# GuardPress Documentation

> GuardPress documentation: setup guides for the firewall, malware scanner, 2FA, brute-force protection, file integrity monitor, and 25+ security features.

- Canonical: <https://royalplugins.com/support/guardpress/>
- Last updated: 2026-09-26
- HTML version: <https://royalplugins.com/support/guardpress/>

---

## 🚀 Start Here

Just installed GuardPress? These four articles take you from zero to fully protected in about 30 minutes.

[★

Start Here

Quick Start: Your First 30 Minutes

A 5-step walkthrough that gets you from freshly installed to fully protected. Three modules turn on automatically at activation; two need your input.](https://royalplugins.com/support/guardpress/quick-start/)

[Setup

Installation & License Activation

Upload the ZIP, activate the license from my.royalplugins.com, run the Cloudflare pre-flight check.](https://royalplugins.com/support/guardpress/installation-activation/)
[Reference

System Requirements

Minimum and recommended WordPress / PHP / MySQL versions, plus hosting-tier and multisite notes.](https://royalplugins.com/support/guardpress/system-requirements/)
[Setup

Two-Factor Authentication Setup

Enable 2FA the safe way. Install an authenticator app first, save backup codes, then flip the toggle.](https://royalplugins.com/support/guardpress/two-factor-authentication-setup/)
[Reference

Understanding the Security Dashboard

Score composition, four stat boxes explained, and how to raise a score that isn’t 100.](https://royalplugins.com/support/guardpress/understanding-the-security-dashboard/)
[Reference

Pre-Launch Security Checklist

35 items grouped by who owns each: what GuardPress automates, what your host handles, what you verify manually.](https://royalplugins.com/support/guardpress/pre-launch-security-checklist/)
[Reference

WordPress Dashboard Widget

The at-a-glance widget on wp-admin’s main Dashboard. Color states and score thresholds.](https://royalplugins.com/support/guardpress/wordpress-dashboard-widget/)

## 🚨 I’m Locked Out

Emergency recovery paths for the most common lockout scenarios. Bookmark this section before you need it.

[⚡

Start Here

The Lockout Recovery Playbook

Three flavours cover almost every lockout. Match your symptom to the right recovery doc in under a minute.](https://royalplugins.com/blog/wordpress-locked-out-recovery/)

[2FA

2FA Recovery

Lost your authenticator? Backup codes and the wp-config disable path when everything else fails.](https://royalplugins.com/blog/wordpress-2fa-recovery-guide/)
[Lockdown

Emergency Lockdown Recovery

Emergency Lockdown is on and you were signed out. The wp-config constant that unblocks you.](https://royalplugins.com/support/guardpress/emergency-lockdown-recovery/)
[Login URL

Forgot Custom Login URL

You enabled a custom login slug and can’t remember it. Find it via wp-config, DB query, or SFTP.](https://royalplugins.com/blog/wordpress-forgot-login-url/)
[White Screen

White Screen Fix

The white-screen-of-death that follows a bad update. Get your admin back with SFTP + wp-config.](https://royalplugins.com/blog/wordpress-white-screen-fix/)
[Malware

Malware Removal Guide

You confirmed a malware detection is real. Steps to isolate, remove, and prevent reinfection.](https://royalplugins.com/blog/wordpress-malware-removal-guide/)

## 🛡️ Firewall & Threat Response

Understanding what your firewall is blocking, tuning false positives, and telling real threats from noise.

[Popular

Spotting Spoofed AI Crawler Attacks

Attackers wearing GPTBot / ChatGLM / YouBot User-Agents. Three real alerts and the two independent checks that catch every spoof.](https://royalplugins.com/support/guardpress/spotting-spoofed-ai-crawler-attacks/)
[Reference

Firewall Overview

Protection types (SQL injection, XSS, LFI/RFI, bad-bot, rate limiting), rule engine, and the administrator auto-whitelist.](https://royalplugins.com/support/guardpress/firewall-overview/)
[Firewall

Firewall False Positives

Real users getting blocked. How to identify the rule and whitelist the specific pattern.](https://royalplugins.com/blog/wordpress-firewall-false-positives/)
[IP

IP Blocking & Whitelisting

The three-list model (Whitelist, Blacklist, Active Lockouts) and how they interact.](https://royalplugins.com/support/guardpress/ip-blocking-whitelisting/)
[Cloudflare

Country Blocking + Cloudflare Real-IP

The Cloudflare real-IP resolver pre-flight check before any IP-based rule is trustworthy.](https://royalplugins.com/support/guardpress/country-blocking-cloudflare-real-ip/)
[Hardening

Uploads PHP Execution Block

Shut down the “upload a shell via a bad file-type check” attack class at the config layer.](https://royalplugins.com/support/guardpress/uploads-php-execution-block-setup/)
[AI Agents

MCP / OAuth Clients Getting Locked Out

AI-agent traffic tripping brute-force rate limits. Whitelist patterns for Claude, n8n, Make.](https://royalplugins.com/support/guardpress/mcp-oauth-apps-locked-out/)

## 🔐 Login & Access Control

Everything about sign-in security: brute-force lockouts, CAPTCHA, 2FA enforcement, and login notifications.

[Reference

Login Security Features

Index of all nine login-security features with links to each setup guide.](https://royalplugins.com/support/guardpress/login-security-features/)
[Setup

Brute-Force Protection Setup

Threshold, lockout duration, and permanent-ban escalation. What the defaults are and when to tune them.](https://royalplugins.com/support/guardpress/brute-force-protection-setup/)
[CAPTCHA

CAPTCHA Blocks WC / MemberPress Login

The classic “customer says they can’t log in” fix. CAPTCHA widget not rendering on custom login forms.](https://royalplugins.com/support/guardpress/captcha-blocks-woocommerce-memberpress-login/)
[CAPTCHA

Cloudflare Turnstile Setup

Site key, secret key, widget placement. Turnstile as a replacement for reCAPTCHA on the login form.](https://royalplugins.com/support/guardpress/cloudflare-turnstile-setup/)
[2FA

Per-Role 2FA Enforcement Setup

Require 2FA for Administrators without forcing it on Subscribers. 7-day grace period for existing users.](https://royalplugins.com/support/guardpress/per-role-2fa-enforcement-setup/)
[Alerts

Sign-In Notifications Setup

Get an email every time an administrator signs in. High-signal alert for high-value accounts.](https://royalplugins.com/support/guardpress/sign-in-notifications-setup/)

## 📊 Monitoring & Alerts

Tune what GuardPress emails you about, and how to investigate each type of finding.

[Alerts

Quieting the Alert Email Flood

Throttle window, category-based toggles, and the auto-allowlist for verified crawlers.](https://royalplugins.com/support/guardpress/quieting-security-alert-emails/)
[Malware

Malware Scanner Explained

Signature matching, behavior heuristics, three post-scan actions, and the expected self-detection behavior.](https://royalplugins.com/support/guardpress/malware-scanner-explained/)
[File Integrity

File Integrity Monitor Explained

Hash-based file monitoring for core, plugins, themes, and uploads. What triggers an alert.](https://royalplugins.com/support/guardpress/file-integrity-monitor-explained/)
[File Integrity

File Integrity Alert Investigation

Triage flow when the FIM widget flags unacknowledged changes. Legitimate updates vs actual tampering.](https://royalplugins.com/support/guardpress/file-integrity-alert-investigation/)
[Vulnerability

Vulnerability Scanner Explained

What the scanner is checking, CISA KEV feed integration, and how to clear findings.](https://royalplugins.com/support/guardpress/outdated-software-check-explained/)
[Database

Database Security Checks Explained

Common WP DB attack surface: exposed DB\_USER, weak admin passwords, tables from removed plugins.](https://royalplugins.com/support/guardpress/database-security-checks-explained/)
[Vulnerability

Core Vulnerability Protection

How GuardPress handles known CVEs in WordPress core, themes, and plugins.](https://royalplugins.com/support/guardpress/core-vuln-protection/)
[Uptime

Uptime Monitoring Setup

Hourly WP-Cron check with rate-limited alerts. Catches WordPress fatal errors that keep the server up but the site down.](https://royalplugins.com/support/guardpress/uptime-monitoring-setup/)
[Spam

Spam Protection Setup

Comment-form and login-form spam filter with no third-party service. Honeypot + time-based + Unicode keyword detection.](https://royalplugins.com/support/guardpress/spam-protection-setup/)

## ⚙️ Reference

Deep dives on individual features and settings for readers who want the full picture.

[Hardening

WordPress Hardening Options

Every hardening toggle: XMLRPC block, WP version hiding, DISALLOW\_FILE\_EDIT, security headers, and the smaller cumulative wins.](https://royalplugins.com/support/guardpress/wordpress-hardening-options/)
[Migration

Backup Module → SiteVault

The backup module has been retired. Migration path to SiteVault for continued backup coverage.](https://royalplugins.com/support/guardpress/backup-module-retired-sitevault-migration/)

## ❓ Frequently Asked Questions

The most common questions we get from GuardPress users.

What is on by default when I activate GuardPress?

Seven modules turn on automatically at activation: the Firewall, Brute-Force Protection, the Malware Scanner, File Integrity Monitor, XMLRPC Protection, WP Version Hiding, and File-Editing Lockdown. Two-Factor Authentication and Email Alerts are off by default because they need your input (a phone for 2FA, an email address and working SMTP for alerts). Uptime Monitoring and custom Security Headers are also off by default and can be enabled after the first-week review.

How long does GuardPress take to fully set up?

About 30 minutes end to end. The 2FA setup is the longest step (5–10 minutes to install an authenticator app, scan the QR code, save backup codes, and test signing back in). Email alerts take 5 minutes to enable plus however long it takes to install an SMTP delivery plugin if your host doesn’t run its own. Everything else is either already on or a one-click confirm. Follow [Quick Start](https://royalplugins.com/support/guardpress/quick-start/) for the exact order.

Real users can’t log in — what happened?

Almost always one of two things. Either the CAPTCHA / Cloudflare Turnstile widget isn’t rendering on the login form they’re using (WooCommerce my-account, MemberPress, a page-builder login widget), or their IP tripped brute-force because they use a corporate NAT that a colleague also uses. See [CAPTCHA Blocks WooCommerce/MemberPress Login](https://royalplugins.com/support/guardpress/captcha-blocks-woocommerce-memberpress-login/) for the first case, and whitelist the shared IP for the second.

I run behind Cloudflare — anything I need to do differently?

Yes, one important thing. Without configuring the Cloudflare real-IP resolver, every request looks like it’s coming from Cloudflare’s IPs, so brute-force lockouts trigger against Cloudflare and geographic rules never work. See [Country Blocking and the Cloudflare Real-IP Gotcha](https://royalplugins.com/support/guardpress/country-blocking-cloudflare-real-ip/). This is a pre-flight check before doing anything IP-based.

I use Claude / ChatGPT / n8n to manage my site — their traffic keeps getting blocked

AI-agent traffic is high-frequency and predictable, so it tends to trip brute-force rate limits fast. Whitelist their known IP ranges or use Application Passwords with a dedicated user for the agent. See [MCP / OAuth Clients Getting Locked Out](https://royalplugins.com/support/guardpress/mcp-oauth-apps-locked-out/) for the pattern.

Does GuardPress slow down my site?

Marginally. The firewall runs on every request at `plugins_loaded` priority 20 (before WordPress loads most of core), but the rule check is optimized to a single regex sweep. Malware and vulnerability scans run in the background via WP-Cron, not during page requests. On typical shared hosting, GuardPress adds approximately 5–20ms to admin page loads and effectively zero to frontend visitors.

Will GuardPress break my caching (Cloudflare, ForgeCache, WP Rocket)?

No. GuardPress is fully compatible with Cloudflare, [ForgeCache](https://royalplugins.com/forgecache/), WP Rocket, server-level FastCGI cache, LiteSpeed, and other cache layers. PHP sessions are scoped to `wp-login.php` only, so the rest of your site caches normally. If you were previously on an older GuardPress version that predates this scoping, purge your cache once after updating so any old `no-store` responses stop being served.

Can I use GuardPress alongside Wordfence, Solid Security, or Sucuri?

We don’t recommend it. Two firewalls fighting over the same request, two CAPTCHAs stacked on the same login form, and two file-integrity scans rotating the same cron lock cause real conflicts that make both plugins behave worse than either would alone. Pick one and deactivate the others.

If you’re switching to GuardPress from another security plugin, deactivate the old one first, then activate GuardPress and walk through **GuardPress → Settings** to enable equivalent protections. Follow [Quick Start](https://royalplugins.com/support/guardpress/quick-start/) for the recommended enable order.

Can I use the same license on multiple sites?

Depends on the plan. Each plan has a fixed site-activation limit shown on the [pricing page](https://royalplugins.com/guardpress/pricing/). Localhost, `.local`, `.test`, and `.localhost` domains are excluded from the site count when `WP_DEBUG` is true and the `GUARDPRESS_DEV_MODE` constant is defined as true in `wp-config.php`, so your local development site doesn’t burn a real slot. See the [Installation and License Activation](https://royalplugins.com/support/guardpress/installation-activation/) article for the full flow.

### Can’t find what you’re looking for?

Our team responds to Pro license holders within one business day.

[Contact Support →](https://royalplugins.com/contact/)
