CenterShield is a WordPress security plugin built for Japanese site owners and the
agencies that maintain their sites.
It brings login protection, two-factor authentication, hardening, file protection and
malware scanning together in one place. Every setting explains what it protects and
what changes when you turn it on, so you can choose the measures your site needs
without security expertise.
The admin interface and all messages are in Japanese only.
Activating the plugin changes nothing on your site. Press "apply recommended settings"
to enable the recommended set in one step, or turn on each feature yourself.
Account and login protection
- Login attempt limiting (brute force protection)
- Username disclosure prevention
- Custom login URL
- HTTP Basic authentication on the login screen (written to .htaccess on Apache)
- reCAPTCHA v2 / v3
- Two-factor authentication (authenticator app, email, backup codes), with an optional grace period and an option to skip the code for 30 days on trusted devices
- XML-RPC disabling (signed Jetpack requests are still allowed)
- IP address restriction for the admin area
Disabling unused features and weak settings
- Pingback
- REST API restriction (well known plugins such as Contact Form 7, Jetpack and WooCommerce stay allowed)
- Author archive pages
- Theme and plugin file editor, application passwords
- Unneeded tags in wp_head, such as the WordPress version, the RSD link and emoji scripts
File and server protection
- Blocking direct access to wp-includes, wp-config.php, configuration and backup files
- Blocking PHP execution in the uploads folder
- Disabling directory listing
- Security headers such as X-Frame-Options
- Removing publicly readable files such as readme.html
- Permission review and correction
Ongoing protection
- Input filtering (lightweight WAF)
- Comment spam blocking (honeypot, rate limit, previous spam history)
- Detection of plugins and themes that have gone two years without an update or are not tested with your version of WordPress
Malware scanning
- Comparison against official checksums for WordPress core and plugins hosted on WordPress.org. Differences limited to comments or line endings are reported as informational
- Matching against a known vulnerability database
- Pattern matching against malware signatures bundled with the plugin and updated from the author's server
- Change detection against the previous scan, for themes and plugins that are not on WordPress.org
- Database inspection of posts, widgets and administrator accounts
- Quarantine, restore from the official original, and difference display
1.0.6
The malware scan now compares plugin files against the official zip and can reinstall a plugin from the official release in one click. The .htaccess notices can be dismissed.
1.0.5
Notices now appear above the tabs, and when the server rejects part of the .htaccess rules, only the unsupported setting is left out and the rest stay in effect.
1.0.4
Settings screens now show unsaved changes and warn before you leave without saving.
1.0.3
The malware scan now checks image files for hidden PHP code and no longer reports translation updates as changed files.
1.0.2
Vulnerability results now refresh right after you update WordPress, a plugin or a theme. Recommended for all users.
1.0.1
Fixes the admin buttons on WordPress 6.x and malware scan false positives in nested WordPress installs, groups scan results by type, and adds a grace period and trusted devices to two-factor authentication.
1.0.0
First release.