Restrict high-risk admin actions
Reduce exposure to plugin/theme source editing, installation, ZIP uploads and deletion from wp-admin.
Upload allowlist
Keep normal approved media workflows while rejecting executable, script, archive and suspicious double-extension uploads.
Local security events
Keep a bounded local record of blocked events without sending the event stream to Brightery.
Optional Must-Use deployment
Support a manually deployed MU mode when trusted server administration requires protection that survives normal plugin deactivation.