BACK TO DIRECTORY

FPX Security Guard

by freepdftxt

0.0
(0 ratings)

FPX Security Guard closes the openings attackers actually use, and does it without sending your site’s data anywhere. There is no account to create and no cloud dashboard: everything runs on your own server.

What it does

  • Login protection — limits failed login attempts per IP with a configurable lockout, shows generic errors that leak no hint about which half of the login was wrong, and hides a honeypot field that silently blocks bots.
  • Two-factor authentication — standard TOTP (Google Authenticator, Authy, 1Password and the rest). Users turn it on from their own profile, scan a QR code, and get ten one-time recovery codes. Works entirely offline.
  • Firewall — blocks SQL injection, XSS, path traversal and RCE patterns in the URL, POST body and cookies, plus known scanner tools and direct requests for sensitive files like .env, .git and wp-config.php.
  • Rate limiting — slows down request floods from a single address.
  • Security headers — X-Frame-Options, nosniff, Referrer-Policy, Permissions-Policy, and HSTS on HTTPS.
  • CAPTCHA — optional reCAPTCHA v2 or hCaptcha on the login and comment forms, using your own key pair.
  • Hardening — turns off XML-RPC and the built-in theme/plugin file editor, removes the WordPress version from your pages, and blocks ?author=N enumeration and the public REST users endpoint.
  • Comment protection — honeypot and link limits.
  • IP allow and deny lists — trust or block specific addresses and IPv4 ranges. Allowed addresses bypass every other rule.
  • Reverse-proxy support — if your site sits behind Cloudflare or a load balancer, tell the plugin, and per-IP blocking acts on the visitor’s real address instead of the proxy’s. The settings screen shows you the address it currently sees so you can confirm it.
  • Overview — a checklist where each gap explains what it costs you and, where possible, is fixed with one click, next to a running count of what was actually blocked over the last seven days.

On first use, one button switches on the settings suited to a typical site. It deliberately skips anything that could lock you out or interrupt publishing.

Upgrading to Pro

The free plugin keeps attackers out. Pro adds the tools for finding out whether anyone already got in, and for dealing with it: a malware scanner with one-click quarantine, core file integrity checking against WordPress.org’s own checksums, a vulnerability scanner, scheduled scans with email alerts, live traffic monitoring, behavioural threat scoring, country blocking, AbuseIPDB reputation checks, auto-ban, a session manager, an activity log, new-device login alerts, a custom login URL, and an emergency lockdown button that expires on a timer so it can never strand you.

Details at https://wp.freepdftxt.com/security-guard/

External Services

This plugin uses a few optional external services, all disabled unless you explicitly turn them on:

Geo Blocking (disabled by default) uses the free geo-location service ip-api.com to determine the country of a visitor’s IP address.

  • What is sent: Only the visitor’s IP address, and only when Geo Blocking is manually enabled and a visitor’s country isn’t already cached.
  • When: On the first request from a given IP; the result is cached locally for 24 hours.

Service provider: ip-api.com — Terms: https://ip-api.com/docs/legal — Privacy: https://ip-api.com/docs/legal

Cloud Threat Intelligence (disabled by default, and inactive until you supply your own API key) checks a visitor’s IP address against AbuseIPDB’s abuse-confidence database.

  • What is sent: Only the visitor’s IP address, sent together with your own AbuseIPDB API key, and only when you’ve entered a key and a visitor’s IP isn’t already cached.
  • When: On the first request from a given IP; the result is cached locally for 24 hours.

Service provider: AbuseIPDB — Terms: https://www.abuseipdb.com/legal — Privacy: https://www.abuseipdb.com/legal

Malware Scanner’s VirusTotal cross-check (disabled by default, and inactive until you supply your own API key) looks up a file’s SHA-256 hash on VirusTotal — a hash, not the file itself.

  • What is sent: Only a SHA-256 hash (a one-way fingerprint that cannot be reversed into the original file) of files already flagged by the local scanner, plus a small sample (up to 15) of recently-modified files, sent together with your own VirusTotal API key.
  • When: Only during a malware scan (manual or scheduled) with this feature enabled and a key configured.
  • Your actual file content is never uploaded or transmitted anywhere.

Service provider: VirusTotal (a Google subsidiary) — Terms: https://support.virustotal.com/hc/en-us/articles/115002145529-Terms-of-Service — Privacy: https://support.virustotal.com/hc/en-us/articles/115002168385-Privacy-Policy

Vulnerability Scanner and Core File Integrity Check read WordPress’s own built-in update-check data and, when you run a scan, query the same official api.wordpress.org endpoints WordPress core itself already uses (the same request the “Check Again” button on the Updates screen makes, and the public core-checksums endpoint). No plugin-specific data is sent beyond what WordPress core itself already sends for update checks.

CAPTCHA (disabled by default, and inactive until you choose a provider and enter both keys) shows a bot challenge on the login and/or comment form using either Google reCAPTCHA v2 or hCaptcha, and verifies the response server-side with that provider.

  • What is sent: The visitor’s CAPTCHA response token and IP address, sent to whichever provider (Google or hCaptcha) you’ve configured, only on form submission.
  • When: Only when a visitor submits the login or comment form with CAPTCHA enabled for that form.

Service providers: Google reCAPTCHA — Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy · hCaptcha — Terms: https://www.hcaptcha.com/terms — Privacy: https://www.hcaptcha.com/privacy

If none of the above features are enabled, the plugin makes no external requests whatsoever.

Plugin Details

Active Installs
0
Total Downloads
193
Version
1.4.1
Requires WP
5.8
Requires PHP
7.4
Tested Up To
7.0.4
Added
2026-07-12
Last Updated
2026-09-17 2:19am GMT

Ratings

5
0
4
0
3
0
2
0
1
0