Linux 软件免费装

TrustSig Security

开发者 robertvahhi
更新时间 2026年9月23日 07:27
PHP版本: 7.2 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

spam security woocommerce brute force bot protection

下载

1.8.2 1.2.7 1.2.9 1.3.0 1.4.0 1.4.1 1.2.6 1.2.8 1.5.0 1.6.0 1.6.1 1.7.0 1.7.2 1.7.3 1.8.0 1.8.3 1.8.4 1.8.1 1.8.5 1.8.6

详情介绍:

TrustSig Security stops scripted bots and brute-force attacks on WordPress forms and API endpoints. There are no puzzles to solve and no "I am not a robot" checkboxes to tick, and you do not have to sign up for anything before it starts working. What exactly gets checked depends on the protection mode you pick, described below. Why TrustSig How it works TrustSig loads a small browser SDK, signs every rendered form with a per-site secret, and checks submissions against the TrustSig Edge service. A real visitor passes the check in about a second without doing anything. A scripted client that never runs JavaScript produces no token and gets stopped. When a request arrives without a valid token, the plugin does not quietly wave it through. Depending on the mode, it either serves a short "please wait" page that re-verifies the browser and then continues the original request, or blocks it. No account and no API keys are needed; the anonymous free tier is the default. Connecting a TrustSig dashboard account is optional and only adds analytics and higher limits. Protection modes What it protects Browser forms are covered automatically, no code needed: On top of that there is an optional brute-force lockout for repeated failed logins, an opt-in guard for admin-ajax and the REST API, and a verification API for developers. For developers Known limitations

安装:

  1. Upload the trustsig-security folder to /wp-content/plugins/, or install the plugin from the WordPress Plugins screen.
  2. Activate it from the Plugins menu.
  3. Open Settings, TrustSig. Protection is already active; there is nothing you have to configure.
  4. Optionally, enter your Site Key and Secret Key to link a TrustSig dashboard account for analytics and higher limits.

屏幕截图:

  • Protection details: per-form coverage across WordPress core, WooCommerce, BuddyPress, EDD, and Elementor.
  • Settings: switch between Monitor, Challenge, and Enforce, configure brute-force lockout, and link an optional dashboard account.

升级注意事项:

1.8.5 Closes a Contact Form 7 and WPForms bypass that let spam through without being checked, and fixes a settings bug that could switch on every optional protection and block anonymous visitors. Recommended for everyone. 1.8.0 Adds an optional scan-on-submit mode: the browser check can run only when a visitor actually uses a form instead of on every page view. Off by default; nothing changes unless you enable it under Advanced, Scan timing. 1.7.3 A TrustSig edge outage no longer blocks your forms; the edge fallback policy is now honoured on the no-token path. The settings export no longer leaks secret keys. WooCommerce block checkout is now covered by the Checkout toggle. Brute-force lockout, when enabled, now counts real failed logins. Recommended for everyone. 1.7.2 API keys are now opt-in and disabled by default, which stops browser autofill from breaking verification, and no cookie is set by default. Recommended for everyone. 1.7.1 Fixes the allowed-domains list saving empty, where domains disappeared on save. Recommended for anyone managing allowed domains. 1.7.0 Adds SureForms protection (on by default), hardens the API key fields against browser autofill, which could break verification by injecting your saved login, and makes the allowed-domains list save immediately. Recommended for any site using SureForms. 1.6.1 Security fix: Elementor Pro forms are now actually bot-protected by default. The previous guard never fired on real admin-ajax submissions. Update recommended for any site using Elementor Pro forms. 1.6.0 Adds Contact Form 7 protection, on by default. CF7 submissions, sent over its REST feedback endpoint, are now bot-checked on their own toggle without enabling the broad REST guard. Anonymous spam is blocked; verified browsers and authenticated API calls are unaffected. 1.5.0 Adds WPForms protection (on by default, covers the Mesmerize and Materialis contact form) and scopes REST and admin-ajax protection to anonymous traffic, so authenticated API calls (WooCommerce REST, Application Passwords, OAuth) are no longer blocked. It is now safe to enable REST and admin-ajax protection alongside API integrations. 1.4.2 Fixes a false-positive 403 on early lei_ajax_settings=1 bootstrap requests under API protection. Tightly scoped allowlist, not a general bypass. 1.4.1 Performance: the SDK and bootstrap now load deferred, so they no longer block rendering, with a preconnect hint to the edge. No behaviour or configuration change. 1.4.0 Compatibility hardening for caching and optimization stacks (WP Rocket, LiteSpeed, SiteGround, Perfmatters, Autoptimize, FlyingPress, Cloudflare). The verification SDK now resists being self-hosted, rewritten or stripped, and self-heals if it never loads. No configuration change needed. 1.3.0 Adds a bulk-add picker for the allowed-domains list (Multisite, WPML, Polylang, or paste). No behaviour change for existing installs; fresh sites still auto-allow only the main domain. 1.2.9 Listing copy refresh only, no behaviour change. 1.2.6 Compliance update: scripts and styles are now enqueued the WordPress way. No behaviour change. 1.2.5 Adds the verified-session layer and global AJAX and REST coverage. Existing sites stay in Monitor mode until you opt into enforcement. 1.2.0 Major enforcement overhaul: missing tokens are no longer silently allowed. Existing installs upgrade safely into Monitor (logging only) mode.

常见问题:

Do I need an account or API keys?

No. The plugin protects your forms the moment you activate it, on the anonymous free tier. An account only adds analytics and higher limits.

What data leaves my site?

A browser verification token, your site host name (or your secret key if you connect an account), and standard HTTPS request metadata go to the TrustSig Edge service. The "External services" section above has the full disclosure, including links to the Terms of Service and Privacy Policy.

Will this block real visitors?

In Challenge mode, the default, a visitor whose token is missing sees a brief "please wait" page that re-verifies the browser and then continues the original request on its own. Monitor mode never blocks. Enforce mode is the strictest and can block visitors who have JavaScript disabled.

Does it work with caching plugins?

Yes. Forms are signed with a server-issued nonce and the SDK fills in the token client-side, so cached pages stay protected.

Does the check run on every page view?

By default, yes: the check runs once when a protected page loads, so the token is ready before any submission. If you would rather not verify visitors who never touch a form, turn on "Scan on submit only" under Advanced, Scan timing. The check then runs at the first interaction with a form, or at submission, in which case the submission is held for about a second, verified, and continued automatically. Protection is the same either way.

How do I temporarily bypass protection if I lock myself out?

Settings, TrustSig, Tools shows a private recovery URL that bypasses all checks once. You can also add your IP to the whitelist.

Is the plugin GPL?

Yes, GPLv2 or later.

更新日志:

1.8.5 1.8.4 1.8.3 1.8.1 1.8.0 1.7.3 1.7.2 1.7.1 1.7.0 1.6.1 1.6.0 1.5.0 1.4.2 1.4.1 1.4.0 1.3.0 1.2.9 1.2.8 1.2.7 1.2.6 1.2.5 1.2.0 1.0.0