WordPress Security

New One-Click WordPress Security Check in iThemes Security

The latest version of iThemes Security Pro (6.4.2) & iThemes Security Free (7.6.1) includes a new "one-click" WordPress Security Check for your WordPress site. The Security Check feature is designed to help save you time and ensure your site is using the recommended security settings. Features/Settings Enabled by Security Check With just one click of the "Secure Site" button, iThemes Security will enable and configure all the recommended security features and settings within the plugin.

Avatar photo
SolidWP Editorial Team

This is a historical article about features released in 2020 for iThemes Security and Security Pro. They became Solid Security and Solid Security Pro in 2023. Learn more about the rebrand and the current state of the Security Check feature in Solid Security.

The latest version of iThemes Security Pro (6.4.2) & iThemes Security Free (7.6.1) includes a new “one-click” WordPress Security Check for your WordPress site. The Security Check feature is designed to help save you time and ensure your site is using the recommended security settings.

wordpress-security-check

Features/Settings Enabled by Security Check

With just one click of the “Secure Site” button, iThemes Security will enable and configure all the recommended security features and settings within the plugin. This table lists out the feature/setting and the benefits activated by the Security Check.

Feature/SettingBenefit
Banned UsersBlocks specific IP addresses and user agents from accessing your site
Database BackupsCreates database backups manually or on a schedule
Local Brute Force ProtectionProtects your site against attackers that try to randomly guess login details to your site
Malware Scan Scheduling (Pro)Protects your site with automated malware scans. When this feature is enabled, your site will be automatically scanned each day
Network Brute Force ProtectionProtects your site against known attackers before they reach your site
Strong Passwords (Pro)Helps enforce that powerful (admin) accounts choose strong passwords for their logins
Two-Factor Authentication (Pro)Greatly increases the security of your WordPress user account by requiring additional information beyond your username and password in order to log in to the site
User Logging (Pro)Logs user actions such as login, editing or saving content and other actions into a viewable list
WordPress TweaksThis feature has a variety of settings that change the behavior of WordPress

By using the “Secure Site” button, the following settings actions will be taken (if they were not previously set):

  • Enable the Enable Ban Lists setting in Banned Users. This ensures that IPs being blocked by other features are not ignored due to the setting being disabled.
  • Enable the Email Notifications setting in Malware Scan Scheduling to ensure that site admins are notified of potential malware issues.
  • Enable the Time-Based One-Time Password (TOTP) provider for Two-Factor Authentication. When a user sets up their account to use TOTP authentication, they greatly increase the security of their account and make it near impossible for attackers to break into their account.
  • Enable the Email provider for Two-Factor Authentication. The email authentication option is a great alternative for users that cannot use Time-Based One-Time Password (TOTP) authentication.
  • Enable the Backup Verification Codes provider for Two-Factor Authentication. It is recommended that every user creates a set of backup verification codes to use in case they lose access to their Time-Based One-Time Password (TOTP) device or their email account.
  • Disable the File Editor in WordPress Tweaks as the file editor can be used by attackers to quickly add back doors or malware injection to existing files.
  • Change the Multiple Authentication Attempts per XML-RPC Request setting in WordPress Tweaks to “Block”. This prevents attackers from using XML-RPC requests to efficiently brute force user login credentials.
  • Enable the Write to Files setting in Global Settings. Since many features of iThemes Security require writing to wp-config.php and server config files, having this setting disabled prevents a large number of features from working properly.

Using the One-Click Security Check in iThemes Security

The new Security Check module should automatically display as soon as you update to the latest version of iThemes Security and visit the Security > Settings page. Simply click the “Secure Site” button to complete the security check.

security-check-for-wordpress

Security Check will then give you a status of all the settings/features enabled by the plugin.

WordPress-security-check-status

After you’ve used Security Check, you can review the settings again from the Security > Security Check page or from the iThemes Security Settings dashboard.

wordpress-security-settings

Update to iThemes Security Pro 2.5.0
& iThemes Security Free 5.6.0

Pro Customers: All current iThemes Security Pro customers will now find the 2.5.0 update available from the WordPress dashboard (for licensed sites) or as a manual download from the iThemes Member Panel. Save time updating all your sites at once from the iThemes Sync Dashboard.
Free Users: All iThemes Security users will now find the 5.6.0 update available from the WordPress dashboard or as a manual download from WordPress.org Plugin Directory. Save time updating all your sites at once from the iThemes Sync Dashboard.

Get iThemes Security Pro now

Did you like this article? Spread the word: