Linux 软件免费装
Banner图

Hide My WP Ghost - Security & Firewall

开发者 johndarrel
更新时间 2026年9月15日 23:59
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security login firewall brute force hide my wp

下载

5.0.29 5.2.04 5.3.02 5.2.02 1.1.008 1.1.013 1.1.021 1.1.023 1.1.033 2.0.05 2.0.12 3.1.00 3.1.02 3.2.01 3.3.00 3.3.03 3.4.00 3.5.00 3.5.01 5.0.20 7.0.09 4.1.03 4.0.09 5.0.02 4.0.08 5.0.01 2.0.16 4.1.08 4.1.09 4.1.07 4.1.10 5.0.23 5.0.12 5.0.14 5.0.13 5.0.17 4.1.06 5.0.10 4.1.02 5.0.11 5.0.15 5.0.18 5.0.22 5.0.16 4.1.05 4.0.10 5.4.07 5.5.01 7.0.01 5.0.26 5.3.00 7.0.11 5.4.02 5.4.03 5.2.01 5.4.06 5.1.01 5.4.05 5.0.27 5.1.02 5.2.03 5.3.01 5.4.01 5.0.28 7.0.00 5.1.03 5.5.04 7.0.10 4.0.11 7.0.02 7.0.03 7.0.05 7.0.06 7.0.07 7.0.08 5.5.02 4.1.11

详情介绍:

WP Ghost (formerly Hide My WP Ghost) is a professional, comprehensive hack-prevention security solution for WordPress. Built for speed and maximum defense, it provides a multi-layered security architecture to block hacker bots, neutralize automated scanners, and stop hacks before reconnaissance begins. While traditional security tools focus on Detection (scanning for malware after a breach) or Signature-Filtering (blocking known exploits), WP Ghost focuses on Architecture. By implementing Paths Security and Site Hardening, it removes digital footprints that make your site a target for automated botnets. This provides a proactive foundation that secures your site before it can be identified as a target. [youtube https://youtu.be/QMdoSN8dk1c] WP Ghost Global Stats: Official websites: WP Ghost (wpghost.com) Hide My WP Ghost (hidemywpghost.com) Hide WordPress with Path Security and Reduce Your Attack Surface Hide WordPress paths that attackers commonly scan, including wp-admin, wp-login.php, wp-content, wp-includes, plugin paths and theme paths. Most WordPress attacks are automated. Bots scan millions of sites per hour looking for default paths like /wp-admin or /wp-login.php to confirm a site is running WordPress. Once confirmed, they launch targeted exploits against known plugin or theme vulnerabilities. WP Ghost breaks this cycle. By changing and securing common paths, you reduce your attack surface by up to 90%. This is not “obscurity”, it is Site Hardening. The visible structure of your site is re-engineered so it is no longer low-hanging fruit for global botnets. NEW: AI Security Explanations - Your Report, Explained for Your Website Every security plugin hands you a list of red warnings. Almost none of them tell you what those warnings mean for your website. WP Ghost now does. One click sends your findings for analysis based on your site’s actual configuration: server type, whether rewrite rules are active, if your config file is writable, and your security mode. It then returns a security report written specifically for you, not for WordPress in general. Requires a WP Ghost subscription, which includes a monthly allowance of AI checks. Everything else on the Security Check page - the scan, the score, the prioritised list, the severity bands and every task detail - is free and works on its own. What you get back: Built with limits you can check. Only your findings and a small description of your setup are ever sent - no page content, no user data, no credentials. Your security list, your score, the severity bands and every task detail are generated locally and keep working whether the AI is available or not. Read more about AI Security Explanations on wpghost.com NEW: Ghost Doctor - Finds and Repairs a Broken Site by Itself Changing your WordPress paths depends on your server honouring the new rules. When it doesn’t - Nginx never reads .htaccess, Apache ignores it without AllowOverride, a host locks the config file - your site can break, and nothing tells you why. Ghost Doctor diagnoses issues and repairs what a plugin can. It checks your homepage, theme files, editor requests, and REST API as a visitor would see them. Then it works through repairs from safest to most invasive. Every repair is tested immediately and undone automatically if it does not help, so no setting is changed unnecessarily. Anything requiring a server change is clearly named with a guide, avoiding guesswork. Read the Ghost Doctor troubleshooting guides Key Protections Included WP Ghost is packed with advanced defensive mechanisms to protect your site against: Over 115 Free Security Features Included We believe professional security should be accessible to everyone. The free version of WP Ghost includes a large suite of tools to harden your WordPress architecture.
  1. Change and Secure Paths (Paths Security)
  2. Change wp-admin & wp-login.php: Move your login to a unique URL and show a 404 error to intruders.
  3. Change Lost Password & Register URLs: Secure all authentication entry points.
  4. Change wp-content & wp-includes: Secure your core system folders from direct access.
  5. Anonymize Plugins & Themes: Change visible plugin/theme paths so hackers can’t identify your software version.
  6. Secure admin-ajax.php & REST API: Change the /wp-json path to prevent data scraping.
  7. Security Presets: One-click activation with three preset levels from minimal to full protection including Firewall, Brute Force, Logs, and 2FA.
  8. Frontend Test: Verify your site loads correctly after changing paths before confirming settings.
  9. Custom Redirects: Set unique login/logout redirects based on user roles.
  10. Login Page Designer: Customize your secured login page with your logo, colors, background, and 10 color schemes.
  11. WordPress Firewall Protection & WordPress Login Security
  12. 8G & 7G Firewall Filters: High-speed, lightweight server-edge filtering to block bad bots.
  13. Passkey Authentication (Passwordless 2FA): Use Face ID, Touch ID, or Windows Hello for un-phishable, device-based logins.
  14. Standard 2FA (Code & Email): Add an extra verification layer to all user accounts.
  15. Security Headers: Automatically implement CSP, HSTS, X-Frame-Options, and more.
  16. IP & User Agent Blocking: Manually blacklist suspicious traffic or referrers.
  17. Security Threats Log: Track blocked attacks and malicious requests directly in your dashboard (limited view).
  18. User Events Log: Monitor login activity, role changes, and user actions (limited view).
  19. GEO Threats Map: Visualize where attacks originate with an interactive world map showing the top 5 threat countries.
  20. Security Optimization Score: Real-time 0-100 score showing exactly how hardened your site is, with actionable recommendations.
  21. Temporary Logins: Create time-limited access links for developers and clients without sharing passwords.
  22. Deep Hiding & Footprint Removal
  23. Scrub Meta Tags: Remove WordPress version numbers and generator tags.
  24. Clean HTML Comments: Strip identifiable comments that reveal your tech stack.
  25. Hide Admin Toolbar: Remove the toolbar for specific roles to hide backend indicators.
  26. Disable Emoticons & RSD: Remove unnecessary header links that bloat code and reveal info.
  27. Advanced Disable Options
  28. Disable XML-RPC: Shut down the most common vector for DDoS and brute force.
  29. Disable REST API Access: Restrict API access to authenticated users only.
  30. Frontend Lockdown: Disable right-click, “View Source,” and text selection to prevent manual reconnaissance.
  31. Disable Directory Browsing: Ensure your server folders are never visible to the public.
  32. Brute Force Protection
  33. Integrated ReCaptcha: Supports Google V2, V3, Enterprise, and Math ReCaptcha.
  34. Targeted Protection: Enable brute force defense on Login, Signup, and WooCommerce pages.
  35. Custom Throttling: Define your own lockout times and attempt limits.
  36. Extra Tools & Integrations
  37. Magic Links: Log in securely without a password via a one-time email link.
  38. Text & URL Mapping: Change any class name or URL in your source code dynamically.
  39. CDN & Cache Support: Works perfectly with WP Rocket, Cloudflare, and Litespeed.
  40. Ghost Doctor: Diagnoses why your paths stopped working and repairs what it can. It tests every repair and undoes anything that does not help.
  41. Prioritized Security Check: Failing paths and failed hardening tasks appear as one list, worst first, with time-based bands such as “worth fixing this week” instead of separate tables to reconcile.
  42. AI Security Explanations: Get every finding explained for your website and ranked by real exposure. Requires a connected WP Ghost account with an active subscription; a monthly allowance applies. Learn more.
Premium Hack-Prevention Features For agencies and high-traffic sites, WP Ghost Premium adds advanced features focused on Security Intelligence, Automated Response, and Copyright Protection. Hide My WP Premium Feature

安装:

From your WordPress Dashboard Step 1. Navigate to Plugins > Add New. Step 2. Search for “WP Ghost”. Step 3. Click Install Now and then Activate. Step 4. Go to the WP Ghost menu in your sidebar. Step 5. Enter your email address to receive your instant Free Access Token. Step 6. Follow the built-in Setup Wizard to begin hardening your paths. Manual Installation Step 1. Download the hide-my-wp.zip file from the WordPress repository or your WP Ghost account. Step 2. Log in to your WordPress dashboard as an Administrator. Step 3. Navigate to Plugins > Add New > Upload Plugin. Step 4. Select the .zip file and click Install Now. Step 5. Click Activate Plugin. Step 6. Connect the plugin using your email address to activate your security features. Reporting a Security Vulnerability Found a security issue in WP Ghost? Report it privately through our Patchstack managed disclosure programme at patchstack.com/database/report or email security@hidemywpghost.com. We acknowledge reports within 48 hours and coordinate disclosure within 90 days. Please do not post details in the support forum before a fix is released. The full policy is included with the plugin in SECURITY.md, and third-party components are listed in sbom.json. Support period: Security updates are provided for 5 years from each version’s release. Version 7.0.11, released September 2026, is supported until September 2031. Installing a newer release extends the end date. Resources & Guides For advanced server configurations or detailed walkthroughs, please visit our comprehensive documentation: How to Install and Setup WP Ghost WP Ghost Knowledge Base:

屏幕截图:

  • Admin Security: Change and secure the wp-admin path to block unauthorized dashboard access.
  • Paths Security: Customize and secure your login and registration entry points.
  • Core Security: Harden your system paths (wp-content, uploads, includes) against bot reconnaissance.
  • API & AJAX Security: Secure the REST API and admin-ajax paths to prevent data scraping.
  • 8G Firewall Engine: High-performance, server-edge threat filtering for proactive hack prevention.
  • Brute Force Defense: Integrated Google reCaptcha and Math protection for all authentication paths.
  • Modern Authentication: Secure logins with 2FA and future-proof Passkey (Passwordless) support.
  • Text Mapping: Dynamically change class names and IDs in your source code to prevent fingerprinting.
  • URL Mapping: Re-engineer internal URLs and paths for elite-level site hardening.
  • Hardening Tweaks: Deep hide options to remove WordPress version tags and identifiable meta-data.
  • Redirect Logic: Custom 404 and role-based redirect options for secured paths.
  • Safe Access: Manage Temporary Logins and Magic Links for secure developer access.
  • Security Threats Log: Activate Security Threats Log to track blocked attacks and malicious requests.
  • Security Threats Log: The list of the recent threats prevented by WP Ghost.
  • Overview Dashboard: An overview of the last 7 days of security events.
  • Front-end View: Example of a custom, secured login path (/newlogin).
  • Attack Blocked: Default wp-login.php now returns a 404 error to confuse hacker bots.
  • Access Denied: Default wp-admin path is fully secured and hidden from public view.
  • Source Code Proof: Core WordPress paths transformed and secured to neutralize bot scans.

常见问题:

Does WP Ghost physically move or rename my WordPress files?

No. WP Ghost uses high-performance server rewrite rules (Nginx, Apache, IIS) to change visible paths in your source code. Your actual WordPress files and directories stay exactly where they are, ensuring no risk to your site’s stability or core updates.

Is WP Ghost a complete standalone solution?

For most WordPress sites, yes. By combining Architectural Hardening with an 8G Firewall and Automated IP Blocking, WP Ghost neutralizes automated reconnaissance and brute-force attempts that account for over 90% of real-world attacks. It provides a foundational defense often sufficient on its own, while remaining fully compatible with “Defense in Depth” strategies involving malware scanners or file-integrity monitors.

What are AI Security Explanations?

Security scanners tell you what is wrong. AI Security Explanations tell you what it means for your website. WP Ghost sends your findings for analysis along with a short description of your site setup: server type, whether rewrite rules are active, if your config file is writable, and your security mode. It returns a plain-language explanation for each finding, one clear action to take, and a priority order based on what genuinely exposes your site. Open Details on any finding to read the reasoning behind it. Read more on wpghost.com.

What data is sent when I use AI Security Explanations?

Only the findings already on your Security Check page and a small description of your configuration are sent: server type, whether the config file is writable, whether rules are present, if a cache plugin is installed, your security mode, and a count of mapped files. No page content, user data, passwords, or database contents are ever sent. The feature is entirely opt-in; nothing is transmitted until you press the button.

Does WP Ghost still work without the AI?

Completely. The Security Check scan, 0-100 score, prioritized list, severity bands, every task detail, and the entire Ghost Doctor diagnosis and repair process run on your server and need no connection. AI Security Explanations only add wording on top. Using them requires a connected WP Ghost account with an active subscription and a monthly allowance of checks. The page shows exactly how many you have left. = Is it compatible with other WordPress security plugins? =Yes. WP Ghost is designed as your “Outer Perimeter” defense. It works perfectly alongside malware scanners and reactive security tools like Wordfence, Sucuri, or Solid Security. By implementing Paths Security first, WP Ghost stops bots before they get close enough to be scanned by other plugins..

Will changing my paths affect my SEO or Google rankings?

Not at all. WP Ghost handles Sitemap.xml and Robots.txt mapping automatically. This ensures Google and other search engines can index your content perfectly, while malicious bots receive a 404 error when probing your system paths.

What is the difference between Paths Security and “Security through Obscurity”?

Obscurity is simply hiding a key under a mat. Paths Security is an architectural hardening strategy like moving the door to a secure, unique location and changing the lock. It is a recognized technical hardening standard used by enterprise-grade sites to prevent Bot Reconnaissance.

Does WP Ghost work on WP Multisite and different server types?

Yes. The plugin is fully compatible with WP Multisite (Network-wide configuration) and supports Apache, Nginx, IIS, and LiteSpeed servers.

How do I configure WP Ghost on an Nginx Server?

WP Ghost fully supports Nginx. Because Nginx does not use .htaccess, you will be guided to add the generated rewrite rules manually to your nginx.conf file. We provide specific tutorials for Kinsta, RunCloud, CloudPanel, CWP7, AAPanel, and Ploi.io.

My theme is not loading correctly after changing paths. What should I do?

This usually happens when the server rewrite rules are not yet active.

  • Purge Cache: Clear your WordPress cache and any server-side caching (Varnish, Nginx FastCGI).
  • Manual Rewrites: If your server config file is not writable, copy the rules from WP Ghost and add them manually to your .htaccess or nginx.conf.
  • Restart Nginx: If on Nginx, you must reload/restart the service after saving settings.
  • Free Support: If the issue persists, contact us and we will set up the plugin for you for free.

I am locked out or forgot my custom login URL. How do I get back in?

  • Safe URL: Use the “Safe URL” text file automatically generated and downloaded when you saved your settings.
  • Manual Reset: Access your server via FTP/SFTP and rename the folder /wp-content/plugins/hide-my-wp to something else. This temporarily disables the path changes so you can login via the default wp-login.php.

Does WP Ghost work for WordPress.com websites?

Due to the restricted infrastructure of WordPress.com managed hosting, changes to the administrative and login paths are not allowed. However, you can still use WP Ghost for Site Hardening, the 8G Firewall, Passkey Authentication, and other Hack Prevention features.

Is the WP Ghost plugin free of charge?

Yes. The Lite version of WP Ghost will always be free and includes essential WordPress Security updates. To unlock advanced features like IP Block Automation, Geo-Security, and Cloud Monitoring, you can upgrade to WP Ghost Premium.

How can I hide my site from WordPress Theme Detectors?

By using Paths Security to change common directories (plugins, themes, wp-content), you effectively neutralize most automated detectors. For a deep-dive on total anonymity, read our guide: How to Hide Your Site From WordPress Theme Detectors.

Is this plugin enough to protect my website from all hackers?

WP Ghost provides an elite proactive defense by neutralizing the Reconnaissance phase of an attack. While the Free version blocks the vast majority of bot traffic, we recommend the Premium version for advanced Brute Force Protection and Automated Threat Intelligence.

How do I change the WordPress paths in the Admin Dashboard area?

By default, WP Ghost only changes paths on the frontend to ensure maximum compatibility. To harden the admin dashboard as well, add define('HMW_ALWAYS_CHANGE_PATHS', true); to your wp-config.php file and re-save your settings.

Does WP Ghost include a security score?

Yes. WP Ghost 7.0 includes a Security Optimization Score from 0 to 100 that shows exactly how hardened your site is. The score updates automatically as you enable features and complete security tasks. It appears on the Overview dashboard and the Security Check page as both a visual gauge and a numeric value.

Can I customize the WordPress login page with WP Ghost?

Yes. WP Ghost includes a Login Page Designer that lets you add your custom logo, background image, and brand colors to your secured login page. It includes 12 layout presets and 10 color scheme presets. The designer works with your custom login URL, so your branded page is served at your hidden path instead of the default wp-login.php.

Does WP Ghost protect my content from AI training bots?

WP Ghost Premium includes an AI Copyright Protection feature that blocks 30+ AI training crawlers including GPTBot, ClaudeBot, PerplexityBot, CCBot, and Bytespider at the firewall level. It also adds Disallow rules to your robots.txt automatically. This protects your copyrighted content from being used for AI model training without affecting your regular Google, Bing, or Yahoo search visibility. The crawler list is automatically updated with each plugin release.

更新日志:

7.0.11 (10 September 2026) 7.0.10 (2 September 2026) 7.0.09 (17 August 2026) 7.0.08 (27 July 2026) 7.0.07 (20 July 2026) 7.0.06 (15 July 2026) 7.0.05 (08 July 2026) 7.0.04 (29 June 2026) 7.0.03 (02 June 2026) 7.0.02 (11 May 2026) 7.0.01 (15 April 2026) 7.0.00 (31 March 2026) Major Release: Security Score, Login Page Designer, Passkey 2FA, Security Threats Log, User Events Log, GEO Threats Map, and expanded 7G/8G Firewall rules. Free update for all users. Firewall & Security Updates: Compatibility: UI & Experience: 5.5.04 (26 Mar 2026) 5.5.02 (10 Feb 2026) 5.5.01 (22 Dec 2025) 5.4.08 (09 Dec 2025) 5.4.07 (29 Sept 2025) 5.4.06 (21 Aug 2025) 5.4.05 (27 May 2025) 5.4.04 (21 Mar 2025) 5.4.03 (11 Mar 2025) 5.4.02 (04 Mar 2025) Security: Ocultar Mi WP - Plugin de seguridad de WordPress Ocultar meu WP - Segurança do WordPress Cacher mon WordPress - Plugin de sécurité WordPress Verstecken Sie mein WordPress - WordPress Sicherheits-Plugin