Executive answer: This plugin has changed names twice since this review was first written. iThemes Security became Solid Security in 2023, when the company rebranded to SolidWP. It then became Kadence Security on May 12, 2026, when Liquid Web folded SolidWP into its Kadence product line. That second change is not cosmetic. Kadence Security’s Pro tier is no longer sold as a standalone product. It is now bundled exclusively into Kadence Pro at $299/year, up from Solid Security Pro’s old $99/year single-site price. On top of that, multiple sources report the free WordPress.org plugin has been unable to install on most hosting environments since August 2026, with settings that won’t save. We are scoring the product as it stands today, not as it was when this review was first published.
Quick Verdict
| Best for | WordPress site owners who want meaningful login/hardening security without leaving the dashboard |
| Not ideal for | Sites wanting traffic-level filtering before requests even reach the server — that’s Sucuri’s job, not this plugin’s |
| Biggest strength | The free tier is a genuinely complete hardening layer, not a crippled trial |
| Biggest weakness | Reported installation failures on most hosts since August 2026, and Pro is no longer purchasable without buying the full $299/year Kadence Pro suite |
| Value for money | Poor right now — the price tripled for security-only buyers, and the free tier has real reported reliability problems |
| Overall | Not Recommended until the installability reports are resolved; re-evaluate Wordfence or Sucuri in the meantime |
- Free tier core modules are still substantial on paper
- 700,000+ existing installs — not an obscure product
- Reported install failures on most hosts since August 2026
- Pro is now a forced $299/year bundle, up from $99/year standalone
What Changed in 2026, and Why It Matters
On May 12, 2026, Liquid Web consolidated its WordPress software portfolio into four core products: Kadence, LearnDash, The Events Calendar, and Give. It stopped selling SolidWP, Iconic, Restrict Content Pro, and MemberDash as standalone products. Solid Security became Kadence Security, and its Pro tier stopped being purchasable on its own. The functionality that used to cost $99/year as Solid Security Pro is now available only inside Kadence Pro, which starts at $299/year. That’s a roughly 3x increase specifically for anyone who only wanted the security features, not a page builder or theme. The consolidation generated real community backlash, covered independently by Search Engine Journal.
Separately, and more urgently: multiple sources report that since August 2026, the free plugin has failed to install on most hosting environments. Settings changes also stop saving once it is active. That plugin is still listed on WordPress.org under the slug better-wp-security, with 700,000+ active installs. We could not reproduce this ourselves, since this assessment is not based on first-hand testing. But it is reported consistently enough across independent sources that it belongs in this review’s headline finding, not a footnote.
What’s still true
The free tier’s core modules are still described as included with no subscription required, when the plugin actually installs and runs. Those modules are brute-force protection, two-factor authentication, vulnerability scanning, a firewall, file-change detection, and database backups. The underlying security approach described throughout the rest of this review — hardening the WordPress install itself, rather than filtering traffic in front of it — hasn’t changed. What’s changed is the price of the Pro tier, the packaging, and, as of this writing, the plugin’s basic reliability.
What Solid Security (Now Kadence Security) Actually Is
A WordPress plugin, not a separate service. It runs from inside your WordPress dashboard and modifies how WordPress itself behaves. It limits failed login attempts, requires two-factor authentication, hides the default login URL, and detects unauthorized file changes. This is fundamentally different from Sucuri‘s approach, which filters traffic before it reaches your server at all. Solid Security hardens what’s already there.

Key Features
- Login hardening — limits failed login attempts, hides or moves the default WordPress login URL, free tier.
- Two-factor authentication — free tier, a meaningful step up from password-only login security.
- Brute-force protection — free tier, blocks the specific attack pattern most commonly used against WordPress logins.
- File change detection — Pro tier, flags unauthorized modifications to core, theme, or plugin files.
- Virtual patching (via Patchstack integration) — Pro tier, protects against known vulnerabilities before you’ve had a chance to update the affected plugin yourself.
- Passkey support — Pro tier, a newer authentication method beyond traditional 2FA.
Real-World Use Cases
- A small business site owner installs the free version, enables 2FA and login limiting, and has a meaningfully hardened site against the most common attack pattern (credential stuffing / brute force) at zero ongoing cost.
- An agency managing 10 client sites uses the Pro multi-site tier for virtual patching specifically. A known vulnerability in a widely-used plugin gets patched across every client site before the agency has manually updated each one. That reduces the window of exposure.
- A site running many third-party plugins relies on file change detection to catch a compromised or malicious plugin update before it causes visible damage. That beats discovering the problem after the fact.
- A membership or client-portal site with many user accounts enables passkey support to reduce password-related support tickets and credential-stuffing risk simultaneously. It’s a case where the authentication upgrade solves a support problem and a security problem at the same time.
- A site owner who just migrated from a different host uses the free version’s login hardening as an immediate first step post-migration. From there, they can evaluate whether the new hosting environment’s own security tooling makes Pro’s additional features redundant or still worthwhile.
Pricing
| Plan | Price | What you get |
|---|---|---|
| Free (Kadence Security) | $0 | Brute-force protection, 2FA, vulnerability scanning, a firewall, file-change detection, and backups — when the plugin installs and runs correctly |
| Kadence Pro (bundle) | $299/year | The only way to get Patchstack virtual patching and the other former “Solid Security Pro” features — bundled with Kadence’s theme, blocks, and page-builder tools, not sold separately |
This is a real, confirmed pricing structure, not a verification gap like the previous version of this review noted. The old per-site tier ladder ($99/$199/$299/$549 for 1/5/10/25 sites) no longer exists. If you only want the security features and don’t use Kadence’s theme or blocks, there is currently no way to buy just that. You pay $299/year for the whole suite, or you stay on the free tier.
Feature/Value Comparison: Solid Security vs. Sucuri
| Solid Security | Sucuri | |
|---|---|---|
| Layer protected | WordPress install itself | Traffic in front of the server |
| Free tier | Real hardening fundamentals, unlimited sites | None |
| Malware cleanup | Not included at any tier | Included on Platform tiers |
| Multi-site pricing | Published, per-site-count tiers | Not published, sales conversation required |
Pros and Cons
| Pros | Cons |
|---|---|
| Free tier’s core modules are still substantial on paper (2FA, brute force, vulnerability scanning, firewall, file monitoring) | Reported installation failures on most hosts and settings that won’t save, since August 2026 |
| 700,000+ existing installs mean the plugin is at least widely deployed and not obscure | Pro is no longer purchasable alone — it’s a forced $299/year bundle with Kadence’s theme and blocks |
| No malware cleanup at any tier — unchanged, still your problem to fix | Two rebrands and a pricing model change in under three years makes long-term commitment genuinely risky |
Alternatives
- Sucuri — traffic-level filtering plus a cleanup team, at a materially higher price. Complementary rather than competing; consider both for a genuinely high-stakes site.
- Wordfence — the other major WordPress-native security plugin, with a comparable free tier and a firewall component Solid Security doesn’t include natively. Its free tier includes a basic firewall that Solid Security’s free tier does not. That’s worth weighing if budget rules out any paid tier entirely.
Solid Security vs. Wordfence, specifically
These two are the most direct competitors in the WordPress-native plugin category. The comparison worth making explicit: Wordfence’s free tier bundles a basic application firewall alongside malware scanning. Solid Security’s free tier does not include either. Solid Security’s free strength is login/authentication hardening specifically, not firewall functionality. If a firewall matters to you and paying for Sucuri isn’t an option, Wordfence’s free tier covers ground Solid Security’s free tier doesn’t. If login security and file monitoring are the priority, Solid Security’s feature set is more focused on exactly that.
Detailed Analysis
Solid Security vs. Sucuri, in practice
These solve adjacent problems rather than competing directly. Solid Security hardens the WordPress install itself — the equivalent of reinforcing the locks and windows. Sucuri filters traffic before it reaches the server at all — the equivalent of a security gate at the property line. Running Solid Security’s free tier alongside Sucuri’s firewall is a reasonable, complementary setup for a site that takes security seriously without the highest budget. The two aren’t redundant with each other, and neither replaces the other’s specific function.
Why the pricing verification gap matters here specifically
We’re flagging the Pro pricing as third-party sourced rather than confirmed. That’s unusual for this site’s normal standard of direct vendor verification. The reason: SolidWP’s pricing URL redirected to an unrelated page when checked directly, and the specific product page returned a 404. This happens with rebranded products, like iThemes becoming SolidWP, where old URLs break during the transition. It’s a real gap in our verification, not a minor caveat. It’s exactly the kind of detail worth confirming yourself before committing to an annual plan.
What the free tier deliberately leaves out
Being direct about the gap matters more than a generic “upgrade for more features” pitch. The free tier’s login hardening and brute-force protection address the single most common WordPress attack vector: automated credential-stuffing bots trying common password combinations at scale. What it doesn’t cover: it won’t detect if an attacker already has valid credentials and is misusing them, since file change detection is Pro-only. It also won’t proactively patch a known vulnerability in a plugin you haven’t updated yet, since virtual patching is also Pro-only. For a site with a small, well-maintained plugin set and strong unique passwords already in place, the free tier’s gaps matter less. For a site running dozens of plugins from varied sources, updated inconsistently, those specific Pro features close a real exposure window.
Frequently Asked Questions
Is the free version of Solid Security actually enough?
For most small to medium sites, yes — login hardening, 2FA and brute-force protection cover the most common attack vectors. The Pro tier’s value is concentrated in vulnerability patching and file monitoring, which matter more for sites with a larger plugin footprint or higher traffic.
Do I need this if I already use Sucuri?
They’re complementary rather than redundant — Sucuri protects at the traffic level, Solid Security hardens the WordPress install itself. Running both isn’t paying twice for the same protection.
What happened to the iThemes brand name?
The company rebranded to SolidWP, and iThemes Security was renamed Solid Security as part of that change. It’s the same underlying product and team, just a different name. Older reviews and guides using “iThemes Security” are referring to the same plugin.
Is Kadence Security the same thing as Solid Security?
Yes — same plugin and codebase, third name in three years. iThemes Security became Solid Security in 2023, in the SolidWP rebrand. It then became Kadence Security on May 12, 2026, when Liquid Web consolidated SolidWP into its Kadence product line. The free WordPress.org plugin slug (better-wp-security) hasn’t changed through any of this.
Why did the price go up so much?
Because it’s no longer priced as a standalone product. The former Solid Security Pro ($99/year, 1 site) doesn’t exist as its own purchase anymore. The equivalent features are only available inside Kadence Pro at $299/year, which also includes Kadence’s theme and page-builder tools whether you want them or not.
Does the free tier include any ongoing update commitment?
The plugin is actively maintained on WordPress.org with a visible update history. Check the current changelog directly for release cadence, since that’s a better signal of active maintenance than any marketing claim.
Can I import settings if I switch from Wordfence?
We could not independently verify a direct settings-import path between the two plugins. Treat a switch as a fresh configuration rather than assuming a one-click migration. Budget time to re-enable 2FA and re-add trusted IPs manually.
Does Solid Security affect page load speed?
As a WordPress plugin running server-side, it adds some processing overhead. But login hardening and brute-force protection specifically only activate on login-related requests, not on every page load. The practical performance impact for a typical visitor browsing the site is minimal. File monitoring on Pro runs as a background scan rather than something visitors experience directly.
How We Scored This
| Criterion | Score | Why |
|---|---|---|
| Free tier completeness | 9/10 | Genuinely covers the fundamentals most small sites need, no artificial crippling — on paper |
| Current reliability | 3/10 | Multiple sources report install failures on most hosts and settings not saving since August 2026 |
| Pricing transparency | 2/10 | Now fully confirmed, and the confirmed number is a 3x price increase forced into a bundle you may not want |
| Feature depth at Pro | 6/10 | Virtual patching and file monitoring are still real, but no longer purchasable on their own |
Overall: 5.0/10. Methodology: this score dropped from a previous 6.75/10 because two things that were previously unverified or unknown are now confirmed and unfavorable. The price for security-only buyers roughly tripled, and independent sources report the free plugin has real installation and settings-saving problems as of August 2026. Re-evaluated August 2026.
PROOF Score
Overall: 4.2 / 10 — Not Recommended. Scored under our PROOF methodology — five checkable pillars, not a vibe. This is a real downgrade from this review’s original assessment, driven by confirmed pricing and reliability facts, not a change in opinion.
Is this worth it for a single small blog with low traffic?
The free tier alone, yes. The fundamentals it covers apply regardless of traffic volume, since automated attack bots don’t check your analytics before targeting a login page. Pro’s additional value scales more with plugin count and complexity than with traffic. A simple, low-plugin blog gets less marginal benefit from Pro specifically than a complex site does.
Final Decision
- Hold off on installing or renewing right now if: you’re not already using it. Confirm the installability reports are resolved on your specific host before relying on it.
- If you’re already running the free tier and it still works, there’s no urgent reason to remove it. But don’t assume an update will keep working without checking first.
- Choose Pro only if you also want Kadence’s theme and page-builder tools. Paying $299/year for security alone no longer makes sense when Wordfence’s comparable tier costs less and doesn’t require buying an unrelated product suite.
- Consider Wordfence or Sucuri instead while this situation stabilizes. Both are covered in the comparisons above, and neither carries an active installability question mark right now.
How We Assessed This
The plugin’s free-tier feature set is confirmed directly against its WordPress.org listing. The May 2026 Kadence/Liquid Web consolidation is corroborated by Search Engine Journal’s independent coverage. So is the resulting $299/year Kadence Pro pricing, which also matches Liquid Web’s own published pricing changes. The August 2026 installability and settings-saving reports come from multiple independent review sources. We have not reproduced this first-hand, and we say so plainly. But the consistency across sources is why it’s reflected in the score rather than omitted. Disclosure: this page contains no affiliate links currently — the product URL is a plain link.
Related
Compare with a popular alternative
Free; Pro from $99/year, 1 site (third-party sourced, unverified)
Stronger at: Free tier is a genuinely complete hardening layer covering login/2FA/brute-force, not a crippled trial
Main limitation: No malware cleanup at any tier, and no traffic-level filtering of incoming requests
From $9.99/mo firewall; $229+/yr Platform
Stronger at: Traffic-level filtering plus a real malware cleanup team on Platform plans
Main limitation: No published multi-site pricing — every extra site needs a sales conversation












