Linux 软件免费装

JR Security Hardening and Login Protection

开发者 reinajhon46
更新时间 2026年5月21日 10:15
PHP版本: 7.4 及以上
WordPress版本: 6.9
版权: GPLv2 or later
版权网址: 版权信息

标签

security login protection hardening

下载

1.0.0

详情介绍:

JR Security Hardening and Login Protection secures your WordPress installation at the application level with one-click hardening modules. Designed to be secure by default and Cloudflare compatible. Included modules: Smart IP detection: Clean uninstall: When the plugin is deleted, all options, the events table and transients are removed. No data is left behind in your database.

安装:

  1. Upload the jr-security-hardening-login-protection folder to /wp-content/plugins/.
  2. Activate the plugin from the WordPress "Plugins" menu.
  3. Go to Settings → JR Security and configure the modules.
  4. For full static file protection, apply the server rules shown in the "Server" tab.

升级注意事项:

1.0.0 First release available on WordPress.org.

常见问题:

Does this plugin replace a server-level firewall?

No. This plugin protects what goes through WordPress. For static files like /readme.html, you need server-level rules (Apache/Nginx). The plugin includes those rules ready to copy and paste in the "Server" tab.

Does it work with Cloudflare?

Yes. It automatically detects the visitor's real IP via CF-Connecting-IP. If you use another proxy, you can enable "Trust proxy headers" in the settings.

What if I lock myself out?

Lockouts use WordPress transients and expire automatically based on the configured hours. You can also add your IP to the whitelist from settings, or temporarily deactivate the plugin via FTP/SSH by renaming the folder.

Can I use this plugin with other security plugins?

Yes, but avoid duplicating functionality. If another plugin already disables XML-RPC or adds headers, disable those modules here to avoid conflicts.

Are settings lost when deactivating the plugin?

No. Settings are preserved when deactivating. They are only deleted when uninstalling the plugin completely.

Why is ?author= enumeration not blocked?

If you are logged in as an administrator, the plugin does NOT block the author page — this is normal behavior. To test, use an incognito window without a WordPress session.

更新日志:

1.0.0