plugin-icon

WordSec – Malware Scanner & Removal, Web Application Firewall (WAF), and 2FA

제작자: WordSec·
WordPress security plugin with firewall, malware scanner, and login protection. Block attacks and scan for malware from one dashboard.
평가
5
버전
1.1.0
최근 업데이트일
Aug 1, 2026
WordSec – Malware Scanner & Removal, Web Application Firewall (WAF), and 2FA

WordSec is a complete WordPress security plugin. Eight modules cover the firewall, malware scanner, login security, live traffic, IP and country blocking, supply-chain intelligence, audit log and alerts, so you block attacks and harden your site from one dashboard instead of installing eight plugins.

If your site gets hacked you do not just lose the site. You lose customer trust, your search rankings, and days of work restoring backups. WordSec is built to stop that before it happens, and to help you recover if it already has: the scanner finds the malware, quarantine takes it out of the way, and modified core, plugin and theme files are repaired from their original copies.

Free, and no license key to enter. WAF firewall rules, malware and file-integrity scanning, brute force protection, two factor authentication, IP and country blocking, the audit log and one-click hardening all run locally on your own server.

Web Application Firewall (WAF)

  • Custom rule builder with regex and wildcard matching
  • Built-in rules for SQL injection, XSS, path traversal, PHP and command injection
  • Learning and active modes, bot blocking, security headers, rate limiting
  • 25+ hardening toggles for wp-config access, author enumeration and REST API
  • Optional Extended Protection: pre-WordPress request inspection (opt-in, fully reversible)

Malware Scanner and Removal

  • Malware detection rules across files, the database and scheduled tasks
  • Core, plugin and theme file-integrity verification via the WordPress.org API
  • Scheduled scans, one-click quarantine and restore
  • Malware removal on a hacked site: quarantine a finding, or repair a modified core, plugin or theme file from its original copy

Login Security, Two-Factor Authentication (2FA) and Brute Force Protection

  • Role-based two-factor authentication (RFC 6238 TOTP)
  • reCAPTCHA, hCaptcha and Cloudflare Turnstile, plus a built-in math CAPTCHA
  • Brute-force protection with progressive lockout, honeypot and login URL rename
  • Leaked-password checking, session management, custom login page

실시간 트래픽

  • Real-time request logging with bot detection and CSV export
  • Exclusion filtering by role, IP, country or URI

IP and Country Blocking

  • 국가 및 대륙 허용 또는 차단 목록
  • IP and CIDR blocking, temporary or permanent, with allow-list support

Supply Chain and Threat Intelligence

  • Reputation scoring and abandoned-plugin detection
  • Known-vulnerability alerts for core, plugins, themes and PHP
  • Update-integrity verification with backups and an SBOM inventory

감사 로그

  • Activity tracking across 11 object types and 14 actions

Alarms

  • 36 alert event types delivered by Email, Telegram or Slack

Every feature runs locally with no license key. Optionally, the WordSec service at wordsec.net supplies threat-intelligence data that cannot be produced locally: managed WAF rule sets, the malware signature feed, IP-reputation lists, the GeoIP database and vulnerability records. Connecting is optional and every external service is documented in “External services” below.

외부 서비스

WordSec은 로컬에서 실행되도록 설계되었으며, 라이선스 키가 없으면 WordSec 서비스로 외부 요청을 보내지 않습니다. 핵심 요청 필터링과 파일 스캔은 서버에서 실행됩니다. 아래 나열된 서비스는 설명된 특정 기능에 대해서만 연결되며, 대부분은 사용자가 해당 기능을 명시적으로 활성화한 경우에만(또는 WordSec API의 경우 라이선스 키를 활성화한 후에만) 연결됩니다. 이 섹션은 플러그인이 연결할 수 있는 모든 타사 서비스와 각 서비스가 받는 데이터를 문서화합니다.

WordSec API (api.wordsec.net)

WordSec은 라이선스 없이 무료로 실행되며, 이 경우 이 서비스에 전혀 연결하지 않습니다. 무료 라이선스는 모든 사용자에게 제공됩니다. 키를 활성화하면 플러그인은 두 가지 별개의 목적으로 WordSec 서비스와 통신합니다:

  1. 필수 서비스 호출(라이선스 키가 활성화되어 있는 동안에만): 라이선스 활성화 및 검증, 그리고 위협 데이터 업데이트(방화벽 규칙, 악성코드 시그니처, IP 평판 목록, GeoIP 데이터, 일회용 이메일 도메인 목록 및 알려진 취약점 데이터). 이러한 호출은 클라우드 기반 기능을 활성화하며 로컬에서 수행할 수 없습니다. 키가 없으면 이러한 호출은 전혀 이루어지지 않습니다. 이러한 기능의 로컬 적용 코드(WAF 엔진, 악성코드 스캐너, IP 차단 필터 및 가입 제한 필터)는 항상 존재하며 활성화되어 있습니다. 최신 피드가 없으면 단지 요청을 대조할 위협 인텔리전스 데이터가 없을 뿐입니다.

* 시점: 활성화/검증 시, 그리고 예약된 위협 데이터 업데이트 검사 시. * 전송 데이터: 사이트 URL 및 라이선스 키(사용자 인증 및 이 사이트에 라이선스를 연결하는 데 사용됨), 그리고 업데이트 검사의 경우 설치된 위협 데이터 피드의 현재 버전.

  1. 선택적 사용/환경 텔레메트리(OPT-IN, 기본값 OFF): WordSec을 개선하는 데 사용되는 익명의 하루 한 번 스냅샷. 사용자가 “사용 & 환경 데이터 공유”를 명시적으로 활성화한 경우에만(라이선스 활성화 시 또는 설정 고급 사용 데이터에서) 전송되며 언제든지 다시 끌 수 있습니다.

* 시점: 하루에 한 번, opt-in이 활성화되어 있는 동안에만. * 전송 데이터: 사이트 환경의 비개인 스냅샷(서버, WordPress, PHP 및 데이터베이스 버전, 활성 플러그인 및 테마 목록)과 WordSec 기능 사용 및 보안 통계 집계. 비밀번호, 데이터베이스 자격 증명, 비밀 키 또는 이메일 주소는 절대 전송되지 않습니다.

  • 서비스 약관: https://wordsec.net/terms
  • 개인정보 처리방침: https://wordsec.net/privacy

Have I Been Pwned (api.pwnedpasswords.com)

선택적 유출 비밀번호 검사가 k-anonymity를 사용하여 비밀번호가 알려진 데이터 유출에 나타나는지 감지하는 데 사용됩니다. * 시점: 사용자가 비밀번호를 설정하거나 제출하고 유출 비밀번호 검사가 활성화되어 있을 때. * 전송 데이터: 비밀번호 SHA-1 해시의 처음 5자만. 비밀번호 자체와 전체 해시는 사이트를 절대 벗어나지 않습니다. * 약관 및 개인정보: https://haveibeenpwned.com/Privacy

WordPress.org API (api.wordpress.org, downloads.wordpress.org, wordpress.org, core.svn.wordpress.org, plugins.svn.wordpress.org, themes.svn.wordpress.org)

Used to verify WordPress core, plugin and theme file integrity, to look up public plugin/theme information (plugins_api/themes_api) for the supply-chain reputation scores and update-integrity checks, to download WordSec’s own translation language pack from translate.wordpress.org when you pick a Display Language that is not installed yet (the same mechanism WordPress itself uses when the site language changes), and — only when you click “Repair” on a scanner finding — to download the original copy of a modified core/plugin/theme file so it can be restored. Repair downloads fetch single original files from plugins.svn.wordpress.org / themes.svn.wordpress.org / core.svn.wordpress.org, falling back to full packages from downloads.wordpress.org (plugin/theme zips) and wordpress.org (core release zips). * When: during malware/integrity scans and supply-chain reputation checks, on an explicit repair action, and when you save a Display Language whose translation is not installed yet. * Data sent: the WordPress core version, site locale, and the slugs/versions of the plugins/themes being checked; for a language download, the plugin slug/version and the chosen locale. * Terms & Privacy: https://wordpress.org/about/privacy/

RDAP (rdap.org)

도구 페이지의 WHOIS/RDAP 조회 도구가 사용자가 조사하는 IP 주소 또는 도메인의 소유자 정보를 표시하는 데 사용됩니다. * 시점: WHOIS/RDAP 조회 도구를 실행할 때만. * 전송 데이터: 사용자가 조회하기로 선택한 IP 주소 또는 도메인. * 약관 및 개인정보: https://about.rdap.org/

ipify (api.ipify.org)

도구 페이지의 블랙리스트 검사기와 서버 정보 도구가 서버 자체의 공개 IP 주소를 확인하는 데 사용됩니다. * 시점: “블랙리스트 확인” 또는 “서버 IP” 도구를 실행할 때만. * 전송 데이터: 서버에서 보내는 단순 요청으로, 사이트 데이터는 포함되지 않습니다(서비스는 요청한 IP를 그대로 반환할 뿐입니다). * 약관 및 개인정보: https://www.ipify.org/

DNS 차단 목록 제공자(블랙리스트 확인 도구)

도구 페이지의 “블랙리스트 확인”은 DNS 기반 차단 목록(DNSBL)을 조회하여 서버의 공개 IPv4 주소가 등록되어 있는지 알려줍니다. 각 제공자는 서버의 IP 주소를 역순 형태로 포함한 표준 DNS 쿼리를 받습니다. 다섯 개의 제공자를 조회합니다: * Spamhaus ZEN (zen.spamhaus.org) – https://www.spamhaus.org/privacy-notice/ * SpamCop (bl.spamcop.net), Cisco 운영 – https://www.cisco.com/c/en/us/about/legal/privacy-full.html * Barracuda Reputation Block List (b.barracudacentral.org) – https://www.barracuda.com/company/legal/privacy-policy * UCEPROTECT Level 1 (dnsbl-1.uceprotect.net) – https://www.uceprotect.net/en/index.php * PSBL (psbl.surriel.com) – https://psbl.org/ 세부 정보: * 시점: 도구 페이지에서 “블랙리스트 확인”을 클릭할 때만. * 전송 데이터: 각 DNS 차단 목록 쿼리에 포함된 서버의 공개 IPv4 주소.

Telegram Bot API (api.telegram.org)

선택적 알람 전달 채널. 사용자 본인의 Telegram 봇 토큰과 채팅 ID를 구성한 경우에만 활성화됩니다. * 시점: 사용자가 활성화한 보안 알람이 발생하고 Telegram 전달이 구성되어 있을 때. * 전송 데이터: 사용자가 구성한 봇/채팅으로 전송되는 알람 메시지 텍스트(이벤트 유형, 사이트 이름, 관련 IP/사용자 컨텍스트). * 서비스 약관: https://telegram.org/tos * 개인정보 처리방침: https://telegram.org/privacy

Slack Incoming Webhooks (hooks.slack.com)

선택적 알람 전달 채널. 사용자 본인의 Slack incoming-webhook URL을 구성한 경우에만 활성화됩니다. * 시점: 사용자가 활성화한 보안 알람이 발생하고 Slack 전달이 구성되어 있을 때. * 전송 데이터: 사용자가 구성한 웹훅으로 전송되는 알람 메시지 텍스트(이벤트 유형, 사이트 이름, 관련 IP/사용자 컨텍스트). * 서비스 약관: https://slack.com/terms-of-service * 개인정보 처리방침: https://slack.com/privacy-policy

Google reCAPTCHA (www.google.com, www.gstatic.com)

선택적 로그인/가입 CAPTCHA. reCAPTCHA를 선택하고 사용자 본인의 키를 제공한 경우에만 활성화됩니다. * 시점: 활성화되어 있는 동안 로그인 및 가입 양식에서. * 원격 로드: reCAPTCHA는 방문자의 브라우저에서 Google로부터 위젯 스크립트(www.google.com/recaptcha/api.js, www.gstatic.com의 자산과 함께 제공됨)를 로드해야 합니다. 이 스크립트는 해당 양식에서, 그리고 reCAPTCHA가 선택된 제공자인 동안에만 등록됩니다. 토큰 검증은 사이트에서 www.google.com으로 이루어지는 서버 측 호출입니다. * 전송 데이터: CAPTCHA 응답 토큰, 공개 사이트 키, 방문자의 IP 주소. * 서비스 약관: https://policies.google.com/terms * 개인정보 처리방침: https://policies.google.com/privacy

hCaptcha (hcaptcha.com, js.hcaptcha.com)

선택적 로그인/가입 CAPTCHA. hCaptcha를 선택하고 사용자 본인의 키를 제공한 경우에만 활성화됩니다. * 시점: 활성화되어 있는 동안 로그인 및 가입 양식에서. * 원격 로드: hCaptcha는 방문자의 브라우저에서 hCaptcha로부터 위젯 스크립트(js.hcaptcha.com/1/api.js)를 로드해야 합니다. 이 스크립트는 해당 양식에서, 그리고 hCaptcha가 선택된 제공자인 동안에만 등록됩니다. 토큰 검증은 사이트에서 hcaptcha.com으로 이루어지는 서버 측 호출입니다. * 전송 데이터: CAPTCHA 응답 토큰, 공개 사이트 키, 방문자의 IP 주소. * 서비스 약관: https://www.hcaptcha.com/terms * 개인정보 처리방침: https://www.hcaptcha.com/privacy

Cloudflare Turnstile (challenges.cloudflare.com)

선택적 로그인/가입 CAPTCHA. Turnstile을 선택하고 사용자 본인의 키를 제공한 경우에만 활성화됩니다. * 시점: 활성화되어 있는 동안 로그인 및 가입 양식에서. * 원격 로드: Turnstile은 방문자의 브라우저에서 Cloudflare로부터 위젯 스크립트(challenges.cloudflare.com/turnstile/v0/api.js)를 로드해야 합니다. 이 스크립트는 해당 양식에서, 그리고 Turnstile이 선택된 제공자인 동안에만 등록됩니다. 토큰 검증은 사이트에서 challenges.cloudflare.com으로 이루어지는 서버 측 호출입니다. * 전송 데이터: CAPTCHA 응답 토큰, 공개 사이트 키, 방문자의 IP 주소. * 서비스 약관: https://www.cloudflare.com/website-terms/ * 개인정보 처리방침: https://www.cloudflare.com/privacypolicy/

ipwhois.io (ipwho.is)

Optional IP details service, disabled by default. All requests go over HTTPS with certificate verification, and none are made until you enable “External IP Lookup Service” in WordSec Settings (Visitor IP Handling section). It is used for exactly one thing: the “IP details” lookup in Live Traffic (country, region, city, ISP, organization, ASN). Traffic logging never contacts this service; country resolution during logging uses only the local GeoIP database. * When: only while the External IP Lookup Service opt-in is enabled, and only on your click in the IP details lookup. * Data sent: the IP address you chose to inspect. * Terms of Service: https://ipwhois.io/terms * Privacy Policy: https://ipwhois.io/privacy

VirusTotal (virustotal.com)

자동으로 연결하지 않습니다. 스캐너는 클릭하면 특정 파일에 대해 브라우저에서 VirusTotal을 여는 “VirusTotal에서 확인” 링크를 표시합니다. * 시점: 링크를 클릭할 때만. * 전송 데이터: 링크 URL에 포함된 파일 해시. * 약관 및 개인정보: https://docs.virustotal.com/docs/privacy-policy

Qualys SSL Labs (ssllabs.com)

자동으로 연결하지 않습니다. 도구 페이지의 “SSL 상태 확인” 테스트는 전적으로 사용자의 서버에서 실행됩니다(사용자 자신의 도메인으로 TLS 연결을 열어 인증서를 읽습니다). 그 옆의 “심층 스캔(SSL Labs)” 링크는 새 브라우저 탭에서 Qualys SSL Labs 테스트를 엽니다. 그러면 SSL Labs가 외부에서 사이트에 연결하여 TLS 구성을 평가합니다. 이 링크에는 “결과 숨김” 플래그가 포함되어 있어 보고서가 SSL Labs 공개 게시판에 게시되지 않습니다. * 시점: “심층 스캔(SSL Labs)” 링크를 클릭할 때만. * 전송 데이터: 링크 URL에 포함된 사이트의 도메인 이름. * 약관: https://www.ssllabs.com/about/terms.html * 개인정보: https://www.qualys.com/company/privacy/

크레딧

WordSec은 아래 나열된 타사 라이브러리를 포함합니다. 모든 라이브러리는 WordSec 자체의 “GPLv2 or later” 라이선스와 호환되는 라이선스로 배포됩니다. 포함된 각 라이브러리는 파일 내 라이선스 배너 및/또는 업스트림 라이선스 파일을 유지하며, 각 라이브러리의 원본 전체(비압축) 소스는 연결된 프로젝트와 버전에서 확인할 수 있습니다.

PHP 라이브러리 (`vendor/`)

TCPDF 6.11.3 * 라이선스: LGPL-3.0-or-later * 저작권: Nicola Asuni, Tecnick.com LTD * 출처: https://github.com/tecnickcom/TCPDF * 라이선스 파일: vendor/tecnickcom/tcpdf/LICENSE.TXT * 용도: PDF 보고서/내보내기 생성

SimpleXLSXGen 1.5.x * 라이선스: MIT * 저작권: (c) 2020-2022 Sergey Shuchkin * 출처: https://github.com/shuchkin/simplexlsxgen * 라이선스 파일: vendor/shuchkin/simplexlsxgen/LICENSE * 용도: XLSX(Excel) 내보내기

JavaScript / CSS 라이브러리 (`assets/*/vendor/`)

Select2 4.1.0-rc.0 * 라이선스: MIT * 저작권: Kevin Brown, Igor Vaynberg, and the Select2 contributors * 출처: https://github.com/select2/select2 * 라이선스 전문: https://github.com/select2/select2/blob/master/LICENSE.md * 포함 파일: assets/js/vendor/select2.min.js, assets/css/vendor/select2.min.css

ApexCharts 5.16.0 * 라이선스: MIT * 저작권: (c) 2018-2026 ApexCharts * 출처: https://github.com/apexcharts/apexcharts.js * 라이선스 전문: https://github.com/apexcharts/apexcharts.js/blob/main/LICENSE * 포함 파일: assets/js/vendor/apexcharts.min.js

jsVectorMap 1.7.0 * 라이선스: MIT * 저작권: (c) Mustafa Omar and the jsVectorMap contributors * 출처: https://github.com/themustafaomar/jsvectormap * 라이선스 전문: https://github.com/themustafaomar/jsvectormap/blob/master/LICENSE * 포함 파일: assets/js/vendor/jsvectormap.min.js, assets/css/vendor/jsvectormap.min.css * 용도: 세계 지도 시각화 (실시간 트래픽 / 차단 / 방화벽)

세계 지도 데이터(world_mill), jsVectorMap의 “world” 지도로 등록됨 * 라이선스: MIT * 저작권: jvectormap-content 기여자, 지도 지오메트리는 Natural Earth(public domain)에서 파생됨 * 출처: https://www.npmjs.com/package/jvectormap-content * 포함 파일: assets/js/vendor/world.js * 용도: 위 세계 지도 시각화에서 렌더링되는 국가 지오메트리

qrcode-generator 1.4.4 * 라이선스: MIT * 저작권: Kazuhiko Arase * 출처: https://github.com/kazuhikoarase/qrcode-generator * 라이선스 전문: https://github.com/kazuhikoarase/qrcode-generator/blob/master/LICENSE * 포함 파일: assets/js/vendor/qrcode.min.js

아이콘 / 자산

flag-icons (국가 국기 SVG) * 라이선스: MIT (SVG 마크업), 국기 디자인 자체는 public domain에 속함 * 저작권: (c) 2013 Panayiotis Lipiridis * 출처: https://github.com/lipis/flag-icons * 라이선스 전문: https://github.com/lipis/flag-icons/blob/main/LICENSE * 포함 파일: assets/images/flags/*.svg (국가 국기, 4×3 viewBox="0 0 640 480")

무료유료 요금제에서
설치하면 WordPress.com 서비스 약관서드파티 플러그인 약관에 동의하게 됩니다.
테스트된 버전
WordPress 7.0.2
이 플러그인은 다운로드할 수 있으며 에서 사용할 수 있습니다.