| 开发者 | shieldwave |
|---|---|
| 更新时间 | 2026年9月30日 12:50 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
wp shieldwave two-factor disable <user> rescues an account from the shell.assets/fonts/inter-license.txt). It is loaded from the plugin itself, only on the ShieldWave screens.
ensomedia-security folder to /wp-content/plugins/.No. All 23 checks, scheduled scans, email alerts and the vulnerability lookup work without one, with no limits.
Yes. Under ShieldWave > Settings > Toolbar, turn off "Show ShieldWave in the toolbar". The choice is per administrator. Visitors never see it.
It trusts the files WordPress.org can vouch for, needs real evidence before it calls something malware, and emails only about problems that are new or got worse. The goal is that every alert you get is one you would want.
The scanner found something unusual that is often harmless: for example a new PHP file in a premium plugin without an update. It is listed so someone who knows the site can look at it, and it never sends an email on its own. Problems under "Fix now" are the ones with clear evidence.
Open the item and press "Ignore". It stays out of the score and the alerts, and an ignored file comes back by itself if it changes again. Ignored items stay under the "Ignored" link below the to-do list, where "Restore" brings one back.
No. Scans never run while a visitor's page loads: they work in the background in steps of a few seconds, and later scans skip files that were clean and did not change. On a busy shared host you can choose the low scan speed in Settings.
Only when scans run: to WordPress.org for checksums, theme packages and plugin information, and to your own site. With the vulnerability lookup, live threat feed or AI second opinion on: to shieldwave.io. With an account connected: to shieldwave.io. Each of those is off until you turn it on, and the External services section below lists exactly what is sent.
The AJAX action shieldwave_worker lets a running scan continue in the background; it does nothing without the random token of the running scan. The plugin's REST routes answer administrators only.
With login protection on, the REST API user list answers only logged-in requests, so an anonymous request for an author gets an error. To keep the list public, add add_filter( 'shieldwave_hide_user_list', '__return_false' ); to a small plugin or to your theme's functions.php. The same filter also brings back the author fields in embeds and the users sitemap.
Yes, network-wide. Scanning, the schedule, alerts, the settings screens and the optional ShieldWave account all live on the main site, in the Network Admin, for network administrators only. Every other site of the network enforces the same choice made there: when login protection, two-factor or a hardening switch is on, it is on for that site too, with no separate settings screen to set up. A lockout after failed logins is shared by the whole network, not counted per site, so an address cannot dodge the limit by trying a different site.
Yes. If WP-Cron is disabled or loopback requests are blocked, scans still run while the ShieldWave screen is open, and scheduled scans run whenever your server cron calls wp-cron.php.
It starts at 100. For each check, the most serious open issue takes off points: critical 30, high 15, medium 8, low 3. Ignored issues, hints and checks that could not run take nothing off.
English, Arabic, Chinese (Simplified), Dutch, French, German, Indonesian, Italian, Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Swedish, Turkish and Vietnamese. The screens, the login protection and the alert emails follow the language of your WordPress admin, and Arabic gets a right-to-left layout. Regional variants such as Spanish (Mexico), German (Switzerland) or French (Canada) use the main language. A translation from translate.wordpress.org, once one is complete, takes precedence.
Builds downloaded from shieldwave.io before the directory listing were called ShieldWave Security, numbered up to 3.6.6, and live in the folder shieldwave-security. They cannot update themselves to this plugin. Keep Ensomedia Security active, deactivate ShieldWave Security, then delete it on the Plugins screen: the settings, results and two-factor set-ups carry over, because Ensomedia Security keeps them while the old copy's clean-up runs. The Plugins screen shows a notice while an old copy is installed.
It shows the site in your shieldwave.io dashboard with its score and open problems, next to the outside scan of shieldwave.io, and confirms that the domain is yours, which the full outside scan needs. A free account shows one site. Everything in the plugin works the same without it.
Open a topic in this plugin's support forum with the check name and what you see. False positives are treated as bugs.
Follow https://shieldwave.io/legal/en/vulnerability-disclosure. Please do not post it in the public support forum.