Everything WordSec Does,
In One Place.
From a five-minute install to eight security modules working around the clock. Here's the full tour.
Up & Running in Minutes
Install WordSec in two ways: straight from the WordPress plugin directory, or by uploading the ZIP file. Either way you're protected in minutes.
From the WordPress Dashboard
- 1
Open Plugins → Add Plugins
In your WordPress admin, go to Plugins and click Add Plugins.
- 2
Search for “WordSec”
Type WordSec into the search box and locate it in the results.
- 3
Install Now
Click Install Now, then click Activate once the button changes.
- 4
Get Key
Open the WordSec menu and click Get Key to activate your license.
Upload the ZIP File
- 1
Open Plugins → Add Plugins
In your WordPress admin, go to Plugins and click Add Plugins.
- 2
Upload Plugin
Click Upload Plugin at the top of the page.
- 3
Select “wordsec.zip” → Install Now
Click Select File, choose wordsec.zip, then click Install Now.
- 4
Activate & Get Key
Activate the plugin, then open WordSec and click Get Key to activate your license.
Eight Modules. One Dashboard.
Every WordSec module lives in your WordPress admin. Features marked Premium are part of the Premium and Business plans.

Firewall
A full WAF in front of your site: inspect every request, write your own rules, and harden WordPress with one-click toggles.
- Detailed firewall logs with full request context
- Custom rules with multi-condition support
- One-click WAF mode: enabled, disabled, or learning
- Block bad bots, AI scrapers & vulnerability scanners
- Blackhole trap for crawlers that ignore the rules
- Block disallowed HTTP methods & sensitive file access
- Role-based REST API access with allowed/blocked namespaces
- Security headers, PHP execution hardening & iFrame protection
- Hide version fingerprints, error messages & REST API links
- 25+ hardening toggles: XML-RPC, user enumeration, directory listing, file editor, hotlinking, forced HTTPS and more

Scanner
Seven scan stages dig through files, the database, and scheduled tasks to surface malware, tampering, and leftovers attackers love.
- 7 scan stages: file integrity, versions, permissions & ownership, backup/log detection, malware, cron tasks, database
- 117 malware detection rulesPremium
- File integrity check: added, deleted & changed files
- Scheduled scans and configurable quick-scan stages
- Remote scan trigger & low resource mode
- Auto fix for common findings
- View flagged file content & check it on VirusTotal
- Quarantine, delete, or restore the original file
- Full scan history

Login Security
Stop credential attacks before they start: captcha, 2FA, brute-force protection, and strict password policies, all role-aware.
- Detailed login attempt logs
- 3 captcha providers (reCAPTCHA, Turnstile, hCaptcha) on 5 forms
- Role-based two-factor authentication with customizable methods
- Hide login URL & login errors
- Brute force protection & honeypot traps
- Whitelisted IPs / CIDR ranges & countries
- Role-based login time restrictions
- Session management: max sessions, idle timeout, remember-me duration
- Strong password enforcement, leaked password check & reuse prevention
- Argon2 password encryption & salt rotation (scheduled or manual)
- Role-based password expiry policy
- Custom login page: logo, background, title & CSS
- Signup restrictions (disposable email)Premium

Live Traffic
Watch hits as they happen and replay past traffic, with safe request/response inspection and precise noise filtering.
- Detailed live view of traffic in real time
- Browse historical traffic streams
- Safe request/response content inspection
- Exclusion filters by role, IP, country, or URI

Blocking
Ban a single IP, a CIDR range, or an entire continent, and let automatic 404/403 and rate-limit protection handle the rest.
- Detailed list of banned IPs/CIDRs with the reason for each
- Block IPs one by one, in bulk, or from an uploaded file
- Country & continent blacklisting or whitelisting
- Automatic 404 and 403 abuse protection
- Rate limiting
- Custom block messages
- IP whitelist support
- Block blacklisted IPs, VPN, proxy & Tor exit IPsPremium

Supply Chain Security
Know what you install before it bites: reputation scoring and risk alerts for every plugin and theme on your site.
- Reputation score: active installs, update recency, WP compatibility, ratings, developer history, vulnerability status
- Vulnerability alerts for installed plugins & themesPremium
- Abandoned & outdated plugin/theme alerts
- Full details: vulnerabilities, version, author, last update, installs, downloads, rating, compatibility requirements

Audit Log
A complete paper trail of who did what and when, across users, content, plugins, themes, and core.
- Detailed tracking of users, events, actions & objects
- 14 tracked actions: login, logout, created, updated, deleted, activated, installed, uploaded, exported, erased and more
- 11 object types: core, options, users, plugins, themes, pages, posts, media, comments, categories, tags

Alarm
Know when something matters: security events across logins, admins, supply chain, and site integrity, delivered to email, Telegram, or Slack.
- 36 event types, each with its own on/off toggle
- 6 event categories: Logins, Admins, Supply Chains, Security, Vulnerabilities, and Monitors
- 3 delivery channels: Email, Telegram, and Slack
- Basic, Advanced, and Full alarm modes to tune signal versus noise
- Vulnerability alertPremium
- Weekly security summaryPremium
- Uptime / downtime monitorBusiness
- SSL certificate monitorBusiness
- Nameserver (NS) changeBusiness
- Server IP (A record) changeBusiness
- MX record changeBusiness
- Domain expiry monitorBusiness
- Blacklist / RBL monitorBusiness
Frequently Asked Questions
Can't find your answer? Contact us and we'll get back to you.