PowerSEC – Firewall, Malware Scanner, Login Security & Backup
Free firewall/WAF, malware scanning, login protection, 2FA, file-integrity monitoring and local backups. Optional multi-site Central dashboard.
Solid choice
PowerSEC is a solid plugin choice in 2026, with a few things worth checking first. It runs on 20+ sites, is rated 5/5 and was last updated 3 days ago, and scores 74/100 on our health check.
- Actively developed — last update 3 days ago
- Tested with the latest WordPress (7.1)
- Small user base (20+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where PowerSEC stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| backup | >100 |
| firewall | #61 |
| login security | >100 |
| malware scanner | #37 |
| security | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About PowerSEC
From the official readme · v1.4.234Description
Free WordPress security: firewall/WAF, malware scanning, login protection, 2FA, file-integrity monitoring and local backup & restore. Protect one site with no account, or connect many sites to the optional PowerSEC Central dashboard for monitoring, cloud backups (paid) and remote management.
PowerSEC can connect to PowerSEC Central for multi-site management and vulnerability scanning, off by default — see External services (1). If connected, it can toggle WordPress’s own plugin/theme auto-updates; it never changes how core updates itself.
External services
Each service below is contacted only when its feature is on; every third-party service is off by default, and Central is off until an administrator connects the site. Out of the box the only request PowerSEC makes on its own is to the first-party WordPress.org checksum API (5); an alert channel’s “Send test” is the one exception, contacting the destination you typed at once. IPs and usernames may be personal data — disclose the services you enable in your own policy. The User-Agent is PowerSEC/<version> alone; see each service below.
1. PowerSEC Central — https://powersec.io — dashboard for multi-site management, cloud backups, alerting, incident response. Trigger: only when an administrator connects the site. Default: off.
Sent: site URL, identifiers and API keys; WordPress/PHP/MySQL versions; plugin and theme inventory (name, slug, version, author, active state); site icon URL; disk, memory and database size; CPU load and core count; up to 14 days of pageview counts; scan summaries, security event metadata and backup status; IPs of blocked or attacking clients; administrator usernames, last login, and their email addresses (only while two-factor is on or this server cannot send mail). If a message this site sends fails, its subject and body go to Central to deliver — to your own administrators only. With two-factor on and connected, the one-time code and recipient email go to Central to deliver (otherwise wp_mail() is used and nothing leaves the site). Database-scan findings carry a short redacted excerpt plus its table and key; whole posts, option values and page output never are.
Cloud backup (paid): archives on Wasabi (*.wasabisys.com); restores use short-lived signed URLs from *.wasabisys.com, *.amazonaws.com or powersec.io. Wasabi https://wasabi.com/legal/ , https://wasabi.com/legal/privacy-policy/ — AWS https://aws.amazon.com/service-terms/ , https://aws.amazon.com/privacy/
Terms https://powersec.io/terms — Privacy https://powersec.io/privacy
2. Google Gemini — https://ai.google.dev (via Central) — an AI second opinion on a file the scanner already flagged.
Trigger: (a) manual — an administrator clicks to explain one flagged file; that click is the authorisation. (b) automated — off by default, needing an explicit local opt-in by an administrator of this site under PowerSEC > Central Connection. Connecting to Central, your plan and Central’s settings do not enable it; switching it off stops future sharing.
Sent: only a bounded, redacted excerpt of that flagged file (size-capped, secrets redacted), plus its path, size, hash and the matching rule. Whole files, whole sites, databases and files that may hold credentials (wp-config.php, .env, key/certificate files) are never sent. Advisory only: it never changes scan results, malware counts or your score, and never removes, quarantines or repairs a file.
Terms https://ai.google.dev/gemini-api/terms — Privacy https://policies.google.com/privacy
3. GeoJS — https://get.geojs.io — IP geolocation. Trigger: only when country blocking is enabled. Default: off. Sent: the visitor’s IP, to resolve its country; cached 24h, and behind Cloudflare the country comes from Cloudflare’s header with no external call.
Terms https://www.geojs.io/tos/ — Privacy https://www.geojs.io/privacy/
4. Tor Project exit list — https://check.torproject.org — the public exit-node list. Trigger: only when Tor blocking is enabled. Default: off. Sent: nothing; the request carries no visitor information.
Privacy https://www.torproject.org/about/privacy_policy/ (a public file served without an account, so no separate terms)
5. WordPress.org — https://api.wordpress.org , https://downloads.wordpress.org — the official checksum APIs core itself uses. Trigger: file-integrity monitoring (on by default) and malware scans. Sent: your WordPress version and locale for core checksums; each plugin’s slug and version for plugin checksums. No personal data.
Privacy https://wordpress.org/about/privacy/
6. Alerting / SIEM destinations — security events sent where you choose. Trigger: only when you configure and enable a channel. Default: off; on every plan. Kinds: webhook URLs you supply (Slack, Discord, Splunk HEC, custom); fixed endpoints (PagerDuty events.pagerduty.com, Datadog http-intake.logs.datadoghq.com or its regional host); raw syslog/CEF over UDP/TCP to a host you supply.
Sent: per event — type, severity, message, the WordPress username involved (on a failed login this is visitor-supplied text), client IP, timestamp, your site name and URL. Custom-webhook and Splunk formats also include event metadata, which for a login can contain the request path and user-agent; the others do not.
Terms/privacy: https://slack.com/terms-of-service , https://slack.com/trust/privacy/privacy-policy , https://discord.com/terms , https://discord.com/privacy , https://www.splunk.com/en_us/legal/terms.html , https://www.splunk.com/en_us/legal/privacy-policy.html , https://www.pagerduty.com/terms-of-service/ , https://www.pagerduty.com/privacy-policy/ , https://www.datadoghq.com/legal/terms/ , https://www.datadoghq.com/legal/privacy/ . A webhook, Splunk HEC or syslog collector you supply is your own server, so its terms are yours.
7. Your own site (loopback) — not a third party. Long backups and scans continue by calling your site’s own admin-ajax.php; nothing leaves your server.
Privacy
Recorded locally: login attempts (attempted username, IP, time), audit log (action, user, IP), sessions (user, IP, user-agent, times), and firewall/WAF/IP-blocking records (IP, path, method, user-agent). Findings describe files, not people. Retention: audit log and login attempts about 90 days (configurable), firewall/WAF/sessions about 30 days, remote requests about 7 days.
Blocked IPs follow their own rules, not the schedule above: a temporary block ends by itself when it expires; a permanent block PowerSEC created automatically is removed after about a year (configurable); one an administrator added by hand is kept until an administrator removes it.
Deleting the plugin keeps your data by default. That site’s PowerSEC tables, settings and connection details stay, so a reinstall resumes where it left off. Running wp option update powersec_delete_data_on_uninstall 1 first (no screen for it) also drops those tables and removes PowerSEC settings, stored keys, connection details, transients, per-account data and scheduled tasks, plus the firewall folder. Backup and quarantine folders remain, as do the uploads PHP-execution guards. One secret-free pending-revocation marker remains when a Central release is unconfirmed, never reported as done. wp-admin deletion cannot notify Central, so disconnect first.
WordPress export and erasure requests are answered for records tied to a WordPress account. IP-only records cannot reliably be linked to an email address, so they are not exported or erased. Where erasure would break the tamper-evident audit chain, identifying fields are anonymised instead of deleted, and the response says so.
Files and directories this plugin writes
Everything is written inside your uploads directory (wp_upload_dir()): powersec-backups/ (archives; deny-all .htaccess), powersec-quarantine/ (detected files), powersec/ (firewall rules), powersec-config-backups/ (wp-config.php copies; removed on data deletion), plus guards stopping PHP executing in uploads. Two things write outside uploads: the prefix change edits wp-config.php after backing it up, and a restore adds .maintenance to the site root, removed when it ends. Restoring overwrites site files.
Credits
Chart.js v4.5.1, @kurkle/color v0.3.2 (MIT; texts in licenses/). https://github.com/chartjs/Chart.js , https://github.com/kurkle/color
Installation
- Install from the Plugins screen, or upload the ZIP.
- Activate it, then open PowerSEC > Dashboard to scan.
- (Optional) Open PowerSEC > Central Connection and choose Connect automatically.
Multisite: PowerSEC supports multisite through per-site activation only. Network activation is intentionally refused, because each site keeps its own data and connection. Activate PowerSEC separately on each site where you need it. Data deletion removes per-user data network-wide.
Frequently asked questions
Is PowerSEC Central free?
Central has a free tier: connect sites and use the fleet dashboard. Paid plans add cloud backups, scheduling, AI review and alerting. Every local feature works on every plan. Automatic AI review stays off until an administrator turns it on — see External services (2).
Changelog
Malware-scan reliability fix. Recommended.
Full history ships in changelog.txt.
1.4.234
- Fix: a malware scan started on a busy server now waits and starts on its own instead of being refused.
1.4.233
- Fix: the malware scan now runs in the background and no longer fails with a network error on some hosts.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best PowerSEC alternatives
All backup plugins →FAQ
PowerSEC: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 1, 2026
Is PowerSEC free?
Yes. PowerSEC is free to download and use from the official WordPress.org plugin directory.
Is PowerSEC safe to use in 2026?
PowerSEC is a solid plugin choice in 2026, with a few things worth checking first. It runs on 20+ sites, is rated 5/5 and was last updated 3 days ago, and scores 74/100 on our health check.
How many websites use PowerSEC?
PowerSEC is active on 20+ WordPress websites and has been downloaded 406 times since it launched in September 2026. It was downloaded 412 times in the last 30 days.
Does PowerSEC work with WordPress 7.1?
Yes. The developer has tested PowerSEC up to WordPress 7.1.2, the latest release. It requires WordPress 5.8 or newer.
What PHP version does PowerSEC need?
PowerSEC requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was PowerSEC last updated?
The latest version, 1.4.234, was released on September 28, 2026 (3 days ago).
Who makes PowerSEC?
PowerSEC is developed and maintained by CinderEye LLC.
What are the best alternatives to PowerSEC?
The most popular alternatives to PowerSEC are All-in-One WP Migration and… (5M+ installs), UpdraftPlus: WP Backup & Mi… (4M+ installs) and Jetpack (3M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card





