About us

Security software that shows its work.

WordSec is a WordPress security platform built around one idea: protection you can inspect, verify and understand.

What we build

WordSec ships eight security modules in a single plugin: a web application firewall, a staged malware scanner, login security with 2FA, vulnerability alerts, and the tooling around them. Every rule the engine applies is listed in the product, not hidden behind a score.

The vulnerability database

We maintain a free, public database of WordPress plugin, theme and core vulnerabilities with CVE identifiers, CVSS scores, affected version ranges and researcher attribution, browsable by anyone and served over a public JSON API. Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence Terms & Conditions.

We practice what we sell

This site runs the hardening we recommend: a scoped Content-Security-Policy, two-year HSTS, frame denial and strict referrer policy on every response. Security vendors should be inspectable too.

Talk to us

Questions, disclosures or feedback: info@wordsec.net

Contact us