Pricing
Real security in the free tier. Not a trial.
Passkeys, 2FA, and brute-force protection are free forever. Upgrade for advanced behavioural detection, honeypots, and agency management tools.
See exactly what's been tested — dated, versioned, and re-verified after every fix →Free
The core protection every WordPress site should have
£0
/ forever
Get free access
Free includes
-
Passkeys (WebAuthn), bound to your domain Phishing-resistant by design. A fake login page cannot trick a browser into offering a passkey scoped to a different site.
-
Standard TOTP two-factor authentication Works with any authenticator app: Google Authenticator, Authy, 1Password, Bitwarden.
-
Trusted devices, one-click to forget Only a hash of the device token is ever stored, never the plaintext.
-
Brute-force protection, automatic lockout Per-IP and per-username, with a clear lockout message rather than a silent failure.
-
Country blocking, 166 countries Matched locally against downloaded range data. Zero visitor telemetry sent to third parties.
-
Verified Googlebot / Bingbot exemption Confirmed via reverse+forward DNS checks, as recommended by official Google documentation.
-
Correct IP resolution behind CDNs and proxies Trusts REMOTE_ADDR by default and only consults a proxy header if you explicitly enable and name it. Other WordPress country-blocking plugins have shipped real, exploitable header-spoofing bugs (CVE-2025-13694, CVE-2022-1762) — this doesn't.
Most Popular
Pro
Single site protection with full active threat detection and hardening
£39.99
/ year
Apply for Pro Beta
Rigorously validated passkey engine: tested against official CBOR spec vectors, real captured authenticator data, and 200,000 fuzzed inputs. See the results →
Pro includes
-
Phantom records New Invisible decoy records with no legitimate path to trigger them — a hit means someone is browsing data that doesn't exist for anyone.
-
Behavioral login cadence New Compares login rhythm against the account's established human patterns — one weighted signal among several, never a standalone verdict.
-
Bot Shield reconnaissance detection Catches automated sweeps by pattern across 3+ fingerprinting paths in 90 seconds.
-
Object injection & malware scanning Catches both PHP serialization markers (O: and C:), plus a tokenizer-based scanner that can't be evaded with whitespace or comment tricks the way a plain text search can.
-
File integrity & semantic version scanning Real version-range comparison against known-vulnerable ranges, not naive string matching that gets "4.9" vs "4.10" wrong.
-
Tamper-evident hash-chained audit log
-
Full site hardening & threat intelligence
-
Emergency kill switch One wp-config.php constant instantly restores access if you're ever locked out — checked consistently across every blocking module, not exposed anywhere an attacker with a compromised admin login could reach it.
-
Offline license validation Checked locally with the same cryptographic signature verification used for passkeys — no phone-home, consistent with zero visitor telemetry.
Agency
Multi-site licensing, white-labelling, and centralized management for client builds
£149
/ year
Get Agency access
Covers up to 25 client sites: under £6/site/year with full Pro detection features and agency workflow tools.
Agency includes
-
25 Pro site licenses included Activate across all client websites with centralized dashboard management.
-
Complete white-labelling Agency Rebrand or hide SecondGate branding completely from client WordPress dashboards.
-
1-Click configuration export & import Deploy pre-configured security profiles to new client builds in seconds.
-
Client-ready audit log exports Generate tamper-evident security reports for monthly client maintenance deliverables.
-
Central webhook & Slack alert routing Send threat alerts from all client sites directly into your agency monitoring channel.
-
Priority developer support channel
Applying for the early release cohort? We are selecting 100 technical testers for complimentary Pro access.
