[WordPress] 外掛分享: Turbo Guard – Security & Malware Scanner

首頁外掛目錄 › Turbo Guard – Security & Malware Scanner
WordPress 外掛 Turbo Guard – Security & Malware Scanner 的封面圖片
全新外掛
安裝啟用
尚無評分
8 天前
最後更新
問題解決
WordPress 5.6+ PHP 7.4+ v1.1.0 上架:2026-08-22

內容簡介

Turbo Guard 是一款全面且完全免費的 WordPress 安全外掛,專為管理多個 WordPress 網站的團隊所開發。它能有效解決惡意程式碼移除、SEO 垃圾郵件清理、漏洞警報等問題,並提供 AI 驅動的指導,幫助使用者了解發生了什麼事及應對措施。

【主要功能】
• 全站掃描,檢查 PHP、JavaScript、HTML 檔案
• 檢查 WordPress 核心檔案完整性
• 偵測 30 多種惡意程式碼模式
• 提供逐步修復指導
• 實時流量分析與安全評分趨勢圖
• 每次掃描後發送電子郵件通知

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.1.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Turbo Guard – Security & Malware Scanner」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Turbo Guard is a comprehensive, 100% free WordPress security plugin built by a team that manages 40+ WordPress sites. It solves real problems: bulk malware removal, Japanese/Chinese SEO spam cleanup, vulnerability alerts, file integrity monitoring, and live traffic analysis — all with AI-powered guidance that explains what happened and exactly what to do.
AI Security Advisor

After every scan, Turbo Guard AI identifies the attack campaign (Japanese SEO spam, web shell, brute force, database injection)
Explains in plain English what happened and the business risk
Provides numbered, step-by-step fix instructions tailored to your specific threats
Optional OpenAI GPT integration for richer analysis (your own API key)
Sends email advisory after every scan
30-day security score trend chart

Malware Scanner

Full-site scan: PHP, JavaScript, HTML files across wp-content, wp-admin, wp-includes, and WordPress root
WordPress Core File Manifest check — compares every file in wp-admin and wp-includes against the official WordPress.org checksums API
Detects 30+ malware patterns: eval+base64, C99/R57/WSO web shells, hidden iframes, pharma spam, code obfuscation
Detects Japanese, Chinese, and Korean SEO spam text inside PHP files
Scans the WordPress database (wp_posts, wp_options) for injected content and rogue admin accounts
PHP-in-uploads detection, PHP-in-core-asset-dirs detection
Polyglot image backdoor detection — scans image files for embedded PHP
Smart false-positive prevention: trusted plugins and themes are never flagged for translation text
Chunked AJAX scanning with live progress bar — handles 10,000+ file sites without timeout

File Integrity and Change Detection

Verifies every WordPress core file against official WordPress.org MD5 checksums
Detects modified or missing core files
File watcher runs every 6 hours via WP-Cron — detects new, modified, and deleted files
Baseline snapshot of all wp-content PHP/JS files with MD5 comparison
Email alert when new files appear

One-Click Bulk Malware Cleanup

Shows every infected file with path, threat name, severity, and file size
Select All Critical button — delete multiple files at once
Automatic ZIP backup before any deletion
Quarantine option — moves files to a protected directory

Web Application Firewall

Blocks SQL injection, XSS, directory traversal in real time
Prevents PHP file uploads
Advanced IP blocking: exact IP, CIDR, ranges, wildcards
Rate limiting (120 requests per minute per IP)
Bad bot blocker: blocks 25+ vulnerability scanners and scrapers

Geo-Fence and Trusted Location

Restrict WordPress admin access to specific IP addresses
Country-based admin lock: only allow access from your country
Block file uploads from untrusted countries
One-click trusted IP setup

Login Security

Brute force protection with configurable thresholds and lockout duration
Login attempt logging with IP, timestamp, and user agent
Email alert when admin logs in from unrecognised IP
Auto-blocks attacker IPs in firewall after brute force detection

Two-Factor Authentication (2FA)

TOTP/RFC 6238 — compatible with Google Authenticator, Authy, and all TOTP apps
Manual secret key setup on user profile page
Recovery codes (8 single-use)
Per-user enable/disable

Vulnerability Scanner

Checks all plugins, themes, and WordPress core against WPScan vulnerability database
CVSS severity scoring, CVE links, version-aware matching
Works without API key (optional WPScan key for higher limits)
Email alert when new vulnerabilities are found

Live Traffic Monitor

Logs every HTTP request with bot/human detection
Identifies 30+ bots including AI crawlers (GPTBot, ClaudeBot, PerplexityBot)
24-hour stats: total requests, humans, bots, blocked, errors
Paginated — handles large traffic volumes
One-click IP block from any traffic row

Site Hardening

HTTP security headers (X-Frame-Options, HSTS, X-Content-Type-Options, Referrer-Policy)
Hide WordPress version, block user enumeration
Optional: disable XML-RPC, restrict REST API, disable file editor

Google Search Console Cleanup

Connects to Google Search Console via OAuth
Detects indexed SEO spam URLs even when files are deleted from server
Bulk removal requests with one click
Sitemap resubmission after cleanup

Privacy
Turbo Guard does not send your website files to any external server. Vulnerability checks send only plugin/theme slugs and versions to the WPScan API — and only on manual scans or when scheduled vulnerability scans are enabled in Settings (off by default). Geo-Fence country blocking sends the visitor IP address to ipapi.co when enabled. 2FA is fully local: TOTP secrets are entered manually in your authenticator app and no QR service is used. GSC integration uses your own Google OAuth credentials. AI analysis (optional OpenAI) sends only anonymised threat type data. No telemetry. No tracking. No account required.
External Services
This plugin connects to external services for certain features. All connections require explicit user action or opt-in.
WordPress.org API
Used to verify WordPress core file integrity by comparing checksums.
* Data sent: WordPress version and locale
* When: Only when the user runs a malware scan or a file integrity check (including scheduled scans)
* Service: https://api.wordpress.org/
* Privacy Policy: https://wordpress.org/about/privacy/
WPScan Vulnerability Database
Used to check plugins and themes for known security vulnerabilities.
* Data sent: Plugin/theme slugs and versions
* When: Only when the user runs a manual vulnerability scan, or when scheduled vulnerability scans are enabled in Settings (off by default)
* Service: https://wpscan.com/
* Terms of Use: https://wpscan.com/terms
* Privacy Policy: https://automattic.com/privacy/
ipapi.co (Geo-Fence)
Used for IP geolocation to support country-based access and upload controls (Geo-Fence).
* Data sent: Visitor IP address
* When: Only when geo-fence country features are enabled
* Service: https://ipapi.co/
* Terms of Service: https://ipapi.co/terms/
* Privacy Policy: https://ipapi.co/privacy/
OpenAI API
Used to provide AI-powered security analysis and recommendations.
* Data sent: Anonymized scan results (no personal data or site content)
* When: Only when user explicitly clicks “AI Analysis” (requires user-provided API key)
* Service: https://api.openai.com/
* Terms of Use: https://openai.com/policies/terms-of-use
* Privacy Policy: https://openai.com/policies/privacy-policy
Google APIs (Search Console)
Used for Google Search Console integration to detect SEO spam and manage indexed URLs.
* Data sent: OAuth tokens, site URL for search analytics queries
* When: Only when user connects their Google account and initiates GSC features
* Service: https://developers.google.com/webmaster-tools
* Terms of Service: https://developers.google.com/terms
* Privacy Policy: https://policies.google.com/privacy

延伸相關外掛

文章
Filter
Mastodon