Linux 软件免费装

Thessley Security Hardening

开发者 martinlundstrom
opseceagleeye
shieldcoresecurity
thessleysecurity
更新时间 2026年9月27日 20:12
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security firewall malware brute-force geo-blocking

下载

1.0.20 1.0.21

详情介绍:

Thessley Security Hardening is a modular security plugin. Each feature is a self-contained module you can enable, configure, and put into log-only or enforcing mode independently — nothing is all-or-nothing. Perimeter Request inspection Detection Hardening Overview Ops Bundled third-party assets

安装:

  1. Upload the plugin files to /wp-content/plugins/thessley-security-hardening, or install directly through the WordPress plugins screen.
  2. Activate the plugin.
  3. Each module starts in log-only mode where applicable — review the Event Log for a few days before switching any module to Block.

常见问题:

Will this lock me out of my own site?

Every blocking module exempts your LAN, reserved/private IP space, and anything in the trusted-networks list, before it ever looks at the rest of its rules. Geo Blocker and Geo Login specifically cannot lock out your own network regardless of which countries you select.

Does this slow down every page load?

The early-request checks (IP Blocklist, Geo Blocker, Geo Login, Rate Limiter, Query Guard's query-string scan) run as a must-use plugin before WordPress finishes bootstrapping, using compiled binary-search lookups rather than database queries — no per-request network calls, no per-request external API hits.

What files does this plugin write, and where?

Two places by default, both created by the plugin itself and both removed when it is deleted (the loader file also when you deactivate it), plus one optional block you can switch on in Hardening:

  1. wp-content/mu-plugins/wp-thessley-early.php — a single small must-use plugin. This is what lets the blocking modules run before WordPress and other plugins load, the same reason caching plugins install a drop-in. It contains no site-specific data and is a copy of mu-loader/wp-thessley-early.php inside this plugin. It loads each enabled module's check.php directly from this plugin's folder, so nothing else is copied into wp-content. If mu-plugins isn't writable, the plugin still works, but early blocking is off and an admin notice says so.
  2. wp-content/uploads/thessley-security-hardening/ — compiled datasets (the merged IP-blocklist ranges, the geo-country index, the trusted-networks list), located with wp_upload_dir() and protected from direct web access with .htaccess and an index.php. They are plain data files (binary, JSON and text), never PHP, and nothing in this folder is executed.
  3. Optional, off by default: the "Web-root protection" setting in Hardening adds one marked block to the site's .htaccess (using WordPress' own insert_with_markers()) that makes Apache refuse files such as wp-config.php.bak, database dumps, error_log, readme.html and stray archives, which the web server would otherwise hand out without PHP ever running. Unchecking the setting, or deactivating the plugin, removes exactly that block.
Everything else (settings, the local blocklist, the event log) is stored in the database. The plugin never writes to WordPress core folders, its own plugin folder, or other plugins' or themes' folders.

Where does the geo data come from?

DB-IP's free Country Lite database (CC BY 4.0), refreshed automatically on a schedule.

更新日志:

1.0.21 1.0.20 1.0.19 1.0.18 1.0.17 1.0.16 1.0.15 1.0.14 1.0.13 1.0.12 1.0.11 1.0.10 1.0.9 1.0.8 1.0.7 1.0.6 1.0.5 1.0.4 1.0.3 1.0.2 1.0.1 1.0.0 0.1.9 0.1.8 0.1.7 0.1.6 0.1.5 0.1.4 0.1.3 0.1.2 0.1.1 0.1.0