| 开发者 | bestseogr |
|---|---|
| 更新时间 | 2026年9月25日 17:38 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
auto_prepend_file, and it does not make a remote decision call while serving a visitor request. Nexus PRO remains the earlier pre-WordPress protection tier through its Early WAF architecture.
Database Threat Scan
When enabled, scheduled malware scans also inspect bounded high-risk database content. Watchdog checks selected options plus rotating batches of posts and post metadata for high-confidence malicious code, hidden redirects, obfuscated JavaScript and persistence indicators.
Large content tables are scanned incrementally rather than swept in one expensive pass.
Security you can understand
Watchdog Lite does more than display raw logs.
Security & Exposure Check reviews practical configuration and attack-surface signals, while Attack Stories groups related Traffic Shield and Login Guard events into a readable sequence. The goal is to help site owners understand what Watchdog actually observed and what it actually restricted.
Watchdog does not invent attack events for visual effect.
WooCommerce-aware protection
WooCommerce stores receive cart, wishlist, checkout, AJAX, crawler and catalog traffic that should not all be treated the same way.
Watchdog Lite includes store-aware request protection and WooCommerce Bot Cart Guard Lite, which can neutralize supported cart and wishlist mutations from crawler-claimed or obvious automation while leaving public pages available.
Watchdog Lite and Nexus PRO
Watchdog Lite provides a strong free security foundation inside WordPress.
The dashboard also includes a Protection Horizon that shows where Lite protection ends and what Lumiverse Nexus PRO adds for sites that need more:
Watchdog Lite is designed to keep heavy work away from normal visitor requests wherever possible. Scanning, reporting and network work are separated from the normal page-delivery path where practical.
It is a fast local review of Watchdog protection plus practical WordPress attack-surface signals, such as risky public artifacts, PHP files in upload-like locations and selected configuration choices that may deserve review. It reports what it can verify locally and avoids claiming that a file or feature is publicly exploitable when server-level access cannot be confirmed.
Attack Stories group related Traffic Shield and Login Guard activity from the same source into a readable sequence. They are built from real events already recorded by Watchdog Lite and do not generate simulated attacks.
No. Exploit Shield Lite runs inside the normal WordPress plugin lifecycle and does not modify auto_prepend_file. Nexus PRO uses its separate Early WAF architecture for earlier pre-WordPress request containment.
No. It inspects selected high-risk options and bounded rotating batches of content tables so large WordPress and WooCommerce databases are covered over time without a full-table sweep on every scheduled scan.
No. TOTP 2FA is optional and configured separately by each administrator.
Threat Intelligence Lite is disabled by default. When enabled, the participating site URL/domain is registered with the authenticated contributor identity. Selected verified security signals may include an attacking public IP address and limited security metadata. Aggregate telemetry contains event counts and contributor/site attribution. Passwords, cookies, form contents, customer/order data and page content are not shared through Threat Network participation.
No. Routine file and enabled database threat scanning is performed locally.
Yes. Malware scanning can include the WordPress MU-plugin directory, and Live Watch can monitor it when enabled.
No. Lite Safe Core Repair restores only verified WordPress core files represented in the official checksum set. It excludes wp-content, wp-config.php and server configuration files, and creates a protected restore point first.
It is a lightweight visual view of real activity already observed by Watchdog Lite, including recent requests, bots and protection events. It does not generate simulated attack events.
Yes. It includes store-aware traffic protection and optional bot cart-action neutralization. Nexus PRO adds broader WooCommerce resource-defense, adaptive protection and investigation layers for higher-pressure business stores.