Title: Secure Owl Firewall
Author: Sajber Sove
Published: <strong>2026年4月10日</strong>
Last modified: 2026年9月24日

---

プラグインを検索

![](https://ps.w.org/secure-owl-firewall/assets/banner-772x250.png?rev=3503274)

![](https://ps.w.org/secure-owl-firewall/assets/icon-256x256.png?rev=3503274)

# Secure Owl Firewall

 作者: [Sajber Sove](https://profiles.wordpress.org/sajbersove/)

[ダウンロード](https://downloads.wordpress.org/plugin/secure-owl-firewall.2.1.0.zip)

 * [詳細](https://ja.wordpress.org/plugins/secure-owl-firewall/#description)
 * [レビュー](https://ja.wordpress.org/plugins/secure-owl-firewall/#reviews)
 *  [インストール](https://ja.wordpress.org/plugins/secure-owl-firewall/#installation)
 * [開発](https://ja.wordpress.org/plugins/secure-owl-firewall/#developers)

 [サポート](https://wordpress.org/support/plugin/secure-owl-firewall/)

## 説明

Secure Owl Firewall is a fast, lightweight firewall plugin with an advanced rule
engine featuring PCRE pattern matching, a transformation pipeline, and JSON-based
rule configuration.

Key features:

 * JSON-based rules — 100+ default rules covering SQLi, XSS, RCE, LFI, SSRF, Log4Shell,
   and more
 * Transformation pipeline — URL decode, lowercase, normalize path, remove whitespace,
   HTML entity decode, trim
 * Inspection targets — REQUEST_URI, QUERY_STRING, USER_AGENT, REFERER, COOKIE, 
   and POST
 * MU-Plugin loader — runs before regular plugins for earliest protection
 * Rate limiting — optional transient-based IP and subnet banning
 * Login protection — PIN field, speed limit and honeypot to block brute-force attacks
 * IP whitelist — CIDR/subnet support for both IPv4 and IPv6
 * IP blacklist — CIDR/subnet support for both IPv4 and IPv6
 * Per-rule toggle — disable individual rules from the admin panel without editing
   files
 * File-based logging — 64MB cap with auto-rotation and protected storage
 * Log retention — configurable policy for GDPR compliance
 * IP anonymization — masks user IP addresses for enhanced privacy and GDPR compliance

### Filter Hooks

 * `sswaf_ip_whitelist` — array of IPs to bypass the firewall
 * `sswaf_ip_blacklist` — array of IPs to block before any rules run
 * `sswaf_trusted_proxies` — array of trusted proxy IPs for X-Forwarded-For
 * `sswaf_post_scanning` — enable POST data inspection (default: true)
 * `sswaf_rules_file` — path to the rules JSON file
 * `sswaf_log_file` — path to the log file
 * `sswaf_log_max_size` — maximum log size in bytes
 * `sswaf_header_status` — HTTP status header for blocked requests
 * `sswaf_before_block` — action hook fired before blocking a request
 * `sswaf_rate_limit_ip_threshold` — override IP hit threshold
 * `sswaf_rate_limit_ip_duration` — override IP ban duration
 * `sswaf_rate_limit_ip_window` — override IP counting window

## インストール

 1. Upload the `secure-owl-firewall` folder to `/wp-content/plugins/`
 2. Activate through the Plugins menu
 3. The MU-Plugin loader is installed automatically for early execution
 4. Configure settings under Settings > Secure Owl Firewall

## 評価

![](https://secure.gravatar.com/avatar/dd8cef4c70bb3a14f5922eb54c92a8166947a303f44eb4a89a954cee4defad6f?
s=60&d=retro&r=g)

### 󠀁[Great Plugin](https://wordpress.org/support/topic/great-plugin-41612/)󠁿

 [tinaponting](https://profiles.wordpress.org/ponting/) 2026年7月1日 1 reply

A great plugin – works very well to protect my login/site

 [ 1件のレビューをすべて表示 ](https://wordpress.org/support/plugin/secure-owl-firewall/reviews/)

## 貢献者と開発者

Secure Owl Firewall はオープンソースソフトウェアです。以下の人々がこのプラグイン
に貢献しています。

貢献者

 *   [ Sajber Sove ](https://profiles.wordpress.org/sajbersove/)

[“Secure Owl Firewall” をあなたの言語に翻訳しましょう。](https://translate.wordpress.org/projects/wp-plugins/secure-owl-firewall)

### 開発に興味がありますか ?

[コードを閲覧](https://plugins.trac.wordpress.org/browser/secure-owl-firewall/)する
か、[SVN リポジトリ](https://plugins.svn.wordpress.org/secure-owl-firewall/)をチェック
するか、[開発ログ](https://plugins.trac.wordpress.org/log/secure-owl-firewall/)を
[RSS](https://plugins.trac.wordpress.org/log/secure-owl-firewall/?limit=100&mode=stop_on_copy&format=rss)
で購読してみてください。

## 変更履歴

#### 1.0.0

 * Initial release.

#### 1.0.1

 * Updated security rules.
 * Updated log file cap to 24MB.

#### 1.0.2

 * Added IP whitelist with CIDR/subnet support (IPv4 + IPv6).
 * File-based storage for zero database overhead.
 * Settings UI with validation.

#### 1.0.3

 * Removed metadata from a JSON rules file.
 * Small CSS admin tweak.

#### 1.0.4

 * Added configurable log retention policy to automatically purge old data for GDPR
   compliance.
 * Added option to anonymize user IP addresses, enhancing privacy and GDPR compliance.
 * Rework plugin update mechanism.
 * Improved coding standards to align better with WordPress guidelines.

#### 1.0.5

 * Updated log file cap to 64MB.
 * Fixed a small bug in admin panel log viewer.

#### 1.0.6

 * Added rate-limited PIN authentication to the login page to mitigate brute-force
   attacks.
 * Added a honeypot trap to the login form to catch unsophisticated bots.

#### 1.0.7

 * Removed a few overly aggressive rules.

#### 1.0.8

 * Added IP blacklist with CIDR/subnet support (IPv4 + IPv6).

#### 1.0.9

 * Fixed a small bug in log viewer.

#### 1.1.0

 * Updated security rules.
 * Added a speed limit protection layer to the login page.

#### 1.1.1

 * Updated security rules.

#### 2.0.0

 * Added JSON request body scanning.
 * Raised maximum request and referrer length limits.

#### 2.0.1

 * Updated security rules.

#### 2.0.2

 * Updated security rules.

#### 2.0.3

 * Updated security rules.

#### 2.0.4

 * Updated security rules.

#### 2.0.5

 * Updated security rules.

#### 2.0.6

 * Updated security rules.

#### 2.0.7

 * Small text update in admin UI.
 * Updated security rules.

#### 2.0.8

 * Updated security rules.

#### 2.0.9

 * Updated security rules.
 * Ensured WordPress compatibility.

#### 2.1.0

 * Improved path normalization.
 * Hardened request decoding against resource exhaustion.
 * Faster rule matching for large requests.
 * Fixed client IP resolution behind trusted proxies; trusted proxies now accept
   CIDR ranges.
 * Removed an over-broad cookie rule that caused false positives.
 * Fixed log export.
 * Updated security rules.

## メタ

 *  バージョン **2.1.0**
 *  最終更新日 **3日前**
 *  有効インストール数 **20+**
 *  WordPress バージョン ** 5.0またはそれ以降 **
 *  検証済み最新バージョン: **7.1.2**
 *  PHP バージョン ** 7.4またはそれ以降 **
 *  言語
 * [English (US)](https://wordpress.org/plugins/secure-owl-firewall/)
 * タグ
 * [firewall](https://ja.wordpress.org/plugins/tags/firewall/)[protection](https://ja.wordpress.org/plugins/tags/protection/)
   [security](https://ja.wordpress.org/plugins/tags/security/)[WAF](https://ja.wordpress.org/plugins/tags/waf/)
 *  [詳細を表示](https://ja.wordpress.org/plugins/secure-owl-firewall/advanced/)

## 評価

 5つ星中5つ星

 *  [  1 5-星レビュー     ](https://wordpress.org/support/plugin/secure-owl-firewall/reviews/?filter=5)
 *  [  0 4-星レビュー     ](https://wordpress.org/support/plugin/secure-owl-firewall/reviews/?filter=4)
 *  [  0 3-星レビュー     ](https://wordpress.org/support/plugin/secure-owl-firewall/reviews/?filter=3)
 *  [  0 2-星レビュー     ](https://wordpress.org/support/plugin/secure-owl-firewall/reviews/?filter=2)
 *  [  0 1-星レビュー     ](https://wordpress.org/support/plugin/secure-owl-firewall/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/secure-owl-firewall/reviews/#new-post)

[すべてのレビューを見る](https://wordpress.org/support/plugin/secure-owl-firewall/reviews/)

## 貢献者

 *   [ Sajber Sove ](https://profiles.wordpress.org/sajbersove/)

## サポート

意見や質問がありますか ?

 [サポートフォーラムを表示](https://wordpress.org/support/plugin/secure-owl-firewall/)