Admin Safety Guard
Admin Safety Guard locks down the two places WordPress sites actually get broken into: the login form and the admin area. You don’t need to know what a firewall rule is to use it. Turn on a switch, pick a number, save. The plugin handles the rest and shows you, in plain words, what it blocked and what still needs your attention. If you have ever looked at your login log and seen hundreds of failed attempts for a user called “admin” that you never created, this plugin is for you. How WordPress sites get broken into Almost every automated attack follows the same three steps: A bot loads yoursite.com/wp-login.php, because that address is the same on every WordPress site in the world. It guesses usernames and passwords, thousands of times an hour, until one works. Once it’s in, it installs a backdoor, injects spam links, or quietly adds itself as an administrator. Admin Safety Guard breaks that chain at every step, and every feature below is free. Free features Limit login attempts (on by default) Lock out an IP address after a set number of failed sign-ins. You choose how many attempts are allowed, how long the lockout lasts, and what the person sees. Keep failing and the address is blocked for a full 24 hours. This is the one feature that switches itself on when you activate the plugin, so your site is covered before you configure anything. It doesn’t only watch wp-login.php. XML-RPC, application passwords and custom theme login forms all count towards the same limit, which is how most bots get around simpler login limiters. Add your own IP to the trusted list so you can never lock yourself out. Single addresses, CIDR ranges (203.0.113.0/24), wildcards (203.0.113.*) and IPv6 all work. Custom login URL Move your sign-in page to an address only you know, like yoursite.com/office-door. After that, wp-login.php and wp-register.php return a 404 for everyone, so scanners find nothing to attack. It works on root installs, WordPress in a subfolder, and multisite. Reserved slugs that would break your site are rejected before you can save them. Two-factor authentication by email After the password comes a one-time code, sent to the user’s inbox. A stolen password on its own becomes useless. You decide which roles need it (administrators and editors only, for example), how many digits the code has, how long it stays valid, and how many wrong guesses are allowed before it’s destroyed. The email is styled by default, and you can write your own subject and body if you’d rather. Google reCAPTCHA (v2 and v3) Add reCAPTCHA to your login form to stop bots before they ever submit a password. Both the “I’m not a robot” checkbox and the invisible v3 score check are supported. Paste in your site key and secret key, pick a version, done. Session security Everything above protects the sign-in. This protects what happens after it. WordPress keeps a session alive for two days, or fourteen if someone ticked “Remember Me” – however long the laptop sits open in a coffee shop. Sign people out after a period of inactivity, shorten the maximum session length, end every other session when someone changes their password, and optionally tie a session to the IP address it started from so a copied cookie stops working elsewhere. IP blocking Some addresses don’t deserve a second chance. Add them to the permanent block list and they never reach your login page again. You can also block an address in one click straight from the login log. Login logs and activity tracking A real audit trail: every successful sign-in and every failed attempt, with username, IP address, browser, and timestamp. Search it, sort it, page through it, export it to CSV for a client report, or clear out old entries by date range. You can also get an email the first time an administrator signs in from an address that account has never used before. That’s often the earliest sign that a password has leaked. Threats blocked Every block the plugin performs is recorded in one place: lockouts, blocked addresses, failed reCAPTCHA checks, wrong two-factor codes, blocked XML-RPC requests, username-discovery attempts. The dashboard shows what was stopped and when, so “is anything actually happening?” has a real answer. Security score The score grades your site, not the plugin. It checks the things that matter – HTTPS, whether core and PHP are current, whether an account is literally called “admin”, whether your usernames are public, whether file editing is still enabled – and weighs them against the protections you have switched on. Anything critical gets flagged at the top of your admin screen until it’s dealt with. Privacy hardening Nine one-click switches that close the small leaks attackers use for reconnaissance: Disable XML-RPC Block username discovery through ?author=1 and the REST users endpoint Show one generic error instead of telling people which half of the login was wrong Hide your WordPress version from page source, feeds and asset URLs Remove the RSD, Windows Live Writer and shortlink meta tags Disable pingbacks so your site can’t be used to flood someone else’s Disable the theme and plugin file editors Send browser security headers (clickjacking, MIME sniffing, referrer leaks, camera and microphone access) Disable application passwords Password protect the whole site Put a password in front of everything. Handy for staging sites, client previews and coming-soon pages. Choose how long access lasts and which roles skip it. Hide the admin bar by role Decide which roles see the toolbar on the front end. Hide it from subscribers and customers, keep it for editors and administrators. Brand your login page Swap the WordPress logo for yours, set its size, where it links to, and its alt text. Change the page background (colour or image), the form background, text, link and button colours, round off the corners, hide the links you don’t want, tick “Remember Me” by default, or write your own CSS. Ready-made templates are included if you’d rather not fiddle. Firewall and malware overview One screen showing your firewall status, with a link to our free Deep Malware Cleaner plugin for scanning and cleanup. If it’s already installed, the screen takes you straight to it. Pro features Admin Safety Guard Pro adds the tools agencies and busier sites tend to ask for. Passwordless login (magic links) Users click a one-time link in their email instead of typing a password. The link works once and then expires. 2FA with an authenticator app Google Authenticator, Authy and anything else that speaks TOTP. Users scan a QR code once and generate codes on their phone from then on – no email delivery to wait for. Social login Let people sign in with Google, Facebook or other accounts they already have, while you keep control of which providers are allowed. Database prefix check The default wp_ prefix is known to every attacker and makes SQL injection easier to write. This finds your current prefix and walks you through changing it safely. Strong password enforcement Set a minimum password strength. Weak passwords get rejected at the point they’re created, not after an incident. Advanced web application firewall Inspect incoming requests and block SQL injection and cross-site scripting payloads before WordPress ever sees them. Run it in monitor-only mode first, whitelist trusted addresses, block user agents, and cap request size. Malware scanning and cleanup Handled by our separate free plugin, Deep Malware Cleaner, rather than a second half-built scanner in here. Upgrade to Pro to unlock all Pro features. Who uses it Bloggers and content creators – protection that runs in the background with nothing to maintain. Small business owners – your site is your shopfront. A hack costs you customers and takes days to clean up. WooCommerce stores – customer records, addresses and order history sit behind that login form. Lock it properly. Freelancers and web designers – hand over a site that’s already hardened and branded, without a security bill attached. Agencies – the same repeatable setup across every client site, with logs you can export when someone asks what happened. Developers – every limit, message and redirect is configurable, and the features are built on standard hooks and filters you can extend. What’s different about it Light. Admin assets only load on the plugin’s own screens, and only the code for the screen you’re actually looking at. Nothing is added to your front end. Useful straight away. Limit login attempts switches itself on at activation. You’re protected before you open the settings. Honest about free vs Pro. Pro features are visible and clearly labelled. Nothing pretends to be free and then asks for a card. Written to WordPress standards. Inputs sanitised, output escaped, nonces on every request, prepared statements on every query, and a real uninstall routine that removes its own data when you delete it. Support Free support is on the WordPress.org forum. For anything Pro-related or urgent, use our contact form. External Services This plugin uses the following third-party and external services: 1) Google reCAPTCHA (Google LLC) Purpose: Used to protect forms from spam and automated abuse. When it is used: – When reCAPTCHA is enabled in plugin settings – On login forms and support forms protected by reCAPTCHA What data is sent: – User IP address – reCAPTCHA response token generated by Google – Browser information as required by Google reCAPTCHA Service provider: Google LLC Terms of Service: https://policies.google.com/terms Privacy Policy: https://policies.google.com/privacy 2) ThemePaste API (Plugin Author Service) Purpose: Used for: – Collecting optional admin email addresses for plugin updates and notifications – Sending support requests from the plugin support form – Collecting optional feedback when a user attempts to deactivate the plugin – Managing plugin-related notifications (only if the user provides contact details) When it is used: – When a user submits the built-in support form – When a user opts to send diagnostic information – Submitting the optional deactivation feedback form What data is sent: – Name – Email address – Phone number (if provided) – Message content – Site URL – Plugin name – Feedback text (if provided) – Support message content – Deactivation reason (if provided) No data is sent without user action. Service provider: ThemePaste.com Terms of Service: https://themepaste.com/terms-condition Privacy Policy: https://themepaste.com/privacy-policy Development / Source Code This plugin ships compiled JavaScript bundles in: – assets/admin/build/*.bundle.js The original, human-readable source files are included in this plugin under: – spa/admin/ They are also available at https://github.com/themepaste/admin-safety-guard Build Tools – Node.js (LTS recommended) – npm – Webpack + Babel Source Entry Points The admin SPA bundles are built from the following entry points: spa/admin/login-template/Main.jsx -> assets/admin/build/loginTemplate.bundle.js spa/admin/login-logs-activity/Main.jsx -> assets/admin/build/loginLogActivity.bundle.js spa/admin/analytics/Main.jsx -> assets/admin/build/analytics.bundle.js spa/admin/security-core/Main.jsx -> assets/admin/build/securityCore.bundle.js spa/admin/firewall-malware/Main.jsx -> assets/admin/build/firewallMalware.bundle.js spa/admin/privacy-hardening/Main.jsx -> assets/admin/build/privacyHardening.bundle.js spa/admin/2fa-using-mobile-app/Main.jsx -> assets/admin/build/twoFAUsingMobileApp.bundle.js React and the webpack runtime are extracted into shared chunks (framework.bundle.js and runtime.bundle.js) so they are downloaded once rather than being inlined into every bundle. Install Dependencies From the plugin root directory (where package.json lives): 1) Install dependencies: npm install Build (Production) To generate the production bundles: npm run build Output Location Webpack outputs the compiled bundles to: assets/admin/build/[name].bundle.js Important Notes – Do not edit files in assets/admin/build/ directly. They are generated files. – Edit the source files under spa/admin/ and re-run the build command. – For WordPress.org distribution, production builds should be used (mode=production). Links Website Documentation Pro Version Facebook Pinterest LinkedIn Instagram
Top keywords
- admin30×1.51%
- login17×0.85%
- build14×0.70%
- bundle12×0.60%
- js12×0.60%
- assets11×0.55%
- bundle js11×0.55%
- site11×0.55%
- wordpress11×0.55%
- address10×0.50%
- admin build10×0.50%
- assets admin10×0.50%
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
WordPress Backup & Migration Plugin Duplicator provides a simple way to move WordPress sites, create reliable backups, or clone a site for staging. With Duplicator, you can easily migrate, transfer, or clone your WordPress site between domains or hosts with no downtime. Create full backups of your website, or package your entire site to download and install elsewhere with only a few steps. At Duplicator, reliability, security, and ease of use are our top priorities. Duplicator is built on the same engine as Duplicator Pro: backups of any size, encrypted archives, 1-click restore and cloud storage are all part of the free plugin. Our easy migration wizard makes Duplicator the most beginner-friendly backup and migration plugin on the market. You don’t have to hire a developer. Create a backup and migrate sites in just a few minutes. Duplicator Pro This plugin is the Lite version of Duplicator Pro, which comes with scheduled backups, cloud storage integrations, multisite support, staging sites and more. Get Duplicator Pro for the complete migration and backup solution. Easy Site Migration, Backup, and Cloning Duplicator streamlines site migrations by packaging your website files and database into a single file, known as a “backup”. Download and re-install your “backup” on any new WordPress location or server without dealing with complicated setups. Launch at your new destination without installing WordPress. Duplicator is the only migration and backup plugin that works on an empty site. See why experts love Duplicator: “Duplicator provides an easy to use tool to make backups of your site, or to transfer it to another location.” Richard McAdams – Expert Web Developer Backups Without Size Limits Duplicator’s chunked backup engine splits the work into small steps, so backups of any size complete even on shared hosting with strict server timeouts. Pick the archive engine that fits your server (DupArchive, ZipArchive or shell zip) and the database engine you prefer (mysqldump or chunked PHP). Backups build in the background while you keep working, and Duplicator runs on managed hosts such as WordPress.com, WP Engine and GoDaddy Managed. AutoTune: Backup Settings That Configure Themselves Not sure which settings your server needs? AutoTune runs real test backups and finds the configuration that works on your host, automatically. Before every backup Duplicator checks your server configuration, and when something goes wrong it explains the problem in plain language and offers a one-click fix. Secure WordPress Backups Duplicator offers WordPress backups with military-grade encryption. Protect any backup with a password and AES-256 archive encryption, and see the security status of every backup at a glance. Automatically backup your entire WordPress site to secure cloud storage. 1-Click Restore Restore any backup with a single click from your WordPress dashboard: no FTP, no manual installer upload. Duplicator makes 1-click restores easy and stress-free. Quickly restore your entire website in minutes just like a time machine. Duplicator Cloud Storage Keep your backups off-site with Duplicator Cloud, our own secure cloud storage built for WordPress backups. Connect your account, send backups to the cloud and restore them from the cloud when you need them. You can also keep backups in several local folders with automatic retention of the most recent ones. Duplicator Pro adds Dropbox, Google Drive, OneDrive, Amazon S3, FTP/SFTP and any S3-compatible provider. Fast WordPress Migrations Duplicator makes WordPress website migrations fast and stress-free. Quickly move to a new host, domain, or server. No downtime, no data loss, and no coding required. WordPress Multisite Backups Duplicator offers automatic WordPress Multisite backups with easy 1-click restore. Safely backup your entire Multisite network to secure cloud storage. WooCommerce Backups Duplicator offers reliable WooCommerce backups with military-grade encryption. Easily and automatically back up your entire online store to secure cloud storage. Pre-configured WordPress Installs Never start from scratch with Duplicator’s smart pre-configured WordPress installs. Save time and hassle duplicating ready-made sites with 1-click. WordPress Recovery Points with Quick Rollbacks Duplicator offers hourly recovery points and 1-click rollbacks for WordPress sites. Quickly and automatically recover from failed WordPress updates or disasters. Partial WordPress Backup Plugin Duplicator makes partial backups for WordPress quick and easy. Save storage and restore sites faster with database-only, media-only, or completely custom backups. Server to Server WordPress Migration Import Tool Duplicator makes server-to-server WordPress migrations fast and hassle-free. Quickly import your website to a new server in minutes. No downtime, no data loss. Smart WordPress Migration Wizard Duplicator’s smart WordPress migration wizard makes transferring your website to a new host or server effortless. Advanced installer options, custom search and replace rules and security key regeneration are all included. No downtime, no data loss, and no code required. Drag & Drop Import WordPress Website Tool Migrating WordPress sites has never been easier with Duplicator’s drag & drop import tools. Quickly transfer your site to a new host or server in minutes, no code required. Clone WordPress Website Plugin Duplicator clones your entire WordPress website with 1-click, no code needed. Perfect for staging sites, sandbox, or site migration. WordPress Staging Site Duplicator Pro lets you create a WordPress staging site directly from your WordPress dashboard. Safely test plugin updates, theme changes, and new features on a staging environment before pushing changes to your live site. No manual setup, no separate hosting, and no risk to your production site. AI Ready Backups Duplicator exposes its backup abilities through the WordPress Abilities API, so AI assistants can list your backups, create a new one and check its status on your behalf. Every action respects your WordPress permissions. Duplicator Pro Features Duplicator Pro takes Duplicator to the next level with features you’ll love, such as: WordPress staging sites – create a staging copy of your site to safely test changes before going live Drag and Drop installs – just drag the backup file to the destination site! Server to server import – import a backup directly from a URL or from cloud storage, no download needed Scheduled backups – daily, weekly, monthly or hourly, each with its own template and storage destinations Backup templates to save and reuse your backup configurations Cloud Storage to Dropbox Backups, Google Drive Backups, Microsoft OneDrive Backups, Amazon S3 Backups and FTP/SFTP Backups Any S3-compatible provider: Backblaze B2, Wasabi, Cloudflare R2, DigitalOcean Spaces, Google Cloud Storage, Vultr, DreamObjects and more Unlimited storage destinations – send every backup to several locations at once Quick Connect to Duplicator Cloud with your license key Custom Backups and Cloning: want just plugins, or just themes, just the media? No problem! Recovery Points added for very fast emergency site restores Multisite support – back up and migrate an entire WordPress network, install a subsite as a standalone site or import a site into a network Subsite filtering – back up only the subsites you need Installer branding – white-label the installer with your own look and feel Multi-threaded, chunked engine to support larger websites & databases Support for managed and shared hosts such as WordPress.com, WPEngine, GoDaddy Managed, and more WP-CLI commands for backups and automation Custom plugin hooks for developers Advanced permissions – control which roles and users can create, restore, transfer or configure backups Email notifications when a scheduled backup fails Automatic updates and professional support … and much more! Supported Backup Cloud Storage Integrations The free plugin stores backups locally and on Duplicator Cloud. Duplicator Pro adds any Amazon S3 compatible storage provider plus these first-party integrations. Duplicator Cloud Backups Localhost Backups FTP/ SFTP Backups Dropbox Backups Google Drive Backups Microsoft OneDrive Backups Amazon S3 Backups Cloudflare R2 Backups Wasabi Backups Dream Objects Backups Vultr Backups Digital Ocean Spaces Backups Google Cloud Storage Backups Backblaze B2 Storage Backups Linode Object Storage Backups You can easily see why Duplicator is the best WordPress backup and migration plugin on the market! Want to unlock these features? Upgrade to our Pro version Branding Guidelines Duplicator® is a registered trademark of Snap Creek LLC. When writing about the backup & migration plugin by Duplicator, please make sure to uppercase the initial first letter. Duplicator (correct) duplicator (incorrect)