[WordPress] 外掛分享: AbilityGuard – Abilities API Monitor

首頁外掛目錄 › AbilityGuard – Abilities API Monitor
WordPress 外掛 AbilityGuard – Abilities API Monitor 的封面圖片
全新外掛
安裝啟用
尚無評分
26 天前
最後更新
問題解決
WordPress 6.9+ PHP 7.2+ v1.1.1 上架:2026-07-04

內容簡介

AbilityGuard 是一款幫助網站管理員了解和審核 WordPress Abilities API 的外掛。它提供了能力的可見性,讓管理員能夠輕鬆檢視註冊的能力、風險標記及執行日誌,確保網站的安全性與透明度。

【主要功能】
• 能力清單:查看所有註冊的 WordPress 能力
• 風險標籤:即時識別風險指標
• 執行日誌:回顧最近的能力執行
• 隱私設定:可配置的輸入輸出日誌
• 電子郵件警報:接收高風險執行通知
• CSV 匯出:匯出當前過濾的日誌視圖

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.1.1) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「AbilityGuard – Abilities API Monitor」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

AbilityGuard helps site administrators understand and audit what the WordPress Abilities API exposes on their site.
The WordPress Abilities API gives plugins, themes, AI tools, automation workflows, and other integrations a structured way to register and execute site capabilities. That is powerful, but it also creates a new visibility problem: administrators need to know which abilities are available, how those abilities are described, whether they are exposed through REST, and what executions have happened recently.
AbilityGuard adds that visibility layer. It inventories registered abilities, highlights risk-related annotations, and keeps a rolling execution log so you can review what ran, who triggered it, how it was triggered, and what data was stored.
What problem does AbilityGuard solve?
Without an inventory or audit trail, administrators may not know:

Which abilities are registered by active plugins or integrations.
Whether an ability is marked as read-only, destructive, or idempotent.
Whether an ability is exposed through REST.
Which abilities executed recently.
Which user triggered an ability execution.
Whether input or output payloads were captured for review.

AbilityGuard is designed to answer those questions from the WordPress admin area.
Features
AbilityGuard turns the WordPress Abilities API into a clear, auditable surface for site administrators. Instead of chasing capability registrations manually, you get a focused dashboard for visibility, risk review, and execution monitoring.
Core Visibility

Ability Inventory: view all registered WordPress abilities in a single, searchable inventory.
Risk Badges: instantly spot risk indicators derived from ability annotations.
Annotation Visibility: inspect read-only, destructive, and idempotent metadata at a glance.
Category & Namespace Details: see the official category, slug, and namespace used by each ability.
REST Exposure & Schema Visibility: identify abilities exposed through REST and whether input/output schemas are registered.
Current User Permission Check: confirm whether the current admin user can execute an ability with its default input.

Execution Monitoring

Execution Log: review recent ability executions with a rolling audit trail.
Log Details: inspect names, users, trigger context, status, and payload data for each event.
Trigger Context: see whether an execution came from REST, WP-CLI, cron, or PHP.
User Links: jump directly from a log entry to the related WordPress user profile when available.

Admin Controls & Privacy

Configurable Payload Logging: choose whether to capture ability input and output data.
Privacy-Conscious Defaults: output logging is disabled by default to reduce sensitive data exposure.
Configurable Log Retention: keep as many execution entries as needed, including unlimited retention.
Advanced Log Filters: narrow the activity view by status, context, risk, category, user ID, date range, or search term.
CSV Export: export the current filtered log view for reporting or review.
Saved Views: save common audit filters for fast reuse.

Operational Oversight

Sensitive Watchlist: flag important abilities for closer monitoring.
Email Alerts: receive notifications for high-risk, failed, or watched ability executions.
Scheduled Reports: send daily or weekly activity summaries by email.
Multisite Dashboard: review per-site ability and log counts from Network Admin.
Uninstall Cleanup Option: optionally remove AbilityGuard data when the plugin is uninstalled.

What AbilityGuard does not log
AbilityGuard monitors Abilities API registrations and executions. It does not replace a general WordPress activity log plugin.
For example, AbilityGuard does not automatically log normal post edits, page updates, media uploads, settings saves, WooCommerce activity, or user profile changes unless those actions are performed through a registered WordPress ability.
Privacy and data storage
AbilityGuard stores logs in a custom database table in your WordPress database. Input logging can be enabled or disabled from the settings page. Output logging is available but disabled by default because ability responses may contain sensitive or large data.
Before enabling output logging, review your site’s privacy and compliance requirements.

延伸相關外掛

文章
Filter
Mastodon