Stop hackers and bots from getting into your WordPress site. Ultimate Security adds two-factor login, blocks password-guessing attacks, stops spam bots and warns you about plugins with known security holes. A setup wizard picks the right settings for your kind of site, so you don't have to understand every option.
[youtube
https://www.youtube.com/watch?v=MU7KivId-cE]
Why site owners choose it
- Free, with no account needed. Install it and it works. No sign-up and no usage tracking.
- Set up in about 3 minutes. The wizard asks what kind of site you run, checks it, and shows every change before applying it. You can undo it all later.
- Try before you enforce. Test Mode shows what would have been blocked, without blocking anyone.
- You can't lock yourself out for good. The wizard gives you an emergency link that switches the plugin off from any browser.
Protect your login
Two-factor login. After the password, users confirm with a code sent by email or shown in an authenticator app (Google Authenticator, Authy, Microsoft Authenticator and similar). Choose which user roles need it. Works on the WordPress, WooCommerce and Ultimate Member login forms.
[youtube
https://www.youtube.com/watch?v=iAEsiGlb_8M]
Stop password-guessing bots.
- Lock out anyone who gets the password wrong too many times. Repeat offenders wait longer each time.
- Permanently block addresses you never want to see again.
- An administrator can send a locked-out user a 15-minute recovery link.
- Works behind Cloudflare automatically. Site Health tells you if your host's setup needs one extra step.
[youtube
https://www.youtube.com/watch?v=TkKENyFl33Y]
Hide your login page. Move
wp-login.php to a private address so bots can't find it.
Stronger passwords.
- Set rules for length, letters, numbers and symbols, or pick a ready-made preset.
- Stop people reusing old passwords, and ask for a new one on first login or after a set time.
- Reject passwords that have appeared in known data leaks. The check never sends the password itself anywhere.
Control who stays signed in.
- Limit how many devices one account can use at once.
- Sign people out automatically after a period of inactivity.
- See who is signed in right now, and end any session with one click.
Block spam and bots on your forms
Add Google reCAPTCHA or Cloudflare Turnstile to your login, registration, password reset and comment forms, and to WooCommerce login, registration and checkout.
- Check that your keys work before going live.
- If the CAPTCHA service is down, your forms keep working.
- Won't clash with another CAPTCHA plugin on the same form.
[youtube
https://www.youtube.com/watch?v=_9oKeDq2ZpQ]
Find security problems before hackers do
Vulnerability scanner. Checks WordPress, your plugins and your themes against a database of known security holes, and emails you when it finds one. It works without an API key; WPScan or Patchstack keys add extra coverage.
- Runs on a schedule in the background.
- Flags plugins that haven't been updated in a long time.
- Results show in the dashboard, Site Health and your plugins list.
[youtube
https://www.youtube.com/watch?v=SsV6Dwn9tbY]
Security score. One number that tells you how well protected your site is, and which fix to do next.
File check. Compares your WordPress core files with the official copies, so changed or added files stand out.
Safer updates. Choose when WordPress, plugins and themes update automatically. Set update days and quiet periods, delay updates by a few days, and get an email when something changes.
Advanced protection
Cloudflare firewall rules. If your site uses Cloudflare, connect your account and turn on ready-made rules from wp-admin: let good bots through, block bad crawlers and risky traffic, and block attacks on known WordPress flaws before you've had a chance to update. You can preview every rule before it goes live.
[youtube
https://www.youtube.com/watch?v=W2v08QaSCl4]
Security keys (salts). Change the secret keys in
wp-config.php on demand or on a schedule, which signs everyone out and makes stolen login cookies useless. You get a warning before a scheduled change, and can restore a previous set.
Test Mode
Turn on your protections without blocking anyone, and review a log of what would have been blocked. Choose which user roles it covers. Visitors who aren't signed in are still held to the login limit, and Test Mode switches itself off after seven days, so a forgotten test never leaves your site unprotected.
Moving from another plugin
- Import your two-factor and login settings from Wordfence Login Security. Preview it first and undo it if you change your mind.
- Copy your settings to another site, or keep a backup, as a file.
- Detects WooCommerce, Ultimate Member, page builders, form, caching and SEO plugins, and warns you if another security plugin is already doing the same job.
Privacy
No usage tracking. The plugin contacts an outside service only when you switch on a feature that needs one, and each is listed under External Services below.
For developers
wp ultimate-security template list
wp ultimate-security template apply [--dry-run]
wp ultimate-security template undo
wp ultimate-security export [--file=]
wp ultimate-security import [--dry-run]
wp ultimate-security status
wp ultimate-security unlock | --ip=
| --all
wp ultimate-security 2fa disable
wp ultimate-security captcha off
wp ultimate-security login-url reset
Video guides
Learn more
Requirements: WordPress 5.6+ and PHP 7.1+. HTTPS is strongly recommended for 2FA and secure sessions.
Install from your dashboard
- In WordPress, go to Plugins → Add New and search for "wpultimatesecurity".
- Click Install Now, then Activate.
- Follow the Security Wizard that appears — it scans your site, recommends settings, and shows you every change before applying it.
Install manually
- Download the plugin ZIP.
- Go to Plugins → Add New → Upload Plugin, choose the ZIP, and click Install Now.
- Click Activate, then follow the Security Wizard.
Or with WP-CLI:
wp plugin install ultimate-security --activate
Your first 3 minutes
- Run the Security Wizard and apply the template that matches your site.
- Save the emergency link the wizard shows you somewhere safe. It gets you back in if you ever lock yourself out.
- Turn on two-factor login for every administrator.
1.0.40
- Fix: Test Mode no longer locks out the accounts it covers when they reach the login limit. The attempt is recorded in the Test Mode log instead.
- Fix: On phones, the plugin's menu no longer makes pages scroll sideways or overlap other buttons.
- Improvement: Notifications on the email verification, two-factor and login settings pages now look and behave like the rest of the plugin.
- Improvement: Code optimized, so the plugin is a little lighter.
1.0.36
This update includes everything since 1.0.29; the versions in between were never released. It strengthens login security, adds new two-factor and lockout controls, fixes a long list of everyday problems and gives the plugin a cleaner, more consistent look. We recommend every site updates.
Security
-
Stronger protection for sign-in, two-factor authentication and brute-force limits, following an internal security review. The details are kept private so sites that have not updated yet stay safe.
New
-
Choose how many email two-factor codes can be requested every 15 minutes, and how long someone must wait before asking for another (Login → Two-Factor → Email Authentication).
- Set how many wrong two-factor codes are allowed, and how long the lockout lasts, for each method on the profile screen.
- The lockout message on the login page counts down and clears itself when the lockout ends.
- Brute-force protection now works in two stages: a few short lockouts first, then a longer one. You choose how many short lockouts come first, and you can switch the longer stage off.
- Site Health tells you when your site is behind Cloudflare but real visitor addresses are not reaching WordPress.
-
On your first visit, a "Setting up your dashboard" window shows each check as it finishes instead of empty cards. The results are saved, so the dashboard opens with real numbers next time.
Improved
-
A fresh, consistent look on every screen, including the setup wizard and the two-factor section on your profile page.
- Dark mode now covers every screen.
- Text is a little larger, and text boxes, dropdowns and switches have an outline you can actually see.
- Severity colours match everywhere: red for critical, amber for high.
- Settings pages show the page name above the form, like the dashboard.
- The unsaved-changes banner tells you which field needs attention.
- The brute-force settings are clearer: they are labelled Initial and Advanced, and the long lockout is set in minutes.
- Update Manager freeze periods need a start and an end date, and dates in the past are rejected.
- The two-factor lockout email is sent once per lockout instead of on every blocked attempt.
-
API keys pasted with an extra space or line break are cleaned up when saved.
Changed
-
The "Require authorization to reset 2FA" option added in 1.0.29 has been removed. It was off by default. If you had turned it on, users can once again reset their own two-factor method without re-entering their password.
Fixed
-
Saving settings is more reliable: switches no longer flip back, a failed save shows the real reason instead of "No internet connection", and page caches are cleared after saving.
- The hidden login page shows the right address after you save.
- Cloudflare Turnstile and Google reCAPTCHA now protect the WooCommerce block checkout as well as the classic one.
- "Update all plugins" and "Update all themes" now run the updates.
- Password-reset links from WordPress or WooCommerce are no longer logged as attacks.
- "Clear all IP lockouts" no longer empties the whole site cache on sites that use Redis or Memcached.
- People on the block list see a clear "blocked" message instead of a countdown.
- Sites behind Cloudflare no longer risk locking out many visitors at once when Cloudflare's visitor-address header is missing.
- Authenticator app setups survive uninstalling and reinstalling the plugin when you choose to keep plugin data.
- Saved API keys stay readable after you change your site's security keys (salts).
- The Patchstack and WPScan vulnerability checks work again and catch more affected versions.
- Test Mode respects the "Always exclude administrators" and "Log simulated blocks" switches, and records the right user.
- Undoing a settings import in Backup & Restore works again, and the Copy button works on sites without HTTPS.
- The reCAPTCHA and Turnstile debug logs load again, the dashboard shows your PHP version straight away, and two messages that could crash on PHP 8 are fixed.
Earlier versions
See the full history at
https://wpultimatesecurity.com/changelog/