Title: Assist Security
Author: AssistPress
Published: <strong>2026년 8월 6일</strong>
Last modified: 2026년 9월 23일

---

플러그인 검색

![](https://ps.w.org/assist-security/assets/icon-256x256.png?rev=3709574)

# Assist Security

 작성자: [AssistPress](https://profiles.wordpress.org/assistpress/)

[다운로드](https://downloads.wordpress.org/plugin/assist-security.0.1.3.zip)

 * [세부사항](https://ko.wordpress.org/plugins/assist-security/#description)
 * [평가](https://ko.wordpress.org/plugins/assist-security/#reviews)
 *  [설치](https://ko.wordpress.org/plugins/assist-security/#installation)
 * [개발](https://ko.wordpress.org/plugins/assist-security/#developers)

 [지원](https://wordpress.org/support/plugin/assist-security/)

## 설명

WordPress signs every login cookie and nonce with eight secret keys and salts stored
in `wp-config.php` (`AUTH_KEY` through `NONCE_SALT`). If those secrets leak — through
an old backup, a stolen config file, or a contractor who still has access — an attacker
can forge valid authentication cookies for as long as the keys stay unchanged. Rotating
them invalidates every existing session immediately.

Assist Security makes that rotation safe, automatic, and auditable.

#### 🔑 Rotate Security Keys

 * **One-click rotation** from a clean, colorful settings screen
 * **Locally generated keys** using PHP’s cryptographically secure random number
   generator. No calls to any external API, no network dependency
 * **Verified atomic writes.** The new configuration is built in memory, written
   to a temporary file with restricted permissions, verified, atomically swapped
   in, then verified again — with automatic rollback if any step fails. The writer
   refuses to touch your file unless all eight keys are found, so a partial rotation
   is impossible
 * **Key health checks** for missing, weak, duplicated, or placeholder keys. Only
   the verdict is ever shown; your key values never leave the server
 * **Audit log** recording every attempt: timestamp, result, trigger, user, optional
   IP, duration, and how many sessions were signed out — with filtering, pagination,
   and CSV export
 * **Failure alerts** emailed to the site administrator if a rotation ever fails
 * **Site Health test** that flags key problems and keys older than 180 days
 * **WP-CLI commands** — `wp assist-security rotate` and `wp assist-security status`
 * **Custom config locations** supported: `wp-salt.php`, a `wp-config.php` above
   the web root, or any path you choose with a filter

#### Built the right way

 * Beautiful, responsive settings screen with no page reloads and no build step
 * REST API under `assist-security/v1`; no admin-ajax
 * No bundled SDKs, no Composer dependencies, no external HTTP requests, no telemetry
 * Every input sanitized, every output escaped, every query prepared
 * Multisite aware: management is restricted to network administrators
 * Privacy-conscious: IP logging is optional and data removal on uninstall is opt-
   in
 * Settings import and export as JSON
 * Fully translatable, with a bundled POT file

Assist Security is built on a module architecture, so further protections can be
added as self-contained modules in future releases.

## 설치

 1. Upload the `assist-security` folder to `/wp-content/plugins/`, or install it through**
    Plugins  Add New**.
 2. Activate **Assist Security** from the Plugins screen.
 3. Open the new **Assist Security** menu in your admin sidebar.
 4. Check your key health on the Security Keys tab and rotate whenever you need to.

**Note:** rotating the keys signs out every user, including you. The plugin warns
you first and sends you to the login screen afterwards.

For rotation to work, `wp-config.php` (or your custom salt file) must be writable
by PHP. The Security Keys tab and Site Health both report this.

## FAQ

### Will rotating the keys break my site?

No. The writer refuses to modify your configuration file unless all eight keys are
found, verifies the result before and after an atomic swap, and rolls back automatically
if anything is wrong. If a rotation cannot complete safely, your original file is
left untouched.

### Why is everyone logged out afterwards?

That is the point. Invalidating existing cookies is what makes rotation a security
measure. Session tokens are cleared as well.

### Where do the new keys come from?

They are generated on your own server with PHP’s cryptographically secure random
number generator. The plugin makes no external requests.

### Does the plugin ever show or send my keys?

No. Key values are never displayed, logged, exported, or transmitted. The health
check reads each constant only long enough to decide whether it is missing, weak,
or duplicated, and reports that verdict alone.

### My wp-config.php is outside the web root, or I use wp-salt.php. Is that supported?

Yes. The plugin checks `wp-salt.php`, `wp-config.php`, and the parent directory 
automatically. You can also point it anywhere:

    ```
    add_filter( 'assist_security_config_file', function () { return '/path/to/wp-salt.php'; } );
    ```

### Is it multisite compatible?

Yes. On multisite, only network administrators (`manage_network_options`) can manage
the plugin.

### How often should I rotate?

Every one to three months suits most sites. Rotate immediately if you suspect a 
leak, after removing an administrator, or after restoring from a backup of unknown
origin. The Site Health test reminds you once your keys pass 180 days.

### What data does the plugin store?

Settings in a single option, and rotation records in its own database table. IP 
addresses are recorded only if you enable that option. Everything is removed on 
uninstall only if you opt in first, on the Tools tab.

## 후기

이 플러그인에 대한 평가가 없습니다.

## 기여자 & 개발자

“Assist Security”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에
기여하였습니다.

기여자

 *   [ AssistPress ](https://profiles.wordpress.org/assistpress/)

[자국어로 “Assist Security”(을)를 번역하세요.](https://translate.wordpress.org/projects/wp-plugins/assist-security)

### 개발에 관심이 있으십니까?

[코드 탐색하기](https://plugins.trac.wordpress.org/browser/assist-security/)는, 
[SVN 저장소](https://plugins.svn.wordpress.org/assist-security/)를 확인하시거나,
[개발 기록](https://plugins.trac.wordpress.org/log/assist-security/)을 [RSS](https://plugins.trac.wordpress.org/log/assist-security/?limit=100&mode=stop_on_copy&format=rss)
로 구독하세요.

## 변경이력

#### 0.1

 * Initial release.

## 기초

 *  버전 **0.1.3**
 *  최근 업데이트: **1일 전**
 *  활성화된 설치 **10보다 적음**
 *  워드프레스 버전 ** 6.0 또는 그 이상 **
 *  다음까지 시험됨: **7.1.2**
 *  PHP 버전 ** 7.4 또는 그 이상 **
 *  언어
 * [English (US)](https://wordpress.org/plugins/assist-security/)
 * 태그:
 * [salts](https://ko.wordpress.org/plugins/tags/salts/)[security](https://ko.wordpress.org/plugins/tags/security/)
   [security keys](https://ko.wordpress.org/plugins/tags/security-keys/)[session](https://ko.wordpress.org/plugins/tags/session/)
   [wp-config](https://ko.wordpress.org/plugins/tags/wp-config/)
 *  [고급 보기](https://ko.wordpress.org/plugins/assist-security/advanced/)

## 평점

아직 제출된 리뷰가 없습니다.

[Your review](https://wordpress.org/support/plugin/assist-security/reviews/#new-post)

[모든  리뷰 보기](https://wordpress.org/support/plugin/assist-security/reviews/)

## 기여자

 *   [ AssistPress ](https://profiles.wordpress.org/assistpress/)

## 지원

할 말 있으신가요? 도움이 필요하신가요?

 [지원 포럼 보기](https://wordpress.org/support/plugin/assist-security/)