सामग्रीमा जानुहोस्
WordPress.org

नेपाली

  • थिमहरू
  • प्लगिनहरू
  • समाचार
  • बारेमा
  • नेपालीमा वर्डप्रेस
  • टिम
  • WP-CLI
  • वर्डप्रेस प्राप्त गर्नुहोस्
वर्डप्रेस प्राप्त गर्नुहोस्
WordPress.org

Plugin Directory

Solutiontech Seguridad de acceso

  • प्लगिन पेस गर्नुहोस्
  • मेरा मनपर्दोहरू
  • लगइन गर्नुहोस्
  • प्लगिन पेस गर्नुहोस्
  • मेरा मनपर्दोहरू
  • लगइन गर्नुहोस्

Solutiontech Seguridad de acceso

solutiontechcl द्वारा
डाउनलोड गर्नुहोस्
  • विवरण
  • समीक्षाहरू
  • स्थापना
  • विकास
सहायता

विवरण

Seguridad de acceso por Solutiontech protects WordPress access and reduces unnecessary public exposure without renaming core files or modifying .htaccess.

Main features:

  • 2FA Emergency Backup Recovery Codes: Generates secure single-use recovery code sets in user profiles to prevent lockouts.
  • Cloudflare Turnstile Anti-Bot Protection: Frictionless, privacy-first bot detection challenge across login, registration, and lost password forms.
  • Malware Upload Shield (PHP File Scanner): Automatically scans /wp-content/uploads/ for suspicious executable PHP scripts and backdoors.
  • Interactive Audit Log Filter & Live Search: Instant client-side search and category filtering across recorded security events.
  • Authenticator App 2FA (TOTP – RFC 6238): Support for Google Authenticator, Microsoft Authenticator, and Authy with QR code pairing in user profiles.
  • GeoIP Country Restriction: Allow or block access based on visitor country code from reverse proxies and Cloudflare.
  • Security Email Alerts: Real-time HTML notifications with anti-flood rate limits for brute force, WAF blocks, and core discrepancies.
  • WordPress Dashboard Widget: Overview widget with security score ring, status pills, and 24-hour threat metrics.
  • Micro-WAF (Web Application Firewall): Early inspection and neutralisation of SQL Injections (SQLi), Cross-Site Scripting (XSS), Path Traversal (LFI), Remote Code Execution (RCE), and malicious security scanners.
  • IP Whitelist & Permanent Blacklist: Allows instant exclusion for trusted IPs and permanent 403 blocking for malicious IPs and CIDR ranges across the entire website.
  • WordPress Core File Integrity Checker: Verifies local core files against official WordPress.org cryptographic MD5 checksums to detect modified or missing CMS files.
  • Two-Factor Authentication (2FA via Email OTP): Delivers a 6-digit one-time code to authorized user emails to secure privileged logins.
  • Strong Password Policies & Expiration: Enforces 12+ character complexity and optional periodic password expiration reminders.
  • Official Internationalization & Translation Template: Standard .pot file included in languages/ for seamless translation with Poedit, Loco Translate, or WordPress.org GlotPress.
  • Invisible Honeypot Anti-Spam: Blocks automated bots across login, password recovery, registration, and comment forms without annoying CAPTCHAs.
  • Pingback & XML-RPC DDoS Protection: Strips X-Pingback headers and disables XML-RPC pingback reflection methods.
  • WordPress Core Hardening: Hide WordPress version from headers/feeds/asset query strings, remove legacy discovery tags (RSD, WLWManifest, oEmbed), and disable built-in file editing.
  • Background automated cleanup with WP-Cron for expired audit logs and 404 entries.
  • Secure CSV export for Audit Log and 404 Monitor with Excel UTF-8 BOM and formula injection protection.
  • Runtime in-memory caching for faster settings retrieval without redundant database queries.
  • Google reCAPTCHA v3 invisible bot protection with score threshold on login and lost-password forms.
  • HTTP Security Headers injection (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and HSTS).
  • Progressive brute-force lockout with escalating lockout tiers for repeat offenders.
  • Optional WooCommerce catalog mode, including controls for administrators and variable products.
  • Security status dashboard with an informative score and links to each setting.
  • Responsive sidebar navigation organized by security area.
  • Session and device management based on native WordPress session tokens.
  • Individual session revocation, single-session policy, and optional inactivity timeout.
  • Optional alerts when a user signs in from a new device.
  • 404 monitor with retention, entry limits, and direct conversion to a redirect rule.
  • Same-site redirect manager supporting 301, 302, 307, and 308 responses.
  • Optional custom login URL and random URL regeneration.
  • Protection against direct access to wp-login.php and wp-admin for visitors.
  • Configurable login attempt limiting by IP address using WordPress transients.
  • Generic login errors to reduce account enumeration.
  • Optional author enumeration and public REST user endpoint protection.
  • Optional XML-RPC restriction.
  • Environment diagnostics for Multisite, subdirectories, proxy/CDN setups, WooCommerce, and recovery flows.
  • Optional deterrents for casual copying of images and text.
  • Local audit log for relevant authentication and administration events.
  • Configurable audit-log retention from 1 to 365 days, limited to 500 events.
  • Independent controls for new comments and pingbacks on posts and pages.
  • Optional email alerts when the login-attempt limit is reached.
  • Configurable response for blocked login routes: 404, home page, or a custom URL.

The plugin does not modify WordPress files. After deactivation, WordPress uses its standard login routes again.

Developer website: https://solutiontech.cl/

External services

This plugin can connect to the following third-party external services when explicitly configured and enabled by the site administrator:

  • Google reCAPTCHA v3:

    • Purpose: Protects authentication and password recovery forms against automated bots and credential-stuffing attacks.
    • Data sent & when: When enabled with site administrator API credentials, user interaction tokens and visitor IP address are sent to https://www.google.com/recaptcha/api/siteverify during form submission to obtain a risk confidence score.
    • Service provider: Google LLC.
    • Terms of Service: https://policies.google.com/terms
    • Privacy Policy: https://policies.google.com/privacy
  • Cloudflare Turnstile:

    • Purpose: Provides frictionless, privacy-preserving smart anti-bot challenge validation on login, registration, and lost password forms.
    • Data sent & when: When enabled with site administrator API credentials, the Turnstile response token and visitor IP address are sent to https://challenges.cloudflare.com/turnstile/v0/siteverify during form submission.
    • Service provider: Cloudflare, Inc.
    • Terms of Service: https://www.cloudflare.com/website-terms/
    • Privacy Policy: https://www.cloudflare.com/privacypolicy/
  • WordPress.org Core Checksums API:

    • Purpose: Validates the integrity of local WordPress CMS files against official cryptographic checksums in the Diagnostics panel.
    • Data sent & when: The current WordPress version and locale string (e.g., version and language code) are sent to https://api.wordpress.org/core/checksums/1.0/ only when an administrator clicks the “Comprobar integridad del núcleo” button in the diagnostics dashboard. No user personal data is sent.
    • Service provider: WordPress Foundation / WordPress.org.
    • Privacy Policy: https://wordpress.org/about/privacy/
  • Note on 2FA QR Codes: Two-Factor Authentication (TOTP) QR codes are generated 100% locally on your server in pure PHP as inline SVG. No secret keys or user data are ever sent to any external server or third-party service.

Privacy

The plugin does not send telemetry to Solutiontech. Optional security modules store their data locally in the WordPress database. Audit events may include complete IP addresses for forensic traceability, while the administration table displays masked addresses. WordPress session tokens may contain IP, browser, and date information. The 404 monitor does not store IP addresses or query parameters. If email alerts are enabled, the site sends the relevant information through its configured mail system. Site administrators are responsible for providing any required privacy notice and choosing an appropriate retention period.

स्क्रिनसटहरू

Security Overview Dashboard with safety score gauge, protection indicators, and module matrix.
Security Overview Dashboard with safety score gauge, protection indicators, and module matrix.
Custom Login URL and Brute-Force Rate Limiting configuration.
Custom Login URL and Brute-Force Rate Limiting configuration.
Micro-WAF (Web Application Firewall), IP Access Lists (Whitelist/Blacklist), and Country Geolocation Filtering (GeoIP).
Micro-WAF (Web Application Firewall), IP Access Lists (Whitelist/Blacklist), and Country Geolocation Filtering (GeoIP).
Interactive Live Forensic Audit Log with instant search, category filtering, and CSV export.
Interactive Live Forensic Audit Log with instant search, category filtering, and CSV export.

स्थापना

  1. Upload the solutiontech-seguridad-de-acceso folder to /wp-content/plugins/, or install the ZIP from Plugins > Add Plugin.
  2. Activate the plugin.
  3. Open Seguridad de acceso from the main WordPress administration menu.
  4. Save or copy the new login URL before signing out.
  5. Enable only the modules required by the site.

प्रश्नोत्तर

What happens if I forget the custom login URL?

Temporarily rename the plugin folder using your hosting control panel, FTP, or SSH. WordPress will use wp-login.php again while the plugin is disabled.

Does the plugin modify .htaccess or WordPress core files?

No.

What does the audit log record?

When enabled, it stores the date and time, related user, available IP address, event type, and a short description of selected security and administration events. The data remains in the site’s own database.

Is the audit log enabled by default?

No. It is optional and disabled by default.

What happens when comments are blocked?

New comments and pingbacks are prevented for the selected content type. Existing comments are not deleted.

Can content protection completely prevent copying?

No. These controls are deterrents. Content downloaded by a browser may still be obtained by other means or captured in a screenshot.

Is the plugin compatible with Multisite, subdirectory installations, and WooCommerce?

The plugin includes diagnostics and dedicated handling for these environments. On Multisite, settings are stored per site. After changing the login URL, test sign-in, sign-out, and password recovery in a private browser window.

Which redirect types are supported?

The redirect manager supports 301, 302, 307, and 308. The source and destination must belong to the current site’s domain. External hosts, duplicates, loops, and critical WordPress routes are rejected.

How does session management work?

The Sessions section uses native WordPress session tokens. Administrators can review devices, close an individual session, close other sessions for their own account, or revoke sessions for another accessible account. The current administrative session is protected against accidental revocation.

What information does the 404 monitor store?

It stores the requested path without query parameters, a referrer without query parameters, a general browser/device description, first and last detection times, and a hit count. It does not store IP addresses and excludes administration, REST, AJAX, cron, critical routes, and request methods other than GET or HEAD.

समीक्षाहरू

यस प्लगिनको लागि कुनै समीक्षाहरू छैनन्।

योगदानकर्ता र डेभलपरहरू

“Solutiontech Seguridad de acceso” खुला स्रोत सफ्टवेयर हो। निम्न व्यक्तिहरूले यो प्लगिनमा योगदान गरेका छन्।

योगदानकर्ताहरू
  • solutiontechcl

“Solutiontech Seguridad de acceso” लाई आफ्नो भाषामा अनुवाद गर्नुहोस्

विकासमा रुचि छ?

आरएसएस द्वारा कोड ब्राउज गर्नुहोस्, एसभीएन रिपजिटरी हेर्नुहोस्, वा विकास लग को सदस्यता लिनुहोस्।

चेन्जलग

1.24.0

  • Threat Defense Center & Forensic Reports: Dedicated intelligence and monitoring panel with live threat KPI cards, visual attack vector distribution, Top 5 recurring hostile IPs with 1-click blacklist action, and custom Date Range Forensic CSV Report Generator (filter by date from/to, attack category, and severity).
  • Automatic IP Blacklist on Critical Attacks: Automatically adds offending IPs to permanent blacklist upon intercepting SQL Injection, Path Traversal / LFI / RCE, or hostile scanning tools.
  • WordPress Auto-Updates Manager: Centralized toggles in site protection to force automatic updates for WordPress core security releases, all installed plugins, and active themes.

1.23.2

  • Internationalization: Adds complete native translation packages for 12 locales: Spanish (Chile, Mexico, Argentina, Colombia, Peru, Spain), English (US), Brazilian Portuguese, European Portuguese, French, Italian, Russian, and Simplified Chinese.

1.23.1

  • Usability: Protected login URL is now disabled by default on initial activation to prevent unintended lockouts, allowing administrators to explicitly activate and customize their desired login route.

1.23.0

  • Adds 2FA Emergency Backup Recovery Codes (8 single-use codes) in user profiles with cryptographic hashing.
  • Adds Cloudflare Turnstile anti-bot integration with support for login, registration, and lost-password forms.
  • Adds Malware Upload Shield (suspicious executable PHP file scanner in /wp-content/uploads/) in diagnostics panel.
  • Adds interactive real-time search and category filtering in the Audit Log panel.

1.22.0

  • Adds Two-Factor Authentication via Authenticator Apps (TOTP – RFC 6238) with Google/Microsoft Authenticator and QR code pairing in user profiles.
  • Adds real-time Security Email Alerts with HTML formatting and anti-flood throttling for Brute Force lockouts, WAF attacks, and Core Integrity modifications.
  • Adds Country Geolocation Filtering (GeoIP) with Allowlist/Blocklist modes and Reverse Proxy / Cloudflare header detection.
  • Adds WordPress Dashboard Security Widget with score gauge, protection indicators, and 24h threat summary.
  • Fully compliant with WordPress.org Plugin Check validation and standards.

1.21.0

  • Adds Micro-WAF (Web Application Firewall) to detect and block SQL Injection, XSS, Path Traversal / LFI / RCE, and malicious scanner tools with forensic audit logging.
  • Adds IP Whitelist and Permanent Blacklist management with support for IPv4, IPv6, and CIDR subnet notations.
  • Adds WordPress Core File Integrity Checker comparing local core files against official WordPress.org cryptographic checksums with diagnostics dashboard integration.
  • Integrates WAF, IP rules, and Core Integrity status into the security dashboard health score.

1.20.0

  • Adds Two-Factor Authentication (2FA via Email OTP) with 6-digit cryptographic verification code and brute-force attempt limits.
  • Adds Strong Password Policies enforcing 12+ characters, uppercase, lowercase, numbers, and symbols during user creation and password resets.
  • Adds optional periodic password expiration reminders for privileged user accounts.
  • Integrates 2FA and password policy health checks into the security dashboard status score.

1.19.0

  • Adds official translation infrastructure with standard GNU gettext POT template (languages/solutiontech-seguridad-de-acceso.pot).
  • Declares Domain Path: /languages in plugin headers for automatic native localization via WordPress Core.
  • Fully compatible with Poedit, Loco Translate, WP-CLI, and WordPress.org GlotPress translation platform.

1.18.0

  • Adds Invisible Honeypot Anti-Spam protection across login, lost password, user registration, and comment forms to eliminate automated spam bot submissions.
  • Adds Pingback protection: removes X-Pingback headers from server responses and disables XML-RPC pingback methods to mitigate DDoS amplification vectors.
  • Adds optional Time-Gate submission speed filter to discard instant automated bot form submissions.
  • Integrates anti-spam and honeypot indicators into the security dashboard score and administration panel.

1.17.0

  • Adds WordPress Core Hardening module: hides generator meta tags, RSS/Atom version info, and removes ?ver= query strings matching the WordPress core version from public assets.
  • Removes legacy and unnecessary discovery tags from HTML head (RSD link, WLWManifest link, and oEmbed discovery links).
  • Adds theme and plugin file editor disabling (DISALLOW_FILE_EDIT enforcement and capability filtering) to prevent arbitrary PHP execution in case of account compromises.
  • Integrates Core Hardening items into the security dashboard health score and environment diagnostics panel.

1.16.0

  • Adds daily scheduled WP-Cron task (solutiontech_seguridad_acceso_daily_cleanup) for automated asynchronous pruning of audit logs and 404 monitor entries.
  • Adds secure CSV export functionality for Audit Log and 404 Monitor with UTF-8 BOM encoding for Excel compatibility and CSV formula injection protection.
  • Implements runtime in-memory caching for settings retrieval to optimize database performance.

1.15.0

  • Adds Google reCAPTCHA v3 invisible protection for login and lost-password forms with customizable confidence score threshold.
  • Adds HTTP Security Headers module (X-Frame-Options, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy, and HSTS).
  • Adds Progressive Brute-Force Lockout feature with escalating penalty tiers for recurring attack IPs (1x base duration -> 4x -> 24 hours).
  • Integrates new protection modules into the security status score and diagnostics dashboard.

1.14.4

  • Resolves Plugin Check update_modification_detected warning by removing core and plugin auto-update management to comply fully with WordPress.org guidelines.

1.14.3

  • Clearly distinguishes deleting a 404 history row from permanently resolving the missing URL.
  • Renames the redirect action to Resolve permanently and uses a permanent 301 redirect by default.
  • Removes the monitored 404 entry after its redirect is saved successfully.

1.14.2

  • Resolves the findings from Plugin Check concerning readme metadata, input handling, nonce analysis, and prefixed uninstall variables.
  • Uses WordPress’ native automatic-update preferences instead of filtering the plugin updater at runtime.
  • Adds regression checks for packaging and WordPress.org compatibility metadata.

1.14.1

  • Fixes an interpolated translation string in the temporary lockout email.
  • Adds regression coverage for static translatable strings and placeholder substitution.

1.14.0

  • Adds WooCommerce catalog mode under Content.
  • Hides purchasing, cart, checkout, and optional variation controls.
  • Can apply catalog mode to administrators while preserving existing order links.

1.13.5

  • Resolves internationalization findings reported by Plugin Check.
  • Adds translator comments and ordered placeholders.

1.13.4

  • Prevents inactivity enforcement from intercepting REST requests used by the block editor.
  • Masks IP addresses in the audit-log table.

1.13.3

  • Restricts redirect sources and destinations to the current domain.

1.13.2

  • Improves redirect normalization for omitted schemes and subdirectory installations.

1.13.1

  • Uses the full available width on desktop displays.

1.13.0

  • Adds individual session management for other accessible users.

1.12.5

  • Strengthens route, redirect, import, IPv6, and Multisite handling.

1.12.4

  • Improves diagnostic-card layout and responsive presentation.

1.12.3

  • Removes the promotional header from the administration panel.

1.12.2

  • Makes dashboard controls link directly to their related settings.

1.12.1

  • Improves the Copy URL button and renames technical hardening labels.

1.12.0

  • Adds the 404 monitor and refreshes the administration design.

1.11.0

  • Adds sessions, device alerts, single-session policy, and inactivity timeout.

1.10.0

  • Adds the same-site redirect manager.

1.9.0

  • Adds responsive sidebar navigation.

1.8.0

  • Adds emergency recovery, JSON import/export, reset tools, and an IP allowlist.

मेटा

  • संस्करण 1.24.0
  • पछिल्लो अपडेट 3 घण्टा अघि
  • सक्रिय स्थापना १० भन्दा कम
  • वर्डप्रेस संस्करण 6.2 वा उच्च
  • जाँच गरिएको 7.1
  • PHP संस्करण 7.4 वा उच्च
  • भाषा
    English (US)
  • ट्यागहरू
    audit logBrute Forcecontent-protectionloginsecurity
  • उन्नत दृश्य

रेटिङ्गहरू

अहिलेसम्म कुनै समीक्षा पेस गरिएको छैन।

तपाईँको समीक्षा

सबै समीक्षाहरू हेर्नुहोस्

योगदानकर्ताहरू

  • solutiontechcl

सहायता

केही भन्नु छ? सहयोग चाहियो?

सहायता फोरम हेर्नुहोस्

  • बारेमा
  • समाचार
  • होस्टिङ
  • गोपनीयता
  • सोकेस
  • थिमहरू
  • प्लगिनहरू
  • प्याटर्नहरू
  • लर्न
  • सहायता
  • डेभलपरहरू
  • WordPress.tv ↗
  • संलग्न हुनुहोस्
  • कार्यक्रमहरू
  • दान ↗
  • स्वाग ↗
  • WordPress.com ↗
  • म्याट ↗
  • बिबिप्रेस ↗
  • बडीप्रेस ↗
WordPress.org
WordPress.org

नेपाली

  • हाम्रो X (पहिले ट्विटर) खातामा जानुहोस्
  • हाम्रो Bluesky खाता भ्रमण गर्नुहोस्
  • हाम्रो म्यास्टोडन खाता भ्रमण गर्नुहोस्
  • हाम्रो थ्रेड्स खातामा जानुहोस्
  • हाम्रो फेसबुक पेजमा जानुहोस्
  • हाम्रो इन्स्टाग्राम खातामा जानुहोस्
  • हाम्रो लिङ्क्डइन खातामा जानुहोस्
  • हाम्रो TikTok खाता भ्रमण गर्नुहोस्
  • हाम्रो युट्युब च्यानलमा जानुहोस्
  • हाम्रो टम्बलर खाता भ्रमण गर्नुहोस्
कोड कविता हो।
The WordPress® trademark is the intellectual property of the WordPress Foundation.