跳至主要內容
WordPress.org

Taiwan 正體中文

  • 佈景主題目錄
  • 外掛目錄
  • 最新消息
  • 技術支援
  • 關於我們
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

Cerrojo Security Toolkit

  • 提交外掛
  • 我的最愛
  • 登入
  • 提交外掛
  • 我的最愛
  • 登入

Cerrojo Security Toolkit

由 carlose119 開發
下載
  • 詳細資料
  • 使用者評論
  • 安裝方式
  • 開發資訊
技術支援

外掛說明

Cerrojo Security Toolkit adds focused security diagnostics and reversible, opt-in controls under Tools > Cerrojo Security Toolkit.

Current tools include:

  • Security posture diagnostics with links to native WordPress Site Health.
  • A file editor control that stores a plugin preference without editing wp-config.php.
  • Best-effort login protection with temporary, progressive throttling.
  • XML-RPC pingback protection that removes native inbound pingback methods and the WordPress-filtered X-Pingback header.
  • Staged HTTP security header policies with baseline, optional groups, compatibility warnings, and rollback controls.
  • Email alerts for supported plugin installation and activation events.
  • Email alerts for supported administrator account lifecycle events.
  • URL Change Alerts for supported successful local WordPress Address and Site Address updates.
  • Selective REST API blocking by HTTP method and registered route template. Matching rules apply to all callers, including administrators and authenticated integrations.

Controls are designed to be reviewed, enabled, verified, and reversed individually. Coverage depends on the WordPress hooks and serving paths described in each tool. Login throttling is best-effort, email delivery depends on the site’s mail transport, and headers must be verified at every cache, proxy, CDN, and origin edge.

Cerrojo Security Toolkit is not a web application firewall or malware scanner. It does not certify a site or guarantee complete protection. Use it as one layer in a broader security and recovery plan.

Saved settings remain until you change them. Deactivation stops the plugin’s runtime behavior but preserves its settings, metrics, and temporary state. The plugin currently provides no uninstall cleanup routine.

安裝方式

  1. Upload the plugin files to /wp-content/plugins/cerrojo-security-toolkit/, or install the plugin through the WordPress Plugins screen.
  2. Activate Cerrojo Security Toolkit through the Plugins screen.
  3. Open Tools > Cerrojo Security Toolkit.
  4. Review the diagnostics before enabling controls.
  5. Enable one control at a time, verify site behavior and integrations, and keep an independent recovery path available.

常見問題集

Does Cerrojo Security Toolkit guarantee that my site is secure?

No. It provides diagnostics and bounded hardening controls. It is not a WAF, malware scanner, certification, or complete protection guarantee.

Can I reverse the settings?

Yes. The settings UI provides controls to disable or clear plugin-managed policies. Some effects outside WordPress, such as an HSTS policy already remembered by a browser or email already handed to a mail server, cannot be recalled immediately.

Who is affected by a blocked REST route?

Every caller whose request matches the selected HTTP method and registered route template. There are no administrator, capability, cookie, or Application Password exemptions.

What do URL Change Alerts observe?

URL Change Alerts are independently opt-in under Tools > Cerrojo Security Toolkit > Hardening. Enable the tool, enter one to 50 valid recipient addresses separated by commas or new lines, and save. There is no administrator-email fallback and no reuse of recipients from another alert tool. Disabling preserves recipients for a later re-enable.

The tool observes only successful update_option_home and update_option_siteurl hooks for the existing home and siteurl settings in the current local-blog context. They are separate settings, so each successful update is a separate event. It does not observe option additions, deletions, network options, direct SQL or file changes, or scheduled scans, and it does not switch sites or fan out on multisite.

A changed raw string is observed even when redaction or truncation makes the displayed references identical. Displayed values remove user information, query strings, and fragments; invalid values are Unavailable. Paths are retained when available and may be sensitive. Cerrojo makes one plain-text wp_mail attempt per recipient; an attempt is not delivery. Mail failures do not block a WordPress update or trigger automatic rollback.

Does uninstalling remove saved data?

No. This version has no uninstall cleanup routine, so plugin-owned settings remain unless they are changed or removed separately.

使用者評論

這個外掛目前沒有任何使用者評論。

參與者及開發者

以下人員參與了開源軟體〈Cerrojo Security Toolkit〉的開發相關工作。

參與者
  • carlose119

將〈Cerrojo Security Toolkit〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

變更記錄

0.3.0

  • Added a read-only debug-display diagnostic.
  • Expanded runtime compatibility reporting to include WordPress 7.1.
  • Verified integration smoke on WordPress 7.1.2 with PHP 8.4.

0.2.2

  • Includes URL Change Alerts, which have been available on master since 0.2.1.
  • Sanitized nonce input, scoped enqueued admin CSS, and replaced URL parsing with wp_parse_url().
  • Renamed the plugin entrypoint and packaged plugin assets. Existing installations may need reactivation after the entrypoint rename.

0.2.1

  • Corrected the public name, text domain, and package slug to avoid an existing WordPress update identity collision.

0.2.0

  • Added an actionable security dashboard and staged HTTP security header policies.
  • Added login protection and XML-RPC pingback protection.
  • Added plugin activity and administrator account alerts.
  • Added selective REST API blocking by HTTP method and registered route template.
  • Improved WordPress.org packaging and directory compliance.

0.1.0

  • Initial release.

中繼資料

  • 版本 0.3.0
  • 最後更新 2 週前
  • 啟用安裝數 少於 10 次
  • WordPress 版本需求 6.8 或更新版本
  • 已測試相容的 WordPress 版本 7.1.2
  • PHP 版本需求 8.1 或更新版本
  • 語言
    English (US)
  • 標籤:
    hardeninglogin securityrest-apisecuritySecurity Headers
  • 進階檢視

評分

這個項目尚無任何評論記錄。

撰寫評分

查看全部使用者評論

參與者

  • carlose119

技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

檢視技術支援論壇

  • 關於我們
  • 最新消息
  • 主機代管
  • 隱私權
  • 展示網站
  • 佈景主題目錄
  • 外掛目錄
  • 區塊版面配置目錄
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • 活動
  • 贊助基金會 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Taiwan 正體中文

  • 查看我們的 X (之前的 Twitter) 帳號
  • 造訪我們的 Bluesky 帳號
  • 造訪我們的 Mastodon 帳號
  • 造訪我們的 Threads 帳號
  • 造訪我們的 Facebook 粉絲專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • 造訪我們的 TikTok 帳號
  • Visit our YouTube channel
  • 造訪我們的 Tumblr 帳號
程式碼,如詩
The WordPress® trademark is the intellectual property of the WordPress Foundation.