FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Analytics
  4. iThemes Security

iThemes Security

AnalyticsWebsite

Related services

34SP.com

34SP.com is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 34SP.com supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 34SP.com enables informed decisions that improve experience and drive results.

Analytics
5

51.LA

51.LA is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 51.LA supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 51.LA enables informed decisions that improve experience and drive results.

Analytics

52Degrees

52Degrees is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. 52Degrees offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, 52Degrees empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

a3 Lazy Load

a3 Lazy Load is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, a3 Lazy Load delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Analytics
A

Able CDP

Able CDP is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Able CDP supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Able CDP enables informed decisions that improve experience and drive results.

Analytics
A

Abralytics

Abralytics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. Abralytics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, Abralytics empowers organizations to optimize strategy and maximize return on investment.

Analytics
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does iThemes Security do?

iThemes Security, now known as Solid Security, is a WordPress security plugin that protects sites against brute force attacks, malware and unauthorised access. It logs IP addresses and login activity, sets security cookies, and can share IP addresses with a network brute force protection service. Because it processes personal data such as IP addresses, the GDPR applies, although its security cookies are generally treated as strictly necessary.

What is iThemes Security?

iThemes Security, rebranded as Solid Security, is one of the most widely used security plugins for WordPress. It hardens a site against brute force attacks, enforces strong passwords and two factor authentication, scans for file changes and malware, and logs suspicious activity. It runs on your own WordPress server rather than as an external service.

What data and cookies does it collect?

The plugin logs IP addresses, usernames and timestamps of login attempts and other security events, which are personal data. It sets cookies related to login security and lockouts. If the network brute force protection feature is enabled, it reports offending IP addresses to the Solid Security network so that known attackers can be blocked across sites.

GDPR and ePrivacy implications

Logging IP addresses and security events is processing of personal data under the GDPR, but it can usually rely on legitimate interest because protecting the site is a clear and necessary purpose. The security cookies are generally treated as strictly necessary under Article 5(3) of the ePrivacy Directive, so they do not require consent, but you must still disclose the processing.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Because the plugin cookies and IP logging serve site security, they are normally treated as strictly necessary and do not need prior consent. You should still inform visitors and users in your privacy notice that security logs and the network brute force feature process IP addresses, and set an appropriate retention period for the logs.

Data transfers

When the network brute force protection feature is enabled, offending IP addresses are shared with the Solid Security network, which operates from the United States. That transfer must rely on Standard Contractual Clauses or the EU US Data Privacy Framework with a Transfer Impact Assessment. If you keep the plugin fully local, no transfer to a third country occurs.

Practical compliance steps

Decide whether to enable the network brute force protection feature, and if you do, document the US transfer and its safeguards. Set a retention period for the security logs, describe the IP logging and security cookies in your privacy notice, and rely on legitimate interest with a documented balancing test. Review the configuration when the plugin updates.

GDPR consent category

Analytics

Websites using iThemes Security must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR)
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law)

DPIA considerations

iThemes Security logs IP addresses, usernames and timestamps of login attempts and other security events, which are personal data. Key DPIA considerations: (1) the security cookies are generally strictly necessary and do not require consent; (2) IP logging can rely on the legitimate interest of protecting the site; (3) the network brute force feature shares IPs with a service in the United States; (4) a retention period for the logs must be set. A DPIA is advisable for large scale logging.

Sample consent text

We use iThemes Security (Solid Security) to protect our site. The plugin logs IP addresses and login activity for security purposes and may share IPs with a network protection service in the United States. This security processing relies on our legitimate interest; you can find more details in our privacy notice.

Technical details

Tracking methodWordPress plugin (server side), security cookies and logs
Server locationYour own WordPress server (self hosted); network brute force protection shares data with Solid Security (United States)
Data transferred outside the EUiThemes Security runs on your own WordPress server, so most processing is local. If the network brute force protection feature is enabled, IP addresses are shared with the Solid Security network in the United States, a transfer that must rely on Standard Contractual Clauses or the EU US Data Privacy Framework.

Third-party domains contacted

solidwp.comapi.ithemes.com

Cookies placed

NameTypeDurationPurpose
itsec_session_stateFunctional / SecuritySessionSupports login security and detects suspicious session activity.
itsec_bfSecurity1 daySupports brute force protection by tracking repeated failed login attempts from a device.

iThemes Security collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

What cookies does iThemes Security set?

iThemes Security sets cookies related to login security and lockouts, which are generally treated as strictly necessary for protecting the site. Because they serve a security purpose, they usually do not require consent, but you should still describe them in your privacy notice.

Does iThemes Security require consent?

Usually not for the security cookies and IP logging, because they are strictly necessary to protect the site and can rely on legitimate interest. If you add non essential features such as external analytics, those would need consent. Always disclose the security processing.

What is the legal basis for iThemes Security?

The lawful basis for logging IP addresses and security events is normally legitimate interest under Article 6(1)(f) GDPR, supported by a balancing test, because site security is a legitimate and necessary purpose. The cookies are strictly necessary, so no separate ePrivacy consent is needed for them.

Does iThemes Security transfer data outside the EU?

A transfer occurs only if you enable the network brute force protection feature, which shares offending IP addresses with the Solid Security network in the United States. That transfer must rely on Standard Contractual Clauses or the EU US Data Privacy Framework. A fully local configuration involves no third country transfer.

Do I need a DPIA for iThemes Security?

A DPIA is usually not required for standard security logging, but it is advisable if you log at large scale or combine the logs with other monitoring. Documenting the IP logging, the retention, the legitimate interest balancing and any network feature transfer supports accountability.

How do I implement iThemes Security compliantly?

Configure iThemes Security with an appropriate log retention period, decide whether to enable the network brute force feature, and document the legitimate interest and any US transfer. Disclose the IP logging and security cookies in your privacy notice. Keep the plugin updated and review its data handling settings.

Are there alternatives to iThemes Security?

Other WordPress security plugins include Wordfence, Sucuri Security, All In One Security and MalCare. They all log IP addresses and security events as personal data, so the compliance approach is similar: legitimate interest, retention limits and disclosure, with attention to any external network features.

How do I update my cookie policy for iThemes Security?

You do not necessarily need a cookie policy entry for strictly necessary security cookies, but you should describe in your privacy notice that the plugin logs IP addresses and security events, the retention period, and whether the network brute force feature shares IPs with a US service. Keep this aligned with your configuration.