Linux 软件免费装
Banner图

Nimble Security

开发者 nimbleplugin
更新时间 2026年10月3日 22:08
PHP版本: 8.1 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security firewall malware scanner integrity two-factor

下载

1.1.12 1.1.13 1.2.1 1.2.2

详情介绍:

Nimble Security protects a WordPress site from the login screen down to the files on disk, and it does all of it on your own server. There is no account to create, no cloud service to connect and no data leaving your site. The only outbound request the free version ever makes is to the official WordPress.org checksum API, and only when an integrity scan runs. Everything listed below is in the free version. It is not a trial, nothing here is time-limited, and no engine is held back. Stop attackers at the door Know when your files change Block bad requests Find and contain what got in Know where you stand Security Score rates your posture out of 100 across hardening, identity, integrity, firewall, malware detection, software updates and recovery readiness. An open high or critical incident caps the score, so a site with an active serious problem cannot display a healthy number. What it deliberately does not do Nimble Security does not upload your files, does not phone home, does not write executable code anywhere and does not replace backups. It protects, detects and responds; recovery comes from a backup. That is why recovery readiness counts towards the score, because remediation is far safer when a verified restore point exists.

安装:

  1. Upload and activate Nimble Security.
  2. On a new installation, choose Start Easy Setup or Skip for now.
  3. Easy Setup can apply the recommended local protection profile and start the first checks automatically.
  4. Enroll administrator 2FA when prompted.
  5. Review Identity, Integrity, Firewall, Scanner and Recovery status from Nimble Security > Overview.
Easy Setup never requires a Nimble account or Threat Cloud connection and can be run again later from the Nimble Security menu. If using Nimble Security Pro, install/upgrade Free first, then Pro.

屏幕截图:

  • The same Overview in light mode. Appearance is per-user, so it follows whoever is signed in.
  • Easy Setup applies a recommended local protection profile without asking you to understand every switch first.
  • Identity Protection: brute-force lockouts, two-factor enrolment, sessions and Application Passwords. Credentials and raw IP addresses never leave the site.
  • Integrity Protection verifies WordPress core against the official checksums and keeps SHA-256 baselines for plugins, themes, must-use plugins and drop-ins.
  • The firewall evaluates requests against local high-confidence rules, in Protect, Learning or Off mode.
  • The malware scanner reads files locally and resumes after a timeout. File contents never leave the server.
  • Vulnerability inventory: what is actually installed, so you can judge what is exposed.
  • Diagnostics are read-only. They verify the runtime, storage and security boundaries without changing any configuration.
  • Settings: every engine is configurable, and the defaults are safe on their own.

升级注意事项:

1.2.0
  • Every link and redirect this plugin makes into its own admin screens is now signed, and nothing in the query string is read before that signature has been checked. Previously a wizard step, a selected finding, the file-permission counters and the notice shown after an action were all read straight from the URL, so a link from anywhere could preselect them. The plugin's own screen slug is read from WordPress rather than the query string, since WordPress sets it from the menu it drew.
  • The two places that still read the query string directly are the ones that cannot be signed: the bulk-activation flag WordPress sets on plugins.php, and the ?author= probe on the front end, which is the request being blocked. Both say so where they happen.
1.2.1
  • A device can be remembered, so the second factor is not demanded on every sign-in. The password is still required on a remembered device; only the code is skipped, which is why the cookie on its own opens nothing.
  • Off unless you turn it on, under Settings, Authentication surfaces. A site that updates keeps asking for the code on every sign-in until somebody decides otherwise.
  • Remembered devices are listed under Identity with when each was remembered and last used, and can be removed one at a time or all at once. They are all dropped automatically when the password changes or 2FA is disabled.
  • A remembered device is not tied to an IP address or a browser string. Both change on their own and would cause sign-outs that look like faults.
1.2.0
  • Every link and redirect this plugin makes into its own admin screens is now signed with a nonce, and nothing in the query string is read before that signature has been verified. The wizard step, the selected malware finding, the file-permission counters and the notice shown after an action were previously read straight from the URL, so a link from anywhere could preselect them.
  • The plugin's own screen slug is read from WordPress' $plugin_page rather than from the query string.
  • Security Pro 1.3.1 or newer is required for its automation notice to appear, because that redirect now has to be signed too.
1.1.13 Wording-only fix on the Response page. No behaviour change; safe to update. 1.1.12 Quarantine storage moves into the uploads directory and is migrated automatically. Extended Protection moves to the Pro add-on; if you use it, see the changelog before updating. 1.1.11 Removes the licence client entirely. Every protection engine is unchanged. 1.1.10 Licence screen wording and visibility only. No behaviour change; safe to update. 1.1.9 Wording only on the licence screen. No behaviour change; safe to update. 1.1.8 Documentation and packaging only. No behaviour change; safe to update. 1.1.6 Declares compatibility with WordPress 7.1 and hardens the uninstall queries. No behaviour change; safe to update. 1.1.4 Adds opt-in Smart 404 blocking and file permission auditing. Both are off or report-only until you enable them, so updating changes nothing on its own.

常见问题:

Do I need a licence key or an account?

No. Nimble Security is complete on its own. It contains no licence check, no account requirement and no time limit, and it does not contact NimblePlugins.

Does Free work without Pro?

Yes. Free owns the local identity, integrity, firewall, malware, vulnerability-inventory and manual response engines.

Does a changed plugin file mean malware?

No. Integrity findings are interpreted in context. Known WordPress maintenance can be correlated automatically; unexplained file changes are presented for review rather than being labelled malware by file type alone.

Why can wp-config.php still require review after WordPress is reinstalled?

WordPress normally preserves wp-config.php. Site-specific cron, proxy, database or debug configuration can therefore legitimately differ from a previous baseline. Nimble Security lets an administrator explicitly mark the current recognized configuration as intentional without storing its contents.

Does Nimble Security upload files for malware scanning?

No. The Free malware scanner runs locally.

Can Security delete malware automatically?

Free response is manual-first. Pro contains conservative recovery-gated automation, but destructive actions remain bounded by the Free enforcement and recovery contracts.

Does Nimble Security replace backups?

No. Security protects/detects/responds; backup provides recovery. Recovery readiness is intentionally part of Security Score because remediation is safer when a verified recovery point is available.

更新日志:

1.2.2 1.1.13 1.1.12 1.1.11 1.1.10 1.1.9 1.1.8 1.1.7 1.1.6 1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.0.1 1.0.0