Switching
Moving from All-In-One Security to Segurium
Two things come across on their own: your banned IP addresses and your scan exclusions, both kinds. Nothing else does, and there is a good reason for each omission. Most people reading this should keep AIOS installed, which is covered further down.
Install the free plugin from WordPress.org
No card, no trial clock. The Migration tab shows you a preview before it writes anything.
What the importer reads
- Banned IP addresses. Your AIOS blacklist, validated as addresses and CIDR ranges, merged into the Segurium firewall rules and deduplicated. If the firewall was off, it switches on in deny-list mode with your imported addresses as the list.
- Scan exclusions, both settings. AIOS keeps excluded file paths
and excluded file extensions in two places. Segurium keeps one list,
so the importer merges both. Each extension becomes a wildcard on the
way in, so an AIOS entry of
.logarrives here as*.log. Your list gets longer and means the same thing.
Read from the shipped adapter on 19 August 2026. Coverage differs per source plugin. The Wordfence importer reads four things and the Solid Security one reads a single thing, so do not carry this list across.
What it skips, and why
- The IP whitelist. Skipped deliberately, not missed. An AIOS whitelist entry means let this address through no matter what. Segurium's firewall runs a deny list, where an address is blocked or simply absent. There is no field here that means what your whitelist means, and writing those addresses into a block list would invert them. The Migration tab reports the skip rather than staying quiet about it.
- Country blocking. An AIOS Premium feature, and the importer does not read it. Segurium ships country blocking on the free plan, so you set your list again in the Geo Blocking tab. Write the countries down before you deactivate anything.
- Brute-force settings. Your lockout counts and durations do not come across. Note the numbers, then set them again under Segurium's login protection.
- Everything else in AIOS. The table prefix change, file permission fixes, salt rotation, spam controls, the .htaccess rules. None of it has a Segurium equivalent to import into, because none of it is something Segurium does. That is the argument for keeping AIOS, not against it.
What you are actually adding
This is worth stating plainly, because a reader who already runs a security plugin reasonably asks what a second one is for.
AIOS answers it in its own shipped code. Open the Malware Scan screen in the free plugin and it says, in their words, that scanning for malware "using a standalone plugin will not work reliably" and that this is "best done via an external scan of your site regularly". They are right, and their answer is a weekly scan from their servers on the paid plan.
The free AIOS scanner is a file change detector. It compares checksums and tells you a file changed, was added or was removed. That is genuinely useful and it is not the same as knowing whether the change was malware. No AIOS tier ships a control that removes, repairs or quarantines a flagged file. The premium offer on that screen is advice for cleanup, delivered by their support team.
Segurium takes the same position AIOS takes, and applies it to every install rather than to the paid ones. Every file is checked by hash against a cloud database, so the answer comes from off your server without your files leaving it. Around 94% of files are settled by hash alone. When something comes back infected, there is a button, and it removes the injected code and leaves the file working. The free plan covers 3 files every 30 days.
AIOS free plugin version 5.4.9, read on 19 August 2026. The quotes above are from the scanner templates shipped inside it.
Step by step
- Note your AIOS brute-force numbers and, if you are on Premium, your blocked countries. Those are the two things you cannot recover later.
- Install Segurium from WordPress.org. Leave AIOS active.
- Accept the service disclosure on the plugin page. Nothing contacts our service and nothing scans until you do.
- Open the Migration tab. All-In-One Security appears with a count. Click Preview.
- Read the preview. It shows the two rows it will import, the whitelist row it will skip, and why. Apply it when the counts look right.
- Check the firewall list. If the firewall switched itself on, confirm the addresses in it are ones you still want blocked.
- Set your country list and your brute-force thresholds from the notes in step one.
- Run a full scan and an integrity scan.
- Leave AIOS installed unless it is doing something you no longer want. The next section is about that decision.
Install the free plugin from WordPress.org
About fifteen minutes, most of it the first scan running while you do something else.
Keep AIOS, in most cases
AIOS does a set of hardening jobs Segurium does not ship at all: changing the database table prefix, fixing file permissions, rotating salts, blocking user enumeration, approving new registrations by hand, and the comment spam controls. If you configured any of that, removing the plugin removes the protection.
The two overlap in three places, and each has a sensible answer. Both ship two-factor authentication, so pick one and turn the other off rather than asking your users to carry two codes. Both block IP addresses, which is why the import merges rather than duplicates, though running two firewalls with different rule sets makes a blocked request hard to trace. Both watch for file changes, and there is no harm in two opinions as long as you are not surprised by two notification emails.
The case for removing AIOS is narrow: you only ever used it for the scanner, or you are consolidating plugins on principle. Neither is urgent.
If you change your mind
There is no undo button on the import. What is true is narrower: the import only adds to two lists, and both are editable fields you can open and prune. It removes nothing, touches no file, and changes no post. AIOS keeps its own settings exactly where they were, so reactivating it finds everything in place.
Questions
- Should I uninstall AIOS after switching?
- Often no. AIOS does hardening Segurium does not: the table prefix change, file permission fixes, salt rotation, user enumeration blocking, comment spam controls. None of that overlaps with malware detection and cleanup. The two sit side by side without fighting, as long as you do not run two firewalls with contradictory rules.
- Why is my exclusion list longer than it was in AIOS?
- Because AIOS keeps file paths and file extensions in two separate settings and Segurium keeps one list. The importer merges both, and each extension becomes a wildcard pattern, so .log arrives as *.log. The count goes up and the meaning stays the same.
- My AIOS whitelist did not come across. Is that a bug?
- No, it is deliberate. An AIOS whitelist entry means let this address through whatever else happens. Segurium's firewall runs a deny list, where an address is either blocked or not mentioned. Importing a bypass entry into a block list would reverse what you meant, so the importer skips it and tells you it skipped it.
- I blocked countries in AIOS Premium. Do those come across?
- No. Country blocking is an AIOS Premium feature and the importer does not read it. Segurium ships country blocking free, so you set the list again in the Geo Blocking tab. Keep a note of the countries before you deactivate anything.
- I already deleted AIOS. Is it too late?
- Probably not. Detection looks for the data rather than an active plugin, so an orphaned settings row left behind by the uninstall is still readable. Open the Migration tab and see what it reports.
- Will importing overwrite my existing rules?
- No. Both lists are merged and deduplicated. Nothing already configured is replaced or removed.
Still deciding?
Moving off something else?
Start with the preview
Install it, accept the disclosure, open the Migration tab. The preview writes nothing and tells you exactly what your own site has to offer. You can close the tab there and think about it.