Switching

Moving from Solid Security to Segurium

One thing imports: your banned IP addresses, including the ones sitting in a table left behind after you deleted the plugin. Everything else you set up again, and this page is mostly about which of those are worth your time. The product ships as Kadence Security today, and the importer reads either version.

Install the free plugin from WordPress.org

Read the two-factor section before you switch anything off. It is the one step that can lock you out.

What the importer reads

That is the entire list, and the Migration tab shows you the count before it writes anything. A short list is not a broken importer. It is two products that overlap in exactly one place, and the rest of this page is about the places they do not.

Read from the shipped adapter on 19 August 2026. The Wordfence importer reads four things and the All-In-One Security one reads two, so do not carry this list across.

What you set up again

What you are actually adding

Worth stating plainly, because a reader who already runs a security plugin should know what a second one is for.

Kadence Security has never scanned your files for malware. Its Site Scanner checks the plugin and theme versions you have installed against a list of known vulnerabilities, and asks Google whether your domain is on a blocklist. File Change Detection tells you a file changed. All three are useful and none of them opens a file and looks at what is inside it, so none of them can tell you whether the change was an injection. There is no cleanup step in the product at any price.

Segurium starts where that stops. Every file is checked by hash against a cloud database, so around 94% of them are settled without leaving your server. When one comes back infected, there is a button, and it removes the injected code and leaves the file working rather than deleting it. The free plan covers 3 files every 30 days, and restoring a modified core, plugin or theme file to its upstream content is unlimited and does not count against that.

Kadence Security free plugin version 10.0.3, checked on 19 August 2026, along with their published feature list.

Step by step

  1. Write down your brute-force numbers and, if you paid for the country restriction, your country list.
  2. List the users who have two-factor set up. You are about to ask each of them to enrol again.
  3. Install Segurium from WordPress.org. Leave the old plugin active for now.
  4. Accept the service disclosure on the plugin page. Nothing contacts our service and nothing scans until you do.
  5. Open the Migration tab. Solid Security appears with a count of the bans it found. Click Preview, then Apply.
  6. Check the firewall list. If the firewall switched itself on, confirm the addresses in it are ones you still want blocked. An IP ban from three years ago is often somebody's reassigned home connection.
  7. Turn on Segurium two-factor and enrol yourself first, with a second admin session open in another browser. Then ask the rest of your users to enrol.
  8. Set your brute-force thresholds and your country list from the notes in step one.
  9. Run a full scan and an integrity scan.
  10. Only once every user has enrolled, turn off the old two-factor. Doing it in the other order is how somebody gets locked out.

Install the free plugin from WordPress.org

The scan is the fast part. Getting your users to re-enrol is what sets the pace.

Should you keep it installed?

There is a real case for it. Kadence Security does login hardening Segurium does not ship: forcing a password reset across all users, refusing passwords that have turned up in a breach, banning by user agent, hiding the login URL. If you configured any of that, removing the plugin removes the protection with it.

Two things to settle if you keep both. Run one two-factor system, not two, or your users will be asked for a code by whichever plugin gets there first and will not know which app to open. Run one brute-force lockout, so a locked-out user has one place to be unlocked from. The IP lists can coexist, which is why the import merges rather than replaces.

If you are consolidating rather than layering, the honest summary is that you are trading their login hardening for file scanning and cleanup. Which of those matters more depends on whether your problem so far has been people trying your password or something already sitting in your uploads folder.

If you change your mind

There is no undo button on the import. What is true is narrower: the import only adds to one list, and that list is an editable field you can open and prune. It removes nothing, touches no file, and changes no post. The old plugin's own tables stay exactly where they are, so reactivating it finds its bans intact.

Questions

Is Solid Security the same thing as Kadence Security?
Yes. The product was iThemes Security, then Solid Security, and it ships today as Kadence Security under Liquid Web. The WordPress.org slug never changed, which is why an install from years ago updates straight into the current name. The importer keys off the database, so it does not care which name your copy carries.
Do my users have to set up two-factor again?
Yes. There is no importer for their two-factor records, so every user enrols again on Segurium. Do this before you turn theirs off, not after, and keep one admin session open in a second browser while you test your own login.
I deleted the plugin months ago. Are my bans gone?
Probably not. Deleting a plugin from the Plugins screen does not drop its database tables unless the plugin chose to, and the ban table usually survives. Detection looks for the table rather than for an active plugin, so open the Migration tab and see what it finds.
Why does so little come across?
Because the two products overlap less than the category suggests. Most of what you configured there is login hardening that Segurium either ships with its own settings or does not ship at all. The one list that means exactly the same thing in both products is the IP ban list, and that is the one that imports.
Will importing overwrite my existing firewall rules?
No. The list is merged and deduplicated. Nothing already configured is replaced or removed.
Should I keep it installed?
You can, and some people should. It does login hardening Segurium does not: forcing password resets, refusing compromised passwords, banning user agents. Turn off one of the two two-factor systems and one of the two brute-force lockouts so a locked-out user has one place to look.

Still deciding?

Moving off something else?

Start with the preview

Install it, accept the disclosure, open the Migration tab. The preview writes nothing and tells you how many bans your own site is carrying. You can close the tab there and think about it.