Security software that shows its work.
WordSec is a WordPress security platform built around one idea: protection you can inspect, verify and understand.
What we build
WordSec ships eight security modules in a single plugin: a web application firewall, a staged malware scanner, login security with 2FA, vulnerability alerts, and the tooling around them. Every rule the engine applies is listed in the product, not hidden behind a score.
The vulnerability database
We maintain a free, public database of WordPress plugin, theme and core vulnerabilities with CVE identifiers, CVSS scores, affected version ranges and researcher attribution, browsable by anyone and served over a public JSON API. Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence Terms & Conditions.
We practice what we sell
This site runs the hardening we recommend: a scoped Content-Security-Policy, two-year HSTS, frame denial and strict referrer policy on every response. Security vendors should be inspectable too.
Talk to us
Questions, disclosures or feedback: info@wordsec.net
Contact us