WordPress Plugin v1.0.0 Last updated

User Security Guard for WordPress

Stop brute-force logins and bots, and block attackers by IP or account

WordPress
$99One-time paymentUpdates & support included
01

Overview

User Security Guard for WordPress protects who can sign in to your WordPress site. It counts failed logins per IP address, username and email, notices when many addresses attack one account, recognises bots and scripts, and scores every authentication request with one risk engine before it allows, flags or blocks it.

Every block stores a reason you can read, and a block lasts until an administrator removes it. Passwords, cookies and request bodies are never written to the database, and the plugin makes no external requests.

It does one job: there is no firewall, no file scanning and no hardening score. Pair it with a malware scanner if you need that too.

02

Why store owners choose it

It blocks the attacker, not your customers: bot signals alone can never block a normal browser, and administrator accounts are never auto-blocked unless you choose it.

Every block, log entry and alert shows the reason, the IP address and the account, so you can see why something was refused.

Blocks stay until you remove them, so the list is an honest record. Allowlist your own address, and use WP-CLI as the way back in.

Passwords, cookies and tokens are never stored, failed logins give one generic error, and the plugin never contacts an outside service.

It protects sign-ins only. There is no firewall, file scanning or hardening score, and nothing leaves your site.

03

Features

Login protection

Counts failed logins per IP address, username and email in a rolling window and scores each request with one risk engine. Defaults: suspicious at 5 failures, block at 10 per IP, 20 per username or email, within 60 minutes. Every limit is a setting.

Distributed attack detection

Catches slow attacks where dozens of addresses guess one account. When an account is targeted from 10 different IP addresses (the default), the account is blocked too.

Administrator protection

Administrators get a stricter limit of 5 failures, dedicated success and failure logging, and a guard rail: an administrator account is never auto-blocked unless you switch that on.

Bot detection

Looks at request frequency, missing browser headers, automation user agents and sustained hammering. All bot signals together are capped below the block threshold, so a normal browser is never blocked on bot grounds alone.

XML-RPC protection

Blocks XML-RPC with a generic 403 by default and blocks an address that keeps hammering it. You can allow XML-RPC, and separately allow authentication through it, for Jetpack or the mobile app.

Default username traps

A login attempt with admin, administrator, root or test that is not an account on your site is stronger evidence than a wrong password. A few of them block the address; a name that is a real account is never treated this way.

Exploit scanner blocking

Counts requests that answer 404 for /.env, /.git/config, wp-config.php.bak, phpmyadmin, web shells and database dumps. Five in 10 minutes blocks sign-ins from that address. Visitors still see your normal 404 page.

Email sign-in code

Optional. Emails a one-time code when someone signs in from an unrecognised browser, on every sign-in form, for the roles you tick. A sign-in that would skip the code gets no login cookie. Includes a test email button and a trusted-browser cookie.

WooCommerce sign-in

Detected automatically. Wrong passwords on My Account and the checkout login are counted, scored and blocked like wp-login.php. Viewing My Account or browsing the shop is never scored.

Country rule

Optional. Refuse sign-ins from chosen countries, or from every country you do not choose, using the country header your CDN or host adds, such as Cloudflare CF-IPCountry. There is no GeoIP database to download.

Blocks and allowlist

Blocked IPs and Blocked Users screens with View, Unblock, Make permanent and Delete, plus an Allowlist for exact IPs, CIDR ranges and 10.0.0.* shorthand. Optional automatic release after N hours, off by default.

Logs, dashboard and alerts

A dashboard with status tiles and a 14-day chart, a dashboard widget, a filterable security log with 20 event types, and throttled email alerts for new blocks, targeted accounts, attack spikes and watched accounts.

04

How it works

  1. 1

    Install and activate

    Upload the plugin and activate it. It creates its tables, seeds the default settings and adds a User Security menu in wp-admin.

  2. 2

    Allowlist your own address

    Open Allowlist and add the IP address you work from, so a false positive can never lock you out.

  3. 3

    Let it watch sign-ins

    Failed logins, bots, default usernames, exploit probes and XML-RPC requests are scored, logged and blocked when they cross a limit. Ordinary page views do no database work.

  4. 4

    Review and unblock

    Open the Dashboard, Security Logs and Blocked screens to see every reason. Unblock anything that should not be there, or make a block permanent.

05

Screenshots & demo

  • WordPress login security plugin dashboard with blocked IPs, failed logins and a 14-day activity chart Dashboard
  • Security dashboard with the latest security events, administrator activity and next steps Dashboard: events
  • Security log listing every failed login, block and administrator event with its risk level and reason Security Logs
  • Blocked IPs screen with the reason, attempt count and Unblock, Make permanent and Delete actions Blocked IPs
  • Blocked Users screen with a form to block an account by username or email address Blocked Users
  • Allowlist screen for trusted IP addresses and ranges that skip every blocking rule Allowlist
  • Login protection and administrator protection settings with failed-attempt limits and risk scores Settings: login and admin protection
  • Settings for bot detection, WooCommerce sign-in, default usernames, exploit probing and XML-RPC Settings: bots, WooCommerce, XML-RPC
  • Settings for blocking behaviour, the country rule and logging Settings: blocking, country, logging
  • Settings for email notifications, reverse proxies and email sign-in codes Settings: notifications and codes
  • Email sign-in code options with role selection, code lifetime and trusted-browser settings, plus privacy Settings: sign-in codes and privacy
  • Tools screen with emergency mode, log retention and WP-CLI lockout recovery steps Tools
  • Tools screen with the attempt counters, what the plugin stores and detected system information Tools: system information
06

Settings & configuration

Login Protection

LOGIN

Set the suspicious and block limits per IP, username and email, the account-attack IP count, the counting window (60 minutes) and the risk scores for suspicious (25) and block (80).

Administrator Protection

ADMIN

Choose the stricter limit for administrators and whether an administrator account may be blocked automatically. That option is off by default.

Default Usernames and Exploit Probing

RULES

Turn each rule on or off and set how many attempts or probes block an address, and over how many minutes. Both are on by default.

Blocking Behaviour

BLOCKS

Allow permanent blocks, release automatic blocks after a number of hours (0 means never), halve the limits for repeat offenders, and optionally refuse blocked addresses with a plain 403.

Reverse Proxies

PROXY

Turn on Trust proxy headers and choose X-Forwarded-For, CF-Connecting-IP, X-Real-IP or True-Client-IP, so the plugin sees the visitor and not your CDN.

Notifications

ALERTS

Pick the email address, the roles to watch (administrator, editor, author and shop manager by default) and which events send an email. One email per type per repeat window.

Email Sign-in Code

CODE

Off by default. Choose who is asked, the code lifetime (10 minutes), wrong codes allowed (5) and how long a browser is remembered (30 days).

Logging and Retention

LOGS

Choose which events are recorded and how long log rows are kept, from 30 days to forever. The default is 90 days. Attempt rows are kept 30 days.

07

Requirements & installation

Who it is for

It suits site owners, agencies and WooCommerce stores that want login protection that does one job carefully, without a firewall, a malware scanner or a hardening score. It is a good fit for sites with customers or editors who sign in, and for sites that are being hit by password guessing.

Requirements

  • WordPress 6.2 or later (tested up to 7.1)
  • PHP 7.4 or later
  • WooCommerce is optional; its sign-in form is protected when it is active
  • Behind Cloudflare or another proxy, turn on Trust proxy headers and choose the header it sets
  • Working email delivery, if you turn on the email sign-in code

Installation

  1. Download the plugin zip from your account.
  2. In WordPress, go to Plugins > Add New > Upload Plugin, choose the zip file and click Install Now.
  3. Activate the plugin. It creates its tables, seeds its default settings and adds a User Security menu.
  4. Open User Security > Allowlist and add your own IP address, so a false positive can never lock you out.
  5. Open the Dashboard and review Settings. The defaults work without changes.
08

Documentation & support

09

Frequently asked questions

Will it lock me out of my own site?

Not by default. Administrator accounts are never auto-blocked unless you switch that on, and allowlisting your own IP address removes the risk. If you are locked out anyway, run wp wpus unblock –account=your-login from the command line, or use password reset, which is never blocked.

How is this different from an all-in-one security plugin?

It does one thing. There is no file scanning, no firewall and no hardening score. It protects accounts and sign-ins; pair it with a malware scanner if you need that too.

Does it slow my site down?

No. On ordinary page views the plugin does no database work. Its queries run only on login, XML-RPC, REST authentication and application-password requests, and rate counters live in transients.

Why is XML-RPC blocked by default?

It is a legacy endpoint that amplifies credential stuffing and is almost never needed. If Jetpack, the mobile app or another tool uses it, turn it back on under Settings → XML-RPC.

Can bot signals block a real visitor?

No. All bot signals combined are capped below the block threshold, so a normal browser with normal headers is never blocked on bot grounds alone.

Does it work behind Cloudflare or a reverse proxy?

Yes, but you must tell it. Turn on Trust proxy headers and choose the header your proxy sets. It is off by default because those headers are easy to fake when there is no proxy in front.

Do blocks ever lift on their own?

Not by default. A block lasts until an administrator removes it. You can opt in to releasing automatic blocks after a number of hours. Blocks you make by hand and permanent blocks never lift on their own.

Does it protect the WooCommerce login form?

Yes, and it finds WooCommerce by itself. Wrong passwords on My Account and the checkout login are counted and blocked like wp-login.php. Browsing the shop is never scored. You can switch it off under Settings → WooCommerce sign-in.

Does it protect the REST API and application passwords?

Yes. A blocked IP address or account cannot authenticate with an application password, and every REST credential failure gets the same generic answer. Only requests that carry credentials are looked at.

How does the email sign-in code work?

It is optional and off by default. When on, it is asked on every sign-in form for the roles you tick, from a browser the plugin does not recognise. Because it can refuse a correct password when mail does not work, use the test email button first. wp wpus two-factor –disable is the way back in.

Does the exploit-probing rule block my visitors?

No. It only looks at requests WordPress already answered with a 404 for a known probe path, and the only consequence is a block on sign-ins from that address. Signed-in editors, allowlisted addresses and shared addresses such as a CDN edge are never counted.

Does it send data anywhere?

No. There is no external service, no tracking, no remote call and no licence server. Everything stays in your own database.

What happens when I delete the plugin?

Deactivating deletes nothing. Under Settings → Privacy, Delete plugin data on uninstall is ticked by default; when it is ticked, deleting the plugin removes its tables, options and transients. Untick it first to keep your block list and logs.

How do I get updates?

New versions are published under My Account → Downloads. Upload the new zip under Plugins → Add New → Upload Plugin and choose Replace current with uploaded. Your settings and data are kept.

How do I get support?

Email support@wpexpertshub.com with your order details and a description of the issue, and our team will help you.

10

Customer reviews

Write a review

User Security Guard for WordPress

Your rating

Only your first name and last initial are shown. Your email is never published — use your purchase email to get the “Verified customer” badge.

Loading…

Every review is checked by our team before it’s published.

Be the first to review it

Used User Security Guard for WordPress on your store? A short review helps other store owners decide — and tells us what to improve.