Linux 软件免费装
Banner图

ETBS Account Guard

开发者 etbsjp
更新时间 2026年10月1日 16:25
捐献地址: 去捐款
PHP版本: 7.3 及以上
WordPress版本: 7.1
版权: GPL-2.0-or-later
版权网址: 版权信息

标签

security login username rest api user enumeration

下载

1.2.1 1.2.2 1.3.0

详情介绍:

WordPress shows the login names of your users, or names made from them, in several places that anyone can reach without logging in: the REST API, oEmbed, the user sitemap, the ?author= redirect and the messages of the login screen. Once a login name is known, only the password is left to guess. ETBS Account Guard closes these places. Each one can be turned on or off from Settings > ETBS Account Guard. What it covers Access Restriction (IP restriction) On the Access Restriction tab of Settings > ETBS Account Guard, you can require an IP address check for a role, for a specific user, or both. The administrator role itself is always unrestricted; a specific administrator can still be restricted from their own user edit screen. A user's own setting always wins over their role's setting, and a user held to more than one requirement (through more than one role) must satisfy all of them. Access Restriction (BASIC authentication) BASIC authentication is a third mode, alongside "no restriction" and "IP restriction", for a role or a specific user. It asks for a separate username and password (not the WordPress login) with a native browser sign-in prompt, on top of your normal WordPress login. Two-Step Verification (verification code by email) On the Two-Step Verification tab of Settings > ETBS Account Guard, you can require a verification code, sent to the user's registered email address, after the password has been accepted. It is off by default (see the FAQ). Emergency switch If Access Restriction ever locks everyone out, add define( 'ACGD_DISABLE_RESTRICTION', true ); to wp-config.php. This stops Access Restriction only; Login Name Protection keeps working. If nobody can sign in because verification codes do not arrive, add define( 'ACGD_DISABLE_TWO_STEP', true ); to wp-config.php. This stops Two-Step Verification only; Access Restriction and Login Name Protection keep working. Define it also on a copy of your site whose email sending is turned off. When the switch is taken off again, users who need a code and signed in while it was on are signed out once on their next request. The two switches are independent. While a switch is on, a warning is shown on the admin screens. What it does not do Authenticator apps (TOTP), login attempt limits, CAPTCHA and firewalls are not included. Two-Step Verification is limited to a code sent by email. Use a dedicated security plugin for the others. The ?author= redirect and the login messages overlap with some of those plugins; having both does no harm. Known limitations

安装:

  1. Upload the etbs-account-guard folder to the /wp-content/plugins/ directory.
  2. Activate the plugin through the Plugins screen.
  3. The protections are active right away. Review them under Settings > ETBS Account Guard.

屏幕截图:

  • The list of users whose display name or nickname is the same as their login name, with a link to each user's profile.
  • The Access Restriction tab, where each role other than administrator can be restricted to allowed IP addresses or asked for a second ID and password (BASIC authentication).
  • The Access Restriction section of the user edit screen, where an administrator can set a user to follow the role setting or give them their own mode, extra IP addresses, and a BASIC authentication ID and password.
  • The Denial Log tab, listing denied sign-ins and requests with the date and time, user, IP address and where it happened.

常见问题:

Does it affect the block editor?

No. The REST API user endpoints stay available to logged-in users, which is what the author panel of the block editor uses.

I turned an item off. Does the plugin still change anything for it?

No. Each item returns to the behavior of WordPress itself when it is turned off.

What is removed when I delete the plugin?

Deleting the plugin removes the denial log of Access Restriction, the saved result of the BASIC authentication receive diagnosis (rebuilt the next time it is run), the sign-in attempts, send records, confirmations and trusted devices of Two-Step Verification, a few internal records and cached counts, and, if present, the update check data left behind by an earlier version distributed outside WordPress.org. All settings, including the per-role and per-user Access Restriction modes, IP lists, BASIC authentication IDs and password hashes, and the per-role and per-user Two-Step Verification settings (including the number of days a device is trusted), are kept so that they come back if you install the plugin again.

Does Two-Step Verification change anything right after updating?

No. It is off for every role and user until you turn it on. Existing settings are not changed.

The verification code does not arrive. What can I do?

Wait a few minutes, check the spam folder, and send a new code from the code screen. If codes never arrive, check the email sending of your site. As a last resort, add define( 'ACGD_DISABLE_TWO_STEP', true ); to wp-config.php to stop Two-Step Verification until the problem is fixed.

Can users turn Two-Step Verification on for themselves?

No. Only users who can manage options can change it, on the settings tab or on the user edit screen.

How does "trust this device" work?

On the code screen, a user can check "Skip the verification code on this device for 30 days" (unchecked by default; do not check it on a shared computer). The number of days is set on the tab: 7, 30 (the default) or off. Only the code is skipped: the password is needed every time, and IP restriction and BASIC authentication still apply. The browser keeps a random value in an HttpOnly cookie, and the site stores only its hash (up to 20 devices per user; the oldest go first). A change of the number of days applies at once to devices already trusted, and saving "Do not trust devices" revokes every trusted device of every user. Changing the password (by a reset, on the profile screen or by any other means) revokes every trusted device of that user, and so does the "Revoke all trusted devices on save" checkbox on the user edit screen — use either if a device is lost. When another user trusts the same browser, the earlier user needs a code again there. Trusted devices do not apply to XML-RPC.

How do I turn Two-Step Verification on for my own account?

First click "Send a confirmation code" at the top of the tab (or in the Two-Step Verification section of your own Profile screen) and enter the code you receive. A save that would turn two-step verification on for your own account is refused until you have done this within the last 10 minutes, so you cannot lock yourself out with an address that does not receive email. Turning it on for someone else requires that their account has a valid email address.

Why were users signed out right after Two-Step Verification was turned on?

A session of a user who needs a code is kept only if it went through the code (or was created inside such a session). Sessions from before the feature was turned on, and sessions created by other plugins' sign-in methods, are signed out on their next request. The acgd_two_step_session_exempt filter can keep them.

Does it work on multisite?

Two-Step Verification is not available on multisite: the login cookie can be shared across the network, so a site without it would let people in. The other features work as before.

更新日志:

1.3.0 1.2.2 1.2.1 1.2.0 1.1.1 1.1.0 1.0.0