Plugin Pulse
← Pulse

Kadence Security – Password, Two Factor Authentication, and Brute Force Protection

by Nexcess · Security

Also makes 22 other plugins · 2.6M+ installs across the portfolio →

Harden your site security with Login Security, Two-Factor Authentication (2FA), Vulnerability Scanner, Firewall, and more. Formerly iThemes Security.

M WP Mayor reviewed this plugin iThemes Security: Secure Your WordPress Site and Get on with Your Life Read review ↗
How scoring works →
86 Health · A
Maintenance 100/100
Rating quality 91/100
Support 55/100

86 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

90 / 100

Excellent listing optimization

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 92/100
Listing tuning 100/100
Support resolution 42/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,422 days · wp.org + Plugin Pulse archive

+303% vs prior 30d
4.7KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

400.1K

now · peak 1.2M

402.9K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Kadence Security · #87 you Titan Anti-spam & Se · #715 Wordfence Security · #11 Jetpack · #18

Rating trend

Star average over time · dips mark rough releases

4.6Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

576per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

11

releases in the last 12 months

3mo ago

latest release · v10.0.2

93

tagged releases on record

Recent releases

10.0.2 · 3mo ago10.0.1 · 4mo ago10.0.0 · 4mo ago9.4.7 · 5mo ago9.4.6 · 6mo ago9.4.5 · 7mo ago9.4.4 · 7mo ago9.4.3 · 9mo ago9.4.2 · 10mo ago9.4.1 · 11mo ago9.4.0 · 11mo ago9.3.10 · 1.1y ago9.3.9 · 1.1y ago9.3.8 · 1.3y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 48% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v10.0 48%
v9.3 16%
v9.4 15%
v8.1 6.7%
Older / other versions 14%

Estimated active installs

The public count shows “700K+”. Our estimate pins where the real number sits.

tracked estimate
700K–800K ≈770K

Refined from the date this plugin crossed into its current band.

Install history · since 2016-03-02 · 1,500 observations

700KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.

Details

Version
10.0.3
Last updated
1mo ago
Added
2010-10-23 · 15 yrs old
Requires WP
6.5
Tested up to
7.0.4
Requires PHP
7.4

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 10.0.2 Bug Fix: Handle WP_Error in login interstitial session creation to prevent fatal errors. 10.0.2
  2. Version 10.0.1 Bug Fix: Race condition in file write could empty wp-config.php/.htaccess files. 10.0.1
  3. Version 10.0.0 Tweak: Updated branding from SolidWP to Kadence. New: QR code for 2FA is generated locally by default (the GD PHP extension is required), with a Kadence Security-hosted solution as a fallback. 10.0.0
  4. Version 9.4.7 Bug Fix: Prevent email retry loops by ensuring the scheduled notification properties are saved. 9.4.7
  5. Version 9.4.6 Enhancement: Update Patchstack details for existing vulnerabilities. 9.4.6
  6. Version 9.4.5 Tweak: Ensure generated Nginx config rules are valid for customized directory structures. 9.4.5

Known vulnerabilities

via Wordfence Intelligence

19 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2024-06-20 CVE-2022-44593 Use of Less Trusted Source Affects <= 9.3.1 Patched in 9.3.2
  2. 2023-10-31 Protection Mechanism Failure Affects <= 9.0.0 Patched in 9.0.1
  3. 2023-03-27 CVE-2023-28786 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 8.1.4 Patched in 8.1.5
  4. 2021-04-22 Protection Mechanism Failure Affects < 7.9.1 Patched in 7.9.1
  5. 2021-01-06 CVE-2020-36176 Incorrect User Management Affects <= 7.6.1 Patched in 7.7.0
  6. 2018-06-25 CVE-2018-12636 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 7.0.3 Patched in 7.0.3
  7. 2018-03-05 CVE-2018-7433 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.9.0 Patched in 6.9.1
  8. 2016-10-06 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 5.6.2 Patched in 5.6.2
  9. 2016-09-27 Observable Response Discrepancy Affects <= 5.6.1 Patched in 5.6.2
  10. 2016-04-25 Improper Access Control Affects < 5.3.6 Patched in 5.3.6
  11. 2016-04-21 Exposure of Sensitive Information to an Unauthorized Actor Affects < 5.3.1 Patched in 5.3.1
  12. 2016-04-05 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 5.3.5 Patched in 5.3.5
  13. 2015-04-14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.6.13 Patched in 4.6.13
  14. 2014-08-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.5.3 Patched in 3.5.4
  15. 2014-08-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.6.4 Patched in 3.6.4
  16. 2014-08-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.3 Patched in 3.6.4
  17. 2012-08-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.4.4 Patched in 3.4.4
  18. 2012-05-11 CVE-2012-4263 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.5 Patched in 3.2.5
  19. 2012-05-11 CVE-2012-4264 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.4 Patched in 3.2.5

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 52 languages, 12 at 90% or more

Danish 100%
Dutch 100%
Dutch (Formal) 100%
English (UK) 100%
Spanish (Chile) 100%
Spanish (Spain) 100%
Hungarian 98%
Spanish (Argentina) 98%
French (France) 93%
Korean 93%
Lao 93%
Vietnamese 91%
Persian 75%
Dutch (Belgium) 60%
Spanish (Colombia) 58%
Spanish (Ecuador) 58%
Spanish (Venezuela) 58%
Swedish 53%
Romanian 47%
Russian 47%
German 45%
German (Formal) 41%
English (South Africa) 37%
Spanish (Mexico) 32%

Plus 28 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-02-15 800K+ → 700K+ down after 562 days in tier
  2. 2024-08-02 900K+ → 800K+ down after 423 days in tier
  3. 2023-06-06 1M+ → 900K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Kadence Security – Password, Two Factor Authentication, and Brute Force Protection into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/better-wp-security" width="480" height="300" style="border:0" loading="lazy" title="Kadence Security – Password, Two Factor Authentication, and Brute Force Protection — Plugin Pulse"></iframe>
Preview card ↗

Kadence Security – Password, Two Factor Authentication, and Brute Force Protection: 700K+ active installs, 4.6★ (3,990 reviews). Plugin Pulse (WP Mayor), as of 2026-08-26. https://plugins.wpmayor.com/plugin/better-wp-security