

<strong>Command Center</strong> showing security score and important folder issues present on your site.
View full plugin documentation – CLICK HERE
Site Lockdown Security gives WordPress administrators, agencies, developers, and support teams a full security command center without hiding the best tools behind a paid upgrade.
Most WordPress security plugins reserve their strongest features for premium plans: firewalls, file change monitoring, malware scanning, scheduled reports, branded client dashboards, email alerts, login protection, cleanup tools, Cloudflare controls, and advanced hardening. Site Lockdown Security includes those kinds of features in one plugin, and they are not treated as upsells.
Use Site Lockdown Security to audit files, lock down important folders, monitor file changes, verify WordPress core integrity, scan for suspicious code, review abandoned folders, enforce password resets, check public file exposure, monitor redirects, protect logins, review risky software, receive branded email alerts, and run a WordPress-aware firewall with Cloudflare and WooCommerce compatibility controls.
Site Lockdown Security is built around a simple promise: powerful WordPress security features should not require surprise upgrade fees.
Features that are commonly sold as premium add-ons in other WordPress security plugins are included here, including white label branding, firewall controls, file change monitoring, scheduled security reports, infection scanning, cleanup tools, email notification previews, Cloudflare edge actions, login security, and client-ready branded alerts.
We will never charge for plugin upgrades or future features. When Site Lockdown Security improves, your security tools improve with it.
Site Lockdown Security includes White Label Branding because security work is often delivered as a professional service.
You can brand the admin experience, email imagery, colors, icons, banners, and plugin presentation around your business or client support program. Branding settings can be exported and imported between sites so the same client-ready experience can be reused across multiple installations.
These are the kinds of client-facing tools that are often locked behind agency or premium licenses elsewhere. In Site Lockdown Security, they are included.
Firewall Security helps protect WordPress from suspicious requests, exploit payloads, scanner signatures, bot signatures, dangerous methods, XML-RPC abuse, REST API exposure, suspicious query strings, and excessive request rates.
Protection modes include Smart Block for high-confidence malicious traffic, Monitor Only for tuning without blocking, WooCommerce Safe for checkout and payment compatibility, and Emergency Shield for active attack situations where public traffic needs to be restricted while administrators retain access.
Firewall Security also includes event logging, severity tracking, searchable timelines, IP allow/block actions, Cloudflare-aware IP detection, Cloudflare edge actions, notification settings, email summaries, and a customizable blocked request page.
Site Lock helps prevent unwanted file additions, injected scripts, unauthorized edits, and accidental deletions by making selected WordPress files and folders read-only.
You can unlock the site when legitimate updates or maintenance are needed, then apply Site Lock again when finished.
Site Lock is useful after a site has been cleaned, audited, updated, or stabilized and you want to reduce the chance of future unexpected file changes.
Watch Dog creates a trusted baseline of your site files and compares future scans against that baseline.
It reports new, modified, and deleted files so administrators can quickly review changes after updates, maintenance, cleanup work, or suspicious activity.
Watch Dog includes file change monitoring, baseline rebuilding, review actions, scheduled scans, protected baseline storage, and email alerts when changes are detected.
Watch Dog stores protected baseline data under:
wp-content/uploads/site-lock/watch-dog/
This keeps baseline data outside the plugin folder so it is not removed during plugin updates.
Sites updating from older versions automatically migrate Watch Dog baseline storage from the previous location:
wp-content/uploads/guard-dog/watch-dog/
After a successful migration, the old storage folder is safely removed and the new Watch Dog storage path remains excluded from Site Lock so baseline files can continue to be updated when needed.
Redirect Monitor tests public site behavior as different visitor types and alerts when visitors may be redirected to an unauthorized website.
It can test the homepage, login page, custom paths, and same-site navigation menu URLs using a focused scan strategy designed to avoid oversized scan jobs.
Core Check compares installed WordPress core files against the official WordPress.org checksum API.
It reports modified, missing, unreadable, or unexpected files in WordPress core areas so administrators can review potential core file integrity problems.
Update Monitor checks pending WordPress core, plugin, and theme updates and sends email alerts only when updates are available.
The infection scanner reviews site files for suspicious patterns commonly associated with malware, backdoors, obfuscated scripts, spam injections, and unwanted code.
Scans can be run manually or scheduled, and results can be included in reports and notifications.
Site Lockdown Security includes configurable email alerts for important security events and scheduled checks.
Supported notification types include:
Each individual alert includes a preview option so administrators can review the email layout before using it.
The global email notification settings form allows administrators to set the default frequency and recipient email for alerts in one place.
White Label Branding is one of the standout features of Site Lockdown Security because it lets agencies and service providers present security work under their own brand.
Administrators can customize branding text, colors, icons, dark icons, banners, email imagery, and dashboard presentation.
White Label settings can be exported to a JSON file and imported on another site, making it easier to reuse the same branding across multiple installations.
The Reset Settings option restores the default Site Lockdown theme and brings back the default support contact button when branding is returned to its original values.
Plugin Refresher helps reinstall fresh copies of WordPress.org plugins.
This can be useful when a plugin may have been modified, corrupted, or affected by suspicious files.
Site Lockdown Security uses native WordPress upgrade handling for safer refresh workflows and supports both individual and bulk plugin refreshes.
Theme Refresher helps reinstall fresh copies of WordPress.org themes.
It includes version information, update status, WordPress.org availability detection, and support for individual or bulk theme refresh workflows.
Require selected user roles to change their password. Active sessions for those users are logged out immediately, and their next valid login attempt shows a clear password-change message with a secure reset link.
Test whether sensitive backup, log, configuration, database, and metadata files can be accessed publicly from the website URL.
Quickly scan for specific files or identify extensionless files that may require review or removal. No shell commands or complex server tasks are required.
Login Security helps protect the WordPress login area with protected login URL controls, login attempt limits, activity tracking, session controls, and role-based expiration options.
Permissions Check reviews important WordPress files and folders and compares current permissions against recommended values.
It helps identify writable files, risky permissions, and items that may need attention.
When Site Lock protects a file or folder, permissions results account for that protected status.
Software Health checks installed plugins and themes for maintenance signals that may indicate abandoned or outdated software.
It helps administrators identify items that may need updates, replacement, removal, or closer review.
Risk Review checks local site risk signals and common security configuration concerns.
It includes severity sorting, ignore/include controls, scheduled checks, and optional email alerts.
The Setup Guide helps administrators complete recommended Site Lockdown Security settings.
Setup items include Site Lock, scheduled infection scans, automated reports, file change baselines, file change notifications, core change notifications, software health alerts, risk review alerts, firewall settings, login protection, and branded email notifications.
Progress tracking helps administrators see which recommended protection steps are complete.