WordPress security score
Fourteen weighted checks roll up into a 0-100 score and five tiers, from Vulnerable to Fortress, with a concrete list of what to fix next.
What it does
Security settings scattered across a dozen screens make it hard to answer the only question that matters: how protected am I, actually? The score condenses your real configuration into one number, one tier, and a prioritized to-do list.
How it works
The critical checks carry the weight: two-factor authentication, SSL, and login rate limiting are 15 points each. CAPTCHA, password policy and an updated core are 10 each; updated plugins, audit logs and file monitoring 5 each; and a set of hardening details (hidden login, disabled file editing, API privacy, content protection, login consent) round out the hundred.
Tiers are deliberately strict: points alone are not enough. Reaching Protected requires SSL, 2FA and rate limiting to actually be on; Hardened adds CAPTCHA and a password policy. The top tier, Fortress, additionally requires audit logs and continuous file monitoring, which are Pro modules, so a free-only site honestly tops out below Fortress rather than being flattered.
- Weighted checks: 45 critical / 30 high / 15 medium / 10 low
- Tier gates: the score cannot be gamed with easy points
- Per-check breakdown showing exactly what to fix next
- Refresh on demand from the dashboard or REST API
Documentation
Security score questions
Why is my score high but my tier low?
Tiers have gates: specific protections must be enabled regardless of points. A pile of low-severity wins cannot substitute for missing 2FA or SSL, by design.
Can a free site reach Fortress?
No. Fortress requires audit logs and continuous file monitoring, which are Pro modules. We would rather the score tell you that plainly than inflate it.
Related features
Secure your site today
Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.
