Overview
User Security Guard for WordPress protects who can sign in to your WordPress site. It counts failed logins per IP address, username and email, notices when many addresses attack one account, recognises bots and scripts, and scores every authentication request with one risk engine before it allows, flags or blocks it.
Every block stores a reason you can read, and a block lasts until an administrator removes it. Passwords, cookies and request bodies are never written to the database, and the plugin makes no external requests.
It does one job: there is no firewall, no file scanning and no hardening score. Pair it with a malware scanner if you need that too.
Why store owners choose it
It blocks the attacker, not your customers: bot signals alone can never block a normal browser, and administrator accounts are never auto-blocked unless you choose it.
Every block, log entry and alert shows the reason, the IP address and the account, so you can see why something was refused.
Blocks stay until you remove them, so the list is an honest record. Allowlist your own address, and use WP-CLI as the way back in.
Passwords, cookies and tokens are never stored, failed logins give one generic error, and the plugin never contacts an outside service.
It protects sign-ins only. There is no firewall, file scanning or hardening score, and nothing leaves your site.
Features
Login protection
Counts failed logins per IP address, username and email in a rolling window and scores each request with one risk engine. Defaults: suspicious at 5 failures, block at 10 per IP, 20 per username or email, within 60 minutes. Every limit is a setting.
Distributed attack detection
Catches slow attacks where dozens of addresses guess one account. When an account is targeted from 10 different IP addresses (the default), the account is blocked too.
Administrator protection
Administrators get a stricter limit of 5 failures, dedicated success and failure logging, and a guard rail: an administrator account is never auto-blocked unless you switch that on.
Bot detection
Looks at request frequency, missing browser headers, automation user agents and sustained hammering. All bot signals together are capped below the block threshold, so a normal browser is never blocked on bot grounds alone.
XML-RPC protection
Blocks XML-RPC with a generic 403 by default and blocks an address that keeps hammering it. You can allow XML-RPC, and separately allow authentication through it, for Jetpack or the mobile app.
Default username traps
A login attempt with admin, administrator, root or test that is not an account on your site is stronger evidence than a wrong password. A few of them block the address; a name that is a real account is never treated this way.
Exploit scanner blocking
Counts requests that answer 404 for /.env, /.git/config, wp-config.php.bak, phpmyadmin, web shells and database dumps. Five in 10 minutes blocks sign-ins from that address. Visitors still see your normal 404 page.
Email sign-in code
Optional. Emails a one-time code when someone signs in from an unrecognised browser, on every sign-in form, for the roles you tick. A sign-in that would skip the code gets no login cookie. Includes a test email button and a trusted-browser cookie.
WooCommerce sign-in
Detected automatically. Wrong passwords on My Account and the checkout login are counted, scored and blocked like wp-login.php. Viewing My Account or browsing the shop is never scored.
Country rule
Optional. Refuse sign-ins from chosen countries, or from every country you do not choose, using the country header your CDN or host adds, such as Cloudflare CF-IPCountry. There is no GeoIP database to download.
Blocks and allowlist
Blocked IPs and Blocked Users screens with View, Unblock, Make permanent and Delete, plus an Allowlist for exact IPs, CIDR ranges and 10.0.0.* shorthand. Optional automatic release after N hours, off by default.
Logs, dashboard and alerts
A dashboard with status tiles and a 14-day chart, a dashboard widget, a filterable security log with 20 event types, and throttled email alerts for new blocks, targeted accounts, attack spikes and watched accounts.
How it works
- 1
Install and activate
Upload the plugin and activate it. It creates its tables, seeds the default settings and adds a User Security menu in wp-admin.
- 2
Allowlist your own address
Open Allowlist and add the IP address you work from, so a false positive can never lock you out.
- 3
Let it watch sign-ins
Failed logins, bots, default usernames, exploit probes and XML-RPC requests are scored, logged and blocked when they cross a limit. Ordinary page views do no database work.
- 4
Review and unblock
Open the Dashboard, Security Logs and Blocked screens to see every reason. Unblock anything that should not be there, or make a block permanent.
Screenshots & demo
Settings & configuration
Login Protection
LOGINSet the suspicious and block limits per IP, username and email, the account-attack IP count, the counting window (60 minutes) and the risk scores for suspicious (25) and block (80).
Administrator Protection
ADMINChoose the stricter limit for administrators and whether an administrator account may be blocked automatically. That option is off by default.
Default Usernames and Exploit Probing
RULESTurn each rule on or off and set how many attempts or probes block an address, and over how many minutes. Both are on by default.
Blocking Behaviour
BLOCKSAllow permanent blocks, release automatic blocks after a number of hours (0 means never), halve the limits for repeat offenders, and optionally refuse blocked addresses with a plain 403.
Reverse Proxies
PROXYTurn on Trust proxy headers and choose X-Forwarded-For, CF-Connecting-IP, X-Real-IP or True-Client-IP, so the plugin sees the visitor and not your CDN.
Notifications
ALERTSPick the email address, the roles to watch (administrator, editor, author and shop manager by default) and which events send an email. One email per type per repeat window.
Email Sign-in Code
CODEOff by default. Choose who is asked, the code lifetime (10 minutes), wrong codes allowed (5) and how long a browser is remembered (30 days).
Logging and Retention
LOGSChoose which events are recorded and how long log rows are kept, from 30 days to forever. The default is 90 days. Attempt rows are kept 30 days.
Requirements & installation
Who it is for
It suits site owners, agencies and WooCommerce stores that want login protection that does one job carefully, without a firewall, a malware scanner or a hardening score. It is a good fit for sites with customers or editors who sign in, and for sites that are being hit by password guessing.
Requirements
- WordPress 6.2 or later (tested up to 7.1)
- PHP 7.4 or later
- WooCommerce is optional; its sign-in form is protected when it is active
- Behind Cloudflare or another proxy, turn on Trust proxy headers and choose the header it sets
- Working email delivery, if you turn on the email sign-in code
Installation
- Download the plugin zip from your account.
- In WordPress, go to Plugins > Add New > Upload Plugin, choose the zip file and click Install Now.
- Activate the plugin. It creates its tables, seeds its default settings and adds a User Security menu.
- Open User Security > Allowlist and add your own IP address, so a false positive can never lock you out.
- Open the Dashboard and review Settings. The defaults work without changes.
Documentation & support
Frequently asked questions
Will it lock me out of my own site?
Not by default. Administrator accounts are never auto-blocked unless you switch that on, and allowlisting your own IP address removes the risk. If you are locked out anyway, run wp wpus unblock –account=your-login from the command line, or use password reset, which is never blocked.
How is this different from an all-in-one security plugin?
It does one thing. There is no file scanning, no firewall and no hardening score. It protects accounts and sign-ins; pair it with a malware scanner if you need that too.
Does it slow my site down?
No. On ordinary page views the plugin does no database work. Its queries run only on login, XML-RPC, REST authentication and application-password requests, and rate counters live in transients.
Why is XML-RPC blocked by default?
It is a legacy endpoint that amplifies credential stuffing and is almost never needed. If Jetpack, the mobile app or another tool uses it, turn it back on under Settings → XML-RPC.
Can bot signals block a real visitor?
No. All bot signals combined are capped below the block threshold, so a normal browser with normal headers is never blocked on bot grounds alone.
Does it work behind Cloudflare or a reverse proxy?
Yes, but you must tell it. Turn on Trust proxy headers and choose the header your proxy sets. It is off by default because those headers are easy to fake when there is no proxy in front.
Do blocks ever lift on their own?
Not by default. A block lasts until an administrator removes it. You can opt in to releasing automatic blocks after a number of hours. Blocks you make by hand and permanent blocks never lift on their own.
Does it protect the WooCommerce login form?
Yes, and it finds WooCommerce by itself. Wrong passwords on My Account and the checkout login are counted and blocked like wp-login.php. Browsing the shop is never scored. You can switch it off under Settings → WooCommerce sign-in.
Does it protect the REST API and application passwords?
Yes. A blocked IP address or account cannot authenticate with an application password, and every REST credential failure gets the same generic answer. Only requests that carry credentials are looked at.
How does the email sign-in code work?
It is optional and off by default. When on, it is asked on every sign-in form for the roles you tick, from a browser the plugin does not recognise. Because it can refuse a correct password when mail does not work, use the test email button first. wp wpus two-factor –disable is the way back in.
Does the exploit-probing rule block my visitors?
No. It only looks at requests WordPress already answered with a 404 for a known probe path, and the only consequence is a block on sign-ins from that address. Signed-in editors, allowlisted addresses and shared addresses such as a CDN edge are never counted.
Does it send data anywhere?
No. There is no external service, no tracking, no remote call and no licence server. Everything stays in your own database.
What happens when I delete the plugin?
Deactivating deletes nothing. Under Settings → Privacy, Delete plugin data on uninstall is ticked by default; when it is ticked, deleting the plugin removes its tables, options and transients. Untick it first to keep your block list and logs.
How do I get updates?
New versions are published under My Account → Downloads. Upload the new zip under Plugins → Add New → Upload Plugin and choose Replace current with uploaded. Your settings and data are kept.
How do I get support?
Email support@wpexpertshub.com with your order details and a description of the issue, and our team will help you.
Customer reviews
Thanks for your review!
It’s waiting for approval and will appear here soon. We’ll email you when it’s live.
Be the first to review it
Used User Security Guard for WordPress on your store? A short review helps other store owners decide — and tells us what to improve.