WP Ghost (Hide My WP Ghost) – Security & Firewall
WP Ghost (formerly known as Hide My WP Ghost) is a professional-grade, comprehensive hack-prevention security solution for WordPress. Built for speed and engineered for maximum defense, WP Ghost provides a multi-layered security architecture designed to block hacker bots, neutralize automated scanners, and stop the hack before the reconnaissance even begins. While traditional security tools focus on Detection (scanning for malware after a breach) or Signature-Filtering (blocking known exploits), WP Ghost focuses on Architecture. By implementing Paths Security and Site Hardening, we remove the digital footprints that make your site a target for automated botnets, providing a proactive foundation that secures your site before it can even be identified as a target. WP Ghost Global Stats: 10 Million+ Monthly Brute-Force Attempts Blocked 100 Million+ Monthly Security Threats Prevented Official websites: WP Ghost (wpghost.com) Hide My WP Ghost (hidemywpghost.com) Stop Attacks with Paths Security & Architectural Hardening Most WordPress attacks are automated. Bots scan millions of sites per hour looking for default paths like /wp-admin or /wp-login.php to confirm a site is running WordPress. Once confirmed, they launch targeted exploits against known plugin or theme vulnerabilities. WP Ghost breaks this cycle. By changing and securing common paths, you reduce your attack surface by up to 90%. This isn’t “obscurity”, it’s Site Hardening. We re-engineer the visible structure of your site so it is no longer a low-hanging fruit for global botnets. NEW: AI Security Explanations — Your Report, Explained for Your Website Every security plugin hands you a list of red warnings. Almost none of them tell you what those warnings mean for your website. WP Ghost now does. One click sends your findings for analysis against the way your site is actually configured — your server type, whether your rewrite rules are live, whether your config file is writable, which security mode you run — and returns a security report written for you, not for WordPress in general. Requires a WP Ghost subscription, which includes a monthly allowance of AI checks. Everything else on the Security Check page — the scan, the score, the prioritised list, the severity bands and every task detail — is free and works on its own. What you get back: A plain-language summary of your whole website. One paragraph that finally answers “so, am I actually secure?” A headline you can understand. The technical task name is replaced with what is genuinely at stake. One clear action per finding. Not a description of the problem — an instruction telling you what to do. A security explanation on demand. Open Details on any finding and you get the reasoning: why it matters on your server, what an attacker would do with it, and why it was ranked where it was. This is the part that teaches you WordPress security instead of just flagging it. Priority based on real exposure. Findings are re-ranked using your actual configuration, so the item at the top is the one that genuinely puts you at risk — not the one that scores highest in a generic table. Built with limits you can check. Only your findings and a small description of your setup are ever sent — no page content, no user data, no credentials. Your security list, your score, the severity bands and every task detail are generated locally and keep working whether the AI is available or not. Read more about AI Security Explanations on wpghost.com NEW: Ghost Doctor — Finds and Repairs a Broken Site by Itself Changing your WordPress paths depends on your server honouring the new rules. When it doesn’t — Nginx never reads .htaccess, Apache ignores it without AllowOverride, a host locks the config file — your site can break, and nothing tells you why. Ghost Doctor diagnoses it and repairs what a plugin is allowed to repair. It checks your homepage, theme files, editor requests and REST API the way a visitor sees them, then works through repairs from the safest to the most invasive. Every repair is tested immediately and undone automatically if it did not help, so a run never leaves a setting changed for nothing. Anything that genuinely needs a server change is named plainly, with a guide, instead of leaving you guessing. Read the Ghost Doctor troubleshooting guides Key Protections Included WP Ghost is packed with advanced defensive mechanisms to protect your site against: Brute Force Attacks: Blocks automated password guessing at the source. SQL Injection & XSS: Neutralizes malicious query strings and script injections. Zero-Day Exploits: Secures paths for plugins before patches are even released. XML-RPC & REST API Attacks: Shuts down common remote-access entry points. Bot Reconnaissance: Prevents “fingerprinting” that hackers use to map your site. Spam & Scrapers: Filters malicious traffic, saving bandwidth and server load. Over 115 Free Security Features Included We believe professional security should be accessible to everyone. The free version of WP Ghost includes a massive suite of tools to harden your WordPress architecture. 1. Change and Secure Paths (Paths Security) Change wp-admin & wp-login.php: Move your login to a unique URL and show a 404 error to intruders. Change Lost Password & Register URLs: Secure all authentication entry points. Change wp-content & wp-includes: Secure your core system folders from direct access. Anonymize Plugins & Themes: Change visible plugin/theme paths so hackers can’t identify your software version. Secure admin-ajax.php & REST API: Change the /wp-json path to prevent data scraping. Security Presets: One-click activation with three preset levels — from minimal to full protection with Firewall, Brute Force, Logs, and 2FA. Frontend Test: Verify your site loads correctly after changing paths before confirming settings. Custom Redirects: Set unique login/logout redirects based on user roles. Login Page Designer: Customize your secured login page with your logo, colors, background, and 10 color schemes. 2. Next-Gen Firewall & Authentication 8G & 7G Firewall Filters: High-speed, lightweight server-edge filtering to block bad bots. Passkey Authentication (Passwordless 2FA): Use Face ID, Touch ID, or Windows Hello for un-phishable, device-based logins. Standard 2FA (Code & Email): Add an extra verification layer to all user accounts. Security Headers: Automatically implement CSP, HSTS, X-Frame-Options, and more. IP & User Agent Blocking: Manually blacklist suspicious traffic or referrers. Security Threats Log: Track blocked attacks and malicious requests directly in your dashboard (limited view). User Events Log: Monitor login activity, role changes, and user actions (limited view). GEO Threats Map: Visualize where attacks originate with an interactive world map showing the top 5 threat countries. Security Optimization Score: Real-time 0-100 score showing exactly how hardened your site is, with actionable recommendations. Temporary Logins: Create time-limited access links for developers and clients without sharing passwords. 3. Deep Hiding & Footprint Removal Scrub Meta Tags: Remove WordPress version numbers and generator tags. Clean HTML Comments: Strip identifiable comments that reveal your tech stack. Hide Admin Toolbar: Remove the toolbar for specific roles to hide backend indicators. Disable Emoticons & RSD: Remove unnecessary header links that bloat code and reveal info. 4. Advanced Disable Options Disable XML-RPC: Shut down the most common vector for DDoS and brute force. Disable REST API Access: Restrict API access to authenticated users only. Frontend Lockdown: Disable right-click, “View Source,” and text selection to prevent manual reconnaissance. Disable Directory Browsing: Ensure your server folders are never visible to the public. 5. Brute Force Protection Integrated ReCaptcha: Supports Google V2, V3, Enterprise, and Math ReCaptcha. Targeted Protection: Enable brute force defense on Login, Signup, and WooCommerce pages. Custom Throttling: Define your own lockout times and attempt limits. 6. Extra Tools & Integrations Magic Links: Log in securely without a password via a one-time email link. Text & URL Mapping: Change any class name or URL in your source code dynamically. CDN & Cache Support: Works perfectly with WP Rocket, Cloudflare, and Litespeed. Ghost Doctor: Diagnoses why your paths stopped working and repairs what it can, testing every repair and undoing anything that did not help. Prioritized Security Check: Failing paths and failed hardening tasks arrive as one list, worst first, with bands described in time — “worth fixing this week” — instead of separate tables to reconcile. AI Security Explanations: Get every finding explained for your website and ranked by real exposure. Requires a connected WP Ghost account with an active subscription; a monthly allowance applies. Learn more. Premium Hack-Prevention Features For agencies and high-traffic sites, WP Ghost Premium adds advanced features focused on Security Intelligence, Automated Response, and Copyright Protection. AI Security Explanations: Your findings explained for your own website and re-ranked by what actually exposes you, with a monthly allowance of AI checks included in your subscription. Read more. Ghost Mode: Maximum security preset, changes all paths, hides all file extensions, and enables all hiding options in one click. IP Block Automation: Automatically block IP addresses that trigger repeated security threats. AI Copyright Protection: Block 30+ AI training crawlers (GPTBot, ClaudeBot, PerplexityBot, and others) at the firewall level. List auto-updated with each release. Does not affect Google, Bing, or regular search visibility. Full Security Threats Log: Unlimited entries with filters by threat type, status, country, and time range, full-text search, pagination, and CSV export. Full User Events Log: Unlimited entries with filters, search, pagination, and CSV export. Cloud Event Storage: 30-day cloud retention for audits and incident reports. Real-time Email Alerts: Get notified instantly of brute-force attempts or suspicious activity. Geo-Security (Country Blocking): Block entire countries or specific paths by country. Advanced File Hardening: Hide file extensions (PHP, CSS, JS, JSON), secure wp-config.php, php.ini, and debug.log. Database & Server Hardening: Fix file permissions, change database prefix, regenerate SALT keys. Priority Support: Direct access to our security experts and founder-led assistance. Hide My WP Premium Feature Technical Compatibility WP Ghost is engineered for the modern WordPress ecosystem: Hosting Support: Optimized for WP Engine, Inmotion Hosting, Hostgator Hosting, Godaddy Hosting, Host1plus, Payperhost, Fastcomet, Dreamhost, Bitnami Apache, Bitnami Nginx, Google Cloud Hosting, Amazon AWS Lightsail, Litespeed Hosting, Flywheels Hosting, Kinsta Hosting, Ploi.io, CloudPanel, RunCloud, Rocket Domain, Yunohost. Server Support: Fully compatible with Nginx, Apache, LiteSpeed, and IIS. Plugin Support: Seamless integration with Woocommerce, WPML, WPMUDEV, W3 Total Cache, Gravity, WP Super Cache, WP Fastest Cache, Hummingbird Cache, Cachify Cache, Litespeed Cache, SiteGround Optimizer, Nitropack, Cache Enabler, CDN Enabler, WOT Cache, Autoptimize, Jetpack by WordPress, Contact Form 7, bbPress, Manage WP, All In One SEO, Rank Math, Yoast SEO, Squirrly SEO, WP-Rocket, Minify HTML, Solid Security, Sucuri Security, Really Simple SSL, WordFence Security, WP Cerber Security, BBQ Firewall, Anti-Malware Security, Back-Up WordPress, Elementor Page Builder, Divi Builder, Weglot Translate, AddToAny Share Btn, Limit Login Attempts Reloaded, Loginizer, Shield Security, Asset CleanUp, WP Hide & Security Enhancer, and more. Stop the hack before it starts. Join over 100,000 users who trust WP Ghost to secure their digital presence.
Top keywords
- security37×2.10%
- wp24×1.36%
- ghost21×1.19%
- wp ghost16×0.91%
- paths14×0.79%
- site13×0.74%
- wordpress11×0.62%
- ai9×0.51%
- cache9×0.51%
- change9×0.51%
- hosting8×0.45%
- server8×0.45%
Login Armor
🇫🇷 Fully translated into French. Interface et documentation intégralement disponibles en français. Thirteen security modules. One lightweight plugin. No premium tier. Login Armor protects WordPress login, accounts and administration with thirteen independent modules. It is built for agencies, freelancers and site owners who want practical security, clear evidence and safe defaults without a remote dashboard, bundled telemetry or upsells. Why Login Armor Complete and free: every module is included under the GPL. Lightweight: modules load only when needed and normal login checks add less than 2 ms on a typical setup. Private by default: data stays on your site. Optional external calls are disabled until you enable the related feature. Ready for real sites: multisite support, reverse-proxy controls, WP-CLI commands and production-safe defaults. Thirteen security modules Hide Login: replace wp-login.php with a private slug and return a 404 or redirect blocked visitors to a chosen URL. Brute Force Protection: escalating lockouts, subnet blocking, trusted proxy headers and coverage for login, password recovery, registration, XML-RPC and REST users. Hardening: fifteen controls for XML-RPC, pingbacks, file editing, version exposure, application passwords, author enumeration, reserved usernames, honeypots and new-admin alerts. Two-Factor Authentication: TOTP, email codes, backup codes, trusted devices, per-role enforcement, grace periods and recovery. Detection and Incidents: group raw events into attack patterns with severity, timelines, source IPs, targeted users and one-click actions. Activity Log: tamper-evident admin audit trail with filters, CSV export, retention controls and optional signed SIEM forwarding. Security Headers: CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy and X-Content-Type-Options for login and lockout pages, with optional site-wide baseline headers. Breach Check: privacy-preserving Have I Been Pwned password checks and an optional XposedOrNot email check. Password Policy: length and character rules, username exclusion, breached-password rejection and optional non-locking expiration reminders. Session Management: idle timeout, maximum lifetime, optional single-device access and one-click revocation of other sessions. IP Geolocation: cached country lookup for IPs shown in Incidents and Events, with private ranges excluded. Request Firewall: optional, monitor-first filtering of malicious paths, query strings and HTTP methods, with administrator exclusions and IP/path allowlists. Bot Challenge: an invisible proof-of-work the browser solves before the login form is accepted, an alternative to CAPTCHAs with no external service; monitor-first, then enforce. Additional tools Login Armor also includes guided onboarding, a 0-100 security score, conflict detection, email/Slack/Discord/webhook notifications, a dashboard widget and a complete WP-CLI suite. The optional AI Security Briefing uses your own WordPress AI connector to explain a thirty-day security snapshot or a single incident. It always starts with deterministic facts, works without AI and sends nothing until an administrator explicitly requests an analysis. GPL forever. PHP 8.1+. WordPress 6.8+. Zero dependencies. Treize modules de sécurité. Une seule extension légère. Aucune version premium. Login Armor protège la connexion, les comptes et l’administration de WordPress grâce à treize modules indépendants. L’extension s’adresse aux agences, freelances et propriétaires de sites qui veulent une sécurité concrète, des preuves lisibles et des réglages sûrs, sans tableau de bord distant, télémétrie imposée ni upsell. Pourquoi Login Armor Complet et gratuit : tous les modules sont inclus sous licence GPL. Léger : les modules se chargent uniquement lorsque nécessaire et les contrôles ajoutent moins de 2 ms sur une connexion normale. Privé par défaut : les données restent sur votre site. Les appels externes optionnels sont désactivés tant que vous n’activez pas la fonction concernée. Prêt pour la production : multisite, reverse proxies, commandes WP-CLI et réglages par défaut sécurisés. Treize modules de sécurité Masquer la connexion : remplace wp-login.php par un slug privé et renvoie une 404 ou redirige les visiteurs bloqués vers l’URL choisie. Protection contre la force brute : verrouillages progressifs, blocage de sous-réseaux, proxies de confiance et protection de la connexion, récupération, inscription, XML-RPC et REST users. Renforcement : quinze contrôles pour XML-RPC, les pingbacks, l’éditeur de fichiers, la version, les mots de passe applicatifs, l’énumération d’auteurs, les identifiants réservés, le pot de miel et les alertes nouvel administrateur. Authentification à deux facteurs : TOTP, codes par e-mail, codes de secours, appareils de confiance, application par rôle, période de grâce et récupération. Détection et incidents : regroupe les événements en scénarios d’attaque avec sévérité, chronologie, IP sources, comptes ciblés et actions immédiates. Journal d’activité : piste d’audit admin infalsifiable avec filtres, export CSV, rétention et transfert SIEM signé optionnel. En-têtes de sécurité : CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy et X-Content-Type-Options pour les pages de connexion et de verrouillage, avec en-têtes de base optionnels sur tout le site. Détection de fuites : vérification confidentielle des mots de passe via Have I Been Pwned et contrôle optionnel des e-mails via XposedOrNot. Politique de mot de passe : longueur, classes de caractères, exclusion de l’identifiant, rejet des mots de passe compromis et rappels d’expiration non bloquants. Gestion des sessions : délai d’inactivité, durée maximale, accès limité à un appareil et révocation des autres sessions. Géolocalisation IP : pays des IP affichées dans Incidents et Événements, avec cache et exclusion des plages privées. Pare-feu de requêtes : filtrage optionnel, d’abord en surveillance, des chemins, requêtes et méthodes HTTP malveillants, avec exclusion des administrateurs et listes d’autorisation IP/chemins. Défi anti-bot : une preuve de calcul invisible résolue par le navigateur avant validation du formulaire de connexion, alternative aux CAPTCHA sans service externe ; d’abord en surveillance, puis en blocage. Outils complémentaires Login Armor inclut aussi un assistant de configuration, un score de sécurité de 0 à 100, la détection de conflits, les notifications par e-mail, Slack, Discord ou webhook, un widget de tableau de bord et une suite WP-CLI complète. Le briefing de sécurité IA optionnel utilise votre propre connecteur IA WordPress pour expliquer les trente derniers jours ou un incident précis. Il commence toujours par des faits déterministes, fonctionne sans IA et n’envoie rien tant qu’un administrateur ne demande pas explicitement une analyse. Conçu par Login Armor est conçu et maintenu par Fabrice Ducarme de WPFormation. Nous l’utilisons sur chaque site que nous livrons. Présentation et fonctionnement de Login Armor Guides de sécurité WordPress sur WPFormation Veille des vulnérabilités WordPress sur WPFormation GPL pour toujours. PHP 8.1+. WordPress 6.8+. Zéro dépendance. External Services Login Armor has no telemetry and requires no Login Armor account. The following services are contacted only when WordPress itself or an administrator enables the related feature. WordPress AI connector (optional) The AI Security Briefing sends a security prompt through the administrator’s own WordPress AI connector only after they click an analysis button. Minimised mode sends counts, categories, severities and role buckets without clear IP addresses or usernames. Explicit deep mode also sends IP addresses and event details. Login Armor stores no provider API key. The selected AI provider’s terms and privacy policy apply. Slack, Discord or custom webhook (optional) When an administrator enables an incident notification channel, Login Armor sends the incident type, severity, IP address, target username, event count and site URL to the configured endpoint. The separate signed Activity Log forwarding option sends the event, object, user ID/login/role, IP address, description, integrity hashes, site URL and plugin version to the administrator’s SIEM or custom webhook. Slack: Terms | Privacy Discord: Terms | Privacy Custom webhook: terms and privacy are controlled by the administrator’s chosen endpoint. Gravatar The Activity Log uses WordPress core’s get_avatar(). If avatars are enabled in WordPress, a hashed email address may be sent to Gravatar to retrieve the image. Gravatar: Terms | Privacy Have I Been Pwned (optional) Breach Check and the optional compromised-password policy send only the first 5 characters of a password’s SHA-1 hash to the Pwned Passwords API. The password and full hash never leave the site. Checks fail soft if the service is unavailable. Public registration and password-reset validation do not call the service; authenticated checks remain active. Have I Been Pwned: Privacy | Acceptable Use XposedOrNot (optional) The separate Email check, disabled by default, sends the user’s email address and a plugin-identifying User-Agent to XposedOrNot when a user is created or changes email. XposedOrNot: Service | Privacy ipwho.is (optional) IP Geolocation sends a displayed public IP address to ipwho.is when an administrator opens Incidents or Events. Results are cached for 30 days. Private and reserved ranges are never sent, and developers can replace the lookup through the login_armor_geoip_lookup filter. ipwho.is: Service | Documentation