Pure Security closes the doors attackers try first — password-guessing bots, the built-in file editor, XML-RPC abuse and missing security headers. One light plugin, safe defaults, done in two minutes.
Most hacked WordPress sites fall to the same few tricks. Pure Security blocks them at the source, without slowing your site or filling your dashboard with alerts.
FREE
Limit login attempts
Locks out an IP after repeated failed logins, so bots can't keep guessing passwords. You set the tries and the lockout time.
FREE
Disable file editing
Removes the theme and plugin code editor from wp-admin, so a stolen login can't be used to inject malicious code.
FREE
Disable XML-RPC
Shuts down xmlrpc.php, the old endpoint attackers use for amplified brute-force and pingback attacks.
FREE
Security HTTP headers
Adds X-Frame-Options, X-Content-Type-Options, Referrer-Policy and more to guard against clickjacking and sniffing — no .htaccess edits.
PRO · COMING SOON
Custom login URL
Move wp-login.php to an address only you know. Bots hitting the default login page find nothing to attack.
PRO · COMING SOON
Block user enumeration
Stops ?author= scans and REST API lookups that reveal your usernames — half of every login a bot needs.
Pricing
Start free today. Pro is on the way.
The free plugin protects your site on its own, right now. Pro — coming soon — will hide your login page and your usernames for sites that want a tighter lock.