5,233 GPL Products · Updated DailyPRO Versions Available · Instant Download
GuardForge 1.3.5 – WordPress Plugin

GuardForge

v1.3.5 Updated 2 days ago Live Demo ↗
Download GuardForge 1.3.5
Free download · version 1.3.5

Description

At a glance

GuardForge v1.3.5 — free WordPress plugin download. Key facts: updated September 25, 2026 · requires WordPress 6.5+ & PHP 7.4+.

GuardForge hardens your WordPress site against common attacks without requiring an account or an API key. It applies proven hardening rules on activation, monitors for brute-force login attempts, protects your own account with two-factor authentication, checks your files against the build wordpress.org actually published, and keeps an audit log whose rows are hash-chained — so a line edited or deleted after the fact is detectable rather than deniable.

Nothing in the Free list below is capped, timed, or unlocked by paying. One thing in it reaches the network, it is off until you switch it on, and External services below describes it exactly: the file-integrity scan asks wordpress.org what your WordPress and your wordpress.org plugins are supposed to contain, so it can tell you when a file is not part of the official build — it sends a version number and a plugin slug, never your site’s address and nothing about your content.

Free

  • Hardening score — twenty-one checks of your own installation, scored 0-100, with each row stating exactly how many points it is worth and linking to the screen that fixes it. No outbound request: every check reads this site.
  • Staging / development mode — GuardForge notices when it is running on a copy of your site and stops acting on the world: lockouts are recorded but not enforced, and no notification e-mail, alert or firewall rule leaves the copy. Nothing that can switch it on survives a database copy, so a dump from staging can never disarm your live site.
  • Login brute-force protection with per-IP lockout and automatic unblock
  • Two-factor authentication for your own account — TOTP, a login challenge, and single-use recovery codes. Every logged-in user can reach the 2FA screen and protect their own login, not just administrators: editors, authors and shop managers hold accounts worth phishing too. The enrolment QR is drawn on your own server: no image is fetched from anywhere, so your secret never leaves the site.
  • File integrity against the official checksums — off until you switch the monitor on in Settings, because the comparison asks wordpress.org for the hashes. Once on: every core file, and every plugin hosted on wordpress.org, is compared against the hashes wordpress.org publishes for that exact release. So the screen can say more than “this changed since yesterday”: it separates files that are official, modified, missing, and not in the official build at all — which is what a backdoor looks like, and which no scan-to-scan comparison can ever see, because a shell that was already there when the baseline was taken looks like every other unchanged file.
  • A premium or custom plugin, and any theme, has no published hashes anywhere. Those files are marked “no reference” and stay on the scan-to-scan comparison. They are never counted as clean — a tick beside something nothing checked is worse than no tick at all.
  • A core file that is modified or missing is named on the screen with its verdict, next to a link to Dashboard Updates: re-installing WordPress is what puts core files back, and this plugin does not write into wp-admin or wp-includes itself.
  • Audit log, hash-chained — it records logins, failed attempts, option changes, plugin and theme activity, and user and role changes, and every row carries the hash of the row before it. Press “Verify chain” and the table is walked: change one field on one row and that row no longer matches its own hash; delete a row and the next one points at a hash nothing in the table produces. Neither is visible in the table itself, which is the point — an audit log an intruder can tidy up afterwards is decoration. Reading and verifying are free; only streaming it out as CSV is a Pro feature.
  • Security hardening: disable XML-RPC, remove version headers, protect wp-config.php via .htaccess
  • Content-Security-Policy header — your policy, sent report-only by default so a wrong rule cannot break the site
  • IP management — allowlist, lift a lockout, login-log browser
  • Spam-bot honeypot on the comment form
  • WordPress core file protection rules (.htaccess)

Pro

GuardForge Pro is a separate add-on (installed alongside this free plugin) that unlocks:

  • Two-factor enforcement policy — require every administrator to be enrolled before they can use the admin
  • Alerts to Telegram, Slack and a signed webhook — a card per channel rather than a box of JSON, each with its own minimum severity, a “Send test” that really sends through the same dispatcher, and a digest you can leave immediate or batch hourly or daily. Quiet hours hold the ordinary traffic until morning, while a lockdown or a malware finding goes straight through them. Bot tokens, Slack URLs and HMAC secrets are encrypted on your own site and the form never prints one back — it shows the last four characters and nothing else
  • Lockdown mode — one switch that closes registration, comments, XML-RPC and anonymous REST writes. It can also throw itself, if you ask it to: twenty different addresses locked out inside ten minutes, or a finding from the malware scanner. An automatic lockdown lifts itself after an hour, writes both ends to the audit log, e-mails you, and never fires on a copy of your site
  • Vulnerability database — published advisories for WordPress, your plugins and your themes, matched against what is installed here, in real time as they are issued
  • Patch by update — off until you switch it on: when an advisory names the version that fixes it and WordPress is offering an update that reaches it, GuardForge installs that update on cron, one plugin per run, with an allow list and a deny list, and tells you by e-mail and in the audit log. Never on a staging copy, never on a plugin directory that is a symbolic link, and never twice in a day after a failure
  • Geo-IP blocking — block or allowlist whole countries
  • Cloudflare Firewall Sync — push locked IPs into your own Cloudflare zone, with your own scoped token. Cloudflare’s published list of edge addresses is refreshed daily, IPv6 included, so a site behind a newer edge does not quietly start logging, counting and geo-locating every visitor as the edge itself
  • WAF managed ruleset — in-PHP firewall covering SQLi, LFI, XSS, and PHP injection
  • Malware scanner — heuristics + signature-based scanning across wp-content
  • AI Threat Analytics — batched incident summary and recommendations via forge-api
  • Audit log export (CSV, streamed — a year of log does not have to fit in memory)

GuardForge is part of the Forge Suite. Learn more and get Pro at https://avakode.com.

External services

This plugin reaches wordpress.org, and nothing else. Activating it contacts nobody and schedules nothing that would — the file-integrity monitor is off on a fresh install, and switching it on is what puts the daily lookup on the schedule. The only outgoing request it ever makes is the checksum lookup below, it happens only while the file-integrity monitor is switched on, and it asks a public catalogue a question that names nothing of yours.

wordpress.org, for the file-integrity scan. Off until you switch the monitor on in GuardForge > Settings. Then once a day, and whenever you press “Run scan now”, GuardForge asks api.wordpress.org for the checksum list of your WordPress version and locale, and downloads.wordpress.org for the checksum list of each installed plugin it hosts (its folder name and version number). Those are public catalogues: the request carries the version, the locale and the slug, and nothing else — not your site’s address, not your user list, not your content, not a licence key. Answers are cached, and one scan makes at most ten requests, so a site with sixty plugins is covered over a few days rather than in one burst. Switch the file-integrity monitor off in Settings and none of this happens.

  • Endpoints: https://api.wordpress.org/core/checksums/1.0/ · https://downloads.wordpress.org/plugin-checksums/
  • WordPress.org terms: https://wordpress.org/about/terms/ — privacy: https://wordpress.org/about/privacy/

Nothing about your site is sent on a schedule or in the background. A fresh install makes no request at all and schedules none; with the file-integrity monitor switched on it has one daily request — the checksum lookup, while that monitor is on — and it asks a public catalogue a question that names nothing of yours. Switch the file-integrity monitor off and this plugin makes no outgoing request at all.

Uninstalling

Deleting GuardForge always removes one thing: your two-factor enrolments. That table holds TOTP shared secrets and single-use recovery codes — credential material — and once the plugin is gone nothing can use them, while a database that outlives the plugin gets backed up, exported and copied to staging. Reinstalling means enrolling again, which takes half a minute; leaving shared secrets behind has no upside at all.

Everything else stays by default: your login log, file-integrity snapshots, audit trail and settings all survive a delete, so removing the plugin by accident does not take your history with it. If you want a clean slate, tick Delete GuardForge data on uninstall in GuardForge Settings before you delete.

The hardening score

GuardForge Hardening score works out one number from twenty-one checks of this installation. Every check reads your own site — options, constants, your .htaccess, your user list, WordPress’s own update transients. Nothing is fetched from anywhere, which is also why the score cannot verify a header by fetching your homepage: the score makes no external request of any kind, and that promise is worth more than the extra check. The three things in the free plugin that reach the network — the “Explain” button, the integrity scan’s checksum lookup and the daily advisory download — are all described above, and none of them is the score: it reads what the last scan already worked out and asks nobody anything.

A check that cannot apply here leaves the sum entirely rather than scoring zero. An nginx site has no .htaccess to write, so the two .htaccess checks go to “does not apply” and the remaining checks grow to fill the hundred. Marking a correctly configured site down for lacking an Apache file would be theatre.

Every check sits in one of four weight buckets, and there are no others. 12 is the control whose absence is how sites actually get taken over; 8 is a direct route in, or the loss of the evidence that one was used; 5 is reconnaissance and exposure that shortens somebody else’s work; 2 is worth doing, cheap, and not what the incident report will name. The full table:

  • https — 12
  • two_factor_admins — 12
  • updates_pending — 12
  • debug_display — 8
  • xmlrpc — 8
  • brute_force — 8
  • file_edit — 8
  • integrity_baseline — 8
  • admin_username — 5
  • user_enumeration — 5
  • rest_restricted — 5
  • security_headers — 5
  • csp — 5
  • sensitive_files — 5
  • audit_log — 5
  • hide_version — 2
  • directory_listing — 2
  • login_captcha — 2
  • pingback — 2
  • bad_useragents — 2
  • notifications — 2

The points a row advertises are the points you actually gain: the weights above are shared out over the checks that apply to your site so that they add up to exactly one hundred, and the headline is the sum of what those rows earned. With the Pro add-on installed and licensed, one more row joins the same list — installed plugins and themes with a published advisory, at 12 — and the shares are worked out again around it. Without the add-on that row does not exist and nothing on the screen mentions it.

The public badge

Off unless you switch it on. When you do, GuardForge issues a link on your own site that publishes a letter grade and the month it was worked out — nothing else.

The grade is not your score. It is worked out only from the eleven checks a stranger can already run against your site from outside with no login: the scheme, XML-RPC, whether ?author=1 gives up a login name, whether the REST API answers anonymous callers, the version in your generator tag, your response headers, your Content-Security-Policy header, whether a directory lists its contents, whether sensitive files answer directly, the login form, and the X-Pingback header. Everything on that list is already public, so the badge tells a passer-by nothing they could not have found by loading your site.

Your numeric score, your two-factor coverage, your brute-force thresholds, your integrity results, whether an account is called admin, your pending updates and any vulnerable components are never published, in any form. The link carries an unguessable token so nobody can walk a list of sites looking for weak ones, it can be reissued or turned off at any moment, views are never logged, and until you switch it on the address is not registered at all — your site answers WordPress’s own 404, exactly like a site without the plugin.

Frequently asked questions

What do I get when I download GuardForge?

GuardForge 1.3.5 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations.

Does GuardForge cost anything?

No. GuardForge 1.3.5 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.

How do I install GuardForge 1.3.5?

Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.

What are the requirements for GuardForge?

GuardForge 1.3.5 requires WordPress 6.5 or higher and PHP 7.4 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.

When was GuardForge last updated?

Version 1.3.5 was last updated on September 25, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.

Is the GuardForge download safe?

The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.

Version: 1.3.5
Updated: October 1, 2026

Technical details

Version1.3.5
Last updatedSeptember 25, 2026
Requires WordPress6.5 or higher
Requires PHP7.4 or higher
Authoravakodeforge
Tagsaudit-log, firewall, login-protection, security, two-factor-authentication
Demo GuardForge

Download GuardForge

Download GuardForge WP Plugin

Official Page ↗

Note: if the download does not start, disable your ad blocker and try again.

Leave a Comment