Plugin Pulse
← Pulse

Security Ninja – WordPress Security & Firewall

by cleverplugins · Security

Also makes 2 other plugins · 16K+ installs across the portfolio →

WordPress security plugin: free 8G firewall/WAF, 50+ tests, vulnerability/core scanning, events logging, AI reports.

M WP Mayor reviewed this plugin Security Ninja Review: Easy-to-Use WordPress Security Plugin Read review ↗
How scoring works →
89 Health · A
Maintenance 100/100
Rating quality 90/100
Support 70/100

89 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

98 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 90/100
Listing tuning 100/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

+165% vs prior 30d
169Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

5.7K

now · peak 49.1K

6.1K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Security Ninja · #2564 you Wordfence Security · #11 Sucuri Security · #105 NinjaFirewall (WP Ed · #350

Rating trend

Star average over time · dips mark rough releases

4.7Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

867per 1k installs · Aug 26

Release cadence

Occasionally updated
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

2

releases in the last 12 months

2mo ago

latest release · v5.289

2

tagged releases on record

Recent releases

5.289 · 2mo ago5.286 · 3mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v5.289 27%
v5.235 20%
v5.244 8.6%
Older / other versions 44%

Estimated active installs

The public count shows “7K+”. Our estimate pins where the real number sits.

tracked estimate
7K–8K ≈7.7K

Refined from the date this plugin crossed into its current band.

Install history · since 2016-12-24 · 1,429 observations

7KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from. The recent download trend is too spiky to read.

Details

Version
5.299
Last updated
yesterday
Added
2016-08-30 · 9 yrs old
Requires WP
4.7
Tested up to
7.1
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. joshuarbeal
    7mo ago

    Thank you, Security Ninja! Your plugin is easy to use, provides clear reports of activity, and includes built-in tools that make security a lightweight task. I look forward to incorporating this into future websites.

    Read on wp.org ↗
  2. nadeistos
    12mo ago

    Pas le choix que de payer… et très cher pour ce que ca apporte ! tant pis, ca sera sans moi

    Read on wp.org ↗
  3. josflachs
    1.1y ago

    I like security ninja, and use it on all my sites to check security. It’s really great! The nice thing about this plugin is that it gives you a report of all security settings that need to be improved, and (this is where it stands out) gives you a detailed explanation how to do that.I rate it one star because of the irritating nag screens. This topic was modified 11 months, 3 weeks ago by josflachs. This topic was modified 11 months, 3 weeks ago by josflachs. This topic was modified 11 months, 3 weeks ago by josflachs. This topic was modified 11 months, 3 weeks ago by josflachs. This topic was modified 11 months, 3 weeks ago by josflachs. This topic was modified 11 months, 3 weeks ago by josflachs. This topic was modified 11 months, 3 weeks ago by josflachs. This topic was modified 11 months, 3 weeks ago by josflachs.

    Read on wp.org ↗
  4. traqbar
    1.2y ago

    I have been using it for a while to occasionally check out security. But then the latest update is forcing you to bgo through a licensing system. Totally not what is expected with WordPress plugins – it is expected you have a choice to upgrade to premium through an external website. Now they interrupt the plugin updating system. It has already been annoying with the licensing system they use, but just about bearable. Now it is too far down the plughole and will be removed, it is hyper-aggressive and very uncomfortable to have around. This topic was modified 1 year, 1 month ago by traqbar. This topic was modified 1 year, 1 month ago by traqbar. This topic was modified 1 year, 1 month ago by traqbar.

    Read on wp.org ↗
  5. Skylabb
    2.0y ago

    The only thing you can run is “Test your website security” which tells you where the vulnerabilities are. My site is hacked and want to find where the malware is,

    Read on wp.org ↗
  6. Vassos Hadjivassiliou
    2.4y ago

    If you’re in the WordPress game, WP Security Ninja is a total game-changer. Seriously, it’s like a secret weapon for developers. It’s so user-friendly, you’ll wonder why you didn’t snag it sooner. And let me tell you, I grabbed the Pro version, and man, no regrets whatsoever. It’s worth every single penny.

    Read on wp.org ↗
  7. Bastbra
    2.6y ago

    Hi, I’ve been using Security Ninja, and I am happy, but it’s getting on my nerves that the plugin asks for acceptance on every dashboard reload to use my data for “freemius.com”. If I click “No, thanks” or “x” it will reappear again and again and again. Is this the way to get users to accept it after 10 times? Edit: Now the new update even crashed the site down and only by luck it was possible to track the problem down (Security Ninja) and gain access again. This topic was modified 1 year, 9 months ago by Bastbra.

    Read on wp.org ↗
  8. earthwormhenry
    2.8y ago

    No problems after one year works perfectly.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 5.289 2026-06-18 FIX: Cloud Firewall (Pro) – Visitor log retention (“Keep visitor logs for”) is now enforced by a daily scheduled cleanup task. NEW: Tools (Pro) – “Clear visitor log” button to delete all firewall visitor log e 5.289
  2. Version 5.288 2026-06-09 FIX: Tools – “Reset 2FA” no longer fails with “The link you followed has expired.”; a success notice is shown after reset; confirmation dialog added before resetting all users. Thank you Jason. 5.288
  3. Version 5.287 2026-06-02 FIX: Change Login URL (Pro) – Works when Cloud Firewall is disabled; only “Change login URL” and the slug need to be enabled under Login Protection. FIX: Change Login URL (Pro) – /your-slug/ login URLs work ev 5.287
  4. Version 5.286 2026-06-01 NEW: MainWP integration – child sites accept allowlisted Security Ninja settings updates from the Security Ninja for MainWP extension ( update_settings remote action; changed keys only). IMPROVED: MainWP setti 5.286
  5. Version 5.285 2026-05-26 FIX: Upgrading from the free plugin to Pro no longer causes a site error when both versions are present during install or activation. Pro skips loading Composer again if the free copy already loaded it, then F 5.285
  6. Version 5.284 2026-05-23 FIX: Change Login URL (Pro) – Checkout and other frontend flows that use WordPress admin-post.php (for example FluentCart account creation during checkout) no longer show “Access Denied” for visitors. Legitima 5.284

Known vulnerabilities

via Wordfence Intelligence

4 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-04-30 CVE-2024-13362 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.222 Patched in 5.225
  2. 2025-07-23 CVE-2025-8009 Absolute Path Traversal Affects 5.201 - 5.242 Patched in 5.243
  3. 2023-07-18 CVE-2023-33999 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 5.50 - 5.158 Patched in 5.159
  4. 2022-03-04 CVE-2022-4974 Missing Authorization Affects < 5.135 Patched in 5.135

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 6.8.2

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 15 languages, 0 at 90% or more

Korean 82%
Danish 27%
German 27%
Spanish (Spain) 27%
German (Formal) 26%
Swedish 25%
Vietnamese 24%
French (France) 13%
Italian 12%
Spanish (Ecuador) 11%
Spanish (Colombia) 10%
Spanish (Venezuela) 10%
Bulgarian 9%
Russian 9%
Dutch 3%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-02-02 8K+ → 7K+ down after 1 days in tier
  2. 2026-02-01 7K+ → 8K+ up after 7 days in tier
  3. 2026-01-25 8K+ → 7K+ down after 5 days in tier
  4. 2026-01-20 7K+ → 8K+ up after 2 days in tier
  5. 2026-01-18 8K+ → 7K+ down after 1 days in tier
  6. 2026-01-17 7K+ → 8K+ up after 1 days in tier
  7. 2026-01-16 8K+ → 7K+ down after 6 days in tier
  8. 2026-01-10 7K+ → 8K+ up after 1 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Security Ninja – WordPress Security & Firewall into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/security-ninja" width="480" height="300" style="border:0" loading="lazy" title="Security Ninja – WordPress Security & Firewall — Plugin Pulse"></iframe>
Preview card ↗

Security Ninja – WordPress Security & Firewall: 7K+ active installs, 4.7★ (100 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/security-ninja