Linux 软件免费装
Banner图

VCNS Security Automation Manager

开发者 vcnstech
更新时间 2026年9月18日 00:35
PHP版本: 8.1 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security csp content security policy hsts ssl certificates

下载

2.10.1 2.11.1 2.9.27 2.9.28 2.9.29 2.9.26 2.9.30 2.9.68 2.9.75

详情介绍:

Turning on strict security headers usually means picking between two bad options: leave Content-Security-Policy off and stay exposed, or turn it on and watch it silently break your checkout page, your embedded videos, or your analytics -- with no warning before it happens. Security Automation Manager takes a third option. It watches your site quietly first, in report-only mode, learning exactly which scripts, styles, and fonts your site actually loads -- nothing gets blocked while it learns. Once you can see the whole picture, you approve a policy built from your real site, not a guess. Only then does it start enforcing. You don't need to know what CSP means to use this The first time you open the plugin, a short, skippable Welcome page asks how you'd like security information explained to you -- nothing more. Answer it or skip it: either way, your Settings page then leads with a plain-language scorecard (how many controls are Protected, still Learning, or Needs your attention), a Protection Status table using six consistent words instead of protocol names, and a consolidated Action Centre for anything worth reviewing. Prefer the technical names and raw evidence instead? Choose Technical presentation and every detail is expanded by default. These are personal display preferences, stored per WordPress user -- they never change how your site is actually protected, and the full technical dashboards this plugin has always had remain exactly where they were. Everything below is free, with nothing held back The WordPress.org edition is a complete free plugin with no subscription-locked functionality. VCNS also distributes a separate commercial edition that includes Fully Automatic mode and associated commercial services. Built for the moment things go wrong, not just the moment you install it Every policy change is written to an append-only audit log, with a reason recorded. Conflict detection catches another plugin or your host quietly emitting a competing security header before it confuses you. Nothing enforces without a report-only learning period first, on every pillar that supports one. For the technically curious CSP ships per-surface profiles, nonce injection, source discovery, violation reporting, policy-change review, and readiness checks, alongside conflict detection for any CSP header already being emitted elsewhere. Seven more pillars (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Strict-Transport-Security, Cross-Origin-Resource-Policy, X-Permitted-Cross-Domain-Policies) are straightforward per-surface toggles. Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy get their own lighter report-only workflow via the browser Reporting API (Chromium-based browsers only, as of this writing). Certificates issues and renews via ACME DNS-01 or HTTP-01 domain validation, with credentials and private keys encrypted at rest, deploying via cPanel, filesystem export, or manual download.

更新日志:

2.11.1 2.11.0 2.10.1 2.10.0 2.9.107 2.9.106 2.9.105 2.9.104 2.9.103 2.9.102 2.9.101 2.9.100 2.9.99 2.9.98 2.9.97 2.9.96 2.9.95 2.9.94 2.9.93 2.9.92 2.9.91 2.9.90 2.9.89 2.9.88 2.9.87 2.9.86 2.9.85 2.9.84 2.9.83 2.9.82 2.9.81 2.9.80 2.9.79 2.9.78 2.9.77 2.9.76 2.9.75 2.9.74 2.9.73 Full changelog history: https://github.com/vcns/security-automation-manager/blob/main/CHANGELOG.md