
內容簡介
版本: 1.6.7
您可以在日文網頁和英文網頁上找到文件、常見問題和更詳細的資訊。
安裝SiteGuard WP Plugin後,WordPress安全性會得到提高。
本外掛是一個專門針對暴力登錄攻擊的防護和管理功能的安全外掛。
注意事項
不支援WordPress的多站點功能。
僅支援Apache 1.3和2.x的Web伺服器。
若要使用CAPTCHA功能,php必須安裝mbstring和gd擴展庫。
若要使用管理頁面篩選功能和登錄頁面更改功能,Apache必須加載mod_rewrite。
若要使用WAF Tuning Support,WAF(SiteGuard Server Edition)必須在Apache上安裝。
以下是功能列表。
管理員頁面IP篩選
這是一個用於保護管理頁面(wp-admin下)免受攻擊的功能。
對於從未登錄管理頁面的連線源IP地址,會返回404(未找到)。
登錄時會記錄連線源IP地址,允許訪問該頁面。
連續24小時未登入的連線源IP地址會被刪除。
可以指定要排除此功能的URL(wp-admin下)。
更改登錄頁面
這是為了減少非法登錄嘗試攻擊(如暴力攻擊或密碼列表攻擊)的漏洞而設計的功能。
更改登錄頁面名稱(wp-login.php)。初始值為“login_<5個隨機數字>”,但可以改成喜歡的名稱。
CAPTCHA
這是為了減少非法登錄嘗試攻擊(如暴力攻擊或密碼列表攻擊),或減少評論垃圾郵件的功能。
可以選擇平假名和字母數字作為CAPTCHA字符。
登錄鎖定
這是為了減少非法登錄嘗試攻擊(如暴力攻擊或密碼列表攻擊)的漏洞而設計的功能。
特別是用於防止自動攻擊。登錄失敗次數在指定時間內達到指定次數的連線源IP地址將會被封鎖指定時間。
每個使用者帳戶都不會被鎖定。
登錄警報
這是為了更容易地注意到未經授權的登錄而設計的功能。登錄用戶登錄時會收到電子郵件。
如果您收到未登錄的郵件,請懷疑未經授權的登錄。
一次失敗
這個功能是為了降低密碼列表攻擊的漏洞。即使登錄輸入正確,第一次登錄也必定失敗。
5秒或更長時間之後,在60秒內,再次輸入正確的登錄輸入即可登錄成功。在第一次登錄失敗時,會顯示以下錯誤消息。
禁用Pingback
禁用Pingback功能,防範其濫用。
阻止作者查詢
防止因「/?author =」訪問而洩露使用者名稱。
更新通知
安全的基礎是始終使用最新版本。如果WordPress核心,外掛和主題有更新,就會通知。
外掛標籤
開發者團隊
📦 歷史版本下載
原文外掛簡介
SiteGuard WP Plugin helps protect WordPress sites by strengthening login and admin-area security. It helps reduce brute-force login attacks, password list attacks, comment spam, and unauthorized access to /wp-admin/.
Main Features
Admin Page IP Filter: Restricts wp-admin access to IP addresses that have successfully logged in.
Rename Login: Changes the URL of the login page from wp-login.php to a custom path.
CAPTCHA: Adds CAPTCHA to login, comment, password reset, and user registration forms.
Login Lock: Temporarily locks out IP addresses after repeated failed login attempts.
Login Alert: Sends email notifications when users log in.
Fail Once: Intentionally rejects the first valid login attempt and requires the user to try again shortly after.
Protect XML-RPC: Disables pingbacks or all XML-RPC access to help prevent abuse.
Block Author Query: Helps prevent username leakage through /?author=
Update Notifications: Sends email notifications when updates are available for WordPress core, plugins, or themes.
WAF Tuning Support: Creates exclusion rules to help prevent false positives when SiteGuard Server Edition WAF is installed.
Requirements and Compatibility
WordPress multisite is not supported.
Apache 1.3, Apache 2.x, and Nginx are supported.
CAPTCHA requires the PHP extensions mbstring and gd.
WAF Tuning Support requires SiteGuard Server Edition on Apache.
Documentation
Documentation, FAQs, and more details are available in English and Japanese.
Translations
This plugin is translated by the community. We appreciate your help with translations on the WordPress translation platform.
