CyberPulse — Advanced Security & Bot Protection

Beschreibung

🛡️ CyberPulse is a powerful security firewall with IP blocking and whitelist that protects your website 24/7.

Every request is analyzed in real time. Bots, scanners, and attackers are blocked instantly — before they reach your site. The plugin detects suspicious behavior, blocks AI data collectors like GPTBot and ClaudeBot, and stops brute force attacks with automatic IP bans.

Why Choose CyberPulse:

  • Echtzeitschutz — überwacht jede Anfrage und blockiert Bedrohungen sofort
  • 🍃 Lightweight & Fast — no database load, logs stored in files with automatic cleanup
  • 🌍 10 Languages — Russian, English, German, French, Italian, Spanish, Portuguese, Chinese, Japanese, Korean
  • 🚀 Easy to Use — install and protect your site in under a minute
  • 🚫 No Ads — clean interface, no upsells in your admin panel
  • 🔗 Works with Caching — compatible with WP Rocket, W3 Total Cache, LiteSpeed Cache, and CDN services

Schutzfunktionen:

  • 🤖 AI Scraping Protection — blocks GPTBot, ClaudeBot, PerplexityBot, CCBot, and other AI data collectors
  • 🔍 Mehrschichtige Bot-Erkennung (11 unabhängige Prüfungen: User-Agent, HTTP-Header, Referer, Accept-Language und mehr)
  • 🔐 Brute force protection — automatic permanent /24 subnet ban after exceeding attempt limit
  • 🌍 IP Management — block IPs, subnets (/24), whitelist trusted addresses, detect visitor country by IP
  • 📁 WordPress system files hiding — blocks access to wp-config.php, .env, .git, and other sensitive files
  • ⏱️ Rate Limiting — configurable request limits to prevent DDoS and aggressive scraping
  • ✅ IP Whitelist — manual and automatic (server IP, search engines, administrator IPs)
  • 🛡️ XSS attack protection — blocks cross-site scripting in requests
  • 🔎 404 scanner detection — blocks vulnerability scanners by excessive 404 errors
  • 🔒 URL Firewall — manual path blocking for specific endpoints
  • 👤 User-Agent blacklist with statistics — block specific bots by User-Agent
  • 🔗 Referer verification — blocks suspicious requests without proper Referer header
  • 📊 Security score dashboard — hourly attack histogram, fix recommendations
  • 📧 E-Mail-Benachrichtigungen bei Angriffsspitzen
  • 📝 Event audit log — track logins, settings changes, and plugin activity
  • 🎨 Dark & Light theme for admin panel

Externe Dienste

Dieses Plugin verbindet sich mit externen Diensten, um bestimmte Funktionalitäten bereitzustellen.

🌍 IP Geolocation
* Service: ip-api.com
* Purpose: Determines visitor country for statistics
* Data sent: Visitor IP address
* When: On each page visit from non-whitelisted IP
* Terms of Service: https://ip-api.com/docs/legal
* Privacy Policy: https://ip-api.com/docs/legal

🖥️ Server IP Detection
* Service: https://www.ipify.org/
* Purpose: Detects the server’s public IP address
* Data sent: None (only receives IP)
* When: Once on plugin activation, then cached for 24 hours

🔒 Threat Intelligence
* Service: blocklist.de, abuse.ch (FeodoTracker), Tor Project
* Purpose: Checks visitor IPs against known malicious IP databases
* Data sent: None (downloads threat lists locally)
* When: Periodically (cached for 24 hours)
* blocklist.de: https://www.blocklist.de/en/impressum.html
* abuse.ch: https://abuse.ch/
* Tor Project: https://www.torproject.org/about/trademark/

🔄 WordPress.org API
* Service: api.wordpress.org
* Purpose: Checks for WordPress core updates (security score feature)
* Data sent: None (standard WordPress update check)
* When: On security score calculation
* Privacy Policy: https://wordpress.org/about/privacy/

Quellcode

Der ursprüngliche, nicht minifizierte Entwickler-Quellcode ist verfügbar unter: https://github.com/gataurus/cyberpulse

Screenshots

Installation

  1. Gehe im WordPress-Adminbereich zu Plugins Plugin hinzufügen
  2. Suche nach „CyberPulse“
  3. Klicke auf Jetzt installieren und dann auf Aktivieren
  4. Navigiere im Admin-Menü zu CyberPulse
  5. ✅ Your site is protected — default settings provide optimal security

FAQ

🔍 Wie funktioniert die Bot-Erkennung?

CyberPulse analysiert 11 Parameter jeder Anfrage: User-Agent, HTTP-Header, Accept-Language, Referer, Browser-Header (Sec-Fetch-*) und mehr. Verdächtige Anfragen werden automatisch durch vorübergehende oder dauerhafte IP-Sperren blockiert.

🌍 Wie funktioniert die IP-Blockierung?

CyberPulse erkennt automatisch die IP-Adressen der Besucher, gleicht sie mit bekannten bösartigen IP-Datenbanken ab und blockiert dauerhaft verdächtige IPs oder komplette /24-Subnetze. Du kannst außerdem IPs und Subnetze (CIDR) manuell blockieren und vertrauenswürdige IP-Adressen auf die Freigabeliste setzen.

⚡ Verlangsamt es meine Website?

No. CyberPulse is designed to be lightweight. All checks use efficient caching, and logs are stored in files — not in the database. It works smoothly with high-traffic sites.

🔗 Ist es mit Caching- und CDN-Diensten kompatibel?

Ja. CyberPulse funktioniert mit WP Rocket, W3 Total Cache, LiteSpeed Cache, Cloudflare und anderen CDN- und Caching-Lösungen. Echte Besucher-IPs werden über Proxy-Header korrekt erkannt.

🔎 Blockiert es Suchmaschinen?

No. Google, Bing, Yandex, Baidu, DuckDuckGo, and other legitimate search bots are automatically detected and whitelisted by IP subnet and User-Agent signature.

✅ Can I whitelist my IP or specific services?

Ja. Du kannst IPs, Subnetze (CIDR), Hostnamen, User-Agent-Muster und bestimmte URL-Pfade auf die Freigabeliste setzen. Administratoren werden bei der Anmeldung automatisch zur Freigabeliste hinzugefügt.

🔐 Wie funktioniert der Brute-Force-Schutz?

When failed login attempts exceed the limit (default: 5 attempts in 15 minutes), the entire /24 subnet is permanently blocked. No temporary bans — attackers go straight to permanent block.

🤖 Does it protect against AI scraping?

Yes. CyberPulse blocks known AI training bots: GPTBot (OpenAI), ClaudeBot (Anthropic), PerplexityBot, CCBot (Common Crawl), and others. AI scrapers are detected by User-Agent and IP signatures.

⭐ Wodurch unterscheidet sich dies von anderen Sicherheits-Plugins?

CyberPulse offers AI scraping protection, 10 languages out of the box, a real-time dashboard with hourly attack histogram, and a clean interface with no ads or upsells. It’s lightweight and stores logs in files — not in your database.

🛡️ Gibt es eine PRO-Version?

Ja. PRO fügt Zwei-Faktor-Authentifizierung, Geoblocking (195 Länder), DDoS-Schutz, Malware-Scanner, Kopierschutz für Inhalte, Dateiintegritätsüberwachung und vieles mehr hinzu. Mehr erfahren

Rezensionen

Zu diesem Plugin liegen noch keine Rezensionen vor.

Mitwirkende und Entwickler

„CyberPulse — Advanced Security & Bot Protection“ ist Open-Source-Software. Folgende Menschen haben an diesem Plugin mitgewirkt:

Mitwirkende

„CyberPulse — Advanced Security & Bot Protection“ wurde in 2 Sprachen übersetzt. Danke an die Übersetzer für ihre Mitwirkung.

Übersetze „CyberPulse — Advanced Security & Bot Protection“ in deine Sprache.

Interessiert an der Entwicklung?

Durchstöbere den Code, sieh dir das SVN-Repository an oder abonniere das Entwicklungsprotokoll per RSS.

Änderungsprotokoll

5.8.9.7

  • 🚀 Performance optimization: Added Object Cache support for 15+ functions (whitelist, offenders, threat level, UA stats, and more)
  • 🛡️ Security enhancement: Removed browser header bypass in request checks, improved XSS validation for all users
  • ⚡ Improved bot detection: Expanded real browser detection with 50+ UA patterns (VK, Telegram, WhatsApp, Instagram, and more)
  • 🔧 Optimized log rotation with safe truncation to prevent file corruption
  • 🧹 Enhanced transient cleanup with lower DB load
  • 🌐 Added caching for geo-location lookups (ip-api.com)
  • 📈 Security test now validates 20+ protection features

5.8.9

  • 🌍 Übersetzungsdateien für 10 Sprachen hinzugefügt
  • 🔗 Link zur PRO-Website aktualisiert
  • 🛠️ SQL-Kompatibilität mit MariaDB behoben

5.8.6

  • 🚀 Initial release with AI scraping protection, bot detection, brute force defense, and more