콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

FPX Security Guard

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

FPX Security Guard

작성자: mamuniu06
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

FPX Security Guard protects your WordPress site with:

  • Two-Factor Authentication (2FA) — Standard TOTP support (Google Authenticator, Authy, Microsoft Authenticator, 1Password). Users enable it individually from their Profile page with QR-code setup, and receive 10 one-time recovery codes. Works fully offline — no external service or email required.
  • Login Protection — Limits failed login attempts per IP with configurable lockout duration, generic error messages (no username/password hints), and a hidden honeypot field that silently blocks bots.
  • Firewall & Headers — Sends modern security headers (X-Frame-Options, nosniff, Referrer-Policy, Permissions-Policy, HSTS on HTTPS) and blocks requests containing common SQL injection / XSS / path traversal patterns.
  • Hide WordPress Info — Removes the WP version from meta tags and asset URLs, blocks ?author=N user enumeration scans, and hides the public REST API users endpoint.
  • Hardening — Disables XML-RPC (a common brute-force vector) and the built-in theme/plugin file editor.

Want more? FPX Security Guard Pro adds daily File Change Detection with malware-injection alerts — a background scanning service, hosted and sold separately from this free plugin.

All features can be toggled individually from Settings → FPX Security Guard. A lockout log shows the last 20 blocked login attempts.

External Services

This plugin’s optional Country Block feature (disabled by default) uses the free geo-location service ip-api.com to determine the country of a visitor’s IP address.

  • What is sent: Only the visitor’s IP address is sent to ip-api.com, and only when the Country Block feature is manually enabled by the site administrator and a visitor’s country is not already cached.
  • When: On the first request from a given IP; the result is cached locally for 24 hours, so repeat visitors trigger no external calls.
  • No other data (no personal info, no site data) is ever transmitted.

Service provider: ip-api.com — Terms: https://ip-api.com/docs/legal — Privacy: https://ip-api.com/docs/legal

If the Country Block feature is disabled (the default), the plugin makes no external requests whatsoever.

Does rate limiting slow down my site?

Rate limiting tracks each visitor’s request count using WordPress’s core Transients API. If your host has a persistent object cache (Redis/Memcached), this data is stored there with no database writes at all. Without one, it falls back to the options table like any request-level counter — the tracked data expires within seconds, so it never accumulates.

설치

  1. Upload the fpx-security-guard folder to /wp-content/plugins/, or upload the zip via Plugins → Add New → Upload Plugin.
  2. Activate the plugin through the Plugins menu.
  3. Configure options under Settings → FPX Security Guard.

FAQ

I’m locked out of two-factor authentication. How do I get back in?

There are three rescue paths, in order of ease:

  1. Recovery codes — enter one of your saved one-time recovery codes in the Authentication Code field on the login screen.
  2. Ask an administrator — any admin can open Users → your profile and reset your 2FA with one click. You can then log in with just your password and set 2FA up again.
  3. Server access (site owners) — add this line to your wp-config.php file: define( 'FPXSG_DISABLE_2FA', true ); — this temporarily bypasses 2FA for all logins. Log in, reset your 2FA from your profile, then REMOVE the line again. Because it requires file access, only someone who controls the server can use it.

Will this conflict with other security plugins?

Avoid running multiple firewall/login-limit plugins at once — features may overlap.

I use Jetpack or a mobile app to publish.

Disable the “Disable XML-RPC” option in settings.

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“FPX Security Guard”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • mamuniu06

자국어로 “FPX Security Guard”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

1.0.0

  • Initial release.
  • Login protection: per-IP attempt limits, lockouts, honeypot, generic error messages.
  • Two-Factor Authentication (TOTP): QR-code setup, recovery codes, low-code warnings, works offline.
  • DDoS/flood protection via per-IP rate limiting.
  • Firewall: malicious query blocking and modern security headers.
  • Country blocking (optional, via ip-api.com with local caching).
  • Comment spam protection: honeypot and link limits.
  • Hardening: XML-RPC off, file editor off, version hiding, user-enumeration blocking.
  • Bundled QRCode.js by davidshimjs (MIT license, GPL-compatible) for local QR rendering.

기초

  • 버전 1.0.0
  • 최근 업데이트: 1개월 전
  • 활성화된 설치 10보다 적음
  • 워드프레스 버전 5.8 또는 그 이상
  • 다음까지 시험됨: 7.0.4
  • PHP 버전 7.4 또는 그 이상
  • 언어
    English (US)
  • 태그:
    Brute Forcefirewallhardeninglogin protectionsecurity
  • 고급 보기

평점

아직 제출된 리뷰가 없습니다.

Your review

모든 리뷰 보기

기여자

  • mamuniu06

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.