--- site: "wpghost.com" title: "WP Ghost" description: "WP Ghost stops WordPress hacks before they start. Hide paths, block bots with 7G/8G Firewall, add 2FA & brute force protection. Trusted by 250,000+ sites." canonical_url: "https://wpghost.com" generator: Crawlbrain generated_at: 2026-09-04T08:07:23+00:00 language: en-US pages_total: 12 pages_included: 12 schema_version: llms-full/1.0 page_boundary_marker: "# Page:" --- # WP Ghost > WP Ghost stops WordPress hacks before they start. Hide paths, block bots with 7G/8G Firewall, add 2FA & brute force protection. Trusted by 250,000+ sites. This file contains the full content of wpghost.com as of the sync timestamp above. Each page is delimited by a `# Page:` header and is followed by a metadata block (URL, section, last updated, language, optional description). Site-wide chrome (navigation, footers, repeated CTAs) has been stripped to improve signal density. For a curated index of entry-point pages, see the companion `llms.txt`. ## Sections in this file - Knowledge Base › Overview - Knowledge Base › How-To - Knowledge Base - Pricing - Pages - Home - Knowledge Base › Errors - Knowledge Base › Compatibility --- # Page: Overview - Page 2 of 2 URL: https://wpghost.com/kb/category/overview/ Section: Knowledge Base › Overview Last-Updated: 2026-09-04 Language: en-US Description: Learn the six attack types bots use against WordPress: brute force, SQL injection, file inclusion, XSS, and endpoint exploits. See how WP Ghost blocks each one. ### Hacker Bot Attack Types Against WordPress Sites Learn the six attack types bots use against WordPress: brute force, SQL injection, file inclusion, XSS, and endpoint exploits. See how WP Ghost blocks each one. [Read More →](https://wpghost.com/kb/hacker-bots-attack-types/) ### Install WP Ghost Free Plugin for WordPress Step-by-step guide to installing, activating, and configuring WP Ghost free from the WordPress directory. Set up Lite Mode path security in minutes. Free plugin. [Read More →](https://wpghost.com/kb/install-wp-ghost-plugin/) ### Install WP Ghost Premium Plugin for WordPress Download, install, and activate WP Ghost Premium with your license token. Set up Ghost Mode for maximum WordPress path security. Step-by-step Premium install guide. [Read More →](https://wpghost.com/kb/install-wp-ghost-premium-plugin/) ### WP Ghost Compatible Plugins List WP Ghost works with 1,000+ WordPress plugins including WP Rocket, Elementor, WooCommerce, Yoast SEO, Wordfence, and all major cache, security, and SEO plugins. [Read More →](https://wpghost.com/kb/wp-ghost-compatibility-plugins-list/) ### WP Ghost – Why You Must Have It! WP Ghost is an easy-to-use product designed to prevent hack attempts and provide the best protection against hackers. [Read More →](https://wpghost.com/kb/wp-ghost-why-you-must-have-it/)[← Newer Entries](https://wpghost.com/kb/category/overview/) --- # Page: How To WordPress Security Guides WP Ghost Tutorials URL: https://wpghost.com/kb/category/how-to/ Section: Knowledge Base › How-To Last-Updated: 2026-09-04 Language: en-US Description: Step-by-step WordPress security tutorials: hide wp-admin, block bots, protect plugins, configure SSL, change paths, fix vulnerabilities. Practical WP Ghost guides. ### WP Ghost 9.1: The Release Where the Plugin Started Diagnosing Itself Bots do not guess your login page. They request /wp-login.php. They do not hunt for your plugins either, they read /wp-content/plugins/. Changing those paths is the whole idea behind this plugin, and it has worked well for years. What has not been easy is knowing whether it is still working after you switch hosts, add […] [Read More →](https://wpghost.com/kb/wp-ghost-9-1/) ### WP Ghost Paths Not Working? Ghost Doctor Finds the Cause and Repairs It Site broken after hiding WordPress paths? Ghost Doctor in WP Ghost 9.0.13 tests your live site, repairs what a plugin can, reverts what did not help. [Read More →](https://wpghost.com/kb/wp-ghost-paths-not-working-ghost-doctor/) ### WP Ghost 9.0: Biggest Security Update of 2026 This update introduces a redesigned security dashboard with a real-time Security Optimization Score, a customizable login page designer, AI crawler blocking (copyright protection from AI Crawlers), interactive threat geography mapping, and CSV export for all security logs. [Read More →](https://wpghost.com/kb/wp-ghost-9-0-biggest-security-update-of-2026/) ### WP Ghost – Version 8.3.07 We are pleased to announce the release of WP Ghost 8.3.07. This update focuses on the “Senior Developer Experience,” refining the precision of our monitoring tools and ensuring seamless compatibility with the latest enterprise standards in the WP ecosystem. As part of our commitment to proactive site hardening, this version introduces critical fixes for real-time […] [Read More →](https://wpghost.com/kb/wp-ghost-8-3-07/) ### WP Ghost With WooCommerce Ecommerce Security Secure your WooCommerce store with WP Ghost. Brute force protection on login, anti-spam for reviews, 8G firewall, security headers, and country blocking. Guide. [Read More →](https://wpghost.com/kb/wp-ghost-with-woocommerce-ecommerce-security/) ### Passkey 2FA for WordPress – Face ID, Touch ID Passkeys are the next step in modern authentication. Instead of receiving a code, you simply confirm your login using your device – with Face ID, Touch ID, Windows Hello, fingerprint scan, or a secure PIN. [Read More →](https://wpghost.com/kb/introducing-passkey-2fa-in-wp-ghost/) ### WP Ghost Refund Policy WP Ghost offers a 30-day refund on initial purchases and 24-hour refund on annual renewals. How to request a refund and what happens to your account afterward. [Read More →](https://wpghost.com/kb/payment-refund/) ### Update Payment Details for WP Ghost Subscription Update your credit card or payment method for WP Ghost subscription via the Dashboard and Paddle. Prevent subscription lapses. Step-by-step payment update guide. [Read More →](https://wpghost.com/kb/update-payment-details-for-wp-ghost-subscription/) ### WP Ghost GDPR Compliance WP Ghost is GDPR compliant. Minimal data collection, no visitor tracking, payments via Paddle. Events Log data auto-deleted after 30 days. Full privacy details. [Read More →](https://wpghost.com/kb/wp-ghost-gdpr-compliance/) ### WP Ghost – Advanced Pack Advanced Pack takes the basic security provided by the free version and enhances it with cutting-edge features like Two-Factor Authentication (2FA), Temporary Login, and more. [Read More →](https://wpghost.com/kb/wp-ghost-advanced-pack/)[Older Entries →](https://wpghost.com/kb/category/how-to/page/2/) --- # Page: WP Ghost 9.1: Ghost Doctor, Faster Files, Fewer Alarms URL: https://wpghost.com/kb/wp-ghost-9-1/ Section: Knowledge Base Last-Updated: 2026-09-04 Language: en-US Description: WP Ghost 9.1 adds Ghost Doctor, a one-click diagnostic and repair layer with Undo, plus a rewrite of how the plugin serves files. What changed and why. Bots do not guess your login page. They request `/wp-login.php`. They do not hunt for your plugins either, they read `/wp-content/plugins/`. Changing those paths is the whole idea behind this plugin, and it has worked well for years. What has not been easy is knowing whether it is still working after you switch hosts, add a CDN, or install a caching plugin that rewrites the same rules. **TL;DR** WP Ghost 9.1 adds Ghost Doctor, a diagnostic layer that inspects your server rules, cache and theme, explains what is broken in plain language, and repairs most of it in one click with an Undo. It also rewrites how the plugin serves files, so a stylesheet is processed once instead of once per visitor. Path security stays the same. Keeping it working got easier. WP Ghost is the WordPress hack-prevention plugin for site owners who prioritize attack-surface reduction over post-incident cleanup. Version 9.1 is the release where it started checking its own work. ### What’s actually new in 9.1 The 9.0 release was a feature release. This one is mostly a reliability release, which is less exciting to announce and more useful to run. | Area | What changed | Where it lives | |---|---|---| | Diagnostics | Ghost Doctor: full site diagnosis, plain-language findings, one-click repair, Undo, and a fallback to protection that needs no server rules | WP Ghost > Security Check | | Prioritisation | Security Check now opens with a scored list, highest-impact first | WP Ghost > Security Check | | Vulnerability scan | Looks up every installed plugin and theme, active or not, against the open WP Vulnerability database, with severity scores and version-range matching | WP Ghost > Security Check | | Frontend check | Confirms theme stylesheets and scripts genuinely load, catching a broken layout behind a 200 OK | WP Ghost > Security Check | | Authentication | Force 2FA for chosen roles, with a guided setup screen after login | WP Ghost > Two-Factor | | Performance | Served files are built once and reused; conditional requests answered without opening the file; large media streamed rather than buffered | Automatic | | False alarms | Files you deliberately have WP Ghost serve are no longer reported as broken; REST API path changes apply on save | Automatic | | Compatibility | Work across LiteSpeed/QUIC.cloud, WooCommerce checkout and payment callbacks, WPML, Polylang, Elementor, and the major cache and security plugins | Automatic | The vulnerability scan is the one worth pausing on. According to Patchstack’s _State of WordPress Security in 2026_, 91% of the 11,334 vulnerabilities disclosed across the ecosystem in 2025 were in plugins and 9% in themes, with only six in WordPress core, all low risk. A scan that tells you which of your installed plugins has a published advisory is aimed directly at where the risk actually sits. ### Ghost Doctor, and why path security needed a diagnostic layer Changing 30+ default WordPress paths means writing rewrite rules into `.htaccess` or the nginx config, filtering output, and staying consistent with whatever else on the site rewrites URLs. Three things routinely break that chain: a host that ignores `.htaccess`, a caching plugin that serves a stale rewrite map, and a theme that hard-codes asset paths. Until now the plugin told you something was wrong and left you to work out which. Ghost Doctor runs a full diagnosis, writes each finding against your actual server, theme and configuration rather than a generic help page, says what an attacker would do with the gap, and fixes most of it in one click. If a repair does not help, Undo restores the previous settings exactly. If the server refuses to serve rewrite rules at all, it can move you to a protection mode that does not need them. The part I argued hardest for internally was Undo. A one-click repair without a one-click reversal is a worse product than no repair at all, because the failure mode is a locked-out owner at midnight rather than a confused one. The plugin already had a [Safe URL rollback](https://wpghost.com/kb/rollback-settings/) and an FTP emergency disable, and Ghost Doctor now sits on top of both rather than beside them. ### The vulnerability scan, and what it actually looks up Security Check now looks up every plugin and theme installed on the site, active or not, against the WP Vulnerability database. Each finding comes back with a severity score, so the list is ordered by what to deal with first rather than alphabetically. The reason this belongs in a hardening plugin rather than only in a scanner is the shape of the problem. According to Patchstack’s _State of WordPress Security in 2026_, only four of the ten most-exploited plugins of 2025 had been disclosed in 2025. The rest were disclosed in 2023 or 2024. The flaw was published, patched and publicly documented, and the site was still running the vulnerable version a year or more later. That is not a detection problem. It is an inventory problem. Two details decide whether a scan like this is useful or just noisy. ### Faster where it was slowest When WP Ghost serves a file itself, it used to rebuild that file on every request. Now it builds it once, keeps it, and rebuilds only when the file or your settings change. There is no cache for you to clear. When a browser or CDN asks whether its copy is still current, the plugin answers without opening the file. The figures we measured, with the methodology stated as we measured it: - 30% faster response when a browser re-checks a file - 0 bytes re-sent on a conditional request instead of the whole file - A stylesheet is processed once per change, not once per visitor Measured on our own LiteSpeed demo site with a 108 KB stylesheet, median of 25 requests. That is a single site on a single stack, and your numbers depend on your host, your theme and your traffic. I would treat it as a direction, not a promise. Two related changes matter more on constrained hosting than the percentage does. Large images and fonts are streamed to the visitor rather than loaded into memory first, so a big upload no longer costs its full size in server memory on every request. And files are compressed only the way the requesting browser actually asked, which resolves a class of “my CSS looks broken behind the CDN” reports. ### What carried over from 9.0 If you are upgrading from 8.x, these arrived in 9.0 and are worth knowing about. The Overview dashboard carries an interactive map showing the five countries sending the most blocked traffic; clicking one opens the threat log filtered to it. Both the threat log and the user activity log filter, sort and export to CSV. AI crawler blocking rejects GPTBot, ClaudeBot, PerplexityBot, Bytespider and 30+ other identified AI and scraper bots at the firewall level and writes the matching `robots.txt` rules, without touching Google, Bing or Yahoo indexing. The login page designer restyles the login screen served at your custom path. Full detail is in the [WP Ghost 9.0 release notes](https://wpghost.com/kb/wp-ghost-9-0-biggest-security-update-of-2026/) and the [AI crawler blocking guide](https://wpghost.com/kb/block-ai-crawlers/). | Capability | Free | Premium | |---|---|---| | Path security for 30+ default paths | Yes | Yes | | 7G and 8G firewall rules | Yes | Yes | | Brute-force protection and captcha | Yes | Yes | | 2FA by code, email and passkey; magic link; temporary logins | Yes | Yes | | AI crawler blocking, security headers, text and URL mapping | Yes | Yes | | Login page designer | Most options | All layout presets | | Security Threats Log and User Events Log | No | Yes | | Country threat map and CSV export | No | Yes | | Country blocking, file permissions, DB prefix, SALT regeneration | No | Yes | | Ghost Doctor | No | Yes | The free version on wordpress.org carries 65+ hardening options, including the firewall and passkey 2FA. Full breakdown on the [free vs premium page](https://wpghost.com/kb/wp-ghost-free-vs-premium/). ### When WP Ghost is the right choice **You changed hosts or added a CDN and no longer trust your configuration.** A diagnostic that reads your actual server and repairs in one click resolves this faster than any support thread, because the finding is written against your stack rather than a generic case. Reach for 9.1 the week you migrate. **You run path security on LiteSpeed or behind an aggressive cache.** Serving each processed file once instead of once per visitor removes the overhead that made people disable path features on busy sites. Reach for it if you turned something off for performance reasons. **You need 2FA on a team that will not set it up voluntarily.** Forcing it per role with a guided screen at first login is more reliable than asking, and it is in the free tier rather than behind an upgrade. Reach for it when you have contributors you cannot chase. **Your budget is zero.** Path changes, the 8G firewall and passkey 2FA are all free on wordpress.org. Reach for it before deciding whether security is worth paying for. **Where it is the wrong tool:** if your site is infected right now, run a scanner first and clean it. Hardening an infected site makes the infection harder to find. ### Why you can rely on it Four commitments that are dull and load-bearing: five years of security updates from each version’s release, stated in writing; a published disclosure policy with acknowledgement inside 48 hours and coordinated disclosure; a full list of the third-party code we ship; and tested readiness for WordPress 7.1 and PHP 8.5 ahead of the upgrade rather than after it. Sixteen languages, with Indonesian and Turkish added this cycle. WP Ghost has a free version on wordpress.org if you want to test 9.1 before deciding anything. [Pricing](https://wpghost.com/pricing/) covers the paid tiers. ### FAQ #### What’s new in WP Ghost 9.1? Ghost Doctor, a diagnostic layer that inspects your server rules, cache and theme and repairs most problems in one click with an Undo. Alongside it: a prioritised Security Check, a vulnerability scan for installed plugins and themes, a frontend check, forced 2FA per role, and a rewrite of how the plugin serves files so each one is processed once rather than once per visitor. #### Does Ghost Doctor fix problems automatically, or just report them? Both. It reports findings written against your actual server, theme and configuration, explains what an attacker would do with each gap, and repairs most of them in one click. If a repair does not help, Undo restores your previous settings exactly. If your server will not serve rewrite rules at all, it can switch you to a protection mode that does not need them. #### Is the WP Ghost vulnerability scan the same as a malware scan? No, and the distinction matters. The vulnerability scan compares your installed plugins and themes against published security advisories and flags the ones with known issues. It does not read your files looking for injected code. For that you need a malware scanner such as Wordfence or MalCare running alongside. #### Will 9.1 make my site faster? It removes repeated work rather than speeding up your site generally. Files WP Ghost serves are built once and reused, conditional requests are answered without opening the file, and large media is streamed instead of buffered into memory. Sites on LiteSpeed with heavy path processing see the most benefit. Our figures come from a single demo site and are not a promise. #### Do I need to clear my cache after upgrading to 9.1? No. The new file handling rebuilds only when the file or your settings actually change, so there is no WP Ghost cache to clear. If you run a separate caching plugin or a CDN, treat this upgrade like any other plugin update and purge those normally. #### Is WP Ghost ready for WordPress 7.0 and PHP 8.5? Yes, both were tested ahead of release rather than patched afterwards. Compatibility work this cycle also covered LiteSpeed and QUIC.cloud, WooCommerce checkout and payment callbacks, WPML and Polylang, Elementor, and the major caching and security plugins. #### What happens if a repair makes things worse? Undo reverts the change. Underneath that, the Safe URL rollback bypasses WP Ghost so you can reach the dashboard, and renaming the plugin folder over FTP restores access if even that fails. No WordPress core files are modified at any point, so deactivating returns the site to defaults immediately. #### Does WP Ghost itself have a vulnerability record? It does. CVE-2025-26909, an unauthenticated file-inclusion issue rated 9.6, was reported through Patchstack on 3 March 2025 and patched the next day in 5.4.02. CVE-2026-59546, a 2FA bypass rated 4.3, was patched in 7.0.07. Keep the plugin updated. Judge security vendors on disclosure handling and turnaround, not on a claimed clean sheet. --- # Page: WP Ghost Pricing – Plans from $49/yr or One-Time Lifetime from $399 URL: https://wpghost.com/pricing/ Section: Pricing Last-Updated: 2026-09-04 Language: en-US Description: Current WP Ghost pricing: annual plans from $49/yr and one-time lifetime licenses for agencies. Discounts are applied automatically - no coupon code needed. 30-day refund. ## WP Ghost Pricing & Plans: Choose Your Protection Level ### Every second, a bot is trying to access your site. Don’t be part of the 64% that experience a security incident. Get 24/7 Protection →YearlyLifetime #### Ghost 1 Best for: freelancers, blogs $ 49 /yr All premium features [Protect My Site](/buy/1_website) - 1 Website - All premium features included - Renews at the same price you pay today - Paddle Secure Payment​ - Priority email support #### Ghost 5 Best for: small businesses, devs $119$ 59 50 /yr $23.80 / site / year [Protect 5 Sites](/buy/5_websites?coupon=5HIDEMYWP50) - 5 Website - All premium features included - Renews at the same price you pay today - Paddle Secure Payment​ - Priority email support #### Ghost 25 Best for : medium businesses $ 249 /yr from $9.96 / site / year [Protect 25 Sites](/buy/25_websites) - 25 Website - All premium features included - Renews at the same price you pay today - Paddle Secure Payment​ - Priority email support #### Ghost All Best for : WordPress agencies $ 499 /yr Unlimited sites [Protect All My Sites](/buy/unlimited_websites) - Unlimited Website - All premium features included - Renews at the same price you pay today - Paddle Secure Payment​ - Priority email support #### Ghost 5 LTD Best for: agencies $ 399 $79.80 / site · lifetime [Get Lifetime Access - 5 Sites](/buy/5_ltd) - 5 Website - All premium features included - One-time payment. Never renews. - Paddle Secure Payment​ - Priority email support #### Ghost 25 LTD Best for: agencies $ 799 $31.96 / site · lifetime [Get Lifetime Access - 25 Sites](/buy/25_ltd) - 25 Website - All premium features included - One-time payment. Never renews. - Paddle Secure Payment​ - Priority email support #### Ghost 1000 LTD Best for: agencies $ 1449 from $1.45 / site · lifetime [Get Lifetime Access - 1000 Sites](/buy/unlimited_ltd) - 1000 Website - All premium features included - One-time payment. Never renews. - Paddle Secure Payment​ - Priority email support Trusted by 250,000+ WordPress Sites Worldwide Your website’s security is backed by proven results, excellent support, and thousands of happy users. #### Excellent Email Support 4.5 4.8 4.8 4.8 Included in every paid plan #### Everything you need to harden a WordPress site **Hide & Harden** - Secure WP paths & endpoints - Protect plugins & themes paths - Custom login URL - SQL & script injection protection **Monitor & Control** - Real-time threat monitoring - User activity logs - Security Threats Log **Block & Protect** - Built-in firewall protection - Block bots & malicious crawlers - Brute force login protection - reCAPTCHA login protection - IP allowlist & blocklist - Two Factor Authenticator (2FA) - 150+ security features in Premium Free version ### Start free on WordPress.org Try the free version first, then upgrade when you need deeper hardening, automation, and advanced protection. - Basic path security - 7G & 8G Firewall - 2FA with code, email and passkeys - Security Threats Log - One-click security presets - 115+ free security features in Free Plan [Download Free](https://wordpress.org/plugins/hide-my-wp/)[Compare Free vs Premium →](https://wpghost.com/free-vs-premium/) ### It’s an investment. #### Recovery Costs Professional cleanup runs $300–$1,000+ per incident.¹ #### SEO Damage Lost rankings and traffic that take months to recover. #### Blacklist Risk Google may flag your site as "Unsafe," driving users away. #### Zero Cleanup Fees Keep your hard-earned money in your pocket. #### Proactive Defense Attacks are blocked automatically before they happen. #### Total Peace of Mind Focus on your growth while we handle the bots. ¹ Based on published pricing from Sucuri, SolidWP, and Wordfence (2025) ### What WordPress Site Owners Say After Buying WP Ghost Trusted by Agencies, Freelancers, and Site Owners Worldwide _★__★__★__★__★_ Rated 5 out of 5Best Deal For The MoneyComparing it with security plugins in terms of features and security, they offer the best deal for the bucks. Now I use this plugin on all of my websites, and I do not see any attacks anymore on my website. This is a game-changer for me! Shaikat R. CEO, Marketing and Advertising Verified review on [Capterra](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) _★__★__★__★__★_ Rated 5 out of 5Stopped All Brute Force AttacksSince I installed the plugin, it has stopped all the brute force attacks on my site, which is a total win. I do not have to worry about my account data or my customers' info being hacked. Adrian N. Owner, Marketing & Advertising Verified review on [Capterra](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) _★__★__★__★__★_ Rated 5 out of 5This One Just WorksIn the past, I used a similar product, but it did not satisfy my needs. I decided to buy the Pro version of this plugin and did not regret it. This one just works. It is relatively simple to set up, and it has many security features beyond just hiding some WordPress traces. Sinisa S. CEO, Internet industry Verified review on [Capterra](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) _★__★__★__★__★_ Rated 5 out of 5Works Alongside My Existing SetupI like the fact that you can use this product alongside other WP security plugins and it adds that much more security for my site. It is easy to set up and reliable. Brandi A. Owner, Cosmetics Verified review on [Capterra](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) _★__★__★__★__★_ Rated 5 out of 5Pricing Matters When You Manage 100+ SitesI like the combination of features and options available with WP Ghost. It works alongside other well-known security plugins. Pricing was important, makes a big difference when you manage 100+ sites. Ninos M. Creative Director, Design Agency Verified review on [Capterra](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) _★__★__★__★__★_ Rated 5 out of 5Better Security Than BeforeWP Ghost now provides my site with better security than before due to the extra features such as hiding plugin names, theme names and even the WordPress operating system. It is a must-have for anyone serious about security. Sam.R. IT Professional _Verified review on [G2](https://www.g2.com/products/hide-my-wp-ghost/reviews)_ ### And it’s not just words Here’s the proof in numbers.​ [2.5M+](https://wpghost.com/statistics/)plugin downloads [100M+](https://wpghost.com/statistics/)monthly threats prevented [250K+](https://wpghost.com/statistics/)Secured websites [10M+](https://wpghost.com/statistics/)monthly brute force stopped ### WP Ghost Pricing Questions Do I need a coupon code to get the WP Ghost discount?No. When a discount is running, it is applied automatically on this page – there is no code to enter. Coupon codes listed on third-party aggregator sites are not issued by us and are never required to get our best price. Does my price increase when my subscription renews?No. Your annual plan renews at the same price you paid when you subscribed. If you subscribe during a discount period, that discounted rate stays on your subscription for every future renewal – there is no first-year-only pricing and no automatic increase. Lifetime licences never renew; they are a single one-time payment Is tax included in the price?No. All displayed prices exclude local tax. VAT or sales tax is calculated and added at checkout based on your billing country, so the final amount charged may be higher than the price shown on this page. The exact total is always shown before you confirm payment. Is the lifetime licence worth it compared to the annual plan?At standard pricing, a lifetime licence costs about four years of the equivalent annual plan – $600 for Ghost 5 Lifetime against $149 per year for Ghost 5. During a discount period the payback is shorter, around three and a half years. If you plan to keep your sites online longer than that, lifetime works out cheaper. Bear in mind that annual plans lock in your subscription rate permanently, so the comparison is against a price that never rises. Can I upgrade or change my plan later?Yes. You can upgrade your licence at any time directly from your account dashboard. Your existing settings and protection stay intact during the upgrade, no reconfiguration needed. What happens when my licence expires?Your site keeps the protection you already configured, nothing is switched off. What stops is your access to plugin updates. You can activate a new subscription for the same account at any time, and your settings are preserved. Is there a money-back guarantee?Yes. 30 days, full refund, no questions asked. Payments are processed by Paddle as merchant of record. If WP Ghost isn’t the right fit for your site, contact our support team and you’ll receive a complete refund. Can I use one license on multiple websites?It depends on your plan. Ghost 1 covers 1 website, Ghost 5 covers up to 5 websites, and Ghost All covers up to 1000 websites. Lifetime licences follow the same limits: 5, 10 or 1000 websites. Do I get updates and support?Yes. All plans include automatic plugin updates and access to our human support team via email. PRO plans receive priority support with faster response times. #### Don’t wait for the next attack Join 250,000+ site owners already protected from WordPress attacks. Start Protecting My Site Now #### Product - [Free vs Premium](https://wpghost.com/free-vs-premium/) - [Pricing](https://wpghost.com/pricing/) - [Changelog](/kb/changelog/) #### Features - [Path Security](/kb/category/features/change-paths/) - [Firewall Security](/kb/category/features/firewall/) - [Brute Force Protection](/kb/category/features/brute-force/) - [Two-Factor Authentication](/kb/category/features/two-factor/) - [User Events Log](/kb/events-log-report/) - [Security Threats Log](/kb/security-threats-log/) #### Resources - [Getting Started Guide](/kb/wp-ghost-settings-best-practice/) - [Developer Hooks](/kb/wp-ghost-hooks-reference-for-developers/) - [Security Solutions](/category/security/) #### Company - [Security Policy](https://wpghost.com/security-policy/) --- # Page: WordPress Security Plugin for Beginners: 4 Settings First URL: https://wpghost.com/wordpress-security-plugin-for-beginners/ Section: Pages Last-Updated: 2026-09-04 Language: en-US Description: Which settings in a WordPress security plugin actually protect a beginner's site, which ones break it, and how to get back in if you lock yourself out. - September 3, 2026 - John Darrel, MINBO QRE SRL This guide is for someone who has just installed their first WordPress security plugin, opened the settings panel, and found several hundred toggles with no indication of which ones do anything. You do not need all of them. You need about four, in a particular order, and a reliable way to undo the rest. **TL;DR** A WordPress security plugin for beginners is not the one with the fewest features. It is the one that ships a safe default configuration, tells you which settings carry real protection, and gives you a documented way back in when something breaks. Four controls do most of the work: changed paths, a request firewall, login rate limiting, and two-factor authentication. The other two hundred can wait. WP Ghost is the WordPress hack-prevention plugin for first-time site owners who want a secure default configuration rather than a settings panel to study. This page explains the general approach first, because the approach is what transfers to whatever plugin you end up running. ### Why the beginner problem is configuration, not coverage Beginners rarely get hacked because their plugin lacked a feature. They get hacked because the feature existed, sat off by default, and nobody knew it mattered. The shape of the risk supports that. According to [Patchstack’s _State of WordPress Security in 2026_](https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/), 91% of the 11,334 vulnerabilities disclosed across the WordPress ecosystem in 2025 were in plugins and 9% in themes. Only six were found in WordPress core, all rated low risk. So the attack surface a beginner actually owns is the code they installed, not the CMS underneath it. The same report adds the part that catches people out: 46% of those 2025 vulnerabilities had no patch available at the moment of disclosure. Patchstack’s own conclusion is that site owners cannot rely on plugin updates as a security measure. Updating is necessary. It is not a strategy on its own, which is why a hardening layer sits underneath it. That layer has a name worth learning early. Attack Surface Reduction means removing the endpoints, paths and signals an automated attack needs before it can use them, rather than detecting the attack once it arrives. It is the difference between prevention-first and scan-and-clean, and it decides which four settings you turn on first. ### The four settings that carry most of the protection Almost every credible security plugin exposes these in some form. The names differ. The mechanism does not. - **Change the default paths.** `wp-login.php`, `wp-admin`, the registration and lost-password endpoints, `wp-json`, and the plugin and theme directories are the same on every WordPress install on earth, which is exactly why scanners target them. Reconfigure them and a probe against the default path returns 404 before PHP loads. The brute-force phase never starts because the login form was never reached. - **Turn on the firewall ruleset.** A 7G or 8G ruleset rejects SQL injection strings, directory traversal, file-inclusion attempts and malformed requests by pattern. On Apache and LiteSpeed these run as rewrite directives, so the request is dropped before WordPress boots. - **Rate-limit the login.** Cap failed attempts, set a lockout window, and add a captcha to the login and registration forms. This is the control that turns a thousand-attempt overnight run into five attempts and a block. - **Turn on two-factor authentication.** According to the Verizon 2025 Data Breach Investigations Report, 88% of Basic Web Application attacks involved stolen credentials. A stolen password is the single most common way in, and a second factor is what makes it useless. Passkeys are the strongest version, because the cryptographic challenge is bound to your domain and a phished credential cannot be replayed from somewhere else. Do those four, in that order, and stop. In WP Ghost this is one preset rather than four decisions: the [install and activate flow](https://wpghost.com/kb/install-wp-ghost-plugin/) takes about 60 seconds and applies a starting configuration, and the [settings best-practice guide](https://wpghost.com/kb/wp-ghost-settings-best-practice/) documents what each preset actually changes. ### The settings a beginner should deliberately leave alone This is the part vendor pages usually skip, and it is where beginners break their sites. WP Ghost can change 30+ default WordPress paths. That does not mean a first-time user should change all 30 on day one. Leave these until later: - **Renaming the `wp-content`, plugins and themes directories on a live site.** These are the changes most likely to collide with a caching plugin, a CDN with a stale rewrite map, or a page builder that hard-codes asset URLs. Change them on staging, or after you have confirmed the site is stable with paths and firewall on. - **Disabling the REST API outright.** The block editor, WooCommerce, Jetpack and most mobile apps talk over `wp-json`. Restricting it to authenticated users is reasonable; switching it off entirely will produce a broken editor and an afternoon of confusion. - **Database prefix changes and SALT key regeneration.** These are migration-class operations. They are safe when done properly and they are not where a beginner should start. - **Hand-authored Content-Security-Policy headers.** A CSP written without knowing which third-party scripts your theme loads will silently break analytics, embeds and payment iframes. - **Disabling right-click, copy and paste.** No attacker is inconvenienced. Your readers are. The reason to name these out loud is that the real beginner fear is not being under-protected. It is being locked out of your own site by a setting you do not understand. That fear is well founded, and the answer is a rollback path you know about before you need it. WP Ghost keeps a [Safe URL rollback](https://wpghost.com/kb/rollback-settings/) you can bookmark to bypass the plugin and reach the dashboard, plus an emergency disable by renaming the plugin folder over FTP. No WordPress core files are modified, so deactivation restores every default immediately. What surprised me, reading support tickets for years, is that the failure mode is almost never a site that was hardened too little. It is a panel somebody half-configured, could not verify, and then stopped trusting. Fewer settings, confidently understood, beats a full panel you are afraid to touch. ### How to compare beginner-friendly WordPress security plugins The signals people compare on are mostly the wrong ones. According to Patchstack’s 2025 pentest of common defences, internal WAFs, Cloudflare, Imunify360 and ModSecurity blocked only 12% of attacks against known-exploited vulnerabilities, rising to 26% on a broader test. One host in the same test blocked nothing at all. “Has a firewall” is therefore not a differentiator. Where the rules run is. | What people compare | Why it tells you little | What to check instead | |---|---|---| | Feature count | Every vendor counts differently; a toggle is not a control | How much is active after install with nothing configured | | “Includes a firewall” | Coverage varies enormously, per the pentest above | Whether rules run at the server rewrite layer or inside PHP after WordPress loads | | Free vs paid split | The free tier can be a demo or a working baseline | Whether paths, firewall and 2FA are all in the free tier | | Star rating alone | Averages bury the specific failure you will hit | Recent support threads about lockouts, and how fast the vendor answers them | | Claimed setup time | Anyone can claim five minutes | Whether a documented rollback exists that works when you are already locked out | That last row is the one I would weight heaviest as a beginner. A plugin you can reverse is a plugin you will actually configure. ### When WP Ghost is the right choice Four situations where this specific approach fits better than the alternatives, and one where it does not. **You want protection active before you fully understand it.** Applying a preset that reconfigures 30+ default paths and switches on the firewall in one step covers more ground than any per-feature checklist a beginner can work through by hand. Reach for this if you are setting the site up on a weekend and will not open the dashboard again for a month. **Your budget is zero and you want the strong controls anyway.** The 8G firewall ruleset and passkey 2FA are in the free tier on wordpress.org rather than behind an upgrade, alongside 65+ hardening options. The phishing-resistant login factor is available on day one instead of after a purchase decision. Reach for this if you are still testing whether security is worth paying for. **You have no staging site and you are afraid of breaking things.** Because path changes are rewrite rules and no core files are modified, deactivating restores WordPress defaults instantly. That is a cleaner undo than any tool that alters your database schema. Reach for this the first time a setting produces a white screen and you need to be back in within a minute. **Your host is emailing you about CPU on a small site.** Rejecting default-path probes at the rewrite layer stops them earlier in the request than an application-layer firewall can, because PHP never starts. Reach for this when a site with 200 visitors a day is somehow generating thousands of requests to `wp-login.php`. **Where it is the wrong tool:** WP Ghost does not scan files for malware. If your site is already infected, run a scanner such as Wordfence or MalCare first, clean it, then harden. Prevention on top of an existing infection just makes the infection harder to find. ### Where to go next If you want the wider context for why prevention comes before detection, the [WordPress hack prevention guide](https://wpghost.com/wordpress-hack-prevention/) is the parent article for this one. To see exactly which controls sit in each tier before you spend anything, the [free vs premium comparison](https://wpghost.com/kb/wp-ghost-free-vs-premium/) lists them feature by feature, and [pricing](https://wpghost.com/pricing/) covers the paid plans if you get there. WP Ghost has a free version on wordpress.org if you want to test this approach on a site before deciding anything. ### FAQ #### What is the easiest WordPress security plugin for a beginner to set up? The one that applies a working configuration on activation rather than presenting an empty panel. Look for a preset or wizard that turns on path changes, a firewall ruleset, login rate limiting and 2FA together, and check that the vendor documents a rollback. Setup time matters less than whether the defaults are safe before you touch anything. #### What if I turn something on and lock myself out of my own site? This is the most common beginner accident and every good plugin plans for it. Find the recovery method before you change settings, not after. In WP Ghost that means bookmarking the Safe URL rollback, which bypasses the plugin and gets you to the dashboard. The fallback is renaming the plugin folder over FTP, which restores access immediately. #### Do I need a paid plan to be secure as a beginner? No. Path security, the 7G and 8G firewall rules, brute-force protection and two-factor authentication including passkeys are in the free tier, with 65+ hardening options in total. Paid tiers add logging, country blocking, file-permission fixes and support. Those are useful once you are running several sites; they are not the baseline. #### Is changing the login URL just security through obscurity? Obscurity assumes the attacker is the limiting factor. Path security assumes the automated attack chain is the limiting factor, and for a small site it usually is. When a script probes `/wp-login.php` and the server returns 404 at the rewrite layer, the exploit code never loads. That is removing attack surface, not covering it up. #### Do I still need a malware scanner if I have a hardening plugin? Yes. They answer different questions. A hardening plugin reduces what an attacker can reach; a scanner tells you whether something already got in. WP Ghost does not scan files. Wordfence and MalCare do that well, and running one of them alongside a prevention layer is the standard arrangement. #### Will a security plugin slow my site down? It depends on where the enforcement runs. Rules written into `.htaccess` or the nginx config are evaluated by the web server before PHP starts, so a blocked request costs almost nothing. Firewalls implemented as PHP still load WordPress and the plugin stack before deciding to block, which is where the cost usually shows up. #### How many settings should I change on day one? Four categories: paths, firewall, login rate limiting, 2FA. Then leave it alone for a week and confirm the site behaves normally, especially checkout, the block editor and any page builder. Adding a second batch of changes before you have verified the first makes it impossible to tell which one caused a problem. #### Does WP Ghost itself have a vulnerability record? It does, and pretending otherwise would be silly for a security plugin. CVE-2025-26909 was an unauthenticated file-inclusion issue rated 9.6, reported through Patchstack on 3 March 2025 and patched the following day in 5.4.02. CVE-2026-59546, a 2FA bypass rated 4.3, was patched in 7.0.07. Keep the plugin updated; judge vendors on response time, not on a claimed clean sheet. #### Product - [Free vs Premium](https://wpghost.com/free-vs-premium/) - [Pricing](https://wpghost.com/pricing/) - [Changelog](/kb/changelog/) #### Features - [Path Security](/kb/category/features/change-paths/) - [Firewall Security](/kb/category/features/firewall/) - [Brute Force Protection](/kb/category/features/brute-force/) - [Two-Factor Authentication](/kb/category/features/two-factor/) - [User Events Log](/kb/events-log-report/) - [Security Threats Log](/kb/security-threats-log/) #### Resources - [Getting Started Guide](/kb/wp-ghost-settings-best-practice/) - [Developer Hooks](/kb/wp-ghost-hooks-reference-for-developers/) - [Security Solutions](/category/security/) #### Company - [Security Policy](https://wpghost.com/security-policy/) --- # Page: WP Ghost (Hide My WP Ghost) - Knowledge Base URL: https://wpghost.com/kb/ Section: Knowledge Base Last-Updated: 2026-09-04 Language: en-US Description: Discover comprehensive guides, troubleshooting tips, and best practices for using WP Ghost (Hide My WP Ghost). Our Knowledge Base is your go-to resource for securing your WordPress site, protecting against hacks, and optimizing performance. [Getting Started](https://wpghost.com/kb/category/getting-started/)(6 Articles)New to WP Ghost? Start here. Install the plugin, pick Safe Mode or Ghost Mode, activate brute force protection, hide your site from theme detectors, and secure your login in under 10 minutes. Step-by-step lessons with no coding required. - [WP Ghost – Free vs Premium ](https://wpghost.com/kb/wp-ghost-free-vs-premium/) - [WP Ghost Settings – Best Practice ](https://wpghost.com/kb/wp-ghost-settings-best-practice/) - [Lesson 1 – Customize Paths and Hide Your WordPress Website ](https://wpghost.com/kb/how-to-hide-wordpress-website/) - [Lesson 2 – Activate Brute Force Protection on Your Login Page ](https://wpghost.com/kb/activate-brute-force-protection/) - [Lesson 3 – Hide Your Site from WordPress Theme Detectors and Bots ](https://wpghost.com/kb/hide-from-wordpress-theme-detectors/) - [ + View all](https://wpghost.com/kb/category/getting-started/) [Features](https://wpghost.com/kb/category/features/)(154 Articles)Every feature in WP Ghost documented, with step-by-step setup guides, configuration options, and troubleshooting. From core path security and the 8G firewall to two-factor authentication, security logs, and country blocking, this is the complete reference for protecting a WordPress site with WP Ghost. - [How to Block WordPress Pingbacks with WP Ghost ](https://wpghost.com/kb/how-to-block-wordpress-pingbacks-with-wp-ghost/) - [Login Page Design Customization with WP Ghost ](https://wpghost.com/kb/login-page-design-customization/) - [Security Threats Log – Monitor Blocked Attacks ](https://wpghost.com/kb/security-threats-log/) - [How to Hide Source Map References in WordPress ](https://wpghost.com/kb/hide-source-map-references/) - [Passkey 2FA for WordPress – Face ID, Touch ID ](https://wpghost.com/kb/introducing-passkey-2fa-in-wp-ghost/) - [ + View all](https://wpghost.com/kb/category/features/) [How To](https://wpghost.com/kb/category/how-to/)(36 Articles)Practical how-to guides for common WordPress security tasks. Hide your login URL, block specific user roles, redirect logged users, protect custom post types, fix file permissions, and solve real problems one guide at a time. - [WP Ghost Paths Not Working? Ghost Doctor Finds the Cause and Repairs It ](https://wpghost.com/kb/wp-ghost-paths-not-working-ghost-doctor/) - [WP Ghost 9.0: Biggest Security Update of 2026 ](https://wpghost.com/kb/wp-ghost-9-0-biggest-security-update-of-2026/) - [WP Ghost – Version 8.3.07 ](https://wpghost.com/kb/wp-ghost-8-3-07/) - [WP Ghost With WooCommerce Ecommerce Security ](https://wpghost.com/kb/wp-ghost-with-woocommerce-ecommerce-security/) - [Passkey 2FA for WordPress – Face ID, Touch ID ](https://wpghost.com/kb/introducing-passkey-2fa-in-wp-ghost/) - [ + View all](https://wpghost.com/kb/category/how-to/) [Compatibility](https://wpghost.com/kb/category/compatibility/)(95 Articles)WP Ghost is tested for compatibility with 50+ popular plugins, caching tools, other security plugins, all major hosting providers, and every common server type. Confirm your stack works with WP Ghost before or after installing. - [WP Ghost on aaPanel Multi-WebServer Setup Nginx + OLS ](https://wpghost.com/kb/wp-ghost-and-aapanel-multi-webserver-hosting/) - [WP Ghost on YunoHost Server Setup ](https://wpghost.com/kb/yunohost-server-wp-ghost-setup/) - [WP Ghost and LiteSpeed Cache Setup Guide ](https://wpghost.com/kb/wp-ghost-and-litespeed-cache/) - [WP Ghost and WP Security Ninja Compatibility ](https://wpghost.com/kb/wp-ghost-and-wp-security-ninja/) - [WP Ghost on Local by Flywheel Setup Guide ](https://wpghost.com/kb/local-flywheel-wp-ghost-setup/) - [ + View all](https://wpghost.com/kb/category/compatibility/) [Hooks](https://wpghost.com/kb/category/hooks/)(9 Articles)Developer reference for WP Ghost hooks. Filters and actions to customize path security, brute force thresholds, 2FA behavior, firewall whitelists, and logging output. Full PHP examples for every hook. Written for WordPress developers and agencies. - [WP Ghost Plugin Hooks Reference for Developers ](https://wpghost.com/kb/wp-ghost-hooks-reference-for-developers/) - [Add Files to Hide WordPress Common Files ](https://wpghost.com/kb/add-files-to-hide-wordpress-common-files/) - [Change or Remove WordPress Login Logo Link ](https://wpghost.com/kb/change-or-remove-login-logo-link/) - [Disable WP Ghost on Specific Pages Whitelist ](https://wpghost.com/kb/disable-wp-ghost-on-specific-pages/) - [Customize Right-Click Disable for Specific Pages ](https://wpghost.com/kb/customize-right-click-disable-for-specific-pages/) - [ + View all](https://wpghost.com/kb/category/hooks/) [Troubleshooting](https://wpghost.com/kb/category/errors/)(43 Articles)Stuck after configuring WP Ghost? Fix 404 errors, redirect loops, broken admin access, frontend not loading, missing CSS, theme issues, and more. Emergency disable instructions included for when you cannot log in. Real solutions to real problems. - [WP Ghost Paths Not Working? Ghost Doctor Finds the Cause and Repairs It ](https://wpghost.com/kb/wp-ghost-paths-not-working-ghost-doctor/) - [CONNECTION ERROR! Make sure your website can access account.wpghost.com ](https://wpghost.com/kb/connection-error-make-sure-your-website-can-access-https-account-wpghost-com/) - [Cache Plugins Not Minifying CSS and JS Files ](https://wpghost.com/kb/cache-plugins-not-minifying-css-and-js-files/) - [The New Admin Path Is Redirected To Front Page When Logged In ](https://wpghost.com/kb/new-admin-path-redirects-to-front-page-when-logged-in/) - [The New Admin Path Is Redirected To Front Page ](https://wpghost.com/kb/the-new-admin-path-is-redirected-to-front-page/) - [ + View all](https://wpghost.com/kb/category/errors/) --- # Page: WP Ghost 9.0 WordPress Hack Prevention Plugin URL: https://wpghost.com/ Section: Home Last-Updated: 2026-09-04 Language: en-US Description: WP Ghost stops WordPress hacks before they start. Hide paths, block bots with 7G/8G Firewall, add 2FA & brute force protection. Trusted by 250,000+ sites. ## The WordPress Hack Prevention Suite for Path Security and Site Hardening ### Stop the Hack Before It Starts with WP Ghost 9.0 [Start Protecting My Site](/pricing)No code edits. Instant results. Join 250,000+ sites already protected. ### Get Your WordPress Security Optimization Score See in 30 seconds how exposed your WordPress site is to automated attacks. WP Ghost, previously called Hide My WP Ghost, analyzes your visible fingerprints, login surface, and active hardening status, then gives you a 0–100 score with concrete next steps. **WordPress sites are constantly scanned by automated bots. Without protection, yours is an easy target 24/7.** Trusted by **25****0,000+** websites ### What Is WordPress Hack Prevention? **WordPress hack prevention** means securing your site before an attack begins, hiding vulnerable paths, blocking automated bots, and removing the WordPress fingerprints hackers use to find and target sites. WP Ghost is built specifically for this approach, trusted by 250,000+ websites to block over 100 million threats every month. Most security plugins wait for hackers to attack, then react. WP Ghost works the opposite way, by removing what hackers can see and reach in the first place. This approach has a name: Attack Surface Reduction, a security discipline recognized by NIST and OWASP. ### From Vulnerable to Secured in Under 1 Minute Install & Activate Install the plugin from your WordPress dashboard - no code edits, no setup wizard. Run Security Check Quick-scan your site to detect current security threats and exposure points. Activate Path Security Secure WP paths, login page, and plugins from bots and spammers in one click. [2.5M+](https://wpghost.com/statistics/)plugin downloads [100M+](https://wpghost.com/statistics/)monthly threats prevented [250K+](https://wpghost.com/statistics/)Secured websites [10M+](https://wpghost.com/statistics/)monthly brute force stopped ### Most Security Plugins React Too Late. WP Ghost Prevents WordPress Hacks Before They Start. While others block intrusions after they happen, WP Ghost makes WordPress sites invisible to bots by hiding login, plugin, and theme paths before scanners can reach them. | Other Plugins | WP Ghost Plugin | |---|---| | ✕ React after attacks begin | ✓ Hides vulnerable paths before bots find them | | ✕ Show the WordPress login & structure | ✓ Invisible to automated scanners and bots | | ✕ Require advanced config & rules | ✓ Easy setup. No code edits. One-click protection | | ✕ Leave security traces visible | ✓ Ghost Mode removes all WordPress fingerprints | #### Ready to Switch to Proactive Protection? [Secure My Site Now](/pricing)Every day without protection increases your risk. ### WordPress Hack Prevention Features Designed to Prevent, Not Just React All the protection you need without slowing down your site. Hide Critical WordPress Paths If hackers can’t find it, they can’t attack it. Hide and protect common paths, wp-login, plugins, and themes so attackers can’t even locate your entry points. Firewall & Anti-Bot Shield Block threats before they touch your site. Stop spam bots, malicious crawlers, and automated scanners with advanced hack prevention firewall and filters. SQL & Brute Force Protection Defend against the most common hacks. Prevent password-guessing attacks and database exploits that can compromise your site and sensitive data. Geo-Blocking & IP Control Only let the right, l egitimate visitors in. Block access from high-risk countries and allow only trusted IPs to reach your site. Secure Login with reCAPTCHA & 2FA Secure your login with reCAPTCHA and 2FA. Add two-factor authentication and reCAPTCHA to ensure only verified users can log in. Security Threat & User Events Logs Monitor all threats and users activity. Detailed log of attacks, bot scans, firewall blocks, and suspicious behavior. See the Full Defense System Behind [WP Ghost](https://wpghost.com/features/) ### Why Site Owners Trust Us Trusted by Agencies, Freelancers, and Site Owners Worldwid _★__★__★__★__★_ Rated 5 out of 5A+ Security Score, No Coding RequiredI am not a coder nor a technically advanced user. I installed the plugin, followed the prompts, messaged support and received a friendly reply from Peter within 24 hours. The result: an A+ score on security scanning websites. It has not slowed down my site, Core Web Vitals are all in the green. @sofasurfer75 Website Designer Verified review on [WordPress.org](https://wordpress.org/support/topic/5-simple-steps-to-a-score-for-a-secure-website/) _★__★__★__★__★_ Rated 5 out of 5Bots Don't Even Try If They Can't See WordPressIf bots and hackers do not know that your website is running on WordPress, they do not even try to hack it. Before, we had to use reCaptcha to keep spammers away, with WP Ghost we do not have to worry about spammers anymore. David S. Director of Installation, Construction Verified review on [Capterra](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) _★__★__★__★__★_ Rated 5 out of 5Real Peace of Mind With Real SupportThis plugin improves my peace of mind regarding the security of my WordPress sites. After a minor conflict with my theme, Peter investigated right away and updated the plugin to resolve it. I am impressed and very pleased. Cynthia Armistead @technomom Verified review on [Capterra ](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) ### And it’s not just words Here’s the proof in numbers.​ 4.5 4.8 4.8 4.8 [Secure My Site Now](/pricing)Most website owners think about security only after an attack.By then, the damage is already done. ### Common Questions About WordPress Hack Prevention How does WP Ghost prevent hacks before they even start?Most security plugins wait for a hack attempt to block it. WP Ghost (formerly Hide My WP Ghost) takes a proactive approach by hiding your WordPress “fingerprints.” By changing your login paths (wp-admin), plugin directories, and theme paths, and more you become invisible to the **automated bots responsible for millions of daily brute-force attempts**. If they can’t find you, they can’t hack you. What is the difference between WP Ghost and Hide My WP Ghost?WP Ghost and Hide My WP Ghost are the same plugin. We renamed the product from Hide My WP Ghost to WP Ghost – same security engine, same team, same features. If you’re an existing Hide My WP Ghost user, nothing changes on your end. Will implementing these security layers slow down my site?**No.** We believe security shouldn’t come at the cost of performance. WP Ghost uses high-performance rewrite rules that process requests at the server level. This prevents hacks without running heavy, resource-draining scans, ensuring your site stays both **secure and lightning-fast** for your real visitors. Is this prevention method compatible with my current theme and plugins?**Yes.** WP Ghost is engineered to be compatible with the entire WordPress ecosystem, including **Elementor, Divi, WooCommerce, and BuddyPress**. Our “Compatibility Mode” ensures that while your site’s internal structure is hidden from hackers, your plugins and themes continue to communicate and function perfectly. Does hiding my WordPress paths interfere with Google’s indexing?**Not at all.** Our hack prevention suite is designed to be **SEO-transparent**. SEO-safe when configured correctly. All public pages remain fully indexable. If you customize the uploads path, WP Ghost’s built-in redirect helper preserves image-search traffic. ### Still have questions about your site's safety? Don’t wait for an attack to find out if you’re vulnerable.Check My Security Score_★__★__★__★__★_ Rated 5 out of 5 #### Product - [Free vs Premium](https://wpghost.com/free-vs-premium/) - [Pricing](https://wpghost.com/pricing/) - [Changelog](/kb/changelog/) #### Features - [Path Security](/kb/category/features/change-paths/) - [Firewall Security](/kb/category/features/firewall/) - [Brute Force Protection](/kb/category/features/brute-force/) - [Two-Factor Authentication](/kb/category/features/two-factor/) - [User Events Log](/kb/events-log-report/) - [Security Threats Log](/kb/security-threats-log/) #### Resources - [Getting Started Guide](/kb/wp-ghost-settings-best-practice/) - [Developer Hooks](/kb/wp-ghost-hooks-reference-for-developers/) - [Security Solutions](/category/security/) #### Company - [Security Policy](https://wpghost.com/security-policy/) --- # Page: WP Ghost - Changelog and Updates URL: https://wpghost.com/kb/changelog/ Section: Knowledge Base Last-Updated: 2026-09-04 Language: en-US Description: Stay informed about the latest updates and improvements to the WP Ghost plugin. This changelog provides a detailed record of all version releases, including new features, security enhancements, bug fixes, and performance optimizations. Last plugin update: **02 Sep 2026** Stay informed about the latest updates and improvements to the **WP Ghost** plugin. This changelog provides a detailed record of all version releases, including new features, security enhancements, bug fixes, and performance optimizations. Whether you’re a casual user or a WordPress security expert, our changelog ensures you’re always up to date with how WP Ghost is evolving to keep your website secure. Check back often to see what’s new and take advantage of WP Ghost’s advanced protection for your WordPress site. = 9.0.15 (2 Sept 2026) = - Update – Security update: hardening for the way the plugin resolves and handles the current request - Fix – Static files and the REST API path are now handled correctly when your site is reached on an alias domain - Fix – REST API responses handled by the plugin no longer carry compression headers that do not match the returned content - Fix – No longer stops with a fatal error on servers where the getallheaders() function is missing - New – New hmwp_files_allowed_hosts, hmwp_files_request_headers, hmwp_files_response_headers and hmwp_files_skip_headers filters for developers = 9.0.14 (17 Aug 2026) = - Fix – Fix it now works for the Security Check tasks that change a plugin setting, such as Hide Old Paths, Hide Common Files, Hide wp-login and Disable XML-RPC - Fix – Fix it no longer answers with Ajax is not loading correctly. Clear all cache and try again. = 9.0.13 (04 Aug 2026) = - New – Developers can now redact or skip log entries before they are saved, using the new hmwp_log_row filter - New – Vulnerability scan: flags installed plugins and themes with published security issues - New – Ghost Doctor: finds what is breaking your paths and repairs it in one click - New – Ghost Doctor can switch to protection that needs no server rules when your server will not serve them - New – Security Check now opens with one prioritized list of what to fix first - New – AI explanations written for your own website, server and configuration - New – Undo restores your settings if a repair does not help - Fix – Security Check no longer reports wp-content, the login path or the admin path as visible on sites that are hiding them correctly - Fix – Ghost Doctor no longer reports a failure when Disable REST API Access is on - Fix – Open on a failing path check no longer leads to a 404 while the new paths are not working yet - Fix – Fix it now works for Security Keys, Table Prefix, wp-config constants and plugin updates - Fix – Security Check runs on its own the first time you open it - Fix – Last check now shows how long ago the scan ran, not a clock time - Fix – Change Paths shows one card after a path change instead of two - Fix – Security Tasks no longer shows an empty table when every task passed = 9.0.12 (20 July 2026) = - Security – Two-Factor Authentication settings are now bound to the account they belong to, so the 2FA method, authenticator, email codes, backup codes and passkeys can only be managed by the account owner or by an administrator allowed to edit that user - Security – Passkey enrollment is now always self-service, matching the device the passkey is created on - Security – Temporary Login updates and deletions now apply only to temporary accounts, so regular accounts are never affected from this screen - Security – The role assigned to a temporary login is now validated and can never grant more capabilities than the user creating it already has - Security – Magic Login links now require the same permissions as the screen they are offered from = 9.0.11 (16 July 2026) = - Fix – Editing a custom post type that uses the built-in Categories/Tags taxonomy no longer crashes the Block Editor - Fix – Block Editor no longer crashes with “Cannot read properties of undefined” when Hide User Enumeration is on; the users REST endpoint is now hidden from anonymous visitors only, so logged-in Editors and Authors can still edit posts and custom post types = 9.0.10 (13 July 2026) = - Fix – Cloud Activity Log entries are now sent in the background, so a slow logging server can no longer delay backend requests, including the Block Editor and other REST calls - Fix – Force 2FA Setup no longer redirects custom user roles that can’t access their profile to a setup screen they are unable to open - Fix – Settings page navigation menu no longer loses its layout on sites where another plugin or theme restricts the allowed HTML tags; the menu now keeps its own classes and attributes regardless of the site’s wp_kses filters = 9.0.09 (08 July 2026) = - New – Force 2FA Setup: require selected user roles to set up Two-Factor Authentication before they can access the dashboard, with a guided setup screen shown right after login - Fix – WP-CLI commands no longer emit a PHP 8.5 Undefined array key hostname warning = 9.0.08 (01 July 2026) = - Fix – Temporary Login page no longer triggers a fatal error when opened for a user that was deleted or expired - Fix – Two-Factor email setup and Magic Login no longer emit PHP warnings when the requested user no longer exists = 9.0.07 (29 June 2026) = - New – Frontend Check now also verifies the theme’s CSS and JS files load, catching a broken layout on pages that still return 200 - New – Detects when CSS/JS/font files load through WordPress instead of the server config, falls back to safe paths and warns you on the settings page - Improvement – Redesigned the Frontend Check results into clear, uniform rows that stay readable with long URLs = 9.0.06 (02 June 2026) = - Fix – Some sites could show a blank page when source code optimization was enabled; the header find & replace is now fail-safe and never blanks the output on a regex error - Fix – Prefetch/speculation rules cleanup now removes the wp-admin and wp-*.php entries without leaving the rules JSON invalid - Security – Fixed unauthenticated Open Redirect via the `redirect_to` parameter on the custom logout URL. = 9.0.05 (18 May 2026) = - Fix – WPML/Polylang with a custom or renamed REST API path: WPML Advanced Translation Editor and other REST API calls no longer fail with a network error in the admin - Fix – REST API requests made through the ?rest_route= form are no longer mistakenly treated as normal page requests and blocked - Fix – Renamed REST API path: legacy, cached and external clients still calling the default wp-json path are now recognized correctly instead of being 404’d - Fix – Compatibility module for WPML: the Advanced Translation Editor sync routes and requests are no longer rewritten with the active language prefix - Security – Hardened REST API detection: the firewall can no longer be bypassed by appending to the query string of another request - Security – Brute force protection also covers REST API Application Password authentication = 9.0.04 (14 May 2026) = - Fix – Compatibility with WPML and Polylang: static asset URLs (wp-content, wp-includes) no longer get the language prefix prepended (e.g. /en/wp-content/…) when “Change Relative URLs to Absolute URLs” is enabled - Fix – Password-protected pages (built-in WordPress post password) now submit correctly on Nginx and other servers without server-level rewrites when the login URL is customized - Fix – Refreshed knowledge base links across admin notices to point to the new documentation - Fix – Minor bugs and typos = 9.0.03 (06 April 2026) = - Fix – Fixed an issue where the Dark Mode popup remained white and some settings fields were too dark - Fix – Fixed Login Page Design to work in Disable mode - Fix – Fixed Firewall whitelist IPs and paths to work in disabled mode when the Firewall is activated - Fix – Fixed minor bugs and typos = 9.0.02 (01 April 2026) = - New – Translation in Indonesian (id_ID) language - New – Translation in Turkish (tr_TR) language - Update – Translations updated in all 16 supported languages: Arabic, Brazilian Portuguese, Chinese (Simplified), Dutch, Finnish, French, German, Italian, Japanese, Portuguese, Romanian, Russian, Spanish, and English (default). - Fix – Friendly time display (e.g. “3 hours ago”) now renders correctly in all translated languages - Fix – Dropdown and Help icon in the RTL languages = 9.0.01 (30 March 2026) = - Fix – Resolved robots.txt warning when user agents are blocked - New – Country filter in Security Threats Log and User Events Log - New – Click on a country circle in the GeoMap to open Security Threats Log filtered by that country for the last 7 days - Update – Moved Export CSV button to below the table in Security Threats Log and User Events Log to avoid accidental clicks - Update – Added proper color handling for dark mode (browser-based) - Update – Enhanced security progress indicator and introduced Security Optimization Score - Update – Add a loading process on login submit - Fix – GeoMap country circle counts now match Security Threats Log counts for the same 7-day window - Fix – Security Threats counting for the last 7 days on widget now matches the log totals (timezone-aligned day buckets) - Fix – Passkey login spinner not showing due to missing classList calls - Fix – Country codes missing from threats log rows now resolved on-the-fly from GeoIP when cron is not running = 9.0.00 (26 March 2026) = - New – Customize the login page with custom logo (with live preview), logo link URL, and color scheme (page, form, button, text, link colors) with one-click presets - New – Block AI Crawler Bots at firewall level with automatic robots.txt Disallow rules (GPTBot, ClaudeBot, PerplexityBot, Bytespider, and 30+ others) - New – GEO Map with top 5 threat countries visualization on the Overview dashboard - New – Export Security Threats Log and User Events Log to CSV - New – Security Check task to verify IP block automation is configured correctly - New – Threats count in the Overview widget now shows the full 7-day period totals - New – Notification in the Overview widget to activate 7G/8G Firewall when unblocked threats are detected - Update – Store country code in the threats log table for faster country stats - Update – Missing country codes resolved in background via cron without slowing down threat logging = 8.3.07 (16 March 2026) = - Fix – Sorting and filtering in the Events Log & Security Threats Log - Fix – Rules and Threats filters to work with WP Multisite subpaths structure - Fix – Temporary login user edit link on WP Multisite - Fix – Compatibility with Woocommerce 10.6 - Fix – Compatiibility with the Blocksy theme - Fix – Optimize the plugin speed = 8.3.06 (09 March 2026) = - Update – JS requirements for WordPress 6.9.2 - Fix – Security Log and Events Log not recording properly - Fix – Optimize user logged in verification - Fix – Don’t show the 2FA and Magic Login form when the Safe URL parameter is set - Fix – Prevent logging out when the paths are changed - Fix – Sending the code too often on 2FA Email verification. The code can be resent only every 30 seconds. - Fix – Remove unused JS, CSS and fonts = 8.3.04 (02 March 2026) = - Update – Remove the option to send the new paths by email as the are already on WP Ghost dDashboard - Update – Send the Brute Force, 2FA and Magic Login texts to the multilingual plugins like WPML and Polylang - Update – Add the Magic Login options to Change Paths > Login Security section - Update – Compatibility with PHP 8.5 - Fix – Small bugs and typos = 8.3.03 (25 Feb 2026) = - New – Added Automation on IP address blocking in the Firewall - Update – Added compatibility with Photo Gallery from 10Web - Update – Translations in all 14 languages - Update – Moved 2FA and Magic Login feature in WP Ghost core - Update – UI for Security Threats Log and Events Log - Update – Plugin core security acording to the latest WordPress security recommendations - Fix – Firewall rules to work with the new WordPress 6.9.2 update = 8.3.02 (20 Feb 2026) = - New – Added Automation on IP address blocking in the Firewall - Update – Added compatibility with Photo Gallery from 10Web - Update – Translations in all 14 languages - Fix – Firewall rules to work with the new WordPress 6.9.2 update = 8.3.01 (10 Feb 2026) = - Fix – Fatal error on log table creation when the plugin is activated - Fix – Safe URL parameter on login form to prevent 2FA from showing when is activated = 8.3.00 (07 Feb 2026) = - New – Security Threats Log added to track blocked attacks and malicious requests - Change – Events Log renamed to Logs, now split into User Events and Security Threats - Update – Expanded 7G / 8G Firewall rules to block advanced brute-force attempts, SQL injection, XSS payloads, file inclusion, directory traversal, and automated vulnerability scans before reaching WordPress - Update – Improved threat detection to stop malicious requests before WordPress core execution - Update – Added advanced request pattern analysis to identify and block malicious payloads - Update – Enhanced threat classification to clearly separate blocked attacks from allowed traffic in security logs - Update – Optimized firewall execution path to reduce overhead and improve performance under high attack traffic = 8.2.18 (09 Jan 2026) = - Update – Added the option to Hide Source Map References - Fix – Brute Force compatibility with Elementor Pro on form submit - Fix – Update Google reCaptcha JavaScript to work with Woocommerce Ajax = 8.2.17 (09 Dec 2025) = - Fix – Remove the wp-*.php and admin path from prefetch paths in WP 6.9 - Fix – Small bugs and warnings = 8.2.16 (01 Dec 2025) = - Update – Compatibility with WP 6.9 - Update – 2FA to allow each user to select the 2FA method in the profile - Update – 2FA to connect through passkey and fingerprint - Update – 2FA to trust the current browser = 8.2.14 (22 Aug 2025) = - Update – Firewall rules for more compatibility - Update – Safe URL verification process - Update – Compatibility with the plugin Debloat - Update – Compatibility with WP Social login customization = 8.2.13 (08 July 2025) = - Update – Compatibility with Riode theme on Brute Force protection - Update – Compatibility with WP Engine and added support for Bulk Rewrite Rules - Fix – Plugin update check error message = 8.2.12 (19 June 2025) = - Update – 7G & 8G Firewall for more compatibility with WP Plugin - Update – Compatibility with Kadence Blocks = 8.2.11 (27 May 2025) = - Update – Compatibility with the WP 6.8 - Update – Firewall compatibility with WooCommerce - Update – Add AI support in the plugin settings - Fixed – Function _load_textdomain_just_in_time was called incorrectly - Fixed – Compatibility WooCommerce login/register with reCaptcha V3 = 8.2.10 (11 Apr 2025) = - Update – Compatibility with WordPress version 6.8 - Fix – File security when the rewrite rules are not loaded correctly - Fix – Prevent Brute Force from updating the warning text without space when switched off - Fix – Prevent PHP warning when IP address unknown in Brute Force IP check - Fix – Load i18n on the login page for password-strength-meter messages when the Clean Login option is activated - Fix – Detect if parent theme has caps when child theme is activated - Fix – Dynamic file mapping to load through index.php for better compatibility with all server types = 8.2.04 (07 Mar 2025) = - Update – Add the option to customize all active and inactive themes - Fix – Brute Force error in comments when no recaptcha option is selected - Fix – WP Multisite root directory for custom WP directory installation = 8.2.03 (04 Mar 2025) = - Update – Security update on wp-activate.php path call - Fix – Headers check on Brute Force to get the real IP behind Proxy - Fix – Admin layout issue when other plugins notification is loading in Wp Ghost settings - Fix – Remove newlines from the rewrite rules = 8.2.01 (26 Feb 2025) = - Update – Add Google reCaptcha Enterprise - Update – Increase security on Brute Force feature - Update – Compatibility with Sucuri plugin on Events Log and Brute Force - Update – Add the _HMWP_CONFIG_DIR_ constant to define the config root path - Update – Translations files for the last text changed - Fix – Get the real IP address behind proxy - Fix – Brute Force compatibility with Advanced Pack Magic Login and small bugs - Fix – Include parent theme in the custom theme name list if the child theme is loaded = 8.1.04 (06 Feb 2025) = - Update – New WP Ghost Dashboard design - Update – Login Attempt and Blocked IPs chart in WP Ghost Dashboard - Update – Email Alerts log report in WP Ghost Dashboard - Fix – Paths changed in dynamically loaded CSS and JS files - Fix – Prevent redirecting URLs to hidden paths on config rules issue - Fix – Prevent hiding the wp-admin on config rules issue - Fix – Prevent changing the wp-admin on config rules issue = 8.1.03 (22 Jan 2025) = - Update – Knowledge Base links and responsive layout - Update – GeoIP Country database for Geo-Blocking - Fix – Config update issue when saving the whitelist from Level Of Security = 8.1.02 (14 Jan 2025) = - Update – Added the AI support in the plugin settings page - Update – Remove the help icons for the plugin whitelabel option with custom domain - Fix – Prevent changing the login path in posts slug - Fix – Advanced Pack install domain not found error = 8.1.01 (04 Jan 2025) = - Update – Changed Hide My WP Ghost plugin name with short WP Ghost - Update – WP Ghost comes with a new plugin logo in 2025 - Update – More security on REST API for user listing when User Security is activated - Update – Plugin Security and Firewall rules = 8.0.21 (21 Dec 2024) = - Update – Added gif and tiff to media redirect in Hide WP Common Paths - Update – Allow activating hmwp_manage_settings capability only for a user using Roles & Capabilities plugin - Fix – Layout and improved functionality = 8.0.20 (04 Nov 2024) = - Update – Compatibility with WP 6.7 - Update – Compatibility with LiteSpeed Quic Cloud IP addresses automatically - Fix – Litespeed cache plugin compatibility and set /cache/ls directory by default - Fix – Whitelist website IP address on REST API disable to be able to be accessed by the installed plugins = 8.0.19 (20 Oct 2024) = - Fix – Compatibility with LiteSpeed when CDN is not set - Fix – Change paths when www. prefix exists on the domain = 8.0.17 (12 Oct 2024) = - Update – Compatibility with WP Rocket Background CSS loader - Update – Compatibility with LiteSpeed Cache CDN - Update – Map Litespeed cache directory in URL Mapping - Fix – Remove dynamic CSS and JS when Text Mapping is switched off - Fix – Prevent changing wp-content and wp-includes paths in deep URL location and avoid 404 errors = 8.0.16 (10 Oct 2024) = - Update – Layouts, colors - Update – Added Drupal 11 in CMS simulation - Update – Set 404 Not Found error as default option for hidden paths - Fix – Compatibility with Wordfence Scan - Fix – Changed deprecated PHP functions - Fix – Warnings when domain schema is not identified for the current website - Fix – Redirect to homepage the newadmin when user is not logged in = 8.0.15 (03 Oct 2024) = - Fix – Compatibility with WP 6.6.2 - Fix – Compatibility with Squirrly SEO buffer when other cache plugins are active - Fix – Compatibility with Autoptimize minify = 8.0.14 (07 Sept 2024) = - Update – Added the option to select all Countries in Geo Blocking - Update – Brute Force compatibility with UsersWP plugin - Update – Whitelist path to not check Brute force reCaptcha in case of login whitelist paths = 8.0.13 (23 Aug 2024) = - Update – Added the option to disable Copy & Paste separately - Fix – PHP Error on HMWP_Models_Files due to the not found class - Fix – Small Bugs = 8.0.12 (15 Aug 2024) = - Update – Compatibility with Wordfence = 8.0.11 (14 Aug 2024) = - Update – Plugin security and compatibility with WP 6.6.1 & PHP 8.3 - Update – Adding wp-admin path extensions into firewall when user is not logged in = 8.0.10 (11 Aug 2024) = - Fix – Google reCaptcha on frontend popup to load google header if not already loaded - Fix – Hide New Login Path to allow redirects from custom paths: lost password, signup and disconnect - Fix – WP Multisite active plugins check to ignore inactive plugins - Fix – Small bugs = 8.0.09 (10 Aug 2024) = - Update – Add security preset loading options in Hide My WP > Restore - Fix – Library integrity on the update process - Fix – Cookie domain on WP multisite to redirect to new login path when changing sites from the network - Fix – Brute Force shortcode to work with different login forms = 8.0.07 (01 Aug 2024) = - Fix – Compatibility with WP 6.6 - Fix – Security update on wp-login.php and login.php = 8.0.06 (29 July 2024) = - Update – Compatibility with WordPress 6.5.5 - Update – Added the option to immediately block a wrong username in Brute Force - Update – Sub-option layouts - Fix – File Permission check to receive the correct permissions when is set stronger than required - Fix – Hide login.php path together with wp-login.php path from being redirect to the new login - Fix – Small bugs = 8.0.05 (18 July 2024) = - Update – Added more path in Frontend Test to make sure the settings are okay before confirmation - Fix – Compatibility with Wordfence to not remove the rules from htaccess - Fix – Filter words in 8G Firewall that might be used in article slugs - Fix – Trim error in cookie when main domain cookie is set - Fix – Login header hooks to not remove custom login themes = 8.0.03 (03 July 2024) = - Fix – isPluginActive check error when is_plugin_active is not yet declared - Fix – Disable clicks and keys to work without jQuery - Fix – Compatibility with Wordfence scan process = 8.0.02 (22 June 2024) = - Fix – Show error messages in Temporary login when a user already exists - Fix – Temporary users to work on WP Multisite > Subsites = 8.0.01 (20 June 2024) = - Fix – Login security when Elementor login form is created and Brute Force is active - Fix – Login access when member plugins are used for login process - Fix – Firewall warning on preg_match bot check in firewall.php = 8.0.00 (15 June 2024) = - Update – Added Country Blocking & Geo Security feature - Update – Added Firewall blacklist by User Agent - Update – Added Firewall blacklist by Referrer - Update – Added Firewall blacklist by Hostname - Update – Added ‘Send magic link login’ option in All Users user row actions on Hide My WP Advanced Pack plugin - Update – Added the option to select the level of access for an IP address in whitelist - Removed – Mysql database permission check as WordPress 6.5 handles DB permissions more secure - Moved – Firewall section was moved to the main menu as includes more subsections - Fix – 8G Firewall compatibility with all page builder plugins = 7.3.05 (30 May 2024) = - Update – Compatibility with WPEngine rules on wp-admin and wp-login.php - Update – New Feature added ‘Magic Login URL’ on Hide My WP Advanced Pack plugin - Fix – Prevent firewall to record all triggered filters as fail attempts - Fix – Remove filter on robots when 8G firewall is active - Fix – Frontend Login Check popup to prevent any redirect to admin panel in popup test - Fix – Prevent redirect the wp-admin to new login when wp-admin path is hidden = 7.3.04 (28 May 2024) = - Update – Search option in Hide My WP > Overview > Features - Update – Send Temporary Logins in Events log - Fix – Don’t show Temporary Logins & 2FA in main menu when deactivated = 7.3.03 (22 May 2024) = - Update – 8G Firewall on User Agents filters - Update – Compatibility with WP 6.5.3 - Update – Load the options when white label plugin is installed - Fix – Restore settings error on applying the paths - Fix – Prevent redirect the wp-admin to new login when wp-admin path is hidden = 7.3.01 (17 May 2024) = - Update – Added translation in more languages like Arabic, Spanish, Finnish, French, Italian, Japanese, Dutch, Portuguese, Russian, Chinese - Fix – ‘wp_redirect’ when function is not yet declared in brute force - Fix – ‘wp_get_current_user’ error in events log when function is not yet declared = 7.3.00 (02 May 2024) = - Update – Added the option to detect and fix all WP files and folders permissions in Security Check - Update – Added the option to fix wp_ database prefix in Security Check - Update – Added the option to fix admin username in Security Check - Update – Added the option to fix salt security keys in Security Check - Update – Layout and Fonts to integrate more with WordPress fonts - Update – 7G & 8G firewall compatibility to work with more WP plugins and themes = 7.2.07 (22 Feb 2024)= - Update – Added the option on Apache to insert the firewall rules into htaccess - Fix – Screen 120dpi display layout - Fix – Hide reCaptcha secret key in Settings = 7.2.06 (09 Jan 2024) = - Update – Added the 8G Firewall filter - Update – Added the option to block the theme detectors - Update – Added the option to block theme detectors crawlers by IP & agent - Update – Added compatibility with Local by Flywheel - Update – Firewall loads during WP load process to work on all server types - Fix – Load most firewall filters only in frontend to avoid compatibility issues with analytics plugins in admin dashboard - Fix – Avoid loading recaptcha on Password reset link - Fix – Avoid blocking ajax calls on non-admin users when the Hide wp-admin from non-admin users is activated = 7.2.05 (28 Oct 2023) = - Update – Added the option ot manage/cancel the plan on Hide My WP Cloud - Fix – Custom login path issues on Nginx servers - Fix – Issues when the rules are not added correctly in config file and need to be handled by HMWP - Fix – Don’t change the admin path when ajax path is not changed to avoid ajax errors = 7.2.04 (18 Oct 2023) = - Compatibility with WP 6.5 - Update – Compatibility with CloudPanel & Nginx servers - Fix – Warning in Nginx for $cond variable = 7.2.03 (15 Oct 2023) = - Compatibility with PHP 8.3 & WP 6.4.3 - Update – Compatibility with Hostinger - Update – Compatibility with InstaWP - Update – Compatibility with Solid Security Plugin (ex iThemes Security) - Update – Added the option to block the API call by rest_route param - Update – Added new detectors in the option to block the Theme Detectors - Update – Security Check for valid WP paths - Fix – Don’t load shortcode recapcha for logged users - Fix – Rewrite rules for the custom wp-login path on Cloud Panel and Nginx servers - Fix – Issue on change paths when WP Multisite with Subcategories - Fix – Hide rest_route param when Rest API directory is changed - Fix – Multilanguage support plugins - Fix – Small bugs & typos = 7.2.02 (25 Sept 2023) = - Update – Add shortcode on BruteForce ‘hmwp_bruteforce’ for any login form - Update – Add security schema on ssl websites when changing relative to absolute paths - Update – Compatibility with WP 6.4.2 & PHP 8.3 - Fix – Change the paths in cache files when WP Multisite with Subdirectories - Fix – Small bugs in rewrite rules = 7.2.01 (20 Sept 2023) = - Update – Compatibility with WP 6.4.1 & PHP 8.3 - Update – The Frontend Check to check the valid changed paths - Update – The Security Check to check the plugins updated faster and work without error with Woocommerce update process - Update – Compatibility with Solid Security Plugin (ex iThemes Security) - Update – Hidden wp-admin and wp-login.php on file error due to config issue - Update – Hide rest_route param when Rest API directory is changed - Update – Add emulation for Drupal 10 and Joomla 5 - Fix – Hide error when there are invalid characters in theme/plugins directory name - Fix – Small bugs = 7.2.00 (05 Aug 2023) = - Update – Added the 2FA feature with both Code Scan and Email Code - Update – Added the option to add random number for static files to avoid caching when users are logged to the website - Fix – Added the option to pass the 2FA and Brute Force protection when using the Safe URL - Fix – Tweaks redirect for default path wasn’t saved correctly - Fix – Small Bugs = 7.1.17 (18 July 2023) = - Fix – File extension blocked on wp-includes when WP Common Paths are activated - Fix – Remove hidemywp from file download when the new paths are saved = 7.1.16 (10 July 2023) = - Update – Compatibility with WP 6.3.1 - Update – Compatibility with WPML plugin - Update – Security on Brute Force for the login page - Fix – Small Bugs = 7.1.15 (02 July 2023) = - Update – Compatibility with WP 6.3 - Update – Security Check Report for debugging option when debug display is set to off - Update – Security Check Report for the URLs and files to follow the redirect and check if 404 error = 7.1.13 (30 June 2023) = - Update – Compatibility with more 2FA plugins - Update – Compatibility with ReallySimpleSSL - Fix – Small bugs = 7.1.11 (14 June 2023) = - Update – Compatibility with FlyingPress plugin - Update – Use WordPress function for ajax requests - Fix – Remove infinite loading icon on settings backup action - Fix – Small bugs = 7.1.10 (30 May 2023) = - Update – Compatibility with WP 6.2.2 - Fix – Update checker to work with the latest WordPress version - Fix – Hide wp-login.php path for WP Engine server with PHP 7.0 = 7.1.08 (26 May 2023) = - Update – Added the user role ‘Other’ for unknown user roles - Update – Sync the new login with the Cloud to keep a record of the new login path and safe URL - Update – Compatibility with WP 6.2.2 - Fix – Typos and small bugs = 7.1.07 (19 May 2023) = - Update – Compatibility with WPEngine hosting - Update – Compatibility with WP 6.2.1 - Fix – Loading on defaut ajax and json paths when the paths are customized - Fix – Compatibility issues with Siteground when Ewww plugin is active - Fix – To chnage the Sitegroud cache on Multisite in the background = 7.1.06 (16 May 2023) = - Update – Compatibility with Siteground - Update – Compatibility with Avada when cache plguins are enabled = 7.1.05 (05 May 2023) = - Update – Add compatibility for Cloud Panel servers - Update – Add the option to select the server type if it’s not detected by the server - Fix – Remove the rewrites from WordPress section when the plugin is deactivated - Fix – User roles names display on Tweaks = 7.1.04 (03 May 2023) = - Update – File processing when the rules are not set correctly - Update – Security headers default values - Fix – Compatibilities with the last versions of other plugins - Fix – Reduce resource usage on 404 pages from version 7.1.03 = 7.1.02 (24 Apr 2023) = - Update – Compatibility with other plugins - Update – UI & UX to guide the user into the recommended settings - Update – Compatibility with WP User Manager plugin - Update – Security in Brute force option to work with more plugins - Update – Compatibility with Ewww Image Optimizer plugin CDN option - Fix – Increased plugins speed on compatibility check - Fix – Common paths extensions check in settings = 7.0.15 (04 Apr 2023) = - Update – Add the option to check the frontend and prevent broken layouts on settings save - Update – Brute Force protection on lost password form - Update – Compatibility with MemberPress plugin - Fix – My account link on multisite option = 7.0.14 (23 Mar 2023) = - Update – Compatibility with WP 6.2 - Update – Added the option to whitelist URLs - Update – Added the sub-option to show a white-screen on Inspect Element for desktop - Update – Added the options to hook the whitelisted/blacklisted IPs - Fix – small bugs / typos / UI = 7.0.13 (28 Feb 2023) = - Update – Compatibility with PHP 8 on Security Check = 7.0.12 (20 Feb 2023) = - Compatibile with WP 6.2 - Fix – Handle the physical custom paths for wp-content and uploads set by the site owner - Fix – Compatibility with more plugins and themes = 7.0.11 (26 Ian 2023) = - Update – Remove the atom+xml meta from header - Update – Save all section on backup restore = 7.0.10 (19 Dec 2022) = - Update – Remove the noredirect param if the redirect is fixed - Update – Check the XML and TXT URI by REQUEST_URI to make sure the Sitemap and Robots URLs are identified - Update – Check the rewrite rules on WordPress Automatic updates too - Fix – To remove the version from URL even if the ‘ver’ param doesn’t have any value - Fix – Typo in Security Check = 7.0.05 (22 Nov 2022) = - Update – Fix login path on different backend URL from home URL = 7.0.04 (25 Oct 2022) = - Update – Compatibility with WP 6.1 - Update – Add More security to XML RPC - Update – Add GeoIP flag in Events log to see the IP country - Update – Compatibility with LiteSpeed servers and last version of WordPress = 7.0.03 = - Update – Add the Whitelabel IP option in Security Level and allow the Whitelabel IP addresses to pass login recaptcha and hidden URLs - Fix – Allow self access to hidden paths to avoid cron errors on backup/migration plugins - Fix – White screen on iphone > safari when disable inspect element option is on = 7.0.02 (28 Sept 2022) = - Update – Add the Brute Force protection on Register Form to prevent account spam - Update – Added the option to prioritize the loading of HMWP Ghost plugin for more compatibility with other plugins - Update – Compatibility with LiteSpeed servers and last version of WordPress - Update – Compatibility with FlyingPress by adding the hook for fp_file_path on critical CSS remove process - Fix – Remove the get_site_icon_url hook to avoid any issue on the login page with other themes - Fix – Compatibility with ShortPixel webp extention when Feed Security is enabled - Fix – Fixed the ltrim of null error on PHP 8.1 for site_url() path - Fix – Disable Inspect Element on Mac for S + MAC combination and listen on Inspect Element window = 7.0.01 (12 Sept 2022)= - Update – Added Temporary Login feature - Fix – Not to hide the image on login page when no custom image is set in Appearance > Customize > Site Logo - Update – Compatibility with Nicepage Builder plugin - Update – Compatibility with WP 6.0.2 = 6.0.24 (29 July 2022)= - Update – Add custom emulator/generator name in the website header = 6.0.23 (25 July 2022)= - Update – Compatibility with the last version of Flywheel including Redirects - Fix – Don’t show brute force math error for pages where the Brute Force is not loaded - Fix – Compatibility with Breakdance plugin - Fix – Fixed the ltrim of null error on PHP 8.1 for site_url() path = 6.0.22 (28 June 2022)= - Fix – URL Mapping for Nginx servers to prevent 404 pages - Fix – PHP error in Security Check when the X-Powered-By header is not string - Fix – Compatibility with Wp-Rocket last version = 6.0.21 (21 June 2022)= - Fix – infinite loop in admin panel = 6.0.20 (03 June 2022)= - Update – Compatibility with Coming Soon & Maintenance Mode PRO - Update – New feature added to automatically redirect the logged users to the admin dashboard - Update – Security Check report for minimum PHP version and visible custom login - Fixed the hidden URLs process - Fixed the site_url() and home_url() issue when they are different - Add compatibility with WordPress 6.0 = 6.0.19 (19 May 2022)= - Update – Add compatibility with Elementor Builder plugin for WP Multisite - Update – Tested/Update Compatibilities with more themes and plugins = 6.0.18 (03 May 2022)= - Update – Add compatibility with LiteSpeed webp images - Update – Update Compatibilities - Fix – Small Bugs = 6.0.16 (01 Mar 2022)= - Update – Added compatibility with Backup Guard Plugin - Update – Prevent affecting the cron processes on Wordfence & changing the paths during the cron process - Update – Change the WP-Rocket cache files on all subsites for WP Multisite - Update – Automatically add the CDN URL if WP_CONTENT_URL is set as a different domain - Fixed the Change Paths for Logged Users issue = 6.0.15 (21 Feb 2022)= - Update – Added 7G Firewall option in Hide My WP > Change Paths > Firewall & Headers > Firewall Against Script Injection - Update – Fixed the menu hidden issue when other security plugins are active - Update – Compatibility with Login/Signup Popup plugin when Brute Force Google reCaptcha is activated - Update – Compatibility with Buy Me A Cofee plugin - Update – Automatically add the CDN URL if WP_CONTENT_URL is set as a different domain - Fix – Change Paths for Logged Users issue when cache plugins are installed - Fix – Library loading ID in HMWP Ghost = 6.0.14 (07 Feb 2022)= - Update – Security & Compatibility - Update – Compatibility with Namecheap hosting - Update – Compatibility with Ploi.io - Fix – Removed the ignore option from Nginx notification - Fix – The Security check on install.php and upgrade.php files - Fix – The Restore to default to remove the rules from the config file = 6.0.13 (03 Feb 2022)= - Update – Added new option in Login Security: Hide the language switcher option on the login page - Update – Compatibility with WordPress 5.9 - Update – Compatibility with Coming Soon & Maintenance Mode PRO - Update – Compatibility with Advanced Access Manager (AAM) plugin - Update – Compatibility with WPS Hide Login - Update – Compatibility with JobCareer theme - Fix – Popup issue when Safe Mode or Ghost Mode is selected and other plugins are modifying the bootstrap javascript - Fix – 404 error on WordPress upgrade when access the file upgrade.php for logged users - Fix – Brute Force blocking Wordfence Cron Job = 6.0.12 (10 Ian 2022)= - Update – Compatibility with Smush plugin - Update – Compatibility with WordPress 5.8.3 - Update – Compatibility with Wordfence 2FA when reCaptcha is active - Fix – Infinit loop when POST action on unknown paths = 6.0.11 (08 Dec 2021)= - Update – Added the Ctrl + Shift + C restriction when Inspect Element option is active - Update – Added the features text for translation - Update – Removed the WordPress title tag from login/register pages - Update – Added the option to ignore the notifications and avoid repeating alerts - Fix – Remove the login URL from the logo on the custom login page - Fix – Set Filesystem to direct connection for file management = 6.0.10 (20 Nov 2021)= - Update – Added Permissions-Policy & Referrer-Policy default security headers - Update – Added the option to disable Right-Click for logged users and user roles - Update – Added the option to disable Inspect Element for logged users and user roles - Update – Added the option to disable View Source for logged users and user roles - Update – Added the option to disable Copy/Paste for logged users and user roles - Update – Added the option to disable Drag/Drop for logged users and user roles - Fix – Whitelist and Blacklist error messages in Brute Force when no IP was added - Fix – Typos in HMWP Ghost plugin = 6.0.09 (03 Nov 2021)= - Fix – Remove Sitemap style from Yoast, Rank Math, XML Sitemap on Nginx servers when the option Change Paths in Sitemaps XML is active - Update – Compatibility with Wordfence Security Scan when the wp-admin is hidden - Update – Compatibility with the Temporary Login Without Password plugin to work with the passwordless connection on custom admin - Update – Compatibility with the LoginPress plugin to work with the passwordless connection on custom admin - Update – Compatibility with WordPress Sitemap, Rank Math SEO, SEOPress, XML Sitemaps to hide the paths and style on Nginx servers = 6.0.08 (22 Oct 2021)= - Update – Compatibility with Nitropack - Update – Compatibility with OptimizePress Dashboard - Update – Change the Plugin Name on update check success message - Fix – Compact the frontend scripts for removing right click and keys - Fix – Add links to the Change Paths page from Security Check = 6.0.07 (18 Oct 2021)= - Update – Select the WordPress common files you want to hide - Update – Add the option to block comments that may lead to spam - Update – Removed Plugins Section from Settings - Update – Removed any affiliate links from the plugin - Update – Compatibility with MainWP - Update – Compatibility with Limit Login Attempts Reloaded - Update – Compatibility with Loginizer - Update – Compatibility with Shield Security - Update – Compatibility with iThemes Security - Fix – Login & Logout redirects for Woocommerce - Fix – Don’t show the rewrite alert messages if nothing was changed in HMWP = 6.0.06 (14 Oct 2021)= - Update – Update the White Label options to remove plugin name, and author while the plugin is active - Fix – Added handle when the plugin is not installed correctly - Fix – Avoid changing the cache in the paths like plugins and themes and broke the website = 6.0.05 (6 Oct 2021)= - Update – Add the option to hide the wp-admin path for non-admin users - Update – Advanced Text Mapping to work with Page Builders in admin - Update – Changing the paths in sitemap.xml and robots.txt to work with all SEO plugins - Update – Translate the plugin in more languages - Update – Select the cache directory if there is a custom cache directory set in the cache plugin - Update – Show the change in cache files option for more cache plugins - Fix – Showing the old paths on unfound files - Fix – Not load the Click Disable while editing with Page Builders = 6.0.04 (1 Oct 2021)= - Update – Use WordPress filesystem for all file actions - Fix – Rewrite built on custom register and lostpassword path - Fix – wp_ previx detection in Website Security Check - Fix – plugin typos & translations = 6.0.03 (28 Sept 2021)= - Update – Added compatibility with JCH Optimize 3 plugin - Update – Added compatibility with Oxygen 3.8 plugin - Update – Added compatibility with WP Bakery plugin - Update – Added compatibility with Bunny CDN plugin - Update – Update compatibility with Manage WP plugin - Update – Update compatibility with Autoptimize plugin - Update – Update compatibility with Breeze plugin - Update – Update compatibility with Cache Enabler plugin - Update – Update compatibility with CDN Enabler plugin - Update – Update compatibility with Comet Cache plugin - Update – Update compatibility with Hummingbird plugin - Update – Update compatibility with Hyper Cache plugin - Update – Update compatibility with Litespeed Cache plugin - Update – Update compatibility with Power Cache plugin - Update – Update compatibility with W3 Total Cache plugin - Update – Update compatibility with WP Fastest Cache plugin - Update – Update compatibility with iThemes plugin - Update – Added compatibility with Hummingbird Performance plugin - Fix – Small Bugs = 6.0.02 (21 Sept 2021)= - Update – A new UI for Hide My WP Ghost - Update – Added new features in the plugin - Update – Compatibility with other plugins ** Tagged: **[changelog](https://wpghost.com/kb/tag/changelog/)[plugin changes](https://wpghost.com/kb/tag/plugin-changes/) --- # Page: WP Ghost Error Troubleshooting Fix Common WordPress Issues URL: https://wpghost.com/kb/category/errors/ Section: Knowledge Base › Errors Last-Updated: 2026-08-18 Language: en-US Description: Fix 404 errors, redirect loops, broken login, frontend not loading, style issues, and other common WP Ghost errors. Step-by-step troubleshooting and recovery guides. ### WP Ghost Paths Not Working? Ghost Doctor Finds the Cause and Repairs It Site broken after hiding WordPress paths? Ghost Doctor in WP Ghost 9.0.13 tests your live site, repairs what a plugin can, reverts what did not help. [Read More →](https://wpghost.com/kb/wp-ghost-paths-not-working-ghost-doctor/) ### CONNECTION ERROR! Make sure your website can access account.wpghost.com This error indicates that your WordPress website is unable to connect to the WP Ghost Cloud servers. The most common reason is a firewall or server restriction imposed by your hosting provider, which prevents your website from communicating with third-party APIs [Read More →](https://wpghost.com/kb/connection-error-make-sure-your-website-can-access-https-account-wpghost-com/) ### Cache Plugins Not Minifying CSS and JS Files If your cache plugin (WP Rocket, Autoptimize, LiteSpeed Cache, W3 Total Cache, etc.) stops minifying or combining CSS and JS files when WP Ghost is active, the cache plugin can’t access the original file paths because WP Ghost has changed them. The cache plugin tries to fetch files from the new custom paths, fails to […] [Read More →](https://wpghost.com/kb/cache-plugins-not-minifying-css-and-js-files/) ### The New Admin Path Is Redirected To Front Page When Logged In If you’re logged in as an administrator but the custom admin path still redirects to the homepage, the browser session wasn’t established on the new path. WP Ghost creates sessions on both the default and custom admin paths when you log in. If the session creation fails (due to server config or plugin conflicts), WordPress […] [Read More →](https://wpghost.com/kb/new-admin-path-redirects-to-front-page-when-logged-in/) ### The New Admin Path Is Redirected To Front Page If your custom admin path (the one you set to replace wp-admin) redirects to the homepage when you’re not logged in, the Hide the New Admin Path option is active. This option hides the custom admin path from non-logged-in users, so accessing it before logging in redirects to the front page. Use the custom login […] [Read More →](https://wpghost.com/kb/the-new-admin-path-is-redirected-to-front-page/) ### Why Has Elementor Stopped Working with WP Ghost Safe or Ghost Mode? Elementor relies on the REST API, admin-ajax.php, and the wp-admin path to load its editor. When WP Ghost changes these paths in Safe Mode or Ghost Mode, Elementor may lose access to them if your server configuration, cache, or other settings are not updated to match. Here is how to fix it step by step. […] [Read More →](https://wpghost.com/kb/elementor-stopped-working-after-changing-paths/) ### The Paths Are Not Changed in Frontend After Activating this Option If you’ve activated path changes in WP Ghost but the frontend still shows original WordPress paths (like /wp-content/ or /wp-includes/), the changes aren’t being applied. Work through these checks. Clear all caches This is the most common cause. Your cache plugin is serving a cached version of the page from before the path changes. Clear […] [Read More →](https://wpghost.com/kb/the-paths-are-not-changed-in-frontend-after-activating-this-option/) ### Temporary Login URL is Redirecting to the Home Page If clicking a temporary login URL redirects to the homepage instead of logging the user in, the session is being interrupted before authentication completes. Check these causes in order. Clear all caches Clear your WordPress cache plugin, CDN cache, and browser cache. Cached redirects or stale page versions can intercept the temporary login URL before […] [Read More →](https://wpghost.com/kb/temporary-login-url-is-redirecting-to-the-home-page/) ### Plugin or Theme Conflicts If something breaks after activating WP Ghost, the issue is likely a conflict with another plugin or your theme. Follow this process to isolate the conflict. Deactivate other plugins one by one Deactivate all plugins except WP Ghost. If the issue disappears, reactivate plugins one at a time, testing after each one. The plugin that […] [Read More →](https://wpghost.com/kb/plugin-or-theme-conflicts/) ### Cannot Access the Login Page After Changing Wp-Login Path If you can’t reach the login page or see errors after changing the login path in WP Ghost, work through these checks. Clear all caches Changing the login path alters URL structures that cache plugins and server caches store. Clear your WordPress cache plugin (WP Rocket, LiteSpeed Cache, W3 Total Cache, etc.), your CDN cache […] [Read More →](https://wpghost.com/kb/cannot-access-the-login-page-after-changing-wp-login-path/)[Older Entries →](https://wpghost.com/kb/category/errors/page/2/) --- # Page: WP Ghost Plugin Compatibility WooCommerce, Elementor, More URL: https://wpghost.com/kb/category/compatibility/plugins/ Section: Knowledge Base › Compatibility Last-Updated: 2026-06-25 Language: en-US Description: Configure WP Ghost with WooCommerce, Elementor, Wordfence, Sucuri, Solid Security, WP Rocket, LiteSpeed Cache, Cloudflare, and 50+ popular WordPress plugins. ### WP Ghost and LiteSpeed Cache Setup Guide If you want to optimize your WordPress website’s performance, LiteSpeed is a great plugin to help you achieve that. The best part is that it’s compatible with WP Ghost, allowing you to keep your website secure while improving its speed. [Read More →](https://wpghost.com/kb/wp-ghost-and-litespeed-cache/) ### WP Ghost and WP Security Ninja Compatibility Use WP Ghost with WP Security Ninja for prevention plus vulnerability testing. Path security and firewall in WP Ghost; 50+ security tests and scanning in Ninja. [Read More →](https://wpghost.com/kb/wp-ghost-and-wp-security-ninja/) ### Add Brute Force Protection to Elementor Login Forms Add reCAPTCHA brute force protection to Elementor login forms using WP Ghost’s [hmwp_bruteforce] shortcode. Works with Divi and other page builders too. [Read More →](https://wpghost.com/kb/integrating-brute-force-protection-in-elementor-login-forms/) ### WP Ghost and Hummingbird Cache Plugin Setup Configure WP Ghost with Hummingbird cache. Change cache directory, enable minification, and turn on Change Paths in Cache Files for full WordPress path security. [Read More →](https://wpghost.com/kb/wp-ghost-and-hummingbird-cache-plugin/) ### WP Ghost and Breeze Cache Plugin Setup Guide Configure WP Ghost with Breeze cache by Cloudways. Enable minification, exclude custom paths from caching, turn on Change Paths in Cache Files. Step-by-step. [Read More →](https://wpghost.com/kb/wp-ghost-and-breeze-cache-plugin/) ### WP Ghost and SiteGround Security Compatibility Use WP Ghost with SiteGround Security for layered WordPress protection. Path security, firewall, 2FA in WP Ghost; activity logging and post-hack tools in SG. [Read More →](https://wpghost.com/kb/wp-ghost-and-siteground-security/) ### WP Ghost and WP Cerber Security Compatibility Use WP Ghost with WP Cerber Security for layered WordPress protection. Path security, firewall, 2FA in WP Ghost; malware scanning and anti-spam in Cerber. [Read More →](https://wpghost.com/kb/wp-ghost-and-wp-cerber-security/) ### WP Ghost and BBQ Firewall Compatibility Guide Use WP Ghost with BBQ Firewall (Block Bad Queries) for layered WordPress security. Comprehensive path security and firewall in WP Ghost; pattern filter in BBQ. [Read More →](https://wpghost.com/kb/wp-ghost-and-bbq-firewall/) ### WP Ghost and Sucuri Security Compatibility Together with the Sucuri Security plugin, it will boost your website security by stopping hacker bot attacks, spammers, and viruses and preventing data loss. [Read More →](https://wpghost.com/kb/wp-ghost-and-sucuri-security/) ### WP Ghost and Anti-Malware Security Compatibility Use WP Ghost with Anti-Malware Security (GOTMLS) for prevention plus detection. Path security and firewall in WP Ghost; malware scanning and cleanup in GOTMLS. [Read More →](https://wpghost.com/kb/hide-my-wp-ghost-with-anti-malware-security/)[Older Entries →](https://wpghost.com/kb/category/compatibility/plugins/page/2/) #### Company - [Media Kit](https://drive.google.com/drive/folders/1J1ebjPhZCDuycBFP3lB_7_wTxBlgpmdc?usp=sharing) --- # Page: WP Ghost Compatibility Plugins, Themes, Servers, Hostings URL: https://wpghost.com/kb/category/compatibility/ Section: Knowledge Base › Compatibility Last-Updated: 2026-06-25 Language: en-US Description: WP Ghost compatibility with WooCommerce, Elementor, Wordfence, Cloudflare, Nginx, LiteSpeed, Kinsta, WP Engine, SiteGround, and 50+ other plugins and platforms. #### Company - [Media Kit](https://drive.google.com/drive/folders/1J1ebjPhZCDuycBFP3lB_7_wTxBlgpmdc?usp=sharing)