Linux 软件免费装
Banner图

Rapid Security Manager

开发者 rapidplugins
更新时间 2026年9月18日 20:34
PHP版本: 8.1 及以上
WordPress版本: 7.1
版权: GPL-2.0-or-later
版权网址: 版权信息

标签

security geoip firewall csp two-factor

下载

1.1.6 1.1.9

详情介绍:

Rapid Security Manager is a local-first WordPress security plugin with a source-aware Web Application Firewall, encrypted TOTP two-factor authentication, structured Content Security Policy, security headers, WordPress hardening, local WAF and CSP logs, optional local GeoIP enrichment, and diagnostics. No Rapid Security Manager account or online security service is required. Security events and uploaded GeoIP data remain on the WordPress installation. Rapid Security Manager does not include telemetry, does not send logs to the developer, does not bundle a GeoIP database, and does not use an online GeoIP lookup API. The Free plugin owns the shared request engine and WAF event handling used by compatible add-ons. Optional hourly CSP Log email notifications use a shared Free/Core mail service and one Rapid Security Manager WordPress Cron task. The Diagnostics page performs no external HTTP self-tests and does not automatically change security settings. Current Free features include: Rapid Security Manager does not replace or modify WordPress 7.1 Document-Isolation-Policy headers on editor screens.

安装:

  1. Upload the rapid-security-manager folder to /wp-content/plugins/, or install Rapid Security Manager through the WordPress Plugins screen.
  2. Activate Rapid Security Manager from the Plugins screen. On multisite, use Network Activate only when the same Free/Core protection should be available across the network.
  3. Open Rapid Security Manager > Diagnostics and review the detected environment and registered modules.
  4. Configure Network & GeoIP before trusting proxy-provided client IP headers. Leave trusted proxy detection disabled unless the site is actually behind a supported proxy or explicitly configured proxy range.
  5. Start the WAF in Log Only mode, review legitimate traffic, and switch to Enforce only after the enabled rules have been tested on the site.
  6. Build the CSP gradually in Report Only mode before enabling enforcement.
  7. Users can enable TOTP two-factor authentication from their WordPress profile and should store their one-time recovery codes safely.
  8. Optionally upload a current DB-IP Lite Country MMDB file on Network & GeoIP for local country enrichment.

屏幕截图:

  • Network & GeoIP.
  • Security Headers
  • Content Security Policy.
  • Web Application Firewall.

常见问题:

Does Rapid Security Manager require an account or license key?

No. Rapid Security Manager Free works without registration, a Rapid Security Manager account, or a license key.

Does Rapid Security Manager send telemetry, logs, visitor data, or site content to the developer?

No. Rapid Security Manager does not include telemetry and does not send WAF logs, CSP logs, visitor IP addresses, site content, credentials, cookies, or two-factor secrets to the developer.

When does Rapid Security Manager contact Cloudflare?

Only when both trusted proxy detection and Cloudflare support are enabled. A scheduled request then refreshes Cloudflare's published proxy IP ranges. Normal security requests never perform an online Cloudflare lookup. See the External services section for the exact endpoints and transmitted data.

Is a GeoIP database bundled with the plugin?

No. An administrator may separately obtain and upload a DB-IP Lite Country MMDB database. Lookups are performed locally, and the uploaded database remains subject to DB-IP's license and attribution terms.

Where are WAF and CSP logs stored?

They are stored in bounded custom tables in the site's WordPress database. Depending on the log, records can include an IP address, a bounded User-Agent, request or document metadata, rule information and short evidence labels. Observation-only WAF thresholds use a separate table of automatically expiring keyed-hash counters; account names and raw request paths are not stored in that counter table. WAF targets retain the path and query after pre-storage redaction, up to 16 KiB. Optional payload recording is disabled by default and records only the original triggered field, not an entire HTTP request. Known password fields, tokens, authorization values and session/cookie data are masked regardless of whether the user exists or authentication succeeds; opaque raw bodies are omitted. CSP URL query strings and fragments remain excluded. Payload recording and the Payload display column are separate settings. Turning recording off does not delete already retained samples. Every grouped row represents the latest event/sample in that group, not a per-request history. Historical query strings and payloads that were not recorded cannot be reconstructed. Samples may still contain personal data or unrecognized custom secrets: enable recording only when needed, review your test inputs and privacy notices, and keep an appropriate retention period. Truncated and unavailable samples are explicitly labelled.

Is Rapid Security Manager Pro required?

No. All features described as Free work independently. Rapid Security Manager Pro is a separately installed add-on that extends the shared Free/Core services with additional controls and analysis.

Can Rapid Security Manager Free download or install Rapid Security Manager Pro?

No. The Free plugin contains only an informational Upgrade to Pro page. It does not download, install, activate, update, or execute Pro packages. Those operations belong to the separately installed Pro add-on.

Does Rapid Security Manager automatically import data from a plugin with a different slug?

No. Rapid Security Manager uses only its own final identifiers and starts as an independent installation. It does not read, rename, delete or import settings, logs, two-factor metadata, uploaded GeoIP files or other data owned by a differently named plugin.

What happens when Rapid Security Manager Free is uninstalled?

The uninstall routine removes Free/Core settings, scheduled tasks, transients, custom WAF and CSP tables, uploaded DB-IP files, Rapid Security Manager-managed Apache/LiteSpeed marker blocks, and Free/Core two-factor user metadata. Data owned by a separately installed compatible add-on is not removed by the Free plugin.

更新日志:

1.1.9 1.1.8 1.1.7 1.1.6 1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.1.0 1.0.9 1.0.8 1.0.7 1.0.6 1.0.5 1.0.4 1.0.3 1.0.2 1.0.1 1.0.0 0.10.14 0.10.13 0.10.12 0.10.11 0.10.10 0.10.9 0.10.8 0.10.7 0.10.6 0.10.5 0.10.4 0.10.3 0.10.2 0.10.1 0.10.0 0.9.9 0.9.8 0.9.7 0.9.6 0.9.5 0.9.4 0.9.3 0.9.2 0.9.1 0.9.0 0.8.9 0.8.8 0.8.7 0.8.6 0.8.5 0.8.4 0.8.3 0.8.2 0.8.1 0.8.0 0.7.9 0.7.5 0.7.4 0.7.3 0.7.2 0.7.1 0.7.0 0.6.0 0.5.0 0.4.1 0.4.0 0.3.5 0.3.4 0.3.3 0.3.2 0.3.1 0.2.0 0.1.1 0.1.0