Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
WordPress security and maintenance plugin: schedule auto-updates, block malicious updates during supply chain attacks, enforce two-factor authenticati …
Fuerte-WP is a WordPress plugin designed to enhance security and manage updates for WordPress sites. It offers features such as update management, admin oversight, login security, and two-factor authentication, aiming to protect sites from supply chain attacks and other vulnerabilities.
The plugin provides granular control over update settings, allowing you to schedule, defer, or block updates for plugins and themes. It is particularly suited for agencies, e-commerce stores, and anyone managing multiple WordPress sites who requires robust security measures.
Best for: This plugin is suitable for agencies and individuals managing multiple WordPress sites who need enhanced security and update management.
What it does well
Where it falls short
Fuerte-WP provides essential security and update management features for WordPress users, particularly those managing multiple sites. It may be a useful tool for enhancing site security.
Esteban's own description of Fuerte-WP, lightly tidied.
🛡️ WordPress Security and Maintenance That Prevents Problems Before They Happen
Every day, WordPress sites are compromised through supply chain attacks. A trustworthy plugin developer has their account hacked, malicious code ships as an “update”, and thousands of sites auto-install it within hours. Fuerte-WP protects your site when developers cannot protect their own update systems.
Fuerte-WP combines four defenses in one lightweight plugin: update management, admin oversight, login security, and two-factor authentication. It is built for agencies, e-commerce stores, and anyone who manages WordPress sites and needs to sleep at night.
🚨 CRITICAL: SUPPLY CHAIN ATTACK AND MALICIOUS UPDATE PROTECTION
A supply chain attack happens when an attacker compromises a developer account and pushes a malicious update that thousands of sites auto-install before anyone notices. When you learn an attack is in progress, you need to act in minutes, not days.
Fuerte-WP gives you three update modes so you can react correctly:
This is not a generic “disable updates” toggle. Deferred and Blocked are separate, intentional controls, so you can hold one compromised plugin back while the rest of the site keeps updating normally.
⚡ AUTO-UPDATE MANAGEMENT FOR CORE, PLUGINS, THEMES, AND TRANSLATIONS
Granular control over every update channel:
You can configure this once on your main site and reuse the same file-based configuration across every site you manage.
👑 ADMINISTRATOR OVERSIGHT AND ACCESS CONTROL
Most WordPress security plugins assume the administrator is the threat. Fuerte-WP assumes the administrator is trusted but busy, and that you want to protect them from themselves and from each other.
edit.php (Posts, Pages, and custom post types) and index.php are hide-only so you never strand a non-super user on a blank screen. Single-purpose core scripts (themes.php, tools.php, plugins.php) block by $pagenow. Plugin pages block by their ?page= query argument.🔒 LOGIN SECURITY (OPTIONAL, ON BY DEFAULT)
Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...