WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Cornelius Bergen v1.4.1

Gauntlet Security

Performs a detailed security analysis of your WordPress installation. Provides specific instructions on how to make your site more secure.

Gauntlet Security

The facts

Rating
5★ from 8
Active installs
50+
Price
Free
Last updated
19 Jul 2016
Added
Sep 2014
Requires WP
3.4
Tested up to
WP 4.6.30
Downloads
8,576

Our analysis

AI-assisted

Gauntlet Security is a WordPress plugin designed to help you identify potential security improvements for your website. It conducts checks on various aspects of your site's configuration, including file permissions, server software, and user accounts, providing a detailed report with pass, warning, or fail statuses for each check. The plugin does not make changes to your files or database, leaving the implementation of fixes up to you.

This plugin is suitable for users who want to enhance their site's security by following best practices. It offers clear guidance based on recommendations from the WordPress codex, making it accessible for those who are comfortable with basic site management and configuration adjustments.

Best for: This plugin is best for WordPress site owners looking to improve their security posture.

What it does well

  • Identifies security issues in site configuration
  • Provides clear explanations for each check
  • Compatible with other security plugins
  • Does not alter files or database directly
  • Based on WordPress codex recommendations

Where it falls short

  • Requires user to implement recommended fixes
  • Some changes may need technical knowledge
  • Last updated in July 2016, may be outdated

Verdict

Gauntlet Security can be a useful tool for identifying security vulnerabilities, but users should be prepared to take action on the recommendations provided.

From the developer

Cornelius Bergen's own description of Gauntlet Security, lightly tidied.

Gauntlet Security can find opportunities for improving the security of your site. It checks many aspects of the site’s configuration including file permissions, server software, PHP, database, plugins, themes, and user accounts. The plugin will give each check a pass, warning, or fail and explain in clear language how you can fix the issue.

How you ultimately choose to patch these issues is up to you but whatever method you use, this plugin should always provide an accurate report. It does not make changes to your database or to any of your files and it should be compatible with all other security plugins.

Checks and recommendations include:

  • Set correct file and directory permissions
  • Turn off directory indexing
  • Prevent code execution in the uploads directory
  • Block files in the includes directory
  • Prevent access to stray files which could be useful to attackers
  • Keep PHP up-to-date
  • Disable dangerous PHP functions
  • Disable allow_url_include and allow_url_fopen PHP flags
  • Turn off the display of PHP errors
  • Don’t advertise the PHP version you are running
  • Use a strong database password
  • Change the default database table prefix
  • Keep WordPress up-to-date
  • Turn off file editing in the control panel
  • Set security keys in WP-Config file
  • Don’t advertise the WordPress version you are running
  • Turn off self-registration
  • Force SSL when accessing the admin area
  • Review the development activity and reputation of all plugins
  • Remove unused themes from the server
  • Rename the plugin directory
  • Move the active theme to an alternate location
  • Do not use TimThumb
  • Do not use common user names (such as “admin”)
  • Do not use weak passwords
  • Do not have a user with an ID = 1
  • Minimize the number of admin users
  • Users should not display their login usernames publicly
  • Prevent username enumeration through standard author URLs
  • …more tests planned

Check the screenshots for more detail on some of the above features.

Many of these security checks are based on recommendations from the WordPress codex: https://codex.wordpress.org/Hardening_WordPress.

Disclaimer

Some of the tips included in this plugin only require making small changes to configuration files (.htaccess, php.ini, wp-config.php, functions.php). Others require more in-depth changes to the filesystem or database. Before attempting any of these fixes, you should be comfortable experimenting and know how to undo any change you make. That includes making backups and knowing how restore your site from those backups. I can’t guarantee that the recommendations or sample code provided in this plugin will not break your site or that they will prevent it from being hacked.

Requirements

  • Apache web server
  • WordPress 3.4 minimum
  • PHP 5.2.7 minimum

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)