Linux 软件免费装

sHub-Log

开发者 syntaxcloud
更新时间 2026年8月29日 14:17
PHP版本: 7.2 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security protection ip blocking attack log

下载

1.3.4 1.3.5 1.3.6 1.0.3 1.2.10 1.2.12 1.2.13 1.2.9 1.2.1 1.2.3 1.2.5 1.1.6 1.1.7 1.1.8 1.2.0 1.1.3 1.1.4 1.1.5 1.1.9 1.2.4 1.2.6 1.1.0 1.2.11 1.2.15 1.2.7 1.2.8 1.3.1 1.2.14 1.2.2 1.3.0 1.3.2 1.3.3

详情介绍:

sHub-Log strengthens WordPress site security. Main features:

安装:

  1. Upload or install the plugin
  2. Activate the plugin
  3. Configure settings from the sHub-Log admin menu

升级注意事项:

1.3.6 May contact syn-c.jp only during the license renewal-warning window and post-expiry grace, to apply a signed replacement code. Network failure keeps the existing offline license. 1.3.5 Keeps the sHub-Log menu open on Attack Log and Protected IP screens, adds links between those screens, and translates remaining attack-category labels. 1.3.4 Adds offline license codes for paid features. After expiry, paid UI stops while 90-day log retention continues for 14 days. The paid-preview switch is unchanged. 1.3.3 Aligns the admin header with the chart panels, appends /sHub-Log to header titles, and removes non-working category link styling on the free Security Trend screen. 1.3.2 Adds translations for page-access tables and the paid-preview switch, and enlarges the admin header icon. 1.3.1 Admin UI polish: white header bar, larger plugin icon, and Security Trend chart title aligned with the menu in all bundled languages. 1.3.0 Protected IPs now return HTTP 403 instead of 500, and show post-block denial counts. Recommended for all sites using auto IP protection. 1.2.12 Hardens false-positive handling (admin lockouts, REST/editor, proxy/CDN IP resolution, timezone-correct blocking) and makes rate counters durable. Existing sites with login limit count still at 3 are migrated to 5 once. 1.2.11 Adds WordPress core scan detection and optional sustained-volume alert emails (max once per day). Enable sustained alerts in Advanced Settings if needed. 1.2.10 Fixes bundled translation files so Japanese and other admin language packs display correctly. Recommended for all 1.2.9 users. 1.2.9 Adds admin UI translations for Japanese, Korean, Simplified and Traditional Chinese, Vietnamese, and Thai. No settings changes required. 1.2.8 Admin submenu now uses native WordPress expand/collapse behavior. No settings changes required. 1.2.7 Admin UI is reorganized into submenus. Settings are split across Basic, Advanced, Risk Scoring, and Bot Logging pages. Review your settings after updating. 1.2.6 If you saved settings from Basic Settings or Bot Logging Settings before the settings-group fix, verify Advanced Settings or use the Recommended settings button. 1.2.3 Security update including CSV formula injection protection. All users should update. 1.2.1 Simple and Advanced settings views added for easier daily operation. 1.2.0 Per-IP risk scoring added (disabled by default). 1.1.9 Rate-limit customization, 404 flood detection, IP whitelist, and trusted proxy support added. 1.1.0 Category-based attack detection, statistics, retention settings, and auto IP blocking added. 1.0.3 Security update recommended for all users.

常见问题:

How do I unblock an IP address?

Open sHub-Log → Security Trend, scroll to Protected IP, and unblock the address from the list.

Does the plugin make external requests?

When attack spike alerts are enabled, the plugin may fetch alert definitions and email templates from syn-c.jp. When remote scoring is enabled, it may fetch a signed score-config.json from syn-c.jp. When verified bot exclusion is enabled, it may fetch published IP range JSON from bot vendors (cached for 24 hours). License verification is performed entirely on the site (offline signed license codes) and does not contact syn-c.jp, except around expiry: during the renewal-warning window and the 14-day post-expiry grace, the plugin may request a signed renewal payload from syn-c.jp. If that request fails, the existing offline expiry is kept (paid features are not dropped solely because of a network error). No attack logs, IP addresses, user information, or site content are sent to syn-c.jp. The Advanced Settings paid-preview switch is an internal verification control. It is shown on syn-c.jp hosts, to administrators whose email ends with @syn-c.jp, when SYNTAXHUB_SECURELOG_PAID_PREVIEW_SWITCH is defined in wp-config.php, or when a filter enables it. It is not a customer license.

What should I check after updating to 1.2.6?

If you saved settings from Basic Settings or Bot Logging Settings before the settings-group fix in 1.2.6, review Advanced Settings or use the Recommended settings button on Basic Settings to restore factory defaults. Recommended factory defaults: | Setting | Default | | --- | --- | | Login attempt limit window | 5 minutes | | Login attempt limit count | 5 | | Block duration | 60 minutes | | High-volume request threshold | 90/minute | | 404 flood threshold | 30/5 minutes | | Attack spike email alerts | OFF | | Risk scoring | OFF | | Bot access logging | OFF (search bot logging ON / AI bot logging OFF when enabled) | | Auto-trust private proxies / Cloudflare | ON | | Remember administrator IPs | ON |

更新日志:

1.3.6 1.3.5 1.3.4 1.3.3 1.3.2 1.3.1 1.3.0 1.2.15 1.2.14 1.2.13 1.2.12 1.2.11 1.2.10 1.2.9 1.2.8 1.2.7 1.2.6 1.2.5 1.2.4 1.2.3 1.2.2 1.2.1 1.2.0 1.1.9 1.1.8 1.1.7 1.1.6 1.1.5 1.1.4 1.1.2 1.1.1 1.1.0 1.0.3 1.0.2 1.0.1 1.0.0