Skip to main content
Kadence Security logo

Kadence Security

Adds login security, 2FA, password policy, brute-force protection, vulnerability scanning, and optional Pro virtual patching to WordPress.
SecurityFreemium
Visit Plugin
Last Updated: September 9, 2026

Plugin Health & Stats

Checked 2 weeks agoSource: WordPress.org
Active installs
700,000+Official WordPress.org tier
WP.org rating
4.6/53,990 ratings
Version
10.0.4Current repository release
Last updated
2 weeks agoSep 16, 2026
Total downloads39,432,766
Tested with WP7.1.1
Requires WP6.5+
Requires PHP7.4+
Support resolved (2 mo.)5 of 14 (36%)
Plugin age15 years, 11 months
Updates observed1
Tracking sinceSep 12, 2026
Repository data is older than 3 days. Showing the latest successful snapshot.

Historical overview

364-day WordPress.org history
Download trendDaily package downloads · last 90 days
7d44,560 30d384,026 90d890,149 Peak day204.6KSep 17
Jul 3Aug 1Aug 31Sep 30
Active version adoptionCurrent usage share
10.0 55.2%9.3 14.2%other 13.8%9.4 10.6%8.1 6.3%

Quick take

Kadence Security is a strong fit when you want WordPress login security, two-factor authentication, brute-force protection, password policy controls, vulnerability scanning, and hardening in one plugin. It is the product formerly known as iThemes Security and Solid Security, so the current Kadence Security review needs to account for both its mature feature set and its recent rebranding.

I would use the free version when the priority is strengthening user accounts and identifying vulnerable software. Kadence Security Pro becomes more relevant when you need Patchstack virtual patching, trusted-device controls, passwordless login, reCAPTCHA, richer activity logging, hourly scanning, and version-management automation.

Best fit: Kadence Security makes the most sense for WordPress sites that want strong account protection, two-factor authentication, vulnerability scanning, and optional virtual patching. I would look elsewhere for sites that only need a simple login limiter or teams expecting a standalone malware-cleanup service.

What Kadence Security focuses on

Kadence Security is primarily a WordPress hardening and account-protection plugin. Its strongest area is controlling how users authenticate, reducing brute-force exposure, enforcing stronger passwords, monitoring for vulnerable software, and adding firewall-oriented protections around WordPress.

The plugin also includes a Site Scanner. In the free version, scheduled checks can run four times per day for known vulnerabilities in WordPress core, plugins, and themes. Kadence Security Pro increases the scanning cadence and adds more automation around vulnerable software.

Features that matter in a Kadence Security setup

Two-factor authentication and password policy

Kadence Security can add two-factor authentication using authenticator apps, email, and backup codes, and it can enforce password requirements for users. These are practical protections because compromised passwords remain one of the most common paths into WordPress accounts.

Brute-force protection and login hardening

The plugin includes brute-force defenses and other login protections designed to reduce repeated credential attacks. It also provides controls that make common WordPress login patterns less predictable and easier to monitor.

Vulnerability scanning

The free Site Scanner checks WordPress core, plugins, and themes for known vulnerabilities and also uses Google Safe Browsing data to check whether a site has been flagged. The free scanning schedule is four times per day, while Pro can scan hourly.

Patchstack virtual patching in Pro

Kadence Security Pro integrates with Patchstack for automated virtual patching of supported vulnerabilities. This can reduce exposure when a vulnerable plugin or theme has not yet shipped its own fix, but it should not be treated as a reason to stop updating software.

Trusted devices, passwordless login, and activity logging

Pro adds trusted-device controls, passwordless login, reCAPTCHA, user activity logging, and version-management features. Those tools are most useful on sites with multiple administrators, editors, customers, or other user roles where account behavior needs more oversight.

Kadence Security Free vs Pro

The Kadence Security Free vs Pro decision starts with account protection. As a WordPress security plugin, Kadence Security Free is enough when you mainly need two-factor authentication, password policies, brute-force protection, and regular vulnerability scanning. It covers the account-security layer well without forcing a paid upgrade just to enable 2FA.

Kadence Security Pro becomes more compelling for sites that need virtual patching, hourly scanning, trusted-device controls, passwordless login, reCAPTCHA, richer security logs, and automated version-management behavior. Those are operational features rather than basic protection.

Choose Kadence Security if

  • You want strong user-account protection and vulnerability visibility inside WordPress.
  • You value 2FA and password policy controls in the free version.
  • You may want Patchstack virtual patching and advanced login controls later.

Keep it simpler if

  • You only need a basic failed-login limiter.
  • Your hosting or external security platform already handles vulnerability patching and account policy.
  • You do not want a plugin that changes multiple areas of WordPress security configuration.

Compatibility and operational trade-offs

Kadence Security 10.0.3 currently requires WordPress 6.5 or newer and PHP 7.4 or newer, and WordPress.org lists it as tested through WordPress 7.0.4. That tested-up-to value is worth noting if your site is already on WordPress 7.1.

Official plugin guidance also says the plugin requires Apache or LiteSpeed with mod_rewrite, or NGINX. Some security features make meaningful changes to site files, database settings, and rewrite behavior, so Kadence recommends making a complete backup before enabling protection on an existing site.

I would also separate vulnerability patching from malware cleanup. Virtual patches can block exploitation paths for supported vulnerabilities, but that is not the same thing as guaranteeing an already-compromised site has been cleaned.

Kadence Security pricing

Pricing checked September 9, 2026. Kadence Security has a free version on WordPress.org and the plugin page clearly identifies multiple Pro-only features. However, Kadence’s current public pricing and product pages do not give me a clean standalone Kadence Security Pro price that I can verify independently.

Rather than quote an outdated iThemes or Solid Security price, I would verify the current paid route directly in Kadence’s checkout or current bundle before buying. Kadence’s broader product subscriptions are annual and renew automatically unless cancelled, but that does not give enough evidence for me to assign a standalone Security Pro number here.

PluginSuggest verdict

This Kadence Security review is strongest for sites that care about login security, vulnerability monitoring, and account policy. The free version covers more than a simple brute-force plugin, while Pro adds virtual patching and operational controls that matter more on multi-user or business sites.

As a WordPress security plugin, Kadence Security is most useful when those account and vulnerability features match your threat model. I would shortlist it on that basis. I would not choose it simply because it has many settings, and I would verify current Pro licensing before making a paid decision because the present Kadence pricing structure is not presented as a simple standalone security-plugin price.

Kadence Security FAQs

Is Kadence Security free?

Yes. The free plugin includes core login security, two-factor authentication, password requirements, brute-force protection, and vulnerability scanning.

What was Kadence Security called before?

The plugin was previously known as iThemes Security and later Solid Security before being rebranded as Kadence Security.

Does Kadence Security include two-factor authentication for free?

Yes. Two-factor authentication is available in the free plugin, with additional advanced authentication controls available in Pro.

What does Kadence Security Pro add?

Pro adds features including Patchstack virtual patching, hourly Site Scanner checks, trusted devices, passwordless login, reCAPTCHA, user logging, and version-management controls.

How much does Kadence Security Pro cost?

Kadence currently exposes Pro functionality but its public pricing pages do not provide a clean standalone Kadence Security Pro price I can verify as of September 9, 2026. I would confirm the current checkout or bundle before buying.

Is Kadence Security tested with WordPress 7.1?

Not according to the current WordPress.org listing. Version 10.0.3 is listed as tested through WordPress 7.0.4.

Similar Plugins

Community Reviews

0 community reviews
Log in or create an account to write a review.
No published community reviews yet.