Plugin reviews.
We run the main WordPress security plugins against live attack traffic on our own test installs, then rank them on technical merit. Rankings move when a product does, not when a press release lands. The methodology is boring. The rankings are occasionally not.
What we review.
Six categories of WordPress security tooling. Each solves a different part of the defensive picture. We pick the representative products, test them, and publish what we find.
Firewall and scanner suites
All-in-one plugin-layer security that handles firewall, scanner, 2FA, and login protection in a single install. The default-choice category.
Virtual patching
Vulnerability-intelligence-driven firewalls that ship rules for disclosed plugin CVEs before you update. Narrow scope, high value.
Malware cleanup
Incident-focused plugins built around scan, quarantine, and cleanup workflow. Measured on first-try remediation rate, not feature count.
Managed cloud WAF
DNS-layer reverse-proxy firewalls bundled with human cleanup services. The agency and enterprise tier of the market.
Hardening automation
Config-first plugins that automate the hardening layer rather than run the firewall. Security headers, 2FA, file integrity, brute-force protection.
Authentication security
Two-factor authentication, passwordless login, single sign-on, and the specialist plugins that do auth better than the suites do.
Reviews from this desk.
Best WordPress security plugins, adjusted for reality
Five plugins tested on live installs against real attack traffic. Where each one wins and where it does not.
Wordfence Review: the plugin we install by default
The firewall-plus-scanner suite that handles most of the defensive stack in one plugin. Where Premium is worth $149 and where Free is enough.
Patchstack Review: virtual patching, measured
The CVE-intelligence firewall that ships virtual patches before you update. What it catches Wordfence does not, and what it does not try to do.
MalCare Review: the cleanup plugin we install when prevention fails
Tested against three deliberate malware injections. First-try cleanup timing, pricing tiers, and when the economics of unlimited cleanups pay off.
Sucuri Review: cloud WAF, cleanup service, and who it is actually for
The agency-tier security bundle from GoDaddy. Why most WordPress sites should use Cloudflare instead, and the specific operators for whom Sucuri is the right call.
Solid Security Review: the hardening plugin, honestly assessed
Formerly iThemes Security. The best free-tier value for hardening and 2FA, with one major blind spot (no malware scanner) you should know about.
How we test.
Every review is run on the same methodology. Consistent rig, repeated process, results documented with enough specificity that you can second-guess the conclusion if you want to.
Fresh WordPress on isolated VPS
Clean install, standard plugin stack, no existing compromise. Each plugin under review is tested on an identical environment.
Live credential-stuffing pool and malware injection
120,000 credential pairs from public breach dumps. Three malware classes: pharma hack, PHP backdoor, fake plugin with webshell.
Installation to verdict: ~6 weeks per plugin
Install, configure defaults, run attack workloads, measure detection, triage false positives, test support, document pricing and paid tier upgrades.
Related work.
Reviews inform the tooling choices in our hardening playbooks and the cleanup procedures we run when prevention fails. The three pieces below are where the review work lands in practice.
How to secure a WordPress site: the complete hardening model
The eight defensive layers and where each plugin from this roster fits in the stack.
WordPress malware removal: the procedure we run on client sites
The manual cleanup methodology we use when plugin-based cleanup does not resolve an infection on the first pass.
The Essential Plugin backdoor
Why plugin selection is a trust decision, not a feature decision. The supply-chain compromise that reframed our review criteria.