Local security, no account: firewall/WAF; brute-force lockouts, 2FA, CAPTCHA, magic-link, bot/honeypot; IP blocklist/allowlist and country blocks; malware and file-change scanning; WordPress, database and session hardening; on-site backups with 1-click restore; tamper-evident audit log.
PowerSEC can connect to PowerSEC Central (
https://powersec.io) for multi-site management and vulnerability scanning (plugins, themes and core),
off by default — see External services (1). If connected, it can switch WordPress's own plugin and theme auto-update settings on or off. It never changes how core updates itself.
- Install from the Plugins screen, or upload the ZIP.
- Activate it, then open PowerSEC > Dashboard to scan.
- (Optional) Open PowerSEC > Central Connection and choose Connect automatically.
Multisite: PowerSEC supports multisite through per-site activation only. Network activation is intentionally refused, because each site keeps its own data and connection. Activate PowerSEC separately on each site where you need it. Data deletion removes per-user data network-wide.