Most hacks start at your login. Stop them there.
Real login protection, set up in minutes by a guided wizard. No security expertise needed.
Free forever · No credit card required · WordPress 5.6+ and PHP 7.0+
- Two-Factor Authentication
- Brute-Force Protection
- Password Policies
- CAPTCHA Protection
- Cloudflare WAF Rules
- Vulnerability Scanner
- File Integrity Checks
- Security Score
Protection where attacks actually happen
Most break-ins start at the login screen or an outdated plugin. Ultimate Security covers both, then keeps watch.
Lock down every login
Two-factor authentication, brute-force limiting, a custom login URL and compromised-password checks stop attackers before they get in.
Learn more →Stop bots at the door
Google reCAPTCHA or Cloudflare Turnstile on your login, registration and comment forms, with an outage circuit-breaker so you are never locked out.
Learn more →Block threats at the edge
Deploy 5 groups of WAF rules to your own Cloudflare account so attacks are stopped before they ever reach your server. Fully free.
Learn more →Find weak spots first
The vulnerability scanner checks your plugins, themes and core against the WPScan and Patchstack databases, and verifies core files against WordPress.org checksums.
Learn more →Harden without breaking things
Rotate security keys, control update behavior, an emergency recovery URL and settings backup. Safety nets included.
Learn more →See where you stand
A security score built from 14 checks rates your site across 5 tiers and tells you exactly what to fix next.
Learn more →A closer look at six of them
Every number below comes from the plugin itself, not a marketing round-up.
Two-factor authentication for WordPress
Add a second step to every WordPress login with email one-time codes or authenticator apps. Free, with per-role enforcement, encrypted secrets and brute-force lockouts built in.
- Email one-time codes, no app required
- TOTP and HOTP authenticator apps
- Per-role enforcement
Cloudflare WAF rules for WordPress
Deploy 5 curated firewall rule groups to your own Cloudflare account in one click. Hostile traffic is dropped at the edge, before it ever reaches your server.
- Allow good bots
- Block crawlers & WP paths
- Block web hosts & TOR
- Challenge cloud providers & countries
- Challenge VPN & login
WordPress vulnerability scanner
Check your plugins, themes and core against the WPScan and Patchstack vulnerability databases, using your own API key, with resumable scans and a full scan history.
- Plugins, themes and core checked against WPScan or Patchstack
- Your own API key, with free tiers from both providers
- Batched, resumable scan execution
WordPress security score
Fourteen weighted checks roll up into a 0-100 score and five tiers, from Vulnerable to Fortress, with a concrete list of what to fix next.
- Weighted checks: 45 critical / 30 high / 15 medium / 10 low
- Tier gates: the score cannot be gamed with easy points
- Per-check breakdown showing exactly what to fix next
Activity log for WordPress
A complete record of who did what and when: user, content, plugin and theme events, filterable, exportable to CSV or JSON, and forwardable to your SIEM.
- Per-domain event toggles; retention 6 months by default (1 to 24)
- Filterable dashboard with full event detail
- CSV and JSON export with column selection
AI malware scanner for WordPress
Send suspicious files to Google, OpenAI, OpenRouter or Requesty with your own API key, and quarantine what comes back dirty. You control the provider, the model and the bill.
- Google, OpenAI, OpenRouter or Requesty, with per-engine model choice
- On-demand and scheduled scans (hourly to weekly)
- Chunked uploads with per-chunk failure tolerance
Pick the site that sounds like yours
Six realistic scenarios drawn from how the plugin is actually configured, not invented testimonials.
The solo blogger
What free gives you
- Two-factor authentication
- A hidden login page
- Brute-force limits
- CAPTCHA on comments
What Pro adds
- Login alerts for new devices
- Magic-link login
- An audit trail of every change
The small agency
What free gives you
- Every author on 2FA
- Password policies
- Setup templates that copy between client sites
What Pro adds
- Temporary contractor logins
- Express links for support
- Activity logs that answer "who changed that?"
- Slack webhooks
The WooCommerce store
What free gives you
- CAPTCHA on login forms
- CAPTCHA on checkout forms
What Pro adds
- Email verification and blacklists at checkout
- Order-change logging
- AI file scanning
- Fatal-error emails, before customers see a white screen
The membership site
What free gives you
- Password policies across the member base
- Session limits
What Pro adds
- SMS 2FA and passkeys for members without authenticator apps
- Breach monitoring of member emails
- Incident detection
The regulated enterprise
What Pro adds
- SIEM forwarding to Syslog or CloudWatch
- GDPR and audit reports
- Incident timelines
- An independent watchdog on the plugin itself
- Retention-managed logs
The multilingual publisher
What free gives you
- 2FA with per-role enforcement
- Session limits
What Pro adds
- Bulk 2FA management
- An activity log that answers edit disputes
- Login digests instead of alert noise
Protected in three steps
No security expertise required. The wizard does the tuning.
1. Install free
Grab Ultimate Security from WordPress.org like any other plugin. No account, no credit card.
2. Run the wizard
Pick a basic, moderate or strict protection profile and the wizard switches on the right protection for your kind of site.
3. Watch the score climb
The security score shows exactly where you stand and what to fix next, from Vulnerable to Fortress.
Go further with Pro
Pro extends the free plugin for teams that need more than the basics.
Passwordless logins
Passkeys, magic links, trusted devices and SMS two-factor authentication via your Twilio account.
Learn more →AI malware scanning
Scan suspicious files with your own API key for Google, OpenAI, OpenRouter or Requesty.
Learn more →Full activity trail
Activity logs, incident detection for 5 attack patterns, and log forwarding to 6 SIEM targets.
Learn more →Everything in free, and where Pro picks up
The full breakdown, module by module. Free is free forever, not a trial.
| Feature | Free | Pro |
|---|---|---|
| Login & authentication | ||
| Two-factor authentication Email one-time codes and authenticator apps (TOTP and HOTP), enforced per role. | Email + authenticator | + SMS, backup codes, trusted devices |
| Passkeys & passwordless Passkeys (WebAuthn) with role enforcement, plus magic-link login. | Not included | Included |
| Custom login URL & brute-force limits Move wp-login to an address only you know; escalating lockouts with an emergency recovery URL. | Included | Included |
| Password policies Length, complexity, history and expiry rules, plus a compromised-password check against Have I Been Pwned. | Included | Included |
| Sessions & presence Concurrent-login limits, hardened auth cookies and a Who's Online view. | Included | + tracking, revocation and 2FA audit log |
| Temporary & express logins Time-boxed accounts and one-click support links: single-use tokens, self-deleting accounts. | Not included | Included |
| Login notifications & digests Know when and where accounts sign in, with digest emails. | Not included | Included |
| Bots & edge protection | ||
| CAPTCHA that fails safe reCAPTCHA v2/v3 or Cloudflare Turnstile on login, registration and comments, with an outage circuit-breaker. | Included | Included |
| Cloudflare WAF rules 5 curated rule groups deployed to your own Cloudflare account in one click. Threats stop at the edge. | All 5 rule groups | All 5 rule groups |
| Email defenses Blacklist with wildcards, verification against 27,300+ disposable domains, breach monitoring. | Not included | Included |
| Monitoring & detection | ||
| Vulnerability scanner Plugins, themes and core checked against the WPScan and Patchstack databases. | Included | Included |
| Core file-integrity scan Your WordPress core files compared against official WordPress.org checksums. | Included | Included |
| Continuous file monitoring Baseline core, plugins, themes and mu-plugins and get alerted when a file changes, not just core. | Not included | Included |
| AI malware scanner Suspicious files analyzed with your own key for Google, OpenAI, OpenRouter or Requesty, quarantine included. | Not included | Included |
| Activity log Who did what and when: user, content, plugin and theme events, exportable to CSV or JSON. | Lighter logger + login snapshot | Full trail with export |
| Incident detection 5 attack patterns auto-detected and assembled into timelines, with email, Slack or webhook alerts. | Not included | Included |
| Security score 14 checks, 5 tiers from Vulnerable to Fortress, and a clear list of what to fix next. | Included | Included |
| Hardening & self-defense | ||
| Hardening toggles Around 25 switches: file editors, XML-RPC, user enumeration, version leaks, security headers. | Not included | Included |
| Content protection 14 toggles against casual scraping (copy, right-click, hotlinking), site-wide or per page. | Not included | Included |
| Plugin self-defense Re-authentication before anyone can deactivate the plugin; tamper attempts logged and alerted. | Not included | Included |
| Security-key rotation Rotate your salts in one click, invalidating stolen sessions. | Included | Included |
| Ops, compliance & tools | ||
| SIEM & webhooks Forward logs to 6 targets including syslog, CloudWatch and Loggly. | Not included | Included |
| Compliance reports 5 report types, including GDPR and audit reports, generated from your real security data. | Not included | Included |
| Maintenance tools Update manager, settings backup and restore, Wordfence migration and WP-CLI commands. | Included | Extended |
| Database cleanup Database cleanup and comments cleaner. | Not included | Included |
| Download free | Talk to us about Pro | |
Free tools, no plugin required
Small utilities that run entirely in your browser. No sign-up, no email address, nothing sent to us.
Pwned Password Checker
Check whether a password appears in known data breaches. Your password never leaves your browser.
Open tool →Password Generator
Generate a strong random password and see exactly how much entropy it carries.
Open tool →Password Crack Time Calculator
Test a password policy, not a password: see how long the weakest password your rules allow would survive each kind of attack.
Open tool →Security Breach Cost Calculator
Work out what one security incident would cost your site in downtime, recovery time and lost revenue.
Open tool →Answers when you need them
Documentation
Setup guides for every module, from the first install through Cloudflare tokens, 2FA enforcement and SIEM forwarding.
Read the docs →Talk to us
Questions about a feature, a deployment or whether Pro is worth it for your site? Ask before you commit to anything.
Contact support →Changelog
Every release, what changed in it and when it shipped, including the security fixes.
See what shipped →Frequently asked questions
The things people ask before installing. Longer answers live in the docs.
Is the free plugin actually free?
Yes. Free forever on WordPress.org, including 2FA, CAPTCHA, brute-force limiting and all 5 Cloudflare WAF rule groups. It is not a trial.
Does the plugin phone home?
Telemetry is opt-in, anonymous and off by default. Some features contact external services by design: vulnerability databases, Have I Been Pwned, Cloudflare, Twilio and AI providers you configure.
What do I need to run it?
The free plugin installed and active, WordPress 5.6 or newer, and PHP 7.0 or newer. Passkeys need PHP 8.2.
Do the Cloudflare WAF rules need a paid Cloudflare plan?
You need your own Cloudflare account with your site on it. The plugin deploys 5 rule groups to Cloudflare's edge for you. The feature itself is fully free.
Which authenticator apps are supported?
Any app that implements the open TOTP or HOTP standards: Google Authenticator, Authy, 1Password, Bitwarden, Microsoft Authenticator and others.
What happens if I lose access to my second factor?
Rename the plugin folder over SFTP to disable the plugin and log in normally, then re-enable it. Pro adds backup codes so users can recover themselves.
Are SMS codes included in the free plugin?
No. Free covers email codes and authenticator apps. SMS codes through your own Twilio account are part of Pro.
Does AI malware scanning cost extra?
AI scanning uses your own API key for Google, OpenAI, OpenRouter or Requesty, so the provider bills you directly for usage. File contents are sent to the provider you choose.
Do some features have third-party costs?
A few integrate with services you bring: Twilio for SMS 2FA, your AI provider key for malware scanning, and your own Cloudflare account for WAF rules.
Can Pro run without the free plugin?
No. Pro is an extension: it requires the free plugin active and refuses to boot without it.
Secure your site today
Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.
