[WordPress] 外掛分享: CMS ADMINS Security Check Report

首頁外掛目錄 › CMS ADMINS Security Check Report
WordPress 外掛 CMS ADMINS Security Check Report 的封面圖片
20+
安裝啟用
尚無評分
4 天前
最後更新
問題解決
WordPress 7.0+ PHP 7.4+ v2.3.2 上架:2026-09-03

內容簡介

CMS ADMINS Security Check Report 外掛檢查 WordPress 安裝的 60 個方面,並生成分級報告,幫助用戶了解安全狀況。此外掛不會改變任何設置,僅提供建議與改進步驟。

【主要功能】
• 提供 A 到 F 的加權評分
• 列出最多五項優先處理事項
• 比較上次檢查的變更
• 支援純文字、JSON 和 CSV 匯出
• 提供可搜尋的檢查說明

外掛標籤

開發者團隊

⬇ 下載最新版 (v2.3.2) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「CMS ADMINS Security Check Report」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Security Check Report looks at 60 aspects of a WordPress installation and turns the findings into a graded report. It changes nothing. Every check reads state, and the only thing ever written is one temporary file in the uploads folder that is deleted again in the same request.
The report opens with the five things worth doing first, not with a table of 60 rows. Every finding says what was found, why it matters and what to do about it. From the second run onwards the report also says what changed since the last one, which is usually the part worth reading.
What you get

A weighted grade from A to F, where one failing critical check cannot be hidden by fifty passing minor ones
A priority list of at most five items, derived from urgency and score rather than from guesswork
A comparison with the previous run: newly failing, resolved, changed
Muting that remembers what a finding said, so an accepted finding comes back the moment it actually changes
“Not determined” as a real outcome, so a blocked request is never reported as a problem and never moves the grade
Exports as plain text, JSON and CSV
A WP-CLI command that produces the same grade as the screen
An explanation of every check, searchable, right on the page

What it checks
Core, plugins and themes. WordPress version, PHP version against the published end-of-life dates, automatic core updates, core file integrity against the official checksums, files in the core directories that are not part of WordPress, pending plugin and theme updates, unused plugins and themes, plugins that look abandoned, plugins whose listing was closed, plugins whose author changed, must-use plugins and drop-ins, other installations sharing the account.
Configuration. Debug mode, debug log exposure, the theme and plugin editor, installing code from the dashboard, authentication keys and salts, table prefix, database user privileges, whether the scheduler actually runs, autoloaded options size, injected content in the options table, backups, login protection, password policy.
Files and permissions. Permissions on wp-config.php, the uploads folder and the core directories, world-writable paths, executable files among the media, whether the server runs PHP from the uploads folder, configuration and backup files that the server hands out, readable .git, .svn and .hg folders, database dumps in the web root, leftovers from interrupted updates, directory listing.
Accounts and access. Guessable passwords, predictable administrator names, how many accounts hold administrator rights and which have gone dormant, roles below administrator holding capabilities they should not have, open registration and the role it hands out, two-factor coverage per administrator, the application password inventory including when each was last used and from where.
Network and transport. HTTPS and the redirect from http, TLS certificate expiry and negotiated protocol, the security headers and their quality rather than their mere presence, cookie attributes, CORS, exposed software versions, legacy discovery tags, XML-RPC, user enumeration, REST routes that accept writes without checking permissions, and whether the client address can be faked through forwarded headers.
What it is not

Not a firewall. It blocks nothing and intercepts no requests.
Not a malware scanner. It compares core files against the official checksums and looks for injected content in the options table, but it does not hunt for signatures in plugin or theme code, and it removes nothing.
Not a vulnerability database. It reports that a plugin is outdated, abandoned or delisted; it does not look up individual CVEs.
Not an auto-fixer. Every finding comes with instructions, and you carry them out.

Data and connections
The plugin talks to api.wordpress.org and to your own site. Nothing else, and there is no telemetry. See the questions below for exactly which endpoints and what is stored locally.
Who builds it
CMS ADMINS maintains, hosts and secures WordPress and Drupal sites from Munich. This plugin is the checklist we run ourselves, packaged up. It is free, it stays free, and it works the same whether or not you ever talk to us.

What we do about WordPress security
Documentation and guides
Source code and issues on GitHub

延伸相關外掛

文章
Filter
Mastodon