[WordPress] 外掛分享: WP Ghost (Hide My WP Ghost) – Security & Firewall

首頁外掛目錄 › WP Ghost (Hide My WP Ghost) – Security & Firewall
WordPress 外掛 WP Ghost (Hide My WP Ghost) – Security & Firewall 的封面圖片
100,000+
安裝啟用
★★★★
4.5/5 分(369 則評價)
剛更新
最後更新
67%
問題解決
WordPress 5.3+ PHP 7.0+ v5.5.02 上架:2016-06-30

內容簡介

WP Ghost (前稱 Hide My WP Ghost) 是一款專業級的 WordPress 安全解決方案,旨在預防駭客攻擊。透過多層安全架構,WP Ghost 能有效阻擋駭客機器人和自動掃描器,保護網站不受未經授權的訪問。

【主要功能】
• 路徑安全與架構加固
• 阻擋暴力破解攻擊
• 中和 SQL 注入與 XSS 攻擊
• 隱藏管理工具列與元標籤
• 自訂登錄與登出重定向
• 提供超過 65 項免費安全功能

外掛標籤

開發者團隊

⬇ 下載最新版 (v5.5.02) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「WP Ghost (Hide My WP Ghost) – Security & Firewall」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

WP Ghost (formerly known as Hide My WP Ghost) is a professional-grade, comprehensive hack-prevention security solution for WordPress. Built for speed and engineered for maximum defense, WP Ghost provides a multi-layered security architecture designed to block hacker bots, neutralize automated scanners, and prevent unauthorized access at the root.
While traditional security plugins are reactive (scanning for malware after the fact), WP Ghost is preventative. It implements Paths Security and Architectural Hardening to remove the “footprints” that make your site a target. If a hacker bot cannot find your admin panel or identify your tech stack, it cannot launch an exploit. We stop the hack before it starts.

WP Ghost Global Stats:

10 Million+ Monthly Brute-Force Attempts Blocked
100 Million+ Monthly Security Threats Prevented

Stop Attacks with Paths Security & Architectural Hardening
Most WordPress attacks are automated. Bots scan millions of sites per hour looking for default paths like /wp-admin or /wp-login.php to confirm a site is running WordPress. Once confirmed, they launch targeted exploits against known plugin or theme vulnerabilities.
WP Ghost breaks this cycle. By changing and securing common paths, you reduce your attack surface by up to 90%. This isn’t “obscurity”, it’s Site Hardening. We re-engineer the visible structure of your site so it is no longer a low-hanging fruit for global botnets.
Key Protections Included
WP Ghost is packed with advanced defensive mechanisms to protect your site against:

Brute Force Attacks: Blocks automated password guessing at the source.
SQL Injection & XSS: Neutralizes malicious query strings and script injections.
Zero-Day Exploits: Secures paths for plugins before patches are even released.
XML-RPC & REST API Attacks: Shuts down common remote-access entry points.
Bot Reconnaissance: Prevents “fingerprinting” that hackers use to map your site.
Spam & Scrapers: Filters malicious traffic, saving bandwidth and server load.

Over 65 Free Security Features Included
We believe professional security should be accessible to everyone. The free version of WP Ghost includes a massive suite of tools to harden your WordPress architecture.
1. Change and Secure Paths (Paths Security)

Change wp-admin & wp-login.php: Move your login to a unique URL and show a 404 error to intruders.
Change Lost Password & Register URLs: Secure all authentication entry points.
Change wp-content & wp-includes: Secure your core system folders from direct access.
Anonymize Plugins & Themes: Change visible plugin/theme paths so hackers can’t identify your software version.
Secure admin-ajax.php & REST API: Change the /wp-json path to prevent data scraping.
Custom Redirects: Set unique login/logout redirects based on user roles.

2. Next-Gen Firewall & Authentication

8G & 7G Firewall Filters: High-speed, lightweight server-edge filtering to block bad bots.
Passkey Authentication (Passwordless 2FA): Use Face ID, Touch ID, or Windows Hello for un-phishable, device-based logins.
Standard 2FA (Code & Email): Add an extra verification layer to all user accounts.
Security Headers: Automatically implement CSP, HSTS, X-Frame-Options, and more.
IP & User Agent Blocking: Manually blacklist suspicious traffic or referrers.

3. Deep Hiding & Footprint Removal

Scrub Meta Tags: Remove WordPress version numbers and generator tags.
Clean HTML Comments: Strip identifiable comments that reveal your tech stack.
Hide Admin Toolbar: Remove the toolbar for specific roles to hide backend indicators.
Disable Emoticons & RSD: Remove unnecessary header links that bloat code and reveal info.

4. Advanced Disable Options

Disable XML-RPC: Shut down the most common vector for DDoS and brute force.
Disable REST API Access: Restrict API access to authenticated users only.
Frontend Lockdown: Disable right-click, “View Source,” and text selection to prevent manual reconnaissance.
Disable Directory Browsing: Ensure your server folders are never visible to the public.

5. Brute Force Protection

Integrated ReCaptcha: Supports Google V2, V3, Enterprise, and Math ReCaptcha.
Targeted Protection: Enable brute force defense on Login, Signup, and WooCommerce pages.
Custom Throttling: Define your own lockout times and attempt limits.

6. Extra Tools & Integrations

Magic Links: Log in securely without a password via a one-time email link.
Text & URL Mapping: Change any class name or URL in your source code dynamically.
CDN & Cache Support: Works perfectly with WP Rocket, Cloudflare, and Litespeed.

Premium Hack-Prevention Features
For agencies and high-traffic sites, WP Ghost Premium adds over 80 advanced features focused on Security Intelligence and Automated Response.

Advanced File Hardening: Secure sensitive files like wp-config.php, php.ini, and debug.log.
IP Block Automation: Proactively and automatically block repeat offenders at the firewall.
Security Threats Monitoring: A professional dashboard to track every blocked scan and exploit.
User Events Cloud Log: Optional 30-day cloud storage for auditing user activity and detecting internal threats.
Real-time Email Alerts: Get notified instantly of brute-force attempts or suspicious activity.
Geo-Security (Country Blocking): Block entire countries known for high malicious traffic.
Priority Support: Direct access to our security experts and founder-led assistance.

Hide My WP Premium Feature
Technical Compatibility
WP Ghost is engineered for the modern WordPress ecosystem:

Hosting Support: Optimized for WP Engine, Inmotion Hosting, Hostgator Hosting, Godaddy Hosting, Host1plus, Payperhost, Fastcomet, Dreamhost, Bitnami Apache, Bitnami Nginx, Google Cloud Hosting, Amazon AWS Lightsail, Litespeed Hosting, Flywheels Hosting, Kinsta Hosting, Ploi.io, CloudPanel, RunCloud, Rocket Domain, Yunohost.
Server Support: Fully compatible with Nginx, Apache, LiteSpeed, and IIS.
Plugin Support: Seamless integration with Woocommerce, WPML, WPMUDEV, W3 Total Cache, Gravity, WP Super Cache, WP Fastest Cache, Hummingbird Cache, Cachify Cache, Litespeed Cache, SiteGround Optimizer, Nitropack, Cache Enabler, CDN Enabler, WOT Cache, Autoptimize, Jetpack by WordPress, Contact Form 7, bbPress, Manage WP, All In One SEO, Rank Math, Yoast SEO, Squirrly SEO, WP-Rocket, Minify HTML, Solid Security, Sucuri Security, Really Simple SSL, WordFence Security, WP Cerber Security, BBQ Firewall, Anti-Malware Security, Back-Up WordPress, Elementor Page Builder, Divi Builder, Weglot Translate, AddToAny Share Btn, Limit Login Attempts Reloaded, Loginizer, Shield Security, Asset CleanUp, WP Hide & Security Enhancer, and more.

Stop the hack before it starts. Join over 100,000 users who trust WP Ghost to secure their digital presence.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon