Linux 软件免费装
Banner图

Solutiontech Seguridad de acceso

开发者 solutiontechcl
更新时间 2026年9月16日 02:09
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security login audit log content protection brute force

下载

2.1.0 2.2.0 2.2.1 1.23.0 1.23.1 1.23.2 1.30.0 1.40.0 1.24.0 1.50.0 1.50.1 1.50.2 2.0.0

详情介绍:

Seguridad de acceso por Solutiontech protects WordPress access and reduces unnecessary public exposure without renaming core files or modifying .htaccess. Main features: The plugin does not modify WordPress files. After deactivation, WordPress uses its standard login routes again. Developer website: https://solutiontech.cl/

安装:

  1. Upload the plugin files to the /wp-content/plugins/solutiontech-seguridad-de-acceso directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the 'Plugins' screen in WordPress.
  3. Use the 'Seguridad Solutiontech' screen to configure the plugin settings.

屏幕截图:

  • Custom Login URL and Brute-Force Rate Limiting configuration.
  • Micro-WAF (Web Application Firewall), IP Access Lists (Whitelist/Blacklist), and Country Geolocation Filtering (GeoIP).
  • Interactive Live Forensic Audit Log with instant search, category filtering, and CSV export.

常见问题:

What happens if I forget the custom login URL?

Use the emergency recovery URL shown on the plugin settings page. Keep a secure copy of this address. If you also lose that address, you can access your hosting panel or FTP client and temporarily rename the plugin folder in /wp-content/plugins/ to disable it and sign in through /wp-login.php.

Does the plugin modify .htaccess or web server configuration files?

No. All protections, including login redirection, rate limiting, and session handling, are executed dynamically inside WordPress.

Does rate limiting affect all users?

Rate limiting applies to any IP address attempting to sign in. The default allows 5 attempts, followed by a temporary lockout. Legitimate users can wait for the lockout period to expire or request an administrator to clear their IP address from the lockout pool.

Can I use Two-Factor Authentication with Authenticator Apps?

Yes. Version 1.22.0 introduces Authenticator App 2FA (TOTP RFC 6238) supporting Google Authenticator, Microsoft Authenticator, Authy, and 1Password with pure PHP offline SVG QR code pairing.

How does Country Geolocation (GeoIP) work?

GeoIP lets you restrict access based on visitor country code. It works out of the box with Cloudflare (CF-IPCountry) and reverse proxies (X-Country-Code). You can set it to allowlist or blocklist mode.

What does the Micro-WAF protect against?

The built-in Web Application Firewall inspects incoming HTTP requests to block SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion / Remote Code Execution (LFI/RCE), and malicious penetration testing scanners (such as sqlmap, nikto, wpscan).

What is the difference between IP Whitelist and Permanent Blacklist?

The IP Whitelist excludes trusted IPs and CIDR ranges from rate limiting and WAF blocking. The Permanent Blacklist immediately rejects all traffic from designated IPs and subnets with a 403 Forbidden response.

How does the WordPress Core Integrity Checker work?

It fetches the official cryptographic MD5 checksums for your current WordPress version from WordPress.org and compares every local file in wp-admin, wp-includes, and the root directory to detect unauthorized modifications, malware injections, or missing files.

Does disabling XML-RPC affect Jetpack or the WordPress Mobile App?

Disabling XML-RPC prevents automated brute force and pingback DDoS attacks. If you use Jetpack or the mobile app, you can keep XML-RPC enabled or use the dedicated toggle in the Sites Protection tab.

What does content protection do?

It adds optional client-side controls that discourage casual visitors from right-clicking images, dragging images to their desktop, selecting and copying text, or using common copy shortcuts.

Can I disable new user registration while keeping the site open?

Yes. You can disable registration entirely or restrict new registrations to specific roles such as Subscriber or Customer.

Can I disable comments on all posts or pages at once?

Yes. The plugin includes toggles to disable comments across all published posts, all pages, or both.

Does disabling comments delete existing comments?

New comments and pingbacks are prevented for the selected content type. Existing comments are not deleted.

Can content protection completely prevent copying?

No. These controls are deterrents. Content downloaded by a browser may still be obtained by other means or captured in a screenshot.

Is the plugin compatible with Multisite, subdirectory installations, and WooCommerce?

The plugin includes diagnostics and dedicated handling for these environments. On Multisite, settings are stored per site. After changing the login URL, test sign-in, sign-out, and password recovery in a private browser window.

Which redirect types are supported?

The redirect manager supports 301, 302, 307, and 308. The source and destination must belong to the current site's domain. External hosts, duplicates, loops, and critical WordPress routes are rejected.

How does session management work?

The Sessions section uses native WordPress session tokens. Administrators can review devices, close an individual session, close other sessions for their own account, or revoke sessions for another accessible account. The current administrative session is protected against accidental revocation.

What information does the 404 monitor store?

It stores the requested path without query parameters, a referrer without query parameters, a general browser/device description, first and last detection times, and a hit count. It does not store IP addresses and excludes administration, REST, AJAX, cron, critical routes, and request methods other than GET or HEAD.

更新日志:

2.2.1 2.2.0 2.1.0 2.0.0 1.50.2 1.50.1 1.50.0 1.40.0 1.30.0 1.24.0 1.23.2 1.23.1 1.23.0 1.22.0 1.21.0 1.20.0 1.19.0 1.18.0 1.17.0 1.16.0 1.15.0 1.14.4 1.14.3 1.14.2 1.14.1 1.14.0 1.13.5 1.13.4 1.13.3 1.13.2 1.13.1 1.13.0 1.12.5 1.12.4 1.12.3 1.12.2 1.12.1 1.12.0 1.11.0 1.10.0 1.9.0 1.8.0