콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

Cerrojo Security Toolkit

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

Cerrojo Security Toolkit

작성자: carlose119
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

Cerrojo Security Toolkit adds focused security diagnostics and reversible, opt-in controls under Tools > Cerrojo Security Toolkit.

Current tools include:

  • Security posture diagnostics with links to native WordPress Site Health.
  • A file editor control that stores a plugin preference without editing wp-config.php.
  • Best-effort login protection with temporary, progressive throttling.
  • XML-RPC pingback protection that removes native inbound pingback methods and the WordPress-filtered X-Pingback header.
  • Staged HTTP security header policies with baseline, optional groups, compatibility warnings, and rollback controls.
  • Email alerts for supported plugin installation and activation events.
  • Email alerts for supported administrator account lifecycle events.
  • URL Change Alerts for supported successful local WordPress Address and Site Address updates.
  • Selective REST API blocking by HTTP method and registered route template. Matching rules apply to all callers, including administrators and authenticated integrations.

Controls are designed to be reviewed, enabled, verified, and reversed individually. Coverage depends on the WordPress hooks and serving paths described in each tool. Login throttling is best-effort, email delivery depends on the site’s mail transport, and headers must be verified at every cache, proxy, CDN, and origin edge.

Cerrojo Security Toolkit is not a web application firewall or malware scanner. It does not certify a site or guarantee complete protection. Use it as one layer in a broader security and recovery plan.

Saved settings remain until you change them. Deactivation stops the plugin’s runtime behavior but preserves its settings, metrics, and temporary state. The plugin currently provides no uninstall cleanup routine.

설치

  1. Upload the plugin files to /wp-content/plugins/cerrojo-security-toolkit/, or install the plugin through the WordPress Plugins screen.
  2. Activate Cerrojo Security Toolkit through the Plugins screen.
  3. Open Tools > Cerrojo Security Toolkit.
  4. Review the diagnostics before enabling controls.
  5. Enable one control at a time, verify site behavior and integrations, and keep an independent recovery path available.

FAQ

Does Cerrojo Security Toolkit guarantee that my site is secure?

No. It provides diagnostics and bounded hardening controls. It is not a WAF, malware scanner, certification, or complete protection guarantee.

Can I reverse the settings?

Yes. The settings UI provides controls to disable or clear plugin-managed policies. Some effects outside WordPress, such as an HSTS policy already remembered by a browser or email already handed to a mail server, cannot be recalled immediately.

Who is affected by a blocked REST route?

Every caller whose request matches the selected HTTP method and registered route template. There are no administrator, capability, cookie, or Application Password exemptions.

What do URL Change Alerts observe?

URL Change Alerts are independently opt-in under Tools > Cerrojo Security Toolkit > Hardening. Enable the tool, enter one to 50 valid recipient addresses separated by commas or new lines, and save. There is no administrator-email fallback and no reuse of recipients from another alert tool. Disabling preserves recipients for a later re-enable.

The tool observes only successful update_option_home and update_option_siteurl hooks for the existing home and siteurl settings in the current local-blog context. They are separate settings, so each successful update is a separate event. It does not observe option additions, deletions, network options, direct SQL or file changes, or scheduled scans, and it does not switch sites or fan out on multisite.

A changed raw string is observed even when redaction or truncation makes the displayed references identical. Displayed values remove user information, query strings, and fragments; invalid values are Unavailable. Paths are retained when available and may be sensitive. Cerrojo makes one plain-text wp_mail attempt per recipient; an attempt is not delivery. Mail failures do not block a WordPress update or trigger automatic rollback.

Does uninstalling remove saved data?

No. This version has no uninstall cleanup routine, so plugin-owned settings remain unless they are changed or removed separately.

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“Cerrojo Security Toolkit”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • carlose119

자국어로 “Cerrojo Security Toolkit”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

0.2.2

  • Includes URL Change Alerts, which have been available on master since 0.2.1.
  • Sanitized nonce input, scoped enqueued admin CSS, and replaced URL parsing with wp_parse_url().
  • Renamed the plugin entrypoint and packaged plugin assets. Existing installations may need reactivation after the entrypoint rename.

0.2.1

  • Corrected the public name, text domain, and package slug to avoid an existing WordPress update identity collision.

0.2.0

  • Added an actionable security dashboard and staged HTTP security header policies.
  • Added login protection and XML-RPC pingback protection.
  • Added plugin activity and administrator account alerts.
  • Added selective REST API blocking by HTTP method and registered route template.
  • Improved WordPress.org packaging and directory compliance.

0.1.0

  • Initial release.

기초

  • 버전 0.2.2
  • 최근 업데이트: 1일 전
  • 활성화된 설치 10보다 적음
  • 워드프레스 버전 6.8 또는 그 이상
  • 다음까지 시험됨: 7.1
  • PHP 버전 8.1 또는 그 이상
  • 언어
    English (US)
  • 태그:
    hardeninglogin securityrest-apisecuritySecurity Headers
  • 고급 보기

평점

아직 제출된 리뷰가 없습니다.

Your review

모든 리뷰 보기

기여자

  • carlose119

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.