Linux 软件免费装
Banner图

WordSentinel

开发者 victorlago
maxouhell
guerricm
nexsol
更新时间 2025年10月24日 17:17
PHP版本: 7.0 及以上
WordPress版本: 6.8
版权: GPLv3
版权网址: 版权信息

标签

security WordPress headers firewall SSL CSP

下载

1.0.1 1.0.2 1.2.0 1.2.1

详情介绍:

The WordSentinel plugin by Nexsol Technologies Sàrl enhances your WordPress website’s security by automatically applying and managing HTTP security headers — including Content Security Policy (CSP) — while providing live security analysis powered by Mozilla Observatory. Unlike simple header managers, WordSentinel actively helps you understand, measure, and improve your site’s protection.\ It provides clear dashboards, actionable insights, and real-time grading so you can reinforce your headers with confidence — no deep technical knowledge required. What WordSentinel Does WordSentinel helps protect your WordPress website against common web vulnerabilities such as: In addition, it connects securely to Mozilla Observatory to scan your site and assign a security grade (A+ to F), helping you benchmark your configuration and understand what needs improvement. Key Features Why Choose WordSentinel? WordSentinel merges modern web security standards with a simple and intuitive configuration experience — making it a must-have for both developers and site owners who care about protection and compliance.

安装:

  1. Install WordSentinel
  2. Upload the plugin files to /wp-content/plugins/wordsentinel/, or install it directly from the WordPress Plugin Directory.
  3. Activate the plugin through the Plugins screen in WordPress.
  4. Run Your First Security Scan
  5. Navigate to WordSentinel → Dashboard in your admin sidebar.
  6. The first scan should run automatically, but if not you can click “Launch Scan” to analyze your site with Mozilla Observatory.
  7. View your grade and detailed results instantly.
  8. Configure Your Security Headers
  9. Go to the Headers tab, you will see that all options are enabled by default, you can toggle on and off HTTP headers such as CSP, HSTS, and Referrer-Policy.
  10. Save changes if you made any and verify results with another scan by clicking on “Launch Scan” at the top of the dashboard.
  11. Review Your Site
  12. Test your website normally to ensure compatibility with your active theme and plugins.
  13. WordSentinel automatically excludes the Divi Builder admin pages from CSP enforcement for a smooth experience.
  14. (Optional) Activate Premium Features
  15. Enter your license key under WordSentinel → License to unlock the Advanced CSP tab.
  16. Premium users gain access to granular Content Security Policy management, automatic hashing, and advanced resource control.
Once activated, open the Advanced CSP tab to fine-tune how your website handles external resources and inline code.\ Each field corresponds to a specific type of resource that browsers enforce under the CSP standard: 💡 When a Resource is Blocked If your browser’s console shows an error such as: Refused to load the script from 'https://example.com' because it violates the Content Security Policy directive: "script-src 'self'" That means WordSentinel is actively protecting your website — the CSP is doing its job.\ To resolve the issue, simply copy the indicated domain (https://example.com) and add it to the corresponding source list (e.g. “Script Sources”) in the Advanced CSP tab.\ Save your changes, refresh your site, and the resource will load securely while keeping full CSP protection active. WordSentinel’s premium CSP module is designed to make advanced header configuration safe and understandable, even for non-developers — giving you both control and peace of mind.

屏幕截图:

  • The dashboard gives you an overview of your site's current ratings, scan history and benchmark comparison.
  • The dashboard gives you an overview of your site's current ratings, scan history and benchmark comparison.
  • The dashboard gives you an overview of your site's current ratings, scan history and benchmark comparison.
  • WordSentinel lets you configure which header is active.
  • Advanced CSP configuration panel, in this tab you can whitelist the external resources and assure a fully functional website without lowering the level of protection.

升级注意事项:

No upgrade notices available yet.

常见问题:

  1. What are HTTP security headers?

HTTP security headers tell browsers how to handle your site’s resources safely, helping to prevent data leaks and malicious injections.

  1. Do I need coding skills to use WordSentinel?

No. Everything is managed through an intuitive interface with clear explanations and automatic validation.

  1. Why does the “Scan” button have a cooldown?

To comply with Mozilla Observatory’s API limits and prevent overloading the service, scans are limited to one per site every few minutes.

  1. Will WordSentinel conflict with my caching or firewall plugins?

No. WordSentinel adds headers at the HTTP level and is compatible with most caching, CDN, and security tools including Wordfence and Cloudflare.

更新日志:

1.2.1 – October 24, 2025 1.2.0 – October 24, 2025 1.1.0 – June 6, 2025 1.0.2 – March 1, 2025 1.0 – February 2025