10 Best WordPress Security Plugins in 2024
We recently looked at several of the top results when you search Google for the “best WordPress security plugins 2024.” Several things stood out about those.
The most important thing that stood out is that these posts were biased in ways that were not disclosed. One post promoted the developer’s solution as the best, without bothering to ever disclose it was theirs. Another claimed the best plugins were ones that are paying affiliate revenue to the poster. So the post was an ad, without that key detail being disclosed.
The second thing that stood out is that those biased posts didn’t provide accurate information about the solutions they were biased to (or about others for that matter). For example, one of the plugins was described as containing features it doesn’t contain. That was because the post was really advertising an unrelated paid service. Multiple were promoted as providing protection against a type of attack that doesn’t even happen.
The third thing that stood out was that while the posts were labeled as being from 2024, it wasn’t hard to spot that these were old posts with the year simply updated. They listed plugins under old names they stopped using before 2024. And they listed plugins that haven’t been supported or worked for several years.
The fourth thing that stood out was a complete lack of any evidence of effectiveness of the solutions recommended versus other solutions. That was unsurprising considering the people writing the post are marketing content creators, not security professionals.
You can actually do testing to see how well security plugins work. We have done plenty of testing of them to see if they protect against vulnerabilities in other plugins. The results haven’t been good for most of the plugins. What is worse is that results for them are not steadily improving or even, for the most part, improving at all. You can see the results of the individual tests we have done here.
What we also have to measure that type of protection is software we mainly use to make sure that our own Plugin Vulnerabilities Firewall’s protection continues to work as we make changes to it. By running that against other plugins, we can quickly assess how much of the protection we offer that they also offer. Below, we have listed the top 10 plugins by that measure. Notably, the second best plugin is one that wasn’t mentioned on the best plugins posts we looked recently, despite being a great free option.
1. Plugin Vulnerabilities Firewall
2. NinjaFirewall
3. Wordfence Security
4. Pareto Security
5. All-In-One Security (AIOS)
6. Web Application Firewall
7. (tied) Hide My WP
7. (tied) Hide My WP Ghost Lite
9. BulletProof Security
10. Anti-Malware Security and Brute-Force Firewall
1. Plugin Vulnerabilities Firewall
- Page on our website
- Active Installs: N/A
- Version Tested: 1.0.34
Protection Percentage: 100%
2. NinjaFirewall
- WordPress.org Plugin Directory page
- Active Installs: 100,000+
- Version Tested: 4.5.10
Protection Percentage: 38.8%
3. Wordfence Security
- WordPress.org Plugin Directory page
- Active Installs: 4+ Million
- Version Tested: 7.11.0
Protection Percentage: 22.4%
4. Pareto Security
- WordPress.org Plugin Directory page
- Active Installs: 500+
- Version Tested: 3.2.8
Protection Percentage: 19.7%
5. All-In-One Security (AIOS)
- WordPress.org Plugin Directory page
- Active Installs: 1+ Million
- Version Tested: 5.2.5
Protection Percentage: 14.7%
6. Web Application Firewall
- WordPress.org Plugin Directory page
- Active Installs: 300+
- Version Tested: 2.1.1
Protection Percentage: 9.8%
7. (tied) Hide My WP
- Code Canyon page
- Active Installs: N/A
- Version Tested: 6.2.11
Protection Percentage: 9.8%
7. (tied) Hide My WP Ghost Lite
- WordPress.org Plugin Directory page
- Active Installs: 200,000+
- Version Tested: 5.0.27
Protection Percentage: 8.2%
9. BulletProof Security
- WordPress.org Plugin Directory page
- Active Installs: 40,000+
- Version Tested: 6.9
Protection Percentage: 7.6%
10. Anti-Malware Security and Brute-Force Firewall
- WordPress.org Plugin Directory page
- Active Installs: 200,000+
- Version Tested: 4.21.96
Protection Percentage: 3.8%