[WordPress] 外掛分享: Lunexia Security – .htaccess Shield, Firewall, Two Factor Authentication (2FA) & Malware Protection

首頁外掛目錄 › Lunexia Security – .htaccess Shield, Firewall, Two Factor Authentication (2FA) & Malware Protection
WordPress 外掛 Lunexia Security – .htaccess Shield, Firewall, Two Factor Authentication (2FA) & Malware Protection 的封面圖片
全新外掛
安裝啟用
尚無評分
剛更新
最後更新
問題解決
WordPress 5.0+ PHP 7.4+ v3.2.2 上架:2026-05-15

內容簡介

Lunexia Security 是一款全方位的 WordPress 安全外掛,旨在保護網站免受攻擊、惡意機器人、未經授權的登錄嘗試及惡意軟體感染。它結合了 .htaccess 強化、智能網路應用防火牆、雙重身份驗證及深度惡意軟體掃描,提供輕量級且安全的網站防護。

【主要功能】
• 雙重身份驗證 (2FA) 及 OTP 登錄安全
• 登錄暴力破解保護
• 網路應用防火牆 (WAF)
• 惡意軟體掃描及威脅檢測
• 一鍵隔離及清理功能
• 自動 .htaccess 強化

外掛標籤

開發者團隊

⬇ 下載最新版 (v3.2.2) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Lunexia Security – .htaccess Shield, Firewall, Two Factor Authentication (2FA) & Malware Protection」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Lunexia Security & .htaccess Shield is an all-in-one WordPress security suite engineered to defend your website against attacks, malicious bots, unauthorized login attempts, and malware infections. Combining proven .htaccess server hardening, an intelligent Web Application Firewall (WAF), Two-Factor Authentication (2FA / OTP login protection), login brute force defense, and a deep malware scanner with 1-click quarantine, Lunexia provides comprehensive website security that is ultra-lightweight, safe, and fully compatible with WordPress 7.0 Modern admin and PHP 8+.
Whether you need rock-solid login protection, two-factor authentication, malware removal, or instant .htaccess security headers, Lunexia delivers enterprise-grade protection with zero bloat.
🛡️ Key Security Features:

Two-Factor Authentication (2FA) & OTP Login Security: Add time-based one-time password (OTP) verification for Administrators, Editors, and custom roles. Protect your login forms from credential stuffing and unauthorized access.
Login Brute Force Protection: Detect, limit, and automatically block malicious IP addresses attempting brute force login attacks.
Web Application Firewall (WAF): Real-time inspection for SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion (LFI), and Remote Code Execution (RCE) attempts without breaking page builders like Elementor or Gutenberg.
Malware Scanner & Threat Detection: Deep file integrity and heuristic scanner to detect webshells, backdoors, obfuscated base64 code, eval injections, and unauthorized core file modifications.
1-Click Quarantine & Cleanup: Instantly isolate infected files into a safe, non-executable quarantine vault with full 1-click restoration and permanent deletion controls.
Automatic .htaccess Hardening: Safely apply proven Apache/LiteSpeed security rules with automatic timestamped backups before every change.
Admin Approval Workflow: Require administrator approval for newly registered administrative and editor accounts before they can log in.
Backend Access Control: Restrict access to wp-admin and wp-login.php exclusively to trusted, whitelisted IP addresses.
Security Headers Protection: Automatically enforce Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, and Referrer-Policy.
Live Traffic Monitor & IP Reputation: Real-time traffic surveillance tracking visitor requests, malicious bots, automated crawlers, and blocked threat origins.
Modern WordPress 7.0 Ready: Centered layout, high-DPI retina interface, and modern glassmorphic dashboard widgets.

🔒 Security Rules Included:

Disable directory browsing and file listing (Options -Indexes)
Protect wp-config.php database credentials and .htaccess configuration files
Block direct web access to sensitive files (.bak, .sql, .log, .ini, .sh, .env)
Disable XML-RPC (xmlrpc.php) to block pingback DDoS and brute force amplifications
Prevent unauthorized PHP script execution in the wp-content/uploads/ directory
Block malicious query string injections, GLOBALS variable overrides, and script tags
Block author enumeration attacks (?author=1) to prevent username discovery
Enforce essential HTTP security headers (XSS Protection, No-Sniff, HSTS, Frame Guard)

⚡ Safe, Non-Destructive & Reliable:

Automatically creates a backup before applying any file modifications.
Uses native WordPress filesystem APIs for maximum server compatibility.
All generated rules are cleanly encapsulated in custom markers for 1-click restore.
Seamless compatibility with Elementor, Gutenberg, WooCommerce, and caching plugins.

External Services
This plugin connects to external services as follows:
Lunexia License Authority (api.lunexiait.com)
This plugin connects to the Lunexia central license server to validate commercial license authenticity, verify cryptographic Ed25519 tokens, and check domain bindings. This connection is used when activating, validating, or deactivating a license key in the plugin dashboard.

Purpose: Validates license authenticity, cryptographic tokens, and domain licensing.
When it’s used: When activating, validating, or deactivating an enterprise license.
What data is sent: License key, website URL/domain, verification nonces, PHP and WordPress version numbers.
Service provider: Lunexia IT (api.lunexiait.com)
Terms of Service: https://lunexiait.com/terms/
Privacy Policy: https://lunexiait.com/privacy/

延伸相關外掛

文章
Filter
Mastodon