WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by WPFastSec v1.7.1

HT Security

Complete Security Suite: Security Headers, CVE Detection, Core Integrity, Login Alerts, Plugin Update Management, Force Cron, and Maintenance Mode.

HT Security

The facts

Rating
5★ from 1
Active installs
100+
Price
Free
Last updated
10 Aug 2026
Added
Apr 2025
Requires WP
6.5
Tested up to
WP 7.0.4
Requires PHP
8.2
Downloads
1,533

Our analysis

AI-assisted

HT Security is a WordPress plugin designed to enhance the security of your website through multiple protective features. It includes functionalities such as login alerts, core integrity checks, and CVE vulnerability detection by querying the National Vulnerability Database. The plugin is suitable for users looking to bolster their site's security with automated checks and notifications.

The plugin offers features like security headers, user enumeration protection, and maintenance mode with IP whitelisting. It is particularly useful for website administrators who want to monitor and manage security vulnerabilities effectively.

Best for: Website administrators seeking to enhance their WordPress site's security.

What it does well

  • Queries the National Vulnerability Database for known CVE vulnerabilities
  • Offers email notifications for login attempts and security alerts
  • Includes a core integrity check against official checksums
  • Provides maintenance mode with IP whitelisting
  • Supports multiple languages

Where it falls short

  • Limited information on user experience and support
  • No details on compatibility with specific themes or other plugins

Verdict

HT Security provides a comprehensive suite of security features for WordPress users. It is a practical choice for those prioritising website protection and vulnerability management.

From the developer

WPFastSec's own description of HT Security, lightly tidied.

HT Security is a complete security suite for WordPress, offering multiple layers of protection for your website.

Important – External Service:
This plugin queries the National Vulnerability Database (NVD) API to check for known CVE vulnerabilities. Requests are made to:
* API URL: https://services.nvd.nist.gov/rest/json/cves/2.0
* Terms of Use: https://nvd.nist.gov/general/legal-disclaimer
* Privacy Policy: https://www.nist.gov/privacy-policy
* Frequency: Automatic check every 12 hours or manual on-demand
* Data sent: Name and version of WordPress/installed plugins (no personal data is sent)

The NVD API query is essential for the plugin’s CVE vulnerability detection functionality.

Key Features

  • Security Headers – HSTS, X-Frame-Options, Content-Security-Policy, and more
  • Login Alerts – Email notifications for successful and failed login attempts with rate limiting
  • Login Captcha – Built-in SVG numeric captcha or Cloudflare Turnstile for login, password reset, and registration forms
  • Core Integrity Check – Verify WordPress core files against official checksums with 24h cache
  • CVE Vulnerability Detection – Check WordPress Core and active plugins against NVD database
  • User Enumeration Protection – Block user enumeration via REST API and author parameters
  • Maintenance Mode – Maintenance mode with authorized IP whitelist (IPv4, IPv6, CIDR support)
  • File Permissions Audit – Audit and automatic correction of critical file permissions
  • Plugin Security Indicators – Visual badges on plugins page showing vulnerability status
  • Plugin Update Management – Notify when plugins need updates; optionally auto-update only selected plugins
  • Force Cron – Secret HTTP ping to spawn WordPress cron when official wp-cron is unreliable

CVE Detection Features

  • Integration with NVD (National Vulnerability Database) API 2.0
  • Check WordPress Core and active plugins for known vulnerabilities
  • Intelligent batch processing with rate limiting
  • 8 layers of anti-false-positive validation
  • Vulnerability badges on plugins page (enable/disable option)
  • Dismissible alerts per user
  • Email notification when vulnerabilities are detected
  • Automatic check every 12 hours
  • NVD API Key support (increased rate limit)

Security Improvements in v1.5.0

  • IP Spoofing Fix – Properly detects real IP behind Cloudflare, proxies, and load balancers
  • Capability Check Fix – Authorization verified before processing
  • Rate Limiting by IP – More granular rate limiting for login alerts
  • Input Validation – Maximum length validation for feedback form

Supported Languages

  • English (US) – 100%
  • English (UK) – 100%
  • Português do Brasil – 100%
  • Português de Portugal – 100%
  • Español – 100%

License

This plugin is licensed under the GNU General Public License v2.0 or later. For more information, visit https://www.gnu.org/licenses/gpl-2.0.html.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)