Amazing Security: In development ยท Comparison reviewed September 28, 2026
Amazing Security vs Custonis.
Custonis already checks for exposed WordPress files. It also documents HTTP validation and soft-404 handling. Amazing Security's independent verifier is a plan we still need to prove in a controlled comparison.
Need an exposure scan now? Custonis is available on WordPress.org. Amazing Security is in development and has no download.
What each project covers
| Area | Custonis 1.1.7 | Amazing Security |
|---|---|---|
| Public backup and log checks | Available; finds backup files, debug logs, and config copies. Source | Planned |
| HTTP and soft-404 validation | Available per its release notes, including soft-404 handling. Source | Planned from an independent verifier service |
| Scan history and exposure age | Available per its listing. Source | History and regression alerts planned |
| Database health checks | Available for large tables, autoload size, transients, and revisions. Source | Not in the Amazing Security first release |
| Firewall, login, malware, vulnerabilities | Not claimed as product features in the reviewed listing. Source | Planned as separate free modules |
| External service and MCP | Local scans; listing says no external API calls. Source | Optional public verifier and MCP planned, each with explicit consent |
Method and disclosure: AmazingPlugins is building Amazing Security. Custonis claims are from its WordPress.org listing and release notes, reviewed September 28, 2026. In a local WordPress fixture, Custonis 1.1.7 found dummy public log and SQL files, then stopped reporting the log after it was removed. We did not complete an HTTPS/CDN mismatch or normal dashboard-flow comparison. This page does not claim one scanner is more accurate.
The difference we need to test
Custonis runs locally and says it does not send data to an external API. Our proposed verifier would test from a separate network after explicit opt-in. That may help on hosting or CDN setups where the origin and a visitor see different responses. It also creates a privacy and service-availability tradeoff.
We need a controlled CDN-versus-origin test before saying that approach gives owners a clearer answer. The broader Amazing Security plan also includes hardening checks, login protection, malware and vulnerability findings, and optional MCP. Those modules are not released. For practical steps today, see the WordPress security checklist.