WordPress · Security Free

Demfilz Security

A lightweight, no-nonsense security plugin for WordPress: brute-force lockouts, email two-factor, a firewall, hardening, core file scans and an activity log — plus protections built specifically for WooCommerce stores, like card-testing defence and fake-order blocking. Sensible protections are on from the moment you activate.

v1.0.0 · .zip · WordPress 5.6+ · PHP 7.2+ · free · GPL-2.0+

Brute-force lockouts & email 2FA Firewall with IP block/allow lists WooCommerce card-testing defence

What it does

Demfilz Security locks down the places attackers actually hit: the login screen (including XML-RPC and the WooCommerce My Account login), malicious requests probing your URLs, quiet file changes in WordPress core, and — if you run a store — the checkout, where card testers and bot orders do real damage.

The WordPress protections work on any site. The WooCommerce features switch on automatically when WooCommerce is active — nothing extra to install.

Sensible from the first minute

Activate the plugin and open Security in the admin menu — sensible protections are already on. Review the settings and add your own IP to the allowlist for peace of mind. Everything is a switch you can see and turn off.

Nothing phones home

The plugin makes no calls to Demfilz servers. The only outbound request is to the official api.wordpress.org checksums API, used by the file scanner — and no data about your site is sent anywhere.

Protection

Six layers, one plugin

Every protection group from the plugin — each one a switch you control.

Login protection

Limit failed logins per IP with automatic escalation to a 24-hour block, require an emailed 6-digit code for chosen roles, reject bots with an invisible honeypot, and stop leaking whether the username or password was wrong. Covers wp-login.php, XML-RPC and the WooCommerce My Account login.

Firewall

IP blocklist and allowlist with CIDR ranges, heuristic filtering of SQL injection, path traversal, XSS and code-execution probes (multi-decoded), optional attack-tool user agent blocking, user enumeration blocking, one-switch XML-RPC disable, and trusted-proxy support for CDNs.

Hardening

Hide the WordPress version, disable the plugin/theme file editors, send security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, optional HSTS), and disable pingbacks and, optionally, application passwords.

File integrity scanning

Compares every core file against the official wordpress.org checksums — flagging modified or missing core files, unexpected files inside wp-admin / wp-includes, and PHP files hiding in your uploads folder. Daily or weekly, with a one-click manual scan and optional email alerts.

Activity log

Logins, failed logins, lockouts, firewall blocks, user and role changes, plugin and theme changes, core updates, password resets and scans — all in a filterable log with configurable retention.

WooCommerce protection

Card-testing defence that blocks IPs racking up failed payments and rate-limits checkout per IP, checkout and registration honeypots, disposable-email blocking, an order blocklist (email, domain, IP/CIDR, phone) and alerts when card testing is detected.

How it works

Protected in four steps

1

Install

Upload the plugin .zip and activate it.

2

Open Security

Go to Security in the admin menu — sensible protections are already on.

3

Allowlist your IP

Add your own IP to the allowlist for peace of mind.

4

Tune it

Choose two-factor roles, firewall options and WooCommerce protections.

Read the full setup guide →
activity log
# recent activity
firewall .. blocked SQLi probe in URL
login ..... 5 failures → 20-min lockout
login ..... repeat offender → 24-h block
scan ...... core files match wordpress.org ✓
checkout .. card testing → IP blocked

// every event filterable, retention configurable

Running WooCommerce? The store protections — card-testing defence, checkout honeypots, disposable-email blocking and the order blocklist — switch on automatically when WooCommerce is active.

Download

Get Demfilz Security — free

Download the plugin, upload it to WordPress and activate — sensible protections are on from the start.

Demfilz Security v1.0.0

.zip · ~42 KB · WordPress 5.6+ · PHP 7.2+ · GPL-2.0+

Download the plugin (.zip)

Read the setup guide →

Free and open source (GPL-2.0+). Works on any WordPress site — the WooCommerce protections activate automatically when WooCommerce is present.

FAQs

Common questions

Is Demfilz Security a good free WordPress security plugin?

Demfilz Security is a lightweight, free security plugin for WordPress with protections built specifically for WooCommerce stores. It covers login protection (brute-force lockouts and email two-factor authentication), a firewall, hardening, core file integrity scanning and a filterable activity log, plus card-testing and fake-order defences for WooCommerce. It's a free download from this page — it isn't listed in the WordPress.org plugin directory — and it runs on WordPress 5.6+ and PHP 7.2+.

How do I stop brute force attacks on my WordPress login?

Demfilz Security limits failed login attempts per IP and automatically escalates repeat offenders to a 24-hour block. An invisible login honeypot instantly rejects most bots, and generic login errors stop telling attackers whether the username or the password was wrong. The protection covers wp-login.php, XML-RPC and the WooCommerce My Account login. Lockouts expire automatically — 20 minutes by default.

Does Demfilz Security protect WooCommerce against card testing?

Yes. The card-testing defence automatically blocks IPs that rack up failed payments and rate-limits checkout attempts per IP, and the plugin can alert you when card testing is detected. These store protections switch on automatically when WooCommerce is active — there's nothing extra to install.

Is there a WordPress firewall included in the plugin?

Yes. The firewall gives you an IP blocklist and allowlist with CIDR range support, heuristic filtering of malicious requests (SQL injection, path traversal, cross-site scripting and code-execution probes in URLs, multi-decoded to catch obfuscation), optional blocking of attack-tool user agents like sqlmap, nikto and wpscan, user enumeration blocking, and a one-switch option to disable XML-RPC entirely. It's a tripwire that stops opportunistic scanners — not a substitute for keeping plugins updated — and logged-in administrators are exempt, so it won't get in your way. It's also reverse proxy and CDN aware via an opt-in trusted proxy header.

Can I add two-factor authentication to WordPress with this plugin?

Yes. Demfilz Security adds email two-factor authentication: the roles you choose (administrators, shop managers and so on) must enter a 6-digit code emailed to them when they log in. Password-only logins over XML-RPC and the REST API are refused for two-factor users, while application passwords continue to work for apps that need API access. There's an emergency off-switch via wp-config.php if you ever can't receive email.

Does the plugin scan WordPress files for malware or tampering?

It runs a file integrity scan that compares every core file against the official wordpress.org checksums for your exact WordPress version and locale. It flags modified core files, missing core files, unexpected files inside wp-admin and wp-includes, and PHP files hiding in your uploads folder — a classic sign of compromise. Scans run daily or weekly, with a one-click manual scan and optional email alerts. No data about your site is sent anywhere; the only outbound request is to wordpress.org for the checksums.

How do I block fake orders and spam accounts in WooCommerce?

Demfilz Security adds checkout and registration honeypots that reject bot orders and fake customer accounts, blocks disposable (throwaway) email addresses at registration and checkout using a built-in list plus your own additions, and includes an order blocklist so you can block checkout by email address, email domain, IP or CIDR range, or phone number.

Need a WordPress plugin like this?

Security, payments, integrations or something entirely custom — this is the kind of thing we build. Tell us what you need and we'll come back with a plan and a fixed quote.