[WordPress] 外掛分享: Steel Security & Hardening – Site Audit Tools

首頁外掛目錄 › Steel Security & Hardening – Site Audit Tools
WordPress 外掛 Steel Security & Hardening – Site Audit Tools 的封面圖片
全新外掛
安裝啟用
尚無評分
3 天前
最後更新
問題解決
WordPress 6.4+ PHP 8.0+ v1.0.4 上架:2026-04-27

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.0.4) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Steel Security & Hardening – Site Audit Tools」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Steel Security & Hardening – Site Audit Tools focuses on practical security hygiene for WordPress administrators.
The free plugin provides:

on-demand security scans
risk summaries grouped by severity and category
checks for common WordPress hardening gaps
checks for exposed root-level artifacts such as .env, SQL dumps, phpinfo files, and backup archives
a quarantine vault for operator-reviewed file isolation
uploads PHP execution blocking on supported server environments
manual guidance when automatic server hardening is not safely supported

This plugin is positioned as an auditing and hardening tool. It helps surface risk and apply selected preventive controls, but it does not promise malware removal, incident response, or complete server protection.
Included checks
The scan currently looks for items such as:

PHP error display exposure
WP_DEBUG and debug.log exposure
XML-RPC availability
author and REST user enumeration exposure
theme/plugin file editor availability
WordPress generator meta output
comments enabled by default
uploads PHP execution hardening status
root-level sensitive files and archives

Server-aware behavior
This plugin only auto-applies server config changes where it can do so in a scoped and reversible way.

Apache and LiteSpeed: uploads PHP blocking is managed through a Steel Security-marked .htaccess block
IIS: uploads PHP blocking is managed through a Steel Security-marked web.config section
Nginx and unsupported environments: Steel Security provides manual guidance instead of claiming automatic protection

Pro companion
This plugin can work with a separate Pro companion plugin that adds features such as scheduled scans, scan history, reports, and managed server-level controls such as directory listing protection and baseline security headers. The free plugin remains usable on its own.

延伸相關外掛

文章
Filter
Mastodon