Description
Professional WordPress security designed to detect suspicious activity, respond automatically, and help protect your website around the clock.
Vardalion Security provides intelligent protection against brute-force attacks, malicious requests, automated bots, user enumeration, vulnerability scanning, authentication attacks and other suspicious WordPress traffic.
Instead of relying on a single security rule, Vardalion Security monitors multiple signals and builds a threat score for suspicious visitors. Repeated or increasingly dangerous behaviour can trigger automatic rate limiting and IP blocking.
Key Features
Intelligent Threat Detection
Vardalion Security monitors incoming WordPress traffic for suspicious behaviour including:
- Brute-force login attempts
- WordPress username enumeration
- Vulnerability scanning
- Malicious URL requests
.envand configuration-file probes- PHP shell and backdoor probes
- Directory traversal attempts
- REST API abuse
- XML-RPC authentication attacks
- Excessive 404 scanning
- Automated bot activity
- High-frequency requests
- Suspicious authentication behaviour
Threat Scoring
Suspicious activity contributes to an IP-based threat score.
This allows Vardalion Security to distinguish between an isolated suspicious request and a visitor repeatedly displaying malicious behaviour.
As the threat level increases, Vardalion Security can progressively respond with stronger protection.
Automatic IP Blocking
Repeated attackers can be automatically blocked.
Vardalion Security uses escalating block durations so persistent attackers receive progressively stronger penalties.
Depending on the configured security policy, repeated offenders can progress from temporary blocks to extended or permanent blocking.
Brute-Force Protection
Vardalion Security monitors failed WordPress authentication attempts and helps protect login endpoints against automated password attacks.
Repeated login failures contribute to the attacker’s threat score and can result in automatic blocking.
WordPress User Enumeration Protection
Attackers frequently attempt to discover valid WordPress usernames before launching password attacks.
Vardalion Security detects common username-enumeration techniques and records them as suspicious security events.
Malicious Request Detection
Vardalion Security examines requests for patterns commonly associated with automated vulnerability scanners and exploit attempts.
This includes probes for sensitive configuration files, vulnerable plugin paths, PHP shells, traversal attacks and other suspicious resources.
Bot and Automated Traffic Detection
Automated scanners can generate large numbers of requests while searching for vulnerable WordPress installations.
Vardalion Security monitors suspicious automated behaviour and request frequency to help identify potentially hostile traffic.
Advanced Rate Limiting
Vardalion Security Pro provides enhanced request-rate enforcement designed to reduce abusive high-frequency traffic before it becomes a larger attack.
Automatic Subnet Protection
When enabled, Vardalion Security Pro can analyse suspicious activity originating from related network ranges and use that intelligence as part of its automated protection system.
Country Access Controls
Vardalion Security Pro includes geographical access controls that can be used to enforce country-based security policies.
Security Event Logging
Security events are recorded inside WordPress so administrators can see what Vardalion Security is detecting.
Logs can include information such as:
- Date and time
- Source IP address
- Security event
- Severity
- Threat-score contribution
This provides visibility into automated attacks and suspicious activity that would otherwise often go unnoticed.
Security Dashboard
The Vardalion Security dashboard provides an overview of security activity and protection status directly inside WordPress.
Administrators can monitor detected threats, blocked addresses and other important security information without relying on an external dashboard.
Security Notifications
Vardalion Security can notify administrators about important security activity.
Vardalion Security Pro also includes security digest functionality for summarising relevant security events.
Built for WordPress
Vardalion Security is developed specifically for WordPress and integrates directly with the WordPress security and administration environment.
There is no separate security dashboard required for normal operation.
Simple Licence Activation
Vardalion Security Pro is designed to be straightforward to install and activate:
- Install the Vardalion Security plugin.
- Enter your licence key.
- Click Activate Licence.
- Vardalion Security Pro protection is enabled.
No licence-server configuration or editing of wp-config.php is required.
Baseline Protection
Core Vardalion Security protection includes:
- Request and firewall inspection
- Manual IP and network-range blocking
- Essential security event logging
- Login protection
- Emergency recovery controls
- Security dashboard access
Vardalion Security Pro
An active Pro licence unlocks additional protection including:
- Country access enforcement
- Advanced request-rate enforcement
- Automatic subnet blocking
- Daily security digests
Vardalion Security Pro – 1 Site Licence
This product provides a licence for one WordPress website.
Licence period: 1 year
Website activations: 1
Product: Vardalion Security Pro
Platform: WordPress
Your licence key is generated automatically after the qualifying WooCommerce order completes and is associated with your purchase.
Registered customers can also access their Vardalion Security licence from the My Account area.
Licence Renewal
Vardalion Security Pro licences are valid for the purchased licence period.
An active licence is required to continue using Pro functionality after the licence expires. Baseline Vardalion Security security functionality remains available without an active Pro licence.
Important Security Information
No WordPress security product can guarantee that a website will never be compromised.
Vardalion Security is designed to reduce attack exposure, detect suspicious behaviour and automatically respond to many common forms of hostile WordPress traffic. Website owners should continue to maintain WordPress core, themes and plugins, use strong authentication credentials, maintain reliable backups and follow appropriate server-security practices.
