Linux 软件免费装
Banner图

All-In-One Security (AIOS) – Security and Firewall

开发者 Tips and Tricks HQ
wpsolutions
Peter Petreski
Ruhul Amin
mbrsolution
DavidAnderson
pmbaldha
更新时间 2024年9月16日 20:03
捐献地址: 去捐款
PHP版本: 5.0 及以上
WordPress版本: 6.6
版权: GPLv3 or later

标签

security two factor authentication login security firewall malware scanning

下载

2.3 2.4 2.5 2.6 2.7 2.8.1 2.9 3.0 3.1 3.2 3.3 3.4 3.7.1 3.7.5 3.7.6 3.7.7 3.8.7 3.9.5 3.9.6 3.9.9 4.0.7 4.0.9 4.1.0 4.1.4 4.1.7 4.2.2 4.0.1 4.0.3 4.4.0 5.2.4 5.3.1 5.3.2 5.3.3 5.2.8 5.2.9 2.8 3.7.3 4.0.8 4.2.8 4.2.9 4.3.1 4.3.7.1 4.3.8.1 1.7 4.3.8.2 4.4.11 3.5.1 4.3.9.1 5.0.1 5.1.5 1.0 1.1 1.2 1.4 4.3.9.4 4.4.12 4.4.2 4.4.4 5.0.0 5.0.3 5.0.4 5.0.5 5.0.8 5.0.9 4.3.9.3 1.3 4.3.8.3 4.4.10 4.4.8 5.1.0 5.1.2 5.1.3 5.1.4 5.1.8 5.2.2 5.2.3 5.0.6 5.0.7 5.1.1 5.2.5 5.2.6 1.8 5.2.7 1.6 1.9 2.2 4.3.9.2 5.2.0 2.0 1.5 2.1.1 3.6 4.3.7.2 4.4.9 5.0.2 5.1.6 5.1.7 5.1.9 5.2.1 5.3.0

详情介绍:

THE TOP RATED WORDPRESS SECURITY AND FIREWALL PLUGIN All-in-One Security (AIOS) is a security plugin designed especially for WordPress, now brought to you from the team at UpdraftPlus. Customers love All-In-One Security because it’s easy to use, and it does a whole lot for free. All-In-One Security gives you Login Security Tools, to keep bots at bay and protect your website from brute force attacks. Our Web Application Firewall gives you automatic protection from security threats. Content Protection Features protect what you’ve worked so hard to build; All-In-One Security eliminates comment spam and prevents other websites from stealing your content with features like iFrame prevention and copywriting protection. https://www.youtube.com/watch?v=CJvCTlVtazA Still on the fence? LOGIN SECURITY FEATURE SUITE Protect against brute-force attacks and keep bots at bay. All-In-One Security takes WordPress’ default login security features to a whole new level. * Supports best practice: All-In-One Security detects if an account has the default ‘admin’ username or if a user has identical login and display names, prompting the user to change this in support of better security practices. * Hide login page from bots: Configure a custom URL for the WordPress ‘Admin’ login page, making it harder for bots to find. * Change default wp_ prefix: Hackers use automated code to attack websites like yours. Make life harder for them and protect your site with this simple but effective AIOS security feature. * Login lockout: External users making multiple login attempts can be locked out for a configured period of time. You can also lockout users with invalid usernames. See a list of all locked out users and unlock with one click. * Reporting: All-In-One Security provides a wealth of information about website users. View activity by username, IP address, login and logout dates and times. See a list of users currently logged in, and a list of all failed login attempts. * Force logouts: Ensure users don’t stay logged in indefinitely. With All-In-One Security you can force logouts for all users after a configurable amount of time. * Robot verification: For additional security and to prevent spam registrations, implement Cloudflare Turnstile, Google reCAPTCHA, plain maths CAPTCHA or a honeypot to registration pages, or enable manual approval of user accounts instead. * Stops user enumeration: Prevent external users and bots from fetching user information via author permalink. * Two-factor authentication: All-In-One Security TFA supports Google Authenticator, Microsoft Authenticator, Authy and many more. * Password strength tool: Calculates how long it would take for your password to be cracked through a brute force attack. * General visitor lockout Put your site into “maintenance mode” and lock down the front-end to all visitors. This can be useful while doing back end tasks, like performing site upgrades or investigating security threats. * WordPress Salts Security Feature Extended: All-In-One Security adds 64 new characters to WordPress Salts and changes them weekly, making it even more challenging for hackers to crack your users’ WordPress passwords. FIREWALL & FILE PROTECTION SECURITY SUITE A Web Application Firewall (WAF) is your website’s first line of defence, protecting your site by monitoring traffic and blocking malicious requests. * Progressively activate firewall settings: These range from basic, intermediate and advanced. * Automatic protection from the latest threats: Our team maintains a list of known exploits, actively building protections against them which are then released as new firewall rules to free and paying customers. * 6G blacklist: All-In-One Security incorporates ‘6G Blacklist’ firewall rules, protecting your site against a known list of malicious URL requests, bots, spam referrers and other attacks (courtesy of Perishable Press). * Protect against fake Google bots: Bots presenting as Google crawlers can steal your content and litter your webpage with comment spam. Protect against it with the All-In-One Security Web Application Firewall. * Blacklist functionality: Ban users by IP address, IP address range or by specifying user agents. * Prevent DDOS attacks: Prevent malicious users from performing DDOS attacks through a known vulnerability in WordPress XML-RPC pingback functionality. * Prevent image hotlinking: Protect server bandwidth and your website’s content by preventing other sites from using your imagery via hotlinking. * Cross site scripting (XSS) protection: All-In-One Security prevents attackers from injecting malicious script into your website via a special cookie. * File change detection: Security scanners alert you to file changes in your WordPress system, so you can see if a change is legitimate or suspicious, and investigate as appropriate. * Disable PHP file editing: Protect your PHP code by disabling the ability to edit files in the WordPress administration area. * Permission setting alerts: Identify files or folders where the permission settings are not secure and correct with one-click. * Ability to create custom rules: Advanced users can add custom rules to block access to various resources on your site. * Access prevention: Prevent external users from accessing the readme.html, license.txt and wp-config-sample.php files of your WordPress site. CONTENT PROTECTION SECURITY SUITE Eliminate spam, protect your WordPress content, and your search engine rankings with these important security features from All-In-One-Security. * Comment SPAM prevention : Webpages littered with spam comments damage your brand, effect the user experience and impact SEO. All-In-One Security stops SPAM at the source by preventing comments that originate from other domains. AIOS automatically and permanently blocks spammers’ IP addresses. Site owners can use Cloudflare Turnstile or Google reCAPTCHA to reduce comment spam and block malicious users with just one click. * iFrame protection: Preventing other websites from reproducing your content via an ‘iFrame’ is a useful security feature that protects your intellectual property and your website visitors. * Copywriting protection: Stop users from stealing your content by disabling the right-click, select and copy text function. * Disable RSS and Atom Feeds: RSS and Atom Feeds can be used by bots to ‘scrape’ your website content and present it as their own. This feature prevents that by disabling RSS and Atom Feeds on your website. LATEST AND GENERAL SECURITY FEATURES INTERESTED IN AIOS PREMIUM? For even greater protections, consider All-In-One Security (AIOS) Premium. It’s one of the most cost-effective and comprehensive WordPress Security plugins on the market and extends the powers of ‘Free’ with: MALWARE SCANNING (Premium only) Finding out by accident that your website’s security has been compromised due to malware is too late. Malware can have a dramatic effect on search rankings. It can slow your site down, access customer data, send unsolicited emails, change your content or prevent users from accessing it. FLEXIBLE TWO-FACTOR AUTHENTICATION (PREMIUM ONLY) TFA is available in our free packages. All-In-One Security Premium affords whole new levels of control over how TFA is implemented. * Role specific configuration: Make TFA compulsory for certain roles, e.g. for admin and editor roles. * Require TFA after set time period: For example, you could require all admins to have TFA once their accounts are a week old. * Trusted Devices: Ask for TFA after a chosen number of days for trusted devices instead of on every login. * Anti-bot Protection: Option to hide the existence of forms on WooCommerce login pages unless JavaScript is active. * Customise design layout: Customise the design of TFA so that it aligns with your existing web design. * Emergency Codes: Generate a one-time use emergency code to allow access if your device is lost. * Multisite Compatible: Compatible with WordPress multisite networks and sub-sites. * Support for login forms: Support for WooCommerce and Affiliates-WP, Elementor Pro, bbPress and all third-party login forms without any further coding needed. Also compatible with ‘Theme my Login’ SMART 404 BLOCKING (PREMIUM ONLY) 404 errors occur when someone legitimately mistypes a URL, but they’re also generated by hackers searching for security weaknesses in your site. * Block bots producing 404s: All-In-One Security Premium automatically and permanently blocks IP addresses of bots and hackers based on how many 404 errors they generate. * Reporting: Handy charts keep you informed of how many 404s have occurred and which IP address or country is producing them COUNTRY BLOCKING (PREMIUM ONLY) Most security attacks come from a handful of countries and so it’s possible to prevent most attacks with our country blocking tool. * Block traffic based on country of origin: All-In-One Security Premium utilises an IP database that promises 99.5% accuracy. * Block traffic to specific pages: Block access to your whole WordPress site or on a page-by-page basis. * Whitelist some users from blocked countries: Whitelist IP addresses or IP ranges even if they are part of a blocked country. PREMIUM SUPPORT 插件支持 Developers 翻译

安装:

开始让您的 WordPress 站点更安全:
  1. Upload the 'all-in-one-wp-security.zip' file from the Plugins->Add New page in the WordPress administration panel.
  2. 通过 WordPress 的“插件”菜单激活插件
  3. Go to Settings menu under 'WP Security' and start activating the security features of the plugin.

升级注意事项:

  • 5.3.3: Added full captcha support for the MemberPress plugin, UI enhancements and various tweaks. See changelog for full details. A recommended update for all.

常见问题:

How is All-In-One Security (AIOS) supported?

Customers of ‘Free’ AIOS can get support from this very webpage. Select ‘Support’ from the tabs above and post a topic. We aim to respond to all support requests within 24 hours during the working week.

Is All-In-One Security compatible with other plugins?

Yes. AIOS works smoothly with most popular WordPress plugins.

Is All-in-One-Security regularly updated?

Yes. WordPress Security is something that evolves over time. We update AIOS with new security features (and fixes if required) on a regular basis so you can be assured that your site will keep benefitting from new security protection techniques for as long as you need them.

Will All-In-One Security slow down my website?

No.

Should I install All-In-One Security for free or should I purchase AIOS Premium?

The decision is yours to make. ‘Free’ AIOS incorporates a web application firewall, comprehensive login security tools including two-factor authentication and all the latest recommended WordPress security practices and techniques. But if your WordPress site is a business website, if it showcases what you do, or who you are, we generally recommend AIOS Premium. Prices start from as little as $70 for the year.

What are the additional features of All-In-One Security Premium?

AIOS Premium scans your WordPress website for malware whilst also monitoring your site's response time and uptime, notifying you of any issues within 24 hours, AIOS Premium customers also benefit from hands-on ticketed support via email (rather than via WP Support forums). Additional security tools include Country Blocking, Smart 404 Error Blocking and Advanced Two Factor Authentication. More information is available from our All-In-One Security website

How do I get started with All-In-One Security Premium?

In the web shop, purchase your preferred subscription. After completing the purchase, you will be emailed a link to download the plugin. You can also access the link through your "My Account" page. After downloading the zip file, install and activate the plugin through WP Admin->Plugins->Add New->Upload Plugin. The premium extends the free version. Therefore you should keep the free version installed and active. You will also be prompted to enter your AIOS username and password to connect your site to licenses. This will allow the plugin to receive updates.

Do I need to have the free version before downloading Premium?

Yes, you need to have the free version of the plugin installed and activated before installing Premium. Premium plugin is an add-on that requires the free version to be present.

Does All-In-One Security work with multi-site network installations?

Yes, AIOS Premium is compatible with WordPress multisites. For multisite networks, the protection will apply to the network as a whole, and the dashboard and options will be available on the main site of the WordPress multisite.

Can a WordPress security plugin stop all attacks on my site?

There is no 100% guarantee that a security plugin will be able to protect against all attacks, as there is always the possibility of unknown WordPress vulnerabilities or other unexpected factors, and attackers are always seeking to develop new ways around protections. However, All-In-One Security gives good protection against known attack methods, and is under continuous development to monitor and improve protections.

Does All-In-One Security work on all servers and hosts?

AIOS should be compatible with most hosts, unless the host has specifically restricted the use of security plugins. Similarly, certain features may not work on some servers, especially Windows/IIS platforms. Features that use the ‘.htaccess’ file will not apply on a Windows IIS server or NGINX server (but development is ongoing to port those protections to all servers).

Can I cover my subdomains and test sites with a licence for AIOS Premium?

Development and test sites require their own licence if updates to the plugin are needed. However, these sites can be disconnected from the licence when they have served their purpose. You can disconnect the licence via the site's WP Admin->Plugins page, and it will be available to be reassigned to a different site.

Is the All In One Security & Firewall Plugin GDPR and other privacy law compliant?

Please read more about GDPR compliance here: https://aiosplugin.com/privacy-policy/ .

更新日志:

5.3.3 - 16/Sep/2024 5.3.2 - 06/Aug/2024 5.3.1 - 26/Jun/2024 5.3.0 - 01/May/2024 5.2.9 - 06/Mar/2024 5.2.8 - 05/Mar/2024 5.2.7 - 06/Feb/2024 5.2.6 - 06/Feb/2024 5.2.5 - 25/Oct/2023 5.2.4 - 16/Aug/2023 5.2.3 - 09/Aug/2023 5.2.2 - 04/Aug/2023 5.2.1 - 12/Jul/2023 5.2.0 - 10/Jul/2023 5.1.9 - 09/May/2023 5.1.8 - 11/April/2023 5.1.7 - 24/March/2023 5.1.6 - 21/March/2023 5.1.5 - 13/February/2023 5.1.4 - 14/December/2022 5.1.3 - 09/December/2022 5.1.2 - 07/December/2022 5.1.1 - 16/November/2022 5.1.0 - 12/October/2022 5.0.9 - 06/October/2022 5.0.8 - 29/September/2022 5.0.7 - 08/September/2022 5.0.6 - 07/September/2022 5.0.5 - 05/September/2022 5.0.4 - 03/September/2022 5.0.3 - 02/September/2022 5.0.2 - 02/September/2022 5.0.0 - 01/September/2022 4.4.12 - 22/April/2022 4.4.11 - 29/March/2022 4.4.10 - 21/Jan/2022 4.4.9 4.4.8 4.4.7 4.4.6 4.4.5 4.4.4 4.4.3 4.4.2 4.4.1 4.4.0 4.3.9.4 4.3.9.3 4.3.9.2 4.3.9.1 4.3.9 4.3.8.3 4.3.8.2 4.3.8.1 4.3.8 4.3.7.2 4.3.7.1 4.3.7 4.3.6 4.3.5 4.3.4 4.3.3.1 4.3.3 4.3.2 4.3.1 4.3.0 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 4.2.4 4.2.3 4.2.2 4.2.1 4.2.0 4.1.9 4.1.8 4.1.7 4.1.6 4.1.5 4.1.4 4.1.3 4.1.2 4.1.1 4.1.0 4.0.9 4.0.8 4.0.7 4.0.6 4.0.5 4.0.4 4.0.3 4.0.2 4.0.1 4.0.0 3.9.9 3.9.8 3.9.7 3.9.6 3.9.5 3.9.4 3.9.3 3.9.2 3.9.1 3.9.0 3.8.9 3.8.8 3.8.7 3.8.6 3.8.5 3.8.4 3.8.3 3.8.2 3.8.1 3.8.0 3.7.9.2 3.7.9.1 3.7.9 3.7.8 3.7.7 3.7.6 3.7.5 3.7.4 3.7.3 3.7.2 3.7.1 3.7 3.6 3.5.1 3.5 3.4 3.3 3.2 3.1 3.0 2.9 2.8.1 2.8 2.7 2.6 2.5 2.4 2.3 2.2 2.1.1 2.1 2.0 1.9 1.8 1.7 1.6 1.5 1.4 1.3 1.2 1.1 1.0