
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… Security & Risk Analysis
wordpress.org/plugins/vigilantePremium WordPress Security - 100% FREE: Firewall, 2FA, Security Headers, Login and Malware Protection, File Monitor, Activity Log, Under Attack & more
Is Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… Safe to Use in 2026?
Generally Safe
Score 100/100Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'vigilante' v1.5.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to output escaping and robust use of prepared statements for SQL queries, indicating good development practices in these areas. The complete absence of known CVEs and a clean vulnerability history are also significant strengths. However, a substantial attack surface exists within its AJAX handlers, with a concerning 23 out of 42 handlers lacking authentication checks. Furthermore, the taint analysis reveals 6 flows with unsanitized paths, 5 of which are categorized as high severity, suggesting potential vulnerabilities related to how user input is processed. While no critical issues were found in the taint analysis, these high-severity unsanitized paths on a plugin with a large number of unprotected AJAX endpoints represent the most significant risks.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized paths
- Unsanitized paths in taint analysis
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… Security Vulnerabilities
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… Attack Surface
AJAX Handlers 42
WordPress Hooks 143
Scheduled Events 4
Maintenance & Trust
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… Maintenance & Trust
Maintenance Signals
Community Trust
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… Alternatives
VMP Security – Firewall, Malware Scan, and Login Security
vmpfence-security
Your all-in-one WordPress security solution. Stop hackers with our firewall, detect malware before it spreads, and protect your site.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall
ninjafirewall
A true Web Application Firewall to protect and secure WordPress.
Iron Security – WordPress Security Plugin
iron-security
Hardening tool that blocks hackers and protect against: Brute Force Attacks, Exploits, Injections, Clickjacking and other important functionalities.
ArkHost Security Pack
arkhost-security-pack
WordPress security without the nonsense. No upsells, no premium tier, no fake threat counters.
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… Developer Profile
21 plugins · 24K total installs
How We Detect Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vigilante/admin/css/style.css/wp-content/plugins/vigilante/admin/js/script.js/wp-content/plugins/vigilante/assets/css/frontend.css/wp-content/plugins/vigilante/assets/js/frontend.js/wp-content/plugins/vigilante/admin/js/script.js/wp-content/plugins/vigilante/assets/js/frontend.js/wp-content/plugins/vigilante/admin/css/style.css?ver=/wp-content/plugins/vigilante/admin/js/script.js?ver=/wp-content/plugins/vigilante/assets/css/frontend.css?ver=/wp-content/plugins/vigilante/assets/js/frontend.js?ver=HTML / DOM Fingerprints
vigilante-admin-menu-iconvigilante-noticevigilante_admin_object/wp-json/vigilante/v1/settings