Solid Security
by SolidWP
Login hardening, two-factor, passkeys and file change detection with a lighter footprint than a full firewall.
This link may earn us a commission. It never changes our rating.
What Solid Security does
Login hardening, two-factor, passkeys and file change detection with a lighter footprint than a full firewall.
It sits in the security part of a WordPress stack and is sold by SolidWP on a freemium basis. We recommend it in our security guides because it does that one job well without asking you to rebuild the rest of the site around it.
Every plugin adds work to a page request, so treat this as a decision with a cost. Record a speed test before you install it and run the same test afterwards, on the same page, so you know exactly what it charged you.
Real user ratings
Solid Security is sold outside the WordPress.org directory, so there is no public user rating to quote. Our own editorial score is 4.5/5, based on the vendor documentation, the refund window and the measured performance cost.
Where Solid Security ranks elsewhere
| Publisher | List | Position |
|---|---|---|
| Elegant Themes | Best WordPress Plugins | #10 of 40 |
Positions are read from the published articles themselves, so they reflect that publisher's order rather than ours. Lists get re-ordered over time, so follow the link if you want the current version.
What changed in the latest version
Solid Security does not publish a changelog we can read automatically, so check the vendor's own release notes before you update a live site.
Pros and cons
- Strong login protection, modest overhead
- A free tier you can trial before paying
- Actively maintained and used on production sites we test
- No live traffic view
- The features most sites need sit in the paid tier
How to use it
- 1Take a full backup before enabling any blocking feature.
- 2Turn on login protection and two-factor for administrator accounts first.
- 3Schedule scans outside peak hours to protect response times.
- 4Set alerts to a monitored inbox, not the default admin address.
- 5Re-run the speed test so you know what the protection costs you.
How it compares
Other security plugins we recommend, with their rating and pricing model.
| Plugin | Our rating | WordPress.org | Pricing | Best for |
|---|---|---|---|---|
| Solid Security | 4.5 | n/a | Freemium | Strong login protection, modest overhead |
| Akismet | 4.7 | 4.7 (1,186) | Freemium | Catches almost all comment spam with no tuning |
| Antispam Bee | 4.8 | 4.8 (226) | Free | Privacy friendly spam filtering with no account |
| Duo | 4.2 | 4 (1) | Freemium | Central policy control for teams |
| Jetpack Protect | 4.3 | 4.6 (123) | Freemium | Free vulnerability alerts |
| Limit Login Attempts Reloaded | 4.8 | 4.8 (1,483) | Freemium | Big protection for almost no overhead |
Guides that cover Solid Security

8 Best WordPress Two-Factor Authentication Plugins for 2026
Two-factor authentication limits the damage of a stolen password. A sound rollout also needs recovery codes, role policies and an emergency access procedure.
Updated 10 September 2026

8 Best Brute Force Security Plugins for WordPress in 2026
Good brute force defence blocks automated login attempts without locking out real administrators. That takes layers, not one plugin.
Updated 10 September 2026
Alternatives
Other security plugins
Akismet
Automattic
Comment and form spam filtering run through Automattic's hosted service, checked against a global spam corpus.
1,186 reviews · 406.0M downloads · v5.7.2
Antispam Bee
pluginkollektiv
Blocks comment spam locally with no external service and no personal data leaving your server.
226 reviews · 13.0M downloads · v2.11.13
Duo
Cisco Duo
Enterprise two-factor from Cisco Duo, with push approval and device policy controls.
1 reviews · 20K downloads · v1.2.1
