Linux 软件免费装

sHub-Log

开发者 syntaxcloud
更新时间 2026年7月20日 13:13
PHP版本: 7.2 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

security protection ip blocking attack log

下载

1.2.8 1.2.9 1.2.10 1.2.11 1.2.2 1.2.1 1.2.3 1.2.5 1.0.3 1.1.6 1.1.7 1.1.8 1.2.0 1.1.0 1.1.3 1.1.4 1.1.5 1.1.9 1.2.4 1.2.6 1.2.7

详情介绍:

sHub-Log strengthens WordPress site security. Main features:

安装:

  1. Upload or install the plugin
  2. Activate the plugin
  3. Configure settings from the sHub-Log admin menu

升级注意事项:

1.2.11 Adds WordPress core scan detection and optional sustained-volume alert emails (max once per day). Enable sustained alerts in Advanced Settings if needed. 1.2.10 Fixes bundled translation files so Japanese and other admin language packs display correctly. Recommended for all 1.2.9 users. 1.2.9 Adds admin UI translations for Japanese, Korean, Simplified and Traditional Chinese, Vietnamese, and Thai. No settings changes required. 1.2.8 Admin submenu now uses native WordPress expand/collapse behavior. No settings changes required. 1.2.7 Admin UI is reorganized into submenus. Settings are split across Basic, Advanced, Risk Scoring, and Bot Logging pages. Review your settings after updating. 1.2.6 If you saved settings from Basic Settings or Bot Logging Settings before the settings-group fix, verify Advanced Settings or use the Recommended settings button. 1.2.3 Security update including CSV formula injection protection. All users should update. 1.2.1 Simple and Advanced settings views added for easier daily operation. 1.2.0 Per-IP risk scoring added (disabled by default). 1.1.9 Rate-limit customization, 404 flood detection, IP whitelist, and trusted proxy support added. 1.1.0 Category-based attack detection, statistics, retention settings, and auto IP blocking added. 1.0.3 Security update recommended for all users.

常见问题:

How do I unblock an IP address?

Open sHub-Log → Security Trend, scroll to Protected IP, and unblock the address from the list.

Does the plugin make external requests?

When attack spike alerts are enabled, the plugin may fetch alert definitions and email templates from syn-c.jp. When remote scoring is enabled, it may fetch a signed score-config.json from syn-c.jp. When verified bot exclusion is enabled, it may fetch published IP range JSON from bot vendors (cached for 24 hours). No attack logs, IP addresses, user information, or site content are sent to syn-c.jp.

What should I check after updating to 1.2.6?

If you saved settings from Basic Settings or Bot Logging Settings before the settings-group fix in 1.2.6, review Advanced Settings or use the Recommended settings button on Basic Settings to restore factory defaults. Recommended factory defaults: | Setting | Default | | --- | --- | | Login attempt limit window | 5 minutes | | Login attempt limit count | 3 | | Block duration | 60 minutes | | High-volume request threshold | 90/minute | | 404 flood threshold | 30/5 minutes | | Attack spike email alerts | OFF | | Risk scoring | OFF | | Bot access logging | OFF (search bot logging ON / AI bot logging OFF when enabled) |

更新日志:

1.2.11 1.2.10 1.2.9 1.2.8 1.2.7 1.2.6 1.2.5 1.2.4 1.2.3 1.2.2 1.2.1 1.2.0 1.1.9 1.1.8 1.1.7 1.1.6 1.1.5 1.1.4 1.1.2 1.1.1 1.1.0 1.0.3 1.0.2 1.0.1 1.0.0