WordPress security plugins: firewalls, scanners and hardening explained
WordPress security plugins: firewalls, scanners and hardening explained

WordPress security plugins do four different jobs: blocking malicious requests (a firewall), finding malware or changed files (scanning), locking down logins and settings (hardening), and warning you when something you run has a known vulnerability (alerts or virtual patching). Most plugins combine two or three of these, and none of them replaces keeping WordPress, themes and plugins updated.
The risk is concentrated in add-ons. Patchstack's State of WordPress Security in 2026 report found 11,334 new vulnerabilities in the WordPress ecosystem in 2025: 91% in plugins, 9% in themes and just 6 in WordPress core. It also reported that 46% of vulnerabilities were not fixed in time for public disclosure, which is the gap a firewall or virtual patch is meant to cover.
This guide explains each layer, what core and your host already provide, how to evaluate a security plugin, and how well-known options such as Wordfence, Sucuri, Kadence Security (formerly Solid Security) and Patchstack differ. It is a guide, not a ranking.
Key Takeaways
- Updates are the most important security control; a plugin is a second layer, not a substitute.
- According to Patchstack, 91% of the 11,334 new WordPress vulnerabilities found in 2025 were in plugins and only 6 were in core.
- Endpoint firewalls (inside WordPress) and cloud or DNS-level firewalls (in front of the server) protect in different ways and suit different sites.
- Solid Security is now called Kadence Security; the WordPress.org slug is unchanged.
- Wordfence's free tier receives firewall rules and malware signatures 30 days after Premium, according to its WordPress.org listing.
- Run one main security plugin; overlapping firewalls and scanners cause conflicts and slowdowns.
What WordPress core and your host already do
Core security is solid and actively maintained:
- Automatic security updates. Minor and security releases install automatically by default. For the July 2026 critical release (7.0.2), WordPress.org enabled forced updates for affected sites.
- Plugin and theme auto-updates. Since 5.5 you can opt in per plugin and per theme; they run twice a day.
- Password hashing. WordPress 6.8 moved to bcrypt.
- Application Passwords (since 5.6) for API access without sharing the main password.
- Hardening constants. The official hardening guide explains that DISALLOW_FILE_EDIT in wp-config.php removes the built-in theme and plugin file editors.
What core does not include: a web application firewall, malware scanning, login attempt limits, or two-factor authentication. The official hardening guide recommends two-step authentication, which you add with a plugin such as the WordPress.org-maintained Two Factor plugin or a security suite.
Many managed hosts add a server or network firewall, malware scanning and cleanup. Ask your host what they cover so you do not pay twice or stack conflicting firewalls.
The four layers of WordPress security
1. Firewall (WAF)
A web application firewall inspects requests and blocks known attack patterns. There are two kinds:
- Endpoint firewalls run inside WordPress on your server. Wordfence describes its firewall as protecting "at the endpoint, enabling deep integration with WordPress". They see WordPress context (users, roles) but still consume your server's resources.
- Cloud or DNS-level firewalls sit in front of your server, so bad traffic is filtered before it arrives. Sucuri's firewall (a paid service) and Cloudflare work this way. They also absorb some traffic spikes, but setup involves DNS changes.
2. Scanning
Scanners compare core files against official versions, look for known malware signatures, and flag changed files. Server-side scanners see files directly; remote scanners, like the free scanner in the Sucuri plugin, check what the public site serves.
3. Hardening and login protection
This covers two-factor authentication, passkeys, login attempt limits, CAPTCHA on login, blocking compromised passwords and disabling features you do not use. Brute-force protection matters because login pages are attacked constantly.
4. Vulnerability alerts and virtual patching
Vulnerability tools match your installed plugins and themes against a database of known issues and alert you. Virtual patching goes a step further, deploying a targeted rule that blocks exploitation of a specific vulnerability until you can update. Patchstack's free plugin alerts you; its paid plans add virtual patching.
How to evaluate a security plugin
- Which layers you need. If your host already runs a firewall and malware scanning, you may only need login hardening and vulnerability alerts.
- Rule and signature freshness. Check whether the free tier gets new firewall rules and signatures immediately or on a delay.
- Maintenance. Check "last updated" and "tested up to". A security plugin that falls behind is a liability.
- Performance impact. Endpoint firewalls and server-side scans use CPU and memory. Test on staging and schedule scans for quiet hours.
- Its own security history. Security plugins are code too; check how quickly past issues were fixed.
- Support and cleanup. Check whether malware removal is included or extra, and how fast the vendor commits to respond.
- Lock-in and uninstall. Some firewalls add an auto_prepend_file setting or .htaccess rules. Make sure uninstalling removes them cleanly, or you can lock yourself out.
Our plugin security article covers how to vet any plugin's code and vendor.
Well-known security plugins
Listed in no particular order. Install bands are from WordPress.org and pricing from each vendor's site, as of October 2026.
| Plugin | Main layers | Active installs (WordPress.org) | Pricing model (vendor site) |
|---|---|---|---|
| Wordfence | Endpoint firewall, malware scan, login security (2FA, passkeys, CAPTCHA) | 5+ million | Free (rules and signatures delayed 30 days); paid tiers with real-time updates |
| Sucuri Security | Audit log, file integrity monitoring, remote malware scan, hardening | 600,000+ | Free plugin; paid platform plans from $229/yr; cloud firewall from $9.99/mo |
| Kadence Security (formerly Solid Security, formerly iThemes Security) | 2FA, brute-force protection, scheduled vulnerability scans | 700,000+ | Free; Pro features sold in Kadence plans, priced per site |
| Patchstack | Vulnerability alerts; virtual patching on paid plans | 60,000+ | Free alerts (needs a Patchstack account); Developer plan $69/mo billed annually; enterprise and host plans by quote |
| All-In-One Security (AIOS) | Firewall rules, login protection, hardening | 1+ million | Free on WordPress.org |
| Jetpack Protect | Vulnerability and malware scanning | 100,000+ | Free; Jetpack Security bundle (Scan with WAF, backups, Akismet) $19.95/mo regular, billed yearly |
| Limit Login Attempts Reloaded | Brute-force login protection | 1+ million | Free on WordPress.org |
| Two Factor | Two-factor authentication, maintained by WordPress.org contributors | 100,000+ | Free |
Notes: Wordfence's 30-day delay for free users is stated on its WordPress.org listing; we could not load its pricing page to confirm current paid prices, so check wordfence.com directly. Sucuri's plan tiers (Basic $229, Pro $339, Business $549 per year) differ by scan frequency and malware-removal response time, per its signup page. Sucuri says its firewall is not included free in the plugin. Kadence Security's WordPress.org listing still uses the better-wp-security slug, so existing installs update in place. Patchstack's pricing page says personal plans are available through partners and resellers.
Common mistakes
- Stacking suites. Two firewalls or two scanners can block each other, double server load and produce confusing alerts.
- Relying on a plugin instead of updating. A firewall reduces risk during the window before a patch; it does not make outdated plugins safe.
- Ignoring alerts. Vulnerability notices only help if someone acts on them. Patchstack reported a weighted median time to first exploit of 5 hours for heavily targeted vulnerabilities.
- Leaving inactive plugins installed. Their files can still be reached and exploited. Delete what you do not use.
- No backups. If a site is compromised, a clean, recent, off-site backup is the fastest way back. See the backup plugins guide.
A practical security baseline
- Enable automatic minor core updates (default) and turn on auto-updates for low-risk plugins; review the rest weekly. See WordPress updates and auto-updates.
- Require two-factor authentication for every administrator and editor.
- Add brute-force protection and a firewall: from your host, a cloud service or one security plugin.
- Subscribe to vulnerability alerts for the plugins and themes you run.
- Set DISALLOW_FILE_EDIT and remove unused plugins, themes and admin accounts.
- Keep off-site backups and test a restore.
The full checklist is in our WordPress security guide, and if you are dealing with an active infection, start with what to do when WordPress is hacked.
What to do when a vulnerability alert arrives
- Check the details. Note the affected versions, whether the flaw needs a logged-in user, and whether it is reported as exploited.
- Update if a fix exists. Take a backup, update, and check the affected feature. For critical issues, update the live site first and test right after.
- If no fix exists, deactivate the plugin if you can live without it, or rely on a firewall or virtual patching rule while you wait.
- Look for signs of compromise if the flaw was exploitable before you patched: new admin users, changed files, unknown scheduled tasks or redirects.
- Record what you did, so the next person knows the history of the site.
Our guide to security patching and plugin updates goes deeper on update workflows.
Conclusion
Choose security tools by layer, not by brand. Decide what your host already covers, then fill the gaps with one main plugin or service: a firewall, scanning, login hardening and vulnerability alerts. Keep everything updated, act on alerts quickly and keep tested backups. If you would rather have someone else watch this, eSEOspace includes updates, monitoring and backups in its website maintenance services. More guides are in our WordPress hub.
Frequently asked questions
Do I need a security plugin if my host has a firewall?
Possibly not a full suite. You may still want two-factor authentication, login protection and vulnerability alerts, which host firewalls often do not provide. Avoid running a second firewall that duplicates your host's.
Is Solid Security the same as Kadence Security?
Yes. The plugin formerly called iThemes Security, then Solid Security, is now Kadence Security. Its 10.0.0 changelog notes the rebranding, and the WordPress.org slug stayed the same.
Is the free version of Wordfence enough?
It includes the firewall, scanner and login security features, but its WordPress.org listing says new firewall rules and malware signatures reach free users 30 days after Premium. Whether that is acceptable depends on your risk and what else protects the site.
What is virtual patching?
A firewall rule that blocks attempts to exploit a specific known vulnerability, so a site is protected before the plugin itself is updated. Patchstack offers it on paid plans.
How many WordPress vulnerabilities are in core?
Very few. Patchstack's 2026 report counted 6 core vulnerabilities in 2025, compared with 91% of 11,334 total in plugins and 9% in themes.
Put this into action with eSEOspace
We help businesses grow with website design that actually performs. Explore the services behind this guide:
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!





