Solid Security Pro (formerly iThemes Security) is the hardening-first security suite from the SolidWP/StellarWP stack: brute-force protection networked across its user base, two-factor authentication, password policies, vulnerability scanning against a maintained database, file-change detection, and the security checklist that made iThemes the guided-hardening standard. Its position versus malware-centric competitors is structural: Solid covers breadth – login, users, passwords, updates, file integrity – while malware cleaning happens through its Scan module and pairing with backup tools. Against guided hardening rivals, Solid has the more polished interface and version management; against Cerber Security Pro, it is broader where Cerber is deeper on access control.
The 9.4.x line reflects the StellarWP modernization: continuous improvement of the vulnerability database, Site Scan features, and dashboard reporting – the plugin consolidating its position as the hardening baseline for the SolidWP ecosystem (Kadence, The Events Calendar, Restrict Content Pro).
Competitive Features
- Brute-force network protection – attack data shared across Solid’s user base
- Two-factor authentication – TOTP, push, and email methods
- Password policies – enforced strength and expiration per role
- Vulnerability scanning – plugin/theme checks against Solid’s database
- File change detection – core, plugin, and theme modification alerts
- Security checklist – guided hardening with pass/fail indicators
- Version management – automatic updates controlled per plugin
Key Features
- Login security – lockouts, CAPTCHA, hide-login options
- Database backups (Pro) – scheduled database-only backups
- Malware Scan (Pro) – site scanning with reporting
- User security – idle logout, strong password enforcement
- 404 detection – scanner-behavior blocking
- Security reports – scheduled email status digests
- Multisite support – network-wide management
Comparison with Competitors
Solid Security Pro vs All In One WP Security Pro
| Aspect | Solid Security Pro | All In One WP Security Pro |
|---|---|---|
| Interface | Modern, StellarWP standard | Functional, denser |
| Malware scanning | Via Scan module (Pro) | Built in |
| Password policy | Yes | Limited |
| Version management | Yes | No |
| Checklist UX | Guided, modern | Traffic-light |
| Ecosystem | SolidWP stack (Kadence, Events Calendar) | Standalone |
Bottom line: AIOWPS includes built-in malware scanning and the traffic-light audit for free-tier friendliness; Solid Security Pro wins on interface modernity, password policies, version management, and the StellarWP ecosystem integration. Both are hardening-first rather than malware-removal-first.
Solid Security Pro vs MalCare
| Aspect | Solid Security Pro | MalCare |
|---|---|---|
| Architecture | Self-hosted suite | Cloud scanning + cleanup |
| Malware removal | Manual with guidance | Automatic, bot-based |
| Hardening checklists | Comprehensive | Basic |
| Password policy | Yes | No |
| Server load | Moderate | Minimal |
Bottom line: MalCare automates the malware lifecycle in its cloud; Solid covers the hardening breadth self-hosted. Many stacks run both – Solid for hardening, MalCare for the malware layer – but pick Solid when self-hosted control matters.
Recommended Stack – hardening pairs with privacy compliance: combine Solid Security Pro with Complianz GDPR so the same site covers attack defense and visitor consent – the two obligations a security-complete stack needs.
Official Changelog
Version 9.4.4
Release Date: August 25, 2026
- Feature release: vulnerability database updates and dashboard refinements.
Version 9.4.0
Release Date: July 20, 2026
- Feature release: Site Scan improvements and hardening additions.
Version 9.3.4
Release Date: June 12, 2026
- Maintenance release: security hardening and stability fixes.
Frequently Asked Questions
What changed when iThemes Security became Solid Security?
Brand and ecosystem: iThemes rebranded to SolidWP (StellarWP), and the plugin became Solid Security with the same codebase continuing under the new name – the StellarWP stack including Kadence, The Events Calendar, and Restrict Content Pro.
Does it include malware cleanup?
The Scan module (Pro) detects malware and suspicious files with reporting and guidance – but Solid is hardening-first rather than an automated cleaner. Pair it with a malware specialist or backups for full recovery coverage.
How does the brute-force protection work?
Login attempts filter through Solid’s network – attack patterns seen across its user base protect all sites in the network, with lockouts and CAPTCHA enforcement locally configurable.
Is two-factor authentication included?
Yes – TOTP authenticator apps, push methods, and email 2FA across the Pro feature set, with per-role enforcement.
How is it different from Cerber Security?
Breadth versus depth. Solid covers password policy, version management, and the full hardening surface with a modern interface; Cerber goes deep on access control granularity and in-plugin malware scanning. Ecosystem (StellarWP) versus specialist depth decides.

Leave a Reply