Defend every WordPress site from one console.
Rush Security is a firewall, malware scanner, and login shield that installs in about a minute — then reports to a master console where you watch, scan, update, and lock down all of your sites at once.
One plugin on every site, one console to run them all.
Rush Security is a WordPress security platform made of two parts: a lightweight client plugin that protects an individual site — application firewall, malware scanning, file-integrity monitoring, brute-force and two-factor login protection, spam filtering, and vulnerability checks — and a master console that manages a fleet of those sites from one dashboard over an Ed25519-signed channel. Owners and agencies install the plugin, add a license, and immediately protect and centrally manage any number of sites — no server access, no complex setup.
Enterprise defense that stays out of your way.
Sensible protection is on by default. Every layer is tunable, and nothing needs a developer to run.
on by default
Application firewall
Inspects every request for injection, traversal, bad bots and rate abuse. A smart human-verification page throttles false positives instead of hard-blocking real visitors, then bans repeat offenders per your rules.
signature + heuristic
Malware scanner
Chunked scanning finds obfuscated backdoors, web shells and injected spam — with quarantine, one-click delete, ignore-as-false-positive, and a scan that resumes safely across large sites.
Login protection & 2FA
Brute-force lockouts, generic errors that stop user enumeration, and TOTP two-factor with recovery codes.
File integrity monitor
Baselines core, plugins and themes and alerts the moment a watched file is modified, added or deleted.
Vulnerability & spam
Flags outdated or CVE-affected plugins and themes, and scores comments and posts to hold spam automatically.
the differentiator
Central master console
See every site’s security score, blocked attacks, malware findings and versions in one place. Push presets, trigger scans, apply official updates and lock sites down remotely — all over a signed, pinned channel that a rogue server can’t forge.
hands-off
Self-updating agent
Publish a new version once; every connected site verifies its signature and hash, then updates itself. Clients only ever install and add a license — you handle the rest from the console.
From install to protected in minutes.
Install the plugin
Upload and activate Rush Security on any WordPress site. It runs on standard shared hosting — no SSH, no server changes.
Add your license
Paste the license key. The site connects to your master console, applies recommended hardening, and starts protecting immediately.
Manage it centrally
Watch every site from the console — scores, attacks, malware and updates — and push scans, presets and lockdowns without ever logging into each one.
Protect one site or a whole fleet.
Every plan includes the full security suite and the master console. Scale up as you add sites.
Starter
For a single WordPress site you want fully protected.
- 1 site license
- Full firewall, scanner & login shield
- File integrity & vulnerability checks
- Automatic signed updates
Pro
For freelancers and small agencies running several sites.
- Up to 10 sites
- Central master console for the fleet
- Remote scans, presets & lockdown
- Priority email support
Agency
For agencies and hosts managing many client sites.
- Unlimited sites
- White-label block & support pages
- Self-hosted master console
- Priority support & onboarding
Frequently asked questions
What is Rush Security?
How is it different from other WordPress security plugins?
Do I need a server, SSH or technical setup?
Does it slow my site down?
Will the firewall block my real visitors?
How do updates work?
Can I manage many client sites as an agency?
Does it support two-factor authentication?
Secure your WordPress sites today.
Install Rush Security, add a license, and run every site’s protection from a single console.
