76 Quality Score
Active Installs
14/30

With around 1,000 active installs it is a niche tool, well behind the million-plus install leaders in this category, though it scores above the baseline for that footprint.

Update Freshness
25/25

It was updated on July 2, 2026 and tested against WordPress 7.0, which is an unusually forward-looking test target and signals active development.

User Rating
15/15

A perfect 100 from 5 ratings is encouraging but the sample is very small, so the rating carries limited statistical weight.

Support Health
8/15

There are zero support threads and zero resolutions, which is neutral rather than negative given the tiny user base, but it means no public track record to fall back on.

WP Compatibility
15/15

Requires WordPress 3.0 and PHP 7.0, so it runs on virtually any modern WordPress install with no compatibility red flags.

Scores higher than 46% of indexed plugins

About

This plugin blocks all unauthorized and irrelevant requests through query strings and provides extended session tracking and capability audit.

Active Installs 1k+
Rating ★★★★★ 5/5
Last Updated 2026-07-02 10:04pm GMT
Requires WordPress 3.0+
Tested Up To 7.0.4
Requires PHP 7.0+

Security History

6 known vulnerabilities, all patched
1 High 5 Medium

Most recent: March 20, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Injection Guard filters incoming HTTP requests and blocks query strings that look like SQL injection attempts or other malicious payloads. It also adds session tracking and capability audit logging so administrators can review who did what on the site. In practice it acts as a lightweight request-filtering layer sitting in front of WordPress.

Who It's For

This plugin suits developers or site administrators on small to mid-sized WordPress installations who want a focused query-string firewall without hauling in a full security suite. It is also useful for sites in regulated environments where capability audit logs are required for compliance. Beginners looking for an all-in-one security dashboard will find it too narrow.

Who Should Skip It

Anyone already running Wordfence, Jetpack Security, or Really Simple Security does not need this layer, since those plugins include equivalent or broader request filtering. Large enterprise sites with dedicated WAF infrastructure will also get little additional value.

The Bottom Line

Injection Guard is a competent, narrowly focused request-filtering and audit tool that scores 75.93/100, held back mainly by its tiny install base and zero public support history. The perfect rating from a handful of users is promising but not yet conclusive evidence of long-term reliability. It is worth a look for hands-on admins who want a lightweight injection shield, not for anyone seeking a complete security suite.

Tags

anti-hacking firewall security sql-injection wordpress security