You do not need a 50-step “enterprise configuration” checklist to get Security Ninja useful. Install Free, run the tests and scanners, then turn on Pro layers when the site needs them. Prefer one WordPress security plugin as the primary stack. Still choosing between suites? Start with the best WordPress security plugins comparison.

Before you install
- Confirm you have a backup you can restore (backup plan)
- Prefer one application security stack, not three WAFs fighting each other (plugin comparison, conflicts guide)
- Note admin emails and who has administrator access
- On inherited sites, run vulnerability and malware scans before you enable strict firewall rules
What not to stack
Avoid running two or more of these as primary WordPress security suites on the same site:
- Security Ninja + Wordfence + Sucuri-style all-in-one stacks
- Two plugin firewalls both filtering every request
- Two login lockout plugins with different thresholds
- Two scheduled malware scanners hammering disk on the same cron
A host or CDN WAF in front of WordPress is fine. That is edge filtering, not a second wp-admin security plugin.
If a client site already has another suite, migrate deliberately: export settings you need, disable the old firewall first, then remove the old plugin. See security plugin conflicts.
Free setup (baseline)
- Install from WordPress.org or your preferred package
- Run the install wizard if offered; otherwise open the Security Ninja menu
- Run the 50+ security tests and fix what you understand (security tests)
- Run the vulnerability scanner and update or remove flagged plugins/themes
- Run core scanner if you want a known-good check on WordPress core
- Skim events / logs so you know where alerts land later
What Free covers vs Pro: Free vs premium and features. Install docs: /docs/installation-and-usage/install/.
Pro setup (protection layer)
Turn these on when you are ready for active protection, not on day one if you are still cleaning house:
- Cloud Firewall (cloud firewall): enable the bad-IP list (600M+), then add country or custom rules only if you need them
- Malware scanner (malware scanner): on-demand first, then scheduled scans
- Login protection + 2FA (login protection, 2FA): lockouts, rename login if you use it, 2FA on admins
- WooCommerce limits if you run a store (WooCommerce)
- Webhooks / email alerts so findings reach Slack or your inbox (webhooks)
False positives and “something broke”
Firewalls and login tools sometimes block legitimate traffic:
Order of rollback: disable the last feature you changed, not everything at once. Document what you disabled so you can re-enable safely on staging.
Agency and multi-site setup
For agencies managing many WordPress installs:
- Standardize a baseline on staging: Free tests + vuln scan on every site; Pro firewall + login + scheduled scans on production tiers that pay for it
- MainWP and similar: use MainWP integration so updates and Security Ninja visibility stay centralized where your workflow supports it
- White label (white label) when clients see the plugin in wp-admin; keep internal runbooks with the real product name
- Document per client: which modules are on, alert email or webhook destination, and who owns firewall rule changes
- Bulk licensing lives under agencies and pricing
Do not copy one client’s aggressive country block list to every site without checking each audience.
A sane order for the first week
Deeper habits: checklist, hardening, login guide, configuration hub.
If something breaks after enabling a feature
Disable the last change (firewall rule, login URL rename, or a conflicting plugin). See security plugin conflicts. Locked out of admin? Use the firewall unblock docs under /docs/firewall/.
Bottom line
Setup is maintenance, not theater. Free gives visibility. Pro adds block, scan, and login hardening on a schedule you will keep. One primary stack, staged enablement, and a rollback plan beat enabling every toggle on day one. Start free, then pricing when you want the full loop.