Skip to content

EP Security

EP Security is the intended home for AI-era security on PageMotor: web-server firewall management, log-driven attack detection, plain-English explanation of security events, and two-factor gating on sensitive admin actions. This page documents what has actually shipped, which today is the groundwork for those features rather than the features.

Published by ElmsPark Studio.

The remaining work depends on things outside the plugin: a PageMotor core api() valet method that has not shipped, and an open question about how far the login flow can be extended. Rather than sit unversioned, the database surface and the settings shape went out first so they are stable when the behaviour lands.

That is a reasonable engineering decision and a dangerous documentation one, which is why the warning above is the first thing on this page.

  • The plugin’s database tables.
  • A settings page whose controls render correctly.
  • Nothing that reads those controls.

The settings you can see, none of which currently do anything, cover detection (login path, lockout threshold, lookback window), firewall rules and enforcement mode, two-factor enrolment and gate window, log ingestion interval, and AI explanations including model choice. Treat the list as a statement of intent about where the plugin is going.

  • PageMotor 0.8.3 or later
  • EP Suite base class (bundled with the plugin)

There is no reason to install 0.0.3 on a production site. If you are tracking the plugin’s development:

  1. ep-security.zip comes with an EP Suite licence — ElmsPark supplies it directly (see EP Suite plugins); after install it updates through your site’s Updates screen.
  2. Upload via Plugins → Manage Plugins. Activate.
  3. Open Plugin Settings → EP Security.

Nothing here replaces the basics. Keep your PageMotor core current, keep admin accounts few and their passwords strong, and use EP Host Check to confirm your hosting is not undermining you. For sign-in hardening today, EP Passkeys is a shipped, working plugin; EP Security’s two-factor gating is not.

  • Settings language menu. The language menu in this plugin’s settings now lists only the languages it is actually translated into, plus English, so you can no longer pick a language that changes nothing.
  • Saved keys and passwords that stopped working are recovered. On PageMotor 0.11.3 or later, a key or password saved in this plugin’s settings before this plugin protected its keys itself could be kept in a scrambled form the plugin could not read, so the connection it was for failed. The plugin now unscrambles it once and keeps it protected as usual.
  • If a saved key cannot be recovered, it is no longer stored in its unreadable form. The error log says which one to enter again in the plugin settings.
  • Keys you save from now on are unaffected.
  • Fixes stored keys and passwords reading as empty after a PageMotor 0.11.3 or 0.11.4 update. After the core update, every secret this plugin had encrypted at rest came back blank, so anything that needed it failed with an authentication error until the value was typed in again. Nothing was deleted: the encrypted value was still in the settings row, but PageMotor 0.11.3 moved the site secret that opens it, and this plugin was still looking in the old place. It now finds the secret in both places, so an existing value opens again without re-entry, and a value that was re-entered in the meantime keeps working and is moved back under the site secret.
  • If you updated PageMotor and then re-entered a key or password, there is nothing to do. If you updated and have not re-entered it, this release restores it on the next page load.
  • Your Anthropic API key is now stored encrypted. Until this release it sat in plain text in the plugin’s settings, where anyone holding an API or MCP connection to your site with permission to configure plugins could read it straight back out. Your site’s visitors were never able to see it.
  • Existing sites convert themselves the next time the plugin loads, once. There is nothing to re-enter and no key to replace.
  • Reading your settings over the API now returns a placeholder rather than the value, and writing that placeholder back leaves the stored secret untouched. Clearing it by submitting an empty value still works as before.
  • On hosting without encryption support the previous behaviour is kept and the reason is written to the log, because quietly discarding a working key would be worse than the exposure this closes.
  • Fixes “Your session has expired. Please reload to ensure your security.” on PageMotor 0.11. The message appeared on this plugin’s admin screens even though you were signed in perfectly normally, and whatever you were doing failed to save.
  • Nothing was wrong with your session. PageMotor 0.11 started handling part of the security check that this plugin was already handling itself, and the two together made every save look invalid. The plugin now checks whether PageMotor has already done it.
  • Visitors who were not signed in were never affected, on any version.
  • There is nothing to reconfigure, and nothing else changed.

Fixes six settings toggles that never rendered. Each was declared as a checkbox with no options array, and PageMotor’s form builder silently emits an empty wrapper for a field type it cannot match, so the controls were invisible rather than broken-looking.

The toggles are still not wired to anything. Making them visible made the declarations correct for when the features land; it did not make them functional.