[WordPress] 外掛分享: Fuerte-WP | WordPress Security, Auto-Updates and Admin Control

首頁外掛目錄 › Fuerte-WP | WordPress Security, Auto-Updates and Admin Control
WordPress 外掛 Fuerte-WP | WordPress Security, Auto-Updates and Admin Control 的封面圖片
100+
安裝啟用
尚無評分
14 天前
最後更新
問題解決
WordPress 6.5+ PHP 8.2+ v1.11.4 上架:2021-08-26

內容簡介

Fuerte-WP 是一款專為 WordPress 提供安全性、更新管理及管理控制的外掛,能有效防範供應鏈攻擊及惡意更新,確保網站安全無虞。它特別適合代理商、電子商務商店及任何需要管理 WordPress 網站的使用者。

【主要功能】
• 更新管理:提供多種更新模式以應對不同需求
• 管理監控:增強管理員的監控能力
• 登入安全:加強網站登入的安全性
• 雙重身份驗證:提供額外的安全層級
• 阻擋更新:凍結外掛或佈景主題的更新

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.11.4) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Fuerte-WP | WordPress Security, Auto-Updates and Admin Control」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

🛡️ WordPress Security and Maintenance That Prevents Problems Before They Happen
Every day, WordPress sites are compromised through supply chain attacks. A trustworthy plugin developer has their account hacked, malicious code ships as an “update”, and thousands of sites auto-install it within hours. Fuerte-WP protects your site when developers cannot protect their own update systems.
Fuerte-WP combines four defenses in one lightweight plugin: update management, admin oversight, login security, and two-factor authentication. It is built for agencies, e-commerce stores, and anyone who manages WordPress sites and needs to sleep at night.
🚨 CRITICAL: SUPPLY CHAIN ATTACK AND MALICIOUS UPDATE PROTECTION
A supply chain attack happens when an attacker compromises a developer account and pushes a malicious update that thousands of sites auto-install before anyone notices. When you learn an attack is in progress, you need to act in minutes, not days.
Fuerte-WP gives you three update modes so you can react correctly:

Scheduled Updates: choose how often WordPress checks for and applies updates. Options are 6, 12, 24, or 48 hours. Slower cycles give you a review window. Faster cycles keep client sites current.
Deferred Updates: keep a plugin out of auto-updates while still letting you update it manually. Useful when you want to test a release on staging before it reaches production.
Blocked Updates: completely freeze a plugin or theme. Neither WordPress nor manual clicks can update it. This is the supply chain defense. When a developer account is compromised, you block the plugin at its last known safe version and wait until the all-clear.

This is not a generic “disable updates” toggle. Deferred and Blocked are separate, intentional controls, so you can hold one compromised plugin back while the rest of the site keeps updating normally.
⚡ AUTO-UPDATE MANAGEMENT FOR CORE, PLUGINS, THEMES, AND TRANSLATIONS
Granular control over every update channel:

WordPress core auto-updates (on or off)
Plugin auto-updates (on or off, with per-plugin defer and block)
Theme auto-updates (on or off, with per-theme defer and block)
Translation auto-updates (on or off)
Update check frequency: 6, 12, 24, or 48 hours
Zero performance impact: all checks run in the background through a dedicated cron event. Page load times are unaffected.

You can configure this once on your main site and reuse the same file-based configuration across every site you manage.
👑 ADMINISTRATOR OVERSIGHT AND ACCESS CONTROL
Most WordPress security plugins assume the administrator is the threat. Fuerte-WP assumes the administrator is trusted but busy, and that you want to protect them from themselves and from each other.

Super User Access: designate one or more super users by email. Super users bypass every restriction and are the only accounts that can change Fuerte-WP settings or disable the plugin.
Restrict Other Administrators: prevent non-super administrators from installing unstable plugins, editing theme and plugin code, changing permalinks, or touching sensitive WordPress settings.
Hide and Block Admin Menus: a searchable, discovery-driven interface lists every registered admin menu, submenu, and admin-bar node on your site. You select what to hide. Hide and block are unified: hiding a page also blocks direct URL access to it. A manual textarea stays available as a precision escape hatch for slugs the discovery scan does not surface.
Smart Block Targeting: the block engine avoids over-blocking. Shared scripts like edit.php (Posts, Pages, and custom post types) and index.php are hide-only so you never strand a non-super user on a blank screen. Single-purpose core scripts (themes.php, tools.php, plugins.php) block by $pagenow. Plugin pages block by their ?page= query argument.
Account Protection: protect your own admin account from being modified or deleted by another administrator.

🔒 LOGIN SECURITY (OPTIONAL, ON BY DEFAULT)
Brute force attacks against wp-login.php and XML-RPC are the most common way WordPress sites are compromised. Fuerte-WP ships with a full login hardening suite:

Rate Limiting and Brute Force Protection: block an IP address after too many failed login attempts. Progressive penalties apply to repeat offenders.
Lockout Protection: escalating lockout windows for repeated security violations.
Hide Login URL / Custom Login URL: move your login page away from the default wp-login.php and wp-admin paths so automated bots that scan for those endpoints find nothing. Your real login URL is whatever you choose.
Real-Time Monitoring: a live dashboard shows login attempts, lockouts, and security events.
Registration Protection: control who can register and from which IP ranges.

🔐 TWO-FACTOR AUTHENTICATION (2FA) FOR ADMINS
Since version 1.10.0, Fuerte-WP bundles the official WordPress Two-Factor library and enforces a safe provider policy:

Email codes (default for enforced admins)
Authenticator app / TOTP (Time-based One-Time Password, Google Authenticator, Authy, 1Password, etc.)
Recovery / backup codes
The insecure Dummy Method is stripped site-wide, even under WP_DEBUG.

Enforce 2FA for Administrators is on by default. Administrators and Super Admins are challenged with an emailed code at login even before they set up an authenticator app. Each admin can switch to TOTP from their own profile page. Enforcement is read-only: it never writes to user meta, so unchecking the box releases admins immediately. Fuerte super users always bypass enforcement.
Crash-safe coexistence: if you already run the standalone Two-Factor plugin, Fuerte-WP detects it and steps aside. No class-redeclare fatal, no duplicate provider screens.
Operator escape hatch: define FUERTEWP_DISABLE_2FA in wp-config.php to skip the bundled library entirely.
🛠 REST API, XML-RPC, AND APP PASSWORD HARDENING
Modern WordPress exposes several attack surfaces beyond the login form:

Disable Application Passwords site-wide (on by default)
Disable the XML-RPC API (on by default), removing the pingback vector and brute force amplification
Disable weak passwords during user creation and password reset
REST API and authentication filters centralized so you can lock down application access without editing code

📧 EMAIL CONTROLS AND RECOVERY
WordPress sends a lot of email. Fuerte-WP lets you redirect and silence it:

Rewrite the sender address and name on every outgoing wp_mail() (falls back to no-reply@ when left empty)
Redirect Recovery Mode and fatal-error emails to a monitored address
Toggle individual notifications: fatal errors, automatic updates, comment moderation, comment publication, password resets, personal-data export requests, new-user creation

🌐 MULTISITE, PERFORMANCE, AND DEVELOPER FRIENDLINESS

Multisite compatible: network-activate for centralized management across every site on the network
Self-protecting: non-super users cannot disable Fuerte-WP or change its settings
Performance optimized: background cron processing, no per-request overhead
File-based configuration: define $fuertewp in wp-config-fuerte.php for mass deployment. File config wins over the database, so the same settings ship to every site without touching the admin UI
Translation ready: ships with Spanish (es_CL / es_ES); contribute more via translate.wordpress.org

🔧 HOW FUERTE-WP WORKS
Fuerte-WP follows a single-source-of-truth model. Configuration lives in one normalized array and is read the same way everywhere:

Load: a transient-cached config loader checks a wp-config-fuerte.php file first, then falls back to the database option saved by the admin UI. File always wins.
Enforce: a singleton enforcer applies every restriction, login rule, and update policy from that normalized array.
Recover: super users (matched by email, case-insensitive) bypass restrictions. Define FUERTEWP_FORCE to enforce even on super users, or FUERTEWP_DISABLE to switch the whole plugin off without uninstalling.

Because the enforcer reads one normalized array, there is no drift between what the admin UI shows and what the site enforces. After editing config logic in code, bust the transient with delete_transient('fuertewp_config') so the new rules take effect.
📁 FILE-BASED CONFIGURATION FOR MASS DEPLOYMENT
For agencies and platform teams, Fuerte-WP can be configured entirely from a file, with no admin UI clicks. Drop a wp-config-fuerte.php file in your ABSPATH directory defining a $fuertewp array:
`

array( ‘sender_email_enable’ => true ),
‘super_users’ => array( ‘[email protected]’ ),
‘auto_updates’ => array(
‘core’ => true, ‘plugins’ => true, ‘themes’ => true,
‘translations’ => true, ‘frequency’ => ’12h’,
),
‘restrictions’ => array(
‘disable_theme_editor’ => true,
‘disable_plugin_editor’ => true,
‘restapi_disable_app_passwords’ => true,
‘disable_xmlrpc’ => true,
),
‘login_security’ => array( ‘login_security_enable’ => true, ‘two_factor_enable’ => true ),
);
`
Commit this file to your deployment pipeline and every site in your fleet ships the same security baseline. The admin UI still renders for inspection, but saved values never override the file. This is the recommended path for WordPress multisite networks and managed-hosting platforms.
📋 SECURITY HARDENING CHECKLIST
Fuerte-WP ships with safe defaults so a fresh install is already hardened. The following are on by default and can be toggled on the Restrictions and Login Security tabs:

Disable the Theme Editor and Plugin Editor (prevents code injection from the admin)
Disable Theme Install and Plugin Install (prevents untrusted uploads)
Disable the Customizer CSS Editor
Restrict access to Permalinks and Advanced Custom Fields
Disable Application Passwords and the XML-RPC API
Disable weak passwords
Enable login security, brute force protection, and registration protection
Enforce two-factor authentication for administrators
Send fatal-error and recovery-mode emails to a monitored address

Review the Restrictions tab after your first install and adjust to your workflow.
🎯 PERFECT FOR:

Agencies managing many client WordPress websites
E-commerce and WooCommerce stores that require maximum uptime
Educational institutions and universities running WordPress multisite networks
Enterprise and government deployments needing strict maintenance and change-control policies
Developers who want a reproducible, file-driven security baseline
Anyone serious about WordPress security, login protection, and update reliability

⚡ INSTALL IN SECONDS, PROTECT FOR YEARS

Install and activate Fuerte-WP
Add yourself as a super user (by email)
Configure your auto-update preferences and login security
Your site is now protected from supply chain attacks, brute force login attempts, and accidental admin changes

延伸相關外掛

文章
Filter
Mastodon