[WordPress] 外掛分享: Owl Security

首頁外掛目錄 › Owl Security
全新外掛
安裝啟用
尚無評分
剛更新
最後更新
問題解決
WordPress 6.2+ PHP 7.4+ v1.12.0 上架:2026-07-29

內容簡介

Owl Security 是一款集成多種實用的 WordPress 保護與恢復工具的外掛,提供即時的安全狀態概覽與風險評分,幫助網站管理員有效防範安全威脅。

【主要功能】
• 實時風險評分與安全狀態概覽
• 暴力破解保護與登錄速率限制
• 內建數學 CAPTCHA 與 honeypot 保護
• TOTP 雙重身份驗證與恢復控制
• 惡意程式碼掃描與核心檔案驗證
• 活動日誌記錄安全相關事件

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.12.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Owl Security」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Owl Security brings practical WordPress protection and recovery tools into one responsive administration screen. The Free build works without a license, does not perform remote entitlement checks, and keeps its security features available locally.
Free capabilities include:

Live risk score and security status overview.
Brute-force protection, login rate limiting, login alerts, built-in math CAPTCHA and honeypot protection.
Optional Google reCAPTCHA v2/v3 or Cloudflare Turnstile when an administrator selects and configures one of those providers.
RFC 6238 TOTP two-factor authentication and recovery controls.
Malware signature scanning and administrator-requested WordPress core checksum verification.
Reversible quarantine with path and symlink safety checks.
Firewall rules for high-confidence SQL injection, cross-site scripting, command execution, traversal, abusive bots, endpoint abuse, and request rate limiting.
Comment and registration anti-spam controls.
Activity logging for security-relevant WordPress events without storing passwords or submitted form bodies.
File-integrity baselines, file-permission checks, upload MIME validation, and upload-directory execution protection.
Manual protected backups, downloads, restore checks, and recovery tools available in the Free build.
Reversible hardening for the file editor, XML-RPC, directory browsing, version output, author enumeration, and anonymous REST access.
Manual reports, CSV/PDF exports, and a bounded debug-log viewer.
Multisite-aware activation, deactivation, and uninstall behavior.

Owl Security does not silently enable commercial vulnerability, CAPTCHA, password-breach, GeoIP, reputation, AI, or uptime services. Optional providers remain inactive until the administrator chooses the related feature and supplies any required credentials.
External services and privacy
Owl Security can contact the services listed below. Optional services remain disabled until an administrator enables the related feature and, where required, enters credentials.
WordPress.org Core Checksums API
What it is: The official WordPress.org service that returns file checksums for a specific WordPress release.
When data is sent: Only when an administrator runs a malware scan with WordPress core verification enabled.
Data sent: The installed WordPress version and locale are sent in the request URL. The request User-Agent also contains the Owl Security version and the site’s home URL. No site content, users, passwords, form submissions, or database records are sent.
Service information: https://wordpress.org/about/
Privacy: https://wordpress.org/about/privacy/
WPScan Vulnerability Database API
What it is: An optional vulnerability-information service operated by Automattic.
When data is sent: Only after an administrator enables vulnerability intelligence, enters a WPScan API token, and runs or loads a vulnerability scan.
Data sent: The WPScan API token is sent in the Authorization header, and the plugin or theme slug is sent in the request URL. The request User-Agent contains the Owl Security version and the site’s home URL. Installed component versions are compared locally against the returned records. Site content, users, passwords, and form submissions are not sent.
Terms: https://wpscan.com/terms/
Privacy: https://automattic.com/privacy/
Have I Been Pwned Pwned Passwords API
What it is: An optional compromised-password lookup service.
When data is sent: Only when compromised-password checking is enabled and WordPress validates a password during a supported password or login flow.
Data sent: Only the first five characters of an uppercase SHA-1 hash are sent through the k-anonymity range API. The raw password and the complete hash never leave the site. The request User-Agent contains only the Owl Security version.
API information: https://haveibeenpwned.com/API/v3#PwnedPasswords
Terms: https://haveibeenpwned.com/TermsOfUse
Privacy: https://haveibeenpwned.com/Privacy
Google reCAPTCHA
What it is: An optional third-party CAPTCHA provider.
When data is sent: Only when an administrator selects reCAPTCHA v2 or v3, saves valid provider credentials, and a protected form is submitted.
Data sent: The configured secret key, the provider response token, and the visitor IP address are sent server-side to Google’s siteverify endpoint. Google’s browser script may also receive browser, device, network, and interaction data under Google’s policies. Built-in Math and Honeypot modes do not contact Google.
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy
Cloudflare Turnstile
What it is: An optional third-party CAPTCHA provider.
When data is sent: Only when an administrator selects Turnstile, saves valid provider credentials, and a protected form is submitted.
Data sent: The configured secret key, the provider response token, and the visitor IP address are sent server-side to Cloudflare’s siteverify endpoint. Cloudflare’s browser script may also receive browser, device, network, and interaction data under Cloudflare’s policies. Built-in Math and Honeypot modes do not contact Cloudflare.
Terms: https://www.cloudflare.com/website-terms/
Privacy: https://www.cloudflare.com/privacypolicy/
Email reports and login notices use the WordPress site’s configured wp_mail() transport. Owl Security does not operate that mail service. Administrators can disable IP logging or enable IP anonymization. Request query values and submitted form bodies are not stored in the request log.

延伸相關外掛

文章
Filter
Mastodon