| 开发者 | marcelloruoppolome |
|---|---|
| 更新时间 | 2026年5月1日 01:39 |
| 捐献地址: | 去捐款 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 6.9.4 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
eval, base64_decode, shell_exec) hidden in your files.
* 1-Click Auto-Repair: Found a modified core file? Click "Repair" and Protector will automatically fetch a clean, original version directly from the official WP SVN and overwrite the infected file.
🛡️ Login Fortress (Brute-Force Protection)
Hackers relentlessly target the wp-login.php page. We make it disappear.
* Secret Login URL: Hide wp-login.php completely. Any unauthorized attempt will be instantly redirected to a custom URL of your choice.
* Smart Honeypots: Inject invisible fields into your login and comment forms to trap and block spam/brute-force bots automatically.
* Block Username Scanning: Prevent attackers from discovering your admin usernames via ?author=1 enumeration.
🔒 1-Click Site Hardening
Lock down common vulnerabilities instantly:
* Security Headers: Protect against XSS, Clickjacking, and MIME-Sniffing attacks with a single toggle.
* XML-RPC Control: Disable XML-RPC completely to eliminate one of the biggest brute-force attack vectors on WordPress.
* Version Obfuscation: Hide your WordPress version from the source code so hackers can't target known exploits.
* Restrict REST API: Block public access to endpoints that expose sensitive user data.
📊 Live Attack Log
Peace of mind you can actually see. Monitor every blocked attack, triggered honeypot, and deleted malware in real-time straight from your dashboard.
🚀 Upgrade to KloxStudios Pro
Need absolute maximum power? Protector integrates seamlessly with the KloxStudios Cloud AI. Pro users unlock Cloud AI Malware Verification for 3rd-party plugins/themes, Automatic IP Lockouts, Instant Admin Login Alerts (Email & Webhook), and 2FA.
protector-security folder to the /wp-content/plugins/ directory (or install directly via the WP Plugin directory).mysecretaccess).yoursite.com/wp-login.php?mysecretaccess.Don't panic! You can temporarily disable the plugin by renaming the protector-security folder inside wp-content/plugins/ via FTP or your hosting File Manager. This will instantly restore the default wp-login.php access.
No! The scanner uses AJAX-based asynchronous batch processing. This means it scans your files in small chunks, preventing server timeouts and CPU spikes, even on massive websites with thousands of files.