Wordfence Premium

Wordfence Premium 8.0.1

No permission to download
Wordfence Premium

Requires at least: 4.7
Requires PHP: 7.0
Tested up to: 6.7
Stable tag: 8.0.1
License: GPLv3

== Description ==

### THE MOST POPULAR WORDPRESS FIREWALL & SECURITY SCANNER

WordPress security requires a team of dedicated analysts researching the latest malware variants and WordPress exploits, turning them into firewall rules and malware signatures, and releasing those to customers in real-time. Wordfence is widely acknowledged as the number one WordPress security research team in the World. Our plugin provides a comprehensive suite of security features, and our team's research is what powers our plugin and provides the level of security that we are known for.

At Wordfence, WordPress security isn't a division of our business - WordPress security is all we do. We employ a global 24 hour dedicated incident response team that provides our priority customers with a 1 hour response time for any security incident. The sun never sets on our global security team and we run a sophisticated threat intelligence platform to aggregate, analyze and produce ground breaking security research on the newest security threats.

Wordfence Security includes an endpoint firewall, malware scanner, robust login security features, live traffic views, and more. Our Threat Defense Feed arms Wordfence with the newest firewall rules, malware signatures and malicious IP addresses it needs to keep your website safe. Rounded out by 2FA and a suite of additional features, Wordfence is the most comprehensive WordPress security solution available.

#### WORDPRESS FIREWALL
* Web Application Firewall identifies and blocks malicious traffic. Built and maintained by a large team focused 100% on WordPress security.
* [Premium] Real-time firewall rule and malware signature updates via the Threat Defense Feed (free version is delayed by 30 days).
* [Premium] Real-time IP Blocklist blocks all requests from the most malicious IPs, protecting your site while reducing load.
* Protects your site at the endpoint, enabling deep integration with WordPress. Unlike cloud alternatives does not break encryption, cannot be bypassed and cannot leak data.
* Integrated malware scanner blocks requests that include malicious code or content.
* Protection from brute force attacks by limiting login attempts.

#### WORDPRESS SECURITY SCANNER
* Malware scanner checks core files, themes and plugins for malware, bad URLs, backdoors, SEO spam, malicious redirects and code injections.
* [Premium] Real-time malware signature updates via the Threat Defense Feed (free version is delayed by 30 days).
* Compares your core files, themes and plugins with what is in the WordPress.org repository, checking their integrity and reporting any changes to you.
* Repair files that have changed by overwriting them with a pristine, original version. Delete any files that don’t belong easily within the Wordfence interface.
* Checks your site for known security vulnerabilities and alerts you to any issues. Also alerts you to potential security issues when a plugin has been closed or abandoned.
* Checks your content safety by scanning file contents, posts and comments for dangerous URLs and suspicious content.
* [Premium] Checks to see if your site or IP have been blocklisted for malicious activity, generating spam or other security issue.

#### LOGIN SECURITY
* Two-factor authentication (2FA), one of the most secure forms of remote system authentication available via any TOTP-based authenticator app or service.
* Login Page CAPTCHA stops bots from logging in.
* Disable or add 2FA to XML-RPC.
* Block logins for administrators using known compromised passwords.

#### SECURITY AUDIT LOG [Premium]
* Monitors all changes and actions in security-sensitive areas of the site.
* Remote tamper-proof data storage via Wordfence Central.
* Monitored actions range from user creation and editing to plugin/theme installation and updates to post and page changes.
* Configurable to log all events or significant events only, which includes all authentication, site configuration, and site functionality events.

#### WORDFENCE CENTRAL
* Wordfence Central is a powerful and efficient way to manage the security for multiple sites in one place.
* Efficiently assess the security status of all your websites in one view. View detailed security findings without leaving Wordfence Central.
* Powerful templates make configuring Wordfence a breeze.
* Highly configurable alerts can be delivered via email, SMS or Slack. Improve the signal to noise ratio by leveraging severity level options and a daily digest option.
* Track and alert on important security events including administrator logins, breached password usage and surges in attack activity.
* Free to use for unlimited sites.

#### SECURITY TOOLS
* With Live Traffic, monitor visits and hack attempts not shown in other analytics packages in real time; including origin, their IP address, the time of day and time spent on your site.
* Block attackers by IP or build advanced rules based on IP Range, Hostname, User Agent and Referrer.
* Country blocking available with Wordfence Premium.

== Installation ==

Secure your website using the following steps to install Wordfence:

1. Install Wordfence automatically or by uploading the ZIP file.
2. Activate the Wordfence through the 'Plugins' menu in WordPress. Wordfence is now activated.
3. Go to the scan menu and start your first scan. Scheduled scanning will also be enabled.
4. Once your first scan has completed, a list of threats will appear. Go through them one by one to secure your site.
5. Visit the Wordfence options page to enter your email address so that you can receive email security alerts.
6. Optionally, change your security level or adjust the advanced options to set individual scanning and protection options for your site.
7. Click the "Live Traffic" menu option to watch your site activity in real-time. Situational awareness is an important part of website security.

To install Wordfence on WordPress Multi-Site installations:

1. Install Wordfence via the plugin directory or by uploading the ZIP file.
2. Network Activate Wordfence. This step is important because until you network activate it, your sites will see the plugin option on their plugins menu. Once activated that option disappears.
3. Now that Wordfence is network activated it will appear on your Network Admin menu. Wordfence will not appear on any individual site's menu.
4. Go to the "Scan" menu and start your first scan.
5. Wordfence will do a scan of all files in your WordPress installation including those in the blogs.dir directory of your individual sites.
6. Live Traffic will appear for ALL sites in your network. If you have a heavily trafficked system you may want to disable live traffic which will stop logging to the DB.
7. Firewall rules and login rules apply to the WHOLE system. So if you fail a login on site1.example.com and site2.example.com it counts as 2 failures. Crawler traffic is counted between blogs, so if you hit three sites in the network, all the hits are totalled and that counts as the rate you're accessing the system.
  • Like
Reactions: Mad Max
Similar resources Most view View more
Back
Top Bottom