Security Ninja – WordPress Security & Firewall
Security Ninja is a lightweight WordPress security plugin that helps protect your site from common attacks and security mistakes – without turning your dashboard into a cockpit. Web Application Firewall (WAF) (based on the 8G ruleset) to block common malicious requests, plus 50+ security checks, a full vulnerability scanner, and a core integrity scanner to spot risky settings and unexpected file changes. Upgrade to Pro for Cloud Firewall, malware scanning/cleanup, login brute-force protection and 2FA, export/webhooks, and scheduled scans. This plugin can be downloaded for free without any paid subscription from the official WordPress repository. Included for free – Basic Firewall (8G-based) – Blocks common malicious requests and bot noise before it becomes a problem. – 50+ Security Tests – Fast audit of common WordPress security misconfigurations. – Vulnerability Scanner – Highlights known issues in plugins/themes so you can patch faster. – Core Scanner – Detect modified or unexpected files in WordPress core folders. – Basic Events Logger – Logs firewall events and login attempts (successful/failed). – AI Security Advisor (WordPress 7) – AI-generated audit summaries and guided follow-ups from your scans, using WordPress AI Connectors (you choose the LLM provider). Optional WordPress Abilities let other AI tools on your site read test summaries, attack activity, and your latest saved report. Pro adds – Cloud Firewall & advanced WAF – Block 600+ million known bad IPs, country blocking, IP management, and stronger firewall controls (free includes the 8G-based firewall). – Advanced Malware Scanner – Detect and clean malicious code and suspicious files. – Login protection & 2FA – Limit failed logins, rename the login URL, and add two-factor authentication. – One-click Fixes – Harden WordPress from the Fixes page (XML-RPC, file editor, headers, and more). – Full Events Logger – Export logs, scheduled email reports, webhooks (e.g. Slack/Discord), and deeper alerting. – Scheduled scans & reporting – Automated security scans and reports. Key Features Security Ninja is a lightweight WordPress firewall plugin and security toolkit designed to help you find misconfigurations, block common attacks, and stay ahead of known vulnerabilities – without slowing your site down. Comprehensive WordPress Security Testing Security Ninja performs 50+ advanced security tests to identify issues before attackers exploit them. This includes: Login and password checks – Audits weak passwords and related settings (Pro adds failed-login limits, rename login, and 2FA). File integrity monitoring – Detects unauthorized changes to WordPress core files, themes, and plugins. Database security checks – Identifies weak database permissions and potential SQL injection threats. User role audits – Ensures no unauthorized administrator accounts exist. Security misconfiguration scans – Identifies and fixes weak settings that could compromise security. Enhanced Vulnerability Scanner Proactively alerts you to known vulnerabilities in plugins and themes so you can patch before they are exploited. Core Scanner – WordPress Installation Integrity Ensures your WordPress installation remains untampered and free of unauthorized files. Full core file integrity check – Scans every file in core WordPress folders for modifications. Unknown file detection – Flags extra or unexpected files in core directories. Built-in file viewer – Review flagged files in the dashboard. Restore or delete – Restore altered core files with one click, or remove suspicious unknowns. Advanced Malware Scanner – Detect & Remove Malware Instantly (PRO) Security Ninja includes a high-performance malware scanner that automatically checks your WordPress core, plugins and themes for: Malicious scripts and backdoors – Identifies hidden malware and harmful injections. Trojan and virus detection – Scans for suspicious PHP and JavaScript entries. One-click malware removal – Instantly quarantine and delete infected files. WordPress Firewall & Real-Time Threat Protection Security Ninja includes a basic firewall for free (8G-based) to block common malicious requests. Upgrade to Pro for more advanced WAF controls. Basic protection (Free) – 8G rules block many common exploit patterns and abusive requests. Advanced protection (Pro) – Cloud Firewall, country blocking, IP lists, and additional intelligence/automation. Login brute-force protection (Pro) – Limit failed logins and harden the login flow (not included in the free firewall). Automatic service whitelisting (Pro) Cloud Firewall (Pro) whitelists known third-party service IPs so remote maintenance, optimization, and monitoring tools are less likely to be blocked. No manual IP entry is required for these built-in lists. WP Compress – image optimization and compression service MonSpark – uptime and website monitoring Modular DS – remote site management WPMU DEV – hosting and management platform Divi Dash – Elegant Themes site management Fastpixel – optimization service Broken Link Checker – link checking service GetTerms – cookie consent scanner (getterms.io) Optional one-click whitelists (Firewall → IP Management; enable per service): – ManageWP – enabled by default on new installs – WP Rocket – caching and optimization – UptimeRobot – uptime monitoring – Uptimia – uptime monitoring You can still add your own IPs and CIDR ranges manually on the IP Management screen. Login Security & Two-Factor Authentication (2FA) (PRO) Your WordPress login page is a primary target for hackers. Security Ninja enhances login security with: Two-Factor Authentication (2FA) – Requires additional verification for safer logins. Brute-force attack protection – Limits failed login attempts to block unauthorized access. Rename login – Getting a lot of requests to your login form? Hide it for spammers. One-Click Security Fixes & WordPress Hardening (PRO) Manually fixing security issues is time-consuming. Security Ninja provides one-click hardening to: Disable XML-RPC – Blocks common DDoS attacks and brute-force exploits. Restrict file editing – Prevents unauthorized theme and plugin modifications. Hide PHP error messages – Stops hackers from exploiting sensitive error details. And many more fixes to harden your WordPress security! Events Logger / Activity Tracking Security Ninja includes a basic events logger for free so you can see what’s happening on your site. Free: firewall events and login attempts (successful/failed) in the dashboard. Pro: export security logs, scheduled email reports, webhooks (e.g. Slack/Discord), and deeper alerting. Automated Security Scans & Reports (PRO) Security Ninja performs scheduled security scans and sends reports directly to your inbox. Set up daily, weekly, or monthly security scans. Receive email alerts about vulnerabilities and malware infections. Analyze detailed reports to keep your website secure. Block Spam & Malicious Bots Instantly (PRO) Hackers and spammers use bots to exploit WordPress websites. Security Ninja prevents: Fake registrations and spam comments – Stops bots from even getting to your site. Malicious bot attacks – Blocks scripts attempting to hack your site. Unwanted traffic – Reduces server load by preventing unnecessary bot access. AI Security Advisor – from scan results to clear next steps (WordPress 7) Understanding a security scan shouldn’t feel like homework. AI Security Advisor uses your connected LLM (via WordPress 7 AI Connectors) to turn Security Ninja findings into a readable audit: executive summary, prioritized improvements, and suggested follow-up prompts-not an open-ended chatbot. Reports draw on Security Tests, the Vulnerability Scanner, Core Scanner, recent firewall/login events, and on Pro sites Malware Scanner results when available. Saved reports stay on your site until you remove them. What you need AI Security Advisor is included in the free plugin but requires WordPress 7. You connect the AI/LLM provider yourself under Settings → Connectors in WordPress; Security Ninja does not host or supply API keys. WordPress Abilities (optional) On WordPress 7, Security Ninja can register read-only Abilities so other AI tools on the same site can fetch a test summary, 7-day attack activity, or your latest saved audit-useful if you use multiple AI integrations. Report generation and follow-ups on the Security Advisor page work independently of this. Privacy, in everyday language Only non-identifying security context (test results, scan status, event counts-not personal data) is sent to your chosen AI provider to build a report. If you are not on WordPress 7 yet, you will see a notice on the AI Security Advisor screen; the rest of Security Ninja continues to work as usual. Join thousands of satisfied users who trust Security Ninja to keep their websites safe. Start protecting your online presence today. Extensions MainWP – Manage Security Ninja across many sites from one MainWP Dashboard. Security Ninja on each child site includes MainWP integration built in (no extra plugin on child sites). Free addon – Security Ninja for MainWP (WordPress.org): view test results and vulnerabilities per site, trigger remote security scans, and sync fresh results. Works with child sites on free or Pro Security Ninja; data shown matches what each site’s installed version provides. Premium addon – Adds a combined events log across all connected sites, search/filter for security events, and remote white-label control on Pro child sites. Requires Security Ninja Pro on child sites for log and white-label features. Available from your WP Security Ninja account; see MainWP integration for details. https://wordpress.org/plugins/security-ninja-for-mainwp/ Security Ninja Pro adds Cloud Firewall (600+ million known bad IPs), country blocking, advanced WAF controls, Malware Scanner, login protection (failed-login limits, rename login, 2FA), One-click Fixes, full Events Logger (export, webhooks, scheduled reports), and scheduled scans. The free plugin already includes the 8G firewall, 50+ security tests, Vulnerability Scanner, Core Scanner, basic Events Logger, and AI Security Advisor on WordPress 7. An all-in-one security solution for any site. With premium support and continuous updates Security Ninja Pro is a perfect tool to keep your site safe. See what the PRO version offers Automatically block 600+ million bad IPs with one click! Security Ninja Pro Firewall will help you stay one step ahead of bad guys by using the collective know-how of millions of attacked sites, and ban bad guys before they even open your site. Read more about Pro features on the Security Ninja website What others say about the plugin Kinsta Hostinger Cloudways AppSumo Freemius WP Mayor: “Easy-to-Use WordPress Security Plugin” WPMarmite WPExplorer WPLift WP Loop InfluenceWP G2 Tests * The tests include: * brute-force attack on user accounts to test password strength * numerous installation parameters tests * file permissions * version hiding * 0-day exploits tests * debug and auto-update modes tests * database configuration tests * Apache and PHP related tests * WP options tests * security headers and related server response checks The full suite covers 50+ checks across WordPress core/plugins/themes, user accounts and passwords, file permissions, debug modes, database configuration, PHP settings, security headers, and more. Open Security Ninja in your dashboard for the complete list with explanations and fix guidance. License info jQuery Cookie Plugin, Copyright 2013 Klaus Hartl The vulnerability scanner uses data from the National Vulnerability Database – NVD This product includes IP2Location LITE data available from https://lite.ip2location.com. This plugin uses the Persist Admin notice Dismissals by Collins Agbonghama @collizo4sky Firewall rules are based on 8G Firewall by Jeff Starr – https://perishablepress.com/8g-blacklist/ How can I report security bugs? You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability.
Top keywords
- security68×3.95%
- wordpress32×1.86%
- ninja26×1.51%
- security ninja26×1.51%
- pro23×1.34%
- firewall21×1.22%
- login18×1.05%
- scanner17×0.99%
- site16×0.93%
- ai13×0.76%
- core13×0.76%
- scans12×0.70%
SiteFort Security – Malware Scanner, Firewall, Login Security & Hardening
SiteFort is a prevention-first WordPress security plugin that combines security hardening, firewall and bot protection, login security and 2FA, vulnerability scanning, and malware detection in one protection layer. It blocks common attack paths early, before they turn into compromises, while supported firewall rules can sync to Cloudflare for enforcement at the edge. SiteFort’s cloud-assisted malware scanner verifies trusted files by hash and sends only unknown or suspicious files for deep threat analysis, keeping scans reliable even on shared and lower-resource hosting. Security hardening, firewall protection, login security, 2FA, and vulnerability scanning are free forever. Try the Live Demo | Features | Try Online Scanner Core WordPress Security Features WordPress Security Hardening: Reduces common exposure through XML-RPC, user enumeration, sensitive files, direct PHP execution, REST access, security headers, and other WordPress security controls. Firewall & Bot Protection: Blocks vulnerability probes, abusive requests, malicious traffic, and unwanted automation with IP, country, rate limiting, and configurable bot controls. Supported rules can also sync to Cloudflare for edge enforcement. Login Security & 2FA: Protects WordPress login, WooCommerce customer accounts, and membership account access with two-factor authentication, CAPTCHA, brute-force lockouts, a custom login URL, breached-password checks, and password policies. Vulnerability Scanner: Checks WordPress core, plugins, and themes for known vulnerabilities, affected versions, severity, CVE references where available, and remediation guidance. Cloud-Assisted Malware Scanner: Detects backdoors, web shells, injected code, malicious redirects, SEO spam, and suspicious file changes, with deep threat analysis in the cloud to reduce server load. Compromise & Reputation Checks: Detects suspicious administrator accounts, injected content, unsafe URLs, exposed sensitive files, malicious redirects, and domain or server reputation issues. WordPress Security Hardening SiteFort provides simple, toggle-based WordPress hardening controls to reduce common security exposure and shrink the attack surface. Sensitive File Protection: Blocks public access to WordPress configuration backups, database dumps, debug logs, backup files, installer files, and other sensitive resources, including exposed .env or .git data when present. PHP Execution Protection: Blocks PHP execution in uploads and restricts direct access to PHP files in plugin and theme directories. XML-RPC Controls: Disable XML-RPC, restrict authentication, or block pingback abuse. User Enumeration Blocking: Reduces username exposure through author archives, REST endpoints, and common discovery paths. REST & Application Password Controls: Restricts REST API access and controls WordPress Application Passwords based on site requirements. File Editor Protection: Disables the built-in WordPress theme and plugin file editor. Directory Browsing Protection: Disables directory listing to reduce file discovery and unintended information exposure. Security Headers: Analyze and manage CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and disclosure headers. Version & Metadata Cleanup: Reduces exposed WordPress version, generator, and header information. Protection Verification: Confirms supported hardening protections are active and identifies items that require manual hosting or server configuration. WordPress Malware Scanner SiteFort combines hash-first file verification with cloud-assisted deep threat analysis to detect malware while reducing scan workload on the WordPress server. Hash-First File Verification: Known WordPress core, plugin, and theme files are verified against trusted hashes. Deep Threat Analysis: Files that cannot be verified by hash or show suspicious indicators are sent to the SiteFort cloud for deep threat analysis, including backdoors, web shells, injected PHP or JavaScript, malicious redirects, SEO spam, and obfuscated code. File Integrity: Detects modified WordPress core, plugin, and theme files, along with unexpected files that do not belong in trusted packages. Account & Content Checks: Checks administrator accounts, WordPress content, options, URLs, and redirects for suspicious changes and indicators of compromise. Sensitive File Exposure: Identifies publicly accessible backups, logs, configuration files, debug files, and other sensitive files commonly targeted by attackers. Domain & IP Reputation: Checks the site domain and server IP against supported blocklists and abuse intelligence. Database and content checks run on the protected site and are not uploaded to the SiteFort cloud. Login Security & 2FA SiteFort protects WordPress login and account access against brute-force attacks, credential abuse, and unauthorized access. Brute-Force & CAPTCHA Protection: Limits repeated login attempts and adds CAPTCHA protection to WordPress, WooCommerce, and supported custom login and registration forms. Two-Factor Authentication: Adds role-based 2FA with authenticator apps, email codes, recovery codes, grace periods, and trusted devices. WooCommerce & Membership 2FA: Lets customers and members manage 2FA from WooCommerce My Account or supported custom account pages. Custom Login URL: Move the WordPress login page to a private URL and control requests to the default wp-login.php address. Password Security: Detects weak and breached passwords, enforces password strength, prevents reuse, and supports optional expiration policies. WordPress Firewall SiteFort filters malicious and abusive traffic early, with clear controls for IPs, countries, rate limits, sensitive paths, bots, and optional Cloudflare edge enforcement. IP, CIDR & Country Rules: Block or allow individual IP addresses, CIDR ranges, and countries, including an allow-only mode. Sensitive Path Probe Protection: Blocks requests probing for commonly targeted sensitive paths, including WordPress configuration backups, database dumps, debug logs, installer files, .env, and .git. Rate Limiting & 404 Controls: Reduces abusive request bursts, repeated missing-page requests, and automated scanning activity. Bot & User-Agent Controls: Block or allow selected bots, crawlers, scanners, and user agents with configurable firewall rules. Community Threat Intelligence: Blocks known malicious IPs identified across the SiteFort network, helping stop repeat bad actors before they reach the site. Vulnerability Probe Protection: Blocks automated requests searching for vulnerable plugins, themes, backup files, and configuration leaks. Cloudflare Sync: Synchronizes supported IP, country, and user-agent rules to Cloudflare, with temporary edge blocks for repeat attackers where supported. Traffic Log: Review firewall traffic, blocked requests, bot activity, rate-limit events, and rule matches from the firewall dashboard. Bot Protection Policy SiteFort provides three bot protection presets for straightforward setup, with the option to allow or block specific bots and crawlers individually. Basic: Blocks known hacking tools and bots probing for vulnerable files and common attack paths. Balanced: Adds protection against scraping bots and automated scripts. Recommended for most WordPress sites. Maximum: Extends filtering to unrecognized bot traffic for sites that require stricter automation controls. AI Training Crawlers: Optionally block training-focused crawlers such as GPTBot, ClaudeBot, CCBot, and Bytespider while supported AI assistants and AI search crawlers remain allowed. Supported search crawlers are verified using reverse DNS and published IP ranges and are allowed through bot protection, while bots impersonating known search engines are detected and blocked. Vulnerability Scanner SiteFort checks installed WordPress core, plugins, and themes against vulnerability intelligence and identifies affected versions, severity, and available remediation. Affected Components: Identifies vulnerable WordPress core, plugins, and themes with installed versions, severity, and CVE references where available. Fix Guidance: Shows fixed versions and recommended actions when remediation information is available. Vulnerability Probe Protection: Firewall controls block automated discovery attempts targeting vulnerable plugins, themes, and known component paths while affected software is being updated, replaced, or removed. SiteFort does not virtually patch vulnerable code. Vulnerable components should be updated, replaced, or removed using the available remediation guidance. Malware Repair & Quarantine Delete or Quarantine (Free): Remove malicious or unwanted files from scan results, with optional quarantine for recovery when needed. One-Click Repair (Pro): Repairs malicious or modified files directly from scan results when a trusted clean source is available. Clean-File Restore (Pro): Restores supported WordPress core, plugin, and theme files, including selected commercial plugins and themes when verified clean sources are available. For active WordPress compromises requiring hands-on investigation, Securewp expert cleanup is available for malware removal, root-cause remediation, blocklist assistance, and post-cleanup review. WordPress Security Audit Log SiteFort records important security and administrative activity, providing a clear history for review and investigation. Login Activity: Successful and failed logins, lockouts, 2FA events, and account-related activity. User Changes: User creation, updates, role changes, and other account actions. Plugin & Theme Activity: Installations, activations, deactivations, updates, and other recorded changes. Security & Settings Changes: Hardening, login security, firewall configuration, and other sensitive administrative changes. SiteFort Console SiteFort Console provides a central panel for managing security across multiple WordPress sites. No separate add-on is required; Console connectivity can be enabled or disabled directly from the SiteFort plugin. Run security scans and review findings across sites. Monitor vulnerabilities and update hardening settings remotely. Review security status, scan history, uptime, and SSL expiry. Route alerts and download reports for individual sites or clients. Manage team access and support workflows from one place. All site-level security features remain available directly in WordPress; Console adds centralized management for multiple sites. Hosting Compatibility SiteFort supports shared hosting, managed WordPress hosting, VPS, and dedicated servers across Apache, Nginx, and LiteSpeed. Cloudflare: Works with Cloudflare-proxied sites and supports optional firewall rule sync for edge enforcement. Lower-Resource Hosting: Hash-first file verification and cloud-assisted deep analysis reduce scan workload on the hosting server. Flexible Server Support: Does not require a specific web server stack or managed hosting environment. Free vs Pro SiteFort Free includes security hardening, firewall and bot protection, login security and 2FA, vulnerability scanning, activity logging, and 3,000 monthly cloud scan credits. Pro removes the cloud analysis limit and adds automation, repair, monitoring, alerts, and reporting. SiteFort Pro adds: Unlimited deep threat analysis Scheduled malware scans and automated vulnerability alerts One-click malware repair and clean-file restore Uptime and SSL expiry monitoring Slack, Discord, email, and webhook alerts Remote scan history and detailed security reports White-label options for agencies Managed adds hands-on monitoring, incident response workflows, and expert cleanup coverage from the Securewp team. See the WordPress Security Plugin Comparison for a feature-by-feature comparison with other WordPress security plugins. External services SiteFort uses external services only for features that require them, including license activation, cloud-assisted malware analysis, vulnerability and firewall intelligence, reputation checks, optional Console sync, CAPTCHA, GeoIP, Cloudflare Sync, and administrator-configured notifications. Optional integrations are not contacted unless they are enabled or used. SiteFort Cloud Servers: securewp.net, intel.securewp.net, console.securewp.net Used for: License activation, service metadata, cloud malware analysis, vulnerability intelligence, firewall intelligence, reputation checks, community blocklist sync, clean-file repair, and optional Console sync. Data sent: Email address, license key or token, site URL, WordPress and plugin versions, installed plugin and theme names and versions, file hashes, scan results, vulnerability findings, reputation status, firewall metadata, blocked IP addresses, and security configuration metadata. Malware scanning: File hashes are sent first. Only unknown or suspicious files may be uploaded for deeper analysis and are deleted after processing. Database and content checks run on the protected site and are not uploaded to the SiteFort cloud. If wp-config.php requires analysis, sensitive configuration values are removed before upload. Temporary storage: SiteFort Cloud may return temporary *.amazonaws.com upload or download URLs for malware analysis or clean-file repair. Privacy: https://securewp.net/privacy-policy/ Terms: https://securewp.net/terms-and-conditions/ Storage provider policies: AWS privacy https://aws.amazon.com/privacy/ and terms https://aws.amazon.com/service-terms/; Cloudflare privacy https://www.cloudflare.com/privacypolicy/ and terms https://www.cloudflare.com/website-terms/ Optional integrations MaxMind GeoLite2 (download.maxmind.com): Used only when an administrator downloads or updates the local GeoIP database. The configured MaxMind account ID and license key are sent to MaxMind. Visitor IP addresses are resolved locally and are not sent to MaxMind during normal requests. Privacy: https://www.maxmind.com/en/privacy-policy Terms: https://www.maxmind.com/en/geolite2/eula Have I Been Pwned Passwords (api.pwnedpasswords.com): Used for breached-password checks when enabled. SiteFort sends only the first 5 characters of the SHA-1 password hash. Full passwords and full hashes are not sent. Privacy: https://haveibeenpwned.com/Privacy Terms: https://haveibeenpwned.com/TermsOfUse Google reCAPTCHA (www.google.com) and Cloudflare Turnstile (challenges.cloudflare.com): Used only when selected and configured for CAPTCHA protection. The selected provider receives the challenge token, site key, and visitor or browser data required to process the challenge. Policies: https://policies.google.com/privacy https://policies.google.com/terms https://www.cloudflare.com/turnstile-privacy-policy/ https://www.cloudflare.com/website-terms/ Cloudflare API (api.cloudflare.com): Used only when Cloudflare Sync is enabled. SiteFort sends the Zone ID, API token or credentials, zone details, blocked IP addresses, country rules, selected user-agent rules, and firewall rule data required for synchronization. Privacy: https://www.cloudflare.com/privacypolicy/ Terms: https://www.cloudflare.com/website-terms/ Notification webhooks: Security alerts may be sent to Slack (hooks.slack.com), Discord (discord.com, discordapp.com), or a custom HTTPS webhook configured by the administrator. Payloads may include site name, site URL, event type, severity, scan counts, vulnerability names, CVE identifiers, firewall counts, usernames, IP addresses, browser names, action URLs, timestamps, and event details. Slack policies: https://slack.com/trust/privacy/privacy-policy https://slack.com/terms-of-service/user Discord policies: https://discord.com/privacy https://discord.com/terms Local site checks Some SiteFort checks send loopback requests to the protected site’s own public URL, including security-header checks, public-file exposure checks, and homepage link collection. These requests contact the protected site itself, not a third-party service.