Prevention-First WordPress Security Plugin

SiteFort protects WordPress with free firewall controls and security hardening, plus login security, vulnerability monitoring, bot protection, and cloud-assisted malware scanning.
★★★★★5.0 rating on WordPress.orgThreat intelligence informed by real incidentsFirewall & hardening included free
Why we built SiteFort

Built from Real WordPress Security Incidents

Securewp grew from years of WordPress incident response and malware cleanup. That experience shaped SiteFort around the controls that matter most in real compromises: reducing common attack paths, strengthening login and firewall protection, detecting vulnerabilities, and scanning for malware without placing unnecessary load on the server. SiteFort brings those protections together in one WordPress security plugin, with core firewall and hardening features included free.

2016
Security experience since
25,000+
WordPress sites secured
30 min
Incident response SLA
See SiteFort in action

Your WordPress Security Workspace

Manage malware scanning, firewall protection, login security, vulnerabilities, hardening, and audit activity from one interface inside WordPress.

yourdomain.com/wp-admin/admin.php?page=sitefort
SiteFort WordPress security dashboard showing security status and monitoring
SiteFort cloud-assisted WordPress malware scanner showing scan findings
SiteFort WordPress firewall, bot protection, and traffic control settings
SiteFort WordPress login security with 2FA, CAPTCHA, and login protection
SiteFort WordPress security hardening controls
SiteFort WordPress vulnerability scanner showing plugin and theme vulnerabilities
SiteFort WordPress security audit log showing site activity and security events

01 · Detect

Detect Malware and WordPress Vulnerabilities Early

Cloud-assisted malware scanning and vulnerability monitoring across WordPress core, plugins, themes, files, and database content.

Cloud-assisted malware scanner

Reliable Scanning With Low Server Impact

SiteFort verifies known files locally first and sends files for deeper cloud analysis only when needed. This reduces server load and helps malware scans run reliably across shared hosting, managed WordPress, VPS, and cloud environments.

Files, Database & Core Integrity
Detect malicious PHP, backdoors, web shells, injected scripts, SEO spam, suspicious redirects, and database threats while verifying WordPress core against known-good checksums.
One-Click Repair for Supported Files
Pro users can restore supported WordPress core, plugin, and theme files directly from scan results.
Hash First, Deep Analysis When Needed
Known files are verified locally first. Only files that need deeper inspection are sent for cloud analysis.
How SiteFort Cloud Scanning Workshash-first analysis
1
File Signatures Generated LocallySiteFort creates file hashes on your server before deeper analysis is considered.
2
Known Files VerifiedRecognized WordPress core, plugin, and theme files are checked against known-good signatures.
3
Unknown Files Analyzed in the CloudFiles that cannot be verified locally are securely sent for deeper malware analysis.
4
Findings and Repair OptionsScan findings are categorized by type and severity, with repair options available for supported files.
Vulnerability monitoring

Monitor WordPress Vulnerabilities Across Your Stack

SiteFort checks WordPress core, plugins, and themes for known vulnerabilities and helps you prioritize remediation based on severity and available fixes.

Severity and CVE References
Findings include CVE details and severity scores so you can prioritize the most important issues first.
Core, Plugins & Themes
Monitor active and inactive WordPress components for known security vulnerabilities.
Update From the Report
Apply available plugin and theme updates directly from the vulnerability report when supported.
SiteFort → Vulnerabilities
Page Builder Plugin
Plugin · Installed: 3.11.5 · 2 issues
Update Plugin
VulnerabilityAffectedCVESeverity
Broken Access Control<=3.35.5CVE-2026-32445Low (2.7)
Stored Cross-Site Scripting via REST API<=3.35.5CVE-2025-14732Medium (6.4)
Contact Form Plugin
Plugin · Installed: 1.6.13 · 2 issues
Update Plugin
VulnerabilityAffectedCVESeverity
Cross-Site Scripting (XSS)<2.5.0CVE-2025-9703Medium (5.9)
Missing Authorization on Settings Update<=2.4.6CVE-2025-8488Medium (5.4)
02 · Block

WordPress Firewall and Traffic Protection

Block malicious requests, control unwanted bots, limit abusive traffic, and sync supported rules to Cloudflare for edge-level enforcement.

Firewall · Cloudflare Edge Sync

Extend WordPress Firewall Protection to the Cloudflare Edge

SiteFort detects abusive traffic with WordPress-level context and can sync supported blocks to Cloudflare. Repeat attackers can then be stopped at the edge before their requests reach your origin server.

Edge
Cloudflare enforcement
Auto
Attack escalation
Simple
Cloudflare setup
Simple Cloudflare Integration
Connect your Cloudflare account once and let SiteFort manage supported firewall rules from WordPress.
Automatic Edge Escalation
Repeated abusive traffic can be escalated to temporary Cloudflare blocks that expire automatically.
Works With Your Existing Cloudflare Setup
Use SiteFort alongside your current Cloudflare-proxied WordPress site without moving to a separate security service.
SiteFort → Firewall → Cloudflare Sync
SiteFort Cloudflare firewall sync settings with automatic edge blocking
Firewall · Bot & Crawler Policy

Block Unwanted Bots Without Disrupting Search Crawlers

Choose Basic, Balanced, or Maximum protection based on how aggressively you want to restrict automated traffic. Recognized search crawlers and AI assistants are handled separately, with independent controls for AI training bots.

3 levels
Bot protection policy
Search aware
Known crawlers handled separately
AI control
Training crawler rules
SiteFort → Firewall → Bot & Crawler Policy
Recognized search crawlers, social preview bots, and supported AI assistants remain allowed by default across protection levels.
Basic

Block known hacking and vulnerability-scanning tools.

Hacking & pentesting tools
Data scraping bots
Automated scripts
Unrecognized bots
Balanced
Recommended

Block hacking tools, data scrapers, and automated scripts.

Hacking & pentesting tools
Data scraping bots
Automated scripts
Unrecognized bots
Maximum

Block hacking tools, scrapers, automated scripts, and unrecognized bot traffic.

Hacking & pentesting tools
Data scraping bots
Automated scripts
Unrecognized bots
Block AI training crawlers

Optionally block crawlers used for AI model training while keeping supported user-requested AI assistants separately controlled.

Detect & block security probes

Detect repeated requests for configuration files, backups, metadata, and other common reconnaissance targets.

Ban IP after3failed attempts within10minutes
SiteFort → Firewall → Traffic Rules
IP Address
Country
Bot / Crawler
Duration:Reason:
Allow my current IP

Active rules

185.220.00.47BlockPermanent
45.00.212.0/24BlockPermanent
203.0.113.5AllowMy IP
Rule builder · Traffic control

Create Precise WordPress Firewall Rules

Create allow or block rules by IP address, CIDR range, country, bot, or user agent. Rules can be permanent or time-limited and include notes for easier auditing.

IP & CIDR Rules
Allow or block individual IP addresses and network ranges with configurable rule duration.
Country Blocking
Restrict traffic by country and sync supported rules to Cloudflare when edge enforcement is enabled.
Bot & User-Agent Rules
Control named crawlers and custom user agents independently from your general bot protection policy.
Community Threat Intelligence

Use shared threat data from the SiteFort network to help identify and block known abusive IP addresses.

Early-Load WordPress Firewall

SiteFort loads its firewall early in the WordPress request lifecycle to evaluate and block malicious requests before normal page processing.

Rate Limiting

Apply per-IP limits to normal requests and repeated 404 probes to reduce abusive automated traffic.

03 · Harden

WordPress Security Hardening and Login Protection

Reduce common WordPress attack paths with hardening controls, stronger login security, and detailed activity logging, all managed from one interface.

Site hardening & audit log

Apply Hardening Controls and Track Security Events

Enable WordPress hardening controls without manually editing configuration files, and keep a clear record of logins, security changes, firewall events, and other important activity.

Protect Uploads and Sensitive Files
Prevent PHP execution in the uploads directory and restrict public access to exposed files such as .env, debug logs, backups, and .git metadata.
Reduce WordPress Information Exposure
Limit username enumeration, remove unnecessary WordPress version exposure, and reduce publicly visible metadata that can help automated reconnaissance.
Detailed WordPress Activity Logging
Track logins, user changes, plugin and theme activity, hardening changes, firewall events, scan findings, and other security-relevant actions.
SiteFort → Hardening
Server Hardening
Block Sensitive File AccessRestrict public access to .env files, debug logs, .git metadata, database backups, and other sensitive server files.
Block PHP Execution in UploadsPrevent PHP files from executing inside the uploads directory, reducing a common persistence path used by malware.
Block Direct PHP Access in PluginsRestrict direct web access to supported plugin PHP files that should normally execute through WordPress.
Block Direct PHP Access in ThemesRestrict direct web access to supported theme PHP files where direct execution is not required.
Disable Directory ListingPrevent directory contents from being exposed when a folder does not contain an index file.
WordPress Hardening
Block User EnumerationReduce username discovery through author archives, REST API endpoints, oEmbed data, and user sitemaps.
Disable Theme & Plugin EditorRemove the built-in WordPress code editor to reduce the risk of unauthorized code changes from the dashboard.
Disable Application PasswordsDisable WordPress Application Passwords when they are not required by external services or integrations.
Hide WordPress VersionReduce version exposure in common metadata and generated output used for automated fingerprinting.
Clean WordPress HeadRemove unnecessary metadata and discovery links from the HTML head when they are not needed.
Login security

Secure WordPress Login and Administrator Access

Strengthen WordPress authentication with 2FA, CAPTCHA, login throttling, breached-password checks, and optional custom login URLs.

Two-Factor Authentication
Use authenticator-app or email-based 2FA, recovery options, and role-based enforcement for WordPress users.
Breached Password Detection
Check passwords against known breach data and alert users when credentials appear to have been exposed.
CAPTCHA & Login Throttling
Use CAPTCHA and configurable lockout rules to reduce automated login abuse and repeated failed authentication attempts.
SiteFort → Login Security
Two-Factor AuthenticationRequired: Administrator, Editor
4 8 3 · 2 1 6
Expires in 18s · Authenticator app
Limit Login Attempts5 failed attempts per IP · 30-minute lockout
847 login attempts blocked today14 IPs locked
Example login protection activity
Bot Detection (CAPTCHA)
Google reCAPTCHA or Cloudflare Turnstile
Active
Custom Login URL
yoursite.com/my-login
403404Redirect
04 · Scale

Centralize WordPress Security Across Every Site You Manage

Connect SiteFort to the Securewp Console to manage malware scans, vulnerabilities, uptime, SSL monitoring, alerts, team access, and security reports across multiple WordPress sites.

Unified WordPress Security Dashboard
View site status, malware findings, vulnerabilities, uptime, SSL health, firewall activity, and recent security events from one console.
Multi-Site Scans and Security Alerts
Run scans across one or multiple sites and route important security alerts to Slack, Discord, email, or connected workflows.
Team Access and Client Reporting
Assign team roles, review security history, and export reports for agencies, clients, maintenance plans, or internal security reviews.
console.securewp.net
Sites

Sites

4

Risk Queue

1

Uptime

99.9%

All 4Secure 3Attention 1Scanning 0

clientstore.com

WP 6.9 · PHP 8.3 · Pro

Secure

agency-blog.net

WP 6.8 · PHP 8.2 · Pro

1 Vuln

shop.mybrand.co

WP 6.9 · PHP 8.3 · Managed

Secure

developer-portfolio.io

WP 6.9 · PHP 8.3 · Free

Secure
Included Free

Core WordPress Security Features Included Free

SiteFort includes essential firewall, login security, hardening, vulnerability protection, and traffic controls in the Free plan, with no trial expiry.

Two-Factor Authentication

Protect WordPress accounts with authenticator-app or email-based 2FA, recovery options, and role-based enforcement.

WordPress Activity Logging

Track logins, user changes, plugin and theme activity, firewall events, scan findings, and important security changes.

CAPTCHA & Login Protection

Reduce automated login abuse with CAPTCHA, configurable lockouts, and login throttling controls.

IP & Domain Reputation Checks

Check your website IP address and related domains against supported reputation and blacklist sources.

Cloudflare Firewall Integration

Sync supported IP, country, and traffic rules to Cloudflare for edge-level enforcement directly from SiteFort.

Country Blocking

Restrict traffic by country and optionally extend supported rules to Cloudflare when edge enforcement is enabled.

Trusted by WordPress site owners

What SiteFort Users Say

Feedback from WordPress users using SiteFort for malware scanning, firewall protection, hardening, and ongoing security.

★★★★★

"Our store was getting hammered by AI crawlers and fake Googlebots. Server load sat around 80% for no reason. Turned on SiteFort's bot blocking and the CPU graph flattened out within a day. Didn't expect a security plugin to fix a performance problem, but here we are."

DM
Daniel M.
WooCommerce store owner
★★★★★

"43 client sites. I used to keep a spreadsheet and a folder of wp-admin logins just to check on things. Now it's one console every morning and I'm done in five minutes. Last month I knew about a plugin CVE on a client site before their host even emailed them."

PS
Priya S.
Agency owner, 40+ client sites
★★★★★

"For years, my workflow for WordPress security was frustrating. I would install one plugin to scan for malware, remove it after cleanup, then install and configure another plugin... SiteFort is the first plugin I’ve used that combines both in a clean and lightweight way. Fast malware scanning, practical hardening features, and an easy-to-use interface without slowing down the website."

SU
SiteFort User
WordPress.org
SiteFort Plans

Choose the Right Level of WordPress Security

Start free with core protection. Upgrade when you need unlimited scanning, monitoring, repair tools, or hands-on security management.

Core WordPress protection
Free

Essential WordPress security with no trial expiry.

$0/forever
  • 3,000 cloud scan credits / month
  • Firewall & country blocking
  • Login security & 2FA
  • WordPress security hardening
  • Vulnerability scanning & activity logging
MOST POPULAR
Advanced scanning & monitoring
Pro

Unlimited scanning, monitoring, alerts, and repair tools for active WordPress sites.

$99/year
  • Everything in Free
  • Unlimited cloud-assisted malware scanning
  • Scheduled & automated scans
  • One-click repair for supported files
  • Uptime monitoring & security alerts
  • Slack, Discord & email notifications
Hands-on security management
Managed

SiteFort Pro with expert oversight, ongoing monitoring, and managed remediation.

$299/year
  • Everything in Pro
  • Dedicated security specialist
  • Expert malware cleanup included
  • Core, plugin & theme updates
  • Priority vulnerability remediation
  • 24/7 security monitoring & response
Have questions?

SiteFort Frequently Asked Questions

SiteFort is a WordPress security plugin from Securewp that combines firewall protection, security hardening, login security, vulnerability monitoring, bot protection, activity logging, and cloud-assisted malware scanning in one interface.

SiteFort generates file hashes locally and checks recognized files against known-good signatures. Files that cannot be verified locally can be securely sent to the Securewp cloud for deeper malware analysis. WordPress posts, comments, WooCommerce orders, customer records, and full database content are not uploaded for malware scanning. See the SiteFort documentation for technical details.

SiteFort is designed for low server impact. Known files are verified locally first, while deeper malware analysis is handled in the Securewp cloud when needed. This reduces the amount of intensive scanning work performed on your WordPress server.

The Free plan includes 3,000 cloud scan credits per month, firewall controls, country blocking, community threat intelligence, 2FA, CAPTCHA, login protection, WordPress security hardening, vulnerability scanning, activity logging, bot controls, and access to the Securewp Console.

Yes. SiteFort can sync supported firewall rules to Cloudflare for edge-level enforcement. This includes supported IP, country, and automated blocking rules, while SiteFort's WordPress firewall continues to provide application-level protection on the site itself.

Yes. SiteFort includes configurable bot and crawler policies for hacking tools, scrapers, automated scripts, unknown bots, and supported AI training crawlers. Recognized search crawlers and supported user-requested AI assistants can be handled separately from broader bot restrictions.

Yes. Connect SiteFort to the Securewp Console to centralize malware scans, vulnerability status, uptime, SSL monitoring, alerts, security history, team access, and reporting across multiple WordPress sites.

SiteFort reports the affected files and available details about the finding. Pro users can restore supported WordPress core, plugin, and theme files directly from scan results. Complex or persistent infections can be handled separately through our WordPress malware removal service.

Free includes core WordPress protection and monthly cloud scan credits. Pro adds unlimited cloud-assisted scanning, scheduled scans, monitoring, alerts, and one-click repair for supported files. Managed includes Pro plus hands-on security management, expert malware cleanup, ongoing updates, and priority remediation. See the SiteFort pricing page for the full comparison.

Yes. Volume pricing is available for organizations managing multiple WordPress sites. Teams with larger deployments, custom procurement requirements, DPAs, or contract needs can contact Securewp for enterprise options.

Protect Your WordPress Site with SiteFort

Install SiteFort for ongoing WordPress protection, run a free external security scan, or get expert malware removal if your site is already compromised.

Free firewall & hardeningWorks across WordPress hostingExpert malware cleanup available