Linux 软件免费装
Banner图

Witen Blocker — Login Lockout, 2FA & AI Crawler Blocking

开发者 witenlabs
更新时间 2026年10月4日 09:35
PHP版本: 8.1 及以上
WordPress版本: 7.1
版权: GPL-2.0-or-later
版权网址: 版权信息

标签

login security two factor limit login attempts bot blocker block ai crawlers

下载

0.6.49 0.6.48 0.6.46 0.6.47 0.6.50

详情介绍:

Witen Blocker helps protect your WordPress site from password guessing, unwanted bots, and comment spam. Add two-factor authentication, check suspicious file changes, and review detections and blocks in your WordPress dashboard. Start with free local protection. Connect to Witen when you want blocklists informed by attacks seen across participating sites and servers. Protect your logins Limit repeated failed login attempts and add two-factor authentication with an authenticator app. Recovery codes give you a way back in if you lose your device. Block known exploit requests Built-in checks block template traversal and comment exploit requests before they reach the affected WordPress handlers. These checks work without an account. Keep WordPress, themes, and plugins updated as well. Decide which bots can visit Choose which recognized search crawlers, AI crawlers, and automated clients to allow or block. Manage trusted addresses and review detections before blocking. Cut down comment spam Catch automated submissions with hidden form fields and timing checks. These checks run on your site without sending comment text to a spam service. Find unexpected file changes Compare WordPress core files with official checksums, monitor changes in your content directory, and scan files for suspicious patterns. Bundled checks work without an account. Connected sites can receive maintained malware catalogs. Review findings before taking action. Learn from attacks beyond your own site The optional Witen service combines security reports from participating sites and servers to identify repeat attackers and maintain shared blocklists. An enrolled site can block listed IPs even if they haven't attacked that site before. Reports are processed centrally; request checks use a local blocklist. Connecting requires a Witen account and security-event sharing. All local features are free, with no trial expiry. Free connected WordPress sites receive a daily threat-feed update without an added data delay. Paid plans add more sites and servers, other feed profiles, and optional off-site backup storage. Run on shared hosting or your own server On shared hosting, matching blocklist requests receive an HTTP 403 response from WordPress. No server administration access is needed. On your own server, the optional Witen Warden agent can enforce IP blocks at the firewall, before blocked traffic reaches PHP. Get started: activate Witen Blocker and open Witen > Dashboard. Local protection needs no account. Use Login for login limits and two-factor setup, and Firewall > Bots and AI crawlers to choose which crawlers can visit. Setup guide | Witen plans | Support

安装:

  1. Open Plugins > Add New Plugin, search for Witen Blocker, and install and activate it. You can also upload the plugin ZIP.
  2. Open Witen > Login to review login limits and set up two-factor authentication for your account. In Firewall, choose your bot rules and add your own trusted addresses to the never-block list.
  3. To add shared intelligence, create a Witen account, add your WordPress site from the dashboard, and enter its one-time setup token in Witen > Settings. Review the terms and privacy information before connecting.
  4. Check the connection and blocklist status after background maintenance runs.
See the setup guide to connect a local Warden agent or configure your site through wp-config.php.

屏幕截图:

  • Per-crawler AI policies: choose which recognized crawlers are allowed or blocked.
  • Login limits, two-factor setup links and a custom login address in one place.
  • File integrity and malware scan controls, with unscanned state shown accurately.

升级注意事项:

0.6.50 Review login limits in Settings. Login constants now take effect when no saved override exists. Existing settings and connection details are preserved.

常见问题:

What can I use without an account?

Login limits, two-factor authentication, comment spam checks, bot controls, file-integrity checks, bundled malware checks, and the .htaccess editor. Connecting to Witen adds hosted intelligence and reporting; it is optional.

Will it slow down my site?

Normal request checks use local data and do not wait for a remote service. Updates, reporting, and scans run in background jobs and use server resources. On quiet sites, WordPress cron may wait for a visitor before running jobs.

Can I use it alongside another security plugin?

Check for overlapping two-factor, login, bot, and .htaccess settings. Test your login and site after changes. Keep WordPress, themes, and plugins updated, and maintain a backup.

How do I change login limits or recover from a lockout?

Open Witen > Login > Login lockout to set the failure window, failure count, and ban duration. Defaults are 5 failures in 5 minutes and a 1-hour ban. Saved settings override WITEN_LOGIN_WINDOW_SEC, WITEN_LOGIN_MAX_FAILURES, and WITEN_LOGIN_BAN_SEC in wp-config.php. The same controls remain available in Settings. Keep your 2FA recovery codes. If locked out, wait for the ban to expire or follow the recovery guide, including WP-CLI and SFTP steps. Deactivation leaves existing .htaccess and Warden firewall rules in place; the guide explains how to remove them.

Does a scan finding mean my site is hacked?

Not necessarily. A changed file or suspicious pattern needs review; legitimate customizations can produce findings. Witen helps identify files to investigate. It does not automatically clean an infected site.

What happens if Witen is unavailable?

Local protection continues. Cached intelligence is usable until it expires, and reports queue for background retries within the limits below. Warden socket mode does not fall back to a direct collector connection.

Does it support multisite?

Yes. Each site has its own settings, connection, logs, and jobs, initialized on its first request. The main site's network administrator controls shared .htaccess. User accounts and two-factor setup are network-wide. Connect each site separately if you use a local Warden agent.

更新日志:

0.6.50 0.6.49