Linux 软件免费装
Banner图

IGW Security History

开发者 crishnakh
更新时间 2026年9月11日 05:17
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security vulnerabilities plugin security vulnerability scanner security history

下载

0.1.0

详情介绍:

IGW Security History provides information about the security history of the plugins installed on your WordPress site. The plugin builds a local inventory of installed plugins and combines this information with known vulnerability data. For each plugin, it can show: This makes it possible to distinguish between a plugin that has had security issues in the past and a plugin whose currently installed version is actually affected by a known vulnerability. For example, a plugin may have dozens of historical vulnerabilities while its current version has no known vulnerabilities affecting it. Plugin inventory IGW Security History maintains a local inventory containing information about the plugins detected on the WordPress installation. The inventory includes information such as the plugin slug, main file, installed version, activation status, detected source and the dates when the plugin was first and last detected. This information is stored in custom WordPress database tables. WordPress.org availability The plugin checks whether installed plugins are currently available from the official WordPress.org plugin directory. It can distinguish between plugins found on WordPress.org and plugins detected as commercial or external. A plugin not currently found on WordPress.org is reported as unavailable. This does not necessarily mean that the plugin was removed from the directory, since it may be a commercial, private or custom plugin that was never hosted there. Vulnerability history IGW Security History retrieves a summarized vulnerability history for detected plugins. The information includes: Historical vulnerability information does not mean that the currently installed version is vulnerable. Installed version check In addition to the historical information, IGW Security History compares the currently installed plugin version against the affected version ranges contained in the vulnerability database. This allows the plugin to report separately whether known vulnerabilities affect the version currently running on the site. When no matching vulnerability is found, the plugin reports that there are no known vulnerabilities affecting that version according to the currently available vulnerability data. Detailed security history Each detected plugin can be reviewed individually from the IGW Security History administration screen. The detailed view provides a complete overview of the known vulnerability history for that plugin, including: The vulnerability timeline provides a visual representation of the plugin's security history over time. Each point represents a known vulnerability and its position indicates its publication date and severity. Points can be selected to navigate directly to the corresponding vulnerability information. When an installed version is being evaluated, the detailed view distinguishes vulnerabilities that affect that specific version from vulnerabilities that only form part of the plugin's historical record. Plugins screen integration Security information is also displayed directly on the standard WordPress Plugins screen. Depending on the available information, IGW Security History can display: A security history link provides access to the detailed plugin information directly from the Plugins screen. The detailed security history can be displayed in a modal window without leaving the standard WordPress Plugins screen. Manual updates The administration screen provides controls to refresh the plugin inventory and vulnerability information. Vulnerability checks are performed in batches to reduce the number of external requests.

安装:

  1. Upload the igw-security-history folder to the /wp-content/plugins/ directory, or install the plugin through the WordPress Plugins screen.
  2. Activate IGW Security History from the Plugins screen.
  3. Open the IGW Security History administration screen.
  4. Run the plugin analysis to build the local plugin inventory.
  5. Update the vulnerability information to retrieve the current security history.
No external account or API key is required.

屏幕截图:

  • Detailed security history for an individual plugin, including vulnerability summaries, installed-version status and the chronological vulnerability timeline.
  • Security and vulnerability information integrated into the standard WordPress Plugins screen.
  • Detailed plugin security history displayed in a modal window directly from the standard WordPress Plugins screen.

常见问题:

Does having historical vulnerabilities mean that my installed plugin is vulnerable?

No. IGW Security History separates the historical vulnerability count from vulnerabilities known to affect the version currently installed on your site. A plugin can have many historical vulnerabilities while the currently installed version is not affected by any of them.

What information is sent to the IGW API?

Vulnerability checks may send plugin slugs and installed plugin versions. This information is required to identify the plugin and compare its installed version with known affected version ranges.

Do I need a Wordfence API key?

No. The WordPress plugin communicates with the IGW API. It does not communicate directly with the Wordfence Intelligence API and does not require a Wordfence API key.

Does the plugin guarantee that my plugins are secure?

No. IGW Security History reports known vulnerability information available to its data source. The absence of a known vulnerability does not guarantee that a plugin is free from security issues. The plugin is intended to provide additional security information and should not replace regular updates, backups and other WordPress security practices.

What does "Not available on WordPress.org" mean?

It means that the plugin was not found in the WordPress.org plugin directory during the most recent check. This does not necessarily mean that WordPress.org removed the plugin. Commercial, private and custom plugins may never have been published in the directory.

Are vulnerability checks performed automatically?

The current version provides manual controls for refreshing plugin and vulnerability information from the administration screen.

What happens to the stored information when the plugin is uninstalled?

IGW Security History deletes its stored data when the plugin is uninstalled.

更新日志:

0.1.0