[WordPress] 外掛分享: Polanger Admin Suite – Secure, Control & Customize WordPress Admin

首頁外掛目錄 › Polanger Admin Suite – Secure, Control & Customize WordPress Admin
WordPress 外掛 Polanger Admin Suite – Secure, Control & Customize WordPress Admin 的封面圖片
50+
安裝啟用
★★★★★
5/5 分(2 則評價)
9 天前
最後更新
問題解決
WordPress 5.7+ PHP 7.0+ v1.6.1 上架:2026-01-26

內容簡介

Polanger Admin Suite 是一款模組化的 WordPress 管理控制與安全外掛,旨在幫助用戶從一個地方自訂、保護和管理網站。它整合了多項管理工具,讓開發者、代理商及網站擁有者能夠建立更乾淨的管理介面及更強的存取控制。

【主要功能】
• 模組化管理套件,僅啟用所需工具
• 菜單管理器,支援隱藏、重新命名及自訂圖示
• 登入強化,包含自訂登入 URL 和兩步驟驗證
• 角色基礎的內容可見性控制
• 評論安全層,支援 WooCommerce 評論模式
• 維護中心,提供即將到來及維護模式功能

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.6.1) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Polanger Admin Suite – Secure, Control & Customize WordPress Admin」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Polanger Admin Suite is a modular WordPress administration and security platform built around three simple goals:
Secure WordPress. Control the admin experience. Customize it your way.
Instead of installing separate plugins for admin menus, access control, login protection, two-factor authentication, firewall security, activity tracking, dashboard management, and admin customization, Polanger brings these tools together in one modular suite.
Enable only the features your website needs. Optional addons remain inactive until enabled, helping keep the system focused and lightweight.
Whether you manage your own website, build WordPress projects for clients, or maintain multiple installations, Polanger gives you one place to protect WordPress, control what users can access, and create a cleaner administration experience.

Live Demo

Secure. Control. Customize.
Polanger is organized around three complementary layers instead of one oversized feature set.
Secure WordPress
Build multiple layers of protection around WordPress without turning every visitor request into a heavy security scan.

Polanger Firewall – Request protection, suspicious traffic scoring, authentication rate limiting, REST/XML-RPC hardening, IP and country access rules, integrity monitoring, upload protection, malicious outbound redirect protection, quarantine, recovery tools, and Strict server hardening.
Two-Factor Authentication – Protect accounts with email verification codes, recovery keys, role-based enforcement, and configurable verification policies.
Authenticator App (TOTP) – Add Google Authenticator or Microsoft Authenticator with secure enrollment, recovery keys, trusted-device support, replay protection, and safe secret rotation.
reCAPTCHA Protection – Centralized reCAPTCHA v2/v3 protection for login, registration, password reset, and supported comment forms.
Comment Security Layer – Protect comments with honeypot detection, timing validation, flood controls, behavior scoring, blocklists, and site-wide comment policies.
WooCommerce Security – Extend authentication protection to WooCommerce customer login, registration, password recovery, reCAPTCHA, 2FA, and rate limiting.
Activity Monitoring – Track important administrative and security-related activity without turning WordPress into a full request logging system.

Polanger follows a layered approach: stop common attacks at the request layer, detect trusted-file changes through integrity monitoring, apply stronger server rules where supported, and provide recovery paths for supported security actions.
Control WordPress
Decide what administrators, editors, clients, team members, and other users can see and access.

Admin Menu Manager – Hide, rename, reorder, protect, and customize WordPress admin menus and submenus.
Access Control – Restrict plugin and administration access for selected users and roles.
Polanger Shield – Protect wp-admin pages, hide interface elements, add contextual notes, and create controlled read-only or demo environments.
Frontend Content Visibility – Control access to posts, pages, and supported custom post types by login state or user role.
Multisite Control – Define network defaults, site-level overrides, and locked policies across supported modules.
Dashboard Center – Control widgets, notices, visibility, and the information users see when they enter WordPress.
Admin Bar Control – Remove unwanted items, add custom links, and control frontend/backend toolbar content.

Customize WordPress
Create a cleaner administration experience without replacing WordPress itself.

Design System – Apply admin theme presets, semantic color controls, typography, generated CSS, and WCAG-aware Smart Contrast.
PG Aurora – A polished admin design preset with refined navigation, submenu handling, third-party compatibility, and responsive behavior.
Login Page Customization – Customize branding, colors, backgrounds, layout, and the WordPress login experience.
Custom Admin Menu Builder – Create your own top-level administration menus and links.
Dashboard Customization – Remove unnecessary widgets and create focused dashboard experiences for different users.
Maintenance Center – Manage maintenance, coming-soon, deployment, preview access, branded public pages, countdowns, and bypass rules.

Why Polanger Admin Suite?

One Modular Platform – Replace multiple disconnected admin, access, customization, and security tools with one coordinated suite.
Layered WordPress Security – Protect authentication, incoming requests, critical files, WordPress integrity, geographic access, and suspicious outbound behavior.
Built with Recovery in Mind – High-risk Firewall operations use verification, rollback, quarantine, and emergency recovery paths instead of relying on destructive one-way actions.
Designed for Compatibility – Protection modes, bounded processing, asynchronous heavy work, and cautious handling of custom code help reduce unnecessary lockouts and false positives.
Enable Only What You Need – Optional addons can be activated independently instead of forcing every feature onto every website.
Built for Agencies & Teams – User access controls, Shield rules, Multisite support, activity tracking, and admin customization help manage client and multi-user environments.
Modern WordPress Admin Experience – Clean interfaces, responsive controls, localization, and consistent addon workflows across the suite.
Free, Modular, and Extensible – Core addons are included with Polanger Admin Suite and the architecture remains open for future integrations.

Built for Real-World WordPress
Polanger is designed for:

Agencies managing client websites
Developers building and maintaining WordPress projects
Teams working with multiple users and roles
WooCommerce stores that need stronger customer authentication controls
Multisite administrators managing shared policies
Site owners who want stronger security without giving up control of their WordPress experience
Administrators who want a cleaner and more organized wp-admin

Core Features
Admin Menu Manager

Hide any admin menu or submenu item
Role-based visibility control
Rename menu items and submenus
Change icons with 200+ Dashicons
Drag & drop menu reordering
Block direct URL access to hidden pages
Visual indicators for hidden and modified items
Custom admin menu builder (create your own menus)

Admin Bar Customization

Replace or remove WordPress logo
Hide unwanted admin bar items
Add custom links with icons
Manage frontend and backend admin bar
Auto-detect plugin and theme items

Login Security & Customization

Custom login URL (hide wp-login.php)
Google reCAPTCHA v2 & v3 support
Custom login page design (logo, colors, background)
Brute-force protection with configurable login attempt limits and lockouts
Hardened login flows with safer redirects and protected authentication routes

Email Two-Factor Authentication (2FA)

Email-based verification codes
Role-based enforcement
Recovery keys for backup access
Configurable expiration times
Super admin protection

Authenticator App (TOTP)

Google Authenticator and Microsoft Authenticator support
Time-based One-Time Password (TOTP) verification
Multi-user architecture with per-user enrollment
Mandatory enrollment flow for users in required roles
Profile page 2FA management (Users → Profile)
Admin visibility: enrollment status only, no secret access
Safe secret rotation with pending secret system
Old authenticator remains active until new setup is verified
Secure secret storage with AES-256-CBC encryption
Manual secret entry with provisioning URI support
One-time recovery keys (10 keys per user, auto-regenerated on rotation)
Email fallback option when authenticator is unavailable
Brute-force protection with configurable lockout
Replay attack prevention with time-slice tracking
Seamless integration with core 2FA settings (roles, lockout, expiry)

Activity Log

Track logins, plugin changes, content updates, and more
Filter by user, action, and date
Export logs (CSV)
Email alerts for critical actions
Privacy-conscious logging with controlled activity data collection

Dashboard Control

Hide default WordPress widgets
Hide third-party plugin widgets
Control admin notices
Create custom dashboard widgets
Per-user dashboard visibility

Multisite Control

Network-wide default settings for multisite installations
Site-level override controls for supported modules
Lock system for Menu Manager, Admin Bar, Login Security, Activity Log, and Dashboard Center
Network-aware addon activation support
Developer-friendly effective settings filter architecture

Access Control

Restrict plugin access to specific users
Read-only mode support
Prevent unauthorized access
Super admin safety protection

Design System

Token-based admin theming system for consistent and scalable customization
Customize colors across admin UI (sidebar, admin bar, background, text, surfaces)
Sidebar background, text color, and menu item styling
Admin bar background, text color, submenu background, and submenu text color
Built-in presets (e.g. Dark, Minimal, Default) with one-click application
Automatic CSS generation with cache-friendly performance
Enhanced Smart Contrast uses WCAG-aware ratios, gradient sampling, dynamic admin-surface monitoring, icon correction, and late theme guards while preserving colors that are already readable
Typography controls including font family and basic shape settings
Scoped styling to avoid conflicts with WordPress core and plugins
Extensible architecture for future themes, layouts, and design packs

Frontend Content Visibility

Per-content frontend access control for posts, pages, and supported custom post types
Visibility modes for public, logged-in users only, selected roles only, or hidden-from-selected-roles workflows
Multiple denied behaviors including login redirect, 404, access denied message, and custom redirect
Theme-friendly replacement mode or dedicated access denied page for stricter template control
Optional hiding from archives, search results, public REST responses, and WordPress XML sitemaps
Rich-text access denied messages with TinyMCE, HTML, and shortcode support

reCAPTCHA Protection

Centralized Google reCAPTCHA key management (v2 and v3)
All reCAPTCHA configuration consolidated in one dedicated addon
Login form protection
Registration form protection
Lost password form protection
Comment form protection (works with Comment Security addon)
Configurable v3 score threshold
Badge position customization for v3
Automatic script loading only when needed

Firewall

Lightweight, WordPress-aware Firewall designed to protect common attack surfaces without turning every visitor request into a heavy security scan.
Three protection modes: Monitor Only for observation, Safe Protection for everyday websites, and Strict for more aggressive protection when stronger security is needed.
Blocks common bot probes, exposed-file scans, suspicious paths, traversal attempts, unsafe requests, and other high-risk traffic before it can reach sensitive WordPress functionality.
Protects native WordPress login, registration, and password-reset flows with identity and IP-based rate limiting.
Hardens the REST API and XML-RPC against common abuse, including anonymous request pressure, user enumeration, multicall attacks, and optional anonymous write restrictions.
Uses a request scoring engine that combines multiple suspicious signals before deciding whether traffic should be monitored or blocked.
Malicious Outbound Redirect Protection helps protect visitors when compromised or injected frontend code attempts to open known malicious destinations or trigger unexpected external redirects and popups. Protection is enabled by default in Safe and Strict modes and can be disabled for site-specific compatibility.
A compact local PhishTank reputation index strengthens outbound protection without sending each visitor, URL, or destination to a remote reputation API.
Supports IP allowlists and denylists, IPv4/IPv6 CIDR ranges, trusted proxy configurations, and temporary cooldowns for repeated abusive traffic.
Country Access Control can block visitors from selected countries using a local DB-IP Country Lite database. Visitor IP addresses are not sent to an external geolocation API.
Country data is prepared only when country blocking is configured, checked periodically for updates, and removed when the country policy is cleared.
Adds practical security response headers, username enumeration protection, and controls for WordPress Application Password usage.
WordPress Core Integrity verifies the installed WordPress version against official checksums and detects modified, missing, or unauthorized core files.
Supported WordPress.org plugins can be checked against their official package data, while premium and custom plugins/themes are monitored more cautiously so unverified custom code is not automatically treated as malware.
Monitors executable files inside wp-content for unexpected additions and changes while recognizing normal WordPress core, plugin, theme, and translation updates.
Reduces false positives by distinguishing harmless PHP guard files from files containing actual executable PHP behavior.
Upload Protection detects executable or PHP-bearing media uploads and can prevent PHP execution inside the uploads directory on supported Apache environments.
Uses high-confidence malware behavior signals to detect suspicious patterns such as encoded execution chains, request-driven commands or file writes, dangerous includes, hidden remote frames, forced external redirects, and click-triggered popup behavior.
Strict Extended Server Hardening adds an additional protection layer on supported Apache/LiteSpeed servers to block sensitive-file exposure, development metadata leaks, backup/log access, directory browsing, and selected unsafe requests before WordPress/PHP handles them.
Server hardening rules are applied with verification, health checks, automatic rollback, and safe cleanup without modifying WordPress or third-party rule blocks.
Recommended Actions help administrators understand what to do with security findings instead of only reporting that a problem exists.
Verified official WordPress core and supported WordPress.org plugin files can be safely restored from trusted package sources when appropriate.
High-confidence executable threats can be moved into protected quarantine, while ambiguous custom or premium code is never automatically deleted.
Quarantine Manager provides visibility into quarantined files with controlled restore and permanent deletion actions.
Recovery history and an Emergency Recovery URL provide a safe way to reverse supported Firewall file operations if a remediation action causes unexpected site behavior.
No-reload Scan Now performs a detailed integrity scan with live progress while heavier work is processed asynchronously to reduce timeout and memory pressure.
Scheduled low-impact integrity scans and automatic post-update verification help detect later file changes without requiring constant manual full scans.
Findings are clearly separated into Critical, Review, and Notice levels so package differences, harmless files, and custom code are not automatically presented as malware.
Integrity results are grouped by affected component with a compact preview and a searchable, filtered findings viewer for larger reports.
Recent Firewall Events records important security decisions using bounded storage instead of operating as a heavy full-traffic request logger.
Firewall Diagnostics provides built-in self-tests for request protection, rate limits, REST/XML-RPC behavior, IP/CIDR rules, security headers, country access, integrity protection, uploads protection, scheduled scanning, and Strict server hardening without intentionally sending malicious traffic to the website.
Protection presets configure sensible defaults automatically while still allowing advanced administrators to customize individual controls when needed.

WooCommerce Security

Adds WooCommerce-specific reCAPTCHA locations for customer login, registration, and lost password forms
Extends the existing Polanger 2FA flow into WooCommerce customer login while preserving My Account and checkout return paths
Adds customer authentication rate limiting for login failures, account registrations, and lost password requests
Includes Light, Balanced, and Strict protection profiles so store owners can choose safe limits without tuning every number manually
Requires WooCommerce and uses dependency-aware loading so the addon does not run in incomplete store environments
Reuses Polanger’s existing reCAPTCHA and 2FA systems instead of creating a disconnected WooCommerce security stack

Polanger Shield

Blocks selected wp-admin pages for selected users with optional direct URL blocking
Hides selected admin interface areas from the real screen using the floating Shield tool
Adds contextual notes to admin elements so teams can document workflows directly inside wp-admin
Demo Lock keeps selected admin screens visible while preventing save, publish, AJAX, REST, and destructive changes for demo users
Global Demo Mode turns wp-admin into a controlled read-only demo environment for eligible administrator accounts
Safe Mode gives authorized managers a temporary recovery path when reviewing or troubleshooting Shield rules
Menu Manager integration shows when a menu or submenu item is already protected by Shield, helping avoid duplicate restrictions
The Shield dashboard provides status/type filters, 25-rule pagination, localized dates and states, bulk actions, and a mobile-safe scroll region so every saved rule remains manageable

Modular Addon Architecture
Polanger Admin Suite uses a modular addon architecture so each website can enable only the functionality it actually needs.
Bundled addons share the same Admin Suite foundation and settings experience while remaining independently activatable. …

延伸相關外掛

文章
Filter
Mastodon