WordPress is a CMS based on PHP code for the popular blogging platform today. Freely available and used by millions of people around the world. But because of its popularity, wordpress get more attention by hackers and spammers. Everyone can be a hacker or spammer, even close friends! Do not get us exposed to malware sites/crimes that hurt us, and we reward a warning like the following picture!

DemocraticUnderground malware warning
For wordpress users who do not know anything about the program code, the plugin is the best way to secure your blog. Free, easy to use and safe. This post discusses some of the best wordpress plugins to make WordPress blog to be safe. Each plugin was created for different purposes, so that our blog will get the best protection of each part.
Here are 19 wordpress plugins that can be used to secure your website from hackers.
- Limit Login Attempts
Limit the number of login, so if people are not responsible for conducting experiments login for several times, will pop up a warning and block so that the opportunity will be reduced trial login.
- Login Lock Down
This plugin is the same function as the limit of login attempts plugin. If the login one for a couple of times, it will automatically be blocked so it can not re-login.
- User locker
Just like the previous plugin, Userlocker very useful to protect your blog from bruteforce attacks. It is used to lock the user after a specified number of login attempts.
- Hide Login
This plugin allows to create a custom URL for the login, logout, administration and register for your WordPress blog. You can make the url option to make it easier to remember than wp-login.php/wp-admin, such as your login url address can be set to http://www.aditif.com/login thus more secure login URL. This will confuse the hacker to find the login page, because typically the URL for the login in general is http://www.aditif.com/wp-admin
- Stealth login
As Hide Login plugin, this plugin serves to change the default URL. WordPress has the default login url. This makes it somewhat easier for hackers. So, we can use the plugin Stealth login to change the login url you for something skeptical. So, even if the hacker knows the password us, he will be difficult to enter the admin panel he did not know us as our login url. It certainly helps us in maintaining our blog from hackers.
- WordPress Firewall
Used to create a security code in wp-admin. By enabling Firewall WordPress plugin, all the code in wp-admin can not be changed with editor in wp-admin menu.
- Wp Security Scan
Analyze the file permision, Database security, password, eliminating the wp version.
- Antivirus
This plugin serves to scan themes wordpress, is there a script/file is dangerous, dangerous injection.
- WordPress File Monitor
Monitor the installation of WordPress, for the new file is added/removed/modified. When changes are detected this plugin sends an email alert can be sent to the address specified. If the hacker backdoor instill in our hosting then this plugin will send an alert. This Plugin to investigate a simple web requests with WordPress-specific heuristics to identify and stop most obvious attacks. Whitelist and blacklist intelligently pathological-looking phrases that appear on the field they are in the page request.
- Admin SSL
Admin SSL secures login page, admin area, posts, pages – whatever you want – using Private or Shared SSL. Once you have activated the plugin, you should go to the Admin SSL config page to enable SSL.
- Semisecure Login Reimagined
Semisecure Login Reimagined increases the security of the login process by using a combination of public and secret-key encryption to encrypt the password on the client-side when a user logs in. JavaScript is required to enable encryption. It is most useful for situations where SSL is not available, but the administrator wishes to have some additional security measures in place without sacrificing convenience.
- Content Security Policy
Content Security Policy prevents injection attacks, allowing content management to determine which sites you trust to serve JavaScript and other types of content on their sites. Any content that is not expressly permitted by the policy will be blocked from loading.
- Secure WordPress
Little help to secure your WordPress installation. This plugin removes error information on login page, adds index.html to plugin directory, removes the wp-version, except in admin area.
- WP members
WP-Member is an advanced WordPress membership plugin that adds many membership features including registration customization, total content protection for posts, pages and categories, content teasers, automated membership management, automated payment processing and many more.
- Ultimate security check
One of the rare security plugins which are updated regularly. It is a wordpress security plugin which scans your wordpress installation and assigns security grade based on passed tests.
- AskApache Password Protect
This plugin doesn’t control WordPress or mess with your database, instead it utilizes fast, tried-and-true built-in Security features to add multiple layers of security to your blog. This plugin is specifically designed and regularly updated specifically to stop automated and unskilled attackers attempts to exploit vulnerabilities on your blog resulting in a hacked site.
- Exploit scanner
It seaches in your WordPress database for any sort of infection which may indicate that your blog is accessed by any hacker. It includes all files, comments and database in its scan to detect any sort of suspicion.
- Login encrypt
Login Encrypt is a security plugin. It uses a complex combination of DES and RSA. This combination is used to encrypt your password protecting you from hackers.
- WP Email Guard
WP Email Guard protects your email addresses included on any post or page from being crawled by spammers. It converts every email written within your post body into a JavaScript code, so the emails is readable and can be clicked by humans only. Spammers can’t crawl JavaScript.
Plugins above can help preserve our favorite blogs, but hackers are out there still have a method that can penetrate our security. Nothing is safe in cyberspace, do not forget to periodically backup. At least the above plugin can make us sleep well at night.
If your website is currently being attacked by malware are detected as malware such as the following display, you should immediately do a scan and remove malware code in ways that are here.

Mysticro malware detected