Linux 软件免费装
Banner图

Ultimate Security – Vulnerability Scanner, 2FA, and Login Protection

开发者 programmelab
wpultimatesecurity
更新时间 2026年9月15日 04:50
捐献地址: 去捐款
PHP版本: 7.1 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

captcha security two factor authentication login security vulnerability scanner

下载

1.0.21 1.0.16 1.0.24 1.0.22 1.0.25 1.0.5 1.0.4 1.0.6 1.0.10 1.0.3 1.0.7 1.0.8 1.0.9 1.0.14 1.0.13 1.0.11 1.0.29 1.0.1 1.0.0 1.0.15 1.0.18 1.0.12 1.0.17 1.0.19 1.0.20 1.0.2 1.0.23 1.0.26 1.0.28

详情介绍:

Ultimate Security handles the traffic that actually reaches a WordPress site: automated login attempts, brute-force runs, comment and form spam, and probes at well-known paths. It covers two-factor authentication, login lockouts, CAPTCHA, a movable login URL, session controls, vulnerability scanning, and Cloudflare edge rules — set up from one admin screen, without editing files or writing firewall rules by hand. [youtube https://www.youtube.com/watch?v=MU7KivId-cE] There is no usage tracking and nothing phones home. The plugin contacts an outside service only when you switch on a feature that needs one, and each is listed under External Services below. Features that belong to the Pro add-on are labelled as such. Setup wizard The first run is a five-step wizard. You answer a few questions about the site, it runs a quick scan, and you pick one of seven starting templates: basic, moderate, strict, agency, blog, membership, or WooCommerce. Before it changes anything it shows you a full diff, and you can undo everything it did later without losing edits you made yourself. It also gives you an emergency access link — keep it somewhere safe, and you can switch the plugin off from a browser if you ever lock yourself out. Two-factor authentication Login access control Password policies Brute-force protection Session management CAPTCHA and spam Vulnerability scanning Cloudflare WAF rules Connect your own Cloudflare account and manage edge rules from wp-admin. [youtube https://www.youtube.com/watch?v=W2v08QaSCl4] Security keys (salts) Update manager Monitoring, security score and logs Test mode Run your rules without blocking anyone and review a log of what would have been blocked before you enforce it. Choose which roles it applies to (or leave the list empty for every role), keep admins excluded, and an admin-bar marker plus a dashboard notice remind you it's on. Login limits for visitors who are not signed in are always enforced, even in Test Mode, and Test Mode switches itself off after seven days so a forgotten test cannot leave protections off. Tools, migration and backup Works with what you already run Ultimate Security detects and adapts to WooCommerce, Ultimate Member, common page builders, form plugins, caching plugins and SEO plugins, and warns you when another security plugin is already doing the same job. WP-CLI wp ultimate-security template list wp ultimate-security template apply [--dry-run] wp ultimate-security template undo wp ultimate-security export [--file=] wp ultimate-security import [--dry-run] wp ultimate-security status wp ultimate-security unlock | --ip= | --all wp ultimate-security 2fa disable wp ultimate-security captcha off wp ultimate-security login-url reset Learn more

安装:

Requirements: WordPress 5.6+ and PHP 7.1+. HTTPS is strongly recommended for 2FA and secure sessions. 📘 Full setup walkthrough: Documentation · Video tutorials Install from your dashboard
  1. In WordPress, go to Plugins → Add New and search for "wpultimatesecurity".
  2. Click Install Now, then Activate.
  3. Follow the Security Wizard that appears — it scans your site, recommends settings, and shows you every change before applying it.
Install manually
  1. Download the plugin ZIP.
  2. Go to Plugins → Add New → Upload Plugin, choose the ZIP, and click Install Now.
  3. Click Activate, then follow the Security Wizard.
Or with WP-CLI: wp plugin install ultimate-security --activate Recommended first 5 minutes
  1. Run the Security Wizard and apply a template that matches your site.
  2. Enable 2FA for all administrator accounts.
  3. Set login attempt limits and a lockout duration.
  4. Add CAPTCHA (reCAPTCHA or Cloudflare Turnstile) to your login, registration and comment forms.
  5. Set a custom login URL, save it somewhere safe, and store the emergency access link the wizard showed you.
  6. Run a vulnerability scan, then review the Security Score and Site Health before enabling stricter rules.

屏幕截图:

  • The setup wizard asks what kind of site this is, runs a 30-second check, offers seven ready-made templates, and lists every change before it applies. Undo any time.
  • Brute-force protection you can read: attempts allowed, lockout length, escalating lockouts, a retry-reset window, a permanent block list, and a one-time recovery link if you lock yourself out.
  • Test Mode runs your protections without enforcing them and logs what would have been blocked, so you can review before anyone is locked out.
  • Two-factor sign-in with email codes or an authenticator app (TOTP and HOTP), required per role, on WordPress, WooCommerce and Ultimate Member login forms.
  • Move wp-login.php to a private address, set password rules, and check new passwords against known breaches by k-anonymity. The password never leaves the site.
  • reCAPTCHA v2/v3 or Cloudflare Turnstile on the forms bots hit: login, registration, password reset, comments and WooCommerce. No-conflict mode and fail-open included.
  • The vulnerability scanner checks plugins, themes and core against the keyless WPVulnerability database, flags abandoned plugins, and runs on a schedule. WPScan and Patchstack are optional.
  • Cloudflare WAF rules without writing expressions: six rule groups, virtual patches for known core CVEs, and a preview of the generated expressions before you deploy to your own Cloudflare account.
  • See everyone signed in, with device, browser and IP, and end any session with one click. The security score breakdown shows which checks hold back the next level.
  • Every feature is a module with a switch. Checks run on login and form submission, not on every page view, and pages with no forms, widgets or CAPTCHA load no plugin CSS or JS.
  • Switching is safe: import 2FA and login settings from Wordfence Login Security with a preview and rollback, and move your own settings between sites as JSON.

升级注意事项:

1.0.29 Includes everything since 1.0.28; the internal builds in between never shipped. Security review fixes, plus lockout protection for sites behind a proxy or with a wrong CAPTCHA key. Update promptly. 1.0.28 Includes everything from 1.0.27, which was never released. Security hardening for bot protection and for what admin screens send to the browser, plus much faster admin pages. Update as soon as you can. 1.0.26 Settings and log screens load faster, old log rows are pruned after 90 days, and the plugin now runs on MariaDB and the SQLite used by WordPress Playground. No action needed after updating.

常见问题:

Will this slow down my site?

It is built to stay lightweight — security checks run on login and form submission, not on every page view. Vulnerability scans run on a schedule in the background, not during visitor requests.

Do I need any technical or coding knowledge?

No. The setup wizard scans your site, recommends settings, and shows you every change before it is applied — and you can undo all of it. Every setting is in plain English.

I enabled 2FA or a custom login URL and locked myself out. How do I get back in?

Use the emergency deactivation URL the setup wizard showed you — open it in a browser and the plugin switches itself off. If you did not save it, deactivate the plugin manually: over FTP/SFTP rename the folder /wp-content/plugins/ultimate-security, or over SSH run wp plugin deactivate ultimate-security. Then log in and reconfigure.

CAPTCHA is blocking every login (wrong keys, or after changing my security keys). How do I recover?

Add define( 'ULTIMATE_SECURITY_DISABLE_CAPTCHA', true ); to wp-config.php to switch off both reCAPTCHA and Turnstile, or ULTIMATE_SECURITY_DISABLE_TURNSTILE / ULTIMATE_SECURITY_DISABLE_RECAPTCHA for one provider. This fully disables rendering and verification so you can log in. Then re-enter your Site Key and Secret Key in the plugin settings and remove the constant. Site Health and an admin notice tell you when a stored key has been rejected by the provider or has become unreadable after a salt change. The constant requires server access, so it is never a public bypass. Over SSH, wp ultimate-security unlock --all clears login lockouts, wp ultimate-security captcha off switches CAPTCHA off on every form, wp ultimate-security 2fa disable <user> removes a user's two-factor methods and wp ultimate-security login-url reset restores wp-login.php. A used login-recovery link also lets that address through the login CAPTCHA for 15 minutes.

I use Cloudflare or another CDN or proxy. Do I need to do anything?

Usually not for Cloudflare: requests arriving from Cloudflare's published ranges are recognised and the real visitor address is used. For any other proxy or load balancer, add its address under Brute-force protection → Trusted proxies (hosts can set the ULTIMATE_SECURITY_TRUSTED_PROXIES constant instead). Until you do, every visitor looks like the proxy, so the plugin suspends site-wide IP lockouts to avoid locking everyone out, and Site Health shows a critical notice telling you what to add.

Do I need an API key for vulnerability scanning?

No. The scanner works out of the box using the keyless WPVulnerability database. WPScan and Patchstack API keys are optional and only add extra coverage.

Does it work with WooCommerce?

Yes. Both reCAPTCHA and Cloudflare Turnstile can protect WooCommerce login, registration, lost-password and checkout forms, and there is a WooCommerce setup template in the wizard.

Do I need a Cloudflare account to use this plugin?

Only for the WAF Rules section. Those rules are deployed to your own Cloudflare zone, so they need a Cloudflare account and an API token. Every other feature works without one.

Does it work with a persistent object cache (Redis, Memcached)?

Yes. Login lockouts, two-factor sign-in sessions and similar short-lived state are stored as WordPress transients, so with a persistent object cache they live in that cache instead of the database. Give the cache enough memory that it does not evict entries early, or a lockout can end sooner than configured.

Does it work on WordPress Multisite?

The plugin activates and runs on Multisite, and its uninstall routine is network-aware. It has not been tested as extensively on Multisite as on single-site installs, so validate on a staging network first and configure settings per site.

Does the custom login URL work with caching and CDNs?

Yes. Exclude the login path from full-page caching (most caching plugins do this for login and admin pages automatically) so the secret URL is never served from cache.

Will it conflict with other security or CAPTCHA plugins?

It can if two plugins do the same job. Pick one plugin per function (one 2FA, one CAPTCHA, one login limiter) and disable the overlapping feature in the other. Ultimate Security detects common security plugins and warns you.

I already use another security plugin. Can I bring my settings across?

Settings can be imported from Wordfence Login Security. You get a preview of exactly what will be imported before anything is applied, and you can roll the import back afterwards.

Does the plugin track me or phone home?

No. Ultimate Security does not collect product-usage telemetry. It contacts third-party services only when you use a feature that requires one, and every one of those is listed under External Services below.

What does the plugin store about my visitors?

IP addresses and user agents are recorded in the activity and session logs so you can investigate login attempts, with a retention period you control (30 days by default). Test Mode keeps its own log of what would have been blocked. "Who's online" rows expire after 60 seconds. Nothing is sent off your site except through the services listed below.

Is it GDPR-friendly?

The plugin is self-hosted and stores its data in your own database. Outbound calls are limited to the feature-specific services listed under External Services, such as reCAPTCHA, Turnstile, the vulnerability databases and WordPress.org APIs.

What happens to my data when I uninstall?

By default the plugin leaves its data in place. If you enable the "delete plugin data" option in the plugin's advanced settings before uninstalling, its database tables, options and user meta are removed on uninstall.

What is the difference between Free and Pro?

Everything described on this page is in the free plugin: the setup wizard, email and app-based 2FA, brute-force lockout, custom login URL, password policies, session management, reCAPTCHA and Turnstile, vulnerability scanning, Cloudflare WAF rules, security-key rotation (on demand and scheduled), the Update Manager's policies, windows and notifications, Security Score, activity logs, core file-integrity checking, Site Health, Test Mode, Wordfence migration, and settings backup and restore. The score counts only checks the free plugin can satisfy, so every level is reachable without Pro. Ultimate Security Pro is a separate add-on that requires this free plugin and adds further authentication, monitoring, automation and maintenance features not included here.

How do I get support?

Use the plugin support forum on WordPress.org, or visit https://www.wpultimatesecurity.com.

更新日志:

1.0.29 This update includes everything since 1.0.28 and follows a full security review of the plugin. Most of that work happens behind the scenes; below is what you will notice. If your site sits behind Cloudflare, a CDN or a proxy, or you use CAPTCHA on your login form, update promptly. Login protection 1.0.28 Includes everything from 1.0.27, which was never released. Security 1.0.26 1.0.25 1.0.24 1.0.23 1.0.22 1.0.21 1.0.20 1.0.19 1.0.18 1.0.17 1.0.16 1.0.15 1.0.14 1.0.13 1.0.12 1.0.11 1.0.10 1.0.9 1.0.8 1.0.7 1.0.6 1.0.5 1.0.4