[WordPress] 外掛分享: DecaGuard — Compromise Detection for WooCommerce

首頁外掛目錄 › DecaGuard — Compromise Detection for WooCommerce
WordPress 外掛 DecaGuard — Compromise Detection for WooCommerce 的封面圖片
全新外掛
安裝啟用
尚無評分
2 天前
最後更新
問題解決
WordPress 6.0+ PHP 7.4+ v0.2.0 上架:2026-08-28

內容簡介

DecaGuard 是一款專為 WooCommerce 商店設計的安全外掛,能夠偵測異常變更,幫助商店擁有者在遭受駭客攻擊前及早發現問題,保護商店的資金與顧客資料。

【主要功能】
• 偵測不明檔案與變更
• 監控管理員帳號異常
• 追蹤外部代碼執行情況
• 提供清晰的變更報告
• 不干預商店運作

外掛標籤

開發者團隊

⬇ 下載最新版 (v0.2.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「DecaGuard — Compromise Detection for WooCommerce」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Most shop owners find out they have been hacked when their payment provider tells
them, or when a customer complains about a fraudulent charge. By then the damage
is done.
DecaGuard learns what your shop normally looks like, then watches for anything
that changes without your say-so: files appearing where files should not appear,
new administrator accounts, hidden add-ons, settings that quietly gained code in
them, and outside companies that started running code on your pages.
When it finds something, it explains what happened in ordinary language — what
the risk is to your money and your customers, and what to do next. If the change
was you, one click marks it as expected and you never hear about it again.
It watches. It does not touch anything.
DecaGuard never blocks, deletes, quarantines, modifies, or repairs anything on
your shop. It is not a firewall, it does not sit between your customers and your
pages, and it never touches your checkout, your payment gateway callbacks, or the
WooCommerce API.
This is deliberate. Real compromises leave several ways back in. Automated
cleanup either misses one — leaving you confidently reinfected — or deletes
something your shop needs and takes it offline. Both are worse than a clear
warning and a decision you make yourself.
What it looks at

Your files. Program files appearing in your uploads folder, code hidden
inside images, changes to WordPress’s own files (checked against the official
published list), and changes to your main settings file.
Your database. Web addresses hidden in your shop’s settings, scheduled
tasks that no add-on owns, and tasks that quietly fetch instructions from
outside.
Your accounts. New administrators, accounts that gained powers they did not
have, and — importantly — accounts or add-ons that have been hidden from your
own lists. Nothing legitimate hides from you.
Code running on your pages. Which outside companies run code on your shop,
when one of them quietly changes what it sends you, and web addresses that are
near-identical imitations of ones you trust.

Built to be quiet
A security tool that cries wolf gets switched off, and then it protects nobody.
DecaGuard spends its first two days simply learning your shop and raising
nothing at all. It knows that add-on updates change files constantly, that
payment gateways send odd-looking data, and that bulk imports look like attacks.
Findings are graded, and anything you confirm as expected stays quiet for good.
What this plugin sends outside your site
DecaGuard makes a small number of outbound requests, all of them listed here:

api.wordpress.org — downloads the official checksum list for your exact
WordPress version, so modified core files can be spotted. No information about
your site is sent; only the version number and language are in the request.
Your own shop’s public pages — the plugin requests your homepage, cart page
and one product page, exactly as a visitor’s browser would, to see what code
runs on them. These requests never leave your own server.

Files your pages already load from other companies — if one of your pages
loads a file from, say, a payment provider or a chat widget, the plugin
downloads that same file and compares it with what it saw last time. This is
what lets it tell you when a company you rely on quietly changes the code it
runs on your shop, which is how several large 2026 attacks worked.
The request is anonymous: it identifies the plugin and nothing else. Your
address, your shop’s name, your customers and your orders are not part of it,
and no data is sent anywhere — the plugin only downloads. Only addresses that
already appear in your own pages are ever requested.
If you would rather it did not, switch off Outside code under
DecaGuard → Settings. Every other check carries on working.
No customer data, order data, or personal information ever leaves your site.

延伸相關外掛

文章
Filter
Mastodon