Linux 软件免费装
Banner图

Ultimate Security – Vulnerability Scanner, 2FA, and Login Protection

开发者 programmelab
wpultimatesecurity
更新时间 2026年10月1日 00:06
PHP版本: 7.1 及以上
WordPress版本: 7.1.2
版权: GPLv2 or later
版权网址: 版权信息

标签

security two factor authentication login security brute force vulnerability scanner

下载

1.0.21 1.0.11 1.0.29 1.0.36 1.0.40 1.0.16 1.0.24 1.0.22 1.0.25 1.0.5 1.0.4 1.0.6 1.0.10 1.0.3 1.0.7 1.0.8 1.0.9 1.0.14 1.0.13 1.0.1 1.0.0 1.0.15 1.0.18 1.0.12 1.0.17 1.0.19 1.0.20 1.0.2 1.0.23 1.0.26 1.0.28

详情介绍:

Stop hackers and bots from getting into your WordPress site. Ultimate Security adds two-factor login, blocks password-guessing attacks, stops spam bots and warns you about plugins with known security holes. A setup wizard picks the right settings for your kind of site, so you don't have to understand every option. [youtube https://www.youtube.com/watch?v=MU7KivId-cE] Why site owners choose it Protect your login Two-factor login. After the password, users confirm with a code sent by email or shown in an authenticator app (Google Authenticator, Authy, Microsoft Authenticator and similar). Choose which user roles need it. Works on the WordPress, WooCommerce and Ultimate Member login forms. [youtube https://www.youtube.com/watch?v=iAEsiGlb_8M] Stop password-guessing bots. [youtube https://www.youtube.com/watch?v=TkKENyFl33Y] Hide your login page. Move wp-login.php to a private address so bots can't find it. Stronger passwords. Control who stays signed in. Block spam and bots on your forms Add Google reCAPTCHA or Cloudflare Turnstile to your login, registration, password reset and comment forms, and to WooCommerce login, registration and checkout. [youtube https://www.youtube.com/watch?v=_9oKeDq2ZpQ] Find security problems before hackers do Vulnerability scanner. Checks WordPress, your plugins and your themes against a database of known security holes, and emails you when it finds one. It works without an API key; WPScan or Patchstack keys add extra coverage. [youtube https://www.youtube.com/watch?v=SsV6Dwn9tbY] Security score. One number that tells you how well protected your site is, and which fix to do next. File check. Compares your WordPress core files with the official copies, so changed or added files stand out. Safer updates. Choose when WordPress, plugins and themes update automatically. Set update days and quiet periods, delay updates by a few days, and get an email when something changes. Advanced protection Cloudflare firewall rules. If your site uses Cloudflare, connect your account and turn on ready-made rules from wp-admin: let good bots through, block bad crawlers and risky traffic, and block attacks on known WordPress flaws before you've had a chance to update. You can preview every rule before it goes live. [youtube https://www.youtube.com/watch?v=W2v08QaSCl4] Security keys (salts). Change the secret keys in wp-config.php on demand or on a schedule, which signs everyone out and makes stolen login cookies useless. You get a warning before a scheduled change, and can restore a previous set. Test Mode Turn on your protections without blocking anyone, and review a log of what would have been blocked. Choose which user roles it covers. Visitors who aren't signed in are still held to the login limit, and Test Mode switches itself off after seven days, so a forgotten test never leaves your site unprotected. Moving from another plugin Privacy No usage tracking. The plugin contacts an outside service only when you switch on a feature that needs one, and each is listed under External Services below. For developers wp ultimate-security template list wp ultimate-security template apply [--dry-run] wp ultimate-security template undo wp ultimate-security export [--file=] wp ultimate-security import [--dry-run] wp ultimate-security status wp ultimate-security unlock | --ip= | --all wp ultimate-security 2fa disable wp ultimate-security captcha off wp ultimate-security login-url reset Video guides Learn more

安装:

Requirements: WordPress 5.6+ and PHP 7.1+. HTTPS is strongly recommended for 2FA and secure sessions. Install from your dashboard
  1. In WordPress, go to Plugins → Add New and search for "wpultimatesecurity".
  2. Click Install Now, then Activate.
  3. Follow the Security Wizard that appears — it scans your site, recommends settings, and shows you every change before applying it.
Install manually
  1. Download the plugin ZIP.
  2. Go to Plugins → Add New → Upload Plugin, choose the ZIP, and click Install Now.
  3. Click Activate, then follow the Security Wizard.
Or with WP-CLI: wp plugin install ultimate-security --activate Your first 3 minutes
  1. Run the Security Wizard and apply the template that matches your site.
  2. Save the emergency link the wizard shows you somewhere safe. It gets you back in if you ever lock yourself out.
  3. Turn on two-factor login for every administrator.

屏幕截图:

  • Answer a few questions and the setup wizard secures your site. You see every change first and can undo it later.
  • Stop bots that guess passwords. Repeat offenders are locked out for longer.
  • Test Mode shows what would have been blocked, without blocking anyone.
  • Add a second step to login with an email code or an authenticator app.
  • Hide your login page and require strong passwords.
  • Stop spam bots on your login, comment and WooCommerce forms with reCAPTCHA or Cloudflare Turnstile.
  • Find plugins, themes and WordPress versions with known security holes, automatically.
  • Turn on ready-made Cloudflare firewall rules without writing any code.
  • See who is signed in right now and sign anyone out with one click.
  • Switch each feature on or off. Your site stays fast.
  • Bring your settings over from Wordfence Login Security, or copy them to another site.

升级注意事项:

1.0.36 Security and reliability update that includes everything since 1.0.29. Update as soon as you can. Your settings are kept. 1.0.29 Includes everything since 1.0.28; the internal builds in between never shipped. Security review fixes, plus lockout protection for sites behind a proxy or with a wrong CAPTCHA key. Update promptly. 1.0.28 Includes everything from 1.0.27, which was never released. Security hardening for bot protection and for what admin screens send to the browser, plus much faster admin pages. Update as soon as you can. 1.0.26 Settings and log screens load faster, old log rows are pruned after 90 days, and the plugin now runs on MariaDB and the SQLite used by WordPress Playground. No action needed after updating.

常见问题:

I locked myself out. How do I get back in?

Open the emergency link the setup wizard gave you. It switches the plugin off so you can log in and fix the setting. If you didn't save it, ask your host to rename the folder /wp-content/plugins/ultimate-security, or run wp plugin deactivate ultimate-security over SSH.

Will this slow down my site?

No. Checks run only when someone logs in or submits a form, not on every page view. Scans run in the background on a schedule.

Do I need any technical knowledge?

No. The setup wizard picks settings for your kind of site and shows every change before applying it. You can undo all of it later.

What is Test Mode?

A safe way to try your settings. Your protections run, but nobody is blocked; instead you get a log of what would have been blocked. Once you are happy, switch it off to enforce the rules. It turns itself off after seven days, so a forgotten test never leaves your site unprotected.

Can I undo what the wizard changed?

Yes. The wizard shows every change before applying it, and you can undo them all later. Changes you made yourself afterwards are kept.

Is it really free?

Yes. Everything described on this page is included, with no account, trial or time limit.

Do I need an API key for vulnerability scanning?

No. The scanner works straight away with the free WPVulnerability database. WPScan and Patchstack keys are optional and only add extra coverage.

Does it work with WooCommerce?

Yes. CAPTCHA can protect the WooCommerce login, registration, password reset and checkout forms, two-factor login works on the WooCommerce login form, and the wizard has a WooCommerce template.

Do I need a Cloudflare account?

Only for the Cloudflare firewall rules. Every other feature works without one.

I use Cloudflare or another CDN or proxy. Do I need to do anything?

For Cloudflare, no: it is recognised automatically. For any other proxy or load balancer, add its address under Brute-force protection → Trusted proxies. Until you do, the plugin avoids locking out everyone at once, and Site Health tells you what to add.

CAPTCHA is blocking every login. How do I recover?

Add define( 'ULTIMATE_SECURITY_DISABLE_CAPTCHA', true ); to wp-config.php to switch CAPTCHA off, log in, re-enter your Site Key and Secret Key, then remove the line. To turn off just one provider, use ULTIMATE_SECURITY_DISABLE_TURNSTILE or ULTIMATE_SECURITY_DISABLE_RECAPTCHA. Over SSH, wp ultimate-security captcha off does the same. Site Health warns you when a key stops working.

Will it conflict with other security or CAPTCHA plugins?

It can if two plugins do the same job. Use one plugin per job (one for two-factor, one for CAPTCHA, one for login limits) and switch the overlapping feature off in the other. Ultimate Security warns you when it spots an overlap.

I already use another security plugin. Can I bring my settings across?

You can import two-factor and login settings from Wordfence Login Security. You see exactly what will come across first, and can undo the import afterwards.

Does the custom login URL work with caching and CDNs?

Yes. Make sure your caching plugin doesn't cache the login page; most skip login and admin pages automatically.

Does it work with Redis or Memcached?

Yes. Give the cache enough memory so it doesn't drop entries early, or a lockout can end sooner than you set.

Does it work on WordPress Multisite?

It runs on Multisite, with settings per site. It has been tested less there than on single sites, so try it on a staging network first.

Does the plugin track me or phone home?

No. There is no usage tracking. It contacts an outside service only when you use a feature that needs one, and each is listed under External Services below.

What does the plugin store about my visitors?

IP addresses and browser details are kept in the session log so you can review sign-ins. Test Mode keeps its own log of what it would have blocked. Everything stays in your own database.

Is it GDPR-friendly?

Your data stays on your own server. Outside calls are limited to the services listed under External Services, and only for features you turn on.

What happens to my data when I uninstall?

By default your settings are kept, in case you reinstall. To remove everything, turn on "delete plugin data" in the plugin's advanced settings before uninstalling.

How do I get support?

Ask in the plugin's support forum on WordPress.org, or visit https://www.wpultimatesecurity.com.

更新日志:

1.0.40 1.0.36 This update includes everything since 1.0.29; the versions in between were never released. It strengthens login security, adds new two-factor and lockout controls, fixes a long list of everyday problems and gives the plugin a cleaner, more consistent look. We recommend every site updates. Security Earlier versions See the full history at https://wpultimatesecurity.com/changelog/