Both versions share the same core hack-prevention engine.
Premium adds automated response, advanced hardening, and full security intelligence.
Or download the free version on WordPress.org
WP Ghost Free gives you Lite Mode - the core path security that stops the vast majority of automated bot attacks. It's a real protection layer, not a trial. WP Ghost Premium unlocks the advanced protection features most sites eventually need: full security logs, automated IP blocking, country blocking, AI crawler blocking, and two additional security modes - Safe Mode (maximum compatibility) and Ghost Mode (maximum security).
| FEATURE | FREE | PREMIUM |
|---|---|---|
| 🔒 PATHS SECURITY | ||
| Change wp-admin, wp-login, and all authentication paths | ✓ | ✓ |
| Change wp-content, wp-includes, uploads, plugins, themes paths | ✓ | ✓ |
| Hide plugin and theme names with random names | ✓ | ✓ |
| Ghost Mode (maximum security, one click) PREMIUM | — | ✓ |
| Hide file extensions (PHP, CSS, JS, JSON, media) PREMIUM | — | ✓ |
| Customize each plugin and theme name individually PREMIUM | — | ✓ |
| 🔥 FIREWALL | ||
| 7G & 8G Firewall (SQL injection, XSS, script injection) | ✓ | ✓ |
| Security headers (HSTS, CSP, X-Frame-Options) | ✓ | ✓ |
| IP, user agent, referrer, and hostname blacklist | ✓ | ✓ |
| Automate IP blocking (auto-block repeat offenders) PREMIUM | — | ✓ |
| Block AI Crawler Bots (30+ crawlers, auto-updated)PREMIUM | — | ✓ |
| 🛡 Brute Force Protection | ||
| Login, signup, comments, WooCommerce protection | ✓ | ✓ |
| Google reCAPTCHA v2, v3, Enterprise & Math reCAPTCHA | ✓ | ✓ |
| Custom attempt limits and lockout duration | ✓ | ✓ |
| 🔑 Authentication | ||
| 2FA by code, email, and passkey (Face ID, Touch ID, Windows Hello) | ✓ | ✓ |
| Magic Link login (passwordless email link) | ✓ | ✓ |
| Temporary Logins (time-limited access links) | ✓ | ✓ |
| 👁 Security Monitoring | ||
| Security Optimization Score (0-100) | ✓ | ✓ |
| GEO Threats Map with top 5 countries | ✓ | ✓ |
| Threats prevented chart and lifetime counter | ✓ | ✓ |
| Security Threats Log (last 20 entries) | ✓ | ✓ |
| User Events Log (last 20 entries) | ✓ | ✓ |
| Full logs with filters, search, paginationPREMIUM | — | ✓ |
| Export logs to CSVPREMIUM | — | ✓ |
| Real-time email alertsPREMIUM | — | ✓ |
| Cloud event storage (30-day retention)PREMIUM | — | ✓ |
| 🌍 Geo Security | ||
| GEO Threats Map (view attack origins) | ✓ | ✓ |
| Country Blocking (block entire countries)PREMIUM | — | ✓ |
| Path-based country blockingPREMIUM | — | ✓ |
| 🎨 Login Page Designer | ||
| Custom logo, colors, background, 12 layouts, 10 color presets | ✓ | ✓ |
| Balanced Split layout presetPREMIUM | — | ✓ |
| ⚙️ Hiding & Hardening | ||
| Remove version tags, generator meta, HTML comments | ✓ | ✓ |
| Text Mapping, URL Mapping, CDN Mapping | ✓ | ✓ |
| Disable XML-RPC, REST API, directory browsing | ✓ | ✓ |
| Disable right-click, inspect element, view source | ✓ | ✓ |
| Fix file permissions, database prefix, SALT keysPREMIUM | — | ✓ |
| ⚡ Setup & Support | ||
| One-click security presets | ✓ | ✓ |
| Compatible with WooCommerce, Elementor, 50+ plugins | ✓ | ✓ |
| Compatible with 20+ hosting providers | ✓ | ✓ |
| 16 languages | ✓ | ✓ |
| Priority supportPREMIUM | — | ✓ |
Looking for the full detailed breakdown? See the complete feature list →
Upgrade to Premium and get automated protection, full logs, country blocking, and priority support.
WP Ghost is a WordPress hack prevention plugin that stops attacks before they reach your site. It works by reducing the attack surface, blocking malicious bots, and hardening login security, so threats are eliminated before they can cause damage.
For most WordPress sites, yes. WP Ghost Free has 115+ features including Path Security, the 7G and 8G Firewall, brute force protection with reCAPTCHA, three types of 2FA including passkeys, Magic Link login, and hardening features. This blocks the majority of automated bot attacks. Premium is recommended when you want full security logs, automated IP blocking, country blocking, AI crawler blocking, or the advanced Safe Mode and Ghost Mode security levels.
Premium-exclusive features include: automated IP blocking, country blocking, AI crawler blocking at the firewall level, the full Events Log and Threats Log with CSV export, real-time email alerts, database hardening (prefix change, SALT regeneration, file permission fix), 30-day cloud event storage, priority support, and two additional security modes: Safe Mode (maximum compatibility) and Ghost Mode (maximum security).
WP Ghost Free includes Lite Mode, which changes the most commonly targeted WordPress paths with zero compatibility risk. WP Ghost Premium unlocks Safe Mode (the default — maximum plugin/theme compatibility plus wp-admin and admin-ajax.php protection) and Ghost Mode (maximum security — full file extension hiding and the most aggressive fingerprint removal). Full comparison.