Papy3D Security Guard Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Papy3D Security Guard is a modular WordPress security suite. Protections are disabled by default and can be enabled independently.
- Early login protection, local CAPTCHA, lockouts, honeypots and IPv4/IPv6/CIDR controls.
- Local WAF with observation, balanced and strict modes, plus delegation to Papy3D WAF when installed.
- TOTP, recovery codes, login alerts, forced password resets and session controls.
- WordPress hardening, sensitive-file checks, core integrity verification and bounded security logs.
- Incremental heuristic malware/backdoor scanner with explicit exceptions, encrypted quarantine and WP-CLI support.
- File-permission, HTTPS, trusted-proxy and mixed-content diagnostics.
- Optional Wordfence Intelligence synchronization followed by offline vulnerability checks.
- GDPR controls, centralized alerts and secret-free JSON settings transfer.
CAPTCHA, TOTP and normal malware scans remain local. External requests occur only for explicitly enabled or requested features documented below.
Data and privacy
Settings are stored in WordPress options. The encryption master key is stored separately as a non-autoloaded option or multisite network option. Early-guard runtime state contains bounded counters, timestamps and truncated HMAC identifiers rather than plaintext usernames, passwords or CAPTCHA answers. Local WAF events may contain time, IP address, HMAC identifier, method, path without query string, rule identifiers, severity, action, bounded redacted excerpts, payload hash and user agent. Cookies, authorization headers, complete passwords and complete request bodies are not stored.
TOTP data is encrypted or hashed in user metadata. Repeated-login/TOTP counters are HMAC-keyed and expiring. Username blacklist and honeypot reports can store detected IP addresses, bounded identifiers, counters and timestamps. Login and sensitive-action alerts may include IP address and user agent in email sent through the site’s configured mail system. No analytics, external CAPTCHA, remote QR-code or remote authentication service is used.
External services
External services are contacted only for optional features or explicit administrator actions.
Trusted proxy IP-list sources
When an administrator refreshes a selected provider, or enables the daily refresh, the plugin can request public network lists from Cloudflare, QUIC.cloud, bunny.net, Fastly or Imperva. No site URL, user, visitor IP, content or plugin configuration is sent by the plugin. Providers receive normal HTTPS connection metadata, the server source IP and a generic user agent. Sucuri ranges are bundled locally and StackPath is treated as discontinued.
- Cloudflare lists: https://www.cloudflare.com/ips-v4/ and https://www.cloudflare.com/ips-v6/ ; privacy: https://www.cloudflare.com/privacypolicy/ ; terms: https://www.cloudflare.com/policies/terms/
- QUIC.cloud: https://www.quic.cloud/ips-all ; privacy: https://www.quic.cloud/privacy-policy/ ; terms: https://www.quic.cloud/terms-of-use/
- bunny.net: https://bunnycdn.com/api/system/edgeserverlist and https://bunnycdn.com/api/system/edgeserverlist/IPv6 ; privacy: https://bunny.net/privacy/ ; terms: https://bunny.net/tos/
- Fastly: https://api.fastly.com/public-ip-list ; privacy: https://www.fastly.com/privacy ; terms: https://www.fastly.com/terms
- Imperva: https://my.imperva.com/api/integration/v1/ips ; privacy: https://www.imperva.com/trust-center/privacy-statement/ ; terms: https://www.imperva.com/legal/website-terms-of-use/
- Sucuri source documentation: https://docs.sucuri.net/website-firewall/troubleshooting/same-ip-for-all-users/
Wordfence Intelligence
Used only when an administrator synchronizes/tests the vulnerability feed or enables daily WP-Cron synchronization. Endpoint: https://www.wordfence.com/api/intelligence/v3/vulnerabilities/scanner. The API key is sent as a Bearer token. The site URL and installed inventory are not sent; the complete feed is downloaded and analyzed locally.
- Terms: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/
- Privacy: https://www.wordfence.com/privacy-policy/
- API documentation: https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/
WordPress.org services
Optional core integrity verification uses WordPress core’s checksum service and sends the installed WordPress version and locale. Optional plugin/theme comparison is triggered only by an explicit administrator action and downloads the exact WordPress.org package for the identified slug/version to a temporary file, compares the selected file locally, then deletes the archive.
- Privacy: https://wordpress.org/about/privacy/
- License: https://wordpress.org/about/license/
PayPal
The optional Support tab contains a standard PayPal donation form. No remote PayPal script or image is embedded and nothing is submitted automatically. When the administrator clicks the support button, the selected amount, EUR currency, donation description, recipient account and normal HTTPS metadata are sent directly to PayPal.
- Terms: https://www.paypal.com/us/legalhub/useragreement-full
- Privacy: https://www.paypal.com/us/legalhub/privacy-full
Security
Test security changes on staging where possible and retain SFTP/SSH access for recovery. Keep WordPress, PHP and the plugin updated.
Plugin identifiers and companion integration
Security Guard is autonomous and uses the plugin-specific p3dsg_ / P3DSG_ prefix for its own classes, hooks, options, transients, menu slug and assets. It does not bundle or register a shared administration hub. The p3dwaf_integration_v1_status filter is owned by the optional companion Papy3D WAF plugin; Security Guard only consumes that external public hook when the companion plugin is installed.
Screenshots
No screenshots provided
