Everything your site needs to stay yours
A free core plugin and a Pro extension: no filler, every feature below ships in the plugin today, and every card links to a full breakdown.
The five features doing the heavy lifting
Every module matters, but these are the ones that change what an attack costs.
Two-factor sign-in
A stolen password stops being enough. Free covers email codes and authenticator apps with per-role enforcement; Pro adds passkeys, magic links, SMS codes and trusted devices.
- TOTP and HOTP authenticator support, free
- Passkeys/WebAuthn with role enforcement in Pro
- Backup codes and a full 2FA audit log in Pro
Cloudflare WAF rules at the edge
The plugin deploys 5 rule groups to your own Cloudflare account, so hostile traffic is dropped before it ever reaches your server.
- All 5 rule groups included in the free plugin
- Allow good bots, block scrapers, challenge risky traffic
- Preview, analytics and clean removal built in
AI malware scanning and file monitoring
Baseline core, plugin, theme and mu-plugin files, get alerted on the next hourly scan when one changes, and send suspicious files to an AI provider you choose for a verdict, with quarantine one click away.
- Continuous whole-site file monitoring
- Bring your own key: Google, OpenAI, OpenRouter, Requesty
- Quarantine and whitelist workflows built in
Incident detection with a timeline
The incident engine watches the activity log for 5 attack patterns and assembles what happened into a timeline you can act on, not a wall of raw log lines.
- Detects brute force, privilege escalation, backdoors, plugin compromise and takeovers
- Alerts by email, Slack or webhook
- Full activity log with CSV and JSON export
A setup wizard that does the tuning
Pick a protection profile (basic, moderate or strict) and the wizard applies sensible defaults for your kind of site. Adjust anything later.
- 3 protection profiles: basic, moderate and strict
- Security score shows what to fix next
- Every choice reversible from the settings screen
Free: the core protection layer
Everything here is free forever on WordPress.org. No trial timers, no locked buttons.
Two-factor authentication
Email one-time codes plus authenticator apps (TOTP and HOTP). Three built-in methods, per-role enforcement.
Learn more →Custom login URL
Move wp-login to an address only you know. Automated attacks aimed at the default login page hit a wall.
Learn more →Brute-force limiting
Failed logins earn escalating lockouts. An emergency recovery URL makes sure you are never locked out of your own site.
Learn more →Password policies
Length, complexity, history and expiry rules, plus a compromised-password check against Have I Been Pwned.
Learn more →CAPTCHA that fails safe
Google reCAPTCHA v2/v3 or Cloudflare Turnstile on login, registration and comments, with a key verifier and an outage circuit-breaker.
Learn more →Cloudflare WAF rules
Deploy 5 rule groups to your own Cloudflare account. Threats stop at the edge, not at your server. Fully free.
Learn more →Vulnerability scanner
Plugins, themes and core checked against the WPScan and Patchstack databases, using your own API key.
Learn more →Core file-integrity scan
Compares your WordPress core files against official WordPress.org checksums and flags anything modified.
Learn more →Security score
14 checks, 5 tiers from Vulnerable to Fortress, and a clear list of what to fix next.
Learn more →Security-key rotation
Rotate your salts (the secret keys WordPress uses to secure logins) in one click, invalidating stolen sessions.
Learn more →Sessions & presence
Concurrent-login limits, hardened auth cookies, a Who's Online view and a login activity snapshot.
Learn more →Maintenance tools
Update manager, settings backup and restore, Wordfence migration, WP-CLI commands and a clean opt-in uninstall.
Learn more →Set up in minutes, not weekends
A guided wizard with 3 protection profiles (basic, moderate and strict) tunes the plugin to your kind of site.
Pro: advanced protection for teams that need more
Pro extends the free plugin. It installs alongside it and unlocks the modules below.
Passkeys & passwordless
Passkeys/WebAuthn with role enforcement, magic-link login, and trusted devices that skip 2FA for up to 30 days.
Learn more →SMS 2FA
Text-message codes through your own Twilio account, for teams that will not all install an authenticator app.
Learn more →2FA at scale
Backup codes, session tracking and revocation, a 2FA audit log, and bulk management across every user.
Learn more →Temporary & express logins
Give contractors time-boxed accounts and support staff one-click express links, with no shared passwords.
Learn more →AI malware scanner
Analyze suspicious files with your own API key for Google, OpenAI, OpenRouter or Requesty, with quarantine and whitelist.
Learn more →Continuous file monitoring
Baseline core, plugins, themes and mu-plugins, and get alerted when a file changes: not just core.
Learn more →Full activity log
Content edits, plugin changes, WooCommerce orders: who did what, when. Export to CSV or JSON.
Learn more →Incident detection
The incident engine auto-detects 5 attack patterns and builds timelines, with alerts by email, Slack or webhook.
Learn more →Hardening & self-defense
Around 25 hardening toggles, 15 content-protection toggles, and re-authentication before anyone can disable the plugin.
Learn more →Email defenses
Blacklist with wildcards, verification against 27,300+ disposable domains, and breach monitoring of user emails.
Learn more →Compliance reports
5 report types, including GDPR and audit reports, generated from your real security data. Printable HTML export.
Learn more →Feature questions
Do the Cloudflare WAF rules need a paid Cloudflare plan?
You need your own Cloudflare account with your site on it. The plugin deploys 5 rule groups to Cloudflare's edge for you. The feature itself is fully free.
Does AI malware scanning cost extra?
AI scanning uses your own API key for Google, OpenAI, OpenRouter or Requesty, so the provider bills you directly for usage. File contents are sent to the provider you choose.
Can Pro run without the free plugin?
No. Pro is an extension: it requires the free plugin active and refuses to boot without it.
Does the plugin phone home?
Telemetry is opt-in, anonymous and off by default. Some features contact external services by design: vulnerability databases, Have I Been Pwned, Cloudflare, Twilio and AI providers you configure.
Secure your site today
Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.
