| 开发者 | h3st4k3r |
|---|---|
| 更新时间 | 2026年8月14日 00:35 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
H3SEC Guard in wp-admin.No. The plugin has no mandatory external service or telemetry. Official checksum data is requested only when you explicitly run a core integrity scan, and the behavior is documented in the panel.
No. It complements server-level security controls.
It can affect legacy apps, Jetpack setups, or integrations that rely on XML-RPC.
No. The plugin does not exfiltrate site data, users, emails, or logs by default.
The local activity log can contain IP addresses, event types, attempted usernames, request paths, and security event context. It never stores passwords, tokens, cookies, authorization headers, or form bodies. Retention is configurable and old rows are removed in bounded batches. Email notifications are optional. The branded email logo is loaded by the recipient's email client from https://h3sec.com/assets/img/logo-h3sec.png. The plugin does not download or store it.
The login, reset-password, cron, CLI, AJAX, authenticated H3SEC REST, and administrator paths remain available. For emergency recovery, define H3SG_BYPASS_MAINTENANCE as true before the plugin loads, for example in wp-config.php, then disable maintenance from the panel.