• Features
  • Pricing
  • Help
  • My Account
  • Buy Now
WP Ghost
  • Features
  • Pricing
  • Help
  • My Account
  • Buy Now

Category: Security

Master WordPress hack prevention and Attack Surface Reduction (ASR). Explore actionable guides on Paths Security, stopping automated bots at the rewrite layer, closing brute-force entry points, and implementing modern authentication like passkeys. Learn how to secure and change default WordPress paths to break automated attack chains before they reach your site.

/Security /
A WordPress security check report on a laptop screen with findings ranked by real risk

Your WordPress Security Check Is Ranking Findings It Knows Nothing About

Most WordPress security checks score every finding the same on every site. See how reading your server config first changes the order, and what gets fixed.

Read More →
WordPress login captcha: the four captcha types, the five forms that need one, and the requests that never load a form, shown side by side (WP Ghost)

How to Set Up a WordPress Login Captcha (and What It Actually Stops)

How to set up a WordPress login captcha on every form that needs one, which of the four types to pick, and the requests a captcha never gets to see.

Read More →
Two WordPress security plugins colliding at the same point in the request compared with two plugins acting at different points, one before PHP loads and one after

Do You Need Two WordPress Security Plugins? How to Audit What You Already Have

Most sites need two security plugins, not two of the same kind. How to audit your stack by layer, spot plugin conflicts, and decide which one to remove.

Read More →
Eight WordPress security plugins sorted into five defence layers, showing prevention as the least crowded layer while detection, patching, recovery and edge are full

8 Best WordPress Security Plugins in 2026, Compared by Security Layer

We compared 8 WordPress security plugins by defence layer using wordpress.org data read in August 2026. Which to run, and which combination actually works.

Read More →
WordPress magic link login: a single-use token emailed to the user, governed by three settings, token lifetime, single use, and rate limiting on the endpoint that issues it (WP Ghost)

How to Set Up WordPress Magic Link Login (and the Three Settings That Decide Whether It’s Safe)

How to set up WordPress magic link login, plus the three settings that decide whether it is safe: token lifetime, single use, and endpoint rate limiting.

Read More →
Modern 2FA for WordPress: a passkey signature is bound to the site's own domain so a phished credential has nothing to replay, while a magic link moves account security into the mailbox (WP Ghost)

WordPress Passwordless Login: Passkeys, Magic Links, and What Modern 2FA Actually Fixes

WordPress passwordless login explained: how passkeys, magic links and hardware keys close the stolen-credential path, and the attacks they do not touch. (154 chars)

Read More →
Block ClaudeBot on WordPress, a ClaudeBot request is refused at the robots.txt and rewrite layers while Claude,SearchBot stays allowed for Claude's search answers (WP Ghost)

How to Block ClaudeBot on WordPress (and the Two Other Anthropic Crawlers)

Block ClaudeBot on WordPress to opt out of Anthropic training: add it to robots.txt, enforce it at the rewrite layer, and keep Claude-SearchBot if you want.

Read More →
Block GPTBot on WordPress, a GPTBot request is refused at the robots.txt and rewrite layers while OAI-SearchBot stays allowed for ChatGPT search (WP Ghost)

How to Block GPTBot on WordPress (Without Losing ChatGPT Search Visibility)

Block GPTBot on WordPress to opt out of OpenAI training: add it to robots.txt, enforce at the rewrite layer, and decide OAI-SearchBot separately. 2026 guide.

Read More →
Stop brute force attacks on WordPress, POST requests to /wp-login.php and /xmlrpc.php return 404 at the rewrite layer, so the PHP auth form never loads (WP Ghost)

How to Stop Brute Force Attacks on WordPress (Without Just Counting Them)

Stop brute force attacks on WordPress: reconfigure the login endpoint and close XML-RPC and REST so probes return 404 before the auth form loads.

Read More →
Protect wp-config.php in WordPress — deny direct access so requests for the credentials file return 404 at the rewrite layer (WP Ghost)

How to Protect wp-config.php in WordPress

Protect wp-config.php in WordPress: move it above the web root, deny direct access, set 600 permissions, rotate keys, and return 404 to probes. 2026 guide.

Read More →
123
Older Entries →
WP Ghost

Stop WordPress hacks before they start

Path security, 8G firewall, brute force protection, and passkeys. 60-second setup.

Install Free → See Premium Plans
Last 30 days
100M+ threats blocked
Across 250,000+ protected sites.
Read the Impact Report →
Rated by real users
★ 4.5
WordPress.org
★ 4.8
G2
★ 4.8
Capterra
★ 4.8
AppSumo
Getting Started
  • What is WP Ghost?
  • Install WP Ghost (Free)
  • 3-Minute Safe Mode Setup
  • Best Practice Settings Guide
  • One-Click Security Presets
  • Website Security Check
Path Security
  • Hide wp-admin Path
  • Hide wp-login Path
  • Change wp-content Path
  • Change Plugins Path
  • Hide Author ID & Path
  • Change REST API Path
  • Change admin-ajax.php Path
Login & 2FA
  • Two-Factor Authentication (2FA)
  • Passkey 2FA (Face ID, Touch ID)
  • Magic Link Login
  • Temporary Logins
  • Brute Force Protection + reCAPTCHA
  • Login Page Designer
Firewall & Monitoring
  • 7G & 8G Firewall
  • Security Headers (HSTS, CSP)
  • Security Threats Log
  • User Events Log
  • Country Blocking (Geo)
  • Disable XML-RPC Access
Hardening
  • Hide Your WordPress Website
  • Hide from Theme Detectors
  • Hide Common WordPress Files
  • Prevent Hack Attacks on WordPress
  • Hacker Bot Attack Types
Compatibility
  • Plugin Compatibility List
  • Theme Compatibility List
  • WooCommerce Setup
  • Nginx Server Setup
  • Hosting Setup Guides
  • Emergency: Disable WP Ghost
Help & Resources
  • Full Knowledge Base
  • Frequently Asked Questions
  • Changelog
  • Developer Hooks Reference
  • Contact Support
Free vs Premium?

Lite Mode (Free) covers core path security. Safe Mode and Ghost Mode (Premium) add advanced features.

Compare Plans →

Product

  • What is WP Ghost?
  • Free vs Premium
  • Pricing
  • Changelog
  • Why WP Ghost
  • Knowledge Base

Features

  • Path Security
  • Firewall Security
  • Brute Force Protection
  • Two-Factor Authentication
  • User Events Log
  • Security Threats Log

Resources

  • Getting Started Guide
  • Plugin Compatibility
  • Theme Compatibility
  • Developer Hooks
  • Impact Report
  • Security Solutions

Company

  • Affiliate
  • Terms Of Use
  • Privacy Policy
  • Security Policy
  • GDPR Compliance
  • Contact
  • Facebook
  • YouTube
  • X
© Copyright, A HeroTheme