Serious WordPress security that runs on any host.
IronGuardWP scans for malware, blocks attacks at the firewall, and hardens the settings attackers exploit. Pure PHP — no server access or command-line tools required. Start free, upgrade when you need more.
Free forever for one site. No card required.
plugin scan-results screenshot
(real UI pending — website.md §15)
WordPress is the biggest target on the web.
Not because it is weak — because it is everywhere. Attackers automate against the most common software, and that is WordPress. Almost none of it is targeted: it is automated, indiscriminate, and continuous, which is exactly why automated defence is the answer to it.
40%+
More than 40% of all websites run WordPress — a single exploit scales to millions of sites.
6
Of 11,334 WordPress vulnerabilities disclosed in 2025, just 6 were in core — the rest were plugins and themes.
Source: Patchstack, State of WordPress Security in 2026 (February 2026) (opens in a new tab)
5 hours
The weighted median time from disclosure to first exploit is 5 hours — about half of high-impact vulnerabilities are exploited within 24 hours.
Source: Patchstack, State of WordPress Security in 2026 (February 2026) (opens in a new tab)
How it works
Install the plugin
Upload it like any WordPress plugin and activate with your license key. No server access, nothing to configure on the host.
Scan and harden
Run your first scan, get a security score, and apply one-click fixes for the mistakes attackers rely on.
Stay protected
New malware definitions and firewall rules reach your site automatically as new threats appear.
Everything a WordPress site needs to stay clean
Malware scanning
Checks your files against curated malware signatures and flags anything that matches — in plain language.
Firewall
Blocks malicious requests before WordPress ever runs them.
Login protection
Locks out attackers after repeated failed logins so brute-force attacks fail.
Vulnerability alerts
Tells you when a plugin or theme you run has a newly disclosed CVE.
Hardening
One-click fixes for the common WordPress mistakes attackers rely on.
Plain-language reporting
Every finding says what happened, why it matters, and the recommended next step.
Runs on any host. Really.
Most serious malware scanners assume ClamAV or YARA binaries on the server. Shared hosting almost never has them. IronGuardWP's scanning engine is pure PHP — if WordPress runs, IronGuardWP runs.
Scans are incremental and throttled, and pause under load. Staying inside your host's CPU and memory limits is a design requirement, not an afterthought.
Simple per-site pricing
One license covers one domain. Cancel anytime through your Whop account.
Free
$0
forever · no card required
One personal site, basic hygiene. A real product, not a trial — it does not expire.
Get Started FreeNo card required. Does not expire.
Most Popular
Plus
$49
per site, per year
or $5 per site, per month
Business sites that must stay online. Everything in Free, plus the firewall, deep scanning, real-time monitoring and 2FA.
Get PlusRenews automatically. Cancel anytime through your Whop account.
Pro
$99
per site, per year
or $9 per site, per month
Agencies, e-commerce, high-value targets. Everything in Plus, plus virtual patching, the shared threat feed, auto-remediation and multi-site.
Get ProRenews automatically. Cancel anytime through your Whop account.
Full feature breakdown on the pricing page What counts as a site?
Common questions
Will this slow my site down?
Scans are incremental and throttled, and pause under load. The firewall adds a small amount of work per request. IronGuardWP is built for shared hosting — staying inside your host's CPU and memory limits is a design requirement, not an afterthought.
Do I need server access or special software?
No. The scanning engine is pure PHP. No ClamAV, no YARA, no SSH, no command line. If WordPress runs, IronGuardWP runs.
What counts as one site?
One domain. www.example.com and example.com count as the same site. Separate domains need separate licenses.
What happens if I cancel?
Your license runs to the end of the paid term, then the plugin drops back to Free. Nothing breaks and your site is never locked.
Can a plugin like this lock me out of my own site?
IronGuardWP is designed to fail open — if something goes wrong, it stops protecting rather than stopping your site. There is a documented emergency-disable procedure in the docs.
Protect your site in under five minutes.
Start free. No card, no expiry, no lock-in.
Get Started Free