Everything your site needs to stay yours

A free core plugin and a Pro extension: no filler, every feature below ships in the plugin today, and every card links to a full breakdown.

The five features doing the heavy lifting

Every module matters, but these are the ones that change what an attack costs.

Free

Two-factor sign-in

A stolen password stops being enough. Free covers email codes and authenticator apps with per-role enforcement; Pro adds passkeys, magic links, SMS codes and trusted devices.

  • TOTP and HOTP authenticator support, free
  • Passkeys/WebAuthn with role enforcement in Pro
  • Backup codes and a full 2FA audit log in Pro

Read the 2FA guide →

Free

Cloudflare WAF rules at the edge

The plugin deploys 5 rule groups to your own Cloudflare account, so hostile traffic is dropped before it ever reaches your server.

  • All 5 rule groups included in the free plugin
  • Allow good bots, block scrapers, challenge risky traffic
  • Preview, analytics and clean removal built in

See the WAF setup docs →

Pro

AI malware scanning and file monitoring

Baseline core, plugin, theme and mu-plugin files, get alerted on the next hourly scan when one changes, and send suspicious files to an AI provider you choose for a verdict, with quarantine one click away.

  • Continuous whole-site file monitoring
  • Bring your own key: Google, OpenAI, OpenRouter, Requesty
  • Quarantine and whitelist workflows built in
Pro

Incident detection with a timeline

The incident engine watches the activity log for 5 attack patterns and assembles what happened into a timeline you can act on, not a wall of raw log lines.

  • Detects brute force, privilege escalation, backdoors, plugin compromise and takeovers
  • Alerts by email, Slack or webhook
  • Full activity log with CSV and JSON export
Free

A setup wizard that does the tuning

Pick a protection profile (basic, moderate or strict) and the wizard applies sensible defaults for your kind of site. Adjust anything later.

  • 3 protection profiles: basic, moderate and strict
  • Security score shows what to fix next
  • Every choice reversible from the settings screen

Follow the setup guide →

Free: the core protection layer

Everything here is free forever on WordPress.org. No trial timers, no locked buttons.

Free

Two-factor authentication

Email one-time codes plus authenticator apps (TOTP and HOTP). Three built-in methods, per-role enforcement.

Learn more →
Free

Custom login URL

Move wp-login to an address only you know. Automated attacks aimed at the default login page hit a wall.

Learn more →
Free

Brute-force limiting

Failed logins earn escalating lockouts. An emergency recovery URL makes sure you are never locked out of your own site.

Learn more →
Free

Password policies

Length, complexity, history and expiry rules, plus a compromised-password check against Have I Been Pwned.

Learn more →
Free

CAPTCHA that fails safe

Google reCAPTCHA v2/v3 or Cloudflare Turnstile on login, registration and comments, with a key verifier and an outage circuit-breaker.

Learn more →
Free

Cloudflare WAF rules

Deploy 5 rule groups to your own Cloudflare account. Threats stop at the edge, not at your server. Fully free.

Learn more →
Free

Vulnerability scanner

Plugins, themes and core checked against the WPScan and Patchstack databases, using your own API key.

Learn more →
Free

Core file-integrity scan

Compares your WordPress core files against official WordPress.org checksums and flags anything modified.

Learn more →
Free

Security score

14 checks, 5 tiers from Vulnerable to Fortress, and a clear list of what to fix next.

Learn more →
Free

Security-key rotation

Rotate your salts (the secret keys WordPress uses to secure logins) in one click, invalidating stolen sessions.

Learn more →
Free

Sessions & presence

Concurrent-login limits, hardened auth cookies, a Who's Online view and a login activity snapshot.

Learn more →
Free

Maintenance tools

Update manager, settings backup and restore, Wordfence migration, WP-CLI commands and a clean opt-in uninstall.

Learn more →

Set up in minutes, not weekends

A guided wizard with 3 protection profiles (basic, moderate and strict) tunes the plugin to your kind of site.

Pro: advanced protection for teams that need more

Pro extends the free plugin. It installs alongside it and unlocks the modules below.

Pro

Passkeys & passwordless

Passkeys/WebAuthn with role enforcement, magic-link login, and trusted devices that skip 2FA for up to 30 days.

Learn more →
Pro

SMS 2FA

Text-message codes through your own Twilio account, for teams that will not all install an authenticator app.

Learn more →
Pro

2FA at scale

Backup codes, session tracking and revocation, a 2FA audit log, and bulk management across every user.

Learn more →
Pro

Temporary & express logins

Give contractors time-boxed accounts and support staff one-click express links, with no shared passwords.

Learn more →
Pro

AI malware scanner

Analyze suspicious files with your own API key for Google, OpenAI, OpenRouter or Requesty, with quarantine and whitelist.

Learn more →
Pro

Continuous file monitoring

Baseline core, plugins, themes and mu-plugins, and get alerted when a file changes: not just core.

Learn more →
Pro

Full activity log

Content edits, plugin changes, WooCommerce orders: who did what, when. Export to CSV or JSON.

Learn more →
Pro

Incident detection

The incident engine auto-detects 5 attack patterns and builds timelines, with alerts by email, Slack or webhook.

Learn more →
Pro

Hardening & self-defense

Around 25 hardening toggles, 15 content-protection toggles, and re-authentication before anyone can disable the plugin.

Learn more →
Pro

Email defenses

Blacklist with wildcards, verification against 27,300+ disposable domains, and breach monitoring of user emails.

Learn more →
Pro

SIEM & webhooks

Forward logs to 6 targets including syslog, CloudWatch and Loggly.

Learn more →
Pro

Compliance reports

5 report types, including GDPR and audit reports, generated from your real security data. Printable HTML export.

Learn more →

Feature questions

Do the Cloudflare WAF rules need a paid Cloudflare plan?

You need your own Cloudflare account with your site on it. The plugin deploys 5 rule groups to Cloudflare's edge for you. The feature itself is fully free.

Does AI malware scanning cost extra?

AI scanning uses your own API key for Google, OpenAI, OpenRouter or Requesty, so the provider bills you directly for usage. File contents are sent to the provider you choose.

Can Pro run without the free plugin?

No. Pro is an extension: it requires the free plugin active and refuses to boot without it.

Does the plugin phone home?

Telemetry is opt-in, anonymous and off by default. Some features contact external services by design: vulnerability databases, Have I Been Pwned, Cloudflare, Twilio and AI providers you configure.

Secure your site today

Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.