Linux 软件免费装
Banner图

Stillward Security

开发者 adnanali32038
更新时间 2026年9月30日 18:29
PHP版本: 7.2 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security firewall malware brute force hardening

下载

2.3.3

详情介绍:

Stillward Security follows one rule: protect, don't disturb. Most security plugins break sites by aggressively filtering requests, stripping form data, whitelisting file types, or forcing strict policies. Stillward ships with only non-breaking hardening enabled by default. Anything that can affect how your site works is turned OFF until you knowingly enable it. Enabled by default (safe on any site): Opt-in (off by default — enable knowingly): Malware Shield — and why it will not eat your files The Malware Shield hunts one specific, self-healing infection (fake db.php / advanced-cache.php drop-ins, vapor-* / host-*-bridge mu-plugins, injected theme functions.php, sc_* options and cron). Deleting a legitimate file is worse than the malware, so three gates must all pass before anything is removed:
  1. Confidence — only an exact marker unique to this malware family can lead to a removal. The generic "obfuscated code" heuristic is report-only, because licence loaders, packers and minified libraries look exactly like that.
  2. Location — removal is limited to the places this family actually drops files: the three wp-content drop-ins, mu-plugins, PHP files in /uploads, the wp-content/cache staging copy, filenames it is known to plant, and any file in wp-includes/wp-admin/the web root that the official WordPress checksum manifest says WordPress does not ship. A file that IS part of a real plugin, theme or WordPress itself is never deleted — it is reported instead, because an infected real file needs reinstalling, not erasing. wp-config.php is never deleted under any circumstance.
  3. Protected paths — this plugin's own folder and other security/backup plugins (which legitimately ship malware signatures in their source) are skipped entirely.
Everything that is removed is copied into the plugin's own database table first -- never into another file on the server, because a copy of malware on disk is still malware on disk. If a removal turns out to be a mistake, download the copy from the Malware Shield tab and put it back. Removed options and cron events are backed up the same way and restore in one click. An infected theme functions.php is never modified or deleted: it is reported, so you can reinstall a clean copy of the theme. Developers can force report-only behaviour for any path with the wpss_malware_auto_removable and wpss_malware_protected_paths filters. Database Audit — the things a file scanner cannot see A file scanner is blind to a compromise that never writes a file, and that is not a hypothetical: an SEO-cloaking campaign ran for four months across eight sites on one hosting account while hourly scans reported clean, because its code lived in a plugin's database table, its configuration in an option, its spam in wp_posts, and its administrators were inserted straight into wp_users. The audit runs alongside the file scan and asks three questions that have exact answers: Nothing found in the database is ever changed automatically. A confirmed rogue administrator can be demoted to Subscriber with its sessions ended and password reset — never deleted — and the previous role, capabilities and password hash go into quarantine first so Restore puts the account back exactly as it was. Critical findings are e-mailed the moment they are recorded: once per distinct finding per day, at most twelve an hour, and only for findings that mean something got in. Routine lockouts and firewall blocks are logged but never mailed, because an alert that is always noise teaches people to ignore alerts. Safety guarantees

安装:

  1. Upload the stillward-security folder to /wp-content/plugins/, or install the ZIP via Plugins → Add New → Upload Plugin.
  2. Activate the plugin.
  3. Go to Stillward in the admin menu to review settings. Core protection is already on; enable advanced features only if you need them.

屏幕截图:

  • Malware Shield. Scan-only and scan-and-clean runs, plus a plain account of what a plugin alone cannot fix after an infection.
  • Findings and quarantine. A clean install reports nothing at all, and anything the shield does remove is kept as a copy you can download again.
  • Account-wide scan. Read-only: it looks at every site under the same hosting user and never changes anything outside this one.
  • The activity log, and the full list of event types it can record.

升级注意事项:

2.3.3 Repackaged release; identical in behaviour to 2.3.2. 2.3.2 Activation no longer removes anything, auto-clean is off by default, and an option is only removed when its value carries a malware marker. 2.3.1 Correct handling of installs that move or rename wp-content, the plugins directory or mu-plugins. 2.3.0 Quarantined files move from disk into the database, restoring a removed file becomes a download, and the file editor now follows the WordPress Hardening setting. 2.2.0 Adds database and account scanning, quarantine with one-click restore, and much stricter malware-removal gates. Recommended for all users. 2.1.0 Malware Shield no longer removes a file on a generic heuristic alone. 2.0.0 Major rewrite: safe-by-default, firewall is now opt-in and never edits requests.

常见问题:

Will this plugin break my site?

That is the one thing it is built not to do. Only non-breaking hardening is on after activation. Every feature that can change how your site behaves -- the request firewall, Content-Security-Policy, HSTS, the strict MIME whitelist, the custom login URL and XML-RPC blocking -- is off until you turn it on yourself.

The Malware Shield deletes files. How do I know it will not delete mine?

Three gates must all pass before anything is removed:

  1. The file must contain an exact marker unique to the malware family this scanner targets. The generic "looks obfuscated" heuristic can only report, never remove, because licence loaders and minified libraries look identical.
  2. The file must sit in a location this family actually drops into, and must not be part of a real plugin, theme or WordPress core. An infected real file is reported for reinstalling, never erased. wp-config.php is never deleted.
  3. This plugin's own folder, and other security and backup plugins, are skipped.
Everything removed is copied into the plugin's own database table first -- never onto disk -- and can be downloaded again from the Malware Shield tab.

Does the firewall change my form data?

No. It never edits, strips or re-encodes a submitted request. It runs in log-only mode by default and blocks only if you switch it to Block mode.

Should I disable XML-RPC?

Only if nothing depends on it. Leave it enabled if you use Jetpack, the WordPress mobile app, or any service that publishes to your site remotely.

Does the plugin contact any external service?

One, and only WordPress.org's own API. When the Malware Shield inspects a file in wp-includes, wp-admin or the web root, it asks WordPress's built-in get_core_checksums() for the official checksum manifest of your WordPress version, so it can tell a file WordPress genuinely ships from one an attacker planted. That request goes to api.wordpress.org -- the same endpoint WordPress itself uses for updates -- and carries only your WordPress version number and locale. Nothing about your site, its content or its users is sent. The manifest is cached, and if the request fails the scanner simply reports those files instead of judging them. There is no telemetry, no analytics, no third-party service and no registration. Everything else the plugin records stays in your own database.

What happens when I delete the plugin?

Uninstall removes its options, its log and quarantine tables and its scheduled tasks, on every site in a multisite network. Accounts you demoted through the account scanner are deliberately left as they are -- silently restoring an administrator during an uninstall would be dangerous.

更新日志:

2.3.3 2.3.2 2.3.1 2.3.0 2.2.0 2.1.4 2.1.3 2.1.2 2.1.1 2.0.0