Salt Shaker
View on WordPress.orgScores higher than 31% of indexed plugins
About
Salt Shaker enhances WordPress security by changing WordPress security keys and salts manually and automatically.
Security History
What It Does
Salt Shaker rotates the WordPress authentication secret keys and salts stored in wp-config.php, either on demand from the settings page or on a schedule. New keys invalidate all existing cookies, which forces every logged-in user to re-authenticate. This makes stolen session cookies and old password hashes worthless.
Who It's For
This plugin fits administrators of sites where session integrity is mission critical, such as e-commerce, healthcare, legal, and financial properties, particularly on shared or managed hosting where former admin or developer access may persist. It is also a reasonable fast response tool after a suspected breach because it can cut over to fresh keys in one click.
Who Should Skip It
Casual bloggers and small brochure sites running on well-managed hosting already handle salts automatically and gain little from scheduled rotation, which forcibly logs out editors and can disrupt live sessions. Sites that depend on persistent admin logins during content publishing will find the automated rotation annoying.
The Bottom Line
Salt Shaker does one narrow job and does it well on a current WordPress baseline, earning a quality score of 76.44 out of 100. The zero support track record is a real gap for a security-critical tool, and you should not rely on it as your only hardening layer. Pair it with a firewall and malware scanner if you run a high-value site.
Related Plugins
Pick this when you want a much broader hardening suite with login protection, firewall, and vulnerability scanning rather than just salt rotation.
Choose Wordfence if you need a full endpoint firewall, malware signatures, and live traffic monitoring alongside cookie hardening.
Go with Jetpack when you also want automated backups, downtime monitoring, and brute-force login protection bundled into one plugin.
Pick AIOS if you want free layered security with login lockdown, firewall rules, and database hardening in a single dashboard.
This is not a true alternative; it solves a different problem of sanitizing SVG uploads, so only relevant if your gap is SVG handling, not salt rotation.