[WordPress] 外掛分享: PowerSEC

首頁外掛目錄 › PowerSEC
WordPress 外掛 PowerSEC 的封面圖片
全新外掛
安裝啟用
尚無評分
剛更新
最後更新
問題解決
WordPress 5.8+ PHP 7.4+ v1.4.230 上架:2026-09-15

內容簡介

PowerSEC 是一款強大的 WordPress 安全外掛,提供本地安全防護,無需帳號即可使用。它具備防火牆、暴力破解鎖定、雙重身份驗證等功能,能有效保護網站免受各種攻擊。

【主要功能】
• 防火牆/WAF 及暴力破解鎖定
• 雙重身份驗證 (2FA) 和 CAPTCHA
• IP 黑名單/白名單及國家封鎖
• 惡意軟體及檔案變更掃描
• 一鍵備份及還原功能
• 監控日誌以防篡改

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.4.230) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「PowerSEC」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Local security, no account: firewall/WAF; brute-force lockouts, 2FA, CAPTCHA, magic-link, bot/honeypot; IP blocklist/allowlist and country blocks; malware and file-change scanning; WordPress, database and session hardening; on-site backups with 1-click restore; tamper-evident audit log.
PowerSEC can connect to PowerSEC Central (https://powersec.io) for multi-site management and vulnerability scanning (plugins, themes and core), off by default — see External services (1). If connected, it can switch WordPress’s own plugin and theme auto-update settings on or off. It never changes how core updates itself.
External services
Each service below is contacted only when its feature is on; every third-party service is off by default, and Central is off until an administrator connects the site. Out of the box the only request PowerSEC makes on its own is to the first-party WordPress.org checksum API (5); an alert channel’s “Send test” is the one exception, contacting the destination you typed at once. IPs and usernames may be personal data — disclose the services you enable in your own policy. The User-Agent is PowerSEC/ alone; see each service below.
1. PowerSEC Central — https://powersec.io — dashboard for multi-site management, cloud backups, alerting, incident response. Trigger: only when an administrator connects the site. Default: off.
Sent: site URL, identifiers and API keys; WordPress/PHP/MySQL versions; plugin and theme inventory (name, slug, version, author, active state); site icon URL; disk, memory and database size; up to 14 days of pageview counts; scan summaries, security event metadata and backup status; IPs of blocked or attacking clients; administrator usernames, last login, and their email addresses (only while two-factor is on or this server cannot send mail). If a message this site sends fails, its subject and body go to Central to deliver — to your own administrators only. With two-factor on and connected, the one-time code and recipient email go to Central to deliver (otherwise wp_mail() is used and nothing leaves the site). Database-scan findings carry a short redacted excerpt plus its table and key; whole posts, option values and page output never are.
Cloud backup (paid): archives on Wasabi (*.wasabisys.com); restores use short-lived signed URLs from *.wasabisys.com, *.amazonaws.com or powersec.io. Wasabi https://wasabi.com/legal/ , https://wasabi.com/legal/privacy-policy/ — AWS https://aws.amazon.com/service-terms/ , https://aws.amazon.com/privacy/
Terms https://powersec.io/terms — Privacy https://powersec.io/privacy
2. Google Gemini — https://ai.google.dev (via Central) — an AI second opinion on a file the scanner already flagged.
Trigger: (a) manual — an administrator clicks to explain one flagged file; that click is the authorisation. (b) automated — off by default, needing an explicit local opt-in by an administrator of this site under PowerSEC > Central Connection. Connecting to Central, your plan and Central’s settings do not enable it; switching it off stops future sharing.
Sent: only a bounded, redacted excerpt of that flagged file (size-capped, secrets redacted), plus its path, size, hash and the matching rule. Whole files, whole sites, databases and files that may hold credentials (wp-config.php, .env, key/certificate files) are never sent. Advisory only: it never changes scan results, malware counts or your score, and never removes, quarantines or repairs a file.
Terms https://ai.google.dev/gemini-api/terms — Privacy https://policies.google.com/privacy
3. GeoJS — https://get.geojs.io — IP geolocation. Trigger: only when country blocking is enabled. Default: off. Sent: the visitor’s IP, to resolve its country; cached 24h, and behind Cloudflare the country comes from Cloudflare’s header with no external call.
Terms https://www.geojs.io/tos/ — Privacy https://www.geojs.io/privacy/
4. Tor Project exit list — https://check.torproject.org — the public exit-node list. Trigger: only when Tor blocking is enabled. Default: off. Sent: nothing; the request carries no visitor information.
Privacy https://www.torproject.org/about/privacy_policy/ (a public file served without an account, so no separate terms)
5. WordPress.org — https://api.wordpress.org , https://downloads.wordpress.org — the official checksum APIs core itself uses. Trigger: file-integrity monitoring (on by default) and malware scans. Sent: your WordPress version and locale for core checksums; each plugin’s slug and version for plugin checksums. No personal data.
Privacy https://wordpress.org/about/privacy/
6. Alerting / SIEM destinations — security events sent where you choose. Trigger: only when you configure and enable a channel. Default: off; on every plan. Kinds: webhook URLs you supply (Slack, Discord, Splunk HEC, custom); fixed endpoints (PagerDuty events.pagerduty.com, Datadog http-intake.logs.datadoghq.com or its regional host); raw syslog/CEF over UDP/TCP to a host you supply.
Sent: per event — type, severity, message, the WordPress username involved (on a failed login this is visitor-supplied text), client IP, timestamp, your site name and URL. Custom-webhook and Splunk formats also include event metadata, which for a login can contain the request path and user-agent; the others do not.
Terms/privacy: https://slack.com/terms-of-service , https://slack.com/trust/privacy/privacy-policy , https://discord.com/terms , https://discord.com/privacy , https://www.splunk.com/en_us/legal/terms.html , https://www.splunk.com/en_us/legal/privacy-policy.html , https://www.pagerduty.com/terms-of-service/ , https://www.pagerduty.com/privacy-policy/ , https://www.datadoghq.com/legal/terms/ , https://www.datadoghq.com/legal/privacy/ . A webhook, Splunk HEC or syslog collector you supply is your own server, so its terms are yours.
7. Your own site (loopback) — not a third party. Long backups and scans continue by calling your site’s own admin-ajax.php; nothing leaves your server.
Privacy
Recorded locally: login attempts (attempted username, IP, time), audit log (action, user, IP), sessions (user, IP, user-agent, times), and firewall/WAF/IP-blocking records (IP, path, method, user-agent). Findings describe files, not people. Retention: audit log and login attempts about 90 days (configurable), firewall/WAF/sessions about 30 days, remote requests about 7 days.
Blocked IPs follow their own rules, not the schedule above: a temporary block ends by itself when it expires; a permanent block PowerSEC created automatically is removed after about a year (configurable); one an administrator added by hand is kept until an administrator removes it.
Deleting the plugin keeps your data by default. That site’s PowerSEC tables, settings and connection details stay, so a reinstall resumes where it left off. Running wp option update powersec_delete_data_on_uninstall 1 first (no screen for it) also drops those tables and removes PowerSEC settings, stored keys, connection details, transients, per-account data and scheduled tasks, plus the firewall folder. Backup and quarantine folders remain, as do the uploads PHP-execution guards. One secret-free pending-revocation marker remains when a Central release is unconfirmed, never reported as done. wp-admin deletion cannot notify Central, so disconnect first.
WordPress export and erasure requests are answered for records tied to a WordPress account. IP-only records cannot reliably be linked to an email address, so they are not exported or erased. Where erasure would break the tamper-evident audit chain, identifying fields are anonymised instead of deleted, and the response says so.
Files and directories this plugin writes
Everything is written inside your uploads directory (wp_upload_dir()): powersec-backups/ (archives; deny-all .htaccess), powersec-quarantine/ (detected files kept for inspection), powersec/ (firewall rules), powersec-config-backups/ (wp-config.php copies; removed on data deletion), plus guards stopping PHP executing in uploads. Two things write outside uploads: the prefix change edits wp-config.php after backing it up, and a restore adds .maintenance to the site root, removed when it ends. Restoring overwrites site files.
Credits
Chart.js v4.5.1, @kurkle/color v0.3.2 (MIT; texts in licenses/). https://github.com/chartjs/Chart.js , https://github.com/kurkle/color

延伸相關外掛

文章
Filter
Mastodon