Logo
Search
Get Listed
Sign In

Solid Security Pro Review 2025: Features, Pricing, Pros & Cons

Solid Security Pro

Looking for a WordPress security plugin that actually works? You're not alone. With over 30,000 websites getting hacked every day and nearly half of all WordPress sites running vulnerable code, choosing the right security solution isn't just smart—it's essential.

Solid Security Pro (formerly iThemes Security Pro) has been protecting WordPress sites since 2014, and it's built by people who really know their stuff. But is it worth your money? And more importantly, will it keep your site safe?

In this review, we'll break down everything you need to know about Solid Security Pro—from its key features and pricing to the real pros and cons you should consider before making a decision. No fluff, just the facts to help you figure out if this is the security plugin your site needs.

What is Solid Security Pro & What Does it Do?

Think of Solid Security Pro as your website's personal bodyguard. It's a comprehensive WordPress security plugin that's been protecting sites since 2014, formerly known as iThemes Security Pro. But unlike those intimidating security guards you see in movies, this one's actually pretty friendly and easy to work with.

Solid Security Pro offers a live WordPress security control panel that tracks security activities on your website 24/7. It's like having a security camera system that never sleeps, constantly watching for suspicious activity and blocking threats before they can cause damage. The plugin tackles all the big scary stuff that keeps website owners up at night - from brute force attacks to malware infections.

One of the biggest threats your site faces is brute force attacks, where automated scripts attempt countless password variations to gain access to your admin dashboard. Solid Security Pro blocks these attacks both locally and at the network level, banning IP addresses that have been caught trying to break into other sites in their network of over 1 million websites. It's like having your security system connected to a neighborhood watch program where everyone shares information about suspicious activity.

The plugin also strengthens your login security significantly and acts as your early warning system for vulnerabilities. It makes your WordPress login nearly impenetrable by requiring users to enter a security code along with their password through two-factor authentication. Plus, it performs twice-daily checks for known vulnerabilities in WordPress core files, plugins, and themes, and can even automatically apply patches when they're available.

Perhaps the best part about Solid Security Pro is how user-friendly it is. The plugin comes with six different site templates containing recommended security settings for different types of websites, so you can protect your site within minutes with no special configuration required. Whether you run an e-commerce store, a blog, or a business website, there's a template that fits your needs, making it incredibly easy to get solid protection without needing to be a security expert.

Solid Security Pro Pros & Cons

Pros

  • Complete security toolkit in one plugin
  • Super user-friendly dashboard
  • Smart automation for threats and updates
  • Multiple login protection options
  • Real-time 24/7 monitoring
  • Network-level protection from million-website community

Cons

  • Can conflict with other plugins
  • No dedicated web application firewall
  • Resource intensive on limited servers
  • Limited update transparency
  • Learning curve for beginners

What are Solid Security Pro Key Features?

Security Summary

The Security Summary card serves as your central command center for immediate security concerns, zeroing in on current high-risk security issues and providing clear guidance on how to quickly take corrective action. Beyond immediate threats, it keeps you informed with the latest security news and their weekly vulnerabilities report, acting as both your emergency alert system and security newsletter rolled into one.

User Security Profiles

The User Security Profiles card gives you a comprehensive view of all your site's users and their security practices, allowing you to search for individual users or filter by role and quickly assess account security. You can identify users with weak passwords, those missing two-factor authentication, or abandoned accounts, and take immediate action by sending 2FA reminders or forcing password updates directly from the interface.

Individual User Profile

The Individual User Profile feature allows you to pin specific users' security profiles directly to your dashboard for continuous monitoring, displaying their role, password strength, password age, 2FA status, and last login time. This focused approach is perfect for keeping close tabs on high-privilege users or monitoring accounts you're concerned about without having to search through user lists repeatedly.

Active Lockouts

The Active Lockouts card provides real-time visibility into user accounts and IP addresses currently blocked from your site, listing all locked-out entities with clear explanations of why they were blocked. Since lockouts are temporary, you can quickly revoke them directly from this card, which is essential when legitimate users get accidentally locked out due to failed login attempts or CAPTCHA struggles.

Lockouts

The Lockouts card provides comprehensive analytics by tracking all lockouts over time, breaking them down into three categories: IP addresses (bot attacks), usernames (targeting common names like "admin"), and actual user accounts. User lockouts are particularly concerning and should normally be 0%, as they indicate either legitimate users having serious difficulties or attackers specifically targeting real accounts on your site.

Bans Overview

Bans represent permanent restrictions that go beyond temporary lockouts, automatically created when IP addresses are locked out repeatedly for suspicious behavior or manually applied by administrators. This automated escalation system ensures persistent threats are permanently blocked, with the overview helping you understand the volume of serious threats your site faces and identify attack patterns.

Banned IPs

The Banned IPs card provides detailed forensic information about each permanently banned IP address. When you select individual IPs from the ban list, you can see exactly when they were banned, the specific reasons for the ban, and any notes that security administrators have added about that particular threat. This detailed record-keeping is invaluable for understanding attack patterns and maintaining proper security documentation.

Beyond just viewing information, this card gives you complete control over your ban list. You can add your own notes about specific IP addresses, remove bans with a single click if you determine they were applied in error, or view the complete activity log for any banned IP to understand their full interaction history with your site. 

Threats Blocked

The Threats Blocked card presents a visual day-by-day chart showing security events where firewall rules have been triggered and successfully prevented attacks from reaching your site. This real-time visualization helps you understand the volume and frequency of attacks your site faces, with most blocked threats typically being brute-force login attempts or attempts to exploit known vulnerabilities in plugins and themes.

The card highlights the effectiveness of Solid Security Pro's "virtual patch" system, which protects vulnerable plugins even before official patches are released. You can also monitor the success of any custom firewall rules you've created, giving you complete visibility into your site's defensive capabilities. This feature transforms abstract security concepts into concrete, visual data, helping you understand just how much your security system is actually protecting you from daily threats.

Trusted Devices

The Trusted Devices card tracks successful logins from devices that users have designated as trusted, providing an additional layer of security through device recognition. When users log in, Solid Security Pro can "remember" their trusted devices, and for high-privilege users, you can require that they only log in from these pre-approved devices. This creates a more secure environment while maintaining user convenience for regular, legitimate access.

The security benefit becomes clear when you consider session hijacking attacks - once a device is trusted and associated with a user account, Solid Security Pro will force a logout if the user's device signature changes while they're interacting with the site. This behavior typically indicates malicious session hijacking, where an attacker has somehow gained access to a user's session. The Trusted Devices card charts daily logins from trusted devices, helping you monitor normal user behavior and quickly spot anomalies that might indicate security breaches.

Update Summary

The Update Summary card provides a comprehensive tally of all updates applied to your WordPress installation within a customizable time period. This includes updates to WordPress core, plugins, and themes, giving you a complete picture of how well-maintained your site's software is. Keeping software updated is one of the most critical aspects of WordPress security, as outdated software often contains known vulnerabilities that attackers actively exploit.

This feature helps you maintain oversight of your site's update schedule and ensures nothing falls through the cracks. You can customize the time period to view recent updates or look at longer-term patterns, helping you understand your site's maintenance rhythm. Since many security breaches occur through outdated plugins or themes, having clear visibility into your update history helps you stay on top of this crucial security practice and quickly identify if any components haven't been updated recently.

Solid Security Pro Pricing Plans

Solid Suite: Starts with $199/year
Solid Security Pro: Starts with $99/year
Solid Backups: NextGen: $8.25/month, billed annually
Solid Central Pro: $69/year
It has a 30-day money-back guarantee on its Pro plans.

Solid Security Pro plans

BasicPlusAgency
$99.00 per year$199.00 per year$299.00 per year
  • 1 Secure Site
  • All Pro Features
  • Private, ticketed email support
  • Plugin updates
  • 5 Secure Sites
  • All Pro Features
  • Private, ticketed email support
  • Plugin updates
  • 10 Secure Sites
  • All Pro Features
  • Private, ticketed email support
  • Plugin updates
Get Started

Solid Security Pro Reviews: What Do Its Customers Have to Say?

Looking at customer reviews, Solid Security Pro generally receives positive feedback from users. Most customers praise the plugin's ease of use and intuitive interface, with many highlighting how simple it is to set up and manage compared to other security plugins.

The support team gets consistently good marks, with users describing them as helpful, responsive, and knowledgeable when resolving technical issues.

However, it's not all perfect. Some users report occasional login issues and redirect problems, particularly when syncing across multiple sites. A few customers mention that while they like the end product, they sometimes struggle with technical glitches that require support intervention.

Overall though, the majority of reviews are positive, with many long-term users sticking with the platform for years and recommending it to others.

Final Recommendation

Solid Security Pro is a solid choice for WordPress users who want comprehensive security without the complexity. While it has some drawbacks like ticket-only support and higher resource usage, it delivers where it matters most with an intuitive dashboard, automatic threat protection, and advanced login features. ‘

If you want reliable "set it and forget it" security that actually works, it's worth the investment—just make sure your hosting can handle the extra resource requirements.

Solid Security Pro Frequently Asked Questions (FAQs)

Which is the Best WordPress Security Plugin to Secure WordPress Websites?

There are many WordPress plugins available in the market. However, we would suggest you check here for the list of best rated WordPress security plugins and secure your WordPress website and blog from all the Major Malware attacks and from Hacking.

How do I install Solid Security plugin to my WordPress Website?

Once you purchase this Plugin, you will get an email confirmation along with the link to login to the Solid WP Member Panel, where you can download your Solid Security plugin zip file. You will be also given the set of instructions on the same email.

How do I contact Solid Security Support?

Incase you need to contact Solid WP support, you can always contact them either from https://solidwp.com/support/ or through Email. They will be always responding you for any querries.

Can I get Refund at Solid Security?

Yes, they provide 30 days money back guarantee. Hence, you can request for full refund within this period and claim for the Refund.

What is limit login attempts?

Limit login attempts restricts how many times someone can try to log into your site from the same IP address before getting locked out. You can set custom lockout times, and users see how many attempts they have left. This prevents brute force attacks where hackers try thousands of password combinations to break into your site.

What is security pro certification?

The TestOut Security Pro certification tests your ability to handle tasks that IT security professionals typically do in their jobs. It's designed for people like network administrators, systems administrators, and IT security specialists who want to prove their skills in managing security systems and protecting networks.

How would you rate this host?

Features

Support

Performance

Pricing

Write your review

Take a deep breath and think about exactly what you want to say about this host.

Next
Submit your review

Solid Security Pro Competitors