Security advisorywp2shell: WordPress core vulnerability. Confirm every site is on 6.8.6, 6.9.5, 7.0.2, or newer.

Read the advisory

Security Ninja for MainWP: fleet security from one dashboard

How the Security Ninja MainWP addon works: free vs premium, what installs where, remote scans, vulnerabilities, combined events, and white label.

Topics Hardening & checklists

Lars Koudal

Updated Published

If you already manage sites with MainWP, Security Ninja can surface security status from those child sites inside your MainWP Dashboard. You still install Security Ninja on each site. The MainWP addon sits only on the Dashboard and pulls results after you sync.

This is for people who run many WordPress installs and do not want to open every wp-admin to see scores, known vulnerabilities, or recent security events.

Security Ninja

MainWP logo

What installs where

LocationWhat to install
MainWP Dashboard siteMainWP Dashboard, Security Ninja, and the Security Ninja for MainWP addon
Each child siteSecurity Ninja only (free or Pro). Do not install the MainWP addon on children

Child sites already include the MainWP integration code inside Security Ninja. The addon on the Dashboard reads that data after sync. If the overview is empty or Sync stays grey, you usually have no connected children yet, or Security Ninja is missing on those sites.

Setup paths:

Free vs premium addon

The free addon is on WordPress.org. It works with free or Pro Security Ninja on child sites. Data shown matches what each site’s version can provide.

CapabilityFree addonPremium addon
View Security Ninja test results per siteYesYes
See known vulnerabilitiesYesYes
Trigger remote security scansYesYes
Sync / pull fresh resultsYesYes
Combined event logging across sitesNoYes (needs events on the child; Pro)
Remote white label on/offNoYes (Pro children)

Premium customers should use the zip from their account, not the free wordpress.org build. The free plugin does not include premium code. Agency packs often include MainWP addon value; see agencies and the MainWP integration page.

What you see after sync

MainWP column with Security Ninja status

Useful day-to-day pieces:

Bulk actions in MainWP

Combined events overview

Honest limits

MainWP plus Security Ninja improves visibility and response time. It does not:

  • Replace hardening on each child (hardening guide)
  • Make shared hosting safe by itself
  • Fix abandoned plugins without you updating or removing them
  • Turn free Security Ninja into Pro features on a child site

Keep the Dashboard site locked down the same way you would any high-value admin: MFA, unique passwords, least privilege, and tested backups. Broader fleet habits: WordPress security checklist and the security guide hub.

For a wider look at MainWP itself (updates, backups, extensions), see MainWP for managing multiple WordPress sites.

Next steps

  1. Connect child sites in MainWP and install Security Ninja on each
  2. Install the matching free or premium addon on the Dashboard only
  3. Sync, then use the Sites column and remote scans as part of your weekly maintenance
  4. Vote or suggest ideas on the roadmap if you need something the addon does not do yet

Found this useful? Share it.