Title: SiteGuard WP Plugin
Author: jp-secure
Published: <strong>22. oktober, 2014</strong>
Last modified: 4. desember, 2025

---

Søk i utvidelser

![](https://ps.w.org/siteguard/assets/banner-772x250.png?rev=1011863)

![](https://ps.w.org/siteguard/assets/icon-256x256.png?rev=1011863)

# SiteGuard WP Plugin

 Av [jp-secure](https://profiles.wordpress.org/jp-secure/)

[Last ned](https://downloads.wordpress.org/plugin/siteguard.1.7.9.zip)

 * [Detaljer](https://nb.wordpress.org/plugins/siteguard/#description)
 * [Omtaler](https://nb.wordpress.org/plugins/siteguard/#reviews)
 *  [Installering](https://nb.wordpress.org/plugins/siteguard/#installation)
 * [Utvikling](https://nb.wordpress.org/plugins/siteguard/#developers)

 [Brukerstøtte](https://wordpress.org/support/plugin/siteguard/)

## Beskrivelse

You can find docs, FAQ and more detailed information on [English Page](https://www.jp-secure.com/siteguard_wp_plugin_en/)
[Japanese Page](https://www.jp-secure.com/siteguard_wp_plugin/).

Simply install the SiteGuard WP Plugin, WordPress security is improved.
 This plugin
is a security plugin that specializes in the login attack of brute force, such as
protection and management capabilities.

Notes

 * It does not support the multisite function of WordPress.
 * It only supports Apache 1.3, 2.x for Web servers.
 * To use the CAPTCHA function, the expansion library “mbstring” and “gd” should
   be installed on php.
 * To use the management page filter function and login page change function, “mod_rewrite”
   should be loaded on Apache.
 * To use the WAF Tuning Support, WAF ( SiteGuard Server Edition ) should be installed
   on Apache.

There are the following functions.

 * Admin Page IP Filter

It is the function for the protection against the attack to the management page (
under wp-admin.)
 To the access from the connection source IP address which does
not login to the management page, 404 (Not Found) is returned. At the login, the
connection source IP address is recorded and the access to that page is allowed.
The connection source IP address which does not login for more than 24 hours is 
sequentially deleted. The URL (under wp-admin) where this function is excluded can
be specified.

 * Rename Login

It is the function to decrease the vulnerability against an illegal login attempt
attack such as a brute force attack or a password list attack.
 The login page name(
wp-login.php) is changed. The initial value is “login_<5 random digits>” but it 
can be changed to a favorite name.

 * CAPTCHA

It is the function to decrease the vulnerability against an illegal login attempt
attack such as a brute force attack or a password list attack,
 or to receive less
comment spam. For the character of CAPTCHA, hiragana and alphanumeric characters
can be selected.

 * Login Lock

It is the function to decrease the vulnerability against an illegal login attempt
attack such as a brute force attack or a password list attack.
 Especially, it is
the function to prevent an automated attack. The connection source IP address the
number of login failure of which reaches the specified number within the specified
period is blocked for the specified time. Each user account is not locked.

 * Login Alert

It is the function to make it easier to notice unauthorized login. E-mail will be
sent to a login user when logged in.
 If you receive an e-mail to there is no logged-
in idea, please suspect unauthorized login.

 * Fail Once

It is the function to decrease the vulnerability against a password list attack.
Even is the login input is correct, the first login must fail.
 After 5 seconds 
and later within 60 seconds, another correct login input make login succeed. At 
the first login failure, the following error message is displayed.

 * Disable Pingback

The pingback function is disabled and its abuse is prevented.

 * Block Author Query

Prevents leakage of user names due to «/?author=» access.

 * Updates Notify

Basic of security is that always you use the latest version. If WordPress core, 
plugins, and themes updates are needed , sends email to notify administrators.

 * WAF Tuning Support

It is the function to create the rule to avoid the false detection in WordPress (
including 403 error occurrence with normal access,)
 if WAF ( SiteGuard Server Edition)
by EG Secure Solutions is installed on a Web server. WAF prevents the attack from
the outside against the Web server, but for some WordPress or plugin functions, 
WAF may detect the attack which is actually not attack and block the function. By
creating the WAF exclude rule, the WAF protection function can be activated while
the false detection for the specified function is prevented.

#### Translate

If you have created your own language pack, or have an update of an existing one,
you can send [gettext PO and MO files](https://codex.wordpress.org/Translating_WordPress)
to sgdev@jp-secure.com so that We can bundle it into SiteGuard WP Plugin. You can
download the latest [POT file](https://plugins.svn.wordpress.org/siteguard/trunk/languages/siteguard.pot),
and [PO files in each language](https://plugins.svn.wordpress.org/siteguard/branches/languages/).

## Skjermbilder

 * [[
 * SiteGuard WP Plugin – Dashboard –

## Installasjon

 * WordPress dashboard

 1. Please search and install «SiteGuard WP Plugin» from ‘Plugins’ menu of WordPress
    dashboard
 2. Activate the plugin through the ‘Plugins’ menu of WordPress dashboard

 * WordPress.org plugin directory

 1. Please search and download «SiteGuard WP Plugin»
 2. Please upload and install a ZIP file that you downloaded through ‘Plugins’ menu
    of WordPress dashboard
 3. Activate the plugin through the ‘Plugins’ menu of WordPress dashboard

## Ofte stilte spørsmål

[English Page](https://www.jp-secure.com/siteguard_wp_plugin_en/faq/)
 [Japanese Page](https://www.jp-secure.com/siteguard_wp_plugin/faq/)

## Vurderinger

![](https://secure.gravatar.com/avatar/ee823466c87bf43768dd597aaa33920bbf3ea8db2b79af68fb0f759a45734f4a?
s=60&d=retro&r=g)

### 󠀁[Unsafe](https://wordpress.org/support/topic/unsafe-7/)󠁿

 [alexbrowp](https://profiles.wordpress.org/alexbrowp/) 27. november, 2024

When you log out, the session is not closed and you can still go to wp-admin. Also,
redirecting wp-admin to the custom login page doesn’t help with security

![](https://secure.gravatar.com/avatar/3546620ab46070b37c36542678c8ccbefebd0ea79f4d00fe0ccb1a0aa851a32e?
s=60&d=retro&r=g)

### 󠀁[.](https://wordpress.org/support/topic/%e6%97%a5%e6%9c%ac%e3%81%ae%e4%bc%81%e6%a5%ad%e3%81%aa%e3%81%ae%e3%81%ab%e6%97%a5%e6%9c%ac%e8%aa%9e%e8%a8%80%e8%aa%9e%e3%81%aa%e3%81%97/)󠁿

 [wpuserjp202306t](https://profiles.wordpress.org/wpuserjp202306t/) 27. juli, 2023

.

![](https://secure.gravatar.com/avatar/bce40e97210b52eae7cd03c41e160d2e971fedea0dc4264f1d2da077ac3e9a96?
s=60&d=retro&r=g)

### 󠀁[ログイン保護に利用しています](https://wordpress.org/support/topic/%e3%83%ad%e3%82%b0%e3%82%a4%e3%83%b3%e4%bf%9d%e8%ad%b7%e3%81%ab%e5%88%a9%e7%94%a8%e3%81%97%e3%81%a6%e3%81%84%e3%81%be%e3%81%99/)󠁿

 [Fumiki Takahashi](https://profiles.wordpress.org/takahashi_fumiki/) 23. juni, 
2023

誰でもユーザーを登録できるサイトを作っているのですが、ログイン保護機能を利用してい
ます。スパムアカウントが減りました。

![](https://secure.gravatar.com/avatar/35cbcb591e6ef4013bbd838ea1cb93cbfb26afd446df2946f7a1824692aa88c5?
s=60&d=retro&r=g)

### 󠀁[解決済/ループバックリクエストでの問題(サイトヘルス)](https://wordpress.org/support/topic/%e3%83%ab%e3%83%bc%e3%83%97%e3%83%90%e3%83%83%e3%82%af%e3%83%aa%e3%82%af%e3%82%a8%e3%82%b9%e3%83%88%e3%81%a7%e3%81%ae%e5%95%8f%e9%a1%8c-%e3%82%b5%e3%82%a4%e3%83%88%e3%83%98%e3%83%ab%e3%82%b9%e3%82%88/)󠁿

 [tsutlnps149](https://profiles.wordpress.org/tsutlnps149/) 6. februar, 2021

管理ページアクセス制限を有効にすると、サイトヘルスで「サイトでループバックリクエスト
が完了できませんでした」という文字が出るが、この問題、site-health.phpを除外設定にし
てもなお出続ける。 制限をOFFにすると、出なくなる。 バージョン「1.5.1」でのアップデート
で、この問題は解決したようです。ありがとうございました。

![](https://secure.gravatar.com/avatar/5b307318f224d2c4b2c4cfec4a8e5b7a6ef31cbba0ffc18402b239ff45020c7f?
s=60&d=retro&r=g)

### 󠀁[Multisite is not supported](https://wordpress.org/support/topic/multisite-is-not-supported/)󠁿

 [T. Sagawa](https://profiles.wordpress.org/tscontenna/) 15. september, 2020

Nothing work in multi-site mode.

![](https://secure.gravatar.com/avatar/ca98a7dd96386ac18e0eea67de2cf6a1521783218a137069b6753cb7f1331818?
s=60&d=retro&r=g)

### 󠀁[Good Support](https://wordpress.org/support/topic/good-support-372/)󠁿

 [lw53](https://profiles.wordpress.org/lw53/) 31. august, 2020

All the features I require with easy to follow instructions of how to correctly 
set-up.

 [ Les alle 16 vurderinger ](https://wordpress.org/support/plugin/siteguard/reviews/)

## Bidragsytere og utviklere

«SiteGuard WP Plugin» er programvare med åpen kildekode. Følgende personer har bidratt
til denne utvidelsen:

Bidragsytere

 *   [ jp-secure ](https://profiles.wordpress.org/jp-secure/)

“SiteGuard WP Plugin” har blitt oversatt til 9 språk. Takk til [oversetterne](https://translate.wordpress.org/projects/wp-plugins/siteguard/contributors)
for deres bidrag.

[Oversett “SiteGuard WP Plugin” til ditt språk.](https://translate.wordpress.org/projects/wp-plugins/siteguard)

### Interessert i utvikling?

[Bla gjennom koden](https://plugins.trac.wordpress.org/browser/siteguard/), sjekk
ut [SVN-repositoriet](https://plugins.svn.wordpress.org/siteguard/), eller abonner
på [utviklingsloggen](https://plugins.trac.wordpress.org/log/siteguard/) med [RSS](https://plugins.trac.wordpress.org/log/siteguard/?limit=100&mode=stop_on_copy&format=rss).

## Endringslogg

#### 1.7.9

 * Fix a deprecated notice for get_currentuserinfo() function.

#### 1.7.8

 * Fix a warning that occurred from ver1.7.7

#### 1.7.7

 * Fix a bug where renamed login URL was leaked when wp-register.php was accessed

#### 1.7.6

 * Fix a problem that a warning occurred on the Login screen in the PHP8.x environment

#### 1.7.5

 * Fix a problem that a serious error occurred on the Updates Notify screen in the
   PHP8.x environment

#### 1.7.4

 * Changed the directory to store CAPTCHA image files to wp-content/siteguard/
 * Fix some bugs

#### 1.7.3

 * Fix an issue where password reset could not be sent from the management page 
   when CAPTCHA was enabled

#### 1.7.2

 * Reviewed and modified source code related to security

#### 1.7.1

 * Fix the problem that a syntax error occurs in PHP5.6 or earlier

#### 1.7.0

 * Removed ability to get client IP address from X-Forwarded-For due to IP spoofing
   risk

#### 1.6.1

 * Fix the problem that an error occurs when suppressing the redirect from the management
   page to the login page

#### 1.6.0

 * Add the «Block Author Query» feature

#### 1.5.2

 * Fix a syntax error before php5.4

#### 1.5.1

 * Fix a server error when mod_access_compat is not loaded in apache2.4
 * In the Admin Page IP Filter function, fix an issue where site health loopback
   requests fail

#### 1.5.0

 * Add the function not to redirect from admin page to login page
 * Add site-health.php to the initial value of the exclusion path

#### 1.4.3

 * Fix bug in 1.4.2 «Notice：Use of undefined constant HTTPS»

#### 1.4.2

 * In the Rename Login function, correct the problem that is redirected to the https
   renamed login page from the http /wp-login.php

#### 1.4.1

 * Fix bug that some functions are disabled

#### 1.4.0

 * Enabled to get client IP address from X-Forwarded-For header
 * Strict operation check of each function
 * Change not to use session

#### 1.3.4

 * Fix an issue where CAPTCHA might fail in 1.3.3

#### 1.3.3

 * Fix bug that fatal error occurs when fails to send mail
 * Inprove the security of the CAPTCHA function
 * Disabling the Rename Login function when qTranslate X plugin is enabled in order
   to avoid conflicts

#### 1.3.2

 * Fix bug that fatal error occurs when fails to send mail

#### 1.3.1

 * Fix conflicts with other plugins in a session related

#### 1.3.0

 * Add the «Disable XMLRPC» feature
 * In the Login History, add display the login type that indicates whether via login
   page or xmlrpc
 * Fix that the Fail Once error message to be not the same as the failure
 * Fix that the permission of .htaccess to change from 0644 to 0604
 * Delete the mistaken characters of CAPTCHA

#### 1.2.5

 * In the Admin Page IP Filter function, fix bug that can be accessed from the IP
   address that failed to login to the management page
 * In the Rename Login function, correct the problem that is redirected to the renamed
   login page from the /wp-signup.php

#### 1.2.4

 * Fix bug that there is a case which can acccess management pages from non login
   client
 * Disabling the several functions when there is no .htaccess write permission

#### 1.2.3

 * Fix bug that you can not reply comments from the dashboard, if the CAPTCHA is
   enabled
 * Fix bug that the login page is displayed in ‘/wp-login’ even if the Rename Login
   is enabled

#### 1.2.2

 * Fix bug that XML-RPC access which doesn’t need login is recorded as the nameless
   login history
 * Disabling the all functions when installed in multisite environment
 * Disabling the several functions when settings of .htaccess was eliminated

#### 1.2.1

 * Supported with WP 4.2

#### 1.2.0

 * Add the «Updates Notify» feature
 * Fix bug that login via XML-RPC to fail, if the CAPTCHA is enabled
 * Fix bug that sometimes can’t login when you enable the Fail once

#### 1.1.2

 * Supported with WP 4.1
 * Disabling the Admin IP Filter function by default

#### 1.1.1

 * Fix bug that can not save «Login Alert» settings
 * Add the «Login Alert» notification variables, IP Address, User-Agent and Referer

#### 1.1.0

 * Add the «Login Alert» feature
 * Add the function of inform the new Login page URL by e-mail
 * Fix bug that work «Fail Once» even when the password is a mistake
 * Fix bug that even if the «Rename Login» has been enabled, and have specified 
   a permanent link to the non-standard, jump to the new login page in /login

#### 1.0.6

 * Supported with Apache 1.3
 * Fix garbling of CAPTCHA by environment
 * Fix input check of Rename login path
 * Fix some other bugs

#### 1.0.5

 * Add display a warning about changing the login page URL, when activate the plugin

#### 1.0.4

 * Fix bug that fails to update .htaccess, if there is no WordPress settings in .
   htaccess

#### 1.0.3

 * Fix a problem that «Rename Login» does not work, if you change Permalink settings
 * Fix the collision of class name of Really Simple CAPTCHA

#### 1.0.2

 * Fix a minor html escape leakage
 * Reduced the problem of affinity with other plugin [WordPress HTTPS (SSL)]

#### 1.0.1

 * Supported with WP 4.0

#### 1.0.0

 * First release

## Meta

 *  Versjon **1.7.9**
 *  Sist oppdatert **4 måneder siden**
 *  Aktive installasjoner **600 000+**
 *  WordPress-versjon ** 3.9 eller nyere **
 *  Testet opp til **6.9.4**
 *  Språk
 * [Dutch](https://nl.wordpress.org/plugins/siteguard/), [English (US)](https://wordpress.org/plugins/siteguard/),
   [Japanese](https://ja.wordpress.org/plugins/siteguard/), [Russian](https://ru.wordpress.org/plugins/siteguard/),
   [Spanish (Argentina)](https://es-ar.wordpress.org/plugins/siteguard/), [Spanish (Chile)](https://cl.wordpress.org/plugins/siteguard/),
   [Spanish (Colombia)](https://es-co.wordpress.org/plugins/siteguard/), [Spanish (Mexico)](https://es-mx.wordpress.org/plugins/siteguard/),
   [Spanish (Spain)](https://es.wordpress.org/plugins/siteguard/) og [Spanish (Venezuela)](https://ve.wordpress.org/plugins/siteguard/).
 *  [Oversett til ditt språk](https://translate.wordpress.org/projects/wp-plugins/siteguard)
 * Stikkord
 * [captcha](https://nb.wordpress.org/plugins/tags/captcha/)[Login Alert](https://nb.wordpress.org/plugins/tags/login-alert/)
   [login lock](https://nb.wordpress.org/plugins/tags/login-lock/)[pingback](https://nb.wordpress.org/plugins/tags/pingback/)
   [security](https://nb.wordpress.org/plugins/tags/security/)
 *  [Avansert visning](https://nb.wordpress.org/plugins/siteguard/advanced/)

## Vurderinger

 4.3 av 5 stjerner.

 *  [  11 5-star reviews     ](https://wordpress.org/support/plugin/siteguard/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/siteguard/reviews/?filter=4)
 *  [  2 3-star reviews     ](https://wordpress.org/support/plugin/siteguard/reviews/?filter=3)
 *  [  2 2-star reviews     ](https://wordpress.org/support/plugin/siteguard/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/siteguard/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/siteguard/reviews/#new-post)

[Se alle omtalene](https://wordpress.org/support/plugin/siteguard/reviews/)

## Bidragsytere

 *   [ jp-secure ](https://profiles.wordpress.org/jp-secure/)

## Brukerstøtte

Saker løst siste to måneder:

     0 av 1

 [Vis brukerstøtteforumet](https://wordpress.org/support/plugin/siteguard/)