plugin-icon

StaticGuard

Reduce the public WordPress attack surface with a verified static copy. Elementor pages, galleries, lightboxes and classic forms remain available.
Version
1.0.7
Last updated
Aug 31, 2026
StaticGuard

StaticGuard generates a local static copy of your public WordPress site and serves it to logged-out visitors from the same domain. WordPress remains installed and available to authenticated administrators, while ordinary public pages no longer need to execute PHP or query the database.

The Free edition is focused on Elementor brochure sites and includes:

  • a five-step first-run setup assistant with actionable diagnostics;
  • manual full-site static publication;
  • local discovery and copying of pages, styles, scripts, fonts, images and videos;
  • Elementor-aware asset discovery and validation;
  • frontend support for menus, galleries, lightboxes and common interactions;
  • classic Elementor Pro form delivery through the site’s own AJAX endpoint;
  • form origin checks, a honeypot and essential rate limiting;
  • validation before activation and anonymous verification after activation;
  • automatic recovery to the previous public copy when a new publication fails;
  • daily local integrity checks that rebuild or restore the public copy when it is damaged;
  • two locally stored, restorable versions, with a configurable retention of 2 to 20 copies;
  • hosting diagnostics for Apache, LiteSpeed and common proxy configurations.

No subdomain, second hosting account, DNS change, external static hosting service, StaticGuard account or license key is required for Free.

The administration interface is available in French and English and follows the WordPress dashboard language automatically.

What StaticGuard changes

StaticGuard writes generated files under the WordPress uploads directory, in uploads/staticguard/. Private releases live in uploads/staticguard/data and the active public copy lives in uploads/staticguard/static/current. Already-deployed wp-content/wordpress-shield-data and wp-content/wordpress-shield-static trees can still be read so a live publication is not moved, but new files are never created there. If uploads are offloaded or stored outside the WordPress web root, StaticGuard reports a blocking admin diagnostic instead of writing to wp-content. On supported servers it adds a clearly delimited routing block to the WordPress .htaccess file. Disabling the plugin removes this managed routing and restores ordinary WordPress delivery.

Security scope

Static publication substantially reduces the code exposed on ordinary public pages, but it does not make the complete WordPress installation invulnerable. Keep WordPress, themes and plugins updated; use strong passwords, backups and HTTPS; and protect the hosting account itself.

Free and Pro

StaticGuard Free contains no paid-feature code and does not contact a license or update server. StaticGuard Pro is a separate GPL extension.

Pro adds:

  • automatic publication
  • integrity monitoring and repair
  • a private back-office address
  • email two-factor authentication
  • login protection
  • multipage Elementor audits
  • extended publication history

Buy Pro at staticguard.io/tarifs: 59 € TTC/year per site, 119 € Pro, 239 € Agency.

Freeon paid plans
Tested up to
WordPress 7.1
This plugin is available for download for your site.