Title: Version Cloak
Author: nextdoorentertainment
Published: <strong>2026 年 6 月 25 日</strong>
Last modified: 2026 年 6 月 26 日

---

搜索插件

![](https://ps.w.org/version-cloak/assets/banner-772x250.png?rev=3586364)

![](https://ps.w.org/version-cloak/assets/icon-256x256.png?rev=3586364)

# Version Cloak

 作者：[nextdoorentertainment](https://profiles.wordpress.org/nextdoorentertainment/)

[下载](https://downloads.wordpress.org/plugin/version-cloak.1.0.4.zip)

 * [详情](https://cn.wordpress.org/plugins/version-cloak/#description)
 * [评价](https://cn.wordpress.org/plugins/version-cloak/#reviews)
 *  [安装](https://cn.wordpress.org/plugins/version-cloak/#installation)
 * [开发进展](https://cn.wordpress.org/plugins/version-cloak/#developers)

 [支持](https://wordpress.org/support/plugin/version-cloak/)

## 描述

Version Cloak is a hardening plugin that reduces the information opportunistic, 
automated scanners can read about your site. Version-matching bots fingerprint a
site, look up known issues for the detected versions, and probe the easy targets
first. This plugin shrinks that fingerprint.

**Important:** this plugin obscures version and endpoint information. It does **
not** patch vulnerable code. Keep your plugins, themes, and WordPress core updated—
obscurity is a complement to patching, not a replacement for it.

#### Two version modes (per dropdown)

For **WordPress core** and for **plugins & themes**, choose one of:

 * **Off** — leave the real version visible.
 * **Obfuscate** — remove or block the version so it can’t be read.
 * **Decoy** — report a plausible current version (auto-detected latest, or a value
   you set) so the site reads as up to date.

#### What it covers

 * The WordPress `<meta name="generator">` tag, feed generators and the WLW manifest.
 * Version query strings (`?ver=`) on enqueued CSS/JS, and the same inside inline
   CSS.
 * Version classes on the `<body>` tag (e.g. page-builder version classes).
 * Plugin-emitted `<meta name="generator">` tags.
 * Plugin version strings in HTML comments (e.g. SEO plugins).
 * Static version files served directly by the web server — `readme.txt`, `changelog.
   txt`, `release_log.html` — and version banner comments in CSS/JS assets. In Obfuscate
   these are blocked (Apache/LiteSpeed `.htaccess`, or an Nginx rule you add); in
   Decoy their version strings are rewritten and automatically reverted when you
   switch back.
 * WordPress core `readme.html` / `license.txt`, and the `install.php` / `upgrade.
   php` setup pages (blocked for non-logged-in visitors so admins can still run 
   updates).

#### Other hardening

 * **XML-RPC** — disable and return 404, or keep it but remove pingback and `system.
   multicall`.
 * **WP-Cron** — disable the HTTP pseudo-cron and block external hits to `wp-cron.
   php` (with an optional secret token for your system cron).
 * **REST user enumeration** — block the anonymous `/wp-json/wp/v2/users` endpoint.
 * **Author enumeration** — block the `?author=N` redirect that leaks usernames.

#### Reversible

Setting a mode to **Off**, or deactivating the plugin, restores the real version
strings and removes the `.htaccess` rules — the site returns to its normal state.

## 安装

 1. Upload the `version-cloak` folder to `/wp-content/plugins/`, or install the ZIP
    via **Plugins  Add New  Upload Plugin**.
 2. Activate the plugin through the **Plugins** menu.
 3. Configure under **Settings  Version Cloak**.
 4. If you use a page cache (LiteSpeed, etc.) or a CDN, purge it after changing settings
    so the changes are served.

## 常见问题

### Does this patch vulnerabilities?

No. It hides or decoys version information to reduce automated scanning. The actual
fix for an outdated component is to update it. Use this as an additional layer.

### What is the difference between Obfuscate and Decoy?

Obfuscate removes or blocks the version so a scanner reports “could not determine
the version”. Decoy reports a plausible current version so the site reads as fully
up to date. Use a real, recent version for Decoy — an implausible value may be ignored
by scanners.

### Will it break my plugin or theme updates?

WordPress detects updates from each component’s real version (its main file header
for plugins, `style.css` for themes), which is read independently. Core and plugin
update notifications are unaffected. Masking a theme’s `style.css` version does 
affect that theme’s own update notice, so the plugin shows its own update notice
in that case.

### I changed a setting but nothing changed.

Almost always page caching. Purge your cache (e.g. LiteSpeed  Purge All) and any
CDN after saving.

## 评价

此插件暂无评价。

## 贡献者及开发者

「Version Cloak」是开源软件。 以下人员对此插件做出了贡献。

贡献者

 *   [ nextdoorentertainment ](https://profiles.wordpress.org/nextdoorentertainment/)

[帮助将「Version Cloak」翻译成简体中文。](https://translate.wordpress.org/projects/wp-plugins/version-cloak)

### 对开发感兴趣吗?

您可以[浏览代码](https://plugins.trac.wordpress.org/browser/version-cloak/)，查看
[SVN仓库](https://plugins.svn.wordpress.org/version-cloak/)，或通过[RSS](https://plugins.trac.wordpress.org/log/version-cloak/?limit=100&mode=stop_on_copy&format=rss)
订阅[开发日志](https://plugins.trac.wordpress.org/log/version-cloak/)。

## 更新日志

#### 1.0.4

 * WP-Cron hardening is now OFF by default. Fresh installs keep WordPress’s normal
   scheduled tasks (update checks, scheduled posts, backups) working out of the 
   box. Enable “Disable the HTTP pseudo-cron” only alongside a real system cron.

#### 1.0.3

 * Fix: the 1.0.2 duplicate-copy guard wrongly triggered on normal single-site installs(
   PHP hoists the function it tested), disabling the plugin and its settings. The
   guard now checks only the runtime version constant.

#### 1.0.2

 * Guard against a fatal “cannot redeclare” error when a second copy of the plugin
   is active under a different folder name.
 * Asset version hiding now catches the ver= query parameter in any position (e.
   g. ?cache=9&ver=1.2.3), not only when it is first.

#### 1.0.1

 * Raised minimum PHP to 7.0 (header and readme).
 * Explicitly close the front-end output buffer on shutdown.

#### 1.0.0

 * Initial release.

## 额外信息

 *  版本 **1.0.4**
 *  最后更新：**3 月前**
 *  活跃安装数量 **不到10**
 *  WordPress 版本 ** 5.0 或更高版本 **
 *  已测试的最高版本为 **7.0.5**
 *  PHP 版本 ** 7.0 或更高版本 **
 *  语言
 * [English (US)](https://wordpress.org/plugins/version-cloak/)
 * 标签
 * [hardening](https://cn.wordpress.org/plugins/tags/hardening/)[security](https://cn.wordpress.org/plugins/tags/security/)
   [version](https://cn.wordpress.org/plugins/tags/version/)[wp cron](https://cn.wordpress.org/plugins/tags/wp-cron/)
   [xml-rpc](https://cn.wordpress.org/plugins/tags/xml-rpc/)
 *  [高级视图](https://cn.wordpress.org/plugins/version-cloak/advanced/)

## 评级

尚未提交反馈。

[您的评价](https://wordpress.org/support/plugin/version-cloak/reviews/#new-post)

[查看全部评论](https://wordpress.org/support/plugin/version-cloak/reviews/)

## 贡献者

 *   [ nextdoorentertainment ](https://profiles.wordpress.org/nextdoorentertainment/)

## 支持

有话要说吗？是否需要帮助？

 [查看支持论坛](https://wordpress.org/support/plugin/version-cloak/)