Saltar ao contido
WordPress.org

Galego

  • Temas
  • Plugins
  • Novas
  • Acerca de
  • Padróns
  • Colabora
  • Equipo
  • Meetups
  • Contacto
  • Homenaxes
  • Consigue WordPress
Consigue WordPress
WordPress.org

Plugin Directory

XO Security

  • Enviar un plugin
  • Os meus favoritos
  • Iniciar sesión
  • Enviar un plugin
  • Os meus favoritos
  • Iniciar sesión

XO Security

Por ishitaka
Descargar
  • Detalles
  • Valoracións
  • Instalación
  • Desenvolvemento
Soporte

Descrición

XO Security is a plugin to enhance login related security.
This plugin does not write to .htaccess file. Besides Apache, LiteSpeed, Nginx and IIS also work.

Functions

  • Record login log.
  • Limit login attempts.
  • Add Captcha to the login form and comment form.
  • Change the URL of the login page.
  • Enable two-factor authentication (2FA) for login.
  • Login Alert.
  • Disable login by mail address.
  • Disable login by user name.
  • Change login error message.
  • Disable XML-RPC and XML-RPC Pingback.
  • Disable REST API.
  • Disable author archive page.
  • Remove comment author class of comments list.
  • Remove the username from the oEmbed response data.
  • WooCommerce login page protection.
  • Anti-spam comment.
  • Hide WordPress version information.
  • Edit the author slug.
  • Disable RSS and Atom feeds.
  • Activate maintenance mode.
  • Delete the readme.html file.

WordPress multisite considerations

If you set the login page separately for the main site and the subsite, you will not be able to use the password loss function of the subsite. We recommend that you set the login page to be common to all sites.

Capturas

  • Login log page.
  • Status page.
  • Login setting page.
  • Profile page.

Instalación

  1. Upload the XO-Security folder to the /wp-content/plugins/ directory.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Go to “Settings” -> “XO Security” and customize behaviour as needed.

Preguntas frecuentes

Login page is not displayed.

Please initialize the settings.

  • In wp_options table, the value of the option_name field (column) is to remove the record of “xo_security_options”.
  • If you have set the login page, please delete the file.

The CAPTCHA is not displayed.

Please install mbstring and GD module.

Comentarios

Awesome!

imawc 7 de Febreiro, 2026
This plugin is lightweight and easy to use, so I recommend it.

What a great plugin!

まーちゅう 25 de Decembro, 2025
It’s my top recommendation for security plugins on WordPress sites.It includes all the security features I need.

基本的なセキュリティ機能が揃っています

altmmc 4 de Novembro, 2023
タイトル通りです。AIOS等の定番プラグインと比べると機能は少ないですが、必要最低限の対策が揃っており設定が非常にわかりやすいので使いやすいです。これだけでは不安という人はBBQ Firewallを併用すると良いです。

This one is all you need !

Katsushi Kawamori 8 de Abril, 2023
This one plugin completes my security measures. Thanks !!

Great useful and easy to use!

Anonymous User 20656096 25 de Outubro, 2022
I recommend for those looking for a simple and reliable security plugin.

awesome

ulafox 19 de Agosto, 2021
This plugin has become one of my favorite plugins, it protects my website from malicious users, and the development team provides support very quickly! Thanks!
Ler todas as 11 opinións

Colaboradores e desenvolvedores

“XO Security” é un software de código aberto. As seguintes persoas colaboraron con este plugin.

Colaboradores
  • ishitaka

“XO Security” foi traducido a 1 idioma. Grazas aos desenvolvedores polas súas contribucións.

Traduce “XO Security” ao teu idioma.

Interesado no desenvolvemento?

Revisa o código, bota unha ollada aorepositorio SVN, ou subscríbete ao log de desenvolvemento por RSS.

Rexistro de cambios

3.10.8

  • Fixed a bug that sometimes prevented access to the login page.

3.10.7

  • Fixed a mistake in version 3.10.6.

3.10.6

  • Fixed an issue where the URL in the email sent when resetting a password was incorrect when changing the login page.

3.10.5

  • Supported WordPress 6.9.
  • Fixed a bug that sometimes prevented access to the login page.

3.10.4

  • Supported WordPress 6.6.

3.10.3

  • Supported CAPTCHA for login form using ajax.

3.10.2

  • Fixed a mistake in version 3.10.1.

3.10.1

  • Fixed a bug that sometimes prevented login with two-factor authentication.
  • Enhanced the judgment of comment bots.

3.10.0

  • Added option to change author base.
  • Added option to select CAPTCHA type.
  • Enhanced the judgment of comment bots.

3.9.1

  • Fixed a bug where an error message was displayed on the admin screen in PHP 8.2 or higher.

3.9.0

  • Added two-factor authentication function.
  • Fixed a bug where the login page file created by changing the login page may not be deleted during uninstallation.
  • The REST API URL change feature has been deprecated. If it is currently in use, you can continue to use it, but you cannot use it newly.

3.8.1

  • Supported WordPress 6.5.
  • Added ability to delete readme.html file.
  • Tweaked wording on the admin page.
  • Tweaked CSS on the admin page.

3.8.0

  • Added maintenance mode.

See the previous changelogs here

Meta

  • Versión 3.10.8
  • Última actualización Fai 3 meses
  • Instalacións activas 30.000+
  • Versión de WordPress 4.9 ou superior
  • Probado ata 6.9.1
  • Versión de PHP 5.6 ou superior
  • Idiomas

    English (US) e Japanese.

    Traduce ao teu idioma

  • Etiquetas
    Brute Forceloginmaintenancesecuritytwo factor
  • Vista avanzada

Valoracións

5 de 5 estrelas
  • 11 valoracións de 5 estrelas 5 estrelas 11
  • 0 valoracións de 4 estrelas 4 estrelas 0
  • 0 valoracións de 3 estrelas 3 estrelas 0
  • 0 valoracións de 2 estrelas 2 estrelas 0
  • 0 valoracións de 1 estrelas 1 estrela 0

Engadir a miña recensión

Ver todas as valoracións

Colaboradores

  • ishitaka

Soporte

Tes algo que dicir? Necesitas axuda?

Ver o foro de soporte

  • Acerca de
  • Novas
  • Aloxamento
  • Privacidade
  • Escaparate
  • Temas
  • Plugins
  • Padróns
  • Aprender
  • Soporte
  • Desenvolvedores
  • WordPress.TV ↗
  • Involúcrate
  • Eventos
  • Doar ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Galego

  • Visita la cuenta de X (anteriormente Twitter)
  • Visita a nosa conta de Bluesky
  • Visita a nosa conta de Mastodon
  • Visita a nosa conta de Threads
  • Visita a nosa páxina de Facebook
  • Visita a nosa conta de Instagram
  • Visita a nosa conta de LinkedIn
  • Visita a nosa conta de TikTok
  • Visita a nosa canle de YouTube
  • Visita a nosa conta de Tumblr
O código é poesía.
The WordPress® trademark is the intellectual property of the WordPress Foundation.