Vigilante - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…
by Fernando Tellado 1 (19 reviews)

Vigilante - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…

Premium WordPress security features, 100% free. Firewall, 2FA, security headers, login protection, and file monitoring.

Vigilante ranks #4,481 among WordPress.org plugins with 1+ active installations, is #1,019 of 1,576 in the Authentication category, a 1/5 rating from 19 reviews, and was last updated Feb 12, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 6.9 (Current: 7.1)
v1.0.4 Current Version v1.0.4
Updated 7 months ago Last Update on 12 Feb, 2026
Refreshed 7 hours ago Last Refreshed on
#1,019 of 1,576 in Authentication Downloads +186.8% this week
View on WordPress.org
Rank
#4,481
+8 this week
Active Installs
1+
-100%
KW Avg Position
164
No change
Downloads
90
+297 today
Support Resolved
100%
No change
Rating
20%
Review 1 out of 5
1 (19 reviews)

Next Milestone 10

Total Progress 100%
0+ 10+
3,768
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 0 more installs to reach 10+

Rank Changes

4,467 4,497 4,528 4,559 4,589 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
4,442 4,526 4,610 4,694 4,778 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Current #4,481
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

200 400 600 800 1K 1.2K 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
0 200 400 600 800 1K 1.2K 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
19 reviews
Overall 20%
5
19 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Support Threads Overview

Resolved
Unresolved
16
Total Threads
16
Resolved
0
Unresolved
100%
Resolution Rate

Security History

Source: WPVulnerability

No known vulnerabilities on record for Vigilante. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who want enterprise-level security without paying for premium tiers. It solves the problem of fragmented, paywalled security tools by bundling firewall, two-factor authentication, login protection, file monitoring, and activity logging into one free suite.

  • Firewall against SQL injection, XSS
  • Email-based two-factor authentication
  • Limit login attempts with lockouts
  • Security headers (CSP, HSTS)
  • File integrity monitoring
  • Activity log with CSV export
  • Custom login URL
  • REST API access control

Frequently Asked Questions

Common questions about Vigilante - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…

No. Vigilante is optimized for performance. The firewall uses efficient pattern matching, database queries are cached with transients, and .htaccess rules execute at server level before PHP even loads.
Vigilante immediately creates a backup of your existing .htaccess and wp-config.php files, then applies default security settings. All 8 modules are enabled with balanced defaults suitable for most sites.
All security modifications are automatically reverted. The .htaccess rules are removed, wp-config.php constants are restored to their original values, and scheduled tasks are cleared. Your site returns to its pre-Vigilante state.
After entering your username and password, you receive a 6-digit verification code via email. Enter this code to complete login. You can optionally mark your device as trusted to skip 2FA for 30 days on that browser.
Check your spam folder first. You can click "Resend code" on the verification form. Codes expire after 10 minutes by default. If issues persist, an administrator can temporarily disable 2FA from the plugin settings.
By default, 2FA is enforced for administrators and editors. You can customize which roles require 2FA in the Login Security settings, or exclude specific users.
Access your site via FTP/SFTP and either rename the plugin folder to disable it temporarily, or delete the vigilante_login_attempts table rows for your IP address in the database.
The firewall is configured to allow normal WordPress operations, including the block editor, REST API, and popular page builders. If you experience issues, you can whitelist specific IPs or adjust rate limiting thresholds.
While Vigilante works standalone, running multiple security plugins can cause conflicts. We recommend testing in a staging environment first if you need to combine security solutions.
Yes. Vigilante is compatible with popular caching plugins. The firewall runs before cache layers, and .htaccess rules don't interfere with caching mechanisms.

Sign In / Register

You need to sign in or register to use this feature.