Most hacks start at your login. Stop them there.

Real login protection, set up in minutes by a guided wizard. No security expertise needed.

Free forever · No credit card required · WordPress 5.6+ and PHP 7.0+

Ultimate Security dashboard showing the security score, open findings and recent sign-ins
  • Two-Factor Authentication
  • Brute-Force Protection
  • Password Policies
  • CAPTCHA Protection
  • Cloudflare WAF Rules
  • Vulnerability Scanner
  • File Integrity Checks
  • Security Score

Protection where attacks actually happen

Most break-ins start at the login screen or an outdated plugin. Ultimate Security covers both, then keeps watch.

Lock down every login

Two-factor authentication, brute-force limiting, a custom login URL and compromised-password checks stop attackers before they get in.

Learn more →

Stop bots at the door

Google reCAPTCHA or Cloudflare Turnstile on your login, registration and comment forms, with an outage circuit-breaker so you are never locked out.

Learn more →

Block threats at the edge

Deploy 5 groups of WAF rules to your own Cloudflare account so attacks are stopped before they ever reach your server. Fully free.

Learn more →

Find weak spots first

The vulnerability scanner checks your plugins, themes and core against the WPScan and Patchstack databases, and verifies core files against WordPress.org checksums.

Learn more →

Harden without breaking things

Rotate security keys, control update behavior, an emergency recovery URL and settings backup. Safety nets included.

Learn more →

See where you stand

A security score built from 14 checks rates your site across 5 tiers and tells you exactly what to fix next.

Learn more →

A closer look at six of them

Every number below comes from the plugin itself, not a marketing round-up.

Two-factor authentication for WordPress

Add a second step to every WordPress login with email one-time codes or authenticator apps. Free, with per-role enforcement, encrypted secrets and brute-force lockouts built in.

  • Email one-time codes, no app required
  • TOTP and HOTP authenticator apps
  • Per-role enforcement

Learn more →

3
built-in methods: email codes, TOTP and HOTP apps
5
failed attempts before a 15-minute lockout
Per role
enforcement: require 2FA for exactly the roles you choose
Encrypted
2FA secrets stored encrypted in your database

Cloudflare WAF rules for WordPress

Deploy 5 curated firewall rule groups to your own Cloudflare account in one click. Hostile traffic is dropped at the edge, before it ever reaches your server.

  • Allow good bots
  • Block crawlers & WP paths
  • Block web hosts & TOR
  • Challenge cloud providers & countries
  • Challenge VPN & login

Learn more →

5
rule groups, each individually toggleable
Edge
threats stop at Cloudflare, not at your PHP server
1 click
deploy, update or remove the rules from your dashboard
Free
the entire WAF module ships in the free plugin

WordPress vulnerability scanner

Check your plugins, themes and core against the WPScan and Patchstack vulnerability databases, using your own API key, with resumable scans and a full scan history.

  • Plugins, themes and core checked against WPScan or Patchstack
  • Your own API key, with free tiers from both providers
  • Batched, resumable scan execution

Learn more →

2
databases supported: WPScan and Patchstack
Resumable
scans run in batches and pick up where they left off
History
every scan stored, so you can see what changed
Masked
API keys are never echoed back once saved

WordPress security score

Fourteen weighted checks roll up into a 0-100 score and five tiers, from Vulnerable to Fortress, with a concrete list of what to fix next.

  • Weighted checks: 45 critical / 30 high / 15 medium / 10 low
  • Tier gates: the score cannot be gamed with easy points
  • Per-check breakdown showing exactly what to fix next

Learn more →

14
checks across critical, high, medium and low severity
100
points: 45 critical, 30 high, 15 medium, 10 low
5
tiers from Vulnerable to Fortress
Gated
tiers require specific protections, not just points

Activity log for WordPress

A complete record of who did what and when: user, content, plugin and theme events, filterable, exportable to CSV or JSON, and forwardable to your SIEM.

  • Per-domain event toggles; retention 6 months by default (1 to 24)
  • Filterable dashboard with full event detail
  • CSV and JSON export with column selection

Learn more →

5
event groups you can filter and export: logins, users, components, files, settings
CSV/JSON
exports with column selection; big ranges run in the background
6
SIEM mirror targets, from syslog to CloudWatch
Retention
you choose how many months of history to keep

AI malware scanner for WordPress

Send suspicious files to Google, OpenAI, OpenRouter or Requesty with your own API key, and quarantine what comes back dirty. You control the provider, the model and the bill.

  • Google, OpenAI, OpenRouter or Requesty, with per-engine model choice
  • On-demand and scheduled scans (hourly to weekly)
  • Chunked uploads with per-chunk failure tolerance

Learn more →

4
supported engines: Google, OpenAI, OpenRouter, Requesty
Scheduled
optional hourly, twice-daily, daily or weekly scans; off until you add a key
Quarantine
flagged files isolated with one click, whitelist for false positives
Your key
no middleman: your API key, your data agreement, your bill

Pick the site that sounds like yours

Six realistic scenarios drawn from how the plugin is actually configured, not invented testimonials.

The solo blogger

What free gives you

  • Two-factor authentication
  • A hidden login page
  • Brute-force limits
  • CAPTCHA on comments

What Pro adds

  • Login alerts for new devices
  • Magic-link login
  • An audit trail of every change

The small agency

What free gives you

  • Every author on 2FA
  • Password policies
  • Setup templates that copy between client sites

What Pro adds

  • Temporary contractor logins
  • Express links for support
  • Activity logs that answer "who changed that?"
  • Slack webhooks

The WooCommerce store

What free gives you

  • CAPTCHA on login forms
  • CAPTCHA on checkout forms

What Pro adds

  • Email verification and blacklists at checkout
  • Order-change logging
  • AI file scanning
  • Fatal-error emails, before customers see a white screen

The membership site

What free gives you

  • Password policies across the member base
  • Session limits

What Pro adds

  • SMS 2FA and passkeys for members without authenticator apps
  • Breach monitoring of member emails
  • Incident detection

The regulated enterprise

What Pro adds

  • SIEM forwarding to Syslog or CloudWatch
  • GDPR and audit reports
  • Incident timelines
  • An independent watchdog on the plugin itself
  • Retention-managed logs

The multilingual publisher

What free gives you

  • 2FA with per-role enforcement
  • Session limits

What Pro adds

  • Bulk 2FA management
  • An activity log that answers edit disputes
  • Login digests instead of alert noise

Protected in three steps

No security expertise required. The wizard does the tuning.

1. Install free

Grab Ultimate Security from WordPress.org like any other plugin. No account, no credit card.

2. Run the wizard

Pick a basic, moderate or strict protection profile and the wizard switches on the right protection for your kind of site.

3. Watch the score climb

The security score shows exactly where you stand and what to fix next, from Vulnerable to Fortress.

Go further with Pro

Pro extends the free plugin for teams that need more than the basics.

Pro

Passwordless logins

Passkeys, magic links, trusted devices and SMS two-factor authentication via your Twilio account.

Learn more →
Pro

AI malware scanning

Scan suspicious files with your own API key for Google, OpenAI, OpenRouter or Requesty.

Learn more →
Pro

Full activity trail

Activity logs, incident detection for 5 attack patterns, and log forwarding to 6 SIEM targets.

Learn more →

Everything in free, and where Pro picks up

The full breakdown, module by module. Free is free forever, not a trial.

Feature Free Pro
Login & authentication
Two-factor authentication Email one-time codes and authenticator apps (TOTP and HOTP), enforced per role. Email + authenticator+ SMS, backup codes, trusted devices
Passkeys & passwordless Passkeys (WebAuthn) with role enforcement, plus magic-link login. Not includedIncluded
Custom login URL & brute-force limits Move wp-login to an address only you know; escalating lockouts with an emergency recovery URL. IncludedIncluded
Password policies Length, complexity, history and expiry rules, plus a compromised-password check against Have I Been Pwned. IncludedIncluded
Sessions & presence Concurrent-login limits, hardened auth cookies and a Who's Online view. Included+ tracking, revocation and 2FA audit log
Temporary & express logins Time-boxed accounts and one-click support links: single-use tokens, self-deleting accounts. Not includedIncluded
Login notifications & digests Know when and where accounts sign in, with digest emails. Not includedIncluded
Bots & edge protection
CAPTCHA that fails safe reCAPTCHA v2/v3 or Cloudflare Turnstile on login, registration and comments, with an outage circuit-breaker. IncludedIncluded
Cloudflare WAF rules 5 curated rule groups deployed to your own Cloudflare account in one click. Threats stop at the edge. All 5 rule groupsAll 5 rule groups
Email defenses Blacklist with wildcards, verification against 27,300+ disposable domains, breach monitoring. Not includedIncluded
Monitoring & detection
Vulnerability scanner Plugins, themes and core checked against the WPScan and Patchstack databases. IncludedIncluded
Core file-integrity scan Your WordPress core files compared against official WordPress.org checksums. IncludedIncluded
Continuous file monitoring Baseline core, plugins, themes and mu-plugins and get alerted when a file changes, not just core. Not includedIncluded
AI malware scanner Suspicious files analyzed with your own key for Google, OpenAI, OpenRouter or Requesty, quarantine included. Not includedIncluded
Activity log Who did what and when: user, content, plugin and theme events, exportable to CSV or JSON. Lighter logger + login snapshotFull trail with export
Incident detection 5 attack patterns auto-detected and assembled into timelines, with email, Slack or webhook alerts. Not includedIncluded
Security score 14 checks, 5 tiers from Vulnerable to Fortress, and a clear list of what to fix next. IncludedIncluded
Hardening & self-defense
Hardening toggles Around 25 switches: file editors, XML-RPC, user enumeration, version leaks, security headers. Not includedIncluded
Content protection 14 toggles against casual scraping (copy, right-click, hotlinking), site-wide or per page. Not includedIncluded
Plugin self-defense Re-authentication before anyone can deactivate the plugin; tamper attempts logged and alerted. Not includedIncluded
Security-key rotation Rotate your salts in one click, invalidating stolen sessions. IncludedIncluded
Ops, compliance & tools
SIEM & webhooks Forward logs to 6 targets including syslog, CloudWatch and Loggly. Not includedIncluded
Compliance reports 5 report types, including GDPR and audit reports, generated from your real security data. Not includedIncluded
Maintenance tools Update manager, settings backup and restore, Wordfence migration and WP-CLI commands. IncludedExtended
Database cleanup Database cleanup and comments cleaner. Not includedIncluded
Download free Talk to us about Pro

Free tools, no plugin required

Small utilities that run entirely in your browser. No sign-up, no email address, nothing sent to us.

Free

Pwned Password Checker

Check whether a password appears in known data breaches. Your password never leaves your browser.

Open tool →
Free

Password Generator

Generate a strong random password and see exactly how much entropy it carries.

Open tool →
Free

Password Crack Time Calculator

Test a password policy, not a password: see how long the weakest password your rules allow would survive each kind of attack.

Open tool →
Free

Security Breach Cost Calculator

Work out what one security incident would cost your site in downtime, recovery time and lost revenue.

Open tool →

Answers when you need them

Documentation

Setup guides for every module, from the first install through Cloudflare tokens, 2FA enforcement and SIEM forwarding.

Read the docs →

Talk to us

Questions about a feature, a deployment or whether Pro is worth it for your site? Ask before you commit to anything.

Contact support →

Changelog

Every release, what changed in it and when it shipped, including the security fixes.

See what shipped →

Frequently asked questions

The things people ask before installing. Longer answers live in the docs.

Contact support →

Is the free plugin actually free?

Yes. Free forever on WordPress.org, including 2FA, CAPTCHA, brute-force limiting and all 5 Cloudflare WAF rule groups. It is not a trial.

Does the plugin phone home?

Telemetry is opt-in, anonymous and off by default. Some features contact external services by design: vulnerability databases, Have I Been Pwned, Cloudflare, Twilio and AI providers you configure.

What do I need to run it?

The free plugin installed and active, WordPress 5.6 or newer, and PHP 7.0 or newer. Passkeys need PHP 8.2.

Do the Cloudflare WAF rules need a paid Cloudflare plan?

You need your own Cloudflare account with your site on it. The plugin deploys 5 rule groups to Cloudflare's edge for you. The feature itself is fully free.

Which authenticator apps are supported?

Any app that implements the open TOTP or HOTP standards: Google Authenticator, Authy, 1Password, Bitwarden, Microsoft Authenticator and others.

What happens if I lose access to my second factor?

Rename the plugin folder over SFTP to disable the plugin and log in normally, then re-enable it. Pro adds backup codes so users can recover themselves.

Are SMS codes included in the free plugin?

No. Free covers email codes and authenticator apps. SMS codes through your own Twilio account are part of Pro.

Does AI malware scanning cost extra?

AI scanning uses your own API key for Google, OpenAI, OpenRouter or Requesty, so the provider bills you directly for usage. File contents are sent to the provider you choose.

Do some features have third-party costs?

A few integrate with services you bring: Twilio for SMS 2FA, your AI provider key for malware scanning, and your own Cloudflare account for WAF rules.

Can Pro run without the free plugin?

No. Pro is an extension: it requires the free plugin active and refuses to boot without it.

Secure your site today

Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.