Descripción
WebDmitriev Protection is a compact and efficient security solution for WordPress sites:
- Brute-Force Protection: Limits failed login attempts on
wp-login.php. - Entry Point Security: Disables XML-RPC and prevents user enumeration via REST API and author query parameters.
- File Integrity Guard: Monitors critical files (
.htaccessandwp-config.php) for unauthorized changes. - Uploads Directory Guard: Automatically blocks PHP execution inside
/wp-content/uploads/. - Lightweight WAF: Filters dangerous URL parameters (SQLi/XSS), blocks malicious User-Agent signatures, and manages IP blacklists.
Instalación
- Upload the
webdmitriev-protectionfolder to the/wp-content/plugins/directory. - Activate the plugin through the ‘Plugins’ menu in WordPress.
- Go to ‘WD Protection’ in the admin dashboard to configure settings and view threat logs.
Preguntas frecuentes
-
How does the plugin block brute-force attacks?
-
It tracks failed login attempts by IP address. If an IP exceeds 5 failed attempts within 15 minutes, access to the login form is temporarily blocked.
-
What happens if wp-config.php or .htaccess is edited?
-
The plugin calculates MD5 hashes of critical files. If a modification is detected, a notice appears in the admin panel allowing you to inspect and approve the new file state.
Reseñas
There are no reviews for this plugin.
Colaboradores y desarrolladores
“WebDmitriev Protection” es un software de código abierto. Las siguientes personas han colaborado con este plugin.
ColaboradoresTraduce “WebDmitriev Protection” a tu idioma.
¿Interesado en el desarrollo?
Revise el código , eche un vistazo al repositorio SVN , o suscríbase al log de desarrollo por RSS .
Registro de cambios
1.0.0
- Initial public release.
