[WordPress] 外掛分享: WP Ghost (Hide My WP Ghost) – Security & Firewall

首頁外掛目錄 › WP Ghost (Hide My WP Ghost) – Security & Firewall
WordPress 外掛 WP Ghost (Hide My WP Ghost) – Security & Firewall 的封面圖片
100,000+
安裝啟用
★★★★
4.5/5 分(371 則評價)
16 天前
最後更新
78%
問題解決
WordPress 5.8+ PHP 7.4+ v7.0.01 上架:2016-06-30

內容簡介

WP Ghost 是一款專業級的 WordPress 安全解決方案,專注於防止駭客攻擊。透過多層次的安全架構,WP Ghost 能有效阻擋駭客機器人和自動掃描器,並在攻擊發生前進行防護,確保網站安全。

【主要功能】
• 阻擋暴力破解攻擊
• 中和 SQL 注入與 XSS 攻擊
• 保護零日漏洞
• 改變並加固常見路徑
• 實施網站硬化技術

外掛標籤

開發者團隊

⬇ 下載最新版 (v7.0.01) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「WP Ghost (Hide My WP Ghost) – Security & Firewall」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

WP Ghost (formerly known as Hide My WP Ghost) is a professional-grade, comprehensive hack-prevention security solution for WordPress. Built for speed and engineered for maximum defense, WP Ghost provides a multi-layered security architecture designed to block hacker bots, neutralize automated scanners, and stop the hack before the reconnaissance even begins.
While traditional security tools focus on Detection (scanning for malware after a breach) or Signature-Filtering (blocking known exploits), WP Ghost focuses on Architecture. By implementing Paths Security and Site Hardening, we remove the digital footprints that make your site a target for automated botnets, providing a proactive foundation that secures your site before it can even be identified as a target.

WP Ghost Global Stats:

10 Million+ Monthly Brute-Force Attempts Blocked
100 Million+ Monthly Security Threats Prevented

Official websites:
WP Ghost (wpghost.com)
Hide My WP Ghost (hidemywpghost.com)
Stop Attacks with Paths Security & Architectural Hardening
Most WordPress attacks are automated. Bots scan millions of sites per hour looking for default paths like /wp-admin or /wp-login.php to confirm a site is running WordPress. Once confirmed, they launch targeted exploits against known plugin or theme vulnerabilities.
WP Ghost breaks this cycle. By changing and securing common paths, you reduce your attack surface by up to 90%. This isn’t “obscurity”, it’s Site Hardening. We re-engineer the visible structure of your site so it is no longer a low-hanging fruit for global botnets.
Key Protections Included
WP Ghost is packed with advanced defensive mechanisms to protect your site against:

Brute Force Attacks: Blocks automated password guessing at the source.
SQL Injection & XSS: Neutralizes malicious query strings and script injections.
Zero-Day Exploits: Secures paths for plugins before patches are even released.
XML-RPC & REST API Attacks: Shuts down common remote-access entry points.
Bot Reconnaissance: Prevents “fingerprinting” that hackers use to map your site.
Spam & Scrapers: Filters malicious traffic, saving bandwidth and server load.

Over 115 Free Security Features Included
We believe professional security should be accessible to everyone. The free version of WP Ghost includes a massive suite of tools to harden your WordPress architecture.
1. Change and Secure Paths (Paths Security)

Change wp-admin & wp-login.php: Move your login to a unique URL and show a 404 error to intruders.
Change Lost Password & Register URLs: Secure all authentication entry points.
Change wp-content & wp-includes: Secure your core system folders from direct access.
Anonymize Plugins & Themes: Change visible plugin/theme paths so hackers can’t identify your software version.
Secure admin-ajax.php & REST API: Change the /wp-json path to prevent data scraping.
Security Presets: One-click activation with three preset levels — from minimal to full protection with Firewall, Brute Force, Logs, and 2FA.
Frontend Test: Verify your site loads correctly after changing paths before confirming settings.
Custom Redirects: Set unique login/logout redirects based on user roles.
Login Page Designer: Customize your secured login page with your logo, colors, background, and 10 color schemes.

2. Next-Gen Firewall & Authentication

8G & 7G Firewall Filters: High-speed, lightweight server-edge filtering to block bad bots.
Passkey Authentication (Passwordless 2FA): Use Face ID, Touch ID, or Windows Hello for un-phishable, device-based logins.
Standard 2FA (Code & Email): Add an extra verification layer to all user accounts.
Security Headers: Automatically implement CSP, HSTS, X-Frame-Options, and more.
IP & User Agent Blocking: Manually blacklist suspicious traffic or referrers.
Security Threats Log: Track blocked attacks and malicious requests directly in your dashboard (limited view).
User Events Log: Monitor login activity, role changes, and user actions (limited view).
GEO Threats Map: Visualize where attacks originate with an interactive world map showing the top 5 threat countries.
Security Optimization Score: Real-time 0-100 score showing exactly how hardened your site is, with actionable recommendations.
Temporary Logins: Create time-limited access links for developers and clients without sharing passwords.

3. Deep Hiding & Footprint Removal

Scrub Meta Tags: Remove WordPress version numbers and generator tags.
Clean HTML Comments: Strip identifiable comments that reveal your tech stack.
Hide Admin Toolbar: Remove the toolbar for specific roles to hide backend indicators.
Disable Emoticons & RSD: Remove unnecessary header links that bloat code and reveal info.

4. Advanced Disable Options

Disable XML-RPC: Shut down the most common vector for DDoS and brute force.
Disable REST API Access: Restrict API access to authenticated users only.
Frontend Lockdown: Disable right-click, “View Source,” and text selection to prevent manual reconnaissance.
Disable Directory Browsing: Ensure your server folders are never visible to the public.

5. Brute Force Protection

Integrated ReCaptcha: Supports Google V2, V3, Enterprise, and Math ReCaptcha.
Targeted Protection: Enable brute force defense on Login, Signup, and WooCommerce pages.
Custom Throttling: Define your own lockout times and attempt limits.

6. Extra Tools & Integrations

Magic Links: Log in securely without a password via a one-time email link.
Text & URL Mapping: Change any class name or URL in your source code dynamically.
CDN & Cache Support: Works perfectly with WP Rocket, Cloudflare, and Litespeed.

Premium Hack-Prevention Features
For agencies and high-traffic sites, WP Ghost Premium adds advanced features focused on Security Intelligence, Automated Response, and Copyright Protection.

Ghost Mode: Maximum security preset, changes all paths, hides all file extensions, and enables all hiding options in one click.
IP Block Automation: Automatically block IP addresses that trigger repeated security threats.
AI Copyright Protection: Block 30+ AI training crawlers (GPTBot, ClaudeBot, PerplexityBot, and others) at the firewall level. List auto-updated with each release. Does not affect Google, Bing, or regular search visibility.
Full Security Threats Log: Unlimited entries with filters by threat type, status, country, and time range, full-text search, pagination, and CSV export.
Full User Events Log: Unlimited entries with filters, search, pagination, and CSV export.
Cloud Event Storage: 30-day cloud retention for audits and incident reports.
Real-time Email Alerts: Get notified instantly of brute-force attempts or suspicious activity.
Geo-Security (Country Blocking): Block entire countries or specific paths by country.
Advanced File Hardening: Hide file extensions (PHP, CSS, JS, JSON), secure wp-config.php, php.ini, and debug.log.
Database & Server Hardening: Fix file permissions, change database prefix, regenerate SALT keys.
Priority Support: Direct access to our security experts and founder-led assistance.

Hide My WP Premium Feature
Technical Compatibility
WP Ghost is engineered for the modern WordPress ecosystem:

Hosting Support: Optimized for WP Engine, Inmotion Hosting, Hostgator Hosting, Godaddy Hosting, Host1plus, Payperhost, Fastcomet, Dreamhost, Bitnami Apache, Bitnami Nginx, Google Cloud Hosting, Amazon AWS Lightsail, Litespeed Hosting, Flywheels Hosting, Kinsta Hosting, Ploi.io, CloudPanel, RunCloud, Rocket Domain, Yunohost.
Server Support: Fully compatible with Nginx, Apache, LiteSpeed, and IIS.
Plugin Support: Seamless integration with Woocommerce, WPML, WPMUDEV, W3 Total Cache, Gravity, WP Super Cache, WP Fastest Cache, Hummingbird Cache, Cachify Cache, Litespeed Cache, SiteGround Optimizer, Nitropack, Cache Enabler, CDN Enabler, WOT Cache, Autoptimize, Jetpack by WordPress, Contact Form 7, bbPress, Manage WP, All In One SEO, Rank Math, Yoast SEO, Squirrly SEO, WP-Rocket, Minify HTML, Solid Security, Sucuri Security, Really Simple SSL, WordFence Security, WP Cerber Security, BBQ Firewall, Anti-Malware Security, Back-Up WordPress, Elementor Page Builder, Divi Builder, Weglot Translate, AddToAny Share Btn, Limit Login Attempts Reloaded, Loginizer, Shield Security, Asset CleanUp, WP Hide & Security Enhancer, and more.

Stop the hack before it starts. Join over 100,000 users who trust WP Ghost to secure their digital presence.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon