
內容簡介
CoxWall 是一款強大且輕量的 WordPress 安全外掛,旨在保護您的網站免受現代安全威脅、暴力破解攻擊、惡意軟體和未經授權的訪問。它提供先進的安全工具,讓您的網站在實時中保持安全。
【主要功能】
• 登入保護:限制每個 IP 的登入嘗試次數
• 隱藏登入:移動登入 URL 遠離預設的 wp-login.php
• CAPTCHA:在登入、註冊和 WooCommerce 表單上使用 Google reCAPTCHA
• 防火牆:阻擋 SQLi、XSS 和惡意機器人
• 安全標頭:設置 X-Frame-Options、CSP 和 HSTS
• 檔案完整性:檢測 WordPress 核心和外掛檔案的變更
外掛標籤
開發者團隊
原文外掛簡介
CoxWall is a powerful and lightweight WordPress security plugin designed to protect your website from modern security threats, brute-force attacks, malware attempts, and unauthorized access.
It provides advanced security tools including firewall protection, login hardening, security headers, file integrity monitoring, WooCommerce security, and detailed audit logging — all in an easy-to-use interface.
Whether you run a blog, business website, membership platform, or WooCommerce store, CoxWall helps keep your WordPress site secure and protected in real time.
Key Features:
Login Protection – Limit login attempts per IP, lock out attackers, and receive email alerts.
Hide Login – Move your login URL away from the default wp-login.php.
CAPTCHA – Google reCAPTCHA v2 / v3 on login, registration, and WooCommerce forms.
Firewall – Block SQLi, XSS, directory traversal, malicious bots, and XML-RPC abuse.
Security Headers – Set X-Frame-Options, CSP, HSTS, Referrer-Policy, and more.
File Integrity – Detect changes to WordPress core and plugin files.
WooCommerce – Extra security for WooCommerce stores.
Audit Log – Full event log with IP, user, and timestamp for every security event.
Login History – Track successful and failed login attempts with user, IP, browser, device, and login time details.
Why Choose CoxWall?
Lightweight and performance-friendly
Beginner-friendly setup
Modern security protection
WooCommerce compatible
Advanced firewall system
Detailed security logging
Real-time protection and monitoring
CoxWall helps you secure your WordPress website with enterprise-level protection while keeping the setup simple and user-friendly.
Features:
Login Protection
Hide Login URL
Google reCAPTCHA v2 / v3
Firewall Protection
SQL Injection (SQLi) Blocking
XSS Attack Protection
Directory Traversal Protection
Malicious Bot Blocking
XML-RPC Protection
Security Headers Management
Content Security Policy (CSP)
HSTS Support
Referrer Policy Protection
File Integrity Monitoring
Core File Change Detection
Plugin File Change Detection
WooCommerce Security
Audit Log System
IP Activity Logging
User Activity Tracking
Real-time Security Alerts
Email Notifications
Brute-force Protection
Login Attempt Limiting
IP Lockout System
Malware Defense
Website Hardening
Real-time Monitoring
WordPress Security Suite
External services
This plugin optionally connects to the following third-party / external services. Each service is only contacted when its corresponding module is enabled and the described conditions are met.
Google reCAPTCHA (Google LLC)
What it is and what it is used for:
Google reCAPTCHA is a bot-detection service. CoxWall uses it to protect the WordPress login, registration, lost-password, comment, and WooCommerce My Account forms from automated attacks.
What data is sent and when:
When the CAPTCHA module is enabled, two types of requests are made to Google:
Front-end (page load) – the visitor’s browser loads the reCAPTCHA JavaScript library directly from Google’s CDN (www.google.com). Google receives the visitor’s IP address, browser and device information, and the site’s public reCAPTCHA site key.
Back-end (form submission) – when a visitor submits a protected form, the plugin sends the reCAPTCHA response token, the site’s secret key, and the visitor’s IP address to Google’s verification endpoint (www.google.com/recaptcha/api/siteverify) to confirm the response is valid.
No data is sent if the CAPTCHA module is disabled or if no reCAPTCHA site/secret key has been configured.
Service provider links:
* Terms of Service: https://policies.google.com/terms
* Privacy Policy: https://policies.google.com/privacy
* reCAPTCHA-specific information: https://developers.google.com/recaptcha
WordPress.org Core Checksums API (WordPress.org)
What it is and what it is used for:
The WordPress.org Checksums API provides official MD5 hashes for every file in each WordPress core release. CoxWall’s File Integrity module uses these hashes to detect unauthorized modifications to core files.
What data is sent and when:
When a file integrity scan runs (manually triggered or on schedule), the plugin sends a GET request to https://api.wordpress.org/core/checksums/1.0/ containing:
The installed WordPress version number.
The site’s configured locale/language.
No personal data, user data, or site content is transmitted. The request retrieves a publicly available checksum list.
Service provider links:
* Privacy Policy: https://wordpress.org/about/privacy/
* API documentation: https://codex.wordpress.org/WordPress.org_API
Privacy Policy
CoxWall uses Appsero SDK to collect some telemetry data upon user’s confirmation. This helps us to troubleshoot problems faster & make product improvements.
Appsero SDK does not gather any data by default. The SDK only starts gathering basic telemetry data when a user allows it via the admin notice. We collect the data to ensure a great user experience for all our users.
Integrating Appsero SDK DOES NOT IMMEDIATELY start gathering data, without confirmation from users in any case.
Learn more about how Appsero collects and uses this data.
