Platform & features WooCommerce security Solutions Pricing Customers Partner Contact
  1. Home
  2. Features
Platform

Everything your store needs.
Nothing it doesn't.

Six features, each one aimed at a specific way WooCommerce stores actually get hurt. No 40-tab settings screen, no rule tuning, no false positives blocking your own customers.

Live in 3 minutesNo credit cardAll of it for $99 a year
01 — Dynamic IP whitelisting

Make wp-admin disappear

Every WordPress store on the internet shares one weakness: a login page anybody can load. WooSecure closes it. Your admin and login URLs return nothing to unrecognised visitors — they can't guess a password on a page that doesn't answer.

  • No static IP required. Home broadband, mobile data, hotel Wi-Fi — your access follows you, not your IP address.
  • No .htaccess editing. Nothing to break on your next host migration or plugin update.
  • Storefront untouched. Customers browse, add to cart and check out exactly as before.
  • Instant revocation. Remove a device or a person and the door closes the same second.
access gateway
Admin requests live
You · Berlin/wp-adminOpened
45.155.204.9/wp-login.phpNo response
104.28.9.12/wp-admin/admin-ajax.phpNo response
Dev · Lisbon/wp-admin/plugins.phpOpened
193.32.162.7/xmlrpc.phpNo response
02 — Passwordless authentication

Remove the thing that keeps getting stolen

Most store compromises don't start with clever code. They start with a password that was reused on a forum that got breached in 2019. WooSecure removes the password from the equation entirely — one click and you're in your dashboard.

  • Nothing to phish. There's no credential for a fake login page to capture.
  • Nothing to brute force. Bots can hammer forever and never arrive at an answer.
  • No reset tickets. Your VA never messages you at 11pm asking for the WordPress password again.
  • Recovery built in. Backup codes at setup, plus owner-level restore for any team member.
sign in
Welcome back, Emma

mystore.com · Store manager

Sign in — one click

No password field. There is no password.

03 — User activity logs

Answer “who did this?” in ten seconds

A price drops to $8.90. A coupon appears with 90% off. An order gets refunded twice. Without a log, you're reconstructing the story from memory and Slack messages. With one, you know who, what and when — immediately.

  • Commerce-aware events. Order status changes, refunds, price edits, coupon creation, stock adjustments.
  • WordPress events too. Logins, role changes, plugin activation, theme edits, settings updates.
  • Attributed to a person. Not “admin” — the actual human, with their device and location.
  • Searchable history. Filter by user, date or event type when you need to prove what happened.
activity log
Today recording
Emma R.Price “Merino Crew” $89.00 → $8.90Flagged
Emma R.Reverted price to $89.00Resolved
Dev · LisbonActivated plugin “Shipping Rules”Logged
Marco T.Refunded order #48211 · €240.00Logged
Marco T.Created coupon “VIP90” · 90% offFlagged
04 — Real-time threat detection

Watch the attacks arrive and go nowhere

Credential stuffing, vulnerability scanners, XML-RPC amplification, bots enumerating your usernames — it's happening to your store right now. WooSecure identifies it live and shows you exactly what was stopped.

  • Known-bad IP intelligence shared across every store on the platform.
  • Behavioural signals catch the scanners that rotate addresses to stay under rate limits.
  • Zero customer impact — detection happens at the admin layer, never in the shopping funnel.
  • Weekly digest so you can see the volume you never have to think about.
threat monitor
Last hour
148
Unique IPs
37
Got through
0
Attack types live
Brute forceLogin attempts against wp-login.php98
ScannerPlugin vulnerability probing31
XML-RPCMulticall amplification14
EnumerationAuthor/username discovery5
05 — Team management

Give access. Take it back. Keep the record.

Stores grow by adding people: a VA for order processing, a freelancer for a theme fix, an agency for a replatform. Each one is a key to your business. WooSecure makes handing out and taking back those keys a ten-second job.

  • Invite by email — no shared logins, no passwords in Slack, ever.
  • Per-site access so a contractor on one store can't see the others.
  • Instant revoke that doesn't require rotating credentials afterwards.
  • Unlimited seats, unlimited sites. We don't charge you for good hygiene.
team · mystore.com
4 membersAccess
Sara K.Owner · all storesFull
Emma R.Store manager · mystore.comFull
Marco T.Support · orders onlyLimited
Dev · LisbonContractor · expires in 6 daysTemporary
06 — Error monitoring

A broken checkout is silent. Until the refunds.

A plugin update throws a fatal error on the payment step. Your storefront still looks perfect. Orders just stop. Most owners find out hours later from a customer email — WooSecure tells you in minutes.

  • Fatal error alerts the moment PHP breaks, with the file and the plugin that caused it.
  • Gateway failure signals when webhooks stop arriving or start timing out.
  • Correlated with changes — see which plugin update immediately preceded the failure.
  • Email and panel alerts so it reaches you whether or not you're at your desk.
alerts
Recent monitoring
14:02Fatal error · checkout.php line 214Critical
14:02Triggered by “Shipping Rules” v3.1 updateCause
14:03Alert sent to sara@mystore.comNotified
14:11Plugin rolled back · checkout restoredResolved

Every feature. Every store.
$99 a year.

We don't gate security behind a tier, and we don't charge per site. Whether you run one store or fifty, you get all six layers for the same price.