wsecure lite
by Joomla Service Provider · Login & Users
Also makes 1 other plugin · 200+ installs across the portfolio →
wSecure hides admin URL so that default URL will no longer bring up the admin page. if who enter the secret key will be able to access admin area.
82 health vs 59 average across 1,443 Login & Users plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Rating quality
To rank higher: Too few reviews to rank on quality — nudge happy users to leave one.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,426 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
113
now · peak 172
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Occasionally updatedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
3
releases in the last 12 months
2mo ago
latest release · v3.1
3
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “200+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2016-07-11 · 1,390 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
A small install base leaves thin data to model from. A declining trend compresses what a buyer would pay. The range spans more than 10x because wp.org publishes install counts as broad bands, and conversion and price compound on top. Read the midpoint as an order of magnitude, not a valuation.
How we estimate this
Assumptions
- Free → paid conversion. 0.5%–2% of active installs pay for the pro tier. Typical for freemium WordPress plugins; the real rate varies a lot by product.
- Annual price per customer. $49–$129 a year, typical for Login & Users plugins rather than this plugin's own pricing.
- Acquisition multiple. 1.5x–2.5x annual revenue, the going range for small WordPress-plugin businesses, compressed because the install trend is declining.
- Install base. 200–300 active installs, from our install estimate (wp.org only publishes the floor).
Inputs
- Active installs
- 200–300
- Category
- Login & Users
- Pro tier
- detected ("Lite" naming, the free tier of a paid product)
- Download trend
- declining (30d downloads down vs prior 30d)
- Reviews
- 4
- Last updated
- 52 days ago
Revenue is installs × conversion × price; value is revenue × a typical acquisition multiple. Every factor is an assumption band, so the output is a wide range on purpose. If you're buying or selling, treat this as a starting point for due diligence.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ kingbolo10.8y ago
Still works but I am wondering if I continue to use this plugin when it has not been updated for more than a year.
Read on wp.org ↗ - ★★★★★ mountainguy212.3y ago
I’ve been going through a nightmare of trying to secure our blogs now that the internet is a playground for hackers (can you hear them laughing?). Renaming the WordPress login URL is a bit amateurish of a solution, I’ve been told, but it appears to be quite effective as a basic security measure. Problem is, many of the wp-login.php renaming plugins and Worpress mods don’t play well with other plugins. This one worked for me. I’d give it 5 stars, but was disappointed when I got ready to pay for the delux version and found it would be a yearly wallet ding. A paid “subscription” for a small trivial plugin just doesn’t work. Am happy to pay once, then pay every so often for a major upgrade if necessary. In case anyone is curious, here are the steps we are taking to secure our WordPress admin/login, somewhat listed in order of importance from most to least: 1. Bought SSL and configured so it’s forced for admin. 2. Whitelisted admin IPs, all others blocked, this implemented by managed server company, not us, to block what were essentially DDOS attacks due to the number of login brute force attempts. 3. Country blocked the whole world from admin, other than current country we are in. 4. Login attempt limiter plugin, in case other measures fail or are hacked. 5. Got rid of “Admin” user name, but of course. 6. Created special users that never author a post, are only used for admin, so they remain more private and are easily deleted if compromised. 7. Adjusted all user roles to absolute minimum capabilities, on an as-needed basis. 8. Public user display names are not login names. 9. Rename of login URL, using this plugin! Read it and weep, and pray that the WordPress developers get more aggressive with building security features into the core. Then you might have some time to actually write a blog post (grin).
Read on wp.org ↗ - ★★★★★ sprucehill13.6y ago
I tried this on one site with a view to adding it to several sites. Would not work at all.
Read on wp.org ↗ - ★★★★★ siprof13.6y ago
This plugin could hide wp-admin better than the others. 🙂
Read on wp.org ↗
Known vulnerabilities
via Wordfence Intelligence2 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 4.4 wSecure Lite <= 2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings ↗2023-08-09 CVE-2023-39987 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.5 Patched in 3.0
- High · 8.8 wSecure Lite < 2.4 - Remote Code Execution ↗2016-08-02 CVE-2016-10960 Improper Control of Generation of Code ('Code Injection') Affects < 2.4 Patched in 2.4
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-07-10 300+ → 200+ down after 3 days in tier
- 2026-07-07 900+ → 300+ down after 1140 days in tier
- 2023-05-24 1K+ → 900+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
SecuPress with Simple SSL – Simple and Performant Security 40K+ installs · 4.1★ · 2 shared tags A -
SP Move Login 6K+ installs · 4.3★ · 2 shared tags B
-
WebDefender Security – Protection & AntiSpam 1K+ installs · 4.0★ · 2 shared tags B -
SX User Name Security 900+ installs · 4.0★ · 2 shared tags C -
Easy Basic Authentication – Add basic auth to site or admin area 700+ installs · 4.1★ · 2 shared tags A -
Beagle Security – WP Security, Advanced Penetration Testing 100+ installs · 3.9★ · 2 shared tags D
Embed this report card
Drop a live Pulse card for wsecure lite into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wsecure" width="480" height="300" style="border:0" loading="lazy" title="wsecure lite — Plugin Pulse"></iframe> wsecure lite: 200+ active installs, 3.5★ (4 reviews). Plugin Pulse (WP Mayor), as of 2026-08-31. https://plugins.wpmayor.com/plugin/wsecure