WP Ghost Free vs Premium – Full Feature Comparison
WP Ghost is available in two versions: a free version on WordPress.org with over 115 security features, and a Premium version with over 150 security features focused on security intelligence, automated response, and advanced site hardening. Both versions share the same core hack-prevention engine.
Remove unsafe headers (PHP version, server info, server signature)
Yes
Yes
Block Theme Detector crawlers
Yes
Yes
IP whitelist
Yes
Yes
IP blacklist
Yes
Yes
User agent blacklist
Yes
Yes
Referrer blacklist
Yes
Yes
Hostname blacklist
Yes
Yes
Whitelist paths
Yes
Yes
Automate IP blocking (auto-block repeat offenders)
–
Yes
Configure automation rules (attacks, time window, block duration)
–
Yes
Block AI Crawler Bots at firewall level (30+ crawlers)
–
Yes
Automatic robots.txt Disallow rules for AI crawlers
–
Yes
AI crawler list updated automatically with each release
–
Yes
Brute Force Protection
Feature
Free
Premium
Protection on login form
Yes
Yes
Protection on lost password form
Yes
Yes
Protection on signup form
Yes
Yes
Protection on comments form
Yes
Yes
Protection on WooCommerce login, signup, lost password
Yes
Yes
Google reCAPTCHA v2, v3, Enterprise
Yes
Yes
Math reCAPTCHA
Yes
Yes
Custom attempt limits
Yes
Yes
Custom lockout duration
Yes
Yes
Custom warning messages
Yes
Yes
Block wrong usernames immediately
Yes
Yes
Authentication (2FA, Passkeys, Magic Login)
Feature
Free
Premium
Two-Factor Authentication by code
Yes
Yes
Two-Factor Authentication by email
Yes
Yes
Two-Factor Authentication by passkey (Face ID, Touch ID, Windows Hello)
Yes
Yes
User selects preferred 2FA method in profile
Yes
Yes
Trust current browser (skip 2FA on trusted devices)
Yes
Yes
Magic Link login (one-time passwordless email link)
Yes
Yes
Temporary Logins (time-limited access links)
Yes
Yes
Security Monitoring & Logs
Feature
Free
Premium
Security Optimization Score (0-100) with dynamic gauge
Yes
Yes
GEO Threats Map with top 5 threat countries
Yes
Yes
Threats prevented chart (7-day view)
Yes
Yes
Lifetime attacks blocked counter
Yes
Yes
Weekly domain security monitoring email
Yes
Yes
Security Check with numeric score and task list
Yes
Yes
Notification to activate firewall when unblocked threats detected
Yes
Yes
Security Threats Log (last 20 entries)
Yes
Yes
User Events Log (last 20 entries)
Yes
Yes
Security Threats Log with full history, unlimited entries
–
Yes
User Events Log with full history, unlimited entries
–
Yes
Filter logs by threat type
–
Yes
Filter logs by status
–
Yes
Filter logs by country
–
Yes
Filter logs by time range
–
Yes
Full-text search in logs
–
Yes
Log pagination
–
Yes
Export Security Threats Log to CSV
–
Yes
Export User Events Log to CSV
–
Yes
Click GEO map country to open filtered threats log
–
Yes
Extended log retention (configurable)
–
Yes
Cloud storage for events log (30-day retention)
–
Yes
Log user roles filter
–
Yes
Real-time email alerts for brute force and suspicious activity
–
Yes
Geo Security
Feature
Free
Premium
GEO Threats Map on Overview dashboard
Yes
Yes
Top 5 threat countries with attack counts
Yes
Yes
Country Blocking (block entire countries)
–
Yes
Path-based country blocking (block countries on specific paths)
–
Yes
Login Page Designer
Feature
Free
Premium
Custom logo with live preview
Yes
Yes
Custom logo link URL
Yes
Yes
Background image with blur and overlay controls
Yes
Yes
Page background color
Yes
Yes
Form background color
Yes
Yes
Button color
Yes
Yes
Text color
Yes
Yes
Link color
Yes
Yes
10 color scheme presets
Yes
Yes
12 layout presets
–
Yes
Hiding & Footprint Removal
Feature
Free
Premium
Remove WordPress version tags
Yes
Yes
Remove Generator meta tag
Yes
Yes
Remove RSD header
Yes
Yes
Remove WLW Manifest link
Yes
Yes
Remove WordPress HTML comments
Yes
Yes
Hide admin toolbar by user role
Yes
Yes
Hide REST API URL link
Yes
Yes
Hide rest_route parameter
Yes
Yes
Disable emoticons script
Yes
Yes
Text Mapping (change class names and IDs in source code)
Yes
Yes
URL Mapping (change URLs dynamically)
Yes
Yes
CDN Mapping
Yes
Yes
Hide Source Map References
Yes
Yes
Hide User Enumeration
Yes
Yes
Disable Options
Feature
Free
Premium
Disable XML-RPC
Yes
Yes
Disable REST API access for non-authenticated users
Yes
Yes
Disable rest_route parameter access
Yes
Yes
Disable embed scripts
Yes
Yes
Disable database debug
Yes
Yes
Disable directory browsing
Yes
Yes
Disable right-click (for visitors and by user role)
Yes
Yes
Disable Inspect Element (for visitors and by user role)
Yes
Yes
Disable View Source (for visitors and by user role)
Yes
Yes
Disable Copy/Paste (for visitors and by user role)
Yes
Yes
Disable Drag/Drop (for visitors and by user role)
Yes
Yes
Database & Server Hardening
Feature
Free
Premium
Security Check identifies permission, prefix, username, SALT issues
Yes
Yes
Fix weak admin/administrator usernames
Yes
Yes
Fix file and directory permissions (quick and complete)
–
Yes
Change database table prefix
–
Yes
Regenerate WordPress SALT keys
–
Yes
Fix WordPress debugging mode
–
Yes
Fix script debugging mode
–
Yes
Disable plugin/theme editor
–
Yes
Setup & Compatibility
Feature
Free
Premium
One-click security presets (3 levels)
Yes
Yes
Frontend Test and Login Check
Yes
Yes
Backup and restore settings
Yes
Yes
Pause plugin for 5 minutes for safe testing
Yes
Yes
Dark mode support
Yes
Yes
Translations in 16 languages
Yes
Yes
Compatible with Apache, Nginx, LiteSpeed, IIS
Yes
Yes
Compatible with 20+ hosting providers
Yes
Yes
Compatible with WooCommerce, Elementor, Divi, WPML, and 50+ plugins
Yes
Yes
Compatible with WP Rocket, LiteSpeed Cache, Cloudflare, and 15+ cache plugins
Yes
Yes
Support
Feature
Free
Premium
Knowledge base (wpghost.com/kb)
Yes
Yes
Community support (WordPress.org forums)
Yes
Yes
Free setup assistance
Yes
Yes
Priority support with direct access to security experts
–
Yes
Faster response times
–
Yes
Frequently Asked Questions
Is the free version enough for most sites?
Yes. The free version covers all essential hack prevention: path changes, firewall, brute force protection, 2FA, and security headers. Premium adds intelligence (logs), automated response (IP blocking rules), and advanced hardening for high-security requirements.
Can I upgrade from free to Premium without losing settings?
Yes. Deactivate the free version, install Premium, enter your license token. All existing settings are preserved in the database.
Are both Safe Mode and Ghost Mode free?
Safe Mode is free. Ghost Mode is a Premium feature. Both use the same path-changing engine — Ghost Mode adds wp-admin and admin-ajax.php path changes plus auto-enabled firewall and security headers.
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
Cookie
Duration
Description
cookielawinfo-checkbox-analytics
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional
11 months
The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
viewed_cookie_policy
11 months
The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.