Su

Sucuri

by Sucuri

Cloud firewall and malware clean-up service with a WordPress plugin for scanning and hardening.

4.2384 WordPress.org reviewsSecurityFreemium

This link may earn us a commission. It never changes our rating.

What Sucuri does

Cloud firewall and malware clean-up service with a WordPress plugin for scanning and hardening.

It sits in the security part of a WordPress stack and is sold by Sucuri on a freemium basis. We recommend it in our security guides because it does that one job well without asking you to rebuild the rest of the site around it.

Every plugin adds work to a page request, so treat this as a decision with a cost. Record a speed test before you install it and run the same test afterwards, on the same page, so you know exactly what it charged you.

Real user ratings

Score

4.2/5

Reviews

384

Active installs

600,000+

Downloads

36.7M

Latest version

2.8

Last updated

2026-09-09

These figures come straight from the public WordPress.org plugin directory API for version 2.8, not from us. Check them yourself on the WordPress.org listing. Our own editorial score is 4.5/5.

Where Sucuri ranks elsewhere

PublisherListPosition
WPBeginnerBest WordPress Caching Plugins#4 of 5
TechRadarThe best WordPress plugins#7 of 20

Positions are read from the published articles themselves, so they reflect that publisher's order rather than ours. Lists get re-ordered over time, so follow the link if you want the current version.

What changed in the latest version

v2.8Latest release
  • Add one-time backup codes for Two-Factor Authentication. Ten codes are created when 2FA is turned on, any one of them will get you in if you lose your authenticator app, and each code stops working once it has been used. You can generate...
  • Add a search box and severity, plugin, and theme filters to the Audit Logs page, so you can find a specific event without paging through the whole history. Filtering and paging now happen instantly.
  • Add a one-click CSV download of the complete audit trail, ready for a compliance review, an incident timeline, or an archive before older records age out. Large histories export without slowing the site down.
  • Fix an issue that left the audit trail completely empty on sites that do not run in English. Events were recorded but never shown.
  • Fix audit entries being cut short or lost. Saving the WordPress Writing settings discarded the record of every other option changed in that same save, and a less-than sign in a site title or option value truncated the entry from that poi...
  • Fix plugin and theme names that contain an ampersand being shown with an HTML escape code in place of the character itself, both on the page and in the export, which also stopped them from being found by search.
  • Mask API keys, tokens, and salts in the audit trail. They were previously stored in plain text, and are now masked both as new events are recorded and as existing records are read back.
  • Fix a case where markup returned by the Sucuri API could reach the dashboard without being escaped.
v2.7.4
  • Improve the Two-Factor Authentication page to load the users list in pages, so it stays fast and reliable on sites with hundreds or thousands of users (for example, WooCommerce stores).
  • Add a search box to the Two-Factor Authentication page to quickly find users by username, email, or display name.
  • Strengthen input validation, access checks, and output escaping.
  • Add a one-click "Disable XML-RPC" option to the Hardening page to close a common brute-force and pingback-based DDoS attack vector, with a warning if an active plugin (e.g. Jetpack) depends on XML-RPC.
  • Fix a fatal error on PHP 8 when the API returns the "messages" field as a string instead of an array.
v2.7.3
  • Refactor AJAX handler to an explicit dispatch map for improved security and efficiency.
  • Improve 2FA section with more UI clarity.
  • Make light-mode default when no preference is defined. Correct inverted dark/light mode icons.
  • Fix i18n regression in 2FA status and setup templates.
  • Fix duplicate CSS property declarations.

Release notes are the developer's own words, published on WordPress.org. Read the full changelog

Pros and cons

  • Filtering happens before your server
  • A free tier you can trial before paying
  • Actively maintained and used on production sites we test
  • The firewall is a paid subscription
  • The features most sites need sit in the paid tier

How to use it

  1. 1Take a full backup before enabling any blocking feature.
  2. 2Turn on login protection and two-factor for administrator accounts first.
  3. 3Schedule scans outside peak hours to protect response times.
  4. 4Set alerts to a monitored inbox, not the default admin address.
  5. 5Re-run the speed test so you know what the protection costs you.

How it compares

Other security plugins we recommend, with their rating and pricing model.

PluginOur ratingWordPress.orgPricingBest for
Sucuri4.54.2 (384)FreemiumFiltering happens before your server
Akismet4.74.7 (1,186)FreemiumCatches almost all comment spam with no tuning
Antispam Bee4.84.8 (226)FreePrivacy friendly spam filtering with no account
Duo4.24 (1)FreemiumCentral policy control for teams
Jetpack Protect4.34.6 (123)FreemiumFree vulnerability alerts
Limit Login Attempts Reloaded4.84.8 (1,483)FreemiumBig protection for almost no overhead

Guides that cover Sucuri