BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off β†’
Aegis User Guard icon
Actively maintained Tested with WP 7.1 #61 in login security

Aegis User Guard

WordPress identity policies for password rules, login lockouts, two-factor authentication, IP controls, and Administrator oversight.

Active installs<10New
Downloads Β· 30d114β€’ 0% vs prev. 30d
Ratingβ€”0 reviews
Health score64/100Good
All-time downloads104Since Sep 2026
Support resolvedβ€”No recent threads
RequiresWP 6.2PHP 7.4+
Downloads Β· 7d43β–Ό -49.4% week over week
Our verdict

Solid choice

Aegis User Guard is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 weeks ago, and scores 64/100 on our health check.

  • Actively developed β€” last update 2 weeks ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

122537Sep 25Sep 30Oct 6
Yesterday5
Daily average (1y)10
Peak day50Sep 26, 2026
Last 12 months114

Download spikes usually follow a new release β€” each site that auto-updates counts as a download.

Rankings

Where Aegis User Guard stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
login security >100 4,221 Best login security plugins β†’
password policy >100 2,464 Best password policy plugins β†’
security >100 10,000 Best security plugins β†’
two factor authentication >100 448 Best two factor authentication plugins β†’
user management >100 7,991 Best user management plugins β†’

About Aegis User Guard

From the official readme Β· v1.3.2

Description

Aegis User Guard is a single, self-contained security console that adds the identity-policy controls most sites end up needing eventually: password expiration and complexity, inactivity lockout, brute-force protection, two-factor authentication, an IP allow/block list, and full oversight of every Administrator account. It does not replace WordPress’s login system or session handling; it layers policy and visibility on top of it, and every control can be switched off independently.

Everything lives on one native-feeling admin screen, organized into tabs:

  • Core controls β€” the identity policies below, each with its own on/off switch.
  • Recently added β€” a quick pulse of the newest accounts and their status.
  • Email notifications β€” the shared template and recipient list for Administrator security alerts.
  • Administrator directory β€” every Administrator, their last sign-in, active sessions, and one-click actions.
  • Access & IPs β€” a manual IP allow/block list.
  • Checklist β€” a read-only audit of common WordPress hardening gaps, with one-click fixes where Aegis can apply them.
  • Activity log β€” a chronological, exportable record of every security event Aegis observed.

Identity policies

  • Password freshness β€” prompt users to rotate their password after a configurable age (default 180 days).
  • Password complexity β€” require a minimum length and, optionally, mixed case, a number, and a symbol, enforced on password reset and profile changes.
  • Inactive account lockout β€” pause login access after a configurable period of inactivity (default 90 days).
  • Brute-force lockout β€” lock an account and its originating network after repeated failed sign-ins, independent of whether the attempted username exists.
  • Two-factor authentication (TOTP) β€” self-service setup from any user’s own profile (manual-entry key, no third-party QR service), with one-time backup codes and an option to require it for all Administrators.
  • REST API user-list restriction β€” block anonymous requests to /wp-json/wp/v2/users so usernames cannot be enumerated, while leaving authenticated requests untouched.
  • Administrator alerts β€” independently alert all or selected Administrators when a user is created, signs in, changes username, changes email address, or changes password. Administrator promotions remain covered as well.
  • New-device sign-in alerts β€” email a user when their own account signs in from an IP address not seen before.

Administrator oversight

  • A live directory of every Administrator account: last sign-in, status, active session count, and CSV export.
  • Manual Pause access / Reactivate access for any account, with native WordPress session termination.
  • A “Force password reset” action that requires a new password on next login and signs the account out everywhere.
  • A one-click “Sign out everywhere” action to end every active session for an account immediately.
  • A pending-Administrator review queue: new or newly promoted Administrators are blocked from signing in until an existing Administrator grants access.

Access control

  • A manual IP allow/block list β€” block a network outright, or exempt a trusted IP from brute-force lockouts.
  • Individual failed-sign-in logging, alongside every lockout, pause, and policy change, in the Activity log.

Hardening checklist

A read-only audit covering file-editing access, debug output exposure, HTTPS on wp-admin, a default “admin” username, the two-factor requirement, REST API user enumeration, and pending core/plugin updates β€” each with a plain-language fix, and a direct link into the relevant Aegis setting where Aegis can apply it itself.

Everything native

Aegis stores its data in standard WordPress options and user meta, uses native password-reset and session-termination APIs, and never introduces its own authentication layer. Disabling or deleting the plugin returns the site to stock WordPress behavior.

Features

  • Configurable password-expiration policy (default 180 days).
  • Configurable password-complexity policy (length, case, number, symbol).
  • Configurable inactivity lockout (default 90 days).
  • Configurable brute-force lockout, per account and per originating network.
  • Optional two-factor authentication (TOTP) with one-time backup codes, self-service from each user’s own profile.
  • Optional REST API restriction to stop anonymous username enumeration via /wp-json/wp/v2/users.
  • Event-level Administrator email alerts for account creation, successful sign-in, username, email, and password changes, with selectable recipients and a shared editable template.
  • Optional email alert to a user on sign-in from a new IP address.
  • Pending-Administrator review queue for new or newly promoted Administrators.
  • Administrator directory with last sign-in, live session counts, and CSV export.
  • “Force password reset” and “Sign out everywhere” actions for any account.
  • Security status column and manual Pause access / Reactivate access on the Users screen.
  • Manual IP allow/block list.
  • Read-only security hardening checklist with one-click fixes.
  • Chronological, searchable, exportable Activity log.
  • A single top-level, native-feeling WordPress admin screen β€” no external APIs are required for Aegis’s security controls, and the optional Gravatar avatar lookup is documented below.

External services

This plugin optionally uses the Gravatar service, operated by Automattic, to display profile images for Administrators in the Administrator directory. Gravatar is not required for Aegis’s security controls; the plugin displays its bundled placeholder image if a Gravatar image is unavailable.

When an Administrator directory is opened and WordPress has a Gravatar URL for an Administrator, the visitor’s browser requests the image from secure.gravatar.com (or the Gravatar URL returned by the site’s WordPress configuration). The request URL contains a hash of the Administrator’s normalized email address so Gravatar can select the associated image. The browser also sends normal HTTP request information, such as its IP address and user-agent, to the service. The request is made only to load that optional avatar image; Aegis does not send the Administrator’s raw email address to Gravatar.

Gravatar is provided by Automattic. See Gravatar’s Terms of Service and Privacy Policy for information about the service’s terms and data handling.

Installation

  1. Upload the aegis-user-guard folder to wp-content/plugins/, or upload the plugin ZIP from Plugins > Add New > Upload Plugin.
  2. Activate Aegis User Guard from the Plugins screen.
  3. Open the Aegis User Guard menu item in the main admin sidebar to review the default policies and adjust them to your site.
  4. Use the Administrator directory tab, or Users > All Users, for per-account status and manual access controls.

Frequently asked questions

Does this replace WordPress’s login system?

No. Aegis adds policy checks and visibility on top of native WordPress authentication, session handling, and password reset β€” it does not introduce its own login form, session store, or password hashing.

What happens to existing accounts when I activate the plugin?

Nothing changes immediately. Accounts are initialized with current timestamps on their next successful login, so no one is locked out by policies that were not in effect when they last signed in.

Does two-factor authentication use a third-party service?

No. Setup uses a manual-entry secret key compatible with any standard TOTP authenticator app (Google Authenticator, Authy, 1Password, etc.); no QR code service or external API is involved.

What does β€œSign out everywhere” actually do?

It destroys every active WordPress session token for that account using the native session-token API, the same mechanism behind core’s own β€œLog Out Everywhere Else.”

Does disabling a policy delete its saved settings?

No. Turning a rule’s β€œEnforce rule” switch off keeps its configured value (days, attempts, minimum length, etc.) saved and simply stops it from being evaluated at login until you turn it back on.

Is any data sent off-site?

Aegis stores its settings and activity log in standard WordPress options and user meta on your own database. Email notifications are sent through your site’s normal wp_mail() configuration. If the Administrator directory displays a Gravatar avatar, the visitor’s browser also requests that image from Gravatar as described in the External services section above.

Changelog

Documents the optional Gravatar avatar lookup used by the Administrator directory.

1.3.2

  • Documented the optional Gravatar avatar service, its data transfer conditions, and its legal links.

1.3.1

  • Removed admin notice suppression so native WordPress and other plugin notices remain visible.
  • Removed inline admin style and script output and tightened request-validation ordering.
  • Updated plugin contributor metadata for the WordPress.org owner account.

1.3.0

  • Refactored the plugin bootstrap and core class structure for WordPress coding standards compliance.
  • Added complete PHPDoc coverage and improved translation annotations across the PHP codebase.
  • Improved output escaping, native WordPress hook handling, and standards-compliant input processing.
  • Consolidated the packaged HTML documentation and retina screenshots under the documentation folder.

1.2.0

  • Added WPML compatibility metadata for translating saved Administrator email subject and message settings.
  • Localized dynamic admin JavaScript dialogs, validation messages, pagination, notification emails, and CSV exports.
  • Added locale-aware notification email markup and completed the translation coverage for the plugin’s runtime interface.

1.1.0

  • Added five independently configurable Administrator alert events for account creation, successful sign-in, username changes, email changes, and password changes.
  • Extended the Email notifications template and recipient settings to every Administrator alert event.
  • Added a responsive event-selection interface to Core controls.

1.0.0

  • Initial release.

Full changelog on WordPress.org β†’

Screenshots

Core controls for password, inactivity, brute-force, and two-factor policies.
Core controls for password, inactivity, brute-force, and two-factor policies.
Chronological Activity log with searchable security events.
Chronological Activity log with searchable security events.
Access IP rules for allow/block policy management.
Access IP rules for allow/block policy management.
Configurable Administrator email notifications and recipients.
Configurable Administrator email notifications and recipients.
Users status view with account access and security state.
Users status view with account access and security state.
Recently added Administrator accounts awaiting review.
Recently added Administrator accounts awaiting review.
Administrator directory with sign-in, session, and access details.
Administrator directory with sign-in, session, and access details.
Read-only security hardening checklist with actionable fixes.
Read-only security hardening checklist with actionable fixes.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own β€” no account needed.

Active installs badge Rating badge Health score badge

Best Aegis User Guard alternatives

All login security plugins β†’
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention Limit Login Attempts Security WordPress login security with brute force protection, Two-factor authentication (2FA/MFA)… by WPChef 1M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (1.5K) 2 weeks ago 91
2 All-In-One Security (AIOS) – Security and Firewall All-In-One Security (AIOS) – Security and Firewall Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy… by David Anderson / Team Updraft 1M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.7 (1.7K) 3 weeks ago 92
3 Defender Security – Malware Scanner, Login Security & Firewall Defender Security WordPress security plugin with malware scanner, IP blocking, audit logs, antivirus scans… by WPMU DEV 80K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (334) 1 week ago 91
4 BulletProof Security BulletProof Security WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup… by AITpro 20K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (674) 2 months ago 89
5 DoLogin Security DoLogin Security Login security: KeyLockr SSO scan login, 2FA, passwordless login, Cloudflare Turnstile… by WPDO 8K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.5 (13) 2 months ago 82
6 Entryway – WP Login & Logout Redirect Entryway – WP Login & Logout Redirect Redirect users to any URL after login or logout with per-role rules, a searchable audit… by Md Aminur Islam 6K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (5) 3 months ago 74
7 Melapress Login Security Melapress Login Security Enforce WordPress login and password security policies to protect user accounts and prevent… by Melapress 3K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (20) 3 weeks ago 91
8 SiteLock Security – WP Hardening, Login Security & Malware Scans SiteLock Security Free, lightweight WordPress security. Harden your site with login protection & 2FA, see… by SiteLock 1K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 3.4 (14) 4 months ago 61
9 Power Captcha reCAPTCHA Power Captcha reCAPTCHA Protect WordPress/WooCommerce/Contact Form 7 forms from spam, brute-force attacks, fake… by Denis AlemΓ‘n 900+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.3 (4) 3 months ago 55
10 Block wp-login Block wp-login Blocks direct access to wp-login.php and replaces it with a secret login URL to reduce… by Oliver Campion 600+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.7 (9) 2 months ago 66

FAQ

Aegis User Guard: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org Β· checked Oct 7, 2026

Is Aegis User Guard free?

Yes. Aegis User Guard is free to download and use from the official WordPress.org plugin directory.

Is Aegis User Guard safe to use in 2026?

Aegis User Guard is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 weeks ago, and scores 64/100 on our health check.

How many websites use Aegis User Guard?

Aegis User Guard is active on <10 WordPress websites and has been downloaded 104 times since it launched in September 2026. It was downloaded 114 times in the last 30 days.

Does Aegis User Guard work with WordPress 7.1?

Yes. The developer has tested Aegis User Guard up to WordPress 7.1.3, the latest release. It requires WordPress 6.2 or newer.

What PHP version does Aegis User Guard need?

Aegis User Guard requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Aegis User Guard last updated?

The latest version, 1.3.2, was released on September 26, 2026 (2 weeks ago).

Who makes Aegis User Guard?

Aegis User Guard is developed and maintained by Ahnaf007.

What are the best alternatives to Aegis User Guard?

The most popular alternatives to Aegis User Guard are Limit Login Attempts Securi… (1M+ installs), All-In-One Security (AIOS) (1M+ installs) and Defender Security (80K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages β€” with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org β€” no credit card
Sarah is here to help!
Hi there! πŸ‘‹ Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! πŸ‘‹ Need help finding what you're looking for?

We'll use this to continue our conversation

Just now βœ“ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.