BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
KW Members Fortress icon
Actively maintained Tested up to 7.0.7 #4 in file protection

KW Members Fortress

Make your whole WordPress site private — every page, feed, REST endpoint and uploaded file requires login — and prove it isn't leaking.

Active installs<10New
Downloads · 30d59▲ +34.1% vs prev. 30d
Rating—0 reviews
Health score55/100Fair
All-time downloads182Since Jul 2026
Support resolved—No recent threads
RequiresWP 6.0PHP 7.4+
Downloads · 7d13• 0% week over week
Our verdict

Use with caution

KW Members Fortress works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 55/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

112233Jul 14Aug 25Oct 7
Yesterday5
Daily average (1y)2
Peak day44Jul 25, 2026
Last 12 months189

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where KW Members Fortress stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
file protection >100 4,281 Best file protection plugins →
force login >100 1,234 Best force login plugins →
login required >100 3,466 Best login required plugins →
members-only >100 2,553 Best members-only plugins →
private site >100 4,058 Best private site plugins →

About KW Members Fortress

From the official readme · v1.0.8

Description

KW Members Fortress turns a standalone WordPress site into a private, members-only space. Visitors who aren’t logged in can’t reach anything except the login screen and the legal pages you choose to publish — not your pages, posts, archives, search, feeds, REST API, sitemaps, XML-RPC, and crucially not your uploaded files either.

Most “force login” plugins only gate the pages WordPress renders. They leave every file in /wp-content/uploads/ reachable by anyone who has (or guesses) the URL — PDFs, images, documents. KW Members Fortress routes those file requests through WordPress and serves them only to logged-in members, then continuously self-tests that the seal is holding.

What it does

  • Whole-site gate — logged-out requests are redirected to login: pages, posts, archives, search, feeds, REST, sitemaps, XML-RPC.
  • Protected file URLs — direct hits to /wp-content/uploads/… are served only to members (Apache/LiteSpeed handled automatically; nginx shows you the one snippet to paste).
  • Leak self-test (canary) — about once an hour the plugin makes a cookie-less request to one of its own upload URLs and raises a dashboard alarm if a file ever comes back without login. Silent misconfiguration becomes a visible warning.
  • Branded login screen — set a background image, overlay colour/gradient, accent colour, and logo from the settings page. No file editing.
  • Footer & legal pages — up to three footer items, each a built-in page (rendered theme-less and reachable while logged out) or an external link. Perfect for an Imprint / Privacy notice on an otherwise-private site.
  • Hardening (all optional, on by default) — block logged-out admin-ajax, block user-enumeration, no-cache headers on blocked responses, and a progressive login throttle that auto-recovers.

Good to know

  • No accounts, tiers, payments, or third-party services. One site, one membership wall.
  • Runtime files are stored under …/wp-content/uploads/kw-members-fortress/ — never in the plugin folder.
  • The leak self-test only ever contacts your own site’s URL; it is not an external service.

Installation

  1. Upload the plugin to /wp-content/plugins/ (or install it from your dashboard) and activate it.
  2. On Apache / LiteSpeed the upload-protection rule is written for you. On nginx, the plugin shows a short location snippet — paste it into your server block and reload nginx.
  3. Visit Members Fortress in the admin menu to brand the login screen, add footer/legal pages, and review the Lockdown status (server type, public-asset folder, and the latest leak self-test result).
  4. Log out in a separate browser to confirm the site is sealed.

Caching: because every visitor must be checked individually, full-page caching of the front end must be turned off (or the gate can be bypassed by a cached copy). The plugin sends no-cache headers on blocked responses, but a page cache in front of WordPress should not store logged-in/front-end pages.

Frequently asked questions

Does it really protect uploaded files, or just pages?

Files too — that’s the point. Requests to /wp-content/uploads/… are routed through WordPress and served only to logged-in members. The only exception is a small public sub-folder, uploads/kw-members-fortress/public/, which holds just your chosen login background and logo so they can load on the logged-out login screen.

Why does it edit my root `.htaccess`?

On Apache/LiteSpeed the upload-protection rule is added to .htaccess using WordPress’ own marker API (the same mechanism core uses for permalinks), inside a clearly-marked block. Deactivating the plugin removes the block and restores normal file serving.

What is the “leak self-test”?

A tiny sentinel file lives in the plugin’s folder inside uploads (uploads/kw-members-fortress/canary.txt — a location that must stay locked). About once an hour, while you’re in the dashboard, the plugin requests that file’s URL without sending your login cookies. If the file comes back, the gate isn’t working and you get a red dashboard warning. It only ever contacts your own site — it is not a third-party service.

I’m on nginx and files are still reachable.

nginx configuration can’t be edited from PHP, so the plugin shows the exact location snippet to add to your server block. Add it and reload nginx; the Lockdown tab and the self-test will confirm the seal.

Can I show an Imprint / Privacy page to logged-out visitors?

Yes. Under Footer & Pages, set a slot to Built-in page, give it a title and content, and it renders on its own theme-less page that’s reachable without login (and noindex). Images embedded inside that content won’t display to logged-out visitors, since uploads stay locked — use text and HTML.

The login throttle locked me out.

After several failed logins from one IP, a short, growing cool-down is applied; it expires on its own (no permanent lockout). Note that visitors sharing one office/NAT IP share the counter. You can turn the throttle off on the Lockdown tab.

What happens when I deactivate or delete it?

Deactivating removes the .htaccess rule and turns protection off — by design. Deleting honours the Advanced → “remove all data” option: leave it off to keep your settings, or turn it on to remove the settings and the public-asset folder on uninstall.

Changelog

1.0.8

  • The legal-page styles are now delivered through the enqueue API (registered handle + wp_add_inline_style).
  • All runtime files now live under uploads/kw-members-fortress/: the leak-test sentinel moved there from the uploads root, and public login assets moved into the public/ sub-folder. Existing installs migrate automatically.
  • The sentinel file is now written via the WP_Filesystem API.

1.0.7

  • Initial public release.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best KW Members Fortress alternatives

All file protection plugins →

FAQ

KW Members Fortress: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 8, 2026

Is KW Members Fortress free?

Yes. KW Members Fortress is free to download and use from the official WordPress.org plugin directory.

Is KW Members Fortress safe to use in 2026?

KW Members Fortress works, but test it on a staging site before relying on it in 2026. Was last updated 3 months ago, and scores 55/100 on our health check.

How many websites use KW Members Fortress?

KW Members Fortress is active on <10 WordPress websites and has been downloaded 182 times since it launched in July 2026. It was downloaded 59 times in the last 30 days.

Does KW Members Fortress work with WordPress 7.1?

KW Members Fortress is officially tested up to WordPress 7.0.7, while the latest release is 7.1.3. It may still work, but try it on a staging site first.

What PHP version does KW Members Fortress need?

KW Members Fortress requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was KW Members Fortress last updated?

The latest version, 1.0.8, was released on July 25, 2026 (3 months ago).

Who makes KW Members Fortress?

KW Members Fortress is developed and maintained by KREISWOLKE.

What are the best alternatives to KW Members Fortress?

The most popular alternatives to KW Members Fortress are Site Lockdown Security for… (30+ installs), DownloadSentinel (10+ installs) and Folio Gatehouse (<10 installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.