Title: PowerSEC – Firewall, Malware Scanner, Login Security &amp; Backup
Author: CinderEye LLC
Published: <strong>2026 年 9 月 16 日</strong>
Last modified: 2026 年 9 月 22 日

---

搜尋外掛

![](https://ps.w.org/powersec/assets/banner-772x250.png?rev=3699113)

![](https://ps.w.org/powersec/assets/icon.svg?rev=3699113)

# PowerSEC – Firewall, Malware Scanner, Login Security & Backup

 由 [CinderEye LLC](https://profiles.wordpress.org/amoomj/) 開發

[下載](https://downloads.wordpress.org/plugin/powersec.1.4.232.zip)

 * [詳細資料](https://tw.wordpress.org/plugins/powersec/#description)
 * [使用者評論](https://tw.wordpress.org/plugins/powersec/#reviews)
 *  [安裝方式](https://tw.wordpress.org/plugins/powersec/#installation)
 * [開發資訊](https://tw.wordpress.org/plugins/powersec/#developers)

 [技術支援](https://wordpress.org/support/plugin/powersec/)

## 外掛說明

Free WordPress security: firewall/WAF, malware scanning, login protection, 2FA, 
file-integrity monitoring and local backup & restore. Protect one site with no account,
or connect many sites to the optional PowerSEC Central dashboard for monitoring,
vulnerability intelligence, cloud backups (paid) and remote management.

PowerSEC can connect to PowerSEC Central for multi-site management and vulnerability
scanning, **off by default** — see External services (1). If connected, it can toggle
WordPress’s own plugin/theme auto-updates; it never changes how core updates itself.

### External services

Each service below is contacted **only** when its feature is on; every third-party
service is **off by default**, and Central is off until an administrator connects
the site. Out of the box the only request PowerSEC makes on its own is to the first-
party WordPress.org checksum API (5); an alert channel’s “Send test” is the one 
exception, contacting the destination you typed at once. IPs and usernames may be
personal data — disclose the services you enable in your own policy. The User-Agent
is `PowerSEC/<version>` alone; see each service below.

**1. PowerSEC Central — https://powersec.io** — dashboard for multi-site management,
cloud backups, alerting, incident response. _Trigger:_ only when an administrator
connects the site. _Default:_ off.
 _Sent:_ site URL, identifiers and API keys; 
WordPress/PHP/MySQL versions; plugin and theme inventory (name, slug, version, author,
active state); site icon URL; disk, memory and database size; up to 14 days of pageview
counts; scan summaries, security event metadata and backup status; IPs of blocked
or attacking clients; administrator usernames, last login, and their email addresses(
only while two-factor is on or this server cannot send mail). If a message this 
site sends fails, its subject and body go to Central to deliver — to your own administrators
only. With two-factor on and connected, the one-time code and recipient email go
to Central to deliver (otherwise wp_mail() is used and nothing leaves the site).
Database-scan findings carry a short redacted excerpt plus its table and key; whole
posts, option values and page output never are. _Cloud backup (paid):_ archives 
on Wasabi (`*.wasabisys.com`); restores use short-lived signed URLs from `*.wasabisys.
com`, `*.amazonaws.com` or `powersec.io`. Wasabi https://wasabi.com/legal/ , https://
wasabi.com/legal/privacy-policy/ — AWS https://aws.amazon.com/service-terms/ , https://
aws.amazon.com/privacy/ _Terms_ https://powersec.io/terms — _Privacy_ https://powersec.
io/privacy

**2. Google Gemini — https://ai.google.dev** (via Central) — an AI second opinion
on a file the scanner **already flagged**.
 _Trigger:_ (a) manual — an administrator
clicks to explain one flagged file; that click is the authorisation. (b) automated—**
off by default**, needing an explicit local opt-in by an administrator of this site
under PowerSEC > Central Connection. Connecting to Central, your plan and Central’s
settings do **not** enable it; switching it off stops future sharing. _Sent:_ only
a bounded, redacted excerpt of that flagged file (size-capped, secrets redacted),
plus its path, size, hash and the matching rule. Whole files, whole sites, databases
and files that may hold credentials (`wp-config.php`, `.env`, key/certificate files)
are never sent. Advisory only: it never changes scan results, malware counts or 
your score, and never removes, quarantines or repairs a file. _Terms_ https://ai.
google.dev/gemini-api/terms — _Privacy_ https://policies.google.com/privacy

**3. GeoJS — https://get.geojs.io** — IP geolocation. _Trigger:_ only when country
blocking is enabled. _Default:_ off. _Sent:_ the visitor’s IP, to resolve its country;
cached 24h, and behind Cloudflare the country comes from Cloudflare’s header with
no external call.
 _Terms_ https://www.geojs.io/tos/ — _Privacy_ https://www.geojs.
io/privacy/

**4. Tor Project exit list — https://check.torproject.org** — the public exit-node
list. _Trigger:_ only when Tor blocking is enabled. _Default:_ off. _Sent:_ nothing;
the request carries no visitor information.
 _Privacy_ https://www.torproject.org/
about/privacy_policy/ (a public file served without an account, so no separate terms)

**5. WordPress.org — https://api.wordpress.org , https://downloads.wordpress.org**—
the official checksum APIs core itself uses. _Trigger:_ file-integrity monitoring(**
on by default**) and malware scans. _Sent:_ your WordPress version and locale for
core checksums; each plugin’s slug and version for plugin checksums. No personal
data.
 _Privacy_ https://wordpress.org/about/privacy/

**6. Alerting / SIEM destinations** — security events sent where you choose. _Trigger:_
only when you configure and enable a channel. _Default:_ off; on every plan. Kinds:
webhook URLs you supply (Slack, Discord, Splunk HEC, custom); fixed endpoints (PagerDuty`
events.pagerduty.com`, Datadog `http-intake.logs.datadoghq.com` or its regional 
host); raw syslog/CEF over UDP/TCP to a host you supply.
 _Sent:_ per event — type,
severity, message, the WordPress username involved (on a failed login this is visitor-
supplied text), client IP, timestamp, your site name and URL. Custom-webhook and
Splunk formats also include event metadata, which for a login can contain the request
path and user-agent; the others do not. _Terms/privacy:_ https://slack.com/terms-
of-service , https://slack.com/trust/privacy/privacy-policy , https://discord.com/
terms , https://discord.com/privacy , https://www.splunk.com/en_us/legal/terms.html,
https://www.splunk.com/en_us/legal/privacy-policy.html , https://www.pagerduty.com/
terms-of-service/ , https://www.pagerduty.com/privacy-policy/ , https://www.datadoghq.
com/legal/terms/ , https://www.datadoghq.com/legal/privacy/ . A webhook, Splunk 
HEC or syslog collector you supply is your own server, so its terms are yours.

**7. Your own site (loopback)** — not a third party. Long backups and scans continue
by calling your site’s own `admin-ajax.php`; nothing leaves your server.

### Privacy

Recorded locally: login attempts (attempted username, IP, time), audit log (action,
user, IP), sessions (user, IP, user-agent, times), and firewall/WAF/IP-blocking 
records (IP, path, method, user-agent). Findings describe files, not people. Retention:
audit log and login attempts about 90 days (configurable), firewall/WAF/sessions
about 30 days, remote requests about 7 days.

Blocked IPs follow their own rules, not the schedule above: a temporary block ends
by itself when it expires; a permanent block PowerSEC created automatically is removed
after about a year (configurable); one an administrator added by hand is kept until
an administrator removes it.

**Deleting the plugin keeps your data by default.** That site’s PowerSEC tables,
settings and connection details stay, so a reinstall resumes where it left off. 
Running `wp option update powersec_delete_data_on_uninstall 1` first (no screen 
for it) also drops those tables and removes PowerSEC settings, stored keys, connection
details, transients, per-account data and scheduled tasks, plus the firewall folder.
Backup and quarantine folders remain, as do the uploads PHP-execution guards. One
secret-free pending-revocation marker remains when a Central release is unconfirmed,
never reported as done. wp-admin deletion cannot notify Central, so disconnect first.

WordPress export and erasure requests are answered for records tied to a WordPress
account. IP-only records cannot reliably be linked to an email address, so they 
are not exported or erased. Where erasure would break the tamper-evident audit chain,
identifying fields are anonymised instead of deleted, and the response says so.

### Files and directories this plugin writes

Everything is written inside your uploads directory (`wp_upload_dir()`): `powersec-
backups/` (archives; deny-all `.htaccess`), `powersec-quarantine/` (detected files),`
powersec/` (firewall rules), `powersec-config-backups/` (wp-config.php copies; removed
on data deletion), plus guards stopping PHP executing in uploads. Two things write
outside uploads: the prefix change edits `wp-config.php` after backing it up, and
a restore adds `.maintenance` to the site root, removed when it ends. **Restoring
overwrites site files.**

### Credits

Chart.js v4.5.1, @kurkle/color v0.3.2 (MIT; texts in `licenses/`). https://github.
com/chartjs/Chart.js , https://github.com/kurkle/color

## 螢幕擷圖

[[

[[

[[

[[

[[

[[

## 安裝方式

 1. Install from the Plugins screen, or upload the ZIP.
 2. Activate it, then open **PowerSEC > Dashboard** to scan.
 3. (Optional) Open **PowerSEC > Central Connection** and choose **Connect automatically**.

**Multisite:** PowerSEC supports multisite through per-site activation only. Network
activation is intentionally refused, because each site keeps its own data and connection.
Activate PowerSEC separately on each site where you need it. Data deletion removes
per-user data network-wide.

## 常見問題集

### Is PowerSEC Central free?

Central has a free tier: connect sites and use the fleet dashboard. Paid plans add
cloud backups, scheduling, AI review and alerting. Every local feature works on 
every plan. Automatic AI review stays off until an administrator turns it on — see
External services (2).

## 使用者評論

![](https://secure.gravatar.com/avatar/f28d932a21f3d06dc03960012e91b2b0b5c4aa543e5cf25c889ede2e7d03bac9?
s=60&d=retro&r=g)

### 󠀁[Excellent](https://wordpress.org/support/topic/excellent-14347/)󠁿

 [longman2020](https://profiles.wordpress.org/longman2020/) 2026 年 9 月 19 日

It's a very good security plugin.

 [ 閱讀全部 1 則使用者評論 ](https://wordpress.org/support/plugin/powersec/reviews/)

## 參與者及開發者

以下人員參與了開源軟體〈PowerSEC – Firewall, Malware Scanner, Login Security & Backup〉
的開發相關工作。

參與者

 *   [ CinderEye LLC ](https://profiles.wordpress.org/amoomj/)

[將〈PowerSEC – Firewall, Malware Scanner, Login Security & Backup〉外掛本地化為台灣繁體中文版](https://translate.wordpress.org/projects/wp-plugins/powersec)

### 對開發相關資訊感興趣？

任何人均可[瀏覽程式碼](https://plugins.trac.wordpress.org/browser/powersec/)、查看
[SVN 存放庫](https://plugins.svn.wordpress.org/powersec/)，或透過 [RSS](https://plugins.trac.wordpress.org/log/powersec/?limit=100&mode=stop_on_copy&format=rss)
訂閱[開發記錄](https://plugins.trac.wordpress.org/log/powersec/)。

## 變更記錄

Full history ships in `changelog.txt`.

#### 1.4.232

 * Fix: unmodified WooCommerce, Premium Addons and Stripe SDK files are no longer
   flagged as malware.

#### 1.4.231

 * Security: the firewall now inspects large request bodies fully; notification 
   credentials never leave the site.

## 中繼資料

 *  版本 **1.4.232**
 *  最後更新 **19 小時前**
 *  啟用安裝數 **10+**
 *  WordPress 版本需求 ** 5.8 或更新版本 **
 *  已測試相容的 WordPress 版本 **7.1.2**
 *  PHP 版本需求 ** 7.4 或更新版本 **
 *  語言
 * [English (US)](https://wordpress.org/plugins/powersec/)
 * 標籤:
 * [backup](https://tw.wordpress.org/plugins/tags/backup/)[firewall](https://tw.wordpress.org/plugins/tags/firewall/)
   [login security](https://tw.wordpress.org/plugins/tags/login-security/)[malware scanner](https://tw.wordpress.org/plugins/tags/malware-scanner/)
   [security](https://tw.wordpress.org/plugins/tags/security/)
 *  [進階檢視](https://tw.wordpress.org/plugins/powersec/advanced/)

## 評分

 5 星，滿分為 5 星

 *  [  1 個 5 星使用者評論     ](https://wordpress.org/support/plugin/powersec/reviews/?filter=5)
 *  [  0 個 4 星使用者評論     ](https://wordpress.org/support/plugin/powersec/reviews/?filter=4)
 *  [  0 個 3 星使用者評論     ](https://wordpress.org/support/plugin/powersec/reviews/?filter=3)
 *  [  0 個 2 星使用者評論     ](https://wordpress.org/support/plugin/powersec/reviews/?filter=2)
 *  [  0 個 1 星使用者評論     ](https://wordpress.org/support/plugin/powersec/reviews/?filter=1)

[撰寫評分](https://wordpress.org/support/plugin/powersec/reviews/#new-post)

[查看全部使用者評論](https://wordpress.org/support/plugin/powersec/reviews/)

## 參與者

 *   [ CinderEye LLC ](https://profiles.wordpress.org/amoomj/)

## 技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

 [檢視技術支援論壇](https://wordpress.org/support/plugin/powersec/)