PLUGIN SECURITY
Is Sg Security safe?
Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.
What this plugin does
- Slug:
sg-security - Author: SiteGround
- 1000000+ active installs
- 90/100 rating (157 reviews on wordpress.org)
- 37119296 all-time downloads
- On WordPress.org since 2021-05-31
firewallloginmalware scannersecurityweb application firewall
Maintenance status
- Latest known version: 1.6.5
- Last updated: 2026-07-09 2:31pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.0+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
6 known CVEs on file for Sg Security. Reported between 2022 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-13342 | Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.6.5 | Protection Mechanism Failure | Medium 5.3 | < 1.6.5 | 1.6.5 | 2026-08-06 | ✓ fixed in latest |
| CVE-2025-66121 | Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.5.9 | Missing Authorization | Medium 5.3 | < 1.5.9 | 1.5.9 | 2025-11-30 | ✓ fixed in latest |
| CVE-2024-38774 | Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.5.1 | Missing Authorization | Medium 5.4 | < 1.5.1 | 1.5.1 | 2024-07-19 | ✓ fixed in latest |
| CVE-2023-0234 | Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.3.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 1.3.1 | 1.3.1 | 2023-01-13 | ✓ fixed in latest |
| CVE-2022-0993 | Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.2.6 | Improper Authorization | Critical 9.8 | < 1.2.6 | 1.2.6 | 2022-04-07 | ✓ fixed in latest |
| CVE-2022-0992 | Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.2.6 | Authentication Bypass Using an Alternate Path or Channel | Critical 9.8 | < 1.2.6 | 1.2.6 | 2022-04-06 | ✓ fixed in latest |
How to fix it
Keep Sg Security updated — 1.6.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Wordfence Security – Firewall, Malware Scan, and Login Security — 5000000+ active installs — 94/100 (4978) — max PHP 8.4
- WPS Hide Login — 2000000+ active installs — 96/100 (2111) — max PHP 8.4
- Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention — 1000000+ active installs — 96/100 (1477) — max PHP 8.4
- All-In-One Security (AIOS) – Security and Firewall — 1000000+ active installs — 94/100 (1714)
- Loginizer — 1000000+ active installs — 96/100 (1030) — max PHP <8.0
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.