
WordPress powers millions of websites — and therefore also attracts attackers. Brute force against the login, malicious bots, SQL injection, known CVE vulnerabilities and unauthorized file changes are everyday threats that can take your site offline or compromise data.
maca Sec is a security plugin developed by maca Development. It brings together a firewall (WAF), login protection, two-factor authentication, hardening, scanning, file monitoring and logging in one place. All features are included from the start — no premium tiers, no locked modules.
The plugin is open source (GPL), runs on your own server, and is built for Swedish and international WordPress sites. The interface is shown in Swedish when WordPress is installed in Swedish, and in English for all other language settings. The user guide and legal documents are also available in both languages.
What’s new in the latest version
Collective threat intelligence
maca Sec can anonymously report new attacks to the maca Hub network and receive blocks that have already stopped attacks on hundreds of other sites. Attackers who try again meet protection faster.
File System Guard 2.0
Deep scanning of uploads and themes for new PHP files, webshell signatures and suspicious code — eval, Base64, gzinflate and more.
Security score
Holistic score 0–100 with a checklist on the dashboard: PHP version, HTTPS, 2FA, WAF, CVE status and updates — all at a glance.
Live Attack Map
Real-time data on attacks per minute, countries, attack types and latest exploits — shown in the maca Hub app when the site is connected.
AI bot protection
Per-bot policy (Allow / Block / Limit) for GPTBot, ClaudeBot, Bytespider, PerplexityBot and Amazonbot.
Smart rate limiting
Behavior weighting beyond simple IP blocking — burst, URL patterns, method, cookies and referrer — for fewer false positives and better protection against bots.
Why maca Sec?
Everything included
Firewall, 2FA, captcha, CVE scanning, honeypot traps, file monitoring, supply chain protection and security scanner — without a paywall.
Built for WordPress
Clear dashboard with security score, logs, checklist and step-by-step guide directly in wp-admin.
Protection early
The firewall analyzes traffic before WordPress has time to process dangerous requests. Attacks are stopped at the door.
You stay in control
Whitelist your IP, choose rules, block countries and get email alerts for critical events. Logged-in administrators in wp-admin bypass the firewall so you can work as usual.
Open and transparent
No cloud service required. maca Sec logs locally, can be uninstalled cleanly, and telemetry can be turned off completely.
Swedish and English
The plugin, guide and legal documents are available in both languages — adapted to your WordPress installation.
Features
Firewall (WAF)
Stops SQL injection, XSS, path traversal and dangerous file uploads. Block IP addresses, filter by country code, manage AI bots and whitelist trusted addresses.
Rate limiting and Attack Shield
Limits requests per IP across the entire site, wp-login, wp-admin, XML-RPC and REST API. Smart rate limiting weighs behavioral signals. Attack Shield temporarily activates maintenance mode (HTTP 503) during extreme traffic.
Login protection and honeypot traps
Brute force blocking, fake login-/XML-RPC-/REST paths that catch scanners, captcha (mathematical, reCAPTCHA or Cloudflare Turnstile), strong passwords, session management and email alerts.
Two-factor authentication (2FA)
TOTP with Google Authenticator, Authy or 1Password. QR code and recovery codes per user.
WordPress hardening and HTTP headers
Close common security holes and set security headers (X-Frame-Options, HSTS, CSP, etc.).
Security scanner, CVE table and security score
Score 0–100 with checklist. CVE table per installed plugin with risk level and update recommendations (WPScan). Email alerts for new high-risk vulnerabilities.
File monitoring and File System Guard 2.0
Monitors critical files and looks for new PHP files, webshell signatures and suspicious code in uploads and themes.
Supply chain protection and behavioral analysis
Monitors plugin integrity, developer changes and WordPress.org checksums. Risk score 0–100 for unusual REST and POST behavior.
Security log
All events are collected in one place. Filter, search and block suspicious IP addresses directly from the log.
maca Hub — under development
maca Hub is an iOS app that connects your WordPress sites with maca plugins. Through maca Sec you can get:
- Security status and reports on mobile
- Collective threat intelligence — shared attack patterns from across the network
- Live Attack Map with attacks per minute, countries and attack types
- Remote control and whitelist sync
maca Hub is under active development. The app is currently available only for iOS. We are looking for testers who want to try the integration between maca Sec and maca Hub — contact us via the contact form if you want to join.
maca Hub is not required — maca Sec works fully on its own.
How it works
- Install the plugin in WordPress (requires WordPress 6.0+ and PHP 7.4+).
- Accept the terms of use and privacy policy on first activation.
- Open the dashboard under maca Sec in the side menu.
- Run a security scan and address critical issues.
- Whitelist your IP before enabling stricter rules.
- Enable 2FA on your administrator account.
- Review the logs regularly — or let email alerts notify you of serious events.
Who is it for?
maca Sec is for you if you run a business website, blog or webshop in WordPress and want complete security without a monthly cost per feature — whether you prefer Swedish or English in the admin.
Technical requirements
| Requirement | Version |
|---|---|
| WordPress | 6.0 or later |
| PHP | 7.4+ (8.1+ recommended) |
| Database | MySQL or MariaDB |
| Language | Swedish and English |
Your WordPress site deserves protection that doesn’t cost extra for every new feature. maca Sec gives you that — free, open and ready to install.