{"id":353385,"date":"2026-08-28T17:36:14","date_gmt":"2026-08-28T17:36:14","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/codecanvas-guard\/"},"modified":"2026-08-28T17:45:13","modified_gmt":"2026-08-28T17:45:13","slug":"codecanvas-guard","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/codecanvas-guard\/","author":23548706,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.2","stable_tag":"1.3.2","tested":"7.0.4","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"CodeCanvas Guard","header_author":"CodeCanvas","header_description":"Recovery-first WordPress security with protected login, 2FA, hardening, scanning, repair, monitoring, and activity logs.","assets_banners_color":"0b1419","last_updated":"2026-08-28 17:45:13","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":33,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.3.2":{"tag":"1.3.2","author":"codecanvasinc","date":"2026-08-28 17:45:13","revision":3670754}},"upgrade_notice":{"1.3.1":"<p>WordPress.org Plugin Check remediation release. Existing settings, profiles, protected-login routes, verification state, 2FA data, and recovery records are preserved.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3670780,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3670780,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3670780,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3670780,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.3.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[8534,31093,602,600,9217],"plugin_category":[38,54],"plugin_contributors":[278112],"plugin_business_model":[],"class_list":["post-353385","plugin","type-plugin","status-publish","hentry","plugin_tags-audit-log","plugin_tags-hardening","plugin_tags-login","plugin_tags-security","plugin_tags-two-factor","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-codecanvasinc","plugin_committers-codecanvasinc"],"banners":{"banner":"https:\/\/ps.w.org\/codecanvas-guard\/assets\/banner-772x250.png?rev=3670780","banner_2x":"https:\/\/ps.w.org\/codecanvas-guard\/assets\/banner-1544x500.png?rev=3670780","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/codecanvas-guard\/assets\/icon-128x128.png?rev=3670780","icon_2x":"https:\/\/ps.w.org\/codecanvas-guard\/assets\/icon-256x256.png?rev=3670780","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>CodeCanvas Guard is a local-first WordPress security suite built around reviewable changes and safe recovery.<\/p>\n\n<p>Core features include:<\/p>\n\n<ul>\n<li>Safe, Balanced, and Strict protection profiles.<\/li>\n<li>A recovery-first custom login route with browser verification before activation.<\/li>\n<li>Username-and-IP rate limiting, CIDR allow\/block rules, a login honeypot, and generic login errors.<\/li>\n<li>TOTP two-factor authentication with encrypted secrets and one-use recovery codes.<\/li>\n<li>Optional role-based 2FA enforcement and optional Cloudflare Turnstile.<\/li>\n<li>REST user protection, author-enumeration blocking, XML-RPC and pingback controls, security headers, and file-editor protection.<\/li>\n<li>WordPress core and eligible WordPress.org plugin checksum checks.<\/li>\n<li>Local suspicious-PHP patterns, executable uploads, unsafe permissions, recent sensitive-file changes, and known-vulnerability matching.<\/li>\n<li>Critical, High, Medium, Informational, and Unavailable findings with exact reasons and evidence.<\/li>\n<li>Administrator-reviewed findings, exact-file hash approvals, filters, and protected CSV\/JSON exports.<\/li>\n<li>Scheduled scans and priority-aware file monitoring with explicit coverage reporting.<\/li>\n<li>Administrator-approved trusted repairs, protected recovery points, quarantine, restore, and rollback.<\/li>\n<li>Security activity logs, update awareness, session review, and optional email alerts.<\/li>\n<\/ul>\n\n<p>Scheduled scans do not modify files. Repair, quarantine, restore, and rollback actions require an authenticated administrator action and nonce. Guard does not send telemetry to CodeCanvas.<\/p>\n\n<h3>Emergency Recovery<\/h3>\n\n<p>The dashboard can create a one-time emergency login link. The link expires after 30 minutes and opens a 15-minute recovery session.<\/p>\n\n<p>For hosting-level recovery, add the following above the stop-editing comment in <code>wp-config.php<\/code>:<\/p>\n\n<pre><code>define( 'CODECANVAS_GUARD_DISABLE', true );\n<\/code><\/pre>\n\n<p>Remove the line after access is restored and the configuration is corrected.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>CodeCanvas Guard uses external services only for the features described below.<\/p>\n\n<h4>WordPress.org services<\/h4>\n\n<p>Integrity scans, native update awareness, and approved trusted repairs use official WordPress.org services. Depending on the action, WordPress sends the installed WordPress version and locale, or plugin\/theme identifiers and versions, and receives checksum data, update metadata, or an official package. Guard uses the native WordPress HTTP and updater APIs. These requests occur during manual or scheduled scans, update checks, and an administrator-approved repair.<\/p>\n\n<p>Service: https:\/\/wordpress.org\/\nPrivacy policy: https:\/\/wordpress.org\/about\/privacy\/\nTerms: https:\/\/wordpress.org\/about\/terms\/<\/p>\n\n<h4>Wordfence Intelligence<\/h4>\n\n<p>Known-vulnerability matching is optional. When enabled with an API key, the server sends the API key and normal HTTP request metadata to Wordfence Intelligence and downloads its V3 production vulnerability feed. Guard compares the feed with the installed inventory locally; website files and the installed inventory are not uploaded to Wordfence. The service requires a Wordfence Intelligence API key.<\/p>\n\n<p>Service and setup: https:\/\/www.wordfence.com\/help\/wordfence-intelligence\/v3-accessing-and-consuming-the-vulnerability-data-feed\/\nTerms and privacy: https:\/\/www.wordfence.com\/terms-of-use-and-privacy-policy\/<\/p>\n\n<h4>Cloudflare Turnstile<\/h4>\n\n<p>Turnstile is optional and disabled by default. When configured, Cloudflare's challenge script loads on interactive login pages. Cloudflare can process browser and device information under its policy. During login, Guard sends the challenge response, configured secret, and visitor IP address to Cloudflare for verification.<\/p>\n\n<p>Service: https:\/\/www.cloudflare.com\/products\/turnstile\/\nPrivacy policy: https:\/\/www.cloudflare.com\/privacypolicy\/\nTerms: https:\/\/www.cloudflare.com\/website-terms\/<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Guard can store WordPress user IDs, IP addresses, event times, action summaries, limited technical context, user agents, and hashed device fingerprints for security and accountability. Administrators choose log retention from 7 to 365 days; the default is 30 days.<\/p>\n\n<p>The plugin also stores security settings, encrypted 2FA and optional service credentials, recovery-code hashes, protected-login state, scan evidence, file hashes, approvals, and repair\/quarantine metadata. Repair and quarantine files remain on the same server in a protected local directory.<\/p>\n\n<p>Guard adds suggested text to Settings &gt; Privacy and integrates with WordPress personal-data export and erasure tools. Erasure anonymizes user-linked audit events and removes device fingerprints and unfinished 2FA setup data. Active 2FA credentials are retained while the WordPress account exists to avoid weakening account security.<\/p>\n\n<h3>Source Code and Licenses<\/h3>\n\n<p>CodeCanvas Guard is licensed GPLv2 or later. The bundled QR generator is MIT licensed. Its human-readable upstream source is available at:<\/p>\n\n<p>https:\/\/github.com\/kazuhikoarase\/qrcode-generator\/tree\/js2.0.4\/js<\/p>\n\n<p>See <code>THIRD-PARTY-NOTICES.txt<\/code> for the complete notice.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Back up the site and confirm hosting-panel or SSH access.<\/li>\n<li>Install and activate CodeCanvas Guard.<\/li>\n<li>Open CodeCanvas Guard and apply the Balanced profile.<\/li>\n<li>Configure 2FA from Users &gt; Two-Factor Security.<\/li>\n<li>Generate and save an emergency recovery link before configuring a protected login route.<\/li>\n<li>Verify and activate the protected route, then test it in a private browser.<\/li>\n<li>Test checkout, membership, mobile-app, PWA, password-reset, and integration flows before applying Strict mode.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20guard%20automatically%20remove%20malware%3F\"><h3>Does Guard automatically remove malware?<\/h3><\/dt>\n<dd><p>No. Scans report evidence. Trusted WordPress sources can be reinstalled and executable uploads can be quarantined only after explicit administrator approval. Custom, premium, database, or ambiguous findings remain manual-review items.<\/p><\/dd>\n<dt id=\"why%20can%20some%20plugins%20not%20be%20repaired%20automatically%3F\"><h3>Why can some plugins not be repaired automatically?<\/h3><\/dt>\n<dd><p>Automatic repair is available only when the exact installed version has a trusted WordPress.org package and checksum set. Premium, custom, or repository-removed plugins require a trusted vendor package or manual restoration.<\/p><\/dd>\n<dt id=\"does%20repair%20activate%20another%20plugin%3F\"><h3>Does repair activate another plugin?<\/h3><\/dt>\n<dd><p>No. Guard does not change another plugin's activation status. If WordPress leaves a repaired plugin inactive, Guard verifies the installed files and asks an administrator to reactivate it manually from the native Plugins screen.<\/p><\/dd>\n<dt id=\"are%20repairs%20reversible%3F\"><h3>Are repairs reversible?<\/h3><\/dt>\n<dd><p>Eligible plugin repairs create a protected pre-repair copy. Verification failure triggers file rollback, and successful repairs retain a manual rollback point. Permission repairs retain the previous mode. Quarantined files require a separate restore approval. Keep a current hosting backup.<\/p><\/dd>\n<dt id=\"does%20fingerprint%20reduction%20make%20wordpress%20impossible%20to%20detect%3F\"><h3>Does fingerprint reduction make WordPress impossible to detect?<\/h3><\/dt>\n<dd><p>No. Guard removes common public indicators and simple enumeration paths, but themes, assets, APIs, and behaviour can still reveal WordPress.<\/p><\/dd>\n<dt id=\"does%20the%20protected%20login%20route%20work%20with%20plain%20permalinks%3F\"><h3>Does the protected login route work with plain permalinks?<\/h3><\/dt>\n<dd><p>The request-path fallback is designed to work when pretty permalinks are unavailable. Hosting rules, caching, and other security plugins can interfere, so verify the route before activation.<\/p><\/dd>\n<dt id=\"will%20xml-rpc%20blocking%20affect%20integrations%3F\"><h3>Will XML-RPC blocking affect integrations?<\/h3><\/dt>\n<dd><p>It can. Jetpack, WordPress mobile apps, and other integrations may require XML-RPC. The Balanced profile leaves XML-RPC available.<\/p><\/dd>\n<dt id=\"should%20i%20enable%20hsts%20immediately%3F\"><h3>Should I enable HSTS immediately?<\/h3><\/dt>\n<dd><p>No. Enable HSTS only after the whole site and every required resource work permanently over HTTPS.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.2<\/h4>\n\n<ul>\n<li>Replaced standalone browser <code>&lt;style&gt;<\/code> output with WordPress-enqueued stylesheet assets.<\/li>\n<li>Moved login honeypot and Turnstile presentation rules into an enqueued login stylesheet.<\/li>\n<li>Tightened nonce ordering for settings and session actions so request data is inspected only after intent verification.<\/li>\n<li>Added explicit capability checks to self-service 2FA management actions.<\/li>\n<li>Rotated protected-login route-test tokens after successful verification so each test URL is single-use.<\/li>\n<li>Corrected the bundled QR generator source URL and WordPress.org contributor metadata.<\/li>\n<li>Added narrowly scoped Plugin Check annotations for Cloudflare Turnstile's required external service endpoints and reduced the session-user query to only rendered fields.<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Replaced repair, quarantine, rollback, permission, and vault mutations with the WordPress Filesystem API.<\/li>\n<li>Replaced the dynamic audit query with literal prepared queries and short-lived cache invalidation.<\/li>\n<li>Hardened public route, recovery-cookie, login-challenge, and settings input handling.<\/li>\n<li>Added narrow reviewer annotations for public authentication tokens, one-time migrations, custom audit tables, and optional Turnstile service loading.<\/li>\n<li>Scoped uninstall variables, completed new migration-state cleanup, and preserved the legacy audit table until explicit uninstall.<\/li>\n<li>Removed the export stream close warning and renamed the main runtime class to the unique plugin namespace.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Replaced the former three-letter namespace with the unique <code>CCGUARD_<\/code> and <code>ccguard_<\/code> prefixes.<\/li>\n<li>Added a verified migration for profiles, protected-login state, scan data, encrypted settings, 2FA metadata, transients, scheduled jobs, and audit events.<\/li>\n<li>Preserved existing emergency and pending route-test links during the namespace upgrade.<\/li>\n<li>Removed automatic activation of repaired plugins and added an explicit manual-reactivation result.<\/li>\n<li>Added WordPress privacy-policy text, a personal-data exporter, and an anonymizing eraser.<\/li>\n<li>Completed uninstall cleanup for new and legacy records, schedules, transients, metadata, tables, and protected vaults.<\/li>\n<li>Added complete external-service disclosures and human-readable QR source attribution.<\/li>\n<li>Updated WordPress compatibility metadata and reduced the directory readme below the processing limit.<\/li>\n<\/ul>\n\n<p>Older release history is available in <code>changelog.txt<\/code>.<\/p>","raw_excerpt":"Recovery-first WordPress security with protected login, 2FA, hardening, scanning, repair, monitoring, and activity logs.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353385","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353385"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/codecanvasinc"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353385"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353385"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353385"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353385"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353385"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353385"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}