| 开发者 | solutiontechcl |
|---|---|
| 更新时间 | 2026年9月16日 02:09 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/wp-content/plugins/solutiontech-seguridad-de-acceso directory, or install the plugin through the WordPress plugins screen directly.Use the emergency recovery URL shown on the plugin settings page. Keep a secure copy of this address. If you also lose that address, you can access your hosting panel or FTP client and temporarily rename the plugin folder in /wp-content/plugins/ to disable it and sign in through /wp-login.php.
No. All protections, including login redirection, rate limiting, and session handling, are executed dynamically inside WordPress.
Rate limiting applies to any IP address attempting to sign in. The default allows 5 attempts, followed by a temporary lockout. Legitimate users can wait for the lockout period to expire or request an administrator to clear their IP address from the lockout pool.
Yes. Version 1.22.0 introduces Authenticator App 2FA (TOTP RFC 6238) supporting Google Authenticator, Microsoft Authenticator, Authy, and 1Password with pure PHP offline SVG QR code pairing.
GeoIP lets you restrict access based on visitor country code. It works out of the box with Cloudflare (CF-IPCountry) and reverse proxies (X-Country-Code). You can set it to allowlist or blocklist mode.
The built-in Web Application Firewall inspects incoming HTTP requests to block SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion / Remote Code Execution (LFI/RCE), and malicious penetration testing scanners (such as sqlmap, nikto, wpscan).
The IP Whitelist excludes trusted IPs and CIDR ranges from rate limiting and WAF blocking. The Permanent Blacklist immediately rejects all traffic from designated IPs and subnets with a 403 Forbidden response.
It fetches the official cryptographic MD5 checksums for your current WordPress version from WordPress.org and compares every local file in wp-admin, wp-includes, and the root directory to detect unauthorized modifications, malware injections, or missing files.
Disabling XML-RPC prevents automated brute force and pingback DDoS attacks. If you use Jetpack or the mobile app, you can keep XML-RPC enabled or use the dedicated toggle in the Sites Protection tab.
It adds optional client-side controls that discourage casual visitors from right-clicking images, dragging images to their desktop, selecting and copying text, or using common copy shortcuts.
Yes. You can disable registration entirely or restrict new registrations to specific roles such as Subscriber or Customer.
Yes. The plugin includes toggles to disable comments across all published posts, all pages, or both.
New comments and pingbacks are prevented for the selected content type. Existing comments are not deleted.
No. These controls are deterrents. Content downloaded by a browser may still be obtained by other means or captured in a screenshot.
The plugin includes diagnostics and dedicated handling for these environments. On Multisite, settings are stored per site. After changing the login URL, test sign-in, sign-out, and password recovery in a private browser window.
The redirect manager supports 301, 302, 307, and 308. The source and destination must belong to the current site's domain. External hosts, duplicates, loops, and critical WordPress routes are rejected.
The Sessions section uses native WordPress session tokens. Administrators can review devices, close an individual session, close other sessions for their own account, or revoke sessions for another accessible account. The current administrative session is protected against accidental revocation.
It stores the requested path without query parameters, a referrer without query parameters, a general browser/device description, first and last detection times, and a hit count. It does not store IP addresses and excludes administration, REST, AJAX, cron, critical routes, and request methods other than GET or HEAD.
st_net_...) para sitios clientes conectados.X-ST-Agency-Key para entrega instantánea de feeds de ciberdefensa y stream de telemetría de ataques en vivo.languages/solutiontech-seguridad-de-acceso.pot).Domain Path: /languages in plugin headers for automatic native localization via WordPress Core.DISALLOW_FILE_EDIT enforcement and capability filtering) to prevent arbitrary PHP execution in case of account compromises.solutiontech_seguridad_acceso_daily_cleanup) for automated asynchronous pruning of audit logs and 404 monitor entries.