iThemes Security Pro is the Pro tier of the plugin now branded Solid Security (StellarWP) — the hardening-first suite this catalog tracks under both names: guided security checklist, brute-force network protection, two-factor authentication, password policies, file-change detection, and version management. The iThemes name persists across millions of installed sites and searches, so this page covers the same product lineage: iThemes → Solid Security Pro. The 10.x line tells the story: branding updates (SolidWP to Kadence-era), locally-generated 2FA QR codes (10.0.0), and critical fixes — the 10.0.1 race-condition fix addressed a file-write bug that could empty wp-config.php/.htaccess, exactly the class of bug that makes running current versions non-negotiable in security tooling. Against the detection-first Wordfence Premium and the specialist access-control security, iThemes/Solid leads the guided-hardening experience.
Sites on the iThemes-era versioning should treat this Pro line as the current product: same checklist, same protection network, StellarWP-era maintenance underneath.
Competitive Features
- Guided security checklist — prioritized hardening with pass/fail clarity
- Brute-force network protection — attack data shared across the install base
- Two-factor authentication — TOTP with locally-generated QR codes
- Password policies — strength and expiration per role
- File change detection — core/plugin/theme modification alerts
- Version management — automatic update control per plugin
- Malware Scan (Pro) — site scanning with reporting
Key Features
- Login security — lockouts, CAPTCHA, hide-login
- Database backups — scheduled database-only backups
- Idle logout — session limits per role
- 404 detection — scanner-behavior blocking
- Security reports — scheduled email digests
- Multisite support — network management
- Import/export — settings portability across sites
Comparison with Competitors
iThemes Security Pro vs Wordfence Premium
| Aspect | iThemes Security Pro | Wordfence Premium |
|---|---|---|
| School | Hardening first | Scanner + firewall first |
| Rule updates | Scheduled | Real time (Feed) |
| Password policy | Yes | No |
| Version management | Yes | No |
| Best for | Config-driven security | Threat-active sites |
Bottom line: Wordfence wins on detection speed and network intelligence; iThemes/Solid wins on the guided-hardening surface — password policy, version management, checklist UX. Configuration discipline picks iThemes; active-threat defense picks Wordfence.
iThemes Security Pro vs Cerber Security Pro
| Aspect | iThemes Security Pro | Cerber Security Pro |
|---|---|---|
| Malware scanning | Scan module | Built-in file + DB |
| Access control depth | Role-based standard | Per-page granularity |
| Password policy | Yes | No |
| Traffic monitoring | Basic | Traffic inspector |
| Best for | Broad hardening | Access-control depth |
Bottom line: Cerber specializes in access control and in-plugin malware scanning; iThemes/Solid covers the broader hardening surface with policy tools Cerber omits. Depth picks Cerber; breadth picks iThemes.
Recommended Stack — hardening pairs with backup: combine with scheduled backup routine so configuration discipline extends to recovery readiness.
Official Changelog
Version 10.0.3
Release Date: July 27, 2026
- Maintenance release: stability and compatibility fixes.
Version 10.0.2
Release Date: June 20, 2026
- Bug Fix: Handle WP_Error in login interstitial session creation to prevent fatal errors.
Version 10.0.1
Release Date: May 18, 2026
- Bug Fix: Race condition in file write could empty wp-config.php/.htaccess files.
Frequently Asked Questions
Is iThemes Security Pro still maintained?
Yes — under the SolidWP/StellarWP branding as Solid Security Pro. The iThemes name persists across the install base and this page tracks the same product lineage; the 10.x line is current with active fixes (including the critical 10.0.1 file-write race-condition repair).
What was the 10.0.1 bug and why does it matter?
A race condition in file writing could empty wp-config.php or .htaccess during security-module changes — a site-breaking failure mode. It’s a reminder: security plugins modify critical files, so running current versions and keeping backups is essential.
Does two-factor authentication work without external services?
Yes — TOTP authenticator apps with QR codes generated locally on the server (10.0.0+) — no external push-service dependency.
How is it different from Wordfence?
Hardening versus detection. iThemes/Solid guides configuration discipline — passwords, versions, file monitoring — while Wordfence leads active-threat detection with real-time feeds. Configuration-first sites pick iThemes; attack-facing sites pick Wordfence.
Can I manage multiple sites centrally?
Multisite is supported natively, and StellarWP’s ecosystem tools provide cross-site visibility for agencies running Solid across client fleets.




Leave a Reply