam, critical activity and the selected attack-map retention window.
- Diagnostics distinguish DTD reputation, DTD scan capability, vulnerability intelligence and optional continuity components instead of collapsing them into one ambiguous status.
- Scanner progress shows the active phase, current file, checked total, malware/manual-review counts, speed, elapsed time, ETA and active performance profile.
- Security Center, Persistence Monitor, Anti-Spam, event views, File Inspector and support diagnostics provide separate investigation surfaces for different incident types.
- Digiter Shop → Demo Downloads manages the reviewed Account-gated package. The current commercial release is validated and linked without a duplicate upload. Manual fallback accepts only the exact same current ZIP, version and SHA-256. Publish only after testing both unlicensed minimal mode and licensed full activation.
- With an active update entitlement, signed Shop releases appear automatically in WordPress Plugins and Dashboard Updates. Manual Check now, Update now and authorized rollback remain available in the product administration.
Typical operating workflow
- Begin with the security dashboard and diagnostics to confirm Critical Shield, DTD services, file permissions and supported scan capabilities are in the expected state.
- Configure login, anti-bot, firewall and notification settings conservatively before enabling stricter policies on a production site.
- Run an initial scan to establish the current file state and review findings by severity and context rather than deleting every flagged file automatically.
- Quarantine only items that have been reviewed and preserve the ability to restore them if the finding proves to be benign or the site depends on the file.
- Review authentication, persistence and attack events for repeated sources, unusual patterns or changes that correspond with a reported incident; select seven-day or one-month map retention according to operational need.
- After remediation, run follow-up integrity and malware checks and verify the affected public and administrative workflows.
- Keep the licensed plugin and WordPress core/extensions updated and retain a separate backup because a security product is not a replacement for disaster recovery.
Where the product fits
- Hardening a public WordPress site that receives repeated automated login attempts, form abuse or suspicious request patterns.
- Investigating unexpected file modifications after a compromised account, vulnerable extension or unauthorized server change.
- Adding administrator 2FA and recovery controls on sites where wp-admin access has meaningful business impact.
- Providing an auditable workflow for malware findings, quarantine decisions and post-cleanup verification.
- Using Digiter's maintained global Threat Database and central scan capability as additional intelligence without giving WordPress package-manager or root privileges.
Operational considerations
- Security findings require context. A suspicious pattern can be malicious, intentionally administrative or part of another security product; manual review remains important for high-impact actions.
- The plugin does not grant WordPress sudo or root privileges. Installing system packages, managing daemons and changing server-wide security policy remain server-administrator responsibilities.
- DTD availability depends on valid entitlement, network/service reachability and the supported deployment model. Diagnostics should be checked before treating an optional continuity path as available.
- Quarantine and restore operations should be accompanied by a current site backup and should be tested carefully on business-critical installations.
- Firewall and anti-bot settings can affect integrations, API clients and unusual authentication flows. Increase strictness gradually and test the workflows the site actually uses.
- This is a complex, actively maintained WordPress plugin. Despite pre-release testing, reproducible defects or compatibility issues can occur; confirmed product defects are corrected through maintained updates according to the customer’s active update entitlement.
Compatibility and environment
- The suite is designed for current WordPress installations and common Apache/Nginx/Plesk-style environments, but hosting security restrictions can change which optional local tools are available.
- Caching, CDN and reverse-proxy layers can change the apparent client address. Administrators should configure the surrounding infrastructure correctly so security logs represent the intended source information.
- WooCommerce, APIs, mobile applications, SSO and password-reset flows should be tested after authentication or rate-defense changes because they may use different endpoints from a normal browser login.
- Other security plugins can overlap with firewall, login or scanning functions. Avoid enabling two products to enforce contradictory policies on the same request path.
Recommended best practices
- Create a verified backup before major remediation or hardening changes and keep that backup outside the affected WordPress installation when possible.
- Use 2FA for administrators and maintain recovery codes in a secure offline location.
- Investigate recurring warnings instead of simply whitelisting them; repeated false positives usually indicate that a rule, integration or site behavior needs better context.
- Review diagnostics after PHP, web-server or hosting changes because optional binaries and paths may become inaccessible even though WordPress itself still works.
- Treat security as a process: update, monitor, investigate, remediate, verify and maintain recovery capability rather than relying on a single scan.
Privacy, security and implementation boundary
Security operation necessarily processes request metadata, authentication events, file paths, hashes, IP-related context and configuration information required to detect or investigate suspicious behavior. DTD is designed to exchange only the limited reputation, capability or licensed-service information required for the selected function; scanned file content is not sent to a public malware API and comment text is not sent to an external anti-spam service. Exact intelligence sources, collection rules, detection weights, signatures, service credentials, trust logic, hardening thresholds and internal response decisions are proprietary and are intentionally not published. Site owners remain responsible for their own logging notices, retention policies and legal obligations.
Support and troubleshooting
For a suspected false positive, quarantine question, login lockout or scanner issue, contact [email protected] with the finding category, affected path or workflow, relevant diagnostic state and a screenshot. Do not email passwords, private keys, full database exports or other secrets.
Licensing, updates, support and ownership
A Digiter purchase grants the usage entitlement described by the selected product plan. It does not transfer copyright, source code ownership, trademarks, design rights, private signing material or proprietary implementation knowledge. Lifetime plans, where offered, refer to the stated software-use entitlement; update periods are shown separately in the Shop and purchase record.
Hosted Smart Cloud Monthly is an Account-bound service and is operationally different from a downloadable domain license. Standard plugin purchases may be completed as a guest where the Shop allows it, while Account-based purchases can remain associated with the verified Digiter Account.
Protected downloads and private updates are delivered through the Digiter Shop licensing system. Customers should retain their purchase email and license information and should not publish license keys publicly. For setup, licensing, delivery, update or product questions contact [email protected]. Digiter Team will investigate verified issues and work with the customer toward a practical resolution.