Protects WordPress with a web application firewall, malware scanner, two-factor authentication, and security monitoring tools.
Kadence Security
Plugin Health & Stats
Historical overview
364-day WordPress.org historyQuick take
Kadence Security is a strong fit when you want WordPress login security, two-factor authentication, brute-force protection, password policy controls, vulnerability scanning, and hardening in one plugin. It is the product formerly known as iThemes Security and Solid Security, so the current Kadence Security review needs to account for both its mature feature set and its recent rebranding.
I would use the free version when the priority is strengthening user accounts and identifying vulnerable software. Kadence Security Pro becomes more relevant when you need Patchstack virtual patching, trusted-device controls, passwordless login, reCAPTCHA, richer activity logging, hourly scanning, and version-management automation.
Best fit: Kadence Security makes the most sense for WordPress sites that want strong account protection, two-factor authentication, vulnerability scanning, and optional virtual patching. I would look elsewhere for sites that only need a simple login limiter or teams expecting a standalone malware-cleanup service.
What Kadence Security focuses on
Kadence Security is primarily a WordPress hardening and account-protection plugin. Its strongest area is controlling how users authenticate, reducing brute-force exposure, enforcing stronger passwords, monitoring for vulnerable software, and adding firewall-oriented protections around WordPress.
The plugin also includes a Site Scanner. In the free version, scheduled checks can run four times per day for known vulnerabilities in WordPress core, plugins, and themes. Kadence Security Pro increases the scanning cadence and adds more automation around vulnerable software.
Features that matter in a Kadence Security setup
Two-factor authentication and password policy
Kadence Security can add two-factor authentication using authenticator apps, email, and backup codes, and it can enforce password requirements for users. These are practical protections because compromised passwords remain one of the most common paths into WordPress accounts.
Brute-force protection and login hardening
The plugin includes brute-force defenses and other login protections designed to reduce repeated credential attacks. It also provides controls that make common WordPress login patterns less predictable and easier to monitor.
Vulnerability scanning
The free Site Scanner checks WordPress core, plugins, and themes for known vulnerabilities and also uses Google Safe Browsing data to check whether a site has been flagged. The free scanning schedule is four times per day, while Pro can scan hourly.
Patchstack virtual patching in Pro
Kadence Security Pro integrates with Patchstack for automated virtual patching of supported vulnerabilities. This can reduce exposure when a vulnerable plugin or theme has not yet shipped its own fix, but it should not be treated as a reason to stop updating software.
Trusted devices, passwordless login, and activity logging
Pro adds trusted-device controls, passwordless login, reCAPTCHA, user activity logging, and version-management features. Those tools are most useful on sites with multiple administrators, editors, customers, or other user roles where account behavior needs more oversight.
Kadence Security Free vs Pro
The Kadence Security Free vs Pro decision starts with account protection. As a WordPress security plugin, Kadence Security Free is enough when you mainly need two-factor authentication, password policies, brute-force protection, and regular vulnerability scanning. It covers the account-security layer well without forcing a paid upgrade just to enable 2FA.
Kadence Security Pro becomes more compelling for sites that need virtual patching, hourly scanning, trusted-device controls, passwordless login, reCAPTCHA, richer security logs, and automated version-management behavior. Those are operational features rather than basic protection.
Compatibility and operational trade-offs
Kadence Security 10.0.3 currently requires WordPress 6.5 or newer and PHP 7.4 or newer, and WordPress.org lists it as tested through WordPress 7.0.4. That tested-up-to value is worth noting if your site is already on WordPress 7.1.
Official plugin guidance also says the plugin requires Apache or LiteSpeed with mod_rewrite, or NGINX. Some security features make meaningful changes to site files, database settings, and rewrite behavior, so Kadence recommends making a complete backup before enabling protection on an existing site.
I would also separate vulnerability patching from malware cleanup. Virtual patches can block exploitation paths for supported vulnerabilities, but that is not the same thing as guaranteeing an already-compromised site has been cleaned.
Kadence Security pricing
Pricing checked September 9, 2026. Kadence Security has a free version on WordPress.org and the plugin page clearly identifies multiple Pro-only features. However, Kadence’s current public pricing and product pages do not give me a clean standalone Kadence Security Pro price that I can verify independently.
Rather than quote an outdated iThemes or Solid Security price, I would verify the current paid route directly in Kadence’s checkout or current bundle before buying. Kadence’s broader product subscriptions are annual and renew automatically unless cancelled, but that does not give enough evidence for me to assign a standalone Security Pro number here.
PluginSuggest verdict
This Kadence Security review is strongest for sites that care about login security, vulnerability monitoring, and account policy. The free version covers more than a simple brute-force plugin, while Pro adds virtual patching and operational controls that matter more on multi-user or business sites.
As a WordPress security plugin, Kadence Security is most useful when those account and vulnerability features match your threat model. I would shortlist it on that basis. I would not choose it simply because it has many settings, and I would verify current Pro licensing before making a paid decision because the present Kadence pricing structure is not presented as a simple standalone security-plugin price.
Kadence Security FAQs
Is Kadence Security free?
Yes. The free plugin includes core login security, two-factor authentication, password requirements, brute-force protection, and vulnerability scanning.
What was Kadence Security called before?
The plugin was previously known as iThemes Security and later Solid Security before being rebranded as Kadence Security.
Does Kadence Security include two-factor authentication for free?
Yes. Two-factor authentication is available in the free plugin, with additional advanced authentication controls available in Pro.
What does Kadence Security Pro add?
Pro adds features including Patchstack virtual patching, hourly Site Scanner checks, trusted devices, passwordless login, reCAPTCHA, user logging, and version-management controls.
How much does Kadence Security Pro cost?
Kadence currently exposes Pro functionality but its public pricing pages do not provide a clean standalone Kadence Security Pro price I can verify as of September 9, 2026. I would confirm the current checkout or bundle before buying.
Is Kadence Security tested with WordPress 7.1?
Not according to the current WordPress.org listing. Version 10.0.3 is listed as tested through WordPress 7.0.4.
Compare before you install
Similar Plugins
Hardens WordPress with two-factor authentication, login protection, vulnerability detection, SSL tools, and security controls.
Hardens WordPress with login protection, two-factor authentication, vulnerability scanning, firewall controls, and security tools.