Aug 162014

Best WordPress Security Plugins report, provides information on the following security plugins like iTheme Security, All In One WP Security & Firewall and more.

Last Updated: September 19, 2020

Latest News: Updated the documentation.

Security is one of the most important factor for websites. WordPress already keeps the platform secured with regular updates, patches and improvements to the CMS. However you the website owner, user or site administrator also need to make sure the site is secured.

In this post you will see a list of the most common and some security plugins I recommend for any WordPress website. Some of these plugins might not work in your environment, so make sure you carry out plenty of tests before you go ahead and install a security plugin and find yourself locked out of your site. Or in some case you might see the famous screen of death “the blank page”. I also recommend that you create a backup before you go ahead and install a security plugin. The following link wordpress-backup-plugins can help you choose the right backup plugin or system.

Information: Always remember to try and not have too many plugins added to your website or blog. The more plugins you add the more request and processing resources it requires to use from your server!!!

Please read the following link Help Support WordPress Plugins And Themes Developers to help support the developers.

Best WordPress Security Plugins



iTheme Security (formerly Better WP Security)

Helps protect your WordPress installation from attackers. Hardens standard WordPress security by hiding vital areas of your site, protecting access to important files via htaccess, preventing brute-force login attempts, detecting attack attempts, and more.

Important: This plugin has been downloaded more than 13 million times. There are more than 900 thousand active installations.

You can check my tutorial WordPress iTheme Security Tutorial. It will help you understand and configure the plugin.

Version 7.8.0 | By ithemes, Chris Wiegman, Chris Jean, Matt Danner | Last Updated: August 14, 2020 | Compatible up to WordPress 5.5



 BulletProof Security

Website Security Protection: BulletProof Security protects your website against XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection hacking attempts. One-click .htaccess WordPress security protection. Protects wp-config.php, bb-config.php, php.ini, php5.ini, install.php and readme.html with .htaccess security protection. One-click Website Maintenance Mode (HTTP 503). Additional website security checks: DB errors off, file and folder permissions check… System Info: PHP, MySQL, OS, Server, Memory Usage, IP, SAPI, DNS, Max Upload… Built-in .htaccess file editing, uploading and downloading.

Important: This plugin has been downloaded more than 2 million times.

Version 4.0 | By Edward Alexander | Last Updated: April 21, 2020 | Compatible up to WordPress 5.4.2



All In One WP Security & Firewall

A comprehensive, user-friendly, all in one WordPress security and firewall plugin for your site.

Important: This plugin has been downloaded more than 10 million times. There are more than 800 thousand active installations.

You can check my tutorial  All In One WP Security Firewall to help you configure this plugin.

Version 4.4.4 | By Tips and Tricks HQ, wpsolutions, Peter Petreski, Ruhul Amin, mbrsolution, Chesio | Last Updated: June 21, 2020 | Compatible up to WordPress 5.4.2



Sucuri Scanner

Sucuri Inc. is a globally recognized authority in all matters related to website security, with specialization in WordPress Security.

Important: This plugin has been downloaded more than 3 million times. There are more than 600 thousand active installations.

Version 1.8.24 | By Daniel Cid | Last Updated: February 12, 2020 | Compatible up to WordPress 5.3.2


Intermediate To Advanced WordPress Security Plugins



Wordfence Security

Wordfence Security is a free enterprise class security plugin that includes a firewall, virus scanning, real-time traffic with geolocation and more.

Important: This plugin has been downloaded more than 105 million times. There are more than 3 million active installations.

Version 7.4.9 | By Mark Maunder | Last Updated: July 9, 2020 |Compatible up to WordPress 5.4.2



Shield Security

Don’t Leave Your Site At Risk
If your site is vulnerable to attack, you’re putting your business and your reputation at serious risk. Getting hacked can mean you’re locked out of your site, client data stolen, your website defaced or offline, and Google will penalise you.

Important: This plugin has been downloaded more than 7 million times.

Version 9.0.4 | By iControlWP | Last Updated: June 14, 2020 | Compatible up to WordPress 5.4.2



Anti-Malware Security and Brute Force Firewall


  • Run a Complete Scan to automatically remove known security threats and backdoor scripts.
  • Firewall block SoakSoak and other malware from exploiting Revolution Slider and other plugins from known vulnerabilites.
  • Upgrade vulnerable versions of timthumb scripts.
  • Download Definition Updates to protect against new threats.

Important: This plugin has been downloaded more than 2 million times. There are more than 200 thousand active installs.

Version 4.19.69 | By Eli, Anti Malware Admin | Last Updated: May 21, 2020 | Compatible up to WordPress 5.4.2


Beginner To Intermediate WordPress Security Plugins



Google Apps Login

Simple secure login and user management for WordPress through your Google Apps domain (uses secure OAuth2, and MFA if enabled).

Version 3.4.2 | By levertechadmin, danlester | Last Updated: June 14, 2020 | Compatible up to WordPress 5.4.2


Google Authenticator

Google Authenticator for your WordPress blog.

You can read and follow the instructions in my tutorial Google Authenticator Security WordPress

Ian Dunn has developed an additional plugin Google Authenticator Encourage User Activation that compliments this already great plugin. This plugin allows you to encourage or force users to implement Google Authenticator.

Version 0.52 | By Ivan Kruchkoff | Last Updated: September 16, 2020 Compatible up to WordPress 5.5.1



Two Factor

You might like to check the following tutorial WordPress Two Factor Authentication Core Files.

Version 0.7.0 | By Ivan Kruchkoff | Last Updated: August 27, 2020 | Compatible up to WordPress 5.5



Miniorange 2 Factor Authentication

Note: The plugin is GDPR Compliant and supports wide variety of Language Translation

Have a completely Secure login to your WordPress website using this FREE, Simple & very easy to setup plugin. It provides two factor authentication (2FA, MFA) whenever login to your WordPress website ensuring no unauthorised access to your website.

Version 5.4.14 | By miniOrange, twofactor | Last Updated: August 15, 2020 | Compatible up to WordPress 5.5


This list will change from time to time and it will grow with more plugins added. Please keep coming back to review the changes and additions.

If you have a questions please let me know


Best WordPress Plugins For Blogs List:

I have been working in IT since 1999 and I enjoy the challenges it brings me. I love developing websites with WordPress. I spend a lot of time helping out in forums. I have been writing tutorials since 2011. Now I am learning how to manage my own VPS "Virtual Private Server.

 Leave a Reply

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>