Basic is where the plugin stops
reporting and starts preventing.
Free tells you what happened. Basic, at $4.99 a month, adds the layer that stops much of it happening: one-click hardening, brute-force lockout, two-factor authentication, real-time file monitoring, quarantine, and an audit log you can actually reconstruct an incident from.
Best for: A site that needs to stop the common attacks and know the moment a file changes, without committing to a year up front.
Detection is not the same thing as defence
The free plugin is a good scanner. A scanner is a smoke alarm: it is genuinely valuable and it does nothing whatsoever to stop the fire. Basic is the first plan that closes doors rather than describing what came through them.
One-click hardening applies the configuration changes that remove whole categories of attack: disabling the file editor so a stolen admin session cannot write PHP straight into a theme, controlling XML-RPC, stopping directory listing, suppressing version disclosure and blocking user enumeration. Each toggle explains what it changes and what it might break before you switch it on, because security advice that hides its costs gets switched off again a week later.
Login protection covers the attack that actually happens to ordinary WordPress sites, at volume, every day. Brute-force lockout stops repeated credential guessing. Google reCAPTCHA filters automated form submission. Two-factor authentication with TOTP means a leaked or reused password is no longer sufficient on its own, which matters more than any other single control on this list.
SHA-256 baselines, and why the timing matters
Free checks integrity on a schedule. Basic maintains SHA-256 baselines and watches for change as it happens, which changes what you can do about it. The gap between compromise and discovery is where the damage compounds: card details are skimmed, spam is indexed, your domain reputation is spent, and search engines start showing a warning next to your name.
A daily scan means a payload can operate for the better part of a day before anyone knows. Real-time monitoring narrows that to the time it takes you to read a notification, which is why email notifications arrive at the same tier rather than a higher one. A monitor nobody is told about is a log file.
Quarantine and restore comes in here too, and it is the feature that makes acting on an alert reasonable. Suspicious files can be isolated so they cannot execute, and restored if the call was wrong. Without it, responding to a finding means deleting something from a live site and hoping. Quarantine makes the safe action reversible, which means people actually take it.
The record you only value once
The security audit log records what happened on the site and who did it: logins and failures, user and role changes, plugin and theme activity, settings changes, file events.
Nobody buys a plugin for an audit log. Then a site is compromised, and the only questions that matter are which account was used, when it was first used, and what else it touched, and without a log those questions have no answers. You are left guessing at scope, which means either over-reacting and rebuilding everything, or under-reacting and leaving the way back in.
It also settles the ordinary disputes that are not attacks at all. A plugin was deactivated and the site broke; a setting changed and nobody remembers changing it; a user gained a role they should not have. On a site with more than one administrator, the log is worth its price for that alone.
Basic deliberately has no AI layer
Basic is a protection and logging tier, not a detection upgrade. The LLM scanner, plain-English AI explanations, the Security Intelligence API, the firewall and one-click removal are all Pro.
The plugin backend enforces this rather than merely advertising it: a Basic site is provisioned as a plan type that does not have AI scanning enabled, so the boundary is real. We would rather write that plainly than have you buy Basic expecting the AI layer.
Basic bills monthly, and that is often the actual reason to choose it. If you are not ready to commit to a year, Basic gets you hardening, login protection, real-time monitoring, quarantine and the audit log now, and you can move to Pro whenever it makes sense.
Everything included in Basic
Read from the same definition the checkout and the plugin backend use, so this list cannot drift away from what you actually get.
- Signature malware scanning
- Heuristic analysis
- Database malware scanning
- One-click cleanup of infected database records
- File integrity monitoring
- Targeted scan modes: core, plugins, themes or uploads
- Scheduled scans, daily or weekly
- On-demand scans (3 per day)
- IP block lists and allow lists
- Country-level IP blocking
- Security score and A–D risk grade
- Bundled malware definitions, updated with the plugin
- One-click security hardening
- Brute-force lockout, 2FA and reCAPTCHA
- Real-time file monitoring with SHA-256 baselines
- File quarantine and restore
- Security audit log
- Email security notifications
Not included in Basic
- LLM scanning: reasoning about code intent, Pro and above
- Plain-English AI explanations on every finding, Pro and above
- Web application firewall, Pro and above
- One-click malware removal, Pro and above
How the plans differ
| Basic | Free | Pro | Agency | |
|---|---|---|---|---|
| LLM scanning: reasoning about code intent | No | No | Yes | Yes |
| Database malware scanning | Yes | Yes | Yes | Yes |
| Web application firewall | No | No | Yes | Yes |
| One-click malware removal | No | No | Yes | Yes |
| Real-time file monitoring with SHA-256 baselines | Yes | No | Yes | Yes |
| Security audit log | Yes | No | Yes | Yes |
| Multi-site dashboard | No | No | Yes | Yes |
| White-label client reports | No | No | No | Yes |
| Price | $4.99 per site, per month | $0 forever, one site | $99 per site, per year | $149 per site, per year, before volume discount |
Basic questions
What does Basic add over Free?
One-click hardening, brute-force lockout, two-factor authentication, reCAPTCHA on login, real-time file monitoring with SHA-256 baselines, file quarantine and restore, the security audit log, and email notifications.
Does Basic include AI scanning?
No, and that is by design. The LLM scanner and AI explanations are Pro. The plugin backend provisions Basic sites as a plan type with AI scanning disabled, so the limit is enforced rather than assumed.
Does Basic have a firewall?
No. The WAF and virtual patching are Pro features. Basic does include the IP block and allow lists and country-level blocking that ship in the free plugin.
Can I switch from Basic to Pro?
Yes, at any time. Your scan history, settings and hardening profile carry over. You are changing what the licence covers, not moving to a different product.
Why is Basic monthly and Pro annual?
Basic exists for people who want protection without an annual commitment. Pro is priced annually because that is where the value sits: it works out at roughly a fifth of Basic's monthly rate per month.
Is the Premium add-on a separate install?
Yes. The core plugin comes from wordpress.org and the Premium add-on installs alongside it, then enables features according to your licence. Keeping them separate is what lets the free plugin stay genuinely free rather than becoming a locked shell.
Start free, upgrade to Basic when it earns it
The free scan tells you whether you have a problem. Everything above it is about how much of the fixing you want to do yourself.
No credit card for the free tier. Upgrade from inside the dashboard when you want to.