- Home
- Features
Everything your store needs.
Nothing it doesn't.
Six features, each one aimed at a specific way WooCommerce stores actually get hurt. No 40-tab settings screen, no rule tuning, no false positives blocking your own customers.
Dynamic IP whitelisting
Your admin URL stops responding to everyone who isn't on your team. No static IP needed.
Passwordless authentication
One-click login. Nothing to phish, reuse, leak or brute force.
User activity logs
Every login, order edit, price change and refund — attributed and timestamped.
Real-time threat detection
See the attacks as they hit — and confirm they went nowhere.
Team management
Grant and revoke access to staff, freelancers and agencies in one click.
Error monitoring
Know about a broken checkout before your customers tell you.
Make wp-admin disappear
Every WordPress store on the internet shares one weakness: a login page anybody can load. WooSecure closes it. Your admin and login URLs return nothing to unrecognised visitors — they can't guess a password on a page that doesn't answer.
- No static IP required. Home broadband, mobile data, hotel Wi-Fi — your access follows you, not your IP address.
- No
.htaccessediting. Nothing to break on your next host migration or plugin update. - Storefront untouched. Customers browse, add to cart and check out exactly as before.
- Instant revocation. Remove a device or a person and the door closes the same second.
Remove the thing that keeps getting stolen
Most store compromises don't start with clever code. They start with a password that was reused on a forum that got breached in 2019. WooSecure removes the password from the equation entirely — one click and you're in your dashboard.
- Nothing to phish. There's no credential for a fake login page to capture.
- Nothing to brute force. Bots can hammer forever and never arrive at an answer.
- No reset tickets. Your VA never messages you at 11pm asking for the WordPress password again.
- Recovery built in. Backup codes at setup, plus owner-level restore for any team member.
mystore.com · Store manager
No password field. There is no password.
Answer “who did this?” in ten seconds
A price drops to $8.90. A coupon appears with 90% off. An order gets refunded twice. Without a log, you're reconstructing the story from memory and Slack messages. With one, you know who, what and when — immediately.
- Commerce-aware events. Order status changes, refunds, price edits, coupon creation, stock adjustments.
- WordPress events too. Logins, role changes, plugin activation, theme edits, settings updates.
- Attributed to a person. Not “admin” — the actual human, with their device and location.
- Searchable history. Filter by user, date or event type when you need to prove what happened.
Watch the attacks arrive and go nowhere
Credential stuffing, vulnerability scanners, XML-RPC amplification, bots enumerating your usernames — it's happening to your store right now. WooSecure identifies it live and shows you exactly what was stopped.
- Known-bad IP intelligence shared across every store on the platform.
- Behavioural signals catch the scanners that rotate addresses to stay under rate limits.
- Zero customer impact — detection happens at the admin layer, never in the shopping funnel.
- Weekly digest so you can see the volume you never have to think about.
Give access. Take it back. Keep the record.
Stores grow by adding people: a VA for order processing, a freelancer for a theme fix, an agency for a replatform. Each one is a key to your business. WooSecure makes handing out and taking back those keys a ten-second job.
- Invite by email — no shared logins, no passwords in Slack, ever.
- Per-site access so a contractor on one store can't see the others.
- Instant revoke that doesn't require rotating credentials afterwards.
- Unlimited seats, unlimited sites. We don't charge you for good hygiene.
A broken checkout is silent. Until the refunds.
A plugin update throws a fatal error on the payment step. Your storefront still looks perfect. Orders just stop. Most owners find out hours later from a customer email — WooSecure tells you in minutes.
- Fatal error alerts the moment PHP breaks, with the file and the plugin that caused it.
- Gateway failure signals when webhooks stop arriving or start timing out.
- Correlated with changes — see which plugin update immediately preceded the failure.
- Email and panel alerts so it reaches you whether or not you're at your desk.
Every feature. Every store.
$99 a year.
We don't gate security behind a tier, and we don't charge per site. Whether you run one store or fifty, you get all six layers for the same price.