Plugin Reviews

iThemes Security (formerly Better WP Security)

Protect your WordPress site by hiding vital areas of your site, protecting access to important files, preventing brute-force login attempts, detecting


3499 reviews
Average Rating
4.7 out of 5 stars
Thorough Protection.
By , for WP 3.5.1

Thanks for keeping my sites protected. Had loads of sites hacked, and then since installer this plugin, no trouble!

excellent work
By , for WP 3.5.1

very good plugin

Very useful
By , for WP 3.5.1

I've used this on a number of sites now. Very, very helpful.

Impervious to Thor's hammer
By , for WP 3.5.1

With hackers knocking on my site every day it's good to have this updated shield on watch. Excellent tool.

very helpful script
By ,

good reminder of the security steps that need to be taken

By , for WP 3.5.1

This is the best Security Plugin for WordPress with no doubt.

Great plugin!
By , for WP 3.5.1

I am looking forward to the GitHub Issues.
The username based banning and the rate limiting would be great.

Excellent WP Security Tool
By ,

BWPS is a great tool that any WordPress administrator can leverage in his or her quest to harden WP site security.

It covers all the basics, including:

  • (dot)htaccess and wp-config.php file security
  • HTTP Referrer ("Generator") removal/rewriting
  • WP Administrator account renaming
  • Known bot/malware User Agent blocklisting
  • URL length constraints
  • Changed file notification

... and much more.

I only wish I had discovered this plugin earlier; it could have saved me a lot of startup hassle! :-)

Keep an eye on log size though
By , for WP 3.5.1

I use this plugin on a dozen or so sites. It is good for logging and blocking the login hackers but log files can grow very quickly if there is a a high volume attack.

The 404 log is useful to give clues on what the hackers are trying.

If logging changes make sure to exclude backups & cache directories.

Rock Solid
By , for WP 3.5.1

Have been using this plugin for several months on dozens of websites and would never consider running a site w/o it. A solid, dependable sitesaver that held up to the global brute force attacks valiantly. Massive gratitude to the developers for creating and supporting this essential plugin with such dedication and attention to detail!

You must log in to submit a review. You can also log in or register using the form near the top of this page.