Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
iThemes Security, now known as Solid Security, is a WordPress security plugin that protects sites against brute force attacks, malware and unauthorised access. It logs IP addresses and login activity, sets security cookies, and can share IP addresses with a network brute force protection service. Because it processes personal data such as IP addresses, the GDPR applies, although its security cookies are generally treated as strictly necessary.
iThemes Security, rebranded as Solid Security, is one of the most widely used security plugins for WordPress. It hardens a site against brute force attacks, enforces strong passwords and two factor authentication, scans for file changes and malware, and logs suspicious activity. It runs on your own WordPress server rather than as an external service.
The plugin logs IP addresses, usernames and timestamps of login attempts and other security events, which are personal data. It sets cookies related to login security and lockouts. If the network brute force protection feature is enabled, it reports offending IP addresses to the Solid Security network so that known attackers can be blocked across sites.
Logging IP addresses and security events is processing of personal data under the GDPR, but it can usually rely on legitimate interest because protecting the site is a clear and necessary purpose. The security cookies are generally treated as strictly necessary under Article 5(3) of the ePrivacy Directive, so they do not require consent, but you must still disclose the processing.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because the plugin cookies and IP logging serve site security, they are normally treated as strictly necessary and do not need prior consent. You should still inform visitors and users in your privacy notice that security logs and the network brute force feature process IP addresses, and set an appropriate retention period for the logs.
When the network brute force protection feature is enabled, offending IP addresses are shared with the Solid Security network, which operates from the United States. That transfer must rely on Standard Contractual Clauses or the EU US Data Privacy Framework with a Transfer Impact Assessment. If you keep the plugin fully local, no transfer to a third country occurs.
Decide whether to enable the network brute force protection feature, and if you do, document the US transfer and its safeguards. Set a retention period for the security logs, describe the IP logging and security cookies in your privacy notice, and rely on legitimate interest with a documented balancing test. Review the configuration when the plugin updates.
Websites using iThemes Security must obtain user consent under GDPR regulations.
DPIA considerations
iThemes Security logs IP addresses, usernames and timestamps of login attempts and other security events, which are personal data. Key DPIA considerations: (1) the security cookies are generally strictly necessary and do not require consent; (2) IP logging can rely on the legitimate interest of protecting the site; (3) the network brute force feature shares IPs with a service in the United States; (4) a retention period for the logs must be set. A DPIA is advisable for large scale logging.
Sample consent text
We use iThemes Security (Solid Security) to protect our site. The plugin logs IP addresses and login activity for security purposes and may share IPs with a network protection service in the United States. This security processing relies on our legitimate interest; you can find more details in our privacy notice.
Third-party domains contacted
solidwp.comapi.ithemes.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| itsec_session_state | Functional / Security | Session | Supports login security and detects suspicious session activity. |
| itsec_bf | Security | 1 day | Supports brute force protection by tracking repeated failed login attempts from a device. |
iThemes Security collects user analytics data — you legally need a consent banner. Try FlowConsent free.
iThemes Security sets cookies related to login security and lockouts, which are generally treated as strictly necessary for protecting the site. Because they serve a security purpose, they usually do not require consent, but you should still describe them in your privacy notice.
Usually not for the security cookies and IP logging, because they are strictly necessary to protect the site and can rely on legitimate interest. If you add non essential features such as external analytics, those would need consent. Always disclose the security processing.
The lawful basis for logging IP addresses and security events is normally legitimate interest under Article 6(1)(f) GDPR, supported by a balancing test, because site security is a legitimate and necessary purpose. The cookies are strictly necessary, so no separate ePrivacy consent is needed for them.
A transfer occurs only if you enable the network brute force protection feature, which shares offending IP addresses with the Solid Security network in the United States. That transfer must rely on Standard Contractual Clauses or the EU US Data Privacy Framework. A fully local configuration involves no third country transfer.
A DPIA is usually not required for standard security logging, but it is advisable if you log at large scale or combine the logs with other monitoring. Documenting the IP logging, the retention, the legitimate interest balancing and any network feature transfer supports accountability.
Configure iThemes Security with an appropriate log retention period, decide whether to enable the network brute force feature, and document the legitimate interest and any US transfer. Disclose the IP logging and security cookies in your privacy notice. Keep the plugin updated and review its data handling settings.
Other WordPress security plugins include Wordfence, Sucuri Security, All In One Security and MalCare. They all log IP addresses and security events as personal data, so the compliance approach is similar: legitimate interest, retention limits and disclosure, with attention to any external network features.
You do not necessarily need a cookie policy entry for strictly necessary security cookies, but you should describe in your privacy notice that the plugin logs IP addresses and security events, the retention period, and whether the network brute force feature shares IPs with a US service. Keep this aligned with your configuration.