Security
Protect your WordPress site with security hardening modules. Login protection, version hiding, XML-RPC controls, and more.
16 modulesThese modules help you lock down your WordPress installation by hiding sensitive information, controlling access, and adding protection against common attacks. Each module works independently — enable only what you need.
Activity Log
Track user actions and changes across your WordPress site
Disable All Updates
Completely disable WordPress core, plugin, and theme updates
Disable Application Passwords
Remove the Application Passwords feature from WordPress
Disable Author Archives
Disable author archive pages to prevent username discovery
Disable File Editing
Remove the theme and plugin editor from WordPress admin
Disable REST API
Block REST API access for non-logged-in users
Disable XML-RPC
Turn off XML-RPC to prevent brute force and DDoS attacks
Force SSL Admin
Force HTTPS for all admin and login pages
Hide WP Version
Remove WordPress version from public view
IP Whitelist/Blacklist
Control site access by IP address
Limit Login Attempts
Protect against brute force attacks by limiting failed logins
Login ID Type
Control whether users log in with username, email, or both
Obfuscate Author Slugs
Hide usernames in author URLs with random hashes
Password Protection
Password-protect your entire site from public view
Security Headers
Add HTTP security headers to protect against common attacks
Username Blacklist
Block common and dangerous usernames from registration
Get access to all 147 modules with a single license