WP Ghost is available in two versions: a free version on WordPress.org with over 115 security features, and a Premium version with over 150 security features focused on security intelligence, automated response, and advanced site hardening. Both versions share the same core hack-prevention engine.

Paths Security

FeatureFreePremium
Change wp-admin pathYesYes
Change wp-login.php pathYesYes
Change lost password, register, activation, logout pathsYesYes
Change wp-content pathYesYes
Change wp-includes pathYesYes
Change uploads pathYesYes
Change author pathYesYes
Change comments pathYesYes
Change admin-ajax.php pathYesYes
Change REST API wp-json pathYesYes
Change plugin directory pathYesYes
Change theme directory pathYesYes
Hide plugin names with random namesYesYes
Hide theme names with random namesYesYes
Hide WordPress old plugins pathYesYes
Hide WordPress old themes pathYesYes
Hide WordPress common pathsYesYes
Custom theme style nameYesYes
Custom login/logout/register redirects by user roleYesYes
Frontend Test to verify paths load correctlyYesYes
Change paths in cache filesYesYes
Change paths in sitemapsYesYes
Change paths in robots.txtYesYes
Change paths in RSS feedsYesYes
Ghost Mode (maximum path security preset)Yes
Hide file extensions (PHP, CSS, JS, JSON, HTML, TXT, LOCK, media)Yes
Hide WordPress common files (wp-config.php, readme.html, license.txt, php.ini, debug.log)Yes
Manually customize each individual plugin nameYes
Manually customize each individual theme nameYes

Firewall

FeatureFreePremium
7G Firewall filterYesYes
8G Firewall filterYesYes
Script injection protectionYesYes
SQL injection protectionYesYes
Security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, X-XSS-Protection)YesYes
Remove unsafe headers (PHP version, server info, server signature)YesYes
Block Theme Detector crawlersYesYes
IP whitelistYesYes
IP blacklistYesYes
User agent blacklistYesYes
Referrer blacklistYesYes
Hostname blacklistYesYes
Whitelist pathsYesYes
Automate IP blocking (auto-block repeat offenders)Yes
Configure automation rules (attacks, time window, block duration)Yes
Block AI Crawler Bots at firewall level (30+ crawlers)Yes
Automatic robots.txt Disallow rules for AI crawlersYes
AI crawler list updated automatically with each releaseYes

Brute Force Protection

FeatureFreePremium
Protection on login formYesYes
Protection on lost password formYesYes
Protection on signup formYesYes
Protection on comments formYesYes
Protection on WooCommerce login, signup, lost passwordYesYes
Google reCAPTCHA v2, v3, EnterpriseYesYes
Math reCAPTCHAYesYes
Custom attempt limitsYesYes
Custom lockout durationYesYes
Custom warning messagesYesYes
Block wrong usernames immediatelyYesYes

Authentication (2FA, Passkeys, Magic Login)

FeatureFreePremium
Two-Factor Authentication by codeYesYes
Two-Factor Authentication by emailYesYes
Two-Factor Authentication by passkey (Face ID, Touch ID, Windows Hello)YesYes
User selects preferred 2FA method in profileYesYes
Trust current browser (skip 2FA on trusted devices)YesYes
Magic Link login (one-time passwordless email link)YesYes
Temporary Logins (time-limited access links)YesYes

Security Monitoring & Logs

FeatureFreePremium
Security Optimization Score (0-100) with dynamic gaugeYesYes
GEO Threats Map with top 5 threat countriesYesYes
Threats prevented chart (7-day view)YesYes
Lifetime attacks blocked counterYesYes
Weekly domain security monitoring emailYesYes
Security Check with numeric score and task listYesYes
Notification to activate firewall when unblocked threats detectedYesYes
Security Threats Log (last 20 entries)YesYes
User Events Log (last 20 entries)YesYes
Security Threats Log with full history, unlimited entriesYes
User Events Log with full history, unlimited entriesYes
Filter logs by threat typeYes
Filter logs by statusYes
Filter logs by countryYes
Filter logs by time rangeYes
Full-text search in logsYes
Log paginationYes
Export Security Threats Log to CSVYes
Export User Events Log to CSVYes
Click GEO map country to open filtered threats logYes
Extended log retention (configurable)Yes
Cloud storage for events log (30-day retention)Yes
Log user roles filterYes
Real-time email alerts for brute force and suspicious activityYes

Geo Security

FeatureFreePremium
GEO Threats Map on Overview dashboardYesYes
Top 5 threat countries with attack countsYesYes
Country Blocking (block entire countries)Yes
Path-based country blocking (block countries on specific paths)Yes

Login Page Designer

FeatureFreePremium
Custom logo with live previewYesYes
Custom logo link URLYesYes
Background image with blur and overlay controlsYesYes
Page background colorYesYes
Form background colorYesYes
Button colorYesYes
Text colorYesYes
Link colorYesYes
12 layout presetsYesYes
10 color scheme presetsYesYes
Balanced Split layout presetYes

Hiding & Footprint Removal

FeatureFreePremium
Remove WordPress version tagsYesYes
Remove Generator meta tagYesYes
Remove RSD headerYesYes
Remove WLW Manifest linkYesYes
Remove WordPress HTML commentsYesYes
Hide admin toolbar by user roleYesYes
Hide REST API URL linkYesYes
Hide rest_route parameterYesYes
Disable emoticons scriptYesYes
Text Mapping (change class names and IDs in source code)YesYes
URL Mapping (change URLs dynamically)YesYes
CDN MappingYesYes
Hide Source Map ReferencesYesYes
Hide User EnumerationYesYes

Disable Options

FeatureFreePremium
Disable XML-RPCYesYes
Disable REST API access for non-authenticated usersYesYes
Disable rest_route parameter accessYesYes
Disable embed scriptsYesYes
Disable database debugYesYes
Disable directory browsingYesYes
Disable right-click (for visitors and by user role)YesYes
Disable Inspect Element (for visitors and by user role)YesYes
Disable View Source (for visitors and by user role)YesYes
Disable Copy/Paste (for visitors and by user role)YesYes
Disable Drag/Drop (for visitors and by user role)YesYes

Database & Server Hardening

FeatureFreePremium
Security Check identifies permission, prefix, username, SALT issuesYesYes
Fix weak admin/administrator usernamesYesYes
Fix file and directory permissions (quick and complete)Yes
Change database table prefixYes
Regenerate WordPress SALT keysYes
Fix WordPress debugging modeYes
Fix script debugging modeYes
Disable plugin/theme editorYes

Setup & Compatibility

FeatureFreePremium
One-click security presets (3 levels)YesYes
Frontend Test and Login CheckYesYes
Backup and restore settingsYesYes
Pause plugin for 5 minutes for safe testingYesYes
Dark mode supportYesYes
Translations in 16 languagesYesYes
Compatible with Apache, Nginx, LiteSpeed, IISYesYes
Compatible with 20+ hosting providersYesYes
Compatible with WooCommerce, Elementor, Divi, WPML, and 50+ pluginsYesYes
Compatible with WP Rocket, LiteSpeed Cache, Cloudflare, and 15+ cache pluginsYesYes

Support

FeatureFreePremium
Knowledge base (wpghost.com/kb)YesYes
Community support (WordPress.org forums)YesYes
Free setup assistanceYesYes
Priority support with direct access to security expertsYes
Faster response timesYes

Frequently Asked Questions

Is the free version of WP Ghost enough to protect my site?

Yes, for most WordPress sites. The free version includes full path security, the 7G and 8G Firewall, brute force protection with reCAPTCHA, three types of two-factor authentication including passkeys, security headers, and basic security monitoring. This blocks the majority of automated bot attacks. Premium is recommended for sites that need automated IP blocking, country blocking, full security logs with filters and export, or priority support.

What features are only in WP Ghost Premium?

The main Premium-exclusive features are IP Block Automation, full Security Threats Log and User Events Log with filters, search, pagination, and CSV export, Country Blocking (entire site and path-based), AI Crawler Blocking at the firewall level, Ghost Mode, extended file and path hiding (file extensions, common files), database prefix change, SALT key regeneration, file permission fixes, cloud event storage, real-time email alerts, and priority support.

Can I upgrade from Free to Premium without losing my settings?

Yes. All settings from the free version are preserved when you upgrade. Premium installs as an extension that unlocks additional features while keeping your existing configuration intact.

Does WP Ghost Free include a firewall?

Yes. Both the 7G and 8G Firewall filters are fully included in the free version with no limitations. The firewall blocks SQL injection, XSS, script injection, file inclusion, directory traversal, and automated vulnerability scans at the server edge before they reach WordPress.

Does WP Ghost Free include two-factor authentication?

Yes. The free version includes 2FA by code, 2FA by email, and 2FA by passkey (Face ID, Touch ID, Windows Hello). All three methods are fully functional with no limitations.

What is the difference between Lite Mode and Ghost Mode?

Lite Mode is available in the free version and changes the most important WordPress paths to custom URLs. Ghost Mode is a Premium feature that applies the maximum security configuration, changing all paths, hiding all file extensions, and enabling all available hiding options in a single click.

Does WP Ghost slow down my website?

No. WP Ghost is engineered for zero-bloat performance. The firewall operates at the server edge using lightweight rules, and path security works through rewrite rules and filters rather than heavy database scans.

How much does WP Ghost Premium cost?

Visit https://wpghost.com/pricing for current pricing. Premium is licensed per site per year with volume discounts for agencies managing multiple sites.