BOLT scans WordPress sites and servers for real security misconfigurations, ranks risk, and applies one-click fixes. Free core plugin plus a paid Pro tier…
BOLT (Blueternal BOLT Security Toolkit) is a WordPress security plugin built by Blueternal Solutions, an IT services and hosting company. BOLT runs inside wp-admin and scans both the WordPress installation and the surrounding server environment — PHP configuration, database version, memory limits, OPcache, file permissions, authentication settings, security headers, and update status — for real misconfigurations rather than generic warnings.
Findings are scored and prioritized, and BOLT's attack-path model groups individual findings into realistic compromise chains (Attack Paths), partial risk conditions (Near Misses), and impact multipliers (Amplifiers), so site owners can see which issues actually matter together instead of treating every warning as equal. Where it is safe to do so, BOLT applies one-click hardening fixes (disabling the file editor, blocking directory listing, restricting XML-RPC and the REST API, adding HSTS headers, and more) and keeps a full undo history with file diffs for every automated change.
The free WordPress.org plugin covers a single site: full scanning, scoring, hardening, baseline drift tracking, and weekly email reports. BOLT Pro is a paid add-on that layers hosted services on top of the same free scanner — full CVE/vulnerability advisory detail, on-demand domain and IP reputation checks, AI-generated plain-English security briefings, real-time Slack/webhook alerts, daily and monthly scan schedules, multi-recipient white-labeled reporting, and an unlimited activity timeline. Pro is sold as an annual per-site-count license (Single, Agency, Developer tiers) through Stripe checkout, independent of Blueternal's separate bespoke IT consulting and hosting services.