WP Cerber Security featured image

WP Cerber Security v9.9.5 - WordPress Plugin

Developer: Markov Gregory (Cerber Tech Inc.)Category: WordPress PluginsTrusted with 83 downloadsPro1 favoriteLatest v9.9.5Updated 3w ago

Defends WordPress against hacker attacks, spam, trojans, and malware.

Related items

Related Security Plugins

Complianz Premium – GDPR/CCPA Cookie Consent icon

Complianz Premium - GDPR/CCPA Cookie Consent

by Real Big Plugins

Complianz is a GDPR/CCPA Cookie Consent plugin that supports GDPR, DSGVO, LGPD, POPIA, APA, RGPD, CCPA and PIPEDA with a conditional Cookie Notice and customized Cookie Policy based on the results...

reCaptcha for WooCommerce icon

ReCaptcha For WooCommerce - WordPress Plugin

by Woo

Security is the most important concern nowadays for any website or an eCommerce store.

Wordfence Premium icon

Wordfence Premium - WordPress Security Plugin

by Defiant Inc

Wordfence Premium is for self-administered websites that are looking for the ultimate protection against the latest exploits including real-time firewall rules and malware signature, a continuously...

Defends WordPress against hacker attacks, spam, trojans, and malware. Mitigates brute-force attacks by limiting the number of login attempts through the login form, XML-RPC / REST API requests, or using auth cookies. Tracks user and bad actors activity with flexible email, mobile and desktop notifications. Stops spammers by using a specialized anti-spam engine. Uses Google reCAPTCHA to protect registration, contact, and comments forms. Restricts access with IP Access Lists. Monitors the website integrity with an advanced malware scanner and integrity checker. Reinforces the security of WordPress with a set of flexible security rules and sophisticated security algorithms.

Features you will love

  • Limit login attempts when logging in by IP address or entire subnet.
  • Monitors logins made by login forms, XML-RPC requests or auth cookies.
  • Permit or restrict access by IP Access Lists with a single IP, IP range or subnet.
  • Create Custom login URL (rename wp-login.php).
  • Cerber anti-spam engine for protecting contact and registration forms.
  • Automatically detects and moves spam comments to trash or denies them completely.
  • Manage multiple WP Cerber instances from one dashboard.
  • Two-Factor Authentication for WordPress.
  • Logs users, bots, hacker and other suspicious activities.
  • Security scanner verifies the integrity of WordPress files, plugins and themes.
  • Monitors file changes and new files with email notifications and reports.
  • Mobile and email notifications with a set of flexible filters.
  • Advanced users’ sessions manager
  • Protects wp-login.php, wp-signup.php and wp-register.php from attacks.
  • Hides wp-admin (dashboard) if a visitor isn’t logged in.
  • Immediately blocks an intruder IP when attempting to log in with non-existent or prohibited username.
  • Restrict user registration or login with a username matching REGEX patterns.
  • Restrict access to WP REST API with your own role-based security rules.
  • Block access to WordPress REST API completely.
  • Block access to XML-RPC (block access to XML-RPC including Pingbacks and Trackbacks).
  • Disable feeds (block access to the RSS, Atom and RDF feeds).
  • Restrict access to XML-RPC, REST API and feeds by White IP Access list by an IP address or an IP range.
  • Authorized users only mode
  • Block a user account.
  • Disable automatic redirection to the hidden login page.
  • Stop user enumeration (blocks access to author pages and prevents user data leaks via REST API).
  • Proactively blocks IP subnet class C.
  • Anti-spam: reCAPTCHA to protect WordPress login, register and comment forms.
  • reCAPTCHA for WooCommerce & WordPress forms.
  • Invisible reCAPTCHA for WordPress comments forms.
  • A special Citadel mode for massive brute force attacks.
  • Play nice with fail2ban: write failed attempts to the syslog or a custom log file.
  • Filter out and inspect activities by IP address, user, username or a particular activity.
  • Filter out activities and export them to a CSV file.
  • Reporting: get weekly reports to specified email addresses.
  • Limit login attempts works on a site/server behind a reverse proxy.
  • Be notified via mobile push notifications.
  • Trigger and action for the jetFlow.io automation plugin.
  • Protection against (DoS) attacks (CVE-2018-6389).
Show full description

LIMIT LOGIN ATTEMPTS DONE RIGHT

By default, WordPress allows unlimited login attempts through the login form, XML-RPC or by sending special cookies. This allows passwords to be cracked with relative ease via brute force attack.

WP Cerber blocks intruders by IP or subnet from making further attempts after a specified limit on retries is reached, making brute force attacks or distributed brute force attacks from botnets impossible.

You will be able to create a Black IP Access List or White IP Access List to block or allow logins from a particular IP address, IP address range or a subnet any class (A,B,C).

Moreover, you can create your Custom login page and forget about automatic attacks to the default wp-login.php, which takes your attention and consumes a lot of server resources. If an attacker tries to access wp-login.php they will be blocked and get a 404 Error response.

MALWARE SCANNER

Cerber Security Scanner is a sophisticated and extremely powerful tool that thoroughly scans every folder and inspects every file on a website for traces of malware, trojans, backdoors, changed and new files.

Read more about the malware scanner.

INTEGRITY CHECKER

The scanner checks if all WordPress folders and files match what exist in the official WordPress core repository, compares your plugins and themes with what are in the official WordPress repository and alerts you to any changes. As with scanning free plugins and themes, the scanner scans and verifies commercial plugins and themes that are installed manually.

SCHEDULED SCANS WITH AUTOMATIC FILE RECOVERY

Cerber Security Scanner allows you to configure a schedule for automated recurring scanning easily. Once the schedule is configured the scanner automatically scans the website, deletes malware and recovers modified and infected WordPress files. After every scan, you can get an optional email report with the results of the scan.

Read more about the scheduled scans.

TWO-FACTOR AUTHENTICATION

Two-Factor Authentication (2FA) provides an additional layer of security requiring a second factor of identification beyond just a username and password. When 2FA is enabled on a website, it requires a user to provide an additional verification code when signing into the website. This verification code is generated automatically and sent to the user by email.

Read more about Two-Factor Authentication.

LOG, FILTER OUT AND EXPORT ACTIVITIES

WP Cerber tracks time, IP addresses and usernames for successful and failed login attempts, logins, logouts, password changes, blocked IP and actions taken by itself. You can export them to a CSV file.

LIMIT LOGIN ATTEMPTS REINVENTED

You can hide WordPress dashboard (/wp-admin/) when a user isn’t logged in. If a user isn’t logged in and they attempt to access the dashboard by requesting /wp-admin/, WP Cerber will return a 404 Error.

Massive botnet brute force attack? That’s no longer a problem. Citadel mode will automatically be activated for awhile and prevent your site from making further attempts to log in with any username.

CERBER ANTI-SPAM ENGINE

Anti-spam and anti-bot protection for contact, registration, comments and other forms. WP Cerber anti-spam and bot detection engine now protects all forms on a website. No reCAPTCHA is needed. It’s compatible with virtually any form you have. Tested with Gravity Forms, Caldera Forms, HappyForms, Contact Form 7, Ninja Forms, Formidable Forms, Fast Secure Contact Form, Contact Form by WPForms.

ANTI-SPAM PROTECTION: INVISIBLE RECAPTCHA FOR WOOCOMMERCE

  • WooCommerce login form
  • WooCommerce register form
  • WooCommerce lost password form

ANTI-SPAM PROTECTION: INVISIBLE RECAPTCHA FOR WORDPRESS

  • WordPress login form
  • WordPress register form
  • WordPress lost password form
  • WordPress comment form

INTEGRATION WITH CLOUDFLARE

A special Cloudflare add-on for WP Cerber keeps in sync the list of blocked IP addresses with Cloudflare IP Access Rules.

Stay in compliance with GDPR

How to get full control of personal data to be in compliance with data privacy laws such as GDPR in Europe or CCPA in California.

Recent releases

Release history

View all 10 versions
v9.9.5LatestVerified Safe
Aug 25, 20261.3 MB
Improved
  • A setting link in admin UI now opens the matching role tab in the role-based settings and highlights the target setting, so you can jump from an Activity log event straight to the setting that affected WP Cerber's decision.
  • Following a setting link from a popup explainer now centers the target WP Cerber setting in the browser window instead of aligning it with the top of the page, where the WordPress admin bar could cover it.
  • URL escaping in the admin interface now accepts root-relative URLs that begin with a single slash, in addition to the already supported HTTP(S), FTP(S), and mailto URLs.
  • Admin announcements are now stored as structured JSON instead of pre-rendered HTML markup. A stored announcement that does not match the supported format is rejected instead of being displayed incorrectly.
  • Quotes, angle brackets, and backticks are no longer deleted from URLs in admin pages. HTML escaping of the attribute value now handles these characters safely.
Fixed
  • On the Activity log page, when several explainers described events for the same user and WP Cerber's decision was role-based, only the first setting link scrolled to and highlighted the target setting. The remaining links opened the settings page without scrolling to the target setting.
  • The "Mail Transport" settings section displayed the raw HTML markup for the "Available in the professional version of WP Cerber" link instead of a working link.
  • Non-ASCII characters in a URL path are no longer removed when WP Cerber escapes a URL, so URLs with non-ASCII path characters now point to the intended address.
  • A URL containing invalid UTF-8 no longer becomes an empty link address when WP Cerber escapes it.
Aug 12, 20261.3 MB
View changelog
Fixed
  • When error logging was active, an uncaught PHP failure such as an unhandled exception, a type error, or a parse error could stop the standard PHP fatal error processing. WordPress can again show its critical error page, send the Recovery Mode email, and revert a broken PHP edit made in the built-in plugin or theme editor.
  • Uncaught PHP exceptions and other fatal failures could be missing from the WordPress `debug.log` file when `WP_DEBUG_LOG` was enabled.
  • Not all PHP errors were logged for a request. A fatal error that terminated the request could be replaced by a later diagnostic produced by WP Cerber's own shutdown routines, so the terminating error was missing from the request details in Traffic Inspector and from `cerber-errors.log`.
  • On a non-English website, the issue message reporting a failed email delivery could be shown in the language of the request that failed to send the email, which is usually an unattended request such as a scheduled report or a visitor-triggered alert. The message is now translated into the language of the administrator who reads it.
  • On a non-English website, the message reporting corrupted plugin settings and their recovery was shown untranslated. It is now translated at the moment it is displayed to the administrator.
  • Some messages in the "System Readiness" widget were missing localization support and could not be translated.
  • Rendering the quick navigation block in the admin area could produce `Array to string conversion` warnings when a query parameter carried more than one value. Depending on the PHP error configuration, these warnings could pollute the server logs, appear in the admin output, or corrupt an AJAX response.
  • Some valid IPv6 ranges written in dash or wildcard notation were rejected when adding an entry to the IP Access Lists or filtering records in the Activity log and the Traffic log. Reversed and zero-length ranges are still rejected.
  • IPv6 range matching now uses inclusive boundaries, so the first and the last address of a range are treated as part of that range.
Jul 14, 20261.3 MB
View changelog
Added
  • WP Cerber now automatically maintains a backup copy of the last known valid plugin settings. The backup is refreshed after successful settings updates, settings imports, plugin upgrades, and during daily maintenance.
  • If the stored plugin settings become corrupted, WP Cerber now restores them automatically from the settings backup and shows a dismissible admin notice explaining what happened, what action was taken, and what the administrator should review.
  • The "System Readiness" widget now shows an advisory notice on servers where PHP is built without the modern `mysqlnd` database driver. The notice confirms that WP Cerber keeps working and recommends enabling `mysqlnd` for full compatibility and better performance.
Improved
  • Traffic Inspector now detects additional high-confidence JavaScript obfuscation patterns, including fully escaped strings that use `\uNNNN` and `\u{...}` escape sequences and dangerous execution, DOM, network, and system code decoded from explicit `fromCharCode()` calls, while preserving its low false-positive detection model.
Other
  • Compatibility: WP Cerber now runs correctly on legacy hosting environments where PHP is built without the modern `mysqlnd` database driver. On such servers, database query results are retrieved through a slower compatible method instead of triggering a fatal error.
Fixed
  • A corrupted WP Cerber configuration value stored in the database could cause a fatal `TypeError` in `array_merge()` at plugin load time on PHP 8, taking the whole website down. WP Cerber now detects the unreadable stored value, falls back to the default settings, and reports the failure as a critical issue until the administrator re-saves the settings.
  • A regression in the detection of obfuscated JavaScript by Traffic Inspector. JavaScript strings built entirely of `\xNN` hex escape sequences were not decoded, so obfuscated code such as `eval`, `script`, and `XMLHttpRequest` could go undetected when request fields were inspected.

Frequently asked questions

Is WP Cerber Security GPL licensed?
Yes, WP Cerber Security is distributed under the GNU General Public License (GPL). You can legally use, modify, and redistribute it on unlimited websites.
What is the latest version of WP Cerber Security?
The latest version of WP Cerber Security on GPLCoffee is v9.9.5 (released Aug 25, 2026, 1.3 MB download size). Every new release is synced automatically, and subscribers can update directly from their WordPress dashboard with the one-click connector plugin.
How much does WP Cerber Security cost on GPLCoffee?
WP Cerber Security is available for $5.99 for a 1-year license or $15.99 for a lifetime license. Membership plans also include credit-based access so you can download WP Cerber Security along with thousands of other plugins, themes, and PHP scripts for a single subscription.
Which WordPress and PHP versions does WP Cerber Security support?
The current release of WP Cerber Security requires WordPress 5.8 or higher, tested up to WordPress 7.1, PHP 7.4 or higher. Per-release compatibility details are listed in the version history.
Is WP Cerber Security safe to download?
Yes. The latest release of WP Cerber Security (v9.9.5) was scanned with VirusTotal and came back clean. Scan results are visible on each version page, and releases flagged as malicious are blocked from the catalog.

Auto-updates included

Install it once, update automatically.

The GPLC Connector installs this plugin from your wp-admin and rolls out new versions to your connected sites - up to 25. Included with 12-month and Geek Lifetime plans (plus legacy 6-month).