
Secupress Pro – Premium WordPress Security Plugin
/Year

Comprehensive Security for WordPress Websites
SecuPress Pro is a dedicated security solution designed to protect WordPress websites from unauthorized access, malware infections, brute force attacks, and data breaches. Built with an intuitive admin interface, it allows site administrators to assess their current security posture, run comprehensive scans, and apply fixes to protect critical assets.
Latest Version 2.6.3 Changes
SecuPress released version 2.6.3 on July 21, 2026. This release addresses specific bug fixes, including fixing an uncaught TypeError involving str_rot13(), resolving an antispam.min.js error, and fixing an issue with the is_process_running() function.
- Fix: Uncaught TypeError: strrot13(): Argument #1 ($string) must be of type string, array given.
- Fix: antispam.min.js error.
- Fix: isprocessrunning() error again.
What SecuPress Pro Does
SecuPress Pro acts as a defensive shield for WordPress installations by continuously monitoring site health and blocking malicious activity. Key operational capabilities include:
- Automated malware and file integrity scanning to identify altered core files, suspicious code, or compromised themes and plugins.
- Firewall protection to filter out bad bots, malicious URLs, and illegitimate HTTP requests before they impact your server.
- Login protection features, including customizable login URLs, GeoIP login blocking, brute-force mitigation, and passwordless authentication options.
- Database and core hardening, such as blocking user enumeration, enforcing strong password policies, and securing WordPress security keys.
- Spam prevention mechanisms targeting comment forms and automated registration attempts.
Who Should Use SecuPress Pro
SecuPress Pro is designed for WordPress site owners, web agencies, freelancers, and e-commerce operators who require reliable site protection without complex security configurations. It suits businesses handling sensitive customer data, membership portals with frequent user logins, and high-traffic sites seeking to reduce server overhead caused by bad bots and automated intrusion attempts.
Key Capabilities and Features
SecuPress Pro combines proactive defense mechanisms with diagnostic security scans:
- 35+ Automated Security Scanners: Evaluate core files, configuration settings, user roles, and active plugins to pinpoint vulnerabilities quickly.
- GeoIP Location Blocking: Restrict or allow login attempts based on geographic origin to prevent localized brute-force attacks.
- Custom Login URL (Move Login): Conceal the standard wp-login.php endpoint and implement honeypots to confuse automated hacking scripts.
- Anti-Spam Tools: Block malicious comment bots without burdening real visitors with complex CAPTCHA challenges.
- Security Task Priority Notices: Receive color-coded dashboard notices that help prioritize necessary updates and system patches.
Practical WordPress Use Cases
SecuPress Pro addresses several critical security operational needs across different site environments:
- Hardening WooCommerce Stores: Secures customer checkout and login pages against credential stuffing, protecting user accounts and transactional integrity.
- Agency Management: Enables agencies to apply consistent security configurations across multiple client sites to minimize maintenance overhead.
- Preventing Bot Spam: Eliminates comment and user registration spam on active blogs and online communities using built-in anti-spam filters.
- Blocking Unauthorized Access: Prevents attacker scripts from guessing admin accounts by blocking user enumeration and renaming default admin usernames.
Setup and Compatibility Considerations
SecuPress Pro operates smoothly on standard PHP and WordPress environments. It supports modern WordPress versions and integrates cleanly with mainstream hosting providers. For sites running custom directory structures (such as Bedrock installations), dedicated developer filters are available to ensure proper file path resolution. It is recommended to perform a full site backup prior to applying global security fixes or altering default login endpoints.
Why Choose SecuPress Pro on WPPick
WPPick provides verified, clean software downloads for WordPress professionals and site owners. Obtaining SecuPress Pro through WPPick offers access to essential security management tools, facilitating straightforward site hardening and protection against evolving web threats.
Latest Version Context (v2.6.3)
The latest update for SecuPress Pro (v2.6.3) addresses important bug fixes to maintain plugin stability and script reliability. Specific improvements in this release include:
- Fixed an uncaught TypeError involving the strrot13() function where an array was passed instead of a string.
- Resolved an issue causing errors in the antispam.min.js script.
- Fixed a recurring execution error in the isprocessrunning() background function.
Frequently Asked Questions
How does SecuPress Pro protect against brute-force attacks?
SecuPress Pro limits failed login attempts, allows custom login page URLs, blocks known bad usernames, and offers GeoIP restrictions to stop automated login bots before they gain access.
Does SecuPress Pro replace the need for regular backups?
While SecuPress Pro strengthens site defenses and protects core files, maintaining independent, automated off-site backups remains a best practice for complete disaster recovery planning.
Will SecuPress Pro slow down my WordPress site?
SecuPress Pro is engineered for efficient performance. By blocking malicious traffic and bad bots before they execute resource-heavy PHP scripts, it often helps reduce overall server resource usage.
Can I run SecuPress Pro alongside other security plugins?
It is best practice to run a single primary security plugin to avoid configuration conflicts, duplicate firewall rules, or redundant background file scanning.
I. Download Limits & Account Benefits
- Free Downloads: Each email address receives 3 downloads per day for free products
- Upgrade Benefits: Purchase any paid product to increase your daily download limit by 3 for each paid product
- No Account Required: You can download immediately by receiving the download link via email
- Account Recommended: Create an account for easier access to your order history and direct update downloads
II. Understanding GPL vs Official Versions
Important: The products available on WPPick are GPL-licensed versions, which differ from official developer versions. Before purchasing, please read our comprehensive guide: Understanding GPL & Official Differences at WPPick
Key Points:
- GPL versions may not include premium support from original developers
- Updates may be delayed compared to official releases
- Some premium features might have limitations
- Always consider your specific needs and support requirements
III. Support & Assistance
We’re here to help through multiple channels:
- Email Support: Direct email assistance for all inquiries
- Live Chat: Real-time support during business hours
- Comprehensive Documentation: Detailed guides and tutorials
IV. Order Tracking
Access your complete purchase history and download links anytime: Order History
V. Account Access
New to WPPick? Login or Create Account to manage your downloads and orders efficiently.
VI. Refund Protection
We stand behind our products with a clear refund policy. Review our terms: Refund Policy
VII. Privacy & Security
Your data security is our priority. Learn how we protect your information: Privacy Policy
VII. Terms of Service
Understanding our service terms ensures a smooth experience: Terms of Use
Quick Tips for Best Experience
- Verify Compatibility: Check plugin/theme compatibility with your WordPress version
- Backup First: Always backup your site before installing new plugins or themes
- Test Environment: Consider testing on a staging site first
- Stay Updated: Regularly check for updates in your account dashboard
- Read Documentation: Review any included documentation for optimal setup
Need Help?
If you have questions about downloads, licensing, or need technical assistance, don’t hesitate to contact our support team. We’re committed to ensuring you have the best possible experience with WPPick products.
Ready to get started? Your download adventure begins with just one click!
- Fix: "Uncaught TypeError: str_rot13(): Argument #1 ($string) must be of type string, array given"
- Fix: antispam.min.js error
- Fix: is_process_running() error again.
- Possible fatal error when the data files are not correctly extracted.
- Users with same email domain present before the activation of the same name module were still tagged as bad.
- Fatal error on empty JSON
- Users from REST API still visible, it's CASE SENSITIVE!?
- Require module tools on submodule activation
- User secupress.me instead of google.com for testing
- Do not unvalidate passwordless email on plugin deactivation or licence deco
- GeoIP Location on Login
- Search field in admin UI.
- Scanner for malwares in our 35 scanners.
- UI for Malware Scanner has been improved, and will be again. You'll find a "WP File Integrity" which has always been there since 1.0, just not mentionned as is.
- Add WP 2FA compatibility to Easy Login scan
- Dashboard Widget not displaying graphs
- PHP Version Scanner was saying that the last version was "ok tier"
- PasswordLess activation checkbox was not checked after reload
- Remove secupress-data directory on uninstall (I forgot, my bad)
- "wp-includes/version.php" should not be tagged "different" anymore if you use a localised zip (in malware scanners)
- Possible fatal error when deactivating the module "Disable all actions on plugins" + "disable all actions on FTP"
- Possible fatal error "Call to undefined method SecuPress_Background_Process_Bad_Plugins::is_processing()"
- Colored notices can be added up in the plugins page to help you prioritize updates by showing you since when the update is available.
- The standalone "SF Move Login" is now renamed "SP Move Login" and since it's the same feature as the one here, it will be deactivated and this feature here activated.
- "Move Login" feature can now display a Honeypot instead of a message or page. This is an expert setting, also, only available if you only have Admins on your site.
- Translations are now done using the new `.l10n.php` format.
- "Move login" feature will now display every other slugs, it now depends on the login one. "Register" is only available is the registration is open.
- Dashboard widget finally get a skin, can display a graph to check evolution of monthly attacks.
- All the messages from the "unlock yourself as an admin" on login page have been set to the same one to prevent guessing an admin email. props to Lohen Florent
- JS Error when Antispam Comment Timer module is active.
- Correct custom validity for roles in some cases.
- Warning for undefined SECUPRESS_INSTALLED_MUPLUGINS constant.
- Warning when the distant DB was not accessible.
- Passwords couldn't be updated when Passwordless was active, even if your role was not targeted, or module activation not validated yet.
- Changelogs couldn't be opened in the iframe popup in plugins.php page when "Prevent Actions on Plugins" feature was activated.
- Force Better Encryption System
- Add the filter "secupress.get_wp_directory" to make a better compat with BedRock (with which we are not compatible natively)
- Password reset cannot be asked for account using PasswordLess
- Add a message on "Forbid user enumeration" to recall that author front pages will be replaced by homepage
- Remove ajax call from antispam delay module to prevent unwanted indexed ajax URL
- Password reset was not possible for some roles, due to activation+deactivation of the PasswordLess module
- Some notices where duplicated
- Password not updating in "Force Strong Passwords" module
- Fix: Check allowed IP before auth_redirect in "bad usernames" module
- Update: Allowed IP List
- Remove "1" from "Bad Usernames" because Man/age WP use it as a fake login and it break the connection
- Possible multiple notices when malware database is updating
- Possible PHP Warning when renaming a username
- Fatal error when saving Firewall settings
- Missing captcha session on registration page
- Better UI and UX. We use the WP login page and not our own page design
- Module "Password Lifespan" now depends of "Force Strong Passwords"
- Constant SECUPRESS_MODE improved, read the doc: https://docs.secupress.me/article/237-secupressmode
- Updated ZXCVBN libs
- Cookie hash file was not created when running the autofix
- "Bad Url Access" and "Bad File Extensions" were tagged as "fixable in pro only"
- "Already done your way" message on "Security Keys" module was wrong.
- Upgrader should always check the mu version file
- Remove "mail*" from the bad usernames list, too wide (Hello Maïlis & Mailisa...)
- Regenerating salt keys will now display a notice message as a feedback #UX
- Some strings were not translated.
- Better handling for "Rename User Names"
- "Show Admin Bar Menu" & "Hide Contextual Help & Tips"
- "Show Contextual Help & Tips" and "Admin Bar Menu" are now a user setting