مەزمۇنغا ئاتلاش
WordPress.org

ئۇيغۇرچە

  • ئۆرنەكلەر
  • قىستۇرمىلار
  • خەۋەرلەر
  • قوللاش
  • ھەققىدە
  • WordPress كە ئېرىشىش
WordPress كە ئېرىشىش
WordPress.org

Plugin Directory

MJP Security Tools

  • قىستۇرما تاپشۇرۇڭ
  • ياقتۇرغانلىرىم
  • تىزىمغا كىرىڭ
  • قىستۇرما تاپشۇرۇڭ
  • ياقتۇرغانلىرىم
  • تىزىمغا كىرىڭ

MJP Security Tools

يازغۇچى zackdesign
چۈشۈر
  • تەپسىلاتلار
  • باھالاشلار
  • ئورنىتىش
  • ئىجادىيەت
قوللاش

چۈشەندۈرۈش

MJP Security Tools is a focused hardening plugin that does four things well:

  • XSS Database Scanner — scans every table for <script>, <iframe>, onclick, javascript: and other injection patterns
  • POST Request Log — records all POST data (passwords masked) with IP, user agent, and URL for CSRF/audit detection
  • Failed Login Log — tracks every failed login attempt with username, IP, and timestamp
  • File Permission Checker — verifies WordPress root files and directories have safe permissions, checks for missing index.html files and SVN working copies

What this plugin does NOT do (because WordPress core already handles it):

  • SSL enforcement — use FORCE_SSL_ADMIN or let WordPress 5.7+ auto-redirect
  • Password strength — WordPress core enforces strong passwords since 4.3
  • Login rate limiting — use a dedicated plugin like Limit Login Attempts Reloaded
  • Version number hiding — marginal benefit, not worth the complexity

Upgrading from v1.x:

  • The admin page has moved from jQuery UI tabs to native WordPress nav tabs
  • SSL forcing, password enforcement, login throttling, version hiding, admin username changing, database prefix randomization, password reset, and .htaccess generation have been removed — WordPress core and dedicated security plugins handle these better
  • PHP sessions replaced with WP transients for flash messages
  • Log data is now stored as JSON instead of serialized PHP
  • The Javacrypt client-side crypt(3) script has been removed

ئورنىتىش

  1. Upload the mjp-security-plugin folder to /wp-content/plugins/
  2. Activate through the Plugins menu
  3. Go to Tools > MJP Security Tools

FAQ

What happened to all the other features?

WordPress 6.x handles SSL, password strength, and many security basics natively. Rather than duplicating core functionality, v2.0.0 focuses on the four features that WordPress does NOT provide out of the box: XSS scanning, POST logging, failed login logging, and file permission checking.

Is this a replacement for Wordfence/iThemes?

No — those are comprehensive security suites. MJP Security Tools is a lightweight auditing companion that provides specific database scanning and logging features.

باھالاشلار

بۇ قىستۇرمىغا تېخى باھا يېزىلمىدى.

تۆھپىكار ۋە ئىجادكار

«MJP Security Tools» كودى ئوچۇق يۇمشاق دېتال. تۆۋەندىكى كىشىلەر بۇ قىستۇرمىغا تۆھپە قوشقان.

تۆھپىكار
  • zackdesign
  • AliasIO

«MJP Security Tools» نى تىلىڭىزغا تەرجىمە قىلىڭ

ئىجادىيەتكە قىزىقامسىز؟

كودقا كۆز يۈگۈرتۈپ، SVN خەزىنە تەكشۈرۈپ ياكى RSSئارقىلىق ئىجادىيەت خاتىرىسىگە مۇشتەرى بولغىلى بولىدۇ.

ئۆزگىرىش خاتىرىسى

2.0.0

  • Rewrite: focused on 4 core features — XSS scanner, POST log, failed login log, file permissions
  • Removed: SSL forcing, password enforcement, login throttling, version hiding (handled by WP core)
  • Removed: Admin username changer, DB prefix randomizer, password reset all users, .htaccess generator
  • Removed: jQuery UI 1.8.10 dependency and Javacrypt crypt(3) JavaScript (~500 lines)
  • Removed: PHP sessions — uses WP transients for flash messages
  • New: Native WordPress nav-tab interface (no jQuery UI)
  • New: Dedicated CSS/JS assets instead of inline styles and CDN links
  • New: Clear log buttons for POST and failed login logs
  • New: Log data stored as JSON instead of serialized PHP
  • New: File permission scan limited to 2 levels deep (prevents timeout on large installs)
  • Fixed: HTML parse error in admin template (missing > on div tag)
  • Fixed: Admin page uses dedicated slug instead of __FILE__
  • Changed: Requires WordPress 6.0+

1.2.1

  • Fixed PHP 8.1 deprecation: get_option() returning false passed to substr()

1.2.0

  • PHP 8.x compatibility fixes
  • Replaced deprecated functions and constants
  • Tested with WP 6.9.1

1.1

  • Tested in WP 3.3.2

1.0

  • First Release

Meta

  • Version 2.0.0
  • ئاخىرقى يېڭىلانغان ۋاقىت 5 ئاي بۇرۇن
  • ئاكتىپ ئورنىتىش سانى 10+
  • WordPress نەشرى 6.0 ياكى يۇقىرى
  • 6.9.5 دا سىنالغان
  • PHP نەشرى 7.4 ياكى يۇقىرى
  • تىل
    English (US)
  • بەلگە
    auditloginpermissionssecurityxss
  • ئالىي كۆرۈنۈش

دەرىجە

No reviews have been submitted yet.

Your review

بارلىق ئىنكاسنى كۆرسەت

تۆھپىكار

  • zackdesign
  • AliasIO

قوللاش

چۈشەندۈرۈشىڭىز بارمۇ؟ ياردەم لازىممۇ؟

قوللاش مۇنبىرىنى كۆرسەت

ئىئانە

بۇ قىستۇرمىنىڭ ياخشىلىنىشىنى قوللامسىز؟

بۇ قىستۇرمىغا ئىئانە قىلىش

  • ھەققىدە
  • خەۋەر
  • مۇلازىمىتىر
  • شەخسىيەت
  • كۆرگەزمە
  • ئۆرنەكلەر
  • قىستۇرمىلار
  • ئەندىزە
  • ئۈگىنىش
  • قوللاش
  • ئىجادكارلار
  • WordPress.tv ↖
  • قاتناشقان
  • پائالىيەت
  • ئىئانە ↖
  • Five for the Future
  • WordPress.com ↖
  • Matt ↖
  • bbPress ↖
  • BuddyPress ↖
WordPress.org
WordPress.org

ئۇيغۇرچە

  • Visit our X (formerly Twitter) account
  • Bluesky ھېساباتىمىزنى زىيارەت قىلىڭ
  • Visit our Mastodon account
  • Threads ھېساباتىمىزنى زىيارەت قىلىڭ
  • Facebook بېتىمىزنى زىيارەت قىلىڭ
  • Instagram ھېساباتىمىزنى زىيارەت قىلىڭ
  • LinkedIn ھېساباتىمىزنى زىيارەت قىلىڭ
  • TikTok ھېساباتىمىزنى زىيارەت قىلىڭ
  • YouTube قانىلىمىزنى زىيارەت قىلىڭ
  • Tumblr ھېساباتىمىزنى زىيارەت قىلىڭ
كود شېئىرغا ئوخشايدۇ.
The WordPress® trademark is the intellectual property of the WordPress Foundation.