Linux 软件免费装

SPP Guardian Security & Maintenance

开发者 talhastackbuggs
更新时间 2026年9月1日 00:35
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security maintenance malware scanner integrity quarantine

下载

2.0.2

详情介绍:

SPP Guardian is a standalone, local-first WordPress security and maintenance plugin built for site owners who need clear explanations rather than raw technical alerts. Every security finding answers five questions: The scanner combines official WordPress core checksums, local file-change baselines, offline signatures, code and path heuristics, selected database inspection, administrator-account monitoring, cron inspection, update awareness, safe quarantine, restore, and verified core-file repair. No account, licence server, telemetry service, or cloud scanner is required. The plugin does not automatically delete suspicious content. Main features Important limitation No malware scanner can guarantee detection of every malicious file, database payload, zero-day exploit, hosting compromise, encrypted payload, or attacker-controlled server condition. SPP Guardian provides layered risk detection and guided remediation. It does not replace off-site backups, hosting security, server EDR, a WAF/CDN, log monitoring, or professional incident response.

安装:

  1. In WordPress, open Plugins > Add New > Upload Plugin.
  2. Select the SPP Guardian ZIP file and choose Install Now.
  3. Activate SPP Guardian Security & Maintenance.
  4. Open SPP Guardian > Scan Centre and run the first full scan.
  5. Review SPP Guardian > Maintenance and configure the schedule and email recipient under Settings.
  6. On low-traffic sites, configure a real server cron to call wp-cron.php regularly.
Before quarantining or repairing production files, confirm that a separate, tested backup exists.

常见问题:

Does SPP Guardian automatically delete malware?

No. Automatic deletion is unsafe because false positives and active component dependencies can break a site. SPP Guardian backs up and quarantines a confirmed file only after an authorised user approves the action.

Does a critical alert always mean the site is compromised?

No. Severity describes potential harm. Confidence describes how certain the detector is. Review both values and the evidence before acting.

Why are normal file changes shown?

The local baseline can report changes to code and configuration files. These are low severity unless another rule identifies suspicious behaviour or an official checksum fails. Ignoring a baseline-only change explicitly accepts the current file as the new local reference.

Can it scan very large sites?

Scanning is resumable and divided into small batches. Very large files are sampled or skipped according to the configured limit, and coverage information is recorded. WP-CLI is recommended for large or business-critical sites.

Is it a web application firewall?

SPP Guardian includes an optional, application-layer Protection & Firewall module: brute-force login lockout, GET/POST request filtering against common attack patterns, REST API rate limiting and anonymous user-enumeration blocking, and XML-RPC restriction. It runs inside WordPress itself, so it complements rather than replaces a network or edge WAF, a CDN, or your host's own firewall, and it cannot guarantee blocking every attack. The module is off by default and the GET/POST filters start in a log-only mode so you can review real traffic in the firewall activity log before switching them to block.

更新日志:

2.0.2 2.0.1 2.0.0 1.1.0 1.0.0