跳至主要內容
WordPress.org

Taiwan 正體中文

  • 佈景主題目錄
  • 外掛目錄
  • 最新消息
  • 技術支援
  • 關於我們
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

Shakvaro Shield

  • 提交外掛
  • 我的最愛
  • 登入
  • 提交外掛
  • 我的最愛
  • 登入

Shakvaro Shield

由 Shakil Ahamed 開發
下載
  • 詳細資料
  • 使用者評論
  • 安裝方式
  • 開發資訊
技術支援

外掛說明

Shakvaro Shield is a comprehensive WordPress security plugin designed to protect your site against the most common and advanced threats. It combines a Web Application Firewall (WAF), brute force protection, Two-Factor Authentication, file integrity monitoring, and a full suite of hardening checks into a single, well-organized package. Whether you run a personal blog or a high-traffic business site, Shakvaro Shield gives you enterprise-grade security without the complexity.

At the heart of Shakvaro Shield is a Web Application Firewall that loads via an auto-installed mu-plugin, allowing it to inspect and block malicious requests before WordPress and other plugins even begin to load. The firewall ships with six built-in rules covering SQL injection, cross-site scripting (XSS), directory traversal, file inclusion, and other common attack vectors. Alongside the WAF, Shakvaro Shield performs 15 security hardening checks and calculates an A-F health score so you can see your site’s security posture at a glance. Each check includes a one-click fix or clear remediation instructions, making it easy to bring your score up to an A.

Login security is where Shakvaro Shield truly shines. Brute force protection uses progressive lockouts that increase in duration with each failed attempt, effectively neutralizing automated attacks. Two-Factor Authentication supports any TOTP-compatible authenticator app and generates single-use backup codes so users are never locked out. You can also set a custom login URL to hide wp-login.php entirely, enforce password strength policies, and add CAPTCHA verification using reCAPTCHA v3, Cloudflare Turnstile, or a lightweight math-based fallback that requires no external service.

Shakvaro Shield is built for performance. The entire plugin is under 1 MB, uses PSR-4 autoloading so classes are only loaded when needed, and adds zero JavaScript or CSS to your site’s frontend. File integrity monitoring verifies WordPress core files and installed plugins against official WordPress.org checksums, alerting you to unauthorized changes. Every security-relevant action is recorded in a searchable activity log with over 30 event types, and email notifications use intelligent throttling and optional daily digests so you stay informed without inbox overload. A guided setup wizard walks you through initial configuration in under two minutes.

External services

Shakvaro Shield can connect to the external services below. All are opt-in and default OFF unless marked “automatic”. For each: what is sent and the provider’s Terms/Privacy. Disable any opt-in service by un-checking it in the matching admin tab or leaving its API key empty.

  1. Shakvaro Network Intel (own SaaS, optional) – aggregated IP reputation/blocklist + opt-in failed-login digests. Sends: SHA-256 hash of the site URL, plugin version, offending IP, hashed username. No plaintext usernames/emails/passwords/content. Endpoints: https://api.shakvaro.com/network-intel/{blocklist,report,digest}. Terms: https://shakvaro.com/terms – Privacy: https://shakvaro.com/privacy

  2. Shakvaro WP Insights (own SaaS, optional, OFF by default, two-tier consent) – opt-in usage analytics. Sends: WP/PHP/MySQL versions, theme, locale, multisite, server, plugin version, feature on/off states + coarse buckets (hardening grade, active rule count, CAPTCHA provider), and a one-way hash of site URL+title. No IPs, usernames, emails, passwords, keys, or content. Opt out any time from Settings -> Data Sharing (sends a deletion request). Endpoint: https://track.shakvaro.cloud. Terms: https://shakvaro.com/terms – Privacy: https://shakvaro.com/wp-insights/privacy

  3. WordPress.org checksums (automatic, file integrity) – sends WP version/locale + plugin/theme slug+version (public). Endpoints: https://api.wordpress.org/core/checksums/1.0/, https://downloads.wordpress.org/plugin-checksums/. Privacy: https://wordpress.org/about/privacy/

  4. Have I Been Pwned – Pwned Passwords (optional) – sends only the first 5 chars of a SHA-1 password hash (k-anonymity); the plaintext password never leaves the site. Endpoint: https://api.pwnedpasswords.com/range/. Privacy: https://haveibeenpwned.com/Privacy

  5. Cloudflare Turnstile (optional CAPTCHA) – sends the Turnstile token, user IP, and site secret key. Endpoint: https://challenges.cloudflare.com/turnstile/v0/siteverify. Terms: https://www.cloudflare.com/website-terms/ – Privacy: https://www.cloudflare.com/privacypolicy/

  6. Google reCAPTCHA v3 (optional CAPTCHA) – sends the reCAPTCHA token, user IP, and site secret key; Google’s script also collects browser signals. Endpoint: https://www.google.com/recaptcha/api/siteverify. Terms: https://policies.google.com/terms – Privacy: https://policies.google.com/privacy

  7. WPScan (optional vulnerability data) – sends installed plugin slugs and your WPScan API token. Endpoint: https://wpscan.com/api/v3/plugins/. Terms: https://wpscan.com/terms/ – Privacy: https://automattic.com/privacy/

  8. Patchstack (optional vulnerability data) – sends your Patchstack API key. Endpoint: https://patchstack.com/database/api/v2/vulnerabilities. Privacy: https://patchstack.com/privacy-policy/

  9. NIST NVD (optional CVE enrichment) – sends a public CVE identifier. Endpoint: https://services.nvd.nist.gov/rest/json/cves/2.0. Privacy: https://www.nist.gov/privacy-policy

  10. Google Safe Browsing (optional URL reputation) – sends the URLs being checked and your Safe Browsing API key. Endpoint: https://safebrowsing.googleapis.com/v4/threatMatches:find. Terms: https://policies.google.com/terms – Privacy: https://policies.google.com/privacy

  11. PagerDuty Events (optional alerts) – sends an alert payload (title, severity, summary) and the routing key. Endpoint: https://events.pagerduty.com/v2/enqueue. Terms: https://www.pagerduty.com/terms-of-service/ – Privacy: https://www.pagerduty.com/privacy-policy/

  12. Datadog Logs (optional log forwarding) – sends event log entries and the API key. Endpoint: https://http-intake.logs..datadoghq.com/api/v2/logs. Terms: https://www.datadoghq.com/legal/terms/ – Privacy: https://www.datadoghq.com/legal/privacy/

  13. ip-api.com (optional GeoIP fallback) – sends the visitor IP address. Endpoint: http://ip-api.com/json/. Terms/Privacy: https://ip-api.com/docs/legal

  14. Sucuri SiteCheck (optional URL reputation) – sends the URL being checked. Endpoint: https://sitecheck.sucuri.net/api/v3/. Terms: https://sucuri.net/terms/ – Privacy: https://sucuri.net/privacy/

螢幕擷圖

Security Dashboard with health score grading and at-a-glance security overview.
Security Dashboard with health score grading and at-a-glance security overview.
Firewall settings and real-time block log showing intercepted threats.
Firewall settings and real-time block log showing intercepted threats.
Login security configuration including brute force, 2FA, custom URL, and CAPTCHA.
Login security configuration including brute force, 2FA, custom URL, and CAPTCHA.
File integrity scan results comparing core and plugin files against official checksums.
File integrity scan results comparing core and plugin files against official checksums.
Activity log with advanced filtering by event type, user, date range, and severity.
Activity log with advanced filtering by event type, user, date range, and severity.

安裝方式

  1. Upload the plugin folder to the /wp-content/plugins/ directory, or install the plugin directly through the WordPress plugin screen by searching for “Shakvaro Shield”.
  2. Activate the plugin through the “Plugins” screen in WordPress.
  3. Navigate to Shakvaro Shield > Dashboard in the admin menu. The setup wizard will launch automatically on first activation.
  4. Follow the wizard steps to configure hardening options, firewall rules, login security settings, and notification preferences.
  5. Once the wizard is complete, Shakvaro Shield will automatically install its mu-plugin component for early firewall loading. No manual file copying is required.
  6. Visit the Dashboard to review your security health score and address any recommended actions.

常見問題集

What are the minimum PHP and WordPress versions required?

Shakvaro Shield requires PHP 7.4 or higher and WordPress 6.2 or higher. PHP 8.0+ is recommended for the best performance. The plugin is tested up to WordPress 6.7 and PHP 8.3.

Does Shakvaro Shield slow down my site?

No. Shakvaro Shield is designed with performance as a priority. It adds zero JavaScript or CSS to your frontend pages, uses PSR-4 autoloading so only the classes needed for each request are loaded, and the entire plugin weighs under 1 MB. The mu-plugin firewall component is extremely lightweight and adds negligible overhead to request processing.

What is the mu-plugin and why does Shakvaro Shield install one?

The mu-plugin (must-use plugin) is a small firewall loader that WordPress executes before regular plugins. This allows Shakvaro Shield’s Web Application Firewall to inspect and block malicious requests at the earliest possible stage, before any vulnerable plugin code has a chance to run. The mu-plugin is installed and removed automatically when you activate or deactivate Shakvaro Shield.

Can I use Shakvaro Shield alongside other security plugins?

Shakvaro Shield is designed to be a complete security solution, so running it alongside another full-featured security plugin (such as Wordfence or Sucuri) is not recommended and may cause conflicts, especially with firewall or login protection features. However, Shakvaro Shield can coexist with specialized plugins that handle only backups, uptime monitoring, or spam filtering.

How does Two-Factor Authentication work?

Shakvaro Shield supports Time-Based One-Time Password (TOTP) authentication, which is compatible with apps like Google Authenticator, Authy, and 1Password. When 2FA is enabled, users scan a QR code during setup and then enter a six-digit code from their authenticator app each time they log in. Ten single-use backup codes are also generated so users can regain access if they lose their authenticator device.

What happens if I get locked out of my site?

If you are locked out due to brute force protection, the lockout will expire automatically after the configured duration. If you have lost access to your 2FA device, you can use one of your backup codes to log in. As a last resort, you can disable Shakvaro Shield by connecting to your server via FTP or file manager and renaming the plugin folder (e.g., to shakvaro-shield-disabled) and removing the file wp-content/mu-plugins/shakvaroshield-firewall.php.

Where are activity logs stored?

Activity logs are stored in a custom database table within your WordPress database. This ensures fast querying and filtering without creating files on the filesystem. Logs can be exported to CSV from the Shakvaro Shield > Tools page. By default, log entries older than 90 days are automatically purged to keep your database lean.

How do email notifications work?

Shakvaro Shield sends email alerts for critical security events such as blocked attacks, failed login attempts exceeding your threshold, file integrity changes, and lockouts. To prevent notification fatigue, emails are throttled so that repeated events of the same type are batched. You can also enable a daily digest that summarizes all security activity from the past 24 hours in a single email.

使用者評論

這個外掛目前沒有任何使用者評論。

參與者及開發者

以下人員參與了開源軟體〈Shakvaro Shield〉的開發相關工作。

參與者
  • Shakil Ahamed
  • shakvaro

將〈Shakvaro Shield〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

變更記錄

1.0.2

  • Updated the bundled Shakvaro WP Insights telemetry SDK to 1.2.7.
  • Hardened the uninstall routine against a fatal error (“Cannot redeclare class”) that could occur when another Shakvaro plugin sharing the same telemetry SDK was installed: the SDK class is now loaded with a class_exists() guard before use.

1.0.1

  • Security Headers hardening check: replaced the one-click fix with clear manual instructions (Apache .htaccess / nginx add_header). PHP-set headers can be stripped by a reverse proxy or CDN, or skipped when SSL terminates upstream, so server-level configuration is the reliable fix. The check itself is unchanged and works on any server (it inspects the live HTTP response).
  • Added a Shakvaro credit: a “Support” link on the Plugins screen and a “built and maintained by Shakvaro” footer on the plugin’s admin pages.

1.0.0

  • Initial release
  • Web Application Firewall with 6 built-in rules (SQLi, XSS, directory traversal, file inclusion, PHP code injection, user enumeration)
  • 15 security hardening checks with A-F health score grading
  • Brute force protection with progressive lockouts
  • Two-Factor Authentication (TOTP + backup codes)
  • File integrity monitoring (core + plugin verification against WordPress.org checksums)
  • Activity logging with 30+ event types
  • Email notifications with intelligent throttling and daily digest option
  • Custom login URL to hide wp-login.php
  • CAPTCHA support (reCAPTCHA v3, Cloudflare Turnstile, math fallback)
  • Password strength policy enforcement
  • Setup wizard for first-time configuration
  • Tools: log export to CSV, system diagnostics report
  • Opt-in anonymous usage analytics (Shakvaro WP Insights) — OFF by default, requires explicit consent, fully documented under External Services

中繼資料

  • 版本 1.0.2
  • 最後更新 1 個月前
  • 啟用安裝數 少於 10 次
  • WordPress 版本需求 6.2 或更新版本
  • 已測試相容的 WordPress 版本 7.0.2
  • PHP 版本需求 7.4 或更新版本
  • 語言
    English (US)
  • 標籤:
    firewallloginmalwaresecuritytwo factor
  • 進階檢視

評分

這個項目尚無任何評論記錄。

Your review

查看全部使用者評論

參與者

  • Shakil Ahamed
  • shakvaro

技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

檢視技術支援論壇

  • 關於我們
  • 最新消息
  • 主機代管
  • 隱私權
  • 展示網站
  • 佈景主題目錄
  • 外掛目錄
  • 區塊版面配置目錄
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • 活動
  • 贊助基金會 ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Taiwan 正體中文

  • 查看我們的 X (之前的 Twitter) 帳號
  • 造訪我們的 Bluesky 帳號
  • 造訪我們的 Mastodon 帳號
  • 造訪我們的 Threads 帳號
  • 造訪我們的 Facebook 粉絲專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • 造訪我們的 TikTok 帳號
  • Visit our YouTube channel
  • 造訪我們的 Tumblr 帳號
程式碼,如詩
The WordPress® trademark is the intellectual property of the WordPress Foundation.