Description
Vortix Web Security bundles eleven practical security features that you can switch on and off individually from one screen. Everything is free, works offline, and needs no account, license key or trial. Nothing expires.
Free features
- Basic Hardening – generic login error messages, no public username discovery (
?author=Nand the REST users list for logged-out visitors),X-Content-Type-Options: nosniff. - Login Protection – temporary lockouts after repeated failed logins, per IP address and per username.
- Disable XML-RPC – blocks
xmlrpc.phpand removes the related headers and links. - Bad Bot Blocker – blocks requests from well-known scanner tools by User-Agent.
- Upload Protection – denies access to script files in the uploads folder (Apache and LiteSpeed).
- Disable File Editor – removes the theme and plugin code editors.
- Hide WP Version – removes the WordPress version from the generator tag and asset URLs.
- Disable Directory Browsing – adds
Options -Indexes(Apache and LiteSpeed). - Strong Password Enforcement – strong passwords for users who can edit posts.
- Automatic Plugin Updates – for plugin packages served by WordPress.org over HTTPS.
- Automatic Theme Updates – for theme packages served by WordPress.org over HTTPS.
A Security Scan screen runs sixteen local configuration checks. Each feature’s screen entry explains what it protects and exactly what it changes.
Features that edit .htaccess, may interfere with third-party services, or install updates start switched off on a new install. Basic Hardening, Login Protection, Disable File Editor, Hide WP Version and Strong Password Enforcement start on.
Premium
An optional, separately distributed product called Vortix Web Security Pro exists. It is not included in this plugin, and this plugin contains no locked or hidden premium code. The free features never depend on it. Information about it appears only on this plugin’s own screens: an “Upgrade to Premium” screen and a small card beside the feature list. There are no banners or notices elsewhere in the dashboard.
Privacy
Blocked requests (failed logins, blocked scanner requests, blocked XML-RPC requests) are recorded in a table in your own database: IP address, requested page path without the query string, event type and time. Entries are deleted after the retention period you set (90 days by default) and when the plugin is uninstalled. Login-attempt counters use keyed hashes rather than raw IP addresses or usernames and expire automatically.
The plugin sets no cookies and sends no data to the author or any third party. Suggested privacy-policy text is added under Settings > Privacy.
External services
Vortix Web Security does not connect to any external service.
- The Security Scan and the
.htaccesssafety check request pages from your own site (loopback requests). No other server is contacted. - When Cloudflare is the selected trusted proxy, the plugin reads the
CF-Connecting-IPrequest header. It does not contact Cloudflare. The Cloudflare address ranges it compares against are stored in the plugin. - The “View Premium Plans” button is an ordinary link. Nothing is requested or sent unless you click it, and the link opens the Pro product website in a new tab.
Support
Use the support forum for this plugin on WordPress.org.
Installation
- Upload the plugin to
/wp-content/plugins/vortix-web-security/, or install it from the Plugins screen. - Activate Vortix Web Security.
- Open Vortix Web Security in the admin menu and review the features.
- If your site is behind a CDN or reverse proxy, open Settings and choose the trusted proxy.
FAQ
-
Does anything expire, or do I need a license key?
-
No. There is no trial, license, registration or license server.
-
Why are some features off after activation?
-
Turning on automatic updates, rewriting
.htaccess, or disabling XML-RPC can affect your site or other plugins, so those are your choice. The Free Features screen explains each one. -
Disable XML-RPC broke Jetpack or an app.
-
Jetpack, the legacy WordPress mobile apps and some remote publishing tools use XML-RPC. Switch the feature off again.
-
My site shows an error after enabling an `.htaccess` feature.
-
Before keeping a change, the plugin checks that your server still answers, and reverts it if the server returns HTTP 500. If a host blocks that check, connect by FTP and delete the block between
# BEGIN WPSM Upload Protectionand# END WPSM Upload Protection(orWPSM Directory Browsing Protection) from the relevant.htaccessfile, then disable the feature. -
Everyone gets locked out together.
-
Your site is probably behind a proxy or CDN, so all visitors appear to share one IP address. Open Settings > Trusted proxy and choose Cloudflare or add your proxy’s addresses.
-
Can login lockouts be abused?
-
Login Protection also limits attempts per username (20 in 15 minutes by default), which means someone who knows a username could keep that account locked for a while. The limits can be changed with the filters
wpsm_login_max_attempts,wpsm_login_window,wpsm_login_lockout,wpsm_login_max_attempts_per_user,wpsm_login_window_per_userandwpsm_login_lockout_per_user. -
Does the bot blocker block search engines?
-
No. It only matches names of security-scanner tools. User-Agents can be spoofed, so it is not a firewall.
-
Does this work on multisite?
-
Yes. Modules are configured per site. The directory-browsing rule edits the shared root
.htaccess, so only super admins can change it. -
Does it work on Nginx?
-
The features that do not use
.htaccessdo. Upload Protection and Disable Directory Browsing need an equivalent rule in your Nginx configuration and will refuse to switch on.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Vortix Web Security” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Vortix Web Security” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.1.1
- Refreshed admin design: colour-coded status (green active/pass, red inactive/needs attention, yellow warnings), header banner, feature filter, score ring on the Security Scan screen.
2.1.0
- First WordPress.org release of the free edition. No license, trial or remote licensing code.
- Added the missing Basic Hardening and Disable XML-RPC features.
- Rebuilt the Modules screen: free features first, optional upgrade card beside it. Added Free Features and Upgrade to Premium screens.
- Automatic updates,
.htaccessedits and XML-RPC blocking are now opt-in on new installs. .htaccesschanges are verified with a loopback request and reverted if the server rejects them; the rules are simplified to avoid server errors on restrictive hosts.- Fixed strong-password enforcement on the password-reset form.
- Fixed the log-retention setting being ignored by the daily cleanup.
- Trusted-proxy handling: Cloudflare mode now trusts only CF-Connecting-IP; a Settings screen lets you configure custom proxies.
- Security log stores the request path only, is rate-limited per IP and capped at 50,000 rows.
- Scanner: checks that cannot be verified are reported as such and excluded from the score; no longer calls
wp_head(). - Removed the admin-bar item and unused code.