Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Premium WordPress Security - 100% FREE: Firewall, 2FA, Security Headers, Login and Malware Protection, File Monitor, Security Audit & more
Vigilant is a free WordPress security plugin that offers a comprehensive suite of security features. It includes a firewall, two-factor authentication, brute force protection, and malware detection, among others. The plugin is designed to protect your site from various attacks and provides easy-to-use security presets for immediate protection.
Once activated, Vigilant applies various security measures automatically, including monitoring login attempts and blocking potentially harmful requests. It is suitable for website owners looking for robust security without the cost of premium features or upsells.
Best for: This plugin is best for WordPress site owners seeking a free, all-in-one security solution.
What it does well
Where it falls short
Vigilant provides a solid set of security features at no cost, making it a practical choice for those wanting to enhance their site's protection without financial investment.
Fernando Tellado's own description of Vigilant, lightly tidied.
Vigilant provides enterprise-level WordPress security features completely free. No premium version, no upsells, no hidden features behind paywalls.
Protect your site with a complete security suite: firewall, two-factor authentication, brute force protection, security headers, file integrity monitoring, closed plugin detection, malware detection, user management, security audit logging, under attack mode and much more.
Once activated, Vigilant immediately applies firewall rules against common attacks (SQL injection, XSS, file inclusion), security headers, login attempt monitoring, XML-RPC blocking, WordPress version hiding and sensitive file protection (.htaccess, wp-config.php), after automatically backing up your existing configuration files.
Choose a preset and get protected instantly:
Standard – Balanced security suitable for most websites. Enables all modules with sensible defaults that won’t interfere with normal site operation.
Maximum Security – Strictest settings for high-security sites. Tighter rate limits, stronger CSP rules, mandatory admin notifications. May require fine-tuning for some setups.
You can always customize individual settings after applying a preset.
Is your site under active attack? Activate Under Attack mode with one click and stop malicious traffic instantly:
Under Attack mode works independently from your preset configuration. Your regular settings are preserved and restored when the mode deactivates.
Add a second verification step to your WordPress login:
Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...