iThemes Security Pro – WordPress Security Plugin

Rating★★★★★ 4.6/5
Version10.0.3
PriceFree
Active Installs700,000+
Tested up toWP 7.0.4

iThemes Security Pro is the Pro tier of the plugin now branded Solid Security (StellarWP) – the hardening-first suite this catalog tracks under both names: guided security checklist, brute-force network protection, two-factor authentication, password policies, file-change detection, and version management. The iThemes name persists across millions of installed sites and searches, so this page covers the same product lineage: iThemes → Solid Security Pro. The 10.x line tells the story: branding updates (SolidWP to Kadence-era), locally-generated 2FA QR codes (10.0.0), and critical fixes – the 10.0.1 race-condition fix addressed a file-write bug that could empty wp-config.php/.htaccess, exactly the class of bug that makes running current versions non-negotiable in security tooling. Against the detection-first Wordfence Premium and access-control specialists like WP Cerber, iThemes/Solid leads the guided-hardening experience.

Sites on the iThemes-era versioning should treat this Pro line as the current product: same checklist, same protection network, StellarWP-era maintenance underneath.

Competitive Features

  • Guided security checklist – prioritized hardening with pass/fail clarity
  • Brute-force network protection – attack data shared across the install base
  • Two-factor authentication – TOTP with locally-generated QR codes
  • Password policies – strength and expiration per role
  • File change detection – core/plugin/theme modification alerts
  • Version management – automatic update control per plugin
  • Malware Scan (Pro) – site scanning with reporting

Key Features

  • Login security – lockouts, CAPTCHA, hide-login
  • Database backups – scheduled database-only backups
  • Idle logout – session limits per role
  • 404 detection – scanner-behavior blocking
  • Security reports – scheduled email digests
  • Multisite support – network management
  • Import/export – settings portability across sites

Comparison with Competitors

iThemes Security Pro vs Wordfence Premium

Aspect iThemes Security Pro Wordfence Premium
School Hardening first Scanner + firewall first
Rule updates Scheduled Real time (Feed)
Password policy Yes No
Version management Yes No
Best for Config-driven security Threat-active sites

Bottom line: Wordfence wins on detection speed and network intelligence; iThemes/Solid wins on the guided-hardening surface – password policy, version management, checklist UX. Configuration discipline picks iThemes; active-threat defense picks Wordfence.

iThemes Security Pro vs Defender (WPMU DEV)

Aspect iThemes Security Pro Defender (WPMU DEV)
Model Standalone hardening suite Membership suite module
Malware scanning Scan module (Pro) Included with Hub reporting
Hardening UX Guided checklist Audit-style recommendations
Reporting Email digests WPMU Hub dashboards
Best for Standalone discipline WPMU-stack agencies

Bottom line: Defender packages protection inside the WPMU membership with Hub reporting; iThemes/Solid dedicates the product to guided hardening. Suite consolidation picks Defender; hardening-first discipline picks iThemes.

Recommended Stack – hardening pairs with backup: combine with UpdraftPlus so configuration discipline extends to recovery readiness.

Official Changelog

Version 10.0.3

Release Date: July 27, 2026

  • Maintenance release: stability and compatibility fixes.

Version 10.0.2

Release Date: June 20, 2026

  • Bug Fix: Handle WP_Error in login interstitial session creation to prevent fatal errors.

Version 10.0.1

Release Date: May 18, 2026

  • Bug Fix: Race condition in file write could empty wp-config.php/.htaccess files.

Frequently Asked Questions

Is iThemes Security Pro still maintained?

Yes – under the SolidWP/StellarWP branding as Solid Security Pro. The iThemes name persists across the install base and this page tracks the same product lineage; the 10.x line is current with active fixes (including the critical 10.0.1 file-write race-condition repair).

What was the 10.0.1 bug and why does it matter?

A race condition in file writing could empty wp-config.php or .htaccess during security-module changes – a site-breaking failure mode. It’s a reminder: security plugins modify critical files, so running current versions and keeping backups is essential.

Does two-factor authentication work without external services?

Yes – TOTP authenticator apps with QR codes generated locally on the server (10.0.0+) – no external push-service dependency.

How is it different from Wordfence?

Hardening versus detection. iThemes/Solid guides configuration discipline – passwords, versions, file monitoring – while Wordfence leads active-threat detection with real-time feeds. Configuration-first sites pick iThemes; attack-facing sites pick Wordfence.

Can I manage multiple sites centrally?

Multisite is supported natively, and StellarWP’s ecosystem tools provide cross-site visibility for agencies running Solid across client fleets.

Download the ZIP from the version buttons above, then go to Plugins → Add New → Upload Plugin, choose the file and click Install Now. Activate the plugin and you are done. Full walkthrough on our How to Install page.

Leave a Reply

Your email address will not be published. Required fields are marked *