Product Hall of Fame
ProductFame helps founders launch products, gain visibility, and earn backlinks while users discover new startups and tools.
ProductFame helps founders launch products, gain visibility, and earn backlinks while users discover new startups and tools.

WordSec is a complete WordPress security plugin. Its eight modules cover the firewall, the malware scanner, login security, live traffic, IP and country blocking, supply-chain intelligence, the audit log and real-time alerts, so you can block attacks, find malware and harden your site from one dashboard instead of installing eight separate plugins.
If your WordPress site gets hacked you do not just lose the site. You lose customer trust, your Google rankings and days of work restoring backups. WordSec is built to stop that before it happens.
Free, and no license key to enter. The WAF firewall rules, malware and file-integrity scanning, brute force protection, two factor authentication, login security, IP and country blocking, the audit log and one-click hardening all run locally on your own server, and with no key the plugin makes no outbound request to the WordSec service at all. Every module can be enabled or disabled independently, so you get exactly the protection your site needs without paying for it in performance, and your live security score is always in view.
Firewall
Inspect every request, write your own rules, and harden WordPress with one-click toggles.
- Multi-condition custom rule builder with regex and wildcard matching
- Built-in rules across the major attack categories (SQL injection, XSS, path traversal, PHP and command injection, and more)
- WAF learning and active modes, bot blocking and security headers
- 25+ one-click hardening toggles for wp-config access, author enumeration, REST API and more
- Optional Extended Protection: pre-WordPress request inspection via an auto_prepend_file bootstrap
- Endpoint rate limiting, XML-RPC protection and detailed firewall logs
Scanner
A seven-stage scanning system that examines files, the database and scheduled tasks.
- Malware detection rules (synced from the WordSec service) based content scanning
- WordPress core, plugin and theme file-integrity verification (via the WordPress.org API)
- Scheduled scans with batch processing to avoid timeouts
- One-click quarantine and restore, with complete scan history
Login Security
- Role-based two-factor authentication (RFC 6238 TOTP), no external library required
- Three CAPTCHA providers (reCAPTCHA, hCaptcha, Cloudflare Turnstile) plus a built-in math CAPTCHA
- Brute-force protection with progressive lockout and honeypot traps
- Leaked-password checking (Have I Been Pwned, k-anonymity) and Argon2 password enforcement
- Session management and a custom login page designer
Live Traffic
- Real-time request logging (IP, URI, method, status, response time)
- Safe request and response inspection with automatic bot detection
- Exclusion filtering by role, IP, country or URI, with CSV export
Blocking
- Country and continent allow or block lists
- Single IP and CIDR range blocking, temporary or permanent, with allow-list support
- Automatic abuse protection and endpoint rate limiting
- Custom block messages
Supply Chain
- Reputation scoring for every installed plugin and theme
- Known-vulnerability alerts (data from the WordSec service) for core, plugins, themes and PHP
- Abandoned plugin and theme detection
- Update-integrity verification with automatic backups and a full SBOM inventory
Audit Log
- Complete activity tracking across 11 object types and 14 actions
- Content, plugin, theme and setting changes
- Fast filtering and one-click export
Alarm
- 36 event types across six categories
- Delivery by Email, Telegram or Slack
- Basic, Advanced and Full alert modes
WordSec is fully functional out of the box. Every feature runs locally on your own server.
Product details are supplied by the publisher. Verify current features, availability, and pricing on the official WordSec website.