Linux 软件免费装
Banner图

SiteFort - Advanced Security, Firewall & Malware Scanner

开发者 securewpteam
更新时间 2026年5月20日 00:57
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

security firewall vulnerability malware scanner 2fa

下载

1.0.0 1.0.1

详情介绍:

SiteFort is a performance-first WordPress malware scanner, firewall, and hardening plugin built from real malware cleanup work. Your site stays fast during deep threat analysis. SiteFort offloads suspicious file analysis to the cloud and reduces wasted server work by blocking bad bots, scanner probes, abusive requests, and rate-limit violations. Use SiteFort to find malware, backdoors, web shells, malicious PHP, injected scripts, SEO spam, suspicious redirects, exposed sensitive files, hidden administrator risks, breached passwords, vulnerable plugins, scanner bots, and weak hardening rules before attackers use them against you. Helpful links: Plugin Features | Free Remote Scan | Pricing | Documentation CORE SECURITY FEATURES PERFORMANCE-FIRST WORDPRESS SECURITY Security should not make your site slower. SiteFort is designed for busy websites, WooCommerce stores, agencies, and shared or managed hosting environments where heavy scans and bad-bot traffic can hurt performance. WORDPRESS SECURITY SCANNER SiteFort is not limited to basic file scanning. It runs a layered security review of the WordPress site and organizes findings by severity. Cloud-assisted file scanning helps reduce server load while content and database checks run on your website. Your database content never leaves your site. WORDPRESS FIREWALL SiteFort provides practical firewall controls for production sites without requiring custom WAF rule writing. EASY BOT FILTER POLICY Choose Basic, Balanced, or Maximum bot protection without writing manual rules. Trusted search engines, social previews, and major crawlers can stay allowed while unwanted automation is filtered. LOGIN SECURITY AND 2FA Account takeover is one of the fastest ways to lose control of a WordPress site. SiteFort adds layered login protection without requiring multiple plugins. WORDPRESS SECURITY HARDENING SiteFort helps close the exposure points attackers check first, then verifies whether key protections are actually working. VULNERABILITY MANAGEMENT SiteFort checks installed WordPress core, plugin, and theme versions against vulnerability intelligence and shows affected assets, severity, CVE references where available, and recommended fixes. SiteFort does not claim to virtually patch vulnerable code. Instead, it helps you identify affected components, prioritize fixes, update where possible, and reduce reconnaissance with scanner-bot blocking while you patch. Pro: automated vulnerability alerts notify teams when a known vulnerability affects an installed plugin, theme, or WordPress core version. ONE-CLICK REPAIR AND RESTORE Pro: SiteFort adds guided repair workflows so you can act on scan findings without manually editing files over FTP or SSH. For active compromise, Securewp expert cleanup and managed security services are available when hands-on investigation, root-cause patching, blacklist help, or post-cleanup review is needed. AUDIT LOG AND SITEFORT CONSOLE SiteFort keeps a security event history so you can see what changed, what was blocked, and what needs review. Track logins, failed logins, lockouts, user changes, plugin/theme changes, firewall blocks, scan results, hardening changes, vulnerability findings, settings changes, and sensitive actions. Use SiteFort from WordPress dashboard for site-level protection. Connect to SiteFort Console for multi-site status, scan history, vulnerability tracking, uptime monitoring, SSL expiry checks, remote website scanning, alert routing, downloadable reports, team roles, white-label options, and support workflows. SiteFort Console is available for connected users. Some Console workflows, reporting features, white-label options, managed services, or advanced automations may require a paid plan. HOSTING COMPATIBILITY SiteFort is built for real WordPress hosting environments, including shared hosting, managed hosting, VPS setups, Apache, Nginx, LiteSpeed, and Cloudflare-proxied sites. Some hardening rules depend on server permissions and hosting configuration. When a rule cannot be applied automatically, SiteFort shows the status and helps identify what needs manual server configuration. PRO AND MANAGED SECURITY FEATURES Core protection is available in the plugin. Paid plans are designed for infected sites, larger custom sites, agencies, and teams that need continuous scanning, automated alerts, deeper file analysis, repair workflows, and post-cleanup protection. Pro features may include: Managed security options add hands-on review, monitoring, response workflows, and expert cleanup coverage.

安装:

  1. Install SiteFort from the WordPress plugin directory, or upload the plugin ZIP file.
  2. For manual installation, upload the unzipped sitefort folder to /wp-content/plugins/.
  3. Activate the plugin from the Plugins screen and open SiteFort in wp-admin.
  4. Complete the setup wizard, or open SiteFort > Settings > License and Plan.
  5. Activate with your email address or license key. If a Pro purchase uses the same email as an existing free license, the site can upgrade to Pro from the License and Plan screen.
  6. Review scanner, firewall, country blocking, bot policy, login security, 2FA, and hardening settings.
  7. Connect Cloudflare from Settings > Integrations if you want edge-level firewall enforcement.
  8. Run your first security scan and review malware, account, database, reputation, vulnerability, and hardening findings.
SiteFort requires outbound HTTPS for license activation, cloud malware analysis, vulnerability intelligence, firewall intelligence, community blocklist updates, reputation checks, clean-file repair, and optional Console sync.

屏幕截图:

  • **Security Scanner** - Staged scan progress across files, malware, accounts, database/content safety, reputation, vulnerabilities,  affected files, severity, detection type, file integrity status, and remediation actions.
  • **Firewall Controls** - Easy bot/crawler policy, rate limits, community blocklist, and Cloudflare Sync.
  • **Firewall Rule Builder** - IP rules, country blocking, Bot/crawler firewall rule building
  • **Login Security** - Custom login URL, lockouts, CAPTCHA protection, and password controls.
  • **2FA** - Role enforcement, authenticator app setup, email codes, recovery codes
  • **Server Hardening** - Sensitive file protection, PHP execution controls, XML-RPC and security headers.
  • **WordPress Hardening** - REST API, user enumeration, file editor protection
  • **Vulnerability Scanner** - Affected plugins, themes, WordPress core, CVE references, severity, and fix guidance.
  • **Security Header** - Security headers analyzer, config
  • **Audit Log** - Searchable security events, user activity, firewall actions, scan results, and sensitive changes.
  • **SiteFort Console** - multi-site status, scans, alerts, reports, uptime, SSL, team workflows, and support options.

常见问题:

Can I use SiteFort only from my WordPress dashboard?

Yes. Scanner, malware detection, firewall rules, country blocking, bot policy, login security, 2FA, vulnerability scanning, hardening, audit log, and settings are available from wp-admin. SiteFort Console is optional for centralized management, remote workflows, reports, alert routing, uptime/SSL monitoring, team access, and support workflows.

What does the SiteFort scanner check?

SiteFort scans files, file integrity, malware indicators, user account security, weak and breached passwords, hidden administrator accounts, content and database safety, suspicious URLs, injected content, domain/IP reputation, exposed sensitive files, server state, and known vulnerabilities in WordPress core, plugins, and themes.

Is SiteFort only a file scanner?

No. SiteFort checks files, accounts, passwords, content, database safety, reputation, exposed sensitive files, vulnerabilities, hardening status, and suspicious server exposure. File scanning is only one part of the security review.

Does SiteFort include 2FA and CAPTCHA?

Yes. SiteFort includes login security controls such as role-based 2FA, authenticator app codes, email codes, recovery codes, lockouts, CAPTCHA, custom login URLs, safer login responses, weak password checks, and breached-password detection.

Does SiteFort include country blocking and Cloudflare support?

Yes. Country blocking is part of the firewall rules. Country detection can use Cloudflare country data for proxied sites, Cloudflare integration when configured in SiteFort, or a local MaxMind GeoLite2 database when a free MaxMind license is configured. SiteFort can also sync supported IP, country, and user-agent firewall rules to Cloudflare when the domain is proxied through Cloudflare and a scoped API token is configured.

What is the easy bot filter policy?

The bot filter policy lets you choose Basic, Balanced, or Maximum bot protection. It can block hacking tools, vulnerability scanners, scrapers, automated scripts, and unrecognized bots while keeping trusted search engines and social previews allowed.

Does SiteFort virtually patch vulnerable plugins?

SiteFort does not claim to virtually patch vulnerable code. It identifies known vulnerable core, plugin, and theme versions, shows severity and recommended fixes, and helps reduce automated reconnaissance with scanner-bot blocking while you update or replace affected components.

Does SiteFort verify hardening rules?

Yes. SiteFort does more than toggle settings. It checks whether hardening rules are actually effective where possible and shows when a rule may require manual hosting or server configuration.

What features require a paid plan?

Paid plans add unlimited cloud deep threat analysis, scheduled scans, automated vulnerability alerts, one-click malware repair/restore, supported clean-file restoration, uptime/SSL monitoring, Slack/Discord/email/webhook alert workflows, advanced reports, white-label options, expert cleanup discounts, and managed security options.

How does cloud-assisted malware scanning work?

SiteFort hashes files locally and checks known signatures first. Known clean and known malicious files can be resolved quickly. Only unknown or suspicious files may be sent for deeper cloud file analysis when needed. Results are cached so unchanged files do not need the same work again.

Does SiteFort send my site's database content to the cloud?

No. Database and content checks safety run on your own website. Your database content never leaves your site. For file scanning, file hashes are sent first. Only files that cannot be verified by hash alone may be uploaded for deeper malware analysis. If wp-config.php requires analysis, sensitive configuration values are removed before upload.

Can SiteFort help after a site is already hacked?

Yes. SiteFort can scan for malware, suspicious users, injected content, reputation issues, exposed files, and vulnerable components. Supported plans add one-click malware repair, and expert cleanup or managed security services are available when hands-on response is needed.

How do I activate SiteFort Pro?

Open SiteFort > Settings > License and Plan in your WordPress dashboard. You can activate with the email address used at checkout or a license key. If you already have a free license under the same email, the site can upgrade to Pro from the License and Plan screen.