Every day, thousands of WordPress sites are targeted by automated attacks. Exposed versions, open XML-RPC, user enumeration: all entry points for bots. WP Swiss Knife applies security best practices recommended by experts in one click, without touching the code.
Removes the version number from the source code, RSS feeds and HTTP headers to prevent scanners from identifying known vulnerabilities in your version.
Blocks XML-RPC requests (brute-force and DDoS attack vector) and restricts the REST API to logged-in users only.
Replace /wp-login.php with a secret URL of your choice. Bots targeting the default URL will receive a 404 error.
Automatically blocks an IP address after a configurable number of failed attempts, with progressive ban duration.
Blocks direct access to wp-config.php, .htaccess, readme.html, xmlrpc.php files and sensitive directories via server rules.
Configures HSTS, Content-Security-Policy, Permissions-Policy, X-Frame-Options and X-Content-Type-Options to protect against clickjacking, XSS and injections.
Commencez gratuitement, passez à la version supérieure quand vous êtes prêt.
Check the desired security options from the plugin's Security tab. Each setting comes with a clear explanation.
Set your secret login URL, the number of allowed attempts and the HTTP headers to enable based on your needs.
Rules are applied instantly. Check the login logs to verify that attacks are properly blocked.
Record logins, plugin actions and modifications on your WordPress site. Export to CSV, JSON or PDF. Advanced filters.
Learn moreGet a security score /100 for each site, check SSL and vulnerable plugins, configure security remotely from the portal.
Learn moreEnable an elegant maintenance mode with custom page, admin exceptions and temporary password access. Simple and free.
Learn moreTéléchargez le plugin gratuitement et activez cette fonctionnalité en quelques clics.