Linux 软件免费装
Banner图

Qevix Shield – 2FA, Hide Login, Firewall, File Security & Malware Scanner

开发者 qevixlabs
更新时间 2026年10月6日 15:53
PHP版本: 7.2 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

recaptcha security two factor authentication firewall malware scanner

下载

1.1.4 1.1.5 1.1.0 1.1.1 1.1.3 1.1.2 1.0.0

详情介绍:

Qevix Shield protects the parts of a WordPress site that attackers commonly target first: the login page, XML-RPC, files, and URLs that can reveal information about your site. It can help stop brute-force attacks, add two-factor authentication and reCAPTCHA, scan files for malware, protect sensitive files, and record blocked activity in a searchable log. Important events can also be sent to administrators by email. Qevix Shield is safe to activate. Activation does not change how your site works. All security protections are off until you enable them, so you can turn them on one at a time and check the result. The activity log starts automatically, but it only records activity and does not change your site. Why Qevix Shield Login Protection Two-Factor Authentication (2FA) reCAPTCHA Password Security XML-RPC Protection Malware Scanner File & Server Security Sessions, Activity Log & Dashboard Qevix Shield Pro Qevix Shield is complete on its own, and all features listed above are free. The optional Pro add-on, sold at qevixlabs.com, adds additional features for what happens after a threat is detected. Learn More Every setting has its own screen with a "?" tip explaining the option. For a full walkthrough, including screenshots, feature comparisons, and common questions, see the plugin's home page: Qevix Shield on qevixlabs.com.

安装:

  1. Upload the qevix-shield folder to /wp-content/plugins/, or install Qevix Shield from the WordPress Plugins screen.
  2. Activate the plugin.
  3. Go to Qevix Shield → Settings.
  4. Turn on the protections you want, one at a time.

屏幕截图:

  • Activity Log showing logins, admin actions, and blocked requests. The log can be searched, filtered, and exported to CSV.
  • Login Protection for limiting failed logins, temporarily blocking IPs, and allowing trusted IPs or CIDR ranges.
  • Hide Login for changing the default `/wp-login.php` URL and choosing what blocked visitors see.
  • When the login is hidden, logged-out visitors who open `/wp-admin/` receive a 404 page instead of a login form.
  • Two-Factor Authentication setup using a QR code and authenticator app.
  • Ten one-time recovery codes that can be downloaded and stored safely.
  • Login challenge requiring the authenticator code or a recovery code after the password.
  • reCAPTCHA settings with v2 checkbox or invisible v3 scoring, including the required key test.
  • reCAPTCHA checkbox displayed on the WordPress login form.
  • Password Security settings for minimum length, character requirements, and password restrictions.
  • Password expiry, password reuse prevention, and forced password reset settings.
  • Malware Scanner for checking WordPress core, plugins, themes, and uploads.
  • Malware scan results showing the severity, file location, and reason for each finding.
  • File Security for blocking access to sensitive files, backups, database dumps, and custom file patterns.
  • Security settings for hiding version information and blocking common SQL injection, XSS, traversal, and other attack patterns.
  • XML-RPC Protection for disabling XML-RPC methods or pingbacks and recording requests.
  • Sessions showing signed-in devices with browser, IP address, and last activity, with the option to end sessions.
  • A list of active user sessions so unfamiliar sessions can be found and ended.
  • Email notification settings for important security events.
  • Optional SMS or WhatsApp alerts through Twilio or the WhatsApp Cloud API.
  • Optional Slack, Discord, or webhook alerts.
  • General settings for roles, activity-log retention, and uninstall behavior.
  • A diagnostic report that removes secrets before being sent to the support team.

升级注意事项:

1.1.5 Security fix: login lockouts and IP whitelists could be bypassed with a fake proxy header. Update recommended. 1.1.4 Compatibility release for WordPress 7.1. No settings, defaults, or protection behavior changed. 1.1.3 Improved readability and accuracy. Activity Log events now use simple English, and several screens were corrected when they showed a protection as active when it could not actually run. No settings changed. 1.1.2 Fixed the Enable 2FA switch. When it is off, enrolled users are no longer asked for a 2FA code. Existing enrolments are kept. 1.1.1 Now supports WordPress 6.5 and PHP 7.2, allowing older WordPress sites to install the plugin. No settings or protection behavior changed. 1.1.0 Redesigned the admin screens. Settings, names, and saved values were kept unchanged; only the way they are displayed was changed. 1.0.0 Initial release.

常见问题:

Is everything really free?

Yes. Every feature listed on this page is available after installation. There is no account, license key, trial, expiry, or locked setting. The optional Pro add-on adds separate features. It does not unlock features that are already included in the free plugin.

Do I need to configure anything after activating?

Only the protections you want to use. Qevix Shield does not change your site when you activate it. Turn on each protection from its settings screen when you are ready. The activity log starts recording activity immediately, but it does not change your site.

Will it slow down my site?

Qevix Shield is designed to be lightweight. With all protections enabled, response times are intended to stay close to the same site without the plugin. Visitors do not need to wait for an external security service.

Will it lock me out of my own site?

Qevix Shield is designed to prevent this. Login rate limits and IP lockouts apply only to failed login attempts and are temporary. You can also add your IP address to the whitelist. Hide Login is off by default. If you enable it, save or bookmark your new login URL. If you do get locked out, you can use the recovery method below.

Does it see the real visitor IP behind Cloudflare, a proxy, or a load balancer?

Yes. Qevix Shield reads the visitor IP from proxy headers such as X-Forwarded-For only when the request comes from a proxy it trusts: Cloudflare, or a proxy on a private or local network address. Headers from anyone else are ignored, so an attacker cannot fake an IP to avoid a lockout or pretend to be on your whitelist. If your site sits behind a different CDN or proxy with public IP addresses, add its addresses or CIDR ranges in a must-use plugin: add_filter( 'qevix_shield_trusted_proxies', function () { return array( '192.0.2.0/24' ); } );

I've locked myself out. How do I recover?

Add this line to wp-config.php: define( 'QEVIX_SHIELD_SAFE_MODE', true ); This temporarily disables Qevix Shield protections without changing your saved settings. You can then log in, fix the problem, and remove the line. This works even when you cannot access the WordPress dashboard because wp-config.php loads before the plugin. One exception: server rules already added to .htaccess or nginx are enforced by the web server. If necessary, remove or disable those rules manually.

Does it work with WooCommerce and plugins that have their own login pages?

Yes. WooCommerce, membership plugins, LMS plugins, and page-builder login widgets can continue to use their own login pages. Hide Login only changes the standard WordPress login URL, so these separate login pages can continue to work.

I use the Pro add-on. Do the versions need to match?

No. The free plugin and Pro add-on have separate version numbers. They are released as a pair, but their version numbers may be different. Keeping both updated is recommended. If the versions become too different, Pro will show a notice telling you which one needs to be updated.

更新日志:

1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.1.0 1.0.0