內容簡介
Sentryvine 是一款針對 WordPress 的防病毒與防釣魚安全外掛,提供保守的安全掃描,幫助管理員檢測潛在的惡意程式和釣魚攻擊,確保網站安全。
【主要功能】
• 本地檢查可執行檔案及重定向檔案
• 偵測上傳目錄中的可執行 PHP 檔案
• 針對釣魚攻擊進行分析
• 可選的 WordPress 核心完整性驗證
• 手動掃描及每日 WP-Cron 掃描
• 限制掃描報告顯示嚴重性及建議行動
外掛標籤
開發者團隊
② 後台搜尋「Sentryvine — Antivirus & Anti-Phishing Security」→ 直接安裝(推薦)
原文外掛簡介
Sentryvine provides a conservative, review-first security scan from the WordPress administration area.
The initial release includes:
Local inspection of executable and redirect-capable files for high-signal malware patterns.
Detection of executable PHP files in the uploads directory.
Anti-phishing analysis for deceptive link text, raw IP destinations, embedded URL credentials, Punycode hosts, encoded control characters, dangerous URI schemes, and external password forms.
Optional WordPress core integrity verification against official checksums.
Manual scans and daily WP-Cron scans.
Bounded scan reports with severity, evidence, location, and recommended review actions.
Sentryvine does not automatically delete, edit, or quarantine files or content. Findings are indicators for an administrator to review; they are not proof that a site is compromised. A scan with no findings does not guarantee that a site is safe.
External services
By default, Sentryvine scans locally and does not send site files or content to an external service.
If an administrator enables “Verify WordPress core checksums,” each scan uses WordPress core’s checksum function to contact https://api.wordpress.org/core/checksums/1.0/. The request includes the installed WordPress version and locale so the service can return the matching official file hashes. WordPress HTTP requests may also include the standard WordPress user-agent. No site files, post content, detected URLs, or scan findings are sent.
This service is operated by the WordPress project. See the WordPress.org privacy policy and terms of service.
