This plugin enhances the WordPress security.
Effective such as the brute force attack.
Includes the following specific functions.
1.Google reCaptcha v3 protect login screen from bot attacks.
2.Change the URL of the login screen, to avoid attacks on the login screen.
You can ward off tying for try to login for cracking, such as Brute-force attack.
Adding parameter to login URL so that default login url will hidden.
3.Block the display of author archive page
WordPress leaks your login id because of redirect author archive page by author id to login id.
(If you enter «your-site-url/?author=1», you can try it.)
Simply hideing author archive page so that block to leak login id.
4.To limiting the part of the XML-RCP feature prevents the attack.
Block DDOS attacks against other sites with yor WordPress site, pingback enabled.
Block login via XML-RPC.
5.Disable the REST API function and reduce the risk of receiving external attacks.
You can disable all REST APIs and you can partially disable them.
(This feature will be removed in version 2.1.)
These features will be able to choose whether or not to enable.
This plug-in does not change the .htaccess
You can use with confidence.
Also it works in both Apache and nginx.
(photo by Keoni Cabral https://www.flickr.com/photos/keoni101/)
- Install and activate the plugin through the ‘Plugins’ menu in WordPress.
- Go to Settings > Barbwire Security.
- Perform the necessary settings and press the Save button.
Contributors & Developers
“Barbwire Security” is open source software. The following people have contributed to this plugin.Contributors
fix error message to be displayed once even when the reCaptcha key was correct.
update disabling only XML-RCP pingback to disabling pingback and login.
add Google reCaptcha v3 protect login screen from bot attacks.
add parameter to logout url
update renew readme.txt and plugin file header.
update move the translation from mo files to Polyglots
fix From version 18.104.22.168, part of the login URL change function was not working properly.
update do refactor
update remove unused code.
update replace deprecated action hook.
fix bug for subdirectory type WordPress.
update For WordPress 5.3
fix Fetal error.
fix Bug prevent access to password-protected content.
fix Error when the version of WordPress does not support REST API.
fix Error on setting screen in Version 4.6.x or earlier.
change Possible to finely set the restriction of REST API
change Move menu to submenu of option
fix Remove Notice Error in setting page
add Link to setting page to plugin list page
Specify support for version 4.9
fix settings page duplication
Specify support for version 4.8.2
Add new function, Disable the REST API
Refactor source codes
fix disnable pingback function was not working
add function block the display of author archive page
add help documentation
fix login page will divulge, when using Permalink settings
Thanks to @nyarocom pointed out.(https://wordpress.org/support/topic/login-page-will-divulge/)
fix php warning message
fix error error of removing the plugin