The three ways to install the plugin, how to get your license key, and how to install it. Start here if you are setting up VMP Security for the first time.
Install VMP Security in about a minute from inside WordPress admin, with automatic updates. The recommended route for most sites.
Download the VMP Security ZIP from WordPress.org and upload it through WordPress admin. Use this when the plugin search is blocked or you need a specific version.
Install VMP Security by uploading the plugin folder over SFTP, or in one command with WP-CLI. For locked-down sites and multi-site operators.
Where free and Premium license keys come from, how to find a key you already have, and what to check if a key has not arrived after a purchase.
Four ways to install a VMP Security license key, with screenshots -- the window shown after activation, the resume banner, the All Options page, and remotely from your account.
Where the coupon field is (the cart, not the checkout), how to apply and remove a code, what happens when a coupon covers the full amount, and what each error message means.
Fixes for the problems that come up while installing VMP Security or its license key -- failed key installs, greyed-out fields, a site that drops back to free, and a missing admin menu.
Overview of VMP Security Free — endpoint firewall, security scanner, login security, centralized management, and more.
Real-time firewall protection, real-time scan signatures, IP blocklist, country blocking, and Premium support.
Manage many WordPress sites from a single dashboard — site overview, configuration templates, scan findings, audit log, and alert routing.
Learn how to connect multiple WordPress sites to VMP Security Portal so you can manage them from one place.
Enable two-factor authentication on your VMP Security account from the My Account page.
Create reusable templates of VMP Security plugin options and apply them to any of your connected sites.
Manage VMP Security plugin options for one or more connected sites from a single page in Portal.
See your websites and licenses at a glance after signing in to VMP Security Portal.
Configure Portal-side alert preferences — Scan Findings, Daily Digest, Other Security Events, and the delivery channels (Email, SMS, Slack/Discord).
Review scan findings for a connected site directly from VMP Security Portal.
An overview of the VMP Security Reseller program: what it is, who it is for, and how the day-to-day workflow looks.
What the audit log records, how to filter it, and when to use it for compliance or troubleshooting.
How alerts are raised across your fleet, how to filter them, and what to do when one fires.
How license pools work, how to allocate slots to clients, and what happens when you revoke.
How to add new clients, find existing ones, and suspend, reactivate, or delete a client.
How to read the reseller Dashboard so you can spot client issues without opening every page.
How reseller plans are sized and priced, and what happens when you complete a purchase.
What a VMP Security license key is, how free and Premium differ, how many keys you need, and how renewals and staging sites are handled.
Manage your VMP Security account — profile, password, 2FA, payment methods, billing address, and invoices.
Understand the VMP Security Dashboard — protection status, notifications, Portal connection, toolbar, and firewall statistics.
Configure global VMP Security plugin options that apply across the dashboard.
Configure which security events generate email alerts and where they are sent — all from the All Options page.
A PHP-based application-level firewall that filters out malicious requests — what it protects against, status, optimization, and disabling.
View firewall statistics including blocked attacks, top attackers, and traffic trends.
Move the firewall to Extended Protection so it loads before WordPress and blocks a wider range of attacks.
How to allowlist legitimate requests that the firewall blocked by mistake — from the block page, Live Traffic, or Firewall Options.
Configure firewall mode, rules, advanced blocking, and per-rule behavior.
How VMP Security stores firewall data and how to set the storage engine via the VMPFENCE_WAF_STORAGE_ENGINE constant.
Protect WordPress login forms from automated password-guessing attacks.
Limit how aggressively a single visitor can hit your site, with separate rules for crawlers and humans.
Resolve common firewall issues, false positives, and configuration errors.
Block IP addresses, countries, and custom patterns in VMP Security — including hostnames, browser User-Agents, and referers.
Block traffic from specific countries based on geo-IP lookup — included in the free version.
Diagnose unintended blocks and resolve issues where legitimate visitors or admins are being blocked.
How VMP Security scans your site for malware, backdoors, malicious URLs, and infections — scan types, stages, results, and troubleshooting.
Configure what the VMP Security scanner checks, including file integrity, malware, and reputation checks.
Understand and act on the issues reported by a VMP Security scan.
Schedule when VMP Security runs scans on your site.
Resolve common scan failures and timeouts.
VMP Security Tools — Live Traffic, Audit Log, Whois Lookup, Import/Export Options, and Diagnostics.
Watch real-time traffic on your site, including humans, bots, and security events.
Look up the registered owner and ISP for an IP address or domain.
Export your VMP Security configuration and re-import it on another site or after a reinstall.
Inspect your installation and server configuration to help diagnose issues.
Add a second authentication factor to your WordPress login using TOTP authenticator apps.
Free audit log that records security and admin events on your site so you have a chronological record to consult during incident response.
Settings for two-factor authentication (2FA), reCAPTCHA, WooCommerce integration, and general login-security options.
Move the WordPress login page to an address only you know, and get back in if you ever lose it.
Minimal recommended settings to configure once you have installed and activated VMP Security.
Technical details about VMP Security — automatic updates, cloud servers, infrastructure IP addresses, and allowlisting.
PHP, WordPress, MySQL, and server resource requirements for VMP Security.
Version history of the VMP Security plugin.
Technical details about how the VMP Security plugin operates.
PHP constants you can define in wp-config.php to override or fine-tune VMP Security behavior.
Cleanly remove VMP Security or reset its data without leaving stale files behind.
Public PHP classes, hooks, and shortcodes that VMP Security exposes for developers extending or integrating with the plugin.
Compatibility notes for popular plugins, themes, and hosting environments.
General troubleshooting steps for VMP Security issues that don't fit elsewhere.
Diagnose and resolve conflicts between VMP Security and other plugins or themes.
Learn how to identify callbacks made from VMP Security servers to your site.
How the Login Security page works in the main VMP Security plugin — 2FA, reCAPTCHA, and where Brute Force lives.
How VMP Security complies with GDPR — terms, standard contractual clauses, and the cookies set by the plugin.
The VMP Security Affiliate Program pays you a commission when someone you refer buys VMP Premium. There is no separate affiliate account to create — it rides on your normal...
The affiliate program's earning rules are published in full — here's how a sale turns into a commission, and eventually into a payout.
Once a commission clears its lock period, it moves into your payable balance and waits for the next monthly payout run.
You apply for the affiliate program with your existing VMP account — there's no separate affiliate signup or password to create. If you land on the application page while signed...
Your affiliate dashboard is the one page you need once you're approved — it holds your referral link, your current commission terms, live performance stats, your commission and payout history,...