{"id":373545,"date":"2026-09-26T15:08:12","date_gmt":"2026-09-26T15:08:12","guid":{"rendered":"https:\/\/ja.wordpress.org\/plugins\/security-by-wp-center\/"},"modified":"2026-09-26T15:49:56","modified_gmt":"2026-09-26T15:49:56","slug":"centershield","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/centershield\/","author":23565071,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"CenterShield \u2013 Site Security: Login Protection, 2FA, File Protection & Malware Scan","header_author":"WP\u30bb\u30f3\u30bf\u30fc","header_description":"WP\u30bb\u30f3\u30bf\u30fc\u304c\u63d0\u4f9b\u3059\u308b\u56fd\u7523\u306eWordPress\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u30d7\u30e9\u30b0\u30a4\u30f3\u3002\u30ed\u30b0\u30a4\u30f3\u9632\u5fa1\u30fb\u4e0d\u8981\u6a5f\u80fd\u306e\u7121\u52b9\u5316\u30fb\u30d5\u30a1\u30a4\u30eb\u4fdd\u8b77\u30fb\u30de\u30eb\u30a6\u30a7\u30a2\u30b9\u30ad\u30e3\u30f3\u3092\u3001\u5c02\u9580\u77e5\u8b58\u304c\u306a\u304f\u3066\u3082\u4f7f\u3048\u308bUI\u3067\u4f53\u7cfb\u7684\u306b\u5b9f\u65bd\u3057\u307e\u3059\u3002","assets_banners_color":"0a6ca4","last_updated":"2026-09-26 15:49:56","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/wpcenter.jp\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":48,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"wpcenterjp","date":"2026-09-26 15:49:56","revision":3714422}},"upgrade_notice":{"1.0.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3714371,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3714371,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3714371,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3714371,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3714371,"resolution":"1","location":"assets","locale":"","width":1280,"height":1378},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3714371,"resolution":"2","location":"assets","locale":"","width":1280,"height":1390},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3714371,"resolution":"3","location":"assets","locale":"","width":1280,"height":798},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3714371,"resolution":"4","location":"assets","locale":"","width":1280,"height":1115}},"screenshots":{"1":"Dashboard with the recommended settings status, the apply button and the site environment check","2":"Account and login protection settings","3":"File and server protection written to .htaccess","4":"Malware scan results with severity ratings"}},"plugin_section":[262246],"plugin_tags":[9211,1174,602,1184,600],"plugin_category":[38,54],"plugin_contributors":[282834],"plugin_business_model":[],"class_list":["post-373545","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-2fa","plugin_tags-firewall","plugin_tags-login","plugin_tags-malware","plugin_tags-security","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-wpcenterjp","plugin_committers-wpcenterjp"],"banners":{"banner":"https:\/\/ps.w.org\/centershield\/assets\/banner-772x250.png?rev=3714371","banner_2x":"https:\/\/ps.w.org\/centershield\/assets\/banner-1544x500.png?rev=3714371","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/centershield\/assets\/icon-128x128.png?rev=3714371","icon_2x":"https:\/\/ps.w.org\/centershield\/assets\/icon-256x256.png?rev=3714371","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/centershield\/assets\/screenshot-1.png?rev=3714371","caption":"Dashboard with the recommended settings status, the apply button and the site environment check"},{"src":"https:\/\/ps.w.org\/centershield\/assets\/screenshot-2.png?rev=3714371","caption":"Account and login protection settings"},{"src":"https:\/\/ps.w.org\/centershield\/assets\/screenshot-3.png?rev=3714371","caption":"File and server protection written to .htaccess"},{"src":"https:\/\/ps.w.org\/centershield\/assets\/screenshot-4.png?rev=3714371","caption":"Malware scan results with severity ratings"}],"raw_content":"<!--section=description-->\n<p>CenterShield is a WordPress security plugin built for Japanese site owners and the\nagencies that maintain their sites.<\/p>\n\n<p>It brings login protection, two-factor authentication, hardening, file protection and\nmalware scanning together in one place. Every setting explains what it protects and\nwhat changes when you turn it on, so you can choose the measures your site needs\nwithout security expertise.<\/p>\n\n<p><strong>The admin interface and all messages are in Japanese only.<\/strong><\/p>\n\n<p>Activating the plugin changes nothing on your site. Press \"apply recommended settings\"\nto enable the recommended set in one step, or turn on each feature yourself.<\/p>\n\n<h4>Account and login protection<\/h4>\n\n<ul>\n<li>Login attempt limiting (brute force protection)<\/li>\n<li>Username disclosure prevention<\/li>\n<li>Custom login URL<\/li>\n<li>HTTP Basic authentication on the login screen (written to .htaccess on Apache)<\/li>\n<li>reCAPTCHA v2 \/ v3<\/li>\n<li>Two-factor authentication (authenticator app, email, backup codes)<\/li>\n<li>XML-RPC disabling (signed Jetpack requests are still allowed)<\/li>\n<li>IP address restriction for the admin area<\/li>\n<\/ul>\n\n<h4>Disabling unused features and weak settings<\/h4>\n\n<ul>\n<li>Pingback<\/li>\n<li>REST API restriction (well known plugins such as Contact Form 7, Jetpack and WooCommerce stay allowed)<\/li>\n<li>Author archive pages<\/li>\n<li>Theme and plugin file editor, application passwords<\/li>\n<li>Unneeded tags in wp_head, such as the WordPress version, the RSD link and emoji scripts<\/li>\n<\/ul>\n\n<h4>File and server protection<\/h4>\n\n<ul>\n<li>Blocking direct access to wp-includes, wp-config.php, configuration and backup files<\/li>\n<li>Blocking PHP execution in the uploads folder<\/li>\n<li>Disabling directory listing<\/li>\n<li>Security headers such as X-Frame-Options<\/li>\n<li>Removing publicly readable files such as readme.html<\/li>\n<li>Permission review and correction<\/li>\n<\/ul>\n\n<h4>Ongoing protection<\/h4>\n\n<ul>\n<li>Input filtering (lightweight WAF)<\/li>\n<li>Comment spam blocking (honeypot, rate limit, previous spam history)<\/li>\n<li>Detection of plugins and themes that have gone two years without an update or are not tested with your version of WordPress<\/li>\n<\/ul>\n\n<h4>Malware scanning<\/h4>\n\n<ul>\n<li>Comparison against official checksums for WordPress core and plugins hosted on WordPress.org. Differences limited to comments or line endings are reported as informational<\/li>\n<li>Matching against a known vulnerability database<\/li>\n<li>Pattern matching against malware signatures bundled with the plugin and updated from the author's server<\/li>\n<li>Change detection against the previous scan, for themes and plugins that are not on WordPress.org<\/li>\n<li>Database inspection of posts, widgets and administrator accounts<\/li>\n<li>Quarantine, restore from the official original, and difference display<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to the following external services. No site content, post data\nor user data is transmitted to any of them, and every request identifies itself with a\nfixed user agent rather than the WordPress default, which would carry your site address.<\/p>\n\n<h4>api.wpcenter.jp (WP Center, the plugin author)<\/h4>\n\n<p>Used to download malware signature definitions and known vulnerability data. The\nrequest is sent when the plugin checks for definition updates and when a scan needs\nvulnerability data. What is sent: the plugin version, and the metadata that any web\nrequest carries, namely your server IP address and a fixed user agent string\n(\"WPCenterSecurity\/\" followed by the plugin version) that does not contain your site address. What is\nreceived: signature definitions, their digital signature, and vulnerability records.\nYour site address and the list of plugins and themes installed on your site are never\nsent; matching is performed locally on your site.<\/p>\n\n<p>Terms of service: https:\/\/wpcenter.jp\/plugin-terms\/\nPrivacy policy: https:\/\/wpcenter.jp\/privacy\/<\/p>\n\n<p>The vulnerability records served from this endpoint originate from Wordfence\nIntelligence, provided by Defiant, Inc., and include CVE records from the MITRE\nCorporation. Copyright designations for both are shown with every record in the\nscan results, and the Wordfence Intelligence terms are reproduced in\nlicenses\/wordfence-intelligence-terms.txt inside this plugin. WP Center is not\naffiliated with, endorsed by or sponsored by Wordfence or Defiant, Inc.<\/p>\n\n<p>Wordfence Intelligence: https:\/\/www.wordfence.com\/threat-intel\/\nWordfence Intelligence terms: https:\/\/www.wordfence.com\/wordfence-intelligence-terms-and-conditions\/\nWordfence privacy policy: https:\/\/www.wordfence.com\/privacy-policy\/\nCVE terms of use: https:\/\/www.cve.org\/Legal\/TermsOfUse<\/p>\n\n<h4>api.wordpress.org and downloads.wordpress.org<\/h4>\n\n<p>Used to obtain official checksums during a scan. What is sent: the WordPress version\nand locale, and the slug and version of each plugin being verified. What is received:\nfile checksums.<\/p>\n\n<p>WordPress.org privacy policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h4>core.svn.wordpress.org and plugins.svn.wordpress.org<\/h4>\n\n<p>Used only when you press \"compare with the original\" or \"restore the original\" on a\nscan result. What is sent: the version and file path of the file being retrieved.\nWhat is received: that single original file, from the official WordPress.org\nrepository.<\/p>\n\n<p>WordPress.org privacy policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h4>www.google.com (reCAPTCHA)<\/h4>\n\n<p>Used only if you enable reCAPTCHA and enter your own keys. The reCAPTCHA script is\nthen loaded on the forms you select, and the token is verified against Google. What\nis sent: the reCAPTCHA token, your secret key and the visitor IP address.<\/p>\n\n<p>Google terms: https:\/\/policies.google.com\/terms\nGoogle privacy policy: https:\/\/policies.google.com\/privacy<\/p>\n\n<h3>Third-party resources<\/h3>\n\n<ul>\n<li>Vulnerability data: Wordfence Intelligence Vulnerability Database (https:\/\/www.wordfence.com\/threat-intel\/). Copyright Defiant, Inc. CVE records copyright The MITRE Corporation. Redistributed under the Wordfence Intelligence Terms and Conditions, a copy of which is included in licenses\/wordfence-intelligence-terms.txt. Each record displays its copyright designation in the scan results.<\/li>\n<li>Original file comparison: the public WordPress.org checksum API and SVN repositories.<\/li>\n<li>Part of the malware definitions: Linux Malware Detect (LMD) signatures, Copyright R-fx Networks, GNU GPL v2, https:\/\/github.com\/rfxn\/linux-malware-detect, incorporated under the terms of the GPL. Known malicious domains: URLhaus (abuse.ch, CC0, https:\/\/urlhaus.abuse.ch\/).<\/li>\n<li>QR code generation: qrcode-generator v1.4.4, Copyright (c) 2009 Kazuhiko Arase, MIT License (assets\/js\/qrcode.min.js).<\/li>\n<\/ul>\n\n<h3>\u65e5\u672c\u8a9e<\/h3>\n\n<p>WP\u30bb\u30f3\u30bf\u30fc\u304c\u63d0\u4f9b\u3059\u308b\u56fd\u7523\u30fb\u65e5\u672c\u8a9e\u5bfe\u5fdc\u306e WordPress \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u30d7\u30e9\u30b0\u30a4\u30f3\u3067\u3059\u3002\n\u7ba1\u7406\u753b\u9762\u3068\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u3059\u3079\u3066\u65e5\u672c\u8a9e\u3067\u3059\u3002<\/p>\n\n<p>\u30ed\u30b0\u30a4\u30f3\u4fdd\u8b77\u30012\u6bb5\u968e\u8a8d\u8a3c\u3001\u8a2d\u5b9a\u306e\u5f37\u5316\u3001\u30d5\u30a1\u30a4\u30eb\u4fdd\u8b77\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u30b9\u30ad\u30e3\u30f3\u3092\u307e\u3068\u3081\u3066\u7ba1\u7406\u3067\u304d\u3001\u3072\u3068\u3064\u305a\u3064\u300c\u4f55\u306e\u305f\u3081\u306e\u8a2d\u5b9a\u304b\u300d\u300c\u3069\u3093\u306a\u52b9\u679c\u304c\u3042\u308b\u304b\u300d\u3092\u78ba\u8a8d\u3057\u306a\u304c\u3089\u6709\u52b9\u5316\u3067\u304d\u307e\u3059\u3002\n\u6709\u52b9\u5316\u3057\u305f\u6642\u70b9\u3067\u306f\u4f55\u3082\u5909\u66f4\u3055\u308c\u305a\u3001\u300c\u63a8\u5968\u8a2d\u5b9a\u3092\u307e\u3068\u3081\u3066\u9069\u7528\u300d\u3092\u62bc\u3059\u304b\u3001\u9805\u76ee\u3054\u3068\u306b\u9078\u3093\u3067\u6709\u52b9\u306b\u3057\u307e\u3059\u3002<\/p>\n\n<p>\u30de\u30eb\u30a6\u30a7\u30a2\u30b9\u30ad\u30e3\u30f3\u3067\u306f\u3001WordPress \u672c\u4f53\u3068\u516c\u5f0f\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u539f\u672c\u3068\u7167\u5408\u3057\u3001\u65e2\u77e5\u306e\u8106\u5f31\u6027\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u3068\u7a81\u304d\u5408\u308f\u305b\u3001\u4e0d\u6b63\u30b3\u30fc\u30c9\u306e\u30d1\u30bf\u30fc\u30f3\u3092\u691c\u67fb\u3057\u307e\u3059\u3002\n\u691c\u51fa\u7d50\u679c\u304b\u3089\u306f\u9694\u96e2\u3001\u539f\u672c\u306e\u5fa9\u5143\u3001\u5dee\u5206\u8868\u793a\u304c\u884c\u3048\u307e\u3059\u3002<\/p>\n\n<p>\u8106\u5f31\u6027\u60c5\u5831\u306f Wordfence Intelligence\uff08Defiant, Inc. \u63d0\u4f9b\uff09\u306b\u7531\u6765\u3057\u3001CVE \u60c5\u5831\u306f MITRE Corporation \u306b\u3088\u308b\u3082\u306e\u3067\u3059\u3002\u5404\u30ec\u30b3\u30fc\u30c9\u306b\u8457\u4f5c\u6a29\u8868\u793a\u3092\u8868\u793a\u3057\u3066\u3044\u307e\u3059\u3002\n\u5f53\u30d7\u30e9\u30b0\u30a4\u30f3\u306f Wordfence \u304a\u3088\u3073 Defiant, Inc. \u3068\u306f\u7121\u95a2\u4fc2\u3067\u3059\u3002<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin and activate it. Nothing is changed on your site at this point.<\/li>\n<li>Open the \"CenterShield\" menu and press \"apply recommended settings\" on the dashboard, or enable individual settings yourself.<\/li>\n<li>Run a malware scan.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"i%20forgot%20my%20custom%20login%20url\"><h3>I forgot my custom login URL<\/h3><\/dt>\n<dd><p>Rename this plugin's folder under wp-content\/plugins\/ using FTP or your hosting file\nmanager. The plugin stops loading and \/wp-login.php works again. Your settings are\npreserved. The exact folder name is shown on the Settings tab of the plugin.<\/p><\/dd>\n<dt id=\"i%20am%20locked%20out%20of%20the%20admin%20area\"><h3>I am locked out of the admin area<\/h3><\/dt>\n<dd><p>Add <code>define( 'WPCS_DISABLE', true );<\/code> to wp-config.php. Every feature of the plugin\npauses while that line is present.<\/p><\/dd>\n<dt id=\"i%20forgot%20the%20http%20basic%20authentication%20password\"><h3>I forgot the HTTP Basic authentication password<\/h3><\/dt>\n<dd><p>Basic authentication is applied by .htaccess, so renaming the plugin folder does not\nremove it. Open the .htaccess file in your site root and delete the block that starts\nwith the Basic authentication comment inside the \"CenterShield\" markers. Full\ninstructions are on the Settings tab of the plugin.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20change%20my%20site%20when%20i%20activate%20it%3F\"><h3>Does the plugin change my site when I activate it?<\/h3><\/dt>\n<dd><p>No. Every setting is off after activation. Nothing is written to .htaccess and no\nscan is scheduled until you choose to enable it.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<\/ul>","raw_excerpt":"WordPress security for Japanese sites: login protection, 2FA, file protection and malware scanning, each explained in clear Japanese.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/373545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=373545"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wpcenterjp"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=373545"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=373545"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=373545"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=373545"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=373545"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=373545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}