Aegis User Guard is a single, self-contained security console that adds the identity-policy controls most sites end up needing eventually: password expiration and complexity, inactivity lockout, brute-force protection, two-factor authentication, an IP allow/block list, and full oversight of every Administrator account. It does not replace WordPress's login system or session handling; it layers policy and visibility on top of it, and every control can be switched off independently.
Everything lives on one native-feeling admin screen, organized into tabs:
- Core controls — the identity policies below, each with its own on/off switch.
- Recently added — a quick pulse of the newest accounts and their status.
- Email notifications — the shared template and recipient list for Administrator security alerts.
- Administrator directory — every Administrator, their last sign-in, active sessions, and one-click actions.
- Access & IPs — a manual IP allow/block list.
- Checklist — a read-only audit of common WordPress hardening gaps, with one-click fixes where Aegis can apply them.
- Activity log — a chronological, exportable record of every security event Aegis observed.
Identity policies
- Password freshness — prompt users to rotate their password after a configurable age (default 180 days).
- Password complexity — require a minimum length and, optionally, mixed case, a number, and a symbol, enforced on password reset and profile changes.
- Inactive account lockout — pause login access after a configurable period of inactivity (default 90 days).
- Brute-force lockout — lock an account and its originating network after repeated failed sign-ins, independent of whether the attempted username exists.
- Two-factor authentication (TOTP) — self-service setup from any user's own profile (manual-entry key, no third-party QR service), with one-time backup codes and an option to require it for all Administrators.
- REST API user-list restriction — block anonymous requests to
/wp-json/wp/v2/users so usernames cannot be enumerated, while leaving authenticated requests untouched.
- Administrator alerts — independently alert all or selected Administrators when a user is created, signs in, changes username, changes email address, or changes password. Administrator promotions remain covered as well.
- New-device sign-in alerts — email a user when their own account signs in from an IP address not seen before.
Administrator oversight
- A live directory of every Administrator account: last sign-in, status, active session count, and CSV export.
- Manual Pause access / Reactivate access for any account, with native WordPress session termination.
- A "Force password reset" action that requires a new password on next login and signs the account out everywhere.
- A one-click "Sign out everywhere" action to end every active session for an account immediately.
- A pending-Administrator review queue: new or newly promoted Administrators are blocked from signing in until an existing Administrator grants access.
Access control
- A manual IP allow/block list — block a network outright, or exempt a trusted IP from brute-force lockouts.
- Individual failed-sign-in logging, alongside every lockout, pause, and policy change, in the Activity log.
Hardening checklist
A read-only audit covering file-editing access, debug output exposure, HTTPS on wp-admin, a default "admin" username, the two-factor requirement, REST API user enumeration, and pending core/plugin updates — each with a plain-language fix, and a direct link into the relevant Aegis setting where Aegis can apply it itself.
Everything native
Aegis stores its data in standard WordPress options and user meta, uses native password-reset and session-termination APIs, and never introduces its own authentication layer. Disabling or deleting the plugin returns the site to stock WordPress behavior.