Your WordPress site is being scanned. Vardalion Security is watching back.
Detect brute-force attacks, malicious requests, bot abuse, username enumeration, exploit probes and suspicious traffic — then automatically block repeat offenders before they become a bigger problem.
New to Vardalion Security? Download it from the official WordPress.org Plugin Directory. The 28-day Pro trial starts after installation.
/.env/.git/configHTTP 403/identity.php/ssh3ll.phpHTTP 403Built from real WordPress attack behaviour. Vardalion Security has been exercised across live WordPress installations against automated scanners, login attacks, sensitive-file probes and PHP backdoor hunting.
The internet does not wait for your site to become popular.
Automated systems scan WordPress websites continuously. Vardalion Security combines individual security signals into a threat score so suspicious behaviour can be identified and stopped automatically.
Sensitive file probing
Scanners searching for exposed environment files and development repositories are detected before they can continue probing.
/.env+50/.git/config+50Backdoor and PHP scanning
Rapid requests for suspicious PHP files, web shells and missing files contribute stronger behavioural evidence instead of relying on one weak signal.
/ssh3ll.phpDetected/wp_filemanager.phpDetectedSlow brute-force attacks
Attackers can space login attempts apart to evade basic rate limits. Vardalion Security retains meaningful authentication signals and can still reach a blocking threshold.
wp-login.php+12repeat attempt+12One suspicious request is a clue. A pattern is evidence.
Keep coming back. Keep staying out.
Vardalion Security can progressively increase restrictions for repeat offenders instead of treating every return as a first offence.
Security that responds automatically.
The goal is not simply to maintain a list of bad addresses. Vardalion Security evaluates what a visitor is actually doing and responds according to the evidence.
Blocked visitors know the site is protected.
A branded 403 experience gives legitimate visitors a reference ID while deliberately withholding the detection rule, threat score and other security internals.
WordPress-focused protection without the noise.
Vardalion Security is already blocking real-world WordPress attacks.
Live deployments have shown how quickly WordPress sites receive automated probes — including sites that were only days old. Scanners do not need to know who owns a website or whether it is popular. They are searching for opportunities.
That live traffic is helping refine Vardalion Security around the behaviour that actually matters: combining strong evidence, reducing weak-signal false positives, and escalating persistent offenders.
The internet does not wait for your website to become popular before it starts knocking on the door. Vardalion Security is built to make sure the wrong visitors do not get in.
What people are saying about Vardalion Security.
“OMG! I installed Vardalion Security on a brand-new WordPress site and I can’t believe how many attacks it detected after just one week. Superb. 5 out of 5 stars.”
Start protected. Upgrade when you need the complete suite.
Every new installation starts with 28 days of full Pro protection. After the trial, baseline protection continues free, or upgrade to keep every Pro feature and licensed updates.
| Feature | Free / Baseline | Pro |
|---|---|---|
| Firewall request inspection | ✓ | ✓ |
| Login / brute-force protection | ✓ | ✓ |
| User enumeration & REST user protection | ✓ | ✓ |
| Bot and scanner detection | ✓ | ✓ |
| Threat scoring & automatic IP blocking | ✓ | ✓ |
| Repeat-offender escalation | ✓ | ✓ |
| Manual IP and CIDR/network blocking | ✓ | ✓ |
| Security dashboard and essential logs | ✓ | ✓ |
| Emergency Mode / recovery | ✓ | ✓ |
| Advanced request-rate enforcement | — | ✓ |
| Country access enforcement | — | ✓ |
| Automatic subnet blocking | — | ✓ |
| Daily security digest | — | ✓ |
| Licensed automatic updates | — | ✓ |
Vardalion Security Complete User Guide
Installation, configuration, threat scoring, blocking, IP Intelligence, Emergency Mode, licensing, updates, troubleshooting and administrator guidance.
Free. No registration required.
Choose the coverage that fits your WordPress estate.
Every installation starts with a 28-day full Pro trial. One licence can cover the number of sites shown for its plan.
£79/year
For a single business or WordPress website.
Download Vardalion Security£199/year
For businesses, developers and small site portfolios.
Protect 5 sites£399/year
For agencies and larger WordPress portfolios.
Protect 25 sites£799/year
For agencies and large managed WordPress estates.
Protect 100 sitesA few things worth knowing.
Does Vardalion Security only protect the login page?
No. Authentication protection is one part of the firewall. Vardalion Security also evaluates malicious requests, probes, scanning behaviour, user enumeration, bots and repeated reconnaissance.
What happens when an attacker is blocked?
The request receives an HTTP 403 response. Repeat offenders can receive progressively longer restrictions, up to permanent blocking.
Will Vardalion Security tell attackers why they were blocked?
No. The public block page can provide a neutral reference ID for support, but it does not reveal the detection rule, internal score or security configuration.
Can I try Pro before buying?
Yes. New installations include a 28-day full Pro trial before a paid licence is required for premium functionality.
Your WordPress site already has visitors you never invited.
Give it a firewall designed to recognise them.