| 开发者 | inetcorp |
|---|---|
| 更新时间 | 2026年9月28日 11:02 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
api.wordpress.org MD5 checksums to detect modified, missing, or extra files.X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy on the frontend.wp-login.php that silently rejects spam bots without affecting real users.?author=N probing and the public REST /wp/v2/users endpoint for non-logged-in visitors.manage_options logs in successfully (1-hour cooldown per IP).wp-login.php behind a custom keyword.sitevorx folder to /wp-content/plugins/, or install the ZIP file via Plugins > Add New > Upload Plugin.Yes, both plugins hook into phpmailer_init. We recommend deactivating other SMTP plugins before using Sitevorx's built-in SMTP module.
Yes. Sitevorx reads the CF-Connecting-IP header to identify the real visitor IP behind Cloudflare's proxy.
Open phpMyAdmin (or any database tool), find the wp_options table, and delete the row where option_name is sitevorx_sec_login_key. Then access /wp-login.php as usual.
uploads/sitevorx-migrate/ được tự động dọn khi gỡ plugin.AUTH_KEY/salt thay đổi (thường gặp lúc chuyển hosting), mật khẩu SMTP đã mã hóa không giải mã được — bản cũ vẫn lấy chuỗi mã hóa làm mật khẩu nên mọi wp_mail (đặt lại mật khẩu, đơn hàng WooCommerce…) thất bại âm thầm. Nay tự nhận diện lỗi giải mã, tạm gửi bằng mail() mặc định và hiện cảnh báo trong admin để nhập lại mật khẩu.is_ssl() trả về false khi TLS kết thúc ở CDN khiến không bật/không gửi được HSTS và điểm SSL bị sai; nay nhận biết HTTPS qua header của proxy (X-Forwarded-Proto, CF-Visitor).uploads/sitevorx-migrate/{job} quá hạn (>6h) để không đầy đĩa, đồng thời chừa các job đang chạy. Bước hoàn tất export nay idempotent, tránh tạo file ZIP hỏng khi thao tác bị lặp lại.<ins>), Plausible/Umami (data-*)..svg (không chỉ MIME) và xử lý lỗi ghi tệp an toàn hơn.wp-login.php trống (không kèm từ khóa bí mật), nên việc cho qua phụ thuộc hoàn toàn vào cookie set lúc mở trang login. Khi trang login bị page-cache (CDN / plugin cache) thì setcookie() không chạy → cookie không tồn tại → POST bị chặn và đá về trang chủ TRƯỚC khi xác thực. Nay từ khóa được gắn thẳng vào action của form qua filter site_url (scheme login_post), nên POST tự được uỷ quyền bằng ?key — không còn phụ thuộc cookie/cache.admin-post.php) bị đá về trang chủ khi bật "Đổi URL đăng nhập". Chốt chặn wp-admin dùng is_admin() vô tình chặn cả admin-post.php — endpoint xử lý form gửi đi của khách chưa đăng nhập (admin_post_nopriv_*: form liên hệ, callback thanh toán…). Nay admin-post.php được miễn trừ (nhận diện qua $pagenow + SCRIPT_NAME)..zip ngay sau khi export xong. Nguyên nhân: job_id sinh ra hỗn hợp hoa-thường, nhưng sanitize_key() trong download handler tự lowercase → action string của nonce ở 2 đầu khác case → wp_verify_nonce fail. Job_id giờ luôn lowercase từ lúc tạo.SITEVORX_MIGRATE_STEP_BUDGET_SEC = 15s thay vì chỉ làm 40 file rồi return. Giảm round trip HTTP 5-10× cho site nhiều file.ZipArchive::CM_STORE. Giai đoạn nén nhanh hơn 3-5× trên site WordPress media-heavy..zip ở 1.2.0 đặt thẳng vào wp-content/uploads/sitevorx-migrate/{job_id}/... với job_id chỉ 8 ký tự, không có auth gate → khả năng đoán URL và tải full DB hash. 1.2.1: download chuyển sang endpoint admin-post.php?action=sitevorx_migrate_download có manage_options cap + nonce + per-job binding, stream qua PHP. Job_id tăng lên 32 ký tự + thêm .htaccess (Apache) / web.config (IIS) deny ở root sitevorx-migrate/ làm defense-in-depth.{tmp_dir}/files.json). 1.2.0 nhồi cả mảng path vào transient → site 50k file (5GB media) làm row wp_options vượt max_allowed_packet → set_transient() fail silent, job chết ngay sau init.WHERE pk > $last_pk) khi bảng có primary key integer; fallback OFFSET. 1.2.0 dùng OFFSET cố định → O(n²) trên InnoDB nên bảng triệu row mất hàng phút mỗi chunk thứ 1000+.base_prefix (1.2.0 dùng OR base_prefix → sub-site export nuốt nhầm bảng của các sub-site khác). Giờ chỉ match $wpdb->prefix đúng sub-site hiện tại.node_modules, .git, .svn, .hg, .idea, .vscode ở mọi vị trí trong cây thư mục.includes/sitevorx-migrate.php) — exporter chunked AJAX đóng gói database + wp-content/{uploads,themes,plugins,mu-plugins} thành 1 file .zip duy nhất, kèm manifest.json chứa marker sitevorx-migrate-v1, để chuyển sang hosting khác hoặc lưu sao lưu offline.SELECT … LIMIT/OFFSET, ghi thẳng INSERT vào database.sql không nạp full table vào memory.X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy) — chỉ áp dụng trên frontend.?author=N và REST API /wp/v2/users cho khách.manage_options đăng nhập thành công (cooldown 1h/IP).api.wordpress.org/core/checksums/1.0/ để phát hiện file bị sửa đổi hoặc thiếu (chạy theo yêu cầu, đã khai báo trong External Services).sitevorx_audit_log), không lưu song song nhiều ring buffer.DISALLOW_WP_CRON set in wp-config.php. Warns the admin that internal WP-Cron is off and an external cron must be calling wp-cron.php, otherwise scheduled cleanup will not run.$wpdb->prepare() + $wpdb->esc_like() to satisfy Plugin Check, even though both patterns are hardcoded.login_key=off | disable_editor=on | ....revisions=1 | spam=0 | transients=1 | items=2.sitevorx_audit_summarize_diff() for any module that wants to produce a similar before/after change list.login_unlock event to the audit log.login_lockout event the moment the threshold is hit, with IP, attempt count, last submitted username, and configured lockout window.sitevorx_get_client_ip() so Cloudflare's CF-Connecting-IP is only trusted when the matching CF-Ray header is present (not spoofable from arbitrary clients).$wpdb->prepare() for the LIMIT clause to satisfy automated SQL-injection scanners.@ error suppression on the malware scanner's file read; the scanner now checks is_readable() first and still gracefully skips unreadable files.api/siteverify verification endpoint explicitly.sitevorx_audit_log option (no new database table).OPTIMIZE TABLE on tables larger than 500MB to avoid long table locks on shared hosting.sitevorx_recaptcha_v3_score_threshold (default 0.5).index.php files in /assets, /includes, /languages for directory listing protection.wp_kses() with a strict allow-list (sitevorx_kses_tracking_tags()) that permits only tracking / verification markup (script, noscript, meta, link, iframe, img, a, div, span, p). Every attribute value is still run through wp_kses_bad_protocol() which strips javascript:, data: and vbscript: URLs.WP_CONTENT_DIR/debug.log location and uses the WordPress WP_Filesystem API. The plugin no longer writes anywhere outside wp-content/.esc_url( home_url( '/?' . $key ) )..po -> .mo translation compiler. The plugin previously regenerated languages/sitevorx-en_US.mo on demand; that wrote to the plugin folder, which is not allowed. The compiled .mo is now shipped pre-built with the plugin and WordPress loads it normally..mo file is now the only source of English strings.echo $active ? 'on' : 'off') with esc_attr() across the sidebar, dashboard overview, SMTP/Optimizer/Utilities/Disk Cleaner tab navigation, and server stat cards, so automated scanners can see the escape explicitly.sanitize_text_field() wrapper around every nonce value passed to wp_verify_nonce().$_POST raw script fields (header/footer injection) with a dedicated helper (sitevorx_sanitize_raw_script) before update_option(); save path remains gated by the unfiltered_html capability.esc_url_raw() with esc_url() for inline CSS output in the custom login logo.__() inside echo/printf/sprintf: now wrapped with esc_html__(), esc_html( sprintf(...) ), or the sitevorx_kses_basic() helper (allowlisted <strong>, <a>, <br>, <code>, ...).wp_unslash() + wp_check_invalid_utf8() before json_decode(); per-field sanitization was already enforced on every decoded value.(int), esc_attr(), and esc_html() across all admin screens.heavy_files[] array from the disk cleaner with array_map( 'sanitize_text_field', wp_unslash(...) ).