بازدان بۆ ناوەڕۆک
WordPress.org

وۆردپرێس بەکوردی

  • ڕووکارەکان
  • پێوەکراوەکان
  • دەربارە
  • وۆردپرێس بە دەستبێنە
وۆردپرێس بە دەستبێنە
WordPress.org

Plugin Directory

CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan

  • پێوەکراوێک بڵاوبکەرەوە
  • دڵخوازەکانم
  • Log in
  • پێوەکراوێک بڵاوبکەرەوە
  • دڵخوازەکانم
  • Log in

CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan

لەلایەن WPセンター
داگرتن
  • وردەکارییەکان
  • پێداچوونەوەکان
  • دامەزراندن
  • گەشەپێدان
پشتیوانی

وەسف

CenterShield is a WordPress security plugin built for Japanese site owners and the
agencies that maintain their sites.

It brings login protection, two-factor authentication, hardening, file protection and
malware scanning together in one place. Every setting explains what it protects and
what changes when you turn it on, so you can choose the measures your site needs
without security expertise.

The admin interface and all messages are in Japanese only.

Activating the plugin changes nothing on your site. Press “apply recommended settings”
to enable the recommended set in one step, or turn on each feature yourself.

Account and login protection

  • Login attempt limiting (brute force protection)
  • Username disclosure prevention
  • Custom login URL
  • HTTP Basic authentication on the login screen (written to .htaccess on Apache)
  • reCAPTCHA v2 / v3
  • Two-factor authentication (authenticator app, email, backup codes), with an optional grace period and an option to skip the code for 30 days on trusted devices
  • XML-RPC disabling (signed Jetpack requests are still allowed)
  • IP address restriction for the admin area

Disabling unused features and weak settings

  • Pingback
  • REST API restriction (well known plugins such as Contact Form 7, Jetpack and WooCommerce stay allowed)
  • Author archive pages
  • Theme and plugin file editor, application passwords
  • Unneeded tags in wp_head, such as the WordPress version, the RSD link and emoji scripts

File and server protection

  • Blocking direct access to wp-includes, wp-config.php, configuration and backup files
  • Blocking PHP execution in the uploads folder
  • Disabling directory listing
  • Security headers such as X-Frame-Options
  • Removing publicly readable files such as readme.html
  • Permission review and correction

Ongoing protection

  • Input filtering (lightweight WAF)
  • Comment spam blocking (honeypot, rate limit, previous spam history)
  • Detection of plugins and themes that have gone two years without an update or are not tested with your version of WordPress

Malware scanning

  • Comparison against official checksums for WordPress core and plugins hosted on WordPress.org. Differences limited to comments or line endings are reported as informational
  • Matching against a known vulnerability database
  • Pattern matching against malware signatures bundled with the plugin and updated from the author’s server
  • Change detection against the previous scan, for themes and plugins that are not on WordPress.org
  • Database inspection of posts, widgets and administrator accounts
  • Quarantine, restore from the official original, and difference display

External services

This plugin connects to the following external services. No site content, post data
or user data is transmitted to any of them, and every request identifies itself with a
fixed user agent rather than the WordPress default, which would carry your site address.

api.wpcenter.jp (WP Center, the plugin author)

Used to download malware signature definitions and known vulnerability data. The
request is sent when the plugin checks for definition updates and when a scan needs
vulnerability data. What is sent: the plugin version, and the metadata that any web
request carries, namely your server IP address and a fixed user agent string
(“WPCenterSecurity/” followed by the plugin version) that does not contain your site address. What is
received: signature definitions, their digital signature, and vulnerability records.
Your site address and the list of plugins and themes installed on your site are never
sent; matching is performed locally on your site.

Terms of service: https://wpcenter.jp/plugin-terms/
Privacy policy: https://wpcenter.jp/privacy/

The vulnerability records served from this endpoint originate from Wordfence
Intelligence, provided by Defiant, Inc., and include CVE records from the MITRE
Corporation. Copyright designations for both are shown with every record in the
scan results, and the Wordfence Intelligence terms are reproduced in
licenses/wordfence-intelligence-terms.txt inside this plugin. WP Center is not
affiliated with, endorsed by or sponsored by Wordfence or Defiant, Inc.

Wordfence Intelligence: https://www.wordfence.com/threat-intel/
Wordfence Intelligence terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
Wordfence privacy policy: https://www.wordfence.com/privacy-policy/
CVE terms of use: https://www.cve.org/Legal/TermsOfUse

api.wordpress.org and downloads.wordpress.org

Used to obtain official checksums during a scan. What is sent: the WordPress version
and locale, and the slug and version of each plugin being verified. What is received:
file checksums.

WordPress.org privacy policy: https://wordpress.org/about/privacy/

core.svn.wordpress.org and plugins.svn.wordpress.org

Used only when you press “compare with the original” or “restore the original” on a
scan result. What is sent: the version and file path of the file being retrieved.
What is received: that single original file, from the official WordPress.org
repository.

WordPress.org privacy policy: https://wordpress.org/about/privacy/

www.google.com (reCAPTCHA)

Used only if you enable reCAPTCHA and enter your own keys. The reCAPTCHA script is
then loaded on the forms you select, and the token is verified against Google. What
is sent: the reCAPTCHA token, your secret key and the visitor IP address.

Google terms: https://policies.google.com/terms
Google privacy policy: https://policies.google.com/privacy

Third-party resources

  • Vulnerability data: Wordfence Intelligence Vulnerability Database (https://www.wordfence.com/threat-intel/). Copyright Defiant, Inc. CVE records copyright The MITRE Corporation. Redistributed under the Wordfence Intelligence Terms and Conditions, a copy of which is included in licenses/wordfence-intelligence-terms.txt. Each record displays its copyright designation in the scan results.
  • Original file comparison: the public WordPress.org checksum API and SVN repositories.
  • Part of the malware definitions: Linux Malware Detect (LMD) signatures, Copyright R-fx Networks, GNU GPL v2, https://github.com/rfxn/linux-malware-detect, incorporated under the terms of the GPL. Known malicious domains: URLhaus (abuse.ch, CC0, https://urlhaus.abuse.ch/).
  • QR code generation: qrcode-generator v1.4.4, Copyright (c) 2009 Kazuhiko Arase, MIT License (assets/js/qrcode.min.js).

سکرین شۆتەکان

Dashboard with the recommended settings status, the apply button and the site environment check
Dashboard with the recommended settings status, the apply button and the site environment check
Account and login protection settings
Account and login protection settings
File and server protection written to .htaccess
File and server protection written to .htaccess
Malware scan results with severity ratings
Malware scan results with severity ratings

دامەزراندن

  1. Upload the plugin and activate it. Nothing is changed on your site at this point.
  2. Open the “CenterShield” menu and press “apply recommended settings” on the dashboard, or enable individual settings yourself.
  3. Run a malware scan.

پهد

I forgot my custom login URL

Rename this plugin’s folder under wp-content/plugins/ using FTP or your hosting file
manager. The plugin stops loading and /wp-login.php works again. Your settings are
preserved. The exact folder name is shown on the Settings tab of the plugin.

I am locked out of the admin area

Add define( 'WPCS_DISABLE', true ); to wp-config.php. Every feature of the plugin
pauses while that line is present.

I forgot the HTTP Basic authentication password

Basic authentication is applied by .htaccess, so renaming the plugin folder does not
remove it. Open the .htaccess file in your site root and delete the block that starts
with the Basic authentication comment inside the “CenterShield” markers. Full
instructions are on the Settings tab of the plugin.

Does the plugin change my site when I activate it?

No. Every setting is off after activation. Nothing is written to .htaccess and no
scan is scheduled until you choose to enable it.

پێداچوونەوەکان

هیچ پێداچوونەوەیەک نەنووسراوە بۆ ئەم پێوەکراوە.

بەشداربووان و گەشەپێدەران

“CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan” نەرمەواڵەیەکی سەرچاوە کراوەیە. ئەم کەسانەی خوارەوە بەشدارییان تێدا کردووە.

بەشداربووان
  • WPセンター

“CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan” وەرگێڕدراوە بۆ 1 زمان. سوپاسی وەرگێڕەکان دەکەین بۆ بەشداریکردنیان.

“CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan” وەربگێڕە بۆ زمانەکەی خۆت.

دەتەوێت بەشداربیت لە گەشەپێدان؟

گەڕان لە کۆدەکەدا بکە، سەیری تەمارگەی (SVN) بکە، یان بەشداربە لە ڕووداوتۆماری گەشەپێدان لە ڕێگەی (RSS).

ڕووداوتۆمارگەریی گۆڕین

1.0.6

  • CenterShield notices (malware scan results and .htaccess status) now appear only on the CenterShield screens instead of on every admin page. The .htaccess notices can be dismissed with the close button and come back only when the situation changes.
  • Dashboard: the malware scan card now has separate “View results” and “Start a new scan” buttons, and the scan button starts the scan right away instead of only opening the scan screen.
  • Malware scan: when several files of one plugin differ from the official release, the official zip of that version is downloaded once and compared file by file, so differences that are only line endings or comments are reported as minor instead of critical. Plugin findings now offer “Reinstall the plugin from the official release”, which replaces the whole plugin folder with the official files of the same version and resolves all findings of that plugin at once.
  • Malware scan: PHP files that only stop at the first line and contain plain text after it (such as plugin log files), or that only return a list of values (such as plugin settings files), are now reported as reference information instead of critical or warning.
  • Settings: new “Clear scan results” section with a button that clears the last malware scan result. Quarantined files, the ignore list and settings are kept, and the action is recorded in the log with the user name.

1.0.5

  • Notices on the CenterShield screens now appear between the header and the tabs instead of inside the header.
  • “Apply recommended settings” now checks whether the site links to author pages (menus, the front page, the latest post, or the theme) and leaves author pages visible on sites that use them, explaining why in the notice.
  • The header and the dashboard now show how many security measures exist in total and how many of them are recommended, alongside how many are enabled.
  • When the server rejects part of the .htaccess rules, CenterShield now identifies which setting the server does not support, keeps the other rules in place, and names that setting and the required AllowOverride permission in the notice instead of removing all rules. Settings that are on but not in effect are marked on the settings screen and no longer count as applied.

1.0.4

  • Two-factor authentication: the list of roles that can be required now shows how many users each role has.
  • Settings screens now keep the save button visible with an “unsaved changes” message after you change a setting, and warn you before leaving the page without saving.

1.0.3

  • Malware scan: image files (JPEG, PNG, GIF, WebP, BMP) are now checked for hidden PHP code.
  • Malware scan: translation files (.l10n.php) that contain only translated text are no longer reported as changed when WordPress updates translations.
  • The Japanese interface now uses the term used in the WordPress Japanese glossary for two-factor authentication.

1.0.2

  • Fixed vulnerability results continuing to show the old version for up to 12 hours after updating WordPress, a plugin or a theme from the WordPress update screen.
  • Two-factor authentication: the grace period setting can now be changed only after at least one role is set to require two-factor authentication.
  • Clearer notice for plugins and themes distributed outside WordPress.org, so it no longer reads as if CenterShield itself were missing from the directory.

1.0.1

  • Fixed the icon position and size of the admin buttons on WordPress 6.x.
  • Fixed malware scan false positives for security plugin files inside another WordPress installed in a subfolder.
  • Scan results are now grouped by type (suspected malware, suspected tampering, accounts and database, vulnerabilities) so the nature of each finding is clear at a glance.
  • WordPress core vulnerability results now show an “Update WordPress” button at the top of the result.
  • Two-factor authentication: added a grace period that lets users in required roles log in for a set number of days before they must set up two-factor authentication.
  • Two-factor authentication: added an option to skip the code for 30 days on devices the user chooses to remember.
  • Fixed the QR code on the two-factor authentication setup screen being stretched vertically.
  • Two-factor authentication: when you choose email codes on the profile screen, a confirmation code is now sent first, and the method is turned on only after you enter it.

1.0.0

  • First release.

مێتا

  • وەشان 1.0.6
  • دوایین بەڕۆژکردنەوە 22كاتژمێر لەمەوبەر
  • دامەزراندنی چالاک کەمتر لە 10
  • وەشانی وۆردپرێس 5.8 یان بەرزتر
  • تاقیکراوەتەوە تا 7.1.2
  • وەشانی PHP 7.4 یان بەرزتر
  • زمانەکان

    English (US) و Japanese.

    وەریبگێڕە بۆ زمانەکەی خۆت

  • تاگەکان
    2FAfirewallloginmalwaresecurity
  • بینینی پێشکەوتوو

هەڵسەنگاندنەکان

No reviews have been submitted yet.

Your review

بینینی هەموو پێداچوونەوەکان

بەشداربووان

  • WPセンター

پشتیوانی

هیچت هەیە بۆ وتن؟ پێویستت بە یارمەتییە؟

بینینی مەکۆی پاڵپشتی

  • دەربارە
  • هەواڵەکان
  • خانەخوێکردن
  • تایبەتمەندێتی
  • پیشاندان
  • ڕووکاره‌کان
  • پێوه‌کراوه‌کان
  • شێوەئاساکان
  • فێربە
  • پاڵپشتی
  • گەشەپێدەران
  • WordPress.tv ↖
  • بەشداری بکە
  • بۆنەکان
  • بەخشین ↖
  • سواگ ↖
  • WordPress.com ↖
  • Matt ↖
  • bbPress ↖
  • BuddyPress ↖
WordPress.org
WordPress.org

وۆردپرێس بەکوردی

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • سەردانی هەژماری (Mastodon) بکە
  • Visit our Threads account
  • سەردانی پەڕەی فەیسبووکمان بکە
  • سەردانی هەژماری ئینستاگراممان بکە
  • سەردانی هەژماری لینکدئینمان بکە
  • Visit our TikTok account
  • سەردانی کەناڵەکەمان بکە لە یوتیوب
  • Visit our Tumblr account
کۆد هۆنراوەیە.
The WordPress® trademark is the intellectual property of the WordPress Foundation.