Kadence Security – Password, Two Factor Authentication, and Brute Force Protection
by Nexcess · Security
Also makes 22 other plugins · 2.6M+ installs across the portfolio →
Harden your site security with Login Security, Two-Factor Authentication (2FA), Vulnerability Scanner, Firewall, and more. Formerly iThemes Security.
M WP Mayor reviewed this plugin iThemes Security: Secure Your WordPress Site and Get on with Your Life Read review ↗86 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,422 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
400.1K
now · peak 1.2M
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
11
releases in the last 12 months
3mo ago
latest release · v10.0.2
93
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 48% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “700K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2016-03-02 · 1,500 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 10.0.2 Bug Fix: Handle WP_Error in login interstitial session creation to prevent fatal errors. 10.0.2
- — Version 10.0.1 Bug Fix: Race condition in file write could empty wp-config.php/.htaccess files. 10.0.1
- — Version 10.0.0 Tweak: Updated branding from SolidWP to Kadence. New: QR code for 2FA is generated locally by default (the GD PHP extension is required), with a Kadence Security-hosted solution as a fallback. 10.0.0
- — Version 9.4.7 Bug Fix: Prevent email retry loops by ensuring the scheduled notification properties are saved. 9.4.7
- — Version 9.4.6 Enhancement: Update Patchstack details for existing vulnerabilities. 9.4.6
- — Version 9.4.5 Tweak: Ensure generated Nginx config rules are valid for customized directory structures. 9.4.5
Known vulnerabilities
via Wordfence Intelligence19 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2023-10-31 Protection Mechanism Failure Affects <= 9.0.0 Patched in 9.0.1
- 2023-03-27 CVE-2023-28786 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 8.1.4 Patched in 8.1.5
- 2021-04-22 Protection Mechanism Failure Affects < 7.9.1 Patched in 7.9.1
- 2018-06-25 CVE-2018-12636 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 7.0.3 Patched in 7.0.3
- 2018-03-05 CVE-2018-7433 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.0 Patched in 6.9.1
- 2016-10-06 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 5.6.2 Patched in 5.6.2
- 2016-09-27 Observable Response Discrepancy Affects <= 5.6.1 Patched in 5.6.2
- 2016-04-25 Improper Access Control Affects < 5.3.6 Patched in 5.3.6
- 2016-04-21 Exposure of Sensitive Information to an Unauthorized Actor Affects < 5.3.1 Patched in 5.3.1
- 2016-04-05 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 5.3.5 Patched in 5.3.5
- 2015-04-14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.6.13 Patched in 4.6.13
- 2014-08-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.5.3 Patched in 3.5.4
- 2014-08-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.6.4 Patched in 3.6.4
- 2014-08-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.3 Patched in 3.6.4
- Medium · 6.5 iThemes Security < 3.4.4 - Cross-Site Scripting ↗2012-08-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.4.4 Patched in 3.4.4
- 2012-05-11 CVE-2012-4263 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.5 Patched in 3.2.5
- 2012-05-11 CVE-2012-4264 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.4 Patched in 3.2.5
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 52 languages, 12 at 90% or more
Plus 28 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-02-15 800K+ → 700K+ down after 562 days in tier
- 2024-08-02 900K+ → 800K+ down after 423 days in tier
- 2023-06-06 1M+ → 900K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter 50K+ installs · 4.4★ · 3 shared tags A -
Wordfence Security – Firewall, Malware Scan, and Login Security 5M+ installs · 4.7★ · 2 shared tags A
-
Jetpack – WP Security, Backup, Speed, & Growth 3M+ installs · 3.8★ · 2 shared tags A
-
All-In-One Security (AIOS) – Security and Firewall 1M+ installs · 4.7★ · 2 shared tags A -
Sucuri Security – Auditing, Malware Scanner and Security Hardening 600K+ installs · 4.2★ · 2 shared tags A -
Jetpack Protect 100K+ installs · 4.6★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for Kadence Security – Password, Two Factor Authentication, and Brute Force Protection into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/better-wp-security" width="480" height="300" style="border:0" loading="lazy" title="Kadence Security – Password, Two Factor Authentication, and Brute Force Protection — Plugin Pulse"></iframe> Kadence Security – Password, Two Factor Authentication, and Brute Force Protection: 700K+ active installs, 4.6★ (3,990 reviews). Plugin Pulse (WP Mayor), as of 2026-08-26. https://plugins.wpmayor.com/plugin/better-wp-security