Royal Security Features
Every tool you need to protect your WordPress site from hackers, malware, brute force attacks, and vulnerabilities.
Protection & Prevention
Stop attacks before they reach your site with proactive defense layers.
Intelligent WAF analyzes every request in real-time. Blocks SQL injection, XSS attacks, and malicious traffic before it reaches WordPress.
Learn more →IP Blocking & Whitelisting
ProBlock individual IPs, entire ranges, or auto-block repeat offenders. Whitelist trusted IPs for guaranteed access.
Country Blocking
ProBlock traffic from specific countries or allow only selected regions. Reduce attack surface by geographic filtering.
Rate Limiting
Automatically throttle excessive requests from single IPs. Prevents resource exhaustion and slows down automated attacks.
Bot Protection
ProIdentify and block malicious bots while allowing legitimate crawlers. Protects against scraping, spam, and credential stuffing.
Spam Protection
ProComment-spam filter, hidden honeypot fields, time-based bot detection, and disposable-email blocking. Optional login-form honeypot for sites under credential-stuffing attack.
Detection & Scanning
Find threats hiding in your site with comprehensive scanning technology.
Malware Scanner
ProDeep scanning checks every file for known malware signatures, suspicious code patterns, and hidden backdoors.
Learn more →Real CVE IDs, CVSS scores, and CISA KEV cross-reference on every finding, delivered via Wordfence Intelligence through the Royal Plugins proxy. Plus pending updates, abandoned-plugin detection, and hardening misconfiguration checks.
Learn more →File Integrity Monitoring
ProDetect unauthorized changes to core WordPress files. Compare against official checksums and get instant alerts.
Scheduled Scans
ProSet automatic daily, weekly, or custom scan schedules. Never forget to check your site's security status.
Database Security Check
Scan database tables for suspicious content, injected scripts, and unauthorized admin accounts.
Authentication & Access Control
Lock down your login and control who can access your WordPress admin.
TOTP-based 2FA works with Google Authenticator, Authy, and other apps. Even if passwords leak, accounts stay secure.
Learn more →Per-Role 2FA Enforcement
ProRequire 2FA for selected roles — Administrators only, or Editors and above, your choice. Existing users get a 7-day grace period with a dashboard countdown banner before the gate kicks in.
Emergency Lockdown
ProSingle toggle that denies all new sign-ins site-wide. Existing sessions keep working. The kill switch you flip when an account gets compromised and you need to buy time to investigate. Bypass via wp-config constant if you lock yourself out.
Sign-in Notifications
ProEach user gets emailed when their account signs in — the Gmail / GitHub pattern. If their account is compromised they see the unfamiliar sign-in immediately and can reset the password from the email. Per-role allow-list, default on for Administrators.
Brute Force Protection
Intelligent lockout after failed login attempts. Blocks attackers without inconveniencing legitimate users.
CAPTCHA Integration
Cloudflare Turnstile or a built-in math challenge on login, registration, lost-password, and WooCommerce auth forms. Stops automated attacks without forcing visitors to click traffic lights.
Login URL Hiding
ProMove wp-login.php to a custom URL. Bots targeting default login paths find nothing.
Password Strength Enforcement
Require strong passwords for all users. Prevent weak credentials that hackers easily guess.
Admin Email Change Verification
Pro New in 1.6.41When an administrator email is changed, the change is held pending until a confirmation link sent to the OLD address is clicked. Closes an account-takeover path where a compromised admin session swaps the email and password-resets to a new inbox. WordPress core's native flow confirms to the NEW address, which doesn't prevent this attack.
Monitoring & Alerts
Know exactly what's happening on your site with real-time visibility.
Activity Logging
ProComplete audit trail of all user actions, login attempts, plugin changes, and security events.
Learn more →Uptime Monitoring
ProGet alerted instantly when your site goes down. Know about outages before your visitors do.
Email Security Alerts
Receive notifications for critical security events: failed logins, blocked attacks, malware detection, and more.
Attacker-Behavior Alerts
Pro New in 1.6.41Five new event types that catch what attackers do after a session compromise: new administrator user created, admin role granted to an existing user, plugin activated, plugin deactivated, and administrator email changed. Individually toggleable, each with a Send test button. All route through the existing throttle so bursts collapse into a digest instead of flooding the inbox.
Dashboard Widget
See your security score, threat count, and protection status at a glance from the WordPress dashboard.
Attack Statistics
ProVisualize blocked attacks, login attempts, and threat trends over time. Understand your risk profile.
WordPress Hardening
Close security holes and reduce your attack surface with one-click hardening options.
Security Headers
ProAdd Content-Security-Policy, X-Frame-Options, and other headers that protect against clickjacking and XSS.
XML-RPC Protection
Disable or restrict XML-RPC to prevent amplification attacks and unauthorized remote access.
REST API Control
Restrict WordPress REST API access to authenticated users only. Prevent username enumeration.
File Editor Disabling
Disable the built-in theme and plugin editors. If attackers get admin access, they can't inject code.
Directory Listing Prevention
Block directory browsing to prevent attackers from seeing your file structure.
Version Hiding
Remove WordPress version from HTML and feeds. Don't advertise which vulnerabilities apply to your site.
Writes an .htaccess rule that denies PHP execution inside wp-content/uploads/. Shuts down the “upload a .php through a bad file-type check in another plugin, then hit the URL to run a shell” attack class regardless of which plugin has the weak validator. Pre-enable scan with plugin attribution, AllowOverride canary probe, and Nginx equivalent config included.
Compatibility & Support
Works seamlessly with your existing WordPress setup.
WooCommerce Compatible
Tested and optimized for WooCommerce stores. Protects customer data and checkout pages.
Caching Plugin Friendly
Works alongside WP Rocket, W3 Total Cache, LiteSpeed, and other caching solutions without conflicts.
Auto-Updates
ProReceive security patches automatically. Stay protected without manual intervention.
Security isn't a feature you add later. It's the foundation everything else stands on. Protect your site before you have something to lose.
Ready to Secure Your WordPress Site?
Get complete protection with GuardPress Pro. All features included, no add-ons required.