SecuPress Free — WordPress Security


Test it now!

You can test SecuPress Free now.


Protect your WordPress with malware scans; block bots & suspicious IPs. Get a complete WordPress security toolkit for free or as a pro plugin. SecuPress is GDPR compliant.

What’s the difference between free and pro version?
If you are proactive, our free WordPress security plugin is a great choice! No time to activate weekly scans? Then SecuPress pro is the way to go. Our plugin takes care of everything with automated tasks.

Here are some of our most popular features:

  • Anti Brute Force login
  • Blocked IPs
  • Pare-Feu
  • Security alerts (1)
  • Malware Scan (1)
  • Block country by geolocation (1)

We have included some features you won’t find in most WordPress security plugins:

  • Protection of Security Keys
  • Block visits from Bad Bots
  • Vulnerable Plugins & Themes detection (1)
  • Security Reports in PDF format (1)

You can check out Frequently Asked Questions or get in touch with our support. Want to know all about SecuPress? You can read our documentation here:

How will you know it works?
Well, we have a dedicated security scanner that will give you a clear security grade and report for your website. This way, you’ll know exactly what to fix.

WordPress Features

Security Audit
SecuPress is the only plugin with a full scanner able to fix the issues for you. And when it requires a decision from you, it will ask you before proceeding. With this feature, you can check 35 security points in 5 minutes and let us take care of the rest.

Once done, you get a security grade that gives you a clear idea of what your security level is. You can export this analysis in PDF format to share with others (clients or colleagues) (1).

Users & Login
This feature is the easiest way to make sure your users’ data is protected and to keep their accounts from being compromised. With this feature you can limit the number of bad login attempts, ban non-existing usernames login attempts and set a non-login time slot. SecuPress also makes sure you can avoid double logins and control your sessions.

SecuPress also adds a 2FA (Two Factor Authentication) because it’s almost a mandatory feature when it comes to WordPress security!

The plugin also gives you greater user and password control as you can set:

  • Password lifetimes for your users.
  • Enforce strong password use.
  • Forbid the use of vague usernames like www or admin.

Tired of bots finding your WordPress login page? Finally, don’t let bots find your login page, just move it with the famous Move Login plugin, now included in SecuPress.

Plugins and Themes
SecuPress helps you detect themes and plugins that are vulnerable or that have been tampered with to include malicious code. If you install one of these, your security module will send out an email alert and give you a warning in WordPress.

SecuPress takes security further by limiting plugin activation, deactivation, installation and removal in your production (live) website. Plugin and theme uploads via .zip files will be on lockdown as well to block off this easy hacking route.

WordPress Core
SecuPress reinforces the WordPress Core to keep it safe. The security plugin optimizes what’s under the hood to secure the config file by setting the proper parameters.

Sensitive Data
SecuPress secures content in many ways:

  • The plugin secures WordPress Endpoints and APIs by blocking bad requests for XML-RPC or REST API.
  • It blocks bad bots with its Robots Blackhole feature.
  • It provides an anti-hotlink feature to preserve your bandwidth.
  • The plugin packs 7 anti-disclose security modules to make sure no precious information is available to hackers in your PHP or WordPress itself.
  • Profile and SecuPress settings pages are password protected to keep sensitive information away from prying eyes.


  • SecuPress is one of the most efficient WordPress bouncer you’ll ever see!
  • The plugin blocks malicious incoming requests.
  • It blocks bad User Agents (no bad crawlers allowed).
  • Bad requests methods also get the boot in a single click.
  • Les URL sont conservées dans la vérification : pas de mauvais contenus d’URL.
  • SQL injection scanners are kept out as well.
  • Brute force attempts are stopped in their tracks.
  • GeoIP Blocking by country gives you more control over your traffic.

Malware Scan
SecuPress has a unique malware scan developed by our security experts. It hunts down bad files and provides you with an easy step-by-step report that lets you take action. It looks into:

  • Bad files in your FTP.
  • Your uploads folder for dangerous files.
  • Potential phishing attempts via index.php loads.

We know firsthand how painful it is to pick up the pieces after an attack damages your WordPress. SecuPress preserves your data to help you avoid lost content or settings if your website comes under attack. The plugin backs up your database and files and lets you download them to guarantee you peace of mind.

Anti Spam
Did you know that 60% of the traffic on the Internet is generated by bots? Most of them happen to be spam bots. We developed our own anti-spam system that works quietly in the background. Just activate it and enjoy a spam free experience.

Alerts are an essential tool when your website is under attack. When something important happens on your website, SecuPress will send you an alert via email. We’re working on alerts via SMS, Slack & Twitter as well.

Vous recevez aussi un rapport quotidien qui fournit un résumé des attaques tentées et de toutes les activités bloquées par SecuPress.

Scheduled Security Tasks
SecuPress can run 3 separate scheduled tasks for you. It’s like having a security patrol on your WordPress.

Scheduled Scanner: SecuPress scans your website to detect any issues. After the scan is complete, you get a report in your inbox outlining any actions you have to take to protect your website.
Scheduled Backup: our team knows that everyone at one time or another forgets to back things up. We made it an automatic task to help ensure you always can recover from an attack with your content safe.
Scheduled Malware Scan: this security feature scans your website at regular intervals to hunt down any malware that may have gotten into your WordPress.

SecuPress will keep a log of important security activities and 404 pages triggered by users, bots or even Chuck Norris. This lets you keep an eye on what’s going on in your WordPress at any time. You can also control banned IPs from this option.

(1) Available in the Pro Version.

(SecuPress est une extension de sécurité WordPress française)

Captures d’écran

  • All modules from SecuPress
  • A module page (here is Users & Login)
  • Le premier scan
  • La 1ère étape: résultat du scan
  • La 2ème étape: choisissez ce que voulez corriger automatiquement
  • SecuPress is fixing issue for you
  • The 3rd step: manual fix, when you have to decide something
  • The 4th step: final report, you can export it as PDF (1)


Il est important de supprimer toutes les autres extensions de sécurité avant d’activer SecuPress.

  1. Upload the plugin files to the /wp-content/plugins/secupress directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress.
  3. Use the SecuPress->Settings screen to configure the plugin.


What does SecuPress do, exactly?

SecuPress est une extension pour les sites WordPress qui amène une meilleure sécurité sans sacrifier l’utilisation. C’est simple à utiliser pour vous et difficile à pirater pour les hackers. D’abord SecuPress scanne votre site, cherche les vulnérabilités et fourni un rapport détaillé sur la façon de renforcer la sécurité de WordPress. La majorité des recommandations sont simples à mettre en place via une simple case à cocher, peu de manipulations sont à faire manuellement.

What makes SecuPress better than any other security plugin?

SecuPress protège votre site sur plusieurs fronts : anti spam, double authentification. Sa meilleure fonctionnalité est sa simplicité d’utilisation. Vous n’avez pas à être une personne expérimentée pour utiliser et sécuriser votre site WordPress comme un expert !

Nos alarmes de sécurité hébergées sur nos serveurs amènent des données des vulnérabilités récentes des extensions et thèmes. Cela permet de toujours être attentif et sécurisé.

Is SecuPress compatible with multisites installation?

Yes, SecuPress can be activated for all your sub-sites, just activate it from your main network site.

Est-ce que SecuPress est compatible avec tous les hébergeurs ?

Yes, SecuPress is compatible with all web hosters like o2switch, OVH, Siteground, BlueHost, PlanetHoster, WP Engine or GoDaddy? If you encounter an issue, do not hesitate to contact our support team.

Is SecuPress compatible with all caching plugins like WP Rocket, WP Fastest Cache, W3 Total Cache, WP Super Cache?

Yes, SecuPress is compatible with all WordPress caching plugins. If you encounter an issue, do not hesitate to contact our support team.

Is SecuPress compatible with all multilingual plugins like WeGlot, PolyLang, WPML, qTranslate?

Oui, SecuPress est compatible avec toutes les extensions WordPress multilingue comme PolyLang, WPML, qTranslate. SI vous rencontrez un problème, merci de contacter l’équipe de support.

Is SecuPress compatible with all server engines like Apache, Nginx, IIS7?

Yes, SecuPress is compatible with all server engines. If you encounter an issue, do not hesitate to contact our support team.

Is SecuPress compatible with other security plugins like WordFence, iThemes Security, Bullet Proof Security?

La réponse est non. SecuPress n’est pas compatible avec d’autres extensions de sécurité. Tout comme 2 extensions de cache ne rendrons pas le site plus rapide, 2 extensions de sécurité ne rendent pas votre WordPress plus sécure. Les règles de sécurité pourraient être en conflit si 2 extensions étaient installées. Ceci peut causer des erreurs et ce n’est pas recommandé.


21 avril 2023
Very Disappointed with this. Pros: Nice UI and thats it. Cons: Nothing works. Scan does not work. When you check move login, nothing apprears to add the login url. So when it is save, error shows up to add the login url. No documentation as to where to add the login url. Would have gladly paid for it, if it worked. Moving to Wordfence or Ithemes.
8 mars 2023
<font _mstmutation="1" _msttexthash="8450481" _msthash="756">Installation et réglage simplissime, conseils très clairs pour optimiser la sécurité du site, Top et performant. Bravo!</font><font _mstmutation="1"></font> <font _mstmutation="1"></font>
22 janvier 2023
When trying to activate SecuPress Free, I seemed to get stuck on a screen asking me to provide the license for the pro version. I get that developers want to get paid for their work - I don't work for free, so why should they? But if it's not free, why not just say so?
20 janvier 2023
Bonjour, Voici une extension excellente car efficace, qui fait donc le job parfaitement, simplement, et surtout indispensable pour un incompétent comme moi en codage... Version pro recommandée, entre autres et surtout pour un site e-commerce (De C+ avec version gratuite je suis passé à A+). Support réactif et compétent. Et il est Français et elle est Française (l'extension), ah mais.
19 décembre 2022
Bonjour, J’ai découvert un soucis sur mon site e-commerce en production pour lequel le processus de vente est bloqué lors de la validation de la commande par carte bancaire. Si je désactive secupress tout fonctionne correctement. Et à ma grande surprise lorsque j'ai réactivé le plugin, mon site était en vrac : les polices web ne s'affichait plus (po. J'ai dû restorer l'ensemble du site et la bdd via mon hébergeur o2switch pour retrouver un fonctionnement normal ce que justement n'est pas normal. j'ai envoyé un ticket support (j'ai la version pro) mais j'ai eu un message auto : The SecuPress Team is light during xmas, we count on your understanding and wish you happy celebrations. J'avais choisi ce plugin parce français et le version pro pour avoir un support rapide. C'est pas gagné. A suivre
29 novembre 2022
Not as effective as Wordfence which allows you to see live traffic and cannot mass ban IPs
Lire les 98 avis

Contributeurs/contributrices & développeurs/développeuses

« SecuPress Free — WordPress Security » est un logiciel libre. Les personnes suivantes ont contribué à cette extension.


“SecuPress Free — WordPress Security” a été traduit dans 3 locales. Remerciez l’équipe de traduction pour ses contributions.

Traduisez « SecuPress Free — WordPress Security » dans votre langue.

Le développement vous intéresse ?

Parcourir le code, consulter le SVN dépôt, ou s’inscrire au journal de développement par RSS.



  • 17 April 2023
  • Update: Malware Database
  • Fix#1001: Call to undefined function secupress_format_message() in /secupress-pro/free/admin/functions/scan-fix.php:51
  • Fix#1000: Passing null to parameter #1 ($string) of type string is deprecated in /secupress/free/functions/files.php on line 693
  • Fix#996: PHP Fatal error: Allowed memory size of 1075838976 bytes exhausted in secupress-pro/pro/modules/file-system/tools.php on line 88
  • Fix#993: joker in IPs ban everything
  • Fix#977: Time to soon for antispam
  • Fix#904: cannot deactivate default role lock
  • Fix global i18n