Linux 软件免费装

VMP Wordpress Security - Firewall, Malware Scan

开发者 tanveer269
更新时间 2025年12月11日 21:07
PHP版本: 7.4 及以上
WordPress版本: 6.8
版权: GPLv2 or later
版权网址: 版权信息

标签

security protection firewall malware vulnerability scanner brute force waf

下载

1.0.0 2.0.0

详情介绍:

COMPREHENSIVE WORDPRESS SECURITY WITH ADVANCED FIREWALL VMP Wordpress Security provides complete protection for WordPress websites through an advanced multi-scanner architecture combined with a powerful Web Application Firewall. Our plugin features 11 specialized security scanners and comprehensive firewall protection that work together to detect malware, vulnerabilities, block attacks, and protect against security threats. VMP Wordpress Security includes Web Application Firewall (WAF), brute force protection, rate limiting, malware detection, file integrity monitoring, vulnerability scanning, user security analysis, and comprehensive threat protection. 🔥 WEB APPLICATION FIREWALL (WAF) - NEW IN 2.0 🛡️ BRUTE FORCE PROTECTION - NEW IN 2.0 ⚡ RATE LIMITING & THROTTLING - NEW IN 2.0 🚫 ADVANCED BLOCKING FEATURES - NEW IN 2.0 🛡️ MULTI-SCANNER SECURITY ARCHITECTURE 🔍 MALWARE DETECTION & FILE SCANNING 🚨 VULNERABILITY & THREAT DETECTION ⚙️ SCAN CONFIGURATION & MANAGEMENT 🔧 FIREWALL CONFIGURATION & MANAGEMENT - NEW IN 2.0 📊 ADMIN INTERFACE & REPORTING 🔧 ADVANCED FEATURES

安装:

Secure your website with VMP Wordpress Security in just a few steps:
  1. Install VMP Wordpress Security through the WordPress plugin directory or upload the ZIP file
  2. Activate VMP Wordpress Security through the 'Plugins' menu in WordPress
  3. Navigate to VMP Wordpress Security > Dashboard to access the security interface
  4. Navigate to VMP Wordpress Security > Firewall to configure firewall protection
  5. Configure your scan preferences using the scan configuration options
  6. Run your first security scan from VMP Wordpress Security > Scan
  7. Review and address any security issues found in the scan results
  8. Set up scheduled scans and enable firewall protection for ongoing automated security

屏幕截图:

  • Security Dashboard with firewall status, scan status, and notifications overview
  • Comprehensive Scan Interface showing real-time scan progress and security statistics
  • Comprehensive Scan Interface showing completed scan results with details and appropriate actions.
  • Scan options including  Scan Scheduling, Scan Type, General, Performance, Advanced scan options.
  • Firewall Dashboard showing WAF protection status, brute force protection, and attack statistics
  • Firewall Options page with comprehensive WAF, brute force, and rate limiting settings

升级注意事项:

2.0.0 Major update with complete Web Application Firewall (WAF) and brute force protection. Recommended for all users. Adds 150+ WAF rules, rate limiting, attack logging, and advanced blocking features. Review firewall settings after upgrade. 1.0.0 Initial release. Install to enable comprehensive WordPress security scanning and protection.

常见问题:

What is the Web Application Firewall (WAF)?

The WAF is a real-time security layer that inspects all incoming traffic to your website and blocks malicious requests before they reach WordPress. It protects against XSS, SQL injection, file inclusion attacks, and other common web vulnerabilities using pattern-based detection with 150+ built-in security rules.

How does brute force protection work?

VMP Wordpress Security monitors login attempts and automatically locks out IP addresses after a configurable number of failed logins. It can also block invalid usernames immediately, enforce strong passwords, and check credentials against known breach databases to prevent compromised password usage.

What is rate limiting?

Rate limiting prevents abuse by restricting how many requests an IP address can make within a time period. This protects against content scraping, resource exhaustion, and vulnerability scanning. You can configure different limits for humans, crawlers, and error pages with options to throttle or block violators.

Can I whitelist my own IP address?

Yes. Navigate to Firewall > Options > Advanced Firewall Options and add your IP address to the "Allowlisted IP addresses that bypass all rules" field. Whitelisted IPs bypass all firewall rules including WAF, rate limiting, and brute force protection.

How do I manage WAF rules?

Go to Firewall > WAF Rules to see all available rules organized by attack category (XSS, SQLi, RFI, LFI, RCE, etc.). You can enable/disable individual rules, view rule details, and filter by category or action type. 150+ default rules are included and automatically installed.

What happens when an attack is blocked?

Blocked attacks are logged in the firewall attack log with details including IP address, timestamp, attack type, violated rules, and severity score. The attacker receives a 403 Forbidden page with security information. Repeat offenders can be automatically permanently blocked based on your settings.

Does the firewall affect website performance?

No. The WAF is optimized for minimal performance impact using efficient pattern matching and caching. Rate limiting only affects traffic that exceeds configured thresholds. Normal legitimate visitors experience no slowdown or interruption.

What types of security threats does VMP Wordpress Security detect?

VMP Wordpress Security detects a comprehensive range of security threats including malware, backdoors, trojans, suspicious file changes, plugin/theme vulnerabilities, compromised user accounts, spam content injection, malicious URLs, exposed configuration files, brute force attacks, XSS, SQL injection, and various forms of code injection attacks.

How does the multi-scanner architecture work?

VMP Wordpress Security uses 11 specialized scanners that each focus on specific security aspects. The Server State Scanner checks configuration, File Changes Scanner monitors file integrity, Malware Scanner detects malicious code, Vulnerability Scanner identifies security flaws, and so on. This modular approach provides comprehensive coverage while maintaining performance.

What scan types are available?

VMP Wordpress Security offers four scan types:

  • Limited: Quick scan focusing on critical security checks and core files
  • Standard: Balanced scan covering most security aspects with good performance
  • High Sensitivity: Deep comprehensive scan with maximum threat detection
  • Custom: Fully configurable scan where you can enable/disable individual scanner modules

Can VMP Wordpress Security repair infected files automatically?

VMP Wordpress Security focuses on detection and detailed reporting of security issues. While it identifies infected files and provides comprehensive analysis, VMP Wordpress Security offers repair options that you can execute manually for infected files. The plugin provides safe file restoration capabilities, but repairs require user confirmation to ensure complete and safe remediation.

How does the Google Safe Browsing integration work?

VMP Wordpress Security integrates with Google's Safe Browsing API to check URLs found in your content, posts, and comments against Google's database of known malicious websites, phishing sites, and malware distribution points. This helps identify compromised content early.

Does VMP Wordpress Security affect my website's performance?

No. VMP Wordpress Security is designed for optimal performance with background scanning, intelligent resource management, and optimized algorithms. Scans run independently without affecting your website's front-end performance or user experience.

What file types can VMP Wordpress Security scan?

VMP Wordpress Security can scan PHP files, JavaScript, CSS, WordPress core files, theme files, plugin files, configuration files, and optionally binary files including images and executables for embedded threats.

How does scheduled scanning work?

VMP Wordpress Security includes a flexible scheduling system that can run automatic scans at specified intervals (daily, twice daily, weekdays, weekends, or custom schedules). The scan monitor system ensures scans complete successfully and can automatically recover from interrupted scans.

Can I exclude certain files or directories from scanning?

Yes. VMP Wordpress Security provides flexible exclusion options allowing you to exclude specific files, directories, or file patterns from scanning. This is useful for large media directories, custom code, or known safe files that might trigger false positives.

What happens when VMP Wordpress Security finds a security issue?

When security issues are detected, VMP Wordpress Security provides detailed reports with issue classification, severity ratings, affected files, and remediation recommendations. You can choose to ignore false positives, repair infected files, or take manual action based on the findings.

Does VMP Wordpress Security work with multisite installations?

Yes. VMP Wordpress Security is fully compatible with WordPress multisite (network) installations and can scan all sites in your network while providing centralized management and reporting.

What notifications does VMP Wordpress Security provide?

VMP Wordpress Security provides comprehensive security reporting and activity logging for all scan results and security events. The plugin tracks scan completion, threat discoveries, and security activities through detailed logs accessible via the admin interface.

更新日志:

2.0.0 - December 11, 2025 MAJOR UPDATE: Advanced Firewall Protection 1.0.0 - September 29, 2025