Descrição
O WP Cerber Security – Firewall, Anti-spam & Malware Scan permite a configuração de firewall, filtro anti-spam e scanner de malware para administradores de sites WordPress, bloqueando tentativas de invasão e comentários indesejados em tempo real. Com ele, você monitora arquivos suspeitos, restringe acessos por IP e ativa o reCAPTCHA nos formulários de login, registro e comentários, fortalecendo a proteção sem sobrecarregar o servidor.
Principais Características do WP Cerber Security – Firewall, Anti-spam & Malware Scan
- Firewall inteligente
Bloqueia requisições maliciosas antes que atinjam o WordPress, filtrando por IP, user-agent e padrões de ataque. - Anti-spam avançado
Filtra comentários e registros com base em regras personalizáveis, eliminando spam sem depender de serviços externos. - Scanner de malware
Varre arquivos do core, temas e plugins em busca de código malicioso, gerando alertas e ações corretivas. - Proteção contra brute force
Limita tentativas de login, bloqueia IPs após falhas repetidas e exibe reCAPTCHA para autenticação adicional. - Monitoramento de atividades
Registra logins, alterações de arquivos e tentativas de invasão, exibindo um painel centralizado de auditoria.
Benefícios do WP Cerber Security – Firewall, Anti-spam & Malware Scan
- Redução de ataques
Impede acessos não autorizados e exploração de vulnerabilidades comuns em sites WordPress. - Economia de recursos
Substitui múltiplos plugins de segurança por uma solução unificada, leve e otimizada. - Monitoramento contínuo
Recebe notificações por email sobre atividades suspeitas, mantendo o controle mesmo fora do painel. - Facilidade de configuração
Ativa proteções essenciais com poucos cliques, sem exigir conhecimento técnico avançado.
Para Quem o WP Cerber Security – Firewall, Anti-spam & Malware Scan é Indicado?
- Administradores de sites WordPress que buscam segurança completa sem complexidade.
- Desenvolvedores que precisam de um firewall e scanner integrados para múltiplos projetos.
- Agências de hospedagem e provedores que desejam proteger instâncias de clientes contra malware e invasões.
Como Baixar o WP Cerber Security – Firewall, Anti-spam & Malware Scan
O WP Cerber Security – Firewall, Anti-spam & Malware Scan está disponível para download aqui no Ultrapack. Após baixar o arquivo .zip, acesse Plugins > Adicionar Novo > Enviar plugin, selecione o arquivo e ative. O painel de segurança aparecerá no menu do WordPress, pronto para configuração imediata.
Combinando firewall de borda, scanner de arquivos e proteção contra spam e brute force, o WP Cerber Security oferece uma camada de defesa robusta para qualquer site WordPress, desde blogs pessoais até lojas virtuais e portais corporativos. Sua interface enxuta permite gerenciar todas as ameaças em um único lugar, reduzindo a superfície de ataque sem comprometer a performance.
Perguntas Frequentes
O plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan é GPL?
Sim. O WP Cerber Security – Firewall, Anti-spam & Malware Scan é distribuído sob a licença GPL (GNU General Public License). Você pode usar, modificar e redistribuir legalmente, em quantos sites quiser.
Posso usar o plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan em mais de um site?
Sim. Você pode instalar o WP Cerber Security – Firewall, Anti-spam & Malware Scan em quantos sites quiser. Só as atualizações automáticas pelo Ultrapack Auto Updater têm limite: de 3 a 80 sites, conforme o plano.
Quanto custa o plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan no Ultrapack?
O WP Cerber Security – Firewall, Anti-spam & Malware Scan sai por R$ 14,90 na compra avulsa, e também está incluído nos planos de assinatura a partir de R$59/mês (VIP I).
O plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan inclui atualizações?
Sim. A versão atual do WP Cerber Security – Firewall, Anti-spam & Malware Scan é a 9.9.5, publicada no Ultrapack em 26/08/2026. Assinantes atualizam direto do painel do WordPress com o UAU (Ultrapack Auto Updater).
O plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan é seguro para baixar e instalar no meu WordPress?
Sim. Cada versão do WP Cerber Security – Firewall, Anti-spam & Malware Scan passa por varredura de malware (ClamAV e regras YARA, no UltraHub) antes de ser publicada.
Quais são os requisitos do plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan?
Requer WordPress 5.8 ou superior e PHP 7.4 ou superior. Testado até o WordPress 7.1.
O que mudou nesta versão
Versão 9.9.5
- Improved: A setting link in admin UI now opens the matching role tab in the role-based settings and highlights the target setting, so you can jump from an Activity log event straight to the setting that affected WP Cerber's decision.
- Improved: Following a setting link from a popup explainer now centers the target WP Cerber setting in the browser window instead of aligning it with the top of the page, where the WordPress admin bar could cover it.
- Changed: URL escaping in the admin interface now accepts root-relative URLs that begin with a single slash, in addition to the already supported HTTP(S), FTP(S), and mailto URLs.
- Changed: Admin announcements are now stored as structured JSON instead of pre-rendered HTML markup. A stored announcement that does not match the supported format is rejected instead of being displayed incorrectly.
- Fixed: On the Activity log page, when several explainers described events for the same user and WP Cerber's decision was role-based, only the first setting link scrolled to and highlighted the target setting. The remaining links opened the settings page without scrolling to the target setting.
- Fixed: The "Mail Transport" settings section displayed the raw HTML markup for the "Available in the professional version of WP Cerber" link instead of a working link.
- Fixed: Non-ASCII characters in a URL path are no longer removed when WP Cerber escapes a URL, so URLs with non-ASCII path characters now point to the intended address.
- Fixed: A URL containing invalid UTF-8 no longer becomes an empty link address when WP Cerber escapes it.
- Changed: Quotes, angle brackets, and backticks are no longer deleted from URLs in admin pages. HTML escaping of the attribute value now handles these characters safely.
Versão 9.9.3
- Fixed: When error logging was active, an uncaught PHP failure such as an unhandled exception, a type error, or a parse error could stop the standard PHP fatal error processing. WordPress can again show its critical error page, send the Recovery Mode email, and revert a broken PHP edit made in the built-in plugin or theme editor.
- Fixed: Uncaught PHP exceptions and other fatal failures could be missing from the WordPress `debug.log` file when `WP_DEBUG_LOG` was enabled.
- Fixed: Not all PHP errors were logged for a request. A fatal error that terminated the request could be replaced by a later diagnostic produced by WP Cerber's own shutdown routines, so the terminating error was missing from the request details in Traffic Inspector and from `cerber-errors.log`.
- Fixed: On a non-English website, the issue message reporting a failed email delivery could be shown in the language of the request that failed to send the email, which is usually an unattended request such as a scheduled report or a visitor-triggered alert. The message is now translated into the language of the administrator who reads it.
- Fixed: On a non-English website, the message reporting corrupted plugin settings and their recovery was shown untranslated. It is now translated at the moment it is displayed to the administrator.
- Fixed: Some messages in the "System Readiness" widget were missing localization support and could not be translated.
- Fixed: Rendering the quick navigation block in the admin area could produce `Array to string conversion` warnings when a query parameter carried more than one value. Depending on the PHP error configuration, these warnings could pollute the server logs, appear in the admin output, or corrupt an AJAX response.
- Fixed: Some valid IPv6 ranges written in dash or wildcard notation were rejected when adding an entry to the IP Access Lists or filtering records in the Activity log and the Traffic log. Reversed and zero-length ranges are still rejected.
- Fixed: IPv6 range matching now uses inclusive boundaries, so the first and the last address of a range are treated as part of that range.
Versão 9.9
- New: WP Cerber now automatically maintains a backup copy of the last known valid plugin settings. The backup is refreshed after successful settings updates, settings imports, plugin upgrades, and during daily maintenance.
- New: If the stored plugin settings become corrupted, WP Cerber now restores them automatically from the settings backup and shows a dismissible admin notice explaining what happened, what action was taken, and what the administrator should review.
- New: The "System Readiness" widget now shows an advisory notice on servers where PHP is built without the modern `mysqlnd` database driver. The notice confirms that WP Cerber keeps working and recommends enabling `mysqlnd` for full compatibility and better performance.
- Improved: Traffic Inspector now detects additional high-confidence JavaScript obfuscation patterns, including fully escaped strings that use `\uNNNN` and `\u{...}` escape sequences and dangerous execution, DOM, network, and system code decoded from explicit `fromCharCode` calls, while preserving its low false-positive detection model.
- Compatibility: WP Cerber now runs correctly on legacy hosting environments where PHP is built without the modern `mysqlnd` database driver. On such servers, database query results are retrieved through a slower compatible method instead of triggering a fatal error.
- Fixed: A corrupted WP Cerber configuration value stored in the database could cause a fatal `TypeError` in `array_merge` at plugin load time on PHP 8, taking the whole website down. WP Cerber now detects the unreadable stored value, falls back to the default settings, and reports the failure as a critical issue until the administrator re-saves the settings.
- Fixed: A regression in the detection of obfuscated JavaScript by Traffic Inspector. JavaScript strings built entirely of `\xNN` hex escape sequences were not decoded, so obfuscated code such as `eval`, `script`, and `XMLHttpRequest` could go undetected when request fields were inspected.
Versão 9.8.3
- New: The Activity log and Traffic log CSV exports now report the date range they cover, adding the oldest and newest record timestamps to the export header.
- Improved: Activity log and Traffic log CSV exports now stream matching rows in a single unbuffered pass, keeping memory usage flat and avoiding deep-offset scanning, which makes exporting large logs faster and more reliable.
- Improved: Activity log and Traffic log exports now send the `X-Accel-Buffering: no` response header so an Nginx proxy in front of PHP-FPM forwards each chunk immediately instead of buffering the whole export, improving time-to-first-byte on large exports.
- Improved: Decoding of stored Traffic Inspector request field data is now more robust, consistently treating nullable legacy values, empty values, invalid JSON, and unsupported serialized payloads as an empty array.
- Fixed: Corrected memory limit handling during Activity log and Traffic log exports, where a numeric limit such as `512` could be applied as bytes instead of megabytes, preventing WP Cerber from raising the available memory and causing exports to stop earlier than expected.
- Fixed: In the Traffic Inspector Log "Advanced Search", combining the "Any software error" option with other filters could return requests with recorded PHP errors that did not match the other criteria; results now match all selected filters.
- Fixed: Dashboard links in Activity alert notification emails could carry mismatched query parameters, for example the IP filter receiving an IP-range boundary value, which opened an unrelated filtered view; the links now use the correct values.
- Fixed: Activity alerts that match on a search string now resolve the user of the logged event instead of falling back to the current administrator, so user-based alert matching behaves correctly.
- Fixed: Prevented an undefined array key notice in `CRB_Activity::is_modified_since` when the `data_modified` status value was missing, and corrected an operator-precedence error so a missing modification timestamp is correctly treated as modified.
- Security: Sanitized user-controlled profile display names (first name, last name, and display name) before they are concatenated into `Name ` mail recipient strings, closing an email header injection vector that could add an extra recipient to the two-factor authentication PIN email and to Activity alert notification emails.
- Security: Plugin ownership-change messages on the scanner page are now rendered through WP Cerber's UI layer with contextual output escaping instead of raw HTML, removing a potential stored admin XSS vector from externally supplied plugin ownership metadata provided by the WordPress.org plugin repository.
- Security: Activity log and Traffic log CSV exports now send the `Cache-Control: no-store` response header to prevent a sensitive security-log export from being cached by the browser or an intermediate proxy.
Versão 9.8
- Changed: Renamed the "White IP Access List" and "Black IP Access List" terms to "Allowed IP Access List" and "Blocked IP Access List" across the admin UI for clearer access-control terminology.
- Changed: Client IP address detection now converts IPv4-mapped IPv6 addresses to standard IPv4 notation in proxy and IPv6 environments. ACL entries using mapped IPv6 notation no longer match these normalized client IP addresses.
- Changed: Client IP address detection no longer falls back to the `HTTP_CLIENT_IP` header when the `X-Forwarded-For` proxy header is empty or does not contain a valid address.
- Improved: The integrity scanner now records detailed database error information in the log when diagnostic logging is enabled in the settings.
- Fixed: Geolocation data for IPv6 addresses is now cached correctly, so country names appear immediately in the Activity log and Traffic log instead of being re-fetched from the geolocation service on each view, which previously caused extra AJAX requests and a noticeable delay.
- Fixed: Eliminated the `ERROR 1062` ("Duplicate entry") messages that the IPv6 geolocation caching bug wrote to the server error log on each IPv6 lookup.
- Fixed: If more than one IPv6 range or IPv6 network defined in IP Access Lists, the Traffic and Activity logs could display comments or labels belonging to a different IPv6 Access List entry, for example showing the label "IP whitelisted" for a request that was actually denied. The logs now show details that match the Access List entry involved.
- Fixed: Database operations now compatible with WordPress table prefixes starts with a digit, such as `123_`. This resolves a regression introduced by the stricter database operation validation in WP Cerber 9.7.4, where affected sites could fail to run integrity scanner.
Notas de versão publicadas pelo desenvolvedor.
Como instalar
Atualização automática: este item é atualizado pelo Ultrapack Auto Updater. Com ele instalado, a versão nova aparece no seu painel como qualquer outra atualização do WordPress (como configurar).
- Baixe o arquivo
wp-cerber.zip. - No painel do WordPress, vá em Plugins > Adicionar novo > Enviar plugin.
- Selecione o arquivo
wp-cerber.zipe clique em Instalar agora. - Clique em Ativar.
Requisitos: Requer WordPress 5.8 ou superior e PHP 7.4 ou superior. Testado até o WordPress 7.1.
Travou em algum passo? Abra um chamado dizendo em qual deles parou.

UAU Ready