Title: Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ
Author: WP Ultimate Security
Published: <strong>22 ມີນາ 2025</strong>
Last modified: 30 ກັນຍາ 2026

---

ຄົ້ນຫາປລັກອິນ

![](https://ps.w.org/ultimate-security/assets/banner-772x250.png?rev=3695904)

![](https://ps.w.org/ultimate-security/assets/icon-256x256.gif?rev=3678713)

# Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ

 ໂດຍ [WP Ultimate Security](https://profiles.wordpress.org/wpultimatesecurity/)

[ດາວໂຫຼດ](https://downloads.wordpress.org/plugin/ultimate-security.1.0.40.zip)

 * [ລາຍລອຽດ](https://lo.wordpress.org/plugins/ultimate-security/#description)
 * [ການຣີວິວ](https://lo.wordpress.org/plugins/ultimate-security/#reviews)
 *  [ການຕິດຕັ້ງ](https://lo.wordpress.org/plugins/ultimate-security/#installation)
 * [ການພັດທະນາ](https://lo.wordpress.org/plugins/ultimate-security/#developers)

 [ການຊ່ວຍເຫຼືອ](https://wordpress.org/support/plugin/ultimate-security/)

## ຄຳອະທິບາຍ

**Stop hackers and bots from getting into your WordPress site.** Ultimate Security
adds two-factor login, blocks password-guessing attacks, stops spam bots and warns
you about plugins with known security holes. A setup wizard picks the right settings
for your kind of site, so you don’t have to understand every option.

#### Why site owners choose it

 * **Free, with no account needed.** Install it and it works. No sign-up and no 
   usage tracking.
 * **Set up in about 3 minutes.** The wizard asks what kind of site you run, checks
   it, and shows every change before applying it. You can undo it all later.
 * **Try before you enforce.** Test Mode shows what would have been blocked, without
   blocking anyone.
 * **You can’t lock yourself out for good.** The wizard gives you an emergency link
   that switches the plugin off from any browser.

#### Protect your login

**Two-factor login.** After the password, users confirm with a code sent by email
or shown in an authenticator app (Google Authenticator, Authy, Microsoft Authenticator
and similar). Choose which user roles need it. Works on the WordPress, WooCommerce
and Ultimate Member login forms.

**Stop password-guessing bots.**

 * Lock out anyone who gets the password wrong too many times. Repeat offenders 
   wait longer each time.
 * Permanently block addresses you never want to see again.
 * An administrator can send a locked-out user a 15-minute recovery link.
 * Works behind Cloudflare automatically. Site Health tells you if your host’s setup
   needs one extra step.

**Hide your login page.** Move `wp-login.php` to a private address so bots can’t
find it.

**Stronger passwords.**

 * Set rules for length, letters, numbers and symbols, or pick a ready-made preset.
 * Stop people reusing old passwords, and ask for a new one on first login or after
   a set time.
 * Reject passwords that have appeared in known data leaks. The check never sends
   the password itself anywhere.

**Control who stays signed in.**

 * Limit how many devices one account can use at once.
 * Sign people out automatically after a period of inactivity.
 * See who is signed in right now, and end any session with one click.

#### Block spam and bots on your forms

Add Google reCAPTCHA or Cloudflare Turnstile to your login, registration, password
reset and comment forms, and to WooCommerce login, registration and checkout.

 * Check that your keys work before going live.
 * If the CAPTCHA service is down, your forms keep working.
 * Won’t clash with another CAPTCHA plugin on the same form.

#### Find security problems before hackers do

**Vulnerability scanner.** Checks WordPress, your plugins and your themes against
a database of known security holes, and emails you when it finds one. It works without
an API key; WPScan or Patchstack keys add extra coverage.

 * Runs on a schedule in the background.
 * ແຈ້ງເຕືອນປລັກອິນທີ່ບໍ່ໄດ້ຮັບການອັບເດດມາເປັນເວລາດົນນານ.
 * Results show in the dashboard, Site Health and your plugins list.

**Security score.** One number that tells you how well protected your site is, and
which fix to do next.

**File check.** Compares your WordPress core files with the official copies, so 
changed or added files stand out.

**Safer updates.** Choose when WordPress, plugins and themes update automatically.
Set update days and quiet periods, delay updates by a few days, and get an email
when something changes.

#### Advanced protection

**Cloudflare firewall rules.** If your site uses Cloudflare, connect your account
and turn on ready-made rules from wp-admin: let good bots through, block bad crawlers
and risky traffic, and block attacks on known WordPress flaws before you’ve had 
a chance to update. You can preview every rule before it goes live.

**Security keys (salts).** Change the secret keys in `wp-config.php` on demand or
on a schedule, which signs everyone out and makes stolen login cookies useless. 
You get a warning before a scheduled change, and can restore a previous set.

#### ໂໝດທົດສອບ

Turn on your protections without blocking anyone, and review a log of what would
have been blocked. Choose which user roles it covers. Visitors who aren’t signed
in are still held to the login limit, and Test Mode switches itself off after seven
days, so a forgotten test never leaves your site unprotected.

#### Moving from another plugin

 * Import your two-factor and login settings from Wordfence Login Security. Preview
   it first and undo it if you change your mind.
 * Copy your settings to another site, or keep a backup, as a file.
 * Detects WooCommerce, Ultimate Member, page builders, form, caching and SEO plugins,
   and warns you if another security plugin is already doing the same job.

#### Privacy

No usage tracking. The plugin contacts an outside service only when you switch on
a feature that needs one, and each is listed under External Services below.

#### For developers

    ```
    wp ultimate-security template list
    wp ultimate-security template apply <template> [--dry-run]
    wp ultimate-security template undo
    wp ultimate-security export [--file=<path>]
    wp ultimate-security import <file> [--dry-run]
    wp ultimate-security status
    wp ultimate-security unlock <user> | --ip=<address> | --all
    wp ultimate-security 2fa disable <user>
    wp ultimate-security captcha off
    wp ultimate-security login-url reset
    ```

#### Video guides

 * [Set up an authenticator app](https://www.youtube.com/watch?v=2hu-4C4RsqE)
 * [Two-factor login by email](https://www.youtube.com/watch?v=oXF1IWAISTc)
 * [Hide your login page](https://www.youtube.com/watch?v=O-h6rVUPSw4)
 * [Set strong password rules](https://www.youtube.com/watch?v=2mTDSrdpMI0)
 * [Limit login sessions](https://www.youtube.com/watch?v=qGdDc_loPyM)
 * [Manage plugin and theme updates](https://www.youtube.com/watch?v=mlT0zbGP_wc)
 * [Change your security keys after a breach](https://www.youtube.com/watch?v=9m85pe8JX8Q)
 * [Spot changed WordPress files](https://www.youtube.com/watch?v=dOzK9pDmEZI)
 * [Understand Site Health reports](https://www.youtube.com/watch?v=7h7eMOUucVA)
 * [Dashboard walkthrough](https://www.youtube.com/watch?v=8UaUn7rgh6g)
 * [Move your Wordfence two-factor settings](https://www.youtube.com/watch?v=6sw8FNnbTPU)

#### ຮຽນຮູ້ເພີ່ມເຕີມ

 * [ເວັບໄຊ](https://www.wpultimatesecurity.com) — ຟີເຈີ ແລະ ບົດຄວາມຕ່າງໆ.
 * [ເອກະສານອ້າງອີງ](https://docs.wpultimatesecurity.com/) — ຄູ່ມືການຕັ້ງຄ່າ, ການແກ້ໄຂ
   ບັນຫາ ແລະ ວິທີການຕ່າງໆ.
 * [YouTube](https://www.youtube.com/@wpultimatesecurity) — all video guides.

### ບໍລິການພາຍນອກ

ປລັກອິນນີ້ເຊື່ອມຕໍ່ກັບບໍລິການພາຍນອກຕໍ່ໄປນີ້, ແລະ ສະເພາະເມື່ອທ່ານໃຊ້ຟີເຈີທີ່ກ່ຽວຂ້ອງ
ເທົ່ານັ້ນ:

#### Google reCAPTCHA

 * ເວລາໃດ: ເມື່ອເປີດໃຊ້ການປ້ອງກັນຂອງ reCAPTCHA. ສະຄຣິບ reCAPTCHA ຈະຖືກໂຫຼດໃນບຣາວ
   ເຊີຂອງຜູ້ເຂົ້າຊົມໃນຟອມທີ່ຖືກປົກປ້ອງ.
 * ຂໍ້ມູນທີ່ສົ່ງ: token ການຕອບສະໜອງຂອງ reCAPTCHA ຂອງຜູ້ເຂົ້າຊົມ, secret key ຂອງເວັບ
   ໄຊ, ແລະ ທີ່ຢູ່ IP ຂອງຜູ້ເຂົ້າຊົມສຳລັບການກວດສອບ.
 * Endpoints: https://www.google.com/recaptcha/api.js (ສະຄຣິບເທິງບຣາວເຊີ, ພ້ອມການເຊື່ອມ
   ຕໍ່ລ່ວງໜ້າໄປທີ່ https://www.gstatic.com) ແລະ https://www.google.com/recaptcha/
   api/siteverify (ການກວດສອບຝັ່ງເຊີບເວີ).
 * ເງື່ອນໄຂ: https://policies.google.com/terms — ຄວາມເປັນສ່ວນຕົວ: https://policies.
   google.com/privacy

#### Cloudflare Turnstile

 * ເວລາໃດ: ເມື່ອເປີດໃຊ້ການປ້ອງກັນຂອງ Cloudflare Turnstile. ສະຄຣິບ Turnstile ຈະຖືກ
   ໂຫຼດໃນບຣາວເຊີຂອງຜູ້ເຂົ້າຊົມໃນຟອມທີ່ຖືກປົກປ້ອງ.
 * ຂໍ້ມູນທີ່ສົ່ງ: token ການຕອບສະໜອງຂອງ Turnstile ຂອງຜູ້ເຂົ້າຊົມ, secret key ຂອງເວັບ
   ໄຊ, ແລະ ທີ່ຢູ່ IP ຂອງຜູ້ເຂົ້າຊົມສຳລັບການກວດສອບ.
 * Endpoints: https://challenges.cloudflare.com/turnstile/v0/api.js (ສະຄຣິບເທິງບຣາວ
   ເຊີ) ແລະ https://challenges.cloudflare.com/turnstile/v0/siteverify (ການກວດສອບ
   ຝັ່ງເຊີບເວີ).
 * ເງື່ອນໄຂ: https://www.cloudflare.com/website-terms/ — ຄວາມເປັນສ່ວນຕົວ: https://
   www.cloudflare.com/privacypolicy/

#### WPVulnerability

 * ເວລາໃດ: ເມື່ອຕົວສະແກນຊ່ອງໂຫວ່ເຮັດວຽກ. ນີ້ແມ່ນຖານຂໍ້ມູນຊ່ອງໂຫວ່ເລີ່ມຕົ້ນ ແລະ ບໍ່
   ຈຳເປັນຕ້ອງໃຊ້ API key.
 * ຂໍ້ມູນທີ່ສົ່ງ: ເວີຊັນ WordPress ຂອງທ່ານ ແລະ slugs ຂອງປລັກອິນ ແລະ ທີມທີ່ທ່ານຕິດຕັ້ງ
   ໄວ້.
 * Endpoint: https://www.wpvulnerability.net/
 * ຄວາມເປັນສ່ວນຕົວ: https://www.wpvulnerability.net/

#### WPScan

 * ເວລາໃດ: ເມື່ອຕົວສະແກນຊ່ອງໂຫວ່ເຮັດວຽກ ແລະ ທ່ານໄດ້ຕັ້ງຄ່າ WPScan API key ໄວ້.
 * ຂໍ້ມູນທີ່ສົ່ງ: WPScan API key ຂອງທ່ານ, ເວີຊັນ WordPress ຂອງທ່ານ, ແລະ slugs ຂອງ
   ປລັກອິນ ແລະ ທີມທີ່ທ່ານຕິດຕັ້ງໄວ້.
 * Endpoint: https://wpscan.com/api/v3/
 * ເງື່ອນໄຂ: https://wpscan.com/terms-of-service/ — ຄວາມເປັນສ່ວນຕົວ: https://wpscan.
   com/privacy-policy/

#### Patchstack

 * ເວລາໃດ: ເມື່ອຕົວສະແກນຊ່ອງໂຫວ່ເຮັດວຽກ ແລະ ທ່ານໄດ້ຕັ້ງຄ່າ Patchstack API key ໄວ້.
 * ຂໍ້ມູນທີ່ສົ່ງ: Patchstack API key ຂອງທ່ານ, ເວີຊັນ WordPress ຂອງທ່ານ, ແລະ slugs
   ຂອງປລັກອິນ ແລະ ທີມທີ່ທ່ານຕິດຕັ້ງໄວ້.
 * Endpoint: https://patchstack.com/database/api/v2/
 * ເງື່ອນໄຂ: https://patchstack.com/terms-of-service/ — ຄວາມເປັນສ່ວນຕົວ: https://
   patchstack.com/privacy-policy/

#### WordPress.org Plugin and Theme Information API

 * ເວລາໃດ: ເມື່ອຕົວສະແກນຊ່ອງໂຫວ່ກວດສອບວ່າສ່ວນເສີມຖືກປະຖິ້ມແລ້ວຫຼືບໍ່, ແລະ ເມື່ອຕົວ
   ຈັດການການອັບເດດລວບລວມຂໍ້ມູນການອັບເດດ.
 * ຂໍ້ມູນທີ່ສົ່ງ: slugs ຂອງປລັກອິນ ແລະ ທີມທີ່ທ່ານຕິດຕັ້ງໄວ້ (ບໍ່ມີຂໍ້ມູນຜູ້ໃຊ້).
 * Endpoints: https://api.wordpress.org/plugins/info/1.2/ ແລະ https://api.wordpress.
   org/themes/info/1.2/
 * ຄວາມເປັນສ່ວນຕົວ: https://wordpress.org/about/privacy/

#### WordPress.org Core Version Check

 * ເວລາໃດ: ເມື່ອຕົວຈັດການການອັບເດດກວດສອບຫາການອັບເດດລະບົບຫຼັກຂອງ WordPress.
 * ຂໍ້ມູນທີ່ສົ່ງ: ຄຳຂໍກວດສອບເວີຊັນລະບົບຫຼັກຂອງ WordPress ມາດຕະຖານ (ບໍ່ມີຂໍ້ມູນຜູ້
   ໃຊ້).
 * Endpoint: https://api.wordpress.org/core/version-check/1.7/
 * ຄວາມເປັນສ່ວນຕົວ: https://wordpress.org/about/privacy/

#### WordPress.org Core Checksums

 * ເວລາໃດ: ເມື່ອທ່ານລັນການກວດສອບຄວາມສົມບູນຂອງໄຟລ໌ລະບົບຫຼັກ WordPress.
 * ຂໍ້ມູນທີ່ສົ່ງ: ເວີຊັນ ແລະ ພາສາ WordPress ຂອງທ່ານ, ເພື່ອດຶງຂໍ້ມູນ checksums ຂອງ
   ໄຟລ໌ຢ່າງເປັນທາງການມາປຽບທຽບ.
 * Endpoint: https://api.wordpress.org/core/checksums/1.0/
 * ຄວາມເປັນສ່ວນຕົວ: https://wordpress.org/about/privacy/

#### WordPress.org Secret-Key (Salt) API

 * ເວລາໃດ: ເມື່ອທ່ານປ່ຽນຄີຄວາມປອດໄພ ແລະ salts ຂອງ WordPress, ບໍ່ວ່າຈະຕາມຄວາມຕ້ອງການ
   ຫຼື ຕາມກຳນົດເວລາ.
 * ຂໍ້ມູນທີ່ສົ່ງ: ຄຳຂໍສຳລັບສ້າງຂໍ້ຄວາມ salt ແບບສຸ່ມ (ບໍ່ມີຂໍ້ມູນເວັບໄຊ ຫຼື ຜູ້ໃຊ້).
 * Endpoint: https://api.wordpress.org/secret-key/1.1/salt/
 * ຄວາມເປັນສ່ວນຕົວ: https://wordpress.org/about/privacy/

#### Cloudflare API

 * ເວລາໃດ: ເມື່ອທ່ານເຊື່ອມຕໍ່ Cloudflare ຫຼື ເບິ່ງຕົວຢ່າງ, ນຳໃຊ້, ລຶບ ຫຼື ວິເຄາະ
   ກົດລະບຽບ WAF.
 * ຂໍ້ມູນທີ່ສົ່ງ: ຂໍ້ມູນເຂົ້າສູ່ລະບົບ Cloudflare ຂອງທ່ານ ຫຼື API token, ໂຊນທີ່ເລືອກ
   ແລະ ຂໍ້ມູນກົດລະບຽບ, ລວມທັງຄຳຂໍ API ທີ່ຈຳເປັນສຳລັບການກວດສອບ, ການນຳໃຊ້ ແລະ ການວິເຄາະ.
 * Endpoint: https://api.cloudflare.com/client/v4/
 * ເງື່ອນໄຂ: https://www.cloudflare.com/website-terms/ — ຄວາມເປັນສ່ວນຕົວ: https://
   www.cloudflare.com/privacypolicy/

#### Have I Been Pwned (ລະຫັດຜ່ານທີ່ເຄີຍຫຼຸດຮົ່ວ)

 * ເວລາໃດ: ເມື່ອຕົວເລືອກນະໂຍບາຍລະຫັດຜ່ານ “ປະຕິເສດລະຫັດຜ່ານທີ່ຫຼຸດຮົ່ວ” ເປີດໃຊ້ງານ
   ແລະ ມີການຕັ້ງຄ່າ ຫຼື ປ່ຽນລະຫັດຜ່ານໃໝ່.
 * ຂໍ້ມູນທີ່ສົ່ງ: 5 ຕົວອັກສອນທຳອິດຂອງ SHA-1 hash ຂອງລະຫັດຜ່ານ (ການສອບຖາມຊ່ວງແບບ 
   k-anonymity). ລະຫັດຜ່ານຕົວຈິງຈະບໍ່ຖືກສົ່ງໄປເດັດຂາດ.
 * Endpoint: https://api.pwnedpasswords.com/range/
 * ຄວາມເປັນສ່ວນຕົວ: https://haveibeenpwned.com/Privacy

#### ອີເມວຄຳຕິຊົມ ແລະ ໃຫ້ການຊ່ວຍເຫຼືອ

 * ເວລາໃດ: ສະເພາະເມື່ອຜູ້ເບິ່ງແຍງລະບົບສົ່ງແບບຟອມຕິດຕໍ່, ຮ້ອງຂໍຍ້າຍຂໍ້ມູນ ຫຼື ສົ່ງ
   ຄຳຕິຊົມໃນການປິດໃຊ້ງານຢ່າງຊັດເຈນ. ຖ້າເລືອກ “ຂ້າມ & ປິດໃຊ້ງານ” ຈະບໍ່ມີການສົ່ງຫຍັງ
   ເລີຍ.
 * ຈຸດໝາຍປາຍທາງ: support@wpultimatesecurity.com, ສົ່ງຜ່ານບໍລິການອີເມວ WordPress 
   ທີ່ກຳນົດໄວ້ຂອງເວັບໄຊ.
 * ຄວາມເປັນສ່ວນຕົວ: https://www.wpultimatesecurity.com/privacy-policy/

## ພາບໜ້າຈໍ

[⌊The dashboard tells you in plain words how safe your site is and what to fix next.⌉⌊
The dashboard tells you in plain words how safe your site is and what to fix next
.⌉[

The dashboard tells you in plain words how safe your site is and what to fix next.

[⌊Answer a few questions and the setup wizard secures your site. You see every change
first and can undo it later.⌉⌊Answer a few questions and the setup wizard secures
your site. You see every change first and can undo it later.⌉[

Answer a few questions and the setup wizard secures your site. You see every change
first and can undo it later.

[⌊Stop bots that guess passwords. Repeat offenders are locked out for longer.⌉⌊Stop
bots that guess passwords. Repeat offenders are locked out for longer.⌉[

Stop bots that guess passwords. Repeat offenders are locked out for longer.

[⌊ໂໝດທົດສອບ shows what would have been blocked, without blocking anyone.⌉⌊ໂໝດທົດສອບ
shows what would have been blocked, without blocking anyone.⌉[

ໂໝດທົດສອບ shows what would have been blocked, without blocking anyone.

[⌊Add a second step to login with an email code or an authenticator app.⌉⌊Add a 
second step to login with an email code or an authenticator app.⌉[

Add a second step to login with an email code or an authenticator app.

[⌊Hide your login page and require strong passwords.⌉⌊Hide your login page and require
strong passwords.⌉[

Hide your login page and require strong passwords.

[⌊Stop spam bots on your login, comment and WooCommerce forms with reCAPTCHA or 
Cloudflare Turnstile.⌉⌊Stop spam bots on your login, comment and WooCommerce forms
with reCAPTCHA or Cloudflare Turnstile.⌉[

Stop spam bots on your login, comment and WooCommerce forms with reCAPTCHA or Cloudflare
Turnstile.

[⌊Find plugins, themes and WordPress versions with known security holes, automatically.⌉⌊
Find plugins, themes and WordPress versions with known security holes, automatically
.⌉[

Find plugins, themes and WordPress versions with known security holes, automatically.

[⌊Turn on ready-made Cloudflare firewall rules without writing any code.⌉⌊Turn on
ready-made Cloudflare firewall rules without writing any code.⌉[

Turn on ready-made Cloudflare firewall rules without writing any code.

[⌊See who is signed in right now and sign anyone out with one click.⌉⌊See who is
signed in right now and sign anyone out with one click.⌉[

See who is signed in right now and sign anyone out with one click.

[⌊Switch each feature on or off. Your site stays fast.⌉⌊Switch each feature on or
off. Your site stays fast.⌉[

Switch each feature on or off. Your site stays fast.

[⌊Bring your settings over from Wordfence Login Security, or copy them to another
site.⌉⌊Bring your settings over from Wordfence Login Security, or copy them to another
site.⌉[

Bring your settings over from Wordfence Login Security, or copy them to another 
site.

## ການຕິດຕັ້ງ

**ຄວາມຕ້ອງການລະບົບ:** WordPress 5.6+ ແລະ PHP 7.1+. ແນະນຳຢ່າງຍິ່ງໃຫ້ໃຊ້ HTTPS ສຳລັບ
2FA ແລະ ເຊດຊັນທີ່ປອດໄພ.

#### ຕິດຕັ້ງຈາກໜ້າຄວບຄຸມຂອງທ່ານ

 1. ໃນ WordPress, ໄປທີ່ **ປລັກອິນ  ເພີ່ມໃໝ່** ແລະ ຄົ້ນຫາຄຳວ່າ “wpultimatesecurity”.
 2. ຄລິກ **ຕິດຕັ້ງຕອນນີ້**, ຈາກນັ້ນ **ເປີດໃຊ້ງານ**.
 3. ເຮັດຕາມ **Security Wizard** ທີ່ປາກົດຂຶ້ນ — ມັນຈະສະແກນເວັບໄຊຂອງທ່ານ, ແນະນຳການຕັ້ງ
    ຄ່າ, ແລະ ສະແດງທຸກການປ່ຽນແປງກ່ອນນຳໃຊ້.

#### ຕິດຕັ້ງດ້ວຍຕົນເອງ

 1. ດາວໂຫຼດໄຟລ໌ ZIP ຂອງປລັກອິນ.
 2. ໄປທີ່ **ປລັກອິນ  ເພີ່ມໃໝ່  ອັບໂຫຼດປລັກອິນ**, ເລືອກໄຟລ໌ ZIP, ແລະ ຄລິກ **ຕິດຕັ້ງຕອນນີ້**.
 3. ຄລິກ **ເປີດໃຊ້ງານ**, ຈາກນັ້ນໃຫ້ເຮັດຕາມ Security Wizard.

ຫຼື ດ້ວຍ WP-CLI: `wp plugin install ultimate-security --activate`

#### Your first 3 minutes

 1. ເປີດໃຊ້ **Security Wizard (ຕົວຊ່ວຍສ້າງຄວາມປອດໄພ)** ແລະ ນຳໃຊ້ແມ່ແບບທີ່ເໝາະສົມກັບ
    ເວັບໄຊຂອງທ່ານ.
 2. Save the **emergency link** the wizard shows you somewhere safe. It gets you back
    in if you ever lock yourself out.
 3. Turn on **two-factor login** for every administrator.

## ຄຳຖາມທີ່ພົບເລື້ອຍ

### I locked myself out. How do I get back in?

Open the **emergency link** the setup wizard gave you. It switches the plugin off
so you can log in and fix the setting. If you didn’t save it, ask your host to rename
the folder `/wp-content/plugins/ultimate-security`, or run `wp plugin deactivate
ultimate-security` over SSH.

### ປລັກອິນນີ້ຈະເຮັດໃຫ້ເວັບໄຊຂອງຂ້ອຍຊ້າລົງບໍ່?

No. Checks run only when someone logs in or submits a form, not on every page view.
Scans run in the background on a schedule.

### Do I need any technical knowledge?

No. The setup wizard picks settings for your kind of site and shows every change
before applying it. You can undo all of it later.

### What is Test Mode?

A safe way to try your settings. Your protections run, but nobody is blocked; instead
you get a log of what would have been blocked. Once you are happy, switch it off
to enforce the rules. It turns itself off after seven days, so a forgotten test 
never leaves your site unprotected.

### Can I undo what the wizard changed?

Yes. The wizard shows every change before applying it, and you can undo them all
later. Changes you made yourself afterwards are kept.

### Is it really free?

Yes. Everything described on this page is included, with no account, trial or time
limit.

### ຂ້ອຍຈຳເປັນຕ້ອງມີ API key ສຳລັບການສະແກນຊ່ອງໂຫວ່ບໍ່?

ບໍ່. ຕົວສະແກນສາມາດເຮັດວຽກໄດ້ທັນທີໂດຍໃຊ້ຖານຂໍ້ມູນ WPVulnerability ທີ່ບໍ່ຕ້ອງໃຊ້ຄີ.
WPScan ແລະ Patchstack API keys ແມ່ນທາງເລືອກເສີມເພື່ອເພີ່ມການຄອບຄຸມເທົ່ານັ້ນ.

### ມັນເຮັດວຽກກັບ WooCommerce ບໍ່?

Yes. CAPTCHA can protect the WooCommerce login, registration, password reset and
checkout forms, two-factor login works on the WooCommerce login form, and the wizard
has a WooCommerce template.

### Do I need a Cloudflare account?

Only for the Cloudflare firewall rules. Every other feature works without one.

### I use Cloudflare or another CDN or proxy. Do I need to do anything?

For Cloudflare, no: it is recognised automatically. For any other proxy or load 
balancer, add its address under Brute-force protection  Trusted proxies. Until you
do, the plugin avoids locking out everyone at once, and Site Health tells you what
to add.

### CAPTCHA is blocking every login. How do I recover?

Add `define( 'ULTIMATE_SECURITY_DISABLE_CAPTCHA', true );` to `wp-config.php` to
switch CAPTCHA off, log in, re-enter your Site Key and Secret Key, then remove the
line. To turn off just one provider, use `ULTIMATE_SECURITY_DISABLE_TURNSTILE` or`
ULTIMATE_SECURITY_DISABLE_RECAPTCHA`. Over SSH, `wp ultimate-security captcha off`
does the same. Site Health warns you when a key stops working.

### ມັນຈະຂັດແຍ້ງກັບປລັກອິນຄວາມປອດໄພ ຫຼື CAPTCHA ອື່ນບໍ່?

It can if two plugins do the same job. Use one plugin per job (one for two-factor,
one for CAPTCHA, one for login limits) and switch the overlapping feature off in
the other. Ultimate Security warns you when it spots an overlap.

### ຂ້ອຍໃຊ້ປລັກອິນຄວາມປອດໄພອື່ນຢູ່ແລ້ວ. ຂ້ອຍສາມາດນຳການຕັ້ງຄ່າມາໃຊ້ໄດ້ບໍ່?

You can import two-factor and login settings from Wordfence Login Security. You 
see exactly what will come across first, and can undo the import afterwards.

### URL ເຂົ້າສູ່ລະບົບແບບກຳນົດເອງເຮັດວຽກກັບລະບົບແຄດ ແລະ CDN ບໍ່?

Yes. Make sure your caching plugin doesn’t cache the login page; most skip login
and admin pages automatically.

### Does it work with Redis or Memcached?

Yes. Give the cache enough memory so it doesn’t drop entries early, or a lockout
can end sooner than you set.

### ມັນເຮັດວຽກເທິງ WordPress Multisite ບໍ່?

It runs on Multisite, with settings per site. It has been tested less there than
on single sites, so try it on a staging network first.

### ປລັກອິນມີການຕິດຕາມຂ້ອຍ ຫຼື ສົ່ງຂໍ້ມູນກັບຄືນຫາເຊີບເວີຂອງຜູ້ພັດທະນາບໍ່?

No. There is no usage tracking. It contacts an outside service only when you use
a feature that needs one, and each is listed under External Services below.

### ປລັກອິນເກັບຂໍ້ມູນຫຍັງແດ່ກ່ຽວກັບຜູ້ເຂົ້າຊົມຂອງຂ້ອຍ?

IP addresses and browser details are kept in the session log so you can review sign-
ins. Test Mode keeps its own log of what it would have blocked. Everything stays
in your own database.

### ມັນຮອງຮັບ GDPR ບໍ່?

Your data stays on your own server. Outside calls are limited to the services listed
under External Services, and only for features you turn on.

### ຈະເກີດຫຍັງຂຶ້ນກັບຂໍ້ມູນຂອງຂ້ອຍເມື່ອຂ້ອຍຖອນການຕິດຕັ້ງ?

By default your settings are kept, in case you reinstall. To remove everything, 
turn on “delete plugin data” in the plugin’s advanced settings before uninstalling.

### ຂ້ອຍຈະຂໍຮັບການຊ່ວຍເຫຼືອໄດ້ແນວໃດ?

ໃຊ້ເວທີສົນທະນາໃຫ້ການຊ່ວຍເຫຼືອຂອງປລັກອິນເທິງ WordPress.org, ຫຼື ເຂົ້າເບິ່ງທີ່ https://
www.wpultimatesecurity.com.

## ການຣີວິວ

ບໍ່ມີການຣີວິວສຳລັບປລັກອິນນີ້.

## ຜູ້ຮ່ວມພັດທະນາ ແລະ ຜູ້ພັດທະນາ

“Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ” ແມ່ນຊອຟ
ແວໂອເພັນຊອດ (Open Source). ບຸກຄົນຕໍ່ໄປນີ້ໄດ້ມີສ່ວນຮ່ວມໃນການພັດທະນາປລັກອິນນີ້.

ຜູ້ຮ່ວມພັດທະນາ

 *   [ WP Ultimate Security ](https://profiles.wordpress.org/wpultimatesecurity/)

“Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ” ໄດ້ຖືກ
ແປເປັນ 1 ພາສາທ້ອງຖິ່ນ. ຂໍຂອບໃຈ [ທີມງານຜູ້ແປ](https://translate.wordpress.org/projects/wp-plugins/ultimate-security/contributors)
ສຳລັບການປະກອບສ່ວນຂອງເຂົາເຈົ້າ.

[ແປ “Ultimate Security – ຕົວສະແກນຊ່ອງໂຫວ່, 2FA ແລະ ການປົກປ້ອງການເຂົ້າສູ່ລະບົບ” ເປັນພາສາຂອງເຈົ້າ.](https://translate.wordpress.org/projects/wp-plugins/ultimate-security)

### ສົນໃຈຮ່ວມພັດທະນາບໍ່?

[ເບິ່ງລະຫັດ](https://plugins.trac.wordpress.org/browser/ultimate-security/), ກວດເບິ່ງ
[ຄັງເກັບ SVN](https://plugins.svn.wordpress.org/ultimate-security/), ຫຼື ຕິດຕາມ 
[ບັນທຶກການພັດທະນາ](https://plugins.trac.wordpress.org/log/ultimate-security/) ຜ່ານ
[RSS](https://plugins.trac.wordpress.org/log/ultimate-security/?limit=100&mode=stop_on_copy&format=rss).

## ບັນທຶກການປ່ຽນແປງ

#### 1.0.40

 * Fix: Test Mode no longer locks out the accounts it covers when they reach the
   login limit. The attempt is recorded in the Test Mode log instead.
 * Fix: On phones, the plugin’s menu no longer makes pages scroll sideways or overlap
   other buttons.
 * Improvement: Notifications on the email verification, two-factor and login settings
   pages now look and behave like the rest of the plugin.
 * Improvement: Code optimized, so the plugin is a little lighter.

#### 1.0.36

This update includes everything since 1.0.29; the versions in between were never
released. It strengthens login security, adds new two-factor and lockout controls,
fixes a long list of everyday problems and gives the plugin a cleaner, more consistent
look. We recommend every site updates.

Security
 * Stronger protection for sign-in, two-factor authentication and brute-
force limits, following an internal security review. The details are kept private
so sites that have not updated yet stay safe.

New
 * Choose how many email two-factor codes can be requested every 15 minutes,
and how long someone must wait before asking for another (Login  Two-Factor  Email
Authentication). * Set how many wrong two-factor codes are allowed, and how long
the lockout lasts, for each method on the profile screen. * The lockout message 
on the login page counts down and clears itself when the lockout ends. * Brute-force
protection now works in two stages: a few short lockouts first, then a longer one.
You choose how many short lockouts come first, and you can switch the longer stage
off. * Site Health tells you when your site is behind Cloudflare but real visitor
addresses are not reaching WordPress. * On your first visit, a “Setting up your 
dashboard” window shows each check as it finishes instead of empty cards. The results
are saved, so the dashboard opens with real numbers next time.

Improved
 * A fresh, consistent look on every screen, including the setup wizard
and the two-factor section on your profile page. * Dark mode now covers every screen.*
Text is a little larger, and text boxes, dropdowns and switches have an outline 
you can actually see. * Severity colours match everywhere: red for critical, amber
for high. * Settings pages show the page name above the form, like the dashboard.*
The unsaved-changes banner tells you which field needs attention. * The brute-force
settings are clearer: they are labelled Initial and Advanced, and the long lockout
is set in minutes. * Update Manager freeze periods need a start and an end date,
and dates in the past are rejected. * The two-factor lockout email is sent once 
per lockout instead of on every blocked attempt. * API keys pasted with an extra
space or line break are cleaned up when saved.

Changed
 * The “Require authorization to reset 2FA” option added in 1.0.29 has been
removed. It was off by default. If you had turned it on, users can once again reset
their own two-factor method without re-entering their password.

Fixed
 * Saving settings is more reliable: switches no longer flip back, a failed
save shows the real reason instead of “No internet connection”, and page caches 
are cleared after saving. * The hidden login page shows the right address after 
you save. * Cloudflare Turnstile and Google reCAPTCHA now protect the WooCommerce
block checkout as well as the classic one. * “Update all plugins” and “Update all
themes” now run the updates. * Password-reset links from WordPress or WooCommerce
are no longer logged as attacks. * “Clear all IP lockouts” no longer empties the
whole site cache on sites that use Redis or Memcached. * People on the block list
see a clear “blocked” message instead of a countdown. * Sites behind Cloudflare 
no longer risk locking out many visitors at once when Cloudflare’s visitor-address
header is missing. * Authenticator app setups survive uninstalling and reinstalling
the plugin when you choose to keep plugin data. * Saved API keys stay readable after
you change your site’s security keys (salts). * The Patchstack and WPScan vulnerability
checks work again and catch more affected versions. * Test Mode respects the “Always
exclude administrators” and “Log simulated blocks” switches, and records the right
user. * Undoing a settings import in Backup & Restore works again, and the Copy 
button works on sites without HTTPS. * The reCAPTCHA and Turnstile debug logs load
again, the dashboard shows your PHP version straight away, and two messages that
could crash on PHP 8 are fixed.

#### Earlier versions

See the full history at https://wpultimatesecurity.com/changelog/

## ຂໍ້ມູນກຳກັບ (Meta)

 *  ເວີຊັນ **1.0.40**
 *  ອັບເດດຫຼ້າສຸດເມື່ອ **9 ຊົ່ວໂມງ ທີ່ຜ່ານມາ** ທີ່ຜ່ານມາ
 *  ການຕິດຕັ້ງທີ່ໃຊ້ງານຢູ່ **10+**
 *  ເວີຊັນ WordPress ** 5.6 ຫຼື ສູງກວ່າ **
 *  ທົດສອບເຖິງເວີຊັນ **7.1.2**
 *  ເວີຊັນ PHP ** 7.1 ຫຼື ສູງກວ່າ **
 *  ພາສາ
 * [English (US)](https://wordpress.org/plugins/ultimate-security/) ແລະ [Lao](https://lo.wordpress.org/plugins/ultimate-security/).
 *  [ແປເປັນພາສາຂອງເຈົ້າ](https://translate.wordpress.org/projects/wp-plugins/ultimate-security)
 * ແທັກ
 * [Brute Force](https://lo.wordpress.org/plugins/tags/brute-force/)[login security](https://lo.wordpress.org/plugins/tags/login-security/)
   [security](https://lo.wordpress.org/plugins/tags/security/)[two factor authentication](https://lo.wordpress.org/plugins/tags/two-factor-authentication/)
   [vulnerability scanner](https://lo.wordpress.org/plugins/tags/vulnerability-scanner/)
 *  [ມຸມມອງຂັ້ນສູງ](https://lo.wordpress.org/plugins/ultimate-security/advanced/)

## ການໃຫ້ຄະແນນ

ຍັງບໍ່ມີການສົ່ງຄຳວິຈານເທື່ອ.

[ການທົບທວນຂອງທ່ານ](https://wordpress.org/support/plugin/ultimate-security/reviews/#new-post)

[ເບິ່ງທັງໝົດ ການຣີວິວ](https://wordpress.org/support/plugin/ultimate-security/reviews/)

## ຜູ້ຮ່ວມພັດທະນາ

 *   [ WP Ultimate Security ](https://profiles.wordpress.org/wpultimatesecurity/)

## ການຊ່ວຍເຫຼືອ

ມີຄຳຖາມ ຫຼື ຕ້ອງການຄວາມຊ່ວຍເຫຼືອບໍ່?

 [ເບິ່ງຟໍຣັມການຊ່ວຍເຫຼືອ](https://wordpress.org/support/plugin/ultimate-security/)