{"id":337793,"date":"2026-07-28T10:06:47","date_gmt":"2026-07-28T10:06:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ic-security-guard\/"},"modified":"2026-07-28T10:06:15","modified_gmt":"2026-07-28T10:06:15","slug":"ic-security-guard","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ic-security-guard\/","author":16888027,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.0.2","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"IC Security Guard","header_author":"ITclan","header_description":"IC Security Guard is a lightweight security hardening plugin that protects your WordPress site from brute force login attacks, secures the REST API and XML-RPC, adds Email OTP Two-Factor Authentication, and sends real-time email alerts when it blocks an attack.","assets_banners_color":"000e2e","last_updated":"2026-07-28 10:06:15","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/itclanproducts.com\/wp\/ic-security-guard.zip","header_author_uri":"https:\/\/www.itclanbd.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":23,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.0":{"tag":"1.2.0","author":"itclan","date":"2026-07-28 10:06:15"}},"upgrade_notice":{"1.2.0":"<p>Adds REST API &amp; XML-RPC brute force protection and real-time email alerts. No configuration is changed automatically \u2014 visit Settings \u2192 IC Security Guard to enable the new options.<\/p>","1.0.0":"<p>Initial release of IC Security Guard.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3625724,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3625724,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3625734,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3625734,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3625724,"resolution":"1","location":"assets","locale":"","width":1895,"height":867},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3625724,"resolution":"2","location":"assets","locale":"","width":1910,"height":857}},"screenshots":{"1":"Backend settings","2":"Change Login Url","3":"Readme"}},"plugin_section":[],"plugin_tags":[2439,1229,23853,600,1909],"plugin_category":[54],"plugin_contributors":[168627],"plugin_business_model":[],"class_list":["post-337793","plugin","type-plugin","status-publish","hentry","plugin_tags-brute-force","plugin_tags-login-security","plugin_tags-rest-api","plugin_tags-security","plugin_tags-two-factor-authentication","plugin_category-security-and-spam-protection","plugin_contributors-itclan","plugin_committers-itclan"],"banners":{"banner":"https:\/\/ps.w.org\/ic-security-guard\/assets\/banner-772x250.jpg?rev=3625734","banner_2x":"https:\/\/ps.w.org\/ic-security-guard\/assets\/banner-1544x500.jpg?rev=3625734","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ic-security-guard\/assets\/icon-128x128.png?rev=3625724","icon_2x":"https:\/\/ps.w.org\/ic-security-guard\/assets\/icon-256x256.png?rev=3625724","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ic-security-guard\/assets\/screenshot-1.png?rev=3625724","caption":"Backend settings"},{"src":"https:\/\/ps.w.org\/ic-security-guard\/assets\/screenshot-2.png?rev=3625724","caption":"Change Login Url"}],"raw_content":"<!--section=description-->\n<p>IC Security Guard is a lightweight, all-in-one security hardening plugin that protects your WordPress site from brute force login attacks, REST API abuse, and XML-RPC amplification attacks \u2014 and keeps your site owner informed in real time when an attack is blocked.<\/p>\n\n<p>Instead of leaving <code>wp-login.php<\/code>, <code>\/wp-admin<\/code>, <code>xmlrpc.php<\/code>, and the REST API open for anyone to probe, IC Security Guard lets you move your login page to a custom secret URL, lock out anyone who fails to log in too many times, require a one-time email code before login completes, shut down common XML-RPC and REST API attack vectors, and get emailed the moment something is blocked.<\/p>\n\n<h4>Special Features<\/h4>\n\n<p><strong>Hide Default Login Page<\/strong><\/p>\n\n<ul>\n<li>Hide the default <code>wp-login.php<\/code> and <code>\/wp-admin<\/code> login pages from unauthenticated visitors<\/li>\n<li>Serve the login form only on a custom, secret URL that you choose<\/li>\n<li>Redirect anyone hitting the default login URL to a page of your choice, or a plain 404<\/li>\n<li>Logged-in users always pass through untouched \u2014 no impact on legitimate access<\/li>\n<\/ul>\n\n<p><strong>Login Attempt Limiting &amp; Lockout<\/strong><\/p>\n\n<ul>\n<li>Limit failed login attempts with a configurable maximum<\/li>\n<li>Automatic lockout for a configurable duration after too many failed attempts<\/li>\n<li>Live countdown timer shown on the login form while locked out<\/li>\n<li>Lockout state persists across page reloads and resets automatically once it expires<\/li>\n<li>Correct credentials are still rejected while a lockout is active<\/li>\n<\/ul>\n\n<p><strong>Email OTP Two-Factor Authentication<\/strong><\/p>\n\n<ul>\n<li>Optional two-factor authentication using a one-time code sent by email<\/li>\n<li>After a correct username and password, the user is redirected to a dedicated verification page<\/li>\n<li>A 6-digit code is emailed to the account's registered email address and must be entered to complete login<\/li>\n<li>Configurable code expiry, limited verification attempts, and a resend cooldown to prevent abuse<\/li>\n<li>Automatically skipped for REST API and XML-RPC requests so API clients and integrations are not broken<\/li>\n<\/ul>\n\n<p><strong>REST API &amp; XML-RPC Brute Force Protection<\/strong><\/p>\n\n<ul>\n<li>Optionally disable XML-RPC entirely, closing off <code>system.multicall<\/code>-based amplification attacks that let attackers test hundreds of password combinations in a single request<\/li>\n<li>Optionally block unauthenticated REST API user enumeration (<code>\/wp-json\/wp\/v2\/users<\/code>) so attackers cannot harvest valid usernames<\/li>\n<li>Failed REST API and XML-RPC authentication attempts share the same per-IP lockout as the login form, so an attacker locked out on one entry point is locked out everywhere<\/li>\n<\/ul>\n\n<p><strong>Real-time Email Alerts<\/strong><\/p>\n\n<ul>\n<li>Get notified by email the moment a security event is blocked: a login lockout, a blocked XML-RPC request, or a blocked REST API user-enumeration attempt<\/li>\n<li>Each alert includes the event type, the offending IP address, and the time it occurred<\/li>\n<li>A configurable cooldown period per alert type keeps a sustained attack from flooding your inbox<\/li>\n<li>Alerts are sent to your site's admin email address and are fully optional<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install the plugin directly through the WordPress Plugins screen.<\/li>\n<li>Activate the plugin through the \"Plugins\" screen in WordPress.<\/li>\n<li>Go to <strong>Settings \u2192 IC Security Guard<\/strong> to configure the plugin.<\/li>\n<li>On the <strong>General Settings<\/strong> tab:\n\n<ul>\n<li>Enable login attempt limiting and set your maximum failed attempts and lockout duration.<\/li>\n<li>Optionally enable \"Email OTP Two-Factor Authentication\" and set the OTP code expiry.<\/li>\n<li>Optionally enable \"Disable XML-RPC\" and \"Block REST API User Enumeration\".<\/li>\n<li>Optionally enable \"Real-time Email Alerts\" and set an alert cooldown.<\/li>\n<\/ul><\/li>\n<li>On the <strong>Hide Default Logged-in<\/strong> tab, enable \"Hide Default Login Pages\", set your new secret login slug, and optionally set a redirect target for blocked visitors.<\/li>\n<li>Save your changes and bookmark your new login URL before logging out.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20happens%20if%20i%20forget%20my%20new%20login%20url%3F\"><h3>What happens if I forget my new login URL?<\/h3><\/dt>\n<dd><p>You can always reach your site's database (via phpMyAdmin or your host) and update the <code>icsegu_hidelogin_options<\/code> option in the <code>wp_options<\/code> table to disable <code>hide_login_url<\/code>, restoring access to the default <code>wp-login.php<\/code>.<\/p><\/dd>\n<dt id=\"will%20this%20lock%20me%20out%20of%20my%20own%20site%3F\"><h3>Will this lock me out of my own site?<\/h3><\/dt>\n<dd><p>Logged-in users are always allowed through to <code>\/wp-admin<\/code> regardless of the hidden login setting. The failed-login lockout only applies to failed authentication attempts, and resets automatically once the configured lockout duration passes.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20affect%20logged-in%20users%3F\"><h3>Does this plugin affect logged-in users?<\/h3><\/dt>\n<dd><p>No. Logged-in users pass through untouched. The hidden login, lockout, REST API, and XML-RPC protections only apply to unauthenticated visitors and failed authentication attempts.<\/p><\/dd>\n<dt id=\"where%20is%20the%20lockout%20state%20stored%3F\"><h3>Where is the lockout state stored?<\/h3><\/dt>\n<dd><p>Lockout state is stored per IP address using WordPress transients, so it persists across page reloads and works with whatever caching layer your site already uses. The same lockout state is shared by the login form, the REST API, and XML-RPC.<\/p><\/dd>\n<dt id=\"how%20does%20email%20otp%20two-factor%20authentication%20work%3F\"><h3>How does Email OTP Two-Factor Authentication work?<\/h3><\/dt>\n<dd><p>When enabled, after a user enters the correct username and password, they are redirected to a dedicated verification page and emailed a 6-digit code (sent to their WordPress account email address). The code must be entered within the configured expiry window to complete login. Codes can be resent with a short cooldown between requests, and login only completes after the correct code is verified. This step is automatically skipped for REST API and XML-RPC requests, since application passwords and API integrations authenticate programmatically and have no page to display a challenge on.<\/p><\/dd>\n<dt id=\"what%20does%20disabling%20xml-rpc%20protect%20against%3F\"><h3>What does disabling XML-RPC protect against?<\/h3><\/dt>\n<dd><p>XML-RPC's <code>system.multicall<\/code> method allows an attacker to test many username\/password combinations in a single HTTP request, bypassing typical per-request throttling. Enabling \"Disable XML-RPC\" turns off the XML-RPC endpoint entirely. If you rely on XML-RPC for a mobile app, Jetpack, or another integration, leave this option off \u2014 any failed XML-RPC login attempts are still covered by the shared lockout.<\/p><\/dd>\n<dt id=\"what%20does%20blocking%20rest%20api%20user%20enumeration%20protect%20against%3F\"><h3>What does blocking REST API user enumeration protect against?<\/h3><\/dt>\n<dd><p>By default, WordPress's REST API exposes a list of registered usernames at <code>\/wp-json\/wp\/v2\/users<\/code> to anyone, even when logged out. Attackers use this to harvest valid usernames before a brute-force attempt. Enabling \"Block REST API User Enumeration\" returns an authorization error for unauthenticated requests to this endpoint, while logged-in requests are unaffected.<\/p><\/dd>\n<dt id=\"will%20i%20get%20an%20email%20for%20every%20single%20failed%20login%3F\"><h3>Will I get an email for every single failed login?<\/h3><\/dt>\n<dd><p>No. Real-time email alerts are sent once per alert type whenever an event first triggers, then suppressed for the configured cooldown period (15 minutes by default) even if the same type of event keeps happening. This keeps you informed without flooding your inbox during a sustained attack.<\/p><\/dd>\n<dt id=\"is%20.htaccess%20or%20wp-config.php%20hardening%20included%3F\"><h3>Is .htaccess or wp-config.php hardening included?<\/h3><\/dt>\n<dd><p>Those sections are currently marked \"Coming soon\" in the plugin settings and will be added in a future release.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Added optional REST API &amp; XML-RPC brute force protection: disable XML-RPC entirely, block unauthenticated REST API user enumeration, and share the login lockout state across the login form, REST API, and XML-RPC.<\/li>\n<li>Added optional real-time email alerts for login lockouts, blocked XML-RPC requests, and blocked REST API user-enumeration attempts, with a configurable per-alert-type cooldown.<\/li>\n<li>Email OTP Two-Factor Authentication is now automatically skipped for REST API and XML-RPC requests to avoid breaking application password and API-based logins.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added optional Email OTP Two-Factor Authentication with a dedicated verification page.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Hide default login page and serve login only on a custom URL.<\/li>\n<li>Configurable failed login attempt limiting with automatic lockout.<\/li>\n<li>Live countdown timer on the login form during lockout.<\/li>\n<\/ul>","raw_excerpt":"Protect your site from brute force attacks with hidden login, login lockout, Email OTP 2FA, REST API &amp; XML-RPC hardening, and real-time email alerts.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/337793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=337793"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/itclan"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=337793"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=337793"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=337793"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=337793"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=337793"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=337793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}