The only WordPress security plugin you’ll ever need to install

Stop juggling 8 different security plugins. Midnay Security Central puts login protection, 2FA, a firewall, activity logging, and more into one clean dashboard.

10

Security Modules

80+

Individual Controls

1

Plugin Install

$0

Forever Free

Everything you need, in one install

  • Brute-Force Protection
  • Two-Factor Authentication
  • Audit Logging
  • Web Application Firewall
  • HTTP Security Headers
  • Session Management
  • File Integrity Monitoring
  • Security Scanning

Brute-Force & Login Protection

Stop password attacks
before they get in

Most WordPress sites absorb hundreds of automated login attempts every day without you ever knowing. Midnay locks out attackers by IP after repeated failures, adds CAPTCHA to every login entry point, and gives you a real-time view of what’s happening.

  • Attackers get locked out after repeated failures, and you choose the exact threshold
  • Cloudflare Turnstile and Google reCAPTCHA stop bots before they reach your login form
  • Your own IP stays safe from lockouts, even when you mistype your password repeatedly
  • Every login attempt is logged clearly, so you can review successful, failed, and blocked access
lock-icon

Login Protection

Active lockout monitoring

Lockouts in last 24h

24

CAPTCHA provider

Cloudflare Turnstile

Max attempts before lockout

5

Lockout duration

30 min

Admin email on lockout

check-green

Two-Factor Authentication

A stolen password
still isn’t enough to get in

Even if a password is compromised, MFA means the attacker still can’t log in. Midnay supports biometric passkeys, authenticator apps, and email codes – all from the same settings page, enforced per user role.

  • Users can sign in with Face ID, Touch ID, or Windows Hello without any extra app
  • Works with Google Authenticator, Authy, 1Password, and other TOTP apps your team already uses
  • Require MFA only for admins and editors, while leaving lower-risk user roles untouched
  • Trusted devices can skip repeated verification, so your team is not slowed down every day
lock-icon

Multi-Factor Authentication

Enrollment by role

Biometric passkeys (Face ID / Touch ID)

check-green

Authenticator app (TOTP)

check-green

Email OTP

check-green

Per-role enforcement

check-green

Trusted device memory

check-green

Admin reset per user

check-green

Audit Logging & Activity Monitoring

Know exactly what happened
and who did it

When something goes wrong on a WordPress site – a post disappears, a plugin gets deactivated, a user’s role changes – you need to know who did it and when. Midnay’s activity log captures it all, permanently.

  • Every user action is logged, including logins, content changes, plugin installs, and settings edits
  • See exactly what changed with the old value and new value shown side by side
  • Get an email as soon as a critical event happens, even before you open the dashboard
  • WooCommerce orders, coupons, and product changes are tracked, not just WordPress core events
lock-icon

Activity Log

Recent events

⬤ CRITICAL  admin password changed

2m ago

⬤ WARNING  plugin deactivated: akismet

11m ago

⬤ INFO  user logged in: editor@site.com

23m ago

⬤ INFO post published: “Q2 Review”

1h ago

Retention period

90 days

Export (CSV & HTML)

check-green

Everything above is free.  No trial period, no premium tier to unlock, no credit card. Just install and turn on what you need.

Web Application Firewall

Block bad traffic before WordPress even loads

Most attacks never reach a vulnerable plugin – they’re caught at the door. Midnay’s WAF inspects every request before WordPress boots, blocking SQL injection, XSS, path traversal, and bad bots with no server configuration required.

  • Start in monitor mode first, then switch to block mode when you are ready
  • Unknown bots are blocked automatically, reducing spam, scraping, and noisy traffic at the source
  • Rate limits stop any one IP from hammering your server and overwhelming site resources
  • Every blocked request is logged with the IP, URL, and the rule that triggered it
lock-icon

WAF Lite

Request firewall

Mode

Blocking

Requests blocked today

37

SQL injection detection

check-green

Per-role enforcement

check-green

Trusted device memory

check-green

Admin reset per user

120 req/min

HTTP Security Headers

Harden your site’s defences without touching a config file

Security headers tell browsers how to behave when loading your site – blocking clickjacking, stopping MIME sniffing, enforcing HTTPS. Normally you’d need server access to set them. With Midnay, it’s a toggle in the WordPress admin.

  • Prevent your site from loading inside iframes on other domains, which helps stop phishing tricks
  • Force browsers to use HTTPS automatically, even when a visitor types the older HTTP version
  • Hide your WordPress version from the source code, which reduces easy targeting by attackers
  • Load sensible defaults instantly, without researching every security header one by one
lock-icon

Security Headers

HTTP response header status

Clickjacking protection (X-Frame-Options)

check-green

MIME sniffing prevention

check-green

HTTPS enforcement (HSTS)

check-green

Referrer-Policy

check-green

WP version hidden from source

check-green

Content Security Policy

Configured

Session Management

See every active login. Revoke any of them instantly.

Shared hosting accounts, former employees, or a device you’re not sure about – Midnay shows every active session on your site with the IP, browser, and last activity, and lets you end any of them in one click.

  • See every logged-in user with their IP address, browser, and recent activity at a glance
  • Terminate any suspicious session immediately, with no password reset required
  • Log users out after inactivity with different limits for admins, editors, and subscribers
  • Limit simultaneous logins per user, and remove the oldest session when the cap is reached
lock-icon

User Session Management

4 active sessions

admin · 192.168.1.1 · Chrome

now

editor · 10.0.0.42 · Firefox

3m

subscriber · 203.x.x.x · Safari

18m

Idle timeout (admin)

60 min

Max concurrent sessions

3

Eight Problems. One Plugin.

Your current security stack, replaced.

Every plugin on this list has a free, built-in equivalent inside Midnay Security Central. Replace them one by one.

Plugin you might already haveMidnay module that replaces itCost
Limit Login Attempts ReloadedLogin ProtectionFree
WP 2FA / Two Factor AuthenticationMulti-Factor AuthenticationFree
WP Activity Log / Simple HistoryActivity LogFree
Wordfence / NinjaFirewallWAF LiteFree
HTTP Headers / Shield SecuritySecurity HeadersFree
WP Session Manager / Inactive LogoutUser Session ManagementFree
WPScan / Security NinjaSecurity Scanner (A–F grade)Free
iThemes Security / File MonitorFile & Directory SecurityFree

All Modules

Ten modules. One dashboard.

Each module can be turned on or off independently from its own settings page. Enable only what your site needs.

security header

Security Headers

CSP, HSTS, X-Frame-Options, and more – no server config needed.

Authentication

Multi-Factor Authentication

Biometric passkeys, TOTP, and email OTP with per-role enforcement.

security

REST API Security

Block user enumeration, disable XML-RPC, restrict endpoint access.

file

File & Directory Security

Directory indexing scan, upload restrictions, and file integrity monitoring.

scanner

Security Scanner

On-demand audit with an A–F security grade and prioritised fixes.

user

User Session Management

Live session table, instant revocation, idle timeouts, and concurrent limits.

log

Activity Log

Complete audit trail across 9 event categories with export and email alerts.

protection

Login Protection

Brute-force lockout, CAPTCHA integration, and real-time attempt log.

firewall

WAF Lite

Request firewall blocking bad bots, SQL injection, XSS, and path traversal.

dashboard

Dashboard

Live security command centre – grade, threats, MFA status, and recent events.

Every setting is clearly labelled

So you always know what’s safe to enable right now, and what deserves a second look.

Safe

Enable freely. No configuration needed and no real risk of breakage.

Careful

Review the settings first. Low risk when configured thoughtfully.

Expert

Requires developer knowledge. Can break integrations if configured incorrectly.

Free Forever

No premium tier. No upsells. Ever.

Every feature on this page – all 80+ controls across 10 modules – is included free. GPL-licensed, no account required, install straight from WordPress.org.

  • WordPress 6.5+ & PHP 8.1+
  • GPL-2.0 licensed
  • WooCommerce support
  • Zero page-load impact
  • Modules load only when active

Documentation

Every module, explained step by step

From your first install to locking down the REST API, the full documentation walks you through setup, configuration, and troubleshooting for all 10 modules

  • Installation & 5-minute first-time setup
  • Module-by-module configuration guides
  • How-to workflows: stop brute-force attacks, run scans, lock down APIs
  • Troubleshooting & FAQ

FAQ

Frequently Asked Questions.

What does the Midnay WordPress Security plugin do?

faq-plus-icon

The Midnay WordPress Security plugin helps protect your website from common security threats, including malware, brute-force attacks, unauthorized logins, vulnerabilities, and suspicious activity. It strengthens your WordPress security without requiring advanced technical knowledge.

Why do I need a WordPress security plugin?

faq-plus-icon

WordPress websites are frequent targets for automated attacks, malware injections, and login attempts. A security plugin adds an extra layer of protection by monitoring threats, securing access points, and helping prevent security breaches.

Does the plugin protect against brute-force login attacks?

faq-plus-icon

Yes. The plugin helps block repeated login attempts, reducing the risk of attackers gaining access through password guessing or credential-stuffing attacks.

Can the plugin detect malware and security vulnerabilities?

faq-plus-icon

Yes. It scans your WordPress installation for potential vulnerabilities, suspicious files, and malware, helping you identify and resolve security risks before they cause damage. 

Will the plugin slow down my website?

faq-plus-icon

No. The plugin is designed to provide strong security while maintaining website performance. Security measures are implemented with minimal impact on loading speed and user experience. 

Does it offer firewall protection?

faq-plus-icon

Yes. The plugin includes firewall functionality that helps block malicious requests and unauthorized access attempts before they reach your website.

Can I use the plugin with any WordPress theme or plugin?

faq-plus-icon

Yes. The plugin is compatible with most WordPress themes and plugins. It is designed to work seamlessly without affecting your website’s functionality.

Does the plugin provide activity logs?

faq-plus-icon

Yes. Activity logging helps you track important changes, login attempts, and administrative actions, making it easier to monitor your website’s security.

Is the plugin suitable for WooCommerce websites?

faq-plus-icon

Absolutely. The plugin can protect WooCommerce stores by securing customer data, login pages, payment-related processes, and administrative access.

Do I still need a security plugin if my hosting provider offers security features?

faq-plus-icon

Hosting security is important, but it does not always provide complete WordPress-level protection. Using a dedicated security plugin adds additional monitoring, firewall protection, and vulnerability detection for better overall security.

Can beginners use this plugin?

faq-plus-icon

Yes. The plugin is built to be user-friendly, allowing website owners to improve security without requiring technical expertise.

How often should I monitor my website security?

faq-plus-icon

Website security should be monitored continuously. Regular updates, security scans, backups, and vulnerability checks help keep your WordPress site protected against emerging threats. 

What should I do if my website gets hacked?

faq-plus-icon

If your website is compromised, immediately run a security scan, remove malicious files, change passwords, update WordPress core, themes, and plugins, and restore from a clean backup if necessary. A security plugin can help identify and resolve many common security issues. 

Is the Midnay WordPress Security plugin suitable for business websites?

faq-plus-icon

Yes. Whether you run a business website, blog, membership site, or WooCommerce store, the plugin provides the security features needed to protect your website, data, and reputation. 

Found a Vulnerability?

Report it to our security team

If you’ve discovered a security issue in Midnay Security Central, email us directly and we’ll respond as quickly as possible.

Back to Top