Kadence Security – Password, Two Factor Authentication, and Brute Force Protection
Plugin Review
AI-ResearchedWhat is Kadence Security?
Kadence Security is a WordPress security plugin that protects sites from brute force attacks, malware, and login vulnerabilities. Formerly known as iThemes Security, it is now developed by Nexcess. The plugin has been actively maintained for 16 years, making it one of the oldest security solutions in the WordPress ecosystem. It currently has over 700,000 active installs and a 4.6 out of 5 rating from 3,987 user reviews. A full 86% of those reviews are five-star, indicating strong user satisfaction across a vast install base.
The plugin reduces your site’s risk by automatically locking out malicious users identified by a Brute Force Protection Network of nearly 1 million sites. It focuses on the most attacked part of WordPress: user login authentication. With a Pro upgrade, Patchstack integration provides protection before a plugin or theme vulnerability is even patched. This creates a 24/7/365 security layer for your website.
Key Features of Kadence Security
- Brute Force Protection Network: Automatically blocks attackers identified across a network of nearly 1 million sites, using your own blacklist.
- Two-Factor Authentication (2FA): Adds an extra layer of login security to protect user accounts from credential theft.
- Security Site Templates: Applies pre-configured security settings for six site types, including Ecommerce, Blog, and Non-Profit.
- Real-Time Security Dashboard (Pro): Monitors brute force attacks, banned users, active lockouts, and site scan results in a single view.
- Password Protection: Enforces strong password policies to reduce the risk of compromised user accounts.
- Patchstack Integration (Pro): Automatically protects your site from known vulnerabilities before a patch is released.
- Malware Protection: Scans for and helps remove malicious code that could harm your site or visitors.
- Onboarding Wizard: Guides any user through securing their site in under 10 minutes, regardless of technical skill.
Who Should Use Kadence Security?
Kadence Security is built for site owners who want a hands-on yet guided approach to security. The plugin’s six Site Templates make it ideal for beginners running eCommerce stores, community networks, or simple blogs. You do not need to be a developer. The 10-minute setup wizard walks you through each decision. With 700,000+ active installs, it is trusted by both small site owners and larger organizations managing multiple sites.
Advanced users will appreciate the real-time dashboard and Patchstack integration in the Pro version. The plugin requires a minimum of WordPress 6.5 and PHP 7.4. It works on Apache, LiteSpeed, or NGINX servers. If you manage a site that needs proactive brute force blocking and user authentication security, this plugin fits your workflow. The 86% five-star rating confirms it meets expectations for a wide range of site types.
Installation & Setup
Install Kadence Security from your WordPress admin dashboard like any other plugin. The onboarding wizard activates immediately, letting you choose a Security Site Template based on your site type. The entire process takes under 10 minutes, even for non-technical users. The plugin strongly recommends a full site backup before activation, as it makes changes to your database and site files.
Support & Community
Support data from the last 2 months shows 24 open threads and only 6 resolved, giving a 39% resolution rate. This is notably low compared to the plugin’s high rating. The 7% one-star reviews often cite failed backups or site breakage after applying security settings. The FAQ itself warns users to back up before using the plugin. The development team tests only on the latest stable WordPress version, which can cause issues for sites not fully updated. Despite these support challenges, the plugin remains popular due to its proven track record over 16 years and its large, active user base of over 700,000 sites.
Pros & Cons
- With 700K+ active installs and a 4.6/5 rating from nearly 3,987 reviews, it has broad community trust and validation.
- The Brute Force Protection Network leverages nearly 1 million sites to automatically lock out bad actors, reducing login attacks.
- Setup is designed to take under 10 minutes, making it accessible for users with minimal technical experience.
- Six security site templates (e.g., eCommerce, Network) allow tailored protection based on site type, improving relevance of settings.
- Patchstack integration in Pro offers vulnerability protection before patches are released, addressing zero-day risks proactively.
- Only 25% of support threads are resolved (6 of 24), indicating low responsiveness for user issues.
- Despite 86% 6% of reviews are 1-star, suggesting notable dissatisfaction among a minority of users.
- The plugin is a rebranded version of iThemes Security, which may cause confusion or migration friction for existing users.
- Core advanced features like Patchstack integration require a Pro upgrade, limiting full protection for free users.
Technical Details
- Requires WordPress
- 6.5+
- Requires PHP
- 7.4+
- Tested up to WP
- 7.0
- First Released
- 2010 (16+ years)
- Support (last 2 months)
- 23 threads — 39% resolved
Feature Tags
Frequently Asked Questions
Yes, Kadence Security is free and available on WordPress.org. It has over 700,000 active installs and a rating of 4.6 out of 5 stars from nearly 3,987 reviews.
Kadence Security is used by more than 700,000 active WordPress installations. This large user base also contributes to its Brute Force Protection Network, which is nearly 1 million sites strong.
Kadence Security requires WordPress 6.5 or higher. The plugin is only tested and guaranteed to work on the latest stable version of WordPress to ensure optimal security.
Yes, Kadence Security is actively maintained and was last updated on May 28, 2026. It was first released in 2010 and is currently at version 10.0.2.
Kadence Security requires PHP 7.4 or higher. This ensures compatibility with modern security features and performance improvements.
Support is available through WordPress.org forums, with 24 support threads in the last 2 months and a 39% resolution rate. Most support requests involve users who did not make a backup before applying features.
Yes, the setup and onboarding experience allows anyone to secure their WordPress website in under 10 minutes, regardless of technical skill. It provides security site templates to fit different types of sites.
Key features include brute force protection, two-factor authentication, password security, and a Brute Force Protection Network of nearly 1 million sites. It also integrates with Patchstack (Pro) for proactive vulnerability protection.