Skip to content
WordPress.org

Azərbaycan Türkcəsi

  • Themes
  • Plugins
  • News
  • Support
  • About
  • Contact
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Vortix Web Security

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Vortix Web Security

By MohtamimNayeem
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Vortix Web Security provides practical WordPress hardening without accounts, license keys, remote telemetry or a license server. The plugin is designed to be conservative: new compatibility-sensitive protections are off by default, and .htaccess changes are verified and reverted if the site’s own loopback probe reports an HTTP 500.

Free protection modules

  1. Basic Hardening – generic login errors, public username-enumeration protection and MIME-sniffing protection.
  2. Login Protection – temporary IP and username lockouts after repeated failed logins.
  3. Disable XML-RPC – disables the XML-RPC interface and related discovery links.
  4. Bad Bot Blocker – blocks requests from a small list of known scanner/exploit User-Agents.
  5. Upload Protection – blocks execution of common script files in the uploads directory on Apache/LiteSpeed.
  6. Disable File Editor – disables the WordPress plugin and theme code editors.
  7. Hide WP Version – removes common WordPress version disclosures.
  8. Disable Directory Browsing – adds a verified Options -Indexes rule on Apache/LiteSpeed.
  9. Strong Password Enforcement – requires stronger passwords for users who can publish content.
  10. Automatic Plugin Updates – allows automatic updates for packages served by WordPress.org over HTTPS.
  11. Automatic Theme Updates – allows automatic theme updates for packages served by WordPress.org over HTTPS.
  12. Pingback & Trackback Control – disables legacy pingback/trackback publishing paths.
  13. Safe Security Headers – adds conservative X-Content-Type-Options and Referrer-Policy headers.
  14. Sensitive File Protection – blocks direct access to common deployment/configuration filenames and Git metadata directories.
  15. Malicious Query Blocking – blocks a small set of high-confidence XSS, traversal, null-byte, webshell and SQL injection signatures in the query string.

A 20-point Security Scan provides local checks for HTTPS, XML-RPC state, debug mode, file permissions, upload protection, version exposure, administrator username, login protection, directory listing, user enumeration, REST user exposure, file editors, RSD/WLW links, outdated plugins, pingback/trackback control, security headers, sensitive-file protection and malicious-query protection. Checks that cannot be verified are reported as unknown and excluded from the score.

Compatibility-sensitive modules remain off by default, including XML-RPC blocking, bot blocking, .htaccess protections, automatic updates, pingback/trackback control and malicious-query blocking. Existing installations keep their current choices when updating; newly introduced 2.2.0 modules are not enabled automatically.

Login recovery

If Vortix Login Protection ever locks out an administrator, add this temporary line to wp-config.php:

define( 'VORTIX_DISABLE_LOGIN_PROTECTION', true );

Log in, remove the line, and then review the Login Protection settings. This bypass affects only Vortix’s lockout module.

Privacy

Blocked requests are logged locally in the site’s own database. The log contains the client IP address, request path without the query string, event type and time. Entries are automatically removed according to the configured retention period. Login-attempt counters use keyed hashes and expire automatically.

The plugin does not send telemetry, security logs, license data or scan results to the author or another server.

External services

Vortix Web Security does not contact an external service.

  • Security Scan and .htaccess safety checks may make loopback requests to the site’s own URL.
  • Cloudflare mode only reads the CF-Connecting-IP request header and uses address ranges bundled with the plugin; it does not contact Cloudflare.
  • The optional Premium link is an ordinary user-initiated external link. No request is made by the plugin merely because the link is displayed.

Installation

  1. Upload the plugin to /wp-content/plugins/vortix-web-security/, or install it from Plugins.
  2. Activate Vortix Web Security.
  3. Open Vortix Web Security and review the protection modules.
  4. If the site is behind a CDN or reverse proxy, review Settings > Trusted proxy.

FAQ

Does it require a license or account?

No. The free plugin has no license key, trial, registration or remote licensing system.

Will an update enable the new 2.2.0 protections automatically?

No. Existing installations keep their current module choices. New 2.2.0 modules start disabled so an update does not silently change site behaviour.

Can Login Protection lock me out?

A temporary lockout can occur after repeated failures. If recovery is needed, use the VORTIX_DISABLE_LOGIN_PROTECTION wp-config.php bypass described above.

Can .htaccess features break my site?

The plugin uses marked rules and probes the site’s own URL after a write. If the response indicates HTTP 500, the change is reverted. Hosts that do not support .htaccess are not modified.

Does Malicious Query Blocking inspect POST data?

No. It inspects only the query string and uses conservative, high-confidence signatures. It is disabled by default because application-specific query formats vary.

Does it work on Nginx?

Features that do not depend on .htaccess work on Nginx. Upload Protection, Disable Directory Browsing and Sensitive File Protection require equivalent Nginx configuration and will not claim to enforce those rules through .htaccess.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Vortix Web Security” is open source software. The following people have contributed to this plugin.

Contributors
  • MohtamimNayeem

Translate “Vortix Web Security” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

2.2.0

  • Added Pingback & Trackback Control.
  • Added Safe Security Headers with conservative, compatibility-focused headers.
  • Added Sensitive File Protection with verified .htaccess changes.
  • Added conservative Malicious Query Blocking for high-confidence query-string payloads.
  • Expanded Security Scan from 16 to 20 local checks.
  • Added a wp-config.php emergency bypass for Login Protection.
  • Added versioned migration on plugins_loaded; new 2.2.0 modules stay off for existing installations.
  • Removed unsupported premium marketing claims that were not represented by the separately distributed Pro codebase.
  • Kept the free plugin offline-first with no telemetry or remote license infrastructure.

2.1.1

  • Refreshed admin design: colour-coded status, header banner, feature filter and score ring.

2.1.0

  • First WordPress.org release of the free edition.
  • Added Basic Hardening and Disable XML-RPC.
  • Rebuilt the Modules screen and made compatibility-sensitive features opt-in.
  • Added verified .htaccess changes with loopback safety checks.
  • Added trusted proxy handling and local security logging.

Meta

  • Version 2.2.0
  • Last updated 5 days ago
  • Active installations Fewer than 10
  • WordPress version 6.2 or higher
  • Tested up to 7.0.7
  • PHP version 8.0 or higher
  • Language
    English (US)
  • Tags
    Brute Forcehardeninglogin securitysecurityxmlrpc
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • MohtamimNayeem

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Support
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

Azərbaycan Türkcəsi

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry.