The all-in-one WordPress security plugin. Enterprise firewall, malware scanner, 2FA & brute-force protection – setup in 3 minutes.
The most comprehensive WordPress firewall with 10+ protection modules. Geo-blocking, rate limiting, bot protection and more.
Whitelist & blacklist with CIDR notation and wildcard support. Full control over allowed and blocked IPs.
Block access from 70+ countries. Block high-risk countries with one click. Integrated IP-country test.
Block SEO crawlers, scrapers and malicious bots. Predefined lists for standard and aggressive blocking.
Protect sensitive URLs with exact, wildcard and regex patterns. Recommended blocks for xmlrpc, .env, .git and more.
Restrict admin areas to specific user roles. Perfect for multi-user websites and agencies.
Limit requests per IP/minute. Auto-block on violation. Protection against DDoS and brute-force.
Honeypot fields, time-based checks, blacklist words. Blocks spam comments and fake registrations.
Checks file types, MIME types and scans for hidden PHP code. Automatically blocks dangerous uploads.
Unix shared memory for maximum performance. Syslog integration for centralized logging.
Modern, intuitive dashboard right in your WordPress admin.
Everything at a glance: Security score, active modules, recent activities and quick actions.
Whitelist & blacklist with CIDR notation (192.168.1.0/24) and wildcard support (192.168.1.*).
Block access from 70+ countries via Geo-IP. Quick select for high-risk countries: RU, CN, KP, IR, SY, CU.
Block SEO crawlers like AhrefsBot, SemrushBot and more. Predefined lists for quick setup.
Protect sensitive URLs with exact, wildcard and regex patterns. Recommended blocks integrated.
Restrict admin areas to specific WordPress roles. Ideal for multi-user websites.
Limit requests per IP/minute. Auto-block on violation. Protection against DDoS attacks.
Honeypot fields, time-based checks and blacklist words. Blocks spam comments and fake registrations.
Checks file types, MIME types and scans for hidden PHP code. Blocks dangerous uploads.
Unix shared memory, response body filter, syslog integration and custom block pages.
Check your website for malware, suspicious files and security vulnerabilities with one click.
Compares WordPress core files against official checksums and shows deviations, missing or added files.
Brute-force protection with login attempt statistics and configurable limits.
Enable security best practices with one click: hide version, disable XML-RPC and more.
Complete logging of all security events: logins, firewall blocks, settings changes and more.
Configure all security modules to your needs – clear and simple.
Comprehensive protection without compromise. From firewall to malware scanner.
10+ protection modules: IP control, geo-blocking, bot protection, URL blocking, rate limiting, antispam and more. The most comprehensive WordPress firewall.
ProBrute-force protection with configurable limits. Automatic IP blocking after failed attempts. Detailed login statistics.
FreeHides WordPress version, disables XML-RPC, protects the file editor and adds important security headers.
FreeComplete logging of all security events: logins, firewall blocks, scan results, settings changes and more. With CSV export.
FreeDeep scan detects known malware signatures, backdoors and suspicious code patterns. With file integrity check.
ProCompares all WordPress core files (3,300+ files) against official WordPress.org checksums. Detects modified, missing and added files – including auto-repair with backup before repair.
ProUse a custom login URL instead of /wp-login.php (e.g. /my-login). Direct access to wp-login.php is blocked (404) and drastically reduces brute-force attacks.
ProAutomatic malware scans daily or weekly – with configurable scan time. Email scan reports included.
ProPro alerts for brute-force attacks, malware findings, admin logins from unknown IPs, license expiry warnings and scheduled scan results – including test email function.
ProConfigure how long the activity log is stored: 7/30/90 days or unlimited.
ProTOTP-based 2FA for all users. Compatible with Google Authenticator, Authy and other apps.
ProSmart fraud detection with scoring system. Checks disposable emails, country mismatch, VPN/proxy and more.
ProInstant alerts for critical security incidents: blocked attacks, IP bans, suspicious activity.
FreeInstallation and setup take less than 3 minutes.
Download SafetyPress and install it like any other WordPress plugin.
SafetyPress immediately activates all basic protection measures. Firewall, login protection and hardening are active.
Enter your license key to unlock enterprise firewall, 2FA and WooCommerce protection.
No hidden costs. No surprises.
"The new firewall is amazing! Geo-blocking and rate limiting reduced our attacks by 95%. Finally peace from Russian and Chinese bots."
"The activity log is priceless! Finally I can see exactly what's happening on my website. Every login, every attack – all logged."
"Setup in 2 minutes, zero problems since. The firewall has already blocked hundreds of SQL injection attempts. Highly recommend!"
The free version includes a basic firewall with SQL injection and XSS protection. The Pro version offers an enterprise firewall with 10+ modules: IP access control, geo-blocking (70+ countries), bot control, URL blocking, role-based access control, rate limiting, antispam, upload security, response body filter and syslog integration.
Yes! SafetyPress is compatible with all common WordPress themes and plugins. We regularly test with popular page builders like Elementor, Divi and Beaver Builder as well as WooCommerce.
No. SafetyPress is optimized for performance and uses Unix shared memory for lightning-fast firewall checks. Geo-IP results are cached to minimize API calls. The plugin has no measurable impact on load time.
The Activity Log records: Successful and failed logins, IP blocks, firewall blocks (SQL injection, XSS, geo-blocking, rate limiting etc.), scan results, settings changes and plugin activations. All events with IP, timestamp and details. Optionally with syslog integration.
The Core Integrity Check compares all WordPress core files (3,300+ files) against official WordPress.org checksums. It detects modified, missing or added files. With auto-repair you can restore corrupted core files with one click – including automatic backup before repair.
Yes. You can set a custom login URL instead of /wp-login.php (e.g. /my-login). Direct access to wp-login.php is blocked (404), which significantly reduces brute-force attacks.
Yes. Pro supports scheduled malware scans daily or weekly with configurable scan time. After each scheduled scan you automatically receive a report via email.
Pro notifies you about brute-force attacks, malware findings, admin logins from unknown IPs, license expiry warnings and scheduled scan results. There's also a test email function.
Yes. In Pro you can configure how long the Activity Log is stored: 7, 30, 90 days or unlimited.
Your website stays protected! When your license expires, you won't receive updates and Pro features (enterprise firewall, 2FA, WooCommerce protection) will be deactivated, but basic protection remains active.
Yes! We offer a 7-day money-back guarantee. If you're not satisfied, you get your money back – no questions asked.
Have questions? Write to us – we usually respond within 24 hours.