plugin-icon

SiteGuard WP Plugin

Плагин SiteGuard WP - это плагин, специализирующийся на защите от атак на страницу управления и входа в систему.
Рейтинги
4.3
Последние изменения
May 29, 2024
Версия
1.7.7
Активные установки
500K
SiteGuard WP Plugin

Документацию, FAQ и более подробную информацию можно найти на сайте Английская страница Японская страница.

Просто установите плагин SiteGuard WP Plugin, и безопасность WordPress будет повышена. Этот плагин представляет собой плагин безопасности, специализирующийся на атаках «грубой силы» при входе в систему, таких как возможности защиты и управления.

Заметки

  • Он не поддерживает функцию многосайтовости WordPress.
  • Он поддерживает только Apache 1.3, 2.x для Web-серверов.
  • Для использования функции CAPTCHA на php должна быть установлена библиотека расширения «mbstring» и «gd».
  • Для использования функции фильтрации страниц управления и функции изменения страницы входа в систему в Apache должен быть загружен «mod_rewrite».
  • Для использования WAF Tuning Support на Apache должен быть установлен WAF (SiteGuard Server Edition).

Имеются следующие функции.

  • IP-фильтр страницы администратора

It is the function for the protection against the attack to the management page (under wp-admin.) To the access from the connection source IP address which does not login to the management page, 404 (Not Found) is returned. At the login, the connection source IP address is recorded and the access to that page is allowed. The connection source IP address which does not login for more than 24 hours is sequentially deleted. The URL (under wp-admin) where this function is excluded can be specified.

  • Rename Login

It is the function to decrease the vulnerability against an illegal login attempt attack such as a brute force attack or a password list attack. The login page name (wp-login.php) is changed. The initial value is “login_<5 random digits>” but it can be changed to a favorite name.

  • CAPTCHA

It is the function to decrease the vulnerability against an illegal login attempt attack such as a brute force attack or a password list attack, or to receive less comment spam. For the character of CAPTCHA, hiragana and alphanumeric characters can be selected.

  • Login Lock

It is the function to decrease the vulnerability against an illegal login attempt attack such as a brute force attack or a password list attack. Especially, it is the function to prevent an automated attack. The connection source IP address the number of login failure of which reaches the specified number within the specified period is blocked for the specified time. Each user account is not locked.

  • Login Alert

It is the function to make it easier to notice unauthorized login. E-mail will be sent to a login user when logged in. If you receive an e-mail to there is no logged-in idea, please suspect unauthorized login.

  • Fail Once

It is the function to decrease the vulnerability against a password list attack. Even is the login input is correct, the first login must fail. After 5 seconds and later within 60 seconds, another correct login input make login succeed. At the first login failure, the following error message is displayed.

  • Disable Pingback

The pingback function is disabled and its abuse is prevented.

  • Block Author Query

Prevents leakage of user names due to «/?author=» access.

  • Updates Notify

Basic of security is that always you use the latest version. If WordPress core, plugins, and themes updates are needed , sends email to notify administrators.

  • WAF Tuning Support

It is the function to create the rule to avoid the false detection in WordPress (including 403 error occurrence with normal access,) if WAF ( SiteGuard Server Edition ) by EG Secure Solutions is installed on a Web server. WAF prevents the attack from the outside against the Web server, but for some WordPress or plugin functions, WAF may detect the attack which is actually not attack and block the function. By creating the WAF exclude rule, the WAF protection function can be activated while the false detection for the specified function is prevented.

Translate

If you have created your own language pack, or have an update of an existing one, you can send gettext PO and MO files to sgdev@jp-secure.com so that We can bundle it into SiteGuard WP Plugin. You can download the latest POT file, and PO files in each language.

Активные установки
500K
Проверено на
6.5.4
Этот плагин можно скачать и использовать при автономной установке WordPress.