BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
PowerSEC – Firewall, Malware Scanner, Login Security & Backup icon
Actively maintained Tested with WP 7.1

PowerSEC – Firewall, Malware Scanner, Login Security & Backup

Free firewall/WAF, malware scanning, login protection, 2FA, file-integrity monitoring and local backups. Optional multi-site Central dashboard.

Active installs20+10+ tier
Downloads · 30d412• 0% vs prev. 30d
Rating5/51 reviews
Health score74/100Good
All-time downloads406Since Sep 2026
Support resolved—No recent threads
RequiresWP 5.8PHP 7.4+
Downloads · 7d155▼ -29.9% week over week
Our verdict

Solid choice

PowerSEC is a solid plugin choice in 2026, with a few things worth checking first. It runs on 20+ sites, is rated 5/5 and was last updated 3 days ago, and scores 74/100 on our health check.

  • Actively developed — last update 3 days ago
  • Tested with the latest WordPress (7.1)
  • Small user base (20+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

132639Sep 16Sep 23Sep 30
Yesterday12
Daily average (1y)27
Peak day52Sep 17, 2026
Last 12 months412

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where PowerSEC stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
backup >100 3,497 Best backup plugins →
firewall #61 966 Best firewall plugins →
login security >100 4,132 Best login security plugins →
malware scanner #37 246 Best malware scanner plugins →
security >100 10,000 Best security plugins →

Version adoption

Share of active sites per release.

  • 1.4100.0%

Rating breakdown

★★★★★★★★★★ 5 from 1 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About PowerSEC

From the official readme · v1.4.234

Description

Free WordPress security: firewall/WAF, malware scanning, login protection, 2FA, file-integrity monitoring and local backup & restore. Protect one site with no account, or connect many sites to the optional PowerSEC Central dashboard for monitoring, cloud backups (paid) and remote management.

PowerSEC can connect to PowerSEC Central for multi-site management and vulnerability scanning, off by default — see External services (1). If connected, it can toggle WordPress’s own plugin/theme auto-updates; it never changes how core updates itself.

External services

Each service below is contacted only when its feature is on; every third-party service is off by default, and Central is off until an administrator connects the site. Out of the box the only request PowerSEC makes on its own is to the first-party WordPress.org checksum API (5); an alert channel’s “Send test” is the one exception, contacting the destination you typed at once. IPs and usernames may be personal data — disclose the services you enable in your own policy. The User-Agent is PowerSEC/<version> alone; see each service below.

1. PowerSEC Central — https://powersec.io — dashboard for multi-site management, cloud backups, alerting, incident response. Trigger: only when an administrator connects the site. Default: off.
Sent: site URL, identifiers and API keys; WordPress/PHP/MySQL versions; plugin and theme inventory (name, slug, version, author, active state); site icon URL; disk, memory and database size; CPU load and core count; up to 14 days of pageview counts; scan summaries, security event metadata and backup status; IPs of blocked or attacking clients; administrator usernames, last login, and their email addresses (only while two-factor is on or this server cannot send mail). If a message this site sends fails, its subject and body go to Central to deliver — to your own administrators only. With two-factor on and connected, the one-time code and recipient email go to Central to deliver (otherwise wp_mail() is used and nothing leaves the site). Database-scan findings carry a short redacted excerpt plus its table and key; whole posts, option values and page output never are.
Cloud backup (paid): archives on Wasabi (*.wasabisys.com); restores use short-lived signed URLs from *.wasabisys.com, *.amazonaws.com or powersec.io. Wasabi https://wasabi.com/legal/ , https://wasabi.com/legal/privacy-policy/ — AWS https://aws.amazon.com/service-terms/ , https://aws.amazon.com/privacy/
Terms https://powersec.io/terms — Privacy https://powersec.io/privacy

2. Google Gemini — https://ai.google.dev (via Central) — an AI second opinion on a file the scanner already flagged.
Trigger: (a) manual — an administrator clicks to explain one flagged file; that click is the authorisation. (b) automated — off by default, needing an explicit local opt-in by an administrator of this site under PowerSEC > Central Connection. Connecting to Central, your plan and Central’s settings do not enable it; switching it off stops future sharing.
Sent: only a bounded, redacted excerpt of that flagged file (size-capped, secrets redacted), plus its path, size, hash and the matching rule. Whole files, whole sites, databases and files that may hold credentials (wp-config.php, .env, key/certificate files) are never sent. Advisory only: it never changes scan results, malware counts or your score, and never removes, quarantines or repairs a file.
Terms https://ai.google.dev/gemini-api/terms — Privacy https://policies.google.com/privacy

3. GeoJS — https://get.geojs.io — IP geolocation. Trigger: only when country blocking is enabled. Default: off. Sent: the visitor’s IP, to resolve its country; cached 24h, and behind Cloudflare the country comes from Cloudflare’s header with no external call.
Terms https://www.geojs.io/tos/ — Privacy https://www.geojs.io/privacy/

4. Tor Project exit list — https://check.torproject.org — the public exit-node list. Trigger: only when Tor blocking is enabled. Default: off. Sent: nothing; the request carries no visitor information.
Privacy https://www.torproject.org/about/privacy_policy/ (a public file served without an account, so no separate terms)

5. WordPress.org — https://api.wordpress.org , https://downloads.wordpress.org — the official checksum APIs core itself uses. Trigger: file-integrity monitoring (on by default) and malware scans. Sent: your WordPress version and locale for core checksums; each plugin’s slug and version for plugin checksums. No personal data.
Privacy https://wordpress.org/about/privacy/

6. Alerting / SIEM destinations — security events sent where you choose. Trigger: only when you configure and enable a channel. Default: off; on every plan. Kinds: webhook URLs you supply (Slack, Discord, Splunk HEC, custom); fixed endpoints (PagerDuty events.pagerduty.com, Datadog http-intake.logs.datadoghq.com or its regional host); raw syslog/CEF over UDP/TCP to a host you supply.
Sent: per event — type, severity, message, the WordPress username involved (on a failed login this is visitor-supplied text), client IP, timestamp, your site name and URL. Custom-webhook and Splunk formats also include event metadata, which for a login can contain the request path and user-agent; the others do not.
Terms/privacy: https://slack.com/terms-of-service , https://slack.com/trust/privacy/privacy-policy , https://discord.com/terms , https://discord.com/privacy , https://www.splunk.com/en_us/legal/terms.html , https://www.splunk.com/en_us/legal/privacy-policy.html , https://www.pagerduty.com/terms-of-service/ , https://www.pagerduty.com/privacy-policy/ , https://www.datadoghq.com/legal/terms/ , https://www.datadoghq.com/legal/privacy/ . A webhook, Splunk HEC or syslog collector you supply is your own server, so its terms are yours.

7. Your own site (loopback) — not a third party. Long backups and scans continue by calling your site’s own admin-ajax.php; nothing leaves your server.

Privacy

Recorded locally: login attempts (attempted username, IP, time), audit log (action, user, IP), sessions (user, IP, user-agent, times), and firewall/WAF/IP-blocking records (IP, path, method, user-agent). Findings describe files, not people. Retention: audit log and login attempts about 90 days (configurable), firewall/WAF/sessions about 30 days, remote requests about 7 days.

Blocked IPs follow their own rules, not the schedule above: a temporary block ends by itself when it expires; a permanent block PowerSEC created automatically is removed after about a year (configurable); one an administrator added by hand is kept until an administrator removes it.

Deleting the plugin keeps your data by default. That site’s PowerSEC tables, settings and connection details stay, so a reinstall resumes where it left off. Running wp option update powersec_delete_data_on_uninstall 1 first (no screen for it) also drops those tables and removes PowerSEC settings, stored keys, connection details, transients, per-account data and scheduled tasks, plus the firewall folder. Backup and quarantine folders remain, as do the uploads PHP-execution guards. One secret-free pending-revocation marker remains when a Central release is unconfirmed, never reported as done. wp-admin deletion cannot notify Central, so disconnect first.

WordPress export and erasure requests are answered for records tied to a WordPress account. IP-only records cannot reliably be linked to an email address, so they are not exported or erased. Where erasure would break the tamper-evident audit chain, identifying fields are anonymised instead of deleted, and the response says so.

Files and directories this plugin writes

Everything is written inside your uploads directory (wp_upload_dir()): powersec-backups/ (archives; deny-all .htaccess), powersec-quarantine/ (detected files), powersec/ (firewall rules), powersec-config-backups/ (wp-config.php copies; removed on data deletion), plus guards stopping PHP executing in uploads. Two things write outside uploads: the prefix change edits wp-config.php after backing it up, and a restore adds .maintenance to the site root, removed when it ends. Restoring overwrites site files.

Credits

Chart.js v4.5.1, @kurkle/color v0.3.2 (MIT; texts in licenses/). https://github.com/chartjs/Chart.js , https://github.com/kurkle/color

Installation

  1. Install from the Plugins screen, or upload the ZIP.
  2. Activate it, then open PowerSEC > Dashboard to scan.
  3. (Optional) Open PowerSEC > Central Connection and choose Connect automatically.

Multisite: PowerSEC supports multisite through per-site activation only. Network activation is intentionally refused, because each site keeps its own data and connection. Activate PowerSEC separately on each site where you need it. Data deletion removes per-user data network-wide.

Frequently asked questions

Is PowerSEC Central free?

Central has a free tier: connect sites and use the fleet dashboard. Paid plans add cloud backups, scheduling, AI review and alerting. Every local feature works on every plan. Automatic AI review stays off until an administrator turns it on — see External services (2).

Changelog

Malware-scan reliability fix. Recommended.

Full history ships in changelog.txt.

1.4.234

  • Fix: a malware scan started on a busy server now waits and starts on its own instead of being refused.

1.4.233

  • Fix: the malware scan now runs in the background and no longer fails with a network error on some hosts.

Full changelog on WordPress.org →

Screenshots

PowerSEC – Firewall, Malware Scanner, Login Security & Backup screenshot
PowerSEC – Firewall, Malware Scanner, Login Security & Backup screenshot
PowerSEC – Firewall, Malware Scanner, Login Security & Backup screenshot
PowerSEC – Firewall, Malware Scanner, Login Security & Backup screenshot
PowerSEC – Firewall, Malware Scanner, Login Security & Backup screenshot
PowerSEC – Firewall, Malware Scanner, Login Security & Backup screenshot

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best PowerSEC alternatives

All backup plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 All-in-One WP Migration and Backup All-in-One WP Migration and Backup Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate… by ServMask 5M+ ★★★★★★★★★★ 4.5 (7.7K) 2 weeks ago 97
2 UpdraftPlus: WP Backup & Migration Plugin UpdraftPlus: WP Backup & Migration Plugin Backup, restore or migrate your WordPress website to another host or domain. Schedule… by David Anderson / Team Updraft 4M+ ★★★★★★★★★★ 4.8 (8.7K) 1 week ago 96
3 Jetpack – WP Security, Backup, Speed, & Growth Jetpack – WP Security, Backup, Speed, & Growth Improve your WP security with powerful one-click tools like backup, WAF, and malware scan… by Automattic 3M+ ★★★★★★★★★★ 3.7 (2.4K) 3 weeks ago 91
4 Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Duplicator The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy… by Syed Balkhi 1M+ ★★★★★★★★★★ 4.9 (4.9K) 2 days ago 96
5 ManageWP Worker ManageWP Worker A better way to manage dozens of WordPress websites. by ManageWP 1M+ ★★★★★★★★★★ 4.6 (679) 1 month ago 77
6 WPvivid — Backup, Migration & Staging WPvivid — Backup, Migration & Staging All-in-one WordPress backup, migration and staging plugin — schedule automatic backups… by wpvividplugins 900K+ ★★★★★★★★★★ 4.9 (1.6K) 4 days ago 94
7 Backuply – Backup, Restore, Migrate and Clone Backuply – Backup, Restore, Migrate and Clone Backup, restores, and migration with Backuply are fairly simple with a wide range of… by Softaculous 600K+ ★★★★★★★★★★ 4.5 (135) 8 hours ago 95
8 BackWPup – WordPress Backup & Restore Plugin BackWPup – WordPress Backup & Restore Plugin Back up, restore, and protect your WordPress website with automated backups, cloud storage… by WP Media 400K+ ★★★★★★★★★★ 4 (1.3K) 3 weeks ago 92
9 JetBackup – Backup, Restore & Migrate JetBackup – Backup, Restore & Migrate Backup, restore, and migrate WordPress sites fast. Supports TAR, remote backups, multi… by JetBackup 200K+ ★★★★★★★★★★ 4.5 (1.1K) 1 month ago 70
10 InfiniteWP Client InfiniteWP Client Install this plugin on unlimited sites and manage them all from a central dashboard. This… by revmakx 200K+ ★★★★★★★★★★ 4.4 (177) 1 month ago 69

FAQ

PowerSEC: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 1, 2026

Is PowerSEC free?

Yes. PowerSEC is free to download and use from the official WordPress.org plugin directory.

Is PowerSEC safe to use in 2026?

PowerSEC is a solid plugin choice in 2026, with a few things worth checking first. It runs on 20+ sites, is rated 5/5 and was last updated 3 days ago, and scores 74/100 on our health check.

How many websites use PowerSEC?

PowerSEC is active on 20+ WordPress websites and has been downloaded 406 times since it launched in September 2026. It was downloaded 412 times in the last 30 days.

Does PowerSEC work with WordPress 7.1?

Yes. The developer has tested PowerSEC up to WordPress 7.1.2, the latest release. It requires WordPress 5.8 or newer.

What PHP version does PowerSEC need?

PowerSEC requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was PowerSEC last updated?

The latest version, 1.4.234, was released on September 28, 2026 (3 days ago).

Who makes PowerSEC?

PowerSEC is developed and maintained by CinderEye LLC.

What are the best alternatives to PowerSEC?

The most popular alternatives to PowerSEC are All-in-One WP Migration and… (5M+ installs), UpdraftPlus: WP Backup & Mi… (4M+ installs) and Jetpack (3M+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.