CloudSecure WP Security
CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。 簡単な設定だけで、不正アクセスや不正ログインからWordPressを保護し、サイトのセキュリティを高めます。 各機能は有効/無効を切り替えるだけで設定でき、必要な対策をわかりやすく管理できます。シンプルで扱いやすい設計のため、日々のサイト運用にも取り入れやすいプラグインです。 ※ 本プラグインは日本国内の利用者向けに提供しているものであり、EU居住者を対象とした提供は意図していません。 ドキュメントやFAQなど、より詳細な情報は こちら でご覧いただけます。 WordPressのマルチサイト機能には対応していません。 WebサーバーはApache2.xでの動作を確認済みです。 画像認証追加機能を利用するためには、PHPに拡張ライブラリ「gd」をインストールする必要があります。 管理画面アクセス制限機能、ログインURL変更機能を利用するためには、Apacheに「mod_rewrite」を読み込む必要があります。 本プラグインの機能は以下のとおりです。 ログイン無効化 指定した期間内に指定した回数ログインに失敗した場合、指定した時間ログインを無効化(ブロック)します。 ブルートフォースアタックやパスワードリスト攻撃など、不正なログインを試みる攻撃を防ぐための機能です。 とくに、自動化された攻撃に有効です。 ログインURL変更 ログインURL(wp-login.php)を変更します。 半角英小文字、半角数字、ハイフン、アンダースコアのいずれかを使用し、4文字以上12文字以下でお好みの名前(文字列)に設定できます。 ブルートフォースアタックやパスワードリスト攻撃など、不正なログインを試みる攻撃を受けにくくするための機能です。 ログインエラーメッセージ統一 ログイン時、ユーザー名、パスワード、画像認証のどれを間違えても同一のメッセージを表示します。 ユーザー名の存在を調査する攻撃を受けにくくするための機能です。 2段階認証 ログイン時、ユーザー名とパスワードの入力に加え、別のコードで追加認証を行います。 認証方法はGoogle Authenticator またはメール認証のいずれかを選択できます。 各認証方法で生成された6桁の認証コードをログイン画面で入力し、すべての情報が一致すればログインできます。 ユーザー名やパスワードを不正入手した第三者によるログインやなりすましを防止し、セキュリティを強化します。 画像認証追加 画像データ上にランダムに表示される文字の入力を求め、一致しなければ次の画面に進めないようにする機能です。 ログインフォーム、コメントフォーム、パスワードリセットフォーム、ユーザー登録フォームに設定できます。 ブルートフォースアタックやパスワードリスト攻撃などの不正なログインを試みる攻撃や、悪意のあるプログラムからの機械的な不正アクセスを防止する機能です。 ユーザー名漏えい防止 「?author=数字」アクセスによるユーザー名の漏えいを防止します。 XML-RPC無効化 XML-RPC機能、またはピンバック機能を無効化し、その乱用から管理画面を保護します。 REST API無効化 REST APIを無効化し、その悪用から管理画面を守ります。 管理画面アクセス制限 管理画面にログインしていない接続元IPアドレスから管理ページ(/wp-admin/以降)にアクセスすると、404エラー(Not Found)を返します。 24時間以上管理画面にログインしていない接続元IPアドレスが対象です。 ログインすると接続元IPアドレスが記録され、管理画面にアクセスできるようになります。 この機能を除外するページ(wp-admin以下)を指定できます。 設定ファイルアクセス防止 WordPressのシステムに関するファイルへの不正アクセスを遮断する機能です。 シンプルWAF WordPressへの攻撃に対して、基本的な防御機能を備えたシンプルなWAF(Web Application Firewall)機能です。 SQLインジェクションやクロスサイトスクリプティングなどの一般的な攻撃を遮断します。 ログイン通知 ログインがあったとき、ユーザーにメールで通知します。 心当たりのないメールを受信した場合、不正なログインを疑ってください。 アップデート通知 WordPress、プラグイン、テーマの更新が必要になったとき、WordPressの管理者ユーザーにメールで通知します。 更新の確認は24時間ごとに行われます。 常に最新版を使用することが、セキュリティの基本です。 サーバーエラー通知 サーバーエラー「HTTPステータスコード500(Internal Server Error)」が発生したとき、エラーの履歴を記録し、WordPressの管理者ユーザーにメールで通知します。 1時間以内に同じタイプのエラーが発生した場合、エラーの履歴は記録しますが、メールでの通知は行いません。 ログイン履歴 管理画面にログインした履歴を表示します。 それぞれの項目で絞り込んでの検索も可能です。 ログイン通知と同様、不正なログインの気づきを促す機能です。
Top keywords
- wordpress7×11.48%
- url4×6.56%
- ip3×4.92%
- 242×3.28%
- api2×3.28%
- ip wp-admin2×3.28%
- php2×3.28%
- rest2×3.28%
- rest api2×3.28%
- waf2×3.28%
- web2×3.28%
- wordpress waf2×3.28%
La Sentinelle antispam
Feel safe knowing that your website is safe from spam. La Sentinelle will guard your WordPress website against spam in a simple and effective way. It has antispam filters for comment forms and registration forms and can be extended to support plugins. The default settings should catch most spambots, and there is a settingspage to set it up according to your wishes. Current features include: 3 antispam features; Honeypot, Nonce, Form Timeout. These 3 spamfilters depend on JavaScript on the frontend. 1 antispam feature; Stop Forum Spam. Settingspage to set things up according to your wishes. Transparent to the visitor, no nagging with Captcha’s or other annoying things. By default no use of third-party services and no tracking of visitors. Lightweight and simple code. Logging for WordPress Comments and which spamfilter marked it as spam. Logging for Custom forms and which spamfilter marked it as spam. Statistics for every form how many spam submissions were blocked. WordPress forms that are protected: WordPress Comments form. WordPress Login form. WordPress Register form. WordPress Lost Password form. Form Plugins that are protected: Caldera Forms. Clean Login (Login form). Contact Form 7. Easy Digital Downloads (Login form, Register form). Everest Forms. Formidable Form Builder. Forminator. Newsletter Optin Box plugin (noptin) (standalone forms). Ultimate Member (Login form, Register form and Lost Password form). WooCommerce (Login form, Lost Password form). WPForms Lite. WP Job Manager plugin (submit job form when registering is enabled). Support If you have a problem or a feature request, please post it on the plugin’s support forum on wordpress.org. I will do my best to respond as soon as possible. If you send me an email, I will not reply. Please use the support forum. Translations Translations can be added very easily through GlotPress. You can start translating strings there for your locale. They need to be validated though, so if there’s no validator yet, and you want to apply for being validator (PTE), please post it on the support forum. I will make a request on make/polyglots to have you added as validator for this plugin/locale. How to choose an antispam plugin When you look through the WordPress Plugin Repository you will see more than a hundred antispam plugins. Which one is the best one? Short answer, there is no “best one”. No spamfilter and no method for spamfiltering is perfect. Slightly longer answer, you could try about twenty and choose the one that fits your needs best. But there is also a really long answer. There are different methods that can be used against spam, and every method has its drawbacks. In my opinion, having a low number of false positives is more important than perfectly marking all spam, you don’t want to miss out on important people or information. Nagging the user in some way has a similar effect, the user might not even want to bother with that and just walk away. Third party services: Services like Akismet, OOPSpam, Stop Forum Spam and also reCAPTCHA offer third party services to check for spam. This can be very effective, but you are giving user submitted data away to these third parties and are also giving your users up for tracking them. Captcha’s, reCAPTCHA and Quizz Questions: You are annoying your users and probably sending some of them away. This especially counts for reCAPTCHA for visitors who have third party cookies disabled. Blacklists: Often running behind the facts. That goes for the way of getting users off that list, and also in getting users on that list. Referer check: check if the Referer header is set correctly. You can never trust it is set correctly. Modern browsers are limiting the use of Referers, though for now that is mostly for third-party domains. JavaScript methods: Spammers often (always?) don’t use JavaScript, they just post the form with spammy data. Drawback for this method is that statistics say that about 1 percent of users has JavaScript disabled. Also, some websites have broken JavaScript, which might make the spamfilter break as well. Activation email for registering users. Users only get activated after clicking a link in an activation email. You still have all the non-activated users in your site however. You could have a bright idea about combining several methods, but then you get the drawbacks of all the methods you use. Another complication of choosing a good plugin is that most antispam plugins don’t tell you what methods they use. The documentation doesn’t tell you, and looking at the source code just leaves you confused at the chaos that it often is. My main motivation for writing this plugin is to offer a plugin that does spamfiltering with JavaScript methods in a simple and effective way. The claimed 1 percent of users that has JavaScript disabled will also be tech-savy enough to enable it again for your website. Compatibility This plugin is compatible with ClassicPress. Contributions This plugin is also available in Codeberg.