All-In-One Security (AIOS) – Security and Firewall
by David Anderson / Team Updraft · Security
Also makes 15 other plugins · 6.3M+ installs across the portfolio →
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
M WP Mayor reviewed this plugin All In One WP Security & Firewall Plugin Review Read review ↗96 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
126.2K
now · peak 1.5M
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
7
releases in the last 12 months
3mo ago
latest release · v5.4.9
116
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 74% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “1M+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-04-07 · 1,491 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent review vibe
read from the latest 12 reviews to 2026-07-14Reviewers keep calling AIOS reliable for hardening and firewall work, with praise for the setup wizard and fast support, though one recent reviewer says its comment spam blocking let hundreds through.
Recent reviews
All reviews on wp.org ↗- ★★★★★ tsor101mo ago
Efficient and reliable.
Read on wp.org ↗ - ★★★★★ Oleg Chuvakin1mo ago
I have been using the AIOS plugin since around 2016, and working with WordPress since 2014. This means I have trusted AIOS with the core security of my projects for a very long time. I especially value the firewall, which is the very heart of this plugin. Without this shield, my sites would feel fragile and vulnerable. The AIOS plugin comes with exceptional technical support: their responses are fast, concise, and accurate. Outstanding work and excellent service!
Read on wp.org ↗ - ★★★★★ WSANADA2mo ago
Helped me to keep my websites safe.
Read on wp.org ↗ - ★★★★★ Scott2mo ago
I tried out a few AIOS plugins and wasn’t really satisfied with any of them. Then I installed this AIOS and was pleasantly surprised, because there was a wizard for the most important settings that opened right away. I then went through every tab in this plugin. Everywhere I looked, there were detailed explanations of what the available settings do. There’s also a scoring system that indicates the level of security. And all of this without even using the paid version—it’s basically basic protection. The paid version offers even more options, but even the Basic version alone is great for keeping yourself locked out! 🙂 The support team was friendly and patient; they helped me get back into the system quickly and even had some advice for me at the end. You can’t ask for more from an AIOS. I won’t be using the subscription service—I simply can’t afford it. :-/
Read on wp.org ↗ - ★★★★★ babysavers2mo ago
Decided to try this instead of moderating all comments. Nope nope nope. Hundreds of spam comments to parse through in just a few days. This is not even close to “spam prevention” even with every option enabled for both Comment Spam and Comment Spam IP monitoring. Do not rely on this plugin for spam control.
Read on wp.org ↗ - ★★★★★ juanmag3mo ago
Easy setup, clear logs, and it blocked suspicious traffic without breaking my site.
Read on wp.org ↗ - ★★★★★ m0n0mind3mo ago
We’re using AIOS for quite some years now already as our basic go-to solution for adding some extra-layers of security hardening features to our wordpress installs. In my opinion it’s one of the best freely available plugins in this category, actively developed and maintained and we have never been disappointed. We’re not using the whole set of available features, though. The support staff is also very helpful and the developers are open to feature and improvement requests as well. Keep up the good work!
Read on wp.org ↗ - ★★★★★ WPHostee3mo ago
At WPHostee.com, we host thousands of WordPress websites, and one thing they all have in common is AIOS. Quite simply, we would not feel comfortable running WordPress websites without it. We have tried many security plugins over the years, but AIOS remains our preferred choice thanks to its excellent protection, reliability, ease of use, and continuous improvements. It gives us confidence that our clients’ websites are protected against many of the most common security threats. For us, AIOS is not just another plugin—it is an essential part of every WordPress website we host. We highly recommend it to anyone serious about WordPress security. Thank you to the AIOS team for building such an outstanding product. Keep up the excellent work!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 5.4.9 TWEAK: Added a filter that validates POST requests containing UDRPC messages TWEAK: Update the internal common libs package to latest version 5.4.9
- — Version 5.4.8 SECURITY: Escaped debug log messages before rendering them in the admin area to prevent a stored XSS vulnerability. Thanks to Dmitrii Ignatyev for disclosing this defect. (This issue required both the debug logging featu 5.4.8
- — Version 5.4.7 FEATURE: Added a dashboard widget for the top 5 failed login attempts by IP & username and a chart for the number of failed logins over the last 7 days. FIX: WordPress 7.0 admin UI compatibility issues resolved. FIX: Bla 5.4.7
- — Version 5.4.6 FIX: PHP Fatal error: Uncaught Error: Call to a member function get_user_otp_algorithm() on null. FIX: Prevent redirection to settings when AIOS is installed through the onboarding wizard of another plugin. 5.4.6
- — Version 5.4.5 FEATURE: Added onboarding wizard on activation of the plugin. FEATURE: Added reports function for UDC. FEATURE: Added additional commands for interoperability with UDC FIX: Logged in users table not correctly tracking mu 5.4.5
- — Version 5.4.4 FEATURE: Added new and improved existing modules for UpdraftCentral. FIX: The theme’s custom 404 page does not parse and instead displays the shortcodes for wp-login.php, due to the login page having been renamed. FIX: 4 5.4.4
Known vulnerabilities
via Wordfence Intelligence27 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-06-05 CVE-2026-8438 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.4.7 Patched in 5.4.8
- Medium · 6.1 All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting ↗2024-02-06 CVE-2024-1037 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.2.5 Patched in 5.2.6
- 2023-07-11 Plaintext Storage of a Password Affects 5.1.9 Patched in 5.2.0
- Medium · 4.4 All-In-One Security (AIOS) <= 5.1.4 - Authenticated (Admin+) Stored Cross-Site Scripting ↗2023-03-20 CVE-2023-0157 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.1.4 Patched in 5.1.5
- 2023-02-14 CVE-2023-0156 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 5.1.4 Patched in 5.1.5
- 2022-12-09 CVE-2022-4346 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 5.1.2 Patched in 5.1.3
- 2022-11-17 Cross-Site Request Forgery (CSRF) Affects <= 5.1.0 Patched in 5.1.1
- 2022-09-30 Use of Less Trusted Source Affects 5.0.0 - 5.0.7 Patched in 5.0.8
- Medium · 6.1 All In One WP Security & Firewall <= 4.4.10 - Open Redirect and Reflected Cross-Site Scripting ↗2022-04-11 CVE-2021-25102 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.4.11 Patched in 4.4.11
- 2020-12-24 CVE-2020-29171 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.4.6 Patched in 4.4.6
- 2020-09-08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.3 Patched in 4.4.4
- Critical · 9.8 All In One WP Security & Firewall <= 4.0.8 - SQL Injection ↗2019-08-14 CVE-2016-10887 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.0.9 Patched in 4.0.9
- 2016-11-11 CVE-2016-10866 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.2.0 Patched in 4.2.0
- 2016-07-31 Guessable CAPTCHA Affects <= 4.1.2 Patched in 4.1.3
- Critical · 9.8 All In One WP Security & Firewall <= 4.0.6 - SQL Injection ↗2016-04-06 CVE-2016-10888 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.0.7 Patched in 4.0.7
- 2016-02-23 CVE-2016-10867 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.0.6 Patched in 4.0.6
- 2016-02-22 CVE-2016-10868 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.0.5 Patched in 4.0.5
- 2015-08-15 CVE-2015-9293 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.9.8 Patched in 3.9.8
- 2015-04-20 CVE-2015-9294 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.9.5 Patched in 3.9.5
- Critical · 9.8 All In One WP Security & Firewall <= 3.9.0 - SQL Injection ↗2015-04-06 CVE-2015-9310 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.9.1 Patched in 3.9.1
- Critical · 9.0 All In One WP Security & Firewall <= 3.8.7 - SQL Injection ↗2015-03-06 CVE-2015-0894 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.8.8 Patched in 3.8.8
- 2014-09-24 CVE-2014-6242 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.8.3 Patched in 3.8.3
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 55 languages, 9 at 90% or more
Plus 31 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention 1M+ installs · 4.8★ · 3 shared tags A -
Defender Security – Malware Scanner, Login Security & Firewall 80K+ installs · 4.8★ · 3 shared tags A -
Wordfence Login Security 60K+ installs · 3.9★ · 3 shared tags B
-
BulletProof Security 20K+ installs · 4.8★ · 3 shared tags A -
Wordfence Security – Firewall, Malware Scan, and Login Security 5M+ installs · 4.7★ · 2 shared tags A
-
Security Optimizer – The All-In-One Protection Plugin 1M+ installs · 4.5★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for All-In-One Security (AIOS) – Security and Firewall into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/all-in-one-wp-security-and-firewall" width="480" height="300" style="border:0" loading="lazy" title="All-In-One Security (AIOS) – Security and Firewall — Plugin Pulse"></iframe> All-In-One Security (AIOS) – Security and Firewall: 1M+ active installs, 4.7★ (1,715 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/all-in-one-wp-security-and-firewall