Skip to main content

Legal / Definitions

Definition source attributions

IronGuardWP’s malware definitions and threat intelligence incorporate data derived from the third-party sources below, each used under its own licence. This page lists every source that ships, what it is used for, and the attribution notice that licence requires.

Nothing third-party ships raw. Every signature is normalised into our own format, de-duplicated, and false-positive tested against a clean WordPress corpus before it reaches your site. Sources are recorded per signature, so this list reflects what is actually published rather than what we once intended to publish.

Licences we do not accept. No NonCommercial data and no vendor feed without a redistribution grant ships in any tier of IronGuardWP — including the Free tier, which is part of a commercial product line. Feeds on those terms are refused by the pipeline’s licence gate before a bundle is built, which is why some sources named in earlier product documents are not on this page.

Sources currently shipping

Linux Malware Detect (LMD / RFXN)

GPL-2.0

Licence: GNU General Public License v2.0 or later GPL-2.0-or-later

PHP and web malware signatures, normalised into the IronGuardWP definition format, de-duplicated, and false-positive tested before release.

Attribution: Contains signature data licensed under the GNU GPL v2.0 or later.

Shipped as separately-updated data. These rules travel inside the downloaded definition bundle, which the plugin reads as data at runtime. They are never copied into, generated into, or linked with plugin source, so the plugin’s own licence is unaffected.

Required notice, reproduced verbatim

Notice not yet transcribed

The upstream copyright line and the GNU GPL v2.0 licence text, as carried by the released definition bundle.

Neo23x0 signature-base

DRL-1.1

Licence: Detection Rule License 1.1 DRL-1.1

Web shell and PHP backdoor detection rules, adapted into the IronGuardWP definition format.

Attribution: Detection logic derived from rules licensed under the Detection Rule License (DRL) 1.1. Attribution to the original rule authors is retained.

The DRL permits commercial use and redistribution provided attribution is retained and derived rules stay under the DRL. The author of each individual rule is carried through the pipeline and reproduced per rule in the bundle’s attributions file.

Required notice, reproduced verbatim

Notice not yet transcribed

The Detection Rule License 1.1 text, plus the per-rule author attributions for the rules present in the current bundle.

NSA — Mitigating Web Shells

Public domain

Licence: Work of the US Government, public domain (17 U.S.C. §105) LicenseRef-US-Gov-Public-Domain

Web-shell detection patterns and guidance.

Attribution: Derived from US Government work released into the public domain.

No attribution is legally required for a US Government public-domain work. We credit it anyway, and record it in the source ledger, so it has an explicit entry rather than an unrecorded one.

This licence requires no reproduced notice.

Web Shell Detector

MIT

Licence: MIT License MIT

A file-digest database of known web shells, used for exact-match detection.

Attribution: Includes data from an MIT-licensed project; the MIT copyright notice is reproduced with the definition bundle.

Required notice, reproduced verbatim

Notice not yet transcribed

The MIT copyright line and permission notice exactly as carried by the shipped database file.

NVD / CVE

Public domain

Licence: NVD and CVE Program terms of use LicenseRef-NVD-CVE-Terms

CVE identifiers and vulnerability metadata for WordPress plugins and themes, used for the vulnerability alerts in Pro.

Attribution: Vulnerability data from the National Vulnerability Database and the CVE Program.

NVD data carries no copyright, being a US Government work. The trademark and non-endorsement notices below are a separate obligation and are reproduced exactly as required — never paraphrased, never summarised.

Required notice, reproduced verbatim

CVE is a registered trademark of The MITRE Corporation.
This product uses data from the NVD API but is not endorsed or certified by the NVD.

Notice not yet transcribed

MITRE’s copyright designation and the CVE Program Terms of Use, transcribed from https://www.cve.org/Legal/TermsOfUse — the ToU grants the copyright licence "provided that you reproduce MITRE’s copyright designation and this license in any such copy".

Before launch

4 required notices on this page have not been transcribed from their sources yet and are shown as marked placeholders. Each must be copied word for word from the source. Do not paraphrase, do not summarise, and do not reconstruct a copyright line from memory.

What these sources do and do not cover

Malware and web-shell detection draws on all five sources above, combined and curated into a single definition set.

Vulnerability data comes from NVD and the CVE Program alone. The vulnerability alerts in Pro tell you when a plugin or theme you run has a disclosed CVE. That is the public vulnerability record, filtered to WordPress plugin and theme entries. It is not a WordPress-specific vulnerability feed, and a WordPress plugin issue that never receives a CVE will not appear in it.

We would rather tell you the shape of the coverage than let you infer a wider one. If that changes — because a source is added, or because terms we can accept become available — this page changes with it.

A definition bundle also ships its own attributions file, generated from the rules that were actually published in that bundle rather than from an intended source list. It is the per-release record; this page is the public summary of the same set.

Questions about a source, a licence, or an attribution on this page? Get in touch