Hack Halt gives WordPress sites serious security without forcing owners to become security experts. Start free, and step up as your site becomes more important.
Free and Pro are the same plugin — a licence unlocks the premium modules. ProSecure is a separate, larger platform for sites that need full detection and response.
Essential protection, running in minutes.
For personal sites, side projects and anyone who wants real protection at no cost.
Automation and intelligence for sites that matter.
For businesses, ecommerce, agencies and production sites where downtime costs money.
The complete security platform.
For business-critical sites that need detection, response and recovery in one place.
Verified against the products themselves — not a marketing wish list.
| Capability | Free | Pro | ProSecure |
|---|---|---|---|
| Core protection | |||
| Real-time firewall | ✓ | ✓ | ✓ |
| Intrusion prevention / lockouts | ✓ | ✓ | ✓ |
| MFA enforcement | ✓ | ✓ | ✓ |
| Guided hardening | ✓ | ✓ | ✓ |
| Recovery tools | ✓ | ✓ | ✓ |
| Detection | |||
| Vulnerability scanning | Manual | Scheduled | Scheduled |
| File integrity monitoring | — | ✓ | ✓ |
| Webshell scanning | — | — | ✓ |
| Database integrity monitoring | — | — | ✓ |
| WAF request inspection | — | — | ✓ |
| Intelligence | |||
| Live traffic visibility | ✓ | ✓ | ✓ |
| Geo-IP resolution | Live only | Persistent cache | Persistent cache |
| Threat-intelligence feeds | — | ✓ | ✓ |
| Honeypot deception | — | ✓ | ✓ |
| Response | |||
| Autodefense / attack-chain correlation | — | ✓ | ✓ |
| Incident Orchestration | — | — | ✓ |
| Backups and one-click restore | — | — | ✓ |
| Security Advisor | — | — | ✓ |
| Supply chain | |||
| CSP controls | Manual | Automated | Automated |
| SRI integrity monitoring | — | — | ✓ |
You run a personal site, blog or small business site and want genuine protection — firewall, intrusion prevention and MFA — without paying anything.
Your website supports your business. You want the security work automated: threat feeds, file integrity, scheduled scans and automatic attack-chain response.
Your site is business-critical. You need full detection and response — WAF inspection, webshell and database integrity scanning, incident orchestration and backups.
Most people overthink this. The question is not which product has the longest feature list — it is how much of the security work you want to be personally responsible for.
A personal site, a portfolio, a blog, a small brochure site. Free gives you a real firewall, intrusion prevention and multi-factor authentication. That combination stops the automated attacks that make up the overwhelming majority of what any WordPress site actually faces.
The moment your site earns money, holds customer data, or would embarrass you if it went down, the danger stops being ‘no protection’ and starts being ‘protection that depends on me remembering’. Pro automates the scanning, the file integrity checks and the response.
If a compromise means lost revenue, disclosure obligations or a hard conversation with customers, prevention alone is not enough. ProSecure adds the detection, response and recovery layers — so the hour after an incident is a procedure rather than a panic.
Free and Pro are the same plugin, so upgrading is a licence change rather than a migration. Nothing is reinstalled and no settings are lost.
Yes. Hack Halt Free and Hack Halt Pro are the same plugin — a licence unlocks the premium modules. Upgrading changes what is available, not what is installed, and none of your settings or rules are lost.
Pro automates protection: threat-intelligence feeds, file integrity monitoring, scheduled scans and automated attack-chain response. ProSecure is a separate, larger platform that adds detection, response and recovery — WAF request inspection, webshell and database integrity scanning, incident orchestration, and backup and restore.
No. They are levels, not components. You run one of them on a site, chosen by how critical that site is.
No. There is no expiry, no request cap and no throttling. It requires a free registration tied to your domain, which is how licensing and updates work across every tier.
Usually Pro. Free is genuinely protective, but a site that generates revenue benefits most from the automation — scheduled scanning and file integrity monitoring catch the problems nobody has time to look for manually.
Running two firewalls is rarely a good idea. They duplicate work and conflicting rules make it much harder to tell what blocked something and why. If you are switching, disable the other one first.
Yes. WooCommerce sites are ordinary WordPress installations from a security standpoint, and they are exactly the case where the automation in the paid tiers earns its cost, because downtime and data exposure both carry a direct price.
Every tier in detail — what it includes, who it is for, and what the software actually looks like.
Start with Free today. Step up whenever your site earns it.
