A standalone security suite that runs on your own server: firewall rule categories, IP rules, rate limits, scheduled integrity scans, file change monitoring, file repair and quarantine, and live traffic.
Read the documentationThe Suite contains everything it needs and does not require the free plugin. If the free 007AJ Security Scanner & Firewall plugin is also active, it pauses itself and the Suite does all the work. Every protection is off until you turn it on.
SQL injection, XSS, path traversal, code and command injection, sensitive file probes and attack-tool user agents, each switchable. Custom allow and block paths, optional form value checks and an XML-RPC switch.
IPv4 and IPv6 addresses and CIDR ranges. Allowlisted addresses skip the firewall, limits and lockout; block-listed addresses get 403. Your own address cannot be blocked by mistake.
Per-IP limits for login posts, all requests, REST requests and “not found” floods, with temporary blocks you can lift from the Dashboard.
Core files against WordPress.org checksums, plus optional checks of plugins from WordPress.org against their published checksums.
Restore a modified or missing core or WordPress.org plugin file from WordPress.org, only if the download matches the official checksum, with a backup first. Quarantine unknown files and restore them if needed.
Daily or weekly scans with WP-Cron and a plain-text email digest.
Baseline of core, plugin and theme files; reports added, modified and removed files and accepts changes from updates automatically.
The newest 1,000 requests from the last 7 days, without query strings, with optional IP shortening and one-click blocking.
Everything in the free plugin, in one standalone plugin.
wp-cron.php) for scheduled scans and file change checksREMOTE_ADDR