CloudSecure WP Security
CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。 簡単な設定だけで、不正アクセスや不正ログインからWordPressを保護し、サイトのセキュリティを高めます。 各機能は有効/無効を切り替えるだけで設定でき、必要な対策をわかりやすく管理できます。シンプルで扱いやすい設計のため、日々のサイト運用にも取り入れやすいプラグインです。 ※ 本プラグインは日本国内の利用者向けに提供しているものであり、EU居住者を対象とした提供は意図していません。 ドキュメントやFAQなど、より詳細な情報は こちら でご覧いただけます。 WordPressのマルチサイト機能には対応していません。 WebサーバーはApache2.xでの動作を確認済みです。 画像認証追加機能を利用するためには、PHPに拡張ライブラリ「gd」をインストールする必要があります。 管理画面アクセス制限機能、ログインURL変更機能を利用するためには、Apacheに「mod_rewrite」を読み込む必要があります。 本プラグインの機能は以下のとおりです。 ログイン無効化 指定した期間内に指定した回数ログインに失敗した場合、指定した時間ログインを無効化(ブロック)します。 ブルートフォースアタックやパスワードリスト攻撃など、不正なログインを試みる攻撃を防ぐための機能です。 とくに、自動化された攻撃に有効です。 ログインURL変更 ログインURL(wp-login.php)を変更します。 半角英小文字、半角数字、ハイフン、アンダースコアのいずれかを使用し、4文字以上12文字以下でお好みの名前(文字列)に設定できます。 ブルートフォースアタックやパスワードリスト攻撃など、不正なログインを試みる攻撃を受けにくくするための機能です。 ログインエラーメッセージ統一 ログイン時、ユーザー名、パスワード、画像認証のどれを間違えても同一のメッセージを表示します。 ユーザー名の存在を調査する攻撃を受けにくくするための機能です。 2段階認証 ログイン時、ユーザー名とパスワードの入力に加え、別のコードで追加認証を行います。 認証方法はGoogle Authenticator またはメール認証のいずれかを選択できます。 各認証方法で生成された6桁の認証コードをログイン画面で入力し、すべての情報が一致すればログインできます。 ユーザー名やパスワードを不正入手した第三者によるログインやなりすましを防止し、セキュリティを強化します。 画像認証追加 画像データ上にランダムに表示される文字の入力を求め、一致しなければ次の画面に進めないようにする機能です。 ログインフォーム、コメントフォーム、パスワードリセットフォーム、ユーザー登録フォームに設定できます。 ブルートフォースアタックやパスワードリスト攻撃などの不正なログインを試みる攻撃や、悪意のあるプログラムからの機械的な不正アクセスを防止する機能です。 ユーザー名漏えい防止 「?author=数字」アクセスによるユーザー名の漏えいを防止します。 XML-RPC無効化 XML-RPC機能、またはピンバック機能を無効化し、その乱用から管理画面を保護します。 REST API無効化 REST APIを無効化し、その悪用から管理画面を守ります。 管理画面アクセス制限 管理画面にログインしていない接続元IPアドレスから管理ページ(/wp-admin/以降)にアクセスすると、404エラー(Not Found)を返します。 24時間以上管理画面にログインしていない接続元IPアドレスが対象です。 ログインすると接続元IPアドレスが記録され、管理画面にアクセスできるようになります。 この機能を除外するページ(wp-admin以下)を指定できます。 設定ファイルアクセス防止 WordPressのシステムに関するファイルへの不正アクセスを遮断する機能です。 シンプルWAF WordPressへの攻撃に対して、基本的な防御機能を備えたシンプルなWAF(Web Application Firewall)機能です。 SQLインジェクションやクロスサイトスクリプティングなどの一般的な攻撃を遮断します。 ログイン通知 ログインがあったとき、ユーザーにメールで通知します。 心当たりのないメールを受信した場合、不正なログインを疑ってください。 アップデート通知 WordPress、プラグイン、テーマの更新が必要になったとき、WordPressの管理者ユーザーにメールで通知します。 更新の確認は24時間ごとに行われます。 常に最新版を使用することが、セキュリティの基本です。 サーバーエラー通知 サーバーエラー「HTTPステータスコード500(Internal Server Error)」が発生したとき、エラーの履歴を記録し、WordPressの管理者ユーザーにメールで通知します。 1時間以内に同じタイプのエラーが発生した場合、エラーの履歴は記録しますが、メールでの通知は行いません。 ログイン履歴 管理画面にログインした履歴を表示します。 それぞれの項目で絞り込んでの検索も可能です。 ログイン通知と同様、不正なログインの気づきを促す機能です。
Top keywords
- wordpress7×11.48%
- url4×6.56%
- ip3×4.92%
- 242×3.28%
- api2×3.28%
- ip wp-admin2×3.28%
- php2×3.28%
- rest2×3.28%
- rest api2×3.28%
- waf2×3.28%
- web2×3.28%
- wordpress waf2×3.28%
Web-Art Login Shield with reCAPTCHA
Web-Art Login Shield with reCAPTCHA protects WordPress authentication, Elementor Login widgets and Elementor Forms. It provides optional Google reCAPTCHA v2/v3, IP lockouts, Advanced login URL protection, IP blocking and REST/XML-RPC protection. It preserves WordPress core authentication logic. No ads, author telemetry or external dashboard. All modules are opt-in and disabled by default. Key Features reCAPTCHA v2/v3 selectable v2 checkbox or v3 score-based verification protection for wp-login.php, Elementor Login and Elementor Forms server-side token, action, score and hostname validation where applicable configurable v3 score threshold one active type at a time configuration verification before activation Elementor support protection for Elementor Login and Elementor Pro Forms native Elementor reCAPTCHA fields are skipped to avoid duplication v2 alignment controls login errors and lockouts remain inside the Login widget dynamic content and Elementor popup support Login Protect per-IP failed-attempt counting and temporary lockouts safe concurrent-request handling active-lockout countdown local security event log with bounded retention optional REST API, Application Password and XML-RPC protection independent operation with or without reCAPTCHA Advanced login URL optional custom login endpoint protection of default login routes while preserving required public actions logout and password-link compatibility emergency wp-config.php recovery constant IP allowlists and blocking separate reCAPTCHA allowlist and Login Protect trusted IP list permanent IP blocking for public site requests with HTTP 403 optional IP | reason notes XML-RPC hardening Optional blocking of: pingback.ping pingback.extensions.getPingbacks system.multicall Security Model Protected flows use fail-closed handling. If an enabled check cannot be completed safely, the request is rejected instead of bypassing protection. Login Protect preserves active lockouts and safely handles concurrent requests. Setting Maximum login attempts or Lockout duration to 0 disables lockout enforcement. All modules remain disabled until enabled. Recovery constants are available in wp-config.php for selected modules. External Services This plugin integrates with Google reCAPTCHA v2 and v3, services provided by Google LLC. reCAPTCHA is disabled by default. Google scripts or verification requests are used only after an administrator enables reCAPTCHA or runs a settings-page verification test. Google’s reCAPTCHA JavaScript (https://www.google.com/recaptcha/api.js) may load on protected wp-login.php requests, pages containing protected Elementor widgets or forms, and the settings page during a verification test. Allowlisted visitors bypass frontend loading where applicable. When reCAPTCHA runs, the visitor’s browser connects directly to Google. Google may process browser, device and interaction information and may set the necessary _GRECAPTCHA cookie under its policies. For server-side verification, the plugin sends the token, configured Secret Key and visitor IP address when available to Google’s siteverify endpoint. It does not include usernames, passwords, email addresses or form contents in that request. The plugin sends no telemetry, analytics or usage data to its author. Google policies: https://policies.google.com/privacy https://policies.google.com/terms Privacy Locally stored security data may include: IP addresses, failed-attempt counts and lockout timestamps a username or email associated with an IP lockout recent events containing an IP address, username or email, source, type and timestamp the latest reCAPTCHA configuration or transport error used for diagnostics permanent IP blocklist entries and optional notes Inactive Login Protect entries become eligible for deletion after seven days. Active lockouts remain until expiry. The event log is limited to 30 entries and 30 days. WordPress privacy tools export or erase records matched to the requested email address or associated account. Unmatched IP-only records remain subject to retention and administrator cleanup. Permanent blocklist entries remain until removed by an administrator. Plugin data can be removed during uninstall when uninstall cleanup is enabled. Legal reCAPTCHA is a trademark of Google LLC. Elementor is a trademark of Elementor Ltd. This plugin is not affiliated with, endorsed by, or sponsored by Google LLC or Elementor Ltd.