Kadence Security – Password, Two Factor Authentication, and Brute Force Protection
Reduce your WordPress website’s risk to nearly zero with Kadence Security Formerly iThemes Security. Looking for iThemes? Learn more here. On average, 30,000 websites are hacked every day.* Cyberattacks in the US increased by 57% in 2022.** Bad actors who want to hack your site, steal your data, and cripple your business are a 24/7/365 threat. You need a proactive, strategic approach to WordPress website security that protects your site from brute force attacks, malware infections, and other cyber threats. Kadence Security shields your site from cyberattacks and prevents security vulnerabilities. It automatically locks out bad users identified by our Brute Force Protection Network that is nearly 1 million sites strong and leverages your own blacklist. It secures and protects your most commonly attacked part of your WordPress website – user login authentication. With Patchstack integration (Pro) protects your site before you even have a chance to address vulnerabilities and before a plugin or theme vendor or developer can even issue a patch. That’s 24/7/365 always-on truly Kadence Security. 🌐 Secure your Website in Minutes The Kadence Security setup and onboarding experience allows anyone to secure their WordPress website in under 10 minutes, regardless of technical acumen. Knowing that you have enabled all the right security settings for your website will leave you feeling like your site has never been more secure. 📚 Security Site Templates to Fit Your Type of Site Enabling the correct security settings based on the type of website you are building or maintaining is essential for proper security. An eCommerce site requires a different level of security than a basic blog. Kadence Security Site Templates make it quick and easy to apply the right security settings for your website. Choose from six different site templates to apply the type of security your site needs: Ecommerce – websites that sell products or services Network – websites that connect people or communities Non-Profit – websites that promote your cause and collect donations Blog – websites that share your thoughts or start a conversation Portfolio – websites that showcase your craft Brochure – simple websites that promote your business ⌚ Real-Time Website Security Dashboard Every day, lots of activity is happening on your website that you can’t see. Many of these activities can be related to your site’s security, so monitoring these events is vital to keeping your site secure. The Kadence Security Pro plugin provides a real-time WordPress security dashboard that monitors security-related events on your site around the clock. The Kadence Security Dashboard is a dynamic dashboard with all your WordPress website’s security activity stats in one place, including brute force attacks, banned users, active lockouts, site scan results, and user security stats (Pro). 🗝️ WordPress Login Security Setting up and maintaining proper WordPress configurations and managing user account access are essential aspects of hardening your site against threats and vulnerabilities. Basic and Pro include features that address both of these factors. Two Factor Authentication (2FA) – Make your WordPress login nearly impenetrable to attack by requiring users to enter a security code along with a password to login. The Kadence Security plugin allows you to add two-factor authentication to your WordPress login with several authentication methods, including mobile apps like Authy and Google Authenticator, email, and backup codes. Password Requirements – Create and enforce a password policy for your users in less than a minute. reCAPTCHA (Pro) – Stop bad bots from engaging in abusive activities on your website, such as attempting to break into your website using compromised passwords, posting spam, or even scraping your content. Passwordless Logins (Pro) – WordPress security made easy. Secure your user accounts with 2fa & strong passwords while allowing real users login with a click of a mouse. Trusted Devices (Pro) – Identify the devices you and other users use to block session hijacking attacks and limit Administrator privileges to Trusted Devices. Automated Vulnerability Patching (Pro) – Kadence Security Pro includes Patchstack which patches vulnerabilities before you have a chance to and applies fixes even before a plugin developer or vendor has issued a patch. Learn more about how passwordless login is the future and how Kadence Security can help you implement it today. 👨👩👧👦 The Right Amount of Security for Every User Level Different types of user levels require different levels of security. During the Kadence Security setup process, you can identify your website’s key user groups. Once the different types of users are identified, you can apply the level of security that is just right for each user group. Here are a couple of examples of how User Groups are useful for securing your site: For Clients – Let’s say you are configuring Kadence Security on a client’s website. You will decide whether or not they are required to use two-factor authentication and if they should have access to the Kadence Security settings. For Customers – If you have an eCommerce website, you will decide whether or not you want to protect customer accounts with a password policy. Privilege Escalation (Pro) also adds a safe, secure way to grant temporary admin-level access to your website. 🤖 Block Bad Bots & Ban User Agents with Lockouts Ban Users (Basic and Pro) – Permanently block repeat offenders from accessing your site. Local Brute Force Protection – Automatically identify and stop the most common method of attack on WordPress sites. Local Brute Force Protection (Basic and Pro) – Automatically identify and stop the most common method of attack on WordPress sites. Network Brute Force Protection (Basic and Pro) – The network is the Kadence Security community and is nearly one million websites strong. If someone tries to break into websites in the Kadence Security community, Kadence Security will block them across the network. Magic Links (Pro) – Security shouldn’t get in your way. Magic Links allow you to log in to your WordPress site while your username is locked out by the Kadence Security Local Brute Force Protection feature. 🔍 Monitor Your Site’s Security Health File Change Detection (Basic and Pro) – Kadence Security logs changes made to your website that can help detect malicious activity on your website. Site Scanner (Basic and Pro) – Schedule checks to run four times per day (Basic) or hourly (Pro) for known vulnerabilities of WordPress core file, plugins and themes. Using the Google Safe Browsing API, the Site Scan also checks your Google’s blocklist status and will alert you if Google has found any malware on your website. Patchstack integration (Pro) – Automated virtual patching of some vulnerabilities before you even have a chance to address them yourself, and before a plugin or theme vendor or developer can even issue a patch. Site Scanner (Pro) – Unlock Version Management to automatically apply a patch to vulnerable software detected by the Site Scan when one is available. User Logging (Pro) – Keep a record of user activity in your WordPress security logs, including login/logout, user registration, adding/removing plugins, switching themes, changes to posts and pages, and more. Version Management (Pro) – The Version Management feature in Kadence Security Pro allows you to auto-update WordPress, plugins, and themes. Beyond that, Version Management also has options to harden your website when you are running outdated software and scan for old websites. 🧠 Smarter, More Actionable Vulnerability Prioritization Not all vulnerabilities pose the same level of risk, and the traditional Common Vulnerability Scoring System (CVSS) score doesn’t always reflect the realities of running a WordPress site. Kadence Security now uses the Patchstack Priority score, which goes beyond CVSS to provide a real-world risk assessment tailored to WordPress. It factors in how likely a vulnerability is to be exploited and its actual impact on your site. With Patchstack Priority, you get a clearer picture of what really matters, helping you focus on the vulnerabilities that pose the greatest risk, and worry less about noise from low-impact issues. 🛠️ Website Security Utilities Enforce SSL – Force all connections to the website to be made over SSL/TLS. Database Backups – Create backups of your WordPress database. (Not a complete backup.) Geolocation (Pro) – Improve Trusted Devices by connecting to an external location or mapping API. 🚀 Advanced Security Tools Identify Server IPs – Prevent issues caused by inadvertently locking out your server IPs. Change User ID 1 – Change the user ID for the first WordPress user, potentially preventing attacks that assume the user with ID1 exists and is an administrator. Change Database Prefix – Change the database prefix that WordPress uses, potentially preventing attacks that assume the database prefix is “wp_”. Check File Permission – See the file and directory permissions of key areas of your site. Server Config Rules – View or flush the server security rules generated by Kadence Security. wp-config.php Rules – View or flush the wp-config.php security rules generated by Kadence Security. Change WordPress Salts – Secure your site after a successful attack by changing the WordPress salts used to secure cookies and security tokens. Hide Login URL – change the login URL of your site, making it harder for bots to find your login page and attack it. 🛟 Need Help? Free support may be available with the community’s help in the WordPress.org support forums. Our Kadence Security support team provides top-notch technical support to all our Kadence Security Basic users there. Our Help Center will help you become an iThemes Security expert. Get additional peace of mind with professional support from our expert team and pro features to take your site’s security to the next level with Kadence Security Pro. Recover From a Hacked Site Kadence Security makes regular backups of your WordPress database, allowing you to get back online quickly in the event of a hack or security breach. Use Kadence Security to create and email database backups on a customizable schedule. For complete site backups and the ability to restore or move WordPress to a new host or domain, check out Solid Backups. Solid Central Integration Manage more than one WordPress site? Release lockouts and keep your themes, plugins, and WordPress core up to date from one dashboard with Solid Central. *Zippia. “30 Crucial Cybersecurity Statistics [2023]: Data, Trends And More” Zippia.com. Jun. 15, 2023, https://www.zippia.com/advice/cybersecurity-statistics/ **https://blog.checkpoint.com/2023/01/05/38-increase-in-2022-global-cyberattacks/ License Released under the terms of the GNU General Public License.
Top keywords
- security59×3.48%
- site33×1.95%
- wordpress29×1.71%
- kadence27×1.59%
- kadence security27×1.59%
- pro25×1.47%
- website23×1.36%
- user17×1.00%
- login11×0.65%
- websites10×0.59%
- basic9×0.53%
- users9×0.53%
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit
Most WordPress sites run 20–40 plugins. That means 20–40 things that slow your site, conflict with each other, and need updating every week. Nexter Extension fixes that. One plugin. 50+ features. Every module is toggle on/off — nothing loads unless you need it. Pure Vanilla JS, zero jQuery. It’s the one WordPress plugin that handles your SEO, security, performance, email delivery, theme design, code management, and admin cleanup — all in one place, completely free to start. 👉 Website | All Features | Nexter SEO | Free vs Pro | Pricing | Docs | Roadmap | Support | Premium Support | AI Chat 🔍 Nexter SEO — Built-In WordPress SEO, Schema & AI Search Handle your on-page SEO, schema, XML sitemaps, redirects, and AI search from one plugin. Nexter SEO is a complete, lightweight WordPress SEO toolkit built into Nexter Extension — drop your standalone SEO plugin, with no extra page weight and no plugin conflicts. 100% free. SEO Site Audit — Scan your site for on-page and technical issues, with a 0-100 health score and a prioritized list of top fixes. Meta Title & Description Templates — Set site-wide title and meta description templates with dynamic variables and a live Google search preview. Social / Open Graph — Control how your pages look when shared, with a default share image and Facebook and X (Twitter) cards. Schema Builder — Add 18 structured-data types (Article, Product, FAQ Page, How-To, Local Business, Event, Recipe, Video, and more) with dynamic variables and display conditions. No code. XML Sitemaps — Generate XML sitemaps, plus optional image, video, news, and HTML sitemaps, with exclude lists. Robots & Robots.txt Editor — Set per-type index, follow, and archive rules and edit your virtual robots.txt right from the dashboard. Instant Indexing (IndexNow) — Push new and updated URLs to search engines that support IndexNow instantly, automatically or in bulk. LLMs.txt for AI Search — Generate an LLMs.txt file so AI engines like ChatGPT, Perplexity, and Google AI can find and cite your content. Site Verification — Verify your site with Google, Bing, Pinterest, and Facebook in one place. Redirects & 404 Monitor — Create 301, 302, and other redirects with flexible matching, and log broken URLs to fix. Image SEO — Add automatic alt text from the filename or title (no AI needed) and redirect attachment pages to their parent post. Import / Export — Move your entire SEO configuration between sites with a single JSON file. 🏗️ Theme Builder — Free for Elementor & Gutenberg Build custom headers, footers, 404 pages, single post templates, and archive pages using Elementor widgets or Gutenberg blocks — completely free, no premium page builder needed. Works with Astra, Hello Elementor, GeneratePress, Kadence, Blocksy, OceanWP, Neve, and Bricks Builder. Header Builder — Design sticky, transparent, or conditional headers with full page builder control. No coding. Footer Builder — Build any footer layout — multi-column, widgets, blocks — no template limits. Breadcrumbs Bar — SEO-structured breadcrumb navigation with full design control. 404 Page Builder — Custom-designed 404 pages that keep visitors on your site instead of bouncing. Single Post & Archive Templates — Unique layouts per post type, category, tag, or custom post type. Display Conditions — Show/hide templates by page, user role, device, login status, and 50+ more conditions (Pro). 💻 Code Snippets — PHP, CSS, JS & HTML Manager Add custom PHP, CSS, JavaScript, and HTML to WordPress without touching functions.php or creating a child theme. All snippets run as static files — zero extra database queries, faster than other WordPress code snippets plugins. PHP, HTML, CSS & JS Snippets — Manage all four code types with live syntax validation. Auto crash-protection stops bad code from breaking your site. File-Based Execution — Snippets compile to static files, not database queries — a speed advantage over traditional code manager plugins. 22+ Conditional Load Rules — Load code only on specific pages, post types, user roles, devices, WooCommerce pages, EDD, or MemberPress. Scheduling (Pro) — Set start/end dates for any snippet. Perfect for seasonal banners and timed scripts. Smart Placement (Pro) — Inject code before/after specific HTML elements, after X words, at a content percentage, or via shortcode. Import / Export & Tagging — Move snippets between sites in one click. Tag and annotate your whole snippet library. 🖼️ Image Optimizer — WebP, AVIF & Bulk Compress A fully built-in wordpress image optimizer — convert, compress, and bulk-optimize images without any API key, external account, or monthly subscription. Everything runs on your own server. WebP Conversion — Auto-convert JPG/PNG uploads to WebP. Up to 35% smaller files, zero quality loss. AVIF Support — Next-gen format, up to 50% smaller than JPEG. Built-in AVIF conversion at no extra cost. Bulk Image Compression — Compress your entire media library in one go. No image-by-image processing. Auto Resize on Upload — Automatically shrink oversized images on upload and delete the original to save disk space. No API Key. No Account. No Monthly Fee. — Enable the module, and it just works. ⚡ WordPress Performance & Page Speed Optimization Granular WordPress speed optimization toggles — disable only what your site doesn’t need. No all-or-nothing switches that break things. Disable Bloat Scripts — Individual toggles for Emoji scripts, Embeds, Dashicons, Pingbacks, Feed Links, Shortlink tag, and more — each one separate. Defer CSS & JS — Defer non-critical stylesheets and scripts to improve First Contentful Paint and page load scores. Self-Host Google Fonts — Host Google Fonts on your own server. Eliminates the external Google request and makes your site GDPR-compliant. Heartbeat Control — Throttle or disable the WordPress Heartbeat API — a common cause of high CPU on shared hosting. Revision Control — Cap post revisions to prevent database bloat on content-heavy sites. Disable Comments — Turn off WordPress comments site-wide or per post type. Removes all comment scripts from page output. Disable Unused Image Sizes & Elementor Icons — Stop generating thumbnails and loading Font Awesome on pages that don’t use them. 🔒 WordPress Security Plugin — Hardening, Login Protection & More A layered WordPress security plugin with individual on/off toggles. Covers the most-used hardening and login protection features without adding a heavy security daemon to every page load. Security Hardening — Disable XML-RPC, hide WP version, remove REST API head links, block file editor, add XSS headers, and more — each as a separate toggle. Limit Login Attempts (Freemium) — Block brute-force attacks by locking out IPs after failed logins. No separate brute force protection plugin needed. CAPTCHA Spam Protection — Add Google reCAPTCHA v2/v3 or Cloudflare Turnstile to login, registration, comments, password reset, and WooCommerce checkout. Two-Factor Authentication (2FA) (Pro) — Email-based two-step verification with role-based enforcement. Replaces standalone two factor authentication plugins. Change WP Admin Login URL — Move your login page from the default wp-login.php to a custom URL. Stops automated bot scanning cold. Login Email Notifications (Pro) — Get alerted by email on every login with role-based filters and custom email content. Content Protection (Pro) — Disable right-click, text selection, image drag, copy-paste, and developer console access. SVG Upload — Let trusted roles upload SVG files with automatic sanitization. Clean icon uploads, no malicious payload risk. Last Login & Registration Tracking — See the last login date and registration date of every user right in the Users table. 📧 WordPress SMTP Email Fix WordPress emails going to spam in minutes. The built-in WordPress smtp plugin routes your contact forms, order notifications, and password resets through a real mail provider — so they actually arrive. Gmail SMTP — Connect Google Workspace or Gmail via OAuth or App Password. Mailgun, SendGrid & Custom SMTP — Works with any provider: Brevo, Amazon SES, Postmark, Mailchimp Mandrill, or your host’s SMTP. Test Email Tool — Send a test email from inside the settings panel to confirm delivery before you go live. 🔧 WordPress Utilities — Replace a Dozen Single-Use Plugins Custom Font Uploads — Upload TTF, WOFF, WOFF2 and variable fonts. Apply in any page builder without a separate WordPress custom fonts plugin. Adobe Fonts Integration — Connect your Adobe Creative Cloud via Project ID and load any Typekit font in WordPress. Redirect 404 (Freemium) — Auto-redirect all broken 404 pages to your homepage (Free) or any custom URL (Pro). Post & Page Duplication — Clone any post or page with full layout and metadata preserved. No separate post duplicator plugin needed. Bulk Text & URL Replacement — Find and replace any string across your entire database in one click. Essential after domain migrations. Thumbnail Regeneration — Regenerate all image thumbnails after changing image sizes. No extra plugin. Rollback Manager — Downgrade any plugin to a previous version instantly if a new update causes conflicts. Admin Role Switcher — Switch between any WordPress user role without logging out. Perfect for testing permissions. Disable Gutenberg — Restore Classic Editor on specific post types without an extra plugin. WP Debug Mode — Toggle WP_DEBUG on/off from your dashboard. No wp-config.php editing. Content Post Order — Drag-and-drop reorder posts and pages. No code, no custom fields. Public Preview for Drafts (Pro) — Share a preview link for any unpublished post without requiring a login. Replace Media (Pro) — Swap any file without changing its URL or breaking existing links. Taxonomy Term Order (Pro) — Drag-and-drop reorder categories, tags, and custom taxonomies on the frontend. 🎨 WordPress Admin Customization & Dashboard Cleanup Branded Admin Interface / White Label WordPress (Pro) — Replace the WordPress login page with your agency logo and colors. Full white-label WordPress admin for client sites. Admin Menu Organizer (Pro) — Reorder, rename, or hide sidebar menu items per user role. Show clients only what they need. Elementor Ad-Free — Hide all Elementor upgrade banners, AI popups, and upsell buttons from the editor. Clean workspace, focused editing. Clean Admin Bar — Remove any item from the WordPress toolbar: WP logo, site name, comments counter, Howdy greeting, plugin nodes, and more — each as a separate toggle. Disable Admin Notices & Dashboard Widgets — Hide update nags, plugin notices, At a Glance, Quick Draft, WooCommerce setup panel, and the WordPress Events feed — individually. Wider Admin Menu — Expand the sidebar so long menu labels display fully without truncation. Display Active Plugins First (Pro) — Pin active plugins to the top of the plugins list for faster access. User Profile Clean (Pro) — Remove unnecessary fields from user profiles for a cleaner client-facing backend. 🔁 Import / Export Settings Export your full WordPress Customizer configuration and all Nexter Extension settings to a file — then import on any site instantly. Zero re-configuration for agencies managing multiple client sites. ⚡ Upgrade to Nexter Extension Pro → 🏆 Our Other WordPress Products The Plus Addons for Elementor — 120+ Elementor widgets. Pairs perfectly with Nexter Extension’s free Theme Builder. Nexter Blocks — 90+ Gutenberg blocks. Zero jQuery. Built for speed. NexterWP Theme — Lightest, fastest starter theme for Elementor and Gutenberg. No jQuery. UiChemy – Figma to WordPress — Convert Figma designs into live Elementor pages with a free Figma plugin. WDesignKit — 1000+ WordPress templates, widget builder, block converter, and cloud storage. External services Nexter Extension may connect to external services below only when the related feature is enabled: api.posimyth.com — usage analytics. Off by default; submitting the deactivation feedback form also sends it, plus your admin email if you tick the contact box. Terms · Privacy · what’s shared store.posimyth.com — Pro licence, template library, newsletter opt-in. Terms · Privacy api.wdesignkit.com, etemplates.wdesignkit.com — templates and preview images. Terms · Privacy api.indexnow.org — sends a post URL when you save it, to notify search engines. Terms api.openai.com — AI content, using your own API key. Terms · Privacy generativelanguage.googleapis.com — AI content, using your own API key. Terms · Privacy fonts.googleapis.com, fonts.gstatic.com, google.com/recaptcha, accounts.google.com, oauth2.googleapis.com — self-hosted fonts, CAPTCHA, SMTP OAuth. Terms · Privacy typekit.com, use.typekit.net — Adobe Fonts, using your own project ID. Terms · Privacy challenges.cloudflare.com — Turnstile CAPTCHA, using your own site key. Terms · Privacy api.wordpress.org, themes.svn.wordpress.org — Rollback Manager lookups and downloads. Privacy