{"id":357298,"date":"2026-08-25T20:41:48","date_gmt":"2026-08-25T20:41:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/vyntic-wp-guard\/"},"modified":"2026-08-26T21:28:03","modified_gmt":"2026-08-26T21:28:03","slug":"vyntic-guard","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/vyntic-guard\/","author":23547160,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.7.2","stable_tag":"1.7.2","tested":"7.1","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"Vyntic Guard","header_author":"Vynatics","header_description":"WordPress security hardening with brute-force protection, blocked-IP management, activity logging, custom login URLs, security checks, and malware scanning.","assets_banners_color":"cbd1d5","last_updated":"2026-08-26 21:28:03","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/vynatics.corsysltd.com\/vyntic-guard","header_author_uri":"https:\/\/vynatics.corsysltd.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":56,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.7.1":{"tag":"1.7.1","author":"vynatics","date":"2026-08-25 21:20:24","revision":3666014},"1.7.2":{"tag":"1.7.2","author":"vynatics","date":"2026-08-26 21:28:03","revision":3667810}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3665986,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3665986,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500-rtl.jpg":{"filename":"banner-1544x500-rtl.jpg","revision":3665986,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3665986,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250-rtl.jpg":{"filename":"banner-772x250-rtl.jpg","revision":3665986,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3665986,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.7.1","1.7.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3665986,"resolution":"1","location":"assets","locale":"","width":1448,"height":1086},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3665986,"resolution":"2","location":"assets","locale":"","width":1448,"height":1086},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3665986,"resolution":"3","location":"assets","locale":"","width":1448,"height":1086},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3665986,"resolution":"4","location":"assets","locale":"","width":1448,"height":1086}},"screenshots":[]},"plugin_section":[],"plugin_tags":[8531,2439,1229,55021,600],"plugin_category":[54],"plugin_contributors":[],"plugin_business_model":[],"class_list":["post-357298","plugin","type-plugin","status-publish","hentry","plugin_tags-activity-log","plugin_tags-brute-force","plugin_tags-login-security","plugin_tags-malware-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_committers-vynatics"],"banners":{"banner":"https:\/\/ps.w.org\/vyntic-guard\/assets\/banner-772x250.jpg?rev=3665986","banner_2x":"https:\/\/ps.w.org\/vyntic-guard\/assets\/banner-1544x500.jpg?rev=3665986","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/vyntic-guard\/assets\/icon-128x128.png?rev=3665986","icon_2x":"https:\/\/ps.w.org\/vyntic-guard\/assets\/icon-256x256.png?rev=3665986","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/vyntic-guard\/assets\/screenshot-1.png?rev=3665986","caption":""},{"src":"https:\/\/ps.w.org\/vyntic-guard\/assets\/screenshot-2.png?rev=3665986","caption":""},{"src":"https:\/\/ps.w.org\/vyntic-guard\/assets\/screenshot-3.png?rev=3665986","caption":""},{"src":"https:\/\/ps.w.org\/vyntic-guard\/assets\/screenshot-4.png?rev=3665986","caption":""}],"raw_content":"<!--section=description-->\n<p>Vyntic Guard helps secure WordPress against brute-force login attacks, suspicious file changes, weak security configuration, and unwanted access attempts.<\/p>\n\n<p>The free plugin combines a malware scanner, brute-force protection, login security controls, IP blocking, activity logging, WordPress hardening, security checks, and a custom login URL in one dashboard. It runs locally without requiring a Vyntic account or license key.<\/p>\n\n<h4>Malware Scanner<\/h4>\n\n<p>Review potential file-security issues before taking action.<\/p>\n\n<ul>\n<li>Malware scanner with administrator review<\/li>\n<li>WordPress core integrity checks using official WordPress checksums when available<\/li>\n<li>Encrypted quarantine for selected files<\/li>\n<li>Recovery-copy downloads before destructive actions<\/li>\n<li>Permanent delete controls for administrator-reviewed findings<\/li>\n<li>No automatic deletion of scan findings<\/li>\n<\/ul>\n\n<h4>Brute Force &amp; Login Protection<\/h4>\n\n<p>Reduce repeated login attacks and control access to your WordPress login route.<\/p>\n\n<ul>\n<li>Brute-force protection with progressive lockouts<\/li>\n<li>Blocked IP manager with manual unblock controls<\/li>\n<li>Custom public login URL<\/li>\n<li>WordPress-generated login links updated for the custom route<\/li>\n<li>No renaming of WordPress core login files<\/li>\n<\/ul>\n\n<h4>Activity Log, IP Blocking &amp; Hardening<\/h4>\n\n<p>Monitor important activity and strengthen common WordPress security settings.<\/p>\n\n<ul>\n<li>Activity logging with configurable retention<\/li>\n<li>Security dashboard with configuration score<\/li>\n<li>Security configuration check<\/li>\n<li>WordPress hardening controls<\/li>\n<li>Fingerprint-reduction controls<\/li>\n<li>Central blocked-IP management<\/li>\n<\/ul>\n\n<h4>Local-First Privacy<\/h4>\n\n<p>Vyntic Guard Free does not require a Vyntic account. Activity logs and blocked-IP data are stored in the site's WordPress database and are not sent to Vyntic servers.<\/p>\n\n<h4>Vyntic Guard Pro<\/h4>\n\n<p>Vyntic Guard Pro is an optional add-on distributed separately. It adds:<\/p>\n\n<ul>\n<li>Two-factor authentication (2FA)<\/li>\n<li>Authenticator App (TOTP) with local QR enrollment<\/li>\n<li>Email, SMS, and WhatsApp OTP<\/li>\n<li>Passkey verification<\/li>\n<li>CAPTCHA and Google reCAPTCHA integration<\/li>\n<li>SMTP and Twilio provider configuration<\/li>\n<li>Stealth Engine for public WordPress path virtualization<\/li>\n<li>Drag-and-drop Login and 2FA Verification Page Builder<\/li>\n<\/ul>\n\n<p>Learn more about Vyntic Guard Pro at https:\/\/vynatics.corsysltd.com\/vyntic-guard<\/p>\n\n<h3>External Services<\/h3>\n\n<h4>WordPress Core Checksum API<\/h4>\n\n<p>The malware scanner can request official WordPress core checksums from <code>api.wordpress.org<\/code> when performing core-file integrity checks. The request contains the installed WordPress version and locale required by the WordPress checksum API. No Vyntic account is required for this request.<\/p>\n\n<h4>Site Self-Check<\/h4>\n\n<p>The Security Check can request the site's own public home page to inspect visible WordPress fingerprints. This request targets the site itself.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Vyntic Guard Free does not require a Vyntic account and does not send site security logs to Vyntic servers. Activity logs and blocked-IP data are stored in the site's WordPress database.<\/p>\n\n<p>The malware scanner can contact the official WordPress checksum API for core-file integrity checks as described in the External Services section.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install Vyntic Guard from Plugins &gt; Add New, or upload the <code>vyntic-guard<\/code> ZIP through Plugins &gt; Add New &gt; Upload Plugin.<\/li>\n<li>Activate Vyntic Guard.<\/li>\n<li>Open Vyntic Guard in wp-admin.<\/li>\n<li>Run the Security Check to review your current configuration.<\/li>\n<li>Review Login Protection before enabling or changing a custom login URL on a production site.<\/li>\n<li>Run the Malware Scanner and review findings before quarantining or deleting any file.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20security%20features%20are%20included%20in%20vyntic%20guard%20free%3F\"><h3>What security features are included in Vyntic Guard Free?<\/h3><\/dt>\n<dd><p>Vyntic Guard Free includes brute-force protection, login security controls, IP blocking, activity logging, WordPress hardening, security configuration checks, a custom login URL, and malware scanning.<\/p><\/dd>\n<dt id=\"does%20vyntic%20guard%20protect%20against%20brute-force%20login%20attacks%3F\"><h3>Does Vyntic Guard protect against brute-force login attacks?<\/h3><\/dt>\n<dd><p>Yes. Vyntic Guard uses progressive lockouts for repeated failed login activity. Administrators can review blocked IPs and manually unblock them when needed.<\/p><\/dd>\n<dt id=\"does%20vyntic%20guard%20include%20a%20malware%20scanner%3F\"><h3>Does Vyntic Guard include a malware scanner?<\/h3><\/dt>\n<dd><p>Yes. The free plugin includes a malware scanner that presents findings for administrator review. Selected files can be quarantined in encrypted storage, downloaded as recovery copies, or permanently deleted by an administrator.<\/p><\/dd>\n<dt id=\"does%20the%20malware%20scanner%20automatically%20delete%20files%3F\"><h3>Does the malware scanner automatically delete files?<\/h3><\/dt>\n<dd><p>No. Findings are presented for administrator review. Destructive actions require explicit administrator action.<\/p><\/dd>\n<dt id=\"can%20i%20change%20the%20wordpress%20login%20url%3F\"><h3>Can I change the WordPress login URL?<\/h3><\/dt>\n<dd><p>Yes. Vyntic Guard can expose a custom public login route and update WordPress-generated login links while leaving WordPress core files in place.<\/p><\/dd>\n<dt id=\"does%20vyntic%20guard%20free%20require%20a%20license%20key%20or%20account%3F\"><h3>Does Vyntic Guard Free require a license key or account?<\/h3><\/dt>\n<dd><p>No. Vyntic Guard Free does not require a license key or Vyntic account.<\/p><\/dd>\n<dt id=\"does%20vyntic%20guard%20send%20security%20logs%20to%20vyntic%20servers%3F\"><h3>Does Vyntic Guard send security logs to Vyntic servers?<\/h3><\/dt>\n<dd><p>No. Activity logs and blocked-IP data are stored in the site's WordPress database and are not sent to Vyntic servers by the free plugin.<\/p><\/dd>\n<dt id=\"are%20pro%20features%20included%20but%20disabled%20in%20the%20free%20zip%3F\"><h3>Are Pro features included but disabled in the free ZIP?<\/h3><\/dt>\n<dd><p>No. Premium implementation code is distributed separately in the Vyntic Guard Pro add-on.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.7.2<\/h4>\n\n<ul>\n<li>Fixed responsive hamburger colors, dark-mode Protection Module and table surfaces, icon backgrounds, active sidebar contrast, and topbar interaction cursors.<\/li>\n<li>Set command-search shortcut padding to 7px.<\/li>\n<li>Refined sidebar scrolling, profile menu, switches, upgrade hover states, and SVG toast icons.<\/li>\n<\/ul>\n\n<h4>1.7.1<\/h4>\n\n<ul>\n<li>Rebuilt the Vyntic Guard admin experience around the Security Command Center UI references.<\/li>\n<li>Refined the header, navigation, overview, login protection, security check, malware scan, cards, tables, responsive layout, and Pro upgrade surfaces.<\/li>\n<li>Added copy-login-URL interaction and printable security report export.<\/li>\n<li>Reset WordPress wp-toolbar padding on Vyntic Guard screens.<\/li>\n<li>Sidebar upgrade card scrolls with the navigation instead of remaining pinned.<\/li>\n<li>Fixed the Login Protection Summary layout with isolated icon, label, value, and meta selectors; full-width responsive alignment is preserved.<\/li>\n<li>Moved quarantine storage into a plugin-specific WordPress uploads directory and encrypted quarantined payloads at rest.<\/li>\n<li>Removed server-side arbitrary-path restore and added nonce-protected recovery-copy downloads.<\/li>\n<li>Reworked brute-force tracking to bounded storage and removed attacker-controlled per-IP\/per-username transients.<\/li>\n<li>Sanitized settings before extension hooks receive them and moved admin menu CSS into the enqueued stylesheet.<\/li>\n<li>Expanded unique prefixes for PHP classes and admin\/AJAX actions.<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>Renamed the plugin to Vyntic Guard and changed the WordPress.org slug\/text domain to <code>vyntic-guard<\/code>.<\/li>\n<li>Split premium features into the separately distributed Vyntic Guard Pro add-on.<\/li>\n<li>Added a Free vs Pro comparison table and Upgrade to Pro button.<\/li>\n<li>Kept brute-force protection, hardening, activity logging, custom login URLs, security checks, and malware scanning in Free.<\/li>\n<li>Added extension hooks used by the Pro add-on without bundling premium implementation code in the Free package.<\/li>\n<li>Kept the custom login URL disabled by default on new installs; administrators can enable it explicitly from Login Protection.<\/li>\n<\/ul>","raw_excerpt":"Security plugin with malware scanning, brute-force protection, login security, IP blocking, activity logs, hardening, and custom login URLs.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/357298","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=357298"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/vynatics"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=357298"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=357298"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=357298"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=357298"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=357298"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=357298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}