• Home
  • Services
    • Col 1
      • Tech & Analytics
      • Web Development
      • Technical Audit
      • Analytics & Tracking
    • Col 2
      • Growth Marketing
      • SEO Strategy
      • SEM & PPC
      • Social Growth
    • Col 3
      • AI & Strategy
      • Al Search (GEO)
      • SEO Content
      • Growth Consulting
    • Col 4
      • Operations & CRO
      • Conversion (CRO)
      • AI Automation
      • Full-stack Ops
  • Projects
    • Strategies
    • Plugins
    • Extensions
    • Creatives
  • Insights
  • About
  • Contact
  • English
    • Chinese
FREE ANALYSIS
  • Home
  • Services
    • Col 1
      • Tech & Analytics
      • Web Development
      • Technical Audit
      • Analytics & Tracking
    • Col 2
      • Growth Marketing
      • SEO Strategy
      • SEM & PPC
      • Social Growth
    • Col 3
      • AI & Strategy
      • Al Search (GEO)
      • SEO Content
      • Growth Consulting
    • Col 4
      • Operations & CRO
      • Conversion (CRO)
      • AI Automation
      • Full-stack Ops
  • Projects
    • Strategies
    • Plugins
    • Extensions
    • Creatives
  • Insights
  • About
  • Contact
  • English
    • Chinese
FREE ANALYSIS
  • Home
  • Services
    • Col 1
      • Tech & Analytics
      • Web Development
      • Technical Audit
      • Analytics & Tracking
    • Col 2
      • Growth Marketing
      • SEO Strategy
      • SEM & PPC
      • Social Growth
    • Col 3
      • AI & Strategy
      • Al Search (GEO)
      • SEO Content
      • Growth Consulting
    • Col 4
      • Operations & CRO
      • Conversion (CRO)
      • AI Automation
      • Full-stack Ops
  • Projects
    • Strategies
    • Plugins
    • Extensions
    • Creatives
  • Insights
  • About
  • Contact
  • English
    • Chinese

NiyiGuard

  • Home
  • Trends
  • NiyiGuard
NiyiGuard
  • 2026-06-01
  • by LethaldiranMX
  • Trends
  • 0 Comments
Expert Insight

NiyiGuard addresses a critical gap in the WordPress security ecosystem by providing a self-hosted, application-layer hardening toolkit tailored for developers and e-commerce operators who prioritize data sovereignty. By centralizing essential security vectors—such as two-factor authentication, rate limiting, and file integrity monitoring—into a single dashboard, it eliminates the need for multiple single-purpose plugins. Its target audience spans from privacy-conscious site owners running WooCommerce stores to developers requiring programmatic control over custom endpoints. Ultimately, it serves as an excellent application-level complement to network-level firewalls and CDNs, ensuring robust defense-in-depth without external telemetry.

Key Strengths & Role: The plugin’s standout feature is its Developer SDK, which introduces middleware-style helpers to secure custom admin-post handlers, REST routes, and forms directly within the codebase. For e-commerce sites, the dedicated WooCommerce protection pipelines effectively mitigate checkout abuse, cart spam, and Store API exploitation without requiring heavy third-party integrations. Furthermore, its strict privacy-first architecture guarantees that all security logs, audit trails, and user data remain entirely on the local server, free from external licensing checks or telemetry overhead.

Potential Limitations & Pitfalls: Because NiyiGuard operates strictly at the application layer, it cannot replace a network-level Web Application Firewall (WAF) or CDN, meaning high-volume DDoS attacks must still be mitigated upstream. Additionally, resource-intensive operations such as file integrity scans and database-driven rate limiting or audit logging may introduce minor performance overhead on budget shared hosting environments if not configured with appropriate pruning schedules.

Plugin Specification

WordPress.org Official Data

Developer harish282
Version v0.1.0
Active Installs 0 +
Requires / Tested 6.4 / 7.0
Last Updated 2026-06-01 9:37am GMT
Official Link View Details →
Self-hosted WordPress security: 2FA, lockouts, audit log, integrity, headers, rate limits, WooCommerce protection, and SDK. Free.

NiyiGuard hardens WordPress at the application layer: login abuse, accountability, file integrity, browser security headers, optional rate limits, and WooCommerce-specific threats. It complements your host firewall, CDN, or WAF — it does not replace them.

Why install NiyiGuard?

  • Self-hosted — security data stays on your server; no NiyiGuard account and no usage telemetry to the author.
  • One dashboard — enable or disable modules (authentication, audit log, integrity, headers, rate limits, WooCommerce protection).
  • For store owners — reduce fake checkouts, cart and coupon abuse, registration spam, and Store API abuse when WooCommerce is active.
  • For developers — protect custom admin-post handlers, forms, and REST routes with the Security SDK (CSRF, rate limits, signed URLs, route guards).
  • Fully free — no license key, beta trial, or paywalled module in 0.1.0.

What makes it different?

Many security plugins offer two-factor auth, lockouts, headers, or malware scanning. NiyiGuard does not claim to be the only plugin with those features. It stands out in three ways:

  1. Developer SDK — middleware-style helpers for your code paths, not only wp-admin toggles.
  2. WooCommerce abuse pipelines — checkout, cart, registration, and Store API protection in the same package as audit logging and login hardening.
  3. Privacy-first — no license server and no analytics to the author (see Privacy section below).

Longer positioning notes and reusable marketing copy: docs/WHY_NIYIGUARD.md.

Features included (0.1.0)

  • Authentication hardening — login lockouts (IP and username), TOTP and email two-factor authentication, recovery codes, session tracking with remote revoke, and new-device suspicious-login email alerts.
  • Security headers — HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy, and X-Content-Type-Options (each header can be toggled).
  • Audit log — logins, plugin changes, role changes, selected option changes, file editor use, and WooCommerce-related actions. Admin list UI, detail view, retention, and scheduled pruning.
  • File integrity monitoring — WordPress.org core checksum comparison, plugin manifest diff scans, suspicious PHP heuristics, and optional themes/uploads scopes (scheduled scans).
  • Rate limiting — optional global throttling for front-end, AJAX, wp-login, and REST API traffic (wp-admin dashboard loads excluded by default).
  • WooCommerce Protection — checkout, cart, registration, and Store API pipelines (velocity limits, honeypots, disposable-email checks, fraud scoring, coupon abuse). Requires WooCommerce.
  • CSRF middleware and SDK — nonce verification for custom routes, forms, and REST handlers you register.
  • Signed URLs — time-limited HMAC links for downloads, invites, and sensitive actions.
  • Login URL disguise — optional custom login path instead of wp-login.php (off by default; test on staging first).
  • Safe mode — emergency bypass via NIYIGUARD_SAFE_MODE in wp-config.php without changing saved settings.
  • Health diagnostics — hooks, database tables, and module state on an admin screen.
  • MU loader helper — optional must-use loader for earlier bootstrap in the request lifecycle.

The NiyiGuard → Dashboard includes optional links to leave a WordPress.org review or support development (Ko-fi). Neither is required.

Developer APIs

The Security facade provides route guards, CSRF fields, rate limiters, signed URLs, and related helpers. Documented in docs/USAGE.md. Middleware applies to routes you protect — it is not automatic site-wide protection for every WordPress hook. Before production, follow docs/STAGING_TEST_PLAN.md.

Requirements

  • WordPress 6.4+
  • PHP 8.2+
  • MySQL 5.7+ or MariaDB 10.3+ (standard WordPress database)

Privacy

NiyiGuard processes security-related data on your WordPress server (IP addresses, user agents, user IDs, audit events, session metadata, and similar fields when features are enabled). It does not sell personal data or include advertising trackers.

Third-party service

  • WordPress.org Core Checksums API (https://api.wordpress.org/core/checksums/1.0/) — used for core file integrity checks (WordPress version and locale only; responses may be cached about 12 hours).

Email

Optional security emails (two-factor codes, suspicious-login alerts) use WordPress wp_mail() and your site’s mail configuration.

Optional donations

If you use the dashboard Ko-fi link, payment and any data you provide are handled by Ko-fi under their terms, not by NiyiGuard.

Full details: docs/PRIVACY.md in the plugin folder, and the Privacy section below.

  • audit,
  • login,
  • security,
  • two factor,
  • woocommerce,
  • wordpress plugin
Previous Post

Golisto Connector

Next Post

LeadBot

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Thoughts (1)
  • Trends (1,232)
  • Tutorials (1)

Recent Posts

2026-10-04
Uplink Analytics Dashboard for Cabin
2026-10-03
FDesign Withdrawal Button for WooCommerce
2026-10-02
PW WooCommerce BOGO
2026-10-02
Albertoit Client Management for Coaches
2026-10-02
PerseiaThink Accessibility Audit for EAA

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026

Tags

accessibility admin AI analytics automation backup blocks booking calendar chat chatbot checkout contact form contact form 7 content customer support delivery ecommerce elementor forms GDPR GEO gutenberg lead generation live chat llms.txt login openai optimization payment gateway performance popup privacy products Schema security SEO shipping shortcode support tracking whatsapp widget woocommerce wordpress plugin
  • shape1
  • shape2
  • shape3
  • shape4
  • shape5
  • shape6
  • shape7

Newsletter SignUp!

    About Us

    GROWTH,ARCHITECTED.
    Empowering global brands through data-driven SEO, high-performance web development, and AI-forward strategies.

    Information

    • Extensions
    • Strategies
    • Creatives
    • Plugins

    Services

    • AI & Strategy
    • Growth Marketing
    • Operations & CRO
    • Tech & Analytics

    Office Address

    • Nan'an District, Chongqing
    • +86-133-1028-2690
    • [email protected]
    • +86-133-1028-2690
    © Copyright AEOSUB 2026 | Digital Growth & Full-stack Operations
    • Home
    • About
    • Case Study
      • Case Study 1
      • Case Study 2
      • Case Study 3
      • Case Study 4
      • Case Study 5
    • Elements
      • Blog
        • Blog Post 1
        • Blog Post 2
        • Blog Post 3
        • Blog Post 4
        • Blog Post 5
        • Blog Post 6
      • Service
        • Service Gallery 1
        • Service Gallery 2
        • Service Gallery 3
        • Service Gallery
        • Service Gallery 5
      • Team
        • Team Gallery 1
        • Team Gallery 2
        • Team Gallery 3
      • Testimonial
        • Testimonial – 1
        • Testimonial – 2
        • Testimonial – 3
      • Contact Info Box
        • Contact Info Box 1
        • Contact Info Box 2
      • Info Box
        • Info Box 1
        • Info Box 2
        • Info Box 3
      • Miscellaneous
        • Brand Showcase
        • Counter 1
        • Progress Bar
        • Progress Box Image
        • Radius Button
        • Section Title Subtitle
      • Pricing
        • Pricing Plan 1
        • Pricing Plan 2
        • Pricing Plan 3
        • Pricing Plan 4
        • Pricing Plan 5
    • Pages
      • Service
        • Service Archive
      • Case Study
        • Case Study Archive
        • Single Case Study 1
        • Single Case Study 2
        • Single Case Study 3
      • Team
        • Team Gallery 1
        • Team Gallery 2
        • Team Gallery 3
      • Typography
      • 404 Error
    • Blog
      • Blog 1
      • Blog 2
      • Blog 3
    • Contact
    Follow Us
    FREE ANALYSIS
    • Home
    • Services
      • Col 1
        • Tech & Analytics
        • Web Development
        • Technical Audit
        • Analytics & Tracking
      • Col 2
        • Growth Marketing
        • SEO Strategy
        • SEM & PPC
        • Social Growth
      • Col 3
        • AI & Strategy
        • Al Search (GEO)
        • SEO Content
        • Growth Consulting
      • Col 4
        • Operations & CRO
        • Conversion (CRO)
        • AI Automation
        • Full-stack Ops
    • Projects
      • Strategies
      • Plugins
      • Extensions
      • Creatives
    • Insights
    • About
    • Contact
    • English
      • Chinese
    Follow Us