Nexura Security
Enterprise-grade WordPress security plugin featuring malware scanning, login protection, security hardening, and vulnerability detection.
#Nexura Security
The most complete free WordPress security plugin. Malware scanner, firewall, 2FA, brute-force protection, file integrity monitoring, and more.
Nexura Security is a complete, all-in-one WordPress security plugin that protects your website from hackers, malware, and brute-force attacks — completely free.
Whether you run a personal blog, an online store, or a business website, Nexura Security gives you advanced protection designed for low performance overhead.
🔗 Download Free on WordPress.org | 🌐 nexurasecurity.com | 📋 Changelog
#⚡ Why Choose Nexura Security?
Looking for a lightweight, faster alternative to Wordfence, Sucuri, or MalCare? Tired of heavy security plugins? Nexura is designed for low performance overhead and designed to minimize database growth.
- Designed for low database overhead — Uses smart micro-batching so scans run quietly in the background without slowing down your server.
- No Performance Hit — Designed to minimize performance impact during or after a security scan.
- Easy to Use — One-click setup. No technical knowledge required.
- 100% Free Core — All essential security features are included at no cost.
#🛡️ Free Features (Included with This Plugin)
- 🔍 Deep Malware Scanner: Automatically scans your entire WordPress installation — themes, plugins, uploads, and core files — for hidden backdoors, obfuscated PHP code, suspicious JavaScript, and known malware patterns.
- 📂 File Integrity Monitor: Compares your WordPress core files against clean, official versions to detect any unauthorized changes, and checks the root directory for suspicious drops.
- 🔐 Advanced Login Protection: Includes Two-Factor Authentication (2FA) with TOTP support and passwordless magic link logins.
- 🚫 Brute-Force & Bot Protection: Automatically blocks IP addresses after failed login attempts, checks for Pwned Passwords, and stops spam bots with Cloudflare Turnstile or Google reCAPTCHA.
- 🌍 Cloud-Based Threat Intelligence: Syncs with the Nexura Threat Intel Cloud to receive up-to-date malicious IP blocklists and attack signatures.
- 🛠️ Security Hardening (One-Click): Disable the built-in file editor, block PHP execution in the uploads folder, disable directory listing, and block XML-RPC.
- 🚑 Extended WAF & Auto-Heal: Advanced
.htaccessWAF, Core Auto-Restore, and Fatal Error Auto-Heal features keep your site online and resilient against crashes or core file deletions. - 🗄️ Database & Upload Scanning: Scans for hidden administrator accounts and automatically scans uploads for malware before they reach the server.
- 🔍 Google Safe Browsing Check: Verifies whether your website has been flagged for malware or phishing.
#🌟 Pro Features (Upgrade to Unlock)
Want to go further? Nexura Security Pro adds powerful automation and advanced protection:
- Web Application Firewall (WAF) — Blocks SQLi/XSS/Bot attacks before WordPress even boots.
- Automated Malware Cleanup & Core Auto-Restore — Automatically strips malware injections and replaces modified core files with clean copies from WordPress.org.
- Custom Login URL & File Quarantine — Hide your login page behind a secret URL and securely quarantine suspicious files.
- HTTP Security Headers & REST API Security
- WooCommerce Security — Anti-card-testing protection and account takeover prevention.
- Vulnerability Audit & Database Optimizer — Detect outdated plugins/themes and optimize database tables.
- 📡 Active Monitoring & Visitor Stats — Real-time visitor tracking dashboard and beautiful glassmorphism shortcodes for visitor stats.
- Scheduled Automatic Scans & Advanced Audit Logs
Upgrade to Nexura Security Pro →
#🚀 Installation
#✅ Automatic (Recommended)
- Go to Plugins → Add New in your WordPress dashboard.
- Search for "Nexura Security".
- Click Install Now, then click Activate.
- Navigate to the Nexura Security menu in your sidebar to run your first security scan.
👉 Install directly from WordPress.org →
#📦 Manual Installation
- Download the plugin zip file from WordPress.org.
- Upload it via Plugins → Add New → Upload Plugin.
- Activate the plugin.
#🔗 Third-Party Services & Privacy
To provide comprehensive security, Nexura Security connects to several trusted third-party services (e.g., Cloudflare, HaveIBeenPwned, VirusTotal, WordPress.org API, the Nexura GeoIP Service, and the Nexura Threat Intel Cloud). No connections are made automatically — each feature must be enabled by you in the plugin settings.
We believe in complete transparency about how your data is handled:
- Nexura Security does NOT collect any personal data from your website visitors.
- All scan results, logs, and settings are stored locally in your own WordPress database.
- We are committed to respecting user privacy and designing our features with data protection in mind.
For full details, please review our Privacy Policy and Terms & Conditions.
Developed by the Nexura Security Team
#License
Nexura Security is released under the GPL v2 or later license. This software is provided "as is", without warranty of any kind.