iThemes Security Pro — WordPress Hardening Suite

Updated:

iThemes Security Pro is the Pro tier of the plugin now branded Solid Security (StellarWP) — the hardening-first suite this catalog tracks under both names: guided security checklist, brute-force network protection, two-factor authentication, password policies, file-change detection, and version management. The iThemes name persists across millions of installed sites and searches, so this page covers the same product lineage: iThemes → Solid Security Pro. The 10.x line tells the story: branding updates (SolidWP to Kadence-era), locally-generated 2FA QR codes (10.0.0), and critical fixes — the 10.0.1 race-condition fix addressed a file-write bug that could empty wp-config.php/.htaccess, exactly the class of bug that makes running current versions non-negotiable in security tooling. Against the detection-first Wordfence Premium and the specialist access-control security, iThemes/Solid leads the guided-hardening experience.

Sites on the iThemes-era versioning should treat this Pro line as the current product: same checklist, same protection network, StellarWP-era maintenance underneath.

Competitive Features

  • Guided security checklist — prioritized hardening with pass/fail clarity
  • Brute-force network protection — attack data shared across the install base
  • Two-factor authentication — TOTP with locally-generated QR codes
  • Password policies — strength and expiration per role
  • File change detection — core/plugin/theme modification alerts
  • Version management — automatic update control per plugin
  • Malware Scan (Pro) — site scanning with reporting

Key Features

  • Login security — lockouts, CAPTCHA, hide-login
  • Database backups — scheduled database-only backups
  • Idle logout — session limits per role
  • 404 detection — scanner-behavior blocking
  • Security reports — scheduled email digests
  • Multisite support — network management
  • Import/export — settings portability across sites

Comparison with Competitors

iThemes Security Pro vs Wordfence Premium

Aspect iThemes Security Pro Wordfence Premium
School Hardening first Scanner + firewall first
Rule updates Scheduled Real time (Feed)
Password policy Yes No
Version management Yes No
Best for Config-driven security Threat-active sites

Bottom line: Wordfence wins on detection speed and network intelligence; iThemes/Solid wins on the guided-hardening surface — password policy, version management, checklist UX. Configuration discipline picks iThemes; active-threat defense picks Wordfence.

iThemes Security Pro vs Cerber Security Pro

Aspect iThemes Security Pro Cerber Security Pro
Malware scanning Scan module Built-in file + DB
Access control depth Role-based standard Per-page granularity
Password policy Yes No
Traffic monitoring Basic Traffic inspector
Best for Broad hardening Access-control depth

Bottom line: Cerber specializes in access control and in-plugin malware scanning; iThemes/Solid covers the broader hardening surface with policy tools Cerber omits. Depth picks Cerber; breadth picks iThemes.

Recommended Stack — hardening pairs with backup: combine with scheduled backup routine so configuration discipline extends to recovery readiness.

Official Changelog

Version 10.0.3

Release Date: July 27, 2026

  • Maintenance release: stability and compatibility fixes.

Version 10.0.2

Release Date: June 20, 2026

  • Bug Fix: Handle WP_Error in login interstitial session creation to prevent fatal errors.

Version 10.0.1

Release Date: May 18, 2026

  • Bug Fix: Race condition in file write could empty wp-config.php/.htaccess files.

Frequently Asked Questions

Is iThemes Security Pro still maintained?

Yes — under the SolidWP/StellarWP branding as Solid Security Pro. The iThemes name persists across the install base and this page tracks the same product lineage; the 10.x line is current with active fixes (including the critical 10.0.1 file-write race-condition repair).

What was the 10.0.1 bug and why does it matter?

A race condition in file writing could empty wp-config.php or .htaccess during security-module changes — a site-breaking failure mode. It’s a reminder: security plugins modify critical files, so running current versions and keeping backups is essential.

Does two-factor authentication work without external services?

Yes — TOTP authenticator apps with QR codes generated locally on the server (10.0.0+) — no external push-service dependency.

How is it different from Wordfence?

Hardening versus detection. iThemes/Solid guides configuration discipline — passwords, versions, file monitoring — while Wordfence leads active-threat detection with real-time feeds. Configuration-first sites pick iThemes; attack-facing sites pick Wordfence.

Can I manage multiple sites centrally?

Multisite is supported natively, and StellarWP’s ecosystem tools provide cross-site visibility for agencies running Solid across client fleets.

Rating★★★★★ 4.6/5
Version10.0.3
PriceFree
Active Installs700,000+
Tested up toWP 7.0.4

Related Plugins

Share your experience

Leave a Reply

Your email address will not be published. Required fields are marked *