Solid Security, previously iThemes Security, is one of the longest-running WordPress security plugins. It focuses on the login and hardening layer: brute-force protection, two-factor and passwordless authentication, WordPress hardening recommendations, file-change detection, and a user security dashboard.
If you represent Solid Security (formerly iThemes), claiming is free and adds a Verified badge to this security profile. Start verification →
The free version covers the core login and hardening features, while Solid Security Pro adds a vulnerability and site scanner, trusted devices, a magic-link login, and more granular controls. It is now part of the StellarWP family (Liquid Web), alongside its backup and page-builder siblings.
It sits alongside a scanner and, ideally, a server-level or edge WAF: Solid Security is strong on access control and hardening but is not a full WAF or malware-cleanup service on its own. For many WordPress sites it is a familiar, capable login-and-hardening layer.
Category context: Plug-in or service that runs inside the WordPress install. Application-level protection; the user controls it directly.
The most-installed WordPress security plugin. Application-level WAF + malware scanner.
Compare →WordPress security suite focused on automatic, off-site malware cleanup.
Compare →Vulnerability database and virtual patching layer for WordPress.
Compare →Solid Security is a WordPress security plugin, formerly known as iThemes Security, focused on login protection, two-factor and passwordless authentication, WordPress hardening, file-change detection, and site scanning. It has a free version and a Pro tier, and is now part of the StellarWP (Liquid Web) family.
Yes. iThemes Security was rebranded to Solid Security in 2023 when iThemes became SolidWP under StellarWP. It is the same plugin lineage with continued development, so existing iThemes Security users were transitioned to the Solid Security branding.
Wordfence leans on an application-level WAF and malware scanner; Solid Security leans on login security, 2FA, and hardening. They overlap but emphasise different layers. Many sites run one as their primary WordPress security plugin and rely on the host or an edge WAF for the request-filtering layer.
HostList is independent. This profile is editorial; HostList accepts no sponsorship, affiliate commission, or paid placement from Solid Security (formerly iThemes) or any security vendor.