IC Security Guard
by ITclan BD 0 (0 reviews)

IC Security Guard

Protect your site from brute force attacks with hidden login, login lockout, Email OTP 2FA, REST API & XML-RPC hardening, and real-time email alerts.

IC Security Guard ranks #66,865 among WordPress.org plugins with 0+ active installations, is #3,732 of 4,596 in the Security category, and was last updated Aug 18, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.6 (Current: 7.1.2)
v1.3.0 Current Version v1.3.0
Updated 1 month ago Last Update on 18 Aug, 2026
Refreshed 17 hours ago Last Refreshed on
#3,732 of 4,596 in Security
View on WordPress.org
Rank
#66,865
No change
Active Installs
0+
-100%
KW Avg Position
196
21 worse
Downloads
226
+3 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 10

Total Progress 0%
0+ 10+
47,125
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 10 more installs to reach 10+

Rank Changes

45,768 51,601 57,435 63,269 69,103 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026 24-09-2026
45,739 51,581 57,423 63,264 69,106 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026 24-09-2026
Current #66,865
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026 24-09-2026
0 10 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026 24-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about IC Security Guard

You can always reach your site's database (via phpMyAdmin or your host) and update the icsegu_hidelogin_options option in the wp_options table to disable hide_login_url, restoring access to the default wp-login.php.
Logged-in users are always allowed through to /wp-admin regardless of the hidden login setting. The failed-login lockout only applies to failed authentication attempts, and resets automatically once the configured lockout duration passes.
No. Logged-in users pass through untouched. The hidden login, lockout, REST API, and XML-RPC protections only apply to unauthenticated visitors and failed authentication attempts.
Lockout state is stored per IP address using WordPress transients, so it persists across page reloads and works with whatever caching layer your site already uses. The same lockout state is shared by the login form, the REST API, and XML-RPC.
When enabled, after a user enters the correct username and password, they are redirected to a dedicated verification page and emailed a 6-digit code (sent to their WordPress account email address). The code must be entered within the configured expiry window to complete login. Codes can be resent with a short cooldown between requests, and login only completes after the correct code is verified. This step is automatically skipped for REST API and XML-RPC requests, since application passwords and API integrations authenticate programmatically and have no page to display a challenge on.
XML-RPC's system.multicall method allows an attacker to test many username/password combinations in a single HTTP request, bypassing typical per-request throttling. Enabling "Disable XML-RPC" turns off the XML-RPC endpoint entirely. If you rely on XML-RPC for a mobile app, Jetpack, or another integration, leave this option off — any failed XML-RPC login attempts are still covered by the shared lockout.
By default, WordPress's REST API exposes a list of registered usernames at /wp-json/wp/v2/users to anyone, even when logged out. Attackers use this to harvest valid usernames before a brute-force attempt. Enabling "Block REST API User Enumeration" returns an authorization error for unauthenticated requests to this endpoint, while logged-in requests are unaffected.
No. Real-time email alerts are sent once per alert type whenever an event first triggers, then suppressed for the configured cooldown period (15 minutes by default) even if the same type of event keeps happening. This keeps you informed without flooding your inbox during a sustained attack.
Those sections are currently marked "Coming soon" in the plugin settings and will be added in a future release.

Sign In / Register

You need to sign in or register to use this feature.