Linux 软件免费装
Banner图

Securizer

开发者 wppodrska
更新时间 2026年9月16日 07:22
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security login brute force integrity hardening

下载

1.0.4

详情介绍:

Securizer is a lightweight WordPress security and diagnostics plugin focused on local protection, verification and reporting. It provides login protection, hardening, core integrity, Safe Repair, diagnostics and account hygiene without a Securizer cloud service. Read-only checks do not repair files. Disruptive actions require administrator confirmation; safety-sensitive workflows use verification and rollback. Login Protection Safe Login URL Securizer can provide a custom login path and hide normal anonymous access to wp-login.php and wp-admin. The new route is verified before the default route is hidden, and the previous configuration is restored if verification fails. An emergency recovery constant is available if access problems occur. WordPress Hardening Hardening controls cover XML-RPC and pingbacks, generator exposure, author enumeration, REST API user exposure, the file editor, Application Passwords, security headers, directory listing and public access to PHP-like files inside uploads. Potentially incompatible server-level changes are not forced automatically. Core Integrity and Safe Repair Core Integrity compares WordPress core files with official checksums and identifies modified files, missing official files and unexpected files inside wp-admin and wp-includes. Scanning is read-only. For selected modified or missing files, Safe Repair downloads the matching official WordPress package, reads only selected files into memory, verifies checksums, writes them through the WordPress Filesystem API and scans again. Pre-repair contents remain in memory for rollback if verification fails. Unexpected files are reported and not deleted. Diagnostics and Safe File Protection Diagnostics checks security configuration, public exposure, HTTPS/SSL behavior, headers, file/directory protection and WordPress configuration. Some checks request the site's public URLs to verify effective behavior. Safe File Protection can verify directory listing and denial of PHP-like requests in uploads. Its uploads test requests a randomized, non-existent PHP-like URL and creates no probe file. Where supported, Securizer can apply its own marked rules, verify the result immediately and roll back a newly applied rule when it cannot confirm a safe and effective change. Account Hygiene, Salts and Logs Account Hygiene reviews administrator usernames, active sessions and Application Passwords, and includes a controlled administrator login-name change workflow. Securizer also audits the eight WordPress authentication keys and salts without displaying or storing their values; explicit rotation includes verification and rollback. Security events are stored locally and can include IP address, attempted username, event type, timestamp and limited event context. Passwords and authentication secrets are never logged. Logs can be reviewed in WordPress administration and exported as CSV. What Securizer is not Securizer is not a WAF, cloud malware scanner or vulnerability-intelligence service. It does not replace secure hosting, backups, updates or a dedicated firewall where required.

安装:

  1. Install Securizer through the WordPress plugin installer or upload the plugin ZIP.
  2. Activate Securizer.
  3. Open Securizer from the WordPress administration menu.
  4. Review the initial Diagnostics and Core Integrity baseline.
  5. Review Login Protection and Hardening settings and adjust them if needed.
A new installation stores conservative defaults and schedules a read-only Diagnostics and Core Integrity baseline. It does not repair files, rotate authentication salts, change the login URL or apply server-level file-protection rules.

屏幕截图:

  • Login Protection with IP handling, targeted-account monitoring, active lockouts and Safe Login URL.
  • Hardening controls for exposure reduction, remote access and browser security headers.
  • Administrative hardening, Authentication Keys & Salts rotation, and Safe File Protection.
  • Core Integrity verification against official WordPress checksums.
  • Diagnostics / Self Test with update hygiene and security configuration checks.

常见问题:

Does Securizer include a firewall?

No. Securizer does not include a WAF or replace a server, CDN or dedicated firewall.

Does Securizer scan for malware?

Securizer verifies WordPress core integrity against official checksums and can identify unexpected files in core directories. It is not a general-purpose malware scanner.

Does Securizer send site data to a Securizer server?

No. Securizer has no product telemetry or Securizer cloud service. Some features use official WordPress.org services, and some diagnostics request the site's own public URLs as documented above.

Can Securizer lock me out after changing the login URL?

Safe Login URL verifies the new route before hiding normal anonymous login access, restores the previous configuration if verification fails, and provides an emergency recovery bypass.

How do I enable emergency recovery?

Add this line to wp-config.php: define( 'WPPS_SECURITY_BYPASS', true ); This disables active Securizer protection modules while keeping the administration interface available. Remove the line after resolving the problem.

Does Securizer automatically repair or delete WordPress core files?

No. Core Integrity scanning is read-only. An administrator can explicitly select modified or missing official core files and run Safe Repair; Securizer validates the matching official WordPress package and re-verifies checksums after replacement. Unexpected files are reported rather than deleted.

Will Securizer disable another security plugin?

No. Securizer can detect known overlapping login-protection functionality and display a compatibility recommendation, but it does not automatically disable or reconfigure another plugin.

What happens when Securizer is deactivated or deleted?

Deactivation preserves Securizer settings, logs and managed file-protection rules. By default, uninstall also preserves stored data; administrators can explicitly enable database cleanup.

更新日志:

1.0.4 1.0.3 1.0.2