Software Alternatives & Startups

Officially verified details WordSec

All-in-one WordPress security: WAF, scanner, 2FA & more.

WordSec

WordSec Reviews and Details

This page is designed to help you find out whether WordSec is good and if it is the right choice for you.

Screenshots and images

  • Firewall //
    2026-08-06
  • Malware Scanner //
    2026-08-06
  • IP & Geo Blocking //
    2026-08-06
  • Login Security //
    2026-08-06
  • Live Traffic //
    2026-08-06
  • Supply Chains //
    2026-08-06
  • Audit Log //
    2026-08-06
  • Alarm //
    2026-08-06

Features & Specs

  1. Firewall

    Inspect every request, write your own rules, and harden WordPress with one-click toggles. - Multi-condition custom rule builder with regex and wildcard matching - Built-in rules across the major attack categories (SQL injection, XSS, path traversal, PHP and command injection, and more) - WAF learning and active modes, bot blocking and security headers - 25+ one-click hardening toggles for wp-config access, author enumeration, REST API and more - Optional Extended Protection: pre-WordPress request inspection via an auto_prepend_file bootstrap - Endpoint rate limiting, XML-RPC protection and detailed firewall logs

  2. Scanner

    A seven-stage scanning system that examines files, the database and scheduled tasks. - Malware detection rules (synced from the WordSec service) based content scanning - WordPress core, plugin and theme file-integrity verification (via the WordPress.org API) - Scheduled scans with batch processing to avoid timeouts - One-click quarantine and restore, with complete scan history

  3. Login Security

    - Role-based two-factor authentication (RFC 6238 TOTP), no external library required - Three CAPTCHA providers (reCAPTCHA, hCaptcha, Cloudflare Turnstile) plus a built-in math CAPTCHA - Brute-force protection with progressive lockout and honeypot traps - Leaked-password checking (Have I Been Pwned, k-anonymity) and Argon2 password enforcement - Session management and a custom login page designer

  4. Live Traffic

    - Real-time request logging (IP, URI, method, status, response time) - Safe request and response inspection with automatic bot detection - Exclusion filtering by role, IP, country or URI, with CSV export

  5. Blocking

    - Country and continent allow or block lists - Single IP and CIDR range blocking, temporary or permanent, with allow-list support - Automatic abuse protection and endpoint rate limiting - Custom block messages

  6. Supply Chain

    - Reputation scoring for every installed plugin and theme - Known-vulnerability alerts (data from the WordSec service) for core, plugins, themes and PHP - Abandoned plugin and theme detection - Update-integrity verification with automatic backups and a full SBOM inventory

  7. Audit Log

    - Complete activity tracking across 11 object types and 14 actions - Content, plugin, theme and setting changes - Fast filtering and one-click export

  8. Alarm

    - 36 event types across six categories - Delivery by Email, Telegram or Slack - Basic, Advanced and Full alert modes

Badges

Promote WordSec. You can add any of these badges on your website.

SaaSHub badge
Show embed code

Videos

We don't have any videos for WordSec yet.

Do you know an article comparing WordSec to other products?
Suggest a link to a post with product alternatives.

Suggest an article

WordSec discussion

Log in or Post with

Is WordSec good? This is an informative page that will help you find out. Moreover, you can review and discuss WordSec here. The primary details have been verified within the last quarter. So they could be considered up to date. If you think we are missing something, please use the means on this page to comment or suggest changes. All reviews and comments are highly encouranged and appreciated as they help everyone in the community to make an informed choice. Please always be kind and objective when evaluating a product and sharing your opinion.