WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Get started

GDPR compliance

Security Ninja may log visitor IPs for firewall protection under legitimate interest. Default visitor log retention is 7 days (up to 14). Update your privacy policy.

Security Ninja can store visitor IP addresses to identify and block harmful traffic. Under GDPR, that is often treated as legitimate interest for security (see Article 6(f)). The plugin does not link those IPs to named visitor profiles on its own.

You should still update your Privacy Policy: say that you log IPs for security, how long you keep them, and that visitors can read that notice. Consent is not typically required for this kind of security logging, but transparency is.

Visitor Log retention (Pro): Under Firewall → Settings → Visitor Logging, the default is 7 days. You can choose 1, 3, 7, or 14 days. Old entries are pruned automatically.

Example wording you can adapt:

“We use firewall software to protect our website from malicious software and attacks. As part of this, visitor IP addresses may be logged for a limited period (by default up to 7 days on our firewall visitor log, configurable up to 14 days) to identify repeat suspicious behavior. This is in accordance with GDPR Article 6.f.”

Shared bad-IP network (Pro)

With Security Ninja Pro, your site can take part in a shared blocked-IP network. When participating sites report blocked attack attempts, other sites can block those IPs earlier.

Reports are limited to the blocked IP, the reporting site, and the block reason. No personal visitor profiles are built. You can opt out of reporting if you prefer not to share that data.

More detail: Block IP network and non-sensitive diagnostic data.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image