BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Site Lockdown Security icon
Actively maintained Tested up to 7.0.6 #29 in firewall

Site Lockdown Security

Audit, protect, monitor, firewall, and secure WordPress with premium tools at no cost.

Active installs700+100+ tier
Downloads · 30d522▼ -22.4% vs prev. 30d
Rating5/55 reviews
Health score62/100Good
All-time downloads14.4KSince Aug 2025
Support resolved0 / 10% in last 2 months
RequiresWP 5.0PHP 7.4+
Downloads · 7d102▼ -10.5% week over week
Our verdict

Solid choice

Site Lockdown Security is a solid plugin choice in 2026, with a few things worth checking first. It runs on 700+ sites, is rated 5/5 and was last updated 2 months ago, and scores 62/100 on our health check.

  • Small user base (700+ active installs)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

97195293Jul 3Aug 16Sep 30
Yesterday12
Daily average (1y)37
Peak day391Jul 21, 2026
Last 12 months13.6K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Site Lockdown Security stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
firewall #54 966 Best firewall plugins →
malware scanner #34 246 Best malware scanner plugins →
wordpress security #53 10,000 Best wordpress security plugins →

Version adoption

Share of active sites per release.

  • 9.298.4%
  • 6.61.7%

Rating breakdown

★★★★★★★★★★ 5 from 5 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About Site Lockdown Security

From the official readme · v9.2

Description

View full plugin documentation – CLICK HERE

Site Lockdown Security gives WordPress administrators, agencies, developers, and support teams a full security command center without hiding the best tools behind a paid upgrade.

Most WordPress security plugins reserve their strongest features for premium plans: firewalls, file change monitoring, malware scanning, scheduled reports, branded client dashboards, email alerts, login protection, cleanup tools, Cloudflare controls, and advanced hardening. Site Lockdown Security includes those kinds of features in one plugin, and they are not treated as upsells.

Use Site Lockdown Security to audit files, lock down important folders, monitor file changes, verify WordPress core integrity, scan for suspicious code, review abandoned folders, enforce password resets, check public file exposure, monitor redirects, protect logins, review risky software, receive branded email alerts, and run a WordPress-aware firewall with Cloudflare and WooCommerce compatibility controls.

Premium Features Without Premium Upgrade Fees

Site Lockdown Security is built around a simple promise: powerful WordPress security features should not require surprise upgrade fees.

Features that are commonly sold as premium add-ons in other WordPress security plugins are included here, including white label branding, firewall controls, file change monitoring, scheduled security reports, infection scanning, cleanup tools, email notification previews, Cloudflare edge actions, login security, and client-ready branded alerts.

We will never charge for plugin upgrades or future features. When Site Lockdown Security improves, your security tools improve with it.

Key Features

  • Firewall Security with Smart Block, Monitor Only, WooCommerce Safe, and Emergency Shield protection modes
  • WooCommerce-aware firewall handling for checkout, cart, Store API, REST API, AJAX, and payment gateway flows
  • Cloudflare integration with visitor IP detection, API credential testing, edge actions, managed challenges, access rule syncing, and automatic rule cleanup
  • Firewall Event Timeline with searchable and filterable events, severity details, manual IP actions, pagination, and daily summary alerts
  • IP allowlist and blocklist controls for trusted IPs, CIDR ranges, immediate blocks, and manual firewall response management
  • Custom blocked request page with editable title, subtitle, message, button, footer note, and live preview
  • Site Lock to make important WordPress files and folders read-only after a site is clean and stable
  • Watch Dog File Change Monitor with trusted baselines, new/modified/deleted file detection, review actions, scheduled scans, and alerts
  • WordPress Core Check using official WordPress.org checksums to detect modified, missing, unreadable, or unexpected core files
  • Infection Scanner for suspicious patterns, malware indicators, obfuscated code, backdoors, spam injections, and unwanted scripts
  • Scheduled infection scans, security reports, update checks, and digest emails
  • Email notification previews for individual alert types before notifications are sent
  • Branded security emails for plugin updates, file changes, core changes, reports, infection scans, risk reviews, software health, digests, and firewall summaries
  • White Label Branding for agencies, developers, maintenance providers, and support teams
  • White Label import and export to move branding settings between client sites
  • Custom branding controls for plugin text, colors, icons, dark icons, banners, email imagery, and dashboard presentation
  • Folder and file auditing for root files, wp-content, plugins, themes, uploads, .htaccess files, abandoned folders, and suspicious items
  • File preview, download, approve, ignore, delete, include, and bulk actions
  • Cleanup tools for old backups, temporary files, logs, cache files, abandoned folders, and other clutter
  • Plugin Refresher and Theme Refresher to reinstall clean WordPress.org copies of plugins and themes
  • Permissions Check for important WordPress files and folders, including Site Lock-aware status
  • Software Health to identify outdated, abandoned, or potentially risky plugins and themes
  • Risk Review for common local security issues, severity sorting, ignore/include controls, scheduled checks, and alerts
  • Redirect Monitor to test public visitor behavior and alert when visitors may be redirected to an unauthorized website
  • Update Monitor for pending WordPress core, plugin, and theme updates with alerts only when updates are available
  • Password Reset Enforcement by user role, including immediate session logout and secure reset guidance
  • Public File Exposure Check for sensitive backup, log, configuration, database, and metadata files
  • Login Security with protected login URL controls, login limits, activity tracking, session controls, and role-based expiration
  • Security Tools for XML-RPC exposure, author scans, debug exposure, SSL information, blacklist status, file finding, and hardening reviews
  • Setup Guide with progress tracking for recommended protection steps
  • Responsive AJAX admin interface designed for fast navigation and practical daily use

Built For Agencies And Client Support Teams

Site Lockdown Security includes White Label Branding because security work is often delivered as a professional service.

You can brand the admin experience, email imagery, colors, icons, banners, and plugin presentation around your business or client support program. Branding settings can be exported and imported between sites so the same client-ready experience can be reused across multiple installations.

These are the kinds of client-facing tools that are often locked behind agency or premium licenses elsewhere. In Site Lockdown Security, they are included.

Firewall Security

Firewall Security helps protect WordPress from suspicious requests, exploit payloads, scanner signatures, bot signatures, dangerous methods, XML-RPC abuse, REST API exposure, suspicious query strings, and excessive request rates.

Protection modes include Smart Block for high-confidence malicious traffic, Monitor Only for tuning without blocking, WooCommerce Safe for checkout and payment compatibility, and Emergency Shield for active attack situations where public traffic needs to be restricted while administrators retain access.

Firewall Security also includes event logging, severity tracking, searchable timelines, IP allow/block actions, Cloudflare-aware IP detection, Cloudflare edge actions, notification settings, email summaries, and a customizable blocked request page.

Site Lock

Site Lock helps prevent unwanted file additions, injected scripts, unauthorized edits, and accidental deletions by making selected WordPress files and folders read-only.

You can unlock the site when legitimate updates or maintenance are needed, then apply Site Lock again when finished.

Site Lock is useful after a site has been cleaned, audited, updated, or stabilized and you want to reduce the chance of future unexpected file changes.

Watch Dog

Watch Dog creates a trusted baseline of your site files and compares future scans against that baseline.

It reports new, modified, and deleted files so administrators can quickly review changes after updates, maintenance, cleanup work, or suspicious activity.

Watch Dog includes file change monitoring, baseline rebuilding, review actions, scheduled scans, protected baseline storage, and email alerts when changes are detected.

Watch Dog Baseline Storage

Watch Dog stores protected baseline data under:

wp-content/uploads/site-lock/watch-dog/

This keeps baseline data outside the plugin folder so it is not removed during plugin updates.

Sites updating from older versions automatically migrate Watch Dog baseline storage from the previous location:

wp-content/uploads/guard-dog/watch-dog/

After a successful migration, the old storage folder is safely removed and the new Watch Dog storage path remains excluded from Site Lock so baseline files can continue to be updated when needed.

Redirect Monitor

Redirect Monitor tests public site behavior as different visitor types and alerts when visitors may be redirected to an unauthorized website.

It can test the homepage, login page, custom paths, and same-site navigation menu URLs using a focused scan strategy designed to avoid oversized scan jobs.

Core Check

Core Check compares installed WordPress core files against the official WordPress.org checksum API.

It reports modified, missing, unreadable, or unexpected files in WordPress core areas so administrators can review potential core file integrity problems.

Update Monitor

Update Monitor checks pending WordPress core, plugin, and theme updates and sends email alerts only when updates are available.

Infection Scanner

The infection scanner reviews site files for suspicious patterns commonly associated with malware, backdoors, obfuscated scripts, spam injections, and unwanted code.

Scans can be run manually or scheduled, and results can be included in reports and notifications.

Email Notifications

Site Lockdown Security includes configurable email alerts for important security events and scheduled checks.

Supported notification types include:

  • Plugin Update Notification
  • Security Snapshot Digest
  • Scheduled Infection Scan
  • Automated Security Report
  • File Change Notification
  • Core Change Notification
  • Software Health Alert
  • Risk Review Alert
  • Firewall Realtime Alerts
  • Firewall Summary Notifications

Each individual alert includes a preview option so administrators can review the email layout before using it.

The global email notification settings form allows administrators to set the default frequency and recipient email for alerts in one place.

White Label Branding

White Label Branding is one of the standout features of Site Lockdown Security because it lets agencies and service providers present security work under their own brand.

Administrators can customize branding text, colors, icons, dark icons, banners, email imagery, and dashboard presentation.

White Label settings can be exported to a JSON file and imported on another site, making it easier to reuse the same branding across multiple installations.

The Reset Settings option restores the default Site Lockdown theme and brings back the default support contact button when branding is returned to its original values.

Plugin Refresher

Plugin Refresher helps reinstall fresh copies of WordPress.org plugins.

This can be useful when a plugin may have been modified, corrupted, or affected by suspicious files.

Site Lockdown Security uses native WordPress upgrade handling for safer refresh workflows and supports both individual and bulk plugin refreshes.

Theme Refresher

Theme Refresher helps reinstall fresh copies of WordPress.org themes.

It includes version information, update status, WordPress.org availability detection, and support for individual or bulk theme refresh workflows.

Password Reset Enforcement

Require selected user roles to change their password. Active sessions for those users are logged out immediately, and their next valid login attempt shows a clear password-change message with a secure reset link.

Public File Exposure Check

Test whether sensitive backup, log, configuration, database, and metadata files can be accessed publicly from the website URL.

File Finder and Removal Tool

Quickly scan for specific files or identify extensionless files that may require review or removal. No shell commands or complex server tasks are required.

Login Security

Login Security helps protect the WordPress login area with protected login URL controls, login attempt limits, activity tracking, session controls, and role-based expiration options.

Permissions Check

Permissions Check reviews important WordPress files and folders and compares current permissions against recommended values.

It helps identify writable files, risky permissions, and items that may need attention.

When Site Lock protects a file or folder, permissions results account for that protected status.

Software Health

Software Health checks installed plugins and themes for maintenance signals that may indicate abandoned or outdated software.

It helps administrators identify items that may need updates, replacement, removal, or closer review.

Risk Review

Risk Review checks local site risk signals and common security configuration concerns.

It includes severity sorting, ignore/include controls, scheduled checks, and optional email alerts.

Setup Guide

The Setup Guide helps administrators complete recommended Site Lockdown Security settings.

Setup items include Site Lock, scheduled infection scans, automated reports, file change baselines, file change notifications, core change notifications, software health alerts, risk review alerts, firewall settings, login protection, and branded email notifications.

Progress tracking helps administrators see which recommended protection steps are complete.

Installation

  1. Upload the plugin files to the /wp-content/plugins/ directory, or install through the WordPress Plugins screen.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Navigate to Site Lockdown to begin auditing and protecting your site.
  4. Use Site Lock to lock files when your site is clean and stable.
  5. Use Watch Dog > File Change Monitor to create a trusted baseline and scan for file changes.
  6. Use Watch Dog > Core Check to verify WordPress core file integrity.
  7. Use Setup Guide to complete recommended protection steps.
  8. Configure email alerts, scheduled scans, reports, and white label branding as needed.

Frequently asked questions

Why do I need this plugin?

Site Lockdown Security helps you identify leftover folders, suspicious files, unexpected file changes, weak security settings, risky permissions, and WordPress core file issues. It gives administrators better visibility into what exists on the server and what may need review.

Does Site Lockdown Security automatically delete orphaned folders or suspicious files?

No. Site Lockdown Security is built to help you review and take informed action. Files and folders are shown with action buttons so you can decide whether to view, download, ignore, include, delete, approve, refresh, or lock them.

What is Site Lock?

Site Lock makes protected files and folders read-only to help prevent unauthorized changes. You can unlock the site when updates or maintenance are needed, then lock it again when finished.

What is Watch Dog File Change Monitor?

Watch Dog File Change Monitor creates a trusted baseline of your site files. Future scans compare the current site against that baseline and report new, modified, or deleted files.

What is Watch Dog Core Check?

Watch Dog Core Check compares your installed WordPress core files against the official WordPress.org checksum API. It helps detect modified, missing, unreadable, or unexpected files in WordPress core areas.

Does Core Check scan plugins and themes?

No. Core Check only verifies WordPress core files in the WordPress root, wp-admin, and wp-includes areas. Plugins, themes, uploads, and custom content are handled by other Site Lockdown Security tools.

Will Watch Dog work when Site Lock is enabled?

Yes. Watch Dog stores baseline and scan data in its protected uploads storage folder, and Site Lockdown Security allows that required Watch Dog path to remain writable while Site Lock is active.

Where is Watch Dog baseline data stored?

Watch Dog stores protected baseline data under wp-content/uploads/site-lock/watch-dog/. This keeps baseline data outside the plugin folder so it is not removed during plugin updates. Sites updating from older versions automatically migrate baseline storage from the previous wp-content/uploads/guard-dog/watch-dog/ location.

Does Watch Dog email me when file changes or core issues are found?

Yes. File Change Monitor and Core Check each include email alert settings. Emails are sent only when the related scan finds issues.

Can I preview email notifications?

Yes. Individual email alert settings include preview tools so you can review how each notification type will look. Preview layouts are available for plugin update alerts, security snapshot digests, scheduled infection scans, automated security reports, file change notifications, core change notifications, software health alerts, and risk review alerts.

What makes the White Label options unique?

Most WordPress security plugins focus only on scanning, hardening, firewalls, or alerts. Site Lockdown Security also includes built-in White Label Branding, allowing agencies, developers, and support providers to present the security dashboard, branding assets, and notification imagery with their own identity. This makes it especially useful for client management, maintenance services, and branded support programs.

Can I white label Site Lockdown Security?

Yes. Site Lockdown Security includes White Label settings for customizing plugin branding text, colors, icons, dark icons, banners, and email imagery.

Can I move White Label settings to another site?

Yes. Use White Label Export to download the current branding settings as a JSON file. Use White Label Import on another site to upload and apply those settings. Imported settings are validated and sanitized before being saved.

What happens when I reset White Label settings?

Reset Settings restores the default Site Lockdown theme. When the settings return to the default theme, the default support contact button is shown again.

Will this slow down my website frontend?

No. Site Lockdown Security tools run inside the WordPress admin area and do not run on the public frontend during normal page visits.

Does it work on multisite?

Site Lockdown Security is currently designed for single-site WordPress installations. Multisite support may be added in a future release.

Changelog

Cleans up Site Lock progress with section-aware, WordPress-relative paths without pre-counting large file trees or changing MainWP compatibility.

9.2

  • Redesigned Site Lock progress so each batch clearly identifies the active WordPress section, such as Plugins, Themes, Uploads, WordPress Admin, or WordPress Core.
  • Replaced full hosting-account paths with safe WordPress-relative locations such as plugins/example/vendor.
  • Added compact Section, Folders, Files, and Failed progress cards with a cleaner current-location panel.
  • Replaced the misleading file-count percentage with an active progress indicator, avoiding an expensive pre-count on large sites.
  • Applied the same progress experience to Site Lock actions started from the Security tab and the WordPress admin bar.
  • Preserved the lock engine, MainWP bridge files, routes, authentication, requests, and existing response fields.
  • Rebuilt Site Lock permission jobs around compact, resumable depth-first checkpoints whose saved size grows with directory depth instead of total site file count.
  • Added private disk-backed manifests for very large flat directories so hundreds of thousands of filenames are never stored in WordPress options, transients, or PHP memory at once.
  • Added three durable checkpoint paths: non-autoloaded database options, transient/object-cache compatibility storage, and a private temporary-file fallback for restrictive hosting environments.
  • Saved the permission checkpoint before the first chmod operation and after every batch so interrupted requests, proxy timeouts, and browser retries can continue safely.
  • Added stable client job IDs and automatic retry of temporary network, rate-limit, gateway, and server interruptions without starting an unrelated duplicate job.
  • Added adaptive execution-time, operation-count, and memory-pressure limits for both small and large sites.
  • Added a private system-temporary manifest fallback when uploads storage is immutable, remotely mounted, or owned by a different server user.
  • Fixed false programmatic stall detection while a massive directory manifest is still being generated or consumed.
  • Bounded realpath caches, error details, summaries, and stale job cleanup to prevent permission jobs from gradually increasing memory or database usage.
  • Kept protected cache, backup, log, and Site Lock working folders unlocked without recursively rescanning those potentially massive excluded trees after every action.
  • Preserved all MainWP bridge files, routes, authentication, request parameters, and response fields.
  • Fixed the Software Health Action column so row controls remain fully inside the results table at desktop widths.
  • Added a dedicated action-column width, full-width wrapping action buttons, and horizontal table scrolling on narrower admin screens.
  • Preserved all Software Health actions, scanner logic, and MainWP bridge behavior.
  • Reworked the public WordPress and WooCommerce login bot shields to use an adaptive multi-signal score instead of blocking on the first failed check.
  • Prevented fast password-manager submissions, stale cached login forms, one missing token, and legacy honeypot autofill from blocking legitimate users by themselves.
  • Added an autofill-resistant hidden guard field and lightweight browser execution proof while retaining compatibility with older cached login forms.
  • Added same-site request signals, browser user-agent context, and WooCommerce native nonce trust to improve bot confidence without adding CAPTCHAs.
  • Added developer filters to bypass or tune the bot shield for SSO, custom login, and membership integrations.
  • Preserved all existing MainWP bridge routes, authentication, request parameters, and response data.
  • Fixed media upload status so the current year/month destination is tested with a real PHP write-and-delete probe instead of checking only the uploads root.
  • Fixed partial unlocks where nested folders could remain read-only while the parent folder appeared unlocked.
  • Improved Lock All and Unlock All for very large sites by removing the fixed 500-batch completion cap, detecting stalled jobs, reducing duplicate recursive target work, and using a scalable queue cursor.
  • Limited stored filesystem error details on large jobs while preserving the full failure count and first errors.
  • Added support for approved custom or symlinked WordPress upload/content paths outside the resolved site root.
  • Added live browser lock-state refresh so an editor already open during a MainWP or another-tab unlock stops blocking media actions without requiring a full page reload.
  • Preserved the existing MainWP bridge routes, authentication, request parameters, and response contract.

9.1.1

  • Improved Firewall UI and functions to allow even when Cloudflare is not setup

9.1

  • Improved Firewall UI and functions

9.0

  • Added a dedicated Firewall Security section under Secure & Protect.
  • Added a new Firewall Control Center with firewall mode status, blocked request totals, critical request totals, and latest event timing.
  • Added Smart Block mode to block high-confidence malicious traffic while preserving normal WordPress compatibility.
  • Added Monitor Only mode to log matching threats without blocking so rules can be tuned before enforcement.
  • Added Emergency Shield mode to temporarily block public access during active attacks while keeping admin access available.
  • Added Trusted IP Allowlist controls for IPs or CIDR ranges that should bypass firewall enforcement.
  • Added Immediate IP Blocklist controls for IPs or CIDR ranges that should be blocked before other firewall rules run.
  • Added a customizable Blocked Request Page with editable title, subtitle, message, footer note, button label, button URL, and live preview.
  • Added logic to hide the Return to Site button when Emergency Shield blocks the entire site.
  • Added firewall rules for exploit payloads, dangerous HTTP methods, scanner signatures, bot signatures, XML-RPC abuse, REST API exposure, suspicious query strings, and excessive request rates.
  • Added configurable Rate Limit Protection with per-IP request limits and custom time windows.
  • Added a dedicated Firewall Event Timeline with searchable and filterable firewall events.
  • Added timeline filters for blocked, monitored, critical, and today’s firewall events.
  • Added timeline pagination with page navigation and Show All support.
  • Added manual IP allow/block actions directly from firewall timeline events.
  • Removed internal Changed actions from the event timeline so settings updates and internal system actions do not clutter firewall logs.
  • Added Cloudflare-aware IP detection using trusted Cloudflare visitor IP headers.
  • Added Cloudflare event detail support including Ray ID, country, and edge IP information.
  • Added Cloudflare API credential testing for validating Zone ID and API token access.
  • Added automatic Cloudflare edge actions for confirmed firewall blocks.
  • Set Managed Challenge at Cloudflare edge as the default automatic Cloudflare edge action.
  • Added Cloudflare duplicate rule protection by checking for an existing matching IP/action rule before creating another.
  • Removed the Cloudflare edge push transient so rules can be recreated if deleted from Cloudflare and triggered again.
  • Added an Automatic Edge Action IPs management card showing IPs automatically sent to Cloudflare.
  • Added the ability to remove automatically created Cloudflare edge rules directly from the website without logging into Cloudflare.
  • Added local cleanup when automatically created Cloudflare edge rules are removed from the website.
  • Prevented Emergency Shield blocks from creating Cloudflare edge rules.
  • Added firewall email notification settings for blocked requests, critical severity events, rate limit events, emergency shield events, Cloudflare edge actions, and manual firewall changes.
  • Added configurable local timeline storage limits and event retention settings.
  • Added firewall setup/status indicators for active mode, core protections, Cloudflare integration, logging, and alerts.

8.7

  • Added a dedicated Login Security section under Secure & Protect.
  • Added custom login URL protection with a configurable login slug and options for handling direct wp-login.php access.
  • Added login attempt protection controls with configurable failed-attempt limits, tracking rules, lockout windows, XML-RPC failure counting, and REST authentication failure counting.
  • Added tooltip descriptions to the Login Attempt Protection and Login Hardening settings.
  • Added login activity logging with filters, refresh controls, pagination, and manual log clearing.
  • Added active session management with grouped user/IP session rows, session revoke, session block, ignore user/IP pair, clear ignored pairs, and revoke-all controls.
  • Added protections so “Revoke All Sessions” does not revoke the current admin’s active session.
  • Added role-based session expiration so different user roles can have different maximum login durations.
  • Added administrator login email alerts and lockout email alerts.
  • Moved “Limit login attempts” and “Block login with email address” out of User Security and into the new Login Security section.
  • Added a new Login card to the Secure & Protect overview page.
  • Improved Login Security pagination with page numbers, previous/next controls, and direct “go to page” jumping.
  • Added refresh buttons for Login Activity and Active Sessions that update through AJAX without reloading the page or moving the user back to the top.
  • Added modal feedback while refreshing Login Activity and Active Sessions.
  • Improved active session display by grouping matching username/IP sessions together and showing the newest login time with the soonest expiration time.
  • Added safer session discovery using indexed/recent login session users instead of relying only on full user scans.
  • Added a safer login security helper that loads on public login requests so login protections can run before the heavier admin only stack.
  • Added safe unserialize handling for stored scanner data to reduce object injection risk when reading saved scan results.
  • Strengthened MainWP bridge security with generated per-child bridge tokens instead of the previous shared token value.
  • Changed MainWP lock/unlock bridge actions to require POST requests for state-changing actions.
  • Added safer bridge token validation through the X-WPFA-Token header.
  • Improved MainWP update auto-unlock checks so unauthenticated heuristic update detection is disabled by default.
  • Added Redirect Monitor resumable AJAX batch scanning for more reliable scans on large sites.
  • Added Redirect Monitor safe fallback scanning when a full browser-based scan cannot complete.
  • Added Redirect Monitor progress details showing scan tasks, current URL, profile checks, errors, and completion progress.
  • Updated Redirect Monitor to test the homepage, login page, saved custom paths, and same-site navigation menu URLs.
  • Added a hard Redirect Monitor scan cap of 25 URLs to prevent oversized scan jobs.
  • Removed the Facebook visitor profile from Redirect Monitor scans.
  • Removed the Redirect Monitor “Scan Coverage” setting in favor of the fixed menu-focused URL selection strategy.
  • Improved Redirect Monitor handling when WP-Cron is disabled so manual scans and settings can still be saved.
  • Added Redirect Monitor warnings when scans complete with request errors.
  • Improved Watch Dog baseline creation with true server-side progress tracking.
  • Added Watch Dog baseline batch processing so large baselines can be built with better progress visibility.
  • Improved shared modal progress styling for Redirect Monitor and Watch Dog actions.
  • Improved Update Monitor by clearing update caches before forcing update checks.
  • Improved Update Monitor and Risk Review so stale update entries are ignored when the related plugin or theme is no longer installed.
  • Improved admin access control so newly added feature tabs are automatically available to admins who previously had access to every available area, while restricted/custom admins do not receive new areas automatically.
  • Added Login Security to the admin tab access system.
  • Improved Security hub layout and wording for the Secure & Protect area.
  • Improved Watch Dog file change action button spacing and table layout.
  • Removed the old bundled Security-Report.html helper report file.

= 8.6.1=
* Removed the Facebook visitor profile from Redirect Monitor scans.
* Redirect Monitor now uses desktop, mobile, Googlebot, and Google Search visitor profiles only.

= 8.6.5=
* Redirect Monitor now uses a fixed menu-focused URL selection strategy instead of a Scan Coverage setting.
* Added a hard 25 URL scan cap so very large websites cannot create oversized Redirect Monitor jobs.
* Redirect Monitor now tests homepage, login page, saved custom paths, and same-site navigation menu URLs before a small no-menu fallback sample.

= 8.6.4=
* Reverted the Redirect Monitor scan modal contrast treatment back to the original themed modal styling.
* Kept the updated Redirect Monitor Scanning modal title.

= 8.6.1=
* Added resumable Redirect Monitor AJAX batch scanning for large-site reliability.
* Added dynamic Redirect Monitor progress details during manual scans.

= 8.6=
* Added Password Reset Enforcement
* Added Public File Exposure Check
* Ignored audit flag on default index.php files
* Re-styled menu for cleaner navigation

= 8.5.1=
* Added Redirect Monitor
* Added Update Monitor
* Improved targeted unlocking for single targets

= 8.5=
* Fixed lock and unlock actions that trigger outside of WordPress install

8.0.1

  • Fixed stale lock/unlock request error in admin bar actions
  • Updated endpoints for MainWP extension

Full changelog on WordPress.org →

Screenshots

Command Center showing security score and important folder issues present on your site.
Command Center showing security score and important folder issues present on your site.
Main Folder Auditor displaying folders and files in the root of your WordPress installation.
Main Folder Auditor displaying folders and files in the root of your WordPress…
Content Folder Auditor listing folders and files found inside the wp-content directory.
Content Folder Auditor listing folders and files found inside the wp-content directory.
Plugins Folder Auditor showing installed plugin folders and hidden or orphaned plugin directories.
Plugins Folder Auditor showing installed plugin folders and hidden or orphaned plugin…
Themes Folder Auditor displaying theme folders on disk and alerting you to invalid or unrecognized themes.
Themes Folder Auditor displaying theme folders on disk and alerting you to invalid or…
Uploads Folder Auditor showing upload folders and identifying PHP files present in uploads.
Uploads Folder Auditor showing upload folders and identifying PHP files present in…
.htaccess Auditor listing every .htaccess file detected across your site for review and management.
.htaccess Auditor listing every .htaccess file detected across your site for review and…
Security Settings page where you can configure Site Lock, security headers, and user hardening features.
Security Settings page where you can configure Site Lock, security headers, and user…
Infection Scanner selection screen allowing you to choose which areas of your site to scan.
Infection Scanner selection screen allowing you to choose which areas of your site to…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Site Lockdown Security alternatives

All firewall plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Wordfence Security – Firewall, Malware Scan, and Login Security Wordfence Security Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by… by Mark Maunder 5M+ ★★★★★★★★★★ 4.7 (5K) 1 day ago 96
2 Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention Limit Login Attempts Security WordPress login security with brute force protection, Two-factor authentication (2FA/MFA)… by WPChef 1M+ ★★★★★★★★★★ 4.8 (1.5K) 1 week ago 91
3 Security Optimizer – The All-In-One Protection Plugin Security Optimizer – The All-In-One Protection Plugin Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to… by SiteGround 1M+ ★★★★★★★★★★ 4.5 (157) 1 month ago 87
4 All-In-One Security (AIOS) – Security and Firewall All-In-One Security (AIOS) – Security and Firewall Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy… by David Anderson / Team Updraft 1M+ ★★★★★★★★★★ 4.7 (1.7K) 2 weeks ago 93
5 Sucuri Security – Auditing, Malware Scanner and Security Hardening Sucuri Security The Sucuri WordPress Security plugin is a security toolset for security integrity… by Sucuri 600K+ ★★★★★★★★★★ 4.2 (384) 3 weeks ago 93
6 MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall MalCare WordPress Security Plugin Get Bulletproof Security for your WordPress site. WordPress security plugin packed with… by malcare 100K+ ★★★★★★★★★★ 4.4 (554) 2 weeks ago 93
7 Anti-Malware Security and Brute-Force Firewall Anti-Malware Security and Brute-Force Firewall This Anti-Malware scanner searches for Malware, Viruses, and other security threats and… by Eli 100K+ ★★★★★★★★★★ 4.9 (783) 3 months ago 81
8 BBQ Firewall – Fast & Powerful Firewall Security BBQ Firewall – Fast & Powerful Firewall Security The fastest firewall plugin for WordPress. Protect against a wide range of threats with… by Jeff Starr 100K+ ★★★★★★★★★★ 4.9 (160) 2 months ago 92
9 NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall NinjaFirewall (WP Edition) A true Web Application Firewall to protect and secure WordPress. by nintechnet 100K+ ★★★★★★★★★★ 4.9 (220) 1 week ago 89
10 Login Lockdown & Protection Login Lockdown & Protection Protect, lockdown & secure login form by limiting login attempts from the same IP & banning… by WebFactory 100K+ ★★★★★★★★★★ 4.3 (61) 2 months ago 89

FAQ

Site Lockdown Security: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 1, 2026

Is Site Lockdown Security free?

Yes. Site Lockdown Security is free to download and use from the official WordPress.org plugin directory.

Is Site Lockdown Security safe to use in 2026?

Site Lockdown Security is a solid plugin choice in 2026, with a few things worth checking first. It runs on 700+ sites, is rated 5/5 and was last updated 2 months ago, and scores 62/100 on our health check.

How many websites use Site Lockdown Security?

Site Lockdown Security is active on 700+ WordPress websites and has been downloaded 14,374 times since it launched in August 2025. It was downloaded 522 times in the last 30 days.

Does Site Lockdown Security work with WordPress 7.1?

Site Lockdown Security is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does Site Lockdown Security need?

Site Lockdown Security requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Site Lockdown Security last updated?

The latest version, 9.2, was released on July 20, 2026 (2 months ago).

Who makes Site Lockdown Security?

Site Lockdown Security is developed and maintained by WP Fix It - WordPress Experts.

What are the best alternatives to Site Lockdown Security?

The most popular alternatives to Site Lockdown Security are Wordfence Security (5M+ installs), Limit Login Attempts Securi… (1M+ installs) and Security Optimizer (1M+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.