[WordPress] 外掛分享: Dotsquares Custom Login URL & Security Suite

首頁外掛目錄 › Dotsquares Custom Login URL & Security Suite
WordPress 外掛 Dotsquares Custom Login URL & Security Suite 的封面圖片
全新外掛
安裝啟用
尚無評分
58 天前
最後更新
問題解決
WordPress 6.0+ PHP 7.4+ v1.6.4 上架:2026-02-06

內容簡介

Dotsquares Custom Login URL & Security Suite 是一款強化 WordPress 網站安全的外掛,讓使用者能夠變更預設登入 URL,並在一個精美的控制台中應用額外的安全層級,保護網站免受攻擊。

【主要功能】
• 自訂登入 URL,隱藏 wp-login.php
• 防止暴力破解攻擊,設置鎖定閾值
• 深度掃描 WordPress 核心、外掛與佈景主題
• 兩步驟驗證,支援 Google Authenticator
• 使用者會話管理,查看並終止活躍會話
• 實時安全評分,提供安全事件日誌

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.6.4) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Dotsquares Custom Login URL & Security Suite」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Dotsquares Custom Login URL & Security Suite helps secure your WordPress site by allowing you to change the default login URL and apply additional security layers — all from one beautifully designed dashboard.
🔑 Login Security

Custom login slug — redirect wp-login.php to your own secret URL
Optionally hide wp-login.php (returns 404 for guests)
Optionally block wp-admin for non-logged-in users
Brute force protection with configurable lockout thresholds
Login honeypot trap (hidden field that catches bots)
Two-Factor Authentication (TOTP — works with Google Authenticator, Authy, etc.)
Weak username detection (blocks “admin”, “root”, “test”, etc.)
Force logout after inactivity (configurable timeout)
Manual approval for new user registrations
Prevent display name from matching username

🛡️ Firewall

Disable XML-RPC (common attack vector)
Block bad bots and fake user agents (40+ known bots)
Block POST requests with empty User-Agent headers
Rate limiting per IP address
IP blacklist and whitelist (supports CIDR ranges)
Geo-blocking by country code
Restrict REST API for non-logged-in users
Prevent user enumeration via ?author= scans

🔍 Malware & File Scanner

Deep scan of WordPress core, plugins, themes and uploads
40+ malware signature patterns (PHP shells, backdoors, crypto miners, pharma hacks, SEO spam injections)
Detects known web shells by filename (c99, r57, WSO, b374k, adminer, etc.)
WordPress core file integrity check (compares against official api.wordpress.org checksums)
Detects PHP files hidden inside the uploads folder
Suspicious code pattern detection (eval, exec, base64_decode combos, etc.)
File change detection using MD5 hash baseline
File permission scanner (755/644 standards)
.htaccess security rules generator

👥 User & Session Management

View and kill active user sessions
Session tracking with IP and user-agent logging
Manual user approval workflow

📊 Monitoring & Logs

Security event log (login, logout, failed attempts, plugin/theme changes)
IP blocking log with unblock controls
Real-time security score (A–F grade with per-check breakdown)

⚙️ Other Features

Maintenance mode with custom message
Database backup download
Email alerts for security events
Beautiful admin dashboard with quick-toggle switches

Important
Hardening actions such as DB prefix change and wp-content rename are advanced operations.
Always run these features on a staging environment and ensure you have a full backup before applying them on production.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon