Descripción
WP Cerber Security – Firewall, Anti-spam & Malware Scan permite la configuración de firewall, filtro antispam y escáner de malware para administradores de sitios WordPress, bloqueando intentos de invasión y comentarios no deseados en tiempo real. Con él, monitoreas archivos sospechosos, restringes accesos por IP y activas reCAPTCHA en los formularios de inicio de sesión, registro y comentarios, fortaleciendo la protección sin sobrecargar el servidor.
Principales Características de WP Cerber Security – Firewall, Anti-spam & Malware Scan
- Firewall inteligente
Bloquea solicitudes maliciosas antes de que alcancen WordPress, filtrando por IP, user-agent y patrones de ataque. - Anti-spam avanzado
Filtra comentarios y registros basándose en reglas personalizables, eliminando spam sin depender de servicios externos. - Escáner de malware
Revisa archivos del core, temas y plugins en busca de código malicioso, generando alertas y acciones correctivas. - Protección contra brute force
Limita intentos de inicio de sesión, bloquea IPs tras fallos repetidos y muestra reCAPTCHA para autenticación adicional. - Monitoreo de actividades
Registra inicios de sesión, cambios en archivos y intentos de invasión, mostrando un panel centralizado de auditoría.
Beneficios de WP Cerber Security – Firewall, Anti-spam & Malware Scan
- Reducción de ataques
Impide accesos no autorizados y explotación de vulnerabilidades comunes en sitios WordPress. - Ahorro de recursos
Reemplaza múltiples plugins de seguridad por una solución unificada, ligera y optimizada. - Monitoreo continuo
Recibe notificaciones por correo electrónico sobre actividades sospechosas, manteniendo el control incluso fuera del panel. - Facilidad de configuración
Activa protecciones esenciales con pocos clics, sin requerir conocimientos técnicos avanzados.
¿Para Quién es Indicado WP Cerber Security – Firewall, Anti-spam & Malware Scan?
- Administradores de sitios WordPress que buscan seguridad completa sin complejidad.
- Desarrolladores que necesitan un firewall y escáner integrados para múltiples proyectos.
- Agencias de hosting y proveedores que desean proteger instancias de clientes contra malware e invasiones.
Cómo Descargar WP Cerber Security – Firewall, Anti-spam & Malware Scan
WP Cerber Security – Firewall, Anti-spam & Malware Scan está disponible para descarga aquí en Ultrapack. Después de descargar el archivo .zip, accede a Plugins > Añadir Nuevo > Subir plugin, selecciona el archivo y activa. El panel de seguridad aparecerá en el menú de WordPress, listo para configuración inmediata.
Combinando firewall perimetral, escáner de archivos y protección contra spam y brute force, WP Cerber Security ofrece una capa de defensa robusta para cualquier sitio WordPress, desde blogs personales hasta tiendas virtuales y portales corporativos. Su interfaz sencilla permite gestionar todas las amenazas en un solo lugar, reduciendo la superficie de ataque sin comprometer el rendimiento.
Preguntas frecuentes
¿El plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan es GPL?
Sí. WP Cerber Security – Firewall, Anti-spam & Malware Scan se distribuye bajo la licencia GPL (GNU General Public License). Puedes usarlo, modificarlo y redistribuirlo legalmente en todos los sitios que quieras.
¿Puedo usar el plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan en más de un sitio?
Sí. Puedes instalar WP Cerber Security – Firewall, Anti-spam & Malware Scan en todos los sitios que quieras. Solo las actualizaciones automáticas con Ultrapack Auto Updater tienen límite: de 3 a 80 sitios, según el plan.
¿Cuánto cuesta el plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan en Ultrapack?
WP Cerber Security – Firewall, Anti-spam & Malware Scan cuesta US$ 2,99 en la compra individual, y también está incluido en los planes de suscripción desde US$12/mes (VIP I).
¿El plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan incluye actualizaciones?
Sí. La versión actual de WP Cerber Security – Firewall, Anti-spam & Malware Scan es la 9.9.5, publicada en Ultrapack el 26/08/2026. Los suscriptores actualizan directamente desde el panel de WordPress con UAU (Ultrapack Auto Updater).
¿Es seguro descargar e instalar el plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan en mi WordPress?
Sí. Cada versión de WP Cerber Security – Firewall, Anti-spam & Malware Scan pasa por un análisis de malware (ClamAV y reglas YARA, en UltraHub) antes de publicarse.
¿Cuáles son los requisitos del plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan?
Requiere WordPress 5.8 o superior y PHP 7.4 o superior. Probado hasta WordPress 7.1.
Qué cambió en esta versión
Versión 9.9.5
- Improved: A setting link in admin UI now opens the matching role tab in the role-based settings and highlights the target setting, so you can jump from an Activity log event straight to the setting that affected WP Cerber's decision.
- Improved: Following a setting link from a popup explainer now centers the target WP Cerber setting in the browser window instead of aligning it with the top of the page, where the WordPress admin bar could cover it.
- Changed: URL escaping in the admin interface now accepts root-relative URLs that begin with a single slash, in addition to the already supported HTTP(S), FTP(S), and mailto URLs.
- Changed: Admin announcements are now stored as structured JSON instead of pre-rendered HTML markup. A stored announcement that does not match the supported format is rejected instead of being displayed incorrectly.
- Fixed: On the Activity log page, when several explainers described events for the same user and WP Cerber's decision was role-based, only the first setting link scrolled to and highlighted the target setting. The remaining links opened the settings page without scrolling to the target setting.
- Fixed: The "Mail Transport" settings section displayed the raw HTML markup for the "Available in the professional version of WP Cerber" link instead of a working link.
- Fixed: Non-ASCII characters in a URL path are no longer removed when WP Cerber escapes a URL, so URLs with non-ASCII path characters now point to the intended address.
- Fixed: A URL containing invalid UTF-8 no longer becomes an empty link address when WP Cerber escapes it.
- Changed: Quotes, angle brackets, and backticks are no longer deleted from URLs in admin pages. HTML escaping of the attribute value now handles these characters safely.
Versión 9.9.3
- Fixed: When error logging was active, an uncaught PHP failure such as an unhandled exception, a type error, or a parse error could stop the standard PHP fatal error processing. WordPress can again show its critical error page, send the Recovery Mode email, and revert a broken PHP edit made in the built-in plugin or theme editor.
- Fixed: Uncaught PHP exceptions and other fatal failures could be missing from the WordPress `debug.log` file when `WP_DEBUG_LOG` was enabled.
- Fixed: Not all PHP errors were logged for a request. A fatal error that terminated the request could be replaced by a later diagnostic produced by WP Cerber's own shutdown routines, so the terminating error was missing from the request details in Traffic Inspector and from `cerber-errors.log`.
- Fixed: On a non-English website, the issue message reporting a failed email delivery could be shown in the language of the request that failed to send the email, which is usually an unattended request such as a scheduled report or a visitor-triggered alert. The message is now translated into the language of the administrator who reads it.
- Fixed: On a non-English website, the message reporting corrupted plugin settings and their recovery was shown untranslated. It is now translated at the moment it is displayed to the administrator.
- Fixed: Some messages in the "System Readiness" widget were missing localization support and could not be translated.
- Fixed: Rendering the quick navigation block in the admin area could produce `Array to string conversion` warnings when a query parameter carried more than one value. Depending on the PHP error configuration, these warnings could pollute the server logs, appear in the admin output, or corrupt an AJAX response.
- Fixed: Some valid IPv6 ranges written in dash or wildcard notation were rejected when adding an entry to the IP Access Lists or filtering records in the Activity log and the Traffic log. Reversed and zero-length ranges are still rejected.
- Fixed: IPv6 range matching now uses inclusive boundaries, so the first and the last address of a range are treated as part of that range.
Versión 9.9
- New: WP Cerber now automatically maintains a backup copy of the last known valid plugin settings. The backup is refreshed after successful settings updates, settings imports, plugin upgrades, and during daily maintenance.
- New: If the stored plugin settings become corrupted, WP Cerber now restores them automatically from the settings backup and shows a dismissible admin notice explaining what happened, what action was taken, and what the administrator should review.
- New: The "System Readiness" widget now shows an advisory notice on servers where PHP is built without the modern `mysqlnd` database driver. The notice confirms that WP Cerber keeps working and recommends enabling `mysqlnd` for full compatibility and better performance.
- Improved: Traffic Inspector now detects additional high-confidence JavaScript obfuscation patterns, including fully escaped strings that use `\uNNNN` and `\u{...}` escape sequences and dangerous execution, DOM, network, and system code decoded from explicit `fromCharCode` calls, while preserving its low false-positive detection model.
- Compatibility: WP Cerber now runs correctly on legacy hosting environments where PHP is built without the modern `mysqlnd` database driver. On such servers, database query results are retrieved through a slower compatible method instead of triggering a fatal error.
- Fixed: A corrupted WP Cerber configuration value stored in the database could cause a fatal `TypeError` in `array_merge` at plugin load time on PHP 8, taking the whole website down. WP Cerber now detects the unreadable stored value, falls back to the default settings, and reports the failure as a critical issue until the administrator re-saves the settings.
- Fixed: A regression in the detection of obfuscated JavaScript by Traffic Inspector. JavaScript strings built entirely of `\xNN` hex escape sequences were not decoded, so obfuscated code such as `eval`, `script`, and `XMLHttpRequest` could go undetected when request fields were inspected.
Versión 9.8.3
- New: The Activity log and Traffic log CSV exports now report the date range they cover, adding the oldest and newest record timestamps to the export header.
- Improved: Activity log and Traffic log CSV exports now stream matching rows in a single unbuffered pass, keeping memory usage flat and avoiding deep-offset scanning, which makes exporting large logs faster and more reliable.
- Improved: Activity log and Traffic log exports now send the `X-Accel-Buffering: no` response header so an Nginx proxy in front of PHP-FPM forwards each chunk immediately instead of buffering the whole export, improving time-to-first-byte on large exports.
- Improved: Decoding of stored Traffic Inspector request field data is now more robust, consistently treating nullable legacy values, empty values, invalid JSON, and unsupported serialized payloads as an empty array.
- Fixed: Corrected memory limit handling during Activity log and Traffic log exports, where a numeric limit such as `512` could be applied as bytes instead of megabytes, preventing WP Cerber from raising the available memory and causing exports to stop earlier than expected.
- Fixed: In the Traffic Inspector Log "Advanced Search", combining the "Any software error" option with other filters could return requests with recorded PHP errors that did not match the other criteria; results now match all selected filters.
- Fixed: Dashboard links in Activity alert notification emails could carry mismatched query parameters, for example the IP filter receiving an IP-range boundary value, which opened an unrelated filtered view; the links now use the correct values.
- Fixed: Activity alerts that match on a search string now resolve the user of the logged event instead of falling back to the current administrator, so user-based alert matching behaves correctly.
- Fixed: Prevented an undefined array key notice in `CRB_Activity::is_modified_since` when the `data_modified` status value was missing, and corrected an operator-precedence error so a missing modification timestamp is correctly treated as modified.
- Security: Sanitized user-controlled profile display names (first name, last name, and display name) before they are concatenated into `Name ` mail recipient strings, closing an email header injection vector that could add an extra recipient to the two-factor authentication PIN email and to Activity alert notification emails.
- Security: Plugin ownership-change messages on the scanner page are now rendered through WP Cerber's UI layer with contextual output escaping instead of raw HTML, removing a potential stored admin XSS vector from externally supplied plugin ownership metadata provided by the WordPress.org plugin repository.
- Security: Activity log and Traffic log CSV exports now send the `Cache-Control: no-store` response header to prevent a sensitive security-log export from being cached by the browser or an intermediate proxy.
Versión 9.8
- Changed: Renamed the "White IP Access List" and "Black IP Access List" terms to "Allowed IP Access List" and "Blocked IP Access List" across the admin UI for clearer access-control terminology.
- Changed: Client IP address detection now converts IPv4-mapped IPv6 addresses to standard IPv4 notation in proxy and IPv6 environments. ACL entries using mapped IPv6 notation no longer match these normalized client IP addresses.
- Changed: Client IP address detection no longer falls back to the `HTTP_CLIENT_IP` header when the `X-Forwarded-For` proxy header is empty or does not contain a valid address.
- Improved: The integrity scanner now records detailed database error information in the log when diagnostic logging is enabled in the settings.
- Fixed: Geolocation data for IPv6 addresses is now cached correctly, so country names appear immediately in the Activity log and Traffic log instead of being re-fetched from the geolocation service on each view, which previously caused extra AJAX requests and a noticeable delay.
- Fixed: Eliminated the `ERROR 1062` ("Duplicate entry") messages that the IPv6 geolocation caching bug wrote to the server error log on each IPv6 lookup.
- Fixed: If more than one IPv6 range or IPv6 network defined in IP Access Lists, the Traffic and Activity logs could display comments or labels belonging to a different IPv6 Access List entry, for example showing the label "IP whitelisted" for a request that was actually denied. The logs now show details that match the Access List entry involved.
- Fixed: Database operations now compatible with WordPress table prefixes starts with a digit, such as `123_`. This resolves a regression introduced by the stricter database operation validation in WP Cerber 9.7.4, where affected sites could fail to run integrity scanner.
Notas de versión publicadas por el desarrollador.
Cómo instalar
Actualización automática: este ítem se actualiza con el Ultrapack Auto Updater. Con él instalado, la versión nueva aparece en tu panel como cualquier otra actualización de WordPress (cómo configurarlo).
- Descarga el archivo
wp-cerber.zip. - En el panel de WordPress, ve a Plugins > Añadir nuevo > Subir plugin.
- Selecciona el archivo
wp-cerber.zipy haz clic en Instalar ahora. - Haz clic en Activar.
Requisitos: Requiere WordPress 5.8 o superior y PHP 7.4 o superior. Probado hasta WordPress 7.1.
¿Te trabaste en algún paso? Abre un ticket diciendo en cuál te detuviste.

UAU Ready