跳至内容
WordPress.org

China 简体中文

  • 主题
  • 插件
  • 新闻
    • 文档
    • 论坛
  • 关于
  • 获取 WordPress
获取 WordPress
WordPress.org

Plugin Directory

VaultShift

  • 提交插件
  • 我的收藏
  • 登录
  • 提交插件
  • 我的收藏
  • 登录

VaultShift

作者:Saju Gopal
下载
  • 详情
  • 评价
  • 安装
  • 开发进展
支持

描述

VaultShift hardens your WordPress site with a unified security dashboard, real-time threat monitoring, and tools that run locally on your server. Every core module is included and works out of the box after you activate your Free or Cloud key from myapps.wontonee.com.

Optional VaultShift Cloud services (signature sync, IP reputation, cloud spam scoring) stay off by default until you enable them under Settings.

Malware & file integrity scanner

  • Full-site file scans in the background — no need to keep a browser tab open
  • Daily or weekly scheduled scans, plus on-demand manual scans
  • WordPress core checksum verification against the official release
  • Database malware scan (options, posts, post meta, comments, users)
  • Quarantine suspicious files instead of deleting immediately
  • Security score and scan history on the dashboard
  • Automatic scan triggers when attacks are detected

Web Application Firewall (WAF)

  • Runs as a must-use plugin before WordPress loads, blocking threats early
  • Learning, active, and paranoid modes
  • Built-in rule sets plus optional cloud rule updates (when Cloud is enabled)
  • Block and allow lists, rate limiting, and WAF event logging
  • Geo-blocking by country and optional VPN/proxy blocking

Login protection

  • Brute-force lockout after failed attempts
  • Optional custom login URL to hide wp-login.php
  • Google reCAPTCHA v3 when you add your own site keys
  • Two-factor authentication (TOTP) for administrator accounts

WordPress hardening

  • One-click checklist: disable file editor, limit REST user enumeration, security headers, and more
  • Sensible defaults with per-toggle control
  • WordPress Site Health tests for scan freshness, WAF status, and backup directory

Activity log

  • Tamper-evident log of logins, file changes, plugin updates, and security events
  • Filterable admin view and REST API access
  • Helps with audits and incident response

Spam protection

  • Honeypot, heuristics, and scoring for comments and registration
  • Optional cloud spam check when VaultShift Cloud is enabled
  • Integrations for common form plugins

Backup & restore

  • Create compressed backups of your database and wp-content
  • Scheduled or manual backups with retention controls
  • Restore from backup history with progress tracking

VaultShift Cloud (optional)

Enable Cloud services under Settings when you want enhanced protection backed by VaultShift servers:

  • Up-to-date malware signatures
  • IP reputation and VPN/proxy detection
  • Cloud-based spam scoring

Remote calls are opt-in only — nothing is sent until you turn Cloud on.

Free vs Cloud keys

VaultShift requires a cloud key to activate (Free or Cloud tier). Keys tie your site to myapps for plan validation. All local security features remain on your server; Cloud keys unlock optional remote services when you choose to enable them.

External services

This plugin may connect to external services when configured or when you opt in.

VaultShift Cloud

Optional malware signature updates, IP reputation checks, VPN/proxy detection, and cloud-based spam scoring when Cloud services is enabled under Settings.

Sends visitor IP addresses, comment metadata/content (when cloud spam check is enabled), and site identification data when those features run.

Service: VaultShift Cloud API at https://myapps.wontonee.com/v1
Terms of use: https://wontonee.com/terms/
Privacy policy: https://wontonee.com/privacy/

myapps cloud keys (VaultShift activation)

Used when you activate a Free or Cloud key during setup or under Settings.

Sends your cloud key and site domain to register and validate your plan.

Service: https://myapps.wontonee.com/api/vaultshift
Terms of use: https://wontonee.com/terms/
Privacy policy: https://wontonee.com/privacy/

Google reCAPTCHA

Used when you enter reCAPTCHA v3 site and secret keys under Login Protection.

Sends the visitor IP address and reCAPTCHA token to Google for verification when someone logs in or registers.

Terms of use: https://policies.google.com/terms
Privacy policy: https://policies.google.com/privacy

ipapi.co

Used for country-based geo-blocking when you configure blocked country codes under Firewall.

Sends the visitor IP address when determining country code.

Terms of use: https://ipapi.co/terms/
Privacy policy: https://ipapi.co/privacy/

WordPress.org API

Used during malware scans to verify WordPress core file checksums against the official release.

Sends WordPress version and locale.

Terms of use: https://wordpress.org/about/gpl/
Privacy policy: https://wordpress.org/about/privacy/

屏幕截图

Security dashboard with score, WAF status, activity feed, and recommendations
Security dashboard with score, WAF status, activity feed, and recommendations
Malware scanner — run scans and review findings
Malware scanner — run scans and review findings
Login protection — brute-force lockout, custom login URL, and reCAPTCHA
Login protection — brute-force lockout, custom login URL, and reCAPTCHA
Hardening checklist with one-click security toggles
Hardening checklist with one-click security toggles
Tamper-evident activity log of security events
Tamper-evident activity log of security events
Web Application Firewall modes, geo-blocking, and WAF log
Web Application Firewall modes, geo-blocking, and WAF log
Spam protection with local heuristics and optional cloud scoring
Spam protection with local heuristics and optional cloud scoring
Backup, restore, and backup history
Backup, restore, and backup history
Settings — cloud key, VaultShift Cloud, and threat response
Settings — cloud key, VaultShift Cloud, and threat response

安装

  1. Upload the plugin to /wp-content/plugins/vaultshift/ or install via Plugins → Add New → Upload Plugin.
  2. Activate VaultShift through the Plugins menu.
  3. Enter your Free or Cloud key from myapps.wontonee.com when prompted.
  4. Open VaultShift → Dashboard to review your security score and run your first scan.
  5. Optionally enable Cloud services under VaultShift → Settings if you use a Cloud key and want remote features.

常见问题

Does VaultShift send data to external servers?

Most processing runs locally on your server. Remote requests are opt-in: enable Cloud services under VaultShift → Settings only if you want optional VaultShift Cloud features. Geo-blocking uses ipapi.co when configured. reCAPTCHA uses Google when you add your own site keys. Cloud key activation sends your key and domain to myapps once during setup.

Where is the WAF loaded?

On activation, VaultShift installs a must-use plugin at wp-content/mu-plugins/vaultshift-waf.php. It loads before WordPress core so malicious requests can be blocked early.

Do I need a paid Cloud key?

No. A Free cloud key activates VaultShift and includes all local security modules. A Cloud key adds access to optional VaultShift Cloud services when you enable them in Settings.

Can I run scans on a schedule?

Yes. Choose daily, weekly, or manual-only under VaultShift → Scanner. Scans run in the background via Action Scheduler.

评价

此插件暂无评价。

贡献者及开发者

「VaultShift」是开源软件。 以下人员对此插件做出了贡献。

贡献者
  • Saju Gopal

帮助将「VaultShift」翻译成简体中文。

对开发感兴趣吗?

您可以浏览代码,查看SVN仓库,或通过RSS订阅开发日志。

更新日志

1.1.1

  • Database malware scan: options, posts, post meta, comments, users, and usermeta.
  • Detects injected scripts, malware markers, and critical option hijacks (siteurl/home/theme).
  • Reduced database false positives (trusted embeds, skip WordPress transients).
  • Scanner progress uses stage-weighted percentages; more reliable on large sites.
  • Faster local scan batch fallback when Action Scheduler is unavailable.

1.1.0

  • Cloud key activation: Free and Cloud plans require a myapps cloud key before using VaultShift admin.
  • Onboarding modal with Free vs Cloud plan comparison, blurred background overlay, and one-click activation.
  • Settings panel shows active cloud key status when registered.
  • myapps API integration for register, validate, remove, and plan info.

1.0.3

  • Plugin URI points to GitHub; cloud API and legal links use wontonee.com domains (removed vaultshift.io).

1.0.2

  • WordPress.org review compliance: removed feature gating, cloud opt-in only, enqueue fixes, path constants, readme external services disclosure.

1.0.1

  • Daily and weekly scheduled malware scans.
  • WordPress Site Health tests for scan freshness, WAF, and backup directory.
  • Backup restore from history, detailed restore progress, and improved queue handling.
  • Plugin Check and PHPCS compliance fixes.

1.0.0

  • Initial release: security modules and REST API.

额外信息

  • 版本 1.1.1
  • 最后更新:10 小时前
  • 活跃安装数量 不到10
  • WordPress 版本 5.8 或更高版本
  • 已测试的最高版本为 7.0.4
  • PHP 版本 7.4 或更高版本
  • 语言
    English (US)
  • 标签
    firewallloginmalwaresecurityspam
  • 高级视图

评级

尚未提交反馈。

您的评价

查看全部评论

贡献者

  • Saju Gopal

支持

有话要说吗?是否需要帮助?

查看支持论坛

  • 关于
  • 新闻
  • 主机
  • 隐私
  • 陈列窗
  • 主题
  • 插件
  • 区块样板
  • 学习
  • 支持
  • 开发者
  • WordPress.tv ↗︎
  • 参与
  • 活动
  • 捐赠 ↗
  • 周边商品 ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

China 简体中文

  • 关注我们的 X(原 Twitter)账号
  • 访问我们的 Bluesky 账号
  • 关注我们的 Mastodon 账号
  • 访问我们的 Threads 账号
  • 访问我们的 Facebook 公共主页
  • 关注我们的 Instagram 账号
  • 关注我们的 LinkedIn 主页
  • 访问我们的 TikTok 账号
  • 访问我们的 YouTube 频道
  • 访问我们的 Tumblr 账号
代码如诗
The WordPress® trademark is the intellectual property of the WordPress Foundation.