Title: CenterShield – Site Security: Login Protection, 2FA, File Protection &amp; Malware Scan
Author: WPセンター
Published: <strong>2026年9月26日</strong>
Last modified: 2026年9月27日

---

プラグインを検索

![](https://ps.w.org/centershield/assets/banner-772x250.png?rev=3714371)

![](https://ps.w.org/centershield/assets/icon-256x256.png?rev=3714371)

# CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan

 作者: [WPセンター](https://profiles.wordpress.org/wpcenterjp/)

[ダウンロード](https://downloads.wordpress.org/plugin/centershield.1.0.1.zip)

 * [詳細](https://ja.wordpress.org/plugins/centershield/#description)
 * [レビュー](https://ja.wordpress.org/plugins/centershield/#reviews)
 *  [インストール](https://ja.wordpress.org/plugins/centershield/#installation)
 * [開発](https://ja.wordpress.org/plugins/centershield/#developers)

 [サポート](https://wordpress.org/support/plugin/centershield/)

## 説明

CenterShield は、WPセンターが提供する国産で日本語対応の WordPress セキュリティ対策
プラグインです。日本のサイト運営者と、サイトの保守を担う制作会社のために作ってい
ます。

It brings login protection, two-factor authentication, hardening, file protection
and
 malware scanning together in one place. Every setting explains what it protects
and what changes when you turn it on, so you can choose the measures your site needs
without security expertise.

**管理画面とメッセージはすべて日本語です。**

プラグインを有効化しただけでは、サイトは何も変わりません。「推奨設定をまとめて適用」
で推奨の設定を一度に有効にするか、必要な項目だけを個別に有効にできます。

#### アカウントとログインの防御

 * ログイン試行の制限 (ブルートフォース攻撃対策)
 * ユーザー名の漏えい防止
 * ログイン URL の変更
 * ログイン画面のベーシック認証 (Apache では .htaccess に書き込み)
 * reCAPTCHA v2 / v3
 * Two-factor authentication (authenticator app, email, backup codes), with an optional
   grace period and a 30-day “remember this device” option
 * XML-RPC の無効化 (Jetpack の署名付き通信は引き続き許可)
 * 管理画面への IP アドレス制限

#### 不要機能と脆弱な設定の無効化

 * ピンバック
 * REST API の制限 (Contact Form 7、Jetpack、WooCommerce など主要なプラグインは引き続き
   利用可能)
 * 投稿者ページ
 * テーマとプラグインのファイル編集機能、アプリケーションパスワード
 * HTML の head 部分 (wp_head) に出力される不要なタグ (WordPress のバージョン、RSD
   リンク、絵文字スクリプトなど)

#### ファイル・サーバー保護

 * WordPress の内部ファイル (wp-includes)、wp-config.php、設定ファイル、バックアップファイル
   への直接アクセスの禁止
 * アップロードフォルダでの PHP 実行の禁止
 * ディレクトリ一覧表示の禁止
 * X-Frame-Options などのセキュリティヘッダー
 * 誰でも閲覧できる readme.html などのファイルの削除
 * パーミッションの確認と修正

#### 継続的な安全性の確保

 * 攻撃パターンを含む入力の遮断 (簡易 WAF)
 * コメントスパムの拒否 (ハニーポット、投稿間隔の制限、過去のスパム履歴)
 * 2年以上更新されていない、またはお使いの WordPress で動作確認されていないプラグ
   インやテーマの検知

#### マルウェアスキャン

 * WordPress 本体と、WordPress.org で公開しているプラグインを、公式のチェックサム
   と照合。コメントや改行コードだけの違いは「情報」として報告
 * 既知の脆弱性データベースとの照合
 * プラグインに同梱し、作者のサーバーから更新するマルウェア定義によるパターン検査
 * WordPress.org にないテーマやプラグインの、前回スキャンからの変更検知
 * データベース (投稿、ウィジェット、管理者アカウント) の検査
 * 隔離、公式の原本からの復元、差分の表示

### 外部サービス

このプラグインは、以下の外部サービスに接続します。いずれにも、サイトのコンテンツ、
投稿データ、ユーザーデータは送信しません。また、すべての通信で、サイトのアドレス
を含む WordPress 標準のユーザーエージェントではなく、固定のユーザーエージェントを
使います。

#### api.wpcenter.jp (プラグイン作者の WPセンター)

マルウェア定義と既知の脆弱性データのダウンロードに使います。通信するのは、定義の
更新を確認するときと、スキャンで脆弱性データが必要になったときです。送信する内容
は、プラグインのバージョンと、あらゆる Web 通信に含まれる情報 (サーバーの IP アドレス
と、”WPCenterSecurity/” にプラグインのバージョンを続けた固定のユーザーエージェント。
サイトのアドレスは含まない) です。受信する内容は、マルウェア定義、その電子署名、
脆弱性情報です。サイトのアドレスと、インストールしているプラグインやテーマの一覧
は送信しません。照合はサイト内で行います。

利用規約: https://wpcenter.jp/plugin-terms/
 プライバシーポリシー: https://wpcenter.
jp/privacy/

この配信元の脆弱性情報は、Defiant, Inc. が提供する Wordfence Intelligence に由来
し、The MITRE Corporation の CVE 情報を含みます。両者の著作権表示はスキャン結果の
各項目に表示し、Wordfence Intelligence の利用規約はプラグイン内の licenses/wordfence-
intelligence-terms.txt に収録しています。WPセンターは、Wordfence および Defiant,
Inc. と提携、推奨、後援の関係にはありません。

Wordfence Intelligence: https://www.wordfence.com/threat-intel/
 Wordfence Intelligence
利用規約: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
Wordfence プライバシーポリシー: https://www.wordfence.com/privacy-policy/ CVE 利用
規約: https://www.cve.org/Legal/TermsOfUse

#### api.wordpress.org と downloads.wordpress.org

スキャン中に公式のチェックサムを取得するために使います。送信する内容は、WordPress
のバージョンと言語設定、照合するプラグインのスラッグとバージョンです。受信する内容
は、ファイルのチェックサムです。

WordPress.org プライバシーポリシー: https://wordpress.org/about/privacy/

#### core.svn.wordpress.org と plugins.svn.wordpress.org

スキャン結果で「原本と比較」または「原本に戻す」を押したときだけ使います。送信する
内容は、取得するファイルのバージョンとパスです。受信する内容は、WordPress.org の
公式リポジトリにある、そのファイル1つの原本です。

WordPress.org プライバシーポリシー: https://wordpress.org/about/privacy/

#### www.google.com (reCAPTCHA)

ご自身のキーを入力して reCAPTCHA を有効にした場合にだけ使います。その場合、選んだ
フォームで reCAPTCHA のスクリプトを読み込み、トークンを Google に照会して検証します。
送信する内容は、reCAPTCHA のトークン、シークレットキー、訪問者の IP アドレスです。

Google 利用規約: https://policies.google.com/terms
 Google プライバシーポリシー:
https://policies.google.com/privacy

### 第三者のリソース

 * 脆弱性データ: Wordfence Intelligence Vulnerability Database (https://www.wordfence.
   com/threat-intel/) を利用しています。Copyright Defiant, Inc. CVE 情報の著作権
   は The MITRE Corporation に帰属します。Wordfence Intelligence の利用規約に基づ
   いて再配信しており、その写しを licenses/wordfence-intelligence-terms.txt に収録
   しています。各項目の著作権表示はスキャン結果に表示します。
 * 原本ファイルとの比較: WordPress.org の公開チェックサム API と SVN リポジトリ。
 * マルウェア定義の一部: Linux Malware Detect (LMD) のシグネチャ (Copyright R-fx
   Networks, GNU GPL v2, https://github.com/rfxn/linux-malware-detect) を、GPL の
   条件に基づいて取り込んでいます。既知の不正ドメイン: URLhaus (abuse.ch, CC0, https://
   urlhaus.abuse.ch/)。
 * QR コードの生成: qrcode-generator v1.4.4、Copyright (c) 2009 Kazuhiko Arase、
   MIT ライセンス (assets/js/qrcode.min.js)。

### 日本語

WPセンターが提供する、国産で日本語対応の WordPress セキュリティ対策プラグインです。

管理画面とメッセージはすべて日本語です。

ログイン保護、2段階認証、設定の強化、ファイル保護、マルウェアスキャンをまとめて管理
でき、ひとつずつ「何のための設定か」「どんな効果があるか」を確認しながら有効化でき
ます。
 有効化した時点では何も変更されず、「推奨設定をまとめて適用」を押すか、項目
ごとに選んで有効にします。

マルウェアスキャンでは、WordPress 本体と公式プラグインを原本と照合し、既知の脆弱
性データベースと突き合わせ、不正コードのパターンを検査します。
 検出結果からは、
隔離、原本の復元、差分の表示ができます。

脆弱性情報は Wordfence Intelligence (Defiant, Inc. 提供) に由来し、CVE 情報は MITRE
Corporation によるものです。各レコードに著作権表示を表示しています。
 当プラグイン
は Wordfence および Defiant, Inc. とは無関係です。

## スクリーンショット

[⌊推奨設定の適用状況、まとめて適用するボタン、サイト環境のチェックを表示したダッシュボード⌉⌊
推奨設定の適用状況、まとめて適用するボタン、サイト環境のチェックを表示したダッシュボード⌉[

推奨設定の適用状況、まとめて適用するボタン、サイト環境のチェックを表示したダッシュボード

[⌊「アカウントとログインの防御」の設定⌉⌊「アカウントとログインの防御」の設定⌉[

「アカウントとログインの防御」の設定

[⌊.htaccess に書き込む「ファイル・サーバー保護」の設定⌉⌊.htaccess に書き込む「ファイル・
サーバー保護」の設定⌉[

.htaccess に書き込む「ファイル・サーバー保護」の設定

[⌊重大度付きのマルウェアスキャン結果⌉⌊重大度付きのマルウェアスキャン結果⌉[

重大度付きのマルウェアスキャン結果

## インストール

 1. プラグインをアップロードして有効化します。この時点では、サイトには何も変更を加え
    ません。
 2. 管理画面の「CenterShield」メニューを開き、ダッシュボードの「推奨設定をまとめて適用」
    を押すか、設定を個別に有効にします。
 3. マルウェアスキャンを実行します。

## FAQ

### 変更したログイン URL を忘れてしまいました

FTP やサーバーのファイルマネージャーで、wp-content/plugins/ にあるこのプラグイン
のフォルダ名を変更してください。プラグインが停止し、/wp-login.php から再びログイン
できるようになります。設定はそのまま残ります。正確なフォルダ名は、プラグインの「
設定」タブで確認できます。

### 管理画面に入れなくなりました

設定ファイル wp-config.php に `define( 'WPCS_DISABLE', true );` を追加してください。
この行がある間は、プラグインのすべての機能が停止します。

### ベーシック認証のパスワードを忘れてしまいました

ベーシック認証は .htaccess で設定しているため、プラグインのフォルダ名を変更しても
残ります。サイトのルートにある .htaccess を開き、”CenterShield” のマーカーの内側
にある、ベーシック認証のコメントから始まるブロックを削除してください。詳しい手順
は、プラグインの「設定」タブにあります。

### 有効化するとサイトが変わりますか ?

いいえ。有効化した直後は、すべての設定がオフです。ご自身で有効にするまで、.htaccess
への書き込みも、スキャンの予約も行いません。

## 評価

このプラグインにはレビューがありません。

## 貢献者と開発者

CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan
はオープンソースソフトウェアです。以下の人々がこのプラグインに貢献しています。

貢献者

 *   [ WPセンター ](https://profiles.wordpress.org/wpcenterjp/)

“CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware 
Scan” は1ロケールに翻訳されています。 [翻訳者](https://translate.wordpress.org/projects/wp-plugins/centershield/contributors)
のみなさん、翻訳へのご協力ありがとうございます。

[“CenterShield – Site Security: Login Protection, 2FA, File Protection & Malware Scan” をあなたの言語に翻訳しましょう。](https://translate.wordpress.org/projects/wp-plugins/centershield)

### 開発に興味がありますか ?

[コードを閲覧](https://plugins.trac.wordpress.org/browser/centershield/)するか、
[SVN リポジトリ](https://plugins.svn.wordpress.org/centershield/)をチェックするか、
[開発ログ](https://plugins.trac.wordpress.org/log/centershield/)を [RSS](https://plugins.trac.wordpress.org/log/centershield/?limit=100&mode=stop_on_copy&format=rss)
で購読してみてください。

## 変更履歴

#### 1.0.1

 * Fixed the icon position and size of the admin buttons on WordPress 6.x.
 * Fixed malware scan false positives for security plugin files inside another WordPress
   installed in a subfolder.
 * Scan results are now grouped by type (suspected malware, suspected tampering,
   accounts and database, vulnerabilities) so the nature of each finding is clear
   at a glance.
 * WordPress core vulnerability results now show an “Update WordPress” button at
   the top of the result.
 * Two-factor authentication: added a grace period that lets users in required roles
   log in for a set number of days before they must set up two-factor authentication.
 * Two-factor authentication: added an option to skip the code for 30 days on devices
   the user chooses to remember.
 * Fixed the QR code on the two-factor authentication setup screen being stretched
   vertically.
 * Two-factor authentication: when you choose email codes on the profile screen,
   a confirmation code is now sent first, and the method is turned on only after
   you enter it.

#### 1.0.0

 * 初回リリース。

## メタ

 *  バージョン **1.0.1**
 *  最終更新日 **9時間前**
 *  有効インストール数 **10未満**
 *  WordPress バージョン ** 5.8またはそれ以降 **
 *  検証済み最新バージョン: **7.1.2**
 *  PHP バージョン ** 7.4またはそれ以降 **
 *  言語
 * [English (US)](https://wordpress.org/plugins/centershield/)、[Japanese](https://ja.wordpress.org/plugins/centershield/).
 *  [プラグインを翻訳](https://translate.wordpress.org/projects/wp-plugins/centershield)
 * タグ
 * [2FA](https://ja.wordpress.org/plugins/tags/2fa/)[firewall](https://ja.wordpress.org/plugins/tags/firewall/)
   [login](https://ja.wordpress.org/plugins/tags/login/)[malware](https://ja.wordpress.org/plugins/tags/malware/)
   [security](https://ja.wordpress.org/plugins/tags/security/)
 *  [詳細を表示](https://ja.wordpress.org/plugins/centershield/advanced/)

## 評価

レビューはまだ送信されていません。

[Your review](https://wordpress.org/support/plugin/centershield/reviews/#new-post)

[すべてのレビューを見る](https://wordpress.org/support/plugin/centershield/reviews/)

## 貢献者

 *   [ WPセンター ](https://profiles.wordpress.org/wpcenterjp/)

## サポート

意見や質問がありますか ?

 [サポートフォーラムを表示](https://wordpress.org/support/plugin/centershield/)