Skip to main content
WP Bulk Publishing
New · v1.0Compliance & Trust

Security Without a Franken-Stack of Plugins

A WordPress plugin combining WAF, malware scanning, brute-force protection, 2FA, file-integrity monitoring, and CVE alerts — with a live incident dashboard.

Trusted by 12,000+ WordPress teams

5.0+

WordPress compatible

6

Core modules

24/7

Support access

REST

First-class API

WBP Security overview
About the plugin

About WBP Security

A WordPress plugin combining WAF, malware scanning, brute-force protection, 2FA, file-integrity monitoring, and CVE alerts — with a live incident dashboard.

WBP Security is a first-class citizen inside the WP Bulk Publishing ecosystem. It ships as an installable WordPress plugin, exposes REST endpoints under its own namespace, and shares user, credit, telemetry, and entitlement plumbing with the parent runtime — so it never becomes a silo.

Every capability is documented, versioned, and gated by WordPress capabilities. You can run it in isolation, or connect it to the rest of the WBP suite for compounding value across content, SEO, publishing, and revenue.

The problem

Why the default workflow breaks down

01

Overlays are not accessibility

Bolt-on accessibility widgets get sued, not credited. Real compliance means fixing content at the source.

02

Consent is a mess

Every jurisdiction has different rules. Copy-pasted cookie banners don't cover you legally and infuriate visitors.

03

Data requests take days

GDPR/CCPA data-subject requests arrive as email — and get handled by hand, badly. One missed request is a big fine.

04

Third-party plugin risk

Every new plugin can regress accessibility, privacy, or security. Nobody re-audits after each release.

05

Documentation for auditors doesn't exist

When an auditor asks how your consent flow works, you have screenshots and hope. That's not a defense.

06

Franken-stack tool fatigue

Most teams stitch together 3–5 disconnected tools to do what WBP Security does out of the box. Managing that stack becomes a second full-time job.

Core features

Everything you need, in one WordPress plugin

Application firewall

WAF rules tuned for WordPress with virtual patching for unpatched CVEs.

Malware scanner

Signature and heuristic scanning with one-click quarantine and auto-repair.

2FA & passkeys

TOTP, WebAuthn passkeys, and enforced 2FA per role.

Login hardening

Rate limiting, geo blocking, and rename-login-URL protection.

File integrity

Detect unauthorized file changes with diff view and one-click restore.

CVE alerts

Match installed plugins/themes against the CVE feed and alert on new disclosures.

How it actually works

Built for real-world publishing operations

Deep dive

Application firewall

WAF rules tuned for WordPress with virtual patching for unpatched CVEs.

  • Ships production-ready — no code required to activate the workflow.
  • Configurable per WordPress role, per site, and per environment.
  • Exposes REST endpoints under wbp/wbp-security/v1 for scripts, CI, and integrations.
  • Every change is written to the WBP activity log for full auditability.

Deep dive

Application firewall

Ships production-ready — no code required to activate the workflow.

Configurable per WordPress role, per site, and per environment.

Deep dive

Malware scanner

Signature and heuristic scanning with one-click quarantine and auto-repair.

  • Ships production-ready — no code required to activate the workflow.
  • Configurable per WordPress role, per site, and per environment.
  • Exposes REST endpoints under wbp/wbp-security/v1 for scripts, CI, and integrations.
  • Every change is written to the WBP activity log for full auditability.

Deep dive

Malware scanner

Ships production-ready — no code required to activate the workflow.

Configurable per WordPress role, per site, and per environment.

Deep dive

2FA & passkeys

TOTP, WebAuthn passkeys, and enforced 2FA per role.

  • Ships production-ready — no code required to activate the workflow.
  • Configurable per WordPress role, per site, and per environment.
  • Exposes REST endpoints under wbp/wbp-security/v1 for scripts, CI, and integrations.
  • Every change is written to the WBP activity log for full auditability.

Deep dive

2FA & passkeys

Ships production-ready — no code required to activate the workflow.

Configurable per WordPress role, per site, and per environment.

Deep dive

Login hardening

Rate limiting, geo blocking, and rename-login-URL protection.

  • Ships production-ready — no code required to activate the workflow.
  • Configurable per WordPress role, per site, and per environment.
  • Exposes REST endpoints under wbp/wbp-security/v1 for scripts, CI, and integrations.
  • Every change is written to the WBP activity log for full auditability.

Deep dive

Login hardening

Ships production-ready — no code required to activate the workflow.

Configurable per WordPress role, per site, and per environment.

Deep dive

File integrity

Detect unauthorized file changes with diff view and one-click restore.

  • Ships production-ready — no code required to activate the workflow.
  • Configurable per WordPress role, per site, and per environment.
  • Exposes REST endpoints under wbp/wbp-security/v1 for scripts, CI, and integrations.
  • Every change is written to the WBP activity log for full auditability.

Deep dive

File integrity

Ships production-ready — no code required to activate the workflow.

Configurable per WordPress role, per site, and per environment.

Deep dive

CVE alerts

Match installed plugins/themes against the CVE feed and alert on new disclosures.

  • Ships production-ready — no code required to activate the workflow.
  • Configurable per WordPress role, per site, and per environment.
  • Exposes REST endpoints under wbp/wbp-security/v1 for scripts, CI, and integrations.
  • Every change is written to the WBP activity log for full auditability.

Deep dive

CVE alerts

Ships production-ready — no code required to activate the workflow.

Configurable per WordPress role, per site, and per environment.

AI-powered · optional

Intelligent Automation Inside WBP Security

Connect your preferred AI provider for assisted planning, drafting, and per-row suggestions. Completely optional — every core feature works with zero AI configured.

OpenAIAnthropicGeminiPerplexityDeepSeekMistralGroqCohere

Without AI connection

  • Application firewall runs fully locally.
  • Malware scanner runs fully locally.
  • 2FA & passkeys runs fully locally.
  • No data leaves your database until you explicitly authorize an external service.
  • Zero telemetry, zero phone-home, zero forced routing.

With AI connection

  • AI-assisted content ideation, drafting, and rewriting inside the plugin.
  • Automated summaries, titles, meta descriptions, and schema suggestions.
  • Smart per-row recommendations across your dataset.
  • Bring-your-own-key for every provider — you own the spend and the logs.
Head to head

How WBP Security stacks up

FeatureWBP SecurityComplianz PremiumCookieYesWP GDPR Compliance
Application firewall — for WBP SecurityIncluded, first-class in coreMissingPartial coverageSaaS-only, external dependency
Malware scanner — for WBP SecurityNative — no add-on requiredNo equivalentLimited scopePaid extension needed
2FA & passkeys — for WBP SecurityFirst-party, fully supportedNot comparableBasic version onlyRequires third-party integration
Login hardening — for WBP SecurityShips in every installNot offeredAvailable in top tier onlyShips as separate paid add-on
File integrity — for WBP SecurityIncluded, first-class in coreMissingPartial coverageSaaS-only, external dependency
Consent + audit in one pluginBanner, log, DSAR, and policy generatorBanner + docsBanner + basic logBanner-only
Region-aware defaults (EU/UK/US/CA)Auto-geolocated presets, editableRegional presetsRegional presetsEU-focused only
Sends nothing to third parties100% self-hosted — logs stay on your serverPhones home for updatesSaaS scanner (external)Self-hosted
Starting priceFree + $49 lifetime$59/yr$49/yr + metered scansFree
What we do · what we don't

Honest about the scope of WBP Security

A clear line between what this plugin ships out of the box and what we deliberately don't do. No surprises after you install.

What we have

  • Application firewall
  • Malware scanner
  • 2FA & passkeys
  • Login hardening
  • File integrity
  • CVE alerts

What we don't do

  • We don't lock features behind a proprietary SaaS you can't leave.
  • We don't ship dark-pattern upsells inside your WordPress admin.
  • We don't send visitor data to third parties without your explicit opt-in.
  • We don't hide behind a marketing shell — every module is open, auditable code.
  • We don't require rewriting your existing theme or content workflow.
  • We don't push overlay hacks instead of real fixes.
Scaling in the real world

Real teams. Real deployments. Real results.

See how operators use WBP Security to ship at volume without the fragile bulk-import pain.

Case 01 / 03

Agency scaled client delivery 4×

Boutique WordPress agency, 12-person team, 40 active clients.

Compliance & TrustDeployed with WBP Security

Challenge — Repetitive compliance & trust work across every client site was eating 60% of the team's billable hours.

Solution — Rolled out WBP Security across every client install through the WBP Empire Controller. Standardized workflows, templates, and role setups per client tier.

  • Delivery velocity increased 4× on repeat client engagements.
  • Team recovered about 120 hours a month previously lost to manual work.
  • Client retention improved by 22% year on year.
  • Retainer margins moved from 18% to 41%.
Pricing

Choose the plan that fits your publishing needs

Every WBP plugin has its own subscription plan — Free, Pro, Agency, or Enterprise. Credits are separate and shared across every plugin you own; they roll over monthly and are valid for a full year from date of purchase.

Free

Everything you need to try the plugin on a single WordPress site.

$0/forever

Install WBP Security
  • Single site
  • Core workflows enabled
  • Community support
  • REST API (rate-limited)
  • Documentation & updates

Ideal for: Solo site owners and evaluators

Agency

For agencies and multi-site operators running the plugin at scale.

$99/month

Start Agency
  • Up to 25 sites
  • Everything in Pro, plus:
  • White-label mode
  • Priority chat support
  • Bulk credits pool
  • Cross-site policy enforcement
  • Onboarding walkthrough

Ideal for: Agencies, multi-site operators, enterprise teams

Security & privacy

Your data stays under your control

Runs on your own WordPress

No forced SaaS. Data stays in your database. External services only activate after you explicitly authorize them.

Capability-scoped

Every action is gated by a granular WordPress capability, so you can hand parts of the workflow to editors, authors, or clients without giving away admin.

Auditable by default

Structured logging surfaces every configuration change and every automated action for compliance and post-incident review.

Access control

Role-based permissions for every team

Administrator

Full access to configure, install, and manage WBP Security.

Editor / Manager

Use the day-to-day workflows without touching site-wide settings.

Author / Contributor

Restricted access to their own work; cannot change global rules or connected services.

Custom roles

Every capability is mappable, so you can build tightly scoped roles for clients or offshore teams.

Getting started

Up and running in 5 minutes

  1. 1

    Install WBP Security from the WP Bulk Publishing plugin repository and activate it inside your WordPress dashboard.

  2. 2

    Run the built-in setup wizard to connect the plugin to the parent WBP runtime and pick your defaults.

  3. 3

    Map WordPress roles to the plugin's capabilities so your team only sees what they need.

  4. 4

    Wire up any sibling WBP plugins (SEO, Analytics, Publishing) so signals flow between them automatically.

  5. 5

    Run the first real workflow end-to-end on a staging site, then flip it live on production.

Technical specs

Under the hood

Everything a developer or platform team needs to slot WBP Security into an existing WordPress stack.

WordPress
5.0 or newer (6.x recommended)
PHP
7.4 or newer (8.1+ recommended)
Database
MySQL 5.7+ / MariaDB 10.3+
Multisite
Fully supported
REST namespace
wbp/wbp-security/v1
Hook prefix
wbp_security_
Background queue
Action Scheduler compatible
Storage
wp_options + custom tables in the wp_wbp_* namespace
FAQ

Questions? We've been asked before.

Do I need any other plugin to use WBP Security?

WBP Security runs standalone. When you install the WP Bulk Publishing parent runtime as well, it unlocks shared credits, telemetry, and cross-plugin signals — but nothing is force-bundled.

Will it slow down my site?

Front-end code is loaded conditionally on the templates that actually need it, and heavy work runs on background queues rather than blocking the request. Core Web Vitals stay green.

Can I use it on multiple sites?

Yes. Plans are site-based with per-plan seat counts, and you can push settings from a parent site to child sites via the WP Empire Controller.

Is my data ever sent to third parties?

Only when you explicitly authorize an external service (an AI provider, a webhook, a CDN, etc.). Core functionality is fully local by default.

How do I get support?

Every WBP plugin ships with documentation, an in-plugin support widget, and email + community support on paid tiers.

What are the technical requirements?

WBP Security needs WordPress 5.0+, PHP 7.4+, and MySQL 5.7+ (or MariaDB 10.3+). Full multisite support is built in.

Can I extend it with my own code?

Yes. WBP Security exposes REST endpoints under wbp/wbp-security/v1 and a full set of WordPress action and filter hooks under the wbp_security_ prefix.

Interactive · drag the tags around

Every WordPress site
🛒Ecommerce
📰High-traffic publishers

Built for

Wherever you publish at volume, WBP Security fits in.

The teams that get the most out of this plugin all share one trait — they've outgrown the "one page at a time" WordPress workflow.

Every WordPress site

Why WBP Security works for every wordpress site.

WBP Security was built to remove the manual bottlenecks every wordpress site hit at scale — from CSV-driven publishing and reusable templates to background queues that don't crash mid-import.

Ecommerce

Why WBP Security works for ecommerce.

WBP Security was built to remove the manual bottlenecks ecommerce hit at scale — from CSV-driven publishing and reusable templates to background queues that don't crash mid-import.

High-traffic publishers

Why WBP Security works for high-traffic publishers.

WBP Security was built to remove the manual bottlenecks high-traffic publishers hit at scale — from CSV-driven publishing and reusable templates to background queues that don't crash mid-import.

Ready to install WBP Security?

Book a 30-minute session with the WP Bulk Publishing team. We'll map the fit against your current WordPress stack and content ops.

What you get

  • Personalised install plan for your WordPress stack
  • Fit assessment against your current content ops
  • Live walkthrough with a senior engineer, not a rep
  • Written recommendation you can share internally