Idi na sadržaj
WordPress.org

Bosanski

  • Teme
  • Plugini
  • News
  • Podrška
  • O nama
  • Projekti
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Webro Security

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Webro Security

Od webro
Skini
  • Detalji
  • Recenzije
  • Instalacija
  • Razvoj
Podrška

Opis

A WordPress plugin that adds security headers, CSP, login protection, SMTP, spam protection and more. Functionality is continuously being expanded to cover more ground.

Features

  • Adds security headers, including configurable HSTS, X-Frame-Options, COOP and CORP
  • Supports Content Security Policy (CSP), editable from the admin UI and validated against unrecognized directives
  • Protects login with rate-limiting
  • Blocks weak passwords, with an exemption list for individual users
  • Blocks common/guessable usernames
  • Validates protected brand names against required domains — self-registration blocks a brand-impersonating email outright
  • Locks file editing, with a temporary admin-bar toggle that automatically relocks after a period of inactivity
  • Honeypot spam protection (CF7, Elementor, WPForms, Forminator, lost password)
  • Custom SMTP sending, with a test-email button
  • Central security log with automatic retention, including new user account creation
  • Removes certain default WordPress traces from <head>
  • Blocks usernames from leaking through author URLs, the REST API and embedded author data
  • English, with community translations available via translate.wordpress.org

What does it protect against?

  • Basic login attacks
  • Some forms of user enumeration
  • Unwanted WordPress metadata
  • Missing security headers

Important: it does not protect against vulnerabilities in other plugins or themes, poor server configuration, or missing updates.

Compatibility

Some security headers can affect elements such as iframes, embeds and third-party scripts. Some of the CSP directives may be too strict and might need loosening depending on your needs — this is done from the admin UI's CSP field (administrator role).

Support

Contact webro with questions or bug reports at len@webro.dk

Slike ekrana

Instalacija

  1. Upload the plugin to wp-content/plugins/
  2. Activate it via the WordPress admin panel

Uninstallation

  • Removes the plugin's saved options
  • Removes the plugin's transients
  • Cleans up its own settings on uninstall

Recenzije

Nema recenzija za ovaj dodatak.

Saradnici i programeri

“Webro Security” is open source software. The following people have contributed to this plugin.

Doprinositelji
  • webro
  • Lasse Enggaard
  • Rikke Rasmussen

Prevedi “Webro Security” na vaš jezik.

Zainteresirani za razvoj?

Pregledajte kôd, pogledajte SVN spremišteili se pretplatite na dnevnik razvoja od RSS.

Zapis promijena

1.0.4

  • Fixed the security headers blocking the block editor when adding a new page/post: blob: is now allowed in the frame-src and connect-src directives of the default CSP
  • wp-admin and wp-login are now excluded from the .htaccess security headers without depending on the mod_setenvif Apache module, also on sites installed in a subdirectory
  • The PHP fallback for the security headers no longer applies to wp-admin and wp-login
  • After an update, the plugin now rewrites its .htaccess security headers itself and drops an outdated saved default CSP, so the settings no longer have to be re-saved by hand
  • Hardened the honeypot: the timing check is now signed by the server, and the way the honeypot field is hidden varies between page loads
  • Expanded the list of blocked usernames
  • The author name and author URL are no longer exposed in oEmbed responses, and WordPress’ built-in users sitemap is turned off, since both revealed usernames to visitors who are not logged in

1.0.0

  • First version

Meta

  • Version 1.0.4
  • Last updated prije 5 dana
  • Active installations Manje od 10
  • WordPress version 6.0 ili viša
  • Tested up to 7.1.3
  • PHP version 8.0 ili viša
  • Language
    English (US)
  • Tags
    csplogin protectionsecuritysmtpspam protection
  • Napredni pogled

Ocjene

No reviews have been submitted yet.

Your review

See all reviews

Doprinositelji

  • webro
  • Lasse Enggaard
  • Rikke Rasmussen

Podrška

Imate nešto za reći? Trebate pomoć?

Pogledaj forum podrške

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Support
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

Bosanski

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Kod je poezija.