
FPX Security Guard closes the openings attackers actually use, and does it without sending your site’s data anywhere. There is no account to create and no cloud dashboard: everything runs on your own server.
What it does
On first use, one button switches on the settings suited to a typical site. It deliberately skips anything that could lock you out or interrupt publishing.
The free plugin keeps attackers out. Pro adds the tools for finding out whether anyone already got in, and for dealing with it: a malware scanner with one-click quarantine, core file integrity checking against WordPress.org’s own checksums, a vulnerability scanner, scheduled scans with email alerts, live traffic monitoring, behavioural threat scoring, country blocking, AbuseIPDB reputation checks, auto-ban, a session manager, an activity log, new-device login alerts, a custom login URL, and an emergency lockdown button that expires on a timer so it can never strand you.
Details at https://wp.freepdftxt.com/security-guard/
This plugin uses a few optional external services, all disabled unless you explicitly turn them on:
Geo Blocking (disabled by default) uses the free geo-location service ip-api.com to determine the country of a visitor’s IP address.
Service provider: ip-api.com — Terms: https://ip-api.com/docs/legal — Privacy: https://ip-api.com/docs/legal
Cloud Threat Intelligence (disabled by default, and inactive until you supply your own API key) checks a visitor’s IP address against AbuseIPDB’s abuse-confidence database.
Service provider: AbuseIPDB — Terms: https://www.abuseipdb.com/legal — Privacy: https://www.abuseipdb.com/legal
Malware Scanner’s VirusTotal cross-check (disabled by default, and inactive until you supply your own API key) looks up a file’s SHA-256 hash on VirusTotal — a hash, not the file itself.
Service provider: VirusTotal (a Google subsidiary) — Terms: https://support.virustotal.com/hc/en-us/articles/115002145529-Terms-of-Service — Privacy: https://support.virustotal.com/hc/en-us/articles/115002168385-Privacy-Policy
Vulnerability Scanner and Core File Integrity Check read WordPress’s own built-in update-check data and, when you run a scan, query the same official api.wordpress.org endpoints WordPress core itself already uses (the same request the “Check Again” button on the Updates screen makes, and the public core-checksums endpoint). No plugin-specific data is sent beyond what WordPress core itself already sends for update checks.
CAPTCHA (disabled by default, and inactive until you choose a provider and enter both keys) shows a bot challenge on the login and/or comment form using either Google reCAPTCHA v2 or hCaptcha, and verifies the response server-side with that provider.
Service providers: Google reCAPTCHA — Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy · hCaptcha — Terms: https://www.hcaptcha.com/terms — Privacy: https://www.hcaptcha.com/privacy
If none of the above features are enabled, the plugin makes no external requests whatsoever.