[WordPress] 外掛分享: HT Security

首頁外掛目錄 › HT Security
100+
安裝啟用
★★★★★
5/5 分(1 則評價)
36 天前
最後更新
問題解決
WordPress 6.5+ PHP 8.2+ v1.7.1 上架:2025-04-23

內容簡介

HT Security 是一款完整的 WordPress 安全套件,提供多層次的網站保護,並透過國家漏洞資料庫 (NVD) API 檢查已知的 CVE 漏洞,確保網站的安全性。

【主要功能】
• 安全標頭設定:HSTS、X-Frame-Options、Content-Security-Policy 等
• 登入警報:成功與失敗登入的電子郵件通知
• 登入驗證碼:內建 SVG 數字驗證碼或 Cloudflare Turnstile
• 核心完整性檢查:驗證 WordPress 核心檔案的官方檢查碼
• CVE 漏洞檢測:檢查 WordPress 核心及啟用的外掛
• 使用者枚舉保護:透過 REST API 阻擋使用者枚舉

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.7.1) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「HT Security」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

HT Security is a complete security suite for WordPress, offering multiple layers of protection for your website.
Important – External Service:
This plugin queries the National Vulnerability Database (NVD) API to check for known CVE vulnerabilities. Requests are made to:
* API URL: https://services.nvd.nist.gov/rest/json/cves/2.0
* Terms of Use: https://nvd.nist.gov/general/legal-disclaimer
* Privacy Policy: https://www.nist.gov/privacy-policy
* Frequency: Automatic check every 12 hours or manual on-demand
* Data sent: Name and version of WordPress/installed plugins (no personal data is sent)
The NVD API query is essential for the plugin’s CVE vulnerability detection functionality.
Key Features

Security Headers – HSTS, X-Frame-Options, Content-Security-Policy, and more
Login Alerts – Email notifications for successful and failed login attempts with rate limiting
Login Captcha – Built-in SVG numeric captcha or Cloudflare Turnstile for login, password reset, and registration forms
Core Integrity Check – Verify WordPress core files against official checksums with 24h cache
CVE Vulnerability Detection – Check WordPress Core and active plugins against NVD database
User Enumeration Protection – Block user enumeration via REST API and author parameters
Maintenance Mode – Maintenance mode with authorized IP whitelist (IPv4, IPv6, CIDR support)
File Permissions Audit – Audit and automatic correction of critical file permissions
Plugin Security Indicators – Visual badges on plugins page showing vulnerability status
Plugin Update Management – Notify when plugins need updates; optionally auto-update only selected plugins
Force Cron – Secret HTTP ping to spawn WordPress cron when official wp-cron is unreliable

CVE Detection Features

Integration with NVD (National Vulnerability Database) API 2.0
Check WordPress Core and active plugins for known vulnerabilities
Intelligent batch processing with rate limiting
8 layers of anti-false-positive validation
Vulnerability badges on plugins page (enable/disable option)
Dismissible alerts per user
Email notification when vulnerabilities are detected
Automatic check every 12 hours
NVD API Key support (increased rate limit)

Security Improvements in v1.5.0

IP Spoofing Fix – Properly detects real IP behind Cloudflare, proxies, and load balancers
Capability Check Fix – Authorization verified before processing
Rate Limiting by IP – More granular rate limiting for login alerts
Input Validation – Maximum length validation for feedback form

Supported Languages

English (US) – 100%
English (UK) – 100%
Português do Brasil – 100%
Português de Portugal – 100%
Español – 100%

License
This plugin is licensed under the GNU General Public License v2.0 or later. For more information, visit https://www.gnu.org/licenses/gpl-2.0.html.

延伸相關外掛

文章
Filter
Mastodon