Cerber Security Pro’s differentiator is access control granularity. Where most security suites treat the admin area as a single gate, Cerber restricts individual admin pages per user role — editors can reach posts and media while plugins and settings stay invisible to them. Around that core sits a complete stack: hook-level WAF filtering SQL injection and XSS before WordPress processes the request, a malware scanner covering both files and the database (including hidden admin accounts injected into wp_usermeta), TOTP two-factor authentication, and a traffic inspector logging every hit on wp-login.php, XML-RPC, and the REST API. The philosophy differs from broader suites like Solid Security: Cerber goes deep on access control and scanning, while Solid layers in password policy and version management.
The IP reputation layer taps Cerber’s global threat network — known botnet nodes and spam sources get dropped before consuming your server’s cycles. For teams, the audit trail matters as much as the blocking: every user action, plugin installation, and failed login is attributed, which turns incident response from guesswork into a timeline.
Competitive Features
- Per-role admin lockdown — restrict specific admin pages to specific roles, a control almost no competitor offers natively
- Hook-level WAF — SQL injection, XSS, CSRF, and path traversal filtering before application code runs
- File + database malware scanner — signatures, backdoors, base64 injections, and unauthorized admin accounts
- Global IP reputation — Cerber’s threat network blocks known malicious IPs pre-request
- Full activity auditing — user-attributed logs of admin changes, installs, and login failures
- Traffic inspector — searchable logs of login, REST API, and XML-RPC requests with user agents
- TOTP two-factor authentication — works with Google Authenticator, Authy, and standard apps, backup codes included
Key Features
- Custom firewall rules — whitelist/blacklist by IP, user agent, URL pattern, and HTTP headers
- Geolocation controls — country-based admin access restrictions
- reCAPTCHA enforcement — v2 and v3 on login, registration, password reset, and comments
- Database scanner — checks posts, options, comments, and usermeta for injected content
- File integrity monitor — core, plugin, and theme files verified against official checksums
- Scheduled scans — with email report delivery
- Instant email alerts — critical events including brute-force waves and 2FA bypass attempts
Comparison with Competitors
Cerber Security Pro vs Solid Security
| Aspect | Cerber Security Pro | Solid Security |
|---|---|---|
| Malware scanning | Built-in, file + database | Via add-on |
| Admin access control | Per-role, per-page | Global |
| IP reputation network | Cerber global DB | No |
| Activity logging | Detailed, user-attributed | Yes |
| Password policy | No | Yes |
| Version management | No | Yes |
Bottom line: Solid Security wins on password enforcement and update management; Cerber wins on deep access control and a malware scanner that ships in the box. Agencies running multi-editor sites get the most from Cerber’s per-page restrictions.
Cerber Security Pro vs Malcare
| Aspect | Cerber Security Pro | Malcare |
|---|---|---|
| Architecture | Self-hosted WordPress plugin | SaaS with cloud scanning |
| Malware scanning | On your server | Off-server cloud |
| WAF | Hook-level, in-plugin | Cloud WAF |
| Data location | Your infrastructure | Vendor cloud |
| Server load | Moderate | Minimal |
| Admin granularity | Per-role page control | Dashboard-level |
Bottom line: MalCare offloads scanning to its cloud and lightens your server; Cerber keeps everything self-hosted with far finer access control. Compliance requirements around data residency usually decide this one.
Recommended Stack — Cerber handles prevention and detection; recovery needs its own tool. Pair it with UpdraftPlus Premium so scheduled backups exist before the day the scanner finds something you can’t just clean.
Official Changelog
Version 9.6.9
Release Date: August 11, 2026
- New: IP reputation check with Cerber global threat network integration.
- Enhancement: Database scanner detects hidden admin accounts.
- Fix: Firewall rule conflict with WooCommerce REST API endpoints resolved.
Version 9.6.8
Release Date: July 7, 2026
- New: Two-factor authentication backup codes for account recovery.
- Enhancement: Traffic inspector log entries now searchable.
- Fix: CAPTCHA display conflict with caching plugins.
Version 9.6.7
Release Date: June 14, 2026
- New: Admin area lockdown module with per-role page restrictions.
- New: Scheduled malware scanning with email report delivery.
- Performance: IP reputation lookups optimized for high-traffic sites.
Frequently Asked Questions
Does Cerber work with caching plugins?
Yes. Operating at the WordPress hook level means security checks run after cached content is delivered — login protection, CAPTCHA, and firewall rules are unaffected by page caching, and the traffic inspector still records requests to cached pages.
Does it scan the database, not just files?
Yes. The database scanner inspects posts, options, comments, and usermeta for injected content, hidden links, base64-encoded payloads, and unauthorized admin accounts — the injection points that file-only scanners miss.
Can I restrict admin pages by user role?
Yes, and it’s Cerber’s signature feature. Define which admin pages each role can access — editors see posts and media, not plugins or settings. No other mainstream security plugin implements this natively at the same granularity.
How does the IP reputation check work?
Each request’s IP is checked against Cerber’s global threat database, built from thousands of protected sites. Known malicious IPs and botnet nodes are blocked before your server processes them — cutting attack noise at the source.
What does Pro add over the free version?
The malware scanner, IP reputation checking, 2FA, country blocking, admin lockdown, the database scanner, and email alerts. The free tier covers the firewall, basic login protection, and activity logging.




Leave a Reply