NimblePlugins WordPress tool
Security — Pro
Everything in Nimble Security Free, plus automatic incident correlation, conservative recovery-gated response automation and country blocking — with the signed Nimble Threat Cloud client already built in.
Self-hosted · No telemetry · GPL licensed
Running more than one of these?
All 3 Pro plugins together are $309 a year — separately they are $477, so you save $168.
Compare the bundlesNimble Security Pro extends Nimble Security Free without replacing any part of it. Free stays the owner of every enforcement engine and all security state; Pro adds the judgement layer on top — turning a stream of individual detections into correlated incidents, and letting a deliberately narrow class of critical findings be handled without waiting for you.
What Pro adds today
- Automatic incident correlation — high and critical malware, integrity, vulnerability and authentication events are grouped into correlated incidents automatically. Repeated detections on the same target update one incident instead of flooding you with duplicates, and each incident carries a risk score so the serious ones surface first.
- Recovery-gated response automation — one intentionally narrow policy: a newly detected critical malware file can be quarantined automatically, but only when Free already classifies that exact file as safe for file-level isolation and a recovery provider such as Nimble Backup is connected. No recovery point available means the action is recorded as skipped, not performed.
- Manual-first for everything else — active plugins and themes, privileged-session containment and Emergency Lockdown stay under your control. Pro never widens the blast radius Free allows.
- Pro diagnostics — signature-verification availability, threat-feed state and cloud authentication status appear alongside Free's own readiness checks.
Nimble Threat Cloud — coming soon
The complete signed threat-intelligence client ships inside Pro today, but the cloud service itself is not live yet. The plugin says so plainly in its own interface rather than showing you an empty configuration screen, and your site keeps working exactly as before until the service launches.
What is already implemented and waiting: HTTPS-only transport, detached Ed25519 signature verification with overlapping trust-key rotation, strict data-only schemas for advisories, malware definitions, virtual patches and IP reputation, monotonic sequence and rollback protection, and a bounded last-known-good cache. The feed carries data only — by design it cannot deliver executable code into your site.
Requirements
- Nimble Security 1.1.12 or newer, installed and activated first.
- WordPress 6.6+, PHP 8.1+.
- One site per licence. Licensing lives entirely in Pro: the free plugin contains no licence code and is never gated by it. Activate the key under Nimble Security › Licence.
Self-hosted. No telemetry. GPL licensed. Your security data never leaves your server.