Guides/Edit your website/Site settings/Security settings

Security settings

Last reviewed on November 12, 2025

In your website’s Security Settings, you can manage certain aspects of your site’s security. This guide will explain each setting.

This feature is available on sites with the WordPress.com Business and Commerce plans. If you have a Business plan, make sure to activate it. For free sites and sites on the Personal and Premium plans, upgrade your plan to access this feature.

Access your security settings

To visit the Security settings:

  1. Visit your site’s dashboard.
  2. Navigate to JetpackSettings.
  3. Select the “Security” tab.

Each setting found here is explained below.

Sidebar navigation menu for Jetpack, displaying options including Activity Log, Dashboard, Settings, VaultPress, Akismet Anti-spam, Search, and Stats.
Settings → Security

Backups and security scanning

Your site is automatically and regularly backed up with Jetpack Backup and Scan. You can review and restore from a backup at any time.

Downtime monitoring

While rare, a site may go offline if an unexpected error occurs, such as an unsuccessful plugin or theme update. In these cases, you can have our downtime monitoring system check your site and notify you if it becomes unresponsive. This is a great way to reduce downtime on your site.

The Downtime monitoring section of Jetpack Security.
Downtime monitoring

Anti-spam

Your site is automatically protected from spam with Akismet. Akismet filters comment, form, and text spam on your site.

Prevent brute force login attacks

We monitor login attempts on your site to identify and block malicious actors who may try to gain access with a technique called brute force login attacks. When an attacker fails to log into your site too many consecutive times, Jetpack temporarily blocks any further login attempts from their IP and may present a math problem to solve to get back in.

The prevent brute force login attacks settings is a toggle.
Brute force protection

Always allowed IP addresses

This option lets you tell Jetpack not to block certain IP addresses — even if its security system detects suspicious behavior from them.

WordPress.com log in

WordPress.com uses features from our own admin alongside the traditional WP Admin dashboard. We enable “Allow users to log in to this site using WordPress.com accounts” by default to seamlessly bridge the WP Admin and WordPress.com settings. This setting is referred to as Secure Sign On.

We recommend keeping this setting turned on, as disabling this option will result in some pages in the dashboard prompting you to log into WP Admin manually. For more details, check out our Secure Sign On page.

The WordPress.com login option with toggles to configure the settings.
WordPress.com login

Was this guide helpful for you?

Not quite what you're looking for? Get Help!

Copied to clipboard!