Alternatives
The best WordPress security plugin depends on what already went wrong
Nine plugins share this category and they do not do the same job. Some are firewalls. Some watch for known vulnerabilities. Some scan files and then hand you a delete button. This page sorts them by what each one actually does when a file on your server turns out to be infected, with every price and install count checked on 19 August 2026.
Install the free plugin from WordPress.org
If you are here because something is already wrong, skip to the cleanup section. That is the part we are for.
The category is four categories
Search results treat these as interchangeable and they are not. Sorting them by what they are for is the whole difference between buying the right one and finding out in an emergency.
- Firewalls stop a bad request. Wordfence and NinjaFirewall can both run before WordPress loads, which is the strongest position available to a plugin. Sucuri's paid product goes further and filters at the edge, before the request reaches your server at all.
- Vulnerability watchers tell you a plugin you already run has a known hole. Patchstack and Jetpack Protect are both in this business, and Patchstack can additionally neutralise a specific hole without the plugin being updated. Neither looks at your files.
- Hardeners close doors before anything happens: two-factor, permissions, login limits, headers. All-In-One Security, Kadence Security and Defender are strongest here, and most of the list ships some of it free.
- Scanners and cleaners answer whether something is in a file right now, and what to do about it. This is the smallest group and the one where the differences are largest, which is what the next section is about.
What "removal" means, four different ways
Every product in this list that touches an infected file does one of these four things. They are not equivalent and the wording on a pricing page rarely tells you which one you are buying.
- Delete. The file goes. Fine for a dropped backdoor with no legitimate purpose. On a theme file it takes the site down with it.
- Overwrite from upstream. The file is replaced with the vendor's published copy from WordPress.org. This is the industry norm and it works well, right up to the point where the infected file never came from WordPress.org. It also discards any edits you made.
- Quarantine. The file is moved somewhere unreachable and kept, so you can put it back. It stops the malware running. It repairs nothing.
- Clean in place. The injected code is removed and the rest of the file is kept, so a custom theme file carries on rendering. This is what Segurium does and it is rare enough that most of the pages ranking for this query do not distinguish it from the other three.
The nine, and what each is for
| Plugin | Installs | What it is for | Free tier | Paid tier |
|---|---|---|---|---|
| Wordfence | 5,000,000 | Firewall in front of WordPress, plus scanning | Scans, and repairs by overwriting from WordPress.org or deleting. Signatures arrive 30 days late | $149/yr for same-day signatures, blocklist, audit log |
| All-In-One Security | 1,000,000 | Hardening: permissions, prefixes, salts, spam | File change detection. No malware scanning, and no action on a flagged file | $89/yr for a weekly off-server scan and cleanup advice |
| Kadence Security | 700,000 | Login hardening | Vulnerability checks and file change logging. Has never read file contents | Inside a $299/yr theme bundle. No cleanup step at any price |
| Sucuri | 600,000 | Edge firewall and human incident response | Audits, monitors and hardens. Does not clean | $229/yr and up. Their staff clean it, 30 to 6 hours by plan |
| MalCare | 200,000 | Scanning plus a management dashboard | Detects and stops. Their own words | $299/yr before anything is removed |
| Jetpack Protect | 100,000 | Vulnerability alerting, backed by WPScan | Checks version numbers daily. Does not look at files | $119.40/yr to scan files. Fixes by deleting and restoring a backup |
| NinjaFirewall | 100,000 | Firewall, and the best-rated plugin in this set | Does not scan. Their separate NinjaScanner quarantines or restores from upstream | $89/yr per domain for country and IP access control |
| Defender | 80,000 | Broad free hardening from a plugin suite | Scans once you connect a free account. Repairs by overwriting, or deletes with a 30-day quarantine | $60/yr list, inside a membership, for scheduled scans and alerts |
| Patchstack | 50,000 | Stopping a known vulnerability being exploited | Emails you when an installed plugin has a known hole | From $5 per site per month for virtual patching |
| Segurium | Since July 2026 | Removing an injection and keeping the file working | Same detection as paid, 3 cleanups every 30 days, unlimited integrity restores | $79/yr per site lifts the cleanup ceiling and adds unattended fixing |
Install counts from api.wordpress.org and prices from each vendor's own pricing page, all read on 19 August 2026. Segurium has no meaningful install count yet, which is why the column says when it arrived instead of inventing one.
About the ratings, before you sort by them
The WordPress.org scores on 19 August 2026 were: NinjaFirewall 98 across 220 ratings, Patchstack 98 across 61, Defender 96 across 334, Wordfence 94 across 4,974, All-In-One Security 94 across 1,714, Kadence Security 92 across 3,990, Jetpack Protect 92 across 123, MalCare 88 across 544, and Sucuri 84 across 384.
Read the counts before the scores. Holding 94 across nearly five thousand ratings is a harder result than 98 across 61, and a plugin with a small, self-selected user base scores well for reasons that have little to do with how it behaves on your site. Sucuri's 84 is the one genuine outlier, and it sits under 600,000 installs, which is its own kind of signal.
Segurium has been listed since July 2026 and has almost no ratings. That is a real reason to be careful with us and we are not going to argue otherwise. The free plan exists so you can judge it on your own site.
Which one, for your situation
- Nothing is wrong and you want to keep it that way, for free. Wordfence Free is the default answer and it is a good one. Its firewall can load before WordPress does. Accept that new signatures reach you 30 days after paying users, which their own pricing page states plainly. Defender Free is the alternative if you want more hardening in one plugin and do not mind connecting an account.
- You run a plugin you cannot update. Patchstack, and nothing else on this list. Virtual patching neutralises a specific known vulnerability while the vulnerable code stays where it is. We do not ship it and neither does anyone else here.
- You want the strictest firewall and can configure a server. NinjaFirewall in Full WAF mode. It carries the best rating in the set. Their own documentation warns it may not work at all on some shared hosting, so read that before you commit.
- You want a person to handle the incident. Sucuri from $229 a year, or Wordfence Care at $590. Both put trained people on your site. Nobody at Segurium logs into yours, ever, and if you want a phone number during an incident you should buy theirs.
- Something is already in a file and you want it out today. That is the one column where this list thins out, and it is the rest of this page.
The gap that runs through all of them
We read eleven scanners on 18 August 2026 and found the same boundary in every one. Every repair path is gated on recognising the file as WordPress core, a WordPress.org plugin, or a WordPress.org theme, because the repair is an overwrite from the vendor's published copy. Wordfence does not render the Repair control at all otherwise.
That covers a great many infections, because a great many infections land in core or in a directory plugin. It has nothing to offer for a custom theme, a paid plugin bought outside the directory, a client site with hand-written code, or the one file in your tree nobody else on earth has a copy of. Those are the files where an injection is worth the attacker's time, and they are the files where the button on offer is Delete.
Of the eleven, three kept a restorable copy of what they removed: NinjaScanner on disk with no expiry, WP Cerber on disk with a 30-day default, and Anti-Malware Security in the posts table with no expiry. Defender quarantines too, with a 30-day default, though only for plugin files that came from WordPress.org. The rest delete and keep nothing.
How Segurium cleans a file
Segurium hashes every file on your server and checks each hash against a cloud database of known-good and known-bad files. Around 94% of your files are settled by the hash alone and never leave the server. A lookup takes about 24 milliseconds.
Detection is not a paid tier. Free and Pro read the same feed at the same moment. The only thing money changes is how many files you may clean.
When a file comes back infected, you click Fix. For an injection into an otherwise-working file, Segurium fetches a cleaned version of that exact file, whether or not it ever came from WordPress.org. Your theme keeps rendering and your plugin keeps loading. A file that is nothing but malware becomes zero bytes at the same path. When no clean version can be produced, the cleanup stops and leaves the file exactly as it found it.
The original goes into an encrypted backup on your own server first, and one click puts it back. Separately, an integrity scan compares every core, plugin and theme file against the canonical upstream copy of the exact version installed and restores anything that drifted, which is unlimited on the free plan while the file is clean.
The free ceiling is real and worth knowing before you rely on it: 3 cleanups every 30 days. A site with forty infected files is not finished in one sitting on the free plan. The integrity restore covers the core, plugin and theme half of most infections without touching that count, which in practice leaves the quota for the files nothing else can fix. Pro at $79 a year lifts the limit and turns on unattended fixing.
Install the free plugin from WordPress.org
Bulk Fix All ships free on every install, with a preflight preview of exactly what it will touch.
What Segurium does not do
Read this before you replace anything on the list above with it.
- No firewall in front of WordPress. Ours filters inside WordPress, after PHP has accepted the request. Wordfence and NinjaFirewall both do better than that, and Sucuri's paid product filters at the edge before the request reaches you.
- No virtual patching and no vulnerability database. We do not check your installed versions against known holes at all. Patchstack owns that and their database is free to browse whether or not you use their plugin.
- No curated IP blocklist, and no security audit log. Wordfence Premium and Defender both offer a maintained blocklist. You write your own rules here.
- No CDN, no DDoS protection, no uptime monitoring, no backups product. DDoS protection normally arrives from your host or a CDN, so a bare no overstates what you would be losing, but if you were buying Sucuri for the edge then you were buying something we have no answer to.
- Nobody cleans it for you. No incident response, no phone number, no analyst logging into your site. That is most of the price difference against Sucuri and Wordfence Care.
- No track record. Listed since July 2026. Everything else on this page has years of it.
What leaves your server, in plain terms
Scanning is opt-in. Until you accept the disclosure on the plugin page, Segurium does not contact our service and does not scan.
Files are checked by SHA-256 first. A file has its bytes sent in two cases: when its hash is one we have never seen, which in practice is about 6% of them, and when you clean it and we build the replacement. Everything else is settled by hash.
Samples we do receive are kept for up to 365 days and then deleted by an automated purge, and an analyst can delete one sooner once it has been triaged. Our privacy policy lists every retention period we hold to.
Our servers are in the European Economic Area and Segurium is run from Spain, so GDPR applies to us directly rather than reaching us through an adequacy decision. Two subprocessors sit outside the EEA, for payments and for support email. Both are covered by Standard Contractual Clauses and both are named in the privacy policy.
We do not track your visitors. Segurium looks at files and login attempts.
Questions
- So which one is best?
- The question has no answer as asked, and any page that gives you one is selling something. Wordfence is the best free firewall for most sites. NinjaFirewall is better if you can configure your server and you want the strictest one. Patchstack is the only answer if an unpatched plugin is the thing keeping you awake. Sucuri is right if you want a person to handle the incident and you have the budget. Segurium is the answer to one question: something is already in a file and you want it out without breaking the site.
- Can I run more than one?
- Yes, and most people should run two. A firewall and a scanner are different jobs and the good free options are strongest in different ones. The rule is to run only one of each: one firewall, one malware scanner, one two-factor system. Two scanners walk every file twice and give you two reports to reconcile. Two two-factor systems means your users do not know which app to open.
- Why does the ratings column look strange?
- Because a rating out of 100 with 61 votes is not comparable to one with 4,974 votes, and this page refuses to pretend otherwise. NinjaFirewall and Patchstack both score 98. Wordfence scores 94 on nearly five thousand ratings, which is a much harder number to hold. Read the counts before the scores.
- Is a free plugin enough?
- For a site with no infection today, often yes. Free tiers now cover two-factor authentication, brute-force protection, IP blocking and hardening across most of this list. What free tiers rarely cover is the moment something gets in: most of them detect and then hand you a delete button. That is the gap worth planning for before you need it.
- What happens to a file that never came from WordPress.org?
- In most of these plugins, nothing useful. Every repair path in every one we read is gated on recognising the file as WordPress core, a WordPress.org plugin, or a WordPress.org theme, because the repair is an overwrite from the vendor's published copy. Wordfence does not even render the Repair control otherwise. A custom theme file, a paid plugin or anything hand-written leaves you with delete or an editor. That is the specific gap Segurium was built for.
- How current are these figures?
- Every price, install count and rating on this page was read from the vendor's own pricing page or from api.wordpress.org on 19 August 2026. They are all theirs to change, so check anything you are about to spend money on.
Comparing something else?
Pick a firewall, then pick a cleaner
Most sites want two plugins, not one. Take the free firewall that suits your host, then install Segurium and run one scan to find out whether anything got in before you started paying attention. It is free and it takes twenty minutes.