InMotion Hosting Support Center
This is archived and no longer maintained. Any information contained in this article may be out of date.

There are many different security plugins available for WordPress. Below are the most recommended plugins and a brief explanation of the plugin from the developers.

Wordfence Security

Plugin site URL:
Notes from the plugin developer: "Wordfence Security is a free enterprise class security plugin that includes a firewall, anti-virus scanning, malicious URL scanning and live traffic including crawlers. Wordfence is the only WordPress security plugin that can verify and repair your core, theme and plugin files, even if you don't have backups. Wordfence is now Multi-Site compatible."

BulletProof Security

Plugin site URL:
Notes from the plugin developer: "WordPress Website Security Protection: BulletProof Security protects your WordPress website against XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection hacking attempts. One-click .htaccess WordPress security protection. Protects wp-config.php, bb-config.php, php.ini, php5.ini, install.php and readme.html with .htaccess security protection. Security Logging. HTTP Error Logging."

Better WP Security

Plugin site URL:
Notes from the plugin developer: "Better WP Security takes the best Wordpress security features and techniques and combines them in a single plugin thereby ensuring that as many security holes as possible are patched without having to worry about conflicting features or the possibility of missing anything on your site."

MVIS Security Center

Plugin site URL:
Notes from the plugin developer: "Official Launch The beta phase is officially over and we are very happy with the feedback and reception so far! Thanks for all your support! We have implemented a coupon system, so upon subscribing multiple sites you will receive coupons that can be entered to activate any other plugin. This allows you to share subscription costs and get a juicy discount! Security has never been this simple!"

Login Security Solution

Plugin site URL:
Notes from the plugin developer: "A simple way to lock down login security for multisite and regular WordPress installations. Blocks brute force and dictionary attacks without inconveniencing legitimate users or administrators Tracks IP addresses, usernames, and passwords Monitors logins made by form submissions and auth cookies If a login failure uses data matching a past failure, the plugin."

Secure Image Protection

Plugin site URL:
Notes from the plugin developer: "Insert Secure Image Pro encrypted images to pages and posts from your WordPress page editor that are supported across all web browsers on all operating systems, ie: Windows, Mac and Linux. Hand-held devices that can use Java will also be supported. Easy install. Upload and embed encrypted images using WordPress native media tools."

Simple Security

Plugin site URL:
Notes from the plugin developer: "Simple Security Plugin for WordPress is an Access Log to track Logins and Failed Login Attempts for the admin area of your WordPress Website You can add a widget to the admin dashboard for logins and failed login attempts. Upgrade to Simple Security Ultra for advanced features including: Configurable email alert notifications when selected conditions are met."

Security Ninja Lite

Plugin site URL:
Notes from the plugin developer: "Visit Security Ninja's homepage for more details, FAQ and documentation. perform numerous security tests with one click check your site for security vulnerabilities and holes take preventive measures against attacks don’t let script kiddies hack your site prevent 0-day exploit attacks more test coming daily."

User Name Security - By SeoMix

Plugin site URL:
Notes from the plugin developer: "WordPress automaticaly uses User login to fill in User Display Name. WordPress also allows everyone to use the same value for Nickanme, Display Name and Login. A hacker may use this information to find your login. And the body_class function also shows to everyone your User ID and Nicename ont author pages. Once activated, User Name Security will prevent WordPress from showing those informations."

Look-See Security Scanner

Plugin site URL:
Notes from the plugin developer: "Look-see Security Scanner is a relatively quick and painless way to locate the sorts of file irregularities that turn up when a site is hacked. This is broken down into multiple searches: Verify the integrity of all core WordPress files; Search wp-admin/ for unexpected files; Search wp-includes/ for unexpected files; Search wp-content/uploads/ for hidden PHP scripts;."

IOSEC HTTP Anti Flood/DoS Security Gateway Module

Plugin site URL:
Notes from the plugin developer: "This module provides security enhancements against (HTTP) Flood & Brute Force Attacks for Wordpress. Massive scanning tools (like vulnerability scanners), HTTP Flood tools can be blocked or detected by this module. This module can be integrated with htaccess, any firewall, iptables or etc. via "banlist" file."

Secure Folder wp-content/uploads

Plugin site URL:
Notes from the plugin developer: "This is plugin will put empty index.html on every folders on wp-content/uploads to prevent content theft."

Transparent Secured Images

Plugin site URL:
Notes from the plugin developer: "This plugin will use jQuery and JavaScript, as well as CSS3, to secure your images a little bit more. NOTE: It is NOT possible to completely secure your images since all browsers have to get them in order to show them your users, but we do a little approach to secured pictures. The plugin will replace your image with a transparent image and set your image, you want to show to the user, as background."

All In One WP Security & Firewall

Plugin site URL:
Notes from the plugin developer: "WordPress itself is a very secure platform. However, it helps to add some extra security and firewall to your site by using a security plugin that enforces a lot of good security practices. The All In One WordPress Security plugin will take your website security to a whole new level. This plugin is designed and written by experts and is easy to use and understand. It reduces security risk by checking for vulnerabilities, and by implementing and enforcing the latest recommended WordPress security practices and techniques."

Related Questions

Here are a few questions related to this article that our customers have asked:
Web site hack which will be better Wordfence or bollet proof
Would you like to ask a question about this page? If so, click the button below!
Ask a Question

Support Center Login

Our Login page has moved, Click the button below to be taken to the login page.

n/a Points
2014-09-14 3:03 am

Do you recommend the in the order in which you listed them? -- i.e. WordFence is no. 1 on your list? Are there any that you think are simpler for "regular people" to manage, but still give good protection. I know that for some of these plugins, there are some dangerous settings! Thanks.

43,761 Points
2014-09-15 8:29 am
Hello Susan,

They are not listed in order of preference, but WordFence was one of the better ones. As for which one is easier to use, that is entirely up to the individual so feel free to see which one you are more comfortable with.

Kindest Regards,
Scott M
n/a Points
2014-05-17 8:30 pm

Do you need to install more than one? I was thinking of installing the All In One WP with the  Wordfence security plugins. Bad Idea?

11,186 Points
2014-05-19 8:42 am
It is typically a good idea to only install one of these as multiple installations of different security plugins can cause unexpected results.
11,186 Points
2014-03-04 12:07 pm
As this is indeed a great plugin to use, I have added it to our list.
n/a Points
2014-03-04 3:54 am


Is there any chance that you could please include the All In One WP Security & Firewall plugin on your "recommended-security-plugins" page?

Post a Comment

Email Address:
Phone Number:

Please note: Your name and comment will be displayed, but we will not show your email address.

6 Questions & Comments

Post a comment

Back to first comment | top

Need more Help?


Ask the Community!

Get help with your questions from our community of like-minded hosting users and InMotion Hosting Staff.

Current Customers

Chat: Click to Chat Now E-mail:
Call: 888-321-HOST (4678) Ticket: Submit a Support Ticket

Not a Customer?

Get web hosting from a company that is here to help. Sign up today!