← All website monitoring tools
Wordfence
Most popular WordPress security plugin — free firewall, $119/yr for real-time threat updates.
Free tier: free firewall + malware scan with 30-day delay
What it does well
- Provides a functional firewall and malware scanner at no cost.
- Offers detailed scan results and repair options directly within the WordPress dashboard.
- Includes two-factor authentication (2FA) and login attempt limits to harden user accounts.
Where it falls short
- Free version's firewall and malware signatures are updated on a 30-day delay.
- The scanner runs on your own server, which can consume resources and slow down sites.
- Firewall rules are applied after WordPress loads, making it less effective than a cloud-based WAF.
Alternatives to Wordfence
Sucuri
paidCloud WAF + malware cleanup service from $19/mo — independent of host; specialty: hack recovery.
Patchstack
freemiumVulnerability database + virtual patches for WordPress plugins — free scanning, $5/mo Pro for auto-patching.
Solid Security (iThemes)
freemiumWordPress security suite from StellarWP — free version covers basics, Pro $99/yr adds 2FA, scans, login monitoring.
WP Cerber
freemiumWordPress security plugin focused on brute-force prevention and anti-spam — free core, $9/mo Pro for malware scanning.