內容簡介
HT Security 是一款完整的 WordPress 安全套件,提供多層次的網站保護,並透過國家漏洞資料庫 (NVD) API 檢查已知的 CVE 漏洞,確保網站的安全性。
【主要功能】
• 安全標頭設定:HSTS、X-Frame-Options、Content-Security-Policy 等
• 登入警報:成功與失敗登入的電子郵件通知
• 登入驗證碼:內建 SVG 數字驗證碼或 Cloudflare Turnstile
• 核心完整性檢查:驗證 WordPress 核心檔案的官方檢查碼
• CVE 漏洞檢測:檢查 WordPress 核心及啟用的外掛
• 使用者枚舉保護:透過 REST API 阻擋使用者枚舉
外掛標籤
開發者團隊
原文外掛簡介
HT Security is a complete security suite for WordPress, offering multiple layers of protection for your website.
Important – External Service:
This plugin queries the National Vulnerability Database (NVD) API to check for known CVE vulnerabilities. Requests are made to:
* API URL: https://services.nvd.nist.gov/rest/json/cves/2.0
* Terms of Use: https://nvd.nist.gov/general/legal-disclaimer
* Privacy Policy: https://www.nist.gov/privacy-policy
* Frequency: Automatic check every 12 hours or manual on-demand
* Data sent: Name and version of WordPress/installed plugins (no personal data is sent)
The NVD API query is essential for the plugin’s CVE vulnerability detection functionality.
Key Features
Security Headers – HSTS, X-Frame-Options, Content-Security-Policy, and more
Login Alerts – Email notifications for successful and failed login attempts with rate limiting
Login Captcha – Built-in SVG numeric captcha or Cloudflare Turnstile for login, password reset, and registration forms
Core Integrity Check – Verify WordPress core files against official checksums with 24h cache
CVE Vulnerability Detection – Check WordPress Core and active plugins against NVD database
User Enumeration Protection – Block user enumeration via REST API and author parameters
Maintenance Mode – Maintenance mode with authorized IP whitelist (IPv4, IPv6, CIDR support)
File Permissions Audit – Audit and automatic correction of critical file permissions
Plugin Security Indicators – Visual badges on plugins page showing vulnerability status
Plugin Update Management – Notify when plugins need updates; optionally auto-update only selected plugins
Force Cron – Secret HTTP ping to spawn WordPress cron when official wp-cron is unreliable
CVE Detection Features
Integration with NVD (National Vulnerability Database) API 2.0
Check WordPress Core and active plugins for known vulnerabilities
Intelligent batch processing with rate limiting
8 layers of anti-false-positive validation
Vulnerability badges on plugins page (enable/disable option)
Dismissible alerts per user
Email notification when vulnerabilities are detected
Automatic check every 12 hours
NVD API Key support (increased rate limit)
Security Improvements in v1.5.0
IP Spoofing Fix – Properly detects real IP behind Cloudflare, proxies, and load balancers
Capability Check Fix – Authorization verified before processing
Rate Limiting by IP – More granular rate limiting for login alerts
Input Validation – Maximum length validation for feedback form
Supported Languages
English (US) – 100%
English (UK) – 100%
Português do Brasil – 100%
Português de Portugal – 100%
Español – 100%
License
This plugin is licensed under the GNU General Public License v2.0 or later. For more information, visit https://www.gnu.org/licenses/gpl-2.0.html.
