Linux 软件免费装
Banner图

Hide My WP Ghost - Security & Firewall

开发者 johndarrel
更新时间 2026年10月7日 01:40
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security login firewall brute force hide my wp

下载

5.0.29 5.3.02 5.2.02 1.1.008 1.1.013 1.1.021 1.1.023 1.1.033 2.0.05 2.0.12 3.1.00 3.1.02 3.2.01 3.3.00 3.3.03 3.4.00 3.5.00 3.5.01 5.0.20 4.1.03 4.0.09 5.0.02 4.0.08 7.0.11 5.0.01 2.0.16 4.1.08 4.1.09 4.1.07 4.1.10 5.0.23 5.0.12 5.0.14 5.0.13 5.0.17 4.1.06 5.0.10 4.1.02 5.0.11 5.0.15 5.0.18 5.0.22 5.0.16 4.1.05 4.0.10 5.4.07 5.5.01 7.0.01 5.0.26 5.3.00 5.4.02 5.4.03 5.2.01 5.4.06 5.1.01 5.4.05 5.0.27 5.1.02 5.2.03 5.3.01 5.4.01 5.0.28 7.0.00 5.1.03 5.5.04 7.0.10 4.0.11 7.0.02 7.0.03 7.0.05 7.0.06 7.0.07 5.5.02 4.1.11 5.2.04 7.0.08 7.0.09 7.0.12 7.0.13

详情介绍:

WP Ghost (formerly Hide My WP Ghost) is a professional, comprehensive hack-prevention security solution for WordPress. Built for speed and maximum defense, it provides a multi-tiered security architecture that blocks hacker bots, neutralizes automated scanners, and stops hacks before reconnaissance begins. While traditional security tools focus on Detection (scanning for malware after a breach) or Signature-Filtering (blocking known exploits), WP Ghost focuses on Architecture. It implements Paths Security and Site Hardening to remove digital footprints that make your site a target for automated botnets. This provides an active foundation for securing your site before it can be identified as a target. [youtube https://youtu.be/QMdoSN8dk1c] WP Ghost Global Stats: Official websites: WP Ghost (wpghost.com) Hide My WP Ghost (hidemywpghost.com) Hide WordPress with Path Security and Reduce Your Attack Surface Hide WordPress paths that attackers commonly scan, including wp-admin, wp-login.php, wp-content, wp-includes, plugin paths, and theme paths. Most WordPress attacks are automated. Bots scan millions of sites per hour looking for default paths like /wp-admin or /wp-login.php to confirm a site is running WordPress. Once confirmed, they launch targeted exploits against known plugin or theme vulnerabilities. WP Ghost breaks this cycle. By changing and securing common paths, you reduce your attack surface by up to 90%. This isn't “obscurity”; it is site hardening. We re-engineer your site's visible structure so it is no longer low-hanging fruit for global botnets. NEW: AI Security Explanations - Your Report, Explained for Your Website Every security plugin hands you a list of red warnings. Almost none of them tell you what those warnings mean for your website. WP Ghost now does. One click sends your findings for analysis based on your site’s actual configuration: server type, rewrite rules status, config file writability, and security mode. It then returns a security report written specifically for you, not for WordPress in general. Requires a WP Ghost subscription, which includes a monthly allowance of AI checks. Everything else on the Security Check page - the scan, the score, the prioritized list, the severity bands, and every task detail - is free and works on its own. What you get back: Built with limits you can check. Only your findings and a small description of your setup are ever sent - no page content, no user data, no credentials. Your security list, your score, the severity bands, and every task detail are generated locally and keep working whether the AI is available or not. NEW: Ghost Doctor - Finds and Repairs a Broken Site by Itself Changing your WordPress paths depends on your server honoring the new rules. When it doesn’t - Nginx never reads .htaccess, Apache ignores it without AllowOverride, a host locks the config file - your site can break, and nothing tells you why. Ghost Doctor diagnoses issues and repairs what a plugin can. It checks your homepage, theme files, editor requests, and REST API the way a visitor would. Then it applies repairs from safest to most invasive. Every repair is tested immediately and automatically undone if it doesn't help, so no settings change unnecessarily. Anything requiring a server change is clearly named with a guide so that you can avoid guesswork. Read the Ghost Doctor troubleshooting guides. Key Protections Included WP Ghost is loaded with advanced defensive mechanisms to protect your site against: Over 115 Free Security Features Included We believe professional security ought to be accessible to everyone. The free version of WP Ghost includes a large collection of tools to harden your WordPress architecture. 1. Change and Secure Paths (Paths Security) 2. WordPress Firewall Protection & WordPress Login Security 3. Deep Hiding & Footprint Removal 4. Advanced Disable Options 5. Brute Force Protection 6. Extra Tools & Integrations Premium Hack-Prevention Features For agencies and high-traffic sites, WP Ghost Premium adds advanced features focused on Security Intelligence, Automated Response, and Copyright Protection. Hide My WP Premium Feature

安装:

From your WordPress Dashboard Step 1. Navigate to Plugins > Add New. Step 2. Search for “WP Ghost”. Step 3. Click Install Now and then Activate. Step 4. Go to the WP Ghost menu in your sidebar. Step 5. Enter your email address to receive your instant Free Access Token. Step 6. Follow the built-in Setup Wizard to begin hardening your paths. Manual Installation Step 1. Download the hide-my-wp.zip file from the WordPress repository or your WP Ghost account. Step 2. Log in to your WordPress dashboard as an Administrator. Step 3. Navigate to Plugins > Add New > Upload Plugin. Step 4. Select the .zip file and click Install Now. Step 5. Click Activate Plugin. Step 6. Connect the plugin using your email address to activate your security features. Reporting a Security Vulnerability Found a security issue in WP Ghost? Report it privately through our Patchstack managed disclosure program at patchstack.com/database/report or email security@hidemywpghost.com. We acknowledge reports within 48 hours and coordinate disclosure within 90 days. Please do not post details in the support forum before we release a fix. The full policy is included in the plugin's SECURITY.md, and third-party components are listed in sbom.json. Support period: We provide security updates for 5 years from each version’s release. Version 7.0.11, released September 2026, is supported until September 2031. Installing a newer release extends the end date. Resources & Guides For advanced server arrangements and detailed walkthroughs, please visit our full documentation: How to Install and Set Up WP Ghost WP Ghost Knowledge Base:

屏幕截图:

  • Admin Security: Change and secure the wp-admin path to block unauthorized dashboard access.
  • Paths Security: Customize and secure your login and registration entry points.
  • Core Security: Harden your system paths (wp-content, uploads, includes) against bot reconnaissance.
  • API & AJAX Security: Secure the REST API and admin-ajax paths to prevent data scraping.
  • 8G Firewall Engine: High-performance, server-edge threat filtering for proactive hack prevention.
  • Brute Force Defense: Integrated Google reCAPTCHA and Math protection for all authentication paths.
  • Modern Authentication: Secure logins with 2FA and future-proof Passkey (Passwordless) support.
  • Text Mapping: Dynamically change class names and IDs in your source code to prevent fingerprinting.
  • URL Mapping: Re-engineer internal URLs and paths for elite-level site hardening.
  • Hardening Tweaks: Deep hide options to remove WordPress version tags and identifiable metadata.
  • Redirect Logic: Custom 404 and role-based redirect options for secured paths.
  • Safe Access: Manage Temporary Logins and Magic Links for secure developer access.
  • Security Threats Log: Activate Security Threats Log to track blocked attacks and malicious requests.
  • Security Threats Log: The list of recent threats prevented by WP Ghost.
  • Overview Dashboard: An overview of the last 7 days of security events.
  • Front-end View: Example of a custom, secured login path (`/newlogin`).
  • Attack Blocked: Default `wp-login.php` now returns a 404 error to confuse hacker bots.
  • Access Denied: Default `wp-admin` path is fully secured and hidden from public view.
  • Source Code Proof: Core WordPress paths transformed and secured to neutralize bot scans.

常见问题:

Does WP Ghost physically move or rename my WordPress files?

No. WP Ghost uses high-performance server rewrite rules (Nginx, Apache, IIS) to change visible paths in your source code. Your actual WordPress files and directories stay exactly where they are, providing no risk to your site’s stability or core updates.

Is WP Ghost a complete standalone solution?

For most WordPress sites, yes. By combining Architectural Hardening with an 8G Firewall and Automated IP Blocking, WP Ghost neutralizes automated reconnaissance and brute-force attempts that account for over 90% of real-world attacks. It delivers a foundational defense often sufficient on its own, while remaining fully compatible with “Defense in Depth” strategies involving malware scanners or file-integrity monitors.

What are AI Security Explanations?

Security scanners tell you what is wrong. AI Security Explanations tell you what it means for your website. WP Ghost sends your findings for analysis along with a short description of your site setup: server type, whether rewrite rules are active, if your config file is writable, and your security mode. It returns a plain-language explanation for each finding, one definite action to take, and a priority order based on what genuinely exposes your site. Open Details on any finding to read the reasoning behind it. Read more on wpghost.com.

What data is sent when I use AI Security Explanations?

Only the findings already on your Security Check page and a small description of your configuration are sent: server type, whether the config file is writable, whether rules are present, if a cache plugin is installed, your security mode, and a count of mapped files. No page content, user data, passwords, or database contents are ever sent. The feature is entirely opt-in; nothing is transmitted until you press the button.

Does WP Ghost still work without the AI?

Completely. The Security Check scan, 0-100 score, prioritized list, severity bands, every task detail, and the entire Ghost Doctor diagnosis and repair process run on your server and need no connection. AI Security Explanations only add wording on top. Using them requires a connected WP Ghost account, an active subscription, and a monthly allowance of checks. The page shows exactly how many you have left.

Is it compatible with other WordPress security plugins?

Yes. WP Ghost is designed as your “Outer Perimeter” defense. It works perfectly alongside malware scanners and reactive security tools like Wordfence, Sucuri, or Solid Security. By implementing Paths Security first, WP Ghost stops bots before they get close enough to be scanned by other plugins.

Will changing my paths affect my SEO or Google rankings?

Not at all. WP Ghost handles Sitemap.xml and Robots.txt mapping automatically. This ensures Google and other search engines can index your content perfectly, while malicious bots receive a 404 error when probing your system paths.

What is the difference between Paths Security and “Security through Obscurity”?

Obscurity is simply hiding a key under a mat. Paths Security is an architectural hardening strategy, like moving the door to a secure, unique location and changing the lock. It is a recognized technical hardening standard used by enterprise-grade sites to prevent Bot Reconnaissance.

Does WP Ghost work on WP Multisite and different server types?

Yes. The plugin is fully compatible with WP Multisite (Network-wide configuration) and supports Apache, Nginx, IIS, and LiteSpeed servers.

How do I configure WP Ghost on an Nginx Server?

WP Ghost fully supports Nginx. Because Nginx does not use .htaccess, you will be guided to add the generated rewrite rules manually to your nginx.conf file. We provide specific tutorials for Kinsta, RunCloud, CloudPanel, CWP7, AAPanel, and Ploi.io.

My theme is not loading correctly after changing paths. What should I do?

This usually happens when the server rewrite rules aren't active yet.

  • Purge Cache: Clear your WordPress cache and any server-side caching (Varnish, Nginx FastCGI).
  • Manual Rewrites: If your server config file is not writable, copy the rules from WP Ghost and add them manually to your .htaccess or nginx.conf.
  • Restart Nginx: If on Nginx, you must reload/restart the service after saving settings.
  • Free Support: If the problem continues, contact us and we will set up the plugin for you for free.

I am locked out or forgot my custom login URL. How do I get back in?

  • Safe URL: Use the “Safe URL” text file automatically generated and downloaded when you saved your settings.
  • Manual Reset: Access your server via FTP/SFTP and rename the folder /wp-content/plugins/hide-my-wp to something else. This temporarily disables the path changes so you can log in via the default wp-login.php.

Does WP Ghost work for WordPress.com websites?

Because of the restricted infrastructure of WordPress.com managed hosting, you can't change administrative and login paths. However, you can still use WP Ghost for Site Hardening, the 8G Firewall, Passkey Authentication, and other Hack Prevention features.

Is the WP Ghost plugin free of charge?

Yes. The Lite version of WP Ghost is always free and includes essential WordPress Security updates. To unlock advanced features like IP Block Automation, Geo-Security, and Cloud Monitoring, you can upgrade to WP Ghost Premium.

How can I hide my site from WordPress Theme Detectors?

By using Paths Security to change common directories (plugins, themes, wp-content), you can successfully neutralize most automated detectors. For a deep dive on total anonymity, read our guide: How to Hide Your Site From WordPress Theme Detectors.

Is this plugin enough to protect my website from all hackers?

WP Ghost provides an elite proactive defense by neutralizing the Reconnaissance phase of an attack. While the Free version blocks most bot traffic, we recommend the Premium version for advanced Brute Force Protection and Automated Danger Intelligence.

How do I change the WordPress paths in the Admin Dashboard area?

By default, WP Ghost only changes paths on the frontend to ensure maximum compatibility. To harden the admin dashboard as well, add define('HMW_ALWAYS_CHANGE_PATHS', true); to your wp-config.php file and re-save your settings.

Does WP Ghost include a security score?

Yes. WP Ghost 7.0 includes a Security Optimization Score from 0 to 100 that shows exactly how hardened your site is. The score updates automatically as you enable features and complete security tasks. It appears on the Overview dashboard and the Security Check page as both a visual gauge and a numeric value.

Can I customize the WordPress login page with WP Ghost?

Yes. WP Ghost includes a Login Page Designer that lets you add your custom logo, background image, and brand colors to your secured login page. It includes 12 layout presets and 10 color scheme presets. The designer works with your custom login URL, so your branded page is served at your hidden path instead of the default wp-login.php.

Does WP Ghost protect my content from AI training bots?

WP Ghost Premium includes an AI Copyright Protection feature that blocks 30+ AI training crawlers, including GPTBot, ClaudeBot, PerplexityBot, CCBot, and Bytespider at the firewall level. It also automatically adds Disallow rules to your robots.txt. This protects your licensed content from being used to train AI models without affecting your regular Google, Bing, or Yahoo search visibility. The crawler list is automatically updated with each plugin release.

更新日志:

7.0.13 (3 Oct 2026) 7.0.12 (29 Sept 2026) 7.0.11 (10 September 2026) 7.0.10 (2 September 2026) 7.0.09 (17 August 2026) 7.0.08 (27 July 2026) 7.0.07 (20 July 2026) 7.0.06 (15 July 2026) 7.0.05 (08 July 2026) 7.0.04 (29 June 2026) 7.0.03 (02 June 2026) 7.0.02 (11 May 2026) 7.0.01 (15 April 2026) 7.0.00 (31 March 2026) Major Release: Security Score, Login Page Designer, Passkey 2FA, Security Threats Log, User Events Log, GEO Threats Map, and expanded 7G/8G Firewall rules. Free update for all users. Firewall & Security Updates: Compatibility: UI & Experience: 5.5.04 (26 Mar 2026) 5.5.02 (10 Feb 2026) 5.5.01 (22 Dec 2025) 5.4.08 (09 Dec 2025) 5.4.07 (29 Sept 2025) 5.4.06 (21 Aug 2025) 5.4.05 (27 May 2025) 5.4.04 (21 Mar 2025) 5.4.03 (11 Mar 2025) 5.4.02 (04 Mar 2025) Security: Ocultar Mi WP - Plugin de seguridad de WordPress Ocultar meu WP - Segurança do WordPress Cacher mon WordPress - Plugin de sécurité WordPress Verstecken Sie mein WordPress - WordPress Sicherheits-Plugin