[WordPress] 外掛分享: Site Add-on Watchdog

首頁外掛目錄 › Site Add-on Watchdog
WordPress 外掛 Site Add-on Watchdog 的封面圖片
30+
安裝啟用
尚無評分
11 天前
最後更新
問題解決
WordPress 6.0+ PHP 8.1+ v1.8.0 上架:2025-12-21

內容簡介

Site Add-on Watchdog 是一款監控您網站外掛的工具,能夠在外掛版本落後、發現安全性修補或漏洞時發出警告,確保網站安全無虞。

【主要功能】
• 監控外掛版本更新情況
• 提供安全性修補和漏洞通知
• 支援多種通知方式(Email、Discord、Slack等)
• 自訂掃描時間表(每日、每週等)
• 本地儲存掃描結果,保護隱私
• 提供管理工具和歷史紀錄查詢

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.8.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Site Add-on Watchdog」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Site Add-on Watchdog keeps an eye on your site’s plugins and warns you when:

Your installed version is two or more minor releases behind the directory build.
The official changelog mentions security or vulnerability fixes.
(Optional) WPScan lists open CVEs for the plugin when you provide your own API key.

The plugin runs on a schedule you control—choose daily, weekly, a twenty-minute testing cadence, or rely on manual scans—and stores results locally. Nothing leaves your site unless you explicitly configure outgoing notifications.
Privacy first

No plugin inventory or telemetry is ever sent off-site by default.
Optional webhooks are opt-in and only post the detected risks.
WPScan lookups only run when you add your personal API token.

Admin tools

Focused dashboard with risk summaries, searchable history, delivery health, and manual actions.
Ignore list to suppress noisy plugins.
Validated notification settings with a save-and-test action for every channel.

Notifications

Email: send to one or more recipients separated by commas, semicolons, or spaces; site administrators are always included.
Discord: post to a channel via webhook.
Slack: connect via an incoming webhook to post alerts into any workspace channel.
Microsoft Teams: send notices through Teams Workflows or an existing Incoming Webhook connector.
Generic webhook: post JSON payload to any endpoint you control, with optional HMAC signatures. Failed deliveries are logged and highlighted on the Watchdog admin screen so you can reconfigure or resend manually.

Troubleshooting
Scheduled scans are not running
Watchdog relies on WP-Cron to trigger scheduled scans and notifications. If you have set DISABLE_WP_CRON to true or your site receives very little traffic (so WP-Cron rarely runs), configure a system cron job to call either wp-cron.php or the plugin’s REST endpoint. The admin Delivery health panel lists the REST URL you can target; a typical example looks like this:
curl -X POST https://example.com/wp-json/site-add-on-watchdog/v1/cron

Testing-mode notifications also rely on this trigger, so be sure your cron job is running when validating delivery.
CLI Usage
Watchdog bundles a WP-CLI command so you can run scans outside of the WordPress admin. All examples below assume the command is executed from a shell where wp (WP-CLI) is available.
wp watchdog scan [--notify=]

--notify (optional): Accepts true or false (defaults to true). When set to false, Watchdog will skip any configured email or webhook notifications and only record the scan locally.

Examples:

Run a scan and send notifications (default): wp watchdog scan
Run a scan silently (skip notifications): wp watchdog scan --notify=false

Recommended workflow: on CI/CD platforms, add a job step that boots your WordPress/WP-CLI container, runs pending database migrations if needed, and then calls wp watchdog scan --notify=false to verify the plugin state without spamming production channels. Promote to production by rerunning the same command with notifications enabled when you are ready to alert your team.
Development
The development repository is available on GitHub: https://github.com/happyloa/site-add-on-watchdog. Clone it locally to review the source or run the test suite.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon