Enterprise-grade protection in one free plugin — a real WAF, a 10-layer malware scanner, passkey authentication, live traffic monitoring, and compliance reporting.
Automated bots probe every WordPress installation around the clock — testing known vulnerabilities, weak credentials, and unpatched plugins. A compromised site means lost revenue, blacklisted domains, and customers who never return.
Protect My Site — FreeMost security plugins lock their best features behind expensive plans. UltraGuard ships its entire core — WAF, malware scanner, login protection — free with no time limit.
8 detection layers — OWASP patterns, geo-blocking, rate limiting, bot detection, auto-ban.
MD5 hashes, PHP heuristics, JS threats, core integrity via api.wordpress.org.
Brute-force lockout, URL obfuscation, IP bans, session management.
One-click: disable XML-RPC, remove version exposure, protect sensitive files.
Real-time SSE request feed — threat labels, geo hints, one-click blocking.
CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy.
Full activity trail — logins, failures, settings changes. Exportable.
Automated core, plugin, theme updates with scheduling and rollback.
Visual editor with template library and safe rollback.
Email, webhook, and Slack alerts per event type.
Takes under 2 minutes. Onboarding wizard launches automatically.
Other plugins scan files. UltraGuard goes deeper — ten independent detection layers including WordPress core integrity verification against official WordPress.org checksums, supply-chain dropper detection, and high-entropy string analysis.
Most plugins intercept requests after WordPress loads — too late. UltraGuard's WAF runs at the earliest possible hook, blocking threats at the door across 8 detection layers.
Unlock vulnerability scanning with virtual patching, database security, passkey auth, WooCommerce protection, and compliance reporting. Pro is $149 per year for one site, and Agency is $399 per year for up to 20 sites.
WebAuthn passkeys and TOTP two-factor with per-role enforcement.
CVE detection + Virtual WAF Patching against unpatched exploits.
Scan every DB table for injections, spam, and backdoors.
Instant alerts when any tracked file changes.
Cloud-synced hostile IP feeds integrated with your WAF.
Checkout rules, JS skimmer detection, WooCommerce-aware logging.
Continuous domain and IP blacklist monitoring.
Availability and certificate health with expiry alerts.
GDPR, PCI-DSS, ISO 27001, SOC 2 evidence reports.
Route-level access controls, API keys, rate limiting.
"The WAF alone replaced two paid plugins. The real-time traffic monitor is something I've never seen in a free plugin."
"We needed PCI-DSS compliance reports for an audit. UltraGuard Pro generated exactly what our auditors needed in minutes."
"Deployed across 15 agency sites in an afternoon. The onboarding wizard is clear and the dashboard gives real confidence."
Open the UltraGuard download page, grab the latest plugin ZIP, then upload it from Plugins → Add New → Upload Plugin.
The onboarding wizard launches automatically — select modules, apply settings, and seed baseline scan data.
WAF is live. Scans running. Login protection active. Monitor everything from the UltraGuard dashboard.
Download UltraGuard from our site in under two minutes. No account. No credit card. No trial period.