GitHub Username: wobqqq
Security suite for Nova: hardens sessions, passwords and HTTPS, runs security checks and composer audit, scans for exposed files, open ports and expiring TLS, and takes add-on modules.
Aegis module: opens Nova (pages, sign-in, nova-api, tools) only to whitelisted IPv4/IPv6 addresses and CIDR subnets, with lock-out protection and console recovery.
Aegis module: blocks listed IPv4/IPv6 addresses and CIDR subnets from the whole application (site, API and Nova), with lock-out protection and no database query per request.
Aegis module: rate-limits every IP per minute and bans abusers for hours with 429 and Retry-After, with IP and header exclusions and lock-out protection.
Aegis module: a Content-Security-Policy header for the site and Nova, edited per directive from Nova, with report-only mode, strict validation and a policy-strength check.
Aegis module: blocks XSS, template injection, command injection, path traversal, null bytes and other malicious input in query, body, headers and URL, with editable patterns.