Linux 软件免费装
Banner图

Karetaker

开发者 krikir
更新时间 2026年9月20日 05:39
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security activity log monitoring hardening file integrity

下载

0.1.3 1.0.1 1.0.0 0.1.1 1.1.1 1.1.2

详情介绍:

Karetaker is a watchtower, not a wall. Most security plugins either shout at you all day or quietly lock you out of your own site. Karetaker does neither. It watches the handful of changes that actually mean something went wrong, keeps a readable record, and emails you only when a human needs to act. What it watches One-checkbox catastrophes The quiet business killers that no scanner reports, because technically nothing is "hacked": Opt-in hardening, with receipts A small set of hardening toggles, every one of them off until you turn it on, and every one reversible from Karetaker → Protection. Each toggle shows Desired next to Live now, so you always see what is actually in effect rather than what was merely requested. How it reaches you Who it is for It is deliberately not Kill switch Define KARETAKER_DISABLE as true in wp-config.php, or place an empty file at wp-content/karetaker-disable. The plugin then boots nothing. Uninstall removes the plugin's table, options, and scheduled hooks. Open source Karetaker is GPL, built by Team Krikir. It does not phone home, load third-party scripts, or show ads. Issues and pull requests are welcome. Credits Karetaker ships no third-party code, fonts or images. It relies on these projects and services, and thanks them: WordPress is a registered trademark of the WordPress Foundation. Microsoft and Microsoft Teams are trademarks of the Microsoft group of companies. Slack is a trademark of Slack Technologies, LLC. Discord is a trademark of Discord Inc. Google and Googlebot are trademarks of Google LLC. Telegram and all other trademarks are the property of their respective owners. Karetaker is an independent project by Team Krikir. It is not created, endorsed, sponsored or certified by any of these companies; their names are used only to describe the services Karetaker can connect to.

安装:

  1. Upload the karetaker folder to /wp-content/plugins/, or install the zip via Plugins → Add New → Upload.
  2. Activate through the Plugins screen.
  3. Open Karetaker in the admin sidebar. The one-minute setup asks where alerts go and what kind of site this is, runs a first check, and offers three safe protections.

屏幕截图:

  • Home when there is nothing urgent: worth a look, but it can wait.
  • Home on a quiet week, because staying silent is the point.
  • Activity: everything Karetaker recorded, grouped by day and written in plain words.
  • Protection: optional protections you can switch on or off. None of them can lock you out.
  • Settings: where alerts go, the weekly summary, a one-hour pause, site type, and privacy and data options.
  • The one-minute setup that runs on first activation.

升级注意事项:

1.1.2 Fixes repeated alerts for uploads config files that had not changed. Worth updating if you have seen the same alert more than once. 1.1.1 Small developer update. No visible changes. 1.1.0 Advanced mode is removed. Every check, alert and protection stays; Settings gains privacy and data options. 1.0.2 Maintenance release with extension hooks for developers. No visible changes. 1.0.1 Clearer, better-looking alert and summary emails. 1.0.0 First public release.

常见问题:

Is this a firewall?

No. Karetaker watches and alerts. It does not filter HTTP traffic.

Will it lock me out of wp-login?

Not by default. There is no login lockout or renamed login URL in the default set. Hardening toggles are opt-in and reversible from Karetaker → Protection.

How do I stop it immediately?

Define KARETAKER_DISABLE as true in wp-config.php, or create wp-content/karetaker-disable. The plugin then boots nothing.

What happened to Advanced mode?

Agency tools (issue tracking with owners, incident cases, client reports, role access and the read-only API) are no longer part of Karetaker. Everything that watches your site, alerts you and protects it stays here and stays free: every check, every alert channel, the weekly summary, all protections and the activity export.

Does uninstall leave data behind?

No. Uninstall drops the events table, plugin options, and cron hooks.

What if I think the site was hacked?

Run wp karetaker incident. That runs a deeper multi-pass scan and shows a checklist (admins, plugins, uploads PHP, integrity, Guard, passwords). If you think someone else is logged in, use Karetaker → Protection → "Sign out all administrators". Karetaker does not clean malware or lock anyone out; it is a guided review, not a clean certificate.

Can hosting providers use this?

Yes. Karetaker does not ship a WAF, does not lock logins by default, and does not write server config. wp karetaker status prints the host safety profile as JSON, and Site Health reports scan freshness, Guard flags, and the same profile. Kill switch: KARETAKER_DISABLE or wp-content/karetaker-disable.

What data leaves the site?

By default, only integrity checks contact WordPress.org to fetch published core/plugin checksums (same family of APIs WordPress itself uses). Optional features you turn on yourself may also leave the site: ACT alert emails (to the address you choose), an ACT webhook POST (to the URL you set), Slack Incoming Webhooks, Telegram Bot API, Discord and Microsoft Teams webhook messages (when enabled), the weekly summary and end-of-pause emails (when enabled), and vulnerability lookup requests to wpvulnerability.net (plugin slug only, when enabled under Settings). The daily "What Google sees" check requests your own home page twice (once with a Googlebot user agent); it does not contact Google. Karetaker does not phone home to Team Krikir and does not load third-party scripts or ads. When you enable those optional services, you also accept their terms:

更新日志:

1.1.2 1.1.1 1.1.0 1.0.2 1.0.1 1.0.0 First public release.