WordPress security, explained

Know what is looking.
Know what changed.

DecoyNest is a detection and evidence stack built around the way WordPress is actually attacked — predictable paths, vulnerable extensions, stolen credentials and persistence hidden outside the normal admin screens.

40%
The platform is not obscure. It is predictable.

Small sites are scanned for the same reason large ones are.

WordPress runs roughly 40% of the web, and each installation exposes familiar paths. Automated tooling can identify plugins, test login surfaces and look for disclosed flaws without knowing anything about the organisation behind the domain.

Where the risk sits

Most disclosed WordPress vulnerabilities are in the extension ecosystem, not core. The practical risk is the collection of plugins and themes layered on top.

The complete stack

Fifteen functions. One connected view.

Detection first, then context, evidence and recovery. Select a function to jump to the full explanation.

01Free

Honeypot sensors

Reconnaissance starts before exploitation. Automated scanners map plugin paths, admin panels and XML-RPC long before anyone tries to break in.

What it does

Places convincing decoys around the site: a login path that is not real, readme files for plugins you do not run and a watched XML-RPC endpoint. Real visitors never encounter them; anything that does has gone looking.

Why WordPress specifically

WordPress paths are identical across sites, so fingerprinting is cheap and automatic. Decoys work because the attacker’s script requests a standard list without knowing which paths are genuine.

What it does not do

It detects and records; it does not block. Use it alongside a firewall, not instead of one.

Who needs it most

Anyone who wants warning while an attacker is still mapping the site, before something breaks.

Back to all functions ↑
02Free

Attack correlation

A vulnerability list tells you what might be exploitable. A probe for a plugin you actually run says someone is checking your site now.

A scanner says a flaw exists. Correlation says someone is looking for it on your site.

What it does

Connects what an attacker was hunting for to what is installed and alerts when those facts overlap. It turns their reconnaissance into your prioritised warning.

Why WordPress specifically

Public vulnerability disclosures are rapidly converted into mass scans. Correlation closes the gap by combining probe evidence with the site’s real plugin inventory.

What it does not do

It does not update plugins automatically. An attack signal informs the decision; it should not trigger an unattended production change.

Who needs it most

Sites running third-party plugins, especially plugins with a history of critical vulnerabilities.

Back to all functions ↑
03Free

Two-factor authentication

Password reuse, credential stuffing and brute force make a password-only administrator account fragile.

What it does

Requires a time-based authenticator code as well as the password, with per-role enforcement, rollout grace periods and single-use backup codes.

Why WordPress specifically

The login URL is predictable and usernames are often discoverable. XML-RPC can also bundle many authentication attempts into one request.

What it does not do

It protects login. It cannot stop an attacker entering through vulnerable plugin code.

Who needs it most

Every site with an administrator account, especially sites managed by more than one person.

Back to all functions ↑
04Free

Single sign-on

Separate WordPress passwords create sprawl, and accounts often remain active long after a person leaves an organisation.

What it does

Lets verified users sign in with Microsoft 365, Google Workspace or GitHub, scoped to the organisation’s tenant and still protected by two-factor authentication.

Why WordPress specifically

WordPress accounts are an identity island by default. The marketing site can remain outside the directory controls used everywhere else.

What it does not do

It does not migrate existing accounts automatically. Local login remains as a deliberate fallback during an identity-provider outage.

Who needs it most

Organisations with managed identity and agencies that administer client sites.

Back to all functions ↑
05Free

Firewall rules

Public admin endpoints attract automated traffic from places that have no legitimate reason to reach them.

What it does

Adds IP allow and block lists with CIDR support, country rules, login rate limiting, REST API restrictions and XML-RPC control.

Why WordPress specifically

Every installation exposes the same login and admin paths. XML-RPC multicall can pack hundreds of login attempts into a single HTTP request.

What it does not do

Rules run inside WordPress, after traffic reaches the server. Geoblocking reduces noise but does not stop a determined attacker using a VPN.

Who needs it most

Sites whose administrators sign in from predictable networks or countries.

Back to all functions ↑
06Free

Vulnerability scanner

Known plugin flaws remain one of the cheapest and most common ways to compromise a WordPress site.

What it does

Inventories WordPress core, plugins and themes, checks known vulnerabilities, reports severity and shows the version containing the fix.

Why WordPress specifically

A typical site combines many plugins from authors with different maintenance standards. Tracking all versions and advisories manually does not scale.

What it does not do

It reports rather than patches. It cannot detect an undisclosed flaw and version checks cannot prove that local files were not modified.

Who needs it most

Anyone running plugins or themes they did not write and audit themselves.

Back to all functions ↑
07Free

Hardening score

WordPress defaults are designed to make setup easy, not to minimise every production attack surface.

What it does

Runs twenty configuration checks, produces one understandable score and gives a specific fix for each failed check.

Why WordPress specifically

Features such as the file editor, public user enumeration, open registration and XML-RPC are useful in some environments and risky in others.

What it does not do

It never applies changes on its own. Several hardening choices can break workflows or lock out administrators if used carelessly.

Who needs it most

Sites configured once and then left alone, and teams that need a simple view of whether security is improving.

Back to all functions ↑
08Free

Audit log

After a suspicious change, WordPress alone cannot reliably answer who did it, when it happened or where the session came from.

What it does

Records security-relevant administration: new admins, role changes, plugin and theme changes, settings updates and built-in file edits.

Why WordPress specifically

Core keeps no complete administrative audit trail, even though a new administrator or edited file is a common persistence method.

What it does not do

It records administrative security actions, not every page view or every content edit. WordPress revisions remain the source for content history.

Who needs it most

Multi-admin sites, agencies and organisations with NIS2, ISO 27001 or other evidence requirements.

Back to all functions ↑
09Free

Security headers

Cross-site scripting, clickjacking and protocol downgrade attacks execute in the visitor’s browser, beyond ordinary server-side controls.

What it does

Sends CSP with report-only rollout, HSTS, frame options, referrer policy and permissions policy directly through WordPress.

Why WordPress specifically

Advice to edit .htaccess does not work on every nginx or LiteSpeed host. Applying headers through WordPress is server-independent.

What it does not do

Browsers enforce headers, not the server. A strict CSP can break themes with inline code, so report-only mode should be used first.

Who needs it most

Sites handling logins or payments and anyone preparing for a security assessment.

Back to all functions ↑
10Free

File integrity monitoring

A compromise commonly leaves a backdoor: a new PHP file in uploads or malicious code appended to a legitimate theme or plugin.

What it does

Checks core, plugins and themes against official checksums, hashes everything else, and reports files that changed, appeared or should not exist.

Why WordPress specifically

WordPress.org publishes canonical checksums for core and hosted extensions. A PHP file in uploads is an especially strong warning signal.

What it does not do

It never deletes or quarantines. A baseline taken after a compromise cannot prove that an unverified file was safe beforehand.

Who needs it most

Sites investigating compromise and sites using commercial or custom plugins without public checksums.

Back to all functions ↑
11Free

Persistence surface checks

Attackers hide in places the normal plugins screen does not show, allowing a cleaned site to be reinfected.

What it does

Inspects scheduled tasks, must-use plugins, drop-ins, dormant administrators and modified .htaccess files.

Why WordPress specifically

MU plugins load automatically and cannot be deactivated; drop-ins execute early; cron tasks can recreate a deleted backdoor every few minutes.

What it does not do

It reports and explains rather than removes. A legitimate cron entry can look much like a malicious one.

Who needs it most

Anyone previously compromised or dealing with reinfection after cleanup.

Back to all functions ↑
12Free

Tamper-evident logging

An attacker with database access can edit or delete the same local log that records their activity.

What it does

Chains each log entry to the one before it. Removing or altering a row breaks the chain and reveals where the record became incomplete.

Why WordPress specifically

The evidence and the site it describes live behind the same credentials. Local logs cannot be made truly untouchable.

What it does not do

It is tamper-evident, not tamper-proof. Genuine resistance requires sending events off the compromised machine.

Who needs it most

Organisations that may need credible evidence for incident response, an insurer or a regulator.

Back to all functions ↑
13Free

Forensic export

Incident response loses hours assembling conflicting timelines from different tools when answers are needed quickly.

It is free because it is your evidence, from your database, when you need it most.

What it does

Builds one archive containing a merged timeline, authentication history, integrity findings, persistence checks, honeypot activity and log-chain verification in human- and machine-readable formats.

Why WordPress specifically

Evidence is normally scattered across plugins with different timestamps and retention. The export assembles context before it is handed to a responder.

What it does not do

It presents evidence; it does not declare that a compromise occurred. Broken chains and truncated retention are explicitly identified.

Who needs it most

Anyone handing an incident to another person or working to NIS2 reporting timelines.

Back to all functions ↑
14Pro

Encrypted backups

A backup can rescue a damaged site, but an unencrypted database dump in cloud storage can become a breach of its own.

Your cloud. Your encryption key. DecoyNest never takes custody of the backup.

What it does

Schedules database and file backups, encrypts them on your server, then keeps them locally or sends them to your Google Drive, OneDrive or Dropbox.

Why WordPress specifically

A backup can contain users, password hashes and, for WooCommerce, names, addresses and order histories. Encryption happens before it leaves the site.

What it does not do

If the passphrase is lost, neither you nor DecoyNest can recover the archive. Store it away from the site and test a restore before relying on any backup.

Who needs it most

Anyone whose site earns money or would be difficult to rebuild from scratch.

Back to all functions ↑
15Pro

Microsoft Sentinel integration

WordPress is often the one externally reachable production system whose security dashboard is invisible to the SOC.

Events leave the site as they happen, beyond the reach of an attacker who later compromises WordPress.

What it does

Streams honeypot and audit events into an Azure Log Analytics custom table through the Logs Ingestion API, with sample analytics rules, a workbook, CEF and Syslog export.

Why WordPress specifically

The marketing site may be hosted and managed outside the monitored estate even while it provides attackers with an internet-facing foothold.

What it does not do

It sends evidence; it does not analyse it for you. Setup requires an Azure App Registration and a data collection rule.

Who needs it most

Organisations already operating a SIEM. If you do not have one, this feature is not intended for you.

Back to all functions ↑
Start with evidence

The detection stack is free.

Install it on unlimited sites. No account required for local protection.