Sucuri Security is the free scanner and auditing tool from the incident-response company known for cleaning hacked sites professionally. The plugin covers file integrity monitoring (core files verified against checksums), malware scanning (remote and server-side), security activity auditing, blacklist status checks across major services (Google Safe Browsing, Norton, McAfee), and post-hack security actions. Its identity is the endpoint of a full security stack: the Sucuri cloud WAF and incident-response services sit behind the free plugin, and the plugin’s posture reflects that – it tells you the truth about your site’s state and connects to professional help when the answer is bad. Against cloud suites like MalCare, Sucuri’s free scanner is more transparent and less automated; the WAF and cleanup guarantees are the paid layer.
The 2.7.x/2.8.0 line shows focused maintenance: one-time backup codes for two-factor authentication (2.8.0), paginated 2FA user lists for large sites like WooCommerce stores (2.7.4), and an AJAX dispatch-map refactor for security and efficiency (2.7.3) – engineering hygiene from a security-first team.
Competitive Features
- File integrity monitoring – core files verified against WordPress.org checksums
- Malware scanning – remote Sucuri scanning plus server-side YARA rules
- Blacklist status monitoring – Google Safe Browsing, Norton, McAfee, SiteAdvisor checks
- Two-factor authentication – with one-time backup codes (2.8.0)
- Post-hack security actions – hardened recovery steps after compromise
- Security activity audit log – user and system events tracked
- Incident-response ecosystem – professional cleanup behind the free scanner
Key Features
- Email alerts – security events notified immediately
- Hardening checklist – PHP and server configuration guidance
- Core integrity tool – verify and repair modified core files
- Sucuri WAF integration – optional cloud firewall connection
- Scheduled scans – automated malware checks
- API-based reporting – scan results via Sucuri’s API
- Multisite compatible – network security auditing
Comparison with Competitors
Sucuri Security vs MalCare
| Aspect | Sucuri Security | MalCare |
|---|---|---|
| Cleanup | Professional service (paid guarantees) | Automated in-product |
| WAF | Cloud WAF (flagship, paid) | Cloud layer included |
| Free scanner depth | Remote + server-side + integrity | Behavioral + signatures |
| Blacklist monitoring | Multi-service | Basic |
| Incident reputation | Industry reference | Growing |
Bottom line: MalCare automates the common cleanup lifecycle; Sucuri brings the incident-response pedigree – when a compromise is serious, Sucuri’s cleanup guarantees are the industry reference. Critical e-commerce often pairs Sucuri’s WAF with their scanner; the long tail runs MalCare for automation.
Sucuri Security vs Jetpack Security
| Aspect | Sucuri Security | Jetpack Security |
|---|---|---|
| Focus | Security specialization | Bundled suite (security + backups + AI) |
| WAF | Cloud WAF flagship | Not included |
| Backups | Separate product | Real-time included |
| Post-hack response | Professional guarantees | Paid plans |
| Data path | Through Sucuri (WAF) | Through WordPress.com |
Bottom line: Jetpack Security bundles protection with backups and monitoring in one ecosystem; Sucuri specializes in the security layer with the strongest WAF and incident response. Ecosystem consolidation versus security depth is the split.
Recommended Stack – security pairs with independent backups: pair Sucuri with BackupBuddy so recovery archives live in your own storage, independent of the security vendor’s infrastructure.
Official Changelog
Version 2.8
Release Date: August 25, 2026
- New: One-time backup codes for Two-Factor Authentication – ten codes generated when 2FA is enabled, each working once, with fresh sets generatable from the WordPress profile.
Version 2.7.4
Release Date: July 28, 2026
- Improvement: The Two-Factor Authentication page loads the users list in pages, staying fast and reliable on sites with hundreds or thousands of users (for example, WooCommerce stores).
- New: Search box on the Two-Factor Authentication page to quickly find users by username, email, or role.
Version 2.7.3
Release Date: June 30, 2026
- Improvement: AJAX handler refactored to an explicit dispatch map for improved security and efficiency.
- Improvement: 2FA section with more UI clarity.
- Fix: Light mode default when no preference is defined; corrected inverted dark/light mode icons.
- Fix: i18n regression in 2FA status and setup templates.
Frequently Asked Questions
Does the free Sucuri plugin include a firewall?
No – the cloud WAF is Sucuri’s paid platform layer. The free plugin handles scanning, integrity monitoring, auditing, and alerts, and connects to the WAF if you subscribe. The scanner alone is still more capable than most free security plugins.
What makes Sucuri’s malware scanning different?
It combines remote scanning (Sucuri’s servers check your site externally), server-side YARA rule scanning, and blacklist monitoring across multiple services – Google Safe Browsing, Norton, McAfee. Multi-source detection catches what single-scanner approaches miss.
What are the one-time backup codes in 2.8.0?
When two-factor authentication is enabled, ten single-use codes generate – any one gets you in if you lose your authenticator app, and each works exactly once. Standard 2FA recovery hygiene, previously missing.
Is it suitable for large WooCommerce stores?
Yes – the 2.7.4 release specifically paginated the 2FA user list for sites with thousands of users, addressing the scaling pain WooCommerce membership sites hit.
How does it compare to cloud cleanup services?
Sucuri’s cleanup is a professional service with guarantees (paid); automated cleaners like MalCare handle common infections autonomously. Sites with compliance requirements or high revenue per hour typically pay for the Sucuri relationship.

Leave a Reply