[WordPress] 外掛分享: PCrisk Trust Badge – Website Security Seal & Malware Scanner

首頁外掛目錄 › PCrisk Trust Badge – Website Security Seal & Malware Scanner
WordPress 外掛 PCrisk Trust Badge – Website Security Seal & Malware Scanner 的封面圖片
全新外掛
安裝啟用
尚無評分
5 天前
最後更新
問題解決
WordPress 6.3+ PHP 7.4+ v1.17.0 上架:2026-09-09

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.17.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「PCrisk Trust Badge – Website Security Seal & Malware Scanner」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Shoppers who don’t know your store ask one silent question before they type a card number: is it safe to buy here? PCrisk Trust Badge answers it with a seal they can click and check for themselves.
PCrisk Trust Badge monitors your site for free and – on a paid plan – puts a “This website is safe” seal on it. The seal is backed by a security scan. Anyone can click the badge to open your live scan report: malware scan results, blacklist checks, and a trust score, verified by PCrisk’s website security scanner.
Every claim the badge makes is one your visitors can check for themselves.
An outside opinion on your site’s safety. PCrisk scans your website from the public web rather than from inside WordPress – the way an antivirus engine, a search engine like Google, or a shopper’s browser sees it – so you find out your online store has been hacked, defaced or blacklisted before your customers do. Continuous scanning covers virus and malware detection, phishing feeds, SSL validity and a domain blacklist checker across 90+ sources – among them Safe Browsing, Spamhaus, SURBL, PhishTank and URLhaus. Built for business sites and ecommerce stores with a hard-won reputation to protect.
Free security monitoring, no card
The free plan is permanent, not a trial. Install the plugin, connect your site, and you get a monthly security scan across 90+ engines and blacklists, your trust score and verdict inside WordPress, and the result of every monthly scan by email – clean or flagged.
Paid plans add the part your visitors see: the public click-to-verify badge, daily scans, and the live report it opens.
The badge itself is served by PCrisk rather than by the plugin, so the verification it displays is issued by the party that actually performed the scan.
How the badge behaves

The badge shows only while your site is actually passing its latest security check (trust score 70 or higher).
If a scan flags something, you get a full report by email within minutes of that scan – your risk score, how many engines flagged you, which threat databases list you, what the file scan found and how to fix it – and the badge takes itself down until the issue is resolved.
One click opens the live PCrisk scan report for your domain: real scan date, real results, real trust score.

The badge is tied to the scan result, so it cannot stay up while your site is failing its own security check.
Why site owners add it

Turn security into social proof. Shoppers hesitate on sites they don’t know. A verifiable safety seal answers the question they’re silently asking: “Is it safe to buy here?”
Give visitors something to check. The badge opens your live scan report, so a cautious shopper can read the evidence for themselves.
Know first. Every scan reports back by email, not just to a dashboard you have to remember to open – so you hear it from us, not from a customer, an ad platform, or a browser warning.

Don’t be the last to know your site got flagged
Antivirus engines and search-engine warnings sometimes flag perfectly legitimate sites – a new TLD, a plugin’s behaviour, a traffic spike, a pattern match gone wrong. Most site owners find out the hard way:

A customer mentions your site won’t load in their browser.
An ad campaign gets suspended without warning.
Email deliverability quietly drops and nobody can work out why.
You check manually months later and realise you’ve been flagged the whole time.

By then the damage is done. PCrisk surfaces new detections within minutes of the scan that finds them – monthly on the free plan, daily on paid – so a one-off false positive becomes a ten-minute fix instead of something you discover months later. And if it is a false positive, PCrisk gives you a dispute path.
What every scan checks
Each scan runs your site through the full PCrisk detection stack – the same engine behind the public PCrisk website scanner. The free plan runs it monthly; paid plans run it every day.

Malware – malicious code, obfuscated scripts and newly reported threats hidden in your HTML, JavaScript and embedded resources.
Phishing – checked against global phishing feeds, so your site isn’t mistaken for a fake-login or fraud page.
Blacklists – your domain cross-referenced against 90+ security and threat-intelligence sources.
SSL – certificate validity verified on every scan, so an expired or broken certificate is caught fast.
Reputation & outbound links – domain reputation, popularity ranking, and the health of the sites you link out to.
Plain-English summary – every finding explained without jargon, refreshed on every scan.

Designed to fit your site
Badge design and placement are yours to tune from the moment you install:

Four looks – Shield, Ribbon, Minimal, and Bubble – in light, dark, or auto (auto follows your site’s light/dark mode), in three sizes.
One-click placement – footer (every page), after content, or a floating corner badge that follows visitors as they scroll.
WooCommerce placements, auto-detected – put the badge on your shop page, product pages (above or below the Add to cart button), cart, and checkout – right where hesitant shoppers decide.
Gutenberg block – drop the badge into any page or post, and give each one its own style, size, theme, alignment and spacing.
Live preview – see exactly how the badge looks and where it sits, before you save anything.
Fine-tuning – alignment, spacing around the badge, and a one-click “Disable all badges” switch that keeps your settings for later.
No API key, no DNS records – the badge is matched to your domain automatically. Pick a placement and it appears by itself, or place it exactly where you want with the Gutenberg block.

Built for WooCommerce stores
For e-commerce stores, the plugin detects WooCommerce automatically and adds dedicated store placements to its settings – no setup needed. They show a live badge once your domain has an active PCrisk verification:

Product pages – above or below the Add to cart button, or at the bottom of the product details
Cart – next to the checkout button
Checkout – beside the “Place order” button, where trust decides the sale
Shop page – top or bottom of your product grid

Checkout is where trust matters most. Put the verified security badge at the exact moment of doubt, and let hesitant shoppers click to verify your store’s safety for themselves. Site-wide placements (footer, floating) cover the rest of your store.
How it works

Install the plugin and start free – a guided setup explains what connecting shares, asks for your approval, then detects your domain and opens PCrisk sign-up. No payment details.
Your site is scanned. Trust score, verdict and blacklist status appear right in your WordPress admin.
Want the badge visitors can click? Upgrade, then pick a look and a spot – it goes live as soon as a scan comes back clean, and takes itself down if one ever doesn’t.

Free plan: monthly security scan, your status in wp-admin, and every scan result by email – free forever, one site, no card. Paid plans add the part your visitors see: PCrisk issues a public verification for your domain, so the badge renders on your site, scans run daily, and your live report page and scan history go live – from $16.95/month, with a 14-day free trial of any paid plan. See pricing and plans.
External services
This plugin connects to the PCrisk website security scanner (pcrisk.com) to power the badge:
Nothing is contacted without your consent. The admin screens make no request to PCrisk until you explicitly approve the connection on the plugin’s setup screen (or the settings screen’s connect card) – the approval text spells out what is shared before you agree. Your site’s public pages load nothing from PCrisk until you enable an automatic placement or add the badge block, and the pcrisk_trust_badge_enabled filter (FAQ above) can gate even that behind your own consent tooling.

On your public pages, only where a badge is set to appear: the badge script https://scanner.pcrisk.com/badge/trust-badge.js is loaded by your visitor’s browser, which then requests your domain’s current verdict. As with any externally hosted script, that request carries the visitor’s IP address, browser user-agent and the page URL. PCrisk sets no cookies through the badge and does not track visitors across sites.
In your WordPress admin only, after you approve the connection: the plugin’s own settings screen and setup wizard request https://scanner.pcrisk.com/api/badge/scan-summary/ to show your trust score and verdict, and load the badge and preview scripts (trust-badge.js and trust-badge-preview.js) plus flag icons from the same host to draw the live preview. If your site has never been scanned – or the last result is stale – those two screens also embed the PCrisk scan runner (https://scanner.pcrisk.com/trust-badge/scan-embed) to start a scan of your domain. The block editor loads the same preview assets and makes the same read-only summary request once per editing session, but only when the page you are editing contains a PCrisk Trust Badge block – it is what tells you there whether the badge will actually render for visitors. Your domain name – plus a marker identifying the request as coming from the WordPress integration – is all that is sent, and no other admin screen contacts PCrisk.
What comes back: your scan status (clean or flagged), your plan state, trust score, last and next scan dates, and the badge itself.
Inbound, so PCrisk doesn’t scan abandoned sites: PCrisk’s scanner periodically checks your-domain/wp-json/pcrisk/v1/verify, a small public endpoint this plugin provides, to confirm the plugin is still installed before spending a scan on your domain. It answers with a random site token, the plugin and WordPress versions, and when the badge dashboard was last used – nothing else, and the plugin itself never sends a request from your server.
Nothing is shown until you choose it: no badge, link or credit appears on your site until you pick a placement. The plugin’s settings and preview work whether or not you ever display one, and no plugin feature depends on displaying it.
Why it’s needed: the badge is a live security seal – without the scanner there is nothing truthful to display.

The free plan requires a PCrisk account (email only, no payment details). The public badge requires a paid subscription, which starts with a 14-day free trial. Service terms: PCrisk Terms of Service · Privacy Policy.

延伸相關外掛

文章
Filter
Mastodon