BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off β†’
Nimble Security icon
Actively maintained Tested with WP 7.1

Nimble Security

Local WordPress security with 2FA, integrity monitoring, firewall, malware scanning, quarantine, incident response and recovery readiness.

Active installs<10New
Downloads Β· 30d252β€’ 0% vs prev. 30d
Ratingβ€”0 reviews
Health score64/100Good
All-time downloads243Since Sep 2026
Support resolvedβ€”No recent threads
RequiresWP 6.6PHP 8.1+
Downloads Β· 7d86β–² 4.3Γ— week over week
Our verdict

Solid choice

Nimble Security is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 days ago, and scores 64/100 on our health check.

  • Actively developed β€” last update 2 days ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far
  • Needs PHP 8.1 or newer

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

122537Sep 7Sep 20Oct 4
Yesterday17
Daily average (1y)9
Peak day50Oct 3, 2026
Last 12 months252

Download spikes usually follow a new release β€” each site that auto-updates counts as a download.

Rankings

Where Nimble Security stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
firewall >100 991 Best firewall plugins β†’
integrity >100 828 Best integrity plugins β†’
malware scanner >100 254 Best malware scanner plugins β†’
security >100 10,000 Best security plugins β†’
two factor >100 639 Best two factor plugins β†’

About Nimble Security

From the official readme Β· v1.2.2

Description

Nimble Security protects a WordPress site from the login screen down to the files on disk, and it does all of it on your own server.

There is no account to create, no cloud service to connect and no data leaving your site. The only outbound request the free version ever makes is to the official WordPress.org checksum API, and only when an integrity scan runs.

Everything listed below is in the free version. It is not a trial, nothing here is time-limited, and no engine is held back.

Stop attackers at the door

  • Brute-force lockouts with generic login errors, so an attacker cannot tell a wrong username from a wrong password.
  • Two-factor authentication with encrypted secrets, local QR enrolment, ten single-use recovery codes and replay protection.
  • Session control, Application Password auditing and revocation, and optional XML-RPC authentication protection.
  • Author-enumeration blocking.

Know when your files change

  • WordPress core verified against the official checksums.
  • SHA-256 baselines for plugins, themes, must-use plugins, drop-ins and selected configuration files.
  • Plugin and theme updates are recognised as maintenance, so a routine update does not turn into a false alarm.
  • Optional permission auditing reports paths writable by group or others and tightens them only when you ask. It never loosens a permission, never acts on its own and never touches anything outside the WordPress installation.

Block bad requests

  • A web application firewall with Protect, Learning and Off modes.
  • Rate limiting, plus correct client-IP handling behind a proxy or CDN.
  • Optional Smart 404 blocking, disabled by default.

Find and contain what got in

  • A local malware scanner that streams files in the background and resumes after a timeout. Nothing is uploaded for analysis.
  • An inventory of installed components, ready to be matched against advisory data.
  • Incidents, encrypted quarantine and restore, plugin component containment, privileged-session containment and Emergency Lockdown.

Know where you stand

Security Score rates your posture out of 100 across hardening, identity, integrity, firewall, malware detection, software updates and recovery readiness. An open high or critical incident caps the score, so a site with an active serious problem cannot display a healthy number.

What it deliberately does not do

Nimble Security does not upload your files, does not phone home, does not write executable code anywhere and does not replace backups. It protects, detects and responds; recovery comes from a backup. That is why recovery readiness counts towards the score, because remediation is far safer when a verified restore point exists.

External services

Nimble Security relies on exactly one external service, and on nothing else.

WordPress.org Core Checksums API

  • What it is: the official checksum service operated by WordPress.org at https://api.wordpress.org/core/checksums/1.0/. It returns the authoritative MD5 checksum set for a given WordPress release.
  • What it is used for: verifying that the WordPress core files on your server match the files that were published for your version. Without it, core integrity cannot be established, because the reference checksums only exist on WordPress.org.
  • What is sent, and when: the installed WordPress core version and the site locale, over HTTPS. Nothing else. The request is made only when a core integrity scan runs: manually when an administrator starts one, or on the daily schedule if an administrator has enabled automatic scans. Automatic scans are off by default. No request is made if integrity scanning is never used.
  • What is never sent: plugin or theme file contents, local file hashes, file paths, credentials, cookies, request bodies, user or customer data, security findings and quarantine payloads.
  • Terms of Service: https://wordpress.org/about/terms/
  • Privacy Policy: https://wordpress.org/about/privacy/

Nimble Security does not contact NimblePlugins, sends no telemetry and has no account, licence or activation requirement of any kind.

Privacy

Security events are minimized. Raw request bodies, cookies and credentials are not stored by the event engine, and network actors are represented with keyed hashes rather than raw IP addresses in Security events.

TOTP secrets are encrypted at rest and recovery codes are stored as one-way hashes in WordPress user metadata. Authentication secrets are never included in the WordPress personal-data export. The privacy eraser anonymizes Security event references and removes the per-user appearance preference; active 2FA material is retained while the account remains active because it is required for authentication.

Quarantine payloads stay local and are encrypted with AES-256-GCM. Operations receives aggregate technical status only, not file contents, raw IP addresses, credentials, request bodies or quarantine data.

Installation

  1. Upload and activate Nimble Security.
  2. On a new installation, choose Start Easy Setup or Skip for now.
  3. Easy Setup can apply the recommended local protection profile and start the first checks automatically.
  4. Enroll administrator 2FA when prompted.
  5. Review Identity, Integrity, Firewall, Scanner and Recovery status from Nimble Security > Overview.

Easy Setup never requires a Nimble account or Threat Cloud connection and can be run again later from the Nimble Security menu.

If using Nimble Security Pro, install/upgrade Free first, then Pro.

Frequently asked questions

Do I need a licence key or an account?

No. Nimble Security is complete on its own. It contains no licence check, no account requirement and no time limit, and it does not contact NimblePlugins.

Does Free work without Pro?

Yes. Free owns the local identity, integrity, firewall, malware, vulnerability-inventory and manual response engines.

Does a changed plugin file mean malware?

No. Integrity findings are interpreted in context. Known WordPress maintenance can be correlated automatically; unexplained file changes are presented for review rather than being labelled malware by file type alone.

Why can wp-config.php still require review after WordPress is reinstalled?

WordPress normally preserves wp-config.php. Site-specific cron, proxy, database or debug configuration can therefore legitimately differ from a previous baseline. Nimble Security lets an administrator explicitly mark the current recognized configuration as intentional without storing its contents.

Does Nimble Security upload files for malware scanning?

No. The Free malware scanner runs locally.

Can Security delete malware automatically?

Free response is manual-first. Pro contains conservative recovery-gated automation, but destructive actions remain bounded by the Free enforcement and recovery contracts.

Does Nimble Security replace backups?

No. Security protects/detects/responds; backup provides recovery. Recovery readiness is intentionally part of Security Score because remediation is safer when a verified recovery point is available.

Changelog

Every link and redirect this plugin makes into its own admin screens is now signed with a nonce, and nothing in the query string is read before that signature has been verified. The wizard step, the selected malware finding, the file-permission counters and the notice shown after an action were previously read straight from the URL, so a link from anywhere could preselect them. The plugin's own screen slug is read from WordPress' $plugin_page rather than from the query string. Security Pro 1.3.1 or newer is required for its automation notice to appear, because that redirect now has to be signed too.

1.2.2

  • Fixes a fatal error on activation in 1.2.1. The file holding the remembered-device code shipped with the plugin, but the line that loads it did not, so the class was missing the moment the plugin booted. This plugin loads its classes from an explicit list rather than an autoloader, and the new file was never added to that list. The build now refuses to package a release where a class file is not on it.

1.1.13

  • The Security incidents banner on the Response page no longer describes automatic incident correlation as an unreleased Pro feature. It now reads “Coming soon” like the rest of the plugin’s Pro references, since Pro is not yet purchasable on nimbleplugins.com.

1.1.12

  • Quarantine payloads now live in a protected folder inside the uploads directory, resolved at runtime with wp_upload_dir() instead of a hard-coded wp-content path. Existing payloads are moved there automatically on update, and the folder is still closed to direct access.
  • Extended Protection has been moved to the Nimble Security Pro add-on. It was the only part of the plugin that generated a PHP file, and generated PHP does not belong in a plugin hosted here. Every rule it enforced is still enforced by the built-in firewall through WordPress; nothing is left unprotected.
  • If Extended Protection was prepared on your site, remove the auto_prepend_file directive you added, or install the Pro add-on to keep managing it.
  • Removes two core-file includes that were not needed: wp-admin/includes/plugin.php in the quarantine policy check and wp-admin/includes/update.php in the update-status refresh.
  • Documents the WordPress.org checksum API in full, including what is sent, when, and links to its Terms of Service and Privacy Policy.

1.1.11

  • Removes the Nimble Security Pro licence client, the licence screen and all licence storage from the free plugin. Licensing now lives entirely in the commercial Pro package; nothing in the free plugin is gated, checked or limited.
  • The two-factor login screen loads its styling from a stylesheet, and the interim-login handoff script is registered through the script API instead of being printed inline.
  • Uninstall still clears any licence options left behind by an earlier version.

1.1.10

  • The licence key field is hidden until Nimble Security Pro is actually installed, so the free plugin never asks for a key that cannot be obtained yet. A filter, nimble_security_license_entry_visible, can reveal it early.
  • No behaviour change.

1.1.9

  • The licence screen no longer presents an unreleased product as a missing one. With no key stored it reads “coming soon” instead of “not activated”, and the key field is labelled for the few who already hold one rather than shown as a call to action.
  • Pro capabilities are described in the future tense throughout, because Pro is not released yet.
  • No behaviour change.

Full changelog on WordPress.org β†’

Screenshots

Overview: Security Score, open incidents and the state of every protection engine on one screen.
Overview: Security Score, open incidents and the state of every protection engine on one…
The same Overview in light mode. Appearance is per-user, so it follows whoever is signed in.
The same Overview in light mode. Appearance is per-user, so it follows whoever is signed…
Easy Setup applies a recommended local protection profile without asking you to understand every switch first.
Easy Setup applies a recommended local protection profile without asking you to…
Identity Protection: brute-force lockouts, two-factor enrolment, sessions and Application Passwords. Credentials and raw IP addresses never leave the site.
Identity Protection: brute-force lockouts, two-factor enrolment, sessions and Application…
Integrity Protection verifies WordPress core against the official checksums and keeps SHA-256 baselines for plugins, themes, must-use plugins and drop-ins.
Integrity Protection verifies WordPress core against the official checksums and keeps…
The firewall evaluates requests against local high-confidence rules, in Protect, Learning or Off mode.
The firewall evaluates requests against local high-confidence rules, in Protect, Learning…
The malware scanner reads files locally and resumes after a timeout. File contents never leave the server.
The malware scanner reads files locally and resumes after a timeout. File contents never…
Vulnerability inventory: what is actually installed, so you can judge what is exposed.
Vulnerability inventory: what is actually installed, so you can judge what is exposed.
Diagnostics are read-only. They verify the runtime, storage and security boundaries without changing any configuration.
Diagnostics are read-only. They verify the runtime, storage and security boundaries…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own β€” no account needed.

Active installs badge Rating badge Health score badge

Best Nimble Security alternatives

All firewall plugins β†’
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Wordfence Security – Firewall, Malware Scan, and Login Security Wordfence Security Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by… by Mark Maunder 5M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.7 (5K) 5 days ago 96
2 Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention Limit Login Attempts Security WordPress login security with brute force protection, Two-factor authentication (2FA/MFA)… by WPChef 1M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.8 (1.5K) 2 weeks ago 91
3 Security Optimizer – The All-In-One Protection Plugin Security Optimizer – The All-In-One Protection Plugin Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to… by SiteGround 1M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.5 (157) 1 month ago 85
4 All-In-One Security (AIOS) – Security and Firewall All-In-One Security (AIOS) – Security and Firewall Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy… by David Anderson / Team Updraft 1M+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.7 (1.7K) 3 weeks ago 93
5 Sucuri Security – Auditing, Malware Scanner and Security Hardening Sucuri Security The Sucuri WordPress Security plugin is a security toolset for security integrity… by Sucuri 600K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.2 (384) 4 weeks ago 93
6 MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall MalCare WordPress Security Plugin Get Bulletproof Security for your WordPress site. WordPress security plugin packed with… by malcare 100K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.4 (554) 3 weeks ago 93
7 Anti-Malware Security and Brute-Force Firewall Anti-Malware Security and Brute-Force Firewall This Anti-Malware scanner searches for Malware, Viruses, and other security threats and… by Eli 100K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.9 (783) 3 months ago 81
8 BBQ Firewall – Fast & Powerful Firewall Security BBQ Firewall – Fast & Powerful Firewall Security The fastest firewall plugin for WordPress. Protect against a wide range of threats with… by Jeff Starr 100K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.9 (160) 2 months ago 85
9 NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall NinjaFirewall (WP Edition) A true Web Application Firewall to protect and secure WordPress. by nintechnet 100K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.9 (220) 2 weeks ago 89
10 Login Lockdown & Protection Login Lockdown & Protection Protect, lockdown & secure login form by limiting login attempts from the same IP & banning… by WebFactory 100K+ β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜…β˜… 4.3 (61) 3 days ago 93

FAQ

Nimble Security: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org Β· checked Oct 5, 2026

Is Nimble Security free?

Yes. Nimble Security is free to download and use from the official WordPress.org plugin directory.

Is Nimble Security safe to use in 2026?

Nimble Security is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 2 days ago, and scores 64/100 on our health check.

How many websites use Nimble Security?

Nimble Security is active on <10 WordPress websites and has been downloaded 243 times since it launched in September 2026. It was downloaded 252 times in the last 30 days.

Does Nimble Security work with WordPress 7.1?

Yes. The developer has tested Nimble Security up to WordPress 7.1.2, the latest release. It requires WordPress 6.6 or newer.

What PHP version does Nimble Security need?

Nimble Security requires PHP 8.1 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Nimble Security last updated?

The latest version, 1.2.2, was released on October 3, 2026 (2 days ago).

Who makes Nimble Security?

Nimble Security is developed and maintained by nimbleplugins.com.

What are the best alternatives to Nimble Security?

The most popular alternatives to Nimble Security are Wordfence Security (5M+ installs), Limit Login Attempts Securi… (1M+ installs) and Security Optimizer (1M+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages β€” with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org β€” no credit card
Sarah is here to help!
Hi there! πŸ‘‹ Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! πŸ‘‹ Need help finding what you're looking for?

We'll use this to continue our conversation

Just now βœ“ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.