Total Security WP Pro

Free protects a site.
Pro runs an operation.

The free plugin is a complete security suite, permanently — it is not a trial and nothing in it expires. Pro exists for a different problem: what happens between the times you log in. Automation, live threat intelligence, and tooling for people responsible for many sites at once.

The gap Pro closes

Almost every WordPress compromise happens in a window nobody was watching. A CVE is published on a Tuesday. Mass exploitation starts within days. The vendor patch lands a week later. Your site is exposed for that entire stretch — not because you did anything wrong, but because the attack moved faster than a human maintenance cycle.

Everything Pro adds is aimed at that window: reacting without you, and seeing across many sites at once.

Faster than you

Hourly signature updates and automatic patching apply while you sleep.

Wider than one site

Reputation data and fleet reporting turn many installs into one picture.

Ready before it happens

Under Attack Mode is one click, not a scramble through settings mid-incident.

Real-time threat intelligence

The free plugin ships a strong bundled signature set that updates with each release. Pro connects to a live advisory feed instead:

  • Hourly WAF signature updates — new attack patterns reach your firewall without waiting for a plugin release.
  • CVE-matched virtual patching — your installed plugin and theme inventory is matched against published advisories, and targeted rules are offered for what is actually on your site rather than everything in the database.
  • Patch-gap intelligence — flags the worst case: a plugin with a public CVE and no vendor fix yet. That is the window where a virtual patch is the only thing standing between the advisory and your site.
  • Automatic patching — approved patches apply themselves as new CVEs are published.
Signed bundles

Signature bundles are cryptographically verified before they are applied. A feed that can push arbitrary rules into your firewall is a supply-chain risk unless it is signed — so it is.

Under Attack Mode

When a site is actively under attack, nobody makes good configuration decisions. Under Attack Mode is one switch that applies the whole emergency posture at once:

  • Aggressive rate limits across the site
  • A bot challenge wall in front of anonymous traffic
  • REST API, XML-RPC and login surfaces locked down
  • Automatic expiry — it turns itself off after the window you set

That last point matters more than it sounds. Emergency modes without expiry get left on, quietly degrading the site for real visitors long after the attack has stopped.

Scan automation & auto-quarantine

Free includes a weekly automatic baseline scan — every site gets scheduled scanning, not just paying ones. Pro tightens the loop:

  • Daily or twice-daily scans with emailed results, cutting the worst-case detection gap from a week to hours.
  • Auto-quarantine — an infected file is isolated the moment it is found, rather than sitting live until you next log in. Quarantine moves the file to a protected store, so a false positive is one click from reversal.

Sentinel AI triage

Reviewing security events is where most people give up: a hundred firewall blocks, and no obvious way to tell the background noise from the one actor doing reconnaissance. Sentinel builds a case for a suspicious actor — correlating their firewall matches, login attempts and audit trail into an evidence bundle — and returns a threat verdict with a recommended action.

  • Opt-in and consent-gated. Off by default.
  • Redacted evidence. Bundles never contain full request bodies, and no personal data beyond what is already in your own audit log.
  • Local fallback. With Sentinel disabled, triage still runs against conservative local rules. The dashboard does not become useless because you declined to share data.
  • It learns from your corrections. Marking a verdict wrong feeds back into future triage on your site.

See the privacy disclosure for exactly what a bundle contains.

Cloud reputation

A file or address that is new to your site may be well known elsewhere. Reputation lookups check hashes and indicators against a shared network of verdicts, with local caching so repeated checks cost nothing. Only hashes and indicators are sent — never file contents.

Login anomaly detection

  • Impossible travel — a login from a location the account could not physically have reached since its previous one is a stolen-session signal that no password check catches.
  • IP reputation at the login gate, so credential-stuffing infrastructure is recognised before it gets a guess.
  • Geo-based escalation — step up requirements for logins from countries your team never works from, instead of blocking them outright and locking out a colleague on holiday.

Reporting & compliance

  • Extended audit retention beyond the free 90 days — often a hard requirement when an auditor asks for a year.
  • Scheduled email digests so the security posture reaches a stakeholder who will never open the dashboard.
  • PDF export of audit history and posture reports.
  • Compliance checker mapping active controls to common framework expectations, so “show me your controls” is an export rather than a week of screenshots.
Worth being precise about

No plugin makes a site compliant. What this does is evidence the technical controls you actually have in place, in a form an auditor can read — which is usually the tedious part of the exercise, not the hard part.

WooCommerce delta backup

A nightly full backup means a store can lose a day of orders. Delta backup captures order and customer records between full backups, so a restore does not silently discard transactions that arrived after the last snapshot — the failure mode that turns a recoverable incident into refunds and support tickets.

Agency tooling

  • Hub and satellite — every managed site reports into one console. A fleet-wide view of scores, findings and incidents, instead of logging into thirty dashboards to find the one that regressed.
  • White label — present the dashboard under your own brand to clients.
  • Security roles — give staff access to security tooling without making them WordPress administrators, which is itself a hardening win.
  • Multisite network support — network-level configuration and reporting.

What's normally paid — and isn't here

“Our free version is complete” is something every security plugin says, so there is no reason to take our word for it. The useful version of that claim is specific: here is where each capability usually sits in this market, and where it sits for us.

The middle column describes general convention across WordPress security plugins, not any particular product. Judge it against whatever you are running today.

CapabilityWhere it usually sitsTotal Security WP
Firewall that runs before WordPress loads
Blocks the request before the bootstrap, DB connection and plugin loading
Usually premiumFree
Virtual patching for vulnerable pluginsUsually premiumFree
Automatic scheduled malware scanningUsually premiumFree — weekly
Country-level geo-blockingUsually premiumFree
Real-time traffic monitor
Live request feed with one-click block
Usually premiumFree
Incident response tooling
Quarantine, clean-file recovery, permission reset
Usually premiumFree
Database scanning
Posts, comments, options, user meta
Usually premiumFree
Backup & restoreUsually a separate pluginFree — built in
Recovery that works when WordPress won't loadRarely offeredFree
Content Security Policy builder
Observed, report-only first, then enforced
Rarely offeredFree
WP-CLI commandsRarely offeredFree
Audit log retentionOften capped or gatedFree — 90 days, CSV export
Webhook alerts (Slack / Teams)Often premiumFree
Two-factor authenticationCommonly freeFree — plus trusted devices
Breached-password checkingUncommon at any tierFree
Sites per installUnlimited, free
You can check this yourself

Every claim above is about software you can install for nothing and read line by line — it is GPLv2 and ships unobfuscated, with no build step hiding what runs. That is the difference between a marketing table and a verifiable one.

So what does Pro actually gate?

Being straight about this is the point. Pro does not hold back protection and sell it back to you. What it adds is automation and a live service:

  • Things that run without you — daily scans, auto-quarantine, automatic patching, Under Attack Mode.
  • Things that need our infrastructure — the hourly threat-intel feed, cloud reputation, Sentinel AI analysis. These are a running service with a running cost, which is what a subscription genuinely pays for.
  • Things only multi-site operators need — white label, security roles, multisite, hub mode, compliance export.

If you log in regularly and run your own scans, the free tier may be all you ever need. We would rather say that than sell you something you will not use.

Full comparison

CapabilityFreePro
Dual-mode WAF (Optimized / Standard)
Rate limiting, brute force, DDoS shield
Bad-bot blocker & geo-blocking
Virtual patching (bundled + custom)
Deep hardening & server rule generation
Content Security Policy builder
Malware scanner (signature + token + taint)
File integrity monitoring & checksums
Database scanner
Quarantine, repair & permission reset
Backup, restore & standalone recovery
2FA, CAPTCHA, password policy, sessions
Breached-password checking
Live Traffic monitor
Admin-bar Security Score
WP-CLI support
Notifications (email, Slack, Teams)
Automatic malware scansWeeklyDaily / twice daily
Audit log retention90 daysExtended
Live threat intelligence feed
Automatic patching as CVEs publish
Under Attack Mode
Auto-quarantine
Sentinel AI triage
Cloud reputation lookups
Impossible travel & IP reputation
Email digests, PDF export, compliance
WooCommerce delta backup
White label, roles, multisite, hub mode

Plans

Free $0

Forever. No credit card, no expiry.

  • The complete security suite above
  • Weekly automatic malware scan
  • 90-day audit log with CSV export
  • Backup, restore and emergency recovery
  • Unlimited sites
  • Community support on WordPress.org
Download free
MOST POPULAR
Pro Pricing on request

Everything in Free, plus automation and intelligence.

  • Live threat intel & hourly WAF updates
  • Automatic patching as CVEs publish
  • Under Attack Mode
  • Daily scans & auto-quarantine
  • Sentinel AI triage & cloud reputation
  • Extended retention, digests, PDF & compliance
  • WooCommerce delta backup
  • White label, roles, multisite & hub mode
  • Priority support
Talk to us about Pro

Pro is licensed per site with an offline grace window, so a temporary network failure never downgrades a site mid-incident. A license activates and deactivates from the dashboard, so moving a license between sites does not need a support ticket.

Questions

Is the free version crippled to push me to Pro?

No, and the comparison table above is the argument. Firewall, hardening, malware scanning, integrity monitoring, 2FA, backups, audit logging, Live Traffic and WP-CLI are all free, on unlimited sites, permanently. Free even includes automatic weekly scanning, which most competitors gate.

Pro sells automation and a live service. If you log in regularly and run scans yourself, free may genuinely be all you need — and we would rather say that than sell you something you will not use.

What happens if my license expires?

The plugin keeps working. Pro features stop and the site continues running the complete free suite — your firewall does not switch off and your site does not become unprotected. You keep the signature set you last received; you stop receiving new ones.

Does Pro send my site data to your servers?

License activation sends the license key and site URL. The threat-intel feed pulls signatures. Cloud reputation sends hashes and indicators, never file contents. Sentinel AI and bypass telemetry are separately consent-gated and off by default. The privacy disclosure lists every call in full.

Can I use Pro on client sites as an agency?

Yes — that is what the agency tooling exists for. White-label the dashboard, give staff security roles without administrator access, and run hub mode so every managed site reports into one console.

How do updates work now the custom updater is gone?

As of 1.2.0, all plugin code updates through WordPress.org like any other plugin. Pro features unlock locally via cryptographic license token, and security data that has to move faster than a release — WAF rules, virtual patches, CVE matches — updates independently through the threat-intel feed.