GuardPress Pro — Complete WordPress Security Plugin
WordPress-native firewall, malware scanner, two-factor authentication, brute force protection, file integrity monitoring, and real-time activity logs. Now with a vulnerability scanner that surfaces real CVE IDs, CVSS scores, and CISA KEV cross-references, so you patch actively-exploited issues first. 30+ protection modules, 30-day audit trail, and no API keys to manage, since vulnerability intelligence flows through the Royal Plugins proxy.
Protect What You've Built
WordPress powers over 40% of the web, making it the biggest target for hackers. Every 39 seconds, a website is attacked somewhere on the internet. Without proper protection, your site is vulnerable to malware, data theft, and devastating SEO penalties.
Google blacklists over 10,000 websites daily for malware. Getting hacked doesn't just cost you data—it destroys visitor trust, tanks your rankings, and can take months to recover from. Prevention is infinitely easier than cleanup.
Without GuardPress
- Vulnerable to malware such as backdoors, cryptominers, and SEO spam injections
- Constant brute force login attempts
- According to Patchstack, 97% of WordPress vulnerabilities come from plugins in 2025. No idea if site is compromised
- Complex security configurations
- Sleepless nights worrying
With GuardPress
- Protected by intelligent firewall — for example, blocking SQL injection, XSS, and file inclusion attacks
- Brute force attacks blocked automatically
- Real-time malware detection & alerts
- One-click setup, zero config needed
- Peace of mind, finally
Great content and SEO work mean nothing if your site gets hacked. Security is the foundation everything else is built on.
30+ protection modules. No add-ons.
Here's the complete list of what GuardPress Pro ships with, grouped by what each one defends.
Core Protection 6
- Brute force attack protection
- Two-factor authentication (TOTP)
- Spam protection (comments & forms)
- Malware scanner with 20+ signatures
- File integrity monitoring
- Downtime & uptime monitoring
WAF & Detection 6
- Web application firewall
- SQL injection detection (UNION / time / stacked / file)
- XSS attack blocking
- SSRF & dangerous-scheme protection
- Rate limiting / request flood prevention
- IP block / whitelist / country block
Login Hardening 7
- Login page CAPTCHA (Turnstile / math)
- Custom login URL (hide /wp-login.php)
- Per-role 2FA enforcement
- Failed-login lockout
- Login notifications
- Emergency lockdown switch
- Admin email change verification (OLD-email confirmation)
Monitoring & Audit 6
- Activity / audit log of every change
- Real-time traffic monitoring
- Email security alerts
- Security dashboard with score
- Dashboard widget summary
- Attacker-behavior alerts (new admin, role granted, plugin toggle)
Hardening & Headers 6
- Security headers (CSP, HSTS, X-Frame-Options)
- Force strong passwords
- XML-RPC protection
- Disable file editing
- Hide WordPress version & signatures
- Uploads PHP execution block
Updates & Compliance 3
- Vulnerability scanner with CVE + CISA KEV data (core / plugins / themes)
- Database security scanner & cleanup
- Core file verification
Powerful Protection, Simple Interface
Intelligent Firewall
Our Web Application Firewall (WAF) analyzes every request before it reaches your site. Malicious traffic is blocked instantly, legitimate visitors pass through seamlessly.
- Real-time threat detection
- SQL injection protection
- XSS attack prevention
- Zero performance impact
- Doesn't block search engine crawlers
Malware Scanner
Deep scanning technology checks every file on your WordPress installation. Known malware signatures and suspicious patterns are detected and reported instantly.
- Scheduled automatic scans
- File integrity monitoring
- Core file comparison
- Detailed threat reports
Login Protection & 2FA
Stop brute force attacks cold. Intelligent rate limiting, CAPTCHA integration, and two-factor authentication keep unauthorized users out permanently.
- Brute force blocking
- Two-factor authentication (TOTP)
- Login CAPTCHA protection
- Login attempt logging
Real-Time Monitoring
Know exactly what's happening on your site at all times. Activity logging tracks every action, while uptime monitoring alerts you instantly if something goes wrong.
- Complete activity logging
- Uptime monitoring
- Email security alerts
- User action audit trail
WordPress Dashboard Widget
See your security status at a glance right from the WordPress dashboard. No need to navigate to the security pages—your protection level is always visible.
- Security score at a glance
- Threat and vulnerability count
- Color-coded status indicators
- Quick link to full dashboard
IP Whitelisting & Blocking
Take full control of who can access your site. Whitelist trusted IPs for guaranteed access, or block malicious IPs and entire ranges with one click.
- IP whitelist for trusted users
- Block individual IPs or ranges
- Country-based blocking
- Auto-block repeat offenders
Vulnerability scanner with CVE + CISA KEV intel
Every finding is enriched with the CVE ID, CVSS score, and a red pill if the vulnerability sits on the CISA Known Exploited Vulnerabilities catalog. Data flows through the Royal Plugins vulnerability intelligence proxy, refreshed daily, so there are zero API keys for you to manage. Alerts prioritize actively-exploited vulnerabilities so you patch the highest-risk items first.
- Real CVE IDs and CVSS scores on every match
- CISA KEV pill for actively-exploited vulnerabilities
- Alerts when wp.org closes a plugin you have installed
- Pending update alerts (core, plugins, themes)
- Hardening misconfiguration checks
Comprehensive Settings
Fine-tune every aspect of your security. From hardening options to notification preferences, you're in complete control with our intuitive settings panel.
- Security hardening toggles
- Email alert configuration
- Custom security headers
- Rate limiting controls
The attacks GuardPress actually catches
Real attack signatures, not generic claims. The detection engine was rewritten in 1.6.18 to use grammar-based matching — so legitimate content with the words “select” and “from” in the same string passes, while a stacked-query injection at /wp-admin/admin-ajax.php gets blocked.
SQL Injection
Grammar-based matching, not greedy keyword pairs. Catches all 7 classical injection vectors without false-positiving SQL tutorials or comments.
- UNION-based with whitespace
- Boolean tautology with end markers (
--,;,/*) - Stacked queries with semicolons
- Time-based:
sleep(),benchmark() - File functions:
LOAD_FILE,INTO OUTFILE information_schemaenumeration
XSS & Script Injection
Cross-site scripting attempts in URL params, headers, POST bodies, and cookie values — matched against known reflected and stored XSS patterns.
- Reflected XSS in GET / POST
- Stored XSS payloads
- DOM-based vector strings
- Event-handler injection
- JavaScript URI schemes
SSRF & Dangerous Schemes
Server-side request forgery attempts and dangerous URL schemes are blocked unconditionally — even when a URL shortener plugin is active.
file://,php://,data:schemes- Loopback:
127.0.0.1/localhost - Private nets:
10.x/192.168.x/172.16-31.x - Link-local:
169.254.x(cloud metadata) - Always runs (post-1.6.19)
Brute Force & Credential Stuffing
Always-on protection independent of CAPTCHA — even if a token is missing, the lockout still fires.
- Failed-login rate limiting
- IP-level lockout after N attempts
- Username enumeration block
- Application Password & XML-RPC paths covered
- WooCommerce / BuddyPress / MemberPress login surfaces
Malware & File Tampering
Deep file scanning catches code patterns and signatures, while file integrity monitoring flags any unexpected change to core, plugin, or theme files.
- 20+ malware signatures
- Suspicious code-pattern matching
- Core file verification (vs WP.org checksums)
- Real-time file change alerts
- Database scanner for poisoned records
Bot & Bad Traffic
Country-level blocking, IP allow / deny, and rate limiting keep low-quality and abusive traffic away before it reaches WordPress.
- Country-based blocking
- IP block / whitelist
- Request rate limiting
- XML-RPC abuse protection
- Spam comment / form filtering
All blocking happens server-side at plugins_loaded:20, before WordPress dispatches a single hook. No outbound scanning queue, no Wordfence-style 30-day rule delay.
Switching from Wordfence?
One-click migration imports your IP blocklists, login settings, and notification preferences. No data lost, no downtime.
Install GuardPress
Install and activate alongside your current plugin.
Auto-Detect
GuardPress finds your Wordfence, Sucuri, or Solid Security data automatically.
One-Click Import
Preview what transfers, then import with one click.
What Transfers
- IP blocklists (permanent & temporary)
- Login security settings
- Email notification preferences
- Ban lists with reasons
Stays Behind
- Firewall learning data
- Scan results
- Live traffic history
GuardPress Pro vs the paid security plugins
All four major paid WordPress security plugins, compared on the protections that matter most.
| Feature | ProGuardPress | PremiumWordfence | PlatformSucuri | Pro bundleKadence Security | PremiumAll-In-One WP Security |
|---|---|---|---|---|---|
| Web application firewall | ✓ | ✓ | ✓ | Partial | ✓ |
| Real-time firewall rules (no 30-day delay) | ✓ | × 30-day delay | ✓ | × | ✓ |
| Malware scanner | ✓ | ✓ | ✓ | ✓ | Basic |
| Two-factor authentication | ✓ | ✓ | ✓ | ✓ | ✓ |
| Per-role 2FA enforcement | ✓ | × | × | Partial | × |
| SSRF & dangerous-scheme protection | ✓ | × | Cloud-only | × | × |
| File integrity monitoring | ✓ | ✓ | ✓ | ✓ | ✓ |
| Vulnerability scanner (real CVE + CVSS) | ✓ Wordfence Intel | ✓ | × | × | × |
| CISA KEV cross-reference | ✓ | ? | × | × | × |
| No API key management for CVE data | ✓ via managed proxy | × Wordfence subscription | × | × | × |
| Plugin-closed watcher (wp.org) | ✓ | × | × | × | × |
| Activity / audit log | ✓ | Limited | ✓ | ✓ | × |
| Country-based blocking | ✓ | ✓ | × | ✓ | × |
| Security headers (CSP / HSTS / X-Frame) | ✓ | × | CDN-only | Partial | ✓ |
| Uptime monitoring | ✓ | × | ✓ | × | × |
| Runs without cloud dependency | ✓ | Partial | × | ✓ | ✓ |
| Uploads PHP execution block | ✓ with pre-scan + canary | × | ✓ | ✓ | ✓ |
| Attacker-behavior email alerts (new admin, role granted, plugin toggle) | ✓ per-event toggle + test | Audit Log | ? | User Logging (Pro) | ? |
| Admin email change verification (OLD-email confirmation) | ✓ | × | ? | × | ? |
| Yearly cost (1 site) | $59 | $149 | $229–$549 | $99–$299 | ~$70 |
| Yearly cost (5 sites) | $149 | $745 | $1,145–$2,745 | $499 (Elite) | ~$280 |
Pricing accurate as of June 2026. Tier names and exact pricing change — check vendor sites for current details. Kadence Security is the current name for the plugin formerly sold as Solid Security (renamed from iThemes Security in 2023, then to Kadence Security in May 2026). “Partial” means the feature exists in the plugin but is limited or requires an add-on; “CDN-only” means the feature is delivered through a paid CDN tier rather than the plugin itself.
Tuned for the way your site actually gets attacked
Same plugin, different threat models. Pick the angle that matches what you protect.
Bloggers & Personal Sites
Set-and-forget protection
Brute force lockout, 2FA on the admin account, malware scanner, and a vulnerability scanner that flags real CVEs on your installed plugins. Configured once, alerts you only when something actually matters.
- 2FA on the admin user
- Brute force protection
- Custom login URL
- Email alerts for real threats
- Outdated plugin check
E-commerce & WooCommerce
PCI-conscious hardening
Bot blocking and rate limiting at the WAF, file integrity monitoring on payment-handling plugins, and security headers (CSP / HSTS) that pass payment-processor security scans.
- WAF + rate limiting against checkout abuse
- Country-based blocking for high-fraud regions
- CSP / HSTS / X-Frame for PCI checks
- File integrity on cart & payment files
- 2FA on shop manager / admin roles
Membership & SaaS
Granular role & audit
For sites where users log in. Per-role 2FA enforcement, full activity log, login notifications, and CAPTCHA that works on WooCommerce / MemberPress / BuddyPress login surfaces (not just wp-login).
- Per-role 2FA enforcement
- Full audit log of every change
- Login notifications to admins
- CAPTCHA on every login surface
- Application Password & XML-RPC controls
Agencies
100 sites, one license
One $299/yr license activates GuardPress on up to 100 client sites. Same dashboard widget on every install — check security score across the portfolio without logging into each site.
- 100 sites for $299/yr
- Per-site dashboard widget summary
- Email alerts grouped by site
- No outbound cloud dependency
- Drop-in deploy across new clients
30-Day Money-Back Guarantee
If you aren't happy with our plugins, our features, or our support, reach out to our support team and request a refund within 30 days of your original purchase for a full refund.
View Refund Policy →Common Questions
Yes — and the 1.6.17 patch was specifically about this. Older versions called session_start() on every init hook, which forced a no-store Cache-Control header on every response and silently neutralized Cloudflare, FastCGI cache, ForgeCache, and WP Rocket. 1.6.17+ scopes session start to wp-login.php only, so caching layers (WP Rocket, LiteSpeed, W3 Total Cache, ForgeCache, Cloudflare APO) work the way they should.
No. The CAPTCHA renders on every login surface (WooCommerce /my-account/, BuddyPress, bbPress, MemberPress, RCP, Paid Memberships Pro, theme login forms, page builder login widgets) — not just wp-login.php. REST API basic auth, Application Passwords, and XML-RPC fail-open if no token is present so your headless / mobile / API clients aren't broken. Brute-force lockout still applies to all surfaces.
Two recovery paths: (1) the IP unblock list in the admin lets you remove a blocked IP in one click, (2) if you're locked out of the admin entirely, deactivate the plugin via FTP or your host's file manager — settings persist, so reactivation restores everything. The 1.6.18 SQL detection rewrite specifically targets false-positive reduction; pre-1.6.18 patterns were too greedy and caught legitimate content.
Format-aware. When a request is blocked, GuardPress detects whether it's a REST call (/wp-json/ or ?rest_route=), an AJAX request, an XML-RPC payload, or a cron run, and emits a JSON / XML / plain-text 403 instead of an HTML page. Pre-1.6.18 every block returned HTML, which broke headless clients and tripped the rate limiter on retries.
Three tiers: 1 Site ($59/yr), 5 Sites ($149/yr), 100 Sites ($299/yr). Same license key activates GuardPress on each site. Deactivate from the admin to free up a slot — staging-to-production moves are one click.
The plugin keeps protecting your site indefinitely — nothing turns off. You stop receiving updates and new firewall / detection rules. Renew anytime to resume updates. Unlike Wordfence Premium, there's no 30-day delay on rules either way.
30-day money-back guarantee. Email support within 30 days of purchase for a full refund — no questionnaire. Full refund policy →
Everything runs on your own server. The firewall, malware scanner, file integrity monitor, and audit log all execute locally and store data in your WordPress database. No outbound scanning queue, no cloud upload of file contents, no visitor data leaves your site for core protection. Outbound calls are limited to three: license validation, the vulnerability scanner's daily CVE + CISA KEV refresh (which sends installed plugin slugs + WP version to the Royal Plugins vulnerability intelligence proxy at my.royalplugins.com, receives an HMAC-signed response, and never uploads file content), and a wp.org check for plugin-closed status. No file contents, no PII, no visitor data.
Four big ones: (1) no 30-day delay on firewall rules, so new rules ship as soon as the plugin updates, (2) less than half the price for 1 site ($59 vs $149), (3) CISA KEV cross-reference on every CVE plus a plugin-closed watcher that Wordfence Premium doesn't ship, (4) per-role 2FA, security headers, SSRF protection, and uptime monitoring are all built in, not extras or absent. And you never manage a Wordfence API key since our vulnerability intelligence flows through the Royal Plugins proxy. Full comparison →
Learn, harden, recover
Articles, docs, and a place to get help.
From the blog
Documentation
"The best security is the kind you never think about—because it simply works, silently protecting you in the background."
Get GuardPress Pro