Free & open-source WordPress security · v1.17.3

Free WordPress Security Plugin with Malware Scanner & 2FA.

Hard Guard Security is a free WordPress security plugin with malware scanning, vulnerability detection, 2FA, brute-force login protection, audit logging and WordPress hardening — without subscriptions, license keys, developer telemetry or paid feature unlocks.

Local-first processing. Clearly disclosed external services are used only when configured or required by an enabled feature.
No telemetryLocal inventory matching
Local scannerFiles stay on your server
Free & open sourceNo license key or paid features
Multisite readyPer-site or network activation
Hard Guard Security feature overview
Complete visibility

One free WordPress security plugin. Six layers of protection.

Use only the modules your site needs. Each area is designed around clear controls, actionable events and documented recovery procedures.

Login protection & 2FA

Progressive lockouts, custom login URL, TOTP, email codes, recovery codes and role-based enforcement. Login rate limiting also protects standard WooCommerce My Account login forms.

Read documentation →

Audit Log & live visibility

Track security events, review active WordPress sessions and watch current visitors on demand without keeping a permanent traffic history.

Read documentation →

Malware scanner & quarantine

Run local file, database, integrity, permissions, vulnerability and suspicious server-rule checks. Review evidence before moving files into protected quarantine.

Read documentation →

GeoIP access control

Apply country allowlists or blocklists using country.is, with caching, safe failure and recovery exceptions.

Read documentation →

Application Password control

Control creation and use, log credential events and associate the last resolved IP with a credential.

Read documentation →

Hardening & recovery

SSL diagnostics, security headers, server-rule integrity with Auto-Heal, uploads protection, optional RSS/Atom feed disabling, emergency bypasses and safe configuration transfer.

Read documentation →
Authentication

Stop automated attacks without locking yourself out.

Progressive lockouts adapt to repeat failures while explicit client-IP sources, trusted-proxy validation, proxy diagnostics, recovery URLs and staged login-path changes help preserve administrator access.

  • IP, username or combined attempt counting
  • Role-enforced TOTP or email 2FA
  • Cloudflare Turnstile on supported login forms
  • Recovery codes and emergency access guidance
Login protection
Active
Failed attempts27
Active lockouts3
2FA coverage100%
Login blocked after progressive threshold2 min ago
TOTP verification completed11 min ago
New recovery codes generatedToday
Detection

Investigate files, database content, vulnerabilities and server rules.

File and optional database malware analysis stay on the WordPress server. Full and Automatic scans also compare installed Core, plugin and theme versions locally against a signed Hard Guard threat-intelligence database.

  • WordPress core file integrity and permissions checks
  • Optional read-only Database Malware Scanner for manual scans
  • Separate Vulnerable and Outdated findings
  • Suspicious .htaccess analysis and protected quarantine
Scanner
Last scan complete
Files checked12,481
Vulnerable2
Outdated5
Plugin version matches a known advisoryHigh
WordPress component update availableUpdate
Unexpected PHP file in uploadsHigh
Privacy focused

No telemetry.
Local security decisions.

Audit logs, scan results, inventory matching and quarantine data remain on the WordPress server. Active Sessions is read only when opened, and Live Traffic uses temporary on-demand state only while an administrator is watching. External connections, including the signed vulnerability feed, are documented and limited to the data required for each request.

Review privacy details
Local security recordsAudit, antispam and scanner information is stored in the site database or filesystem.
Country lookupOnly the resolved IP is sent to country.is when an active country rule requires it.
Optional TurnstileCloudflare verification is used only after the administrator enables and configures it.
Your mail providerNotifications and email 2FA use WordPress mail or administrator-configured SMTP.
Signed vulnerability feedHard Guard downloads threat intelligence without sending the site URL, installed inventory, versions, scan results, file paths or file contents.
Safe deployment

Configure deliberately. Recover confidently.

Security features can change authentication, access rules, server directives and files. Hard Guard Security documents the high-risk steps and provides recovery mechanisms.

Back up

Create and verify a complete backup before changing access or server-level settings.

Configure

Enable only the required modules and review every warning displayed in the admin panel.

Test

Use staging, a private browser and a separate administrator session to verify critical changes.

Monitor

Review Audit Log, alerts and scan findings rather than treating security as a one-time setup.

Product overview

See the complete security suite at a glance.

From authentication and activity monitoring to local file scanning, country controls and recovery, Hard Guard Security brings the essential workflows into one WordPress administration experience.

Compatibility

Clear requirements. No hidden platform dependency.

System requirements

WordPress
7.0 or newer · tested through 7.1
PHP
7.4 or newer
Encryption
Sodium or OpenSSL for secure storage of TOTP, SMTP and Turnstile secrets
Filesystem
Read access for scans; write access for quarantine and selected managed rules
Multisite
Supported

Optional connections

External services are contacted only by configured or explicitly requested functionality.

country.isCloudflare TurnstileWordPress mail / SMTPWordPress.org checksumsHard Guard signed vulnerability feed

See the privacy page for the data involved and the relevant trigger for each connection.

Recent releases

Actively maintained and transparently documented.

Version 1.17.3
  • Added optional Antispam protection for classic WooCommerce My Account registration and lost-password request forms.
  • Added a separate per-IP password-reset rate limit and extended Math CAPTCHA to protected registration and lost-password forms.
  • Clarified that Login protection also protects standard WooCommerce My Account login forms, while checkout and Store API flows remain untouched.
  • Updated compatibility testing through WordPress 7.1.
Version 1.17.2
  • Added an optional Math CAPTCHA for native WordPress comments and WooCommerce reviews with Off, Always and Only for suspicious visitors modes.
  • Suspicious mode uses recent local spam/reject history for the visitor IP and proximity to the configured comment rate limit without external CAPTCHA services.
  • Math challenges are signed, time-limited and validated server-side without exposing the expected answer in HTML or JavaScript.
Version 1.17.1
  • Improved the WordPress.org short description and feature headings to better highlight malware scanning, vulnerability scanning, 2FA, brute-force login protection, audit logging and hardening.
  • Updated the WordPress.org plugin display name to highlight Malware Scanner, 2FA and Login Protection while keeping the shorter Hard Guard Security name in WordPress administration.
  • Updated the plugin contact email shown in the administration footer to contact@wp-hard-guard.ma7.eu.
Version 1.17.0
  • Added read-only Active Sessions, loaded only when the Audit Log tab is opened.
  • Added lightweight on-demand Live Traffic that runs only while an administrator is watching and keeps no permanent traffic history.
  • Added an optional Data hiding control to disable public RSS and Atom feeds.

View the complete changelog →

FAQ

Questions before installation.

Hard Guard does not send telemetry, usage statistics, scan results, website content or the installed software inventory to the developer. When vulnerability-database updates are enabled, it downloads a signed feed from the Hard Guard website; that request can expose normal connection metadata such as the requesting IP and time, but it does not include the site URL, installed plugin/theme names or versions, scan results, file paths or file contents.

No. File scanning and optional Database Malware Scanner processing are performed on the WordPress server. Findings and quarantine files remain local.

No security product can provide that guarantee. Hard Guard Security reduces selected risks and improves visibility, but it does not replace updates, backups, secure hosting, a WAF or professional incident response.

Site-wide GeoIP access control fails open so an external lookup outage does not block the whole website. Antispam follows the unknown-country action selected by the administrator.

Yes. All included features are available without payment, a license key, a trial period or a quota. Donations are voluntary and do not unlock functionality.

Yes. It can be activated per site or network-wide and includes Multisite-aware settings, Audit Log aggregation and cleanup behavior. Review the documentation before network-wide deployment.

Download the free WordPress security plugin.

Download the complete free, open-source suite from GitHub. All included features are available without a license key, trial period or paid unlock.