| 开发者 | brighterycom |
|---|---|
| 更新时间 | 2026年9月7日 00:28 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
example.php.jpg.mu directory.
For WordPress.org transparency and normal plugin lifecycle behavior, Brightery File Lockdown does not copy or install itself into wp-content/mu-plugins automatically.
A trusted server administrator may manually deploy the Must-Use mode using two files from this package:
mu/brightery-file-lockdown-mu-loader.php to wp-content/mu-plugins/brightery-file-lockdown.php.wp-content/mu-plugins/brightery-file-lockdown/ and copy includes/class-brightery-file-lockdown.php into that directory as class-brightery-file-lockdown.php.WP_PLUGIN_DIR or the normal plugin directory name. This lets the Must-Use protection continue loading even if the normal plugin is deactivated or its directory is renamed.
Remove both manually deployed Must-Use files with trusted filesystem access before uninstalling the normal plugin.
This plugin is a hardening layer, not a guarantee against compromise. Keep WordPress, plugins, themes, PHP, and the web server updated and apply server-level upload execution restrictions where appropriate.
server directory.wp-config-example.txt for optional server-side configuration.In standard mode, yes. This respects the normal WordPress plugin lifecycle. For a compromised-admin threat model, manually deploy the included MU loader and engine copy using trusted server access.
No. The WordPress.org package does not automatically create or modify files in wp-content/mu-plugins or other content directories.
The Must-Use loader is intentionally independent of the normal plugin directory. Deploying a copy of the engine beside the loader means the loader does not hardcode the normal plugin folder or rely on WP_PLUGIN_DIR.
Common image, audio, and video formats remain allowed. PDF is disabled by default and can be explicitly enabled in wp-config.php.
Updates are allowed by default. They can be disabled through server-side configuration constants when a site owner intentionally wants a stricter immutable-code workflow.
No. There are no telemetry, tracking, remote API, license-check, or external service calls.
The latest 100 blocked events are kept in a non-autoloaded WordPress option on the local site. Entries can contain the blocked filename, claimed MIME type, reason, and event time. IP addresses and user IDs are not collected.
The plugin removes its local blocked-event option during normal WordPress uninstall. Any manually deployed Must-Use files must be removed separately using trusted filesystem access.
brighterycom.__FILE__ and plugin_dir_path() instead of relying on implicit paths.WP_PLUGIN_DIR and the normal plugin folder slug.DISALLOW_FILE_EDIT constant; it is now documented as optional server configuration.