Vortix Web Security bundles eleven practical security features that you can switch on and off individually from one screen. Everything is free, works offline, and needs no account, license key or trial. Nothing expires.
?author=N and the REST users list for logged-out visitors), X-Content-Type-Options: nosniff.xmlrpc.php and removes the related headers and links.Options -Indexes (Apache and LiteSpeed).A Security Scan screen runs sixteen local configuration checks. Each feature’s screen entry explains what it protects and exactly what it changes.
Features that edit .htaccess, may interfere with third-party services, or install updates start switched off on a new install. Basic Hardening, Login Protection, Disable File Editor, Hide WP Version and Strong Password Enforcement start on.
An optional, separately distributed product called Vortix Web Security Pro exists. It is not included in this plugin, and this plugin contains no locked or hidden premium code. The free features never depend on it. Information about it appears only on this plugin’s own screens: an “Upgrade to Premium” screen and a small card beside the feature list. There are no banners or notices elsewhere in the dashboard.
Blocked requests (failed logins, blocked scanner requests, blocked XML-RPC requests) are recorded in a table in your own database: IP address, requested page path without the query string, event type and time. Entries are deleted after the retention period you set (90 days by default) and when the plugin is uninstalled. Login-attempt counters use keyed hashes rather than raw IP addresses or usernames and expire automatically.
The plugin sets no cookies and sends no data to the author or any third party. Suggested privacy-policy text is added under Settings > Privacy.
Vortix Web Security does not connect to any external service.
.htaccess safety check request pages from your own site (loopback requests). No other server is contacted.CF-Connecting-IP request header. It does not contact Cloudflare. The Cloudflare address ranges it compares against are stored in the plugin.Use the support forum for this plugin on WordPress.org.