

WP Ghost (formerly Hide My WP Ghost)
WP Ghost is a WordPress hack-prevention plugin that secures and changes default WordPress paths and blocks attacking bots with an 8G firewall before they ever reach your plugins, themes, or core.
Cost / License
- Freemium (Subscription)
- Open Source (GPL-2.0)
Application type
Platforms
- Online
- Software as a Service (SaaS)
- Wordpress



Features
- Two-factor Authentication
- Web Application Firewall
- Firewall
WP Ghost (formerly Hide My WP Ghost) News & Activities
Recent activities
BenBitNinja added WP Ghost (formerly Hide My WP Ghost) as alternative to PhantomGuard- wpplugins updated WP Ghost (formerly Hide My WP Ghost)
wordsec added WP Ghost (formerly Hide My WP Ghost) as alternative to WordSec- mikeybeck added WP Ghost (formerly Hide My WP Ghost) as alternative to WP Triage
WP Ghost (formerly Hide My WP Ghost) information
What is WP Ghost (formerly Hide My WP Ghost)?
WP Ghost (formerly Hide My WP Ghost) is a proactive hack-prevention suite for WordPress. Instead of scanning for malware after a breach, it reduces your site's attack surface so automated attacks fail at the reconnaissance stage. Over 100,000 active installations, rated 4.5/5.
HOW IT WORKS
Almost every WordPress attack starts with a bot fingerprinting your site - requesting /wp-login.php, /wp-admin and known plugin folders to confirm you run WordPress and spot vulnerable components. WP Ghost breaks that first step.
-
Paths Security - Change and secure the entry points bots look for: wp-admin, wp-login.php, register, logout, lost password, admin-ajax.php, wp-includes, wp-content, uploads, author paths, wp-json REST API, and individual plugin and theme folder names. No core files are modified; it works through rewrite rules, filters and output mapping.
-
8G Firewall - A lightweight server-edge filter (7G and 8G rulesets) blocking SQL injection, XSS, script injection, directory traversal, file inclusion and bad-bot patterns before the request reaches PHP. Malicious traffic is deflected early, so server load drops rather than rises.
-
Automated IP Blocking - IPs that repeatedly probe secured paths are blocked automatically, with no manual review.
KEY FEATURES
- Text and URL Mapping: change class names and IDs so themes and plugins cannot be fingerprinted from CSS or JS
- Path changes propagate to AJAX, feeds, sitemaps, robots.txt, cache files and CDN URLs
- Security headers: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options
- 2FA by code or email, plus Passkeys - passwordless login via Face ID, Touch ID, Windows Hello or hardware keys
- Brute force protection on login, registration, comments and WooCommerce, with math captcha and Google reCAPTCHA
- Disable XML-RPC, REST API for non-authenticated users and directory browsing
- Remove version tags, generator meta and WP HTML comments; block wp-config.php, readme.html and debug.log
- Fix file permissions, change the database prefix, regenerate SALT keys
FREE VS PREMIUM
Free includes the full 7G/8G firewall, core path changing and hiding, all three 2FA methods, Magic Link and temporary logins, brute force protection, security headers, text and URL mapping, and 65+ hardening options.
Premium adds the Security Threats Log, User Events Log, extended file-extension hiding, country blocking and path-based geo restrictions, automated IP blocking, vulnerability monitoring, cloud management and priority support.
COMPATIBILITY
Works alongside hosting firewalls and other security plugins including Wordfence and Solid Security - it covers the reconnaissance phase those tools do not. Compatible with WooCommerce, Multisite, major caching plugins, Elementor and Yoast SEO. Runs on Apache, Nginx, LiteSpeed and IIS.
WP Ghost is the prevention layer in front of your backups and hosting security, not a replacement for them.




