Beschreibung
WebDmitriev Protection is a compact and efficient security solution for WordPress sites:
- Brute-Force Protection: Limits failed login attempts on
wp-login.php. - Entry Point Security: Disables XML-RPC and prevents user enumeration via REST API and author query parameters.
- File Integrity Guard: Monitors critical files (
.htaccessandwp-config.php) for unauthorized changes. - Uploads Directory Guard: Automatically blocks PHP execution inside
/wp-content/uploads/. - Lightweight WAF: Filters dangerous URL parameters (SQLi/XSS), blocks malicious User-Agent signatures, and manages IP blacklists.
Installation
- Upload the
webdmitriev-protectionfolder to the/wp-content/plugins/directory. - Activate the plugin through the ‚Plugins‘ menu in WordPress.
- Go to ‚WD Protection‘ in the admin dashboard to configure settings and view threat logs.
FAQ
-
How does the plugin block brute-force attacks?
-
It tracks failed login attempts by IP address. If an IP exceeds 5 failed attempts within 15 minutes, access to the login form is temporarily blocked.
-
What happens if wp-config.php or .htaccess is edited?
-
The plugin calculates MD5 hashes of critical files. If a modification is detected, a notice appears in the admin panel allowing you to inspect and approve the new file state.
Rezensionen
There are no reviews for this plugin.
Mitwirkende & Entwickler
„WebDmitriev Protection“ ist Open-Source-Software. Folgende Menschen haben an diesem Plugin mitgewirkt:
MitwirkendeÜbersetze „WebDmitriev Protection“ in deine Sprache.
Interessiert an der Entwicklung?
Durchstöbere den Code, sieh dir das SVN Repository an oder abonniere das Entwicklungsprotokoll per RSS.
Änderungsprotokoll
1.0.0
- Initial public release.
