跳至主要內容
WordPress.org

Taiwan 正體中文

  • 佈景主題目錄
  • 外掛目錄
  • 最新消息
  • 技術支援
  • 關於我們
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

Webro Security

  • 提交外掛
  • 我的最愛
  • 登入
  • 提交外掛
  • 我的最愛
  • 登入

Webro Security

由 webro 開發
下載
  • 詳細資料
  • 使用者評論
  • 安裝方式
  • 開發資訊
技術支援

外掛說明

A WordPress plugin that adds security headers, CSP, login protection, SMTP, spam protection and more. Functionality is continuously being expanded to cover more ground.

Features

  • Adds security headers, including configurable HSTS, X-Frame-Options, COOP and CORP
  • Supports Content Security Policy (CSP), editable from the admin UI and validated against unrecognized directives
  • Protects login with rate-limiting
  • Blocks weak passwords, with an exemption list for individual users
  • Blocks common/guessable usernames
  • Validates protected brand names against required domains. Self-registration blocks a brand-impersonating email outright
  • Locks file editing, with a temporary admin-bar toggle that automatically relocks after a period of inactivity
  • Honeypot spam protection (CF7, Elementor, WPForms, Forminator, lost password)
  • Custom SMTP sending, with a test-email button
  • Central security log with automatic retention, including new user account creation
  • Removes certain default WordPress traces from <head>
  • English, with community translations available via translate.wordpress.org

What does it protect against?

  • Basic login attacks
  • Some forms of user enumeration
  • Unwanted WordPress metadata
  • Missing security headers

Important: it does not protect against vulnerabilities in other plugins or themes, poor server configuration, or missing updates.

Compatibility

Some security headers can affect elements such as iframes, embeds and third-party scripts. Some of the CSP directives may be too strict and might need loosening depending on your needs. This is done from the CSP field in the admin UI, which is available to the administrator role.

About

Webro Security is developed and maintained by Webro, a web agency with offices in Odense and Aabenraa, Denmark. Webro builds and runs WordPress sites for companies across a wide range of industries, and this plugin grew out of that daily work. The same hardening steps were being repeated by hand on site after site, so they were collected into one plugin with settings that can be adjusted per site instead of edited in code.

The plugin is built by Lasse Enggaard and Rikke Rasmussen. Lasse Enggaard is a Danish SEO specialist and partner at Webro. He has worked with SEO since 2015 and with WordPress development alongside it, and today works with search visibility, AI visibility and technical WordPress work for companies.

Rikke Rasmussen is a web developer at Webro and has been closely involved in building the plugin and the testing across sites. Both of them continue to maintain it.

The plugin is aimed at site owners and the people who look after their sites, not at security researchers. Every setting has a plain-language explanation next to it, so it is clear what a given header or policy actually changes before it is turned on. Development continues, and features are added as they prove useful in real projects.

螢幕擷圖

Dashboard with an overview of active protection and recent security events
Dashboard with an overview of active protection and recent security events
Security headers: X-Frame-Options, HSTS, COOP and CORP, with a list of the headers actually sent
Security headers: X-Frame-Options, HSTS, COOP and CORP, with a list of the headers actually sent
Content Security Policy, editable one directive per line
Content Security Policy, editable one directive per line
SMTP settings with sender override and encryption options
SMTP settings with sender override and encryption options
Password exemptions for individual users
Password exemptions for individual users
Brand protection: reserve a domain so only verified accounts can use it
Brand protection: reserve a domain so only verified accounts can use it

安裝方式

  1. Upload the plugin to wp-content/plugins/
  2. Activate it via the WordPress admin panel

Uninstallation

  • Removes the plugin’s saved options
  • Removes the plugin’s transients
  • Cleans up its own settings on uninstall

使用者評論

這個外掛目前沒有任何使用者評論。

參與者及開發者

以下人員參與了開源軟體〈Webro Security〉的開發相關工作。

參與者
  • webro
  • Lasse Enggaard
  • Rikke Rasmussen

將〈Webro Security〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

變更記錄

1.0.0

  • First version

中繼資料

  • 版本 1.0.0
  • 最後更新 19 小時前
  • 啟用安裝數 少於 10 次
  • WordPress 版本需求 6.0 或更新版本
  • 已測試相容的 WordPress 版本 7.0.4
  • PHP 版本需求 8.0 或更新版本
  • 語言
    English (US)
  • 標籤:
    csplogin protectionsecuritysmtpspam protection
  • 進階檢視

評分

這個項目尚無任何評論記錄。

撰寫評分

查看全部使用者評論

參與者

  • webro
  • Lasse Enggaard
  • Rikke Rasmussen

技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

檢視技術支援論壇

  • 關於我們
  • 最新消息
  • 主機代管
  • 隱私權
  • 展示網站
  • 佈景主題目錄
  • 外掛目錄
  • 區塊版面配置目錄
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • 活動
  • 贊助基金會 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Taiwan 正體中文

  • 查看我們的 X (之前的 Twitter) 帳號
  • 造訪我們的 Bluesky 帳號
  • 造訪我們的 Mastodon 帳號
  • 造訪我們的 Threads 帳號
  • 造訪我們的 Facebook 粉絲專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • 造訪我們的 TikTok 帳號
  • Visit our YouTube channel
  • 造訪我們的 Tumblr 帳號
程式碼,如詩
The WordPress® trademark is the intellectual property of the WordPress Foundation.