Seventeen focused features across detection, protection and operations, built to give you real visibility into what's happening inside your site, not just at the perimeter. Every feature ships in the free plugin or unlocks on Pro.
Layered detection methods (signatures, file integrity, heuristics, and LLM-assisted reasoning) that read your files and database the same way an attacker would.
Signature, heuristic and AI-assisted scans of every PHP file, theme and plugin. Runs server-side via WP-Cron.
WordPress malware scanningCompares every core, plugin, theme and custom file against a secure baseline on each scan to flag unauthorized changes, new files or deletions. Review the diff, then approve it or flag it for removal.
WordPress real-time file monitoringLLM reasoning that explains why each suspicious file looks malicious, not just a pattern match.
WordPress AI based scannerContext-aware detection that catches polymorphic malware, encoded payloads, and database-resident threats.
WordPress AI detectionCryptographic hash baselines for core, theme and plugin files. Flags any silent modification.
WordPress file integrityAudits wp_options, post meta and user meta for malicious payloads that never touch the filesystem.
WordPress database scanningActive controls that prevent compromise (login surface reduction, IP-level blocking, hardening rules) plus one-click remediation when something does slip through.
Restores infected core, plugin or theme files from a clean WordPress.org copy in one click. Unrecognized or custom malicious files are safety-checked to confirm they are not in use, then removed on your confirmation.
WordPress one-click malware removalBrute-force protection, login throttling, CAPTCHA and 2FA. Hides /wp-admin from anonymous traffic.
WordPress login securityBlock individual IPs and CIDR ranges on any tier. Pro adds country-level rules and an hourly threat-intel feed.
WordPress IP blockingDisable file editing, hide the WordPress version, restrict XML-RPC and eleven more hardening rules — fifteen toggles in total.
WordPress security hardeningAutomated scans, executive-ready reports, audit-grade logging, and real-time notifications so security never falls off the radar.
Automatically records every important action (admin logins, failed login attempts, logouts, plugin and theme activations, and more), giving you a full timeline of who did what and when.
WordPress audit logReal-time email when an administrator logs in or a plugin, theme or core update becomes available, so vulnerable software never sits unpatched for long. Each alert is sent once per update to keep your inbox clean.
WordPress instant email alertsDaily or weekly scans via WP-Cron on Free; hourly on Pro. Always-on coverage without manual intervention.
WordPress scheduled scanningReal-time email notifications when malware, brute-force attempts, or file changes are detected.
WordPress notificationsPlain-English executive summaries of every scan. Designed for stakeholders, not security analysts.
WordPress AI reportsDashboard to manage allow/block lists, view attempted attacks by IP, and export logs for audit.
WordPress IP managementGranular control over scan depth, notification frequency, hardening rules and detection sensitivity.
WordPress configurationInstall the free plugin in under two minutes. Run your first scan today.