iThemes Security Pro is the Pro tier of the plugin now branded Solid Security (StellarWP) – the hardening-first suite this catalog tracks under both names: guided security checklist, brute-force network protection, two-factor authentication, password policies, file-change detection, and version management. The iThemes name persists across millions of installed sites and searches, so this page covers the same product lineage: iThemes → Solid Security Pro. The 10.x line tells the story: branding updates (SolidWP to Kadence-era), locally-generated 2FA QR codes (10.0.0), and critical fixes – the 10.0.1 race-condition fix addressed a file-write bug that could empty wp-config.php/.htaccess, exactly the class of bug that makes running current versions non-negotiable in security tooling. Against the detection-first Wordfence Premium and access-control specialists like WP Cerber, iThemes/Solid leads the guided-hardening experience.
Sites on the iThemes-era versioning should treat this Pro line as the current product: same checklist, same protection network, StellarWP-era maintenance underneath.
Competitive Features
- Guided security checklist – prioritized hardening with pass/fail clarity
- Brute-force network protection – attack data shared across the install base
- Two-factor authentication – TOTP with locally-generated QR codes
- Password policies – strength and expiration per role
- File change detection – core/plugin/theme modification alerts
- Version management – automatic update control per plugin
- Malware Scan (Pro) – site scanning with reporting
Key Features
- Login security – lockouts, CAPTCHA, hide-login
- Database backups – scheduled database-only backups
- Idle logout – session limits per role
- 404 detection – scanner-behavior blocking
- Security reports – scheduled email digests
- Multisite support – network management
- Import/export – settings portability across sites
Comparison with Competitors
iThemes Security Pro vs Wordfence Premium
| Aspect | iThemes Security Pro | Wordfence Premium |
|---|---|---|
| School | Hardening first | Scanner + firewall first |
| Rule updates | Scheduled | Real time (Feed) |
| Password policy | Yes | No |
| Version management | Yes | No |
| Best for | Config-driven security | Threat-active sites |
Bottom line: Wordfence wins on detection speed and network intelligence; iThemes/Solid wins on the guided-hardening surface – password policy, version management, checklist UX. Configuration discipline picks iThemes; active-threat defense picks Wordfence.
iThemes Security Pro vs Defender (WPMU DEV)
| Aspect | iThemes Security Pro | Defender (WPMU DEV) |
|---|---|---|
| Model | Standalone hardening suite | Membership suite module |
| Malware scanning | Scan module (Pro) | Included with Hub reporting |
| Hardening UX | Guided checklist | Audit-style recommendations |
| Reporting | Email digests | WPMU Hub dashboards |
| Best for | Standalone discipline | WPMU-stack agencies |
Bottom line: Defender packages protection inside the WPMU membership with Hub reporting; iThemes/Solid dedicates the product to guided hardening. Suite consolidation picks Defender; hardening-first discipline picks iThemes.
Recommended Stack – hardening pairs with backup: combine with UpdraftPlus so configuration discipline extends to recovery readiness.
Official Changelog
Version 10.0.3
Release Date: July 27, 2026
- Maintenance release: stability and compatibility fixes.
Version 10.0.2
Release Date: June 20, 2026
- Bug Fix: Handle WP_Error in login interstitial session creation to prevent fatal errors.
Version 10.0.1
Release Date: May 18, 2026
- Bug Fix: Race condition in file write could empty wp-config.php/.htaccess files.
Frequently Asked Questions
Is iThemes Security Pro still maintained?
Yes – under the SolidWP/StellarWP branding as Solid Security Pro. The iThemes name persists across the install base and this page tracks the same product lineage; the 10.x line is current with active fixes (including the critical 10.0.1 file-write race-condition repair).
What was the 10.0.1 bug and why does it matter?
A race condition in file writing could empty wp-config.php or .htaccess during security-module changes – a site-breaking failure mode. It’s a reminder: security plugins modify critical files, so running current versions and keeping backups is essential.
Does two-factor authentication work without external services?
Yes – TOTP authenticator apps with QR codes generated locally on the server (10.0.0+) – no external push-service dependency.
How is it different from Wordfence?
Hardening versus detection. iThemes/Solid guides configuration discipline – passwords, versions, file monitoring – while Wordfence leads active-threat detection with real-time feeds. Configuration-first sites pick iThemes; attack-facing sites pick Wordfence.
Can I manage multiple sites centrally?
Multisite is supported natively, and StellarWP’s ecosystem tools provide cross-site visibility for agencies running Solid across client fleets.

Leave a Reply