{"id":335885,"date":"2026-07-12T17:20:17","date_gmt":"2026-07-12T17:20:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/isecure-guard\/"},"modified":"2026-09-17T02:19:33","modified_gmt":"2026-09-17T02:19:33","slug":"fpx-security-guard","status":"publish","type":"plugin","link":"https:\/\/si.wordpress.org\/plugins\/fpx-security-guard\/","author":23527249,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.1","stable_tag":"1.4.1","tested":"7.0.5","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"FPX Security Guard","header_author":"FreePDFtxt","header_description":"Complete security suite for WordPress \u2014 login protection, firewall headers, WordPress info hiding, and hardening tools.","assets_banners_color":"335495","last_updated":"2026-09-17 02:19:33","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wp.freepdftxt.com\/","header_author_uri":"https:\/\/wp.freepdftxt.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":215,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"mamuniu06","date":"2026-07-12 17:20:08","revision":3605035},"1.4.0":{"tag":"1.4.0","author":"mamuniu06","date":"2026-09-16 15:20:31","revision":3698876},"1.4.1":{"tag":"1.4.1","author":"mamuniu06","date":"2026-09-17 02:19:33","revision":3699446}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3698839,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3698839,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3698839,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3698839,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.4.0","1.4.1"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[2439,1174,15756,163531,600],"plugin_category":[54],"plugin_contributors":[271264],"plugin_business_model":[],"class_list":["post-335885","plugin","type-plugin","status-publish","hentry","plugin_tags-brute-force","plugin_tags-firewall","plugin_tags-login-protection","plugin_tags-malware-scan","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-mamuniu06","plugin_committers-mamuniu06"],"banners":{"banner":"https:\/\/ps.w.org\/fpx-security-guard\/assets\/banner-772x250.png?rev=3698839","banner_2x":"https:\/\/ps.w.org\/fpx-security-guard\/assets\/banner-1544x500.png?rev=3698839","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/fpx-security-guard\/assets\/icon-128x128.png?rev=3698839","icon_2x":"https:\/\/ps.w.org\/fpx-security-guard\/assets\/icon-256x256.png?rev=3698839","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>FPX Security Guard closes the openings attackers actually use, and does it without sending your site's data anywhere. There is no account to create and no cloud dashboard: everything runs on your own server.<\/p>\n\n<p><strong>What it does<\/strong><\/p>\n\n<ul>\n<li><strong>Login protection<\/strong> \u2014 limits failed login attempts per IP with a configurable lockout, shows generic errors that leak no hint about which half of the login was wrong, and hides a honeypot field that silently blocks bots.<\/li>\n<li><strong>Two-factor authentication<\/strong> \u2014 standard TOTP (Google Authenticator, Authy, 1Password and the rest). Users turn it on from their own profile, scan a QR code, and get ten one-time recovery codes. Works entirely offline.<\/li>\n<li><strong>Firewall<\/strong> \u2014 blocks SQL injection, XSS, path traversal and RCE patterns in the URL, POST body and cookies, plus known scanner tools and direct requests for sensitive files like .env, .git and wp-config.php.<\/li>\n<li><strong>Rate limiting<\/strong> \u2014 slows down request floods from a single address.<\/li>\n<li><strong>Security headers<\/strong> \u2014 X-Frame-Options, nosniff, Referrer-Policy, Permissions-Policy, and HSTS on HTTPS.<\/li>\n<li><strong>CAPTCHA<\/strong> \u2014 optional reCAPTCHA v2 or hCaptcha on the login and comment forms, using your own key pair.<\/li>\n<li><strong>Hardening<\/strong> \u2014 turns off XML-RPC and the built-in theme\/plugin file editor, removes the WordPress version from your pages, and blocks ?author=N enumeration and the public REST users endpoint.<\/li>\n<li><strong>Comment protection<\/strong> \u2014 honeypot and link limits.<\/li>\n<li><strong>IP allow and deny lists<\/strong> \u2014 trust or block specific addresses and IPv4 ranges. Allowed addresses bypass every other rule.<\/li>\n<li><strong>Reverse-proxy support<\/strong> \u2014 if your site sits behind Cloudflare or a load balancer, tell the plugin, and per-IP blocking acts on the visitor's real address instead of the proxy's. The settings screen shows you the address it currently sees so you can confirm it.<\/li>\n<li><strong>Overview<\/strong> \u2014 a checklist where each gap explains what it costs you and, where possible, is fixed with one click, next to a running count of what was actually blocked over the last seven days.<\/li>\n<\/ul>\n\n<p>On first use, one button switches on the settings suited to a typical site. It deliberately skips anything that could lock you out or interrupt publishing.<\/p>\n\n<h3>Upgrading to Pro<\/h3>\n\n<p>The free plugin keeps attackers out. Pro adds the tools for finding out whether anyone already got in, and for dealing with it: a malware scanner with one-click quarantine, core file integrity checking against WordPress.org's own checksums, a vulnerability scanner, scheduled scans with email alerts, live traffic monitoring, behavioural threat scoring, country blocking, AbuseIPDB reputation checks, auto-ban, a session manager, an activity log, new-device login alerts, a custom login URL, and an emergency lockdown button that expires on a timer so it can never strand you.<\/p>\n\n<p>Details at https:\/\/wp.freepdftxt.com\/security-guard\/<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin uses a few optional external services, all disabled unless you explicitly turn them on:<\/p>\n\n<p><strong>Geo Blocking<\/strong> (disabled by default) uses the free geo-location service ip-api.com to determine the country of a visitor's IP address.<\/p>\n\n<ul>\n<li><strong>What is sent:<\/strong> Only the visitor's IP address, and only when Geo Blocking is manually enabled and a visitor's country isn't already cached.<\/li>\n<li><strong>When:<\/strong> On the first request from a given IP; the result is cached locally for 24 hours.<\/li>\n<\/ul>\n\n<p>Service provider: ip-api.com \u2014 Terms: https:\/\/ip-api.com\/docs\/legal \u2014 Privacy: https:\/\/ip-api.com\/docs\/legal<\/p>\n\n<p><strong>Cloud Threat Intelligence<\/strong> (disabled by default, and inactive until you supply your own API key) checks a visitor's IP address against AbuseIPDB's abuse-confidence database.<\/p>\n\n<ul>\n<li><strong>What is sent:<\/strong> Only the visitor's IP address, sent together with your own AbuseIPDB API key, and only when you've entered a key and a visitor's IP isn't already cached.<\/li>\n<li><strong>When:<\/strong> On the first request from a given IP; the result is cached locally for 24 hours.<\/li>\n<\/ul>\n\n<p>Service provider: AbuseIPDB \u2014 Terms: https:\/\/www.abuseipdb.com\/legal \u2014 Privacy: https:\/\/www.abuseipdb.com\/legal<\/p>\n\n<p><strong>Malware Scanner's VirusTotal cross-check<\/strong> (disabled by default, and inactive until you supply your own API key) looks up a file's SHA-256 hash on VirusTotal \u2014 a hash, not the file itself.<\/p>\n\n<ul>\n<li><strong>What is sent:<\/strong> Only a SHA-256 hash (a one-way fingerprint that cannot be reversed into the original file) of files already flagged by the local scanner, plus a small sample (up to 15) of recently-modified files, sent together with your own VirusTotal API key.<\/li>\n<li><strong>When:<\/strong> Only during a malware scan (manual or scheduled) with this feature enabled and a key configured.<\/li>\n<li>Your actual file content is never uploaded or transmitted anywhere.<\/li>\n<\/ul>\n\n<p>Service provider: VirusTotal (a Google subsidiary) \u2014 Terms: https:\/\/support.virustotal.com\/hc\/en-us\/articles\/115002145529-Terms-of-Service \u2014 Privacy: https:\/\/support.virustotal.com\/hc\/en-us\/articles\/115002168385-Privacy-Policy<\/p>\n\n<p><strong>Vulnerability Scanner<\/strong> and <strong>Core File Integrity Check<\/strong> read WordPress's own built-in update-check data and, when you run a scan, query the same official api.wordpress.org endpoints WordPress core itself already uses (the same request the \"Check Again\" button on the Updates screen makes, and the public core-checksums endpoint). No plugin-specific data is sent beyond what WordPress core itself already sends for update checks.<\/p>\n\n<p><strong>CAPTCHA<\/strong> (disabled by default, and inactive until you choose a provider and enter both keys) shows a bot challenge on the login and\/or comment form using either Google reCAPTCHA v2 or hCaptcha, and verifies the response server-side with that provider.<\/p>\n\n<ul>\n<li><strong>What is sent:<\/strong> The visitor's CAPTCHA response token and IP address, sent to whichever provider (Google or hCaptcha) you've configured, only on form submission.<\/li>\n<li><strong>When:<\/strong> Only when a visitor submits the login or comment form with CAPTCHA enabled for that form.<\/li>\n<\/ul>\n\n<p>Service providers: Google reCAPTCHA \u2014 Terms: https:\/\/policies.google.com\/terms \u2014 Privacy: https:\/\/policies.google.com\/privacy \u00b7 hCaptcha \u2014 Terms: https:\/\/www.hcaptcha.com\/terms \u2014 Privacy: https:\/\/www.hcaptcha.com\/privacy<\/p>\n\n<p>If none of the above features are enabled, the plugin makes no external requests whatsoever.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>fpx-security-guard-pro<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or upload the zip via Plugins \u2192 Add New \u2192 Upload Plugin.<\/li>\n<li>Activate the plugin through the Plugins menu.<\/li>\n<li>Configure options under Settings \u2192 FPX Security Guard.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"i%20enabled%20custom%20login%20url%20and%20now%20i%20can%27t%20find%20my%20login%20page.\"><h3>I enabled Custom Login URL and now I can't find my login page.<\/h3><\/dt>\n<dd><p>Your new login address is whatever you set as the \"Login Slug\" under Settings \u2014 e.g. yoursite.com\/your-slug\/. It's shown right on the settings page once enabled. If you forget it entirely, add <code>define( 'FPXSG_LOGIN_BYPASS', true );<\/code> to wp-config.php to restore normal wp-login.php access, log in, check the slug under Settings, then remove the line.<\/p><\/dd>\n<dt id=\"i%20enabled%20emergency%20lockdown%20and%20now%20i%20can%27t%20get%20back%20in.\"><h3>I enabled Emergency Lockdown and now I can't get back in.<\/h3><\/dt>\n<dd><p>Three rescue paths, in order of ease:<\/p>\n\n<ol>\n<li><strong>wp-login.php always works<\/strong> \u2014 the lockdown never blocks the login page itself, so sign in as an administrator and it will let you straight through.<\/li>\n<li><strong>It expires automatically<\/strong> \u2014 every lockdown has a maximum duration (set when you enabled it, up to 72 hours) and turns itself off.<\/li>\n<li><strong>Server access (site owners)<\/strong> \u2014 add this line to your wp-config.php file: <code>define( 'FPXSG_LOCKDOWN_BYPASS', true );<\/code> \u2014 this immediately lifts the lockdown for everyone. Remove the line once you're back in.<\/li>\n<\/ol><\/dd>\n<dt id=\"i%27m%20locked%20out%20of%20two-factor%20authentication.%20how%20do%20i%20get%20back%20in%3F\"><h3>I'm locked out of two-factor authentication. How do I get back in?<\/h3><\/dt>\n<dd><p>There are three rescue paths, in order of ease:<\/p>\n\n<ol>\n<li><strong>Recovery codes<\/strong> \u2014 enter one of your saved one-time recovery codes in the Authentication Code field on the login screen.<\/li>\n<li><strong>Ask an administrator<\/strong> \u2014 any admin can open Users \u2192 your profile and reset your 2FA with one click. You can then log in with just your password and set 2FA up again.<\/li>\n<li><strong>Server access (site owners)<\/strong> \u2014 add this line to your wp-config.php file: <code>define( 'ISG_DISABLE_2FA', true );<\/code> \u2014 this temporarily bypasses 2FA for all logins. Log in, reset your 2FA from your profile, then REMOVE the line again. Because it requires file access, only someone who controls the server can use it.<\/li>\n<\/ol><\/dd>\n<dt id=\"will%20this%20conflict%20with%20other%20security%20plugins%3F\"><h3>Will this conflict with other security plugins?<\/h3><\/dt>\n<dd><p>Avoid running multiple firewall\/login-limit plugins at once \u2014 features may overlap.<\/p><\/dd>\n<dt id=\"i%20use%20jetpack%20or%20a%20mobile%20app%20to%20publish.\"><h3>I use Jetpack or a mobile app to publish.<\/h3><\/dt>\n<dd><p>Disable the \"Disable XML-RPC\" option in settings.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Fixed: the admin screen loaded without its stylesheet on some installs.<\/li>\n<li>Fixed: the \"See pricing\" link pointed at a page that no longer exists.<\/li>\n<li>Changed: clearer notice when an older 1.0.x copy of the plugin is still active.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New: reverse-proxy support. On a site behind Cloudflare or a load balancer, every visitor previously appeared to share the proxy's IP address, which quietly broke rate limiting, lockouts, auto-ban and geo blocking. Settings \u2192 \"How visitors reach your site\" now shows the address the plugin currently sees, so you can confirm it at a glance. Forwarded headers are only trusted once you opt in, and for Cloudflare only when the request genuinely arrives from Cloudflare's network.<\/li>\n<li>New: first-run setup. One button applies the settings suited to a typical site, skipping anything that could lock you out.<\/li>\n<li>New: the Overview tab now reports what was actually blocked over the last seven days, and every failing check explains the consequence and offers a one-click fix instead of just a red cross.<\/li>\n<li>New: Live Traffic can log errors only, and has a hard ceiling on stored rows so a flood cannot fill your database between hourly cleanups.<\/li>\n<li>Changed: redesigned the admin screens \u2014 grouped settings, switch controls, and a sticky save bar.<\/li>\n<li>Changed: \"AI Threat Detection\" is now \"Behavioural Threat Scoring\". The feature is unchanged; the old name overstated what it does.<\/li>\n<\/ul>\n\n<h4>1.3.2<\/h4>\n\n<ul>\n<li>Live Traffic Monitor: redesigned again in a clean, light modern style (icon-badged stat cards, indigo accent, proper toggle switch, refined table) that fits naturally into wp-admin instead of a dark floating panel.<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Live Traffic Monitor: redesigned as a dark \"security console\" dashboard \u2014 live stats strip (unique IPs, error count, logged-in hits), instant filter box, colored status\/method badges, country flag emoji, and animated incoming rows.<\/li>\n<li>Security: sensitive query-string values (license keys, passwords, tokens, API keys) are now masked before being stored in \u2014 or displayed from \u2014 the traffic log.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Malware Scanner: expanded pattern list (more webshell signatures, hex\/chr obfuscation, dynamic call-from-request, downloader patterns).<\/li>\n<li>Malware Scanner: optional VirusTotal cross-check \u2014 hashes (never file content) of flagged findings and a small sample of recently-modified files are checked against VirusTotal's antivirus engines.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New: Custom Login URL \u2014 hides wp-login.php behind a secret slug.<\/li>\n<li>New: IP Whitelist \/ Blacklist \u2014 trusted IPs bypass all blocking; blacklisted IPs are denied immediately.<\/li>\n<li>New: Auto-Ban Repeat Offenders \u2014 automatically bans IPs that repeatedly trip other blocking features.<\/li>\n<li>New: Activity Log \u2014 audit trail of settings, user\/role, plugin\/theme changes, and logins.<\/li>\n<li>New: Core File Integrity Check \u2014 verifies core files against official WordPress.org checksums.<\/li>\n<li>New: Security Score Dashboard \u2014 one-glance checklist of your site's security posture (now the default landing tab).<\/li>\n<li>New: Login Notification Emails \u2014 optional email on every login, not just new devices.<\/li>\n<li>New: CAPTCHA \u2014 optional reCAPTCHA v2 \/ hCaptcha on login and\/or comment forms.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: Malware Scanner \u2014 flags PHP-executable files in uploads and backdoor\/obfuscation patterns in plugins\/themes, with one-click quarantine.<\/li>\n<li>New: Vulnerability Scanner \u2014 checks core\/plugin\/theme versions, PHP version, debug output, HTTPS, and other hardening gaps.<\/li>\n<li>New: Scheduled Scan \u2014 runs both scanners automatically (daily\/weekly) with email alerts.<\/li>\n<li>New: Geo Blocking \u2014 Country Block now supports an allow-list mode, in addition to block-list.<\/li>\n<li>New: Live Traffic Monitor \u2014 real-time request log in wp-admin.<\/li>\n<li>New: AI Threat Detection \u2014 local heuristic risk scoring for suspicious requests.<\/li>\n<li>New: Device Fingerprinting \u2014 email alert on a never-seen-before login device.<\/li>\n<li>New: Cloud Threat Intelligence \u2014 optional AbuseIPDB integration with your own API key.<\/li>\n<li>New: Session Manager \u2014 view and force-end active login sessions per user.<\/li>\n<li>New: Emergency Lockdown \u2014 one-click, auto-expiring site lockdown with a wp-config.php escape hatch.<\/li>\n<li>Settings page reorganized into tabs: Settings, Malware Scanner, Vulnerability Scanner, Live Traffic, Threat Log, Sessions, Emergency Lockdown.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Login protection: per-IP attempt limits, lockouts, honeypot, generic error messages.<\/li>\n<li>Two-Factor Authentication (TOTP): QR-code setup, recovery codes, low-code warnings, works offline.<\/li>\n<li>DDoS\/flood protection via per-IP rate limiting.<\/li>\n<li>Firewall: malicious query blocking and modern security headers.<\/li>\n<li>Country blocking (optional, via ip-api.com with local caching).<\/li>\n<li>Comment spam protection: honeypot and link limits.<\/li>\n<li>Daily critical-file change detection with admin and email alerts.<\/li>\n<li>Hardening: XML-RPC off, file editor off, version hiding, user-enumeration blocking.<\/li>\n<li>Bundled QRCode.js by davidshimjs (MIT license, GPL-compatible) for local QR rendering.<\/li>\n<\/ul>","raw_excerpt":"Login protection, two-factor authentication, firewall and hardening for WordPress. Nothing leaves your server \u2014 no account, no cloud dashboard.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/335885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=335885"}],"author":[{"embeddable":true,"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/mamuniu06"}],"wp:attachment":[{"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=335885"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=335885"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=335885"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=335885"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=335885"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/si.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=335885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}