[WordPress] 外掛分享: Destino Access Audit

首頁外掛目錄 › Destino Access Audit
100+
安裝啟用
尚無評分
38 天前
最後更新
問題解決
WordPress 5.6+ PHP 7.4+ v1.5.0 上架:2026-07-23

內容簡介

Destino Access Audit 是一款專為 WordPress 設計的外掛,提供一個集中管理的介面,讓使用者能夠輕鬆查看誰擁有網站的存取權限及相關資訊,並能夠撤銷應用程式密碼,提升網站的安全性。

【主要功能】
• 顯示所有活躍的應用程式密碼及其詳細資訊
• 列出所有管理員帳號,方便識別不明帳號
• 提供 UpdraftPlus、MainWP Child、ManageWP Worker 等外掛的狀態資訊
• 支援 CSV 匯出功能,方便數據管理
• 每次撤銷操作均有安全保護措施

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.5.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Destino Access Audit」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Destino Access Audit adds a single admin page (Tools → Destino Access Audit) that centralizes the answer to one question: who, and what, currently has access to this site?
The page is read-only audit information except for one deliberate action — revoking an Application Password — which delegates entirely to WordPress core’s own API. Destino Access Audit never creates, modifies, or stores any remote-management connection itself.
What it shows

Application Passwords — every active Application Password on the site (all users), with creation date, last used date, last IP, and a one-click Revoke button (AJAX, no page reload) plus a CSV export.
Administrator Users — a plain list of every user with the administrator role, with a direct link to edit each one. Useful for spotting an admin account you don’t recognize.
UpdraftPlus / UpdraftCentral — whether UpdraftPlus is installed/active, a direct link to its settings screen, whether it is connected to an UpdraftCentral dashboard (including which WordPress user made that connection), and whether UpdraftPlus’s own password-protected “Lock Settings” feature is currently hiding that screen.
MainWP Child — whether MainWP Child is installed/active, a direct link to its settings screen, whether it is paired with a MainWP Dashboard, and which WordPress user established that pairing.
ManageWP Worker — installed/active status. ManageWP Worker pairs with its dashboard through an OpenSSL key exchange with no locally readable “connected” flag, so this block documents that limitation instead of guessing.
InfiniteWP Client — installed/active status, with the same honest limitation note as ManageWP Worker.
Wordfence Security — installed/active status. Wordfence Central’s connection state lives in Wordfence’s own proprietary database table, not a readable WordPress option, so this block documents that limitation instead of guessing, the same as ManageWP Worker and InfiniteWP Client.
Elementor Site Management — whether the “Manage” plugin by Elementor.com is installed/active, a direct link to its settings screen, and whether it is connected to my.elementor.com.

The connector blocks above lay out as a 2-column grid on desktop, so they’re easier to scan at a glance; Application Passwords and Administrator Users stay full-width since they contain data tables.
Security notes

Every write action (revoking a key) is protected by a nonce, a manage_options capability check, and a second capability check (edit_user) specific to the user who owns the key.
The CSV export is generated server-side and neutralizes fields that could be interpreted as spreadsheet formulas (CSV/Excel formula injection).
The dashboard itself requires the manage_options capability to view.

延伸相關外掛

文章
Filter
Mastodon