Linux 软件免费装

Aegis User Guard

开发者 WP_Shibly
更新时间 2026年9月26日 08:02
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security two factor authentication user management login security password policy

下载

1.3.2

详情介绍:

Aegis User Guard is a single, self-contained security console that adds the identity-policy controls most sites end up needing eventually: password expiration and complexity, inactivity lockout, brute-force protection, two-factor authentication, an IP allow/block list, and full oversight of every Administrator account. It does not replace WordPress's login system or session handling; it layers policy and visibility on top of it, and every control can be switched off independently. Everything lives on one native-feeling admin screen, organized into tabs: Identity policies Administrator oversight Access control Hardening checklist A read-only audit covering file-editing access, debug output exposure, HTTPS on wp-admin, a default "admin" username, the two-factor requirement, REST API user enumeration, and pending core/plugin updates — each with a plain-language fix, and a direct link into the relevant Aegis setting where Aegis can apply it itself. Everything native Aegis stores its data in standard WordPress options and user meta, uses native password-reset and session-termination APIs, and never introduces its own authentication layer. Disabling or deleting the plugin returns the site to stock WordPress behavior.

安装:

  1. Upload the aegis-user-guard folder to wp-content/plugins/, or upload the plugin ZIP from Plugins > Add New > Upload Plugin.
  2. Activate Aegis User Guard from the Plugins screen.
  3. Open the Aegis User Guard menu item in the main admin sidebar to review the default policies and adjust them to your site.
  4. Use the Administrator directory tab, or Users > All Users, for per-account status and manual access controls.

升级注意事项:

1.3.2 Documents the optional Gravatar avatar lookup used by the Administrator directory. 1.3.1 Improves WordPress.org guideline compliance by preserving native admin notices, using enqueued admin assets, and tightening request validation. 1.3.0 Improves WordPress/WPCS compliance, PHP documentation, input handling, output escaping, and packaged documentation structure. 1.2.0 Adds WPML-ready translation support across the admin interface, email notifications, CSV exports, and saved email templates. 1.1.0 Adds granular user-account security alerts using your existing email notification settings. 1.0.0 Initial release.

常见问题:

Does this replace WordPress's login system?

No. Aegis adds policy checks and visibility on top of native WordPress authentication, session handling, and password reset — it does not introduce its own login form, session store, or password hashing.

What happens to existing accounts when I activate the plugin?

Nothing changes immediately. Accounts are initialized with current timestamps on their next successful login, so no one is locked out by policies that were not in effect when they last signed in.

Does two-factor authentication use a third-party service?

No. Setup uses a manual-entry secret key compatible with any standard TOTP authenticator app (Google Authenticator, Authy, 1Password, etc.); no QR code service or external API is involved.

What does "Sign out everywhere" actually do?

It destroys every active WordPress session token for that account using the native session-token API, the same mechanism behind core's own "Log Out Everywhere Else."

Does disabling a policy delete its saved settings?

No. Turning a rule's "Enforce rule" switch off keeps its configured value (days, attempts, minimum length, etc.) saved and simply stops it from being evaluated at login until you turn it back on.

Is any data sent off-site?

Aegis stores its settings and activity log in standard WordPress options and user meta on your own database. Email notifications are sent through your site's normal wp_mail() configuration. If the Administrator directory displays a Gravatar avatar, the visitor's browser also requests that image from Gravatar as described in the External services section above.

更新日志:

1.3.2 1.3.1 1.3.0 1.2.0 1.1.0 1.0.0