Title: Vortix Web Security
Author: MohtamimNayeem
Published: <strong>October 1, 2026</strong>
Last modified: October 1, 2026

---

Search plugins

![](https://ps.w.org/vortix-web-security/assets/icon-256x256.png?rev=3722599)

# Vortix Web Security

 By [MohtamimNayeem](https://profiles.wordpress.org/mohtamimnayeem/)

[Download](https://downloads.wordpress.org/plugin/vortix-web-security.2.1.1.zip)

 * [Details](https://wordpress.org/plugins/vortix-web-security/#description)
 * [Reviews](https://wordpress.org/plugins/vortix-web-security/#reviews)
 *  [Installation](https://wordpress.org/plugins/vortix-web-security/#installation)
 * [Development](https://wordpress.org/plugins/vortix-web-security/#developers)

 [Support](https://wordpress.org/support/plugin/vortix-web-security/)

## Description

Vortix Web Security bundles eleven practical security features that you can switch
on and off individually from one screen. Everything is free, works offline, and 
needs no account, license key or trial. Nothing expires.

#### Free features

 1.  **Basic Hardening** – generic login error messages, no public username discovery(`?
     author=N` and the REST users list for logged-out visitors), `X-Content-Type-Options:
     nosniff`.
 2.  **Login Protection** – temporary lockouts after repeated failed logins, per IP
     address and per username.
 3.  **Disable XML-RPC** – blocks `xmlrpc.php` and removes the related headers and 
     links.
 4.  **Bad Bot Blocker** – blocks requests from well-known scanner tools by User-Agent.
 5.  **Upload Protection** – denies access to script files in the uploads folder (Apache
     and LiteSpeed).
 6.  **Disable File Editor** – removes the theme and plugin code editors.
 7.  **Hide WP Version** – removes the WordPress version from the generator tag and
     asset URLs.
 8.  **Disable Directory Browsing** – adds `Options -Indexes` (Apache and LiteSpeed).
 9.  **Strong Password Enforcement** – strong passwords for users who can edit posts.
 10. **Automatic Plugin Updates** – for plugin packages served by WordPress.org over
     HTTPS.
 11. **Automatic Theme Updates** – for theme packages served by WordPress.org over 
     HTTPS.

A **Security Scan** screen runs sixteen local configuration checks. Each feature’s
screen entry explains what it protects and exactly what it changes.

Features that edit `.htaccess`, may interfere with third-party services, or install
updates start switched **off** on a new install. Basic Hardening, Login Protection,
Disable File Editor, Hide WP Version and Strong Password Enforcement start on.

#### Premium

An optional, separately distributed product called Vortix Web Security Pro exists.
It is not included in this plugin, and this plugin contains no locked or hidden 
premium code. The free features never depend on it. Information about it appears
only on this plugin’s own screens: an “Upgrade to Premium” screen and a small card
beside the feature list. There are no banners or notices elsewhere in the dashboard.

### Privacy

Blocked requests (failed logins, blocked scanner requests, blocked XML-RPC requests)
are recorded in a table in your own database: IP address, requested page path without
the query string, event type and time. Entries are deleted after the retention period
you set (90 days by default) and when the plugin is uninstalled. Login-attempt counters
use keyed hashes rather than raw IP addresses or usernames and expire automatically.

The plugin sets no cookies and sends no data to the author or any third party. Suggested
privacy-policy text is added under Settings > Privacy.

### External services

Vortix Web Security does not connect to any external service.

 * The Security Scan and the `.htaccess` safety check request pages from **your 
   own site** (loopback requests). No other server is contacted.
 * When Cloudflare is the selected trusted proxy, the plugin reads the `CF-Connecting-
   IP` request header. It does not contact Cloudflare. The Cloudflare address ranges
   it compares against are stored in the plugin.
 * The “View Premium Plans” button is an ordinary link. Nothing is requested or 
   sent unless you click it, and the link opens the Pro product website in a new
   tab.

### Support

Use the support forum for this plugin on WordPress.org.

## Installation

 1. Upload the plugin to `/wp-content/plugins/vortix-web-security/`, or install it 
    from the Plugins screen.
 2. Activate **Vortix Web Security**.
 3. Open **Vortix Web Security** in the admin menu and review the features.
 4. If your site is behind a CDN or reverse proxy, open **Settings** and choose the
    trusted proxy.

## FAQ

### Does anything expire, or do I need a license key?

No. There is no trial, license, registration or license server.

### Why are some features off after activation?

Turning on automatic updates, rewriting `.htaccess`, or disabling XML-RPC can affect
your site or other plugins, so those are your choice. The Free Features screen explains
each one.

### Disable XML-RPC broke Jetpack or an app.

Jetpack, the legacy WordPress mobile apps and some remote publishing tools use XML-
RPC. Switch the feature off again.

### My site shows an error after enabling an `.htaccess` feature.

Before keeping a change, the plugin checks that your server still answers, and reverts
it if the server returns HTTP 500. If a host blocks that check, connect by FTP and
delete the block between `# BEGIN WPSM Upload Protection` and `# END WPSM Upload
Protection` (or `WPSM Directory Browsing Protection`) from the relevant `.htaccess`
file, then disable the feature.

### Everyone gets locked out together.

Your site is probably behind a proxy or CDN, so all visitors appear to share one
IP address. Open **Settings > Trusted proxy** and choose Cloudflare or add your 
proxy’s addresses.

### Can login lockouts be abused?

Login Protection also limits attempts per username (20 in 15 minutes by default),
which means someone who knows a username could keep that account locked for a while.
The limits can be changed with the filters `wpsm_login_max_attempts`, `wpsm_login_window`,`
wpsm_login_lockout`, `wpsm_login_max_attempts_per_user`, `wpsm_login_window_per_user`
and `wpsm_login_lockout_per_user`.

### Does the bot blocker block search engines?

No. It only matches names of security-scanner tools. User-Agents can be spoofed,
so it is not a firewall.

### Does this work on multisite?

Yes. Modules are configured per site. The directory-browsing rule edits the shared
root `.htaccess`, so only super admins can change it.

### Does it work on Nginx?

The features that do not use `.htaccess` do. Upload Protection and Disable Directory
Browsing need an equivalent rule in your Nginx configuration and will refuse to 
switch on.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Vortix Web Security” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ MohtamimNayeem ](https://profiles.wordpress.org/mohtamimnayeem/)

[Translate “Vortix Web Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/vortix-web-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/vortix-web-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/vortix-web-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/vortix-web-security/)
by [RSS](https://plugins.trac.wordpress.org/log/vortix-web-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.1.1

 * Refreshed admin design: colour-coded status (green active/pass, red inactive/
   needs attention, yellow warnings), header banner, feature filter, score ring 
   on the Security Scan screen.

#### 2.1.0

 * First WordPress.org release of the free edition. No license, trial or remote 
   licensing code.
 * Added the missing Basic Hardening and Disable XML-RPC features.
 * Rebuilt the Modules screen: free features first, optional upgrade card beside
   it. Added Free Features and Upgrade to Premium screens.
 * Automatic updates, `.htaccess` edits and XML-RPC blocking are now opt-in on new
   installs.
 * `.htaccess` changes are verified with a loopback request and reverted if the 
   server rejects them; the rules are simplified to avoid server errors on restrictive
   hosts.
 * Fixed strong-password enforcement on the password-reset form.
 * Fixed the log-retention setting being ignored by the daily cleanup.
 * Trusted-proxy handling: Cloudflare mode now trusts only CF-Connecting-IP; a Settings
   screen lets you configure custom proxies.
 * Security log stores the request path only, is rate-limited per IP and capped 
   at 50,000 rows.
 * Scanner: checks that cannot be verified are reported as such and excluded from
   the score; no longer calls `wp_head()`.
 * Removed the admin-bar item and unused code.

## Meta

 *  Version **2.1.1**
 *  Last updated **23 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 8.0 or higher **
 * Tags
 * [Brute Force](https://wordpress.org/plugins/tags/brute-force/)[hardening](https://wordpress.org/plugins/tags/hardening/)
   [login security](https://wordpress.org/plugins/tags/login-security/)[security](https://wordpress.org/plugins/tags/security/)
   [xmlrpc](https://wordpress.org/plugins/tags/xmlrpc/)
 *  [Advanced View](https://wordpress.org/plugins/vortix-web-security/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/vortix-web-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/vortix-web-security/reviews/)

## Contributors

 *   [ MohtamimNayeem ](https://profiles.wordpress.org/mohtamimnayeem/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/vortix-web-security/)