Security advisorywp2shell: WordPress core vulnerability. Confirm every site is on 6.8.6, 6.9.5, 7.0.2, or newer.

Read the advisory

WP Security Ninja

About Security Ninja

A practical WordPress security plugin, built for people who want protection without the drama.

  • ✓ Since 2011
  • ✓ 100,000+ sites
  • ✓ Actively maintained
WP Security Ninja login form protection settings

As featured on

  • Kinsta
  • Hostinger
  • Cloudways
  • AppSumo
  • Freemius
  • WP Mayor
  • WPMarmite
  • WPExplorer
  • WPLift
  • WP Loop
  • InfluenceWP
  • G2

Practical WordPress security since 2011

Security Ninja is built for site owners who will only spend a little time on security. Clear tools, real protection, and steady updates so that little time is enough.

  • ✓ Firewall, malware scanning, login hardening, scheduled scans, and 50+ security tests
  • ✓ Install wizard and import/export for multi-site setups
  • ✓ Free baseline on WordPress.org, full protection with Pro
  • ✓ White label on licenses with 25 or more sites
See the roadmap

A more straightforward take on a well-known problem

For most of us, security is something we think about after it is too late. Security is boring. You do not see it. It does not look cool. Years ago we realized the average site owner will invest the absolute minimum into security. We wanted to turn that minimum into just enough.

  • ✓ Give owners a non-technical, clear look at their site security
  • ✓ Keep the interface simple: this is good, this is bad
  • ✓ No unnecessary buttons, options, or settings
See the security tests

Who's behind all this?

Security Ninja was created by WebFactory Ltd. The plugin was purchased in 2019 and has since then been maintained, supported, and sold by Larsik Corp. Lars Koudal develops and supports it day to day.

  • ✓ Owned through Larsik Corp since 2019
  • ✓ Fuller bio and profiles on the owner page
About Lars Koudal

Getting set up

The install wizard gets the basics on, and import/export helps if you manage more than one site. Prefer reading first? There are 150+ docs, including help from inside the plugin.

On licenses with 25 or more sites, white label lets agencies brand the plugin for client work. The plugin is maintained and sold by Larsik Corp. See what we are building next on the roadmap.

The history of Security Ninja

Security Ninja celebrated its tenth birthday in 2021. In internet years that is a lot. Time flies, and at some point you realize it has been longer than it feels.

Through the years what kept us going was the fact that people used it. Security Ninja kept sites safe, users informed, and us happy.

We hope that will continue for another ten years, at least. Till then, here is a short history of Security Ninja’s birth and growth. For what shipped after this origin story, see the live changelog and the year archives below.

  • Early summer 2011
    Security Ninja (it was called “Site Security Tester” in that first version) was made as an internal tool, used for testing the most common security issues on clients’ sites. It had barely ten tests, but we installed it on every site to quickly check things we knew needed checking.
  • September 27th, 2011
    Security Ninja went live for sale on CodeCanyon! For a disturbingly low $8 you could have bought a lifetime license for unlimited sites. Not a very wise business decision, we know. But those were the prices back in the day.
  • December 31st, 2011
    After three months Security Ninja already racked 318 sales and was featured on CodeCanyon. Wayback machine has a snapshot. The price was increased to a whopping $10.
  • August 31st, 2012
    Core Scanner add-on is released! First add-on in the series of four (on CC) for $6.
    Sales are still going strong; we’re at 823. Which means Security Ninja sales almost 3 copies a day. From the initial ten tests, it’s grown to 26.
  • December 2nd, 2012
    Security Ninja Lite added to the WordPress repository as a free plugin. This was the only terrible move we ever did with Security Ninja. It turns out nobody wants to use a “lite” version of a plugin. It never got any traction.
  • December 23rd, 2012
    Scheduled Scanner is released! For $6 you can automatically run Security Ninja and core scanner add-on tests.
    Security Ninja passed 1,100 sales and Core Scanner 150.
  • August 9th, 2014
    Third add-on released - Events Logger. Security Ninja is already a reputable brand and sales are still going strong.
  • September 17th, 2014
    To make purchasing more accessible, we created the Security Ninja Bundle. A package with all the add-ons and the main plugin. By this time Security Ninja has 2,500+ sales and Core Scanner 1,000+.
  • March 5th, 2015
    Fourth and last add-on on CodeCanyon released - Malware Scanner. Although the sales are still solid, the overall traffic and visibility on CodeCanyon is dropping significantly.
  • August 30th, 2016
    We pulled the trigger! Security Ninja is no longer available on CodeCanyon and the main module is now free and available on the WordPress repository. All add-ons have been packed into one plugin - Security Ninja PRO which we’re selling on our own. Technically we’re utilizing the freemium but most sales come from the website, not from the free version.
  • September 16th, 2016
    Although we’ve started removing other plugins from CodeCanyon too, we’ve decided to put Security Ninja PRO back on it. But on our non-exclusive account since we’re now selling SN on our own. No sales were expected and (almost) none were made. The move was made only for marketing benefits.
  • April 9th, 2017
    New module (ex add-on) - Auto Fixer. Nobody wants to mess with code if they can click one “fix” button, right? New tests are continuously added to the main module - we’re now at 50+.
    After moving from CodeCanyon we lost a lot of traffic, but sales are still going strong.
  • December 7th, 2017
    After asking users what functionality is missing in Security Ninja PRO, we created the Database Optimizer module. A one-click solution to all database speed and maintenance problems.
  • April 5th, 2018
    Cloud Firewall is released! Ban 600 million bad IPs with one click and protect your login from brute-force attacks.

Release notes by year

The origin timeline above stops in 2018. Everything since then lives in the release notes.

Customer reviews

4.9 / 5 from 255 reviews

Leave a review

★★★★★

Great offering

“My Wordpress site had recently been compromised even when I had a scanning plugin that was supposed to detect malware.”

coachcharlescain

★★★★★

“Security Ninja has improved massively over the last year. The plugin keeps getting better and more powerful, and it has become an important part of how I manage WordPress security…”

Vassos Hadjivassiliou

★★★★★

One of my best purchases

“So I end up purchasing quite a few accounts here. Most are just sitting on the shelf, hoping that someday they will mature enough to be worth it.”

Troy

★★★★★

Excellent Plugin

“Security Ninja has everything and more of what you’d want in a security plugin. Some examples are the firewall, limited login attempts, malware scanner, logs, and alerts.”

Cord Varty

See all 255 reviews

Ready to lock down your WordPress site?

Install Security Ninja and get practical protection in place.

Get Started Now