plugin-icon

VMP Security – Firewall, Malware Scan, and Login Security

Av VMP™·
Firewall, malware scanner, 2FA, country blocking, and audit log — all free with real-time updates. No 30-day delays. No paywall.
Version
2.2.7
Senast uppdaterat
Apr 2, 2026
VMP Security – Firewall, Malware Scan, and Login Security

Other WordPress security plugins delay firewall rules by 30 days and charge $119/year for country blocking and audit logs. We don’t.

VMP Security is a free WordPress security plugin that gives you 280+ real-time firewall rules, 9 specialized malware scanners, 40,000+ threat signatures, country blocking, audit logging, two-factor authentication, and brute force protection. Everything runs on your server. Your files and database never leave your hosting.

What’s Included

Web Application Firewall — 280+ real-time rules, zero-day detection, pre-WordPress execution mode ✅ 9 Malware Scanners — Malware, file integrity, CVE, user accounts, content, public files, server state, binary, domain reputation ✅ Country Blocking — Block by country, login-only or full-site (free — competitors charge for this) ✅ Brute Force & Rate Limiting — Login limits, leaked password detection, bot throttling ✅ Two-Factor Authentication — QR setup, backup codes, role enforcement, WooCommerce support ✅ Audit Log & Live Traffic — Complete security event history with real-time monitoring ✅ Privacy-First — All scanning on your server. Files and database never sent externally.

How VMP Security Compares

Feature VMP Security (Free) Wordfence Free Wordfence Premium ($119/yr)

Real-time firewall rules ✅ 280+ ❌ 30-day delay ✅

Real-time malware signatures ✅ 40,000+ ❌ 30-day delay ✅

Malware scanners 9 specialized 1 general 1 general

Country blocking ✅ ❌ ✅

Audit log ✅ ❌ ✅

IP blocklist ✅ ❌ ✅

Two-factor authentication ✅ ✅ ✅

See It In Action

🔥 Web Application Firewall (WAF)

Your first line of defense. Every request is inspected before it reaches WordPress.

What It Stops:

  • SQL injection, cross-site scripting, code injection, file inclusion attacks, and more — all major attack types covered
  • 280+ built-in security rules — updated in real-time, not delayed by 30 days
  • Zero-day protection — pattern-based detection catches new, unknown threats
  • Custom rules — add your own blocking patterns
  • Learning mode — fine-tune rules based on your real traffic
  • Attack logging — full audit trail of every blocked request

Extended Protection (WAF Optimizer)

Run the firewall before WordPress loads — malicious requests are blocked before any vulnerable plugin or theme code can execute. One-click setup with automatic server detection (Apache/LiteSpeed) and built-in backup.

🔍 9 Specialized Malware Scanners

Not one scanner — nine. Each specialized for a different threat type.

  1. Malware Scanner — 40,000+ signatures detect backdoors, trojans, and malicious code
  2. File Integrity Monitor — Compares your files against official WordPress checksums
  3. Vulnerability Scanner — Checks plugins and themes against known CVEs
  4. User Security Scanner — Finds suspicious admin accounts and weak credentials
  5. Content Safety Scanner — Detects malicious content injected into posts and comments
  6. Public Files Scanner — Finds exposed configuration files (wp-config backups, .env, debug logs)
  7. Server State Scanner — Audits PHP settings, file permissions, and server configuration
  8. Binary Scanner — Detects malware embedded in images and executables
  9. Domain Reputation Scanner — Checks URLs against Google Safe Browsing and threat databases

Obfuscation analysis catches encoded malware that basic scanners miss. Behavior analysis flags suspicious file operations beyond known signatures. Legitimacy assessment reduces false positives. Choose from quick, standard, high sensitivity, or custom scan modes.

🌍 Country Blocking & IP Management

Block entire countries or fine-tune access with advanced pattern rules.

  • Geo-Blocking — Block any country, login-only or full site access
  • IP Blocking — Block individual IPs or IP ranges, temporary or permanent
  • Custom Patterns — Block by hostname, user agent, referrer, or IP range with wildcard and regex support
  • Attack Analytics — See which countries attack you most with visual reports
  • Allowlist — Whitelist trusted IPs and services to bypass all blocks
  • GeoIP Integration — Automatic IP-to-country lookup with auto-updating database

🛡️ Brute Force Protection & Rate Limiting

Stop password guessing and resource exhaustion attacks.

  • Smart Login Limiting — Lock out IPs after too many failed login attempts
  • Leaked Password Detection — Check passwords against known breach databases
  • Strong Password Enforcement — Require secure passwords for all user roles
  • Username Blacklist — Block common attack usernames instantly
  • Rate Limiting — Cap requests per IP to stop scrapers and vulnerability scanners
  • Human vs Bot Detection — Smart traffic classification with 404 monitoring

🔐 Two-Factor Authentication (2FA)

Even if someone steals your password, they can’t get in.

  • QR Code Setup — Works with Google Authenticator, Authy, 1Password, and more
  • Backup Codes — Never get locked out of your own site
  • Role Enforcement — Require 2FA for admins or specific user roles
  • Frontend Management — Users manage their own 2FA via shortcode
  • WooCommerce & XML-RPC — Covers your store and API endpoints

📊 Dashboard, Monitoring & Tools

Set it up in 5 minutes. Go deep when you want to.

  • Security Status — Green, yellow, or red — know your protection level at a glance
  • Live Traffic View — Watch visitors and attacks in real-time with human vs. bot classification
  • Complete Audit Log — Every security event tracked with timestamps and IP intelligence
  • Scheduled Scans — Daily, weekly, or custom scan schedules
  • One-Click Actions — Block IPs, ignore false positives, repair infected files
  • Diagnostics — 15+ system health checks for troubleshooting
  • Settings Export/Import — Backup and migrate security configuration between sites
  • Multi-Site Sync — Manage security across multiple WordPress sites from one place

🔒 Privacy-First Security

All scanning happens on YOUR server. Period.

What We DON’T Do:

❌ We don’t send your file content or database data to external servers ❌ We don’t track your users ❌ We don’t collect analytics about your site ❌ We don’t send data without your knowledge

External Services (Optional):

We use external services only when necessary for specific security features. You can see exactly what’s sent:

VMP Security Servers * License activation and validation (free/premium) * WAF rules synchronization and updates * Malware signature database updates * Two-Factor Authentication (2FA) system management * Settings export/import cloud storage (optional) * Privacy: Your site data remains on your server — only configuration and security rules are synced

Google Services (safebrowsing.googleapis.com, www.google.com/recaptcha) * URL threat detection and reCAPTCHA spam protection * Privacy: https://policies.google.com/privacy

WordPress.org APIs (api.wordpress.org, downloads.wordpress.org, core.svn.wordpress.org) * Download original files for integrity checking during malware scans * Privacy: https://wordpress.org/about/privacy/

GitHub (raw.githubusercontent.com) * Download WordPress core files for file comparison

IP Lookup Services (api.ipify.org, ifconfig.me, icanhazip.com, ip-api.com, ipwhois.app, download.ip2location.com) * Server IP detection, geolocation, and country blocking features

Threat Intelligence (api.urlvoid.com, www.virustotal.com, checkurl.phishtank.com) * URL reputation checking and threat validation

Vulnerability Databases (services.nvd.nist.gov, wpscan.com, cvedetails.com, cve.mitre.org) * Check for known security vulnerabilities during scans

All malware scanning happens on YOUR server. We do not upload your files or database content to external services.

Gratispå betalda paket
Testat upp till
WordPress 6.9.4
Detta tillägg är tillgängligt för nedladdning för din .