not at the cleanup layer
Aegis stops attacks before WordPress runs — at the REST API, at the login page, and at every form. When something is tampered, the site locks down immediately. Not just an email. A real lockdown.
The only free plugin that locks your site when tampered. Others only email you.
No account required · No external dependencies · Plugin Check 0/0 · PHP 8.2+
They scan files daily. They email you when something is wrong. Meanwhile, your site is running compromised code.
Scan files once a day. Send an email when they find something. The site keeps running with the compromised code. Visitors are served by an infected WordPress. The damage is already done.
Checks its own files on every request. If anything is changed without your knowledge, the site goes into maintenance mode within 30 seconds. A recovery link lands in your inbox. No one sees the compromised code.
Free covers most sites completely. Intelligence adds smart, adaptive protection. MAX adds enterprise-grade tools for agencies.
WordPress's REST API is open by default — any bot can query your users, content, and plugins. Aegis closes it with a 14-step filter that runs before WordPress processes anything. WooCommerce, Elementor, and 30+ other plugins pass through automatically.
Your wp-login.php returns a genuine 404 — the same as a page that never existed. Bots scanning for your login find nothing. You access WordPress through a secret URL only you know.
Aegis fingerprints its own files. If any file is changed — by an attacker who got in through another plugin — the site locks down within 30 seconds. A recovery link goes to your email. You're back in control in minutes.
An invisible trap field is added to every comment and registration form. Bots that fill forms automatically fall into the trap and are silently rejected. No CAPTCHA. No friction for real visitors.
Aegis adds the headers that browsers need to protect your visitors: no clickjacking, no MIME sniffing, strict referrer policy, Content Security Policy presets. Applied to every response including the REST API.
Every blocked request is recorded with the IP address, country flag, what they tried, and why it was stopped. Export to CSV. Search by IP or route. See patterns before they become problems.
Aegis tracks how each IP address behaves over a 10-minute window. Repeated suspicious actions — failed logins, scanning, enumeration — accumulate a score. High scores trigger automatic slowdowns, then blocks.
Works with Google Authenticator and any TOTP app. Set up with a QR code. 10 recovery codes stored safely. No external service — pure PHP, everything stays on your server.
Block or allow traffic by country. Uses Cloudflare's country detection when available (zero performance cost), with a local database as fallback. Every blocked request shows the country flag in the log.
Checks your active plugins against the WPScan vulnerability database daily. If a vulnerable plugin is found, Aegis shows you the CVE, the severity, and exactly which file in the plugin is affected. One click to remove it.
When Aegis blocks an attack, it identifies which plugin the attacker used as their entry point. "WP File Manager was used in this attack." No other plugin shows you this. You know exactly what to remove.
Tracks failed login attempts per IP and per username. Detects distributed attacks (many IPs, same username). Progressive delay before lockout. Locked IPs shown in the dashboard with one-click unlock.
Inspects every request for SQL injection, cross-site scripting, path traversal, server-side request forgery, XML injection, Log4Shell patterns, and PHP object injection. Covers the full OWASP Top 10. Runs before WordPress touches the request.
Watches your plugins, themes, wp-config.php, and .htaccess for unexpected changes. When a file changes, you get an alert immediately. Suspicious files can be quarantined. WordPress.org plugins can be restored from the original source.
White-label the entire interface with your agency name and logo. GDPR compliance reports for each site. Incident response playbooks that act automatically when a threat is detected. Central fleet dashboard is in development.
An attacker who gets past your other defences and tampers with Aegis will trigger the lockdown themselves. The plugin is its own last line of defence.
Every 30 seconds, on any request, Aegis checks its own files against a secure baseline. A change triggers immediate site lockdown and a recovery email — no waiting for the next admin login.
Your protection settings are cryptographically signed using your WordPress secret keys. An attacker who edits the database directly to disable protection will trigger a lockdown instead.
When lockdown triggers, a one-time recovery link goes to your admin email. Valid for 24 hours. Click it and the site is back online. No FTP, no hosting panel, no technical knowledge needed.
Intelligence installs a guard that runs before any plugin loads. If a core file is tampered, the tampered code never executes — the site returns 503 immediately. This is the key difference from Basic.
Your license is verified across independent nodes. Database edits that try to extend or fake the license are detected and rejected. The verification cannot be bypassed by editing your WordPress database.
The Web Application Firewall runs at the earliest possible point — before plugins, before themes, before WordPress processes the request. SQL injection and XSS attempts are caught before they touch any code.
| Feature | Aegis Basic Free |
Wordfence Free |
Really Simple SSL Free |
Solid Security Free |
|---|---|---|---|---|
| REST API protection | ✓ 14-step gate | — | — | — |
| Tamper → site lockdown | ✓ Immediate | email only | email only | email only |
| Recovery email with unlock link | ✓ | — | — | — |
| Settings tamper detection | ✓ | — | — | — |
| Hidden login page (genuine 404) | ✓ | — | — | PRO only |
| User enumeration blocked (REST + web) | ✓ both | REST only | — | REST only |
| Content Security Policy | ✓ | — | — | — |
| Web Application Firewall | — | 30-day delay free | — | — |
| Brute force lockout | — | ✓ | ✓ | ✓ |
| Malware scanning | — | ✓ | PRO only | ✓ |
| No account required (2026) | ✓ | Now required | — | ✓ |
| Zero overhead on regular pages | ✓ | +200–400ms | — | — |
Free tier features only · Verified June 2026
Every paid plan includes a 15-day trial (no card required) and a 6-month grace period after expiry.
Complete protection for most WordPress sites. No limits, no upsells inside the plugin.
Adaptive protection that learns. For WooCommerce stores, membership sites, and anyone who takes security seriously.
The maximum protection achievable in pure PHP. Built for agencies managing multiple sites and high-traffic infrastructure.