5,233 GPL Products · Updated DailyPRO Versions Available · Instant Download

Aegis User Guard

v1.3.2 Updated 2 days ago
Download Aegis User Guard 1.3.2
Free download · version 1.3.2

Description

At a glance

Looking for Aegis User Guard v1.3.2? It is available here as a free GPL download for WordPress — updated September 26, 2026 · requires WordPress 6.2+ & PHP 7.4+.

Aegis User Guard is a single, self-contained security console that adds the identity-policy controls most sites end up needing eventually: password expiration and complexity, inactivity lockout, brute-force protection, two-factor authentication, an IP allow/block list, and full oversight of every Administrator account. It does not replace WordPress’s login system or session handling; it layers policy and visibility on top of it, and every control can be switched off independently.

Everything lives on one native-feeling admin screen, organized into tabs:

  • Core controls — the identity policies below, each with its own on/off switch.
  • Recently added — a quick pulse of the newest accounts and their status.
  • Email notifications — the shared template and recipient list for Administrator security alerts.
  • Administrator directory — every Administrator, their last sign-in, active sessions, and one-click actions.
  • Access & IPs — a manual IP allow/block list.
  • Checklist — a read-only audit of common WordPress hardening gaps, with one-click fixes where Aegis can apply them.
  • Activity log — a chronological, exportable record of every security event Aegis observed.

Identity policies

  • Password freshness — prompt users to rotate their password after a configurable age (default 180 days).
  • Password complexity — require a minimum length and, optionally, mixed case, a number, and a symbol, enforced on password reset and profile changes.
  • Inactive account lockout — pause login access after a configurable period of inactivity (default 90 days).
  • Brute-force lockout — lock an account and its originating network after repeated failed sign-ins, independent of whether the attempted username exists.
  • Two-factor authentication (TOTP) — self-service setup from any user’s own profile (manual-entry key, no third-party QR service), with one-time backup codes and an option to require it for all Administrators.
  • REST API user-list restriction — block anonymous requests to /wp-json/wp/v2/users so usernames cannot be enumerated, while leaving authenticated requests untouched.
  • Administrator alerts — independently alert all or selected Administrators when a user is created, signs in, changes username, changes email address, or changes password. Administrator promotions remain covered as well.
  • New-device sign-in alerts — email a user when their own account signs in from an IP address not seen before.

Administrator oversight

  • A live directory of every Administrator account: last sign-in, status, active session count, and CSV export.
  • Manual Pause access / Reactivate access for any account, with native WordPress session termination.
  • A “Force password reset” action that requires a new password on next login and signs the account out everywhere.
  • A one-click “Sign out everywhere” action to end every active session for an account immediately.
  • A pending-Administrator review queue: new or newly promoted Administrators are blocked from signing in until an existing Administrator grants access.

Access control

  • A manual IP allow/block list — block a network outright, or exempt a trusted IP from brute-force lockouts.
  • Individual failed-sign-in logging, alongside every lockout, pause, and policy change, in the Activity log.

Hardening checklist

A read-only audit covering file-editing access, debug output exposure, HTTPS on wp-admin, a default “admin” username, the two-factor requirement, REST API user enumeration, and pending core/plugin updates — each with a plain-language fix, and a direct link into the relevant Aegis setting where Aegis can apply it itself.

Everything native

Aegis stores its data in standard WordPress options and user meta, uses native password-reset and session-termination APIs, and never introduces its own authentication layer. Disabling or deleting the plugin returns the site to stock WordPress behavior.

Features

  • Configurable password-expiration policy (default 180 days).
  • Configurable password-complexity policy (length, case, number, symbol).
  • Configurable inactivity lockout (default 90 days).
  • Configurable brute-force lockout, per account and per originating network.
  • Optional two-factor authentication (TOTP) with one-time backup codes, self-service from each user’s own profile.
  • Optional REST API restriction to stop anonymous username enumeration via /wp-json/wp/v2/users.
  • Event-level Administrator email alerts for account creation, successful sign-in, username, email, and password changes, with selectable recipients and a shared editable template.
  • Optional email alert to a user on sign-in from a new IP address.
  • Pending-Administrator review queue for new or newly promoted Administrators.
  • Administrator directory with last sign-in, live session counts, and CSV export.
  • “Force password reset” and “Sign out everywhere” actions for any account.
  • Security status column and manual Pause access / Reactivate access on the Users screen.
  • Manual IP allow/block list.
  • Read-only security hardening checklist with one-click fixes.
  • Chronological, searchable, exportable Activity log.
  • A single top-level, native-feeling WordPress admin screen — no external APIs are required for Aegis’s security controls, and the optional Gravatar avatar lookup is documented below.

External services

This plugin optionally uses the Gravatar service, operated by Automattic, to display profile images for Administrators in the Administrator directory. Gravatar is not required for Aegis’s security controls; the plugin displays its bundled placeholder image if a Gravatar image is unavailable.

When an Administrator directory is opened and WordPress has a Gravatar URL for an Administrator, the visitor’s browser requests the image from secure.gravatar.com (or the Gravatar URL returned by the site’s WordPress configuration). The request URL contains a hash of the Administrator’s normalized email address so Gravatar can select the associated image. The browser also sends normal HTTP request information, such as its IP address and user-agent, to the service. The request is made only to load that optional avatar image; Aegis does not send the Administrator’s raw email address to Gravatar.

Gravatar is provided by Automattic. See Gravatar’s Terms of Service and Privacy Policy for information about the service’s terms and data handling.

Frequently asked questions

What do I get when I download Aegis User Guard?

Aegis User Guard 1.3.2 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations.

Does Aegis User Guard cost anything?

No. Aegis User Guard 1.3.2 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.

How do I install Aegis User Guard 1.3.2?

Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.

What are the requirements for Aegis User Guard?

Aegis User Guard 1.3.2 requires WordPress 6.2 or higher and PHP 7.4 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.

When was Aegis User Guard last updated?

Version 1.3.2 was last updated on September 26, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.

Is the Aegis User Guard download safe?

The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.

Version: 1.3.2
Updated: October 1, 2026

Technical details

Version1.3.2
Last updatedSeptember 26, 2026
Requires WordPress6.2 or higher
Requires PHP7.4 or higher
AuthorAhnaf007
Tagslogin-security, password-policy, security, two-factor-authentication, user-management

Download Aegis User Guard

Download Aegis User Guard WP Plugin

Official Page ↗

Note: if the download does not start, disable your ad blocker and try again.

Leave a Comment