# Royal Security Features

> Explore all GuardPress Pro features: firewall, malware scanning, 2FA, outdated-software alerts, activity monitoring, and WordPress hardening.

- Canonical: <https://royalplugins.com/guardpress/features/>
- HTML version: <https://royalplugins.com/guardpress/features/>

---

- [Overview](https://royalplugins.com/guardpress/)
- [Features](https://royalplugins.com/guardpress/features/)

  [All Features](https://royalplugins.com/guardpress/features/)
  [Firewall](https://royalplugins.com/guardpress/features/firewall/)
  [Malware Scanner](https://royalplugins.com/guardpress/features/malware-scanner/)
  [Vulnerability Scanner](https://royalplugins.com/guardpress/features/vulnerability-scanner/)
  [Two-Factor Auth](https://royalplugins.com/guardpress/features/two-factor-auth/)
  [Activity Logs](https://royalplugins.com/guardpress/features/activity-logs/)
- [Compare](https://royalplugins.com/guardpress/free-vs-pro/)

  [Free vs Pro](https://royalplugins.com/guardpress/free-vs-pro/)
  [vs Wordfence](https://royalplugins.com/guardpress/vs-wordfence/)
  [vs Sucuri](https://royalplugins.com/guardpress/vs-sucuri/)
  [vs Kadence Security](https://royalplugins.com/guardpress/vs-kadence-security/)
- [Pricing](https://royalplugins.com/guardpress/pricing/)
- [Docs](https://royalplugins.com/support/guardpress/)

Overview
All Features
— Firewall
— Malware Scanner
— Vulnerability Scanner
— Two-Factor Auth
— Activity Logs
Compare
— Free vs Pro
— vs Wordfence
— vs Sucuri
— vs Kadence Security
Pricing
Documentation

Every tool you need to protect your WordPress site from hackers, malware, brute force attacks, and vulnerabilities.

By Jameson · Founder & Lead Developer

## Protection & Prevention

Stop attacks before they reach your site with proactive defense layers.

### [Web Application Firewall](https://royalplugins.com/guardpress/features/firewall/)

Pro

Intelligent WAF analyzes every request in real-time. Blocks SQL injection, XSS attacks, and malicious traffic before it reaches WordPress.

[Learn more →](https://royalplugins.com/guardpress/features/firewall/)

### IP Blocking & Whitelisting

Pro

Block individual IPs, entire ranges, or auto-block repeat offenders. Whitelist trusted IPs for guaranteed access.

### Country Blocking

Pro

Block traffic from specific countries or allow only selected regions. Reduce attack surface by geographic filtering.

### Rate Limiting

Automatically throttle excessive requests from single IPs. Prevents resource exhaustion and slows down automated attacks.

### Bot Protection

Pro

Identify and block malicious bots while allowing legitimate crawlers. Protects against scraping, spam, and credential stuffing.

### Spam Protection

Pro

Comment-spam filter, hidden honeypot fields, time-based bot detection, and disposable-email blocking. Optional login-form honeypot for sites under credential-stuffing attack.

## Detection & Scanning

Find threats hiding in your site with comprehensive scanning technology.

### [Malware Scanner](https://royalplugins.com/guardpress/features/malware-scanner/)

Pro

Deep scanning checks every file for known malware signatures, suspicious code patterns, and hidden backdoors.

[Learn more →](https://royalplugins.com/guardpress/features/malware-scanner/)

### [Vulnerability Scanner](https://royalplugins.com/guardpress/features/vulnerability-scanner/)

Pro

Real CVE IDs, CVSS scores, and CISA KEV cross-reference on every finding, delivered via Wordfence Intelligence through the Royal Plugins proxy. Plus pending updates, abandoned-plugin detection, and hardening misconfiguration checks.

[Learn more →](https://royalplugins.com/guardpress/features/vulnerability-scanner/)

### File Integrity Monitoring

Pro

Detect unauthorized changes to core WordPress files. Compare against official checksums and get instant alerts.

### Scheduled Scans

Pro

Set automatic daily, weekly, or custom scan schedules. Never forget to check your site's security status.

### Database Security Check

Scan database tables for suspicious content, injected scripts, and unauthorized admin accounts.

## Authentication & Access Control

Lock down your login and control who can access your WordPress admin.

### [Two-Factor Authentication](https://royalplugins.com/guardpress/features/two-factor-auth/)

Pro

TOTP-based 2FA works with Google Authenticator, Authy, and other apps. Even if passwords leak, accounts stay secure.

[Learn more →](https://royalplugins.com/guardpress/features/two-factor-auth/)

### Per-Role 2FA Enforcement

Pro

Require 2FA for selected roles — Administrators only, or Editors and above, your choice. Existing users get a 7-day grace period with a dashboard countdown banner before the gate kicks in.

### Emergency Lockdown

Pro

Single toggle that denies all new sign-ins site-wide. Existing sessions keep working. The kill switch you flip when an account gets compromised and you need to buy time to investigate. Bypass via wp-config constant if you lock yourself out.

### Sign-in Notifications

Pro

Each user gets emailed when their account signs in — the Gmail / GitHub pattern. If their account is compromised they see the unfamiliar sign-in immediately and can reset the password from the email. Per-role allow-list, default on for Administrators.

### Brute Force Protection

Intelligent lockout after failed login attempts. Blocks attackers without inconveniencing legitimate users.

### CAPTCHA Integration

Cloudflare Turnstile or a built-in math challenge on login, registration, lost-password, and WooCommerce auth forms. Stops automated attacks without forcing visitors to click traffic lights.

### Login URL Hiding

Pro

Move wp-login.php to a custom URL. Bots targeting default login paths find nothing.

### Password Strength Enforcement

Require strong passwords for all users. Prevent weak credentials that hackers easily guess.

### Admin Email Change Verification

Pro
New in 1.6.41

When an administrator email is changed, the change is held pending until a confirmation link sent to the OLD address is clicked. Closes an account-takeover path where a compromised admin session swaps the email and password-resets to a new inbox. WordPress core's native flow confirms to the NEW address, which doesn't prevent this attack.

## Monitoring & Alerts

Know exactly what's happening on your site with real-time visibility.

### [Activity Logging](https://royalplugins.com/guardpress/features/activity-logs/)

Pro

Complete audit trail of all user actions, login attempts, plugin changes, and security events.

[Learn more →](https://royalplugins.com/guardpress/features/activity-logs/)

### Uptime Monitoring

Pro

Get alerted instantly when your site goes down. Know about outages before your visitors do.

### Email Security Alerts

Receive notifications for critical security events: failed logins, blocked attacks, malware detection, and more.

### Attacker-Behavior Alerts

Pro
New in 1.6.41

Five new event types that catch what attackers do after a session compromise: new administrator user created, admin role granted to an existing user, plugin activated, plugin deactivated, and administrator email changed. Individually toggleable, each with a Send test button. All route through the existing throttle so bursts collapse into a digest instead of flooding the inbox.

### Dashboard Widget

See your security score, threat count, and protection status at a glance from the WordPress dashboard.

### Attack Statistics

Pro

Visualize blocked attacks, login attempts, and threat trends over time. Understand your risk profile.

## WordPress Hardening

Close security holes and reduce your attack surface with one-click hardening options.

### Security Headers

Pro

Add Content-Security-Policy, X-Frame-Options, and other headers that protect against clickjacking and XSS.

### XML-RPC Protection

Disable or restrict XML-RPC to prevent amplification attacks and unauthorized remote access.

### REST API Control

Restrict WordPress REST API access to authenticated users only. Prevent username enumeration.

### File Editor Disabling

Disable the built-in theme and plugin editors. If attackers get admin access, they can't inject code.

### Directory Listing Prevention

Block directory browsing to prevent attackers from seeing your file structure.

### Version Hiding

Remove WordPress version from HTML and feeds. Don't advertise which vulnerabilities apply to your site.

### [Uploads PHP Execution Block](https://royalplugins.com/support/guardpress/uploads-php-execution-block-setup/)

Pro
New in 1.6.41

Writes an .htaccess rule that denies PHP execution inside `wp-content/uploads/`. Shuts down the “upload a .php through a bad file-type check in another plugin, then hit the URL to run a shell” attack class regardless of which plugin has the weak validator. Pre-enable scan with plugin attribution, AllowOverride canary probe, and Nginx equivalent config included.

[Learn more →](https://royalplugins.com/support/guardpress/uploads-php-execution-block-setup/)

## Compatibility & Support

Works seamlessly with your existing WordPress setup.

### WooCommerce Compatible

Tested and optimized for WooCommerce stores. Protects customer data and checkout pages.

### Caching Plugin Friendly

Works alongside WP Rocket, W3 Total Cache, LiteSpeed, and other caching solutions without conflicts.

### Auto-Updates

Pro

Receive security patches automatically. Stay protected without manual intervention.

Security isn't a feature you add later. It's the foundation everything else stands on. Protect your site before you have something to lose.

**Royal Plugins** — Philosophy

## Ready to Secure Your WordPress Site?

Get complete protection with GuardPress Pro. All features included, no add-ons required.

[Get GuardPress Pro](https://royalplugins.com/guardpress/#pricing)
[Compare Free vs Pro](https://royalplugins.com/guardpress/free-vs-pro/)
