FP Site Security
by Joseph Mendez 1 (0 reviews)

FP Site Security

Lightweight WordPress security: login defense, firewall, malware scans, file monitoring, and local backups — all running on your own site.

FP Site Security ranks #63,016 among WordPress.org plugins with 1+ active installations, is #2,391 of 4,482 in the Security category, a 1/5 rating from 0 reviews, and was last updated Jun 17, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1)
v1.0.9 Current Version v1.0.9
Updated 2 months ago Last Update on 17 Jun, 2026
Refreshed 7 hours ago Last Refreshed on
#2,391 of 4,482 in Security
View on WordPress.org
Rank
#63,016
-11319 this week
Active Installs
1+
-50%
KW Avg Position
86
1 worse
Downloads
220
+4 today
Support Resolved
0%
No change
Rating
20%
Review 1 out of 5
1 (0 reviews)

Next Milestone 10

Total Progress 10%
0+ 10+
62,303
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 10+

Rank Changes

46,366 52,113 57,860 63,606 69,353 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
46,060 51,938 57,817 63,696 69,574 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Current #63,016
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
0 10 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
0 reviews
Overall 20%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about FP Site Security

It hardens login (brute-force lockout, optional two-factor), runs a built-in firewall with country and IP blocklists, scans your files for malware signatures and integrity changes, offers optional WordPress.org checksum and update verification when you opt in, takes scheduled local backups, and sends you alerts when something looks wrong.
No. Activate the plugin and the defaults turn on login protection, the firewall, and local file integrity monitoring. WordPress.org verification lookups are off by default and must be enabled explicitly. There's no signup, no API key, and no paid tier.
By default it does not send visitor IP addresses to third-party geo-location services. Country-based checks only work when your stack already provides country data locally, such as the CF-IPCountry header from Cloudflare, an equivalent server-side header, or the optional PHP GeoIP extension. Slack, Sentry, Google reCAPTCHA, and WordPress.org verification requests are all feature-driven and only occur when the relevant feature is enabled or used.
Yes, but you need to opt in. By default the plugin trusts only REMOTE_ADDR, so behind a proxy every visitor will look like the proxy IP. To honor CF-Connecting-IP / X-Forwarded-For, set the trust_proxy_headers option to 1 and add your proxy IPs to trusted_proxy_ips (comma- or whitespace-separated). With WP-CLI: wp option patch update firssise_options trust_proxy_headers 1 and wp option patch update firssise_options trusted_proxy_ips "203.0.113.10, 203.0.113.11". Without an allowlist, forwarded headers are spoofable and the firewall would be trivial to bypass.
In the WordPress admin, go to FP Security → Security → Login Security. Scroll to the "Two-factor authentication" section, scan the QR code with any TOTP app (Google Authenticator, 1Password, Authy, Bitwarden), enter the 6-digit code in the "Verify code" field to confirm, and save. TOTP will be required on every subsequent login for that user.
The plugin generates an emergency unlock token on activation, stored in the firssise_options row of wp_options. Three ways to retrieve it: WP-CLI: wp option get firssise_options --format=json and copy the emergency_unlock_token value. phpMyAdmin / database: open the wp_options table, find option_name = 'firssise_options', and read the serialized array — the token is the value of emergency_unlock_token. Last resort (always works): rename the plugin folder via SFTP (firstpage-site-security → _disabled) to deactivate the plugin and log in normally. Once you have the token, append it to your login URL: /wp-login.php?firssise_unlock=YOUR_TOKEN. That bypasses the lockout for a single login. For repeated lockouts, raise the brute-force threshold in FP Security → Security → Login Security.
The default mode is "low resource" — scans run in background cron batches, not on visitor requests. The realtime watcher only fingerprints files modified in the last ten minutes and skips known-large directories like cache/ and upgrade/. On a small or medium site you should not see any measurable impact.
It records an event in the activity log, raises an admin notice, and (if you've enabled them) pushes notifications to Slack, Sentry, or your admin email. From the Findings panel you can quarantine the file or delete it after review.
You can, but you probably don't want to — two firewalls fighting over the same hooks tends to cause double-blocking, lockouts, and slow login. The plugin detects common security plugins on activation and shows a one-time admin notice listing what it found so you can pick one. There is no functional conflict, just duplicated work.
Deactivate the plugin from the Plugins screen, then delete it. The plugin's options, transients, and event log are removed by the uninstall hook. Backups stored under wp-content/uploads/firssise-backups/ are intentionally NOT removed automatically — delete them manually if you don't want them.

Sign In / Register

You need to sign in or register to use this feature.