Alternatives

The best WordPress security plugin depends on what already went wrong

Nine plugins share this category and they do not do the same job. Some are firewalls. Some watch for known vulnerabilities. Some scan files and then hand you a delete button. This page sorts them by what each one actually does when a file on your server turns out to be infected, with every price and install count checked on 19 August 2026.

Install the free plugin from WordPress.org

If you are here because something is already wrong, skip to the cleanup section. That is the part we are for.

The category is four categories

Search results treat these as interchangeable and they are not. Sorting them by what they are for is the whole difference between buying the right one and finding out in an emergency.

What "removal" means, four different ways

Every product in this list that touches an infected file does one of these four things. They are not equivalent and the wording on a pricing page rarely tells you which one you are buying.

The nine, and what each is for

Plugin Installs What it is for Free tier Paid tier
Wordfence 5,000,000 Firewall in front of WordPress, plus scanning Scans, and repairs by overwriting from WordPress.org or deleting. Signatures arrive 30 days late $149/yr for same-day signatures, blocklist, audit log
All-In-One Security 1,000,000 Hardening: permissions, prefixes, salts, spam File change detection. No malware scanning, and no action on a flagged file $89/yr for a weekly off-server scan and cleanup advice
Kadence Security 700,000 Login hardening Vulnerability checks and file change logging. Has never read file contents Inside a $299/yr theme bundle. No cleanup step at any price
Sucuri 600,000 Edge firewall and human incident response Audits, monitors and hardens. Does not clean $229/yr and up. Their staff clean it, 30 to 6 hours by plan
MalCare 200,000 Scanning plus a management dashboard Detects and stops. Their own words $299/yr before anything is removed
Jetpack Protect 100,000 Vulnerability alerting, backed by WPScan Checks version numbers daily. Does not look at files $119.40/yr to scan files. Fixes by deleting and restoring a backup
NinjaFirewall 100,000 Firewall, and the best-rated plugin in this set Does not scan. Their separate NinjaScanner quarantines or restores from upstream $89/yr per domain for country and IP access control
Defender 80,000 Broad free hardening from a plugin suite Scans once you connect a free account. Repairs by overwriting, or deletes with a 30-day quarantine $60/yr list, inside a membership, for scheduled scans and alerts
Patchstack 50,000 Stopping a known vulnerability being exploited Emails you when an installed plugin has a known hole From $5 per site per month for virtual patching
Segurium Since July 2026 Removing an injection and keeping the file working Same detection as paid, 3 cleanups every 30 days, unlimited integrity restores $79/yr per site lifts the cleanup ceiling and adds unattended fixing

Install counts from api.wordpress.org and prices from each vendor's own pricing page, all read on 19 August 2026. Segurium has no meaningful install count yet, which is why the column says when it arrived instead of inventing one.

About the ratings, before you sort by them

The WordPress.org scores on 19 August 2026 were: NinjaFirewall 98 across 220 ratings, Patchstack 98 across 61, Defender 96 across 334, Wordfence 94 across 4,974, All-In-One Security 94 across 1,714, Kadence Security 92 across 3,990, Jetpack Protect 92 across 123, MalCare 88 across 544, and Sucuri 84 across 384.

Read the counts before the scores. Holding 94 across nearly five thousand ratings is a harder result than 98 across 61, and a plugin with a small, self-selected user base scores well for reasons that have little to do with how it behaves on your site. Sucuri's 84 is the one genuine outlier, and it sits under 600,000 installs, which is its own kind of signal.

Segurium has been listed since July 2026 and has almost no ratings. That is a real reason to be careful with us and we are not going to argue otherwise. The free plan exists so you can judge it on your own site.

Which one, for your situation

The gap that runs through all of them

We read eleven scanners on 18 August 2026 and found the same boundary in every one. Every repair path is gated on recognising the file as WordPress core, a WordPress.org plugin, or a WordPress.org theme, because the repair is an overwrite from the vendor's published copy. Wordfence does not render the Repair control at all otherwise.

That covers a great many infections, because a great many infections land in core or in a directory plugin. It has nothing to offer for a custom theme, a paid plugin bought outside the directory, a client site with hand-written code, or the one file in your tree nobody else on earth has a copy of. Those are the files where an injection is worth the attacker's time, and they are the files where the button on offer is Delete.

Of the eleven, three kept a restorable copy of what they removed: NinjaScanner on disk with no expiry, WP Cerber on disk with a 30-day default, and Anti-Malware Security in the posts table with no expiry. Defender quarantines too, with a 30-day default, though only for plugin files that came from WordPress.org. The rest delete and keep nothing.

How Segurium cleans a file

Segurium hashes every file on your server and checks each hash against a cloud database of known-good and known-bad files. Around 94% of your files are settled by the hash alone and never leave the server. A lookup takes about 24 milliseconds.

Detection is not a paid tier. Free and Pro read the same feed at the same moment. The only thing money changes is how many files you may clean.

When a file comes back infected, you click Fix. For an injection into an otherwise-working file, Segurium fetches a cleaned version of that exact file, whether or not it ever came from WordPress.org. Your theme keeps rendering and your plugin keeps loading. A file that is nothing but malware becomes zero bytes at the same path. When no clean version can be produced, the cleanup stops and leaves the file exactly as it found it.

The original goes into an encrypted backup on your own server first, and one click puts it back. Separately, an integrity scan compares every core, plugin and theme file against the canonical upstream copy of the exact version installed and restores anything that drifted, which is unlimited on the free plan while the file is clean.

The free ceiling is real and worth knowing before you rely on it: 3 cleanups every 30 days. A site with forty infected files is not finished in one sitting on the free plan. The integrity restore covers the core, plugin and theme half of most infections without touching that count, which in practice leaves the quota for the files nothing else can fix. Pro at $79 a year lifts the limit and turns on unattended fixing.

Install the free plugin from WordPress.org

Bulk Fix All ships free on every install, with a preflight preview of exactly what it will touch.

What Segurium does not do

Read this before you replace anything on the list above with it.

What leaves your server, in plain terms

Scanning is opt-in. Until you accept the disclosure on the plugin page, Segurium does not contact our service and does not scan.

Files are checked by SHA-256 first. A file has its bytes sent in two cases: when its hash is one we have never seen, which in practice is about 6% of them, and when you clean it and we build the replacement. Everything else is settled by hash.

Samples we do receive are kept for up to 365 days and then deleted by an automated purge, and an analyst can delete one sooner once it has been triaged. Our privacy policy lists every retention period we hold to.

Our servers are in the European Economic Area and Segurium is run from Spain, so GDPR applies to us directly rather than reaching us through an adequacy decision. Two subprocessors sit outside the EEA, for payments and for support email. Both are covered by Standard Contractual Clauses and both are named in the privacy policy.

We do not track your visitors. Segurium looks at files and login attempts.

Questions

So which one is best?
The question has no answer as asked, and any page that gives you one is selling something. Wordfence is the best free firewall for most sites. NinjaFirewall is better if you can configure your server and you want the strictest one. Patchstack is the only answer if an unpatched plugin is the thing keeping you awake. Sucuri is right if you want a person to handle the incident and you have the budget. Segurium is the answer to one question: something is already in a file and you want it out without breaking the site.
Can I run more than one?
Yes, and most people should run two. A firewall and a scanner are different jobs and the good free options are strongest in different ones. The rule is to run only one of each: one firewall, one malware scanner, one two-factor system. Two scanners walk every file twice and give you two reports to reconcile. Two two-factor systems means your users do not know which app to open.
Why does the ratings column look strange?
Because a rating out of 100 with 61 votes is not comparable to one with 4,974 votes, and this page refuses to pretend otherwise. NinjaFirewall and Patchstack both score 98. Wordfence scores 94 on nearly five thousand ratings, which is a much harder number to hold. Read the counts before the scores.
Is a free plugin enough?
For a site with no infection today, often yes. Free tiers now cover two-factor authentication, brute-force protection, IP blocking and hardening across most of this list. What free tiers rarely cover is the moment something gets in: most of them detect and then hand you a delete button. That is the gap worth planning for before you need it.
What happens to a file that never came from WordPress.org?
In most of these plugins, nothing useful. Every repair path in every one we read is gated on recognising the file as WordPress core, a WordPress.org plugin, or a WordPress.org theme, because the repair is an overwrite from the vendor's published copy. Wordfence does not even render the Repair control otherwise. A custom theme file, a paid plugin or anything hand-written leaves you with delete or an editor. That is the specific gap Segurium was built for.
How current are these figures?
Every price, install count and rating on this page was read from the vendor's own pricing page or from api.wordpress.org on 19 August 2026. They are all theirs to change, so check anything you are about to spend money on.

Comparing something else?

Pick a firewall, then pick a cleaner

Most sites want two plugins, not one. Take the free firewall that suits your host, then install Segurium and run one scan to find out whether anything got in before you started paying attention. It is free and it takes twenty minutes.