HT Security

HT Security

توسط

HT Security is a complete security suite for WordPress, offering multiple layers of protection for your website.

Important – External Service:
This plugin queries the National Vulnerability Database (NVD) API to check for known CVE vulnerabilities. Requests are made to:
* API URL: https://services.nvd.nist.gov/rest/json/cves/2.0
* Terms of Use: https://nvd.nist.gov/general/legal-disclaimer
* Privacy Policy: https://www.nist.gov/privacy-policy
* Frequency: Automatic check every 12 hours or manual on-demand
* Data sent: Name and version of WordPress/installed plugins (no personal data is sent)

The NVD API query is essential for the plugin’s CVE vulnerability detection functionality.

Key Features

  • Security Headers – HSTS, X-Frame-Options, Content-Security-Policy, and more
  • Login Alerts – Email notifications for successful and failed login attempts with rate limiting
  • Core Integrity Check – Verify WordPress core files against official checksums with 24h cache
  • CVE Vulnerability Detection – Check WordPress Core and active plugins against NVD database
  • User Enumeration Protection – Block user enumeration via REST API and author parameters
  • Maintenance Mode – Maintenance mode with authorized IP whitelist (IPv4, IPv6, CIDR support)
  • File Permissions Audit – Audit and automatic correction of critical file permissions
  • Plugin Security Indicators – Visual badges on plugins page showing vulnerability status

CVE Detection Features

  • Integration with NVD (National Vulnerability Database) API 2.0
  • Check WordPress Core and active plugins for known vulnerabilities
  • Intelligent batch processing with rate limiting
  • 8 layers of anti-false-positive validation
  • Vulnerability badges on plugins page (enable/disable option)
  • Dismissible alerts per user
  • Email notification when vulnerabilities are detected
  • Automatic check every 12 hours
  • NVD API Key support (increased rate limit)

Security Improvements in v1.5.0

  • IP Spoofing Fix – Properly detects real IP behind Cloudflare, proxies, and load balancers
  • Capability Check Fix – Authorization verified before processing
  • Rate Limiting by IP – More granular rate limiting for login alerts
  • Input Validation – Maximum length validation for feedback form

Supported Languages

  • English (US) – 100%
  • English (UK) – 100%
  • Português do Brasil – 100%
  • Português de Portugal – 100%
  • Español – 100%

License

This plugin is licensed under the GNU General Public License v2.0 or later. For more information, visit https://www.gnu.org/licenses/gpl-2.0.html.

  1. Upload the ht-security folder to the /wp-content/plugins/ directory
  2. Activate the plugin through the ‘Plugins’ menu in WordPress
  3. Go to ‘Settings > HT Security’ to configure

سوالات متداول

When does the plugin send emails?

Successful logins, failed logins, and when CVE vulnerabilities are detected (if CVE alerts option is enabled).

Can I disable the security headers?

Yes, through the settings page.

Does the plugin check WordPress Core integrity?

Yes, since version 1.1.0 we added this functionality to provide clear security visibility for administrators.

How does CVE vulnerability detection work?

The plugin queries the NVD (National Vulnerability Database) to check for known vulnerabilities in WordPress Core and active plugins. The check runs automatically every 12 hours and can also be run manually.

Do I need an NVD API Key?

It’s not required, but recommended. Without an API Key, the rate limit is 5 requests per 30 seconds. With a free API Key, it increases to 50 requests per 30 seconds, making checks much faster.

Can vulnerability badges be disabled?

Yes! In HT Security settings there’s an option to disable badges on the plugins page. The top alert will continue to work.

How do dismissible alerts work?

You can close alerts on the plugins page by clicking the X. They won’t reappear until the next vulnerability check. The dismissed state is saved per user.

How does user enumeration blocking work?

The plugin blocks attempts to list users through the REST API and redirects via author parameters.

Does maintenance mode affect administrators?

No, logged-in administrators can continue accessing the site normally.

Does automatic permission correction always work?

It depends on server settings. In some cases, manual correction via FTP/SSH may be necessary.

Does the anti-false-positive system work well?

Yes! We implemented 8 layers of validation: name validation, version validation, generic term filtering, addon detection, license variant detection, word matching, word count ratio, and more. This eliminates over 99% of false positives.

Will new features be added?

Yes, we’re constantly improving the plugin with new features and security enhancements.

×
نظری برای این آیتم موجود نیست.
0 0 رای ها
امتیازدهی
اشتراک در
اطلاع از
0 نظرات
قدیمی‌ترین
تازه‌ترین بیشترین رأی
نسخه حجم فایل SHA256 تغییرات دانلود
1.5.0 99 کیلوبایت -
دانلود
×
★★★★★
★★★★★
5.0 /5 (1 نظر)

قیمت:

رایگان

نگارش

1.5.0

آخرین انتشار

20 اردیبهشت 1405

آخرین بروزرسانی

3 ماه پیش

نصب های فعال

100+

نگارش وردپرس

وردپرس 6.5+

تست شده از نسخه

وردپرس 6.9.4

نگارش PHP

PHP 8.2+

نسخه ها

1 نسخه