Title: Securizer
Author: WP Podrška
Published: <strong>September 15, 2026</strong>
Last modified: September 15, 2026

---

Search plugins

![](https://ps.w.org/securizer/assets/banner-772x250.png?rev=3697780)

![](https://ps.w.org/securizer/assets/icon-256x256.png?rev=3697780)

# Securizer

 By [WP Podrška](https://profiles.wordpress.org/wppodrska/)

[Download](https://downloads.wordpress.org/plugin/securizer.1.0.4.zip)

 * [Details](https://wordpress.org/plugins/securizer/#description)
 * [Reviews](https://wordpress.org/plugins/securizer/#reviews)
 *  [Installation](https://wordpress.org/plugins/securizer/#installation)
 * [Development](https://wordpress.org/plugins/securizer/#developers)

 [Support](https://wordpress.org/support/plugin/securizer/)

## Description

Securizer is a lightweight WordPress security and diagnostics plugin focused on 
local protection, verification and reporting. It provides login protection, hardening,
core integrity, Safe Repair, diagnostics and account hygiene without a Securizer
cloud service.

Read-only checks do not repair files. Disruptive actions require administrator confirmation;
safety-sensitive workflows use verification and rollback.

#### Login Protection

 * Progressive IP lockouts for repeated failed login attempts
 * Targeted-account activity detection
 * Exact-IP whitelist and blacklist
 * Active lockout management and manual unlock
 * Security event logging
 * Configurable client IP detection, including Cloudflare support
 * Compatibility warnings for overlapping login-protection plugins

#### Safe Login URL

Securizer can provide a custom login path and hide normal anonymous access to wp-
login.php and wp-admin. The new route is verified before the default route is hidden,
and the previous configuration is restored if verification fails. An emergency recovery
constant is available if access problems occur.

#### WordPress Hardening

Hardening controls cover XML-RPC and pingbacks, generator exposure, author enumeration,
REST API user exposure, the file editor, Application Passwords, security headers,
directory listing and public access to PHP-like files inside uploads. Potentially
incompatible server-level changes are not forced automatically.

#### Core Integrity and Safe Repair

Core Integrity compares WordPress core files with official checksums and identifies
modified files, missing official files and unexpected files inside wp-admin and 
wp-includes.

Scanning is read-only. For selected modified or missing files, Safe Repair downloads
the matching official WordPress package, reads only selected files into memory, 
verifies checksums, writes them through the WordPress Filesystem API and scans again.
Pre-repair contents remain in memory for rollback if verification fails. Unexpected
files are reported and not deleted.

#### Diagnostics and Safe File Protection

Diagnostics checks security configuration, public exposure, HTTPS/SSL behavior, 
headers, file/directory protection and WordPress configuration. Some checks request
the site’s public URLs to verify effective behavior.

Safe File Protection can verify directory listing and denial of PHP-like requests
in uploads. Its uploads test requests a randomized, non-existent PHP-like URL and
creates no probe file. Where supported, Securizer can apply its own marked rules,
verify the result immediately and roll back a newly applied rule when it cannot 
confirm a safe and effective change.

#### Account Hygiene, Salts and Logs

Account Hygiene reviews administrator usernames, active sessions and Application
Passwords, and includes a controlled administrator login-name change workflow. Securizer
also audits the eight WordPress authentication keys and salts without displaying
or storing their values; explicit rotation includes verification and rollback.

Security events are stored locally and can include IP address, attempted username,
event type, timestamp and limited event context. Passwords and authentication secrets
are never logged. Logs can be reviewed in WordPress administration and exported 
as CSV.

#### What Securizer is not

Securizer is not a WAF, cloud malware scanner or vulnerability-intelligence service.
It does not replace secure hosting, backups, updates or a dedicated firewall where
required.

### External services and network requests

Securizer has no product telemetry and does not require a Securizer cloud account.

#### WordPress.org services

Core Integrity requests official checksums from WordPress.org. When an administrator
explicitly runs Safe Repair, Securizer also downloads the matching official WordPress
release package and reads only selected repair files from the archive in memory.

These requests send the WordPress core version and locale needed for checksum verification
or package selection.

WordPress.org: https://wordpress.org/
 WordPress.org Privacy Policy: https://wordpress.
org/about/privacy/

#### Requests to the site’s own public URLs

Diagnostics, Safe Login URL verification and Safe File Protection can request URLs
belonging to the same site to verify redirects, login-route behavior, headers, public
exposure and file protection. No Securizer cloud service is involved.

#### RIPEstat

Security Logs can display a manual Lookup link for eligible public IP addresses.
An IP address is opened on RIPEstat only when an administrator explicitly clicks
the link.

RIPEstat: https://stat.ripe.net/
 RIPE NCC Privacy Statement: https://www.ripe.net/
about-us/legal/ripe-ncc-privacy-statement/

### Privacy

Securizer stores settings, scan results and security logs locally in the WordPress
installation. It does not include product telemetry or send Securizer usage statistics
to the developer.

Security logs may contain IP addresses and attempted usernames because they are 
required for login protection and security-event analysis. Securizer provides suggested
text in the WordPress Privacy Policy Guide describing its local logging and relevant
network behavior.

Site administrators are responsible for retained security logs under applicable 
privacy requirements.

## Screenshots

[⌊Dashboard with protection status, recent activity, Action Center, compatibility
checks and security overview.⌉⌊Dashboard with protection status, recent activity,
Action Center, compatibility checks and security overview.⌉[

Dashboard with protection status, recent activity, Action Center, compatibility 
checks and security overview.

[⌊Login Protection with IP handling, targeted-account monitoring, active lockouts
and Safe Login URL.⌉⌊Login Protection with IP handling, targeted-account monitoring,
active lockouts and Safe Login URL.⌉[

Login Protection with IP handling, targeted-account monitoring, active lockouts 
and Safe Login URL.

[⌊Hardening controls for exposure reduction, remote access and browser security 
headers.⌉⌊Hardening controls for exposure reduction, remote access and browser security
headers.⌉[

Hardening controls for exposure reduction, remote access and browser security headers.

[⌊Administrative hardening, Authentication Keys & Salts rotation, and Safe File 
Protection.⌉⌊Administrative hardening, Authentication Keys & Salts rotation, and
Safe File Protection.⌉[

Administrative hardening, Authentication Keys & Salts rotation, and Safe File Protection.

[⌊Core Integrity verification against official WordPress checksums.⌉⌊Core Integrity
verification against official WordPress checksums.⌉[

Core Integrity verification against official WordPress checksums.

[⌊Diagnostics / Self Test with update hygiene and security configuration checks.⌉⌊
Diagnostics / Self Test with update hygiene and security configuration checks.⌉[

Diagnostics / Self Test with update hygiene and security configuration checks.

## Installation

 1. Install Securizer through the WordPress plugin installer or upload the plugin ZIP.
 2. Activate Securizer.
 3. Open Securizer from the WordPress administration menu.
 4. Review the initial Diagnostics and Core Integrity baseline.
 5. Review Login Protection and Hardening settings and adjust them if needed.

A new installation stores conservative defaults and schedules a read-only Diagnostics
and Core Integrity baseline. It does not repair files, rotate authentication salts,
change the login URL or apply server-level file-protection rules.

## FAQ

### Does Securizer include a firewall?

No. Securizer does not include a WAF or replace a server, CDN or dedicated firewall.

### Does Securizer scan for malware?

Securizer verifies WordPress core integrity against official checksums and can identify
unexpected files in core directories. It is not a general-purpose malware scanner.

### Does Securizer send site data to a Securizer server?

No. Securizer has no product telemetry or Securizer cloud service. Some features
use official WordPress.org services, and some diagnostics request the site’s own
public URLs as documented above.

### Can Securizer lock me out after changing the login URL?

Safe Login URL verifies the new route before hiding normal anonymous login access,
restores the previous configuration if verification fails, and provides an emergency
recovery bypass.

### How do I enable emergency recovery?

Add this line to wp-config.php:

    ```
    define( 'WPPS_SECURITY_BYPASS', true );
    ```

This disables active Securizer protection modules while keeping the administration
interface available. Remove the line after resolving the problem.

### Does Securizer automatically repair or delete WordPress core files?

No. Core Integrity scanning is read-only. An administrator can explicitly select
modified or missing official core files and run Safe Repair; Securizer validates
the matching official WordPress package and re-verifies checksums after replacement.
Unexpected files are reported rather than deleted.

### Will Securizer disable another security plugin?

No. Securizer can detect known overlapping login-protection functionality and display
a compatibility recommendation, but it does not automatically disable or reconfigure
another plugin.

### What happens when Securizer is deactivated or deleted?

Deactivation preserves Securizer settings, logs and managed file-protection rules.
By default, uninstall also preserves stored data; administrators can explicitly 
enable database cleanup.

## Reviews

![](https://secure.gravatar.com/avatar/a0782c99edb2ace4fa02545f1940706a7ad94aaf952ed06cbc8d034c7bfb0fb7?
s=60&d=retro&r=g)

### 󠀁[The cleanest, most responsible security plugin on WordPress.org](https://wordpress.org/support/topic/the-cleanest-most-responsible-security-plugin-on-wordpress-org/)󠁿

 [hilandarski](https://profiles.wordpress.org/hilandarski/) September 16, 2026

Securizer is a breath of fresh air for anyone tired of bloated, noisy security plugins
that constantly try to upsell you on cloud services or break your site without warning.
What makes Securizer stand out is its zero-fluff, local-first philosophy. It gives
you robust protection—brute-force defense, login hiding, hardening, account hygiene,
and salt rotation—without phoning home to a proprietary server or collecting unnecessary
telemetry. Here are the key highlights that make it a must-have: Truly Safe Workflows:
The auto-verification and rollback features are absolute lifesavers. Whether you
are setting up a custom login URL, applying file rules, or rotating salts, Securizer
verifies the change before committing. If something fails, it rolls back automatically
so you never get locked out. Smart Core Integrity & Repair: Unlike typical scanners
that just scream at you about modified files, Securizer’s Safe Repair compares your
site against official WordPress.org checksums and selectively repairs files in-memory
using official packages. No unexpected file deletions, no risky guesswork. Privacy-
Focused & Lightweight: Everything stays local. No cloud accounts, no annoying upsells,
and no tracking. Security logs are stored right in your database, giving you clear
visibility without compromising your site's speed or user privacy. Respectful Diagnostics:
The diagnostics don't force aggressive server-level rules blindly. It tests effective
behavior safety-first (like probing for public PHP execution in uploads without 
leaving dirty test files behind). Securizer doesn't try to pretend it's a giant 
cloud WAF—it stays strictly focused on local hardening, diagnostics, and precise
repair. It is clean, reliable, modern, and built with genuine respect for site administrators.
Highly recommended for developers and site owners who want rock-solid security without
the bloat!

 [ Read all 1 review ](https://wordpress.org/support/plugin/securizer/reviews/)

## Contributors & Developers

“Securizer” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ WP Podrška ](https://profiles.wordpress.org/wppodrska/)

[Translate “Securizer” into your language.](https://translate.wordpress.org/projects/wp-plugins/securizer)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/securizer/), check 
out the [SVN repository](https://plugins.svn.wordpress.org/securizer/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/securizer/) by [RSS](https://plugins.trac.wordpress.org/log/securizer/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.4

 * Corrected Core Integrity locale selection. When only en_US fallback checksums
   are available, verification is partial and Safe Repair is blocked for that result.

#### 1.0.3

 * Hardened Cloudflare client-IP detection.
 * Prevented Diagnostics warnings with repeated security headers.
 * Prevented event logging errors when WordPress temporarily uses a database prefix
   without the Securizer event table.

#### 1.0.2

 * WordPress.org review-compliance fixes for safer salt rotation, Safe Login URL
   styling, Safe Core Repair, uploads protection verification and runtime path compatibility.

## Meta

 *  Version **1.0.4**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [Brute Force](https://wordpress.org/plugins/tags/brute-force/)[hardening](https://wordpress.org/plugins/tags/hardening/)
   [integrity](https://wordpress.org/plugins/tags/integrity/)[login](https://wordpress.org/plugins/tags/login/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/securizer/advanced/)

## Ratings

 5 out of 5 stars.

 *  [  1 5-star review     ](https://wordpress.org/support/plugin/securizer/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/securizer/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/securizer/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/securizer/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/securizer/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/securizer/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/securizer/reviews/)

## Contributors

 *   [ WP Podrška ](https://profiles.wordpress.org/wppodrska/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/securizer/)