Перейти к содержимому
WordPress.org

Русский

  • Темы
  • Плагины
  • Новости
    • Документация
    • Форумы
  • О WordPress
  • Сообщество
  • Скачать WordPress
Скачать WordPress
WordPress.org

Plugin Directory

PowerSEC

  • Отправить плагин
  • Мои избранные
  • Войти
  • Отправить плагин
  • Мои избранные
  • Войти

PowerSEC

Автор: CinderEye LLC
Скачать
  • Детали
  • Отзывы
  • Установка
  • Разработка
Поддержка

Описание

Local security, no account: firewall/WAF; brute-force lockouts, 2FA, CAPTCHA, magic-link, bot/honeypot; IP blocklist/allowlist and country blocks; malware and file-change scanning; WordPress, database and session hardening; on-site backups with 1-click restore; tamper-evident audit log.

PowerSEC can connect to PowerSEC Central (https://powersec.io) for multi-site management and vulnerability scanning (plugins, themes and core), off by default — see External services (1). If connected, it can switch WordPress’s own plugin and theme auto-update settings on or off. It never changes how core updates itself.

External services

Each service below is contacted only when its feature is on; every third-party service is off by default, and Central is off until an administrator connects the site. Out of the box the only request PowerSEC makes on its own is to the first-party WordPress.org checksum API (5); an alert channel’s «Send test» is the one exception, contacting the destination you typed at once. IPs and usernames may be personal data — disclose the services you enable in your own policy. The User-Agent is PowerSEC/<version> alone; see each service below.

1. PowerSEC Central — https://powersec.io — dashboard for multi-site management, cloud backups, alerting, incident response. Trigger: only when an administrator connects the site. Default: off.
Sent: site URL, identifiers and API keys; WordPress/PHP/MySQL versions; plugin and theme inventory (name, slug, version, author, active state); site icon URL; disk, memory and database size; up to 14 days of pageview counts; scan summaries, security event metadata and backup status; IPs of blocked or attacking clients; administrator usernames, last login, and their email addresses (only while two-factor is on or this server cannot send mail). If a message this site sends fails, its subject and body go to Central to deliver — to your own administrators only. With two-factor on and connected, the one-time code and recipient email go to Central to deliver (otherwise wp_mail() is used and nothing leaves the site). Database-scan findings carry a short redacted excerpt plus its table and key; whole posts, option values and page output never are.
Cloud backup (paid): archives on Wasabi (*.wasabisys.com); restores use short-lived signed URLs from *.wasabisys.com, *.amazonaws.com or powersec.io. Wasabi https://wasabi.com/legal/ , https://wasabi.com/legal/privacy-policy/ — AWS https://aws.amazon.com/service-terms/ , https://aws.amazon.com/privacy/
Terms https://powersec.io/terms — Privacy https://powersec.io/privacy

2. Google Gemini — https://ai.google.dev (via Central) — an AI second opinion on a file the scanner already flagged.
Trigger: (a) manual — an administrator clicks to explain one flagged file; that click is the authorisation. (b) automated — off by default, needing an explicit local opt-in by an administrator of this site under PowerSEC > Central Connection. Connecting to Central, your plan and Central’s settings do not enable it; switching it off stops future sharing.
Sent: only a bounded, redacted excerpt of that flagged file (size-capped, secrets redacted), plus its path, size, hash and the matching rule. Whole files, whole sites, databases and files that may hold credentials (wp-config.php, .env, key/certificate files) are never sent. Advisory only: it never changes scan results, malware counts or your score, and never removes, quarantines or repairs a file.
Terms https://ai.google.dev/gemini-api/terms — Privacy https://policies.google.com/privacy

3. GeoJS — https://get.geojs.io — IP geolocation. Trigger: only when country blocking is enabled. Default: off. Sent: the visitor’s IP, to resolve its country; cached 24h, and behind Cloudflare the country comes from Cloudflare’s header with no external call.
Terms https://www.geojs.io/tos/ — Privacy https://www.geojs.io/privacy/

4. Tor Project exit list — https://check.torproject.org — the public exit-node list. Trigger: only when Tor blocking is enabled. Default: off. Sent: nothing; the request carries no visitor information.
Privacy https://www.torproject.org/about/privacy_policy/ (a public file served without an account, so no separate terms)

5. WordPress.org — https://api.wordpress.org , https://downloads.wordpress.org — the official checksum APIs core itself uses. Trigger: file-integrity monitoring (on by default) and malware scans. Sent: your WordPress version and locale for core checksums; each plugin’s slug and version for plugin checksums. No personal data.
Privacy https://wordpress.org/about/privacy/

6. Alerting / SIEM destinations — security events sent where you choose. Trigger: only when you configure and enable a channel. Default: off; on every plan. Kinds: webhook URLs you supply (Slack, Discord, Splunk HEC, custom); fixed endpoints (PagerDuty events.pagerduty.com, Datadog http-intake.logs.datadoghq.com or its regional host); raw syslog/CEF over UDP/TCP to a host you supply.
Sent: per event — type, severity, message, the WordPress username involved (on a failed login this is visitor-supplied text), client IP, timestamp, your site name and URL. Custom-webhook and Splunk formats also include event metadata, which for a login can contain the request path and user-agent; the others do not.
Terms/privacy: https://slack.com/terms-of-service , https://slack.com/trust/privacy/privacy-policy , https://discord.com/terms , https://discord.com/privacy , https://www.splunk.com/en_us/legal/terms.html , https://www.splunk.com/en_us/legal/privacy-policy.html , https://www.pagerduty.com/terms-of-service/ , https://www.pagerduty.com/privacy-policy/ , https://www.datadoghq.com/legal/terms/ , https://www.datadoghq.com/legal/privacy/ . A webhook, Splunk HEC or syslog collector you supply is your own server, so its terms are yours.

7. Your own site (loopback) — not a third party. Long backups and scans continue by calling your site’s own admin-ajax.php; nothing leaves your server.

Privacy

Recorded locally: login attempts (attempted username, IP, time), audit log (action, user, IP), sessions (user, IP, user-agent, times), and firewall/WAF/IP-blocking records (IP, path, method, user-agent). Findings describe files, not people. Retention: audit log and login attempts about 90 days (configurable), firewall/WAF/sessions about 30 days, remote requests about 7 days.

Blocked IPs follow their own rules, not the schedule above: a temporary block ends by itself when it expires; a permanent block PowerSEC created automatically is removed after about a year (configurable); one an administrator added by hand is kept until an administrator removes it.

Deleting the plugin keeps your data by default. That site’s PowerSEC tables, settings and connection details stay, so a reinstall resumes where it left off. Running wp option update powersec_delete_data_on_uninstall 1 first (no screen for it) also drops those tables and removes PowerSEC settings, stored keys, connection details, transients, per-account data and scheduled tasks, plus the firewall folder. Backup and quarantine folders remain, as do the uploads PHP-execution guards. One secret-free pending-revocation marker remains when a Central release is unconfirmed, never reported as done. wp-admin deletion cannot notify Central, so disconnect first.

WordPress export and erasure requests are answered for records tied to a WordPress account. IP-only records cannot reliably be linked to an email address, so they are not exported or erased. Where erasure would break the tamper-evident audit chain, identifying fields are anonymised instead of deleted, and the response says so.

Files and directories this plugin writes

Everything is written inside your uploads directory (wp_upload_dir()): powersec-backups/ (archives; deny-all .htaccess), powersec-quarantine/ (detected files kept for inspection), powersec/ (firewall rules), powersec-config-backups/ (wp-config.php copies; removed on data deletion), plus guards stopping PHP executing in uploads. Two things write outside uploads: the prefix change edits wp-config.php after backing it up, and a restore adds .maintenance to the site root, removed when it ends. Restoring overwrites site files.

Credits

Chart.js v4.5.1, @kurkle/color v0.3.2 (MIT; texts in licenses/). https://github.com/chartjs/Chart.js , https://github.com/kurkle/color

Скриншоты

Установка

  1. Install from the Plugins screen, or upload the ZIP.
  2. Activate it, then open PowerSEC > Dashboard to scan.
  3. (Optional) Open PowerSEC > Central Connection and choose Connect automatically.

Multisite: PowerSEC supports multisite through per-site activation only. Network activation is intentionally refused, because each site keeps its own data and connection. Activate PowerSEC separately on each site where you need it. Data deletion removes per-user data network-wide.

Часто задаваемые вопросы

Is PowerSEC Central free?

Central has a free tier: connect sites and use the fleet dashboard free. Paid plans add cloud backups, scheduling, AI review and alerting. Every local feature works on every plan. Automatic AI review stays off until an administrator turns it on — see External services (2).

Отзывы

Нет отзывов об этом плагине.

Участники и разработчики

«PowerSEC» — проект с открытым исходным кодом. В развитие плагина внесли свой вклад следующие участники:

Участники
  • CinderEye LLC

Перевести «PowerSEC» на ваш язык.

Заинтересованы в разработке?

Посмотрите код, проверьте SVN репозиторий, или подпишитесь на журнал разработки по RSS.

Журнал изменений

Full history ships in changelog.txt.

1.4.230

  • Fix: a scan interrupted by the 1.4.229 update now restarts instead of resuming, so no finding is misread.

1.4.228

  • PowerSEC no longer changes how WordPress core auto-updates; subdirectory installs fixed.

Мета

  • Версия 1.4.230
  • Обновление: 2 дня назад
  • Активных установок: Менее 10
  • Версия WordPress 5.8 или выше
  • Совместим вплоть до: 7.1.1
  • Версия PHP 7.4 или выше
  • Язык
    English (US)
  • Метки:
    backupfirewalllogin securitymalware scannersecurity
  • Дополнительно

Оценки

Пока что нет ни одного отзыва.

Ваш отзыв

Посмотреть всеотзывы

Участники

  • CinderEye LLC

Поддержка

Есть что сказать? Нужна помощь?

Перейти в форум поддержки

  • О нас
  • Новости
  • Хостинг
  • Приватность
  • Витрина
  • Темы
  • Плагины
  • Паттерны
  • Обучение
  • Поддержка
  • Разработчики
  • WordPress.TV ↗
  • Присоединиться
  • События
  • Поддержать ↗
  • Сувениры ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Русский

  • Посетите нас в X (ранее Twitter)
  • Посетите нашу учётную запись в Bluesky
  • Посетите нашу ленту в Mastodon
  • Посетите нашу учётную запись в Threads
  • Посетите нашу страницу на Facebook
  • Посетите наш Instagram
  • Посетите нашу страницу в LinkedIn
  • Посетите нашу учётную запись в TikTok
  • Посетите наш канал YouTube
  • Посетите нашу учётную запись в Tumblr
Код — это поэзия.
The WordPress® trademark is the intellectual property of the WordPress Foundation.