WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: secupress (Used by 515 domains)

SecuPress with Simple SSL – Simple and Performant Security

πŸ‘€ SecuPress πŸ“¦ v2.6.1 πŸ”— Plugin Homepage

Test it now!

You can test SecuPress Free now.

YOU MADE IT, WE KEEP IT SAFE!

The most advanced WordPress Protection on the market. SecuPress is focused on WordPress attacks and Malwares, not just β€œusual web protections” like many.

Protect your WordPress with malware scans ; block bots & suspicious IPs. Get a complete WordPress security toolkit for free or as a pro plugin. SecuPress is GDPR compliant.

What’s the difference between free and pro version?
If you are proactive, our free WordPress security plugin is a great choice! No time to activate weekly scans? Then SecuPress pro is the way to go. Our plugin takes care of everything with automated tasks.

Here are some of our most popular features:

  • Brute Force Login Protection
  • Password Spraying Protection
  • Firewall features
  • Security alerts (1)
  • Malware Scanner (1)
  • Block country by geolocation (1)

We have included some features you won’t find in most WordPress security plugins:

  • Protection of Security Keys
  • Block visits from Bad Bots
  • Vulnerable Plugins & Themes detection (1)
  • Security Reports in PDF format (1)

You can check out Frequently Asked Questions or get in touch with our support. Want to know all about SecuPress? You can read our documentation here: docs.secupress.me.

How will you know it works?
Well, we have a dedicated security scanner that will give you a clear security grade and report for your website. This way, you’ll know exactly what to fix.

WordPress Features

Security Audit
SecuPress is the only plugin with a full scanner able to fix the issues for you. And when it requires a decision from you, it will ask you before proceeding. With this feature, you can check 35 security points in 5 minutes and let us take care of the rest.

Once done, you get a security grade that gives you a clear idea of what your security level is. You can export this analysis in PDF format to share with others (clients or colleagues) (1).

Users & Login
This feature is the easiest way to make sure your users’ data is protected and to keep their accounts from being compromised. With this feature you can limit the number of bad login attempts, ban non-existing usernames login attempts and set a non-login time slot. SecuPress also makes sure you control the sessions of your users.

SecuPress also adds a 2FA (Two Factor Authentication) because it’s almost a mandatory feature when it comes to WordPress security!

The plugin also gives you greater user and password control as you can set:

  • Password lifetimes for your users.
  • Enforce strong password use.
  • Forbid the use of vague usernames like www or admin.

Tired of bots finding your WordPress login page? Finally, don’t let bots find your login page, just move it with the famous Move Login plugin, now included in SecuPress.

Plugins and Themes
SecuPress helps you detect themes and plugins that are vulnerable or that have been tampered with to include malicious code. If you install one of these, your security module will send out an email alert and give you a warning in WordPress.

SecuPress takes security further by limiting plugin activation, deactivation, installation and removal in your production (live) website. Plugin and theme uploads via .zip files will be on lockdown as well to block off this easy hacking route.

WordPress Core
SecuPress reinforces the WordPress Core to keep it safe. The security plugin optimizes what’s under the hood to secure the config file by setting the proper parameters.

Sensitive Data
SecuPress secures content in many ways:

  • The plugin secures WordPress Endpoints and APIs by blocking bad requests for XML-RPC or REST API.
  • It blocks bad bots with its Robots Blackhole feature.
  • It provides an anti-hotlink feature to preserve your bandwidth.
  • The plugin packs 7 anti-disclose security modules to make sure no precious information is available to hackers in your PHP or WordPress itself.
  • Profile and SecuPress settings pages are password protected to keep sensitive information away from prying eyes.

Firewall

  • SecuPress is one of the most efficient WordPress bouncer you’ll ever see!
  • The plugin blocks malicious incoming requests.
  • It blocks bad User Agents (no bad crawlers allowed).
  • Bad requests methods also get the boot in a single click.
  • URLs are kept in check: no bad URL contents.
  • SQL injection scanners are kept out as well.
  • Brute force attempts are stopped in their tracks.
  • GeoIP Blocking by country gives you more control over your traffic.

Malware Scan
SecuPress has a unique malware scan developed by our security experts. It hunts down bad files and provides you with an easy step-by-step report that lets you take action. It looks into:

  • Bad files in your FTP.
  • Your uploads folder for dangerous files.
  • Potential phishing attempts via index.php loads.

Backups
We know firsthand how painful it is to pick up the pieces after an attack damages your WordPress. SecuPress preserves your data to help you avoid lost content or settings if your website comes under attack. The plugin backs up your database and files and lets you download them to guarantee you peace of mind.

Anti Spam
Did you know that 60% of the traffic on the Internet is generated by bots? Most of them happen to be spam bots. We developed our own anti-spam system that works quietly in the background. Just activate it and enjoy a spam free experience.

Alerts
Alerts are an essential tool when your website is under attack. When something important happens on your website, SecuPress will send you an alert via email. We’re working on alerts via SMS, Slack & Twitter as well.

You also receive a daily report that provides a debrief of the attempted attack and all the activities blocked by SecuPress.

Scheduled Security Tasks
SecuPress can run 3 separate scheduled tasks for you. It’s like having a security patrol on your WordPress.

Scheduled Scanner: SecuPress scans your website to detect any issues. After the scan is complete, you get a report in your inbox outlining any actions you have to take to protect your website.
Scheduled Backup: our team knows that everyone at one time or another forgets to back things up. We made it an automatic task to help ensure you always can recover from an attack with your content safe.
Scheduled Malware Scan: this security feature scans your website at regular intervals to hunt down any malware that may have gotten into your WordPress.

Logs
SecuPress will keep a log of important security activities and 404 pages triggered by users, bots or even Chuck Norris. This lets you keep an eye on what’s going on in your WordPress at any time. You can also control banned IPs from this option.

(1) Available in the Pro Version.

(SecuPress est une extension de sΓ©curitΓ© WordPress franΓ§aise)

TODO

Create a trust score for each non WP file and displays it
Create a β€œsuspicious” status for alerts
Revamp alerts
Revamp logs
Add http logs
PHP 8.O min
replace %s by ###USERNAME### in emails
.htaccess scanner
login rest disclose scanner
move EDD updater+white label into a mu to allow upgrade+rollback even with plugin deactivated
give possibility to rename logins
target=”_blank” on doc links
AI Scanner
Improve malware scanner, again

DomainExposuresHeadersLast Checked
c*s*j*n*o*.com βœ… F 2026-06-02 19:16:10
c*s*-*u*i*r.com βœ… F 2026-06-02 17:47:36
m*p*o*.fr βœ… F 2026-06-02 11:29:18
s*l*n*a*t*q*a*r*s*a*t*b*s.com βœ… F 2026-06-02 07:55:14
s*a*e*o*t.com βœ… F 2026-06-02 07:30:43
s*h*r*e.fr βœ… F 2026-06-02 06:49:46
s*l*h*-*a*i*.com βœ… F 2026-06-02 05:08:27
f*r*i*a*l*-*a*i*g*.com βœ… F 2026-06-01 23:03:10
a*r*l*e*a*r*.com βœ… F 2026-06-01 21:15:37
a*r*l*e*o*s*e*u.com βœ… F 2026-06-01 21:11:27
e*u*p*o*d.fr βœ… F 2026-06-01 12:27:22
l*v*e*n*o*s*i*n*e.com βœ… F 2026-06-01 10:25:12
c*i*i*e*o*l*a*s.fr βœ… F 2026-06-01 10:11:43
a*e*a*e*e*t*o*l*a*s.fr βœ… D 2026-06-01 10:11:43
a*d*c*o*a.com βœ… F 2026-06-01 09:59:16
a*c*e*r*u*a*a*e*e*t.com βœ… F 2026-06-01 09:19:13
1*0*o*t*r*.com βœ… F 2026-06-01 06:29:25
l*u*e*c*g*i*l*n*n*t*r*.com βœ… F 2026-06-01 04:15:44
c*r*m*n*e*d*-*a*i*g*.fr βœ… F 2026-06-01 03:21:15
l*s*e*i*s*o*s*e*.com βœ… B 2026-06-01 01:39:10
v*m*a*i.com βœ… D 2026-06-01 00:08:25
y*g*r*n*e.fr βœ… D 2026-05-31 23:44:11
e*f*-*e*s.fr βœ… F 2026-05-31 21:56:37
l*c*m*t*i*a*t*e*t*q*e.com βœ… F 2026-05-31 20:37:11
l*-*u*i*.com βœ… F 2026-05-31 17:34:59
m*n*q*e*e*e*c*i.com βœ… F 2026-05-31 07:16:20
i*a*e*l*a*l*r*.com βœ… F 2026-05-31 06:15:06
p*u*p*s*n*o*d.fr βœ… C 2026-05-31 06:07:36
m*n*o*t*u*o*h*u*.com βœ… F 2026-05-31 04:58:46
k*m*p.fr βœ… F 2026-05-31 04:08:37
s*p*r*t*n*e*s*.fr βœ… C 2026-05-31 03:25:05
a*e*i*r*e*p*t*t*s*e*s.com βœ… F 2026-05-31 02:45:09
g*o*s*s*e*a*a*o*i*b*j*u*.com βœ… F 2026-05-31 02:35:33
l*n*t*r*e*v*l*e.eu πŸ”“ F 2026-05-31 02:02:39
m*s*e*-*n*i*o*n*m*n*.fr βœ… C 2026-05-31 00:32:32
g*a*s*h*o*.e*p*i.u*f*.fr βœ… F 2026-05-31 00:21:08
p*e*d*e*o*f*a*c*.com βœ… F 2026-05-31 00:10:06
c*e*-*o*.biz βœ… F 2026-05-30 23:55:00
d*c*a*r*e*v*r*n*e*e*t.org βœ… F 2026-05-30 23:52:09
s*b*n*b*.com βœ… F 2026-05-30 23:11:00
l*q*g*n*.fr βœ… F 2026-05-30 22:08:05
e*t*r*a*i*-*t.be βœ… D 2026-05-30 20:32:15
m*n*j*r*i*-*o*a*e*.com (WP 6.9.4) βœ… F 2026-05-30 19:08:05
l*p*m*e*o*s*n*e*r*.com βœ… F 2026-05-30 18:55:19
l*p*a*c*e*a*r*e*n*i*e.com βœ… F 2026-05-30 18:21:37
b*l*a*s*i.info βœ… F 2026-05-30 17:02:35
p*e*i*r*b*b*.com βœ… F 2026-05-30 16:52:03
g*e*o*y*o*s*i*r.com βœ… F 2026-05-30 14:19:03
u*o*3.fr βœ… F 2026-05-30 14:05:07
a*t*o*a*o*.com βœ… F 2026-05-30 12:35:50
n*u*o*a*u*e*.com βœ… B 2026-05-30 11:19:28
p*t*h*o*k*n*p*r*t*o*s.fr βœ… F 2026-05-30 06:43:44
g*e*n*a*a*a*t.com βœ… F 2026-05-30 05:43:25
m*h*i*d*m*u*i*.com βœ… F 2026-05-30 01:31:04
d*m*i*e*f*r*e*o*.com βœ… F 2026-05-30 01:09:18
l*m*i*o*j*h*z*.com βœ… F 2026-05-29 23:18:53
l*m*i*o*d*r*j*n*.com βœ… F 2026-05-29 23:05:47
s*e*e*o*l*n.be βœ… F 2026-05-29 22:46:20
s*u*i*f*n*y*u*a*n*.com βœ… F 2026-05-29 14:52:38
c*m*i*g*e*c*u*e*.com βœ… F 2026-05-29 14:50:11
k*h*w.com βœ… F 2026-05-29 13:33:22
j*z*p*.a*s*.fr βœ… D 2026-05-29 11:28:45
c*m*a*n*s*a*g*s*i*.com βœ… F 2026-05-29 10:43:04
n*l*t*e*u*y.com βœ… F 2026-05-29 08:32:04
n*l*t*b*a*t*.com βœ… F 2026-05-29 08:32:04
e*e*s*o*e.fr βœ… F 2026-05-29 05:52:45
a*i*n*a*t*e*.com βœ… F 2026-05-29 05:20:31
c*l*u*r*a*i*n.com βœ… F 2026-05-29 05:01:21
l*d*n*e*l*e*e*e*a*t*n.com βœ… F 2026-05-29 01:05:24
i*t*g*a*i*e*a*c*r*o*f*r*n*e.com βœ… F 2026-05-29 00:59:20
l*c*o*e*i*d*l*b*y*e.com βœ… D 2026-05-28 22:02:02
l*c*r*v*n*d*s*e*t*u*s.com βœ… F 2026-05-28 18:43:15
v*l*a*a*m*a*r*c*.com βœ… F 2026-05-28 17:33:58
l*b*i*e*e*r*d.com βœ… A 2026-05-28 13:59:05
i*s*i*e*n*t*r*.com βœ… F 2026-05-28 07:50:54
i*s*i*a*i*n*e*o*e.com βœ… F 2026-05-28 07:18:32
p*o*o*-*o*o*e*.com βœ… D 2026-05-28 07:05:55
t*a*a*s*-*o*t*r*j*s.com βœ… F 2026-05-28 05:52:02
c*e*a*.fr βœ… D 2026-05-28 03:55:35
c*r*s*e*l*p*c*u*.com βœ… F 2026-05-28 02:52:03
c*r*s*e*l*h*c*e*.com βœ… A 2026-05-28 02:52:02
p*c*a*a*a*v*y*g*s.com βœ… F 2026-05-27 23:51:56
p*r*e*o.f*b*r*n*c.fr βœ… D 2026-05-27 23:26:43
g*o*d.com βœ… F 2026-05-27 21:58:26
r*d*o*a.fr βœ… F 2026-05-27 21:47:44
a*i*n*c*n*e*l.online βœ… F 2026-05-27 18:16:12
l*n*e*t*n*.org βœ… F 2026-05-27 17:34:23
c*n*o*c*t*v*l*a*e.fr βœ… F 2026-05-27 15:14:00
c*b*n*t*b*l*e*t*e*s.com βœ… F 2026-05-27 13:59:05
p*a*e*d*-*a*c*e*d*-*a*e*c*y.fr βœ… A 2026-05-27 12:20:12
v*b*a*i*n*d*f*u*i*n.com βœ… F 2026-05-27 12:16:01
r*s*z*s*e.com βœ… F 2026-05-27 12:09:35
y*u*g*i*e*s.fr βœ… F 2026-05-27 12:07:06
v*b*a*i*l*.com βœ… F 2026-05-27 11:21:00
t*r*e*t*o*t.bzh βœ… D 2026-05-27 10:58:42
s*i*t*h*p*o*y*e*d*-*o*t.fr βœ… F 2026-05-27 09:40:55
r*s*c*p*u*e.com βœ… F 2026-05-27 08:56:51
a*t*a*r*a*t*b*s.com βœ… F 2026-05-27 08:53:15
f*n*n*i*l*o*t*n*l*b.com βœ… B 2026-05-27 08:12:16
d*c*i*-*t*d*s*c*i*n*.fr βœ… F 2026-05-27 07:04:27

Top 50 Plugins

Plugin Count
elementor 1,754,320
contact-form-7 1,726,201
elementor-pro 1,023,432
woocommerce 799,034
revslider 604,515
jetpack 458,801
js_composer 422,662
wp-rocket 325,289
essential-addons-for-elementor-lite 282,799
gravityforms 257,929
complianz-gdpr 247,725
cookie-law-info 224,350
instagram-feed 223,021
google-site-kit 216,572
sitepress-multilingual-cms 215,492
google-analytics-for-wordpress 209,983
header-footer-elementor 205,639
elementskit-lite 198,592
bluehost-wordpress-plugin 189,609
gutenberg 158,792
cookie-notice 145,917
gutenberg-core 143,187
wpforms-lite 127,671
the-events-calendar 127,427
litespeed-cache 125,867
gtranslate 124,470
astra-sites 118,199
popup-maker 113,405
woocommerce-payments 111,119
tablepress 104,688
honeypot 94,265
astra-addon 93,304
coblocks 93,197
all-in-one-seo-pack 91,550
wp-smushit 91,448
duracelltomi-google-tag-manager 91,001
LayerSlider 89,759
bb-plugin 89,288
premium-addons-for-elementor 84,929
akismet 84,581
megamenu 83,847
cleantalk-spam-protect 82,420
mailchimp-for-wp 82,013
woocommerce-gateway-stripe 81,354
ml-slider 78,616
fusion-builder 77,853
ewww-image-optimizer 77,141
formidable 76,561
borlabs-cookie 76,319
wp-pagenavi 76,221

Top 50 Themes

Theme Count
hello-elementor 599,515
Divi 499,956
astra 415,349
flatsome 125,689
Avada 121,634
generatepress 116,522
pub 99,092
oceanwp 81,430
kadence 76,170
enfold 70,055
salient 65,396
twentyseventeen 54,728
bb-theme 54,320
twentytwentyfour 52,991
cocoon-master 51,730
h4 50,741
betheme 50,550
blocksy 49,223
dt-the7 44,884
twentytwentyfive 42,646
neve 38,282
Avada-Child-Theme 36,787
gox 32,884
woodmart 32,364
bridge 32,265
twentytwentyone 31,598
lightning 30,772
twentytwenty 29,387
swell 28,208
Impreza 25,646
bricks 25,293
twentytwentythree 23,684
Newspaper 22,719
twentytwentytwo 19,762
sydney 19,583
epik-redesign 19,297
uncode 18,579
voxel 17,877
twentysixteen 17,750
pro 17,574
storefront 17,445
extendable 14,540
Total 14,391
yith-wonder 13,973
kubio 13,880
hello-theme-child-master 12,968
factory-templates-4 12,761
themify-ultra 12,708
yootheme 12,563
hestia 12,439