Security Plugin, Firewall & Malware Scanner with Auto Removal
Brute force, Login security & Two Factor Auth (2FA). Limit login. Malware & Vulnerabilities scan. FireWall. Enterprise ready security plugin. SECURITY PLUGIN BY CLEANTALK (SPBCT) We focus on eliminating the most common security threats for WordPress. At the same time, we strive to ensure that site performance remains unaffected. To achieve this, each release goes through automated and expert-driven testing pipelines. We also verify performance using Google PageSpeed Insights and GTMetrix. Typically, we release a new version twice a month to keep features up to date and protection strong. SECURITY FEATURES Limit Login Attempts and rate limits for logins. Two Factor Authentication (2FA) Custom wp-login URL (wp-login.php) Hide Login Default Login Page Disable or Stop User Enumeration Brute force protection for WordPress accounts and passwords Security Protection for WordPress login form Security FireWall by IP, Networks, or Countries Web Application Firewall (WAF) Real-time traffic monitor (Visitors per pages, IPs, Countires and hits counts per page) Malware scanner with auto-cure function Daily auto malware scan Vulnerabilities scanner among installed plugins and themes Security weekly reports to email Notifications of login events to your website FREE TRIAL THEN $9 PER YEAR CleanTalk is a Cloud security service that protects your website from online threats and provides you great security instruments to control your website security. We provide detailed security stats for all of our security features to have a full control of security. We believe the most honest approach is when every user pays a small fee for using the service, rather than relying on a freemium model where some users subsidize others. The fee is as low as price of a good cup of coffee! So, the security plugin does not have a PRO version-it is completely free and works in combination with our premium Cloud security service at cleantalk.org. Every user has full access to all features of both the service and the plugin. Also, please take a note about WordPress.org policy BRUTE FORCE PROTECTION Our default anti–brute-force policy works as follows, For any failed login attempt to the WordPress admin area, the plugin introduces a brief delay of a few seconds. The plugin reviews the security audit log every hour. If any IP address records 10 or more login attempts in that period, it will be blocked for 24 hours. ALL BRUTE FORCE PROTECTION FUNCTIONS Maximum failed attemtps to login before ban (default is 5). A failed attempt happens when either the login or password is incorrect. Time frame to count login attempts (default is 15 minutes). Ban to login time frame from 2 minutes to 24 hours (default is 1 hour). Two-factor authentication (2FA) with abillity to apply policy to specific users roles. Prevent collecting of login on password reset error. The option exclude the info about the login existing on password change error. Error message will be replaced with followed text: “If the user with the specified credentials exists, check your email for the password reset confirmation link. Then visit login page.” Security Audit Log. Keeps track of actions in the WP Dashboard to let you know what is happening on your blog. With the Security Audit Log is very easy to see user activity in order to understand what changes have done and who made them. Security Audit Log shows who logged in and when and how much time they spent on each page. Two Factor Authentication (2FA). It requires a bit of your time but Two Factor (2 Step) Authentication immediately gives a much higher level of security.With your first authorization, the CleanTalk Security plugin remembers your browser and you won’t have to input your authorization code every time anymore. However, if you started to use a new device or a new browser then you are required to input your security authorization code. CleanTalk security plugin will remember your browser for 30 days. Change the URL of the wp-login page. This option helps you change the default wp-login URL (wp-login.php). Hackers use scripts for massive brute-force attacks, and since most sites use a default login page URL, hackers configure scripts for such URLs. When you change the URL of the authorization page, hackers will not have the opportunity to perform brute-force attacks in scripts in automatic mode. This option does not change files and does not rewrite URLs in system files. To return the address of the default authorization page, it is enough to disable the option in the plugin settings or set a new value. If you are using caching plugins, then you need to add a new authorization page in the caching exceptions. Leaked password check. This feature enhances your website’s security by continuously monitoring users’ passwords for potential exposure in known data breaches and on the dark web. It works in the background and requires no action from users unless a leak is detected. SECURITY FIREWALL To enhance the security of your site, you can use the CleanTalk Security FireWall, which will allow you to block access by HTTP/HTTPS to your website for individual IP addresses, IP networks and block access to users from specific countries. Use personal BlackList to block IP addresses with a suspicious activity to enhance the WordPress security. Security FireWall may significantly reduce the risk of hacking and reduces the load on your web server. CleanTalk Security is fully compatible with the most popular VPN services. Also, CleanTalk security supports all search engines Google, Bing, Yahoo, Baidu, MSN, Yandex, and etc. LIST OF FIREWALL FUNCTIONS Blocks or bypass visitors by IP, IP Network. Country blocking. It also has option to avoid blocking hits from major search engines like Google, Bing, Yahoo, Baidu, Yandex, and etc. Traffic control. CleanTalk security Traffic Control will track every single visitor no matter if they are using JavaScript or not and provides many valuable traffic parameters. Another option in Security Traffic Control – “Block user after requests amounts more than” – blocks access to the site for any IP that has exceeded the number of HTTP requests per hour. If this number of requests will be exceeded, this IP will be added to the Security FireWall Black List for 24 hours. Security Firewall has a limit for requests to your website (by default 1000 requests per hour, so you can change it) and if any IP exceed this threshold it will be added to security firewall for next 24 hours. It allows you to break some of the DDoS attacks. Limit Login Attempts. Limit Login Attempts – is a part of brute-force protection and security firewall. Web Application FireWall (WAF) for WordPress Security Plugin. The main purpose of Web Application FireWall (WAF) is real-time protection from unauthorized access, even if there are critical known/unknown vulnerabilities. Security Web Application FireWall catches all requests to your website and checks HTTP parameters that include, SQL Injection, Cross Site Scripting (XSS), uploading files from non-authorised users, PHP constructions/code, the presence of malicious code in the downloaded files. In addition to effective information security and information security applications are required to know what is quality of protection and CleanTalk Security has logged all blocked requests that allow you to know and analyze accurate information. You can see your Cleantalk Security Logs in your Dashboard CleanTalk’s research team updates WAF database each time as we find a vulnerability, it means plugin’s users get protection even against unpublished vulnurebilites. Learn more how to set up and test About Security Web Application Firewall Email Notifications when administrators or users are logged in. We added this option to our security plugin. Now you can receive notifications if you want to know about an unauthorized entrance to your WP Dashboard. Notification will be sent only when a user was able to authorize entering login and password. If you are logged into the admin panel from the saved session, then the alert won’t be sent. MALWARE SCANNER WITH AUTO-CURE FUNCTION Scans WordPress files for hacker files or code for hacker code. Performs antivirus functions. Security Malware Scanner runs manually by users requests or automaticaly by WordPress cron. All of the results will send in your Security CleanTalk Dashboard with the details and you will be able to investigate them and see if that was a legitimate change or some bad code was injected. If you are unsure how to identify, remove, or clean malware using the plugin, you can book a malware removal service with our Security & Pentest team. As an alternative, you can use the Website Malware Scanner for frontend security and malware checks. It scans by URL and requires no plugins. LIST OF MALWARE SCANNER, ANTIVIRUS FUNCTIONS Malware autoscanning. Scans the website automatically at intervals ranging from once every 12 hours to once every 30 days. Cure malware. It cures infected files automatically if the scanner knows cure methods for these specific cases. If the option is disabled then when the scanning process ends you will be presented with several actions you can do to the found files, Cure. Malicious code will be removed from the file. Replace. The file will be replaced with the original file. Delete. The file will be put in quarantine. Do nothing. Before any action is chosen, backups of the files will be created and if the cure is unsuccessful it’s possible to restore each file. Security Malware Heuristic Check. This option allows you to check files of plugins and themes with heuristic analysis. Probably it will find more than you expect. Security Malware scanner to find SQL Injections. The CleanTalk Security Malware Scanner allows you to find code that allows performing SQL injection. It is this problem that the scanner solves. Operating system cron tasks analysis. This functional provides an overview of scheduled cron jobs on server that perform automated tasks. DB Trigger analysis. Will search for known malicious signatures in database triggers. List unknown files. Shows the list of found unknown files in the malware scanner report. Unknown files do not have known virus signatures and do not have suspicious code. Meanwhile, unknown files do not belong to the public plugins and themes at wordpress.org. File System Watcher. File system Watcher monitors changes in the file system. This allows to quickly respond to a site infection by tracking which files were affected. The Watcher makes file system snapshots as often as one hour and show difference up to seven days time frame. Feedback System. If you don’t have programming experience and don’t know, is there security issue or not, you send some files to CleanTalk Cloud and we check them for malware code. After checking we send you an email notification with results, is there viruses or not. Please, look at our guide How malware file analysis works About Scanner Feedback System LIST OF THE MOST ACTIVE MALWARES BY FILENAMES radio.php admin-ajax.php .1235512.css 8sjdakSJ3.php wso.php cmd.php shell.php reverse_shell.php admin.php The list is actual on July 15th, 2025. The latest data is the article Is my site infected? VULNERABILITIES SCANNER AMONG INSTALLED PLUGINS AND THEMES Plugin checks installed plugins and themes for known (published) vulnerabilities. If finds vulnerable plugin/theme, it sends an Email notification and shows data in the Critical updates tab. List of the most recent vulnerabilities found and published by CleanTalk Research team, CVE-2025-5921 – SureForms – Unauthenticated XSS – POC, 200k+ installs. CVE-2025-3582 – Newsletter – Stored XSS to JS Backdoor Creation – POC, 300k+ installs. CVE-2025-2560 – Ninja Forms – Stored XSS to JS Backdoor Creation – POC, 700k+ installs. The list is effective on July 18th, 2025. Updates are avaible on https://research.cleantalk.org/. MISCELLANEOUS SECURITY OPTIONS Send additional HTTP headers option. There are several additional http-headers which added to the every http-requests by the plugin if this option is enabled: “X-Content-Type-Options” improves the security of your site (and your users) against some types of drive-by-downloads. “X-XSS-Protection” header improves the security of your site against some types of XSS (cross-site scripting) attacks. “Strict-Transport-Security” response header (often abbreviated as HSTS) informs browsers that the site should only be accessed using HTTPS, and that any future attempts to access it using HTTP should automatically be converted to HTTPS. “Referrer-Policy” make the Referer http-header transferring more strictly. Collect and send PHP logs. Collect and send PHP error logs to your CleanTalk Dashboard where you can list them. Prevent collecting of authors logins. Prevent visitors from collecting logins of the content authors from the website links (like example.com/?author=1). Also this function known as Stop User Enumeration. Prevent collecting of user login on password reset. The password reset error will not contain the data about selected username does not exist. Disable REST API for non-authenticated users. Turn this on to deny access to WordPress REST API for non-authenticated users. Denied requests will get a 401 HTTP Code (Unauthorized). Disable the WordPress endpoint “users” REST API. Disables access to /wp-json/wp/v2/users and /wp-json/wp/v2/users/”id_user”. Disable File Editor. By prohibiting file editing, you protect the site from malicious attacks that may try to change the code and gain access to the site or steal confidential information. TRANSLATE INTO YOUR LANGUAGE Thank you for helping translate the plugin! 感谢您帮助翻译这个插件! (Gǎnxiè nín bāngzhù fānyì zhège chājìan!) प्लगइन का अनुवाद करने में मदद के लिए धन्यवाद! (Plugin ka anuvaad karne mein madad ke liye dhanyavaad!) ¡Gracias por ayudar a traducir el complemento! Merci d’avoir aidé à traduire le plugin ! شكرًا لمساعدتك في ترجمة الإضافة! (Shukran limusaa’adatika fi tarjamat al-idafa!) প্লাগইন অনুবাদে সাহায্য করার জন্য ধন্যবাদ! (Plug-in onubade shahajjo korar jonno dhonnobad!) Спасибо за помощь в переводе плагина! (Spasibo za pomoshch v perevode plagina!) Obrigado por ajudar a traduzir o plugin! (Obrigada if female) پلگ ان کا ترجمہ کرنے میں مدد کرنے کا شکریہ! (Plug-in ka tarjuma karne mein madad karne ka shukriya!) Terima kasih telah membantu menerjemahkan plugin! Danke, dass du beim Übersetzen des Plugins geholfen hast! プラグインの翻訳を手伝ってくれてありがとうございます! (Puraguin no hon’yaku o tetsudatte kurete arigatou gozaimasu!) https://translate.wordpress.org/projects/wp-plugins/security-malware-firewall/
Top keywords
- security57×2.48%
- login21×0.91%
- cleantalk18×0.78%
- malware18×0.78%
- files16×0.70%
- firewall15×0.65%
- users15×0.65%
- code13×0.57%
- php13×0.57%
- scanner13×0.57%
- wordpress13×0.57%
- file12×0.52%
WP Hide & Security Enhancer
Effortlessly conceal your WordPress site from detection! With over 99.99% of hacks targeting specific plugin and theme vulnerabilities, this plugin significantly boosts site security by making it invisible to hackers’ web scanners. By removing all traces of WordPress, including themes and plugins, potential exploits are rendered harmless. This method ensures that your site is safe without affecting SEO; in fact, it can enhance certain SEO aspects when used strategically. WP-Hide has launched the easiest way to completely hide your WordPress core files, login page, theme and plugins paths from being shown on front side. This is a huge improvement over Site Security, since no one will know whether you are running or not a WordPress. It also provides a simple way to clean up html by removing all WordPress fingerprints. No file and directory change! No file and directory will be changed anywhere. Everything is processed virtually. The plugin code uses URL rewrite techniques and WordPress filters to apply all internal functionality and features. Everything is done automatically without user intervention required at all. Real hide of WordPress core files and plugins The plugin not only allows you to change default URLs of you WordPress, but it also hides/blocks such defaults. Other similar plugins, just change the slugs, but the defaults are still accessible, obviously revealing WordPress as CMS. You can change the default WordPress login URL from wp-admin and wp-login.php to something totally arbitrary. No one will ever know where to try to guess a login and hack into your site. It becomes totally invisible. Full plugin documentation available at WordPress Hide and Security Enhancer Documentation When testing with WordPress theme and plugins detector services/sites, any setting change may not reflect right away on their reports, since they use cache. So, you may want to check again later, or try a different inner URL. Homepage URL usage is not mandatory. Being the best content management system, widely used, WordPress is susceptible to a large range of hacking attacks including brute-force, SQL injections, XSS, XSRF etc. Despite the fact the WordPress core is a very secure code maintained by a team of professional enthusiast, the additional plugins and themes make ita vulnerable spot for every website. In many cases, those are created by pseudo-developers who do not follow the best coding practices or simply do not own the experience to create a secure plugin. Statistics reveal that every day new vulnerabilities are discovered, many affecting hundreds of thousands of WordPress websites. Over 99,9% of hacked WordPress websites are target of automated malware scripts, which search for certain WordPress fingerprints. This plugin hides or replaces those traces, making the hacking bots attacks useless. It works well with custom WordPress directory structures,e.g. custom plugins, themes, and upload folders. Once configured, you need to clear server cache data and/or any cache plugins (e.g. W3 Cache), for a new html data to be created. If you use CDN this should be cache clear as well. Sample usage Main plugin functionality: Customizes Admin URL Blocks default admin URL Blocks any direct folder access to completely hide the structure Customize wp-login.php filename 2FA – Two-factor Authentication 2FA – Two-factor Authentication – Email Verification Code 2FA – Two-factor Authentication – Authenticator App 2FA – Two-factor Authentication – Recovery Codes 2FA – Two-factor Authentication – Shortcode for front-side user settings interface 2FA – Two-factor Authentication – My Account > Account Details – area for 2FA user settings interface Google Captcha Blocks default wp-login.php Blocks default wp-signup.php Blocks XML-RPC API Creates New XML-RPC paths Adjusts theme URL Creates New child Theme URL Changes theme style file name Cleans any headers for theme style file Customizes wp-include Blocks default wp-include paths Blocks default wp-content Customizes plugins URL Changes Individual plugin URL Blocks default plugins paths Creates New upload URL Blocks default upload URL Removes WordPress version Blocks Meta Generator Disables the emoji and required javascript code Removes pingback tag Removes wlwmanifest Meta Removes rsd_link Meta Removes wpemoji Minifies Html, Css, JavaScript Security Headers and many more. No other plugin functionality will be blocked or interfered in any way by WP-Hide This plugin allows to change the default Admin URL from wp-login.php and wp-admin to something else. All original links turn the default theme to “404 Not Found” page, as if nothing exists there. Besides the huge security advantage, the WP-Hide plugin saves lots of server processing time by reducing php code and MySQL usage since brute-force attacks target the weakURL. Important: Compared to all other similar plugins which mainly use redirects, this plugin turns a default theme to“404 error” page for all blocked URL functionalities, without revealing the link existence at all. Since version 1.2, WP-Hide change individual plugin URLs and made them unrecognizable. For example,the change of the default WooCommerce plugin URL and its dependencies from domain.com/wp-content/plugins/woocommerce/ into domain.com/ecommerce/cdn/ or anything customized. Plugin Sections **Hide -> Scan Exhaustive system security examination with analysis and improvements guidance and fixes Hide -> Rewrite > Theme New Theme Path – Changes default theme path New Style File Path – Changes default style file name and path Remove description header from Style file – Replaces any WordPress metadata information (like theme name, version etc.,) from style file Child – New Theme Path – Changes default child theme path Child – New Style File Path – Changes child theme style-sheet file path and name Child – Remove description header from Style file – Replaces any WordPress metadata information (like theme name, version etc.,) from style file Hide -> Rewrite > WP includes New Include Path – Changes default wp-include path/URL Block wp-include URL – Blocks default wp-include URL Hide -> Rewrite > WP content New Content Path – Change default wp-content path/URL Block wp-content URL – Blocks the default content URL Hide -> Rewrite > Plugins New Plugin Path – Changes default wp-content/plugins path/URL Block plugin URL – Blocks default wp-content/plugins URL New path / URL for Every Active Plugin Customize path and name for any active plugins Hide -> Rewrite > Uploads New Upload Path – Changes default media files path/URL Block upload URL – Blocks default media files URL Hide -> Rewrite > Comments New wp-comments-post.php Path Block wp-comments-post.php Hide -> Rewrite > Author New Author Path Prevent Access to Author Archives Block default path Hide -> Rewrite > Search New Search Path Block default path Hide -> Rewrite > XML-RPC New XML-RPC Path – Changes default XML-RPC path / URL Block default xmlrpc.php – Blocks default XML-RPC URL Disable XML-RPC authentication – Filters whether XML-RPC methods require authentication Remove pingback – Removes pingback link tag from theme Hide -> Rewrite > JSON REST Clean the REST API response Disable JSON REST V1 service – Disables an API service for WordPress which is active by default Disable JSON REST V2 service – Disables an API service for WordPress which is active by default Block any JSON REST calls – Any call for JSON REST API service will be blocked Disable output the REST API link tag into page header Disable JSON REST WP RSD endpoint from XML-RPC responses Disable Sends a Link header for the REST API Hide -> Rewrite > Root Files Block license.txt – Blocks access to license.txt root file Block readme.html – Blocks access to readme.html root file Block wp-activate.php – Blocks access to wp-activate.php file Block wp-cron.php – Blocks outside access to wp-cron.php file Block wp-signup.php – Blocks default wp-signup.php file Block other wp-*.php files – Blocks other wp-.php files within WordPress Root Hide -> Rewrite > URL Slash URL’s add Slash – Add a slash to any links without it. This disguisesthe existence of a file, folder or a wrong URL, which will all be slashed. Hide -> General / Html > Core Disabling Directory Listing Hide -> General / Html > Meta Remove WordPress Generator Meta Remove Other Generator Meta Remove Shortlink Meta Remove DNS Prefetch Remove Resource Hints Remove wlwmanifest Meta Remove feed_links Meta Disable output the REST API link tag into page header Remove rsd_link Meta Remove adjacent_posts_rel Meta Remove profile link Remove canonical link Hide -> General / Block Detectors Block Detectors Hide -> General / Emulate CMS Emulate CMS Hide -> General / Html > Admin Bar Remove WordPress Admin Bar for specified urser roles Hide -> General / Feed Remove feed|rdf|rss|rss2|atom links Hide -> General / Robots.txt Disable admin URL within Robots.txt Hide -> General / Html > Emoji Disable Emoji Disable TinyMC Emoji Hide -> General / Html > Styles Remove Version Remove ID from link tags Hide -> General / Html > Scripts Remove Version Hide -> General / Html > Oembed Remove Oembed Hide -> General / Html > Headers Remove Link Header Remove X-Powered-By Header Remove Server Header Remove X-Pingback Header Hide -> General / Html > HTML Remove HTML Comments Minify Html, CSS, JavaScript Remove general classes from body tag Remove ID from Menu items Remove class from Menu items Remove general classes from post Remove general classes from images Hide -> General / Html > User Interactions Disable Mouse right click Disable Text Selection Disable Copy Disable Cut Disable Paste Disable Print Disable Print Screen Disable Developer Tools Disable View Source Disable Drag / Drop Hide -> Admin > wp-login.php New wp-login.php – Maps a new wp-login.php instead of the default one Block default wp-login.php – Blocks default wp-login.php file from being accessible Customize the default login page Logo image Hide -> Admin > Admin URL New Admin URL – Creates a new admin URL instead of the default ”/wp-admin”. This also applies for admin-ajax.php calls Disable customized Admin Url redirect to the Login page Block default Admin Url – Blocks default admin URL and files from being accessible Security -> 2FA Enable 2FA Enable the 2FA for specific roles Enforce User to Configure 2FA Primary option for Two-Factor Disable 2FA when using Temporary Login Security -> 2FA Email Activate 2FA Email Security -> 2FA Auth App Activate Authenticator app (TOTP) Security -> 2FA Recovery Codes Activate 2FA Recovery Codes Security -> Captcha Google Captcha V2 Google Captcha V3 CloudFlare Turnstile ( PRO ) Settings -> CDN CDN Url – Sets-up CDN if applied. Some providers replace site assets with custom URLs. Security -> Headers HTTP Response Headers are a powerful tool to Harden Your Website Security. * Cross-Origin-Embedder-Policy (COEP) * Cross-Origin-Opener-Policy (COOP) * Cross-Origin-Resource-Policy (CORP) * Referrer-Policy * X-Content-Type-Options * X-Download-Options * X-Frame-Options (XFO) * X-Permitted-Cross-Domain-Policies * X-XSS-Protection This free version works with Apache and IIS server types. For all server types, check with WP Hide PRO This is a basic version that can hide everything for basic sites, example https://demo.wp-hide.com/. When using complex plugins and themes, the WP Hide PRO may be required. We provide free assistance to hide everything on your site, along with the commercial product. Anything wrong with this plugin on your site? Just use the forum or get in touch with us at Contact and we’ll check it out. A website example can be found at https://demo.wp-hide.com/ or our website WP Hide and Security Enhancer Plugin homepage at WordPress Hide and Security Enhancer This plugin is developed by Nsp-Code Localization Please help and translate this plugin to your language at https://translate.wordpress.org/projects/wp-plugins/wp-hide-security-enhancer You are kindly asked to promote this plugin if it comes up to your expectations via an article on your site or any other place. If you liked this code/WP-Hide or if it helped with your project, why not leave a 5 star review on this board.