The protection engine is free on every plan: 16 attack sensors, the Web Application Firewall with its baseline ruleset, IP blocking and the complete 2FA suite never sit behind a paywall. When a report documents an attack wave, the sites contributing that data were also the ones blocking it.
Hive PRO adds rule depth and freshness on top: extended PL2 firewall signatures — including the webshell and upload-abuse group that covers the post-exploitation stage of attacks like wp2shell — delivered through a daily, Ed25519-signed rule sync. Free installs receive new rules with plugin releases; PRO installs receive them as they ship.