Linux 软件免费装
Banner图

Ensomedia Security powered by shieldwave.io

开发者 shieldwave
更新时间 2026年9月30日 12:50
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security malware scanner hardening vulnerability scanner file integrity

下载

1.1.0 1.0.2 1.0.3 1.1.1 1.0.0 1.0.1

详情介绍:

Ensomedia Security, powered by shieldwave.io, scans your site from the inside and tells you, in plain language, what is wrong and how to fix it. It is built around one idea: an alert has to be worth your attention. Every check, the scheduled scans and the email alerts are free, work without an account and have no limits. Why owners switch to it The checks Malware and files: Vulnerabilities and software: Live protection (all opt-in, all off until you turn them on): Content and exposure: Accounts and configuration: Each issue has a severity, what it means, how to fix it and the files, plugins or settings involved. Problems of the same kind are grouped, so a site never faces hundreds of lines. You can ignore a problem; an ignored file comes back if it changes again. The score starts at 100 and loses points for the most serious open issue of each check. Login protection Two-factor login Hardening Alerts ShieldWave dashboard (optional) Press Connect with shieldwave.io under ShieldWave > Settings, sign in or create a free account, and the site shows up in your dashboard at shieldwave.io with its score and open issues, next to ShieldWave's outside scan. A free account shows one site; Pro and Enterprise show every site. The connection sends results only and confirms that the domain is yours; the dashboard cannot change anything on the site. See External services. What this plugin does not do It is not a full web application firewall (it does not inspect and block every request), and it does not remove malware for you. It finds, explains, alerts, stops brute-force logins, adds two-factor login and can switch off the file editor and XML-RPC; you, your developer or your host make the rest of the change. Visitors see nothing of it. Credits The admin screens use the Inter typeface by The Inter Project Authors, licensed under the SIL Open Font License 1.1 (assets/fonts/inter-license.txt). It is loaded from the plugin itself, only on the ShieldWave screens.

安装:

  1. Install the plugin from Plugins > Add New, or upload the ensomedia-security folder to /wp-content/plugins/.
  2. Activate it.
  3. Open ShieldWave and press Scan now. The first scan records the baseline and usually takes a few minutes; later scans are faster.
  4. Scheduled scans run daily at 03:00 (site time). Change that, the alerts and the options under ShieldWave > Settings.
  5. Optional: turn on the known-vulnerability lookup under ShieldWave > Settings > Live protection.
  6. Optional: to see the site in the ShieldWave dashboard, press Connect with shieldwave.io under ShieldWave > Settings > ShieldWave account.

屏幕截图:

  • A problem opened: what was found, how to fix it, and a button to the right WordPress screen.
  • Signs of a break-in: what to do now, and the file, rule and code that matched.
  • A scan running in the background.
  • History: every scan and every change that matters, in plain sentences.
  • Settings: automatic scans, email alerts, extra checks and the optional ShieldWave account.
  • The optional ShieldWave account: connect the site to shieldwave.io with one click, or with an API key.

升级注意事项:

1.1.0 Connect with shieldwave.io in one click, one free site in the dashboard, and a safe way to remove the old ShieldWave Security. 1.0.3 A clearer Overview, the look of shieldwave.io, and screens that fit large monitors and phones. 1.0.2 Alert emails now display correctly in Outlook on Windows, in light and dark mode. 1.0.1 The plugin now speaks 16 languages besides English, including Arabic with a right-to-left layout. 1.0.0 First release in the WordPress.org directory.

常见问题:

Do I need a ShieldWave account?

No. All 23 checks, scheduled scans, email alerts and the vulnerability lookup work without one, with no limits.

Can I hide ShieldWave from the toolbar?

Yes. Under ShieldWave > Settings > Toolbar, turn off "Show ShieldWave in the toolbar". The choice is per administrator. Visitors never see it.

How is this different from other security scanners?

It trusts the files WordPress.org can vouch for, needs real evidence before it calls something malware, and emails only about problems that are new or got worse. The goal is that every alert you get is one you would want.

What does "Ask your developer to check" mean?

The scanner found something unusual that is often harmless: for example a new PHP file in a premium plugin without an update. It is listed so someone who knows the site can look at it, and it never sends an email on its own. Problems under "Fix now" are the ones with clear evidence.

A finding is about a file I changed on purpose.

Open the item and press "Ignore". It stays out of the score and the alerts, and an ignored file comes back by itself if it changes again. Ignored items stay under the "Ignored" link below the to-do list, where "Restore" brings one back.

Will it slow my site down?

No. Scans never run while a visitor's page loads: they work in the background in steps of a few seconds, and later scans skip files that were clean and did not change. On a busy shared host you can choose the low scan speed in Settings.

Which outside requests does it make?

Only when scans run: to WordPress.org for checksums, theme packages and plugin information, and to your own site. With the vulnerability lookup, live threat feed or AI second opinion on: to shieldwave.io. With an account connected: to shieldwave.io. Each of those is off until you turn it on, and the External services section below lists exactly what is sent.

Why does the plugin register a public AJAX action?

The AJAX action shieldwave_worker lets a running scan continue in the background; it does nothing without the random token of the running scan. The plugin's REST routes answer administrators only.

My headless front end reads authors from the REST API.

With login protection on, the REST API user list answers only logged-in requests, so an anonymous request for an author gets an error. To keep the list public, add add_filter( 'shieldwave_hide_user_list', '__return_false' ); to a small plugin or to your theme's functions.php. The same filter also brings back the author fields in embeds and the users sitemap.

Does it work on multisite?

Yes, network-wide. Scanning, the schedule, alerts, the settings screens and the optional ShieldWave account all live on the main site, in the Network Admin, for network administrators only. Every other site of the network enforces the same choice made there: when login protection, two-factor or a hardening switch is on, it is on for that site too, with no separate settings screen to set up. A lockout after failed logins is shared by the whole network, not counted per site, so an address cannot dodge the limit by trying a different site.

Does it work without WP-Cron?

Yes. If WP-Cron is disabled or loopback requests are blocked, scans still run while the ShieldWave screen is open, and scheduled scans run whenever your server cron calls wp-cron.php.

How is the score calculated?

It starts at 100. For each check, the most serious open issue takes off points: critical 30, high 15, medium 8, low 3. Ignored issues, hints and checks that could not run take nothing off.

Which languages does it speak?

English, Arabic, Chinese (Simplified), Dutch, French, German, Indonesian, Italian, Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Swedish, Turkish and Vietnamese. The screens, the login protection and the alert emails follow the language of your WordPress admin, and Arabic gets a right-to-left layout. Regional variants such as Spanish (Mexico), German (Switzerland) or French (Canada) use the main language. A translation from translate.wordpress.org, once one is complete, takes precedence.

The old ShieldWave Security from shieldwave.io is installed too.

Builds downloaded from shieldwave.io before the directory listing were called ShieldWave Security, numbered up to 3.6.6, and live in the folder shieldwave-security. They cannot update themselves to this plugin. Keep Ensomedia Security active, deactivate ShieldWave Security, then delete it on the Plugins screen: the settings, results and two-factor set-ups carry over, because Ensomedia Security keeps them while the old copy's clean-up runs. The Plugins screen shows a notice while an old copy is installed.

What does connecting to shieldwave.io do?

It shows the site in your shieldwave.io dashboard with its score and open problems, next to the outside scan of shieldwave.io, and confirms that the domain is yours, which the full outside scan needs. A free account shows one site. Everything in the plugin works the same without it.

I think a finding is wrong.

Open a topic in this plugin's support forum with the check name and what you see. False positives are treated as bugs.

How do I report a security problem in the plugin?

Follow https://shieldwave.io/legal/en/vulnerability-disclosure. Please do not post it in the public support forum.

更新日志:

1.1.0 1.0.3 1.0.2 1.0.1 1.0.0