Elohim Cyber Guardian Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Elohim Cyber Guardian is a WordPress security plugin developed by Elohim Software Solutions Pvt Ltd to help protect your website from unauthorized access, brute-force attacks, and common login-based threats.
It provides essential security features with simple configuration and a clear dashboard for monitoring activity.
This plugin does not replace a full security solution but adds additional protection layers such as login protection, rate limiting, and monitoring.
Features
Custom Login URL
Use a custom login URL while safely redirecting access from the default login page.
Rate Limiting & IP Blocking
Limit login attempts and automatically block suspicious IP addresses.
Honeypot Protection
Detect and stop automated bots without affecting real users.
CAPTCHA Support
Supports built-in math CAPTCHA and Google reCAPTCHA integration.
Attack Logs
Track login attempts including IP address, username, and status. Includes CSV export and bulk delete.
Email Alerts
Receive notifications for suspicious login activity based on a configurable threshold.
Auto-Block
Automatically block IPs that exceed your configured failed login threshold.
Emergency Access
Generate secure access tokens if you are locked out.
Security Hardening Options
Enable additional protections such as:
- Disable XML-RPC
- Hide WordPress version
- Disable file editor
- Enforce HTTPS
- Add security headers
Security Dashboard
View your current protection status and activity summary.
Community Edition Limitations
This is the Community edition of Elohim Cyber Guardian. It is fully functional and is not a trial: it does not expire, and no feature stops working over time.
One limit applies:
- Actively blocked IPs: up to 3 at a time. Automatic rate-limit blocking, login protection, CAPTCHA, honeypot, logging, email alerts, and all hardening options are unlimited and unaffected.
A paid edition that removes the blocked-IP limit is available separately from the plugin author. This plugin does not display upgrade prompts beyond the notice shown when the limit is reached, and no functionality is disabled to encourage an upgrade.
External Services
This plugin connects to external services only when enabled by the administrator:
-
Google reCAPTCHA (Google LLC)
Used for verifying that a login attempt comes from a human, when the administrator enables reCAPTCHA v2 or v3.
Data sent: on login-page loads the visitor’s browser requests the reCAPTCHA script from google.com, which exposes the visitor’s IP address and browser details to Google; on login submissions this plugin’s server sends the reCAPTCHA response token and the visitor’s IP address to Google’s siteverify endpoint.
Privacy Policy: https://policies.google.com/privacy
Terms: https://policies.google.com/terms -
ipapi.co (Kloudend, Inc.)
Used for optional IP-based country lookup when the administrator enables the country option in Email Alert settings.
Data sent: the IP address of the visitor that triggered a security alert, at the moment the alert email is generated.
Privacy Policy: https://ipapi.co/privacy/
Terms: https://ipapi.co/terms/
Both integrations are disabled by default and can be turned off at any time in the plugin settings. No data is transmitted unless the corresponding feature is enabled by the administrator. The plugin makes no other outbound requests and collects no telemetry.
As of version 1.3 this plugin uses no PHP sessions anywhere: the math CAPTCHA challenge is stored server-side in a short-lived transient keyed by a single-use token, so the plugin is fully compatible with full-page caching.
Privacy
This plugin may store the following data locally:
- IP addresses of login attempts
- Usernames entered during login
- Login timestamps
This data is used only for security monitoring and is not shared externally except as described above.
This plugin does not track users or send personal data to external servers without explicit administrator action.
Screenshots
No screenshots provided

