EN / ZH
A Roundup of Plugins to Improve WordPress Security

Plugin 1: WordFence Security

WordFence Security Cover

Features:

  1. Uses the Falcon Engine to dramatically boost site speed.
  2. Blocks unknown attackers in real time.
  3. Employs two-factor authentication (password + phone verification).
  4. Built-in firewall to prevent common security threats like malicious scans.
  5. Can restore maliciously modified files.
  6. Scans for backdoors and vulnerabilities.
  7. Monitors DNS security to prevent unauthorized DNS modifications.

Plugin download page: https://wordpress.org/plugins/wordfence


Plugin 2: Exploit Scanner

Exploit Scanner Cover

Features:

  1. Detects malicious code on your site.
  2. Identifies exploitable vulnerabilities.
  3. Checks database table security.

Plugin download page: https://wordpress.org/plugins/exploit-scanner


Plugin 3: Sucuri Security - Auditing

Sucuri Security - Auditing Cover

Features:

  1. Security activity auditing.
  2. File integrity monitoring.
  3. Remote malware scanning.
  4. Blacklist monitoring.
  5. Effective security hardening features.
  6. Security activity notifications.
  7. Website firewall.

Plugin download page: https://wordpress.org/plugins/sucuri-scanner


Plugin 4: Bluetrait Event Viewer (BTEV)

BTEV Cover

Features: Monitors the following actions:

  1. Password resets.
  2. User deletions.
  3. Site logins.
  4. Site logouts.
  5. Profile updates.
  6. Attachment uploads.
  7. User registrations.
  8. Theme switches.
  9. Comment submissions.
  10. Monitoring of other installed plugins.

Plugin download page: https://wordpress.org/plugins/bluetrait-event-viewer


Plugin 5: WordPress File Monitor Plus

WordPress File Monitor Plus Cover

Features:

  1. Monitors file system changes including additions, deletions, and modifications.
  2. Sends change notifications via email.
  3. Can monitor changes based on hash values, timestamps, and file types.
  4. Runs external scheduled tasks without impacting site performance.

Plugin download page: https://wordpress.org/plugins/wordpress-file-monitor-plus


Plugin 6: AskApache Password Protect

AskApache Password Protect Cover

Features:

  1. Uses built-in Apache server security levels to effectively prevent malicious attacks.
  2. Effectively blocks spam and other malicious requests, saving CPU, memory, and database resources.
  3. Can encrypt wp-admin files to protect the WordPress admin directory.

Plugin download page: https://wordpress.org/plugins/askapache-password-protect


Plugin 7: Sucuri Security - Website Firewall

Sucuri Security - Website Firewall Cover

Features:

  1. Filters all traffic, screening out security threats.
  2. Applies security patches.
  3. Virtual security hardening.
  4. Prevents XSS attacks.
  5. Prevents SQL injection attacks.
  6. Prevents RFI/LFI attacks.
  7. Prevents RCE attacks.
  8. Advanced security access control.
  9. Performance optimization features.

Plugin download page: https://wordpress.org/plugins/sucuri-cloudproxy-waf


Plugin 8: WordPress Sentinel

WordPress Sentinel Cover

Features:

  1. Detects whether WordPress core files (including core, themes, and plugins) have been modified.
  2. Periodically checks and notifies administrators of modified files.

Plugin download page: https://wordpress.org/plugins/wordpress-sentinel


Plugin 9: Login Lockdown

Login Lockdown Cover

Features:

  1. Limits the number of failed login attempts from the same IP within a short period, preventing brute-force password attacks.
  2. Administrators can manually unblock banned IPs from the backend.

Plugin download page: https://wordpress.org/plugins/login-lockdown


Plugin 10: WP Database Backup

WP Database Backup Cover

Features:

  1. Manual/automatic backup and restoration of the WordPress database, enabling quick recovery when issues arise.
  2. Store backups in secure locations such as Dropbox, FTP, Email, etc.

Plugin download page: https://wordpress.org/plugins/wp-database-backup