Description
At Sucuri, we are dedicated to keeping your website safe and secure. With a focus on protection and monitoring, we offer solutions that help you stay ahead of potential threats for your WordPress site.
Our services include everything from malware detection to performance optimization, all designed to give you peace of mind.
We understand the importance of your online presence and are here to support you every step of the way. Join us, and let’s work together to ensure your website remains secure and resilient.
The Sucuri Security Monitoring Plugin is designed to safeguard your WordPress site with ease and reliability. Our plugin offers a range of essential security features, including:
- Security Activity Auditing: Keep track of every security-related event within your WordPress environment.
- File Integrity Monitoring: Detect unauthorized changes to your files and protect your site from potential vulnerabilities.
- Remote Malware Scanning: Regularly scan your site for malware with our remote scanner to ensure it’s clean and secure.
- Blocklist Monitoring: Receive alerts if your site is blocklisted by any major services, allowing for quick resolution.
- Security Hardening: Implement recommended security practices to fortify your site against threats.
- Post-Hack Security Actions: If the worst happens, our plugin helps you recover your site easily.
With Sucuri, you can focus on what matters most—growing your website—while we handle the security. Our feature set provides a clear view of your site’s status, making it easy to manage, monitor and take action.
Contributors & Maintenance Notice
Our dedicated team of engineers and security analysts is continually working to enhance the Sucuri Security Monitoring Plugin.
We provide regular updates, address bugs, and actively incorporate user feedback to ensure your WordPress site maintains its highest security stance. Our growth roadmap underscores our commitment to keeping you protected against emerging threats.
To support you further, we offer a variety of resources, including prompt responses for the forum, our website’s various content types, and an extensive knowledge base.
Our content is designed to help you maximize your plugin feature usage and benefits with the support you need.
If you want to be ahead of possible threats and keep up-to-date with Plugin updates, subscribe to our content here.
Introducing the Sucuri Firewall + WordPress Security Plugin
We’re excited to introduce the Sucuri Firewall + WordPress Security Plugin, designed for those who seek advanced protection for their WordPress sites.
Building upon our trusted free plugin, this premium offering provides a robust suite of features to ensure comprehensive security and peace of mind.
Key features include:
* Web Application Firewall (WAF): Protect your site from malicious traffic with our powerful firewall solution.
* Brute Force Protection: Safeguard your site against unauthorized login attempts.
* Brute Force Audit & Reporting: Gain insights into login attempts with detailed auditing and reporting.
* DDoS Mitigation: Maintain site availability even during targeted attacks.
* Core Vulnerabilities Scanning: Identify and address security weaknesses in WordPress core files.
* Plugins Vulnerability Scanning: Ensure your installed plugins are secure and up to date.
* Themes Vulnerability Scanning: Protect your site by scanning for vulnerabilities in installed themes.
* PHP Vulnerability Scanning: Detect and address potential security issues in your PHP environment.
With the Sucuri Firewall + WordPress Security Plugin, you benefit from the expertise and dedication of our team, committed to keeping your digital assets secure.
Experience the next level of protection and support, and enjoy the peace of mind that comes with knowing your site is in good hands.
Screenshots









Installation
The installation of the Sucuri WordPress Security plugin is very simple and straight forward. A detailed breakdown of the process is available here (including images), however, below we outline the bare minimum steps.
To install Sucuri Security and complement your Security posture:
- Log into your WordPress administration panel,
- In the sidebar, choose “Plugins” and then “Add New”,
- Type “sucuri” or “sucuri-scanner” in the search box,
- Install the option with the “By Sucuri Inc.” at the foot,
- Once activated, you will find a new icon in the sidebar with the Sucuri logo. Go to the plugin’s dashboard and click the button that says “Generate API Key” to activate the event monitoring, this will generate a unique key to authenticate your website against the remote Sucuri WordPress API service,
- Feel free to visit the plugin’ settings page to configure other options including the security alerts, hardening options, file system scanner paths and API service communication.
Visit the Support Forum to ask questions, suggest new features, or report bugs. And recommend the plugin to your friends and colleagues if you think it can help them.
FAQ
More information on the Sucuri Security WordPress plugin can be found in our Knowledge Base.
-
What is the security activity auditing?
-
One of the standout features of our WordPress plugin is the comprehensive audit logging system. At Sucuri, we recognize that every change within your application can be a potential security event. From user logins to content modifications, our audit logs are designed to capture all security-related activities on your site.
These logs provide you with crucial visibility into your website’s operations, answering key questions such as:
* Who logged in? Understanding who accesses your site is fundamental to ensuring that only authorized users are logging in. This helps in identifying any unauthorized access attempts, allowing you to respond swiftly to potential security breaches.
* What changes were made? Essential for maintaining its integrity and security. By knowing what modifications have been made, you can quickly pinpoint any suspicious activities or errors that need attention.With the release of version 1.9.6, we’ve enhanced this feature, allowing you to filter audit logs by event types and dates. This improvement offers you even greater insight into your site’s activities, enabling proactive security management.
-
What is the file integrity monitoring
-
Security File Integrity Monitoring has been fundamental to the world of security. It’s the act of comparing a known good with the current state. If the current state differs from the known good, you know you have a problem. This is the basis of a lot of host intrusion detection systems. We have built that into this plugin.
It will create a known good the minute the plugin is installed. This will be of all the directories at the root of the install, including plugins, themes and core files.
-
What is remote malware scanning?
-
Once this plugin is installed and activated, we automatically scan your site searching for known malware, viruses, blacklisting status, website errors, out-of-date software, and malicious code.
We access your site just like a regular visitor would as this helps us catch threats that try to stay hidden from bots or search engines. This feature is powered by our free website security scanner – SiteCheck.
-
What is the blocklist monitoring?
-
Another very interesting feature of the website Security Malware Scanner is that it checks various blocklist engines, including the following:
- Sucuri Labs
- Google Safe Browsing
- Norton
- AVG
- Phish Tank
- ESET
- McAfee Site Advisor
- Yandex
- SpamHaus
- Bitdefender
These are some of the largest blocklisting entities, each having the ability to directly impact your brand’s online reputation. By synchronizing with their environments we’re able to tell you whether any of them are negatively flagging your website with a security related issue. If they do, then via our website security product, we’re able to help you get off of the security blocklist.
-
What is effective security hardening?
-
Our team cleans thousands of websites every day, giving us deep insight into the most effective ways to protect WordPress sites.
We’ve used that experience to create a list of actionable recommendations available in the Hardening & Prevention section of this plugin.
To name a few (note that this will depend on your environment), these actions are:
- Enable Website Firewall Protection
- Remove WordPress Version
- Block PHP Files in Uploads, wp-content and wp-includes directories.
- Verify default admin account.
- Disable Plugin and Theme Editor.
- Automatic Secret Keys Updater.
-
What are the post-hack security actions?
-
Even with the strongest security measures, no site is 100% safe from hacking. When a compromise occurs, the Post-Hack section of our plugin guides you through four critical steps to help you regain control of your site:
- Update Secret Keys.
- Reset User Passwords.
- Reset Installed Plugins.
- Update Plugin and Themes.
These steps are designed to help you recover faster after a security incident.
-
What are the security notifications?
-
Security features only matter if you know when something’s wrong, that’s why we included a set of customizable security alerts inside our Settings > Alerts section. You can also customize how frequently you want to be alerted of security related events.
-
This is by far the coolest security feature Sucuri has to offer everyday website owners. It’s an enterprise grade Website Firewall designed to give you the best security protection any website can hope for. It protects your website from a variety of website attacks, including:
- Denial of Service (DOS / DDOS) Attacks.
- Exploitation of Software Vulnerabilities.
- Zero Day Disclosure Patches.
- Brute Force Attacks against your Access Control Mechanisms.
This is coupled with a number of features like:
- Performance Optimization.
- Advanced Access Control Features.
- Failover and Redundancy.
This is not included as a free option of the plugin, but is integrated so that if purchased you are able to activate. If you prefer to leverage the Sucuri Firewall product by itself, you have the option to operate the Website Firewall WordPress Security plugin in standalone mode.
The Sucuri WordPress Security plugin is built by the team that is known for their proactive approach to security. It is built using intelligence gathered from thousands upon thousands of remediation cases, millions of unique domain scans and 10’s of millions of website security attack blocks.
-
What does this plugin do that other security plugins don’t do?
-
Our expertise has given us deep insight into what truly helps prevent security incidents, and we’ve cooked that knowledge directly into this plugin.
To give you a sense of what this security plugin offers, here are some of its most powerful features:
- WordPress core, PHP, plugins and themes vulnerability scanners.
- Firewall Management.
- Events Reporting (auditlogs).
- Headers Management.
- Hardening & Prevention.
- Post-Hack Actions.
- Last Logins.
- And there’s more!
And while other security plugins may offer similar features, few deliver them as effectively as we do. Ask around! 🙂
-
If I install the Sucuri Security plugin do I get a Sucuri account?
-
No, this is a free plugin that we offer at no charge. It does not mean you get a free account.
-
Both the premium and the free version share the same codebase, however, this plugin has a few extra features that are only unlocked when you have a WAF account, some of these features include:
- WordPress Core vulnerability scanning.
- PHP vulnerability scanning.
- Plugin vulnerability scanning.
- Themes vulnerability scanning.
- A beautiful dark theme!
To unlock these features you must go to Firewall Management and input a correct Sucuri Firewall API Key — In the Sucuri Dashboard you can find this key by going to the Sucuri WAF dashboard > API > API Key (for plugin).
-
Do I still need Sucuri’s products if I have this plugin?
-
Yes. This plugin compliments your existing security toolsets. It is not designed to replace the Sucuri Website Security or Firewall products.
-
Do the logs get stored to my database?
-
No, they do not.
-
Are there any issues installing your plugin with any hosts?
-
Not that we are aware of.
-
Do I need this plugin to use the Website Firewall service?
-
No, it is not required. The Website Firewall runs in the cloud without the need of anything installed. We recommend installing this plugin to see your firewall configuration and manage it from your WordPress dashboard.
-
What information does Sucuri collect?
-
We take your privacy seriously. For free plugin users without an API key, no information is collected by Sucuri. After activating an API key, Sucuri will store some information, such as logs. Please see our Terms of Service and Privacy Policy. Please email gdpr@sucuri.net if you have other questions about your privacy.
-
How do I configure the Cache-Control header?
-
Go to the Headers Management page and enable Cache-Control header by selecting a mode according to your website’s need and click on submit.
You can also activate the Cache-Control header by updating the cache header fields in one of the page types by using the “Edit” button in the table rows.
Please remember to enable site caching on your WAF to use these settings. If you are a Sucuri client and require assistance, please create a ticket and reach out to the firewall team for support.
-
How do I configure the CORS headers?
-
To enable CORS headers please visit the Headers Management page. For the time being, we only support “Report-Only” as these headers can break your site.
-
How do I configure the Content Security Policy (CSP) header?
-
To enable CSP (Content Security Policy) headers please visit the Headers Management page.
-
Where do I get support for this plugin?
-
The best place is to engage us via the Support Forum. If you are a client, you can submit a ticket here.
Reviews
Contributors & Developers
“Sucuri Security – Auditing, Malware Scanner and Security Hardening” is open source software. The following people have contributed to this plugin.
Contributors“Sucuri Security – Auditing, Malware Scanner and Security Hardening” has been translated into 14 locales. Thank you to the translators for their contributions.
Translate “Sucuri Security – Auditing, Malware Scanner and Security Hardening” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.8
- Add one-time backup codes for Two-Factor Authentication. Ten codes are created when 2FA is turned on, any one of them will get you in if you lose your authenticator app, and each code stops working once it has been used. You can generate a fresh set at any time from your WordPress profile.
- Add a search box and severity, plugin, and theme filters to the Audit Logs page, so you can find a specific event without paging through the whole history. Filtering and paging now happen instantly.
- Add a one-click CSV download of the complete audit trail, ready for a compliance review, an incident timeline, or an archive before older records age out. Large histories export without slowing the site down.
- Fix an issue that left the audit trail completely empty on sites that do not run in English. Events were recorded but never shown.
- Fix audit entries being cut short or lost. Saving the WordPress Writing settings discarded the record of every other option changed in that same save, and a less-than sign in a site title or option value truncated the entry from that point on.
- Fix plugin and theme names that contain an ampersand being shown with an HTML escape code in place of the character itself, both on the page and in the export, which also stopped them from being found by search.
- Mask API keys, tokens, and salts in the audit trail. They were previously stored in plain text, and are now masked both as new events are recorded and as existing records are read back.
- Fix a case where markup returned by the Sucuri API could reach the dashboard without being escaped.
- Fix removing a file from the Hardening allowlist when its path contains characters that have a special meaning in a regular expression.
- Require PHP 7.4 and WordPress 6.0 or later, and correct the places in the plugin that still advertised PHP 5 support.
2.7.4
- Improve the Two-Factor Authentication page to load the users list in pages, so it stays fast and reliable on sites with hundreds or thousands of users (for example, WooCommerce stores).
- Add a search box to the Two-Factor Authentication page to quickly find users by username, email, or display name.
- Strengthen input validation, access checks, and output escaping.
- Add a one-click “Disable XML-RPC” option to the Hardening page to close a common brute-force and pingback-based DDoS attack vector, with a warning if an active plugin (e.g. Jetpack) depends on XML-RPC.
- Fix a fatal error on PHP 8 when the API returns the “messages” field as a string instead of an array.
2.7.3
- Refactor AJAX handler to an explicit dispatch map for improved security and efficiency.
