WP Ghost (Hide My WP Ghost) – Security & Firewall
WP Ghost (formerly known as Hide My WP Ghost) is a professional-grade, comprehensive hack-prevention security solution for WordPress. Built for speed and engineered for maximum defense, WP Ghost provides a multi-layered security architecture designed to block hacker bots, neutralize automated scanners, and stop the hack before the reconnaissance even begins.
While traditional security tools focus on Detection (scanning for malware after a breach) or Signature-Filtering (blocking known exploits), WP Ghost focuses on Architecture. By implementing Paths Security and Site Hardening, we remove the digital footprints that make your site a target for automated botnets, providing a proactive foundation that secures your site before it can even be identified as a target.
WP Ghost Global Stats:
- 10 Million+ Monthly Brute-Force Attempts Blocked
- 100 Million+ Monthly Security Threats Prevented
Stop Attacks with Paths Security & Architectural Hardening
Most WordPress attacks are automated. Bots scan millions of sites per hour looking for default paths like /wp-admin or /wp-login.php to confirm a site is running WordPress. Once confirmed, they launch targeted exploits against known plugin or theme vulnerabilities.
WP Ghost breaks this cycle. By changing and securing common paths, you reduce your attack surface by up to 90%. This isn’t “obscurity”, it’s Site Hardening. We re-engineer the visible structure of your site so it is no longer a low-hanging fruit for global botnets.
Key Protections Included
WP Ghost is packed with advanced defensive mechanisms to protect your site against:
- Brute Force Attacks: Blocks automated password guessing at the source.
- SQL Injection & XSS: Neutralizes malicious query strings and script injections.
- Zero-Day Exploits: Secures paths for plugins before patches are even released.
- XML-RPC & REST API Attacks: Shuts down common remote-access entry points.
- Bot Reconnaissance: Prevents “fingerprinting” that hackers use to map your site.
- Spam & Scrapers: Filters malicious traffic, saving bandwidth and server load.
Over 65 Free Security Features Included
We believe professional security should be accessible to everyone. The free version of WP Ghost includes a massive suite of tools to harden your WordPress architecture.
1. Change and Secure Paths (Paths Security)
- Change wp-admin & wp-login.php: Move your login to a unique URL and show a 404 error to intruders.
- Change Lost Password & Register URLs: Secure all authentication entry points.
- Change wp-content & wp-includes: Secure your core system folders from direct access.
- Anonymize Plugins & Themes: Change visible plugin/theme paths so hackers can’t identify your software version.
- Secure admin-ajax.php & REST API: Change the /wp-json path to prevent data scraping.
- Custom Redirects: Set unique login/logout redirects based on user roles.
2. Next-Gen Firewall & Authentication
- 8G & 7G Firewall Filters: High-speed, lightweight server-edge filtering to block bad bots.
- Passkey Authentication (Passwordless 2FA): Use Face ID, Touch ID, or Windows Hello for un-phishable, device-based logins.
- Standard 2FA (Code & Email): Add an extra verification layer to all user accounts.
- Security Headers: Automatically implement CSP, HSTS, X-Frame-Options, and more.
- IP & User Agent Blocking: Manually blacklist suspicious traffic or referrers.
3. Deep Hiding & Footprint Removal
- Scrub Meta Tags: Remove WordPress version numbers and generator tags.
- Clean HTML Comments: Strip identifiable comments that reveal your tech stack.
- Hide Admin Toolbar: Remove the toolbar for specific roles to hide backend indicators.
- Disable Emoticons & RSD: Remove unnecessary header links that bloat code and reveal info.
4. Advanced Disable Options
- Disable XML-RPC: Shut down the most common vector for DDoS and brute force.
- Disable REST API Access: Restrict API access to authenticated users only.
- Frontend Lockdown: Disable right-click, “View Source,” and text selection to prevent manual reconnaissance.
- Disable Directory Browsing: Ensure your server folders are never visible to the public.
5. Brute Force Protection
- Integrated ReCaptcha: Supports Google V2, V3, Enterprise, and Math ReCaptcha.
- Targeted Protection: Enable brute force defense on Login, Signup, and WooCommerce pages.
- Custom Throttling: Define your own lockout times and attempt limits.
6. Extra Tools & Integrations
- Magic Links: Log in securely without a password via a one-time email link.
- Text & URL Mapping: Change any class name or URL in your source code dynamically.
- CDN & Cache Support: Works perfectly with WP Rocket, Cloudflare, and Litespeed.
Premium Hack-Prevention Features
For agencies and high-traffic sites, WP Ghost Premium adds over 80 advanced features focused on Security Intelligence and Automated Response.
- Advanced File Hardening: Secure sensitive files like wp-config.php, php.ini, and debug.log.
- IP Block Automation: Proactively and automatically block repeat offenders at the firewall.
- Security Threats Monitoring: A professional dashboard to track every blocked scan and exploit.
- User Events Cloud Log: Optional 30-day cloud storage for auditing user activity and detecting internal threats.
- Real-time Email Alerts: Get notified instantly of brute-force attempts or suspicious activity.
- Geo-Security (Country Blocking): Block entire countries known for high malicious traffic.
- Priority Support: Direct access to our security experts and founder-led assistance.
Technical Compatibility
WP Ghost is engineered for the modern WordPress ecosystem:
- Hosting Support: Optimized for WP Engine, Inmotion Hosting, Hostgator Hosting, Godaddy Hosting, Host1plus, Payperhost, Fastcomet, Dreamhost, Bitnami Apache, Bitnami Nginx, Google Cloud Hosting, Amazon AWS Lightsail, Litespeed Hosting, Flywheels Hosting, Kinsta Hosting, Ploi.io, CloudPanel, RunCloud, Rocket Domain, Yunohost.
- Server Support: Fully compatible with Nginx, Apache, LiteSpeed, and IIS.
- Plugin Support: Seamless integration with Woocommerce, WPML, WPMUDEV, W3 Total Cache, Gravity, WP Super Cache, WP Fastest Cache, Hummingbird Cache, Cachify Cache, Litespeed Cache, SiteGround Optimizer, Nitropack, Cache Enabler, CDN Enabler, WOT Cache, Autoptimize, Jetpack by WordPress, Contact Form 7, bbPress, Manage WP, All In One SEO, Rank Math, Yoast SEO, Squirrly SEO, WP-Rocket, Minify HTML, Solid Security, Sucuri Security, Really Simple SSL, WordFence Security, WP Cerber Security, BBQ Firewall, Anti-Malware Security, Back-Up WordPress, Elementor Page Builder, Divi Builder, Weglot Translate, AddToAny Share Btn, Limit Login Attempts Reloaded, Loginizer, Shield Security, Asset CleanUp, WP Hide & Security Enhancer, and more.
Stop the hack before it starts. Join over 100,000 users who trust WP Ghost to secure their digital presence.
