Beschreibung
🛡️ CyberPulse (Cyber Pulse) is a powerful security firewall with IP blocking and whitelist that protects your website 24/7.
Every request is analyzed in real time. Bots, scanners, and attackers are blocked instantly — before they reach your site. The plugin detects suspicious behavior, blocks AI data collectors like GPTBot and ClaudeBot, and stops brute force attacks with automatic IP bans.
Why Choose Cyber Pulse:
- ⚡ Echtzeitschutz — überwacht jede Anfrage und blockiert Bedrohungen sofort
- 🍃 Lightweight & Fast — no database load, logs stored in files with automatic cleanup
- 🌍 10 Languages — Russian, English, German, French, Italian, Spanish, Portuguese, Chinese, Japanese, Korean
- 🚀 Easy to Use — install and protect your site in under a minute
- 🚫 No Ads — clean interface, no upsells in your admin panel
- 🔗 Works with Caching — compatible with WP Rocket, W3 Total Cache, LiteSpeed Cache, and CDN services
Schutzfunktionen:
- 🤖 AI Scraping Protection — blocks GPTBot, ClaudeBot, PerplexityBot, CCBot, and other AI data collectors
- 🔍 Mehrschichtige Bot-Erkennung (11 unabhängige Prüfungen: User-Agent, HTTP-Header, Referer, Accept-Language und mehr)
- 🔐 Brute force protection — automatic permanent /24 subnet ban after exceeding attempt limit
- 🌍 IP Management — block IPs, subnets (/24), whitelist trusted addresses, detect visitor country by IP
- 📁 WordPress system files hiding — blocks access to wp-config.php, .env, .git, and other sensitive files
- ⏱️ Rate Limiting — configurable request limits to prevent DDoS and aggressive scraping
- ✅ IP Whitelist — manual and automatic (server IP, search engines, administrator IPs)
- 🛡️ XSS attack protection — blocks cross-site scripting in requests
- 🔎 404 scanner detection — blocks vulnerability scanners by excessive 404 errors
- 🔒 URL Firewall — manual path blocking for specific endpoints
- 👤 User-Agent blacklist with statistics — block specific bots by User-Agent
- 🔗 Referer verification — blocks suspicious requests without proper Referer header
- 📊 Security score dashboard — hourly attack histogram, fix recommendations
- 📧 E-Mail-Benachrichtigungen bei Angriffsspitzen
- 📝 Event audit log — track logins, settings changes, and plugin activity
- 🎨 Dark & Light theme for admin panel
Externe Dienste
Dieses Plugin verbindet sich mit externen Diensten, um bestimmte Funktionalitäten bereitzustellen.
🌍 IP Geolocation
* Service: ip-api.com
* Purpose: Determines visitor country for statistics
* Data sent: Visitor IP address
* When: On each page visit from non-whitelisted IP
* Terms of Service: https://ip-api.com/docs/legal
* Privacy Policy: https://ip-api.com/docs/legal
🖥️ Server IP Detection
* Service: https://www.ipify.org/
* Purpose: Detects the server’s public IP address
* Data sent: None (only receives IP)
* When: Once on plugin activation, then cached for 24 hours
🔒 Threat Intelligence
* Service: blocklist.de, abuse.ch (FeodoTracker), Tor Project
* Purpose: Checks visitor IPs against known malicious IP databases
* Data sent: None (downloads threat lists locally)
* When: Periodically (cached for 24 hours)
* blocklist.de: https://www.blocklist.de/en/impressum.html
* abuse.ch: https://abuse.ch/
* Tor Project: https://www.torproject.org/about/trademark/
🔄 WordPress.org API
* Service: api.wordpress.org
* Purpose: Checks for WordPress core updates (security score feature)
* Data sent: None (standard WordPress update check)
* When: On security score calculation
* Privacy Policy: https://wordpress.org/about/privacy/
Quellcode
Der ursprüngliche, nicht minifizierte Entwickler-Quellcode ist verfügbar unter: https://github.com/gataurus/cyberpulse
Screenshots






Installation
- Gehe im WordPress-Adminbereich zu Plugins Plugin hinzufügen
- Suche nach „CyberPulse“
- Klicke auf Jetzt installieren und dann auf Aktivieren
- Navigiere im Admin-Menü zu CyberPulse
- ✅ Your site is protected — default settings provide optimal security
FAQ
-
🔍 Wie funktioniert die Bot-Erkennung?
-
CyberPulse analysiert 11 Parameter jeder Anfrage: User-Agent, HTTP-Header, Accept-Language, Referer, Browser-Header (Sec-Fetch-*) und mehr. Verdächtige Anfragen werden automatisch durch vorübergehende oder dauerhafte IP-Sperren blockiert.
-
🌍 Wie funktioniert die IP-Blockierung?
-
CyberPulse erkennt automatisch die IP-Adressen der Besucher, gleicht sie mit bekannten bösartigen IP-Datenbanken ab und blockiert dauerhaft verdächtige IPs oder komplette /24-Subnetze. Du kannst außerdem IPs und Subnetze (CIDR) manuell blockieren und vertrauenswürdige IP-Adressen auf die Freigabeliste setzen.
-
⚡ Verlangsamt es meine Website?
-
No. CyberPulse is designed to be lightweight. All checks use efficient caching, and logs are stored in files — not in the database. It works smoothly with high-traffic sites.
-
🔗 Ist es mit Caching- und CDN-Diensten kompatibel?
-
Yes. Cyber Pulse works with WP Rocket, W3 Total Cache, LiteSpeed Cache, Cloudflare, and other CDN and caching solutions. Real visitor IPs are correctly detected via proxy headers.
-
🔎 Blockiert es Suchmaschinen?
-
No. Google, Bing, Yandex, Baidu, DuckDuckGo, and other legitimate search bots are automatically detected and whitelisted by IP subnet and User-Agent signature.
-
✅ Can I whitelist my IP or specific services?
-
Ja. Du kannst IPs, Subnetze (CIDR), Hostnamen, User-Agent-Muster und bestimmte URL-Pfade auf die Freigabeliste setzen. Administratoren werden bei der Anmeldung automatisch zur Freigabeliste hinzugefügt.
-
🔐 Wie funktioniert der Brute-Force-Schutz?
-
When failed login attempts exceed the limit (default: 5 attempts in 15 minutes), the entire /24 subnet is permanently blocked. No temporary bans — attackers go straight to permanent block.
-
🤖 Does it protect against AI scraping?
-
Yes. Cyber Pulse blocks known AI training bots: GPTBot (OpenAI), ClaudeBot (Anthropic), PerplexityBot, CCBot (Common Crawl), and others. AI scrapers are detected by User-Agent and IP signatures.
-
⭐ Wodurch unterscheidet sich dies von anderen Sicherheits-Plugins?
-
CyberPulse offers AI scraping protection, 10 languages out of the box, a real-time dashboard with hourly attack histogram, and a clean interface with no ads or upsells. It’s lightweight and stores logs in files — not in your database.
-
🛡️ Gibt es eine PRO-Version?
-
Ja. PRO fügt Zwei-Faktor-Authentifizierung, Geoblocking (195 Länder), DDoS-Schutz, Malware-Scanner, Kopierschutz für Inhalte, Dateiintegritätsüberwachung und vieles mehr hinzu. Mehr erfahren
-
🔍 What is CyberPulse?
-
CyberPulse (also written as Cyber Pulse) is a powerful security firewall for WordPress that protects your site from bots, scanners, and brute force attacks in real time.
Rezensionen
Zu diesem Plugin liegen noch keine Rezensionen vor.
Mitwirkende und Entwickler
„CyberPulse — Advanced Security & Bot Protection“ ist Open-Source-Software. Folgende Menschen haben an diesem Plugin mitgewirkt:
Mitwirkende„CyberPulse — Advanced Security & Bot Protection“ wurde in 3 Sprachen übersetzt. Danke an die Übersetzer für ihre Mitwirkung.
Übersetze „CyberPulse — Advanced Security & Bot Protection“ in deine Sprache.
Interessiert an der Entwicklung?
Durchstöbere den Code, sieh dir das SVN-Repository an oder abonniere das Entwicklungsprotokoll per RSS.
Änderungsprotokoll
5.9.0.2
- ⚡ Performance: Optimized cybersec_is_real_browser() — reduced from 120+ stripos() calls to 3-4 preg_match() operations (95% faster)
- ⚡ Performance: Optimized cybersec_is_legitimate_bot() — reduced from 60+ operations to 5-10 (85% faster)
- 🚀 Added PTR (reverse DNS) verification for legitimate bots (Googlebot, Bingbot, Yandex, etc.)
- 🔒 Security: Added permanent block for system file access attempts (wp-config.php, .env, .git, etc.)
5.9.0.1
- 🔧 Fixed: Counter mismatch between statistics and log files (hotfix)
- 🔧 Fixed: Statistics cache causing stale data (removed cache)
- 🔧 Fixed: Duplicate entries in blocked/allowed logs (60-second dedup)
- 🔧 Fixed: Tracked pages showing nested subpages (exact match only)
- 🔧 Fixed: Internal/private IPs shown in logs
5.9.0.0
- 🔧 Fixed: Counter mismatch between statistics and log files
- 🔧 Fixed: Statistics cache causing stale data (removed cache, count directly from files)
- 🔧 Fixed: Duplicate entries in blocked/allowed logs
- 🔧 Fixed: Internal/private IPs shown in logs (10.x.x.x, 172.16.x.x, 192.168.x.x, 100.64.x.x)
- ⚡ Improved: Dashboard order (Security Score Allowed Blocked Page Tracking Event Log)
- ⚡ Improved: Direct file counting for accurate statistics
5.8.9.9
- 🔒 Security: Fixed XSS vulnerabilities in 403 block page (replaced esc_url with esc_js for JavaScript context)
- 🔒 Security: Added strip_tags() before htmlspecialchars() in XSS detection to prevent stored XSS attacks
- 🔒 Security: Fixed SQL injection vulnerability in stale transients cleanup query
- 🔒 Security: Added current_user_can(‚manage_options‘) check to cybersec_handle_simple_check()
- 🔒 Security: Added IP validation in cybersec_ajax_human_verify() AJAX handler
- 🔒 Security: Added sanitize_text_field() for User-Agent in track_user_agent() function
- 🔒 Security: Fixed cookie removal logic in cybersec_remove_all_blocks()
- ⚡ Performance: Added throttling to cybersec_cleanup_expired_temp_blocks() (5 min cooldown)
- 🔧 Fixed: Proper variable naming in cybersec_cleanup_stale_transients() foreach loop
- 🐛 Fixed: Potential memory issue in cybersec_fs_put_contents() with large log files
5.8.9.8
- 🔒 Security fix: Added XSS protection with input sanitization and esc_url_raw
- 🛡️ Fixed 403 page bugs: increased token lifetime, IP validation
- 🚀 Performance optimization: added wp_cache for settings and whitelist
- 🔧 Fixed cron schedule error: registered cyberpulse_every_5_minutes
- 🧹 Added directory traversal protection in log functions
- ✅ Added nonce verification in AJAX human-verify handler
- 🔄 Full data cleanup on IP unblock (cookies, cache, transients)
5.8.9.7
- 🚀 Performance optimization: Added Object Cache support for 15+ functions (whitelist, offenders, threat level, UA stats, and more)
- 🛡️ Security enhancement: Removed browser header bypass in request checks, improved XSS validation for all users
- ⚡ Improved bot detection: Expanded real browser detection with 50+ UA patterns (VK, Telegram, WhatsApp, Instagram, and more)
- 🔧 Optimized log rotation with safe truncation to prevent file corruption
- 🧹 Enhanced transient cleanup with lower DB load
- 🌐 Added caching for geo-location lookups (ip-api.com)
- 📈 Security test now validates 20+ protection features
5.8.9
- 🌍 Übersetzungsdateien für 10 Sprachen hinzugefügt
- 🔗 Link zur PRO-Website aktualisiert
- 🛠️ SQL-Kompatibilität mit MariaDB behoben
5.8.6
- 🚀 Initial release with AI scraping protection, bot detection, brute force defense, and more
