
BruteGuard – Brute Force Login Protection Security & Risk Analysis
wordpress.org/plugins/bruteguardBruteGuard is a cloud powered brute force login protection that shields your site against botnet attacks.
Is BruteGuard – Brute Force Login Protection Safe to Use in 2026?
Use With Caution
Score 64/100BruteGuard – Brute Force Login Protection has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The bruteguard plugin v0.1.4 presents a mixed security posture. On the positive side, the static analysis reveals a very limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The absence of dangerous functions and file operations is also a strong indicator of good coding practices in those areas. However, the plugin exhibits weaknesses in output escaping, with less than half of its outputs being properly escaped, suggesting a potential for cross-site scripting vulnerabilities. The use of external HTTP requests also warrants attention, as these can sometimes be vectors for attack if not handled carefully.
The vulnerability history is a significant concern. The presence of one known medium-severity CVE, specifically related to Cross-site Scripting, which is also currently unpatched, indicates a direct and actionable security risk. The fact that the last vulnerability was recent further emphasizes the need for immediate attention to this known issue. While the plugin doesn't show critical or high severity vulnerabilities in its history or taint analysis, the unpatched medium CVE coupled with the poor output escaping metrics points to a real and present danger to sites using this plugin.
In conclusion, while bruteguard v0.1.4 has a small attack surface and avoids certain risky coding practices, the unpatched cross-site scripting vulnerability and the high percentage of improperly escaped output are critical weaknesses. The plugin's security is significantly undermined by the known, unaddressed vulnerability. Users should be strongly advised to either ensure this vulnerability is patched or to refrain from using this version of the plugin.
Key Concerns
- Unpatched Medium CVE
- Low Output Escaping Percentage
- SQL queries not fully prepared
BruteGuard – Brute Force Login Protection Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BruteGuard – Brute Force Login Protection <= 0.1.4 - Reflected Cross-Site Scripting
BruteGuard – Brute Force Login Protection Release Timeline
BruteGuard – Brute Force Login Protection Code Analysis
SQL Query Safety
Output Escaping
BruteGuard – Brute Force Login Protection Attack Surface
WordPress Hooks 7
Maintenance & Trust
BruteGuard – Brute Force Login Protection Maintenance & Trust
Maintenance Signals
Community Trust
BruteGuard – Brute Force Login Protection Alternatives
Protect Ai Login
protect-ai-login
Change default login site to a custom URL, block spam, bot registration, and brute-force using Google reCAPTCHA.
CloudSecure WP Security
cloudsecure-wp-security
管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。 かんたんな設定を行うだけで、不正アクセスや不正ログインからあなたのWordPressを保護します。
WP Ghost (Hide My WP Ghost) – Security & Firewall
hide-my-wp
Hide and Secure WP paths with the complete WP security suite for Site Hardening. Includes 8G Firewall, Brute Force protection, and Passkeys.
WP fail2ban – Advanced Security
wp-fail2ban
WP fail2ban uses fail2ban to protect your WordPress site.
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
BruteGuard – Brute Force Login Protection Developer Profile
28 plugins · 120K total installs
How We Detect BruteGuard – Brute Force Login Protection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bruteguard/assets/css/admin.css/wp-content/plugins/bruteguard/assets/js/admin.js/wp-content/plugins/bruteguard/assets/js/admin.jsbruteguard-adminbruteguardHTML / DOM Fingerprints
bruteguard-apikey-fieldbruteguard-email-fieldbruteguard-emailbruteguard-email-submitdata-keybruteguard