Software & Apps

WP Ghost Review 2026: Is It Legit and Worth It?

Disclosure: LegitScout is reader-supported. If you buy through links on our site, we may earn an affiliate commission at no extra cost to you. How we make money

What Is WP Ghost?

WP Ghost is a WordPress security plugin whose central promise is prevention rather than cleanup: instead of scanning your site for malware after the fact, it tries to make your site a harder target in the first place by hiding the paths, files, and fingerprints that automated attackers look for. It was first released around 2016 under the name “Hide My WP Ghost,” and it has since been rebranded to “WP Ghost” — the same product and team, renamed because that’s what its paying customers had started calling it. You’ll still see both names used interchangeably, including on its official WordPress.org listing, which reads “WP Ghost (Hide My WP Ghost) – Security & Firewall.”

The plugin is developed and supported by AISQ, the rebranded name of the Squirrly company, which operates as Squirrly Limited, a UK-registered business. That vendor has been in the WordPress tools space for years — it also publishes the Squirrly SEO and Squirrly Social products — and it began actively developing and supporting this security plugin in 2018. That matters for a security tool: you’re not just buying a feature set, you’re betting on a company being around to patch and update it. On that front, WP Ghost has a reassuring record. The free version on WordPress.org was last updated July 8, 2026, and is tested up to WordPress 7.0.1, which tells you the plugin is being kept current with the platform rather than quietly abandoned.

The latest major release, WP Ghost 9.0, shipped in 2026 and, by the vendor’s account, the product is trusted by more than 250,000 websites across free and paid users, blocking a large volume of automated threats each month. The free version alone shows 100,000+ active installations on WordPress.org. Those are meaningful adoption numbers for a security plugin, and they’re independently visible rather than only claimed in marketing copy.

The single most important thing to understand before you evaluate WP Ghost is its philosophy. It is built around attack-surface reduction: renaming or hiding the default WordPress paths (like /wp-admin and /wp-login.php), stripping the tell-tale signs that a site runs WordPress, and blocking the bots that scan for those signals — combined with a firewall and login protection. It is not primarily a malware scanner, a backup tool, or a full managed security service. Whether that approach is a good fit for you is the real question this review tries to answer, because on the question of legitimacy, WP Ghost clears the bar easily.

Key Features: What You Actually Get

WP Ghost bundles a fairly wide range of hardening and protection features. Based on the vendor’s own feature documentation and the WordPress.org listing, the core capabilities break down roughly as follows.

Path and URL security. This is the flagship feature. WP Ghost renames sensitive WordPress paths — wp-admin, wp-login.php, wp-content, wp-includes, plugin and theme directories — to custom URLs of your choosing, so automated scanners hitting the defaults come up empty. It also removes “WordPress fingerprints”: version meta tags, default file paths, and other signals that let a bot confirm the site is WordPress before targeting known exploits.

Firewall. The plugin includes a 7G/8G firewall designed to block common attack patterns like SQL injection and cross-site scripting (XSS) at the server level, before the request reaches your WordPress application code.

Brute-force and bot protection. It protects login, registration, and WooCommerce forms against automated brute-force attempts, and can add reCAPTCHA or a simple math CAPTCHA to those forms. It also blocks known malicious bots.

Two-factor authentication (2FA). WP Ghost supports multiple second-factor methods, including email codes, authenticator apps, and passkeys (Face ID / Touch ID), adding a real barrier beyond just a password.

Geo/country blocking. A paid feature that lets you restrict access to your site — or just to the login and admin areas — by country, which can sharply cut hostile traffic if your audience is regional.

Security threats log. Also a paid feature, this records blocked attacks and suspicious requests, split into user events and security threats, with filtering and export. It’s what turns “the plugin is doing something” into “here’s exactly what it blocked.”

AI-crawler blocking. A newer addition aimed at blocking 30+ AI training crawlers (such as GPTBot and Claude-Web) at the firewall level, for site owners who don’t want their content scraped for model training.

WP Ghost 9.0 additions. The 9.0 release added a Security Optimization Score (a real-time 0-100 rating of your configuration with recommendations), a full Login Page Designer for customizing the branded, secured login URL, and refinements to the threats log.

The practical takeaway is that WP Ghost covers most of the “hardening” checklist you’d want on a WordPress site — with the important caveat that its firewall is a rule-based server-level filter, not a cloud-based managed WAF with a security team tuning rules in real time. And it deliberately does not try to be a malware scanner. If your mental model is “one plugin to do everything,” WP Ghost is broad but not total; it’s the prevention and access-control layer.

WP Ghost Pricing in 2026

WP Ghost uses a freemium model: a genuinely usable free version on WordPress.org, plus paid tiers that unlock the more advanced protections. The prices below are the regular rates from the official pricing page as of July 2026. Note that the vendor very frequently runs promotions well below these regular prices, so the number you see at checkout may be lower.

PlanSites coveredRegular priceNotes
Free (WordPress.org)No hard site limit$0Core path hiding and basic hardening; advanced features locked
Ghost 1 (annual)1 site$29.99/yearAdvanced firewall, brute-force & bot blocking, country blocking
Ghost 5 (annual)5 sites$149/yearEverything in Ghost 1 plus priority email support
Ghost All (annual)Up to 1,000 sites$640/yearEverything above plus priority support; for agencies/large portfolios
Ghost 5 Lifetime5 sites$600 one-timeLifetime updates, no renewals (frequently discounted to ~$180 on sale)
Ghost 10 Lifetime10 sites$1,196 one-timePriority email support; lifetime updates (frequently discounted to ~$360 on sale)
Ghost 1000 LifetimeUp to 1,000 sites$2,560 one-timePriority support; lifetime updates (frequently discounted to ~$640 on sale)

A few things stand out. First, the entry price is genuinely low for what you get — $29.99/year for a single site puts WP Ghost well below the annual cost of many premium WordPress security suites. Second, the per-site economics get aggressive at scale, which is why the plugin is popular with agencies and freelancers managing lots of client sites; the lifetime multi-site licenses in particular can pencil out favorably if you maintain a large portfolio for years. Third, all paid plans are backed by a stated 30-day money-back guarantee, which lowers the risk of trying it — useful given that compatibility with your specific host and stack is the main variable.

One honest note on pricing presentation: because the vendor almost always displays discounted “sale” pricing (for example, a single-site plan shown around $23.99 and multi-site plans discounted 65-70% during promotions), it’s worth checking the current live price rather than assuming the sale is permanent. The regular prices above are the more durable reference point.

What Customers Say About WP Ghost

The most useful and highest-volume independent signal for any WordPress plugin is its WordPress.org rating, and here WP Ghost does well. As of July 2026, it holds 4.5 out of 5 stars across 371 reviews on WordPress.org — 315 five-star, 5 four-star, 8 three-star, 9 two-star, and 34 one-star. That’s a large enough sample to be meaningful, and the distribution is heavily weighted toward the top. You can read the full review history directly.

Positive reviewers consistently praise a few things: the plugin does what it says (people report a visible drop in bot and brute-force traffic after hiding paths), it bundles a lot of protection into a single tool, the setup is approachable even for non-technical owners, and — a recurring theme — the support team is responsive and helpful. “Top-notch support” comes up repeatedly, which is a genuinely positive signal for a security product, where you want a fast answer when something goes wrong.

The negative reviews are worth taking seriously precisely because they cluster around a consistent, believable issue rather than random dissatisfaction. The dominant complaint is compatibility: some reviewers report conflicts on certain server environments (NGINX-based or specific managed hosts have been named), and because the plugin rewrites URLs at the server level, an aggressive configuration can interfere with caching, page builders, or REST API calls and, in the worst case, temporarily lock someone out of their own admin area. This is the flip side of how the plugin works — the same server-level rewriting that makes it fast and effective is also what can collide with a locked-down or unusual hosting setup. The takeaway isn’t “avoid it,” it’s “set it up incrementally and keep a backup.”

Outside WordPress.org, the independent picture is thinner and should be weighted accordingly. On Trustpilot, the hidemywpghost.com profile carries a 3.8 TrustScore but from only 2 reviews, both five-star and both dating to 2022-2023, with none in the last year; the profile is also marked “Unclaimed.” Two old reviews are not a basis for any conclusion, positive or negative. On software-directory sites like AppSumo, Capterra, and G2, the product shows higher aggregate scores (AppSumo lists roughly 4.8 from a few hundred reviews), but AppSumo audiences in particular skew toward lifetime-deal buyers, so those ratings tend to run rosier than a general population. Dedicated Reddit and security-forum discussion of WP Ghost specifically is relatively sparse; where the security community does engage, the debate is less about this product’s legitimacy and more about the broader value of path-hiding as a technique — the “security through obscurity” question covered in the next section.

Netting it out: the review evidence that matters most (a large, top-heavy WordPress.org sample) is clearly positive, the main documented risk is host/stack compatibility rather than the vendor’s honesty or the product’s core function, and the flashier third-party ratings should be read as supportive but softer signals.

Is WP Ghost Legit and Safe?

On the core legitimacy question, WP Ghost passes comfortably. It is a real, long-running product from an identifiable, established company (AISQ / Squirrly Limited, UK-registered), it has a decade-long release history, it’s actively maintained with updates as recent as July 2026, and it has a large, independently visible user base — 100,000+ active installations of the free version on WordPress.org and 250,000+ sites across all versions by the vendor’s count. None of that resembles a scam or an abandoned plugin. A 4.5-star rating from 371 WordPress.org reviews is a strong, hard-to-fake reputation signal, and the vendor backs paid purchases with a 30-day money-back guarantee.

The more nuanced question is whether the approach is sound, and here you should go in clear-eyed. WP Ghost’s headline features — hiding paths, removing WordPress fingerprints, blocking scanner bots — sit squarely in a technique that security professionals sometimes criticize as “security through obscurity.” The critique is fair as far as it goes: hiding your login URL does not patch a vulnerable plugin, and a determined, targeted attacker who has already identified your site can often work around obscurity. The vendor’s counter-argument is also fair: the overwhelming majority of WordPress attacks are automated bots that fingerprint sites by their default paths before firing exploits, so denying those bots an easy confirmation genuinely reduces the volume of automated attacks a site faces. Both things are true. Obscurity is a weak only defense but a reasonable additional layer.

Where WP Ghost is strongest is when you treat it as one part of a layered setup rather than a silver bullet. Its firewall, brute-force protection, and 2FA are real, non-obscurity security controls, and combining them with hidden paths, current updates, strong passwords, and — critically — off-site backups gives you a defensible posture. Where people get into trouble is expecting it to do jobs it doesn’t do: it is not a malware scanner that finds and cleans an existing infection, it is not a backup tool, and it is not a managed cloud WAF with analysts tuning rules for you. If your site is already compromised, WP Ghost is not the right first tool.

The main safety risk with WP Ghost, ironically, is operational rather than adversarial: a misconfigured rollout can break parts of your own site or lock you out of admin, which is exactly what a subset of the negative reviews describe. That’s manageable — enable features in stages, test after each change, note the custom login URL you set so you don’t lose it, and keep a working backup — but it does mean this is not a strictly “install and forget” plugin on every host. On a mainstream Apache/LiteSpeed setup it’s usually smooth; on a locked-down managed platform or an unusual NGINX configuration, budget time to test.

Bottom Line

WP Ghost earns a 4.3 out of 5 from LegitScout. It’s a legitimate, mature, and genuinely well-reviewed WordPress security plugin from an established vendor, with a strong 4.5-star record across 371 WordPress.org reviews, an actively maintained codebase, a large user base, affordable pricing from $29.99/year, a real free tier to test with, and a 30-day money-back guarantee. For hiding login and admin paths, blocking automated bots and brute-force attempts, and adding a firewall and 2FA, it does exactly what it advertises, and its responsive support is a recurring bright spot in user feedback.

It falls short of a perfect score for two honest reasons rather than any doubt about its legitimacy. First, its core approach is attack-surface reduction, which is a valuable layer but not a complete security strategy — it deliberately isn’t a malware scanner, backup tool, or managed WAF, and buyers who expect one plugin to do everything will be disappointed. Second, because it rewrites paths at the server level, it carries a real (if manageable) risk of conflicting with certain hosts, caches, or page builders, which is the dominant theme in its negative reviews.

Buy WP Ghost if you’re a site owner or agency who wants an affordable, well-supported hardening layer and understands it as one part of a broader setup that still includes updates and backups. Be more cautious if you’re on a heavily locked-down managed host, or if you’re hoping to replace a full security suite with a single tool. Given the 30-day guarantee and the free version, the low-risk move is to test it on your actual site and stack — enabling features gradually — before committing to a paid plan, and to verify the current price directly on the official pricing page, since the vendor’s promotional pricing changes often.

What we like

  • Long track record: the plugin has shipped since 2016 and is actively maintained by AISQ (formerly Squirrly), a UK-registered company, with the free version updated as recently as July 8, 2026 and tested against WordPress 7.0.1
  • Strong, high-volume independent rating on the one platform that matters most for a plugin: 4.5 out of 5 stars from 371 reviews on WordPress.org as of July 2026, with 315 of those being five-star
  • Broad, genuinely useful feature set for the price: path/URL hiding for wp-admin and wp-login, a 7G/8G firewall, brute-force and bot protection, two-factor authentication, geo/country blocking, and a security threats log
  • A real free version on WordPress.org with 100,000+ active installations, so you can test the core path-hiding and hardening features before paying anything
  • Clear, affordable paid pricing starting at $29.99/year for a single site, backed by a stated 30-day money-back guarantee, with lifetime license options also available

What to watch out for

  • Its headline feature is attack-surface reduction (hiding paths, blocking bots, removing WordPress fingerprints), which security professionals debate as partly 'security through obscurity' — it is not a full malware scanner or a replacement for good hosting, backups, and updates
  • Server compatibility can be a real friction point: some WordPress.org reviewers report conflicts on NGINX-based or managed hosts, and aggressive path-rewriting can break page builders, caching, or REST API calls if misconfigured, so it needs careful setup and testing
  • Third-party review volume outside WordPress.org is thin and skewed: its Trustpilot profile carries only 2 reviews as of July 2026, both from 2022-2023, and is marked 'Unclaimed,' so it is not a meaningful independent signal
  • Several of the most useful features (country blocking, AI-crawler blocking, the security threats log, priority support) are gated behind the paid tiers rather than the free version

Frequently Asked Questions

Is WP Ghost legit?

Yes. WP Ghost (formerly Hide My WP Ghost) is a real, long-running WordPress security plugin, first released around 2016 and developed since 2018 by AISQ, the rebranded Squirrly company, which operates as Squirrly Limited, a UK-registered business. It has a substantial, independently verifiable footprint: a 4.5-out-of-5 rating from 371 reviews and 100,000+ active installations on WordPress.org as of July 2026, plus consistent updates (the free version was last updated July 8, 2026). It is not a scam or a fly-by-night product. The more useful question isn't whether it's legitimate — it clearly is — but whether its approach fits your needs, since its core value is reducing your site's attack surface rather than scanning for or removing malware.

Does WP Ghost actually make my WordPress site more secure, or is it just 'security through obscurity'?

It's some of both, and being honest about that matters. A large share of WordPress attacks are automated bots scanning for default paths like /wp-admin and /wp-login.php to fingerprint the site before launching exploits. Hiding those paths, removing version tags, and blocking bots genuinely cuts down that automated noise, which the vendor frames as legitimate 'site hardening.' But obscuring paths is not the same as patching a vulnerability, and it won't stop a determined, targeted attacker or fix an insecure plugin. WP Ghost is most valuable as one hardening layer alongside a firewall (which it also provides), 2FA, current updates, and off-site backups — not as your only line of defense.

How much does WP Ghost cost in 2026?

There is a free version on WordPress.org with core path-hiding and basic hardening. Paid annual plans start at $29.99/year (regular price) for a single site, with a 5-site plan at $149/year and a plan covering up to 1,000 sites at $640/year, according to the official pricing page as of July 2026. The vendor frequently runs promotions below those regular prices, and it also sells lifetime licenses (for example, a 5-site lifetime plan around $180). All paid plans are covered by a stated 30-day money-back guarantee.

Will WP Ghost break my site or slow it down?

It can, if it isn't set up carefully, which is the most common theme in its negative reviews. Because the plugin rewrites URLs and paths at the server level, it can conflict with certain hosts (some reviewers cite NGINX or managed platforms), page builders, caching layers, or REST API calls. The vendor advertises a very low average performance impact (around 0.05 seconds) because the rewriting happens at the server rewrite level rather than in runtime PHP. The practical advice is to enable features gradually, test your login, admin, and key pages after each change, and keep a backup so you can roll back.

What's the difference between WP Ghost and Hide My WP Ghost?

They are the same product. The plugin was long known as 'Hide My WP Ghost,' and the vendor rebranded it to 'WP Ghost' because that's what its paying customers were calling it. You'll still see both names in the wild — the WordPress.org listing, for instance, reads 'WP Ghost (Hide My WP Ghost),' and the older hidemywpghost.com domain is still in use. It's one product and one team, not two competing plugins.

Does WP Ghost replace a malware scanner or a full security suite?

No, and it's important to be clear about that. WP Ghost focuses on prevention and hardening: hiding paths, firewalling requests, blocking brute-force attempts, and logging threats. It is not primarily a malware scanner that inspects your files for existing infections, nor is it a backup tool. If your priority is detecting and cleaning an existing hack, you'd pair it with (or choose) a scanning-focused tool. WP Ghost is best understood as the 'lock the doors and hide the entrances' layer, not the 'scan the house for intruders already inside' layer.