Title: SiteFort Security &#8211; Malware Scanner, Firewall, Login Security &amp; Hardening
Author: securewpteam
Published: <strong>2026 年 5 月 19 日</strong>
Last modified: 2026 年 7 月 20 日

---

搜尋外掛

![](https://ps.w.org/sitefort/assets/banner-772x250.png?rev=3604196)

![](https://ps.w.org/sitefort/assets/icon.svg?rev=3536884)

# SiteFort Security – Malware Scanner, Firewall, Login Security & Hardening

 由 [securewpteam](https://profiles.wordpress.org/securewpteam/) 開發

[下載](https://downloads.wordpress.org/plugin/sitefort.1.7.5.zip)

 * [詳細資料](https://tw.wordpress.org/plugins/sitefort/#description)
 * [使用者評論](https://tw.wordpress.org/plugins/sitefort/#reviews)
 *  [安裝方式](https://tw.wordpress.org/plugins/sitefort/#installation)
 * [開發資訊](https://tw.wordpress.org/plugins/sitefort/#developers)

 [技術支援](https://wordpress.org/support/plugin/sitefort/)

## 外掛說明

Most WordPress hacks start with a door someone left open. An unpatched plugin, an
exposed backup, a weak admin password. SiteFort closes these weak points before 
attackers find them, then backs that up with a firewall, login protection, and cloud
malware scanning.

Malware analysis runs in the SiteFort cloud rather than on your hosting, so full
scans stay fast even on shared servers. The free plugin is not a trial. The protections
most sites need are included without a paywall.

**[Try the Live Demo](https://demo.securewp.net/)** | [Features](https://securewp.net/wordpress-security-plugin/)
| [Free Remote Scan](https://securewp.net/security-checker/)

### Comprehensive WordPress Protection

 * **Cloud Malware Scanner:** Detects backdoors, web shells, injected code, and 
   SEO spam, with the heavy analysis running in the cloud instead of on your server.
 * **Verified Hardening:** Locks down XML-RPC, user enumeration, sensitive files,
   and PHP execution, then verifies each rule is enforced on the server, not just
   enabled in the dashboard.
 * **Firewall & Bot Filter:** Country blocking, rate limits, a community IP blocklist,
   and bot filtering that never blocks real search engines.
 * **Login Security & 2FA:** Custom login URL, CAPTCHA, brute-force lockouts, breached-
   password blocking, and role-based 2FA enforcement. No separate login plugin needed.
 * **Backdoor Admin & Account Audit:** Finds admin accounts hidden from the WordPress
   users list, plus weak, breached, and suspicious accounts.
 * **Vulnerability Checks:** Scans core, plugins, and themes against CVE intelligence
   and shows affected versions, severity, and fix guidance.
 * **Repair & Quarantine:** Quarantine suspicious files (restorable if something
   breaks) or repair infected files from clean sources in one click.
 * **Cloudflare Edge Sync:** Push IP, country, and bot rules to Cloudflare so attacks
   are blocked before they ever reach WordPress.

### WordPress Security Scanner

A single scan covers files, accounts, content, and reputation.

 * **Malware Detection:** Known files clear instantly by local hash. Only unknown
   or suspicious files go to deep cloud analysis for backdoors, web shells, injected
   code, SEO spam, and malicious redirects.
 * **File Integrity:** Catches tampered core, plugin, and theme files, and flags
   files that should not exist on the site at all.
 * **Account Security:** Flags weak, breached, and suspicious accounts, including
   backdoor admins hidden from the WordPress users list or created outside normal
   site workflows.
 * **Content & Database Safety:** Checks WordPress data locally for injected content,
   suspicious options, unsafe URLs, and spam or redirect indicators. Database content
   never leaves your site.
 * **Domain & IP Reputation:** Checks your domain and server IP against blocklists
   and abuse feeds so a listing surfaces early, before it affects traffic or email
   deliverability.
 * **Sensitive File Exposure:** Finds exposed backups, logs, config files, debug
   files, and other files attackers commonly target.
 * **Vulnerability Scanner:** Checks WordPress core, plugins, and themes for known
   vulnerabilities, affected versions, severity, and CVE references where available.

### WordPress Security Hardening

SiteFort closes the exposure points attackers check first.

 * **XML-RPC Controls:** Disable XML-RPC, restrict authentication, or block pingback
   abuse.
 * **User Enumeration Blocking:** Reduces username leaks from author archives, REST
   endpoints, and common discovery paths.
 * **Sensitive File Protection:** Blocks public access to `.env`, backups, logs,
   debug files, `.git` metadata, lock files, sample configs, and server fragments.
 * **PHP Execution Protection:** Blocks PHP execution in uploads and direct PHP 
   access inside plugin and theme folders where supported.
 * **Directory Listing Protection:** Reduces exposure from browsable upload, plugin,
   theme, or backup directories.
 * **File Editor Protection:** Disables the built-in theme and plugin file editor
   to limit damage from compromised admin accounts.
 * **REST & Application Password Controls:** Restricts risky REST access and application
   password behavior based on site needs.
 * **Version & Metadata Cleanup:** Hides WordPress version output and reduces exposed
   generator and header signals.
 * **Security Headers:** Analyze and manage CSP, HSTS, X-Frame-Options, X-Content-
   Type-Options, Referrer-Policy, Permissions-Policy, and disclosure headers.
 * **Enforcement Checks:** Confirms supported hardening rules are active on the 
   server. Items that require manual hosting or server configuration are flagged
   separately.

### Login Security & 2FA

Account takeover is one of the fastest ways to lose control of a WordPress site.
SiteFort adds layered login protection without requiring separate plugins.

 * **Custom Login URL:** Move your login page to a private address; anything hitting
   wp-login.php gets a redirect, a 403, or a 404, your choice.
 * **Attack Prevention:** Brute-force lockouts, CAPTCHA, generic login errors, and
   XML-RPC/REST authentication controls.
 * **Two-Factor Authentication:** Role-based 2FA enforcement with authenticator 
   app codes, email codes, and recovery codes.
 * **Password Policy:** Weak and breached password detection, role-based strength
   enforcement, and expiration rules.

### WordPress Firewall

SiteFort blocks unwanted traffic before it consumes server resources, with no custom
rule syntax to learn.

 * **IP & Country Rules:** Block or allow traffic by IP address, CIDR range, country,
   bot, crawler, or user agent.
 * **Country Blocking:** Supports both block-selected and allow-only modes.
 * **Sensitive File Protection:** Stops bots probing for `.env`, `.git`, `wp-config.
   php` backups, SQL dumps, debug logs, installer files, and other risky paths.
 * **Cloudflare Sync:** Pushes supported IP, country, and user-agent rules to Cloudflare
   so high-volume blocks happen at the edge, including temporary edge blocks for
   repeat attackers.
 * **Rate Limiting & 404 Controls:** Reduces abusive traffic spikes, repeated missing-
   page requests, and automated noise.
 * **Community Threat Intelligence:** Blocks traffic from malicious IPs seen across
   the SiteFort network.
 * **Vulnerability-Hunting Bot Protection:** Blocks bots probing for vulnerable 
   plugins, themes, backup files, and configuration leaks.

### Bot Filter Policy

Not all bots are bad. Pick one of three protection levels; unwanted automation gets
blocked while legitimate search crawlers always pass through, so bot filtering does
not put your SEO at risk.

 * **Basic:** Blocks known hacking tools and bots probing for vulnerable files.
 * **Balanced:** Blocks hacking tools, scraping bots, and automated scripts. Recommended
   for most sites.
 * **Maximum:** Blocks hacking tools, scrapers, automated scripts, and unrecognized
   bot traffic.
 * **Block AI Training Crawlers:** Optional block for AI scrapers that harvest content
   for model training (GPTBot, ClaudeBot, CCBot, Bytespider). AI assistants and 
   AI search crawlers stay allowed.

_Choose the level that fits the site, then adjust individual rules from the firewall
dashboard._

### Vulnerability Management

SiteFort checks installed WordPress core, plugin, and theme versions against vulnerability
intelligence and shows affected assets, severity, CVE references where available,
and the update that fixes each issue. While you apply updates, the firewall blocks
the scanner bots that hunt for vulnerable components.

### One-Click Repair & Restore

**Pro:** Guided repair workflows let you act on scan findings without manually editing
files over FTP or SSH.

 * Repair or delete malicious files directly from scan results.
 * Restore clean WordPress core, plugin, and theme files when a trusted clean source
   is available.
 * Repair supported paid plugin and theme files when clean-source matching is available.
 * Quarantine suspicious files safely, with one-click restore if something on the
   site breaks.

_For an active compromise, [Securewp expert cleanup](https://securewp.net/wordpress-malware-removal/)
and managed security services are available when hands-on investigation, root-cause
patching, blocklist help, or post-cleanup review is needed._

### Audit Log & SiteFort Console

SiteFort keeps a security event history so you can quickly see what changed, what
was blocked, and what needs attention.

 * **Login Activity:** Successful logins, failed attempts, lockouts, 2FA events,
   and account-related actions.
 * **User & Site Changes:** User updates, plugin and theme changes, settings changes,
   and sensitive admin actions.
 * **Firewall Activity:** Blocked IPs, country rules, bot blocks, rate-limit events,
   and suspicious request activity.
 * **Scanner Results:** Malware findings, vulnerability findings, reputation checks,
   hardening issues, and scan history.

Site-level security features are available from the WordPress dashboard. SiteFort
Console is optional for teams that need centralized visibility across multiple sites,
downloadable reports for clients, and team roles and support workflows.

### Hosting Compatibility

SiteFort is built for real WordPress environments.

 * Compatible with shared hosting, managed WordPress hosting, VPS, and dedicated
   servers.
 * Works with Apache, Nginx, and LiteSpeed.
 * Cloudflare-friendly: supports proxied sites and optional Cloudflare rule sync.
 * Cloud-assisted scanning reduces heavy scan work on lower-resource hosting plans.

### Free vs Pro

**Free includes** the firewall, bot filter, login security and 2FA, verified hardening,
vulnerability checks, audit log, quarantine, and cloud malware scanning with 3,000
scan credits every month.

**Pro adds:**

 * Unlimited cloud scanning with deep threat analysis
 * Scheduled scans and automated vulnerability alerts
 * One-click malware repair with clean-file restore for core, plugins, and themes
 * Uptime and SSL expiry monitoring
 * Slack, Discord, email, and webhook alerts
 * Remote scan history, advanced reports, and white-label options for agencies
 * Expert cleanup discounts

**Managed** adds hands-on monitoring, response workflows, and expert cleanup coverage
by the SecureWP team.

Looking for a market comparison? See the [WordPress Security Plugin Comparison](https://securewp.net/wordpress-security-plugin-comparison/).

### External services

SiteFort connects to external services only when needed for license activation, 
cloud-assisted malware analysis, vulnerability intelligence, firewall intelligence,
optional Console sync, optional CAPTCHA, optional GeoIP, Cloudflare sync, and administrator-
enabled notifications.

Optional integrations are not contacted unless they are configured or used.

#### SiteFort Cloud

 * **Servers:** securewp.net, intel.securewp.net, console.securewp.net
 * **Used for:** License activation, service metadata, cloud malware analysis, vulnerability
   intelligence, firewall intelligence, reputation checks, community blocklist sync,
   clean-file repair, and optional Console sync.
 * **Data sent:** Email address, license key/token, site URL, WordPress/plugin versions,
   installed plugin/theme names and versions, file hashes, scan results, vulnerability
   findings, reputation status, firewall metadata, blocked IPs, and security configuration
   metadata.
 * **Malware scanning:** File hashes are sent first. Only unknown or suspicious 
   files may be uploaded for deeper analysis and are deleted after processing. Database
   and content checks run on your website. SiteFort does not upload your database
   or database-stored content to the cloud. If wp-config.php requires analysis, 
   sensitive configuration values are removed before upload.
 * **Temporary storage:** SiteFort Cloud may return temporary upload/download URLs
   on *.amazonaws.com for scan uploads or clean-file repair downloads.
 * **Privacy:** https://securewp.net/privacy-policy/
 * **Terms:** https://securewp.net/terms-and-conditions/
 * **Storage provider policies:** AWS privacy https://aws.amazon.com/privacy/ and
   terms https://aws.amazon.com/service-terms/; Cloudflare privacy https://www.cloudflare.
   com/privacypolicy/ and terms https://www.cloudflare.com/website-terms/

#### Optional integrations

 * **MaxMind GeoLite2** (download.maxmind.com) is used only when an administrator
   downloads or updates the local GeoIP database. It sends the configured MaxMind
   account ID and license key. Visitor IPs are resolved locally and are not sent
   to MaxMind during normal requests. Privacy: https://www.maxmind.com/en/privacy-
   policy Terms: https://www.maxmind.com/en/geolite2/eula
 * **Have I Been Pwned Passwords** (api.pwnedpasswords.com) is used for breached-
   password checks when enabled. SiteFort sends only the first 5 characters of the
   SHA-1 password hash. Full passwords and full hashes are never sent. Privacy: 
   https://haveibeenpwned.com/Privacy Terms: https://haveibeenpwned.com/TermsOfUse
 * **Google reCAPTCHA** (www.google.com) and **Cloudflare Turnstile** (challenges.
   cloudflare.com) are used only when selected and configured for CAPTCHA protection.
   They receive the challenge token, site key, and visitor/browser data required
   by the selected provider. Policies: https://policies.google.com/privacy https://
   policies.google.com/terms https://www.cloudflare.com/turnstile-privacy-policy/
   https://www.cloudflare.com/website-terms/
 * **Cloudflare API** (api.cloudflare.com) is used only when Cloudflare Sync is 
   enabled. It sends Zone ID, API token/credentials, zone details, blocked IPs, 
   country rules, selected user-agent rules, and firewall rule data. Privacy: https://
   www.cloudflare.com/privacypolicy/ Terms: https://www.cloudflare.com/website-terms/
 * **Notification webhooks** may send security alerts to Slack (hooks.slack.com),
   Discord (discord.com, discordapp.com), or a custom HTTPS webhook entered by the
   administrator. Webhook payloads may include site name, site URL, event type, 
   severity, scan counts, vulnerability names, CVE identifiers, firewall counts,
   usernames, IP addresses, browser names, action URLs, timestamps, and event details.
   Slack policies: https://slack.com/trust/privacy/privacy-policy https://slack.
   com/terms-of-service/user Discord policies: https://discord.com/privacy https://
   discord.com/terms

#### Local site checks

Some requests are loopback checks against the protected site’s own public URL, such
as security-header checks, public-file exposure checks, and homepage link collection.
These contact the site being protected, not a third-party service.

## 螢幕擷圖

[⌊Security Scanner: Staged scan progress across files, malware, accounts, database/
content safety, reputation, vulnerabilities, severity, detection type, and remediation
actions.⌉⌊Security Scanner: Staged scan progress across files, malware, accounts,
database/content safety, reputation, vulnerabilities, severity, detection type, 
and remediation actions.⌉[

**Security Scanner:** Staged scan progress across files, malware, accounts, database/
content safety, reputation, vulnerabilities, severity, detection type, and remediation
actions.

[⌊Firewall Controls: Easy bot/crawler policy, rate limits, community blocklist, 
and Cloudflare Sync.⌉⌊Firewall Controls: Easy bot/crawler policy, rate limits, community
blocklist, and Cloudflare Sync.⌉[

**Firewall Controls:** Easy bot/crawler policy, rate limits, community blocklist,
and Cloudflare Sync.

[⌊Firewall Rule Builder: IP rules, country blocking, and bot/crawler firewall rules.⌉⌊
Firewall Rule Builder: IP rules, country blocking, and bot/crawler firewall rules
.⌉[

**Firewall Rule Builder:** IP rules, country blocking, and bot/crawler firewall 
rules.

[⌊Login Security: Custom login URL, lockouts, CAPTCHA protection, and password controls.⌉⌊
Login Security: Custom login URL, lockouts, CAPTCHA protection, and password controls
.⌉[

**Login Security:** Custom login URL, lockouts, CAPTCHA protection, and password
controls.

[⌊2FA: Role enforcement, authenticator app setup, email codes, recovery codes.⌉⌊
2FA: Role enforcement, authenticator app setup, email codes, recovery codes.⌉[

**2FA:** Role enforcement, authenticator app setup, email codes, recovery codes.

[⌊Server Hardening: Sensitive file protection, PHP execution controls, XML-RPC and
security headers.⌉⌊Server Hardening: Sensitive file protection, PHP execution controls,
XML-RPC and security headers.⌉[

**Server Hardening:** Sensitive file protection, PHP execution controls, XML-RPC
and security headers.

[⌊WordPress Hardening: REST API, user enumeration, file editor protection.⌉⌊WordPress
Hardening: REST API, user enumeration, file editor protection.⌉[

**WordPress Hardening:** REST API, user enumeration, file editor protection.

[⌊Vulnerability Scanner: Affected plugins, themes, WordPress core, CVE references,
severity, and fix guidance.⌉⌊Vulnerability Scanner: Affected plugins, themes, WordPress
core, CVE references, severity, and fix guidance.⌉[

**Vulnerability Scanner:** Affected plugins, themes, WordPress core, CVE references,
severity, and fix guidance.

[⌊Security Headers: Security header analyzer and configuration.⌉⌊Security Headers:
Security header analyzer and configuration.⌉[

**Security Headers:** Security header analyzer and configuration.

[⌊Audit Log: Searchable security events, user activity, firewall actions, scan results,
and sensitive changes.⌉⌊Audit Log: Searchable security events, user activity, firewall
actions, scan results, and sensitive changes.⌉[

**Audit Log:** Searchable security events, user activity, firewall actions, scan
results, and sensitive changes.

[⌊SiteFort Console: Multi-site status, scans, alerts, reports, uptime, SSL, team
workflows, and support options.⌉⌊SiteFort Console: Multi-site status, scans, alerts,
reports, uptime, SSL, team workflows, and support options.⌉[

**SiteFort Console:** Multi-site status, scans, alerts, reports, uptime, SSL, team
workflows, and support options.

[[

## 安裝方式

 1. Install SiteFort from the WordPress plugin directory, or upload the plugin ZIP 
    file.
 2. For manual installation, upload the unzipped `sitefort` folder to `/wp-content/
    plugins/`.
 3. Activate the plugin from the **Plugins** screen and open **SiteFort** in wp-admin.
 4. Complete the setup wizard, or open **SiteFort > Settings > License and Plan**.
 5. Activate with your email address or license key.
 6. Review scanner, firewall, country blocking, bot policy, login security, 2FA, and
    hardening settings.
 7. Connect Cloudflare from **Settings > Integrations** if you want edge-level firewall
    enforcement.
 8. Run your first security scan and review the findings.

_Note: SiteFort requires outbound HTTPS for license activation, cloud-assisted scanning,
threat intelligence updates, and optional Console sync._

## 常見問題集

### Can I try SiteFort before installing it?

Yes. Launch a live, disposable WordPress demo with SiteFort preinstalled at https://
demo.securewp.net/. No signup or install needed; you land straight in wp-admin and
the site resets when your session ends.

### How does SiteFort help secure my website?

Prevention first: it closes the weak points attackers look for, blocks the automated
traffic that probes for them, and scans for anything that got through. Everything
is managed from your WordPress dashboard.

### What security risks can SiteFort find?

Malware and backdoors, tampered or exposed files, hidden or weak admin accounts,
vulnerable plugins and themes, injected content, blocklist listings, and hardening
gaps. Each finding includes severity and a recommended action.

### How does SiteFort keep scans lightweight?

Known files are cleared instantly by hash and results are cached, so unchanged files
are not re-analyzed. Only unknown or suspicious files go to the cloud for deep analysis,
and database checks run on your own server.

### Does SiteFort send my database content to the cloud?

No. Database and content checks run entirely on your site. For files, hashes are
sent first and only files that cannot be verified by hash are uploaded for analysis.
If `wp-config.php` requires analysis, sensitive configuration values are removed
before upload.

### Does SiteFort include firewall protection?

Yes. Rules cover IP addresses, CIDR ranges, countries, bots, user agents, and rate
limits, backed by community threat intelligence. Supported rules can also sync to
Cloudflare.

### Does SiteFort support country blocking and Cloudflare?

Yes, in block-selected or allow-only mode. Country detection uses Cloudflare country
data on proxied sites or a local MaxMind GeoLite2 database, and supported firewall
rules sync to Cloudflare with a scoped API token.

### Will bot protection block Google or search engines?

No. Google and Bing crawlers are confirmed by reverse DNS and official published
IP ranges, so genuine search bots always pass while requests that fake their identity
can be blocked.

### Can SiteFort block AI bots and AI training crawlers?

Yes, optionally. SiteFort blocks AI training crawlers such as GPTBot, ClaudeBot,
CCBot, and Bytespider while keeping AI assistants and AI search crawlers allowed,
so you limit bulk scraping without losing useful AI visibility.

### Does SiteFort protect WordPress logins?

Yes: role-based 2FA, brute-force lockouts, CAPTCHA, a custom login URL, generic 
login errors, and password policy enforcement including breached-password checks.

### What hardening protections are included?

Sensitive file protection, PHP execution blocking in risky locations, XML-RPC and
REST controls, user enumeration blocking, file editor lockdown, version hiding, 
and security header management. Where supported, SiteFort also verifies each rule
is enforced on the server.

### How does SiteFort handle vulnerable plugins and themes?

It matches installed versions against vulnerability intelligence and shows severity,
CVE references, and the update that fixes each issue. SiteFort does not claim to
virtually patch vulnerable code; the firewall reduces automated discovery attempts
while you update, replace, or remove affected software.

### Can SiteFort help after a site is already hacked?

Yes. Scans surface malware, suspicious users, injected content, and exposed files,
and Pro adds one-click repair and restore. SecureWP expert cleanup and managed security
services are available when hands-on response is needed.

### What features require a paid plan?

See Free vs Pro above. In short: unlimited deep scanning, scheduled scans and alerts,
one-click repair and restore, uptime and SSL monitoring, advanced reports, white-
label options, and expert cleanup discounts.

### Do I need SiteFort Console?

No. All site-level security features work from your WordPress dashboard. Console
is optional for centralized multi-site visibility, reports, alert routing, and team
workflows.

### Is SiteFort suitable for shared or managed hosting?

Yes. Hash-first file checks, selective cloud analysis, and rate limiting keep server
load low, and SiteFort works with Apache, Nginx, LiteSpeed, and Cloudflare-proxied
sites.

### How do I activate SiteFort Pro?

Open **SiteFort > Settings > License and Plan** and activate with the email address
used at checkout or a license key. An existing free license under the same email
upgrades in place.

## 使用者評論

![](https://secure.gravatar.com/avatar/e36d4faeb072d1dfab7f26ab8e5f4a8b3f83b11412a1711e7277b46a58d2fbe4?
s=60&d=retro&r=g)

### 󠀁[This plugin solved a big headache at a low cost](https://wordpress.org/support/topic/this-plugin-solved-a-big-headache-at-a-low-cost/)󠁿

 [sitetrail](https://profiles.wordpress.org/sitetrail/) 2026 年 7 月 9 日

Many accounts, especially old Godaddy hosting accounts, have major security problems
for which Godaddy charges you a lot. We fixed all of that by using this plugin –
and rolled it out for many client sites and legacy accounts as an update. It helped
to secure the websites fast at scale at a very low cost.

![](https://secure.gravatar.com/avatar/bacb8e8e47e555458afdcc55c7692771af840d528715bd100063692c86371b3d?
s=60&d=retro&r=g)

### 󠀁[Excellent Security Plugin](https://wordpress.org/support/topic/excellent-security-plugin-52/)󠁿

 [mfheroic](https://profiles.wordpress.org/mfheroic/) 2026 年 5 月 22 日

It’s a lightweight option that packs in malware scanning, a web application firewall,
and solid hardening features. Overall, I’d say it’s a great choice if you want strong
security that doesn’t drag your site down. Definitely worth trying if you’re looking
for a modern, efficient alternative.

![](https://secure.gravatar.com/avatar/16fa23963bd70ca45b4495aaa389eb43a3f11d01c60553e5765a32df52d04f90?
s=60&d=retro&r=g)

### 󠀁[My experience on SiteFort.](https://wordpress.org/support/topic/my-experience-on-sitefort/)󠁿

 [anwarhossain33](https://profiles.wordpress.org/anwarhossain33/) 2026 年 5 月 20
日

This is too good! Highly recommended!

![](https://secure.gravatar.com/avatar/6661e0eb6410ef62b3bd49d24e0d08ae4381ec61a09bc42bfaa6118868f3a0d8?
s=60&d=retro&r=g)

### 󠀁[Finally a full package security plugin](https://wordpress.org/support/topic/finally-a-full-package-security-plugin/)󠁿

 [2h1n846](https://profiles.wordpress.org/2h1n846/) 2026 年 5 月 19 日

For years, my workflow for WordPress security was frustrating. I would install one
plugin to scan for malware, remove it after cleanup, then install and configure 
another plugin just for security hardening because the one I used for malware scanner
were too heavy to keep running all the time.SiteFort is the first plugin I’ve used
that combines both in a clean and lightweight way. Fast malware scanning, practical
hardening features, and an easy-to-use interface without slowing down the website.
Good luck to the SiteFort team 🤞

 [ 閱讀全部 4 則使用者評論 ](https://wordpress.org/support/plugin/sitefort/reviews/)

## 參與者及開發者

以下人員參與了開源軟體〈SiteFort Security – Malware Scanner, Firewall, Login Security&
Hardening〉的開發相關工作。

參與者

 *   [ securewpteam ](https://profiles.wordpress.org/securewpteam/)

[將〈SiteFort Security – Malware Scanner, Firewall, Login Security & Hardening〉外掛本地化為台灣繁體中文版](https://translate.wordpress.org/projects/wp-plugins/sitefort)

### 對開發相關資訊感興趣？

任何人均可[瀏覽程式碼](https://plugins.trac.wordpress.org/browser/sitefort/)、查看
[SVN 存放庫](https://plugins.svn.wordpress.org/sitefort/)，或透過 [RSS](https://plugins.trac.wordpress.org/log/sitefort/?limit=100&mode=stop_on_copy&format=rss)
訂閱[開發記錄](https://plugins.trac.wordpress.org/log/sitefort/)。

## 變更記錄

#### 1.7.5 – 2026-07-20

 * Scanner-pattern 404 requests now count toward the Detect & Block Scanners ban
   threshold, so probing bots get banned instead of only rate limited.
 * Sustained scanner-like 404 volume escalates to an automatic IP ban even below
   the per-minute limit.
 * 404 handling now yields to redirects and 410 responses set by SEO plugins; scanner
   probes still count toward bans either way.
 * Search crawler verification now runs only when a block or ban is imminent instead
   of on every crawler request.
 * The Balanced and Maximum bot profiles now block requests that send no user agent.
 * The Maximum bot profile now blocks visitors caught impersonating Google or Bing
   crawlers (proven by DNS verification, never on a failed lookup).
 * Known SEO and service crawlers no longer accumulate scanner-ban points from stale-
   link 404s.
 * The AI-training opt-out now lists all recognized AI training crawlers in robots.
   txt instead of only Google-Extended and Applebot-Extended.
 * Tightened hacking-tool signatures so generic words inside legitimate app names
   can no longer trigger a false block.

#### 1.7.4

 * Console commands now execute and confirm in under a second instead of waiting
   for a background cron cycle.
 * Cloudflare now connects with a single API Token: a pre-scoped token creation 
   link, one Save & Verify step, and clearer errors for tokens with missing permissions.
   Global API Key auth is removed.
 * MaxMind GeoIP credentials are now verified with MaxMind before saving, so a mistyped
   Account ID or License Key is rejected immediately instead of stored.
 * The country database now refreshes weekly as intended and shows its last update
   time.

#### 1.7.3

 * Fixed the Vulnerabilities scan step showing as complete when vulnerabilities 
   were found.
 * Scans now recover and finish on their own if a background security check is interrupted,
   instead of appearing stuck.
 * Improved scan speed and reduced database load, most noticeable on sites with 
   many files.

#### 1.7.2

 * Login URL protection now recognizes browsers that previously signed in to wp-
   admin and sends them to the login page instead of the block page after their 
   session expires.
 * Login lockout emails now include a secure one-click unlock link that works even
   while you are locked out yourself.
 * Redesigned the Security Overview dashboard around a single health banner with
   a clear next action.

#### 1.7.1

 * Moved verified search crawler and Cloudflare safe-network ranges to the SiteFort
   Intel feed with signed updates, bundled fallback data, and migration from the
   old crawler-range cache.
 * Improved verified crawler handling so Google, Bing, and Cloudflare ranges never
   fall back to an empty set, while custom safe ranges can still be cleared from
   the feed.
 * Added standby signing keys for safe-network feeds and scanner hash-cache proofs.
 * Removed the unused firewall WHOIS/RDAP lookup endpoint so the plugin no longer
   makes direct RIPE or ARIN IP ownership lookups.

#### 1.7.0

 * Fixed scans appearing stuck on “Initializing” while checks were completing in
   the background; scan progress now shows as soon as the first check runs.
 * SiteFort now detects when the host cannot run background scan processing, shows
   a notice explaining the reduced-speed mode and how to fix it with a server cron
   job, and stops sending wake-up requests that cannot succeed.
 * Scans in reduced-speed mode now run several checks per status refresh instead
   of one, so they finish much sooner on affected hosts.
 * Background worker dispatch failures are now logged with the failure reason instead
   of failing silently.
 * Added the sitefort_scanner_worker_ack_timeout filter for slow hosts that need
   a longer worker dispatch timeout.

Earlier releases are listed in changelog.txt inside the plugin.

## 中繼資料

 *  版本 **1.7.5**
 *  最後更新 **5 小時前**
 *  啟用安裝數 **40+**
 *  WordPress 版本需求 ** 6.0 或更新版本 **
 *  已測試相容的 WordPress 版本 **7.0.2**
 *  PHP 版本需求 ** 7.4 或更新版本 **
 *  語言
 * [English (US)](https://wordpress.org/plugins/sitefort/)
 * 標籤:
 * [2FA](https://tw.wordpress.org/plugins/tags/2fa/)[firewall](https://tw.wordpress.org/plugins/tags/firewall/)
   [malware scanner](https://tw.wordpress.org/plugins/tags/malware-scanner/)[security](https://tw.wordpress.org/plugins/tags/security/)
   [vulnerability](https://tw.wordpress.org/plugins/tags/vulnerability/)
 *  [進階檢視](https://tw.wordpress.org/plugins/sitefort/advanced/)

## 評分

 5 星，滿分為 5 星

 *  [  4 個 5 星使用者評論     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=5)
 *  [  0 個 4 星使用者評論     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=4)
 *  [  0 個 3 星使用者評論     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=3)
 *  [  0 個 2 星使用者評論     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=2)
 *  [  0 個 1 星使用者評論     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/sitefort/reviews/#new-post)

[查看全部使用者評論](https://wordpress.org/support/plugin/sitefort/reviews/)

## 參與者

 *   [ securewpteam ](https://profiles.wordpress.org/securewpteam/)

## 技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

 [檢視技術支援論壇](https://wordpress.org/support/plugin/sitefort/)