WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Get started

Installation Wizard

Walk through the Security Ninja Installation Wizard: firewall, events, vulnerabilities, and Pro steps for login protection, default fixes, and WooCommerce.

The Installation Wizard walks you through a short setup after install. It usually opens automatically the first time.

Free and Pro: Free covers firewall, events, and vulnerabilities. Pro adds login protection, default Fixes, and WooCommerce protection when WooCommerce is active. Security tests start in the background when the wizard begins.

Security Ninja Install Wizard welcome step

Wizard steps

Welcome

Explains what the wizard covers. Start the steps, or skip to the dashboard and come back later.

Firewall

Activate Firewall Protection turns on firewall protection with global rules and 8G query filtering.

On Pro it also enables Cloud Firewall, the global ban network, and 404 Guard defaults (10 requests in 5 minutes triggers a 10-minute block). Pro shows an unblock URL if you lock yourself out. Save that URL, or use the copy emailed to the admin address.

Activate Firewall Protection wizard step

Events Logger

Activate Events Logger turns on an audit trail with standard modules: logins, user and role changes, plugin and theme updates, settings changes, content edits, and WooCommerce activity when the store plugin is active. Turn modules on or off later under Events Logger settings.

Activate Events Logger wizard step

Vulnerabilities

Activate Vulnerability Scanner checks installed plugins and themes against known issues and notifies you in admin when something needs attention.

Activate Vulnerability Scanner wizard step

Login Protection (Pro)

Login Protection blocks repeated failed logins from the same IP and works with Events Logger to record suspicious login activity. Configure 2FA or a custom login URL later when you are ready.

Login Protection wizard step

Default fixes (Pro)

Activate Default Security Measures applies recommended hardening in one click: hide version info, disable username enumeration, XML-RPC, and application passwords, remove unneeded files, set security headers, and enable secure cookie flags. Details: Activate Default Security Measures.

Activate Default Security Measures wizard step

WooCommerce (Pro, when active)

If WooCommerce is active, the wizard offers store protection defaults: checkout, add-to-cart, and order rate limits, plus coupon protection. Tune the limits later under Cloud Firewall → WooCommerce Protection.

WooCommerce Protection wizard step

Done

Confirms your baseline and points to next steps: run security tests, review vulnerability results, run the core file scanner, browse Events Logger, and explore Login Protection options.

Install Wizard done step

Reopen the wizard later

Open Security Ninja → Wizard in wp-admin. Rerunning can overwrite settings for modules you activate again. Use Skip or Continue on steps you do not want to change.

Marketing overview: Install Wizard.

Video walkthrough

Watch a walkthrough of WP Security Ninja to get started quickly.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image