=== XO Security === Contributors: ishitaka Tags: security, login, pingback, xmlrpc, captcha, rest, nginx Requires at least: 4.6 Tested up to: 4.9 Stable tag: 1.9.0 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html XO Security is a plugin to enhance login related security. == Description == XO Security is a plugin to enhance login related security. This plugin does not write to .htaccess files. Nginx also works. = Functions = * Record login log. * Limit login attempts. * Login Alert. * Login CAPTCHA. * Comment form CAPTCHA. * Change login page URL (WordPress multisite subdomain type is not supported). * Block access to wp-admin. * Disable XML-RPC. * Disable XML-RPC Pingback. * Disable REST API. * Change REST API URL prefix. * Disable author archive page. * Remove comment author class of comments list. * WordPress multisite support. The CAPTCHA feature requires mbstring and a GD library. == Installation == 1. Upload the `XO-Security` folder to the `/wp-content/plugins/` directory. 2. Activate the plugin through the Plugins menu in WordPress. 3. Go to "Settings" -> "XO Security" and customize behaviour as needed. == Screenshots == 1. Login log page. 2. Setting status page. 3. Login setting page. == Frequently Asked Questions == = Login page is not displayed. = Please initialize the settings. * In wp_options table, the value of the option_name field (column) is to remove the record of "xo_security_options". * If you have set the login page, please delete the file. = The CAPTCHA is not displayed. = Please install mbstring and GD library. == Changelog == = 1.9.0 = * Added CAPTCHA to the comment form. = 1.8.2 = * Fixed a bug that CAPTCHA characters could be garbled on some servers. = 1.8.1 = * Fixed minor bugs. * Deleted unused files. = 1.8.0 = * Added WooCommerce to exclusion item of the REST API invalid. * Added CAPTCHA to the login page. = 1.7.0 = * Added a setting to exclude disabling the REST API. * Not supported for WordPress 4.5 and earlier. = 1.6.2 = * Fixed sort bug in login log. * Improve setting page. = 1.6.1 = * Fixed bug that login log was not displayed on multisite. * Tested on WordPress 4.8. = 1.6.0 = * Change the IP address acquired the HTTP_X_FORWARDED_FOR via a proxy server. * Added login limit with language settings. = 1.5.3 = * Fixed XSS vulnerability - Thanks to pluginvulnerabilities.com = 1.5.2 = * Improve setting page. * Tested on PHP 7. = 1.5.1 = * Supported disable the REST API to WordPress 4.7. * Tested on WordPress 4.7. = 1.5.0 = * Added support for WordPress multisite. * Tested on WordPress 4.6. = 1.4.0 = * Added dashboard widget. = 1.3.0 = * Added option in login alert administrators only. * Tested on WordPress 4.5. = 1.2.0 = * Added Login Alert. = 1.1.0 = * Added option to disable the REST API. * Added option to change the REST API URL prefix. * Change UserAgent white list & UserAgent black list option from the settings page to define(). = 1.0.0 = * Initial release.