Fuerte-WP | WordPress Security, Auto-Updates and Admin Control
by Esteban 0 (0 reviews)

Fuerte-WP | WordPress Security, Auto-Updates and Admin Control

WordPress security and maintenance plugin: schedule auto-updates, block malicious updates during supply chain attacks, enforce two-factor authenticati …

Fuerte-WP ranks #15,836 among WordPress.org plugins with 100+ active installations, is #812 of 4,499 in the Security category, and was last updated Sep 12, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.4 (Current: 7.1)
v1.12.0 Current Version v1.12.0
Updated 4 days ago Last Update on 12 Sep, 2026
Refreshed 9 hours ago Last Refreshed on
#812 of 4,499 in Security Top 25% by installs Downloads +171.7% this week Actively maintained
View on WordPress.org
Rank
#15,836
-34 this week
Active Installs
100+
-18.7%
KW Avg Position
88
2.5 worse
Downloads
8.5K
+5 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 200

Total Progress 37%
100+ 200+
4,793
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 63 more installs to reach 200+

Rank Changes

15,632 15,690 15,748 15,805 15,863 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
15,552 15,632 15,713 15,793 15,873 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #15,836
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 30 40 50 60 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 10 20 30 40 50 60 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for Fuerte-WP. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress agencies, site owners, and administrators managing multiple sites or client installations who need to control updates and admin access. It solves the risk of supply chain attacks and unwanted admin changes by letting users freeze plugin versions, schedule updates, and restrict what other administrators can modify.

  • Blocked Updates freeze plugin versions
  • Scheduled auto-updates (6-48 hours)
  • Selective auto-update control
  • Deferred updates for specific plugins
  • Super user access designation
  • Admin menu management
  • Login rate limiting
  • Custom login URLs

Frequently Asked Questions

Common questions about Fuerte-WP | WordPress Security, Auto-Updates and Admin Control

When you learn that a plugin developer's account has been compromised and malicious updates are being distributed, open Fuerte-WP and block that plugin under Blocked Updates. This freezes the plugin at its last safe version and prevents your site from auto-installing malicious code, even while thousands of other sites are being compromised. Once the developer publishes a verified clean release, remove the block.
Deferred Updates: the plugin will not auto-update, but you can still update it manually when you are ready. Good for testing a release on staging before it reaches production. Blocked Updates: the plugin cannot update at all, neither automatically nor manually. Essential during a supply chain attack when any update could contain malicious code.
Yes. Since 1.10.0, Fuerte-WP bundles the official WordPress Two-Factor library. Administrators can use Email codes, an Authenticator App (TOTP, compatible with Google Authenticator, Authy, 1Password), and Recovery Codes. "Enforce 2FA for Admins" is on by default. If you already run the standalone Two-Factor plugin, Fuerte-WP detects it and steps aside.
No. Only super users can modify Fuerte-WP settings or disable the plugin. Other administrators are restricted from making changes that could compromise your site's security. This makes Fuerte-WP self-protecting.
You set a secret login slug. Fuerte-WP redirects the default wp-login.php and wp-admin paths away from unauthenticated visitors, so bots that scan for those endpoints find nothing. You and your team log in at your custom URL instead. Brute force attacks against the default login form stop almost entirely.
Yes, both are one-click toggles and both are on by default. Disabling XML-RPC removes the pingback vector and brute force amplification. Disabling Application Passwords prevents leaked credentials from being used against the REST API.
No. All maintenance and update checks run in the background through a dedicated cron event. Page load times are unaffected. Fuerte-WP is performance optimized.
Yes. Fuerte-WP is fully compatible with WordPress multisite and can be network-activated for centralized management across every site on the network.
Yes. Define a $fuertewp array in wp-config-fuerte.php inside your ABSPATH directory. File configuration wins over the database, so the same baseline ships to every site you manage. See config-sample/wp-config-fuerte.php for the full shape.
Yes. Server operators can create empty marker files in the WordPress root or one level above it: .fuertewp-disable disables Fuerte-WP completely, .fuertewp-disable-mfa disables only the bundled Two-Factor feature. The presence of the file is enough; remove it to re-enable. A marker in the parent directory applies to every site sharing that parent.

Sign In / Register

You need to sign in or register to use this feature.