SeenSecure Help
Complete documentation and guides to get the most out of your WordPress security plugin
This is the official user documentation. Here you'll find step-by-step guides to configure and use all of your WordPress site's security features.
Your first line of defense. Automatic protection against attacks, intrusions and unauthorized access.
Read more →Controls and limits the number of requests from each IP address. Protects against brute force and automated attacks.
Read more →Blocks or allows access based on geographic location. Perfect for local sites or regulatory compliance.
Read more →Configure HTTP security headers that protect against XSS attacks, clickjacking and other web vulnerabilities.
Read more →Your site's first door: filters suspicious requests before WordPress even loads, without using resources or slowing the site down.
Read more →Blocks or allows traffic based on the company providing the connection (Amazon AWS, OVH, Hetzner...), more precise than blocking by country.
Read more →Prevents automatic notifications from Stripe, PayPal and other processors from being blocked by mistake, by verifying their real IP.
Read more →Protects against attacks using many different IPs at once, something per-IP Rate Limiting can't stop on its own.
Read more →Multi-layer Anti-Bot protection: blocks automated bots, scrapers and non-human traffic via User-Agent, fingerprinting and DNS verification.
Read more →Three layers of defense: redirect URL sanitization, anti-injection shield and Referer origin validation.
Read more →Four protection modes, from passive monitoring to aggressive blocking, to choose the level that best fits your site.
Read more →Anonymously report your blocks and receive the collaborative blocklist of IPs confirmed by several sites. Opt-in with explicit consent.
Read more →Absolute manual access control: allow or block specific IPs with top priority over the firewall's other rules.
Read more →Centralizes malicious IP sources (SeenSecure API + Spamhaus DROP), blocks Tor exit nodes and monitors threat traffic in real time.
Read more →Strengthens your login page security with 2FA, URL change, and protection against brute force attacks.
Read more →Adds an extra layer of security by requiring a verification code in addition to the password.
Read more →Applies advanced security settings to protect your WordPress against common vulnerabilities.
Read more →Controls which file types can be uploaded and prevents malicious code from entering through your gallery.
Read more →SeenSecure blocks malicious files before they reach the server: dangerous extensions, invalid MIME types, double extensions and null byte injection.
Read more →View all security events, blocked access attempts, and attack patterns.
Read more →Create whitelists and blacklists of IP addresses. Automatically block known attackers.
Read more →Detects and blocks malicious bots while allowing legitimate crawlers like Googlebot.
Read more →SeenSecure's Traffic Log lets you view, filter and analyze all of your WordPress traffic: allowed, blocked and monitored requests.
Read more →SeenSecure's Incidents module logs a unique ID every time the firewall blocks a request, letting you search, analyze and manage incidents.
Read more →SeenSecure's Security Scanner detects malware, vulnerabilities and unauthorized changes, and manages quarantined files to protect your site.
Read more →SeenSecure's Emergency Restore is a standalone recovery system that works even if WordPress is broken, locked out or deleted, with direct access to backups.
Read more →SeenSecure manages complete backups of your WordPress and protects your configuration changes with automatic rollback.
Read more →We recommend this order:
Yes, it's important to review the logs weekly during the first month. Look for false positives (legitimate users blocked) and adjust the limits as needed. SeenSecure learns from your site's traffic.
No. SeenSecure is optimized to run quickly without affecting speed. Events are logged asynchronously so they don't impact the user experience.