wordpress-premium / wordfence

This repository is a mirror of the full version of Wordfence as hosted on GitLab. Wordfence is one of the most reliable security plugins for WordPress.
GNU General Public License v3.0
9 stars 2 forks source link
security wordfence wordpress wordpress-plugin

=== Wordfence Security - Firewall, Malware Scan, and Login Security === Contributors: mmaunder, wfryan, wfmatt, wfmattr Tags: security, waf, malware, 2fa, two factor, login security, firewall, brute force, scanner, scan, web application firewall, protection, stop hackers, prevent hacks, secure wordpress, wordpress security Requires at least: 3.9 Requires PHP: 5.3 Tested up to: 6.1 Stable tag: 7.9.1 License: GPLv3 License URI: https://www.gnu.org/licenses/gpl-3.0.html

Firewall, Malware Scanner, Two Factor Auth and Comprehensive Security Features, powered by our 24 hour team. Make security a priority with Wordfence.

== Description ==

THE MOST POPULAR WORDPRESS FIREWALL & SECURITY SCANNER

WordPress security requires a team of dedicated analysts researching the latest malware variants and WordPress exploits, turning them into firewall rules and malware signatures, and releasing those to customers in real-time. Wordfence is widely acknowledged as the number one WordPress security research team in the World. Our plugin provides a comprehensive suite of security features, and our team's research is what powers our plugin and provides the level of security that we are known for.

At Wordfence, WordPress security isn't a division of our business - WordPress security is all we do. We employ a global 24 hour dedicated incident response team that provides our priority customers with a 1 hour response time for any security incident. The sun never sets on our global security team and we run a sophisticated threat intelligence platform to aggregate, analyze and produce ground breaking security research on the newest security threats.

Wordfence Security includes an endpoint firewall, malware scanner, robust login security features, live traffic views, and more. Our Threat Defense Feed arms Wordfence with the newest firewall rules, malware signatures and malicious IP addresses it needs to keep your website safe. Rounded out by 2FA and a suite of additional features, Wordfence is the most comprehensive WordPress security solution available.

WORDPRESS FIREWALL

WORDPRESS SECURITY SCANNER

LOGIN SECURITY

WORDFENCE CENTRAL

SECURITY TOOLS

== Installation ==

Secure your website using the following steps to install Wordfence:

  1. Install Wordfence automatically or by uploading the ZIP file.
  2. Activate the Wordfence through the 'Plugins' menu in WordPress. Wordfence is now activated.
  3. Go to the scan menu and start your first scan. Scheduled scanning will also be enabled.
  4. Once your first scan has completed, a list of threats will appear. Go through them one by one to secure your site.
  5. Visit the Wordfence options page to enter your email address so that you can receive email security alerts.
  6. Optionally, change your security level or adjust the advanced options to set individual scanning and protection options for your site.
  7. Click the "Live Traffic" menu option to watch your site activity in real-time. Situational awareness is an important part of website security.

To install Wordfence on WordPress Multi-Site installations:

  1. Install Wordfence via the plugin directory or by uploading the ZIP file.
  2. Network Activate Wordfence. This step is important because until you network activate it, your sites will see the plugin option on their plugins menu. Once activated that option disappears.
  3. Now that Wordfence is network activated it will appear on your Network Admin menu. Wordfence will not appear on any individual site's menu.
  4. Go to the "Scan" menu and start your first scan.
  5. Wordfence will do a scan of all files in your WordPress installation including those in the blogs.dir directory of your individual sites.
  6. Live Traffic will appear for ALL sites in your network. If you have a heavily trafficked system you may want to disable live traffic which will stop logging to the DB.
  7. Firewall rules and login rules apply to the WHOLE system. So if you fail a login on site1.example.com and site2.example.com it counts as 2 failures. Crawler traffic is counted between blogs, so if you hit three sites in the network, all the hits are totalled and that counts as the rate you're accessing the system.

== Frequently Asked Questions ==

Visit our website to access our official documentation which includes security feature descriptions, common solutions and comprehensive help.

= How does Wordfence Security protect sites from attackers? =

The WordPress security plugin provides the best protection available for your website. Powered by the constantly updated Threat Defense Feed, Wordfence Firewall stops you from getting hacked. Wordfence Scan leverages the same proprietary feed, alerting you quickly about security issues or if your site is compromised. The Live Traffic view gives you real-time visibility into traffic and hack attempts on your website. A deep set of additional tools round out the most comprehensive WordPress security solution available.

= What features does Wordfence Premium enable? =

We offer a Premium API key that gives you real-time updates to the Threat Defense Feed which includes a real-time IP blocklist, firewall rules, and malware signatures. Premium support, country blocking, more frequent scans, and spam and spamvertising checks are also included. Click here to sign-up for Wordfence Premium now or simply install Wordfence free and start protecting your website.

= How does the Wordfence WordPress Firewall protect websites? =

= What checks does the Wordfence Security Scanner perform? =

= What security monitoring features does Wordfence include? =

= What login security features are included =

= How will I be alerted if my site has a security problem? =

Wordfence sends security alerts via email. Once you install Wordfence, you will configure a list of email addresses where security alerts will be sent. When you receive a security alert, make sure you deal with it promptly to ensure your site stays secure.

= Do I need a security plugin like Wordfence if I’m using a cloud based firewall (WAF)? =

Wordfence provides true endpoint security for your WordPress website. Unlike cloud based firewalls, Wordfence executes within the WordPress environment, giving it knowledge like whether the user is signed in, their identity and what access level they have. Wordfence uses the user’s access level in more than 80% of the firewall rules it uses to protect WordPress websites. Learn more about the Cloud WAF identity problem here. Additionally, cloud based firewalls can be bypassed, leaving your site exposed to attackers. Because Wordfence is an integral part of the endpoint (your WordPress website), it can’t be bypassed. Learn more about the Cloud WAF bypass problem here. To fully protect the investment you’ve made in your website you need to employ a defense in depth approach to security. Wordfence takes this approach.

= What blocking features does Wordfence include? =

= What differentiates Wordfence from other WordPress Security plugins? =

= Will Wordfence slow down my website? =

No. Wordfence Security is extremely fast and uses techniques like caching its own configuration data to avoid database lookups and blocking malicious attacks that would slow down your site.

= What if my site has already been hacked? =

Wordfence Security is able to repair core files, themes and plugins on sites where security is already compromised. You can follow this guide on how to clean a hacked website using Wordfence. If you are cleaning your own site after a hack, note that site security cannot be assured unless you do a full reinstall if your site has been hacked. We recommend you only use Wordfence Security to get your site into a running state in order to recover the data you need to do a full reinstall. If you need help with a security issue, check out Wordfence Care, which offers hands-on support from our team, including dealing with a hacked site. For mission-critical sites, check out Wordfence Response.

= Does Wordfence Security support IPv6? =

Yes. We fully support IPv6 with all security functions including country blocking, range blocking, city lookup, whois lookup and all other security functions. If you are not running IPv6, Wordfence will work great on your site too. We are fully compatible with both IPv4 and IPv6 whether you run both or only one addressing scheme.

= Does Wordfence Security support Multi-Site installations? =

Yes. WordPress Multi-Site is fully supported. Using Wordfence you can scan every blog in your network for malware with one click. If one of your customers posts a page or post with a known malware URL that threatens your whole domain with being blocklisted by Google, we will alert you in the next scan.

= What support options are available for Wordfence users? =

Providing excellent customer service is very important to us. Our free users receive volunteer-level support in our support forums. Wordfence Premium customers get paid ticket-based support. Wordfence Care customers receive hands-on support including help with security incidents and a yearly security audit. Wordfence Response customers get 24/7/365 support from our incident response team, with a 1 hour response time, and a maximum of 24 hours to resolve a security issue.

= Where can I learn more about WordPress security? =

Designed for every skill level, The WordPress Security Learning Center is dedicated to deepening users’ understanding of security best practices by providing free access to entry-level articles, in-depth articles, videos, industry survey results, graphics and more.

= Where can I find the Wordfence Terms of Service and Privacy Policy? =

These are available on our website: Terms of Service and Privacy Policy

== Screenshots ==

Secure your website with Wordfence.

  1. The dashboard gives you an overview of your site's security including notifications, attack statistics and Wordfence feature status.
  2. The firewall protects your site from common types of attacks and known security vulnerabilities.
  3. The Wordfence Security Scanner lets you know if your site has been compromised and alerts you to other security issues that need to be addressed.
  4. Wordfence is highly configurable, with a deep set of options available for each feature. High level scan options are shown above.
  5. Brute Force Protection features protect you from password guessing attacks.
  6. Block attackers by IP, Country, IP range, Hostname, Browser or Referrer.
  7. The Wordfence Live Traffic view shows you real-time activity on your site including bot traffic and exploit attempts.
  8. Take login security to the next level with Two-Factor Authentication.
  9. Logging in is easy with Wordfence 2FA.

== Changelog ==

= 7.9.1 - March 1, 2023 =

= 7.9.0 - February 14, 2023 =

= 7.8.2 - December 13, 2022 =

= 7.8.1 - December 13, 2022 =

= 7.8.0 - November 28, 2022 =

= 7.7.1 - October 4, 2022 =

= 7.7.0 - October 3, 2022 =

= 7.6.2 - September 19, 2022 =

= 7.6.1 - September 6, 2022 =

= 7.6.0 - July 28, 2022 =

= 7.5.11 - June 14, 2022 =

= 7.5.10 - May 17, 2022 =

= 7.5.9 - March 22, 2022 =

= 7.5.8 - February 1, 2022 =

= 7.5.7 - November 22, 2021 =

= 7.5.6 - October 18, 2021 =

= 7.5.5 - August 16, 2021 =

= 7.5.4 - June 7, 2021 =

= 7.5.3 - May 10, 2021 =

= 7.5.2 - March 24, 2021 =

= 7.5.1 - March 24, 2021 =

= 7.5.0 - March 24, 2021 =

= 7.4.14 - December 3, 2020 =

= 7.4.12 - October 21, 2020 =

= 7.4.11 - August 27, 2020 =

= 7.4.10 - August 5, 2020 =

= 7.4.9 - July 8, 2020 =

= 7.4.8 - June 16, 2020 =

= 7.4.7 - April 23, 2020 =

= 7.4.6 - February 12, 2020 =

= 7.4.5 - January 15, 2020 =

= 7.4.4 - January 14, 2020 =

= 7.4.3 - January 13, 2020 =

= 7.4.2 - December 3, 2019 =

= 7.4.1 - November 6, 2019 =

= 7.4.0 - August 22, 2019 =

= 7.3.6 - July 31, 2019 =

= 7.3.5 - July 16, 2019 =

= 7.3.4 - June 17, 2019 =

= 7.3.3 - June 11, 2019 =

= 7.3.2 - May 16, 2019 =

= 7.3.1 - May 14, 2019 =

= 7.2.5 - April 18, 2019 =

= 7.2.4 - March 26, 2019 =

= 7.2.3 - February 28, 2019 =

= 7.2.2 - February 14, 2019 =

= 7.2.1 - February 5, 2019 =

= 7.1.20 - January 8, 2019 =

= 7.1.19 - January 8, 2019 =

= 7.1.18 - December 4, 2018 =

= 7.1.17 - November 6, 2018 =

= 7.1.16 - October 16, 2018 =

= 7.1.15 - October 1, 2018 =

= 7.1.14 - October 1, 2018 =

= 7.1.12 - September 12, 2018 =

= 7.1.11 - August 21, 2018 =

= 7.1.10 - July 31, 2018 =

= 7.1.9 - July 12, 2018 =

= 7.1.8 - June 26, 2018 =

= 7.1.7 - June 5, 2018 =

= 7.1.6 - May 22, 2018 =

= 7.1.5 - May 22, 2018 =

= 7.1.4 - May 2, 2018 =

= 7.1.3 - April 18, 2018 =

= 7.1.2 - April 4, 2018 =

= 7.1.1 - March 20, 2018 =

= 7.1.0 - March 1, 2018 =

= 7.0.4 - February 12, 2018 =

= 7.0.4 =

= 7.0.3 - February 12, 2018 =

= 7.0.2 - January 31, 2018 =

= 7.0.1 - January 24, 2018 =

= 6.3.22 - November 30, 2017 =

= 6.3.21 - November 1, 2017 =

= 6.3.20 - October 12, 2017 =

= 6.3.19 - September 20, 2017 =

= 6.3.18 - September 7, 2017 =

= 6.3.17 - August 24, 2017 =

= 6.3.16 - August 8, 2017 =

= 6.3.15 - July 24, 2017 =

= 6.3.14 - July 17, 2017 =

= 6.3.12 - June 28, 2017 =

= 6.3.11 - June 15, 2017 =

= 6.3.10 - June 1, 2017 =

= 6.3.9 - May 17, 2017 =

= 6.3.8 - May 2, 2017 =

= 6.3.7 - April 25, 2017 =

= 6.3.6 - April 5, 2017 =

= 6.3.5 - March 23, 2017 =

= 6.3.4 - March 13, 2017 =

= 6.3.3 - March 9, 2017 =

= 6.3.2 - February 23, 2017 =

= 6.3.1 - February 7, 2017 =

= 6.3.0 - January 26, 2017 =

= 6.2.10 - January 12, 2017 =

= 6.2.9 - December 27, 2016 =

= 6.2.8 - December 12, 2016 =

= 6.2.7 - December 1, 2016 =

= 6.2.6 - November 17, 2016 =

= 6.2.5 - November 9, 2016 =

= 6.2.4 - November 9, 2016 =

= 6.2.3 - October 26, 2016 =

= 6.2.2 - October 12, 2016 =

= 6.2.1 - October 11, 2016 =

= 6.2.0 - September 27, 2016 =

= 6.1.17 - September 9, 2016 =

= 6.1.16 - September 8, 2016 =

= 6.1.15 - August 25, 2016 =

= 6.1.14 - August 11, 2016 =

= 6.1.12 - July 26, 2016 =

= 6.1.11 - July 25, 2016 =

= 6.1.10 - June 22, 2016 =

= 6.1.9 - June 21, 2016 =

= 6.1.8 - May 26, 2016 =

= 6.1.7 - May 10, 2016 =

= 6.1.6 - May 9, 2016 =

= 6.1.5 - April 28, 2016 =

= 6.1.4 - April 20, 2016 =

= 6.1.3 - April 14, 2016 =

= 6.1.2 - April 12, 2016 =

= 6.1.1 - April 12, 2016 =

You can find a complete changelog on our documentation site.