Popis
WebDmitriev Protection is a compact and efficient security solution for WordPress sites:
- Brute-Force Protection: Limits failed login attempts on
wp-login.php. - Entry Point Security: Disables XML-RPC and prevents user enumeration via REST API and author query parameters.
- File Integrity Guard: Monitors critical files (
.htaccessandwp-config.php) for unauthorized changes. - Uploads Directory Guard: Automatically blocks PHP execution inside
/wp-content/uploads/. - Lightweight WAF: Filters dangerous URL parameters (SQLi/XSS), blocks malicious User-Agent signatures, and manages IP blacklists.
Inštalácia
- Upload the
webdmitriev-protectionfolder to the/wp-content/plugins/directory. - Activate the plugin through the ‚Plugins‘ menu in WordPress.
- Go to ‚WD Protection‘ in the admin dashboard to configure settings and view threat logs.
Časté otázky
-
How does the plugin block brute-force attacks?
-
It tracks failed login attempts by IP address. If an IP exceeds 5 failed attempts within 15 minutes, access to the login form is temporarily blocked.
-
What happens if wp-config.php or .htaccess is edited?
-
The plugin calculates MD5 hashes of critical files. If a modification is detected, a notice appears in the admin panel allowing you to inspect and approve the new file state.
Recenzie
Pre tento plugin nie sú žiadne recenzie.
Prispievatelia a vývojári
“WebDmitriev Protection” je softvér s otvoreným zdrojovým kódom. Do tohto pluginu prispeli nasledujúci ľudia.
PrispievateliaPreložiť „WebDmitriev Protection“ do vašho jazyka.
Máte záujem o vývoj?
Prehľadávajte zdrojový kód, preskúmajte SVN repozitár, alebo sa prihláste na odber vývojárskeho logu cez RSS.
Zoznam zmien
1.0.0
- Initial public release.
