Linux 软件免费装
Banner图

Init Content Protector – Anti-Copy, Anti-Scrape, Encrypt-All

开发者 brokensmile.2103
更新时间 2026年9月26日 22:13
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

content protection copy protection encryption anti-copy anti-scraping

下载

1.4 1.5 1.6 1.7 1.0 1.1 1.2 1.3 1.3.1

详情介绍:

Init Content Protector is a powerful yet lightweight plugin that safeguards your post content from unauthorized copying, scraping tools, and inspection via browser developer tools. This plugin is part of the Init Plugin Suite — a collection of minimalist, fast, and developer-focused tools for WordPress. GitHub repository: https://github.com/brokensmile2103/init-content-protector Features:

安装:

  1. Upload the plugin files to the /wp-content/plugins/init-content-protector directory, or install via the WordPress plugin screen.
  2. Activate the plugin through the 'Plugins' menu in WordPress.
  3. Go to Settings → Init Content Protector and configure your preferred options.

常见问题:

Will this affect SEO?

If you enable full content encryption, search engines will not be able to see the content. Only use this option if SEO visibility is not required.

Does this plugin support custom post types?

Yes. You can choose which post types are protected in the settings page.

Can I use my own encryption key?

Yes. You can set a custom key per site for added security.

What's the difference between "Inline" and "Enhanced" key delivery?

Inline embeds the decryption key directly in page HTML — simple and works everywhere, but readable via view-source. Enhanced fetches the key from a REST API endpoint after page load instead, keeping it out of cached/static HTML and working cleanly with full-page cache plugins. Neither mode makes content truly secret from a visitor running the page's own JavaScript — both are meant to raise the bar for casual scrapers, not stop a determined human.

Is the "Enhanced" REST API endpoint rate-limited?

No, intentionally. Rate-limiting by visitor IP would mean storing one database row per unique IP with no automatic cleanup — on a busy or bot-scanned site that bloats the database worse than the scraping it aims to prevent. If you need rate limiting, apply it at your server, CDN, or WAF layer.

Does this work with AMP?

The plugin automatically detects AMP endpoints and skips all protection there (JS injection, encryption, noise), since AMP doesn't allow the custom scripts these features rely on.

Can I control how much noise is injected?

Yes, via the "Noise Injection Rate" setting (1–50% per word, default 7%). Noise is only ever inserted into plain text — never inside HTML tags or inside elements like <script>, <style>, <select>, or <svg> — so it can't corrupt markup.

What's the difference between "Enable JavaScript Content Protection" and the new "Advanced DevTools Blocking" / "Anti-Screenshot Protection" options?

"Enable JavaScript Content Protection" is the plugin's original, lightweight protection: it blocks common keyboard shortcuts, right-click, text selection, and printing. "Advanced DevTools Blocking" adds a dedicated third-party detection library (disable-devtool) that recognizes DevTools being opened through several different methods beyond keyboard shortcuts, and reacts by closing or redirecting the tab. "Anti-Screenshot Protection" (Init AntiSnap) is a separate heuristic that watches for scroll-jump and layout-shift patterns typical of automated screenshot/scraping tools and briefly blurs the page instead. All three are independent — enable any combination that fits your site.

Will Advanced DevTools Blocking or Anti-Screenshot Protection ever affect real visitors?

They're designed not to, but both are heuristic and best-effort like every other protection layer in this plugin. Advanced DevTools Blocking only reacts when it detects an open DevTools panel; Anti-Screenshot Protection only reacts to repeated, evenly spaced scroll steps made without any real input from the visitor, or DevTools-style viewport changes, and its blur effect clears itself automatically after a few seconds or as soon as the tab regains focus. Neither is enabled by default.

What does Headless Browser Detection do, and when should I use it?

It's aimed at automated scraping tools built on Puppeteer, Playwright, or Selenium — the kind that run a real browser engine and read the DOM after your page renders, which the plugin's other protections (encryption, noise, keyword cloaking) can't stop on their own once the page is decrypted for them too. When enabled, it scores several client-side automation signals together (no single signal decides on its own) and, if the session looks automated, simply never triggers decryption — the content stays on its loading skeleton instead of appearing in the DOM. It only takes effect when Content Protection Mode is set to Encrypt, and it's off by default. Like every automation signal, well-configured "stealth" tooling can evade individual checks — this raises the cost of scraping, it doesn't guarantee blocking it.

Does Encrypt mode still need CryptoJS?

Not on HTTPS sites. Since 1.7 decryption uses the browser's built-in Web Crypto API, which is much faster and adds no extra download. The bundled CryptoJS file (about 60 KB) is only loaded on sites not served over HTTPS (where browsers disable Web Crypto), or on demand in the rare browser without Web Crypto support. Developers can force it either way with the init_plugin_suite_content_protector_load_cryptojs filter.

My theme or reader app scrolls the page by itself. Will Anti-Screenshot Protection react?

Init AntiSnap 6.0 only reacts to repeated, equally sized scroll steps made by script while the visitor is not touching the page. If your own code does that (an automatic page-turn feature, for example), call InitAntiSnap.trust(ms) before scrolling, or InitAntiSnap.pause() / InitAntiSnap.resume() around it.

更新日志:

1.7 – September 26, 2026 1.6 – August 28, 2026 1.5 – August 28, 2026 1.4 – July 20, 2026 1.3 – November 15, 2025 1.2 – November 14, 2025 1.1 – August 16, 2025 1.0 – July 23, 2025