In the news
VMP™ Security in the media and industry publications
Latest from VMP™ Security
Product updates, security research, and advisories — newest first.
A clearer dashboard
Status, alerts and activity now carry distinct visual weight, text sizes are consistent, and figures line up in neat columns. No panel, metric or control was removed -- it just reads clearly. Plus accessibility fixes: contrast, keyboard outlines, and reduced-motion support.
Read moreSee your blocked attacks by type, over time
The Firewall Summary now charts one coloured line per attack type -- Complex, Brute Force and Blocklist. Switch between Today, Week and Month, and click a type to hide or show its line.
Read moreTighter permissions, less exposed, self-healing
Sensitive firewall, scan and malware actions now confirm the user is an administrator; file tools are confined to your WordPress folder; the beacon and self-test leak less to anonymous visitors; IPs are recorded via the firewall's own detection; and the protection files restore themselves.
Read moreTell us what you think, right from your dashboard
A feedback page built into the plugin plus a compact dashboard card -- pick a topic (something broken, a missing feature, speed, pricing, support, or anything else), write your note, and send. Plus an occasional, dismissible reminder that never bothers new installs and goes quiet once you have sent.
Read moreFour ways back in if you lose the address
Retrieve the current login address from the VMP Security Portal, or fall back to the emailed copy, a one-line wp-config.php switch, or renaming the plugin folder. The portal only ever reads the address -- it can never change it.
Read moreMove your login page somewhere only you know
Automated scanners hammer /wp-login.php by the thousand. Point your login page at an address of your choosing and the old one stops answering -- encoded, mixed-case and dot-segment variants included.
Read moreBots that have to prove who they are
Trusted-bot checks now run a forward-confirmed reverse DNS lookup -- a crawler is trusted only when its hostname resolves back to the same IP. Spoofed user agents no longer pass.
Read moreYour security status, the instant you open it
The dashboard status panel is cached with server-side invalidation -- it opens instantly, and still updates the moment your protection state changes.
Read moreNew signatures reach your site sooner
The plugin now reports its signature and rule state to the update service, so new malware signatures and WAF rules are pushed promptly instead of waiting for the next full refresh.
Read moreSecurity alerts you can actually trust
The alert email is no longer silently auto-filled with your admin address -- empty is respected, with a \"Use admin email\" shortcut. Delivery results are reported, so bounced or suppressed addresses are flagged inline.
Read moreThe audit log, rebuilt and faster
Grouped events now show every change (not just the first), with severity colour-coding and relative timestamps -- and new composite indexes make filtering and paging faster on a long history.
Read moreSmarter blocks that expire and forgive
Automated IP blocks are no longer permanent -- offenders get an escalating, time-limited block (1 hour up to 7 days) and their reputation decays over about 30 days.
Read moreThe official VMP™ Security mailing list
Receive WordPress security news before publication.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Press & media
Covering VMP™ Security or our research in your publication? Get in touch and we’ll feature it here.
Media inquiries
Writing about VMP™ Security or our WordPress vulnerability research? Reach out and we’ll help with details, data, and quotes.
Contact us