- Install and activate
guardforge. Sensible defaults are on from the first request — nothing to configure to be safer than before. - Open GuardForge > Settings and review the hardening switches.
- For Pro: activate
guardforge-pro, open GuardForge > License, paste theFRG-…key.
- Will hardening break my site? The REST allow-list ships with the entries the block editor and the other Forge plugins need. Turning REST off entirely is a separate switch and is off by default.
- Does it phone home? Free: the daily checksum lookup at wordpress.org, the daily advisory download, and “Explain this event” when pressed — see the Product Overview. Pro: licence check, the licensed feed, Cloudflare with your own token, and the AI verdict when enabled.