콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

Rooted Dev Studio Security Toolkit

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

Rooted Dev Studio Security Toolkit

작성자: bigdawgdad2185
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

Rooted Dev Studio Security Toolkit provides a transparent baseline for protecting a WordPress website without hiding important behavior behind vague scores or destructive automatic fixes.

Features include:

  • Configurable failed-login limiting with short, per-login-and-IP temporary lockouts.
  • Administrator controls for reviewing and clearing active Rooted Dev Studio Security Toolkit lockouts.
  • Time-based two-factor authentication with single-use recovery codes.
  • A local Security Timeline for important authentication, administration, hardening, and file events.
  • Hashed origin records without storing raw IP addresses in security events.
  • Baseline browser security headers.
  • Reversible theme and plugin editor protection.
  • Optional XML-RPC authentication restriction.
  • Optional public REST user endpoint restriction.
  • Security configuration checks for HTTPS, updates, debug display, administrator access, WordPress salts, and PHP.
  • Read-only file fingerprinting with expected and unexplained change review.
  • A bounded, manual suspicious-code scan for selected high-risk PHP patterns.
  • Email alerts for important software and administrator changes and repeated-login lockouts.
  • Local retention controls and automatic cleanup.

Rooted Dev Studio Security Toolkit does not transmit site data to Rooted Dev Studio or any third party. It does not execute, edit, quarantine, restore, or delete scanned files. A clean scan is not a guarantee that a website is free of malicious code. Rooted Dev Studio Security Toolkit does not replace secure hosting, backups, software updates, or professional incident response.

설치

  1. Upload the rooted-security folder to /wp-content/plugins/, or install the ZIP through Plugins > Add New > Upload Plugin.
  2. Activate Rooted Dev Studio Security Toolkit.
  3. Open Rooted Dev Studio Security Toolkit > Dashboard.
  4. Review Rooted Dev Studio Security Toolkit > Settings before enabling compatibility-sensitive options.
  5. Configure two-factor authentication from each administrator’s WordPress profile and store recovery codes securely.
  6. Create a file-monitor baseline only after confirming the website is in a known-good state.

FAQ

Does Rooted Dev Studio Security Toolkit send my site data anywhere?

No. Rooted Dev Studio Security Toolkit Free has no telemetry, remote API, account requirement, or external service connection.

Does the suspicious-code scan prove my website is clean?

No. The bounded, read-only scanner looks for selected high-risk PHP patterns in active themes and plugins. Findings require review, and a clean result cannot detect every malware family or hidden compromise.

Why are XML-RPC and REST user restrictions disabled by default?

Those options can affect mobile apps, publishing tools, and integrations. Rooted Dev Studio Security Toolkit keeps compatibility-sensitive controls opt-in.

Are IP addresses stored?

Raw IP addresses are not written to the activity table. Rooted Dev Studio Security Toolkit stores a keyed hash so repeated events can be correlated without retaining the original address.

Can login protection lock every visitor out of an account?

No. Temporary lockouts are tied to the matching login value and the server-observed IP address. Password-reset access remains available, active administrators can clear Rooted Dev Studio Security Toolkit lockouts, and a file-access recovery constant is documented on the Login Protection screen.

Does Rooted Dev Studio Security Toolkit automatically change or delete suspicious files?

No. File monitoring and suspicious-code scanning are review tools. Rooted Dev Studio Security Toolkit does not automatically modify, quarantine, restore, or delete files.

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“Rooted Dev Studio Security Toolkit”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • bigdawgdad2185

자국어로 “Rooted Dev Studio Security Toolkit”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

0.2.1

  • Renamed the plugin for a distinctive WordPress.org identity.

0.2.0

  • Added local two-factor authentication and single-use recovery codes.
  • Added the local Security Timeline and dashboard summary.
  • Added reversible hardening controls and review history.
  • Added read-only file fingerprinting and expected-change review.
  • Added a bounded manual suspicious-code scanner with PHP comment filtering.
  • Added windowed login limiting, administrator lockout recovery, timeline events, and anti-flood email alerts.
  • Expanded privacy, safety-scope, and uninstall cleanup documentation.
  • Addressed WordPress Plugin Check translation, request-validation, package, and database-query findings.
  • Corrected translator-comment placement in administrative templates.
  • Normalized production source-file line endings.

기초

  • 버전 0.2.1
  • 최근 업데이트: 1주 전
  • 활성화된 설치 10보다 적음
  • 워드프레스 버전 6.5 또는 그 이상
  • 다음까지 시험됨: 7.1
  • PHP 버전 7.4 또는 그 이상
  • 언어
    English (US)
  • 태그:
    Activity Loghardeninglogin securitysecuritySecurity Headers
  • 고급 보기

평점

아직 제출된 리뷰가 없습니다.

Your review

모든 리뷰 보기

기여자

  • bigdawgdad2185

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.