Title: Ensomedia Security powered by shieldwave.io
Author: shieldwave
Published: <strong>28.09.2026</strong>
Last modified: 08.10.2026

---

Поиск плагинов

![](https://ps.w.org/ensomedia-security/assets/banner-772x250.png?rev=3716337)

![](https://ps.w.org/ensomedia-security/assets/icon.svg?rev=3716310)

# Ensomedia Security powered by shieldwave.io

 Автор: [shieldwave](https://profiles.wordpress.org/shieldwave/)

[Скачать](https://downloads.wordpress.org/plugin/ensomedia-security.1.1.9.zip)

 * [Детали](https://ru.wordpress.org/plugins/ensomedia-security/#description)
 * [Отзывы](https://ru.wordpress.org/plugins/ensomedia-security/#reviews)
 *  [Установка](https://ru.wordpress.org/plugins/ensomedia-security/#installation)
 * [Разработка](https://ru.wordpress.org/plugins/ensomedia-security/#developers)

 [Поддержка](https://wordpress.org/support/plugin/ensomedia-security/)

## Описание

[shieldwave.io](https://shieldwave.io/?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme)
by [ensomedia.dev](https://ensomedia.dev)

Ensomedia Security на базе shieldwave.io сканирует ваш сайт изнутри и простым языком
рассказывает, что не так и как это исправить. В основе плагина лежит одна идея: **
уведомление должно быть достойно вашего внимания**. Все проверки, плановые сканирования
и уведомления по email бесплатны, работают без учётной записи и не имеют ограничений.

#### Почему владельцы выбирают его

 * **Сначала официальные контрольные суммы.** Каждый файл ядра WordPress, каждый
   плагин из каталога WordPress.org и каждая тема из каталога сравниваются именно
   с теми файлами, которые WordPress.org опубликовал для вашей версии. Совпадающий
   файл считается надёжным и никогда не «выглядит подозрительно». Отличающийся файл
   попадает в отчёт с указанием причины.
 * **Обнаружение вредоносного кода, требующее реальных доказательств.** Один слабый
   признак, например base64 в файле, никогда не становится находкой. Сканер ищет
   код, который выполняет то, что отправляет посетитель, декодирует и выполняет 
   скрытую полезную нагрузку, скрывает имена функций, загружает удалённый код или
   создаёт скрытых администраторов. Находки, в которых ShieldWave не уверен, попадают
   в раздел «Попросите разработчика проверить» и никогда не отправляют письмо.
 * **Отслеживание изменений для всего, что не может проверить WordPress.org.** Премиум-
   плагины, пользовательские темы, обязательные плагины и drop-in-файлы записываются
   как исходное состояние. Изменения, пришедшие вместе с обновлением, принимаются
   сами по себе; новый PHP-файл, появившийся без обновления, попадает в отчёт.
 * **Уведомления, которые не кричат «волк!» по пустякам.** Одно письмо на сканирование,
   только о новых или ухудшившихся проблемах, никогда дважды об одной и той же, 
   не больше четырёх в день. Проверка, которая не смогла выполниться (например, 
   потому что WordPress.org не ответил), никогда не отправляет письмо и никогда 
   не отмечает ничего как исправленное.
 * **Login protection and two-factor login.** Password guessers are locked out for
   a while, user names stay private, and an optional one-time code from an authenticator
   app makes a stolen password not enough.
 * **Бережно к вашему серверу.** Сканирование никогда не выполняется во время загрузки
   страницы для посетителя: оно идёт в фоновом режиме короткими шагами, укладывающимися
   в лимит хостинга в 30 секунд, а файлы, не изменившиеся с прошлого сканирования,
   повторно не анализируются.
 * **Never rewrites your site on its own.** The plugin never edits, moves or deletes
   your files, users or settings by itself. It explains each fix. The one thing 
   it deletes is an unused plugin you tick and confirm, the same as Delete on the
   Plugins screen. The only things it ever refuses are a bad login, a stranger asking
   for your user list, and the file editor and XML-RPC if you switch them off.

#### Проверки

 * **Вредоносный код и бэкдоры**: анализирует каждый PHP-, JavaScript- и .htaccess-
   файл, за который не может поручиться WordPress.org, по правилам для веб-шеллов,
   выполнения кода из запроса, цепочек декодирования и выполнения, обфусцированных
   имён функций, загрузчиков удалённого кода, PHP, скрытого в изображениях, инструментов
   спам-рассылки, скрытых администраторов, внедрённого JavaScript и вредоносных 
   перенаправлений.
 * **Core, plugin and theme files** against the WordPress.org checksums or release
   packages of your versions, plus PHP files those releases do not contain.
 * **File changes** outside those releases against the recorded baseline, and plugin
   or theme folders that appear without going through the WordPress installer.
 * **PHP-файлы в uploads**: веб-шеллы, PHP-файлы и правила .htaccess или .user.ini,
   заставляющие сервер выполнять загруженные файлы как PHP.
 * **Known vulnerabilities** (opt-in) in plugins, themes and WordPress, premium 
   ones included, with the version that fixes each one. Free and without an account;
   see External services.
 * **Closed, abandoned and unused plugins and themes**, **WordPress, plugin and 
   theme updates** and **PHP version** support.
 * **Injected content**: scripts, hidden iframes and spam links in posts, widgets
   and options. Ordinary embeds and tracking codes are left alone.
 * **Exposed files** that your web server hands out to anyone (copies of wp-config.
   php, database dumps, backups, .git folders, .env files, logs), confirmed by requesting
   them from your own site; leftover installers and database tools; folder listings.
 * **Accounts and configuration**: administrators, user registration, wp-config.
   php, debug output, file editor, XML-RPC, HTTPS, user list exposure and suspicious
   scheduled tasks.

Each issue has a severity, what it means, how to fix it and the files, plugins or
settings involved. Problems of the same kind are grouped, so a site never faces 
hundreds of lines. You can ignore a problem; an ignored file comes back if it changes
again.

Живая защита (всё включается вручную и отключено, пока вы не включите):

 * **Live threat feed**: new malware rules and file signatures from ShieldWave reach
   your site within about three hours, verified by signature. It sends nothing about
   your site.
 * **AI second opinion**: for a file the local rules cannot judge, a redacted excerpt
   gets a verdict in plain words. wp-config.php is never sent. See External services.

#### Login protection and two-factor login

 * After five failed logins from one address (you choose), that address waits a 
   cooldown you set. The lock is always temporary, and trusted addresses, including
   the one that turned the feature on, are never locked. Only the connection’s own
   address counts, never a header a request can fake.
 * User names stay private: the login form, the ?author=N trick, the REST API user
   list, embeds and the users sitemap stop giving them to visitors who are not logged
   in.
 * Two-factor login is opt-in for each administrator and works with any authenticator
   app on every login form. Ten recovery codes and `wp shieldwave two-factor disable
   <user>` make sure nobody is locked out. Apps sign in with an application password.
 * Login protection is on by default for new installs and off after an upgrade until
   you turn it on. Every lockout goes to History and can raise an alert.

#### Усиление защиты

Turn off the plugin and theme file editor and XML-RPC with one switch each, without
editing wp-config.php or any other file. ShieldWave warns you first if a plugin 
you use, such as Jetpack, needs XML-RPC. Both are off until you turn them on.

#### Уведомления

Email after scheduled scans for new or more serious issues at or above your threshold,
in real time when an account becomes administrator (naming who did it), and a weekly
summary if you want one.

#### Консоль ShieldWave (необязательно)

Press **Connect with shieldwave.io** under ShieldWave > Settings, sign in or create
a free account, and the site shows up in your dashboard at [shieldwave.io](https://shieldwave.io/?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme)
with its score and open issues, next to ShieldWave’s outside scan. A free account
shows one site; Pro and Enterprise show every site. The connection sends results
only and confirms that the domain is yours; the dashboard cannot change anything
on the site. See External services.

#### Чего этот плагин не делает

Это не полноценный веб-файрвол (он не проверяет и не блокирует каждый запрос) и 
не удаляет вредоносный код за вас. Он находит, объясняет, уведомляет, останавливает
подбор паролей при входе, добавляет двухфакторный вход и может отключить редактор
файлов и XML-RPC; остальные изменения вносите вы, ваш разработчик или хостинг. Он
ничего не добавляет на страницы, которые видят посетители.

#### Who builds it

[shieldwave.io](https://shieldwave.io/?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme)
by [ensomedia.dev](https://ensomedia.dev). Ensomedia Security is designed, built
and maintained by ENSOMEDIA, the web and software practice of Radosław Fedorczuk
in Wrocław, Poland, which also runs the shieldwave.io outside scanner and dashboard
this plugin can connect to.

#### Благодарности

Экраны консоли используют шрифт Inter от The Inter Project Authors, распространяемый
по лицензии SIL Open Font License 1.1 (`assets/fonts/inter-license.txt`). Он загружается
из самого плагина, только на экранах ShieldWave.

### Внешние сервисы

Плагин не выполняет внешних запросов при активации или загрузке страниц консоли.
Запросы происходят при сканировании (вручную или по расписанию), при использовании
действий учётной записи, а при подключённой учётной записи — ещё и при ежечасной
проверке связи. Запросы к WordPress.org и к вашему собственному сайту используют
user agent по умолчанию из HTTP API WordPress, который включает версию WordPress
и адрес сайта, точно так же, как это делает сам WordPress при проверке обновлений.
Запросы к ShieldWave отправляют нейтральный user agent (ShieldWave-Security и версия
плагина) и никогда не включают адрес вашего сайта в заголовки. Как и любой веб-запрос,
каждый из них исходит с IP-адреса вашего сервера.

**Контрольные суммы ядра WordPress.org** (api.wordpress.org/core/checksums/1.0/)

Используется проверкой «Файлы ядра WordPress». Отправляется: версия вашего WordPress
и язык пакета. Кешируется на день.

**Контрольные суммы плагинов WordPress.org** (downloads.wordpress.org/plugin-checksums/)

Используется проверкой «Файлы плагинов». Отправляется: имя папки и версия каждого
установленного плагина, по одному запросу на плагин. Кешируется на неделю.

**Пакеты тем WordPress.org** (downloads.wordpress.org/theme/)
 Используется проверкой«
Файлы темы». Пакет релиза каждой установленной темы из каталога скачивается во временный
файл, хешируется и сразу удаляется. Отправляется: имя папки и версия темы. Результат
кешируется на неделю.

**Информация о плагинах WordPress.org** (api.wordpress.org/plugins/info/1.2/)
 Используется
проверкой «Закрытые и заброшенные плагины». Отправляется: имя папки каждого установленного
плагина. Кешируется на неделю.

Все четыре предоставляются WordPress.org: [политика конфиденциальности](https://wordpress.org/about/privacy/).

**Ваш собственный сайт**
 Проверки XML-RPC, отладочного вывода и открытых файлов
запрашивают несколько адресов вашего собственного сайта (xmlrpc.php, адрес debug.
log, найденные на диске резервные файлы, папку uploads). Пока выполняется сканирование,
плагин также обращается к собственному admin-ajax.php, чтобы продолжать сканирование
в фоновом режиме.

**Проверка уязвимостей ShieldWave** (shieldwave.io, конечная точка /api/plugin/vulnerabilities),
отключена, пока вы её не включите
 Используется проверкой «Известные уязвимости».
При запуске этой проверки отправляется: версия вашего WordPress, а также имя папки,
название продукта и версия каждого установленного плагина и темы, включая премиум.
Премиум-плагин или тема сопоставляется с уязвимостью по имени папки и названию продукта.
Ни адреса сайта, ни учётной записи, ни персональных данных. В ответе перечислены
уязвимости, применимые к этим версиям; данные берутся из Wordfence Intelligence,
и каждый результат ссылается на свою запись с указанием авторских прав. Кешируется
на несколько часов.

**Лента угроз ShieldWave** (shieldwave.io, конечная точка /api/plugin/intel), отключена,
пока вы её не включите
 Используется опцией «Живая лента угроз». Плагин скачивает
подписанный файл с дополнительными правилами обнаружения вредоносного кода и сигнатурами
вредоносных и безопасных файлов примерно раз в три часа, поэтому обнаружение улучшается
между обновлениями плагина. Отправляется: ничего о вашем сайте; единственное, что
уходит, — это версия плагина, которая и так есть в каждом запросе. Перед использованием
файл проверяется криптографической подписью.

**ShieldWave AI second opinion** (shieldwave.io, endpoint /api/plugin/ai/review),
off until you turn it on
 Used by the «AI second opinion» option, and only for a
file the local rules cannot judge on their own. Sent: an excerpt of up to 6,000 
characters around the suspicious code, with your site address, email addresses and
anything that looks like a password, key or token removed (other web and IP addresses
stay), plus the file’s SHA-256 and MD5 fingerprints and size, the folder name of
its plugin or theme, the matched rule identifiers, the site language, the plugin
version and a salted hash of the site. wp-config.php and similar files are never
sent. shieldwave.io passes the excerpt to its AI provider, named in the ShieldWave
privacy policy; the verdict is kept by the file’s fingerprint and shared across 
sites.

**Link to the outside check** (shieldwave.io)
 After a scan, the Overview shows 
one line with a link to the free outside check at shieldwave.io. It is an ordinary
link: nothing is sent when the page loads. If you click it, your browser opens shieldwave.
io with this site’s domain name in the address (shieldwave.io/?check=yourdomain.
com), the same as if you typed it. It is not shown once the site is connected to
an account. Every link from the plugin to shieldwave.io carries the tags utm_source
=wordpress, utm_medium=plugin and utm_campaign=(the screen the link is on).

**ShieldWave account** (shieldwave.io), only after an administrator connects the
site under ShieldWave > Settings

 * Connecting: «Connect with shieldwave.io» opens shieldwave.io/connect in your 
   browser with this site’s address, the address to come back to and a random value.
   Back on the site, the plugin sends the single-use code, this site’s id and address,
   and the plugin, WordPress and PHP versions to /api/plugin/connect/exchange and
   receives a key for this site. With a pasted API key instead, /api/license/verify
   receives the key and /api/plugin/connect the same site facts. These endpoints
   answer only a request that carries a code or key; they are not pages.
 * While connected, the home page carries a meta tag named shieldwave-verify with
   a code of your account, and /api/plugin/verify-domain asks shieldwave.io to read
   it, after connecting and every few hours until the domain is confirmed.
 * Hourly and after each scan: /api/plugin/heartbeat receives the scan status, the
   score and issue counts. Nothing in the answer changes the site.
 * After each scan (if sending is on), for a site the dashboard shows: /api/plugin/
   sync receives the scan summary, score, active theme, site language, the open 
   and ignored issues (severity, title, message, fix, and the file, plugin or setting
   involved) and the installed plugins and themes with versions.
 * Never sent: posts, pages, comments, user names, email addresses or passwords.
   Issues about administrator accounts go with their title and fix only.
 * A free account shows one site. For another site of a free account ShieldWave 
   stores no results, and the plugin pauses these calls for 12 hours.
 * «Disconnect» calls /api/plugin/disconnect, which removes this site and its results
   from shieldwave.io; a key made for this site stops working.

ShieldWave [terms of service](https://shieldwave.io/legal/en/terms-of-service?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme)
and [privacy policy](https://shieldwave.io/legal/en/privacy-policy?utm_source=wordpress&utm_medium=plugin&utm_campaign=readme).

## Скриншоты

[⌊Обзор: безопасен ли сайт, что делать дальше и что его защищает.⌉⌊Обзор: безопасен
ли сайт, что делать дальше и что его защищает.⌉[

Обзор: безопасен ли сайт, что делать дальше и что его защищает.

[⌊Открытая проблема: что было найдено, как это исправить, и кнопка перехода на нужный
экран WordPress.⌉⌊Открытая проблема: что было найдено, как это исправить, и кнопка
перехода на нужный экран WordPress.⌉[

Открытая проблема: что было найдено, как это исправить, и кнопка перехода на нужный
экран WordPress.

[⌊Признаки взлома: что делать прямо сейчас, а также файл, правило и код, которые
совпали.⌉⌊Признаки взлома: что делать прямо сейчас, а также файл, правило и код,
которые совпали.⌉[

Признаки взлома: что делать прямо сейчас, а также файл, правило и код, которые совпали.

[⌊Сканирование, выполняющееся в фоновом режиме.⌉⌊Сканирование, выполняющееся в фоновом
режиме.⌉[

Сканирование, выполняющееся в фоновом режиме.

[⌊История: каждое сканирование и каждое важное изменение — простыми предложениями.⌉⌊
История: каждое сканирование и каждое важное изменение — простыми предложениями.⌉[

История: каждое сканирование и каждое важное изменение — простыми предложениями.

[⌊Настройки: автоматические сканирования, уведомления по email, дополнительные проверки
и необязательная учётная запись ShieldWave.⌉⌊Настройки: автоматические сканирования,
уведомления по email, дополнительные проверки и необязательная учётная запись ShieldWave
.⌉[

Настройки: автоматические сканирования, уведомления по email, дополнительные проверки
и необязательная учётная запись ShieldWave.

[⌊The optional ShieldWave account: connect the site to shieldwave.io with one click,
or with an API key.⌉⌊The optional ShieldWave account: connect the site to shieldwave.
io with one click, or with an API key.⌉[

The optional ShieldWave account: connect the site to shieldwave.io with one click,
or with an API key.

## Установка

 1. Установите плагин через Плагины > Добавить новый, либо загрузите папку `ensomedia-
    security` в `/wp-content/plugins/`.
 2. Активируйте его.
 3. Откройте **ShieldWave** и нажмите **Сканировать сейчас**. Первое сканирование записывает
    исходное состояние и обычно занимает несколько минут; последующие проходят быстрее.
 4. Плановые сканирования запускаются ежедневно в 03:00 (по времени сайта). Изменить
    это, уведомления и другие параметры можно в **ShieldWave > Настройки**.
 5. Необязательно: включите проверку известных уязвимостей в разделе **ShieldWave >
    Настройки > Дополнительные проверки**.
 6. Optional: to see the site in the ShieldWave dashboard, press **Connect with shieldwave.
    io** under **ShieldWave > Settings > ShieldWave account**.

## Часто задаваемые вопросы

### Нужна ли мне учётная запись ShieldWave?

Нет. Все 23 проверки, плановые сканирования, уведомления по email и проверка уязвимостей
работают без неё, без каких-либо ограничений.

### Можно ли скрыть ShieldWave с панели инструментов?

Да. В разделе ShieldWave > Настройки > Панель инструментов отключите «Показывать
ShieldWave на панели инструментов». Выбор действует индивидуально для каждого администратора.
Посетители его никогда не видят.

### Чем это отличается от других сканеров безопасности?

Он доверяет файлам, за которые может поручиться WordPress.org, требует реальных 
доказательств, прежде чем назвать что-то вредоносным кодом, и присылает письма только
о новых или ухудшившихся проблемах. Цель в том, чтобы каждое полученное вами уведомление
было действительно нужным.

### Что означает «Попросите разработчика проверить»?

Сканер нашёл что-то необычное, что часто оказывается безобидным: например, новый
PHP-файл в премиум-плагине без обновления. Это отображается, чтобы кто-то, кто знает
сайт, мог посмотреть, немного снижает оценку и никогда само по себе не отправляет
письмо. Проблемы в разделе «Исправить сейчас» — это те, для которых есть чёткие 
доказательства.

### Находка касается файла, который я изменил намеренно.

Open the item and press «Ignore». It stays out of the score and the alerts, and 
an ignored file comes back by itself if it changes again. Ignored items stay under
the «Ignored» link below the to-do list, where «Restore» brings one back.

### Замедлит ли это мой сайт?

Нет. Сканирование никогда не выполняется во время загрузки страницы для посетителя:
оно работает в фоновом режиме шагами по несколько секунд, а последующие сканирования
пропускают файлы, которые были чистыми и не изменились. На загруженном общем хостинге
в настройках можно выбрать щадящую скорость сканирования.

### What happens to the scheduled scan when the clocks change?

It stays on the hour you chose, in the time zone set under Settings > General, and
it follows a change of that time zone at once. On the one day a year the clocks 
skip the chosen hour, the scan runs right after the skipped hour. On the day an 
hour happens twice, it runs once, the first time the clock shows it.

### Какие внешние запросы он выполняет?

Только при сканировании: к WordPress.org за контрольными суммами, пакетами тем и
информацией о плагинах, а также к вашему собственному сайту. При включённой проверке
уязвимостей, живой ленте угроз или втором мнении ИИ: к shieldwave.io. При подключённой
учётной записи: к shieldwave.io. Каждая из этих функций отключена, пока вы её не
включите, а раздел «Внешние сервисы» ниже перечисляет, что именно отправляется.

### Зачем плагин регистрирует публичное AJAX-действие?

AJAX-действие `shieldwave_worker` позволяет запущенному сканированию продолжаться
в фоновом режиме; без случайного токена текущего сканирования оно ничего не делает.
REST-маршруты плагина отвечают только администраторам.

### Мой headless-фронтенд читает авторов через REST API.

При включённой защите входа список пользователей REST API отвечает только на запросы
от вошедших в систему, поэтому анонимный запрос автора вернёт ошибку. Чтобы оставить
список публичным, добавьте `add_filter( 'shieldwave_hide_user_list', '__return_false');`
в небольшой плагин или в functions.php вашей темы. Тот же фильтр возвращает поля
автора в embeds и карту сайта пользователей.

### Работает ли это в мультисайте?

Да, для всей сети. Сканирование, расписание, уведомления, экраны настроек и необязательная
учётная запись ShieldWave — всё это находится на главном сайте, в консоли управления
сетью, только для сетевых администраторов. Каждый другой сайт сети наследует то 
же самое решение: если защита входа, двухфакторная аутентификация или переключатель
усиления защиты включены там, они включены и для этого сайта — без отдельного экрана
настроек. Блокировка после неудачных попыток входа общая для всей сети, а не считается
отдельно по каждому сайту, поэтому адрес не может обойти лимит, пробуя другой сайт.

### Работает ли это без WP-Cron?

Да. Если WP-Cron отключён или заблокированы loopback-запросы, сканирование всё равно
выполняется, пока открыт экран ShieldWave, а плановые сканирования запускаются, 
когда серверный cron вызывает wp-cron.php.

### Как рассчитывается оценка?

Оценка начинается со 100. Для каждой проверки баллы снимает самая серьёзная открытая
проблема: критическая — 30, высокая — 15, средняя — 8, низкая — 3. Игнорируемые 
проблемы, подсказки и проверки, которые не удалось выполнить, баллов не снимают.

### Which languages does it speak?

English, Arabic, Chinese (Simplified), Dutch, French, German, Indonesian, Italian,
Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Swedish, Turkish
and Vietnamese. The screens, the login protection and the alert emails follow the
language of your WordPress admin, and Arabic gets a right-to-left layout. Regional
variants such as Spanish (Mexico), German (Switzerland) or French (Canada) use the
main language. A translation from translate.wordpress.org, once one is complete,
takes precedence.

### The old ShieldWave Security from shieldwave.io is installed too.

Builds downloaded from shieldwave.io before the directory listing were called ShieldWave
Security, numbered up to 3.6.6, and live in the folder shieldwave-security. They
cannot update themselves to this plugin. Keep Ensomedia Security active, deactivate
ShieldWave Security, then delete it on the Plugins screen: the settings, results
and two-factor set-ups carry over, because Ensomedia Security keeps them while the
old copy’s clean-up runs. The Plugins screen shows a notice while an old copy is
installed.

### What does connecting to shieldwave.io do?

It shows the site in your shieldwave.io dashboard with its score and open problems,
next to the outside scan of shieldwave.io, and confirms that the domain is yours,
which the full outside scan needs. A free account shows one site. Everything in 
the plugin works the same without it.

### Мне кажется, находка ошибочна.

Создайте тему на форуме поддержки этого плагина, указав название проверки и то, 
что вы видите. Ложные срабатывания рассматриваются как ошибки.

### Как сообщить о проблеме безопасности в плагине?

Follow https://shieldwave.io/legal/en/vulnerability-disclosure?utm_source=wordpress&
utm_medium=plugin&utm_campaign=readme. Please do not post it in the public support
forum.

## Отзывы

Нет отзывов об этом плагине.

## Участники и разработчики

«Ensomedia Security powered by shieldwave.io» — проект с открытым исходным кодом.
В развитие плагина внесли свой вклад следующие участники:

Участники

 *   [ shieldwave ](https://profiles.wordpress.org/shieldwave/)

«Ensomedia Security powered by shieldwave.io» переведён на 3 языка. Благодарим [переводчиков](https://translate.wordpress.org/projects/wp-plugins/ensomedia-security/contributors)
за их работу.

[Перевести «Ensomedia Security powered by shieldwave.io» на ваш язык.](https://translate.wordpress.org/projects/wp-plugins/ensomedia-security)

### Заинтересованы в разработке?

[Посмотрите код](https://plugins.trac.wordpress.org/browser/ensomedia-security/),
проверьте [SVN репозиторий](https://plugins.svn.wordpress.org/ensomedia-security/),
или подпишитесь на [журнал разработки](https://plugins.trac.wordpress.org/log/ensomedia-security/)
по [RSS](https://plugins.trac.wordpress.org/log/ensomedia-security/?limit=100&mode=stop_on_copy&format=rss).

## Журнал изменений

#### 1.1.9

 * Unused plugins can be deleted from their finding: tick the ones to remove (all
   are ticked) and confirm. It works like Delete on the Plugins screen, so each 
   plugin’s own uninstall runs. Only plugins in use nowhere are listed, never ShieldWave
   itself, and only for users who may delete plugins on a server where WordPress
   can write the files.
 * On a multisite network, a plugin switched on for one site only is no longer reported
   as unused.
 * Files that an older WordPress release left behind after an update are no longer
   reported as unknown PHP. Each one matches the checksums of the release it comes
   from; the check’s summary counts them and nothing needs to be done. A PHP file
   that no release explains is still reported.
 * Fewer false alarms on premium plugins: the storage index files All-in-One WP 
   Migration writes itself, the html2canvas library in Elementor Pro, a base64 image
   saved with wp_upload_bits(), and $GLOBALS read with a fixed key as in BerlinDB(
   WP Rocket and others) and ACF Pro.
 * An empty debug.log is not reported. A debug log the server refuses to hand out
   is a low note instead of a high finding; only a log that can really be downloaded
   stays high.
 * A site that works over HTTPS but has http:// in Settings > General gets a low
   note instead of «Login and dashboard are not served over HTTPS».
 * With TranslatePress active, findings no longer show its #!trpst# markers, and
   texts follow the language of the admin instead of the site.
 * A new rule finds the cmd.exec remote-control backdoor family as critical, also
   outside the uploads folder. Every file is analysed again under the new rules.
 * In the network admin the texts say «network» where a single site says «site».
 * More room in the layout: a wider side margin, a calmer header with smaller tabs,
   a smaller headline and more space between sections. WordPress notices above the
   plugin are readable in dark mode.

#### 1.1.8

 * A scan no longer stops with an error on hosting whose PHP is built without the
   tokenizer extension (rare; it is on by default almost everywhere). Without it
   the malware rules match the raw text, as before 1.1.7.

#### 1.1.7

 * A finding about files now says where they are: «in the plugin X 2.3.0 (inactive)»,«
   in the theme Y», «in WordPress’s own files» or «in the uploads folder», and the
   advice fits that place. An inactive plugin is to be deleted, a plugin from WordPress.
   org reinstalled, a premium one replaced with a fresh copy from its author, a 
   WordPress file reinstalled from Dashboard > Updates. The same goes into the email
   alert and into «Copy for your developer».
 * Every finding has «Read more»: a fuller explanation for a developer, where the
   file comes from, the steps with WP-CLI commands and how to check the fix worked,
   with a button that copies all of it. The plain message above stays as it was.
 * An old copy of ShieldWave Security (2.x or 3.x) left in the plugins folder is
   no longer reported as malware. Its scanner lists the names of known webshells
   as text to look for, which read like a webshell. Code-pattern rules now count
   only where the pattern is code, not inside a string or a translated sentence;
   real backdoors are still found.
 * After a scan, the Overview asks once whether to turn on live protection, with
   a link to what is sent. «Not now» hides it for 30 days. Nothing is turned on 
   without the click.
 * Translations shipped with the plugin now win over an older language pack from
   translate.wordpress.org, which only fills what the plugin lacks. On Polish sites
   some sentences showed in English and corrected wording never appeared.
 * An empty threat feed says that it has nothing beyond the built-in rules yet, 
   instead of showing three zeros.
 * Many screen fixes: the layout is centred on wide screens, titles wrap instead
   of being cut off, form fields and the selected option read clearly in dark mode,
   notices above the plugin follow its theme, commands and settings fit a phone,
   the settings section list stays in view and marks the right section, changed 
   settings that are not saved yet are marked and leaving asks first, no glow under
   buttons, and one-letter words no longer end a Polish line.
 * The link to this site on shieldwave.io opens «My sites».

#### 1.1.6

 * On a multisite network the ShieldWave screens are styled again. In the network
   admin WordPress names the screen differently from a single site, so the plugin
   did not recognise its own screens there: the stylesheet did not apply (plain 
   lists, tiny text), History and Settings opened as the Overview, and the footer
   line was missing.
 * WordPress itself is no longer reported as vulnerable for two old records that
   match every version and that WordPress has never fixed (a blind server-side request
   through pingbacks and activation keys stored in plain text). An up-to-date site
   was told «WordPress has 2 known vulnerabilities» and to wait for a fix that is
   not coming. A real vulnerability in WordPress is still reported with the release
   that fixes it.
 * A WordPress release that WordPress.org marks as insecure is reported with the
   secure release of its branch, even before the vulnerability databases have a 
   record for the fix.
 * A vulnerability in WordPress itself with no fixed release no longer offers the
   Plugins screen.

#### 1.1.5

 * The site and shieldwave.io agree on a language. When the site connects, the plugin
   tells shieldwave.io the site’s language; an account that has not chosen one yet
   takes it over, so the emails, reports and dashboard of shieldwave.io come in 
   the language the site already uses. The account’s language is shown next to the
   account under Settings and follows a change made in the dashboard within the 
   hour.

#### 1.1.4

 * Known-vulnerability checks and the threat feed now run every hour instead of 
   every three, so a vulnerability disclosed for one of your plugins or themes is
   reported, and emailed if alerts are on, within the hour. The lookups are cached
   on shieldwave.io, so the extra runs cost your site almost nothing. An existing
   schedule is moved to the new rhythm on update.

#### 1.1.3

 * A plain image in the uploads folder is no longer reported as an unknown PHP file.
   With «Images» switched on in Extra checks, every picture was listed as a high
   finding (a shop with 200 product photos saw all 200), and the email alert went
   out for them. An image is now reported only when ShieldWave actually finds PHP
   code inside it, which it still does.

#### 1.1.2

 * The screens keep the size of the WordPress admin on large monitors. Since 1.0.3
   the whole plugin was enlarged on windows wider than 1920 pixels (a third bigger
   at 2560); now a wider window gives the lists more room instead of bigger letters.
   Only a 4K window at 100% scaling gets one small step up.
 * The header, the status band, the lists and the footer share one left and right
   edge, and the light under the current tab sits exactly on the header’s bottom
   line.
 * A tidier header: a slightly lower headline, the theme switch and Scan now in 
   the same rounded shape.
 * More bot traffic in the simulation on the planet, most of it aimed at your site,
   also when the system asks for less motion.

#### 1.1.1

 * The automatic scan stays on the hour you chose. It kept its old clock time after
   the clocks changed or after you picked another time zone under Settings > General,
   so «At 03:00» could sit beside «Next scan at 02:00». Every run now plans the 
   next one from your site’s own time. On the one day the clocks skip the chosen
   hour, the scan runs right after it; when an hour happens twice, it runs once,
   the first time.
 * The update replaces the schedule of 1.1.0 at once, and nothing is scheduled twice.
 * The weekly summary follows your site’s clock in the same way.
 * The hours in the list under «At» use your site’s time format, the same as «Next
   scan», and «today» and «tomorrow» are right on the days the clocks change.
 * «See plans» opens the pricing page with the Pro plan selected.
 * After a scan, the Overview shows one plain line about the free outside check 
   at shieldwave.io, with your domain filled in. There is nothing to dismiss, and
   nothing is sent unless you click it.
 * Every link from the plugin to shieldwave.io carries the tags utm_source=wordpress,
   utm_medium=plugin and utm_campaign=(the screen the link is on), which tell shieldwave.
   io only which link a visit came from.

#### 1.1.0

 * Connect with shieldwave.io in one click, from Settings or the Overview: sign 
   in or create a free account there, press «Connect this site» and you are back.
   Pasting an API key still works, under «Use an API key instead».
 * A free shieldwave.io account shows one site in the dashboard, with its score 
   and open problems.
 * While connected, shieldwave.io confirms that the domain is yours from an invisible
   tag on the home page, so its full outside scan can run on the site.
 * Disconnecting removes the site and its results from shieldwave.io, and a copy
   of the site at another address (a staging copy) shows as a site of its own.
 * The dashboard shows the AI second opinion on a file, and problems you ignored
   as ignored.
 * Known vulnerabilities: plugins whose folder name has capital letters are matched
   again, and one plugin the lookup cannot read no longer stops the check for all
   the others.
 * The old ShieldWave Security from shieldwave.io and this plugin can be installed
   side by side without losing anything: deactivating or deleting one leaves the
   settings, results, schedule and two-factor set-ups of the other alone, and a 
   notice says how to remove the old copy.
 * Problems about administrator accounts are sent to the dashboard without the account
   names, and the texts about what is sent say exactly that.
 * «Turn all of it on» beside Live protection on the Overview works without JavaScript
   too.

#### 1.0.3

 * A clearer Overview: every group of problems has its own heading above its list,
   a row shows the name of the problem, and everything else opens with a click.
 * The tabs in the header are easier to see, and the Settings tab shows how many
   protections are still off.
 * The look of shieldwave.io: its colours, and its planet beside the status of your
   site. The planet marks where your site is and shows a simulation of typical bot
   traffic; a button beside it stops the motion.
 * The screens grow with the window on large monitors, and buttons are easier to
   hit on phones.
 * «New» marks a problem only when some problems are new and others are not.
 * When a problem has no WordPress screen to open, «Copy for your developer» is 
   the main button.
 * No request for a review while something urgent is open.
 * «Turn on» beside Known vulnerabilities opens the right part of Settings, and 
   the time of an AI second opinion no longer says «ago» twice.
 * In the dark theme the hour of the automatic scan stays readable while its list
   is open, and switches that are off have a visible edge.

#### 1.0.2

 * Emails display correctly in Outlook on Windows: the button keeps its padding,
   the fonts stay the same in every part of the message, and a long file path wraps
   instead of widening the message.
 * The ShieldWave mark in emails is in the brand colour, so it shows in Outlook’s
   dark mode too.

#### 1.0.1

 * Translated into Arabic, Chinese (Simplified), Dutch, French, German, Indonesian,
   Italian, Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Swedish,
   Turkish and Vietnamese.
 * Right-to-left layout for Arabic and other right-to-left admin languages.
 * The ShieldWave mark in the plugin’s header and admin menu, the same as on shieldwave.
   io.
 * Alert emails carry the ShieldWave mark (embedded in the email, nothing is loaded
   from outside), a clearer layout and a right-to-left layout for Arabic.
 * After a few scans, the Overview asks once whether you would review the plugin
   on WordPress.org. «Later» and «Do not ask again» are remembered per administrator.

#### 1.0.0

 * Первый релиз в каталоге WordPress.org.
 * Сборки, скачанные ранее с shieldwave.io, имели номера до 3.6.6 включительно. 
   Чтобы перейти на эту версию, деактивируйте и удалите ту копию, затем установите
   эту; первое сканирование заново начнёт историю файлов.

## Мета

 *  Версия **1.1.9**
 *  Обновление: **12 часов назад**
 *  Активных установок: **Менее 10**
 *  Версия WordPress ** 6.2 или выше **
 *  Совместим вплоть до: **7.1.3**
 *  Версия PHP ** 7.4 или выше **
 *  Языки
 * [English (US)](https://wordpress.org/plugins/ensomedia-security/), [Polish](https://pl.wordpress.org/plugins/ensomedia-security/),
   [Russian](https://ru.wordpress.org/plugins/ensomedia-security/) и [Swedish](https://sv.wordpress.org/plugins/ensomedia-security/).
 *  [Перевести на ваш язык](https://translate.wordpress.org/projects/wp-plugins/ensomedia-security)
 * Метки:
 * [File Integrity](https://ru.wordpress.org/plugins/tags/file-integrity/)[hardening](https://ru.wordpress.org/plugins/tags/hardening/)
   [malware scanner](https://ru.wordpress.org/plugins/tags/malware-scanner/)[security](https://ru.wordpress.org/plugins/tags/security/)
   [vulnerability scanner](https://ru.wordpress.org/plugins/tags/vulnerability-scanner/)
 *  [Дополнительно](https://ru.wordpress.org/plugins/ensomedia-security/advanced/)

## Оценки

Пока что нет ни одного отзыва.

[Ваш отзыв](https://wordpress.org/support/plugin/ensomedia-security/reviews/#new-post)

[Посмотреть всеотзывы](https://wordpress.org/support/plugin/ensomedia-security/reviews/)

## Участники

 *   [ shieldwave ](https://profiles.wordpress.org/shieldwave/)

## Поддержка

Есть что сказать? Нужна помощь?

 [Перейти в форум поддержки](https://wordpress.org/support/plugin/ensomedia-security/)