Descripció
A WordPress plugin that adds security headers, CSP, login protection, SMTP, spam protection and more. Functionality is continuously being expanded to cover more ground.
Features
- Adds security headers, including configurable HSTS, X-Frame-Options, COOP and CORP
- Supports Content Security Policy (CSP), editable from the admin UI and validated against unrecognized directives
- Protects login with rate-limiting
- Blocks weak passwords, with an exemption list for individual users
- Blocks common/guessable usernames
- Validates protected brand names against required domains — self-registration blocks a brand-impersonating email outright
- Locks file editing, with a temporary admin-bar toggle that automatically relocks after a period of inactivity
- Honeypot spam protection (CF7, Elementor, WPForms, Forminator, lost password)
- Custom SMTP sending, with a test-email button
- Central security log with automatic retention, including new user account creation
- Removes certain default WordPress traces from
<head> - Blocks usernames from leaking through author URLs, the REST API and embedded author data
- English, with community translations available via translate.wordpress.org
What does it protect against?
- Basic login attacks
- Some forms of user enumeration
- Unwanted WordPress metadata
- Missing security headers
Important: it does not protect against vulnerabilities in other plugins or themes, poor server configuration, or missing updates.
Compatibility
Some security headers can affect elements such as iframes, embeds and third-party scripts. Some of the CSP directives may be too strict and might need loosening depending on your needs — this is done from the admin UI’s CSP field (administrator role).
Support
Contact webro with questions or bug reports at len@webro.dk
Instal·lació
- Upload the plugin to
wp-content/plugins/ - Activate it via the WordPress admin panel
Uninstallation
- Removes the plugin’s saved options
- Removes the plugin’s transients
- Cleans up its own settings on uninstall
Ressenyes
No hi ha ressenyes per a aquesta extensió.
Col·laboradors i desenvolupadors
«Webro Security» és programari de codi obert. La següent gent ha col·laborat en aquesta extensió.
Col·laboradorsTraduïu «Webro Security» a la vostra llengua.
Interessats en el desenvolupament?
Navegueu pel codi, baixeu-vos el repositori SVN, o subscriviu-vos al registre de desenvolupament per fisl de subscripció RSS.
Registre de canvis
1.0.4
- Fixed the security headers blocking the block editor when adding a new page/post: blob: is now allowed in the frame-src and connect-src directives of the default CSP
- wp-admin and wp-login are now excluded from the .htaccess security headers without depending on the mod_setenvif Apache module, also on sites installed in a subdirectory
- The PHP fallback for the security headers no longer applies to wp-admin and wp-login
- After an update, the plugin now rewrites its .htaccess security headers itself and drops an outdated saved default CSP, so the settings no longer have to be re-saved by hand
- Hardened the honeypot: the timing check is now signed by the server, and the way the honeypot field is hidden varies between page loads
- Expanded the list of blocked usernames
- The author name and author URL are no longer exposed in oEmbed responses, and WordPress’ built-in users sitemap is turned off, since both revealed usernames to visitors who are not logged in
1.0.0
- First version






