Total Security WP Pro
Free protects a site.
Pro runs an operation.
The free plugin is a complete security suite, permanently — it is not a trial and nothing in it expires. Pro exists for a different problem: what happens between the times you log in. Automation, live threat intelligence, and tooling for people responsible for many sites at once.
The gap Pro closes
Almost every WordPress compromise happens in a window nobody was watching. A CVE is published on a Tuesday. Mass exploitation starts within days. The vendor patch lands a week later. Your site is exposed for that entire stretch — not because you did anything wrong, but because the attack moved faster than a human maintenance cycle.
Everything Pro adds is aimed at that window: reacting without you, and seeing across many sites at once.
Faster than you
Hourly signature updates and automatic patching apply while you sleep.
Wider than one site
Reputation data and fleet reporting turn many installs into one picture.
Ready before it happens
Under Attack Mode is one click, not a scramble through settings mid-incident.
Real-time threat intelligence
The free plugin ships a strong bundled signature set that updates with each release. Pro connects to a live advisory feed instead:
- Hourly WAF signature updates — new attack patterns reach your firewall without waiting for a plugin release.
- CVE-matched virtual patching — your installed plugin and theme inventory is matched against published advisories, and targeted rules are offered for what is actually on your site rather than everything in the database.
- Patch-gap intelligence — flags the worst case: a plugin with a public CVE and no vendor fix yet. That is the window where a virtual patch is the only thing standing between the advisory and your site.
- Automatic patching — approved patches apply themselves as new CVEs are published.
Signature bundles are cryptographically verified before they are applied. A feed that can push arbitrary rules into your firewall is a supply-chain risk unless it is signed — so it is.
Under Attack Mode
When a site is actively under attack, nobody makes good configuration decisions. Under Attack Mode is one switch that applies the whole emergency posture at once:
- Aggressive rate limits across the site
- A bot challenge wall in front of anonymous traffic
- REST API, XML-RPC and login surfaces locked down
- Automatic expiry — it turns itself off after the window you set
That last point matters more than it sounds. Emergency modes without expiry get left on, quietly degrading the site for real visitors long after the attack has stopped.
Scan automation & auto-quarantine
Free includes a weekly automatic baseline scan — every site gets scheduled scanning, not just paying ones. Pro tightens the loop:
- Daily or twice-daily scans with emailed results, cutting the worst-case detection gap from a week to hours.
- Auto-quarantine — an infected file is isolated the moment it is found, rather than sitting live until you next log in. Quarantine moves the file to a protected store, so a false positive is one click from reversal.
Sentinel AI triage
Reviewing security events is where most people give up: a hundred firewall blocks, and no obvious way to tell the background noise from the one actor doing reconnaissance. Sentinel builds a case for a suspicious actor — correlating their firewall matches, login attempts and audit trail into an evidence bundle — and returns a threat verdict with a recommended action.
- Opt-in and consent-gated. Off by default.
- Redacted evidence. Bundles never contain full request bodies, and no personal data beyond what is already in your own audit log.
- Local fallback. With Sentinel disabled, triage still runs against conservative local rules. The dashboard does not become useless because you declined to share data.
- It learns from your corrections. Marking a verdict wrong feeds back into future triage on your site.
See the privacy disclosure for exactly what a bundle contains.
Cloud reputation
A file or address that is new to your site may be well known elsewhere. Reputation lookups check hashes and indicators against a shared network of verdicts, with local caching so repeated checks cost nothing. Only hashes and indicators are sent — never file contents.
Login anomaly detection
- Impossible travel — a login from a location the account could not physically have reached since its previous one is a stolen-session signal that no password check catches.
- IP reputation at the login gate, so credential-stuffing infrastructure is recognised before it gets a guess.
- Geo-based escalation — step up requirements for logins from countries your team never works from, instead of blocking them outright and locking out a colleague on holiday.
Reporting & compliance
- Extended audit retention beyond the free 90 days — often a hard requirement when an auditor asks for a year.
- Scheduled email digests so the security posture reaches a stakeholder who will never open the dashboard.
- PDF export of audit history and posture reports.
- Compliance checker mapping active controls to common framework expectations, so “show me your controls” is an export rather than a week of screenshots.
No plugin makes a site compliant. What this does is evidence the technical controls you actually have in place, in a form an auditor can read — which is usually the tedious part of the exercise, not the hard part.
WooCommerce delta backup
A nightly full backup means a store can lose a day of orders. Delta backup captures order and customer records between full backups, so a restore does not silently discard transactions that arrived after the last snapshot — the failure mode that turns a recoverable incident into refunds and support tickets.
Agency tooling
- Hub and satellite — every managed site reports into one console. A fleet-wide view of scores, findings and incidents, instead of logging into thirty dashboards to find the one that regressed.
- White label — present the dashboard under your own brand to clients.
- Security roles — give staff access to security tooling without making them WordPress administrators, which is itself a hardening win.
- Multisite network support — network-level configuration and reporting.
What's normally paid — and isn't here
“Our free version is complete” is something every security plugin says, so there is no reason to take our word for it. The useful version of that claim is specific: here is where each capability usually sits in this market, and where it sits for us.
The middle column describes general convention across WordPress security plugins, not any particular product. Judge it against whatever you are running today.
| Capability | Where it usually sits | Total Security WP |
|---|---|---|
| Firewall that runs before WordPress loads Blocks the request before the bootstrap, DB connection and plugin loading | Usually premium | Free |
| Virtual patching for vulnerable plugins | Usually premium | Free |
| Automatic scheduled malware scanning | Usually premium | Free — weekly |
| Country-level geo-blocking | Usually premium | Free |
| Real-time traffic monitor Live request feed with one-click block | Usually premium | Free |
| Incident response tooling Quarantine, clean-file recovery, permission reset | Usually premium | Free |
| Database scanning Posts, comments, options, user meta | Usually premium | Free |
| Backup & restore | Usually a separate plugin | Free — built in |
| Recovery that works when WordPress won't load | Rarely offered | Free |
| Content Security Policy builder Observed, report-only first, then enforced | Rarely offered | Free |
| WP-CLI commands | Rarely offered | Free |
| Audit log retention | Often capped or gated | Free — 90 days, CSV export |
| Webhook alerts (Slack / Teams) | Often premium | Free |
| Two-factor authentication | Commonly free | Free — plus trusted devices |
| Breached-password checking | Uncommon at any tier | Free |
| Sites per install | — | Unlimited, free |
Every claim above is about software you can install for nothing and read line by line — it is GPLv2 and ships unobfuscated, with no build step hiding what runs. That is the difference between a marketing table and a verifiable one.
So what does Pro actually gate?
Being straight about this is the point. Pro does not hold back protection and sell it back to you. What it adds is automation and a live service:
- Things that run without you — daily scans, auto-quarantine, automatic patching, Under Attack Mode.
- Things that need our infrastructure — the hourly threat-intel feed, cloud reputation, Sentinel AI analysis. These are a running service with a running cost, which is what a subscription genuinely pays for.
- Things only multi-site operators need — white label, security roles, multisite, hub mode, compliance export.
If you log in regularly and run your own scans, the free tier may be all you ever need. We would rather say that than sell you something you will not use.
Full comparison
| Capability | Free | Pro |
|---|---|---|
| Dual-mode WAF (Optimized / Standard) | ✓ | ✓ |
| Rate limiting, brute force, DDoS shield | ✓ | ✓ |
| Bad-bot blocker & geo-blocking | ✓ | ✓ |
| Virtual patching (bundled + custom) | ✓ | ✓ |
| Deep hardening & server rule generation | ✓ | ✓ |
| Content Security Policy builder | ✓ | ✓ |
| Malware scanner (signature + token + taint) | ✓ | ✓ |
| File integrity monitoring & checksums | ✓ | ✓ |
| Database scanner | ✓ | ✓ |
| Quarantine, repair & permission reset | ✓ | ✓ |
| Backup, restore & standalone recovery | ✓ | ✓ |
| 2FA, CAPTCHA, password policy, sessions | ✓ | ✓ |
| Breached-password checking | ✓ | ✓ |
| Live Traffic monitor | ✓ | ✓ |
| Admin-bar Security Score | ✓ | ✓ |
| WP-CLI support | ✓ | ✓ |
| Notifications (email, Slack, Teams) | ✓ | ✓ |
| Automatic malware scans | Weekly | Daily / twice daily |
| Audit log retention | 90 days | Extended |
| Live threat intelligence feed | — | ✓ |
| Automatic patching as CVEs publish | — | ✓ |
| Under Attack Mode | — | ✓ |
| Auto-quarantine | — | ✓ |
| Sentinel AI triage | — | ✓ |
| Cloud reputation lookups | — | ✓ |
| Impossible travel & IP reputation | — | ✓ |
| Email digests, PDF export, compliance | — | ✓ |
| WooCommerce delta backup | — | ✓ |
| White label, roles, multisite, hub mode | — | ✓ |
Plans
- The complete security suite above
- Weekly automatic malware scan
- 90-day audit log with CSV export
- Backup, restore and emergency recovery
- Unlimited sites
- Community support on WordPress.org
- Live threat intel & hourly WAF updates
- Automatic patching as CVEs publish
- Under Attack Mode
- Daily scans & auto-quarantine
- Sentinel AI triage & cloud reputation
- Extended retention, digests, PDF & compliance
- WooCommerce delta backup
- White label, roles, multisite & hub mode
- Priority support
Pro is licensed per site with an offline grace window, so a temporary network failure never downgrades a site mid-incident. A license activates and deactivates from the dashboard, so moving a license between sites does not need a support ticket.
Questions
Is the free version crippled to push me to Pro?
No, and the comparison table above is the argument. Firewall, hardening, malware scanning, integrity monitoring, 2FA, backups, audit logging, Live Traffic and WP-CLI are all free, on unlimited sites, permanently. Free even includes automatic weekly scanning, which most competitors gate.
Pro sells automation and a live service. If you log in regularly and run scans yourself, free may genuinely be all you need — and we would rather say that than sell you something you will not use.
What happens if my license expires?
The plugin keeps working. Pro features stop and the site continues running the complete free suite — your firewall does not switch off and your site does not become unprotected. You keep the signature set you last received; you stop receiving new ones.
Does Pro send my site data to your servers?
License activation sends the license key and site URL. The threat-intel feed pulls signatures. Cloud reputation sends hashes and indicators, never file contents. Sentinel AI and bypass telemetry are separately consent-gated and off by default. The privacy disclosure lists every call in full.
Can I use Pro on client sites as an agency?
Yes — that is what the agency tooling exists for. White-label the dashboard, give staff security roles without administrator access, and run hub mode so every managed site reports into one console.
How do updates work now the custom updater is gone?
As of 1.2.0, all plugin code updates through WordPress.org like any other plugin. Pro features unlock locally via cryptographic license token, and security data that has to move faster than a release — WAF rules, virtual patches, CVE matches — updates independently through the threat-intel feed.