WordPress PHP Firewall
por Carles Mateo
(5.00)
WordPress plugins
Security
abusive
Crawlers
DoS
Exploits
Firewall
Forensics
offending IPs
patterns
plugin
Security
WAF
WordPress
xmlrpc
This plugin for WordPress automatically blocks IPs trying exploits to your server and attempting to hack using wp-login, xmlrpc, attempting to post fake comments, DoS attacks...
It detects and blocks using PHP, at an early stage of WordPress loading, so it saves a lot of CPU from bad requests. It is optimised for very low memory usage and very fast execution.
It stores the offending IP Addresses and it doesn't allow them to waste more resources of the server.
This plugin is created by Carles Mateo with more than 30 years of experience with security and more than 20 with WordPress to protect sites from typical attacks and vulnerability scans that make the server go slow and crash.
Dangers of the servers in Internet
You don't see it, but your sites are currently receiving several attacks every single second.
A regular site from our customers, with 1,000 visitors per day, uses to be protected from more than 100,000 malicious requests the first month that PHP Firewall is enabled.
In many occasions the bots trying to hack your site, post Spam comments, or aggressively indexing your site, have the collateral damage that cause collapse to your server performance, causing the server to server the pages slowly to legit users, and in some occasions it causes the servers to crash, and expenses in outgoing (egress) Internet traffic.
PHP Firewall protects your sites
The best IP Firewall is at your provider's level, so before the attacks reach your server, but it blocks by IP Addresses, not attacking patterns (this is performed by the WAF).
After this, the best IP Firewall is to block the connections with ufw or iptables (Firewall in your server at Linux level).
Both IP blocking methods require many hours every month of dedicated System Administrators analysing the logs, and root access, and applying the bans.
Using PHP Firewall plugin and blocking at PHP level is the cheapest, easiest, fastest and safest option. And also the plugin is a WAF (Web Application Firewall), which analyses requests to detect attacks and blocks IP Addresses trying well known attacks. Even if your server is vulnerable to the built-in attacks, they would be blocked.
PHP Firewall for WordPress plugin has rate-connection detectors, which will detect and block IP Addresses making too many requests to the server (you can customise the volumes, and if they are GET or POST requests), or requests that should not be done, like attempts to login per hour, to post comments...
So this Software protects your server from wasting CPU and memory for attending malicious attacks from hackers or bots.
This plugin checks the connections that arrive to the server, detects the abusive patterns or rate-limits and blocks the offending IPs automatically, before WordPress loads completely using few memory.
You can choose permanent ban, or ban for several periods like 1 hour, 2 hours, 4 hours, 1 day, a week, a month or a year...
Very powerful for stopping attacks and forensics
PHP Firewall is very powerful, a tool lovely for System Administrators, and for Forensics too. If you want to investigate, it can help you to detect, troubleshoot, see the patterns of the attacks, see IPs doing more requests and what they request... and keep your sites super well protected with a minimum effort.
You can also add your rules to block certain patterns and you can block individual IPs and IP ranges.
For IPv6 it allows to block all the variable parts of the IP (the device part, to the right of the IP IPv6).
But if you are a business owner or a non-technical user, and you just want something plug and play, that you install and stops most of the attacks easily, immediately, without you doing anything, your site will be protected from most abusive connections as you install it.
Even if you don't know, your server is likely getting thousands of malicious requests per day. Degrading the speed of the response of your site for the real users, and putting your server at risk of being hacked or malfunctioning (like MySQL becoming degraded and becoming extremely slow, disk getting full due to extensive logs).
Carles Mateo's PHP Firewall plugin for WordPress is a very powerful to use plugin, made to solve performance problems because the avalanche of rogue connections causing problems to the server performance and the speed of response and page loading for the legit users or generating expenses in Internet traffic (some Cloud providers charge you per outgoing Internet usage of your servers).
The price of the license it's a single one time payment for one WordPress installation (up to 10 domains in WordPress multi-site), and allows you to receive support and to download free updates for a year. After a year the software continues to work and you don't need to renew it every year, although in order to receive new versions and to have support after a year, you require to renew the license.
If you are an agency, contact support for volume licencing.
The plugin also allows you to export the offending IP addresses as a CSV file or as a shell script that will add to Ubuntu firewall or any other Firewall Software the offending IPs.
The software allows you to get immediate protection with no technical background and also if you're a powerful tech user it's useful for troubleshooting, analysing attacks, reveal which IP Addresses do more requests per day, see the Payload of the POST requests, and detecting attack patterns at an early stage so you can block them before they affect your business.
WordPress multi-site
PHP Firewall for WordPress is fully compatible with WordPress multi-site.
Only main admins can manage the configuration of PHP Firewall, not the sub-sites admins.
The protection is global, at network level, for all the sites in the Server.
In the dashboard you can see what site are being requested, very useful for multi-site and to detect if requests are coming to the server from other domain names (normally DNS configuration errors at your side).
The license allows to run the plugin with up to 10 sites. If you host more sites on the same server, please contact support for pricing.
Compatibility
Compatible verified with: WordPress 7.1.2 and lower versions up to WordPress 6.7.
Code is PHP 7.4 (verified compatible with PHP up to 8.5).
You can watch the video on the left and read an article explaining how to protect your site using PHP Firewall WordPress plugin v.1.0.8.
Contact support for doubts or a live demo.
Adjuntos
- PHP WordPress Firewall plugin v. 1.6.0 (56.7 KB)
€250.00
Última actualización: 2026-09-27