Vortix Web Security

Vortix Web Security

Details
View on WordPress

Vortix Web Security bundles eleven practical security features that you can switch on and off individually from one screen. Everything is free, works offline, and needs no account, license key or trial. Nothing expires.

Free features

  1. Basic Hardening – generic login error messages, no public username discovery (?author=N and the REST users list for logged-out visitors), X-Content-Type-Options: nosniff.
  2. Login Protection – temporary lockouts after repeated failed logins, per IP address and per username.
  3. Disable XML-RPC – blocks xmlrpc.php and removes the related headers and links.
  4. Bad Bot Blocker – blocks requests from well-known scanner tools by User-Agent.
  5. Upload Protection – denies access to script files in the uploads folder (Apache and LiteSpeed).
  6. Disable File Editor – removes the theme and plugin code editors.
  7. Hide WP Version – removes the WordPress version from the generator tag and asset URLs.
  8. Disable Directory Browsing – adds Options -Indexes (Apache and LiteSpeed).
  9. Strong Password Enforcement – strong passwords for users who can edit posts.
  10. Automatic Plugin Updates – for plugin packages served by WordPress.org over HTTPS.
  11. Automatic Theme Updates – for theme packages served by WordPress.org over HTTPS.

A Security Scan screen runs sixteen local configuration checks. Each feature’s screen entry explains what it protects and exactly what it changes.

Features that edit .htaccess, may interfere with third-party services, or install updates start switched off on a new install. Basic Hardening, Login Protection, Disable File Editor, Hide WP Version and Strong Password Enforcement start on.

Premium

An optional, separately distributed product called Vortix Web Security Pro exists. It is not included in this plugin, and this plugin contains no locked or hidden premium code. The free features never depend on it. Information about it appears only on this plugin’s own screens: an “Upgrade to Premium” screen and a small card beside the feature list. There are no banners or notices elsewhere in the dashboard.

Privacy

Blocked requests (failed logins, blocked scanner requests, blocked XML-RPC requests) are recorded in a table in your own database: IP address, requested page path without the query string, event type and time. Entries are deleted after the retention period you set (90 days by default) and when the plugin is uninstalled. Login-attempt counters use keyed hashes rather than raw IP addresses or usernames and expire automatically.

The plugin sets no cookies and sends no data to the author or any third party. Suggested privacy-policy text is added under Settings > Privacy.

External services

Vortix Web Security does not connect to any external service.

  • The Security Scan and the .htaccess safety check request pages from your own site (loopback requests). No other server is contacted.
  • When Cloudflare is the selected trusted proxy, the plugin reads the CF-Connecting-IP request header. It does not contact Cloudflare. The Cloudflare address ranges it compares against are stored in the plugin.
  • The “View Premium Plans” button is an ordinary link. Nothing is requested or sent unless you click it, and the link opens the Pro product website in a new tab.

Support

Use the support forum for this plugin on WordPress.org.

Details

Plugin code:
vortix-web-security
Plugin version:
2.1.1
Outdated:
No
WP version:
6.2 or higher
PHP version:
8.0 or higher
Test up to WP version:
7.1.2
Total installations:
0
Last updated:
2026-10-01
Rating:
Times rated:
0
brute-force
hardening
login-security
security
xmlrpc