Description
With Security Ninja Premium, you can block malicious traffic with a firewall, run security tests, scan files for malware, compare core files against the original ones from WordPress.org, and log site events in audit trails. It serves administrators, agencies, and store owners who need to track vulnerabilities, login attempts, suspicious changes, and protection rules without spreading controls across multiple plugins in the dashboard.
Key Features of Security Ninja Premium
- Protection firewall
Filters suspicious requests, malicious IPs, and automated attempts. - Malware scanner
Checks site files for suspicious code. - Security tests
Analyzes permissions, exposed settings, and vulnerable spots in WordPress. - Login protection
Restricts repeated attempts and reduces brute-force attacks. - Event logs
Records relevant actions, accesses, and changes inside the site.
Benefits of Security Ninja Premium
- Faster response
Alerts and logs help investigate incidents with more context. - Less technical exposure
Guided fixes reduce common WordPress configuration flaws. - Centralized control
Firewall, scanner, and audit features remain in the same dashboard. - More predictable routine
Scheduled checks keep security monitored without constant manual review.
Who Is Security Ninja Premium For?
- WordPress site administrators who need to monitor security, malware, and logins.
- Agencies and freelancers who keep client sites under recurring supervision.
- Stores, portals, and projects with sensitive admin areas or high traffic volumes.
How to Download Security Ninja Premium
Security Ninja Premium is available for download here at Ultrapack. After downloading the .zip file, install it in Plugins > Add New > Upload Plugin, select the .zip, and activate it. After activation, configure the security modules in the WordPress dashboard.
Security Ninja Premium brings together important protection layers in a manageable routine: firewall, malware scanning, integrity checks, security tests, and event logging. For those maintaining WordPress sites in production, this combination makes it easier to detect signs of intrusion, block unauthorized access, and track critical changes before small issues affect availability, reputation, or operations.
Frequently asked questions
Is Security Ninja Premium GPL-licensed?
Yes. Security Ninja Premium is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use Security Ninja Premium on multiple sites?
Yes. You can install Security Ninja Premium on as many sites as you want. Only automatic updates through Ultrapack Auto Updater have a limit: from 3 to 80 sites, depending on the plan.
How much does Security Ninja Premium cost at Ultrapack?
Security Ninja Premium costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does Security Ninja Premium include updates?
Yes. The current version of Security Ninja Premium is 5.303, published at Ultrapack on Sep 9, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is Security Ninja Premium scanned before publication?
Yes. Every version of Security Ninja Premium goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What are the requirements for the plugin Security Ninja Premium?
Requires WordPress 4.7 or higher and PHP 7.4 or higher. Tested up to WordPress 7.1.
What changed in this version
Version 5.303
- 2026-09-08
- NEW: Visitor IP detection - Choose how the firewall reads the visitor IP: Automatic, Cloudflare, proxy headers, or REMOTE_ADDR. Automatic trusts Cloudflare ranges by default. For another load balancer or reverse proxy, add its IPs under Trusted proxy CIDRs. Free and Pro.
- IMPROVED: Vulnerability Scanner - Scheduled warning emails wait for a finished scan, skip plugins and themes that are gone or already patched, and do not repeat the same findings within 24 hours. Thank you Jamie.
- IMPROVED: Uninstall - Removing the plugin also clears module tables, settings, cached files, and related user metadata.
- IMPROVED: Events Logger - Administrator emails now cover new accounts and role promotions.
- IMPROVED: Events Logger - Speed improvement - When logging is off, event hooks and database writes are skipped. Broad REST API error logging stays off by default; turn it on in Events settings if you need those diagnostics.
- IMPROVED: Settings import/export and MainWP - Events REST logging and visitor IP settings, including trusted proxy CIDRs, are included when you copy settings between sites.
- IMPROVED: Malware Scanner - Removed the unused legacy scanner.
- IMPROVED: MainWP - Applying settings remotely now reschedules the scanner cron when the schedule changes, and applies the same wp-config updates as the Fixes page (file editor, debug, secure cookies).
- IMPROVED: MainWP - Remote settings now include WooCommerce rate-limit numbers, 2FA grace period and login copy, and satellite/ASN soft-mode lists.
- IMPROVED: Frontend - Speed improvement - Premium no longer loads unused Pro modules on public page views. Free modules are unchanged. Thank you Jose.
Version 5.302
- 2026-09-01
- FIX: Firewall - Per-visitor reverse-DNS, ASN, and GeoIP caches no longer fill the WordPress options table with one row per IP. On busy sites without Redis/Memcached that could grow to hundreds of thousands of rows and cause intermittent downtime. After update, leftover rows are removed automatically in small batches. Thank you Davina.
- FIX: Firewall - Search-engine and crawler checks only run reverse-DNS when the User-Agent looks like a known crawler. Normal browser traffic no longer triggers a DNS lookup on every page view. AI crawlers (OpenAI, Perplexity, Claude) are checked against published IP ranges only.
- FIX: Firewall - Hostname-based "blocked hosts" matching (part of Filter Suspicious Queries) is off by default. URI, query string, user agent, and referrer rules still run. Developers can re-enable hostname checks with the secnin_cf_check_blocked_hosts filter.
- FIX: Firewall - Satellite/ASN softening (Pro) no longer calls the remote ASN API on every miss when the site has no object cache. With Redis or Memcached, results are cached there instead of in the database.
- FIX: Firewall - The list of remembered validated crawler IPs is limited to 200 entries so it cannot grow without bound.
- FIX: Fixes - Disable Username Enumeration now blocks anonymous REST user listing (/wp/v2/users and ?rest_route=), not only by removing the endpoint. The username enumeration security test checks that path as well. Thank you Elias.
Version 5.301
- 2026-08-31
- FIX: Fixes - Saving Security Fixes with "Disable debug mode" off no longer forces WP_DEBUG to true in wp-config.php. Thank you Mike.
- IMPROVED: Vulnerability Scanner - Update notices now say we are tracking more known vulnerabilities in the database, not that vulnerabilities were "downloaded" to the site. Thank you Tom.
Version 5.300
- 2026-08-25
- FIX: Firewall - Removed the blocked_kanagawa hostname rule again (Japanese prefecture / OCN false positives). Thank you Masahiro.
- IMPROVED: Firewall - Filter Suspicious Queries help text now states that it includes reverse-DNS hostname checks, separate from Cloud Firewall and Prevent Banned IPs.
- FIX: Scheduled Scanner - Security Testing emails no longer fire on message-only diffs or HTTP timeout Warning/Good flaps.
Version 5.299
- 2026-08-24
- FIX: Vulnerability Scanner - Opening the Vulnerabilities tab no longer floods PHP warnings when a CVE reference is missing its display name (Undefined property stdClass::$name) or when strip-http helpers receive null (strpos deprecation on PHP 8+).
- NEW: Cloud Firewall - Claude / Anthropic crawlers (ClaudeBot, Claude-User, Claude-SearchBot) are verified against Anthropic's published IP ranges at claude.com/crawling/bots.json, same pattern as OpenAI and Perplexity. Thank you David.
- FIX: Security Tests - Local site detection no longer strips dots from 127.0.0.1 via sanitize_key (which broke TLS skip-verify). Self-checks against .local hosts and WP_ENVIRONMENT_TYPE=local work again, so tests like debug.log accessibility stop failing with a generic transport error on Local.
- FIX: Security Tests - REST API enabled check now skips TLS verify on local sites (same as other self-checks). Local installs with self-signed certs no longer get a false "Could not determine REST API accessibility" warning.
- FIX: Security Tests - PHP ini boolean checks (allow_url_include, expose_php, display_errors, register_globals, safe_mode) no longer treat the string Off as enabled.
- IMPROVED: Security Tests - expose_php test passes when the PHP version header is already hidden via Security Headers or server config (e.g. .htaccess), not only when php.ini is editable.
- FIX: Auto Fixer - Table prefix change requires an explicit prefix, shows the applied prefix on success, and handles long runs/timeouts more clearly.
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
- Download the file
security-ninja-premium.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
security-ninja-premium.zipand click Install Now. - Click Activate.
Requirements: Requires WordPress 4.7 or higher and PHP 7.4 or higher. Tested up to WordPress 7.1.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready