ຂ້າມໄປທີ່ເນື້ອຫາ
WordPress.org

ລາວ

  • ທິມ
  • ປັກອິນ
  • ຂ່າວ
  • ກ່ຽວກັບ
  • ທິມລາວ
  • ຕິດຕໍ່
  • ດາວໂຫລດ WordPress
ດາວໂຫລດ WordPress
WordPress.org

Plugin Directory

Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ

  • ສົ່ງປລັກອິນ
  • ທີ່ມັກຂອງຂ້ອຍ
  • ເຂົ້າສູ່ລະບົບ
  • ສົ່ງປລັກອິນ
  • ທີ່ມັກຂອງຂ້ອຍ
  • ເຂົ້າສູ່ລະບົບ

Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ

ໂດຍ WP Ultimate Security
ດາວໂຫຼດ
  • ລາຍລອຽດ
  • ການຣີວິວ
  • ການຕິດຕັ້ງ
  • ການພັດທະນາ
ການຊ່ວຍເຫຼືອ

ຄຳອະທິບາຍ

Stop hackers and bots from getting into your WordPress site. Ultimate Security adds two-factor login, blocks password-guessing attacks, stops spam bots and warns you about plugins with known security holes. A setup wizard picks the right settings for your kind of site, so you don’t have to understand every option.

Why site owners choose it

  • Free, with no account needed. Install it and it works. No sign-up and no usage tracking.
  • Set up in about 3 minutes. The wizard asks what kind of site you run, checks it, and shows every change before applying it. You can undo it all later.
  • Try before you enforce. Test Mode shows what would have been blocked, without blocking anyone.
  • You can’t lock yourself out for good. The wizard gives you an emergency link that switches the plugin off from any browser.

Protect your login

Two-factor login. After the password, users confirm with a code sent by email or shown in an authenticator app (Google Authenticator, Authy, Microsoft Authenticator and similar). Choose which user roles need it. Works on the WordPress, WooCommerce and Ultimate Member login forms.

Stop password-guessing bots.

  • Lock out anyone who gets the password wrong too many times. Repeat offenders wait longer each time.
  • Permanently block addresses you never want to see again.
  • An administrator can send a locked-out user a 15-minute recovery link.
  • Works behind Cloudflare automatically. Site Health tells you if your host’s setup needs one extra step.

Hide your login page. Move wp-login.php to a private address so bots can’t find it.

Stronger passwords.

  • Set rules for length, letters, numbers and symbols, or pick a ready-made preset.
  • Stop people reusing old passwords, and ask for a new one on first login or after a set time.
  • Reject passwords that have appeared in known data leaks. The check never sends the password itself anywhere.

Control who stays signed in.

  • Limit how many devices one account can use at once.
  • Sign people out automatically after a period of inactivity.
  • See who is signed in right now, and end any session with one click.

Block spam and bots on your forms

Add Google reCAPTCHA or Cloudflare Turnstile to your login, registration, password reset and comment forms, and to WooCommerce login, registration and checkout.

  • Check that your keys work before going live.
  • If the CAPTCHA service is down, your forms keep working.
  • Won’t clash with another CAPTCHA plugin on the same form.

Find security problems before hackers do

Vulnerability scanner. Checks WordPress, your plugins and your themes against a database of known security holes, and emails you when it finds one. It works without an API key; WPScan or Patchstack keys add extra coverage.

  • Runs on a schedule in the background.
  • ແຈ້ງເຕືອນປລັກອິນທີ່ບໍ່ໄດ້ຮັບການອັບເດດມາເປັນເວລາດົນນານ.
  • Results show in the dashboard, Site Health and your plugins list.

Security score. One number that tells you how well protected your site is, and which fix to do next.

File check. Compares your WordPress core files with the official copies, so changed or added files stand out.

Safer updates. Choose when WordPress, plugins and themes update automatically. Set update days and quiet periods, delay updates by a few days, and get an email when something changes.

Advanced protection

Cloudflare firewall rules. If your site uses Cloudflare, connect your account and turn on ready-made rules from wp-admin: let good bots through, block bad crawlers and risky traffic, and block attacks on known WordPress flaws before you’ve had a chance to update. You can preview every rule before it goes live.

Security keys (salts). Change the secret keys in wp-config.php on demand or on a schedule, which signs everyone out and makes stolen login cookies useless. You get a warning before a scheduled change, and can restore a previous set.

Test Mode

Turn on your protections without blocking anyone, and review a log of what would have been blocked. Choose which user roles it covers. Visitors who aren’t signed in are still held to the login limit, and Test Mode switches itself off after seven days, so a forgotten test never leaves your site unprotected.

Moving from another plugin

  • Import your two-factor and login settings from Wordfence Login Security. Preview it first and undo it if you change your mind.
  • Copy your settings to another site, or keep a backup, as a file.
  • Detects WooCommerce, Ultimate Member, page builders, form, caching and SEO plugins, and warns you if another security plugin is already doing the same job.

Privacy

No usage tracking. The plugin contacts an outside service only when you switch on a feature that needs one, and each is listed under External Services below.

For developers

wp ultimate-security template list
wp ultimate-security template apply <template> [--dry-run]
wp ultimate-security template undo
wp ultimate-security export [--file=<path>]
wp ultimate-security import <file> [--dry-run]
wp ultimate-security status
wp ultimate-security unlock <user> | --ip=<address> | --all
wp ultimate-security 2fa disable <user>
wp ultimate-security captcha off
wp ultimate-security login-url reset

Video guides

  • Set up an authenticator app
  • Two-factor login by email
  • Hide your login page
  • Set strong password rules
  • Limit login sessions
  • Manage plugin and theme updates
  • Change your security keys after a breach
  • Spot changed WordPress files
  • Understand Site Health reports
  • Dashboard walkthrough
  • Move your Wordfence two-factor settings

ຮຽນຮູ້ເພີ່ມເຕີມ

  • ເວັບໄຊ — ຟີເຈີ ແລະ ບົດຄວາມຕ່າງໆ.
  • ເອກະສານອ້າງອີງ — ຄູ່ມືການຕັ້ງຄ່າ, ການແກ້ໄຂບັນຫາ ແລະ ວິທີການຕ່າງໆ.
  • YouTube — all video guides.

ບໍລິການພາຍນອກ

ປລັກອິນນີ້ເຊື່ອມຕໍ່ກັບບໍລິການພາຍນອກຕໍ່ໄປນີ້, ແລະ ສະເພາະເມື່ອທ່ານໃຊ້ຟີເຈີທີ່ກ່ຽວຂ້ອງເທົ່ານັ້ນ:

Google reCAPTCHA

  • ເວລາໃດ: ເມື່ອເປີດໃຊ້ການປ້ອງກັນຂອງ reCAPTCHA. ສະຄຣິບ reCAPTCHA ຈະຖືກໂຫຼດໃນບຣາວເຊີຂອງຜູ້ເຂົ້າຊົມໃນຟອມທີ່ຖືກປົກປ້ອງ.
  • ຂໍ້ມູນທີ່ສົ່ງ: token ການຕອບສະໜອງຂອງ reCAPTCHA ຂອງຜູ້ເຂົ້າຊົມ, secret key ຂອງເວັບໄຊ, ແລະ ທີ່ຢູ່ IP ຂອງຜູ້ເຂົ້າຊົມສຳລັບການກວດສອບ.
  • Endpoints: https://www.google.com/recaptcha/api.js (ສະຄຣິບເທິງບຣາວເຊີ, ພ້ອມການເຊື່ອມຕໍ່ລ່ວງໜ້າໄປທີ່ https://www.gstatic.com) ແລະ https://www.google.com/recaptcha/api/siteverify (ການກວດສອບຝັ່ງເຊີບເວີ).
  • ເງື່ອນໄຂ: https://policies.google.com/terms — ຄວາມເປັນສ່ວນຕົວ: https://policies.google.com/privacy

Cloudflare Turnstile

  • ເວລາໃດ: ເມື່ອເປີດໃຊ້ການປ້ອງກັນຂອງ Cloudflare Turnstile. ສະຄຣິບ Turnstile ຈະຖືກໂຫຼດໃນບຣາວເຊີຂອງຜູ້ເຂົ້າຊົມໃນຟອມທີ່ຖືກປົກປ້ອງ.
  • ຂໍ້ມູນທີ່ສົ່ງ: token ການຕອບສະໜອງຂອງ Turnstile ຂອງຜູ້ເຂົ້າຊົມ, secret key ຂອງເວັບໄຊ, ແລະ ທີ່ຢູ່ IP ຂອງຜູ້ເຂົ້າຊົມສຳລັບການກວດສອບ.
  • Endpoints: https://challenges.cloudflare.com/turnstile/v0/api.js (ສະຄຣິບເທິງບຣາວເຊີ) ແລະ https://challenges.cloudflare.com/turnstile/v0/siteverify (ການກວດສອບຝັ່ງເຊີບເວີ).
  • ເງື່ອນໄຂ: https://www.cloudflare.com/website-terms/ — ຄວາມເປັນສ່ວນຕົວ: https://www.cloudflare.com/privacypolicy/

WPVulnerability

  • ເວລາໃດ: ເມື່ອຕົວສະແກນຊ່ອງໂຫວ່ເຮັດວຽກ. ນີ້ແມ່ນຖານຂໍ້ມູນຊ່ອງໂຫວ່ເລີ່ມຕົ້ນ ແລະ ບໍ່ຈຳເປັນຕ້ອງໃຊ້ API key.
  • ຂໍ້ມູນທີ່ສົ່ງ: ເວີຊັນ WordPress ຂອງທ່ານ ແລະ slugs ຂອງປລັກອິນ ແລະ ທີມທີ່ທ່ານຕິດຕັ້ງໄວ້.
  • Endpoint: https://www.wpvulnerability.net/
  • ຄວາມເປັນສ່ວນຕົວ: https://www.wpvulnerability.net/

WPScan

  • ເວລາໃດ: ເມື່ອຕົວສະແກນຊ່ອງໂຫວ່ເຮັດວຽກ ແລະ ທ່ານໄດ້ຕັ້ງຄ່າ WPScan API key ໄວ້.
  • ຂໍ້ມູນທີ່ສົ່ງ: WPScan API key ຂອງທ່ານ, ເວີຊັນ WordPress ຂອງທ່ານ, ແລະ slugs ຂອງປລັກອິນ ແລະ ທີມທີ່ທ່ານຕິດຕັ້ງໄວ້.
  • Endpoint: https://wpscan.com/api/v3/
  • ເງື່ອນໄຂ: https://wpscan.com/terms-of-service/ — ຄວາມເປັນສ່ວນຕົວ: https://wpscan.com/privacy-policy/

Patchstack

  • ເວລາໃດ: ເມື່ອຕົວສະແກນຊ່ອງໂຫວ່ເຮັດວຽກ ແລະ ທ່ານໄດ້ຕັ້ງຄ່າ Patchstack API key ໄວ້.
  • ຂໍ້ມູນທີ່ສົ່ງ: Patchstack API key ຂອງທ່ານ, ເວີຊັນ WordPress ຂອງທ່ານ, ແລະ slugs ຂອງປລັກອິນ ແລະ ທີມທີ່ທ່ານຕິດຕັ້ງໄວ້.
  • Endpoint: https://patchstack.com/database/api/v2/
  • ເງື່ອນໄຂ: https://patchstack.com/terms-of-service/ — ຄວາມເປັນສ່ວນຕົວ: https://patchstack.com/privacy-policy/

WordPress.org Plugin and Theme Information API

  • ເວລາໃດ: ເມື່ອຕົວສະແກນຊ່ອງໂຫວ່ກວດສອບວ່າສ່ວນເສີມຖືກປະຖິ້ມແລ້ວຫຼືບໍ່, ແລະ ເມື່ອຕົວຈັດການການອັບເດດລວບລວມຂໍ້ມູນການອັບເດດ.
  • ຂໍ້ມູນທີ່ສົ່ງ: slugs ຂອງປລັກອິນ ແລະ ທີມທີ່ທ່ານຕິດຕັ້ງໄວ້ (ບໍ່ມີຂໍ້ມູນຜູ້ໃຊ້).
  • Endpoints: https://api.wordpress.org/plugins/info/1.2/ ແລະ https://api.wordpress.org/themes/info/1.2/
  • ຄວາມເປັນສ່ວນຕົວ: https://wordpress.org/about/privacy/

WordPress.org Core Version Check

  • ເວລາໃດ: ເມື່ອຕົວຈັດການການອັບເດດກວດສອບຫາການອັບເດດລະບົບຫຼັກຂອງ WordPress.
  • ຂໍ້ມູນທີ່ສົ່ງ: ຄຳຂໍກວດສອບເວີຊັນລະບົບຫຼັກຂອງ WordPress ມາດຕະຖານ (ບໍ່ມີຂໍ້ມູນຜູ້ໃຊ້).
  • Endpoint: https://api.wordpress.org/core/version-check/1.7/
  • ຄວາມເປັນສ່ວນຕົວ: https://wordpress.org/about/privacy/

WordPress.org Core Checksums

  • ເວລາໃດ: ເມື່ອທ່ານລັນການກວດສອບຄວາມສົມບູນຂອງໄຟລ໌ລະບົບຫຼັກ WordPress.
  • ຂໍ້ມູນທີ່ສົ່ງ: ເວີຊັນ ແລະ ພາສາ WordPress ຂອງທ່ານ, ເພື່ອດຶງຂໍ້ມູນ checksums ຂອງໄຟລ໌ຢ່າງເປັນທາງການມາປຽບທຽບ.
  • Endpoint: https://api.wordpress.org/core/checksums/1.0/
  • ຄວາມເປັນສ່ວນຕົວ: https://wordpress.org/about/privacy/

WordPress.org Secret-Key (Salt) API

  • ເວລາໃດ: ເມື່ອທ່ານປ່ຽນຄີຄວາມປອດໄພ ແລະ salts ຂອງ WordPress, ບໍ່ວ່າຈະຕາມຄວາມຕ້ອງການ ຫຼື ຕາມກຳນົດເວລາ.
  • ຂໍ້ມູນທີ່ສົ່ງ: ຄຳຂໍສຳລັບສ້າງຂໍ້ຄວາມ salt ແບບສຸ່ມ (ບໍ່ມີຂໍ້ມູນເວັບໄຊ ຫຼື ຜູ້ໃຊ້).
  • Endpoint: https://api.wordpress.org/secret-key/1.1/salt/
  • ຄວາມເປັນສ່ວນຕົວ: https://wordpress.org/about/privacy/

Cloudflare API

  • ເວລາໃດ: ເມື່ອທ່ານເຊື່ອມຕໍ່ Cloudflare ຫຼື ເບິ່ງຕົວຢ່າງ, ນຳໃຊ້, ລຶບ ຫຼື ວິເຄາະກົດລະບຽບ WAF.
  • ຂໍ້ມູນທີ່ສົ່ງ: ຂໍ້ມູນເຂົ້າສູ່ລະບົບ Cloudflare ຂອງທ່ານ ຫຼື API token, ໂຊນທີ່ເລືອກ ແລະ ຂໍ້ມູນກົດລະບຽບ, ລວມທັງຄຳຂໍ API ທີ່ຈຳເປັນສຳລັບການກວດສອບ, ການນຳໃຊ້ ແລະ ການວິເຄາະ.
  • Endpoint: https://api.cloudflare.com/client/v4/
  • ເງື່ອນໄຂ: https://www.cloudflare.com/website-terms/ — ຄວາມເປັນສ່ວນຕົວ: https://www.cloudflare.com/privacypolicy/

Have I Been Pwned (ລະຫັດຜ່ານທີ່ເຄີຍຫຼຸດຮົ່ວ)

  • ເວລາໃດ: ເມື່ອຕົວເລືອກນະໂຍບາຍລະຫັດຜ່ານ “ປະຕິເສດລະຫັດຜ່ານທີ່ຫຼຸດຮົ່ວ” ເປີດໃຊ້ງານ ແລະ ມີການຕັ້ງຄ່າ ຫຼື ປ່ຽນລະຫັດຜ່ານໃໝ່.
  • ຂໍ້ມູນທີ່ສົ່ງ: 5 ຕົວອັກສອນທຳອິດຂອງ SHA-1 hash ຂອງລະຫັດຜ່ານ (ການສອບຖາມຊ່ວງແບບ k-anonymity). ລະຫັດຜ່ານຕົວຈິງຈະບໍ່ຖືກສົ່ງໄປເດັດຂາດ.
  • Endpoint: https://api.pwnedpasswords.com/range/
  • ຄວາມເປັນສ່ວນຕົວ: https://haveibeenpwned.com/Privacy

ອີເມວຄຳຕິຊົມ ແລະ ໃຫ້ການຊ່ວຍເຫຼືອ

  • ເວລາໃດ: ສະເພາະເມື່ອຜູ້ເບິ່ງແຍງລະບົບສົ່ງແບບຟອມຕິດຕໍ່, ຮ້ອງຂໍຍ້າຍຂໍ້ມູນ ຫຼື ສົ່ງຄຳຕິຊົມໃນການປິດໃຊ້ງານຢ່າງຊັດເຈນ. ຖ້າເລືອກ “ຂ້າມ & ປິດໃຊ້ງານ” ຈະບໍ່ມີການສົ່ງຫຍັງເລີຍ.
  • ຈຸດໝາຍປາຍທາງ: support@wpultimatesecurity.com, ສົ່ງຜ່ານບໍລິການອີເມວ WordPress ທີ່ກຳນົດໄວ້ຂອງເວັບໄຊ.
  • ຄວາມເປັນສ່ວນຕົວ: https://www.wpultimatesecurity.com/privacy-policy/

ພາບໜ້າຈໍ

The dashboard tells you in plain words how safe your site is and what to fix next.
The dashboard tells you in plain words how safe your site is and what to fix next.
Answer a few questions and the setup wizard secures your site. You see every change first and can undo it later.
Answer a few questions and the setup wizard secures your site. You see every change first and can undo it later.
Stop bots that guess passwords. Repeat offenders are locked out for longer.
Stop bots that guess passwords. Repeat offenders are locked out for longer.
Test Mode shows what would have been blocked, without blocking anyone.
Test Mode shows what would have been blocked, without blocking anyone.
Add a second step to login with an email code or an authenticator app.
Add a second step to login with an email code or an authenticator app.
Hide your login page and require strong passwords.
Hide your login page and require strong passwords.
Stop spam bots on your login, comment and WooCommerce forms with reCAPTCHA or Cloudflare Turnstile.
Stop spam bots on your login, comment and WooCommerce forms with reCAPTCHA or Cloudflare Turnstile.
Find plugins, themes and WordPress versions with known security holes, automatically.
Find plugins, themes and WordPress versions with known security holes, automatically.
Turn on ready-made Cloudflare firewall rules without writing any code.
Turn on ready-made Cloudflare firewall rules without writing any code.
See who is signed in right now and sign anyone out with one click.
See who is signed in right now and sign anyone out with one click.
Switch each feature on or off. Your site stays fast.
Switch each feature on or off. Your site stays fast.
Bring your settings over from Wordfence Login Security, or copy them to another site.
Bring your settings over from Wordfence Login Security, or copy them to another site.

ການຕິດຕັ້ງ

ຄວາມຕ້ອງການລະບົບ: WordPress 5.6+ ແລະ PHP 7.1+. ແນະນຳຢ່າງຍິ່ງໃຫ້ໃຊ້ HTTPS ສຳລັບ 2FA ແລະ ເຊດຊັນທີ່ປອດໄພ.

ຕິດຕັ້ງຈາກໜ້າຄວບຄຸມຂອງທ່ານ

  1. ໃນ WordPress, ໄປທີ່ ປລັກອິນ → ເພີ່ມໃໝ່ ແລະ ຄົ້ນຫາຄຳວ່າ “wpultimatesecurity”.
  2. ຄລິກ ຕິດຕັ້ງຕອນນີ້, ຈາກນັ້ນ ເປີດໃຊ້ງານ.
  3. ເຮັດຕາມ Security Wizard ທີ່ປາກົດຂຶ້ນ — ມັນຈະສະແກນເວັບໄຊຂອງທ່ານ, ແນະນຳການຕັ້ງຄ່າ, ແລະ ສະແດງທຸກການປ່ຽນແປງກ່ອນນຳໃຊ້.

ຕິດຕັ້ງດ້ວຍຕົນເອງ

  1. ດາວໂຫຼດໄຟລ໌ ZIP ຂອງປລັກອິນ.
  2. ໄປທີ່ ປລັກອິນ → ເພີ່ມໃໝ່ → ອັບໂຫຼດປລັກອິນ, ເລືອກໄຟລ໌ ZIP, ແລະ ຄລິກ ຕິດຕັ້ງຕອນນີ້.
  3. ຄລິກ ເປີດໃຊ້ງານ, ຈາກນັ້ນໃຫ້ເຮັດຕາມ Security Wizard.

ຫຼື ດ້ວຍ WP-CLI: wp plugin install ultimate-security --activate

Your first 3 minutes

  1. Run the Security Wizard and apply the template that matches your site.
  2. Save the emergency link the wizard shows you somewhere safe. It gets you back in if you ever lock yourself out.
  3. Turn on two-factor login for every administrator.

ຄຳຖາມທີ່ພົບເລື້ອຍ

I locked myself out. How do I get back in?

Open the emergency link the setup wizard gave you. It switches the plugin off so you can log in and fix the setting. If you didn’t save it, ask your host to rename the folder /wp-content/plugins/ultimate-security, or run wp plugin deactivate ultimate-security over SSH.

ປລັກອິນນີ້ຈະເຮັດໃຫ້ເວັບໄຊຂອງຂ້ອຍຊ້າລົງບໍ່?

No. Checks run only when someone logs in or submits a form, not on every page view. Scans run in the background on a schedule.

Do I need any technical knowledge?

No. The setup wizard picks settings for your kind of site and shows every change before applying it. You can undo all of it later.

What is Test Mode?

A safe way to try your settings. Your protections run, but nobody is blocked; instead you get a log of what would have been blocked. Once you are happy, switch it off to enforce the rules. It turns itself off after seven days, so a forgotten test never leaves your site unprotected.

Can I undo what the wizard changed?

Yes. The wizard shows every change before applying it, and you can undo them all later. Changes you made yourself afterwards are kept.

Is it really free?

Yes. Everything described on this page is included, with no account, trial or time limit.

ຂ້ອຍຈຳເປັນຕ້ອງມີ API key ສຳລັບການສະແກນຊ່ອງໂຫວ່ບໍ່?

No. The scanner works straight away with the free WPVulnerability database. WPScan and Patchstack keys are optional and only add extra coverage.

ມັນເຮັດວຽກກັບ WooCommerce ບໍ່?

Yes. CAPTCHA can protect the WooCommerce login, registration, password reset and checkout forms, two-factor login works on the WooCommerce login form, and the wizard has a WooCommerce template.

Do I need a Cloudflare account?

Only for the Cloudflare firewall rules. Every other feature works without one.

I use Cloudflare or another CDN or proxy. Do I need to do anything?

For Cloudflare, no: it is recognised automatically. For any other proxy or load balancer, add its address under Brute-force protection → Trusted proxies. Until you do, the plugin avoids locking out everyone at once, and Site Health tells you what to add.

CAPTCHA is blocking every login. How do I recover?

Add define( 'ULTIMATE_SECURITY_DISABLE_CAPTCHA', true ); to wp-config.php to switch CAPTCHA off, log in, re-enter your Site Key and Secret Key, then remove the line. To turn off just one provider, use ULTIMATE_SECURITY_DISABLE_TURNSTILE or ULTIMATE_SECURITY_DISABLE_RECAPTCHA. Over SSH, wp ultimate-security captcha off does the same. Site Health warns you when a key stops working.

ມັນຈະຂັດແຍ້ງກັບປລັກອິນຄວາມປອດໄພ ຫຼື CAPTCHA ອື່ນບໍ່?

It can if two plugins do the same job. Use one plugin per job (one for two-factor, one for CAPTCHA, one for login limits) and switch the overlapping feature off in the other. Ultimate Security warns you when it spots an overlap.

ຂ້ອຍໃຊ້ປລັກອິນຄວາມປອດໄພອື່ນຢູ່ແລ້ວ. ຂ້ອຍສາມາດນຳການຕັ້ງຄ່າມາໃຊ້ໄດ້ບໍ່?

You can import two-factor and login settings from Wordfence Login Security. You see exactly what will come across first, and can undo the import afterwards.

URL ເຂົ້າສູ່ລະບົບແບບກຳນົດເອງເຮັດວຽກກັບລະບົບແຄດ ແລະ CDN ບໍ່?

Yes. Make sure your caching plugin doesn’t cache the login page; most skip login and admin pages automatically.

Does it work with Redis or Memcached?

Yes. Give the cache enough memory so it doesn’t drop entries early, or a lockout can end sooner than you set.

ມັນເຮັດວຽກເທິງ WordPress Multisite ບໍ່?

It runs on Multisite, with settings per site. It has been tested less there than on single sites, so try it on a staging network first.

ປລັກອິນມີການຕິດຕາມຂ້ອຍ ຫຼື ສົ່ງຂໍ້ມູນກັບຄືນຫາເຊີບເວີຂອງຜູ້ພັດທະນາບໍ່?

No. There is no usage tracking. It contacts an outside service only when you use a feature that needs one, and each is listed under External Services below.

ປລັກອິນເກັບຂໍ້ມູນຫຍັງແດ່ກ່ຽວກັບຜູ້ເຂົ້າຊົມຂອງຂ້ອຍ?

IP addresses and browser details are kept in the session log so you can review sign-ins. Test Mode keeps its own log of what it would have blocked. Everything stays in your own database.

ມັນຮອງຮັບ GDPR ບໍ່?

Your data stays on your own server. Outside calls are limited to the services listed under External Services, and only for features you turn on.

ຈະເກີດຫຍັງຂຶ້ນກັບຂໍ້ມູນຂອງຂ້ອຍເມື່ອຂ້ອຍຖອນການຕິດຕັ້ງ?

By default your settings are kept, in case you reinstall. To remove everything, turn on “delete plugin data” in the plugin’s advanced settings before uninstalling.

ຂ້ອຍຈະຂໍຮັບການຊ່ວຍເຫຼືອໄດ້ແນວໃດ?

Ask in the plugin’s support forum on WordPress.org, or visit https://www.wpultimatesecurity.com.

ການຣີວິວ

ບໍ່ມີການຣີວິວສຳລັບປລັກອິນນີ້.

ຜູ້ຮ່ວມພັດທະນາ ແລະ ຜູ້ພັດທະນາ

“Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ” ແມ່ນຊອຟແວໂອເພັນຊອດ (Open Source). ບຸກຄົນຕໍ່ໄປນີ້ໄດ້ມີສ່ວນຮ່ວມໃນການພັດທະນາປລັກອິນນີ້.

ຜູ້ຮ່ວມພັດທະນາ
  • WP Ultimate Security

“Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ” ໄດ້ຖືກແປເປັນ 1 ພາສາທ້ອງຖິ່ນ. ຂໍຂອບໃຈ ທີມງານຜູ້ແປ ສຳລັບການປະກອບສ່ວນຂອງເຂົາເຈົ້າ.

ແປ “Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ” ເປັນພາສາຂອງເຈົ້າ.

ສົນໃຈຮ່ວມພັດທະນາບໍ່?

ເບິ່ງລະຫັດ, ກວດເບິ່ງ ຄັງເກັບ SVN, ຫຼື ຕິດຕາມ ບັນທຶກການພັດທະນາ ຜ່ານ RSS.

ບັນທຶກການປ່ຽນແປງ

1.0.40

  • Fix: Test Mode no longer locks out the accounts it covers when they reach the login limit. The attempt is recorded in the Test Mode log instead.
  • Fix: On phones, the plugin’s menu no longer makes pages scroll sideways or overlap other buttons.
  • Improvement: Notifications on the email verification, two-factor and login settings pages now look and behave like the rest of the plugin.
  • Improvement: Code optimized, so the plugin is a little lighter.

1.0.36

This update includes everything since 1.0.29; the versions in between were never released. It strengthens login security, adds new two-factor and lockout controls, fixes a long list of everyday problems and gives the plugin a cleaner, more consistent look. We recommend every site updates.

Security
* Stronger protection for sign-in, two-factor authentication and brute-force limits, following an internal security review. The details are kept private so sites that have not updated yet stay safe.

New
* Choose how many email two-factor codes can be requested every 15 minutes, and how long someone must wait before asking for another (Login → Two-Factor → Email Authentication).
* Set how many wrong two-factor codes are allowed, and how long the lockout lasts, for each method on the profile screen.
* The lockout message on the login page counts down and clears itself when the lockout ends.
* Brute-force protection now works in two stages: a few short lockouts first, then a longer one. You choose how many short lockouts come first, and you can switch the longer stage off.
* Site Health tells you when your site is behind Cloudflare but real visitor addresses are not reaching WordPress.
* On your first visit, a “Setting up your dashboard” window shows each check as it finishes instead of empty cards. The results are saved, so the dashboard opens with real numbers next time.

Improved
* A fresh, consistent look on every screen, including the setup wizard and the two-factor section on your profile page.
* Dark mode now covers every screen.
* Text is a little larger, and text boxes, dropdowns and switches have an outline you can actually see.
* Severity colours match everywhere: red for critical, amber for high.
* Settings pages show the page name above the form, like the dashboard.
* The unsaved-changes banner tells you which field needs attention.
* The brute-force settings are clearer: they are labelled Initial and Advanced, and the long lockout is set in minutes.
* Update Manager freeze periods need a start and an end date, and dates in the past are rejected.
* The two-factor lockout email is sent once per lockout instead of on every blocked attempt.
* API keys pasted with an extra space or line break are cleaned up when saved.

Changed
* The “Require authorization to reset 2FA” option added in 1.0.29 has been removed. It was off by default. If you had turned it on, users can once again reset their own two-factor method without re-entering their password.

Fixed
* Saving settings is more reliable: switches no longer flip back, a failed save shows the real reason instead of “No internet connection”, and page caches are cleared after saving.
* The hidden login page shows the right address after you save.
* Cloudflare Turnstile and Google reCAPTCHA now protect the WooCommerce block checkout as well as the classic one.
* “Update all plugins” and “Update all themes” now run the updates.
* Password-reset links from WordPress or WooCommerce are no longer logged as attacks.
* “Clear all IP lockouts” no longer empties the whole site cache on sites that use Redis or Memcached.
* People on the block list see a clear “blocked” message instead of a countdown.
* Sites behind Cloudflare no longer risk locking out many visitors at once when Cloudflare’s visitor-address header is missing.
* Authenticator app setups survive uninstalling and reinstalling the plugin when you choose to keep plugin data.
* Saved API keys stay readable after you change your site’s security keys (salts).
* The Patchstack and WPScan vulnerability checks work again and catch more affected versions.
* Test Mode respects the “Always exclude administrators” and “Log simulated blocks” switches, and records the right user.
* Undoing a settings import in Backup & Restore works again, and the Copy button works on sites without HTTPS.
* The reCAPTCHA and Turnstile debug logs load again, the dashboard shows your PHP version straight away, and two messages that could crash on PHP 8 are fixed.

Earlier versions

See the full history at https://wpultimatesecurity.com/changelog/

ຂໍ້ມູນກຳກັບ (Meta)

  • ເວີຊັນ 1.0.40
  • ອັບເດດຫຼ້າສຸດເມື່ອ 9 ນາທີ ທີ່ຜ່ານມາ ທີ່ຜ່ານມາ
  • ການຕິດຕັ້ງທີ່ໃຊ້ງານຢູ່ 10+
  • ເວີຊັນ WordPress 5.6 ຫຼື ສູງກວ່າ
  • ທົດສອບເຖິງເວີຊັນ 7.1.2
  • ເວີຊັນ PHP 7.1 ຫຼື ສູງກວ່າ
  • ພາສາ

    English (US) ແລະ Lao.

    ແປເປັນພາສາຂອງເຈົ້າ

  • ແທັກ
    Brute Forcelogin securitysecuritytwo factor authenticationvulnerability scanner
  • ມຸມມອງຂັ້ນສູງ

ການໃຫ້ຄະແນນ

ຍັງບໍ່ມີການສົ່ງຄຳວິຈານເທື່ອ.

ການທົບທວນຂອງທ່ານ

ເບິ່ງທັງໝົດ ການຣີວິວ

ຜູ້ຮ່ວມພັດທະນາ

  • WP Ultimate Security

ການຊ່ວຍເຫຼືອ

ມີຄຳຖາມ ຫຼື ຕ້ອງການຄວາມຊ່ວຍເຫຼືອບໍ່?

ເບິ່ງຟໍຣັມການຊ່ວຍເຫຼືອ

  • ກ່ຽວກັບ
  • ຂ່າວສານ
  • ໂຮສຕິງ
  • ຄວາມເປັນສ່ວນຕົວ
  • ງານທີ່ໂດດເດັ່ນ
  • ທີມ
  • ປລັກອິນ
  • ຮູບແບບບລັອກ
  • ຮຽນຮູ້
  • ຊ່ວຍເຫຼືອ
  • ນັກພັດທະນາ
  • WordPress.tv ↗
  • ມີສ່ວນຮ່ວມ
  • ກິດຈະກຳ
  • ບໍລິຈາກ ↗
  • ຂອງທີ່ລະນຶກ ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

ລາວ

  • ຢ້ຽມຊົມບັນຊີ X (ຊື່ເກົ່າ Twitter) ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Bluesky ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Mastodon ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Threads ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມໜ້າ Facebook ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Instagram ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ LinkedIn ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ TikTok ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມຊ່ອງ YouTube ຂອງພວກເຮົາ
  • ຢ້ຽມຊົມບັນຊີ Tumblr ຂອງພວກເຮົາ
Code is Poetry.
The WordPress® trademark is the intellectual property of the WordPress Foundation.