Security actions contained
Recorded protection actions that contained request or commerce pressure.
CONTAINEDPrivacy-preserving aggregate telemetry from active Nexus PRO protection. These counters reflect recorded security activity—not simulated dashboard numbers.
No public site list, raw IP feed or customer activity is exposed through this Pulse.
The public Pulse reports privacy-preserving aggregate security activity. Nexus Intelligence separately provides bounded attack-pattern context to participating licensed sites, while every final decision remains local.
Headline totals use since sep 5 while the live charts remain rolling 24-hour views. Containment and observation stay separate.
Recorded protection actions that contained request or commerce pressure.
CONTAINEDRequests rejected by early protection before normal WordPress execution.
EARLY BLOCKCommerce-specific pressure or automated actions contained by Nexus.
COMMERCE DEFENSEMeaningful distributed or repeated login-pressure signals. Ordinary mistyped passwords are not counted.
Temporary login restrictions or lockouts actually enforced by Nexus.
Security-relevant probing, enumeration and reconnaissance observations.
XML-RPC pressure or abuse restricted by Nexus protection layers.
Bars are real hourly aggregate counts. The red-lit peaks mark the busiest containment windows—not a different metric.
Independent counts, scaled against the highest lane. These categories can overlap and are not percentages of one whole.
Observed probing remains visually separate from containment. Credential pressure and reconnaissance do not become block counts unless Nexus actually enforces a restriction.
History begins at the first real telemetry day. Nexus does not invent zero-filled pre-launch history to make the window look older.
24-hour activity stays live and precise. Longer headline totals grow only from real daily telemetry, with 30-day comparison enabled after enough history exists.
The page is deliberately strict about language. A large number is useful only when the label still describes what Nexus actually recorded.
Nexus actively restricted or neutralized activity. Red accents are reserved for real containment and high-pressure moments.
The request was rejected by an early protection layer before normal WordPress execution, reducing avoidable application work.
Reconnaissance and credential pressure that Nexus recorded as security-relevant. Observation does not automatically mean correlation, compromise or enforcement.
Nexus PRO contributes compact aggregate security telemetry in background batches. The public Pulse receives only sanitized totals prepared by the Controller.
Participating Nexus installations contribute carefully selected security evidence and receive fresh network intelligence while enforcement remains local to each protected site.
Network observations are evaluated with contributor independence and freshness rather than treating raw report volume as consensus.
Qualifying evidence and aggregate telemetry are delivered outside visitor requests, with retry and back-pressure behavior designed to avoid slowing protected websites.
Downloaded intelligence adds context to local Nexus decisions. A temporary network-service outage does not turn the cloud into a synchronous dependency.
Threat Network intelligence is included with an active Nexus PRO licence.