[WordPress] 外掛分享: Flex Website Security

首頁外掛目錄 › Flex Website Security
WordPress 外掛 Flex Website Security 的封面圖片
全新外掛
安裝啟用
尚無評分
11 天前
最後更新
問題解決
WordPress 6.2+ PHP 7.4+ v1.2.3 上架:2026-09-01

內容簡介

Flex Website Security 是一款輕量級的安全加固工具,旨在減少常見的攻擊面,包括暴力登入、XML-RPC 濫用和用戶枚舉。它提供多種防護措施,提升網站的安全性。

【主要功能】
• 限制登入失敗次數,提供即時解鎖功能
• 永久封鎖或解除封鎖 IP
• 按國家限制訪問權限
• 自訂登入網址並隱藏 wp-admin
• 支援 Cloudflare Turnstile 或 Google reCAPTCHA
• 隱藏 WordPress 版本與用戶枚舉防護

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.2.3) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Flex Website Security」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Flex Website Security is a lightweight hardening toolkit — not a full WAF or malware scanner. It reduces common attack surfaces: brute-force logins, XML-RPC abuse, user enumeration, and loose admin defaults.

Limit failed login attempts, with a lockout list you can unblock immediately
Permanently block or unblock IPs
Restrict by country: Allow from or Restrict from, on the whole site or admin only
Custom login URL and hide wp-admin for guests
Optional Cloudflare Turnstile or Google reCAPTCHA on login forms
Login honeypot and generic login errors
Disable XML-RPC and the theme/plugin file editor
Hide WordPress version
Block user enumeration
Basic security headers (HSTS is left to Flex SSL)

Admin CSS and JavaScript ship with the plugin. Remote scripts and API calls run only when you enable captcha or the optional country lookup.
Privacy
IP lockouts and permanent blocks are stored in your WordPress database. Only administrators can view or change them on Flex Website Security → Access.
Captcha (off by default): if you choose Cloudflare Turnstile or Google reCAPTCHA and save both keys, the login form loads that provider’s script and sends the visitor IP plus the captcha token to the provider for verification.
Country lookup (off by default): country rules first use CDN headers (Cloudflare, CloudFront, and similar). If you enable the optional geojs.io lookup, public visitor IPs without a header are sent to geojs.io and cached for 7 days.
See Third-party services below for URLs, terms, and privacy policies.
Third-party services
These services are optional and off by default. No third-party script is loaded unless you choose a captcha provider and save both keys, or you enable the geojs.io lookup.
Cloudflare Turnstile
When enabled, the login form loads https://challenges.cloudflare.com/turnstile/v0/api.js and verifies tokens at https://challenges.cloudflare.com/turnstile/v0/siteverify. Cloudflare receives the visitor IP and token.

Service: https://www.cloudflare.com/application-services/products/turnstile/
Terms: https://www.cloudflare.com/website-terms/
Privacy: https://www.cloudflare.com/privacypolicy/

Google reCAPTCHA
When enabled, the login form loads https://www.google.com/recaptcha/api.js and verifies tokens at https://www.google.com/recaptcha/api/siteverify. Google receives the visitor IP and token.

Service: https://www.google.com/recaptcha/about/
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy

geojs.io
When enabled on Access, visitor IPs without a CDN country header are looked up at https://get.geojs.io/v1/ip/country/{ip} and cached for 7 days.

Service: https://www.geojs.io/
Terms / privacy: https://www.geojs.io/

License
Flex Website Security is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version.
For more details, see https://www.gnu.org/licenses/gpl-2.0.html.

延伸相關外掛

文章
Filter
Mastodon