Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Vortix Web Security

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Vortix Web Security

By MohtamimNayeem
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Vortix Web Security bundles eleven practical security features that you can switch on and off individually from one screen. Everything is free, works offline, and needs no account, license key or trial. Nothing expires.

Free features

  1. Basic Hardening – generic login error messages, no public username discovery (?author=N and the REST users list for logged-out visitors), X-Content-Type-Options: nosniff.
  2. Login Protection – temporary lockouts after repeated failed logins, per IP address and per username.
  3. Disable XML-RPC – blocks xmlrpc.php and removes the related headers and links.
  4. Bad Bot Blocker – blocks requests from well-known scanner tools by User-Agent.
  5. Upload Protection – denies access to script files in the uploads folder (Apache and LiteSpeed).
  6. Disable File Editor – removes the theme and plugin code editors.
  7. Hide WP Version – removes the WordPress version from the generator tag and asset URLs.
  8. Disable Directory Browsing – adds Options -Indexes (Apache and LiteSpeed).
  9. Strong Password Enforcement – strong passwords for users who can edit posts.
  10. Automatic Plugin Updates – for plugin packages served by WordPress.org over HTTPS.
  11. Automatic Theme Updates – for theme packages served by WordPress.org over HTTPS.

A Security Scan screen runs sixteen local configuration checks. Each feature’s screen entry explains what it protects and exactly what it changes.

Features that edit .htaccess, may interfere with third-party services, or install updates start switched off on a new install. Basic Hardening, Login Protection, Disable File Editor, Hide WP Version and Strong Password Enforcement start on.

Premium

An optional, separately distributed product called Vortix Web Security Pro exists. It is not included in this plugin, and this plugin contains no locked or hidden premium code. The free features never depend on it. Information about it appears only on this plugin’s own screens: an “Upgrade to Premium” screen and a small card beside the feature list. There are no banners or notices elsewhere in the dashboard.

Privacy

Blocked requests (failed logins, blocked scanner requests, blocked XML-RPC requests) are recorded in a table in your own database: IP address, requested page path without the query string, event type and time. Entries are deleted after the retention period you set (90 days by default) and when the plugin is uninstalled. Login-attempt counters use keyed hashes rather than raw IP addresses or usernames and expire automatically.

The plugin sets no cookies and sends no data to the author or any third party. Suggested privacy-policy text is added under Settings > Privacy.

External services

Vortix Web Security does not connect to any external service.

  • The Security Scan and the .htaccess safety check request pages from your own site (loopback requests). No other server is contacted.
  • When Cloudflare is the selected trusted proxy, the plugin reads the CF-Connecting-IP request header. It does not contact Cloudflare. The Cloudflare address ranges it compares against are stored in the plugin.
  • The “View Premium Plans” button is an ordinary link. Nothing is requested or sent unless you click it, and the link opens the Pro product website in a new tab.

Support

Use the support forum for this plugin on WordPress.org.

Installation

  1. Upload the plugin to /wp-content/plugins/vortix-web-security/, or install it from the Plugins screen.
  2. Activate Vortix Web Security.
  3. Open Vortix Web Security in the admin menu and review the features.
  4. If your site is behind a CDN or reverse proxy, open Settings and choose the trusted proxy.

FAQ

Does anything expire, or do I need a license key?

No. There is no trial, license, registration or license server.

Why are some features off after activation?

Turning on automatic updates, rewriting .htaccess, or disabling XML-RPC can affect your site or other plugins, so those are your choice. The Free Features screen explains each one.

Disable XML-RPC broke Jetpack or an app.

Jetpack, the legacy WordPress mobile apps and some remote publishing tools use XML-RPC. Switch the feature off again.

My site shows an error after enabling an `.htaccess` feature.

Before keeping a change, the plugin checks that your server still answers, and reverts it if the server returns HTTP 500. If a host blocks that check, connect by FTP and delete the block between # BEGIN WPSM Upload Protection and # END WPSM Upload Protection (or WPSM Directory Browsing Protection) from the relevant .htaccess file, then disable the feature.

Everyone gets locked out together.

Your site is probably behind a proxy or CDN, so all visitors appear to share one IP address. Open Settings > Trusted proxy and choose Cloudflare or add your proxy’s addresses.

Can login lockouts be abused?

Login Protection also limits attempts per username (20 in 15 minutes by default), which means someone who knows a username could keep that account locked for a while. The limits can be changed with the filters wpsm_login_max_attempts, wpsm_login_window, wpsm_login_lockout, wpsm_login_max_attempts_per_user, wpsm_login_window_per_user and wpsm_login_lockout_per_user.

Does the bot blocker block search engines?

No. It only matches names of security-scanner tools. User-Agents can be spoofed, so it is not a firewall.

Does this work on multisite?

Yes. Modules are configured per site. The directory-browsing rule edits the shared root .htaccess, so only super admins can change it.

Does it work on Nginx?

The features that do not use .htaccess do. Upload Protection and Disable Directory Browsing need an equivalent rule in your Nginx configuration and will refuse to switch on.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Vortix Web Security” is open source software. The following people have contributed to this plugin.

Contributors
  • MohtamimNayeem

Translate “Vortix Web Security” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

2.1.1

  • Refreshed admin design: colour-coded status (green active/pass, red inactive/needs attention, yellow warnings), header banner, feature filter, score ring on the Security Scan screen.

2.1.0

  • First WordPress.org release of the free edition. No license, trial or remote licensing code.
  • Added the missing Basic Hardening and Disable XML-RPC features.
  • Rebuilt the Modules screen: free features first, optional upgrade card beside it. Added Free Features and Upgrade to Premium screens.
  • Automatic updates, .htaccess edits and XML-RPC blocking are now opt-in on new installs.
  • .htaccess changes are verified with a loopback request and reverted if the server rejects them; the rules are simplified to avoid server errors on restrictive hosts.
  • Fixed strong-password enforcement on the password-reset form.
  • Fixed the log-retention setting being ignored by the daily cleanup.
  • Trusted-proxy handling: Cloudflare mode now trusts only CF-Connecting-IP; a Settings screen lets you configure custom proxies.
  • Security log stores the request path only, is rate-limited per IP and capped at 50,000 rows.
  • Scanner: checks that cannot be verified are reported as such and excluded from the score; no longer calls wp_head().
  • Removed the admin-bar item and unused code.

Meta

  • Version 2.1.1
  • Last updated 17 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.2 or higher
  • Tested up to 7.1.2
  • PHP version 8.0 or higher
  • Tags
    Brute Forcehardeninglogin securitysecurityxmlrpc
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • MohtamimNayeem

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org
  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry
The WordPress® trademark is the intellectual property of the WordPress Foundation.