GuardForge
Security hardening, brute-force protection, two-factor login, file-integrity checks and a tamper-evident audit log. No account required.
Solid choice
GuardForge is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 4 hours ago, and scores 64/100 on our health check.
- Actively developed — last update 4 hours ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where GuardForge stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| audit log | >100 |
| firewall | >100 |
| login protection | >100 |
| security | >100 |
| two factor authentication | >100 |
About GuardForge
From the official readme · v1.4.0Description
GuardForge hardens your WordPress site against common attacks without requiring an account or an API key. It applies proven hardening rules on activation, monitors for brute-force login attempts, protects your own account with two-factor authentication, checks your files against the build wordpress.org actually published, and keeps an audit log whose rows are hash-chained — so a line edited or deleted after the fact is detectable rather than deniable.
Nothing in the Free list below is capped, timed, or unlocked by paying. One thing in it reaches the network, it is off until you switch it on, and External services below describes it exactly: the file-integrity scan asks wordpress.org what your WordPress and your wordpress.org plugins are supposed to contain, so it can tell you when a file is not part of the official build — it sends a version number and a plugin slug, never your site’s address and nothing about your content.
Free
- Hardening score — twenty-one checks of your own installation, scored 0-100, with each row stating exactly how many points it is worth and linking to the screen that fixes it. No outbound request: every check reads this site.
- Staging / development mode — GuardForge notices when it is running on a copy of your site and stops acting on the world: lockouts are recorded but not enforced, and no notification e-mail, alert or firewall rule leaves the copy. Nothing that can switch it on survives a database copy, so a dump from staging can never disarm your live site.
- Login brute-force protection with per-IP lockout and automatic unblock
- Two-factor authentication for your own account — TOTP, a login challenge, and single-use recovery codes. Every logged-in user can reach the 2FA screen and protect their own login, not just administrators: editors, authors and shop managers hold accounts worth phishing too. The enrolment QR is drawn on your own server: no image is fetched from anywhere, so your secret never leaves the site.
- File integrity against the official checksums — off until you switch the monitor on in Settings, because the comparison asks wordpress.org for the hashes. Once on: every core file, and every plugin hosted on wordpress.org, is compared against the hashes wordpress.org publishes for that exact release. So the screen can say more than “this changed since yesterday”: it separates files that are official, modified, missing, and not in the official build at all — which is what a backdoor looks like, and which no scan-to-scan comparison can ever see, because a shell that was already there when the baseline was taken looks like every other unchanged file.
- A premium or custom plugin, and any theme, has no published hashes anywhere. Those files are marked “no reference” and stay on the scan-to-scan comparison. They are never counted as clean — a tick beside something nothing checked is worse than no tick at all.
- A core file that is modified or missing is named on the screen with its verdict, next to a link to Dashboard → Updates: re-installing WordPress is what puts core files back, and this plugin does not write into wp-admin or wp-includes itself.
- Audit log, hash-chained — it records logins, failed attempts, option changes, plugin and theme activity, and user and role changes, and every row carries the hash of the row before it. Press “Verify chain” and the table is walked: change one field on one row and that row no longer matches its own hash; delete a row and the next one points at a hash nothing in the table produces. Neither is visible in the table itself, which is the point — an audit log an intruder can tidy up afterwards is decoration. Reading and verifying are free; only streaming it out as CSV is a Pro feature.
- Security hardening: disable XML-RPC, remove version headers, protect wp-config.php via .htaccess
- Content-Security-Policy header — your policy, sent report-only by default so a wrong rule cannot break the site
- IP management — allowlist, lift a lockout, login-log browser
- Spam-bot honeypot on the comment form
- WordPress core file protection rules (.htaccess)
Pro
GuardForge Pro is a separate add-on (installed alongside this free plugin) that unlocks:
- Two-factor enforcement policy — require every administrator to be enrolled before they can use the admin
- Alerts to Telegram, Slack and a signed webhook — a card per channel rather than a box of JSON, each with its own minimum severity, a “Send test” that really sends through the same dispatcher, and a digest you can leave immediate or batch hourly or daily. Quiet hours hold the ordinary traffic until morning, while a lockdown or a malware finding goes straight through them. Bot tokens, Slack URLs and HMAC secrets are encrypted on your own site and the form never prints one back — it shows the last four characters and nothing else
- Lockdown mode — one switch that closes registration, comments, XML-RPC and anonymous REST writes. It can also throw itself, if you ask it to: twenty different addresses locked out inside ten minutes, or a finding from the malware scanner. An automatic lockdown lifts itself after an hour, writes both ends to the audit log, e-mails you, and never fires on a copy of your site
- Vulnerability database — published advisories for WordPress, your plugins and your themes, matched against what is installed here, in real time as they are issued
- Patch by update — off until you switch it on: when an advisory names the version that fixes it and WordPress is offering an update that reaches it, GuardForge installs that update on cron, one plugin per run, with an allow list and a deny list, and tells you by e-mail and in the audit log. Never on a staging copy, never on a plugin directory that is a symbolic link, and never twice in a day after a failure
- Geo-IP blocking — block or allowlist whole countries
- Cloudflare Firewall Sync — push locked IPs into your own Cloudflare zone, with your own scoped token. Cloudflare’s published list of edge addresses is refreshed daily, IPv6 included, so a site behind a newer edge does not quietly start logging, counting and geo-locating every visitor as the edge itself
- WAF managed ruleset — in-PHP firewall covering SQLi, LFI, XSS, and PHP injection
- Malware scanner — heuristics + signature-based scanning across wp-content
- AI Threat Analytics — batched incident summary and recommendations via forge-api
- Audit log export (CSV, streamed — a year of log does not have to fit in memory)
GuardForge is part of the Forge Suite. Learn more and get Pro at https://avakode.com.
External services
This plugin reaches wordpress.org, and nothing else. Activating it contacts nobody and schedules nothing that would — the file-integrity monitor is off on a fresh install, and switching it on is what puts the daily lookup on the schedule. The only outgoing request it ever makes is the checksum lookup below, it happens only while the file-integrity monitor is switched on, and it asks a public catalogue a question that names nothing of yours.
wordpress.org, for the file-integrity scan. Off until you switch the monitor on in GuardForge > Settings. Then once a day, and whenever you press “Run scan now”, GuardForge asks api.wordpress.org for the checksum list of your WordPress version and locale, and downloads.wordpress.org for the checksum list of each installed plugin it hosts (its folder name and version number). Those are public catalogues: the request carries the version, the locale and the slug, and nothing else — not your site’s address, not your user list, not your content, not a licence key. Answers are cached, and one scan makes at most ten requests, so a site with sixty plugins is covered over a few days rather than in one burst. Switch the file-integrity monitor off in Settings and none of this happens.
- Endpoints: https://api.wordpress.org/core/checksums/1.0/ · https://downloads.wordpress.org/plugin-checksums/
- WordPress.org privacy policy: https://wordpress.org/about/privacy/ (wordpress.org publishes no separate terms page for this lookup)
Nothing about your site is sent on a schedule or in the background. A fresh install makes no request at all and schedules none; with the file-integrity monitor switched on it has one daily request — the checksum lookup, while that monitor is on — and it asks a public catalogue a question that names nothing of yours. Switch the file-integrity monitor off and this plugin makes no outgoing request at all.
Uninstalling
Deleting GuardForge always removes one thing: your two-factor enrolments. That table holds TOTP shared secrets and single-use recovery codes — credential material — and once the plugin is gone nothing can use them, while a database that outlives the plugin gets backed up, exported and copied to staging. Reinstalling means enrolling again, which takes half a minute; leaving shared secrets behind has no upside at all.
Everything else stays by default: your login log, file-integrity snapshots, audit trail and settings all survive a delete, so removing the plugin by accident does not take your history with it. If you want a clean slate, tick Delete GuardForge data on uninstall in GuardForge → Settings before you delete.
The hardening score
GuardForge → Hardening score works out one number from twenty-one checks of this installation. Every check reads your own site — options, constants, your .htaccess, your user list, WordPress’s own update transients. Nothing is fetched from anywhere, which is also why the score cannot verify a header by fetching your homepage: the score makes no external request of any kind, and that promise is worth more than the extra check. The three things in the free plugin that reach the network — the “Explain” button, the integrity scan’s checksum lookup and the daily advisory download — are all described above, and none of them is the score: it reads what the last scan already worked out and asks nobody anything.
A check that cannot apply here leaves the sum entirely rather than scoring zero. An nginx site has no .htaccess to write, so the two .htaccess checks go to “does not apply” and the remaining checks grow to fill the hundred. Marking a correctly configured site down for lacking an Apache file would be theatre.
Every check sits in one of four weight buckets, and there are no others. 12 is the control whose absence is how sites actually get taken over; 8 is a direct route in, or the loss of the evidence that one was used; 5 is reconnaissance and exposure that shortens somebody else’s work; 2 is worth doing, cheap, and not what the incident report will name. The full table:
https— 12two_factor_admins— 12updates_pending— 12debug_display— 8xmlrpc— 8brute_force— 8file_edit— 8integrity_baseline— 8admin_username— 5user_enumeration— 5rest_restricted— 5security_headers— 5csp— 5sensitive_files— 5audit_log— 5hide_version— 2directory_listing— 2login_captcha— 2pingback— 2bad_useragents— 2notifications— 2
The points a row advertises are the points you actually gain: the weights above are shared out over the checks that apply to your site so that they add up to exactly one hundred, and the headline is the sum of what those rows earned. With the Pro add-on installed and licensed, one more row joins the same list — installed plugins and themes with a published advisory, at 12 — and the shares are worked out again around it. Without the add-on that row does not exist and nothing on the screen mentions it.
The public badge
Off unless you switch it on. When you do, GuardForge issues a link on your own site that publishes a letter grade and the month it was worked out — nothing else.
The grade is not your score. It is worked out only from the eleven checks a stranger can already run against your site from outside with no login: the scheme, XML-RPC, whether ?author=1 gives up a login name, whether the REST API answers anonymous callers, the version in your generator tag, your response headers, your Content-Security-Policy header, whether a directory lists its contents, whether sensitive files answer directly, the login form, and the X-Pingback header. Everything on that list is already public, so the badge tells a passer-by nothing they could not have found by loading your site.
Your numeric score, your two-factor coverage, your brute-force thresholds, your integrity results, whether an account is called admin, your pending updates and any vulnerable components are never published, in any form. The link carries an unguessable token so nobody can walk a list of sites looking for weak ones, it can be reissued or turned off at any moment, views are never logged, and until you switch it on the address is not registered at all — your site answers WordPress’s own 404, exactly like a site without the plugin.
Installation
- Upload the
guardforgefolder to/wp-content/plugins/, or install through Plugins → Add New. - Activate GuardForge through the Plugins menu.
- Open GuardForge → Settings to review the hardening options.
- Visit GuardForge → File integrity to create the initial baseline, and GuardForge → 2FA to protect your own login. Point your other users at GuardForge → 2FA as well — it is the one GuardForge screen every logged-in role can open, and it only ever touches the account of whoever is looking at it.
Frequently asked questions
Do I need an account or API key for the free version?
No. Every protection runs on your own server, and the one thing that reaches the network needs no account: the file-integrity scan asks wordpress.org for the official checksums of your WordPress version and your wordpress.org plugins, and says nothing about you. See External services above. Nothing else in this plugin ever leaves your site.
How do I get the Pro features?
Pro features ship in a separate “GuardForge Pro” add-on. Install this free plugin first, then add Pro from https://avakode.com.
Does the Pro add-on send my data anywhere?
Only what each feature needs. Nothing about your site reaches Avakode, the company behind GuardForge, from this plugin at all: its one outgoing request is the integrity scan’s checksum lookup, and that goes to wordpress.org. See External services above. With the Pro add-on installed, more reaches Avakode (Terms: https://avakode.com/terms — Privacy: https://avakode.com/privacy), each piece only for the feature that needs it: your licence key and your site’s address (the licence check, the real-time vulnerability feed and update checks); a visitor’s IP address when Geo-IP blocking has to ask…
How would I know if somebody edited the audit log?
Press “Verify chain” on the audit-log screen. Every row carries the hash of the row before it, so an edited field breaks its own row, and a deleted row leaves the next one pointing at a hash the table cannot produce — the check names the first row that failed. Restoring a database backup over a live log will break it too, for the same honest reason. On a log larger than fifty thousand rows the check covers the oldest part and says plainly that it was truncated, rather than dying half-way and leaving you an empty screen; there is no resume yet, so lower the retention window if your log is…
Will the alerts wake me up at three in the morning?
Only for the things that should. Each channel has its own minimum severity and you can batch the traffic into an hourly or a daily digest instead of sending it as it happens. Quiet hours hold ordinary alerts until the hour you name — but a lockdown and a malware finding are let through immediately, which is why every signal carries a category as well as a severity. Alerts are part of the Pro add-on.
Will GuardForge conflict with other security plugins?
GuardForge is designed to coexist with Wordfence, Sucuri, iThemes Security, and similar plugins. If you notice a conflict, please open a support thread.
Changelog
The Vulnerabilities screen now tells whether GuardForge Pro updates the database each day; the add-on's new daily update and its switch come with GuardForge Pro 1.3.0. If you run GuardForge Pro, it must be 1.2.0 or newer.
1.4.0
- With the Pro add-on’s vulnerability database, the refresh card no longer says the database updates every day when the add-on’s own daily update is switched off, and it asks for a newer add-on when the installed one has no daily update of its own.
- New option vulndb_pro_updates, on by default: the add-on’s new “Keep the vulnerability database up to date” switch is saved through it.
- Deleting the plugin leaves the job queue the Forge plugins share in place while another Forge plugin or add-on is still on the site. The check used to miss add-ons, and Rank Forge installed from wordpress.org, so the queue could be dropped while a neighbour still had jobs in it.
- The request that downloads the public vulnerability feed no longer carries your site’s address: it identifies itself as GuardForge, with the plugin version and “(vulnerability feed)”, instead of using WordPress’s default User-Agent, which includes the address.
1.3.6
- The new-administrator alert fires however a user becomes an administrator: the profile screen, the Users list, the REST API, WP-CLI, wp_update_user(), set_role(), add_role(), add_cap() or a direct write to the user’s capabilities. A promotion through the REST API, add_role() (which is what wp user add-role calls), add_cap() or a direct write used to send no e-mail and no alert. Saving an administrator with the role they already had is not reported as a new one.
- Role changes made through the REST API are written to the audit log as one entry with the roles the user now has and the roles they had, instead of an entry with an empty role. Several roles, and a role taken away, are written in full.
1.3.5
- The Forge Suite screens look for sibling plugins in the directory WordPress reports and nowhere else, so a site whose plugin directory has been moved on its own is read correctly.
1.3.4
- The file-integrity monitor is off until you switch it on, and activation no longer schedules its daily lookup: the comparison asks api.wordpress.org for the official checksums, and no request goes out before you ask for one. “Run scan now” still runs a single scan whenever you press it.
- The Forge Suite screens look for sibling plugins through WordPress’s own constants, so an installation whose content directory has been moved is read correctly.
- The Geo-IP screen names the path it actually reads the MaxMind database from, instead of assuming the default uploads folder.
- Generated admin markup — the log pagers, the enrolment QR code, the header logo and the alert channel cards — is escaped against an allowlist where it is printed.
1.3.3
- This plugin no longer writes into WordPress’s own directories. A modified or missing core file is reported exactly as before, and the screen now links to Dashboard → Updates: re-installing WordPress is what puts core files back.
- The alerts screen loads its script through WordPress instead of printing it into the page.
- Two standing notices — the warning about an add-on too old for this core, and the staging banner — appear on GuardForge screens, the plugin list and the dashboard instead of on every screen in the admin.
1.3.2
- When the vulnerability feed is off, a notice on the dashboard, the plugin list and GuardForge’s own screens tells an administrator so and links to the switch in Settings. It goes away once the feed is on or the notice is dismissed.
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best GuardForge alternatives
All audit log plugins →FAQ
GuardForge: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 5, 2026
Is GuardForge free?
Yes. GuardForge is free to download and use from the official WordPress.org plugin directory.
Is GuardForge safe to use in 2026?
GuardForge is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 4 hours ago, and scores 64/100 on our health check.
How many websites use GuardForge?
GuardForge is active on <10 WordPress websites and has been downloaded 147 times since it launched in September 2026. It was downloaded 149 times in the last 30 days.
Does GuardForge work with WordPress 7.1?
Yes. The developer has tested GuardForge up to WordPress 7.1.2, the latest release. It requires WordPress 6.5 or newer.
What PHP version does GuardForge need?
GuardForge requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was GuardForge last updated?
The latest version, 1.4.0, was released on October 5, 2026 (4 hours ago).
Who makes GuardForge?
GuardForge is developed and maintained by avakodeforge.
What are the best alternatives to GuardForge?
The most popular alternatives to GuardForge are Simple History (300K+ installs), Activity Log (200K+ installs) and Stream (70K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card