Nimble Security protects a WordPress site from the login screen down to the files on disk, and it does all of it on your own server.
There is no account to create, no cloud service to connect and no data leaving your site. The only outbound request the free version ever makes is to the official
WordPress.org checksum API, and only when an integrity scan runs.
Everything listed below is in the free version. It is not a trial, nothing here is time-limited, and no engine is held back.
Stop attackers at the door
- Brute-force lockouts with generic login errors, so an attacker cannot tell a wrong username from a wrong password.
- Two-factor authentication with encrypted secrets, local QR enrolment, ten single-use recovery codes and replay protection.
- Session control, Application Password auditing and revocation, and optional XML-RPC authentication protection.
- Author-enumeration blocking.
Know when your files change
- WordPress core verified against the official checksums.
- SHA-256 baselines for plugins, themes, must-use plugins, drop-ins and selected configuration files.
- Plugin and theme updates are recognised as maintenance, so a routine update does not turn into a false alarm.
- Optional permission auditing reports paths writable by group or others and tightens them only when you ask. It never loosens a permission, never acts on its own and never touches anything outside the WordPress installation.
Block bad requests
- A web application firewall with Protect, Learning and Off modes.
- Rate limiting, plus correct client-IP handling behind a proxy or CDN.
- Optional Smart 404 blocking, disabled by default.
Find and contain what got in
- A local malware scanner that streams files in the background and resumes after a timeout. Nothing is uploaded for analysis.
- An inventory of installed components, ready to be matched against advisory data.
- Incidents, encrypted quarantine and restore, plugin component containment, privileged-session containment and Emergency Lockdown.
Know where you stand
Security Score rates your posture out of 100 across hardening, identity, integrity, firewall, malware detection, software updates and recovery readiness. An open high or critical incident caps the score, so a site with an active serious problem cannot display a healthy number.
What it deliberately does not do
Nimble Security does not upload your files, does not phone home, does not write executable code anywhere and does not replace backups. It protects, detects and responds; recovery comes from a backup. That is why recovery readiness counts towards the score, because remediation is far safer when a verified restore point exists.
- Upload and activate Nimble Security.
- On a new installation, choose Start Easy Setup or Skip for now.
- Easy Setup can apply the recommended local protection profile and start the first checks automatically.
- Enroll administrator 2FA when prompted.
- Review Identity, Integrity, Firewall, Scanner and Recovery status from Nimble Security > Overview.
Easy Setup never requires a Nimble account or Threat Cloud connection and can be run again later from the Nimble Security menu.
If using Nimble Security Pro, install/upgrade Free first, then Pro.