Linux 软件免费装
Banner图

ZeroBot Security – Login Protection, Firewall & Bot Blocker

开发者 zerobot
更新时间 2026年10月6日 20:03
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security login security firewall brute force antibot

下载

1.1.0 1.1.1 1.0.15 1.0.17

详情介绍:

ZeroBot Security protects your site from the first minute, with no account and no setup. Activate it and two protections start working inside WordPress itself. Nothing is sent anywhere. Free, no account needed Network protection (free 7-day trial, then a ZeroBot plan) Connect the site from the plugin dashboard: enter your email, confirm it, and the plugin activates itself. The trial includes 100 IP checks and needs no credit card. When a trial or plan ends, network protection pauses and the free protections keep running. Full Platform Management Other Features

安装:

  1. Install from Plugins → Add New (search "ZeroBot Security"), or upload the zip.
  2. Activate the plugin. Login protection and the XML-RPC kill switch are on right away.
  3. Optional: open ZeroBot → Dashboard and, under "Turn on network protection", enter the email of an administrator of this site and click "Start free trial" (7 days, 100 IP checks, no card). Click the link in the activation email: the site connects and the firewall switches on. Already have a ZeroBot license key? Paste it under ZeroBot → License.
  4. Adjust the layers in ZeroBot → Protection.
No account is needed for the free protections.

升级注意事项:

1.1.1 In-plugin signup now requires the email of a site administrator. 1.1.0 Free login protection and XML-RPC blocking now work without an account, and IP detection can no longer be spoofed. Recommended for all sites.

常见问题:

Do I need an account?

No. Login brute-force protection and the XML-RPC kill switch work right after activation, with no account and no data leaving your site. An account is only needed for network protection.

What happens when my trial ends?

Network protection pauses and the free protections keep running. If you activate a plan later, the plugin notices within a day (or immediately with "Check again") and switches it back on.

I use Cloudflare or another proxy. Will lockouts hit the right IP?

Cloudflare and local reverse proxies (for example nginx in front of Apache) are detected automatically. Behind another CDN, enable "Trust proxy headers" in Protection Settings and check "Your detected IP" on the License page.

I use Jetpack. Is XML-RPC still blocked?

No. Jetpack connects to WordPress.com through XML-RPC, so the kill switch stands down while Jetpack is active. Login protection still runs.

Will this plugin break my site if the ZeroBot API is down?

No. The default Fail Mode is "Fail Open" — visitors are allowed through silently and the incident is logged to the PHP error log. You can switch to Fail Closed in Protection Settings if you prefer strict security.

How much does it call the ZeroBot API?

Every visitor decision is cached per-IP for 24 hours by default, so repeat visitors do not trigger additional API calls. A page that gets 1,000 hits/hour from returning visitors typically results in only a handful of API calls.

Does the fingerprint collector always run?

No. The fingerprint collector is disabled by default and only injects on the public site when the administrator turns on "Browser Fingerprint" under Protection Settings.

Does it work with WooCommerce?

Yes — the REST API Guard auto-exempts /wc/store/ routes. Add other custom routes to the exempt list as needed.

Does it support multisite?

Single-site only for now.

更新日志:

1.1.1 1.1.0 1.0.17 1.0.16 1.0.15 1.0.14 1.0.12 1.0.11 1.0.9 1.0.8 1.0.7 1.0.6 1.0.5 1.0.3 - 1.0.4 1.0.0