Bitkurier Activity Guard

Enterprise WordPress security – transparent, controllable and real time

Protect logins, monitor security-relevant activity and block suspicious web requests with one central WordPress security solution.

Activity Guard WordPress security platform2FAWAFLogs
0Hours of monitoring
0Security modules
0% local QR generation
0HTTP blocking
Secure access

Two-factor authentication with an authenticator app

Activity Guard adds a second, time-based factor to the WordPress login. Once a TOTP-compatible authenticator app has been connected, users must enter a six-digit app code in addition to their password.

  • Support for standard TOTP authenticator apps
  • Clear connection status and protected account information
  • No email login codes after an authenticator app has been enabled
  • QR code generated locally in the browser without an external QR service
  • Controlled removal only after entering a current app code
Activity Guard authenticator and protection status
Authenticator management and protection status in the WordPress dashboard.
Complete traceability

Activity logging for security-relevant WordPress events

The central event log shows what is happening inside the website. Events can be filtered by severity and event type and include the context required for investigation.

  • UTC timestamp and clear severity level
  • Event type, user and IP address
  • Readable message and request context
  • Detail view for additional technical information
  • Logging of content changes, system events and security alerts
Activity Guard activity log
Filterable security log with event, user and context information.
Enterprise Dashboard

Your security posture at a glance

The dashboard summarises authenticator coverage, today's events, warnings and the latest activity in one clear interface.

Bitkurier Activity Guard Enterprise Dashboard

2FA coverage

See how many administrators and users are already protected by an authenticator.

Events today

Current activity volume makes unusual spikes easier to identify.

Warnings and critical events

Security-relevant events are highlighted so that action remains visible.

Quick access

Open authenticator settings, user status and the complete activity log directly.

Request protection

Web Application Firewall and login protection

The integrated WAF checks incoming requests for suspicious patterns. Depending on configuration, malicious requests and file uploads are blocked and logged.

  • Inspection of request paths, query parameters and POST fields
  • Blocking suspicious requests with HTTP 403
  • Detection of common SQL injection, traversal and webshell patterns
  • Optional blocking of suspicious file uploads
  • Configurable brute-force protection with attempt, time-window and lockout values
  • Automatic removal of expired IP blocks
Activity Guard WAF and login protection
Configurable firewall, upload and login-protection rules.
Central configuration

Alerts, file scans and encrypted event transmission

All active protection modules are managed centrally. Email alerts notify administrators about security-relevant events, while a cooldown limits repeated notifications.

  • Configurable email alerts with a dedicated recipient address
  • Encrypted transmission of logged events to the Bitkurier security service
  • Mandatory two-factor login
  • Hourly file scan with a configurable analysis period
  • Individually configurable retention period
  • Visible connection status for the central service
Activity Guard security settings
Central management of alerts, WAF, login protection, file scanning and retention.
Automated protection workflow

From request to security response

1

Request or action

A login, upload, request or WordPress change is initiated.

2

Analysis

Activity Guard checks rules, attack patterns, user context and security status.

3

Block and log

Suspicious activity is blocked according to configuration and recorded in full.

4

Alert and review

Administrators gain visibility through the dashboard, activity log and email alerts.

One system instead of isolated tools

Core protection areas combined centrally

FeatureActivity GuardBasic 2FA pluginBasic logging plugin
Authenticator-based 2FA
Activity log with context
Web Application Firewall
Login and IP protectionPartial
File scanning
Central security transmission
Email alertsPartialPartial
Frequently Asked Questions

Technology explained clearly

Which authenticator apps are supported?+

Activity Guard works with TOTP-compatible authenticator apps, including Google Authenticator, Microsoft Authenticator, Aegis, Authy and FreeOTP.

What happens without an authenticator app?+

In the shown configuration, a six-digit email code is provided through the central Bitkurier mail service. Once an authenticator is configured, only the app code is accepted.

Which requests can the WAF block?+

The rules inspect request paths, query and POST fields for configured SQL injection, traversal and webshell patterns as well as suspicious file uploads.

How does login protection work?+

After a configured number of failed logins within a defined time window, the affected IP address is blocked for the selected duration.

Are events stored permanently?+

The retention period can be configured in days to align storage with internal requirements and data-protection policies.

Protect WordPress reliably

Ready to protect your website with Activity Guard?

Start with one WordPress installation or request a tailored Corporate solution.

Protect now