বৰ্ণনা
Vortix Web Security provides practical WordPress hardening without accounts, license keys, remote telemetry or a license server. The plugin is designed to be conservative: new compatibility-sensitive protections are off by default, and .htaccess changes are verified and reverted if the site’s own loopback probe reports an HTTP 500.
Free protection modules
- Basic Hardening – generic login errors, public username-enumeration protection and MIME-sniffing protection.
- Login Protection – temporary IP and username lockouts after repeated failed logins.
- Disable XML-RPC – disables the XML-RPC interface and related discovery links.
- Bad Bot Blocker – blocks requests from a small list of known scanner/exploit User-Agents.
- Upload Protection – blocks execution of common script files in the uploads directory on Apache/LiteSpeed.
- Disable File Editor – disables the WordPress plugin and theme code editors.
- Hide WP Version – removes common WordPress version disclosures.
- Disable Directory Browsing – adds a verified Options -Indexes rule on Apache/LiteSpeed.
- Strong Password Enforcement – requires stronger passwords for users who can publish content.
- Automatic Plugin Updates – allows automatic updates for packages served by WordPress.org over HTTPS.
- Automatic Theme Updates – allows automatic theme updates for packages served by WordPress.org over HTTPS.
- Pingback & Trackback Control – disables legacy pingback/trackback publishing paths.
- Safe Security Headers – adds conservative X-Content-Type-Options and Referrer-Policy headers.
- Sensitive File Protection – blocks direct access to common deployment/configuration filenames and Git metadata directories.
- Malicious Query Blocking – blocks a small set of high-confidence XSS, traversal, null-byte, webshell and SQL injection signatures in the query string.
A 20-point Security Scan provides local checks for HTTPS, XML-RPC state, debug mode, file permissions, upload protection, version exposure, administrator username, login protection, directory listing, user enumeration, REST user exposure, file editors, RSD/WLW links, outdated plugins, pingback/trackback control, security headers, sensitive-file protection and malicious-query protection. Checks that cannot be verified are reported as unknown and excluded from the score.
Compatibility-sensitive modules remain off by default, including XML-RPC blocking, bot blocking, .htaccess protections, automatic updates, pingback/trackback control and malicious-query blocking. Existing installations keep their current choices when updating; newly introduced 2.2.0 modules are not enabled automatically.
Login recovery
If Vortix Login Protection ever locks out an administrator, add this temporary line to wp-config.php:
define( 'VORTIX_DISABLE_LOGIN_PROTECTION', true );
Log in, remove the line, and then review the Login Protection settings. This bypass affects only Vortix’s lockout module.
Privacy
Blocked requests are logged locally in the site’s own database. The log contains the client IP address, request path without the query string, event type and time. Entries are automatically removed according to the configured retention period. Login-attempt counters use keyed hashes and expire automatically.
The plugin does not send telemetry, security logs, license data or scan results to the author or another server.
External services
Vortix Web Security does not contact an external service.
- Security Scan and .htaccess safety checks may make loopback requests to the site’s own URL.
- Cloudflare mode only reads the
CF-Connecting-IPrequest header and uses address ranges bundled with the plugin; it does not contact Cloudflare. - The optional Premium link is an ordinary user-initiated external link. No request is made by the plugin merely because the link is displayed.
ইনষ্টলেশ্যন
- Upload the plugin to
/wp-content/plugins/vortix-web-security/, or install it from Plugins. - Activate Vortix Web Security.
- Open Vortix Web Security and review the protection modules.
- If the site is behind a CDN or reverse proxy, review Settings > Trusted proxy.
সঘনাই উত্থাপিত প্ৰশ্ন
-
Does it require a license or account?
-
No. The free plugin has no license key, trial, registration or remote licensing system.
-
Will an update enable the new 2.2.0 protections automatically?
-
No. Existing installations keep their current module choices. New 2.2.0 modules start disabled so an update does not silently change site behaviour.
-
Can Login Protection lock me out?
-
A temporary lockout can occur after repeated failures. If recovery is needed, use the
VORTIX_DISABLE_LOGIN_PROTECTIONwp-config.php bypass described above. -
Can .htaccess features break my site?
-
The plugin uses marked rules and probes the site’s own URL after a write. If the response indicates HTTP 500, the change is reverted. Hosts that do not support .htaccess are not modified.
-
Does Malicious Query Blocking inspect POST data?
-
No. It inspects only the query string and uses conservative, high-confidence signatures. It is disabled by default because application-specific query formats vary.
-
Does it work on Nginx?
-
Features that do not depend on .htaccess work on Nginx. Upload Protection, Disable Directory Browsing and Sensitive File Protection require equivalent Nginx configuration and will not claim to enforce those rules through .htaccess.
পৰ্য্যালোচনা
এই প্লাগিনৰ বাবে কোনো পৰ্য্যালোচনা নাই।
অৱদানকাৰী আৰু বিকাশকাৰীসকল
“Vortix Web Security” হৈছে মুক্ত উৎসৰ ছফ্টৱেৰ। এইসকল লোকে এই প্লাগিনত অৱদান আগবঢ়াইছে।
অৱদানকাৰীসকলআপোনাৰ ভাষাত “Vortix Web Security” অনুবাদ কৰক।
বিকাশৰ প্ৰতি আগ্ৰহী?
ক’ড ব্ৰাউজ কৰক, SVN ৰিপজিটৰী চাওক নাইবা RSS-দ্বাৰা বিকাশৰ পঞ্জী ছাবস্ক্ৰাইব কৰক।
সলনি-পঞ্জী
2.2.0
- Added Pingback & Trackback Control.
- Added Safe Security Headers with conservative, compatibility-focused headers.
- Added Sensitive File Protection with verified .htaccess changes.
- Added conservative Malicious Query Blocking for high-confidence query-string payloads.
- Expanded Security Scan from 16 to 20 local checks.
- Added a wp-config.php emergency bypass for Login Protection.
- Added versioned migration on
plugins_loaded; new 2.2.0 modules stay off for existing installations. - Removed unsupported premium marketing claims that were not represented by the separately distributed Pro codebase.
- Kept the free plugin offline-first with no telemetry or remote license infrastructure.
2.1.1
- Refreshed admin design: colour-coded status, header banner, feature filter and score ring.
2.1.0
- First WordPress.org release of the free edition.
- Added Basic Hardening and Disable XML-RPC.
- Rebuilt the Modules screen and made compatibility-sensitive features opt-in.
- Added verified .htaccess changes with loopback safety checks.
- Added trusted proxy handling and local security logging.