Free forever on WordPress.org · v2.4.2

Security at the
execution layer

not at the cleanup layer

Aegis stops attacks before WordPress runs — at the REST API, at the login page, and at every form. When something is tampered, the site locks down immediately. Not just an email. A real lockdown.

The only free plugin that locks your site when tampered. Others only email you.

No account required · No external dependencies · Plugin Check 0/0 · PHP 8.2+

14
Gate steps, fail-fast
30+
Bad bot signatures blocked
30s
Tamper detection window
0
Overhead on regular pages
The problem

Most security plugins
react after the damage.

They scan files daily. They email you when something is wrong. Meanwhile, your site is running compromised code.

⚠️ What other plugins do

Scan files once a day. Send an email when they find something. The site keeps running with the compromised code. Visitors are served by an infected WordPress. The damage is already done.

🛡 What Aegis does

Checks its own files on every request. If anything is changed without your knowledge, the site goes into maintenance mode within 30 seconds. A recovery link lands in your inbox. No one sees the compromised code.

Activity Log — Live
LIVE
14:23:01BLOCKED/wp/v2/users — someone tried to list your users
14:23:00ALLOWED/wc/v3/products — WooCommerce, passed through
14:22:58BLOCKEDsqlmap scanner — known attack tool
14:22:55RATE LIM185.x.x.x — too many requests, slowed down
14:22:51ALLOWED/wp/v2/posts — public content, always allowed
14:22:48WAFSQL injection attempt — caught and blocked
14:22:44COUNTRYCN 🇨🇳 — blocked by country rule
14:22:40ALLOWED/elementor/v1 — Elementor, recognised and passed
What Aegis covers

Three layers of protection.
One platform.

Free covers most sites completely. Intelligence adds smart, adaptive protection. MAX adds enterprise-grade tools for agencies.

FREE
🚪

REST API Gate

WordPress's REST API is open by default — any bot can query your users, content, and plugins. Aegis closes it with a 14-step filter that runs before WordPress processes anything. WooCommerce, Elementor, and 30+ other plugins pass through automatically.

FREE
👻

Hidden Login Page

Your wp-login.php returns a genuine 404 — the same as a page that never existed. Bots scanning for your login find nothing. You access WordPress through a secret URL only you know.

FREE
🔒

Tamper Detection & Lockdown

Aegis fingerprints its own files. If any file is changed — by an attacker who got in through another plugin — the site locks down within 30 seconds. A recovery link goes to your email. You're back in control in minutes.

FREE
🍯

Spam Protection

An invisible trap field is added to every comment and registration form. Bots that fill forms automatically fall into the trap and are silently rejected. No CAPTCHA. No friction for real visitors.

FREE
🛡

Security Headers

Aegis adds the headers that browsers need to protect your visitors: no clickjacking, no MIME sniffing, strict referrer policy, Content Security Policy presets. Applied to every response including the REST API.

FREE
📊

Activity Log

Every blocked request is recorded with the IP address, country flag, what they tried, and why it was stopped. Export to CSV. Search by IP or route. See patterns before they become problems.

INTELLIGENCE
🧠

Behavior Scoring

Aegis tracks how each IP address behaves over a 10-minute window. Repeated suspicious actions — failed logins, scanning, enumeration — accumulate a score. High scores trigger automatic slowdowns, then blocks.

INTELLIGENCE
🔐

Two-Factor Authentication

Works with Google Authenticator and any TOTP app. Set up with a QR code. 10 recovery codes stored safely. No external service — pure PHP, everything stays on your server.

INTELLIGENCE
🌍

Country Blocking

Block or allow traffic by country. Uses Cloudflare's country detection when available (zero performance cost), with a local database as fallback. Every blocked request shows the country flag in the log.

INTELLIGENCE
🔎

Vulnerability Scanner

Checks your active plugins against the WPScan vulnerability database daily. If a vulnerable plugin is found, Aegis shows you the CVE, the severity, and exactly which file in the plugin is affected. One click to remove it.

INTELLIGENCE
🎯

Attack Vector Detection

When Aegis blocks an attack, it identifies which plugin the attacker used as their entry point. "WP File Manager was used in this attack." No other plugin shows you this. You know exactly what to remove.

INTELLIGENCE
🔑

Brute Force Protection

Tracks failed login attempts per IP and per username. Detects distributed attacks (many IPs, same username). Progressive delay before lockout. Locked IPs shown in the dashboard with one-click unlock.

MAX
🔥

Web Application Firewall

Inspects every request for SQL injection, cross-site scripting, path traversal, server-side request forgery, XML injection, Log4Shell patterns, and PHP object injection. Covers the full OWASP Top 10. Runs before WordPress touches the request.

MAX
📁

Filesystem Monitoring

Watches your plugins, themes, wp-config.php, and .htaccess for unexpected changes. When a file changes, you get an alert immediately. Suspicious files can be quarantined. WordPress.org plugins can be restored from the original source.

MAX
🏢

Agency Tools

White-label the entire interface with your agency name and logo. GDPR compliance reports for each site. Incident response playbooks that act automatically when a threat is detected. Central fleet dashboard is in development.

Self-Defending

Aegis protects itself.
No other plugin does this.

An attacker who gets past your other defences and tampers with Aegis will trigger the lockdown themselves. The plugin is its own last line of defence.

Free

File Integrity Check

Every 30 seconds, on any request, Aegis checks its own files against a secure baseline. A change triggers immediate site lockdown and a recovery email — no waiting for the next admin login.

~0.3ms · every request · throttled
Free

Tamper-Proof Settings

Your protection settings are cryptographically signed using your WordPress secret keys. An attacker who edits the database directly to disable protection will trigger a lockdown instead.

~0.1ms · on every settings read
Free

Recovery Email

When lockdown triggers, a one-time recovery link goes to your admin email. Valid for 24 hours. Click it and the site is back online. No FTP, no hosting panel, no technical knowledge needed.

Sent immediately on tamper detection
Intelligence

Early-Load Guard

Intelligence installs a guard that runs before any plugin loads. If a core file is tampered, the tampered code never executes — the site returns 503 immediately. This is the key difference from Basic.

~0.5ms · before any plugin loads
Intelligence

Distributed License Check

Your license is verified across independent nodes. Database edits that try to extend or fake the license are detected and rejected. The verification cannot be bypassed by editing your WordPress database.

Periodic · tamper-proof · offline-tolerant
MAX

WAF Before WordPress

The Web Application Firewall runs at the earliest possible point — before plugins, before themes, before WordPress processes the request. SQL injection and XSS attempts are caught before they touch any code.

~0.8ms · init priority 1 · MAX only
How it compares

What you get free
vs what others charge for.

Feature Aegis Basic
Free
Wordfence
Free
Really Simple SSL
Free
Solid Security
Free
REST API protection 14-step gate
Tamper → site lockdown Immediateemail onlyemail onlyemail only
Recovery email with unlock link
Settings tamper detection
Hidden login page (genuine 404)PRO only
User enumeration blocked (REST + web) bothREST onlyREST only
Content Security Policy
Web Application Firewall30-day delay free
Brute force lockout
Malware scanningPRO only
No account required (2026)Now required
Zero overhead on regular pages+200–400ms

Free tier features only · Verified June 2026

Pricing

Start free.
Upgrade when you need it.

Every paid plan includes a 15-day trial (no card required) and a 6-month grace period after expiry.

Aegis Core
Free

Complete protection for most WordPress sites. No limits, no upsells inside the plugin.

$0/yr
Free forever · WordPress.org
Download Free →
  • 14-step REST API gate
  • Hidden login page (genuine 404)
  • Tamper detection + site lockdown
  • Recovery email with unlock link
  • Honeypot spam protection
  • Bad bot blocking (30+ signatures)
  • Security headers + CSP presets
  • WordPress hardening (6 options)
  • Activity log + CSV export
Coming Soon
Aegis MAX
MAX

The maximum protection achievable in pure PHP. Built for agencies managing multiple sites and high-traffic infrastructure.

$149/yr
Single site · Unlimited sites $299/yr
+ 6 months grace period included
Notify Me When Available
  • Everything in Intelligence
  • Web Application Firewall (OWASP Top 10)
  • Filesystem monitoring + quarantine
  • Core + plugin integrity scan
  • Incident response playbooks
  • Fleet management (multi-site)
  • GDPR compliance reports
  • White-label for agencies
  • 15-day trial · no card required