[WordPress] 外掛分享: Papy3D Security Guard

首頁外掛目錄 › Papy3D Security Guard
WordPress 外掛 Papy3D Security Guard 的封面圖片
全新外掛
安裝啟用
尚無評分
6 天前
最後更新
問題解決
WordPress 6.5+ PHP 8.0+ v2.0.10 上架:2026-08-24

內容簡介

Papy3D Security Guard 是一款模組化的 WordPress 安全套件,提供多種安全防護功能,並可根據需求獨立啟用,確保網站的安全性與穩定性。

【主要功能】
• 提供早期登錄保護與本地 CAPTCHA
• 支援 TOTP、恢復碼及登錄警報
• 本地 WAF 觀察模式與嚴格模式
• 增量式惡意軟體掃描與加密隔離
• WordPress 硬化與敏感檔案檢查
• GDPR 控制與集中警報管理

外掛標籤

開發者團隊

⬇ 下載最新版 (v2.0.10) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Papy3D Security Guard」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Papy3D Security Guard is a modular WordPress security suite. Protections are disabled by default and can be enabled independently.

Early login protection, local CAPTCHA, lockouts, honeypots and IPv4/IPv6/CIDR controls.
Local WAF with observation, balanced and strict modes, plus delegation to Papy3D WAF when installed.
TOTP, recovery codes, login alerts, forced password resets and session controls.
WordPress hardening, sensitive-file checks, core integrity verification and bounded security logs.
Incremental heuristic malware/backdoor scanner with explicit exceptions, encrypted quarantine and WP-CLI support.
File-permission, HTTPS, trusted-proxy and mixed-content diagnostics.
Optional Wordfence Intelligence synchronization followed by offline vulnerability checks.
GDPR controls, centralized alerts and secret-free JSON settings transfer.

CAPTCHA, TOTP and normal malware scans remain local. External requests occur only for explicitly enabled or requested features documented below.
Data and privacy
Settings are stored in WordPress options. The encryption master key is stored separately as a non-autoloaded option or multisite network option. Early-guard runtime state contains bounded counters, timestamps and truncated HMAC identifiers rather than plaintext usernames, passwords or CAPTCHA answers. Local WAF events may contain time, IP address, HMAC identifier, method, path without query string, rule identifiers, severity, action, bounded redacted excerpts, payload hash and user agent. Cookies, authorization headers, complete passwords and complete request bodies are not stored.
TOTP data is encrypted or hashed in user metadata. Repeated-login/TOTP counters are HMAC-keyed and expiring. Username blacklist and honeypot reports can store detected IP addresses, bounded identifiers, counters and timestamps. Login and sensitive-action alerts may include IP address and user agent in email sent through the site’s configured mail system. No analytics, external CAPTCHA, remote QR-code or remote authentication service is used.
External services
External services are contacted only for optional features or explicit administrator actions.
Trusted proxy IP-list sources
When an administrator refreshes a selected provider, or enables the daily refresh, the plugin can request public network lists from Cloudflare, QUIC.cloud, bunny.net, Fastly or Imperva. No site URL, user, visitor IP, content or plugin configuration is sent by the plugin. Providers receive normal HTTPS connection metadata, the server source IP and a generic user agent. Sucuri ranges are bundled locally and StackPath is treated as discontinued.

Cloudflare lists: https://www.cloudflare.com/ips-v4/ and https://www.cloudflare.com/ips-v6/ ; privacy: https://www.cloudflare.com/privacypolicy/ ; terms: https://www.cloudflare.com/policies/terms/
QUIC.cloud: https://www.quic.cloud/ips-all ; privacy: https://www.quic.cloud/privacy-policy/ ; terms: https://www.quic.cloud/terms-of-use/
bunny.net: https://bunnycdn.com/api/system/edgeserverlist and https://bunnycdn.com/api/system/edgeserverlist/IPv6 ; privacy: https://bunny.net/privacy/ ; terms: https://bunny.net/tos/
Fastly: https://api.fastly.com/public-ip-list ; privacy: https://www.fastly.com/privacy ; terms: https://www.fastly.com/terms
Imperva: https://my.imperva.com/api/integration/v1/ips ; privacy: https://www.imperva.com/trust-center/privacy-statement/ ; terms: https://www.imperva.com/legal/website-terms-of-use/
Sucuri source documentation: https://docs.sucuri.net/website-firewall/troubleshooting/same-ip-for-all-users/

Wordfence Intelligence
Used only when an administrator synchronizes/tests the vulnerability feed or enables daily WP-Cron synchronization. Endpoint: https://www.wordfence.com/api/intelligence/v3/vulnerabilities/scanner. The API key is sent as a Bearer token. The site URL and installed inventory are not sent; the complete feed is downloaded and analyzed locally.

Terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
Privacy: https://www.wordfence.com/privacy-policy/
API documentation: https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/

WordPress.org services
Optional core integrity verification uses WordPress core’s checksum service and sends the installed WordPress version and locale. Optional plugin/theme comparison is triggered only by an explicit administrator action and downloads the exact WordPress.org package for the identified slug/version to a temporary file, compares the selected file locally, then deletes the archive.

Privacy: https://wordpress.org/about/privacy/
License: https://wordpress.org/about/license/

PayPal
The optional Support tab contains a standard PayPal donation form. No remote PayPal script or image is embedded and nothing is submitted automatically. When the administrator clicks the support button, the selected amount, EUR currency, donation description, recipient account and normal HTTPS metadata are sent directly to PayPal.

Terms: https://www.paypal.com/us/legalhub/useragreement-full
Privacy: https://www.paypal.com/us/legalhub/privacy-full

Security
Test security changes on staging where possible and retain SFTP/SSH access for recovery. Keep WordPress, PHP and the plugin updated.
Plugin identifiers and companion integration
Security Guard is autonomous and uses the plugin-specific p3dsg_ / P3DSG_ prefix for its own classes, hooks, options, transients, menu slug and assets. It does not bundle or register a shared administration hub. The p3dwaf_integration_v1_status filter is owned by the optional companion Papy3D WAF plugin; Security Guard only consumes that external public hook when the companion plugin is installed.

延伸相關外掛

文章
Filter
Mastodon