[WordPress] 外掛分享: VMP Security – Firewall, Malware Scan, and Login Security

首頁外掛目錄 › VMP Security – Firewall, Malware Scan, and Login Security
WordPress 外掛 VMP Security – Firewall, Malware Scan, and Login Security 的封面圖片
全新外掛
安裝啟用
★★★★
4.5/5 分(2 則評價)
6 天前
最後更新
問題解決
WordPress 5.0+ PHP 7.4+ v2.3.1 上架:2025-10-29

內容簡介

VMP Security 是一款免費的 WordPress 安全外掛,提供超過 280 條即時防火牆規則和 9 種專業惡意程式掃描器,能有效防範各種網路攻擊,並確保網站安全性,無需將檔案和資料庫外洩。

【主要功能】
• 超過 280 條即時防火牆規則
• 9 種專業惡意程式掃描器
• 國家封鎖功能,免費使用
• 暴力破解與速率限制保護
• 兩步驟驗證,支援 WooCommerce
• 審計日誌與即時流量監控

外掛標籤

開發者團隊

⬇ 下載最新版 (v2.3.1) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「VMP Security – Firewall, Malware Scan, and Login Security」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

POWERFUL WORDPRESS SECURITY, FIREWALL & MALWARE SCANNER PLUGIN
Every day, 3,500 websites are hacked or infected with malware. Don’t leave your site exposed. VMP Security is a powerful WordPress security plugin that gives you 750+ firewall rules, 9 specialized malware scanners, 170,000+ threat signatures, country blocking, audit log preview, two-factor authentication, and brute force protection. Free runs the full rule set and signature corpus on your site — new additions reach Free 30 days after Premium. Everything runs on your server, ensuring full website security and data privacy. Your files and database never leave your hosting environment.
Remember, most WordPress security plugins hold back critical protection behind paywalls or delay updates for free users.
VMP Security doesn’t.
What’s Included
✅ Web Application Firewall — 750+ rules running on your site (new rule additions reach Free 30 days after Premium), zero-day detection, pre-WordPress execution mode
✅ 9 Malware Scanners — Malware, file integrity, CVE, user accounts, content, public files, server state, binary, domain reputation
✅ Country Blocking — Block by country, login-only or full-site (free — competitors charge for this)
✅ Brute Force & Rate Limiting — Login limits, leaked password detection, bot throttling
✅ Two-Factor Authentication — QR setup, backup codes, role enforcement, WooCommerce support
✅ Audit Log & Live Traffic — Complete security event history with real-time monitoring
✅ Privacy-First — All scanning on your server. Files and database never sent externally.
See It In Action

How VMP Security Compares
+------------------------------+-------------------+-------------------+----------------------------+
| Feature | VMP Security Free | Wordfence Free | Wordfence Premium ($149/yr)|
+------------------------------+-------------------+-------------------+----------------------------+
| Firewall rules | ✅ - 750+ | ✅ | ✅ |
| Real-time rule updates | ❌ - 30-day delay| ❌ - 30-day delay | ✅ |
| Malware signatures | ✅ - 170,000+ | ✅ - 44,000+ | ✅ - 44,000+ |
| Real-time signature updates | ❌ - 30-day delay| ❌ - 30-day delay | ✅ |
| Malware scanners | ✅ 9 specialized | ✅ 1 general | ✅ 1 general |
| Country blocking | ✅ | ❌ | ✅ |
| Audit log | ✅ | ❌ | ✅ |
| IP blocklist | ✅ | ❌ | ✅ |
| Two-factor authentication | ✅ | ✅ | ✅ |
+------------------------------+-------------------+-------------------+----------------------------+

🔥 Web Application Firewall (WAF)
Your first line of defense. Every request is inspected before it reaches WordPress. Blocks malicious traffic in real time, stopping threats before they can execute or exploit vulnerabilities. Runs before WordPress loads, reducing attack surface and protecting plugins, themes, and core files.
What It Stops:

SQL injection, cross-site scripting, code injection, file inclusion attacks, and more — all major attack types covered
750+ built-in security rules — full rule set running on Free; new rule additions reach Free 30 days after Premium
Zero-day protection — pattern-based detection catches new, unknown threats
Custom rules — add your own blocking patterns
Attack logging — full audit trail of every blocked request

Extended Protection (WAF Optimizer)
Run the firewall before WordPress loads, so malicious requests are blocked before any vulnerable plugin or theme code can execute. One-click setup with automatic server detection for Apache and LiteSpeed, and built-in backup for safe configuration. Improves WordPress security by reducing attack surface, preventing exploit execution, and strengthening overall firewall protection at the earliest entry point.
🔍 9 Specialized Malware Scanners
Not just a basic malware scanner. This is a complete WordPress malware scanner and website security system with 9 specialized scanners, each focused on a different threat type to ensure full protection.
Detect, analyze, and remove threats with advanced scanning built for modern WordPress security vulnerabilities and malware attacks.

Malware Scanner — 170,000+ signatures detect backdoors, trojans, and malicious code
File Integrity Monitor — Compares your files against official WordPress checksums
Vulnerability Scanner — Checks plugins and themes against known CVEs
User Security Scanner — Finds suspicious admin accounts and weak credentials
Content Safety Scanner — Detects malicious content injected into posts and comments
Public Files Scanner — Finds exposed configuration files (wp-config backups, .env, debug logs)
Server State Scanner — Audits PHP settings, file permissions, and server configuration
Binary Scanner — Detects malware embedded in images and executables
Domain Reputation Scanner — Checks URLs against Google Safe Browsing and threat databases

Advanced detection goes beyond traditional malware scanners by using multiple analysis layers to identify both known and unknown threats. Obfuscation analysis detects encoded and hidden malware that basic security plugins often miss, while behavior analysis identifies suspicious file activity and unusual patterns that may indicate new or evolving attacks. A built-in legitimacy assessment helps reduce false positives, ensuring more accurate and reliable malware detection.
You can choose from quick scan, standard scan, high sensitivity scan, or fully custom scan modes based on your website security needs. This system is designed for complete WordPress malware removal, vulnerability detection, and full website protection, all running directly on your server without relying on external scanning services.
🌍 Country Blocking & IP Management
Block entire countries or fine-tune access with advanced pattern rules. Strengthen your WordPress security by controlling who can access your site based on location, IP address, and request behavior, helping prevent brute force attacks, spam traffic, and malicious bot activity.

Geo-Blocking — Block any country, login-only or full site access
IP Blocking — Block individual IPs or IP ranges, temporary or permanent
Custom Patterns — Block by hostname, user agent, referrer, or IP range with wildcard and regex support
Attack Analytics — See which countries attack you most with visual reports
Allowlist — Whitelist trusted IPs and services to bypass all blocks
GeoIP Integration — Automatic IP-to-country lookup with auto-updating database

🛡️ Brute Force Protection & Rate Limiting
Stop password guessing and resource exhaustion attacks. Strengthen your WordPress login security with advanced brute force protection, rate limiting, and bot blocking to prevent unauthorized access, credential stuffing, and automated attacks.

Smart Login Limiting — Lock out IPs after too many failed login attempts
Leaked Password Detection — Check passwords against known breach databases
Strong Password Enforcement — Require secure passwords for all user roles
Username Blacklist — Block common attack usernames instantly
Rate Limiting — Cap requests per IP to stop scrapers and vulnerability scanners
Human vs Bot Detection — Smart traffic classification with 404 monitoring

🔐 Two-Factor Authentication (2FA)
Even if someone steals your password, they can’t get in. Add an extra layer of WordPress login security with secure two-factor authentication to prevent unauthorized access, account takeovers, and brute force login attacks.

QR Code Setup — Works with Google Authenticator, Authy, 1Password, and more
Backup Codes — Never get locked out of your own site
Role Enforcement — Require 2FA for admins or specific user roles
Frontend Management — Users manage their own 2FA via shortcode
WooCommerce & XML-RPC — Covers your store and API endpoints

📊 Dashboard, Monitoring & Tools
Set it up in 5 minutes. Go deep when you want to. Manage your WordPress security dashboard with real-time monitoring, detailed audit logs, and advanced security tools to track threats, analyze activity, and take instant action.

Security Status — Green, yellow, or red — know your protection level at a glance
Live Traffic View — Watch visitors and attacks in real-time with human vs. bot classification
Complete Audit Log — Every security event tracked with timestamps and IP intelligence
Scheduled Scans — Daily, weekly, or custom scan schedules
One-Click Actions — Block IPs, ignore false positives, repair infected files
Diagnostics — 15+ system health checks for troubleshooting
Settings Export/Import — Backup and migrate security configuration between sites
Multi-Site Sync — Manage security across multiple WordPress sites from one place

🔒 Privacy-First Security
All scanning happens on YOUR server. Period. Protect your WordPress website security and data privacy with local malware scanning and firewall processing, ensuring your files, database, and user data never leave your hosting environment.
What We DON’T Do:
❌ We don’t send your file content or database data to external servers
❌ We don’t track your users
❌ We don’t collect analytics about your site
❌ We don’t send data without your knowledge
🚀 Premium Features (Upgrade for Advanced Protection)
Unlock advanced WordPress security, firewall protection, and malware detection with powerful premium features designed for complete website protection:
* Real-Time Firewall Rules – Get instant protection with continuously updated WAF rules (no delays)
* Real-Time Malware Signatures – Detect the latest threats with up-to-date malware intelligence
* Advanced Malware Detection – Enhanced scanning for hidden, obfuscated, and zero-day threats
* Full Audit Log – Complete security event history with extended tracking and detailed insights
* Country Blocking (GeoIP) – Block traffic by country for better control and attack prevention
* Advanced Analytics & Reporting – Deeper insights into attacks, traffic patterns, and security events
* Priority Support – Faster assistance from our security team
* Off-Site Audit Log Sync – Tamper-proof off-site logging via VMP Security Portal
* Continuous Updates & New Features – Stay protected with the latest security improvements
External Services (Optional):
We use external services only when necessary for specific security features. You can see exactly what’s sent:
VMP Security Servers
* License activation and validation (free/premium)
* WAF rules synchronization and updates
* Malware signature database updates
* Two-Factor Authentication (2FA) system management
* Settings export/import cloud storage (optional)
* Privacy: Your site data remains on your server — only configuration and security rules are synced
Google Services (safebrowsing.googleapis.com, www.google.com/recaptcha)
* URL threat detection and reCAPTCHA spam protection
* Privacy: https://policies.google.com/privacy
WordPress.org APIs (api.wordpress.org, downloads.wordpress.org, core.svn.wordpress.org)
* Download original files for integrity checking during malware scans
* Privacy: https://wordpress.org/about/privacy/
GitHub (raw.githubusercontent.com)
* Download WordPress core files for file comparison
IP Lookup Services (api.ipify.org, ifconfig.me, icanhazip.com, ip-api.com, ipwhois.app, download.ip2location.com)
* Server IP detection, geolocation, and country blocking features
Threat Intelligence (api.urlvoid.com, www.virustotal.com, checkurl.phishtank.com)
* URL reputation checking and threat validation
Vulnerability Databases (services.nvd.nist.gov, wpscan.com, cvedetails.com, cve.mitre.org)
* Check for known security vulnerabilities during scans
All malware scanning happens on YOUR server. We do not upload your files or database content to external services.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon