Linux 软件免费装
Banner图

CMS ADMINS Security Check Report

开发者 contexlabs
更新时间 2026年9月5日 07:15
捐献地址: 去捐款
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security malware vulnerability scanner audit

下载

2.2.1 2.2.2

详情介绍:

The CMS ADMINS Security Check Report plugin performs a comprehensive series of security checks on your WordPress site. It evaluates different aspects of security using a weighted scoring system and provides clear recommendations for improvements. Key Features: Security Tests Include: Risk Grading System: | Grade | Risk Level | Description | |-------|------------|-------------| | A | Excellent | Very well protected | | B | Good | Good protection with minor improvements possible | | C | Moderate | Several improvements recommended | | D | Poor | Significant security risks detected | | F | Critical | Immediate action required | Disclaimer: Please note that CMS ADMINS does not take any responsibility for any damages to the system/server and does not guarantee the accuracy of the results. Users are advised to take appropriate precautions and backup their site before making any changes based on the plugin's recommendations.

安装:

  1. Upload the plugin files to the /wp-content/plugins/security-check-report directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the 'Plugins' screen in WordPress.
  3. Navigate to 'Tools' -> 'Security Check Report' to view the security check results.

屏幕截图:

  • **Results Table:** Detailed test results with color-coded scores
  • **Documentation:** Searchable accordion with test explanations

升级注意事项:

2.2.1 First release on WordPress.org. The Spamhaus IP blacklist test has been removed, no data is sent to third parties other than the WordPress.org API anymore. 2.2.0 Major UI overhaul with redesigned interface, searchable documentation, and improved visual consistency. All test descriptions have been rewritten for clarity. 2.1.0 New weighted scoring system with A-F grades ensures critical issues properly impact your risk assessment. Several test methods have been fixed and new tests added. 2.0.0 Major security and architecture update. Important security fixes - please update immediately. Now requires PHP 8.2+.

常见问题:

What security checks does this plugin perform?

The plugin performs 45 security checks across four categories: Critical Category:

  1. Malware Check - Scans for malware signatures in WordPress files
  2. PHP Execution in Uploads - Checks if PHP can execute in uploads directory
  3. Weak Password Users - Detects users with common weak passwords
  4. Two-Factor Authentication - Checks for 2FA plugin presence
  5. Admin Username - Detects insecure "admin" username
  6. Database User Privileges - Analyzes database permissions
  7. wp-config.php - Validates configuration file security
  8. Unallowed Files - Scans uploads for dangerous file types High Category:
  9. WordPress Version - Checks if WordPress is up to date
  10. Outdated Plugins - Identifies plugins needing updates
  11. SSL Enabled - Verifies HTTPS configuration
  12. File Editing - Checks if admin file editing is disabled
  13. Brute-Force Protection - Detects protection plugins
  14. Automatic Core Updates - Verifies auto-update settings
  15. PHP Version - Checks PHP version currency
  16. PHP Version Support - Verifies PHP is still supported
  17. Security Keys and Salts - Validates wp-config security keys
Medium Category: 18. Server Headers - Analyzes security headers 19. Directory Permissions - Checks folder permissions 20. Uploads Permissions - Verifies uploads directory security 21. WP_DEBUG Mode - Detects debug mode status 22. Password Policy - Checks for password policy plugins 23. Login Attempts Limiting - Detects rate limiting 24. User Enumeration - Tests for user enumeration protection 25. Outdated Themes - Identifies themes needing updates 26. Outdated Libraries - Checks for vulnerable libraries Low Category: 27. Database Prefix - Checks for custom table prefix 28. XML-RPC Interface - Detects XML-RPC exposure 29. REST API - Analyzes REST API configuration 30. Windows Live Writer - Checks for legacy meta tags 31. Deactivated Plugins - Lists inactive plugins 32. .htaccess File - Verifies htaccess presence 33. Directory Indexing - Tests for index exposure 34. Unwanted Files in Root - Scans for leftover files 35. Other WordPress Installations - Detects multiple installs Plus additional tests for PHP version in headers, file change detection, configuration backups, and more. Note: For SSL/TLS vulnerability testing (Heartbleed, POODLE, DROWN), we recommend using external tools like SSL Labs.

How does the weighted scoring system work?

Tests are assigned to categories based on their security impact:

  • Critical tests (weight 3.0x): Authentication, malware, code execution
  • High tests (weight 2.0x): Updates, SSL, important configurations
  • Medium tests (weight 1.5x): Headers, permissions, policies
  • Low tests (weight 1.0x): Best practices, cosmetic issues A single critical failure will significantly impact your grade, ensuring serious issues are never hidden by passing minor tests.

How often should I run the plugin?

It is recommended to run the plugin regularly, especially after updates or changes to your site. Monthly scans are a good baseline, with additional scans after major changes.

What should I do if the plugin reports a security risk?

Follow the plugin's recommendations to mitigate the security risk. Each test includes detailed documentation explaining what was checked, why it matters, and specific steps to resolve issues.

更新日志:

2.2.2 2.2.1 2.2.0 2.1.0 2.0.0 1.1.5 1.1.4 1.1.3 1.1.2 1.1.1 1.1 1.0