Icono del producto

Security para WooCommerce

por OPMC
Protect your store from unwanted access, risky traffic, and exposed files
Elige una opción de facturación
$39
Ahorra un 20 %
$78 $62.40

La suscripción incluye

  • Actualizaciones y mejoras del producto
  • Atención al cliente
  • Garantía de devolución de 30 días

Running a WooCommerce store means more than taking orders. You may also need to control where customers can buy from, restrict access to selected products, manage guest downloads, strengthen administrator login security, and reduce unnecessary exposure of WordPress files.

Security for WooCommerce brings practical access controls, download protection, security monitoring, and site-hardening tools into one WooCommerce-focused dashboard.

  • Restrict store, cart, checkout, product, and category access by country
  • Allow or block exact IPv4 and IPv6 addresses
  • Block individual products or restrict selected categories
  • Control guest download access with IP rules and protect selected Media Library files
  • Run manual scans and schedule daily scans for suspicious code indicators
  • Add two-factor authentication for administrator accounts and an extra login gate
  • Apply WordPress hardening options, including file permissions, directory listing, and version metadata controls
Security for WooCommerce is built for merchants who need more control over access to their store, products, checkout, downloadable content, and WordPress administration area.
Security for WooCommerce dashboard showing store access controls, malware scan status, download protection, and site hardening.

Built for common ecommerce security needs

Security for WooCommerce gives merchants practical tools for controlling unwanted access, limiting regional availability, protecting selected files, and strengthening administrator login security.

  • Sell only in approved countries or regions
  • Limit cart, checkout, product, or category access for blocked countries
  • Allow trusted IP addresses and block known unwanted IP addresses
  • Control guest access to WooCommerce download links
  • Protect selected Media Library files from direct access by logged-out visitors
  • Require authenticator-app codes for administrator accounts
  • Review suspicious file indicators through manual or scheduled scans
For broader store protection, Security for WooCommerce can work alongside Anti-Fraud for WooCommerce. Use Security for WooCommerce to control website access, protect selected files, and strengthen WordPress administration. Use Anti-Fraud for WooCommerce to assess checkout and order risk.

Is this extension right for you?

Security for WooCommerce focuses on website access, regional restrictions, protected downloads, administrator login security, file monitoring, and WordPress hardening.

If your primary concern is fraudulent orders, card testing, stolen payment methods, or suspicious checkout activity, Anti-Fraud for WooCommerce by OPMC is designed specifically for order and checkout risk. Merchants can use both extensions together because they address different parts of store security.

Need Security for WooCommerce Anti-Fraud for WooCommerce
Primary purpose Control website access and strengthen WordPress security Assess checkout and order risk
Country controls Restrict access to the store, products, categories, cart, or checkout Use order location as part of fraud analysis
IP address controls Allow or block exact visitor IP addresses Use IP information as part of order risk analysis
Block individual products Yes
Restrict product categories by country Yes
Guest download IP controls Yes
Protect selected Media Library files Yes
Suspicious file scanning Yes
Administrator two-factor authentication Yes
WordPress hardening Yes
Fraud scoring and order risk analysis Yes
Card testing protection Yes
Suspicious order alerts Yes
Need both website security and fraud prevention? Security for WooCommerce helps control who can access your website and adds practical WordPress hardening tools. Anti-Fraud for WooCommerce focuses on checkout activity, fraud scoring, and risky orders.

Control who can access your store

Use country and IP rules to reduce unwanted access and limit important parts of the buying journey.

Restrict access by country

Select countries whose visitors should be restricted, while keeping your configured store country available as a safeguard.

Depending on your settings, restrictions can apply across the storefront or to specific areas such as product pages, product categories, the cart, and checkout.

Country restriction settings for store access, products, cart, and checkout in Security for WooCommerce.

Restrict cart and checkout access

Prevent visitors from blocked countries from adding products to the cart or completing checkout.

This is useful when you do not sell, ship, or provide services in particular regions.

Setting to restrict cart and checkout access for visitors from blocked countries.

Block individual products or limit product pages by country

Mark an individual product as blocked when it should not be publicly available. Administrators and shop managers can still view blocked products while managing the store.

You can also prevent visitors from blocked countries from opening product pages when country-based product restrictions are enabled.

Product access restriction setting in Security for WooCommerce.

Restrict selected product categories

Choose WooCommerce product categories that visitors from blocked countries should not be able to browse.

This can help stores manage regional catalogs, licensing limitations, wholesale ranges, or products that are unavailable in particular locations.

Product category restriction settings for visitors from blocked countries.

Set daily access restrictions

Set a daily time window during which visitors from blocked countries cannot access the site. The schedule is evaluated using the visitor country timezone.

Customize the blocked visitor message

Replace the default blocked-access notice with a message that explains your store policy or tells visitors how to contact you.

Manage access with IP rules

Use exact IPv4 or IPv6 addresses to make exceptions for trusted visitors or block addresses associated with unwanted access.

Allow trusted IP addresses

Add known addresses for team members, agencies, offices, or trusted partners. The allow list takes priority over the block list.

Block known IP addresses

Add exact IP addresses that should not be able to access the storefront while Traffic protection is enabled.

IP allow list and block list settings in Security for WooCommerce.

Protect downloads and selected media files

Add access controls for WooCommerce guest download links and protect selected files from direct access.

Control guest download links by IP address

When WooCommerce does not require customers to log in before downloading, choose how guest download links should handle visitor IP addresses.

Available modes allow all guest download IPs, deny listed IPs, or allow only listed IPs. These rules apply to WooCommerce guest download links and do not replace WooCommerce customer permissions or order-based download controls.

Guest download IP access settings in Security for WooCommerce.
Choose how guest download links handle allowed and blocked IP addresses.

Protect selected Media Library files

Mark individual Media Library attachments as protected. The extension moves protected attachments into a dedicated uploads directory and adds rewrite rules intended to prevent logged-out visitors from opening supported file types directly.

Direct-access protection depends on the server honoring WordPress rewrite rules. Test protected files after enabling this feature.

Discourage search engine indexing

Add robots.txt signals for protected attachment pages and file paths so search engines are less likely to index them. These signals discourage indexing but cannot guarantee removal from every search engine.

Disable directory listing

Add a rule that prevents bare directory indexes when no index file exists. Availability depends on the store’s server configuration.

Monitor files for suspicious code indicators

Run signature-based scans from WordPress and review the results in the Security for WooCommerce dashboard.

Run a manual scan

Start a scan when you want to review site files for suspicious PHP patterns that may require investigation.

Suspicious file scan results in Security for WooCommerce.

Schedule daily scans

Enable background scans that run once per day through WordPress cron. Results appear in the Malware scan area for review.

The scanner reports suspicious indicators. It does not confirm that a file is malicious, remove infected files, or replace a host-level security service or web application firewall. Review findings before changing or deleting files.

Review security activity

Use the activity log to review recorded country restrictions, IP rule matches, product and category restrictions, guest download decisions, and other supported security events. Configure log retention based on your store’s needs.

Harden your WordPress installation

Apply additional protections to common WordPress files and public metadata.

Review and harden file permissions

View a report comparing key WordPress paths with recommended permissions. When file permission hardening is enabled and settings are saved, the extension attempts to apply the recommended permissions.

Many hosting environments prevent PHP from changing file permissions, so review the report and confirm the result with your host when needed.

Hide WordPress version metadata

Remove WordPress version metadata from feeds, scripts, and styles where supported. This reduces public version exposure but is not a substitute for keeping WordPress, WooCommerce, themes, and extensions updated.

Strengthen administrator login access

Add extra protection before or during administrator login.

Add two-factor authentication for administrators

Require users with administrator accounts to enter a time-based code from an authenticator app after entering their WordPress password.

Administrator two-factor authentication setting in Security for WooCommerce.

Add an extra login gate

Display a separate username and password gate at wp-login.php before the normal WordPress login form.

The gate credentials are separate from WordPress user accounts. Store them securely and confirm your recovery process before enabling the feature.

Common use cases

Sell only in selected countries

Restrict visitors from countries you do not serve and decide whether the restriction applies to the storefront, products, categories, cart, or checkout.

Manage regional product availability

Block individual products or hide selected product categories from visitors in restricted countries.

Control guest downloads

Use exact IP rules to allow or deny access to WooCommerce guest download links when login is not required.

Protect selected digital assets

Move selected Media Library attachments into the protected directory and discourage direct access and search indexing.

Strengthen administrator access

Add administrator 2FA and an optional gate before the normal WordPress login form.

Review basic WordPress security indicators

Use suspicious-code scans, activity logging, file permission reporting, directory listing controls, and version metadata removal from one dashboard.

Designed for stores that need more control

Security for WooCommerce can support:

  • Stores selling only within specific countries or regions
  • Stores with regional product or category restrictions
  • Digital product sellers using WooCommerce guest download links
  • Merchants who need exact IP allow and block lists
  • Store owners who want administrator 2FA and an extra login gate
  • Teams that want suspicious file scanning and activity logging inside WordPress
  • Agencies managing access controls and basic hardening for WooCommerce clients

Why choose Security for WooCommerce?

Security for WooCommerce combines WooCommerce-focused access rules with practical WordPress monitoring and hardening tools.

  • Restrict countries, exact IP addresses, products, categories, cart, and checkout
  • Control guest download access and protect selected Media Library files
  • Run manual scans and schedule daily suspicious-code scans
  • Review supported security events through an activity log
  • Add two-factor authentication for administrator accounts
  • Add an optional gate before the normal WordPress login form
  • Review file permissions and reduce common WordPress exposure points
  • Manage settings through a dedicated WooCommerce security dashboard
OPMC logo

Built by OPMC

OPMC has been building and supporting WooCommerce extensions since 2014. Our team works with real ecommerce stores across integrations, automation, checkout workflows, and store security.

Security for WooCommerce is actively maintained and supported to help merchants manage practical access controls and WordPress hardening from inside WooCommerce.

Get started with Security for WooCommerce

Control store access by country and IP address, manage regional product availability, protect guest downloads and selected media files, monitor suspicious code indicators, and strengthen administrator login security.

Add Security for WooCommerce to your store today.


Preguntas frecuentes

How can I stop unwanted visitors from accessing my WooCommerce store?

Security for WooCommerce lets you control who can access your store using country restrictions, IP allowlists and blocklists, passcode protection, and time-based access rules. Whether you want to block high-risk regions, restrict certain products, or protect private areas of your website, you have complete control over who can view and interact with your store.

Can I protect my downloadable products from unauthorized access?

Absolutely. If you sell software, digital downloads, eBooks, templates, or other downloadable products, Security for WooCommerce helps prevent unauthorized access to your download files. This provides an additional layer of protection for your digital assets beyond WooCommerce's standard download controls.

Does this plugin protect my WordPress website as well as my WooCommerce store?

Yes. In addition to WooCommerce-specific security features, the plugin includes WordPress hardening tools such as malware scanning, directory protection, hiding your WordPress version, passcode protection for sensitive areas, and optional two-factor authentication to help reduce common security risks.

Will this plugin slow down my website?

Security for WooCommerce is designed to work efficiently alongside WooCommerce and WordPress. Most stores experience little to no noticeable impact on performance while benefiting from additional layers of protection. As with any security solution, performance depends on your hosting environment and the features you enable.

Will this plugin block legitimate customers?

No—unless you configure it to. You decide how strict your security rules should be. You can create IP allowlists, exclude trusted users, apply restrictions only to specific products or countries, and adjust settings as your business grows. This flexibility helps protect your store while minimizing disruption for genuine customers.

Does Security for WooCommerce stop card testing attacks or payment fraud?

No. While Security for WooCommerce helps protect your website by restricting access, blocking VPNs and proxies, scanning for malware, and strengthening WordPress security, it is not designed to detect or stop card testing attacks or payment fraud.

For protection against card testing, stolen credit cards, fraudulent orders, and other payment-related threats, we recommend OPMC Anti-Fraud for WooCommerce. The two plugins complement each other and can be used together to provide comprehensive protection for both your website and your checkout process.

Why do I need Security for WooCommerce if I already have a firewall or security plugin?

A firewall helps protect your website from many common attacks, but it doesn't provide WooCommerce-specific controls like country restrictions, product-level access rules, secure download protection, or visitor restrictions based on location or IP address.

Security for WooCommerce adds an additional layer of protection specifically designed for WooCommerce stores, giving you greater control over who can access your content, products, and store.

Opiniones de clientes

Estamos aceptando reseñas para este producto, y las mostraremos cuando tengamos unas cuantas más.

Información de la extensión

  • Versión mínima de WordPress requerida: 4.6
  • Versión de WooCommerce requerida: 2.6.0
  • Se requiere una versión de PHP: 7.4
  • Se ha probado con WordPress: 7.0
  • Se ha probado con WooCommerce: 10.9.1
  • Se necesita al menos WordPress: 6.5
  • Se necesita al menos WooCommerce: 5.0

Países

  • Todo el mundo

Idioma:

English (Australia), English (Canada), English (New Zealand), English (South Africa), English (UK), English (United States)

Related Products

Precio: $279/anualmente
Valoración: 3.2 sobre 5 estrellas
Precio: $79/anualmente
Valoración: 3.4 sobre 5 estrellas
Precio: $59/anualmente
Valoración: 3.1 sobre 5 estrellas
Precio: $109/anualmente
Valoración: 2.7 sobre 5 estrellas
Precio: $49/anualmente
Valoración: 4.1 sobre 5 estrellas
Precio: $109/anualmente
Valoración: 2 sobre 5 estrellas
Precio: $109/anualmente
Valoración: 2.3 sobre 5 estrellas
Precio: $39/anualmente
Valoración: 2.8 sobre 5 estrellas
Precio: $109/anualmente
Valoración: 2.6 sobre 5 estrellas
Usar sus datos personales
Tanto nosotros como nuestros socios procesamos tus datos personales (como los datos de navegación, las direcciones IP, la información sobre las cookies y otros identificadores únicos) en función de tu consentimiento o en nuestro interés legítimo para optimizar nuestra web, las actividades de marketing y tu experiencia como usuario.