🔒
Hosting

WordPress powers nearly 43% of all websites on the internet — making it the number one target for attackers worldwide. Every day, botnets scan for WordPress sites looking for weak passwords, unpatched plugins, and vulnerable core files. The challenge isn't that WordPress is insecure by design; it's that its sheer popularity makes it a high-value target. cPGuard is a server-level WordPress security module that works before WordPress even loads, providing multi-layered protection that goes far beyond what plugin-based security can achieve.

cPGuard works before WordPress loads — many malware types are detected and blocked before PHP even runs WordPress, making it significantly more effective than security plugins that operate inside WordPress. This is a fundamental architectural advantage: threats are stopped at the server level rather than filtered through application code.

WordPress Core File Integrity — Checksum Verification

One of the most insidious attack techniques is modifying WordPress core files to embed backdoors. Attackers edit files like wp-login.php, wp-includes/functions.php, or wp-admin/index.php to insert malicious code that survives theme and plugin updates. This is a "low-and-slow" persistence method — the backdoor isn't obvious and can remain in place for months.

cPGuard's Core Checksum feature monitors every WordPress core file and compares its SHA-256 hash against the official checksums published by WordPress.org. When a mismatch is detected, cPGuard immediately alerts the administrator and can trigger automatic remediation: downloading a clean copy of the modified file directly from the WordPress CDN and replacing it, without affecting themes, plugins, custom code, or the database.

The process is completely safe: cPGuard uses official checksums (the same ones WordPress.org publishes), so you can be 100% confident the replacement file is legitimate. The replacement happens at the filesystem level, not through WordPress, so it cannot be blocked by corrupted WordPress code.

This is critical because many hacks go undetected for months using core file modifications. Website owners only realize they've been compromised after discovering a data breach or receiving a phishing complaint from Google Search Console. With cPGuard, such modifications trigger an alert within hours.

CVE Plugin and Theme Vulnerability Scanning

Outdated plugins and themes are the number one attack vector for WordPress sites. Security researchers estimate that more than 70% of WordPress hacks exploit known vulnerabilities in plugins — vulnerabilities that already have public exploit code and an assigned CVE (Common Vulnerabilities and Exposures) number.

cPGuard's CMS Threats module uses a real-time CVE database to continuously scan all installed plugins, themes, and the WordPress core version. When a vulnerability is detected, cPGuard:

Unlike manual checking (which requires logging into each site individually and checking the update dashboard), cPGuard scans across all sites on the server from a central location. If you manage multiple WordPress installations, you get one unified vulnerability report across all of them.

Scope of coverage: cPGuard covers WordPress core itself, all official WordPress plugins from wordpress.org, and the most popular premium plugins (like Yoast SEO, WooCommerce, Elementor). It also tracks vulnerabilities in widely-used premium themes. The CVE database is updated hourly, so newly-disclosed vulnerabilities are added within an hour of publication.

WordPress-Specific WAF Rules — Layer 2 Defense

A traditional Web Application Firewall (WAF) blocks common web attacks (SQL injection, cross-site scripting), but those rules are generic across all web apps. cPGuard includes WordPress-specific WAF rules that target attack patterns unique to WordPress's architecture.

These rules block:

These rules work in conjunction with the core file integrity checks and database scanner — they form concentric layers of defense, each catching different attack patterns.

WordPress Database Scanner — Finding Hidden Infections

The most sophisticated WordPress malware doesn't modify files at all — it injects code directly into the MySQL database. This bypasses file-based security tools and remains invisible to most website owners.

For example, malware might inject:

cPGuard's Database Scanner inspects these tables row-by-row looking for patterns consistent with malware. When suspicious content is found, cPGuard alerts you and can display the potentially malicious data so you can review and remove it.

Why this matters: Many website owners think their site is clean after removing malware, but database-level infections often get missed. cPGuard catches these by scanning the structure of the data itself — for example, looking for user accounts created outside of WordPress's normal account creation process.

Brute Force Protection — CAPTCHA at the Perimeter

The most common WordPress attack is still a brute force attack on wp-login.php. Botnets run millions of login attempts per day trying common passwords. If your WordPress site doesn't have strong password policies and account lockout rules, these attacks can succeed.

cPGuard protects wp-login.php using a clever technique: DNS-based CAPTCHA redirection. Instead of filtering login attempts through PHP (which wastes server resources), cPGuard intercepts login requests at the server level and:

  1. Detects repeated failed logins from the same IP
  2. Redirects that IP to an off-server CAPTCHA challenge hosted on cPGuard's secure servers
  3. Only allows access to WordPress after the CAPTCHA is solved
  4. If too many CAPTCHA failures occur, blocks that IP completely

Performance benefit: CAPTCHA solving happens off your server, so your server resources are preserved for legitimate traffic. Automated bots cannot solve CAPTCHAs, so brute force attacks are stopped in their tracks.

WP-Cron Optimization — Preventing Scheduled Abuse

WordPress includes a "cron" system that triggers scheduled tasks — sending scheduled posts, running backups, and cleaning up transient data. However, WP-Cron has a critical design flaw: it's "fake cron" that only executes when someone visits the site. If nobody visits the site for hours, scheduled tasks don't run. Moreover, attackers can abuse WP-Cron to run malicious scheduled tasks.

cPGuard's WP-Cron Optimization module:

Real-Time Malware Threat Intelligence

cPGuard doesn't rely on a static list of malware signatures — it includes real-time threat intelligence that's updated hourly. This means new malware families discovered in the wild are added to detection rules within hours, not weeks or months.

cPGuard's labs team partners with security research organizations and monitors WordPress-specific malware repositories to stay ahead of emerging threats. This is critical because WordPress malware evolves rapidly — a new variant of a known backdoor might bypass signature-based detection, but behavioral analysis in cPGuard can catch it.

Comparison: cPGuard vs. Plugin-Based Security

You might be wondering: "Why not just use Wordfence, iThemes Security, or All In One WP Security?" These are excellent plugins, but they have fundamental limitations:

Feature cPGuard (Server-Level) WordPress Security Plugins
Protection Before WordPress Loads ✅ Yes ❌ No — plugin runs after WordPress loads
Detects Modified Core Files ✅ Yes ✅ Yes
Resource Usage ✅ Minimal (server-level, not PHP) ❌ High (each site loads plugin, scans)
Works if WordPress is Broken ✅ Yes ❌ No — plugin can't run if WordPress won't load
Protects All Sites on Server ✅ Yes (one config protects all) ❌ No — must install per-site
Database Scanning ✅ Yes (comprehensive) ✅ Yes (but slower)
CVE Vulnerability Alerts ✅ Yes ✅ Yes (many plugins have this)
Can Block Attack Before Reaching PHP ✅ Yes ❌ No — attack reaches PHP, then plugin filters

The key insight: cPGuard and WordPress security plugins complement each other. Many website owners use cPGuard on the server AND a plugin like Wordfence on individual sites — the server-level protection catches threats that reach the filesystem, while the plugin catches threats that exploit WordPress features themselves.

Frequently Asked Questions

What is cPGuard WordPress Core Checksum?

It verifies that WordPress core files match the official checksums from WordPress.org. If a file is modified, cPGuard detects it immediately and can automatically download a clean original from WordPress CDN to replace it. This protects against backdoors inserted into core files.

Can cPGuard scan for plugin and theme vulnerabilities?

Yes — the CMS Threats module uses CVE (Common Vulnerabilities and Exposures) intelligence to check whether installed plugins, themes or WordPress core have known vulnerabilities, then alerts the admin by email or enforces automatic updates. The CVE database is updated hourly.

How is cPGuard different from Wordfence?

cPGuard operates at the server level, protecting all sites on the server simultaneously without installing a plugin on each site. Wordfence is a WordPress plugin installed per-site. cPGuard's main advantage is detecting malware before WordPress even loads, which catches compromised core files that Wordfence cannot.

Can cPGuard restore modified WordPress core files automatically?

Yes — cPGuard downloads the clean original from WordPress.org CDN and replaces the modified file without affecting themes, plugins or the database. The restoration happens at the filesystem level, not through WordPress, so it works even if WordPress itself is broken.

What tables does the WordPress Database Scanner check?

It inspects wp_posts (spam links, phishing content), wp_options (malicious redirects in siteurl/home/widgets), wp_users (hidden admin accounts) and wp_usermeta for backdoor credentials. It also looks for suspicious patterns like posts with unusually high link density or admin users created outside normal registration.

Does cPGuard block login attacks on wp-login.php?

Yes — cPGuard uses DNS-based CAPTCHA to redirect brute force attackers to an off-server CAPTCHA challenge. Attackers that fail the CAPTCHA are blocked there, significantly reducing server load from failed login attempts and making brute force attacks impractical.

What You Should Do Today

If you run WordPress sites, here's a practical checklist:

Protect Your WordPress with AsiaGB Hosting + cPGuard

AsiaGB installs cPGuard on every server — your WordPress is protected from day one. No setup required. On SSD from 500 THB/year with 99% uptime guarantee.

See Hosting Plans

View all cheap Thailand web hosting plans →