--- site: "hidemywpghost.com" title: "Hide My WP Ghost" description: "Hide My WP Ghost protects 250,000+ WordPress sites from hackers. Hide your WordPress, block brute force, prevent SQL injection. Rated 4.8★." canonical_url: "https://hidemywpghost.com" generator: Crawlbrain generated_at: 2026-09-04T08:07:07+00:00 language: en-US pages_total: 6 pages_included: 6 schema_version: llms-full/1.0 page_boundary_marker: "# Page:" --- # Hide My WP Ghost > Hide My WP Ghost protects 250,000+ WordPress sites from hackers. Hide your WordPress, block brute force, prevent SQL injection. Rated 4.8★. This file contains the full content of hidemywpghost.com as of the sync timestamp above. Each page is delimited by a `# Page:` header and is followed by a metadata block (URL, section, last updated, language, optional description). Site-wide chrome (navigation, footers, repeated CTAs) has been stripped to improve signal density. For a curated index of entry-point pages, see the companion `llms.txt`. ## Sections in this file - Pages - Changelog - Home - Contact --- # Page: Hide My WP Ghost Pricing - WordPress Security From $49/yr URL: https://hidemywpghost.com/hide-my-wp-pricing/ Section: Pages Last-Updated: 2026-09-04 Language: en-US Description: Protect 1 to unlimited WordPress sites from $49/yr. Trusted by 250,000+ sites. 4.8★ on G2 & Capterra. 30-day money-back guarantee. Choose your plan. • SUMMER SPECIAL · UP TO 70% OFF ## Serious WordPress security, priced simply. Hide My WP Ghost makes your site invisible to hacker bots. YearlyLifetime #### Ghost 1 For your personal site or a freelancer $ 49 /year All premium features Protect 1 website - Adv. firewall protection - Brute force & bot blocking - Country blocking [Protect my site](/buy/1_website/)Paddle secure payment · 30-day refund #### Ghost 5 For small businesses juggling client sites $119$ 59 50 /yr $23.80 / site / year Protect 5 websites - Everything in Ghost 1 - Protect up to 5 websites - Priority email support [Protect 5 sites](/buy/5_websites?coupon=5HIDEMYWP50)Paddle secure payment · 30-day refund #### Ghost 25 For big businesses protecting their websites $ 249 /yr from $9.96 / site / year Protect 25 websites - Everything in Ghost 1 - 25 websites - Priority email support [Protect 25 sites](/buy/25_websites)Paddle secure payment · 30-day refund #### Ghost All For agencies protecting bigger client portfolios $ 499 /yr Unlimited Websites Protect all websites - Everything in Ghost 1 - Unlimited websites - Priority email support [Protect all my sites](/buy/unlimited_websites)Paddle secure payment · 30-day refund #### Ghost 5 · Lifetime Pay once, Protect 5 sites forever. $ 399 $79.90 / site · lifetime - All premium features, forever - Protect up to 5 websites - Lifetime updates included - No renewals, ever [Get lifetime · 5 sites](/buy/5_ltd)Paddle secure payment · 30-day refund #### Ghost 25 · Lifetime Pay once, Protect 25 sites forever. The agency sweet spot. $ 799 $31.96 / site · lifetime - All premium features, forever - Protect up to 25 websites - Lifetime updates included - Priority email support [Get lifetime · 25 sites](/buy/25_ltd)Paddle secure payment · 30-day refund #### Ghost 1000 · Lifetime For large agencies. Pay once, protect everything. $ 1449 from $1.45 / site · lifetime - All premium features, forever - Protect up to 1000 websites - Lifetime updates included - Priority email support [Get lifetime · 1000 sites](/buy/unlimited_ltd)Paddle secure payment · 30-day refund #### 250K+ secured websites #### 4.8 / 5 avg. rating · G2 · Capterra #### 30-day money-back guarantee #### Paddle secure global checkout #### What's Included - Hide WordPress Common Paths - Hide WordPress Common Files - Protect WordPress Paths - Script Injection Attacks Protection - SQL Injection Attacks Protection - Activity Logs & Alerts - Brute Force Attack Protection - 7G & 8G Firewall Protection - Two Factor Authenticator (2FA) - Country Blocking (GEO Security) - Temporary Login Access - Cross-Site Scripting (XSS) Protection - XML-RPC Attacks Protection - One-click Security Fix - Login Page Designer ### Trusted by 250K+ WordPress Sites Worldwide Your website’s security is backed by proven results, excellent support, and thousands of happy users. ### Free vs Premium Compare WP Ghost Features Path & URL SecurityFreeProChange wp-admin path✔✔Change wp-login.php path✔✔Change plugin & theme directory paths✔✔Change wp-content, wp-includes, uploads paths✔✔Custom login/logout/register redirects by user role✔✔Hide plugin & theme names with random names✔✔Change paths in cache, sitemaps, RSS, robots.txt✔✔Change REST API wp-json path✔✔Change wp-content, wp-includes, uploads paths✔✔Ghost Mode - maximum security preset✘✔Hide common WP files (wp-config, readme, debug.log) ✘✔Manually customize individual plugin & theme names ✘✔Hide file extensions (PHP, CSS, JS, HTML, JSON…)✘✔ Firewall & IP ControlFreePro7G Firewall ✔✔8G Firewall✔✔SQL injection & script injection protection✔✔IP whitelist / blacklist✔✔Security headers (HSTS, CSP, X-Frame-Options, XSS)✔✔Block theme detector crawlers✔✔User agent, referrer & hostname blacklists✔✔Automate IP blocking (repeat offenders)✘✔Configurable automation rules ✘✔AI Crawler Blocking (30+ crawlers)✘✔Auto robots.txt Disallow rules for AI crawlers✘✔ 2FA, Passkeys & LoginFreeProBrute force protection on all forms✔✔Google reCAPTCHA v2, v3, Enterprise + Math CAPTCHA✔✔2FA by authenticator code✔✔2FA by email✔✔2FA by passkey (Face ID, Touch ID, Windows Hello)✔✔Magic Link passwordless login✔✔Temporary time-limited logins for collaborators✔✔Trust current browser (skip 2FA on trusted devices)✔✔ Security Monitoring & LogsFreeProSecurity Optimization Score (0–100)✔✔GEO Threats Map - top 5 attack countries✔✔Weekly domain security monitoring email✔✔Security Threats Log (last 20 entries)✔✔User Events Log (last 20 entries)✔✔Full Security Threats Log - unlimited history✘✔Full User Events Log - unlimited history✘✔Filter logs by type, status, country, time range✘✔Full-text search + pagination in logs✘✔Export logs to CSV✘✔Cloud storage for event logs (30-day retention)✘✔Real-time email alerts for suspicious activity✘✔ Database & Server HardeningFreeProSecurity Check - identify weak usernames, prefix, SALT, permissions✔✔Fix weak admin/administrator usernames✔✔Regenerate WordPress SALT keys✘✔Change database table prefix✘✔Fix file & directory permissions✘✔Fix WordPress & script debugging mode✘✔Disable plugin/theme editor✘✔ Geo SecurityFreeProGEO Threats Map on dashboard✔✔Top 5 threat countries with attack counts✔✔Country Blocking - block entire countries✘✔Path-based country blocking✘✔[Not ready yet? Try the Free version →](https://wordpress.org/plugins/hide-my-wp/) ### Real Reviews from Verified Customers “This one just works.** It’s relatively simple to set up**, and it has many security features. I decided to buy the Pro version and didn’t regret it. I highly recommend it.” Sinisa S. CEO · Internet ✓ [Verified review on Capterra ](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) “Before, we had to use reCaptcha to keep spammers away, but captchas are bad for site performance. With Hide My WP Ghost **we don’t have to worry about spammers anymore.”** David S. Director of Installation · Construction [✓ Verified review on Capterra ](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) “I really like HMWG as alternative to other WP security tools. I use it on several sites, without any probs. At my sites it doesn’t slow down my instances. A clear recommendation.” @planetomobiley WordPress user · Multiple sites ✓ [Verified review on WordPress.org](https://wordpress.org/support/topic/great-functoins-combined-in-1-tool-regularly-updated/) “Since I installed the plugin, it’s stopped all the brute force attacks on my site. I don’t have to worry about my account data or my customers’ info being hacked. If you want to keep your WordPress site safe, you need to get Hide My WP Ghost.” Adrian N. Owner · Marketing & Advertising ✓ [Verified review on Capterra ](https://www.capterra.com/p/240137/Hide-My-WP-Ghost/) ### WordPress ### G2 ### Capterra ### AppSumo ### Frequently Asked Questions About WP Ghost Pricing Do I pay once or every year?You choose. **Yearly plans** (Ghost 1, Ghost 5, Ghost All) renew automatically every 12 months and include continuous updates plus priority support. **Lifetime plans** (Ghost 5 LTD, Ghost 10 LTD, Ghost 1000 LTD) are a single one-time payment with lifetime updates – no renewals, ever. You can cancel a yearly plan anytime from your account without affecting your site’s current protection. How many websites can I use one license on?Each paid license is tied to a specific site count: **Ghost 1** covers 1 site, **Ghost 5** covers 5 sites, **Ghost 10** covers 10 sites, and **Ghost All** covers unlimited sites. A **WordPress Multisite network counts as 1 license** for the entire network, regardless of how many subsites it contains. The free Lite version has no site limit. Can I transfer my license to another website?Yes, unlimited times, with no fees or waiting period. Deactivate WP Ghost on the old domain, then activate it with the same license key on the new one. You can also manage all transfers manually from [WP Ghost Dashboard > Manage License](https://account.hidemywpghost.com). Ideal for agencies rotating clients or site migrations. Does WP Ghost offer a money-back guarantee?Yes, a **full 30-day money-back guarantee**, no questions asked. If the plugin doesn’t work on your site or doesn’t meet your expectations, request a full refund within 30 days of purchase and you’ll get your money back. Full details: [Refund Policy](https://hidemywpghost.com/refund-rules/). What payment methods do you accept?Payments are processed securely through **[Paddle](https://www.paddle.com/)**, which supports **45+ payment methods** worldwide: Visa, Mastercard, American Express, Discover, PayPal, Apple Pay, Google Pay, SEPA, iDEAL, and regional options depending on your country. All transactions are PCI-DSS compliant and VAT is handled automatically on your invoice. What's the difference between Free and Premium?The **free Lite version** covers: hiding wp-admin and wp-login paths, simple brute force protection, core security tweaks, 7G/8G Firewall, SQL injection & XSS protection, two-factor authentication (2FA with passkey and fingerprint support), temporary logins, and the last 20 entries of the security threats and user events logs. **Premium** adds: Country blocking (Geo Security), AI crawler bot blocking (GPTBot, ClaudeBot, PerplexityBot, and 30+ others), full Security Threats Log and User Events Log with CSV export, the Login Page Designer, and priority expert support. See the full Free vs Premium comparison. [Download ](https://wordpress.org/plugins/hide-my-wp/)Free Lite from WordPress.org What happens when my yearly license expires?Your WordPress site **stays fully protected, **the plugin keeps running with every feature you’ve configured. What you lose is access to plugin updates, compatibility patches (for new WordPress, PHP, or WooCommerce versions), new security features, and priority support. Renewing is recommended to stay covered against newly discovered threats and to keep the plugin compatible with future WordPress releases. #### LAST UPDATE 02 Sept 2026 Compatible WP 7.1.x & PHP 8.5 #### VIDEO TUTORIALS Youtube Channel #### KNOWLEDGE BASE Tutorials & FAQs --- # Page: WP Ghost Changelog - All Version Updates, Features, and Fixes URL: https://hidemywpghost.com/changelog/ Section: Changelog Last-Updated: 2026-09-04 Language: en-US Description: Complete changelog for WP Ghost (formerly Hide My WP Ghost). Track every update including new features, securit, bug fixes, and compatibility updates. ## WP Ghost Changelog – All Version Updates, Features, and Fixes MovedThis tutorial has moved to the new WP Ghost Knowledge Base where each feature is presented in detail. [View full changelog](https://wpghost.com/kb/changelog/)**Last plugin update: 03 Sep 2026** Stay informed about the latest updates and improvements to the WP Ghost plugin. This changelog provides a detailed record of all version releases, including new features, security enhancements, bug fixes, and performance optimizations. For the most up-to-date changelog, visit the [WP Ghost Knowledge Base](https://wpghost.com/kb/changelog/). = 9.1.00 (3 Sept 2026) = - Update – Security update: hardening for the way the plugin resolves and handles the current request - Update – Security update: the WooCommerce payment gateway exception is now limited to the real WooCommerce endpoints instead of any address that contains a gateway name - New – Images, fonts and media handled by the plugin are now streamed instead of being loaded in memory, so a large file no longer costs its full size in RAM on every request - New – Changed CSS and JS files are built once and kept on disk, instead of being rebuilt on every visit - New – The saved files are rebuilt on their own when a file or a plugin setting changes, so there is no cache to clear - New – The plugin answers browser and CDN revalidation with 304 Not Modified, without reading or rebuilding the file - New – Every file is sent with a Last-Modified date, so revalidation keeps working with cache plugins that strip ETags - Fix – CSS and JS are compressed only with what the browser actually accepts, instead of always answering compressed - Fix – Compressed responses now use gzip, which every browser and CDN reads the same way - Fix – Static files and the REST API path are now handled correctly when your site is reached on an alias domain - Fix – LiteSpeed: the QUIC.cloud addresses are loaded even when the plugin settings have not been saved since LiteSpeed was installed - Fix – Defender Security: the free edition of the plugin is now recognized, not only the Pro edition - Fix – Ghost Doctor no longer reports the CSS and JS files as not loading when Text Mapping in CSS and JS files is on and those files are served by WordPress on purpose - Fix – Ghost Doctor now checks the REST API path the way WordPress answers it, instead of reporting a working REST API as missing - Fix – Changing the REST API path takes effect on save, without having to open Settings > Permalinks and save again - Fix – No longer stops with a fatal error on servers where the getallheaders() function is missing = 9.0.14 (17 Aug 2026) = - Fix – Fix it now works for the Security Check tasks that change a plugin setting, such as Hide Old Paths, Hide Common Files, Hide wp-login and Disable XML-RPC - Fix – Fix it no longer answers with Ajax is not loading correctly. Clear all cache and try again. = 9.0.13 (04 Aug 2026) = - New – Developers can now redact or skip log entries before they are saved, using the new hmwp_log_row filter - New – Vulnerability scan: flags installed plugins and themes with published security issues - New – Ghost Doctor: finds what is breaking your paths and repairs it in one click - New – Ghost Doctor can switch to protection that needs no server rules when your server will not serve them - New – Security Check now opens with one prioritized list of what to fix first - New – AI explanations written for your own website, server and configuration - New – Undo restores your settings if a repair does not help - Fix – Security Check no longer reports wp-content, the login path or the admin path as visible on sites that are hiding them correctly - Fix – Ghost Doctor no longer reports a failure when Disable REST API Access is on - Fix – Open on a failing path check no longer leads to a 404 while the new paths are not working yet - Fix – Fix it now works for Security Keys, Table Prefix, wp-config constants and plugin updates - Fix – Security Check runs on its own the first time you open it - Fix – Last check now shows how long ago the scan ran, not a clock time - Fix – Change Paths shows one card after a path change instead of two - Fix – Security Tasks no longer shows an empty table when every task passed = 9.0.12 (20 July 2026) = - Security – Two-Factor Authentication settings are now bound to the account they belong to, so the 2FA method, authenticator, email codes, backup codes and passkeys can only be managed by the account owner or by an administrator allowed to edit that user - Security – Passkey enrollment is now always self-service, matching the device the passkey is created on - Security – Temporary Login updates and deletions now apply only to temporary accounts, so regular accounts are never affected from this screen - Security – The role assigned to a temporary login is now validated and can never grant more capabilities than the user creating it already has - Security – Magic Login links now require the same permissions as the screen they are offered from = 9.0.11 (16 July 2026) = - Fix – Editing a custom post type that uses the built-in Categories/Tags taxonomy no longer crashes the Block Editor - Fix – Block Editor no longer crashes with “Cannot read properties of undefined” when Hide User Enumeration is on; the users REST endpoint is now hidden from anonymous visitors only, so logged-in Editors and Authors can still edit posts and custom post types = 9.0.10 (13 July 2026) = - Fix – Cloud Activity Log entries are now sent in the background, so a slow logging server can no longer delay backend requests, including the Block Editor and other REST calls - Fix – Force 2FA Setup no longer redirects custom user roles that can’t access their profile to a setup screen they are unable to open - Fix – Settings page navigation menu no longer loses its layout on sites where another plugin or theme restricts the allowed HTML tags; the menu now keeps its own classes and attributes regardless of the site’s wp_kses filters = 9.0.09 (08 July 2026) = - New – Force 2FA Setup: require selected user roles to set up Two-Factor Authentication before they can access the dashboard, with a guided setup screen shown right after login - Fix – WP-CLI commands no longer emit a PHP 8.5 Undefined array key hostname warning = 9.0.08 (01 July 2026) = - Fix – Temporary Login page no longer triggers a fatal error when opened for a user that was deleted or expired - Fix – Two-Factor email setup and Magic Login no longer emit PHP warnings when the requested user no longer exists = 9.0.07 (29 June 2026) = - New – Frontend Check now also verifies the theme’s CSS and JS files load, catching a broken layout on pages that still return 200 - New – Detects when CSS/JS/font files load through WordPress instead of the server config, falls back to safe paths and warns you on the settings page - Improvement – Redesigned the Frontend Check results into clear, uniform rows that stay readable with long URLs = 9.0.06 (02 June 2026) = - Fix – Some sites could show a blank page when source code optimization was enabled; the header find & replace is now fail-safe and never blanks the output on a regex error - Fix – Prefetch/speculation rules cleanup now removes the wp-admin and wp-*.php entries without leaving the rules JSON invalid - Security – Fixed unauthenticated Open Redirect via the `redirect_to` parameter on the custom logout URL. = 9.0.05 (18 May 2026) = - Fix – WPML/Polylang with a custom or renamed REST API path: WPML Advanced Translation Editor and other REST API calls no longer fail with a network error in the admin - Fix – REST API requests made through the ?rest_route= form are no longer mistakenly treated as normal page requests and blocked - Fix – Renamed REST API path: legacy, cached and external clients still calling the default wp-json path are now recognized correctly instead of being 404’d - Fix – Compatibility module for WPML: the Advanced Translation Editor sync routes and requests are no longer rewritten with the active language prefix - Security – Hardened REST API detection: the firewall can no longer be bypassed by appending to the query string of another request - Security – Brute force protection also covers REST API Application Password authentication = 9.0.04 (14 May 2026) = - Fix – Compatibility with WPML and Polylang: static asset URLs (wp-content, wp-includes) no longer get the language prefix prepended (e.g. /en/wp-content/…) when “Change Relative URLs to Absolute URLs” is enabled - Fix – Password-protected pages (built-in WordPress post password) now submit correctly on Nginx and other servers without server-level rewrites when the login URL is customized - Fix – Refreshed knowledge base links across admin notices to point to the new documentation - Fix – Minor bugs and typos = 9.0.03 (06 April 2026) = - Fix – Fixed an issue where the Dark Mode popup remained white and some settings fields were too dark - Fix – Fixed Login Page Design to work in Disable mode - Fix – Fixed Firewall whitelist IPs and paths to work in disabled mode when the Firewall is activated - Fix – Fixed minor bugs and typos = 9.0.02 (01 April 2026) = - New – Translation in Indonesian (id_ID) language - New – Translation in Turkish (tr_TR) language - Update – Translations updated in all 16 supported languages: Arabic, Brazilian Portuguese, Chinese (Simplified), Dutch, Finnish, French, German, Italian, Japanese, Portuguese, Romanian, Russian, Spanish, and English (default) - Fix – Friendly time display (e.g. “3 hours ago”) now renders correctly in all translated languages - Fix – Dropdown and Help icon in the RTL languages = 9.0.01 (30 March 2026) = - Fix – Resolved robots.txt warning when user agents are blocked - New – Country filter in Security Threats Log and User Events Log - New – Click on a country circle in the GeoMap to open Security Threats Log filtered by that country for the last 7 days - Update – Moved Export CSV button to below the table in Security Threats Log and User Events Log to avoid accidental clicks - Update – Added proper color handling for dark mode (browser-based) - Update – Enhanced security progress indicator and introduced Security Optimization Score - Update – Add a loading process on login submit - Fix – GeoMap country circle counts now match Security Threats Log counts for the same 7-day window - Fix – Security Threats counting for the last 7 days on widget now matches the log totals (timezone-aligned day buckets) - Fix – Passkey login spinner not showing due to missing classList calls - Fix – Country codes missing from threats log rows now resolved on-the-fly from GeoIP when cron is not running = 9.0.00 (26 March 2026) = - New – Customize the login page with custom logo (with live preview), logo link URL, and color scheme (page, form, button, text, link colors) with one-click presets - New – Block AI Crawler Bots at firewall level with automatic robots.txt Disallow rules (GPTBot, ClaudeBot, PerplexityBot, Bytespider, and 30+ others) - New – GEO Map with top 5 threat countries visualization on the Overview dashboard - New – Export Security Threats Log and User Events Log to CSV - New – Security Check task to verify IP block automation is configured correctly - New – Threats count in the Overview widget now shows the full 7-day period totals - New – Notification in the Overview widget to activate 7G/8G Firewall when unblocked threats are detected - Update – Store country code in the threats log table for faster country stats - Update – Missing country codes resolved in background via cron without slowing down threat logging = 8.3.07 (16 March 2026) = - Fix – Sorting and filtering in the Events Log & Security Threats Log - Fix – Rules and Threats filters to work with WP Multisite subpaths structure - Fix – Temporary login user edit link on WP Multisite - Fix – Compatibility with WooCommerce 10.6 - Fix – Compatibility with the Blocksy theme - Fix – Optimize the plugin speed = 8.3.06 (09 March 2026) = - Update – JS requirements for WordPress 6.9.2 - Fix – Security Log and Events Log not recording properly - Fix – Optimize user logged in verification - Fix – Don’t show the 2FA and Magic Login form when the Safe URL parameter is set - Fix – Prevent logging out when the paths are changed - Fix – Sending the code too often on 2FA Email verification. The code can be resent only every 30 seconds - Fix – Remove unused JS, CSS and fonts = 8.3.05 (05 March 2026) = - Update – JS requirements for WordPress 6.9.2 - Fix – Security Log and Events Log not recording properly - Fix – Optimize user logged in verification - Fix – Sending the code too often on 2FA Email verification. The code can be resent only every 30 seconds - Fix – Remove unused JS, CSS and fonts = 8.3.04 (02 March 2026) = - Update – Remove the option to send the new paths by email as they are already on WP Ghost Dashboard - Update – Send the Brute Force, 2FA and Magic Login texts to the multilingual plugins like WPML and Polylang - Update – Add the Magic Login options to Change Paths > Login Security section - Update – Compatibility with PHP 8.5 - Fix – Small bugs and typos = 8.3.03 (25 Feb 2026) = - New – Added Automation on IP address blocking in the Firewall - Update – Added compatibility with Photo Gallery from 10Web - Update – Translations in all 14 languages - Update – Moved 2FA and Magic Login feature in WP Ghost core - Update – UI for Security Threats Log and Events Log - Update – Plugin core security according to the latest WordPress security recommendations - Fix – Firewall rules to work with the new WordPress 6.9.2 update = 8.3.02 (20 Feb 2026) = - New – Added Automation on IP address blocking in the Firewall - Update – Added compatibility with Photo Gallery from 10Web - Update – Translations in all 14 languages - Fix – Firewall rules to work with the new WordPress 6.9.2 update = 8.3.01 (10 Feb 2026) = - Fix – Fatal error on log table creation when the plugin is activated - Fix – Safe URL parameter on login form to prevent 2FA from showing when is activated = 8.3.00 (07 Feb 2026) = - New – Security Threats Log added to track blocked attacks and malicious requests - Change – Events Log renamed to Logs, now split into User Events and Security Threats - Update – Expanded 7G / 8G Firewall rules to block advanced brute-force attempts, SQL injection, XSS payloads, file inclusion, directory traversal, and automated vulnerability scans before reaching WordPress - Update – Improved threat detection to stop malicious requests before execution = 8.2.10 (11 Apr 2025) = - Update – Compatibility with WordPress version 6.8 - Fix – File security when the rewrite rules are not loaded correctly - Fix – Prevent Brute Force from updating the warning text without space when switched off - Fix – Prevent PHP warning when IP address unknown in Brute Force IP check - Fix – Load i18n on the login page for password-strength-meter messages when the Clean Login option is activated - Fix – Detect if parent theme has caps when child theme is activated - Fix – Dynamic file mapping to load through index.php for better compatibility with all server types = 8.2.04 (07 Mar 2025) = - Update – Add the option to customize all active and inactive themes - Fix – Brute Force error in comments when no recaptcha option is selected - Fix – WP Multisite root directory for custom WP directory installation = 8.2.03 (04 Mar 2025) = - Update – Security update on wp-activate.php path call - Fix – Headers check on Brute Force to get the real IP behind Proxy - Fix – Admin layout issue when other plugins notification is loading in WP Ghost settings - Fix – Remove newlines from the rewrite rules = 8.2.01 (26 Feb 2025) = - Update – Add Google reCaptcha Enterprise - Update – Increase security on Brute Force feature - Update – Compatibility with Sucuri plugin on Events Log and Brute Force - Update – Add the HMWP_CONFIG_DIR constant to define the config root path - Update – Translations files for the last text changed - Fix – Get the real IP address behind proxy - Fix – Brute Force compatibility with Advanced Pack Magic Login and small bugs - Fix – Include parent theme in the custom theme name list if the child theme is loaded = 8.1.04 (06 Feb 2025) = - Update – New WP Ghost Dashboard design - Update – Login Attempt and Blocked IPs chart in WP Ghost Dashboard - Update – Email Alerts log report in WP Ghost Dashboard - Fix – Paths changed in dynamically loaded CSS and JS files - Fix – Prevent redirecting URLs to hidden paths on config rules issue - Fix – Prevent hiding the wp-admin on config rules issue - Fix – Prevent changing the wp-admin on config rules issue = 8.1.03 (22 Jan 2025) = - Update – Knowledge Base links and responsive layout - Update – GeoIP Country database for Geo-Blocking - Fix – Config update issue when saving the whitelist from Level Of Security For versions 8.1.02 and earlier, see the [complete changelog on the WP Ghost Knowledge Base](https://wpghost.com/kb/changelog/). #### Previous [Hide WordPress Website From Wappalyzer ](https://hidemywpghost.com/hide-wordpress-from-wappalyzer/) #### Next [Fix Frontend Theme Not Loading After Activating WP Ghost ](https://hidemywpghost.com/frontend-is-not-loading-in-hide-my-wp-ninja-mode/) --- # Page: Hide My WP Ghost 9.1 - WordPress Security Solution URL: https://hidemywpghost.com/ Section: Home Last-Updated: 2026-09-04 Language: en-US Description: Hide My WP Ghost protects 250,000+ WordPress sites from hackers. Hide your WordPress, block brute force, prevent SQL injection. Rated 4.8★. WordPress Security Solution ## Stop the Hack Before It Starts ### Hide My WP Ghost 9.1 + 8G Firewall [ Start Protecting Your Site](/hide-my-wp-pricing/)[See All 150+ Features](/hide-my-wp-ghost-security-features/) ### WordPress ### G2 ### Capterra ### AppSumo #### 100M+ monthly threats prevented #### 250k+ secured websites #### 10M+ monthly brute force stopped ### Take preventive measures before it's too late #### Stop hackers from accessing sensitive information Prevent unauthorized access to your database, user data, and admin panels. #### Prevent crashing or slowing your website Block malicious bots and brute force attacks that consume server resources. #### Protect your customers' data Ensure your visitors’ personal and financial data stays safe at all times. ### How Can Hide My WP Ghost Help You Secure Your Website **Hide My WP Ghost (now WP Ghost) **is a trusted security plugin that helps you prevent common hacker bots attacks on your WordPress site. The plugin adds filters and security layers to prevent Script and SQL Injection, Brute Force attacks, XML-RPC attacks, and more. #### Protect Your wp-admin Area Block unauthorized access to your WordPress admin area with custom login URLs. #### Change and Hide Common Paths Hide WP paths, plugins, and themes from hacker bots and vulnerability scanners. #### Brute Force Protection Prevent repetitive login attempts with intelligent rate limiting and lockouts. #### SQL Injection Protection Add filters and security layers to prevent SQL injection and script attacks. #### XML-RPC Protection Disable XML-RPC feature and block access to prevent brute force via xmlrpc.php. #### XSS Protection Security headers protect against Cross-Site Scripting and other injection attacks. #### URL & Text Mapping Remap any revealing URLs in source code to completely mask your WordPress setup. #### Security Check Run 35+ security tasks to detect potential breaches and get actionable fixes. #### Users' Activity Log Track every important action on your site for complete security visibility. #### Two Factor Authenticator Add 2FA to discourage unauthorized access with double authentication. #### 7G & 8G Firewall Enterprise-grade firewall by Jeff Starr that blocks threats without hurting performance. #### Temporary Logins Create time-limited admin accounts for contractors and support teams. ### Built for Performance & Simplicity #### Easy To Use Install and set up in less than 5 minutes. #### Faster Than Others Average loading time of 0.05s. #### WordPress Multisite Sub-directories & sub-domains. #### Dedicated Support Professional help when you need it. #### All Hosting Servers GoDaddy, SiteGround, WP Engine & more. ### Works with popular WordPress Security Plugins ### Trusted by 250k+ WordPress Sites Worldwide “Great plugin, exactly what I was looking for. WORKS AS DESCRIBED! This plugin will allow you to create a custom login URL and redirect wp-admin to any page you specify.” ### @joelpl “Second year using and loving – webs are fully protected and secure. Support is amazing, kind, efficient, quick response. Very happy with this plugin, totally recommend.” ### @paivaru “I have used this plugin for several months now and it works very well without any problem. It’s easy to set up compared to other security plugins.” ### @lov4affiliate “Really impressed by the personalized support I got when implementing the plugin. Really useful to add a protection layer against hackers.” ### @noxinhh “A good app to hide your WP details, links and other footprints. It might help your site look like it’s not on WP and prevent certain attacks too.” ### @prohealthware ### Compatible With All Major Hosts - Bitnami - GoDaddy - Hostgator - Inmotion - WP Engine - SiteGround - Bluehost - Dreamhost - Hostinger - Google Cloud - DigitalOcean - FlyWheel - CloudPanel - Fastcomet - and more... #### 11,334 11,334 WordPress vulnerabilities discovered in 2025, a 42% year-over-year increase. Source: Patchstack State of WordPress Security 2026 #### 88% 88% of cyberattacks on small businesses involve ransomware. If you run a WordPress site for your business, you're the target.". Source: Verizon 2025 Data Breach Investigations Report #### 95.5% 95.5% of hacked CMS websites are WordPress. Popularity makes you a target.Source: Sucuri 2023 Hacked Website Report [ Start Protecting Your Website](/hide-my-wp-pricing/) --- # Page: WordPress Firewall: Cost, Setup & What It Does (2026) URL: https://hidemywpghost.com/wordpress-firewall/ Section: Pages Last-Updated: 2026-08-30 Language: en-US Description: A WordPress firewall blocks SQL injection, XSS, and bad bots before they reach your site. See what it does, what it should cost, and how to set one up. ## WordPress Firewall: What It Does, What It Should Cost, and How to Set One Up Open your server logs for sixty seconds and watch what’s already happening. Thousands of requests hammering `wp-login.php` with password guesses. Bots probing `/?author=1` to harvest usernames. Strings full of `UNION SELECT` and `` aimed at any form they can find. Your site is still up — but it’s being _tried_, constantly, by automated traffic that never sleeps and never gets bored. A WordPress firewall is the wall that turns those requests away before they reach WordPress at all. Not a scanner that tells you after the fact that something got in — a filter that sits in front of your site and refuses the bad request in the first place. This guide explains, in plain terms, what that firewall actually does, the three types you’ll be choosing between, what a fair price looks like in 2026, and how to switch one on this afternoon. WordPress runs [around 43% of all websites](https://w3techs.com/technologies/details/cm-wordpress), which is exactly why it’s the internet’s favorite target for mass, automated attacks. A firewall is the single highest-leverage layer you can add against them. ### What Is a WordPress Firewall (and What It Actually Does) **A WordPress firewall is a Web Application Firewall (WAF) that inspects every incoming request and blocks the malicious ones — SQL injection, cross-site scripting, brute-force logins, and bad bots — before they ever reach your WordPress site.** A firewall — specifically a Web Application Firewall, or WAF — inspects every incoming request and decides whether to let it through, challenge it, or block it, based on what the request is trying to do. A malware scanner looks _inside_ your site for damage that already happened. A firewall stops the request that would cause the damage. You want both, but the firewall is the one that prevents the incident rather than reporting it. A good WordPress firewall blocks the attack patterns that make up the overwhelming majority of real-world hits: - **SQL injection** — malicious database queries smuggled through forms and URLs. - **Cross-site scripting (XSS)** — injected scripts that hijack sessions or deface pages. XSS is consistently the single most-reported WordPress vulnerability class year after year. - **File inclusion and directory traversal** — attempts to load or read files they shouldn’t. - **Brute-force login attempts** — the endless password guessing against your admin. - **Bad bots and scrapers** — automated traffic probing for known weak spots. The point is coverage _before_ contact. Every request that the firewall refuses is one that never reaches your plugins, your theme, or your database. ### The Three Types of WordPress Firewall (and Which You Actually Need) “Firewall” gets used for three different things. Knowing which is which saves you from paying for the wrong one. #### Application firewall (plugin-level) Runs at the level of your WordPress site — usually via a plugin — and understands WordPress-specific attacks: login abuse, plugin exploits, `xmlrpc` floods, path probing. It’s the cheapest and fastest to deploy, needs no DNS changes, and protects the application layer where most WordPress attacks actually land. For the large majority of sites, this is the layer that matters most. #### Cloud / managed WAF Sits in front of your site as a proxy, filtering traffic before it ever reaches your host. Its strength is scale — it can absorb large DDoS floods and filter enormous request volumes. Its costs are also higher, it adds a network hop, and it requires routing your DNS through the provider. Worth it for high-traffic or high-risk sites; overkill for a typical business site or blog. #### Host / network firewall The firewall your hosting company runs at the server or network level. It handles crude network-layer threats but generally has no idea what a WordPress login-brute-force or an `xmlrpc` amplification attack looks like. Useful, but not a substitute for application-layer protection — which is the objection we’ll come back to below. For most WordPress owners the honest answer is: a solid **application firewall** is the essential layer, a cloud WAF is an optional upgrade for scale, and the host firewall is a baseline you already have and shouldn’t rely on alone. ### What a WordPress Firewall Should Cost in 2026 (Price Ranges) Here’s the money question, because it’s the one you’re actually searching. Firewall pricing is all over the map, and a lot of that spread is margin, not protection. Current market ranges look like this: - **Free plugin firewalls:** $0, but with real limits — the most common one is that new firewall rules and malware signatures are [delayed around 30 days](https://wafplanet.com/blog/waf-pricing-comparison-2026/) behind the paid feed, precisely the window when a fresh exploit is most dangerous. - **Premium plugin firewalls (annual):** roughly **$119/year** at entry level, **~$490/year** mid-tier with hands-on monitoring, and **~$950/year** for premium incident-response plans, per [2026 WAF pricing data](https://wafplanet.com/blog/waf-pricing-comparison-2026/). - **Cloud / managed WAF (monthly):** from about **$10–20/month** for low-traffic sites, **$115–200/month** at medium traffic, and **$400+/month** for enterprise — and note that bot management, API protection, and DDoS mitigation are frequently billed as separate add-ons on top. Now put that next to what a typical site needs. You are not a bank. You need current application-layer rules, brute-force protection, bad-bot filtering, and sane defaults — not a four-figure annual subscription or a per-traffic cloud bill. That gap is the whole argument for a bundled hardening-plus-firewall plugin. [Hide My WP Ghost pricing](https://hidemywpghost.com/hide-my-wp-pricing/) starts at **$23.99/year for a single site** and **$52.50/year for five**, and that includes the 7G and 8G firewall, brute-force blocking, country blocking, security headers, and two-factor authentication — features that live in the “premium subscription” tier almost everywhere else. It sits at the very bottom of the premium price range while covering the protections most sites will ever use. Compare the [full feature list](https://hidemywpghost.com/features/) against whatever your current security solution charges annually; the delta is usually the point. The honest caveat: cheaper isn’t automatically better, and no firewall replaces updates, strong passwords, and backups. But paying enterprise WAF prices for a small-business site is a common, avoidable mistake — you’re buying scale you’ll never use. ### How to Set Up a WordPress Firewall in 6 Steps You can have application-layer protection live in a few minutes. The steps below map to Hide My WP Ghost, but the sequence is the same for any capable firewall. - **Choose a firewall level.** Start with the **8G Firewall** (the current ruleset, built for modern attack patterns) rather than an older or minimal level. If a rule ever conflicts with a plugin, step down to 7G and re-test. See [the 8G firewall protection](https://hidemywpghost.com/the-new-8g-firewall-protection-is-here/) for what changed from the [7G firewall for WordPress](https://hidemywpghost.com/7g-firewall-for-wordpress/). - **Turn on automatic IP blocking.** Let the firewall ban IPs that trigger repeated attacks automatically, so brute-force sources take themselves out instead of needing your attention. - **Add security headers and strip server info.** Enable the security-headers set (HSTS, Content-Security-Policy, X-Frame-Options and the rest) and remove the headers that leak your PHP and server versions — both tighten the surface an attacker sees. - **Block bad bots and detector crawlers.** Filter aggressive scrapers, AI crawler bots, and the technology detectors (Wappalyzer, BuiltWith, WhatCMS) that fingerprint your stack — this ties your firewall into the same work as [hiding WordPress from detectors](https://hidemywpghost.com/hide-wordpress-from-detectors/). - **Restrict by geography if it fits.** If you never sell to certain regions, use [country blocking](https://hidemywpghost.com/geo-security-country-blocking/) to drop traffic from them — a blunt but effective way to cut attack volume. - **Verify it’s working.** Run a [website security check](https://hidemywpghost.com/website-security-check/) to confirm the rules are active, then watch your logs for a day. You should see blocked requests climbing and the noise against `wp-login.php` dropping. Pair the firewall with the basics that reduce the attacks it has to handle: [brute-force protection](https://hidemywpghost.com/brute-force-protection/) and [changing your wp-admin URL](https://hidemywpghost.com/change-wp-admin-urls/) so the login bots have nothing to hammer in the first place. ### What to Look For in a WordPress Firewall If you’re comparing options, judge them on protection and honesty, not on how loud the marketing is. A firewall worth paying for should give you: - **Current application-layer rules** covering SQL injection, XSS, file inclusion, and directory traversal — updated without a month-long delay. - **Brute-force and login protection**, ideally with automatic IP banning. - **Bad-bot and fingerprint-crawler blocking**, so scanners can’t map your stack. - **Geo and IP controls** for cutting attack volume you’ll never do business with. - **Security headers** applied for you, not left as a manual chore. - **Low performance overhead** — protection shouldn’t cost you page speed. - **Transparent, flat pricing** — a predictable annual number, not a bill that climbs with your traffic or hides core protection behind add-ons. ### “My Host Already Has a Firewall — Isn’t That Enough?” This is the most common reason people skip application-layer protection, and it’s a costly misread. Your host’s firewall works at the network level: it’s good at crude things like blocking known-bad IP ranges and absorbing some traffic floods. It has essentially no understanding of WordPress. It doesn’t know that fifty POSTs to `wp-login.php` in a minute is a brute-force attack, that a request to `xmlrpc.php` is an amplification attempt, or that a query string carrying `UNION SELECT` is SQL injection aimed at your database. Those are application-layer attacks, and they’re where WordPress actually gets breached. A network firewall and a WordPress-aware application firewall solve different problems. Having the first is not a reason to skip the second — it’s the reason you still need it. #### Will a firewall slow my site down? A well-built application firewall adds negligible overhead — it inspects request patterns, which is cheap, and it often _improves_ real-world performance by dropping bad-bot traffic that was consuming your server’s resources. If a firewall noticeably slows your site, that’s a sign of a poorly optimized ruleset, not a law of nature. Test your page speed before and after; on most sites the difference is invisible to visitors and the bot noise on your server drops sharply. ### The Bottom Line Those thousands of attempts in your logs aren’t going to stop — automated attacks are the background radiation of running WordPress. What you control is whether they reach your site or hit a wall. An application firewall is that wall, it’s the highest-leverage security layer you can add, and it does not require an enterprise budget: the protection most sites need runs a couple of dollars a month, not a couple hundred. Turn it on, verify it’s blocking, and move the attacks from “constant risk” to “someone else’s problem.” Start with the [firewall and security features](https://hidemywpghost.com/features/) and [pick a plan](https://hidemywpghost.com/hide-my-wp-pricing/) that fits the number of sites you run. ### Frequently Asked Questions **Do I need a firewall if I already have a security plugin?** Check what your current security solution actually does. Many popular plugins lead with malware _scanning_ — which reports damage after it happens — while real-time firewall rules sit behind a higher-tier subscription. If your protection is scan-and-alert rather than filter-and-block, you have a gap a firewall fills. The two jobs are complementary, not redundant. **Is a free WordPress firewall good enough?** For a low-stakes personal site, a free firewall is far better than none. The catch on most free tiers is a delay — new firewall rules and malware signatures arrive around 30 days after paid users get them, and that lag is exactly when a freshly disclosed exploit is being mass-exploited. If your site handles customers, payments, or leads, the modest annual cost of current rules is cheap insurance. **Application firewall or cloud WAF — which do I need?** For most sites, an application (plugin-level) firewall is the essential layer: it understands WordPress-specific attacks, deploys in minutes, and needs no DNS changes. A cloud WAF is an upgrade for high-traffic or high-risk sites that need to absorb large DDoS floods, and it costs more and adds a network hop. Start with the application firewall; add a cloud WAF only if your scale genuinely demands it. **Will a firewall block my real visitors or hurt SEO?** A properly configured firewall targets malicious _request patterns_, not ordinary browsing, so real visitors pass through untouched and search crawlers are allowed by default. The risk comes from over-aggressive custom rules or geo-blocking a region you actually serve — which is why you verify with a security check and review your logs after switching it on. **How much should I pay for a WordPress firewall?** For a typical site, a bundled hardening-and-firewall plugin in the range of roughly $24–53 per year covers the protection you’ll actually use. Premium standalone plugins run about $119–950/year and cloud WAFs $10–400+/month — figures that make sense at high traffic or high risk, but are more than most small and mid-size sites need. #### Previous [How to Protect Your WordPress Site Right Now ](https://hidemywpghost.com/protect-wordpress-from-wp2shell-cve-2026-63030/) --- # Page: Contact - Hide My WP Ghost URL: https://hidemywpghost.com/contact/ Section: Contact Last-Updated: 2026-08-16 Language: en-US Description: Premium Support (click here) If you have the Hide My WP Ghost plugin installed on your website and have an account with us. - [Premium Support (click here) ](https://account.hidemywpghost.com/user/auth/contact)If you have the Hide My WP Ghost plugin installed on your website and have an account with us. #### Why Buy from Us? – Because **we care & love creating awesome, highly-effective and easy to use security plugins** for you guys and gals. – We **frequently release updates & new features** based on feedback we receive from users (yes, we do take feature requests). – **We developed this plugin together with the Squirrly Company**. Marketing, Design and Support for Hide My WP is done by Squirrly. As well as features and [Roadmap](https://squirrly.feedbear.com/boards/hidemywp-ghost-by-squirrly). – Hide My WP Ghost is Brought to you by the [Squirrly Company](https://www.squirrly.co/more/): **A Proven, Profitable and Award-Winning Company**. – Rock solid commitment to delivering** high-quality customer support**. – We believe that** security is the most important thing for open-source CMSs**. Setup shouldn’t take longer than a couple of minutes. Just in case though, you can quickly find videos and super easy to follow written tutorials here: [https://hidemywpghost.com/knowledge-base/](https://hidemywpghost.com/knowledge-base/) --- # Page: How to Change the WordPress Admin URL (wp-admin) WP Ghost URL: https://hidemywpghost.com/change-wp-admin-urls/ Section: Pages Last-Updated: 2026-08-07 Language: en-US Description: Change your WordPress wp-admin URL in under two minutes. The free plugin method, the manual alternative, and how to avoid locking yourself out. ## How to change your WordPress admin URL To change your WordPress admin URL, install WP Ghost, open Change Paths → Admin Security, and replace /wp-admin/ with a custom path such as /my-office/. The setting is available on the free plan and takes under two minutes. WP Ghost applies the change through a redirect rather than by renaming files, so a WordPress core update will not undo it and your theme and plugins keep working. You can also change the path manually by editing server rules, but that method breaks on most WordPress updates and is the usual cause of lockouts. ### What is the wp-admin login URL? The WordPress admin page URL (or ‘login URL’)** is the web address you visit when you want to access the backend of your website.** If you are looking to do some administrative tasks on your website, it is easily possible to do so via: **https://www.your-domain.com/wp-admin.** So, this represents an entry point to your site. Unfortunately, hackers also know this and often use the /wp-admin path as an attack point where they deploy hacking attempts via brute force methods. ### How secure is WordPress admin? Brute force attacks are a common type of hacking attempts which mainly consists of repeatedly guessing username and password combinations until the right login credentials are obtained. There are various methodologies which hackers use, but more often than not,** attackers get into websites and accounts the same way anyone else does – by somehow obtaining access to the login credentials of an account on your site**. ### Why is it important to secure your wp-admin? There are many different reasons why hackers may choose to target your WordPress site. We’ve listed some **common examples **of potential reasons to give you a better idea as to why your site may be targeted: - Inject Malicious Content - Steal Money - Steal Visitors’ Personal Information - Spread Viruses - Steal Private Business Information - Use Your Web Server to Host Phishing Pages - Steal Your Server Bandwidth - Overload Your Web Server - Vandalize Your Website - For Fun or to Get Attention - Disrupt Service The moment hackers realize that your site is a WordPress site, they will **automatically know your WP-Admin path.** It is also common knowledge that **WordPress creates an “admin” username by default**. Armed with this knowledge, a hacker has ⅔ of everything required for login. **All they have to do now is guess your password. ** Hackers do not know if you have a more complex username and password combination. So, they may continue trying their luck for long periods of time. **This process puts a strain on your server resources and places your site at risk of being shut down.** ** ** ### how do you change the wp-admin path? #### using the Hide My WP Ghost Plugin **Security tip! **Do not use words like: _login_, _logon_, _admin_ or _backend_ for the login URL. **If you use Hide my WP Ghost for protecting your website, you can hide the login page and the wp-admin page and change them. Simply follow these steps:** - Log in to your Hide My WP Ghost Dashboard. - Go to Hide My WP > Change Paths >Admin Security. - **Change** the “Custom **Admin Path**” from /**wp-admin/** to newadmin (just an example, you can **change** it to whatever you want). - Click to **save **the new settings and follow the re-login instructions. - This key setting is available even on the free plan! **Important! ** The path will not be physically changed on your server. You will be redirected to the new admin path every time you log in to /wp-admin. **There is a simple yet effective manual process** that allows you to change your /wp-admin URL, and it can help keep potential attackers at bay. This manual process is different based on server type. Unique URLs are much more difficult to guess and are, therefore, less likely to be targeted. However, this manual process may not be the best strategy. You can choose to change the /wp-admin manually, but there are certain risks associated with this: - **Every time you update WordPress, it will re-create the login page file.** This means you’ll need to change the URL all over again. - Manually changing your login page URL **c****an create errors with your logout screen**, and cause other issues related to important site functionality. - **It can also affect website functionality, **as many plugins and themes don’t work if your physical paths are changed. [Try it NOW](/hide-my-wp-pricing/) ### What Can You Do to Tighten Security & how can Hide My WP Ghost help you? If you look at a page’s source code, you can see things like: /wp-content/themes/style.css, /wp-content/plugins/, /wp-content/themes/, /wp-admin/wp-install.php, /wp-content/upload/, /xml-rpc.php etc. **All these URLs are vulnerable to hackers and hiding them is important as well.** Hackers don’t just access the /wp-admin and /wp-login.php paths to hack your website. All the vulnerable paths, including the ones from the installed plugins, can provide a way in for hackers, allowing them to infect your entire website with viruses. Hide My WordPress Ghost is an easy-to-use product designed to provide you with the **best protection against hackers**. When you start using this plugin, you will be able to **hide the fact that you are using WordPress on your site**. Being able to** disguise the common paths** is critical, as you get to keep intruders away from sensitive website data. This is crucial, and it will provide you really good results in the long term. It will surely be worth it, not to mention that **hiding the common paths** will make hacking a lot harder as well. ### The Hide My WP Ghost Plugin helps you hide & change all common paths ​ **Important! ** The paths will not be physically changed on your server. You will be redirected to the new path you’ve created. ### Start Protecting Your WP Website Today With the Most USER-FRIENDLY WordPress Security Plugin [ Get Hide My WP Ghost Now](/hide-my-wp-pricing/)Don’t let hackers know that you are using WordPress. ### Hide My WP Ghost > More Benefits #### Identify Failed Login Attempts Most sites get hacked due to **entirely preventable issues**. Hide My WP Ghost offers a **complete security workflow for any WordPress website owner.** ### Love what you see? [Click to see all features](/hide-my-wp-ghost-security-features/)[Get Hide My WP Ghost Today](/hide-my-wp-pricing/)