{"id":11444,"date":"2026-06-01T18:27:01","date_gmt":"2026-06-01T10:27:01","guid":{"rendered":"https:\/\/aeosub.com\/niyiguard\/"},"modified":"2026-06-01T18:27:01","modified_gmt":"2026-06-01T10:27:01","slug":"niyiguard","status":"publish","type":"post","link":"https:\/\/aeosub.com\/zh\/niyiguard\/","title":{"rendered":"NiyiGuard"},"content":{"rendered":"<div class=\"plugin-expert-review\" style=\"border: 1px solid #e2e8f0; border-left: 4px solid #4a3bca; border-radius: 10px; padding: 20px; margin-bottom: 25px; background: #fff; font-family: -apple-system, system-ui, sans-serif;\">\n<div style=\"font-weight: bold; font-size: 1.1em; color: #4a3bca; margin-bottom: 10px;\">Expert Insight<\/div>\n<div style=\"color: #4a5568; font-size: 14px; line-height: 1.6;\">\n<p>NiyiGuard addresses a critical gap in the WordPress security ecosystem by providing a self-hosted, application-layer hardening toolkit tailored for developers and e-commerce operators who prioritize data sovereignty. By centralizing essential security vectors\u2014such as two-factor authentication, rate limiting, and file integrity monitoring\u2014into a single dashboard, it eliminates the need for multiple single-purpose plugins. Its target audience spans from privacy-conscious site owners running WooCommerce stores to developers requiring programmatic control over custom endpoints. Ultimately, it serves as an excellent application-level complement to network-level firewalls and CDNs, ensuring robust defense-in-depth without external telemetry.<\/p>\n<p><strong>Key Strengths &amp; Role:<\/strong> The plugin&#8217;s standout feature is its Developer SDK, which introduces middleware-style helpers to secure custom admin-post handlers, REST routes, and forms directly within the codebase. For e-commerce sites, the dedicated WooCommerce protection pipelines effectively mitigate checkout abuse, cart spam, and Store API exploitation without requiring heavy third-party integrations. Furthermore, its strict privacy-first architecture guarantees that all security logs, audit trails, and user data remain entirely on the local server, free from external licensing checks or telemetry overhead.<\/p>\n<p><strong>Potential Limitations &amp; Pitfalls:<\/strong> Because NiyiGuard operates strictly at the application layer, it cannot replace a network-level Web Application Firewall (WAF) or CDN, meaning high-volume DDoS attacks must still be mitigated upstream. Additionally, resource-intensive operations such as file integrity scans and database-driven rate limiting or audit logging may introduce minor performance overhead on budget shared hosting environments if not configured with appropriate pruning schedules.<\/p>\n<\/div><\/div>\n<div class=\"plugin-info-card\" style=\"border: 1px solid #e2e8f0; border-radius: 10px; overflow: hidden; margin-bottom: 30px; font-family: -apple-system, system-ui, sans-serif; background: #fff;\">\n<div style=\"padding: 20px; border-bottom: 1px solid #edf2f7; background: #fafafa; display: flex; align-items: flex-start;\">\n                <img decoding=\"async\" src=\"https:\/\/s.w.org\/plugins\/geopattern-icon\/niyiguard.svg\" style=\"width: 45px; height: 45px; border-radius: 8px; margin-right: 15px;\"> <\/p>\n<div style=\"flex: 1; line-height: 1.2;\">\n<div style=\"font-weight: bold; font-size: 1.1em; color: #1a202c;\">Plugin Specification<\/div>\n<p>                    <small style=\"color: #718096;\">WordPress.org Official Data<\/small>\n                <\/div>\n<\/p><\/div>\n<table style=\"width: 100%; border-collapse: collapse; font-size: 14px;\">\n<tr style=\"border-bottom: 1px solid #edf2f7;\">\n<th style=\"padding: 12px 20px; text-align: left; width: 35%; color: #4a5568; background: #fcfcfc;\">Developer<\/th>\n<td style=\"padding: 12px 20px; font-weight: 500;\"><a href=\"https:\/\/profiles.wordpress.org\/harish282\/\" target=\"_blank\" rel=\"noopener\">harish282<\/a><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #edf2f7;\">\n<th style=\"padding: 12px 20px; text-align: left; color: #4a5568; background: #fcfcfc;\">Version<\/th>\n<td style=\"padding: 12px 20px;\">v0.1.0<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #edf2f7;\">\n<th style=\"padding: 12px 20px; text-align: left; color: #4a5568; background: #fcfcfc;\">Active Installs<\/th>\n<td style=\"padding: 12px 20px;\">0 +<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #edf2f7;\">\n<th style=\"padding: 12px 20px; text-align: left; color: #4a5568; background: #fcfcfc;\">Requires \/ Tested<\/th>\n<td style=\"padding: 12px 20px;\">6.4 \/ 7.0<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #edf2f7;\">\n<th style=\"padding: 12px 20px; text-align: left; color: #4a5568; background: #fcfcfc;\">Last Updated<\/th>\n<td style=\"padding: 12px 20px;\">2026-06-01 9:37am GMT<\/td>\n<\/tr>\n<tr>\n<th style=\"padding: 12px 20px; text-align: left; color: #4a5568; background: #fcfcfc;\">Official Link<\/th>\n<td style=\"padding: 12px 20px;\"><a href=\"https:\/\/wordpress.org\/plugins\/niyiguard\/\" target=\"_blank\" style=\"text-decoration: none; color: #4a3bca; font-weight: bold;\" rel=\"noopener\">View Details \u2192<\/a><\/td>\n<\/tr>\n<\/table><\/div>\n<div class=\"plugin-short-desc\" style=\"margin: 20px 0; padding: 12px 15px; background: #f9fafb; border-left: 4px solid #4a3bca; border-radius: 6px; font-style: italic; color: #4a5568;\">Self-hosted WordPress security: 2FA, lockouts, audit log, integrity, headers, rate limits, WooCommerce protection, and SDK. Free.<\/div>\n<p>NiyiGuard hardens WordPress at the <strong>application layer<\/strong>: login abuse, accountability, file integrity, browser security headers, optional rate limits, and WooCommerce-specific threats. It <strong>complements<\/strong> your host firewall, CDN, or WAF \u2014 it does not replace them.<\/p>\n<h4>Why install NiyiGuard?<\/h4>\n<ul>\n<li><strong>Self-hosted<\/strong> \u2014 security data stays on your server; no NiyiGuard account and no usage telemetry to the author.<\/li>\n<li><strong>One dashboard<\/strong> \u2014 enable or disable modules (authentication, audit log, integrity, headers, rate limits, WooCommerce protection).<\/li>\n<li><strong>For store owners<\/strong> \u2014 reduce fake checkouts, cart and coupon abuse, registration spam, and Store API abuse when WooCommerce is active.<\/li>\n<li><strong>For developers<\/strong> \u2014 protect custom <code>admin-post<\/code> handlers, forms, and REST routes with the <strong>Security SDK<\/strong> (CSRF, rate limits, signed URLs, route guards).<\/li>\n<li><strong>Fully free<\/strong> \u2014 no license key, beta trial, or paywalled module in 0.1.0.<\/li>\n<\/ul>\n<h4>What makes it different?<\/h4>\n<p>Many security plugins offer two-factor auth, lockouts, headers, or malware scanning. NiyiGuard does not claim to be the only plugin with those features. It stands out in three ways:<\/p>\n<ol>\n<li><strong>Developer SDK<\/strong> \u2014 middleware-style helpers for <strong>your<\/strong> code paths, not only wp-admin toggles.<\/li>\n<li><strong>WooCommerce abuse pipelines<\/strong> \u2014 checkout, cart, registration, and Store API protection in the same package as audit logging and login hardening.<\/li>\n<li><strong>Privacy-first<\/strong> \u2014 no license server and no analytics to the author (see Privacy section below).<\/li>\n<\/ol>\n<p>Longer positioning notes and reusable marketing copy: <code>docs\/WHY_NIYIGUARD.md<\/code>.<\/p>\n<h4>Features included (0.1.0)<\/h4>\n<ul>\n<li><strong>Authentication hardening<\/strong> \u2014 login lockouts (IP and username), TOTP and email two-factor authentication, recovery codes, session tracking with remote revoke, and new-device suspicious-login email alerts.<\/li>\n<li><strong>Security headers<\/strong> \u2014 HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy, and X-Content-Type-Options (each header can be toggled).<\/li>\n<li><strong>Audit log<\/strong> \u2014 logins, plugin changes, role changes, selected option changes, file editor use, and WooCommerce-related actions. Admin list UI, detail view, retention, and scheduled pruning.<\/li>\n<li><strong>File integrity monitoring<\/strong> \u2014 WordPress.org core checksum comparison, plugin manifest diff scans, suspicious PHP heuristics, and optional themes\/uploads scopes (scheduled scans).<\/li>\n<li><strong>Rate limiting<\/strong> \u2014 optional global throttling for front-end, AJAX, wp-login, and REST API traffic (wp-admin dashboard loads excluded by default).<\/li>\n<li><strong>WooCommerce Protection<\/strong> \u2014 checkout, cart, registration, and Store API pipelines (velocity limits, honeypots, disposable-email checks, fraud scoring, coupon abuse). Requires WooCommerce.<\/li>\n<li><strong>CSRF middleware and SDK<\/strong> \u2014 nonce verification for custom routes, forms, and REST handlers you register.<\/li>\n<li><strong>Signed URLs<\/strong> \u2014 time-limited HMAC links for downloads, invites, and sensitive actions.<\/li>\n<li><strong>Login URL disguise<\/strong> \u2014 optional custom login path instead of <code>wp-login.php<\/code> (off by default; test on staging first).<\/li>\n<li><strong>Safe mode<\/strong> \u2014 emergency bypass via <code>NIYIGUARD_SAFE_MODE<\/code> in <code>wp-config.php<\/code> without changing saved settings.<\/li>\n<li><strong>Health diagnostics<\/strong> \u2014 hooks, database tables, and module state on an admin screen.<\/li>\n<li><strong>MU loader helper<\/strong> \u2014 optional must-use loader for earlier bootstrap in the request lifecycle.<\/li>\n<\/ul>\n<p>The <strong>NiyiGuard <span aria-hidden=\"true\" class=\"wp-exclude-emoji\">\u2192<\/span> Dashboard<\/strong> includes optional links to leave a WordPress.org review or support development (Ko-fi). Neither is required.<\/p>\n<h4>Developer APIs<\/h4>\n<p>The <code>Security<\/code> facade provides route guards, CSRF fields, rate limiters, signed URLs, and related helpers. Documented in <code>docs\/USAGE.md<\/code>. Middleware applies to <strong>routes you protect<\/strong> \u2014 it is not automatic site-wide protection for every WordPress hook. Before production, follow <code>docs\/STAGING_TEST_PLAN.md<\/code>.<\/p>\n<h4>Requirements<\/h4>\n<ul>\n<li>WordPress 6.4+<\/li>\n<li>PHP 8.2+<\/li>\n<li>MySQL 5.7+ or MariaDB 10.3+ (standard WordPress database)<\/li>\n<\/ul>\n<h3>Privacy<\/h3>\n<p>NiyiGuard processes security-related data on your WordPress server (IP addresses, user agents, user IDs, audit events, session metadata, and similar fields when features are enabled). It does not sell personal data or include advertising trackers.<\/p>\n<p><strong>Third-party service<\/strong><\/p>\n<ul>\n<li><strong>WordPress.org Core Checksums API<\/strong> (<code>https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/code>) \u2014 used for core file integrity checks (WordPress version and locale only; responses may be cached about 12 hours).<\/li>\n<\/ul>\n<p><strong>Email<\/strong><\/p>\n<p>Optional security emails (two-factor codes, suspicious-login alerts) use WordPress <code>wp_mail()<\/code> and your site&#8217;s mail configuration.<\/p>\n<p><strong>Optional donations<\/strong><\/p>\n<p>If you use the dashboard Ko-fi link, payment and any data you provide are handled by Ko-fi under their terms, not by NiyiGuard.<\/p>\n<p>Full details: <code>docs\/PRIVACY.md<\/code> in the plugin folder, and the Privacy section below.<\/p>","protected":false},"excerpt":{"rendered":"<p>Self-hosted WordPress security: 2FA, lockouts, audit log, integrity, headers, rate limits, WooCommerce protection, and SDK. Free.<\/p>","protected":false},"author":1,"featured_media":9317,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[252],"tags":[663,1028,664,1824,569,555],"class_list":["post-11444","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trends","tag-audit","tag-login","tag-security","tag-two-factor","tag-woocommerce","tag-wordpress-plugin"],"_links":{"self":[{"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/posts\/11444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/comments?post=11444"}],"version-history":[{"count":0,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/posts\/11444\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/media\/9317"}],"wp:attachment":[{"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/media?parent=11444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/categories?post=11444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aeosub.com\/zh\/wp-json\/wp\/v2\/tags?post=11444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}