WordPress.org

Hong Kong 香港中文

  • 佈景主題
  • 外掛
  • News
  • Support
  • About
  • 重要通知
  • WordPress 常見問題
  • 團隊
  • 取得 WordPress
取得 WordPress
WordPress.org

Plugin Directory

WP jCryption Security

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

這個外掛並未在最新的 3 個 WordPress 主要版本上進行測試。開發者可能不再對這個外掛進行維護或提供技術支援,並可能會與更新版本的 WordPress 產生使用上的相容性問題。

WP jCryption Security

由andreyk
下載
  • 詳情
  • 評價
  • 安裝
  • 開發
支援

描述

The plugin increases security of a site in case it has no SSL certificate,
useful for owners of small sites who want to secure their passwords and
other posted data but don’t want to buy SSL certificate for each domain
and subdomain: it protects from sniffering the most important data such as
passwords when they are being sent from forms of your site to the server.

When the form served by the plugin is submitted all input data are being
joined into a string, then this string is being encrypted with AES algorythm
by disposable key and only encrypred string will be sent.

A browser encrypts the disposable key in javascript by the RSA public key
and sends it to the server; then the server decrypts it with the RSA private
key and then use it to decrypt the posted data with AES.

Translations included: Ukrainian, Russian, German and Brazilian Portuguese.

I just adapted usage in WordPress the jCryption jQuery plugin, v. 3.1.0.
Please check www.jcryption.org to learn how jCryption works.

螢幕截圖

  • HTTP headers without encryption.
  • Log-in process encrypted by WP jCryption.

安裝

Upload wp-jcryption.zip using the wordpress plugin installation interface
and activate the plugin. On the very first activation 1024-bit RSA key pair
will be generated and the list of forms the plugin is primarily destinated
for will be saved. You may add other form IDs to this list on the plugin
settings page: Settings – WP jCryption.

常見問題

Installation Instructions

Upload wp-jcryption.zip using the wordpress plugin installation interface
and activate the plugin. On the very first activation 1024-bit RSA key pair
will be generated and the list of forms the plugin is primarily destinated
for will be saved. You may add other form IDs to this list on the plugin
settings page: Settings – WP jCryption.

Why should I use this plugin?

If you don’t use https on your site your password could be stolen through
man-in-the-middle attack when you are submitting log-in form because form data
(including password) are being sent as plain text. This plugin encrypts submitted
data in a way similar to https transmission.

Does this plugin encrypts transmission of my site pages entirely?

No. The plugin encrypts only data being posted from most important forms
(that contain password fields: login, reset password, user profile)
and forms you specify additionally. To secure all incoming and
outgoing traffic of your site a SSL certificate is needed.

I have SSL certificate installed on my site already. Do I need to install the plugin?

No.

Can I check whether the form data are being sent encrypted?

Yes, you can do it by means of Firefox LiveHTTPHeaders extension, Fiddler or similar tools.

What are system requirements for the plugin?

PHP version >= 5.3 with OpenSSL PHP extension.

Do I need to generate RSA private and public key files with Linux commands?

No. PHP generates keys for you and save them in a database. So, this plugin is usable on (almost) any shared hosting.

The plugin works with login form but disables other form during it’s being submitted.

Try to enable the plugin option: Fix button id=”submit” and name=”submit”.

評價

Don't have SSL? Then this is indispensable!

Gahapati 2016年9月3日
For a number of years I found this plugin to be quite indispensable, since until recently I did not have access to SSL-encryption. If ever I were to set up WordPress on a server that lacked SSL again, WP jCryption Security would be the first plugin to install!

Great

sotnas 2016年9月3日
A small necessary tool!
閱讀全部3個評價

貢獻者及開發者

“WP jCryption Security” 是一個開源的軟體。以下的人對這個外掛作出了貢獻。

貢獻者
  • andreyk

將 WP jCryption Security 外掛本地化為台灣繁體中文版。

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄。

修改日誌

0.5.1

  • Minified javascript.

0.5

  • Minified javascript.
  • Changed endpoint URL to avoid it got cached by caching plugins.
  • Unset session jCryptionKey after decryption.

0.4.1

  • German and Brazilian Portuguese translations by Matthias.

0.4

  • removed unnecessary printing $_POST in the end of wp_jcryption_entry function
    (it was there for testing purpose but could be a target for XSS, thanks to Konstantin Kovshenin for this notice).

0.3

  • ‘fix_submit’ plugin setting is checked on install to let the plugin work with the user profile form;
  • testing of system requirements enhanced.

0.2

  • jCryption entry point moved into the ‘plugins_loaded’ action.

0.1

  • initial version, with separate entry point file using SHORTINIT.

其它

  • Version 0.5.1
  • Last updated 10 年之前
  • Active installations 40+
  • WordPress version 3.8.1 or higher
  • Tested up to 4.8.25
  • Language
    English (US)
  • Tags
    encryptionformsloginpasswordsecurity
  • 進階顯示

評分

4.7 out of 5 stars.
  • 2 5-star reviews 5 stars 2
  • 1 4-star review 4 stars 1
  • 0 3-star reviews 3 stars 0
  • 0 2-star reviews 2 stars 0
  • 0 1-star reviews 1 star 0

Add my review

See all reviews

貢獻者

  • andreyk

支援

有話想說?需要協助?

檢視支援論壇

  • 關於我們
  • 最新消息
  • 寄存
  • 隱私權
  • 展示網站
  • 佈景主題
  • 外掛
  • 區塊版面配置
  • Learn
  • 技術支援
  • 開發者資源
  • WordPress.tv ↗
  • 共同參與
  • Events
  • Donate ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

Hong Kong 香港中文

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • 訪問我們的 Facebook 專頁
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
代碼就是詩歌。