A lightweight, no-nonsense security plugin for WordPress: brute-force lockouts, email two-factor, a firewall, hardening, core file scans and an activity log — plus protections built specifically for WooCommerce stores, like card-testing defence and fake-order blocking. Sensible protections are on from the moment you activate.
v1.0.0 · .zip · WordPress 5.6+ · PHP 7.2+ · free · GPL-2.0+
Demfilz Security locks down the places attackers actually hit: the login screen (including XML-RPC and the WooCommerce My Account login), malicious requests probing your URLs, quiet file changes in WordPress core, and — if you run a store — the checkout, where card testers and bot orders do real damage.
The WordPress protections work on any site. The WooCommerce features switch on automatically when WooCommerce is active — nothing extra to install.
Activate the plugin and open Security in the admin menu — sensible protections are already on. Review the settings and add your own IP to the allowlist for peace of mind. Everything is a switch you can see and turn off.
The plugin makes no calls to Demfilz servers. The only outbound request is to the official api.wordpress.org checksums API, used by the file scanner — and no data about your site is sent anywhere.
Every protection group from the plugin — each one a switch you control.
Limit failed logins per IP with automatic escalation to a 24-hour block, require an emailed 6-digit code for chosen roles, reject bots with an invisible honeypot, and stop leaking whether the username or password was wrong. Covers wp-login.php, XML-RPC and the WooCommerce My Account login.
IP blocklist and allowlist with CIDR ranges, heuristic filtering of SQL injection, path traversal, XSS and code-execution probes (multi-decoded), optional attack-tool user agent blocking, user enumeration blocking, one-switch XML-RPC disable, and trusted-proxy support for CDNs.
Hide the WordPress version, disable the plugin/theme file editors, send security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, optional HSTS), and disable pingbacks and, optionally, application passwords.
Compares every core file against the official wordpress.org checksums — flagging modified or missing core files, unexpected files inside wp-admin / wp-includes, and PHP files hiding in your uploads folder. Daily or weekly, with a one-click manual scan and optional email alerts.
Logins, failed logins, lockouts, firewall blocks, user and role changes, plugin and theme changes, core updates, password resets and scans — all in a filterable log with configurable retention.
Card-testing defence that blocks IPs racking up failed payments and rate-limits checkout per IP, checkout and registration honeypots, disposable-email blocking, an order blocklist (email, domain, IP/CIDR, phone) and alerts when card testing is detected.
Upload the plugin .zip and activate it.
Go to Security in the admin menu — sensible protections are already on.
Add your own IP to the allowlist for peace of mind.
Choose two-factor roles, firewall options and WooCommerce protections.
Running WooCommerce? The store protections — card-testing defence, checkout honeypots, disposable-email blocking and the order blocklist — switch on automatically when WooCommerce is active.
Download the plugin, upload it to WordPress and activate — sensible protections are on from the start.
.zip · ~42 KB · WordPress 5.6+ · PHP 7.2+ · GPL-2.0+
Download the plugin (.zip)Free and open source (GPL-2.0+). Works on any WordPress site — the WooCommerce protections activate automatically when WooCommerce is present.
Demfilz Security is a lightweight, free security plugin for WordPress with protections built specifically for WooCommerce stores. It covers login protection (brute-force lockouts and email two-factor authentication), a firewall, hardening, core file integrity scanning and a filterable activity log, plus card-testing and fake-order defences for WooCommerce. It's a free download from this page — it isn't listed in the WordPress.org plugin directory — and it runs on WordPress 5.6+ and PHP 7.2+.
Demfilz Security limits failed login attempts per IP and automatically escalates repeat offenders to a 24-hour block. An invisible login honeypot instantly rejects most bots, and generic login errors stop telling attackers whether the username or the password was wrong. The protection covers wp-login.php, XML-RPC and the WooCommerce My Account login. Lockouts expire automatically — 20 minutes by default.
Yes. The card-testing defence automatically blocks IPs that rack up failed payments and rate-limits checkout attempts per IP, and the plugin can alert you when card testing is detected. These store protections switch on automatically when WooCommerce is active — there's nothing extra to install.
Yes. The firewall gives you an IP blocklist and allowlist with CIDR range support, heuristic filtering of malicious requests (SQL injection, path traversal, cross-site scripting and code-execution probes in URLs, multi-decoded to catch obfuscation), optional blocking of attack-tool user agents like sqlmap, nikto and wpscan, user enumeration blocking, and a one-switch option to disable XML-RPC entirely. It's a tripwire that stops opportunistic scanners — not a substitute for keeping plugins updated — and logged-in administrators are exempt, so it won't get in your way. It's also reverse proxy and CDN aware via an opt-in trusted proxy header.
Yes. Demfilz Security adds email two-factor authentication: the roles you choose (administrators, shop managers and so on) must enter a 6-digit code emailed to them when they log in. Password-only logins over XML-RPC and the REST API are refused for two-factor users, while application passwords continue to work for apps that need API access. There's an emergency off-switch via wp-config.php if you ever can't receive email.
It runs a file integrity scan that compares every core file against the official wordpress.org checksums for your exact WordPress version and locale. It flags modified core files, missing core files, unexpected files inside wp-admin and wp-includes, and PHP files hiding in your uploads folder — a classic sign of compromise. Scans run daily or weekly, with a one-click manual scan and optional email alerts. No data about your site is sent anywhere; the only outbound request is to wordpress.org for the checksums.
Demfilz Security adds checkout and registration honeypots that reject bot orders and fake customer accounts, blocks disposable (throwaway) email addresses at registration and checkout using a built-in list plus your own additions, and includes an order blocklist so you can block checkout by email address, email domain, IP or CIDR range, or phone number.
Security, payments, integrations or something entirely custom — this is the kind of thing we build. Tell us what you need and we'll come back with a plan and a fixed quote.