SHD Console
Консоль администратора WordPress: аудит настроек и разбор открытой страницы. A WordPress admin console: a settings audit and a breakdown of the open page.
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/smirator/shd-console/archive/refs/heads/main.zipКонсоль администратора WordPress: аудит настроек и разбор открытой страницы. Это не файрвол и не поиск вирусов.
A WordPress administrator console: a settings audit and a breakdown of the open page. This is not a firewall or a malware scanner.
Русский
Содержание
- Назначение
- Где открыть
- Вкладки
- Аудит
- Консоль запроса
- Чего плагин не делает
- Установка
- Командная строка
- Частые вопросы
- Требования и лицензия
Назначение
SHD Console собирает на одном экране то, что администратор обычно смотрит в разных местах.
Аудит — сохранённый чеклист настроек WordPress и ожидающих обновлений. Есть история, сравнение с прошлым сканом и еженедельное письмо, если после первого скана появилась новая критичная проблема.
Консоль запроса описывает страницу, которую вы открыли сейчас: время, память, запросы к базе и шаблон. Эти данные никуда не записываются и в аудит не входят.
Где открыть
После активации: Инструменты → Консоль.
Виджет с кратким итогом последнего скана есть на главной странице консоли WordPress. В админ-баре, на страницах сайта и в панели управления, есть пункт Этот запрос.
Вкладки
На экране плагина описание разложено по вкладкам, чтобы язык и оглавление не смешивались.
Язык описания
Две вкладки: Русский и English. На каждой полный текст и своё оглавление: о плагине, аудит, консоль запроса, вкладки, ограничения, вопросы. Сначала открывается вкладка языка вашей учётной записи. Щелчок по другой вкладке показывает тот же рассказ на втором языке и не перезагружает страницу.
Эти вкладки переводят только описание. Отчёт сканирования, виджет и подписи кнопок переводит отдельный переключатель Язык в строке над кнопкой «Сканировать сейчас». Он запоминается для вашей учётной записи. Письмо о новых критичных проблемах использует язык, ранее сохранённый для всего сайта.
Оглавление на вкладке — это ссылки на разделы той же вкладки: можно перейти к аудиту, к консоли запроса или к вопросам, не прокручивая весь текст.
Панель «Этот запрос»
У пункта админ-бара две свои вкладки.
Запросы. Число обращений к базе и их суммарное время, список SQL, пометка «медленно» от 0,05 с и счётчик, сколько раз повторился тот же запрос. Поиск фильтрует список по тексту запроса или по месту вызова. Если запрос прошёл до включения журнала, он входит в общее число, но без текста. Если в конфиге SAVEQUERIES равна false, текста нет совсем, а счётчик остаётся настоящим.
Шаблоны. Выбранный файл темы, иерархия, по которой WordPress его искал, и подключённые части шаблона. Для экранов без темы об этом написано прямо на вкладке.
Панель видит только администратор и только пока показана админ-панель. На AJAX, cron и REST её нет. Содержимое не сохраняется и в еженедельный аудит не попадает.
Аудит
Чеклист сохраняется в опциях WordPress на вашем сайте. Следующий скан сравнивается с предыдущим: что появилось, что исправлено, что всё ещё открыто. Первое сканирование задаёт точку отсчёта: текущие проблемы не помечаются как новые, и письмо с него не уходит.
Раз в неделю проверка запускается сама. Письмо на адрес администратора уходит только если новая критичная проблема появилась после уже сохранённого скана.
Проверки:
- HTTPS в адресах сайта
- показ ошибок посетителям (
WP_DEBUG_DISPLAYиdisplay_errors) - редактор файлов темы и плагинов (
DISALLOW_FILE_EDITилиDISALLOW_FILE_MODS) - регистрация, при которой новая учётная запись получает права администратора
- логин
admin - ключи и соли аутентификации
- PHP-файлы в верхних папках каталога загрузок
- обновления ядра, плагинов и тем
На локальной и development-среде часть этих пунктов остаётся предупреждением. На staging и production те же пункты критичны. Смена солей завершает все сессии на сайте: об этом написано в подсказке к проверке.
Консоль запроса
Помимо вкладок из раздела выше, в строке админ-бара видны время открытия страницы, пиковая память и число запросов. Полный список открывается по клику.
Чего плагин не делает
- не блокирует вход и не подменяет файрвол
- не ищет вирусы и сам ничего не исправляет
- не отправляет свою статистику наружу
Проверка обновлений обновляет тот же кэш, что экран «Обновления». Настройки сайта скан не меняет.
Установка
Релиз: v1.6.0
- Скачайте zip релиза и загрузите его через Плагины → Добавить новый → Загрузить плагин. Либо клонируйте репозиторий в
wp-content/plugins/shd-console(на Bedrock этоweb/app/plugins/shd-console). - Активируйте плагин и откройте Инструменты → Консоль.
Composer
Пакет shdev/shd-console, тип wordpress-plugin. На Bedrock он встаёт в web/app/plugins/shd-console.
composer config repositories.shd-console vcs https://github.com/Smirator/shd-console
composer require shdev/shd-console:^1.6.0
Командная строка
wp security-audit run
wp security-audit run --format=json
Код выхода 1, если итог критичный.
Частые вопросы
Это замена Wordfence или Sucuri?
Нет. Здесь чеклист настроек и консоль одной страницы.
Кто видит консоль запроса?
Только администратор, и только когда видна админ-панель.
Скан меняет сайт?
Настройки не меняет. Меняется сохранённый отчёт и кэш доступных обновлений.
Зачем две пары вкладок?
«Русский» и «English» — язык этого описания и оглавление. «Запросы» и «Шаблоны» — содержимое открытой страницы. Переключатель «Язык» — это третье: язык самого отчёта.
Подойдёт для Bedrock?
Да. Пути берутся из API WordPress: ABSPATH, каталог загрузок, константы вроде DISALLOW_FILE_EDIT.
Требования и лицензия
WordPress 6.0 или новее, PHP 8.0 или новее. Лицензия GPL-2.0-or-later.
English
Contents
- Purpose
- Where to open it
- Tabs
- Audit
- Request console
- What it does not do
- Install
- Command line
- Common questions
- Requirements and license
Purpose
SHD Console puts on one screen what an administrator usually checks in several places.
The audit is a saved checklist of WordPress settings and pending updates. It keeps a history, a diff against the previous scan, and a weekly email when a new critical problem appears after the first scan.
The request console describes the page you have open: time, memory, database queries, and the template. None of that is stored, and it is not part of the audit.
Where to open it
After activation: Tools → Console.
A short summary of the latest scan is on the WordPress dashboard. The admin bar, on the site and in the admin, has an item named This request.
Tabs
The plugin screen splits the description into tabs so the language and the contents list stay separate.
Description language
Two tabs: Русский and English. Each has the full text and its own contents list: about, audit, request console, tabs, limits, and questions. The tab that opens first matches your account language. Choosing the other tab shows the same text in the other language and does not reload the page.
These tabs translate only the description. The scan report, the widget, and the button labels follow the separate Language switch in the row above Scan now. That choice is saved for your account. Mail about new critical problems uses the language previously saved for the whole site.
The contents list on a tab links to sections of that same tab, so you can jump to the audit, the request console, or the questions without scrolling the whole text.
The “This request” panel
The admin-bar item has two tabs of its own.
Queries. The database call count and total time, the SQL list, a Slow mark from 0.05s, and how many times the same query ran. A filter narrows the list by query text or caller. A query that ran before logging started still counts, without its text. If SAVEQUERIES is false, there is no SQL text at all, but the count stays real.
Templates. The chosen theme file, the hierarchy WordPress searched, and the included template parts. Screens without a theme say so on the tab.
Only an administrator sees the panel, and only while the admin bar is visible. It is absent from AJAX, cron, and REST. The contents are not stored and are not part of the weekly audit.
Audit
The checklist is stored in WordPress options on your site. The next scan is compared with the previous one: what appeared, what was fixed, and what is still open. The first scan sets a baseline. Current problems are not marked as new, and that scan does not send mail.
A weekly check runs on its own. Mail goes to the site admin address only when a new critical problem appears after a scan that was already saved.
Checks:
- HTTPS in the site addresses
- errors shown to visitors (
WP_DEBUG_DISPLAYanddisplay_errors) - the theme and plugin file editor (
DISALLOW_FILE_EDITorDISALLOW_FILE_MODS) - registration that gives new accounts administrator capabilities
- a login of
admin - authentication keys and salts
- PHP files in the top upload folders
- core, plugin, and theme updates
On a local or development site some of these stay warnings. On staging and production the same items are critical. Replacing salts logs everyone out. The check says so.
Request console
Besides the tabs described above, the admin-bar row shows page load time, peak memory, and the query count. The full list opens on click.
What it does not do
- it does not block logins and it is not a firewall
- it does not look for malware and it does not repair the site
- it does not send telemetry of its own
Update checks refresh the same cache as Dashboard → Updates. A scan does not change site settings.
Install
Release: v1.6.0
- Download the release zip and upload it in Plugins → Add New → Upload Plugin. Or clone this repository into
wp-content/plugins/shd-console(web/app/plugins/shd-consoleon Bedrock). - Activate the plugin and open Tools → Console.
Composer
Package name: shdev/shd-console, type wordpress-plugin. On Bedrock, composer/installers places it in web/app/plugins/shd-console.
composer config repositories.shd-console vcs https://github.com/Smirator/shd-console
composer require shdev/shd-console:^1.6.0
Command line
wp security-audit run
wp security-audit run --format=json
The exit code is 1 when the result is critical.
Common questions
Is this a replacement for Wordfence or Sucuri?
No. This is a settings checklist and a console for one page.
Who can see the request console?
An administrator, and only while the admin bar is visible.
Does a scan change the site?
It does not change settings. It updates the stored report and the available-updates cache.
Why are there two pairs of tabs?
Русский and English choose the language of this description and its contents list. Queries and Templates are the open page. The Language switch is a third control: the language of the report itself.
Does it work on Bedrock?
Yes. Paths come from WordPress APIs: ABSPATH, the uploads directory, and constants such as DISALLOW_FILE_EDIT.
Requirements and license
WordPress 6.0 or newer, PHP 8.0 or newer. License: GPL-2.0-or-later.