Linux 软件免费装
Banner图

WordSec – Malware Scanner & Removal, Web Application Firewall (WAF), and 2FA

开发者 wordsec
更新时间 2026年8月1日 22:44
PHP版本: 7.4 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

security firewall malware scanner malware removal waf

下载

1.0.10 1.1.0 1.0.5 1.0.4 1.0.6 1.0.7 1.0.3 1.0.8 1.0.9

详情介绍:

WordSec is a complete WordPress security plugin. Eight modules cover the firewall, malware scanner, login security, live traffic, IP and country blocking, supply-chain intelligence, audit log and alerts, so you block attacks and harden your site from one dashboard instead of installing eight plugins. If your site gets hacked you do not just lose the site. You lose customer trust, your search rankings, and days of work restoring backups. WordSec is built to stop that before it happens, and to help you recover if it already has: the scanner finds the malware, quarantine takes it out of the way, and modified core, plugin and theme files are repaired from their original copies. Free, and no license key to enter. WAF firewall rules, malware and file-integrity scanning, brute force protection, two factor authentication, IP and country blocking, the audit log and one-click hardening all run locally on your own server. Web Application Firewall (WAF) Malware Scanner and Removal Login Security, Two-Factor Authentication (2FA) and Brute Force Protection Live Traffic IP and Country Blocking Supply Chain and Threat Intelligence Audit Log Alarms

安装:

  1. Upload the plugin files to /wp-content/plugins/wordsec/, or install through the WordPress Plugins screen.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Open the WordSec menu to start configuring.
Activation only creates the plugin's database tables, default settings and its own data directory. WordSec never modifies .htaccess, .user.ini or wp-config.php, changes file permissions, or installs the pre-WordPress WAF bootstrap without an explicit, clearly-labelled action from you, and deactivation reverts every such change.

屏幕截图:

  • Malware & Integrity Scanner: a seven-stage scan across files, database and scheduled tasks, with quarantine and restore.
  • Login Security: role-based two-factor authentication, multiple CAPTCHA providers, and brute-force protection.
  • Live Traffic Monitor: real-time traffic with historical replay and safe request inspection.
  • IP & Geo Blocking: country and continent lists, IP and CIDR blocking, and rate limiting.
  • Plugin & Theme Intelligence: reputation scoring, vulnerability alerts, and update-integrity checks.
  • Audit Log: complete activity tracking across object types and actions.
  • Real-Time Security Alerts: 36 event types delivered by email, Telegram or Slack.

升级注意事项:

1.1.0 Fixes a two-factor authentication lockout that could occur after uninstalling the plugin with a data-removal option and reinstalling it later. 1.0.10 External IP lookups now happen only on your click in the Live Traffic IP details window; traffic logging never contacts ipwhois.io, so the lookup quota is no longer spent in the background. 1.0.9 Important fix for sites running WordPress from a subdirectory: Login URL Rename locked administrators out, the uploads exception for sensitive-file blocking did not apply, and several other protections silently did nothing. Update if your site is not installed at the domain root. 1.0.8 Important fix for File Permission Hardening: it set the root .htaccess to a mode the web server cannot read, which returned 403 for every request on Plesk and cPanel style hosts. Update if you use this option, the malware scanner's Fix All, or the security score's automatic fixes. 1.0.7 Fixes user-enumeration hardening so it blocks ID probes without hiding normal author pages, corrects a dark-mode scanner dialog, and unifies the visitor block page across the WordPress and pre-WordPress firewalls. 1.0.6 Scanner accuracy release: detects unexpected extra files in plugin/theme folders, fixes false "Changed Theme File" findings on bundled default themes and a false "not hosted on WordPress.org" repair error, and repairs now fetch originals straight from WordPress.org SVN. 1.0.5 Fixes a scanner false positive that flagged WordSec's own unmodified files as potential malware. 1.0.4 New guided setup wizard, malware scanner and visual improvements, bug fixes, and automatic security-data download on license activation. 1.0.3 Consent and compliance release: server configuration changes are now explicit opt-ins with full reversal, external IP lookups are off by default, and reputation scoring works without a key. 1.0.2 All local features now run free and unrestricted. 1.0.1 Maintenance release: security hardening, library updates and storage-location fixes. 1.0.0 Initial public release of WordSec.

常见问题:

Does WordSec slow down my site?

No. WordSec is built around minimal database queries, batch processing and smart caching so protection does not come at the cost of performance.

Do I need a license key to use WordSec?

No. WordSec installs and runs as a fully functional free plugin with local protection: the web application firewall (your own custom rules plus the built-in preset rules), brute-force and login protection, two-factor authentication, hardening, geo-blocking configuration, the audit log and more all work without any key.

Does it require any external service?

No, not to run. WordSec's core protection runs locally on your server, and with no license key it contacts no external WordSec service at all.

Can WordSec help with malware removal on a hacked site?

Yes. The security scanner examines your files, the database and scheduled tasks, and every finding can be quarantined with one click. A modified WordPress core, plugin or theme file can also be repaired straight from its original copy on WordPress.org, and the scan history keeps a record of everything that was found and changed.

Does WordSec include brute force protection?

Yes. Failed logins are rate limited with progressive lockout, so each further attempt from the same source waits longer. You can also add a honeypot field, rename the login URL, require a CAPTCHA on the login form, and restrict logins by IP, country or time of day.

Does WordSec support two factor authentication?

Yes. Two factor authentication uses RFC 6238 TOTP codes from any standard authenticator app, and you choose which roles have to use it. For the case where a device is lost and nobody can get in, a WORDSEC_DISABLE_2FA constant in wp-config.php provides emergency access.

What does the web application firewall actually block?

The built-in rule sets cover SQL injection, cross-site scripting, path traversal, and PHP and command injection. You can add your own rules with a multi-condition builder, run the firewall in learning mode before you enforce anything, and optionally enable Extended Protection so requests are inspected before WordPress loads.

Can I run WordSec next to another security plugin?

You can, but it is not recommended. Two firewalls inspecting the same request, or two scanners walking the same files, cost you performance and produce duplicate alerts. WordSec is built to own site security end to end, so the usual path is to deactivate the others first.

What are the minimum requirements?

WordPress 6.9+, PHP 7.4+, and MySQL 5.6+ / MariaDB 10.1+.

更新日志:

1.1.0 1.0.10 1.0.9 1.0.8 1.0.7 1.0.6 1.0.5 1.0.4 1.0.3 1.0.2 1.0.1 1.0.0