BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Security Hardener icon
Actively maintained Tested with WP 7.1 #21 in Brute Force

Security Hardener

Basic hardening: secure headers, login honeypot, user enumeration blocking, generic login errors, rate limiting, and more.

Active installs200+100+ tier
Downloads · 30d204▼ -28.4% vs prev. 30d
Rating—0 reviews
Health score65/100Good
All-time downloads2.4KSince Nov 2025
Support resolved—No recent threads
RequiresWP 6.9PHP 8.2+
Downloads · 7d53▲ +43.2% week over week
Our verdict

Solid choice

Security Hardener is a solid plugin choice in 2026, with a few things worth checking first. It runs on 200+ sites and was last updated 2 months ago, and scores 65/100 on our health check.

  • Tested with the latest WordPress (7.1)
  • Small user base (200+ active installs)
  • Very few reviews so far
  • Needs PHP 8.2 or newer

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

71522Jul 6Aug 19Oct 3
Yesterday12
Daily average (1y)7
Peak day62Apr 17, 2026
Last 12 months2.4K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Security Hardener stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
Brute Force >100 683 Best Brute Force plugins →
hardening #53 2,137 Best hardening plugins →
headers >100 10,000 Best headers plugins →
login protection >100 1,792 Best login protection plugins →
security >100 10,000 Best security plugins →

Version adoption

Share of active sites per release.

  • 1.730.6%
  • 2.428.3%
  • 1.514.0%
  • 1.49.7%
  • 1.36.6%
  • 1.66.6%
  • Other4.3%

About Security Hardener

From the official readme · v2.4.5

Description

Security Hardener applies WordPress security best practices based on the WordPress Advanced Administration / Security / Hardening documentation and widely accepted hardening measures. It uses WordPress core functions and follows best practices without modifying core files.

Key Features

File Security:
* Disable file editor in WordPress admin
* Optionally disable all file modifications

XML-RPC Protection:
* Disable XML-RPC completely
* Remove pingback methods when XML-RPC is enabled

Pingback Protection:
* Disable self-pingbacks
* Remove X-Pingback header
* Block incoming pingbacks

User Enumeration Protection:
* Block /?author=N queries (returns 404)
* Secure REST API user endpoints (require authentication)
* Remove users from XML sitemaps
* Prevent canonical redirects that expose usernames
* Optionally block author feed pages (/author/username/feed/)
* Optionally anonymize the author name in oEmbed responses

Login Security:
* Generic error messages (no username/password hints)
* Login honeypot
* Block unsafe usernames
* Application Passwords disabled by default
* IP-based rate limiting with configurable thresholds
* Security event logging

Security Headers:
* X-Frame-Options: SAMEORIGIN (clickjacking protection)
* X-Content-Type-Options: nosniff (MIME sniffing protection)
* Referrer-Policy: strict-origin-when-cross-origin
* Permissions-Policy (restricts geolocation, microphone, camera)
* Optional HSTS (HTTP Strict Transport Security) for HTTPS sites — max-age set to 1 year

Additional Hardening:
* Hide WordPress version (meta generator tag and asset query strings)
* Remove obsolete wp_head items (RSD, WLW manifest, shortlink, emoji scripts)
* System Status — monitors file permissions, WP_DEBUG, user registration, PHP version, administrator accounts, and database version

⚠️ Important: Always test security settings in a staging environment first. Some features may affect third-party integrations or plugins.

Privacy: This plugin does not send data to external services and does not create custom database tables. It stores plugin settings and a security event log in the WordPress options table, and uses transients for temporary login attempt tracking. All data is preserved on uninstall by default and only deleted if the “Delete all data on uninstall” option is explicitly enabled.

Installation

Automatic Installation

  1. Go to Plugins > Add New Plugin
  2. Search for Security Hardener
  3. Click Install Now and then Activate
  4. Configure settings at Settings > Security Hardener

Frequently asked questions

What are the default settings?

By default, the plugin enables: * File editor disabled * XML-RPC disabled * User enumeration blocking * Generic login errors * Login honeypot * Block unsafe usernames * Login rate limiting (5 attempts per 15 minutes) * Security headers * WordPress version hiding (meta generator tag and asset query strings) * Clean wp_head output * Security event logging * Application Passwords disabled HSTS and author feed blocking are disabled by default. Application Passwords are disabled by default — disable this option only if you use the WordPress mobile app, Jetpack, or other REST API integrations that…

Does this plugin slow down my site?

No. The plugin uses lightweight WordPress hooks and native functions. Security headers add negligible overhead, and rate limiting only checks transients during login attempts.

I use a CDN or proxy (Cloudflare, etc.). How do I get the correct IP?

By default, rate limiting uses REMOTE_ADDR. If behind a trusted proxy, add this to wp-config.php: define('WPSH_TRUSTED_PROXIES', array( '173.245.48.0', // Example: Cloudflare IP range // Add your proxy IPs here )); The plugin will then check HTTP_CF_CONNECTING_IP (Cloudflare) or HTTP_X_FORWARDED_FOR headers.

What headers does this plugin add?

When security headers are enabled: * X-Frame-Options: SAMEORIGIN * X-Content-Type-Options: nosniff * Referrer-Policy: strict-origin-when-cross-origin * Permissions-Policy: geolocation=(), microphone=(), camera=() When HSTS is enabled (HTTPS only): * Strict-Transport-Security: max-age=31536000 (optionally with includeSubDomains if enabled)

Does the plugin work with page caching?

Yes. Security headers are sent at the PHP level before caching. However, if you use aggressive server-level caching, you may need to configure your cache to allow these headers through.

Can I use this with other security plugins?

Yes, but be careful of conflicts. If another plugin also: * Sends security headers, you may get duplicates (usually harmless) * Blocks user enumeration, one should be disabled * Has login rate limiting, choose one to avoid confusion This plugin is designed to be lightweight and focused on core WordPress hardening.

What happens to my data when I uninstall?

When you uninstall (not just deactivate) the plugin, data is preserved by default. If you have enabled the “Delete all data on uninstall” option under Settings > Security Hardener > Other Settings, then on uninstall: * All plugin settings are deleted * All security logs are deleted * All login rate limiting transients are cleared * Your WordPress installation is returned to its default state Note: Deactivating the plugin always preserves all settings.

Does this block the WordPress REST API?

No. The plugin only secures user-related endpoints by requiring authentication. All other REST API functionality works normally. Public endpoints like oEmbed continue to work.

I’m locked out after too many failed attempts. What do I do?

Failed login blocks expire automatically based on your configured window (default: 15 minutes). Wait for the block period to expire, or: Access your database (phpMyAdmin, etc.) Search for options with _transient_wpsh_login_ in the name Delete those transient options Try logging in again

How do I know if the plugin is working?

Check Settings > Security Hardener for active features Review the “Recent Security Events” log Use browser dev tools to inspect HTTP headers Try accessing /?author=1 (should return 404 if blocking is enabled) Test failed login attempts to verify rate limiting

Does this plugin require HTTPS?

Not required, but strongly recommended. HSTS features require HTTPS. For maximum security, your entire site should use HTTPS with a valid SSL certificate.

Is this plugin compatible with multisite?

The plugin is designed for single-site installations. Multisite compatibility has not been tested and is not officially supported at this time.

Changelog

2.4.5 – 2026-08-01

  • Security fix.
  • Improved: Security logs now show a message when empty instead of hiding the section.

2.4.4 – 2026-06-13

  • Fixed: Security improvement in get_blocked_usernames().
  • Fixed: Username length limited in security logs.
  • Fixed: Type hints and docblock corrections.
  • Updated: Some text improvements.
  • Improved: Accessibility and UX improvements.

2.4.3 – 2026-05-25

  • Updated: Tested up to WordPress 7.0.

2.4.2 – 2026-04-24

  • Improved: Added RTL language support.
  • Updated: Some text improvements.

2.4.1 – 2026-04-18

  • Improved: System Status PHP version check now uses wp_check_php_version().
  • Improved: System Status database version check now reads directly from wpdb.
  • Improved: System Status administrator count now uses WP_User_Query with count_total.
  • Improved: System Status PHP version and database version status messages are now consistent.
  • Improved: System Status PHP and database checks now show yellow when below the recommended version, green when above.
  • Fixed: Type hints added to get_option(), sanitize_options(), remove_xmlrpc_pingback(), remove_x_pingback(), and disable_self_pingbacks() for PHP 8.2+ consistency.
  • Fixed: render_system_status() docblock updated to reflect all six checks.
  • Fixed: WPSH_FILE constant removed — activation hooks now use FILE directly.

2.4.0 – 2026-04-18

  • Improved: Settings page reduced from 7 to 6 cards — HSTS options merged into Security headers card
  • Improved: “Disable Application Passwords” moved to Login security card, between Block unsafe usernames and Login rate limiting
  • Improved: System Status section now appears before Recent Security Events
  • Improved: System Status expanded with four new checks — public user registration status, PHP version, number of administrator accounts, and database version
  • Improved: System Status is now collapsible
  • Improved: Hardening checklist now displays in two columns to reduce vertical space
  • Improved: “Reset all” renamed to “Reset recommendations” and styled as a standard button for consistency with Clear Logs
  • Improved: Removed persistent “Important” notice from the settings page header
  • Improved: Added aria-label to all toggle inputs for screen reader accessibility
  • Improved: Checklist items shortened to fit a single line in two-column layout
  • Added: Four new checklist items — disable directory browsing, use SFTP instead of FTP, install plugins/themes from trusted sources only, keep active plugins minimal
  • Removed: Two redundant checklist items — “Rename the default admin account” and “Disable WP_DEBUG on live sites”
  • Fixed: AJAX checklist validation aligned with actual item count throughout

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Security Hardener alternatives

All Brute Force plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention Limit Login Attempts Security WordPress login security with brute force protection, Two-factor authentication (2FA/MFA)… by WPChef 1M+ ★★★★★★★★★★ 4.8 (1.5K) 2 weeks ago 91
2 CloudSecure WP Security CloudSecure WP Security CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。… by XServer 100K+ ★★★★★★★★★★ 5 (2) 5 days ago 86
3 Anti-Malware Security and Brute-Force Firewall Anti-Malware Security and Brute-Force Firewall This Anti-Malware scanner searches for Malware, Viruses, and other security threats and… by Eli 100K+ ★★★★★★★★★★ 4.9 (783) 3 months ago 81
4 Hide My WP Ghost – Security & Firewall Hide My WP Ghost – Security & Firewall Hide My WP Ghost is a WordPress security plugin that hides WP paths and protects your site… by John Darrel 100K+ ★★★★★★★★★★ 4.5 (372) 1 day ago 94
5 WP fail2ban – Advanced Security WP fail2ban – Advanced Security WP fail2ban uses fail2ban to protect your WordPress site. by invisnet 60K+ ★★★★★★★★★★ 4.2 (71) 4 days ago 76
6 XO Security XO Security XO Security is a plugin to enhance login related security. by ishitaka 30K+ ★★★★★★★★★★ 5 (11) 3 months ago 77
7 User Login History User Login History Helps you to know your website's visitors by tracking their login related information like… by Faiyaz Alam 10K+ ★★★★★★★★★★ 4.6 (29) 7 months ago 64
8 IP Geo Block IP Geo Block It blocks spam posts, login attempts and malicious access to the back-end requested from… by tokkonopapa 8K+ ★★★★★★★★★★ 4.2 (95) 8 years ago 42
9 HTTP Auth HTTP Auth Provides comprehensive security during development by protecting your entire site and your… by Sami Ahmed Siddiqui 6K+ ★★★★★★★★★★ 4.2 (6) 1 year ago 47
10 Stop XML-RPC Attacks Stop XML-RPC Attacks Blocks dangerous XML-RPC methods while preserving Jetpack, WooCommerce, and mobile apps… by Pascal CESCATO 6K+ ★★★★★★★★★★ 5 (4) 1 month ago 75

FAQ

Security Hardener: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 4, 2026

Is Security Hardener free?

Yes. Security Hardener is free to download and use from the official WordPress.org plugin directory.

Is Security Hardener safe to use in 2026?

Security Hardener is a solid plugin choice in 2026, with a few things worth checking first. It runs on 200+ sites and was last updated 2 months ago, and scores 65/100 on our health check.

How many websites use Security Hardener?

Security Hardener is active on 200+ WordPress websites and has been downloaded 2,357 times since it launched in November 2025. It was downloaded 204 times in the last 30 days.

Does Security Hardener work with WordPress 7.1?

Yes. The developer has tested Security Hardener up to WordPress 7.1.2, the latest release. It requires WordPress 6.9 or newer.

What PHP version does Security Hardener need?

Security Hardener requires PHP 8.2 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Security Hardener last updated?

The latest version, 2.4.5, was released on August 19, 2026 (2 months ago).

Who makes Security Hardener?

Security Hardener is developed and maintained by Marc Armengou.

What are the best alternatives to Security Hardener?

The most popular alternatives to Security Hardener are Limit Login Attempts Securi… (1M+ installs), CloudSecure WP Security (100K+ installs) and Anti-Malware Security and B… (100K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.