Linux 软件免费装
Banner图

CodeCanvas Guard

开发者 codecanvasinc
更新时间 2026年8月29日 02:23
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

security login two-factor hardening audit-log

下载

1.3.2

详情介绍:

CodeCanvas Guard is a local-first WordPress security suite built around reviewable changes and safe recovery. Core features include: Scheduled scans do not modify files. Repair, quarantine, restore, and rollback actions require an authenticated administrator action and nonce. Guard does not send telemetry to CodeCanvas.

安装:

  1. Back up the site and confirm hosting-panel or SSH access.
  2. Install and activate CodeCanvas Guard.
  3. Open CodeCanvas Guard and apply the Balanced profile.
  4. Configure 2FA from Users > Two-Factor Security.
  5. Generate and save an emergency recovery link before configuring a protected login route.
  6. Verify and activate the protected route, then test it in a private browser.
  7. Test checkout, membership, mobile-app, PWA, password-reset, and integration flows before applying Strict mode.

升级注意事项:

1.3.1 WordPress.org Plugin Check remediation release. Existing settings, profiles, protected-login routes, verification state, 2FA data, and recovery records are preserved.

常见问题:

Does Guard automatically remove malware?

No. Scans report evidence. Trusted WordPress sources can be reinstalled and executable uploads can be quarantined only after explicit administrator approval. Custom, premium, database, or ambiguous findings remain manual-review items.

Why can some plugins not be repaired automatically?

Automatic repair is available only when the exact installed version has a trusted WordPress.org package and checksum set. Premium, custom, or repository-removed plugins require a trusted vendor package or manual restoration.

Does repair activate another plugin?

No. Guard does not change another plugin's activation status. If WordPress leaves a repaired plugin inactive, Guard verifies the installed files and asks an administrator to reactivate it manually from the native Plugins screen.

Are repairs reversible?

Eligible plugin repairs create a protected pre-repair copy. Verification failure triggers file rollback, and successful repairs retain a manual rollback point. Permission repairs retain the previous mode. Quarantined files require a separate restore approval. Keep a current hosting backup.

Does fingerprint reduction make WordPress impossible to detect?

No. Guard removes common public indicators and simple enumeration paths, but themes, assets, APIs, and behaviour can still reveal WordPress.

Does the protected login route work with plain permalinks?

The request-path fallback is designed to work when pretty permalinks are unavailable. Hosting rules, caching, and other security plugins can interfere, so verify the route before activation.

Will XML-RPC blocking affect integrations?

It can. Jetpack, WordPress mobile apps, and other integrations may require XML-RPC. The Balanced profile leaves XML-RPC available.

Should I enable HSTS immediately?

No. Enable HSTS only after the whole site and every required resource work permanently over HTTPS.

更新日志:

1.3.2 1.3.1 1.3.0 Older release history is available in changelog.txt.