WordPress security

Find suspicious changes and strengthen everyday WordPress protection

Review suspicious changes, unsafe settings, login abuse, and other security signals directly in WordPress. Start with local checks, then add connected monitoring and response workflows when Pro becomes available.

Free and Pro available

  • Useful Free plugin
  • Local-first Free workflow
  • No cloud account required for Free
  • Clear Free and Pro boundaries

Problem and solution

See the problem before it becomes harder to manage

Small warnings can point to larger security risks

WordPress security issues often start as small warnings: risky settings, exposed uploads, weak login controls, suspicious file changes, or forms that invite abuse. This product gives owners a local security baseline and a paid path for teams that need shared security policies, cloud-assisted checks, scheduled reports, temporary protection for known vulnerabilities, approved remote task coordination, and incident workflows.

See what matters and what to do next

Web Plura Security Center groups the relevant work into a clearer WordPress workflow with practical next steps.

Start locally and add connected help later

Start locally with Free, then add connected history, monitoring, collaboration, or automation only when those capabilities are available and useful.

Key benefits

What becomes easier

Spot risky changes sooner

Bring suspicious files, configuration weaknesses, login abuse, and administrator drift into one review.

Reduce common attack paths

Apply practical login, firewall, upload, permission, and exposure controls from WordPress.

Coordinate recurring protection

Add policy oversight, vulnerability intelligence, reports, and incident follow-up as the security workload grows.

Review security locally

Start with a local security review before committing to a paid workflow.

Workflow

How the workflow fits together

  1. 1.Install the plugin and run an initial site check from WordPress.
  2. 2.Review plain-priority findings so you know what needs attention first.
  3. 3.Use the free local baseline for everyday visibility.
  4. 4.Upgrade to a cloud plan when you need deeper scanning, reporting, and team response.

Free version

Build a useful local security baseline

Choose Free for practical local security scans, login protection, file-change review, firewall controls and WordPress-native incident visibility without a cloud account.

Detect and protect

Find common WordPress security risks and act locally.

Suspicious-file scanning

Check files and recent changes for malware indicators so unusual activity is easier to investigate.

Login and firewall controls

Rate-limit repeated requests and temporarily block abusive traffic to reduce routine login pressure.

Access and exposure review

Find risky administrators, permissions, uploads, debug logs, archives, XML-RPC, and REST exposure.

Pro version

Coordinate monitoring and response with Pro

Pro includes everything in Free and adds the connected capabilities below. Choose Pro if your team needs connected policy, vulnerability intelligence, scheduled reporting and cloud-assisted incident workflows.

Monitor and respond

Keep security posture consistent across time and sites.

Managed security policies

Apply consistent protection expectations across connected sites instead of configuring each site independently.

Vulnerability and patch visibility

See relevant vulnerability intelligence and virtual-patch status so urgent exposure receives attention sooner.

Scheduled reports and incidents

Review recurring security reports and coordinate incident follow-up with a retained response trail.

Free vs Pro

Choose the workflow that fits today

Choose Free for practical local security scans, login protection, file-change review, firewall controls and WordPress-native incident visibility without a cloud account. Choose Pro if your team needs connected policy, vulnerability intelligence, scheduled reporting and cloud-assisted incident workflows.

Web Plura Security Center - Login Protection, Access Safety, and Cloud Policy Free and Pro feature matrix
FeatureFreePro
Free features
Suspicious-file scanningCheck files and recent changes for malware indicators so unusual activity is easier to investigate.YesIncluded in Free.YesIncluded in Pro.
Login and firewall controlsRate-limit repeated requests and temporarily block abusive traffic to reduce routine login pressure.YesIncluded in Free.YesIncluded in Pro.
Access and exposure reviewFind risky administrators, permissions, uploads, debug logs, archives, XML-RPC, and REST exposure.YesIncluded in Free.YesIncluded in Pro.
Local security reviewsLocal security reviews for suspicious file changes, public-risk indicators, and risky configuration.YesIncluded in Free.YesIncluded in Pro.
Form Abuse & Lead Security advisorForm Abuse & Lead Security advisor for form plugins, lead pages, outgoing email delivery, privacy-page status, plugin updates, and risky form markers.YesIncluded in Free.YesIncluded in Pro.
Firewall rulesFirewall rules with rate limiting and temporary blocking controls.YesIncluded in Free.YesIncluded in Pro.
Incident and audit tracking inside the WordPress adminIncident and audit tracking inside the WordPress admin panel.YesIncluded in Free.YesIncluded in Pro.
Email notification supportEmail notification support for new local issues.YesIncluded in Free.YesIncluded in Pro.
Local baseline checks that remain availableLocal baseline checks that remain available without a paid plan or Web Plura Cloud connection.YesIncluded in Free.YesIncluded in Pro.
Pro features
Managed security policiesApply consistent protection expectations across connected sites instead of configuring each site independently.NoPro feature only.YesIncluded in Pro.
Vulnerability and patch visibilitySee relevant vulnerability intelligence and virtual-patch status so urgent exposure receives attention sooner.NoPro feature only.YesIncluded in Pro.
Scheduled reports and incidentsReview recurring security reports and coordinate incident follow-up with a retained response trail.NoPro feature only.YesIncluded in Pro.
Cloud-assisted checks and monitoringCloud-assisted checks and monitoring when the active plan allows them.NoPro feature only.YesIncluded in Pro.
Scheduled reports and incident workflowsScheduled reports and incident workflows for teams that need recurring oversight.NoPro feature only.YesIncluded in Pro.

Who it helps

Built for real WordPress workflows

Site owners

Use Free to establish a local security baseline; add Pro when recurring oversight becomes important.

WordPress maintainers

Review file, user, configuration, and update risks before maintenance handoffs.

Agencies and security teams

Use Pro for consistent policies, scheduled reports, and incident coordination across client sites.

Common use cases

Practical ways to use this product

Take over a WordPress site

Run a first-pass WordPress security review after taking over a site or before handing it to a client.

Investigate suspicious changes

Check suspicious file and configuration signals without requiring a cloud account.

Prepare for a launch

Review form-abuse and administrator-risk posture before campaigns, launches, or support handoffs.

Coordinate recurring protection

Move business-critical sites to Pro when scheduled reporting, policy sync, virtual patching, and incident workflow support are required.

Trust and control

Start free. Add Pro when your workflow grows.

Free is the local foundation. Pro extends that workflow without taking away the Free capabilities that already work on the site.

  • Free remains useful without a subscription.
  • Local data is not synchronized without connection and consent.
  • Pro-only cloud services pause if access ends; Free local work remains available.
  • Cloud account sign-in stays on hosted Web Plura pages, not inside WordPress password fields.
  • Admins stay in control of when cloud features are connected.
  • The plugin is designed for WordPress-native security and permission behavior.

Availability and requirements

Free and Pro available

The Free plugin and paid Pro workflow are available now.

What you need

Free runs in the supported WordPress workflow described here. Connected Pro services require Web Plura Cloud and an available Pro plan.

  • Cloud services are used only when cloud-backed features are connected.
  • Product and policy pages explain how security workflows are handled.

Privacy and data handling

The plugin helps you start from your WordPress dashboard. Web Plura cloud plans add deeper protection, reporting, and team coordination when you need more.

  • Cloud account sign-in stays on hosted Web Plura pages, not inside WordPress password fields.
  • Admins stay in control of when cloud features are connected.
  • The plugin is designed for WordPress-native security and permission behavior.
  • Public messaging separates free plugin capability from paid cloud plans.

FAQ

Questions before you install or connect

Is the Free version fully usable?

Yes. Choose Free for practical local security scans, login protection, file-change review, firewall controls and WordPress-native incident visibility without a cloud account.

Does the Free version require Web Plura Cloud?

No. The verified Free workflow runs locally in WordPress without a cloud account or paid subscription.

What does Pro add?

Choose Pro if your team needs connected policy, vulnerability intelligence, scheduled reporting and cloud-assisted incident workflows.

Can I keep using Free without a subscription?

Yes. The local Free workflow remains available. Pro services are separate and add connected capabilities when they are available and useful.

Where is the data stored?

Free findings and incident history stay in WordPress. Connected Pro services receive only the information required for an approved cloud check or report.

Does the plugin make changes automatically?

No. Security Center identifies risks and provides controls, but it does not promise automatic malware removal or complete protection. The administrator decides what action to take.

Can agencies or multiple sites use it?

Use Pro for consistent policies, scheduled reports, and incident coordination across client sites.

Which platforms or integrations are supported?

Free works with WordPress security, login, form, user, file, and permission signals. Pro adds supported Web Plura Cloud monitoring and response workflows for active plans.

Next step

Start with Security Center Free

Install Free and run a local security review. Add Pro later when recurring monitoring, shared policy, reporting, or response coordination becomes necessary.