Plugin Reviews

Plugin reviews.

We run the main WordPress security plugins against live attack traffic on our own test installs, then rank them on technical merit. Rankings move when a product does, not when a press release lands. The methodology is boring. The rankings are occasionally not.

What we review.

Six categories of WordPress security tooling. Each solves a different part of the defensive picture. We pick the representative products, test them, and publish what we find.

01

Firewall and scanner suites

All-in-one plugin-layer security that handles firewall, scanner, 2FA, and login protection in a single install. The default-choice category.

02

Virtual patching

Vulnerability-intelligence-driven firewalls that ship rules for disclosed plugin CVEs before you update. Narrow scope, high value.

03

Malware cleanup

Incident-focused plugins built around scan, quarantine, and cleanup workflow. Measured on first-try remediation rate, not feature count.

04

Managed cloud WAF

DNS-layer reverse-proxy firewalls bundled with human cleanup services. The agency and enterprise tier of the market.

05

Hardening automation

Config-first plugins that automate the hardening layer rather than run the firewall. Security headers, 2FA, file integrity, brute-force protection.

06

Authentication security

Two-factor authentication, passwordless login, single sign-on, and the specialist plugins that do auth better than the suites do.

Reviews from this desk.

How we test.

Every review is run on the same methodology. Consistent rig, repeated process, results documented with enough specificity that you can second-guess the conclusion if you want to.

01
Test install

Fresh WordPress on isolated VPS

Clean install, standard plugin stack, no existing compromise. Each plugin under review is tested on an identical environment.

02
Attack traffic

Live credential-stuffing pool and malware injection

120,000 credential pairs from public breach dumps. Three malware classes: pharma hack, PHP backdoor, fake plugin with webshell.

03
Timed workflow

Installation to verdict: ~6 weeks per plugin

Install, configure defaults, run attack workloads, measure detection, triage false positives, test support, document pricing and paid tier upgrades.

Related work.

Reviews inform the tooling choices in our hardening playbooks and the cleanup procedures we run when prevention fails. The three pieces below are where the review work lands in practice.

Scroll to Top