這個外掛並未在最新的 3 個 WordPress 主要版本上進行測試。開發者可能不再對這個外掛進行維護或提供技術支援,並可能會與更新版本的 WordPress 產生使用上的相容性問題。

Disable Feeds And Hide Usernames

外掛說明

Disable Feeds And Hide Usernames

removes the rss feeds like below. For a simple CMS site it is not required.
* http://example.com/feed/
* http://example.com/feed/rss/
* http://example.com/feed/rss2/
* http://example.com/feed/rdf/
* http://example.com/feed/atom/

Why Hide WordPress Usernames

WordPress usernames can easily be guessed. If guessed it makes the attackers’ life easier especially in case of a targeted WordPress hack attack. Attackers can use a tool such as WPScan to guess your WordPress username or simply by entering a URL such as the following:

http://www.example.com/?author=1

If the author ID is valid then they will be redirected to the author URL, for example:

http://www.example.com/author/admin

The above is possible even when you change the WordPress user IDs. For example if you changed the user ID to 1000, then by requesting the URL http://www.example.com/?author=1000 the attacker can guess the username. This means that you would be delaying the guessing attack but not completely eliminating it.

WordPress usernames can also be found in the source of rss feeds.

Disable Feeds And Hide Usernames

hides the usernames to make it harder for the attacker.

安裝方式

  1. Install using the WordPress built-in Plugin installer, or Extract the zip file and drop the contents in the wp-content/plugins/ directory of your WordPress installation.
  2. Activate the plugin through the ‘Plugins’ menu in WordPress.

使用者評論

2021 年 3 月 4 日
If you need to do what is says in the title, get it. Ignore the 2star review where someone is unhappy that it disables the feeds as well. Whoever is not OK with that - make your own plugin - its 10 lines of code if you open it (remove the lines regarding the feeds).
閱讀全部 3 則使用者評論

參與者及開發者

以下人員參與了開源軟體〈Disable Feeds And Hide Usernames〉的開發相關工作。

參與者