A security plugin is a useful addition to a WordPress site and a poor substitute for the things that actually keep it safe. It can limit login attempts, add two-factor authentication, watch files for changes and log what happened. It cannot make an outdated plugin safe, it cannot undo a directory left writable by everyone, and it cannot recover a site with no backup.
That distinction is the whole point of this page. If you are looking for the ordered list of what removes the most risk, securing WordPress against vulnerabilities is that list. This one is narrower: which plugin features are worth having, how to configure them so they help, and which ones are theatre.
Install one, not three
The most common mistake is running several security plugins at once, on the theory that more protection is better. It is not. They hook the same points in WordPress, fight over the login form, write contradictory logs, and produce lockouts nobody can explain. Two firewalls filtering the same request is not twice the filtering.
Choose one that is actively maintained, install it alone, and configure it properly. If you already have several, keep the one you understand best and remove the others, deactivate and delete, not just deactivate.
The features that earn their place
Login attempt limiting. The highest-value feature. Automated password guessing runs against every WordPress site continuously; blocking an address after a handful of failures makes it too slow to be worth the attacker's time. Set the threshold somewhere around five attempts, with a lockout measured in tens of minutes.
Two-factor authentication. The single change that makes a stolen password useless. Enable it for every account that can install plugins or edit files. Editors who only write posts can be left alone if that is what gets it adopted.
File change detection. Compares your core files against the official versions and tells you when something changed unexpectedly. This is one of the few ways to notice a compromise you were not looking for. It generates noise after every legitimate update, which is worth tolerating.
Activity logging. Who logged in, what changed, when. Useless on a site with one user and genuinely valuable on a site with several, particularly after something goes wrong and you need to know what happened rather than guess.
Disabling the file editor. Many security plugins offer a toggle for this. It removes the fastest route from a stolen administrator password to arbitrary code on your server. You can also do it in wp-config.php without a plugin:
define( 'DISALLOW_FILE_EDIT', true );
The features that are mostly theatre
Hiding the login URL. Moving wp-login.php somewhere else stops naive scanners and nothing more. It is not harmful, and it is not a defence. Do not let it substitute for attempt limiting or two-factor.
Removing the WordPress version number. The reasoning is that attackers fingerprint your version and target it. In practice automated attacks try the exploit against everything and see what works. They do not check first. Harmless, pointless.
Malware scanners that only match known signatures. They find common injected code and miss anything tailored. Useful as one signal, dangerous as reassurance. A clean scan is not evidence a site is clean.
Country blocking. Occasionally justified, usually a blunt instrument that blocks customers and travelling staff while attackers move to another address. Reach for it when you have a specific problem, not as a default.
Configure it, then read what it produces
An installed security plugin with default settings and an inbox filter deleting its emails provides very little. Two decisions make the difference.
Turn on the features you will act on, and turn off the ones that will only generate noise. A firewall log nobody reads is not security; it is storage.
Then set the alert threshold so alerts stay meaningful. A plugin emailing about every blocked login attempt will send hundreds of messages a week, you will filter them, and the one message that mattered will be filtered with them. Alert on the unusual: a file changed outside an update, a new administrator account, a successful login from somewhere unexpected.
Web application firewalls
Some security plugins include a firewall that inspects requests before WordPress handles them, and blocks patterns matching known attacks. It can genuinely help, particularly in the window between a vulnerability being disclosed and you applying the patch.
Two things worth knowing. A plugin-based firewall runs inside PHP, so the request has already reached your server and consumed resources by the time it is inspected; it protects the application, not the server load. And they produce false positives: a rule blocking a legitimate form submission or a legitimate administrator action is common enough that you should know where the log lives before you need it.
What no plugin will do for you
It will not patch an outdated plugin. Outdated plugins are the leading cause of compromised WordPress sites, and no amount of firewalling substitutes for applying the fix.
It will not fix permissions someone set to 777. Files at 644, directories at 755, wp-config.php tighter still.
It will not protect a shared or reused password. A password that exists on another service that gets breached is a password an attacker already has.
It will not give you a backup. Every layer above tries to prevent a compromise; a backup is what you have left when one of them failed. Managing WordPress backups walks through keeping a copy off the server and testing the restore.
A workable setup
- One maintained security plugin, installed alone.
- Login attempts limited, with a real lockout period.
- Two-factor on every administrator account.
- File change detection on, alerts pointed at an address you read.
- File editor disabled.
- Alerts tuned so that receiving one means something.
- Automatic updates on, because that is what the plugin cannot do for you.
- Off-server backups with a restore you have actually tested.
Items seven and eight are not part of the plugin, and they matter more than everything above them.
The measure that makes a stolen password insufficient is worth setting up on its own. There is more on it, including the interface that bypasses it in How to Set Up Two-Factor Authentication on WordPress.