{"id":325141,"date":"2026-09-21T15:24:18","date_gmt":"2026-09-21T15:24:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/elohim-cyber-guardian\/"},"modified":"2026-09-21T15:57:28","modified_gmt":"2026-09-21T15:57:28","slug":"elohim-cyber-guardian","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/elohim-cyber-guardian\/","author":23515261,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3","stable_tag":"1.3","tested":"7.1.1","requires":"6.2","requires_php":"8.0","requires_plugins":null,"header_name":"Elohim Cyber Guardian","header_author":"Elohim Software Solutions Pvt Ltd","header_description":"Advanced WordPress security plugin with login protection, rate limiting, CAPTCHA, attack logging, and site hardening.","assets_banners_color":"b7ccdd","last_updated":"2026-09-21 15:57:28","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/elohimcyberguardian.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":44,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.3":{"tag":"1.3","author":"elohimsoftwaressolutions","date":"2026-09-21 15:57:28","revision":3705899}},"upgrade_notice":{"1.2":"<p>Fixes for WordPress.org review feedback: removed global constant definitions in favor of scoped WordPress APIs, and corrected output escaping. Update recommended for all users.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3705882,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3705882,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3705882,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3705882,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3705882,"resolution":"1","location":"assets","locale":"","width":1280,"height":720},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3705882,"resolution":"2","location":"assets","locale":"","width":1280,"height":720},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3705882,"resolution":"3","location":"assets","locale":"","width":1280,"height":720},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3705882,"resolution":"4","location":"assets","locale":"","width":1280,"height":720},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3705882,"resolution":"5","location":"assets","locale":"","width":1280,"height":720},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3705882,"resolution":"6","location":"assets","locale":"","width":1280,"height":720},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3705882,"resolution":"7","location":"assets","locale":"","width":1280,"height":720}},"screenshots":{"1":"Dashboard overview showing login attempt statistics.","2":"Custom login URL settings page.","3":"CAPTCHA configuration screen.","4":"Honeypot settings page.","5":"Rate limiting and IP blocking settings.","6":"Email alert configuration.","7":"Security hardening options."}},"plugin_section":[],"plugin_tags":[2439,362,1174,15756,600],"plugin_category":[44,54],"plugin_contributors":[281861],"plugin_business_model":[],"class_list":["post-325141","plugin","type-plugin","status-publish","hentry","plugin_tags-brute-force","plugin_tags-captcha","plugin_tags-firewall","plugin_tags-login-protection","plugin_tags-security","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-elohimsoftwaressolutions","plugin_committers-elohimsoftwaressolutions"],"banners":{"banner":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/banner-772x250.png?rev=3705882","banner_2x":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/banner-1544x500.png?rev=3705882","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/icon-128x128.png?rev=3705882","icon_2x":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/icon-256x256.png?rev=3705882","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/screenshot-1.png?rev=3705882","caption":"Dashboard overview showing login attempt statistics."},{"src":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/screenshot-2.png?rev=3705882","caption":"Custom login URL settings page."},{"src":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/screenshot-3.png?rev=3705882","caption":"CAPTCHA configuration screen."},{"src":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/screenshot-4.png?rev=3705882","caption":"Honeypot settings page."},{"src":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/screenshot-5.png?rev=3705882","caption":"Rate limiting and IP blocking settings."},{"src":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/screenshot-6.png?rev=3705882","caption":"Email alert configuration."},{"src":"https:\/\/ps.w.org\/elohim-cyber-guardian\/assets\/screenshot-7.png?rev=3705882","caption":"Security hardening options."}],"raw_content":"<!--section=description-->\n<p><strong>Elohim Cyber Guardian<\/strong> is a WordPress security plugin developed by Elohim Software Solutions Pvt Ltd to help protect your website from unauthorized access, brute-force attacks, and common login-based threats.<\/p>\n\n<p>It provides essential security features with simple configuration and a clear dashboard for monitoring activity.<\/p>\n\n<p>This plugin does not replace a full security solution but adds additional protection layers such as login protection, rate limiting, and monitoring.<\/p>\n\n<h4>Features<\/h4>\n\n<p><strong>Custom Login URL<\/strong>\nUse a custom login URL while safely redirecting access from the default login page.<\/p>\n\n<p><strong>Rate Limiting &amp; IP Blocking<\/strong>\nLimit login attempts and automatically block suspicious IP addresses.<\/p>\n\n<p><strong>Honeypot Protection<\/strong>\nDetect and stop automated bots without affecting real users.<\/p>\n\n<p><strong>CAPTCHA Support<\/strong>\nSupports built-in math CAPTCHA and Google reCAPTCHA integration.<\/p>\n\n<p><strong>Attack Logs<\/strong>\nTrack login attempts including IP address, username, and status. Includes CSV export and bulk delete.<\/p>\n\n<p><strong>Email Alerts<\/strong>\nReceive notifications for suspicious login activity based on a configurable threshold.<\/p>\n\n<p><strong>Auto-Block<\/strong>\nAutomatically block IPs that exceed your configured failed login threshold.<\/p>\n\n<p><strong>Emergency Access<\/strong>\nGenerate secure access tokens if you are locked out.<\/p>\n\n<p><strong>Security Hardening Options<\/strong>\nEnable additional protections such as:<\/p>\n\n<ul>\n<li>Disable XML-RPC<\/li>\n<li>Hide WordPress version<\/li>\n<li>Disable file editor<\/li>\n<li>Enforce HTTPS<\/li>\n<li>Add security headers<\/li>\n<\/ul>\n\n<p><strong>Security Dashboard<\/strong>\nView your current protection status and activity summary.<\/p>\n\n<h3>Community Edition Limitations<\/h3>\n\n<p>This is the Community edition of Elohim Cyber Guardian. It is fully functional and is not a trial: it does not expire, and no feature stops working over time.<\/p>\n\n<p>One limit applies:<\/p>\n\n<ul>\n<li><strong>Actively blocked IPs:<\/strong> up to 3 at a time. Automatic rate-limit blocking, login protection, CAPTCHA, honeypot, logging, email alerts, and all hardening options are unlimited and unaffected.<\/li>\n<\/ul>\n\n<p>A paid edition that removes the blocked-IP limit is available separately from the plugin author. This plugin does not display upgrade prompts beyond the notice shown when the limit is reached, and no functionality is disabled to encourage an upgrade.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to external services only when enabled by the administrator:<\/p>\n\n<ol>\n<li><p><strong>Google reCAPTCHA<\/strong> (Google LLC)\nUsed for verifying that a login attempt comes from a human, when the administrator enables reCAPTCHA v2 or v3.\nData sent: on login-page loads the visitor's browser requests the reCAPTCHA script from google.com, which exposes the visitor's IP address and browser details to Google; on login submissions this plugin's server sends the reCAPTCHA response token and the visitor's IP address to Google's siteverify endpoint.\nPrivacy Policy: https:\/\/policies.google.com\/privacy\nTerms: https:\/\/policies.google.com\/terms<\/p><\/li>\n<li><p><strong>ipapi.co<\/strong> (Kloudend, Inc.)\nUsed for optional IP-based country lookup when the administrator enables the country option in Email Alert settings.\nData sent: the IP address of the visitor that triggered a security alert, at the moment the alert email is generated.\nPrivacy Policy: https:\/\/ipapi.co\/privacy\/\nTerms: https:\/\/ipapi.co\/terms\/<\/p><\/li>\n<\/ol>\n\n<p>Both integrations are disabled by default and can be turned off at any time in the plugin settings. No data is transmitted unless the corresponding feature is enabled by the administrator. The plugin makes no other outbound requests and collects no telemetry.<\/p>\n\n<p>As of version 1.3 this plugin uses no PHP sessions anywhere: the math CAPTCHA challenge is stored server-side in a short-lived transient keyed by a single-use token, so the plugin is fully compatible with full-page caching.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin may store the following data locally:<\/p>\n\n<ul>\n<li>IP addresses of login attempts<\/li>\n<li>Usernames entered during login<\/li>\n<li>Login timestamps<\/li>\n<\/ul>\n\n<p>This data is used only for security monitoring and is not shared externally except as described above.<\/p>\n\n<p>This plugin does not track users or send personal data to external servers without explicit administrator action.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin via the WordPress admin panel<\/li>\n<li>Go to <strong>Elohim Cyber Guardian<\/strong> to configure settings<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20plugin%20lock%20me%20out%20of%20my%20site%3F\"><h3>Will this plugin lock me out of my site?<\/h3><\/dt>\n<dd><p>No. The emergency access feature allows recovery access if needed.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20down%20my%20website%3F\"><h3>Does it slow down my website?<\/h3><\/dt>\n<dd><p>No noticeable impact. Background tasks run using WordPress scheduling.<\/p><\/dd>\n<dt id=\"is%20this%20plugin%20suitable%20for%20woocommerce%3F\"><h3>Is this plugin suitable for WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. It works with standard WordPress authentication systems.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20support%20auto-blocking%3F\"><h3>Does this plugin support auto-blocking?<\/h3><\/dt>\n<dd><p>Yes. IPs that exceed your configured failed login threshold are automatically blocked.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3<\/h4>\n\n<p>Security and code-quality release addressing the WordPress.org plugin review.<\/p>\n\n<ul>\n<li>Removed all PHP session usage. The math CAPTCHA answer and the rate-limit block notice were previously held in $_SESSION, which forced session_start() and made every visitor uncacheable, bypassing server-side page caches such as Nginx FastCGI cache and Varnish. Both now use short-lived transients, so the plugin is fully compatible with full-page caching and managed WordPress hosts.<\/li>\n<li>The math CAPTCHA challenge is now a single-use, 5-minute token carried in a hidden form field. A token is invalidated on every verification attempt, correct or not, so an answer can never be replayed.<\/li>\n<li>Restructured the custom login handler so the request nonce is verified before any other value is read from $_POST. Verified values are collected once and passed to the CAPTCHA and login-completion steps as arguments; those methods no longer read superglobals at all.<\/li>\n<li>Failed logins through the custom login URL now fire WordPress core's wp_login_failed action. Previously they did not, which meant such attempts were invisible to this plugin's own logging and email alerts, and to any third-party brute-force protection the site owner had installed.<\/li>\n<li>Replaced the $_SERVER['ELOGUARD_INTERNAL_LOGIN'] signalling flag with a private static class property. $_SERVER is request input, not plugin storage.<\/li>\n<li>Fixed the escaping of the reCAPTCHA site key in inline JavaScript. esc_js() is intended for quoted HTML attributes; the value is now emitted with wp_json_encode(), the correct escaper for a raw script context. The site key in the Google API URL is now passed through rawurlencode().<\/li>\n<li>eloguard_req_string() now sanitizes as it reads rather than returning a raw value for callers to sanitize separately. A clearly separated eloguard_req_raw_string() is used only for passwords, which must not be sanitized.<\/li>\n<li>Fixed several inputs that were unslashed or sanitized a line away from where they were read, including the alert email address, REMOTE_ADDR in the log viewer, and the hardening settings AJAX payload.<\/li>\n<li>Proxy headers (CF-Connecting-IP, X-Forwarded-For, X-Real-IP) are now validated with FILTER_VALIDATE_IP before being trusted, in the emergency-access path as well as the honeypot.<\/li>\n<li>Added range validation to the reCAPTCHA v3 score threshold, the email alert throttle, the maximum attempt count, and the block duration.<\/li>\n<li>Split compound nonce conditions in the CAPTCHA and rate-limit settings pages into sequential capability and nonce guards, so the checks cannot be accidentally bypassed by a later edit.<\/li>\n<li>Replaced a CAPTCHA verification routine that looped over guessed method names inside a catch-all try\/catch, which could silently fail open, with a single explicit call.<\/li>\n<li>Renamed plugin variables that collided with WordPress globals ($page, $per_page, $type, $tabs, $path, $file).<\/li>\n<li>Validated the outbound email alert address with is_email() before storing it.<\/li>\n<li>Expanded the External Services disclosure to state exactly what data is sent to Google reCAPTCHA and ipapi.co and when, and removed the outdated note about PHP sessions.<\/li>\n<li>Diagnostic error_log() calls in the hardening module now only run when WP_DEBUG is enabled.<\/li>\n<li>Renamed the \"free plan\" wording in the logs screen to \"Community edition\" and documented the 3 blocked-IP limit in this readme.<\/li>\n<li>Expanded \"Requires at least\" to 6.2 to reflect use of the %%i identifier placeholder in $wpdb-&gt;prepare().<\/li>\n<li>Updated \"Tested up to\" to 7.0.2.<\/li>\n<li>Prefixed all file-scope variables in admin templates with eloguard_ (WordPress.NamingConventions.PrefixAllGlobals).<\/li>\n<li>Replaced esc_sql() table-name interpolation with $wpdb-&gt;prepare() + %%i throughout dashboard, logs, email, and the migration routine, removing PluginCheck.Security.DirectDB.UnescapedDBParameter warnings.<\/li>\n<li>Annotated core hook calls (login_form, login_head, wp_login, etc.) in class-admin-url.php to suppress false-positive NonPrefixedHooknameFound warnings.<\/li>\n<li>Annotated the hardening module's root .htaccess write to suppress PluginCheck.CodeAnalysis.WriteFile.ABSPATHDetected.<\/li>\n<li>Added NoCaching ignore annotations on real-time security counts and one-time migration schema checks.<\/li>\n<\/ul>\n\n<h4>1.2<\/h4>\n\n<ul>\n<li>Renamed the \"ecs\" prefix (too short per WordPress.org guidelines) to \"eloguard\" across all functions, classes, defines, hooks, transients, database tables, and option names<\/li>\n<li>Added automatic one-time migration so existing installs' settings, logs, and blocked IPs carry over from the old \"ecs_\" names to the new \"eloguard_\" names<\/li>\n<li>Removed global define('CONCATENATE_SCRIPTS', false) \u2014 script concatenation is now only disabled on this plugin's own admin pages, not site-wide<\/li>\n<li>Removed global define('DISABLE_WP_CRON', true) \u2014 the plugin now shows an admin notice with instructions instead of silently changing this site-wide setting for every other plugin<\/li>\n<li>Replaced define('FORCE_SSL_ADMIN', true) with WordPress core's force_ssl_admin() function, so enabling HTTPS enforcement no longer defines a raw global constant<\/li>\n<li>Fixed late-escaping issue on the admin menu icon CSS output<\/li>\n<\/ul>\n\n<h4>1.1<\/h4>\n\n<p>2026-05-08\nInitial Public Release<\/p>\n\n<ul>\n<li>Removed all license-gated feature restrictions \u2014 all features are fully free<\/li>\n<li>Fixed unprepared database queries across dashboard and logs pages<\/li>\n<li>Replaced direct file operations with WP_Filesystem API<\/li>\n<li>Moved inline scripts and styles into wp_enqueue_script() \/ wp_enqueue_style() across all admin pages<\/li>\n<li>Added capability checks to all admin page files<\/li>\n<li>Fixed chart data arrays not being built from query results<\/li>\n<li>Improved security score calculation<\/li>\n<li>Fixed admin menu position to avoid conflicting with core WordPress menu items<\/li>\n<li>Performance optimizations \u2014 caching added to all dashboard queries<\/li>\n<\/ul>","raw_excerpt":"A lightweight WordPress security plugin with login protection, rate limiting, CAPTCHA, and security hardening.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/325141","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=325141"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/elohimsoftwaressolutions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=325141"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=325141"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=325141"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=325141"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=325141"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=325141"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}