WordSec is a complete WordPress security plugin. Eight modules cover the firewall, malware scanner, login security, live traffic, IP and country blocking, supply-chain intelligence, audit log and alerts, so you block attacks and harden your site from one dashboard instead of installing eight plugins.
If your site gets hacked you do not just lose the site. You lose customer trust, your search rankings, and days of work restoring backups. WordSec is built to stop that before it happens, and to help you recover if it already has: the scanner finds the malware, quarantine takes it out of the way, and modified core, plugin and theme files are repaired from their original copies.
Free, and no license key to enter. WAF firewall rules, malware and file-integrity scanning, brute force protection, two factor authentication, IP and country blocking, the audit log and one-click hardening all run locally on your own server.
Web Application Firewall (WAF)
Custom rule builder with regex and wildcard matching
Built-in rules for SQL injection, XSS, path traversal, PHP and command injection
Learning and active modes, bot blocking, security headers, rate limiting
25+ hardening toggles for wp-config access, author enumeration and REST API
Optional Extended Protection: pre-WordPress request inspection (opt-in, fully reversible)
Malware Scanner and Removal
Malware detection rules across files, the database and scheduled tasks
Core, plugin and theme file-integrity verification via the WordPress.org API
Scheduled scans, one-click quarantine and restore
Malware removal on a hacked site: quarantine a finding, or repair a modified core, plugin or theme file from its original copy
Login Security, Two-Factor Authentication (2FA) and Brute Force Protection
Role-based two-factor authentication (RFC 6238 TOTP)
reCAPTCHA, hCaptcha and Cloudflare Turnstile, plus a built-in math CAPTCHA
Brute-force protection with progressive lockout, honeypot and login URL rename
Leaked-password checking, session management, custom login page
Live Traffic
Real-time request logging with bot detection and CSV export
Exclusion filtering by role, IP, country or URI
IP and Country Blocking
Country and continent allow or block lists
IP and CIDR blocking, temporary or permanent, with allow-list support
Supply Chain and Threat Intelligence
Reputation scoring and abandoned-plugin detection
Known-vulnerability alerts for core, plugins, themes and PHP
Update-integrity verification with backups and an SBOM inventory
Audit Log
Activity tracking across 11 object types and 14 actions
Alarms
36 alert event types delivered by Email, Telegram or Slack