跳至主要內容
WordPress.org

Taiwan 正體中文

  • 佈景主題目錄
  • 外掛目錄
  • 最新消息
  • 技術支援
  • 關於我們
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

Honeypot Toolkit

  • 提交外掛
  • 我的最愛
  • 登入
  • 提交外掛
  • 我的最愛
  • 登入

Honeypot Toolkit

由 Jeff Sterup 開發
下載
  • 詳細資料
  • 使用者評論
  • 安裝方式
  • 開發資訊
技術支援

外掛說明

This plugin allows you to automatically insert your Project Honeypot links into all of your pages and block IP addresses that are listed on the Http:BL list from Project Honeypot. There is an option to block IP addresses that have been blocked by Spamcop using their blacklist and the SANS Internet Storm Center API as well.
To prevent bots from using brute force attacks and scanning your site there is an option to block users that fail to login a set number of times or use blocked user names. You can also block IP addresses that generate a large number of 404 errors. This plugin will also prevent WordPress User Enumeration and automatically block anyone attempting it.

螢幕擷圖

  • Settings page
  • Blocked list page
  • Activity page
  • Whitelist page

安裝方式

  1. Extract the downloaded Zip file.
  2. Upload the ‘honeypot-toolkit’ directory to the /wp-content/plugins/ directory
  3. Activate the plugin through the ‘Plugins’ menu in WordPress
  4. Use the menu item called Honeypot Toolkit to get the plugin set up.

You should set up an account on the project honeypot website at https://www.projecthoneypot.org if you want to use Project Honeypot.

常見問題集

Where do I get the script for my honeypot?

You must sign up for an account on https://www.projecthoneypot.org. Then go to https://www.projecthoneypot.org/manage_honey_pots.php to set up your honeypot and follow the instructions. After the script has been placed on your site enter the url of your script on the Honeypot Toolkit settings page.

使用者評論

Dont forget to white list your IP Range even short

techguysa 2026 年 4 月 25 日
Warning to all make your white list range short. I thought i white listed it i know its the case on wordfence but i manage to let it think i the admin made it think it was a bot and locked me out. If this is the case use Tor browser to log in since it changes the IP there. 3 stars cause im not 100% sure if this is really working its doing some good heavy lifting but support from these pages seem non existant. not mine just other people. but if your IP is 80.50.10.125 make it 80.50.10.124 – 80.50.10.126 if it happens again cause i swear i did this im gonna loose my mind spent 1 hour trying to figure out WHIHC WAF got triggered

Amazing! A must have for every site!

dichternebel 2023 年 11 月 11 日
This plugin does the job very well. Besides using Project Honyepot and Spamcop, I really love the additional Login and 404 handling that protects from brute force attacks. In combination with a 2FA login plugin this makes me finally feel a lot safer using Wordpress. Thanks a lot!

Unfortunately does not work

thorsten107 2023 年 1 月 6 日
Nevertheless, 10 messages come to spam on day via the contact form. This plugin does not block anything

Still works

Andrea 2021 年 12 月 1 日
with version 5.8.2 (also multiste)

Does all it is designed to do

ogbcashdown 2021 年 4 月 24 日
Has been very effective in blocking malicious traffic to my site.

No logs in Honeypot activity list

Boretsyan 2021 年 2 月 14 日
Hi there, I have installed Honeypot Toolkit plugin on my website, the status is: @ – Honey Pot Active but I haven’t any data in activity list in plugin. I have verified script and the dedicated link is on all my pages but now activity yet! What should I do to enable this plugin and make it working?
閱讀全部 9 則使用者評論

參與者及開發者

以下人員參與了開源軟體〈Honeypot Toolkit〉的開發相關工作。

參與者
  • Jeff Sterup

〈Honeypot Toolkit〉外掛目前已有 2 個本地化語言版本。 感謝全部譯者為這個外掛做出的貢獻。

將〈Honeypot Toolkit〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

變更記錄

5.0.4

Added option to allow IP V6 address checking to be turned off for the Internet Storm Center API as they can report false positives.
Changed from using count to using attacks variable in Internet Storm Center API response.

5.0.3

Added check for 429 response from sans and code to respect their retry time.

5.0.2

Fixing database error on activation for multisite installs.

5.0.1

Added option to automatically retrieve the IP ranges for Googlebot and Bingbot from their developer sites and add them to the allowlist.
Added text length restriction to IP note textareas.

5.0

Added ability to use SANS Internet Storm Center API to block malicious visitors
Changed default HTTP response code to 403
Renamed whitelist to allowlist and blacklist/blocked list to blocklist to create better naming consistency
Added versioning to admin.css to bust cache and force loading of new CSS rules
Fixed typos in settings page help dialog

4.5.2

Updating help text for the settings page.
Adding documentation link to plugin meta.

4.5.1

Replacing single settings template that somehow disappeared during 4.5 update.

4.5

Updating URLs in readme to point to new site.
Bumped tested version of WordPress

4.4.4

Fixed typo in 4.4.3. Used _transient_timeout instead of _site_transient_timeout

4.4.3

Changing transients to use site transients for better compatibility with multisite installs
Added check for transients to ensure that they expire rather than living forever
Added check for empty array when no honeypot positions are selected

4.4.2

Added DNS_A argument to dns_get_record calls to only pull A records since that is all the plugin uses.
Made the logic a little more efficient for deciding if a DNS record was returned.

4.4.1

Added check to make sure honeypot link isn’t included in post excerpt if the_content hook is used.

4.4

Changed the way activity count is updated to use the primary key so the database table will not get locked.

4.3.1

Fixed missing ajax save function for content honeypot.
Fixed check on settings page to make sure honeypot locations have been saved.

4.3

Added options to set the locations where the honeypot will appear.

4.2.2

Fixed PHP warning when checking for a temporary whitelist entry and one doesn’t exist.

4.2.1

Fixed call to explode that was missing the delimiter

4.2

Changed how the server variables are handled. The variables can be a comma delimited list.
Added rel=”nofollow” to honeypot links.

4.1.2

Fixed deprecated message for PHP 7.x

4.1.1

Fixed issue on multisite installs where the plugin would check for temporary whitelist entries in a database table prefixed with the current site DB prefix. Changed $wpdb->prefix to $wpdb->base_prefix

4.1

Added functionality to temporarily whitelist an IP if it has passed the Project Honeypot and Spamcop blacklist checks. This prevents the same IP being checked multiple times while a user is visiting a site.
Fix for dropdown css on IP list pages.

4.0.9

Added the ability to enter a . in the band username field.
Added functionality to automatically whitelist the web servers IP address so it doesn’t block itself while doing a health check.

4.0.8

Improved input validation and sanatization.
Added a checkbox to the IP lists so all entries can be selected.
Added functionality to submit the search query when the enter key is pressed in the search box.
Changed the way notes are stored so line breaks will not be stripped.

4.0.7

Fixing bug with login monitoring. IP v6 addresses were not properly being blocked.
Added better notes when a user is blocked.

4.0.6

Updating scripts to use my new domain name for documentation links so plugins like wordfence don’t alert users.
Updating readme to reflect compatibility with WP 5.1.

4.0.5

Fixed styling issue with jQuery UI dialog.
Changed IP links in the admin to go to domaintools.com since they can handle IPv6 addresses.

4.0.4

Changed from using wp_get_sites to get_sites to remove a deprecated message and stop using a deprecated function.
Changed functionality when updating the check interval for Project Honeypot and Spamcop lists. Now it will reset the timeout when a new interval is set.

4.0.3

Improved functionality to check blocked IP addresses on the SPamcop and Project Honeypot lists.

4.0.2

Fixed typo to correct DB prefix in activate function

4.0.1

Made change to ensure the activate function is called when a new version is released.

4.0

Added support for blocking IPv6 addresses.
Added better support for blocking proxy addresses.
Changed validation functionality to use filter_var for IP addresses.

3.2.3

Added temporary patch for IP v6 addresses.

3.2.2

Fixed bug with transient set and get for blacklist check.

3.2.1

Fixed bug that prevented IPs on the blacklist from being removed if they weren’t on the Spamcop or Project Honeypot lists anymore.
Fixed a bug that moved the dialog box above the top of the screen during an ajax call.

3.2

Changed the process to hide usernames so that it processes 100 at a time. This way it doesn’t fail if there is a large number of users.
Hid the option to show IP lists on individual sites from the settings page if the site is not a multisite install.

3.1

Forced user nicenames to be md5 hashed when usernames are hidden regardless of whether they match the user login or not.

3.0

Added option to change an authors user nicename to an md5 hash to hide their real username.
Changed the plugin to be a network only plugin. Now all IP lists are managed at the network level for multisite installs.

Full Changelog

https://www.sterup.com/wordpress-plugins/honeypot-toolkit/changelog/

中繼資料

  • 版本 5.0.4
  • 最後更新 3 個月前
  • 啟用安裝數 400+
  • WordPress 版本需求 4.6.0 或更新版本
  • 已測試相容的 WordPress 版本 6.9.4
  • 語言

    Dutch (Belgium)、English (US)、及 Swedish.

    將這個外掛本地化為你的母語版本

  • 標籤:
    brute force protectionhoneypotlogin monitorproject honeypotspam prevention
  • 進階檢視

評分

4.3 星,滿分為 5 星
  • 7 個 5 星使用者評論 5 星 7
  • 0 個 4 星使用者評論 4 星 0
  • 1 個 3 星使用者評論 3 星 1
  • 0 個 2 星使用者評論 2 星 0
  • 1 個 1 星使用者評論 1 星 1

Your review

查看全部使用者評論

參與者

  • Jeff Sterup

技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

檢視技術支援論壇

贊助

想要支援這個外掛的發展嗎?

贊助這個外掛

  • 關於我們
  • 最新消息
  • 主機代管
  • 隱私權
  • 展示網站
  • 佈景主題目錄
  • 外掛目錄
  • 區塊版面配置目錄
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • 活動
  • 贊助基金會 ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Taiwan 正體中文

  • 查看我們的 X (之前的 Twitter) 帳號
  • 造訪我們的 Bluesky 帳號
  • 造訪我們的 Mastodon 帳號
  • 造訪我們的 Threads 帳號
  • 造訪我們的 Facebook 粉絲專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • 造訪我們的 TikTok 帳號
  • Visit our YouTube channel
  • 造訪我們的 Tumblr 帳號
程式碼,如詩
The WordPress® trademark is the intellectual property of the WordPress Foundation.