Security Ninja – Secure Firewall & Secure Malware Scanner

Security Ninja – Secure Firewall & Secure Malware Scanner

Wordpress plugin

Install on Wordpress

App Details

This plugin can be downloaded for free without any paid subscription from the official WordPress repository.

Get started in minutes:

For over a decade, Security Ninja has been the guardian of thousands of websites, empowering site owners like you to navigate the digital space with confidence. Instantly run 50+ security tests to uncover hidden issues, ensuring your website’s integrity and security. Embrace Ninja’s simplicity and ease of use to fortify your site’s defenses effortlessly.

Enhanced Vulnerability Scanner
Stay Ahead of Threats: Our vulnerability scanner proactively alerts you to known vulnerabilities, allowing you to address potential threats before they exploit your website.
Comprehensive Protection: Security Ninja not only checks and warns for common issues but also checks for known vulnerabilities in plugins and themes.
Peace of Mind: Knowing your site is monitored for the latest vulnerabilities means you can focus on what matters most—growing your business and creating content, worry-free.

Join thousands of satisfied users who trust Security Ninja to keep their websites safe. Start protecting your online presence today and help yourself to peace of mind.

Extensions

  • MainWP – The MainWP Dashboard allows administrators to manage many WordPress websites from a central location.

Install the FREE Security Ninja for MainWP Extension to get an overview of all websites you have installed Security Ninja on!

Security Ninja For MainWP

Security Tests for your website

Security Ninja – Your WordPress Guardian

Key Features

  • Immediate Vulnerability Alerts: Get instant notifications about vulnerabilities to keep your website safe and secure.

  • Comprehensive One-click Security Audit: With just one click, perform over 50+ detailed security checks that scrutinize every corner of your site for security vulnerabilities and performance issues.

  • You’re in Command: Security Ninja respects your autonomy, providing insights and recommendations without making unsolicited changes to your site.

  • Holistic Security Evaluation: Comprehensive checks on everything from the WordPress core, plugins, and themes to ensure they are up-to-date and secure.

  • Proactive Defense Strategies: Equip yourself with the tools and knowledge to prevent attacks before they happen, safeguarding your site from potential threats.

  • Optimization Beyond Security: Improve your site’s performance with database optimization tips, ensuring a seamless experience for your users.

  • Knowledge Empowerment: Each test comes with an easy-to-understand explanation, documentation, and actionable steps to fix identified issues.

  • Customized Security Insights: Tailored security assessments to check critical updates and configurations specific to your WordPress setup for a personalized protection strategy.

  • Future-Proof Your Site: Stay ahead with tests that include the latest WordPress features and best practices for site security.

  • Prevent Unauthorized Access: Strengthen your defenses with checks designed to prevent weak passwords and unauthorized file access.

  • Secure Configuration Checks: Ensure your website is configured according to security best practices, from file permissions to security headers, for comprehensive protection against threats.

Enhance your website’s security, performance, and user experience with Security Ninja – your trusted partner in WordPress protection.

Security Ninja Pro has extra features: Firewall, Block Suspicious Page Requests, Country Blocking, Core Scanner, Malware Scanner, Auto Fixer for some of the tests, Events Logger & Scheduled Scans.

An all-in-one security solution for any site. With premium support and continuous updates Security Ninja Pro is a perfect tool to keep your site safe. See what the PRO version offers

Automatically block 600+ million bad IPs with one click! Security Ninja Pro Firewall will help you stay one step ahead of bad guys by using the collective know-how of millions of attacked sites, and ban bad guys before they even open your site.

Read more about Pro features on the Security Ninja website

What others say about the plugin

Tests
* The tests include:
* brute-force attack on user accounts to test password strength
* numerous installation parameters tests
* file permissions
* version hiding
* 0-day exploits tests
* debug and auto-update modes tests
* database configuration tests
* Apache and PHP related tests
* WP options tests

  • Complete list of tests:
    • Check if Application Passwords feature is enabled (new to WP 5.6)
    • Check if WordPress core is up to date
    • Check if automatic WordPress core updates are enabled
    • Check if plugins are up to date
    • Check if there are deactivated plugins
    • Check if active plugins have been updated in the last 12 months
    • Check if active plugins are compatible with your version of WP
    • Check if themes are up to date
    • Check if there are any deactivated themes
    • Check if full WordPress version info is revealed in page’s meta data
    • Check if readme.html file is accessible via HTTP on the default location
    • Check if license.txt file is accessible via HTTP on the default location
    • Check if REST API links are displayed in page’s meta data
    • Check the PHP version is up to date
    • Check the MySQL version
    • Check if server response headers contain detailed PHP version info
    • Check if expose_php PHP directive is turned off
    • Check if user with username “admin” and administrator privileges exists
    • Check if “anyone can register” option is enabled
    • Check user’s password strength with a brute-force attack
    • Check for display of unnecessary information on failed login attempts
    • Check if database table prefix is the default one
    • Check if security keys and salts have proper values
    • Check the age of security keys and salts
    • Test the strength of WordPress database password
    • Check if general debug mode is enabled
    • Check if the debug.log file exists
    • Check if database debug mode is enabled
    • Check if JavaScript debug mode is enabled
    • Check if display_errors PHP directive is turned off
    • Check if WordPress installation address is the same as the site address
    • Check if wp-config.php file has the right permissions (chmod) set
    • Check if install.php file is accessible via HTTP on the default location
    • Check if upgrade.php file is accessible via HTTP on the default location
    • Check if register_globals PHP directive is turned off
    • Check if PHP safe mode is disabled
    • Check if allow_url_include PHP directive is turned off
    • Check if plugins/themes file editor is enabled
    • Check if uploads folder is browsable by browsers
    • Test if user with ID 1 and administrator role exists
    • Check if Windows Live Writer link is present in pages’ header data
    • Check if wp-config.php is present on the default location
    • Check if MySQL server is connectable from outside with the WP user
    • Check if EditURI link is present in pages’ header data
    • Check if TimThumb script is used in the active theme
    • Check if the server is vulnerable to the Shellshock bug #6271
    • Check if the server is vulnerable to the Shellshock bug #7169
    • Check if admin interface is delivered via SSL
    • Check if MySQL account used by WordPress has too many permissions
    • Test if a list of usernames can be fetched by looping through user IDs on http://siteurl.com/?author={ID}
    • Check if server response headers contain Strict-Transport-Security
    • Check if server response headers contain X-Frame-Options
    • Check if server response headers contain X-Content-Type-Options
    • Check if server response headers contain Content-Security-Policy
    • Check if server response headers contain Strict-Transport-Security
    • Check if server response headers contain Referrer-Policy
    • Check if server response headers contain Feature-Policy
    • Check for unwanted files in your root folder you should remove

License info

How can I report security bugs?

You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability.

Pricing

Starting from $0 per month.

Check Out the eBay Reviews Widget

By Common Ninja

eBay ReviewsTry For Free!

App Info

Rating

Reviewers

94 reviews

Tags

firewall
login
malware
security
virus

Developed By

Lars Koudal

Quick & Easy

Find the Best Wordpress plugins for you

Common Ninja has a large selection of powerful Wordpress plugins that are easy to use, fully customizable, mobile-friendly and rich with features — so be sure to check them out!

Testimonial

Testimonial plugins for Wordpress

Galleries

Galleries plugins for Wordpress

SEO

SEO plugins for Wordpress

Contact Form

Contact Form plugins for Wordpress

Forms

Forms plugins for Wordpress

Social Feeds

Social Feeds plugins for Wordpress

Social Sharing

Social Sharing plugins for Wordpress

Events Calendar

Events Calendar plugins for Wordpress

Sliders

Sliders plugins for Wordpress

Analytics

Analytics plugins for Wordpress

Reviews

Reviews plugins for Wordpress

Comments

Comments plugins for Wordpress

Portfolio

Portfolio plugins for Wordpress

Maps

Maps plugins for Wordpress

Security

Security plugins for Wordpress

Translation

Translation plugins for Wordpress

Ads

Ads plugins for Wordpress

Video Player

Video Player plugins for Wordpress

Music Player

Music Player plugins for Wordpress

Backup

Backup plugins for Wordpress

Privacy

Privacy plugins for Wordpress

Optimize

Optimize plugins for Wordpress

Chat

Chat plugins for Wordpress

Countdown

Countdown plugins for Wordpress

Email Marketing

Email Marketing plugins for Wordpress

Tabs

Tabs plugins for Wordpress

Membership

Membership plugins for Wordpress

popup

popup plugins for Wordpress

SiteMap

SiteMap plugins for Wordpress

Payment

Payment plugins for Wordpress

Coming Soon

Coming Soon plugins for Wordpress

Ecommerce

Ecommerce plugins for Wordpress

Customer Support

Customer Support plugins for Wordpress

Inventory

Inventory plugins for Wordpress

Video Player

Video Player plugins for Wordpress

Testimonials

Testimonials plugins for Wordpress

Tabs

Tabs plugins for Wordpress

Social Sharing

Social Sharing plugins for Wordpress

Social Feeds

Social Feeds plugins for Wordpress

Slider

Slider plugins for Wordpress

Reviews

Reviews plugins for Wordpress

Portfolio

Portfolio plugins for Wordpress

Membership

Membership plugins for Wordpress

Forms

Forms plugins for Wordpress

Events Calendar

Events Calendar plugins for Wordpress

Contact

Contact plugins for Wordpress

Comments

Comments plugins for Wordpress

Analytics

Analytics plugins for Wordpress

More plugins

plugins You Might Like

Discover Apps By Platform

Discover the best apps for your website

WordPress
Wix
Shopify
Weebly
Webflow
Joomla
PrestaShop
Shift4Shop
WebsiteX5
MODX
Opencart
NopCommerce

Common Ninja Search Engine

The Common Ninja Search Engine platform helps website builders find the best site widgets, apps, plugins, tools, add-ons, and extensions! Compatible with all major website building platforms - big or small - and updated regularly, our Search Engine tool provides you with the business tools your site needs!

Multiple platforms