Linux 软件免费装

Xerotact SHIELD-X Security

开发者 xerotact
更新时间 2026年9月16日 20:20
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv3
版权网址: 版权信息

标签

security login security firewall malware scanner hardening

下载

2.0.167 2.0.90 2.0.189 2.0.54 2.0.20 2.0.180 2.0.181 2.0.27 2.0.175 2.0.182 2.0.183 2.0.184 2.0.38 2.0.84 2.0.166 2.0.169 2.0.170 2.0.171 2.0.179 2.0.15 2.0.19 2.0.21 2.0.22 2.0.23 2.0.26 2.0.30 2.0.149 2.0.53 2.0.81 2.0.91 2.0.151 2.0.46 2.0.148 2.0.163

详情介绍:

SHIELD-X gives you a clearer way to protect your WordPress site without turning security into a server-admin job. From one workspace, you can see what is happening, spot what needs attention, and take practical next steps with confidence. Start with the guided Setup Assistant, then choose the protections that fit your site. SHIELD-X is built for everyday WordPress sites and shared hosting: it works with normal WordPress tools, starts conservatively, and lets you review what it finds before you enable stronger actions. What you get with SHIELD-X Extend SHIELD-X when you need more SHIELD-X is useful on its own. Optional SHIELD-X add-ons let you extend it as your site and workflow grow: Your data stays with your site SHIELD-X stores its security records locally by default. Optional services and add-ons are clearly disclosed and are used only when an administrator enables or uses the matching feature.

安装:

  1. Upload the xerotact-shield-x-security directory to /wp-content/plugins/, or install the ZIP from the WordPress Plugins screen.
  2. Activate SHIELD-X from the WordPress Plugins screen.
  3. Open SHIELD-X > Setup in the WordPress admin menu and follow the Setup Assistant.
  4. Review the System page for PHP extensions, filesystem writability, human challenge settings, file type policy, and configuration portability.
  5. Review Firewall, Malware/Virus, Login Security, Hardening, and Lockdown before enabling enforcement-style controls.
For shared hosting, start with log-only mode and review events before enabling blocking or lockdown actions.

屏幕截图:

  • Setup Assistant with completion status and Normal, Extreme, and Panic profile reviews.
  • Hardening controls with stealth protections and the security-measure checklist.
  • Backup workspace with restore points, database backups, and file shadow copies.
  • Pulse monitoring for website, traffic, mail, and WordPress cron health.
  • Scheduler controlling recurring SHIELD-X security and maintenance tasks.

升级注意事项:

2.0.175 Makes Security Trends appear in its top dashboard position immediately after refresh without requiring a scroll. 2.0.174 Keeps Security Trends visible when an older or invalid saved dashboard layout places it outside WordPress's supported dashboard columns. 2.0.173 Loads the Security Trends widget with the Dashboard so administrators no longer wait for a second WordPress request before seeing it. 2.0.172 Improves backup and restore throughput and lets license checks recover from common cURL connection failures through WordPress's alternate HTTP transport. 0.1.0 Initial public release. Review settings carefully before enabling blocking or lockdown features.

常见问题:

Does SHIELD-X require a cloud account?

No. Core WAF, scanner, hardening, login security, backups, restore points, and logs are local. Vulnerability advisory feeds are optional and configurable by the site administrator.

Does the WAF block traffic by default?

No. SHIELD-X is designed to start conservatively. Use log-only mode first, review hits and false positives, then explicitly choose rule actions or enforce mode when you are ready. Matched scores are diagnostic by default; score-threshold challenge/block behavior is an advanced opt-in setting.

Does the WAF inspect complete request bodies and long headers?

No. For shared-hosting safety, SHIELD-X inspects a bounded body surface, currently 32 KB by default and configurable up to 128 KB. Login, comment, admin-post/admin-ajax, WooCommerce, and contact form bodies are inspected as redacted key/value text so passwords, nonces, tokens, payment fields, and session fields are not stored. Multipart uploads are inspected through form fields, filenames, MIME types, sizes, and part headers, not binary file contents. Country blocking uses country headers supplied by a trusted proxy or CDN, such as Cloudflare, and does not bundle a GeoIP database.

Does the WAF run before WordPress loads?

No. The WordPress.org package is a pure WordPress plugin, so request inspection runs after WordPress begins loading.

What does SHIELD-X not replace?

SHIELD-X does not replace host-level malware cleanup, a server firewall, CDN edge protection, off-site backups, or emergency hosting support. It adds WordPress-level monitoring, hardening, recovery, and investigation tools that work inside the permissions available to a WordPress plugin.

Does SHIELD-X scan vendored libraries inside other plugins?

No. By default, SHIELD-X skips wp-content/cache/, wp-content/upgrade/, wp-content/plugins/xerotact-shield-x-security/, node_modules/, vendor/ inside plugins and themes, and SHIELD-X private storage under .shield-x/. Vendored libraries should be reviewed by their authors. If you want to inspect a specific vendored path, copy it outside vendor/ first and run a targeted recheck from the SHIELD-X Scan page.

Which database content does the scanner inspect?

The database scanner inspects bounded batches from wp_options, recent post/page content, post metadata, comments, administrator accounts, administrator capability metadata, widgets, redirects, and WP-Cron payloads. It is a local security review tool, not a full database export scanner.

Which files can the scanner skip by design?

For performance and safe shared-hosting behavior, SHIELD-X skips vendor dependency folders, package caches, generated build folders, upgrade/temp folders, private backup storage, and oversized or unchanged files where metadata proves they did not change since the trusted baseline. This keeps routine scans responsive while focusing deeper checks on new or modified files.

Does the User Profiler track visitors automatically?

No. The User Profiler is opt-in. When enabled, it uses a first-party cookie and stores recent request metadata locally for security investigation.

Can I move SHIELD-X settings to another site?

No. Settings exports are signed with this site's WordPress auth salts, so they can only be restored on the same WordPress site that created them.

Can I compare modified WordPress core files with clean copies?

Yes. The scanner can download the matching official WordPress release archive from WordPress.org for core files and official WordPress.org plugin packages for installed plugins. SHIELD-X uses those hashes to avoid flagging unmodified official files as suspicious.

Can I use SHIELD-X on shared hosting?

Yes. SHIELD-X is designed for PHP-only shared hosting. Optional features such as filesystem lockdown depend on host permissions and PHP configuration.

Can WP-CLI change hardening files?

Only with explicit confirmation. SHIELD-X hardening writes from WP-CLI require an administrator-gated command and SHIELDX_CLI_CONFIRM=yes, so direct wp eval calls cannot silently modify wp-config.php or .htaccess.

What happens on uninstall?

SHIELD-X treats plugin delete/reinstall as a maintenance path by default. When WordPress runs the plugin uninstaller, SHIELD-X removes scheduled events and reverts active Lockdown state. It keeps SHIELD-X settings, database findings, audit/activity data, backups, restore points, local logs, and private storage so a plugin upload, replacement, or reinstall does not erase customer data. To remove all SHIELD-X data on plugin deletion, enable Delete all SHIELD-X data when WordPress deletes the plugin on SHIELD-X > Cleanup before using WordPress' Delete action. The SHIELDX_PURGE_ON_UNINSTALL constant remains available for managed deployments.

更新日志:

2.0.189 2.0.188 2.0.187 2.0.186 2.0.185 2.0.184 2.0.183 2.0.180 2.0.179 2.0.178 2.0.177 2.0.176 2.0.175 2.0.174 2.0.173 2.0.172 2.0.171 2.0.170 2.0.169 2.0.168 2.0.167 For earlier release history, see the project release history.