
CloudGuard Security & Risk Analysis
wordpress.org/plugins/cloudguardUse Cloudflare's free geolocation service to restrict access to your site's login page.
Is CloudGuard Safe to Use in 2026?
Generally Safe
Score 100/100CloudGuard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cloudguard plugin v1.4.6 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and performing capability checks, there are significant concerns regarding its attack surface. The presence of an unprotected AJAX handler is a critical vulnerability, as it represents a direct entry point for unauthenticated attackers. This single unprotected entry point significantly increases the risk profile despite other positive code signals.
The static analysis reveals a concerning taint flow with an unsanitized path, indicating a potential for directory traversal or other path manipulation vulnerabilities, although it is not classified as critical or high severity. The lack of vulnerability history, while seemingly positive, also means there's no historical context to assess how the developers have addressed past issues. The plugin's strengths lie in its SQL security and capability checks, but the critical weakness of an unprotected AJAX endpoint and the potential unsanitized path require immediate attention and mitigation.
Key Concerns
- Unprotected AJAX handler
- Flow with unsanitized path
- Low percentage of proper output escaping
CloudGuard Security Vulnerabilities
CloudGuard Code Analysis
Output Escaping
Data Flow Analysis
CloudGuard Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
CloudGuard Maintenance & Trust
Maintenance Signals
Community Trust
CloudGuard Alternatives
DoLogin Security
dologin
Easy Login. 2FA login. Passwordless login. Cloudflare Turnstile reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts.
Login Security Captcha
login-security-recaptcha
Secure WordPress login, registration, and comment form with Google reCAPTCHA or Cloudflare Turnstile. Prevent Brute-force attacks and more.
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
Advanced Country Blocker
advanced-country-blocker
An advanced security plugin that blocks website visitors by country, with additional features like blacklisting, logging blocked attempts, admin bypas …
Prevent Concurrent Logins
prevent-concurrent-logins
Prevents users from staying logged into the same account from multiple places.
CloudGuard Developer Profile
10 plugins · 80K total installs
How We Detect CloudGuard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cloudguard/assets/ammap/ammap.js/wp-content/plugins/cloudguard/assets/ammap/maps/js/worldLow.js/wp-content/plugins/cloudguard/assets/ammap/ammap.js/wp-content/plugins/cloudguard/assets/ammap/maps/js/worldLow.jsHTML / DOM Fingerprints
name="cloudguard_options[accepted_country]"name="cloudguard_options[cloudguard_message]"name="cloudguard_options[cloudguard_redirect]"id="country_code"