WordPress Security · Plain-English · AI-Powered

WordPress security that explains itself.

You manage dozens of client sites. SecurynAI blocks attacks in real time and tells you, in plain English, exactly what's wrong and how to fix it — so you stop decoding cryptic scanner alerts. Want every fix applied for you, automatically? That's Pro.

Real-time firewall + login protection · every issue in plain English · the exact fix, every time · auto-fix on Pro
Finding 04-17-2204 ● Severity: High

A core file has been silently altered.

wp-includes/version.php was modified 2 hours ago, outside of any WordPress update. The change altered the reported version number — commonly done to evade version-based vulnerability scanners.

Admin login from an unusual geography.

Account developer_john signed in from   São Paulo, BR  at 03:17 server time. This user normally logs in from the US between 9am–6pm.

Attack chain detected across three signals.

A new admin was created, a rogue cron was scheduled, and an outbound request to t3mp-host.xyz fired within 90 seconds — consistent with a post-exploitation exfiltration pattern.

/ 00 — Position

Not another scanner. A security teammate.

Other plugins scan and dump alerts on you. SecurynAI blocks attacks as they happen, figures out what's wrong, and explains it in plain English — with the exact fix. On Pro, it applies the fix for you.

I · CLARITY

It tells you what happened.

Not "Warning: file modified." Instead: which file changed, why that's a problem, how confident it is, and what you should do — in words you can forward to a client.

II · LESS WORK

Fewer alerts. Fewer tickets.

Security plugins flood your inbox with cryptic codes. SecurynAI cuts the noise — clear, prioritized issues in plain English, so your Monday isn't spent decoding the same warnings across 30 sites.

III · GUIDANCE

It tells you exactly how to fix it.

Most scanners stop at "found a problem." SecurynAI hands you the precise fix — the file, the setting, the steps — and deep-links to WordPress's own tools. On Pro, it applies the fix for you, with one-click undo.

IV · CONTROL

AI does the work. You stay in charge.

You decide what it's allowed to auto-fix. Anything risky needs your approval. Every action is logged and reversible. You can see exactly what it did and why.

/ 01 — Agency Ops

Built for teams managing client sites.

If you're responsible for keeping client WordPress sites secure, this is for you: fewer support tickets, faster cleanups, and security reports clients actually understand.

01

Fewer fire drills.

The firewall blocks attacks before they land, and every issue ships with the exact fix — so cleanups take minutes, not hours. Pro auto-applies the routine ones.

02

Faster cleanups.

Every issue is explained with the exact fix, so you resolve it in minutes instead of digging through logs. Pro groups related alerts into one story.

03

Reports clients understand.

Every issue is explained in plain English with what happened and what was done — share it directly without rewriting it first.

04

More time for real work.

Less time reacting to alerts, fewer "is my site hacked?" emails, and a stronger security offering for your maintenance plans.

Running SecurynAI across a fleet of client sites? Talk to us about bulk licensing and volume pricing — a real person will get back to you.

/ 02 — Features

What it actually does for you.

Every feature maps to a real problem: fewer alerts to deal with, faster incident cleanup, and clear answers when clients ask "what happened?"

Saves time

Pinpoints the routine stuff — fix included

Missing security headers, exposed .env files, stale admin accounts, risky plugin settings — caught and explained with the exact remedy. Pro applies them for you automatically, each a one-click undo.

Client communication

Explain issues to clients without rewriting

No scanner jargon. Every issue explains what happened, why it matters, and what was done — so you can forward it to a client without pulling a developer into the conversation.

Login protection

Stop unauthorized logins

Brute-force blocking, XML-RPC lockout, unusual login alerts, old admin account warnings, and one-click session kill — so a compromised password doesn't turn into a 2am emergency.

File monitoring

Catch hacked files before downtime

WordPress core, plugin, and theme files are checked against known-good versions. Suspicious changes are flagged early with a deep-link to WordPress's own re-install flow. Pro restores or quarantines the file in one click.

Vulnerability alerts

Know which vulnerabilities actually affect you

Known vulnerabilities checked against the plugins and themes you actually have installed — 20,600+ with the optional Wordfence Intelligence feed — so you're not wasting time patching things that don't apply to your sites.

Firewall & hardening

Every site starts locked down

Built-in firewall blocks SQL injection, XSS, and remote code execution from the moment it's active. A hardening checklist flags every gap against a solid baseline — and Pro applies the whole list in one click, no manual work.

Pro adds for teams that want the AI doing more
  • Behavioral monitoring — learns what's normal for your site. Flags when something doesn't fit the pattern, not just when a rule trips.
  • Attack stories — related alerts grouped into one report instead of three separate notifications you have to piece together.
  • More auto-response options — kill sessions, isolate suspicious plugins, roll back changes. Always within rules you set.
  • Risk scored against your plugins — vulnerabilities ranked by whether they actually affect your installed plugins and themes.
  • Adaptive firewall & smarter bot filtering that adjusts to your site's traffic patterns.
  • 90-day activity log, approval workflows, and policy controls for your team.
/ 03 — Method

How it works.

Five steps — the same way a security person would handle a problem, but running around the clock across every site you manage.

01 · Watch

Monitor.

Watches logins, file changes, admin activity, scheduled tasks, and outbound requests. Nothing missed, nothing guessed.

Monitors: 14 different areas
02 · Learn Pro

Baseline.

Learns what's normal for your site — who logs in, when, from where, which files change. When something breaks the pattern, you'll know.

Learning window: 30 days
03 · Connect Pro

Piece together.

Links separate alerts into one story. A vulnerability only matters if it affects the plugins and themes you actually have installed.

Powered by: AI + strict rules
04 · Act

Fix it.

Free hands you the exact fix and deep-links to WordPress's native flow. Pro applies the safe fixes for you — each one a one-click undo.

Risky changes: always asks first
05 · Explain

Tell you.

Every issue explained in plain English. Every action logged with evidence. Everything reversible. Nothing happens without you knowing.

Log: tamper-proof · exportable
/ 04 — Tech

Honest spec sheet.

A WordPress plugin has real constraints. We engineered around them rather than pretending they don't exist.

Platform
WordPress 6.2+ · PHP 7.4+ · MySQL/MariaDB · Apache or Nginx
AI runtime
External only. PHP can't run AI models natively — so all AI calls go through your own OpenAI or Anthropic API key.
Vuln feed
wpvulnerability.net by default · optional Wordfence Intelligence v3 (20,600+ CVEs, refreshed daily) with a free Wordfence key · cached locally
Data locality
All data stored in your own database. Nothing leaves your site unless you explicitly allow it.
License
GPL-2.0 (plugin) · MIT (SDK helpers)
/ 05 — Compare

They dump alerts. We explain them.

Other security plugins are good at scanning. None of them explain what it means in plain English, or hand you the exact fix — and only SecurynAI Pro applies it for you.

What matters Wordfence Sucuri Patchstack SecurynAI
Explains what happened in plain English No No No Yes
Hands you the exact fix (and applies it) Flags only Paid service Flags only Guide · Auto on Pro
One-click undo on every fix No No No Pro
Checks vulnerabilities against your installed plugins Yes No Yes Yes
Learns your site's normal patterns No No No Pro
Groups related alerts into one report No No No Pro
Scans your plugin code for suspicious patterns Yes No No Pro

Full transparency: SecurynAI's vulnerability data defaults to the wpvulnerability.net feed. If you add a free Wordfence API key, it switches to the Wordfence Intelligence v3 feed instead — the same industry-standard data Wordfence itself publishes. We use it and we credit it. The table above compares product capabilities, not the underlying data source.

/ 06 — Safety

AI does the work. You stay in control.

These guardrails govern SecurynAI Pro's automatic fixes — you set the rules, you see the evidence, and anything Pro does can be undone in one click. The free plugin is detection-only: it never changes your site, so there's nothing to undo.

You set the rules Pro

You choose what it can auto-fix and what needs your approval. Change the settings anytime.

Asks before risky changes Pro

Disabling a plugin, killing sessions, touching sensitive files — that's your call, not the AI's.

Undo anything Pro

Every action is one click to reverse. File restores, session reinstatement, setting changes. Nothing is permanent.

Shows its reasoning

Every decision comes with the evidence behind it. You see why it flagged something, not just what.

When unsure, it waits Pro

If the AI isn't confident enough, it watches instead of acting. You can see exactly where that line is.

Tamper-proof log Pro

Every action the AI takes — proposed, approved, done, undone — goes in a log you can export anytime.

/ 07 — Pricing

Two tiers. Clean lines.

The free version is a real security plugin — not a stripped-down demo. Pro adds deeper AI monitoring and response on top of it.

01 / STARTER

Starter

Free · forever
$0/ site / year AI explanations included — you supply your OpenAI or Anthropic key

"Install once. Block the obvious attacks. See exactly what's wrong — and how to fix it."

  • Real-time firewall — blocks SQLi, XSS, RCE, sensitive-file access
  • Brute-force & login protection
  • Plain-English explanation + the exact fix on every issue
  • Vulnerability alerts (20,600+ known CVEs with the optional Wordfence key)
  • File & core integrity detection with native-WP fix links
  • Hardening checklist (detect & guide)
  • 7-day activity log
Install on WordPress.org

Managing multiple sites? Volume pricing for agencies and studios.

Contact us →

No dark patterns. No blurred teasers. No fear-driven upgrades. No nags outside our own plugin UI.

/ 08 — FAQ

Straight answers.

The questions people actually ask before installing a security plugin — answered directly, not buried in a features page.

Is SecurynAI free?

Yes — the Starter tier is free forever, with a real-time firewall, malware scanning, and hardening built in. Pro adds AI-driven behavioral monitoring and one-click auto-fix for $79/site/year. Starter isn't a stripped-down trial; it's a complete, standalone security plugin on its own.

Does SecurynAI need an OpenAI or Anthropic API key?

Only for the plain-English AI explanations. The firewall, scanning, and hardening checks all run without any key. Add your own OpenAI or Anthropic key (typically ~$0.10–$0.30/month in API costs) for fuller AI-written narratives; without one, you still get clear fallback explanations.

Where does the vulnerability data come from?

wpvulnerability.net by default, refreshed daily. If you supply a free Wordfence API key, SecurynAI can optionally use the Wordfence Intelligence v3 feed instead, which covers 20,600+ known CVEs.

What WordPress and PHP versions does it require?

WordPress 6.2+ and PHP 7.4+, running on MySQL/MariaDB with Apache or Nginx — the same platform baseline listed in the plugin's official readme.

Is SecurynAI better than Wordfence?

Depends what you need. Wordfence is a mature, widely-trusted scanner and firewall; SecurynAI covers the same core ground and adds plain-English explanations and alert correlation. See the full, feature-by-feature comparison for where each one has the edge.

Is Pro available to buy right now?

Not through an automated checkout yet — Pro is currently early access by request. Reaching out gets a reply from an actual person, not an autoresponder, and agencies can ask about bulk licensing the same way.

Does SecurynAI send my site's data anywhere?

No — all data stays in your own WordPress database and nothing leaves your site unless you explicitly connect an AI provider. Even then, only the specific finding text is sent to the provider you chose, not your full site data.

Who builds SecurynAI?

Archin Joshi and Rishabh Jha, software engineers at WisdmLabs — see the about page for more on who's behind it and how the content on this site gets fact-checked.

· End of brief ·

The security person you don't have, already working.

Three steps: install the plugin, paste your OpenAI or Anthropic key, scan. Your first issue comes back explained in plain English instead of W32/PHP.Obfus.Gen — with the exact fix spelled out. (On Pro, that fix is one click.)

Install free on one site Get Pro early access