🚀 Start Here
Just installed GuardPress? These four articles take you from zero to fully protected in about 30 minutes.
A 5-step walkthrough that gets you from freshly installed to fully protected. Three modules turn on automatically at activation; two need your input.
Upload the ZIP, activate the license from my.royalplugins.com, run the Cloudflare pre-flight check.
ReferenceMinimum and recommended WordPress / PHP / MySQL versions, plus hosting-tier and multisite notes.
SetupEnable 2FA the safe way. Install an authenticator app first, save backup codes, then flip the toggle.
ReferenceScore composition, four stat boxes explained, and how to raise a score that isn’t 100.
Reference35 items grouped by who owns each: what GuardPress automates, what your host handles, what you verify manually.
ReferenceThe at-a-glance widget on wp-admin’s main Dashboard. Color states and score thresholds.
🚨 I’m Locked Out
Emergency recovery paths for the most common lockout scenarios. Bookmark this section before you need it.
Three flavours cover almost every lockout. Match your symptom to the right recovery doc in under a minute.
Lost your authenticator? Backup codes and the wp-config disable path when everything else fails.
LockdownEmergency Lockdown is on and you were signed out. The wp-config constant that unblocks you.
Login URLYou enabled a custom login slug and can’t remember it. Find it via wp-config, DB query, or SFTP.
White ScreenThe white-screen-of-death that follows a bad update. Get your admin back with SFTP + wp-config.
MalwareYou confirmed a malware detection is real. Steps to isolate, remove, and prevent reinfection.
🛡️ Firewall & Threat Response
Understanding what your firewall is blocking, tuning false positives, and telling real threats from noise.
Attackers wearing GPTBot / ChatGLM / YouBot User-Agents. Three real alerts and the two independent checks that catch every spoof.
ReferenceProtection types (SQL injection, XSS, LFI/RFI, bad-bot, rate limiting), rule engine, and the administrator auto-whitelist.
FirewallReal users getting blocked. How to identify the rule and whitelist the specific pattern.
IPThe three-list model (Whitelist, Blacklist, Active Lockouts) and how they interact.
CloudflareThe Cloudflare real-IP resolver pre-flight check before any IP-based rule is trustworthy.
HardeningShut down the “upload a shell via a bad file-type check” attack class at the config layer.
AI AgentsAI-agent traffic tripping brute-force rate limits. Whitelist patterns for Claude, n8n, Make.
🔐 Login & Access Control
Everything about sign-in security: brute-force lockouts, CAPTCHA, 2FA enforcement, and login notifications.
Index of all nine login-security features with links to each setup guide.
SetupThreshold, lockout duration, and permanent-ban escalation. What the defaults are and when to tune them.
CAPTCHAThe classic “customer says they can’t log in” fix. CAPTCHA widget not rendering on custom login forms.
CAPTCHASite key, secret key, widget placement. Turnstile as a replacement for reCAPTCHA on the login form.
2FARequire 2FA for Administrators without forcing it on Subscribers. 7-day grace period for existing users.
AlertsGet an email every time an administrator signs in. High-signal alert for high-value accounts.
📊 Monitoring & Alerts
Tune what GuardPress emails you about, and how to investigate each type of finding.
Throttle window, category-based toggles, and the auto-allowlist for verified crawlers.
MalwareSignature matching, behavior heuristics, three post-scan actions, and the expected self-detection behavior.
File IntegrityHash-based file monitoring for core, plugins, themes, and uploads. What triggers an alert.
File IntegrityTriage flow when the FIM widget flags unacknowledged changes. Legitimate updates vs actual tampering.
VulnerabilityWhat the scanner is checking, CISA KEV feed integration, and how to clear findings.
DatabaseCommon WP DB attack surface: exposed DB_USER, weak admin passwords, tables from removed plugins.
VulnerabilityHow GuardPress handles known CVEs in WordPress core, themes, and plugins.
UptimeHourly WP-Cron check with rate-limited alerts. Catches WordPress fatal errors that keep the server up but the site down.
SpamComment-form and login-form spam filter with no third-party service. Honeypot + time-based + Unicode keyword detection.
⚙️ Reference
Deep dives on individual features and settings for readers who want the full picture.
❓ Frequently Asked Questions
The most common questions we get from GuardPress users.
What is on by default when I activate GuardPress?
Seven modules turn on automatically at activation: the Firewall, Brute-Force Protection, the Malware Scanner, File Integrity Monitor, XMLRPC Protection, WP Version Hiding, and File-Editing Lockdown. Two-Factor Authentication and Email Alerts are off by default because they need your input (a phone for 2FA, an email address and working SMTP for alerts). Uptime Monitoring and custom Security Headers are also off by default and can be enabled after the first-week review.
How long does GuardPress take to fully set up?
About 30 minutes end to end. The 2FA setup is the longest step (5–10 minutes to install an authenticator app, scan the QR code, save backup codes, and test signing back in). Email alerts take 5 minutes to enable plus however long it takes to install an SMTP delivery plugin if your host doesn’t run its own. Everything else is either already on or a one-click confirm. Follow Quick Start for the exact order.
Real users can’t log in — what happened?
Almost always one of two things. Either the CAPTCHA / Cloudflare Turnstile widget isn’t rendering on the login form they’re using (WooCommerce my-account, MemberPress, a page-builder login widget), or their IP tripped brute-force because they use a corporate NAT that a colleague also uses. See CAPTCHA Blocks WooCommerce/MemberPress Login for the first case, and whitelist the shared IP for the second.
I run behind Cloudflare — anything I need to do differently?
Yes, one important thing. Without configuring the Cloudflare real-IP resolver, every request looks like it’s coming from Cloudflare’s IPs, so brute-force lockouts trigger against Cloudflare and geographic rules never work. See Country Blocking and the Cloudflare Real-IP Gotcha. This is a pre-flight check before doing anything IP-based.
I use Claude / ChatGPT / n8n to manage my site — their traffic keeps getting blocked
AI-agent traffic is high-frequency and predictable, so it tends to trip brute-force rate limits fast. Whitelist their known IP ranges or use Application Passwords with a dedicated user for the agent. See MCP / OAuth Clients Getting Locked Out for the pattern.
Does GuardPress slow down my site?
Marginally. The firewall runs on every request at plugins_loaded priority 20 (before WordPress loads most of core), but the rule check is optimized to a single regex sweep. Malware and vulnerability scans run in the background via WP-Cron, not during page requests. On typical shared hosting, GuardPress adds approximately 5–20ms to admin page loads and effectively zero to frontend visitors.
Will GuardPress break my caching (Cloudflare, ForgeCache, WP Rocket)?
No. GuardPress is fully compatible with Cloudflare, ForgeCache, WP Rocket, server-level FastCGI cache, LiteSpeed, and other cache layers. PHP sessions are scoped to wp-login.php only, so the rest of your site caches normally. If you were previously on an older GuardPress version that predates this scoping, purge your cache once after updating so any old no-store responses stop being served.
Can I use GuardPress alongside Wordfence, Solid Security, or Sucuri?
We don’t recommend it. Two firewalls fighting over the same request, two CAPTCHAs stacked on the same login form, and two file-integrity scans rotating the same cron lock cause real conflicts that make both plugins behave worse than either would alone. Pick one and deactivate the others.
If you’re switching to GuardPress from another security plugin, deactivate the old one first, then activate GuardPress and walk through GuardPress → Settings to enable equivalent protections. Follow Quick Start for the recommended enable order.
Can I use the same license on multiple sites?
Depends on the plan. Each plan has a fixed site-activation limit shown on the pricing page. Localhost, .local, .test, and .localhost domains are excluded from the site count when WP_DEBUG is true and the GUARDPRESS_DEV_MODE constant is defined as true in wp-config.php, so your local development site doesn’t burn a real slot. See the Installation and License Activation article for the full flow.
Can’t find what you’re looking for?
Our team responds to Pro license holders within one business day.