About
All-in-one WordPress security, built to run anywhere.
IronGuardWP protects WordPress sites from malware, brute-force attacks, and known vulnerabilities. It scans your files against a curated malware definition set, blocks malicious traffic before it reaches WordPress, and tells you in plain language what happened and what to do about it. It runs in pure PHP on any host — no server access, no command-line tools, no ClamAV required.
Who we built it for
- Site owners and small businesses running WordPress who cannot afford a breach and do not have a security team.
- Freelancers and agencies managing client sites who need per-site protection and a single place to see it all.
- Hosts and resellers who want to bundle security with their offering.
Three things we will stand behind
Not the longest list we could write — the part of it we can defend.
It runs anywhere
The scanning engine is pure PHP. Most serious scanners assume ClamAV or YARA binaries on the host, and shared hosting rarely has them. IronGuardWP needs neither — no shell access, no command-line tools, no server configuration. If WordPress runs, it runs.
Curated definitions, not a firehose
Nothing third-party ships raw. Every signature is normalised into our own format, de-duplicated, and tested against a clean WordPress corpus before it reaches your site. A rule that matches a legitimate file is rejected outright — because a false positive quarantines a real file on a real site.
Findings you can act on
Every result says what happened, why it matters, and the recommended next step. No raw rule identifiers, no unexplained jargon. Security software that you cannot act on has told you nothing useful.
How we build it
Security software has more ways to hurt you than most software does. These are the constraints we work under.
It fails open, never closed
If something in the plugin goes wrong, it stops protecting rather than stopping your site. A security plugin that locks the owner out of their own admin has caused the outage it was bought to prevent. There is a documented emergency-disable procedure that does not require wp-admin.
Nothing destructive is one-way
Every action that deletes, quarantines, or repairs a file is reversible, or takes a restore point first. Automated cleaning is useful precisely because it can be undone when it gets something wrong.
Scans respect your host
Scanning is incremental, throttled, and resumable, and it pauses under load. Staying inside a shared host’s CPU, memory, and time limits is a design requirement, not a setting you have to discover after your host emails you.
A block hits the attacker, not your CDN
Behind a proxy or CDN, the address in the request is the proxy’s. Getting the real client address right — through configurable trusted headers — is what keeps an IP block from blocking everyone, or from blocking nobody.
We refuse definition feeds we are not licensed to ship.
No NonCommercial data and no vendor feed without a redistribution grant goes into any tier of IronGuardWP — including Free, which is part of a product we sell. Feeds on those terms are refused automatically before a definition bundle is built, rather than being a promise someone has to remember to keep.
This has a real cost. It ruled out the WordPress-specific vulnerability feeds we originally planned to use, which is why vulnerability data currently comes from the public CVE record alone. We would rather tell you that than ship data we have no right to redistribute.
Company details
[ PLACEHOLDER — NOT YET ESTABLISHED ]
The legal entity behind IronGuardWP, its registered address, and its company number are not settled yet, so they are not stated here. They will appear on this page, in the Terms, and in the Privacy Policy at the same time — and none of those documents is in force until they do.
We would rather leave this visibly blank than fill it with something that is not true.
Questions in the meantime, including anything about how the plugin behaves or what data it sends? Ask us directly
Try it on one site
Free is a real product, not a trial — one site, forever, no card. It is the honest way to find out whether any of the above holds up.
