BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Papy3D Security Guard icon
Actively maintained Tested with WP 7.1 #4 in backdoor

Papy3D Security Guard

A modular, self-hosted WordPress security suite with no external CAPTCHA or TOTP service.

Active installs<10New
Downloads · 30d72▼ -41% vs prev. 30d
Rating—0 reviews
Health score60/100Fair
All-time downloads139Since Aug 2026
Support resolved—No recent threads
RequiresWP 6.5PHP 8.0+
Downloads · 7d21▲ +31.3% week over week
Our verdict

Use with caution

Papy3D Security Guard works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.

  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

61320Aug 25Sep 13Oct 2
Yesterday6
Daily average (1y)4
Peak day27Aug 25, 2026
Last 12 months147

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Papy3D Security Guard stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
backdoor #49 104 Best backdoor plugins →
firewall >100 973 Best firewall plugins →
hardening >100 2,133 Best hardening plugins →
malware >100 422 Best malware plugins →
security >100 10,000 Best security plugins →

About Papy3D Security Guard

From the official readme · v2.0.10

Description

Papy3D Security Guard is a modular WordPress security suite. Protections are disabled by default and can be enabled independently.

  • Early login protection, local CAPTCHA, lockouts, honeypots and IPv4/IPv6/CIDR controls.
  • Local WAF with observation, balanced and strict modes, plus delegation to Papy3D WAF when installed.
  • TOTP, recovery codes, login alerts, forced password resets and session controls.
  • WordPress hardening, sensitive-file checks, core integrity verification and bounded security logs.
  • Incremental heuristic malware/backdoor scanner with explicit exceptions, encrypted quarantine and WP-CLI support.
  • File-permission, HTTPS, trusted-proxy and mixed-content diagnostics.
  • Optional Wordfence Intelligence synchronization followed by offline vulnerability checks.
  • GDPR controls, centralized alerts and secret-free JSON settings transfer.

CAPTCHA, TOTP and normal malware scans remain local. External requests occur only for explicitly enabled or requested features documented below.

Data and privacy

Settings are stored in WordPress options. The encryption master key is stored separately as a non-autoloaded option or multisite network option. Early-guard runtime state contains bounded counters, timestamps and truncated HMAC identifiers rather than plaintext usernames, passwords or CAPTCHA answers. Local WAF events may contain time, IP address, HMAC identifier, method, path without query string, rule identifiers, severity, action, bounded redacted excerpts, payload hash and user agent. Cookies, authorization headers, complete passwords and complete request bodies are not stored.

TOTP data is encrypted or hashed in user metadata. Repeated-login/TOTP counters are HMAC-keyed and expiring. Username blacklist and honeypot reports can store detected IP addresses, bounded identifiers, counters and timestamps. Login and sensitive-action alerts may include IP address and user agent in email sent through the site’s configured mail system. No analytics, external CAPTCHA, remote QR-code or remote authentication service is used.

External services

External services are contacted only for optional features or explicit administrator actions.

Trusted proxy IP-list sources

When an administrator refreshes a selected provider, or enables the daily refresh, the plugin can request public network lists from Cloudflare, QUIC.cloud, bunny.net, Fastly or Imperva. No site URL, user, visitor IP, content or plugin configuration is sent by the plugin. Providers receive normal HTTPS connection metadata, the server source IP and a generic user agent. Sucuri ranges are bundled locally and StackPath is treated as discontinued.

  • Cloudflare lists: https://www.cloudflare.com/ips-v4/ and https://www.cloudflare.com/ips-v6/ ; privacy: https://www.cloudflare.com/privacypolicy/ ; terms: https://www.cloudflare.com/policies/terms/
  • QUIC.cloud: https://www.quic.cloud/ips-all ; privacy: https://www.quic.cloud/privacy-policy/ ; terms: https://www.quic.cloud/terms-of-use/
  • bunny.net: https://bunnycdn.com/api/system/edgeserverlist and https://bunnycdn.com/api/system/edgeserverlist/IPv6 ; privacy: https://bunny.net/privacy/ ; terms: https://bunny.net/tos/
  • Fastly: https://api.fastly.com/public-ip-list ; privacy: https://www.fastly.com/privacy ; terms: https://www.fastly.com/terms
  • Imperva: https://my.imperva.com/api/integration/v1/ips ; privacy: https://www.imperva.com/trust-center/privacy-statement/ ; terms: https://www.imperva.com/legal/website-terms-of-use/
  • Sucuri source documentation: https://docs.sucuri.net/website-firewall/troubleshooting/same-ip-for-all-users/

Wordfence Intelligence

Used only when an administrator synchronizes/tests the vulnerability feed or enables daily WP-Cron synchronization. Endpoint: https://www.wordfence.com/api/intelligence/v3/vulnerabilities/scanner. The API key is sent as a Bearer token. The site URL and installed inventory are not sent; the complete feed is downloaded and analyzed locally.

  • Terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
  • Privacy: https://www.wordfence.com/privacy-policy/
  • API documentation: https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/

WordPress.org services

Optional core integrity verification uses WordPress core’s checksum service and sends the installed WordPress version and locale. Optional plugin/theme comparison is triggered only by an explicit administrator action and downloads the exact WordPress.org package for the identified slug/version to a temporary file, compares the selected file locally, then deletes the archive.

  • Privacy: https://wordpress.org/about/privacy/
  • License: https://wordpress.org/about/license/

PayPal

The optional Support tab contains a standard PayPal donation form. No remote PayPal script or image is embedded and nothing is submitted automatically. When the administrator clicks the support button, the selected amount, EUR currency, donation description, recipient account and normal HTTPS metadata are sent directly to PayPal.

  • Terms: https://www.paypal.com/us/legalhub/useragreement-full
  • Privacy: https://www.paypal.com/us/legalhub/privacy-full

Security

Test security changes on staging where possible and retain SFTP/SSH access for recovery. Keep WordPress, PHP and the plugin updated.

Plugin identifiers and companion integration

Security Guard is autonomous and uses the plugin-specific p3dsg_ / P3DSG_ prefix for its own classes, hooks, options, transients, menu slug and assets. It does not bundle or register a shared administration hub. The p3dwaf_integration_v1_status filter is owned by the optional companion Papy3D WAF plugin; Security Guard only consumes that external public hook when the companion plugin is installed.

Installation

  1. Upload the ZIP from Plugins > Add New Plugin.
  2. Activate the plugin.
  3. Open Security Guard in the WordPress administration menu.
  4. Configure each protection before enabling it.
  5. Keep the installed directory name as papy3d-security-guard.

Frequently asked questions

How can I recover from an administrator lockout?

Temporarily add define( 'PAPY3D_SECURITY_BYPASS', true ); to wp-config.php, sign in, correct the configuration, then remove the constant immediately. It suspends Security Guard protections, including the pre-WordPress guard.

How does the pre-WordPress login guard work?

The optional guard uses PHP auto_prepend_file to count credential submissions before WordPress loads and can require a short-lived signed local CAPTCHA during reinforced mode. Because WordPress has not bootstrapped yet, the challenge uses its own expiring HMAC-signed nonce bound to the client IP and user agent; that nonce is verified before the submitted CAPTCHA answer is read. It does not inspect or store passwords or usernames. The stable loader is stored under the plugin-owned directory returned by wp_upload_dir() so plugin updates do not remove a path that PHP workers may still cache…

How are TOTP secrets and the Wordfence API key protected?

They use authenticated encryption with a dedicated versioned random master key stored in the WordPress database. The option is non-autoloaded on single-site and network-scoped on multisite. Historical formats are migrated without rotating the key.

What are the local WAF limits?

The local WAF runs inside WordPress. It can reject application attacks but cannot stop traffic before PHP, protect files served directly by the web server, or absorb volumetric denial-of-service attacks. Administrators are not blocked by the local WAF while authenticated.

How are quarantined files protected?

After explicit administrator confirmation, a source file is streamed into an authenticated-encryption container under wp_upload_dir()/papy3d-security-guard/quarantine. Plaintext hash and size are verified before removal and again during restoration. Existing destination files are never overwritten.

How does vulnerability synchronization work?

The optional Wordfence Intelligence module sends the configured API key only to the official Scanner Feed endpoint in an Authorization Bearer header. The complete feed is imported locally; installed components are then checked offline. A conservative local delay prevents excessive synchronization attempts.

Changelog

2.0.10

  • Replace the administration header PNG with the supplied AVIF banner.
  • Preserve the existing 1454×500 display dimensions and admin layout.

2.0.9

  • Update the WordPress.org compatibility metadata to Tested up to: 7.1.
  • No functional or security code changes.

2.0.8

  • Correct the WordPress plugin author display name from Papy3D to the canonical WordPress.org account name papy3d.
  • Keep product, package and Papy 3D Factory branding unchanged.

2.0.7

  • Remove the deprecated imagedestroy() call from the Early Guard CAPTCHA image response. PHP 8+ automatically releases GD image objects, so CAPTCHA output and validation remain unchanged.

2.0.6

  • Fix the Security Guard WAF connector target validation for current Papy3D WAF releases whose stable loader is stored under wp_upload_dir()/papy3d-waf/.
  • Keep the historical wp-content/papy3d-waf-loader.php target accepted only for bounded backward-compatible migration/rollback while still rejecting every unrelated loader path.

2.0.5

  • Fix local CAPTCHA rendering after transient challenge encryption moved to the t2s: / t2o: formats; the CAPTCHA parser now accepts and decrypts current transient tokens while preserving compatibility with previous token formats.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Papy3D Security Guard alternatives

All backdoor plugins →

FAQ

Papy3D Security Guard: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 3, 2026

Is Papy3D Security Guard free?

Yes. Papy3D Security Guard is free to download and use from the official WordPress.org plugin directory.

Is Papy3D Security Guard safe to use in 2026?

Papy3D Security Guard works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.

How many websites use Papy3D Security Guard?

Papy3D Security Guard is active on <10 WordPress websites and has been downloaded 139 times since it launched in August 2026. It was downloaded 72 times in the last 30 days.

Does Papy3D Security Guard work with WordPress 7.1?

Yes. The developer has tested Papy3D Security Guard up to WordPress 7.1.2, the latest release. It requires WordPress 6.5 or newer.

What PHP version does Papy3D Security Guard need?

Papy3D Security Guard requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Papy3D Security Guard last updated?

The latest version, 2.0.10, was released on August 25, 2026 (1 month ago).

Who makes Papy3D Security Guard?

Papy3D Security Guard is developed and maintained by papy3d.

What are the best alternatives to Papy3D Security Guard?

The most popular alternatives to Papy3D Security Guard are Cleverhog Malware Scanner (70+ installs), Deep Malware Cleaner (50+ installs) and Malroot Security (20+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.