WordPress.org

Plugin Directory

Wordfence Security – 防火牆、惡意軟體掃描及登入安全性

Wordfence Security – 防火牆、惡意軟體掃描及登入安全性

外掛說明

廣受歡迎的 WORDPRESS 防火牆 & 安全掃描器

WordPress 安全需要專責分析師團隊,研究最新的惡意軟體變種與 WordPress 漏洞利用手法,將研究成果轉化為防火牆規則及惡意軟體特徵碼,並即時發布給客戶。

選擇適合您的防護方案:Wordfence Free、Premium、Care 或 Response

Wordfence 是廣受肯定的頂尖 WordPress 安全研究團隊。我們的外掛提供完整的安全功能,而團隊的研究成果正是外掛的核心基礎,讓我們能提供備受肯定的安全防護。

對 Wordfence 而言,WordPress 安全就是我們全部的業務。我們的全球專責事件應變團隊全天候待命,針對優先服務客戶的任何安全事件,提供 1 小時內回應的服務。

我們的全球安全團隊全天候運作,透過精密的威脅情資平台彙整及分析最新安全威脅,並產出突破性的安全研究成果。

Wordfence Security 包含端點防火牆、惡意軟體掃描器、強大的登入安全性功能、即時流量檢視等功能。我們的 威脅防禦資訊源 (Threat Defense Feed) 為 Wordfence 提供保護網站所需的最新防火牆規則、惡意軟體特徵碼及惡意 IP 位址。

Wordfence 結合通行密鑰 (Passkey)、雙重驗證及一系列額外功能,提供完整的 WordPress 安全解決方案。

🔥 WORDPRESS 防火牆

  • 網頁應用程式防火牆可辨識並封鎖惡意流量,由全心投入 WordPress 安全的大型團隊建置與維護。
  • 透過威脅防禦資訊源 (Threat Defense Feed) 提供即時防火牆規則與惡意軟體特徵碼 [Premium]更新(免費版延遲 30 天)。
  • 即時 IP 封鎖清單 [Premium] 可封鎖來自高度惡意 IP 的所有要求,在保護網站的同時降低負載。
  • 在端點保護您的網站,與 WordPress 深度整合。與雲端方案不同,它不會破壞加密、無法遭到繞過,也不會洩漏資料。
  • 內建惡意軟體掃描器可封鎖包含惡意程式碼或內容的要求。
  • 透過限制登入嘗試次數,提供暴力破解防護,抵禦暴力破解攻擊。

📡 WORDPRESS 安全掃描器

  • 惡意軟體掃描器會檢查核心程式檔案、佈景主題及外掛,找出惡意軟體、惡意網址、後門、SEO 垃圾訊息、惡意重新導向及程式碼注入。
  • 透過威脅防禦資訊源 (Threat Defense Feed) 提供即時惡意軟體特徵碼更新 [Premium](免費版延遲 30 天)。
  • 與 WordPress.org 儲存庫比對您的核心程式檔案、佈景主題及外掛,檢查完整性並回報任何變更。
  • 修復遭變更的 WordPress 核心程式、佈景主題及外掛檔案,以未經修改的原始版本覆寫。您也可以直接在 Wordfence 介面輕鬆刪除不應存在的檔案。
  • 惡意軟體移除工具的 [刪除檔案] 與 [刪除所有可刪除的檔案] 選項,讓您有效率地移除惡意軟體。請記得先檢查掃描結果並備份檔案!
  • 檢查網站是否有已知安全漏洞,並在發現問題時向您發出警示。當外掛已下架或停止維護時,也會提醒您潛在的安全問題。
  • 透過掃描檔案內容、文章和留言中的危險網址和可疑內容,檢查您的內容安全性
  • 檢查您的網站或 IP 是否列入封鎖清單 [Premium],原因可能包括惡意活動、產生垃圾訊息或其他安全問題。

🔒 登入安全性

📋 安全性稽核記錄 [Premium]

  • 稽核記錄可監控網站中涉及安全性的區域內所有變更與操作。
  • 透過 Wordfence Central 進行遠端防竄改資料儲存
  • 監控事件與操作,涵蓋使用者的建立與編輯、外掛與佈景主題的安裝與更新,以及文章與頁面的變更。
  • 可設定記錄所有事件或僅記錄重大事件,其中包含所有驗證、網站設定及網站功能事件。

🌐 WORDFENCE CENTRAL

  • Wordfence Central 功能強大且有效率,讓您集中管理多個網站的安全性。
  • 集中管理:在同一畫面快速評估所有網站的安全狀態,並直接在 Wordfence Central 檢視詳細的安全檢查結果。
  • 強大的範本讓設定 Wordfence 變得輕而易舉。
  • 可彈性設定的警示可透過電子郵件、簡訊或 Slack 傳送。使用嚴重性等級與每日摘要選項,減少雜訊,讓重要訊息更清楚。
  • 追蹤重要安全事件並發出警示,包括管理員登入、使用外洩密碼及攻擊活動激增。
  • 免費使用,不限網站數量。

🛠️ 安全工具

  • 即時流量可即時監控其他分析工具未顯示的造訪與入侵嘗試,包括來源、IP 位址、造訪時間及在網站上的停留時間。
  • 依 IP 封鎖攻擊者,或根據 IP 範圍、主機名稱、使用者代理程式和引薦來源建立進階規則。
  • 國家封鎖功能適用於 Wordfence Premium。

螢幕擷圖

安裝方式

請依照下列步驟安裝 Wordfence,保護您的網站:

  1. 自動安裝 Wordfence,或上傳 ZIP 檔案進行安裝。
  2. 透過 WordPress 的 [外掛] 選單啟用 Wordfence。Wordfence 現在已啟用。
  3. 前往 [掃描] 選單,開始第一次掃描。排程掃描也會一併啟用。
  4. 第一次掃描完成後,畫面會顯示威脅清單。請逐一檢查,以確保網站安全。
  5. 前往 Wordfence 選項頁面,輸入您的電子郵件地址,以便接收安全警示郵件。
  6. 您也可以變更安全等級或調整進階選項,為網站設定個別的掃描和防護選項。
  7. 點選 [即時流量] 選單選項,即時查看網站活動。掌握網站狀況是維護網站安全的重要環節。

在 WordPress 多站網路中安裝 Wordfence:

  1. 透過外掛目錄或上傳 ZIP 檔案安裝 Wordfence。
  2. 為整個多站網路啟用 Wordfence。這個步驟很重要,因為在為多站網路啟用前,各網站的 [外掛] 選單都會顯示此外掛的啟用選項。為多站網路啟用後,這個選項便會消失。
  3. 在多站網路中啟用 Wordfence 後,它會出現在 [多站網路管理] 選單中,不會出現在個別網站的選單中。
  4. 前往 [掃描] 選單,開始第一次掃描。
  5. Wordfence 會掃描 WordPress 安裝目錄中的所有檔案,包括各個網站 blogs.dir 目錄中的檔案。
  6. 即時流量會顯示多站網路中所有網站的流量。如果系統流量很大,可以停用即時流量,停止將流量記錄寫入資料庫。
  7. 防火牆規則和登入規則適用於整個系統。因此,如果您分別在 site1.example.com 和 site2.example.com 登入失敗,會累計為 2 次失敗。各部落格的爬蟲流量也會合併計算;如果您存取多站網路中的 3 個網站,系統會加總所有請求,據此計算您的存取速率。

常見問題集

請造訪我們的網站,查閱包含安全功能說明、常見問題解決方法及完整協助資訊的官方說明文件。

Wordfence Security 如何保護網站免受攻擊者侵害?

這款 WordPress 安全外掛為您的網站提供完善的保護。Wordfence 防火牆透過持續更新的威脅防禦資訊源 (Threat Defense Feed),防止網站遭到入侵。Wordfence 掃描使用同一套專有情資,在發現安全問題或網站遭到入侵時迅速發出警示。即時流量檢視讓您即時掌握網站流量與入侵嘗試,再搭配豐富的額外工具,構成完整的 WordPress 安全解決方案。

Wordfence Premium 提供哪些功能?

我們提供 Premium API 金鑰,讓您即時取得威脅防禦資訊源 (Threat Defense Feed) 更新,包括即時 IP 封鎖清單、防火牆規則及惡意軟體特徵碼。方案也包含 Premium 支援、國家封鎖、更頻繁的掃描,以及垃圾訊息與垃圾廣告檢查。點選這裡,立即申請 Wordfence Premium,或直接安裝 Wordfence 免費版,開始保護您的網站。

Wordfence WordPress 防火牆如何保護網站?

  • 網頁應用程式防火牆會辨識惡意流量,在攻擊者存取網站前加以封鎖,防止網站遭到入侵。
  • 威脅防禦資訊源 (Threat Defense Feed) 會自動更新防火牆規則,保護您免受最新威脅侵害。Premium 會員可取得即時更新。
  • 封鎖常見的 WordPress 安全威脅,如假冒的 Googlebot、駭客的惡意掃描和殭屍網路。

Wordfence 安全掃描器會執行哪些檢查?

  • 將核心檔案、佈景主題和外掛與 WordPress.org 儲存庫中的版本比對,檢查檔案完整性。確認原始碼的安全性。
  • 查看檔案的變更內容。您也可以修復遭到變更且構成安全威脅的檔案。
  • 掃描超過 44,000 種已知惡意軟體變種的特徵碼,這些變種均為已知的 WordPress 安全威脅。
  • 掃描多種會造成安全漏洞的已知後門程式,包括 C99、R57、RootShell、Crystal Shell、Matamu、Cybershell、W4cking、Sniper、Predator、Jackal、Phantasma、GFS、Dive、Dx 等。
  • 持續掃描所有留言、文章和檔案,找出構成安全威脅的惡意軟體與網路釣魚網址,包括 Google Safe Browsing 清單中的所有網址。
  • 透過啟發式分析,掃描後門程式、特洛伊木馬、可疑程式碼及其他安全問題。

Wordfence 包含哪些安全監控功能?

  • 即時查看所有流量,包括機器人、真人訪客、404 錯誤、登入與登出,以及哪些訪客存取了較多內容。協助您掌握網站面臨的安全威脅。
  • 即時查看所有流量,包括經常構成安全威脅、卻不會出現在 Javascript 分析套件中的自動化機器人流量。
  • 即時流量資訊包含反向 DNS 查詢及城市層級的地理位置。讓您了解安全威脅來自哪個地區。
  • 監控磁碟空間。磁碟空間與安全息息相關,因為許多 DDoS 攻擊會試圖耗盡磁碟空間,造成阻斷服務。

包含哪些登入安全性功能

  • 即時查看所有流量,包括機器人、真人訪客、404 錯誤、登入與登出,以及哪些訪客存取了較多內容。協助您掌握網站面臨的安全威脅。
  • 即時查看所有流量,包括經常構成安全威脅、卻不會出現在 Javascript 分析套件中的自動化機器人流量。
  • 即時流量資訊包含反向 DNS 查詢及城市層級的地理位置。讓您了解安全威脅來自哪個地區。
  • 監控磁碟空間。磁碟空間與安全息息相關,因為許多 DDoS 攻擊會試圖耗盡磁碟空間,造成阻斷服務。

如果我的網站發生安全問題,我會如何收到警示?

Wordfence 透過電子郵件傳送安全性警示。安裝 Wordfence 後,您可以設定接收警示的電子郵件地址清單。收到安全性警示時,請及時處理,以確保網站安全。

如果我使用雲端防火牆(WAF),還需要 Wordfence 這類安全外掛嗎?

Wordfence 為您的 WordPress 網站提供真正的端點安全防護。Wordfence 在 WordPress 環境中執行,因此能掌握雲端防火牆無法取得的資訊,例如使用者是否登入、身分及存取層級。Wordfence 用來保護 WordPress 網站的防火牆規則中,超過 80% 會使用使用者的存取層級資訊。請進一步了解雲端 WAF 的身分識別問題。此外,攻擊者可能繞過雲端防火牆,讓網站暴露在攻擊風險中。Wordfence 是端點(您的 WordPress 網站)的一部分,因此無法遭到繞過。請進一步了解雲端 WAF 遭到繞過的問題。若要充分保護您對網站的投入,需要採取縱深防禦的安全策略,Wordfence 採用的正是這種策略。

Wordfence 包含哪些封鎖功能?

  • 即時封鎖已知攻擊者。如果其他使用 Wordfence 的網站遭到攻擊並封鎖該攻擊者,您的網站也會自動受到保護。
  • 封鎖整個惡意網路。提供進階 IP 和網域 WHOIS 查詢功能,方便回報惡意 IP 或網路,並透過防火牆封鎖整個網路。向網路擁有者回報 WordPress 安全威脅。
  • 限制存取速率或封鎖 WordPress 安全威脅,例如過度存取的爬蟲、內容擷取程式,以及掃描網站漏洞的機器人。
  • 選擇要封鎖違反 WordPress 安全規則的使用者和機器人,或限制其存取速率。
  • Premium 使用者還可以依國家封鎖存取,並指定掃描時間或提高排程掃描的頻率。

Wordfence 與其他 WordPress 安全外掛有何不同?

  • Wordfence Security 提供專為 WordPress 開發的防火牆,封鎖試圖尋找網站漏洞的攻擊者。防火牆使用威脅防禦資訊源 (Threat Defense Feed),隨著新威脅出現持續更新。Premium 客戶可即時取得更新。
  • Wordfence 會與 WordPress 官方儲存庫比對,驗證網站原始碼的完整性,並顯示變更內容。
  • Wordfence 掃描會檢查所有檔案、留言及文章,找出列在 Google Safe Browsing 清單中的網址。我們是唯一提供這項重要安全強化功能的外掛。
  • Wordfence 掃描不會消耗大量頻寬,因為所有安全掃描都在您的網頁伺服器上進行,因此速度非常快。
  • Wordfence 完整支援 WordPress 多站網路,只要按一下,即可對網路中的每個部落格執行安全掃描。
  • Wordfence 提供通行密鑰 (Passkey) 與雙重驗證,協助保護 WordPress 帳號,防範網路釣魚與暴力破解攻擊。
  • Wordfence 完整支援 IPv6,可查詢 IPv6 位址的位置、封鎖 IPv6 範圍、判斷 IPv6 位址所屬國家,以及執行 IPv6 位址的 whois 查詢等。

Wordfence 會拖慢我的網站速度嗎?

不會。Wordfence Security 執行速度快,會快取本身的設定資料以減少資料庫查詢,並封鎖會拖慢網站速度的惡意攻擊。

如果我的網站已經被駭了怎麼辦?

Wordfence Security 可修復遭入侵網站上的核心程式檔案、佈景主題及外掛。您可以參閱如何使用 Wordfence 清理遭入侵網站的指南。如果您要自行清理遭入侵的網站,請注意,除非完整重新安裝,否則無法保證網站安全。我們建議使用 Wordfence Security 先讓網站重新運作,以便取回完整重新安裝所需的資料。如果您需要協助處理安全問題,請參考 Wordfence Care,由我們的團隊直接提供支援,包括處理遭入侵的網站。對於執行關鍵任務的網站,請參考 Wordfence Response

Wordfence Security 支援 IPv6 嗎?

是的,我們的所有安全功能都完整支援 IPv6,包括國家封鎖、範圍封鎖、城市查詢與 whois 查詢等。即使您未使用 IPv6,Wordfence 也能正常運作。無論您同時使用 IPv4 與 IPv6,或只使用其中一種定址方式,我們都完整相容。

Wordfence Security 支援多站網路安裝嗎?

是的,Wordfence 完整支援 WordPress 多站網路。只要按一下,即可掃描網路中的每個部落格是否有惡意軟體。如果客戶發布的頁面或文章包含已知惡意軟體網址,導致整個網域有被 Google 列入封鎖清單的風險,我們會在下次掃描時向您發出警示。

Wordfence 使用者有哪些可用的支援選項?

我們非常重視優質的客戶服務。免費使用者可在支援論壇獲得志工支援。Wordfence Premium 客戶可透過支援單獲得付費支援。Wordfence Care 客戶可獲得團隊直接協助,包括處理安全事件及年度安全稽核。Wordfence Response 客戶可獲得事件應變團隊全年無休的全天候支援,於 1 小時內回應,並在不超過 24 小時內解決安全問題。

哪裡可以深入了解 WordPress 安全性?

WordPress 安全學習中心適合各種程度的使用者,免費提供入門與深入文章、影片、產業調查結果及圖表等資源,協助使用者深入了解安全最佳實務。

哪裡可以找到 Wordfence 的服務條款和隱私權政策?

您可以在我們的網站找到:服務條款隱私權政策

使用者評論

2026 年 9 月 6 日
I was actually recommended Wordfence by Gemini after it was discovered that my .htaccess was modified by a bot/script. One of the rare times where AI has proven to be extremely helpful for people who are not technically savvy. It’s quite comprehensive for a free program and I like getting regular updates on how it’s protecting my site. 5/5!
2026 年 9 月 5 日
The reason why it’s time saver is because the scan is actually thorough enough to find files that maybe I even left behind that could become vulnerable.
2026 年 9 月 4 日
I am a satisfied user, grateful even. But Wordfence won’t let me use PayPal to purchase premium services, oh well, I’ll just keep using the free version
2026 年 9 月 4 日
If people were simply ethical, mature, sensible, just, and decent–if they had the competence so they would not need to violate others to get something pleasing to themselves, then the need for security would not be so great that people suffer so much. Hackers are a bane on the world. The world would be better off without scammers, spammers, and unethical hackers. And security software, when it is good, is vital.
閱讀全部 4,993 則使用者評論

參與者及開發者

以下人員參與了開源軟體〈Wordfence Security – 防火牆、惡意軟體掃描及登入安全性〉的開發相關工作。

參與者

〈Wordfence Security – 防火牆、惡意軟體掃描及登入安全性〉外掛目前已有 28 個本地化語言版本。 感謝全部譯者為這個外掛做出的貢獻。

將〈Wordfence Security – 防火牆、惡意軟體掃描及登入安全性〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄

變更記錄

9.0.0 – August 10, 2026

  • Improvement: Added support for passkey authentication
    • Available for both free and premium installations
    • Can be enabled for any user role (multisite support is currently limited)
    • WooCommerce integration
    • Support for custom authentication integrations
  • Improvement: GeoIP database updated
  • Improvement: Several mobile styling and layout improvements on the login security page
  • Improvement: Added diagnostics info for authentication hooks to assist with login-related troubleshooting
  • Change: Hardened 2FA flow when installed next to plugins with non-standard authentication (credit: Austin Ginder of Anchor Hosting)
  • Change: Hardened 2FA remember cookie handling
  • Change: The scanner will now display an issue when the standalone Wordfence Login Security plugin is installed because all functionality is already provided by Wordfence itself
  • Change: Updated internal libraries used by the Vue UI
  • Change: Login error masking setting now also applies to the Login Security functionality

8.2.2 – May 13, 2026

  • Improvement: Better presentation of Live Traffic data on wide screens
  • Improvement: Increased legibility of token fields
  • Improvement: Reworked the pagination of the Blocking page for a better UX
  • Improvement: Country blocking token field can now expand to show all entries
  • Improvement: Performance improvements for the activity log and better pause behavior on window blur/focus
  • Improvement: GeoIP database updated
  • Change: Removed deprecated Central endpoint
  • Fix: Addressed issue where the last activity log entry could repeatedly appear
  • Fix: Using the embedded shortcode for the 2FA form now correctly enqueues core JavaScript dependencies
  • Fix: Modals with content that overflows on smaller viewports can now be scrolled
  • Fix: The changelog link in plugin upgrade scan issues now links correctly

8.2.1 – May 6, 2026

  • Fix: Fixed issue with some i18n plugins/themes when a user has no 2FA recovery codes
  • Fix: Toggled options with additional help links now correctly open the link rather than toggling the option
  • Fix: Country Blocking editing fixed when there are multiple pages of block rules
  • Fix: Added better error handling to the initial Vue data load
  • Fix: Handled error when logging in using legacy 2FA with separate prompts enabled

8.2.0 – April 29, 2026

  • Improvement: Migrated all deprecated JavaScript libraries in use to a Vue-based infrastructure
  • Improvement: GeoIP database update
  • Improvement: Better coverage of aria- accessibility attributes
  • Improvement: Added translators comments to translatable strings where previously missing
  • Fix: WordPress 7.0 compatibility fixes
  • Note: Legacy two factor authentication using SMS-based codes will be discontinued around July 1, 2026. Sites using this functionality should migrate users to the TOTP-based two factor authentication on the Login Security page of the plugin

8.1.4 – December 20, 2025

  • Fix: Fixed an issue with inet_pton introduced by a recent patch to PHP 8.1+ that could cause a fatal error if a malformed IP address was passed to the call

8.1.3 – December 3, 2025

  • Improvement: Updated the bundled geoip database
  • Note: Verified compatibility with WordPress 6.9

8.1.2 – November 12, 2025

  • Improvement: Updated the bundled geoip database

8.1.1 – November 5, 2025

  • Improvement: Improved localization support for the various block screens and messages
  • Improvement: Updated the bundled geoip database
  • Improvement: Prioritized Wordfence tables in the diagnostics tool when large numbers of tables exist
  • Improvement: Allow non-US Google crawler IP addresses to pass country blocking
  • Improvement: Enforcement of password strength requirements is now applied on the corresponding REST API endpoints
  • Fix: Fixed detection for first-time logins and overall sending for login alerts when the corresponding settings are enabled
  • Fix: When the WAF is using the mysql storage engine, fixed an issue with exclusion rules for the WAF not running correctly
  • Fix: Reduced per-hit database query load around checking license status for free installations
  • Fix: Optimized data sync with the WAF to better detect when the known server IP address list has changed

8.1.0 – August 25, 2025

  • Improvement: Added password scanning support for WordPress 6.8 and later
  • Improvement: Limited email alerts to 5 per hour by default and added notification when limit has been reached
  • Improvement: Improved URL scanning performance
  • Improvement: Updated GeoIP database
  • Change: Reduced scan result severity for vulnerabilities with high attack complexity or required privileges
  • Change: Added messaging around WAF support when NGINX Unit is detected
  • Change: Added notice and scan result about Wordfence Assistant
  • Change: Adjusted IPv6 connection issue message and appearance
  • Fix: Prevented deprecation notice about calling base64_encode with null parameter
  • Fix: Prevented deprecation message about calling preg_match with null parameter
  • Fix: Corrected license type shown on dashboard when expiring
  • Fix: Prevented disabled getmyuid function from causing fatal error
  • Fix: Prevented disabled get_current_user function from causing fatal error
  • Fix: Prevented notice about _load_textdomain_just_in_time being called incorrectly

8.0.5 – April 8, 2025

  • Fix: Compatibility fixes for WordPress 6.8

8.0.4 – March 19, 2025

  • Improvement: Improved error handling and messaging for some responses from our servers
  • Improvement: Added messaging when a site may be using the same free license shared among multiple sites because it can cause the sites to use the same scan schedule rather than spreading out the load
  • Improvement: Updated the readme content and formatting

8.0.3 – January 15, 2025

  • Improvement: Added support for hosts relocating the WAF’s auto-prepend file via the constant/envvar WORDFENCE_WAF_PREPEND_DIRECTORY
  • Improvement: Added detection for non-repo plugins and themes to avoid the scanner reporting changes when the same slug + version exists within the wordpress.org repo
  • Improvement: Messaging for Central disconnections now better reflects the user making the change
  • Improvement: Scan errors due to unreachable Wordfence servers will now provide a link to our status page to check for outages
  • Improvement: Reduced the number of network calls created to sync scan issues when updates are performed in bulk
  • Change: Reworked setting caching to avoid issues with some object caches
  • Change: Reworked cURL check to avoid using WP_Http_Curl, which has been deprecated
  • Fix: Normalized all wordfence.com links to be https
  • Fix: Fixed a rare error that could occur on the diagnostics page when displaying a list of error logs
  • Fix: Removed the “back to top” button and related script block from emailed diagnostics
  • Fix: Fixed some UI coloring that did not correctly reflect the license type in use

8.0.2 – January 2, 2025

  • Improvement: General compatibility improvements and better error handling for PHP 8+
  • Improvement: Added audit log status to the plugin dashboard
  • Change: Increased width of diagnostics text export for better legibility
  • Fix: Addressed an error with mail hooks and the audit log when third party plugins send unexpected value types

8.0.1 – November 14, 2024

  • Improvement: Updated GeoIP database
  • Change: Revised some help text related to the audit log to be more clear
  • Fix: Improved audit log compatibility with some plugins that would cause excessive noise due to their behaviors around setting up user roles and capabilities
  • Fix: Fixed a log notice that could occur when deactivating Wordfence with audit log events still pending and a broken Wordfence Central link

8.0.0 – November 4, 2024

  • Improvement: Introduced the Wordfence Audit Log, a new premium feature to monitor all changes and actions in security-sensitive areas of the site with remote tamper-proof data storage via Wordfence Central
  • Change: Increased the minimum supported WordPress version to 4.7
  • Change: Increased the minimum supported PHP version to 7.0

7.11.7 – July 29, 2024

  • Improvement: Optimized scan performance by reducing database queries by approximately 38% along with CPU usage
  • Fix: Added translation support for “Page not found” string when viewing recent traffic

7.11.6 – June 6, 2024

  • Improvement: Revised the strong password requirements notice to be more readable
  • Improvement: Removed unnecessary calls for the plugin and theme vulnerability checks
  • Improvement: Reduced the frequency of calls to Wordfence Central during some operations where the values do not need to be synced
  • Improvement: Refactored some queries to avoid the automatic SHOW FULL COLUMNS queries that WordPress performs to verify database encodings
  • Improvement: Infrequently-used config values are no longer automatically loaded into memory and instead loaded only on demand
  • Fix: Fixed an issue where multisite installations using the WAF mysqli storage engine could repeatedly attempt to update WAF rules when not in optimized mode
  • Improvement: Updated the bundled GeoIP database
  • Change: Revised the formatting of TOTP app URLs to prioritize the site’s own URL for better sorting and display
  • Fix: Fixed the last captcha column in the users page so it no longer displays “(not required)” on 2FA users since that no longer applies
  • Fix: Added a check in wflogs/rules.php to only run when within the WAF’s bootstrap stage when hosted behind nginx

7.11.5 – April 3, 2024

  • Fix: Revised the behavior of the reCAPTCHA verification to use the documented expiration period of the token and response to avoid sending verification requests too frequently, which could artificially lower scores in some circumstances
  • Fix: Addressed PHP 8 deprecation notices in the file differ used by file changed scan results
  • Fix: Reduced the frequency of Wordfence Central status update callbacks in sections of the scan that occur quickly in sequence

7.11.4 – March 11, 2024

  • Change: CAPTCHA verification when enabled now additionally applies to 2FA logins (may send an email verification on low scores) and no longer reveals whether a user exists for the submitted account credentials (credit: Raxis)
  • Fix: Addressed a potential PHP 8 notice in the human/bot detection AJAX call
  • Fix: Addressed a potential PHP 8 notice when requesting a lockout unlock verification email
  • Fix: Fixed the emailed diagnostics view not showing the missing table information when applicable
  • Fix: Improved quick scan logic to base timing on regular scans so they’re more evenly distributed

7.11.3 – February 15, 2024

  • Fix: Fixed an issue with sites containing invalid Wordfence Central site data where they could throw an error when viewing Wordfence pages

7.11.2 – February 14, 2024

  • Improvement: Enhanced the vulnerability scan to check and alert for WordPress core vulnerabilities and to adjust the severity of the scan result based on findings or available updates
  • Improvement: Updated the bundled GeoIP database
  • Improvement: Increased compatibility of brute force protection with plugins that override the normal login flow and omit traditional hooks
  • Change: Adjusted the behavior of automatic quick scans to schedule themselves further away from full scans
  • Fix: Added detection for a site being linked to a non-matching Wordfence Central record (e.g., when cloning the database to a staging site)
  • Fix: Streamlined the license and terms of use installation flow to avoid unnecessary prompting
  • Fix: Fixed an issue where user profiles with a selected locale different from the site itself could end up loading the site’s locale instead

7.11.1 – January 2, 2024

  • Improvement: Added “.env” to the files checked for “Scan for publicly accessible configuration, backup, or log files”
  • Improvement: Provided better descriptive text for the option “Block IPs who send POST requests with blank User-Agent and Referer”
  • Improvement: The diagnostics page now displays the contents of any auto_prepend_file .htaccess/.user.ini block for troubleshooting
  • Fix: Fixed an issue where a login lockout on a WooCommerce login form could fail silently
  • Fix: The scan result for abandoned plugins no longer states it has been removed from wordpress.org if it is still listed
  • Fix: Addressed an exception parsing date information in non-repo plugins that have a bad last_updated value
  • Fix: The URL scanner no longer generates a log warning when matching a potential URL fragment that ends up not being a valid URL

7.11.0 – November 28, 2023

  • Improvement: Added new functionality for trusted proxy presets to support proxies such as Amazon CloudFront, Ezoic, and Quic.cloud
  • Improvement: WAF rule and malware signature updates are now signed with SHA-256 as well for hosts that no longer build SHA1 support
  • Improvement: Updated the bundled trusted CA certificates
  • Change: The WAF will no longer attempt to fetch rule or blocklist updates when run via WP-CLI
  • Fix: Removed uses of SQL_CALC_FOUND_ROWS, which is deprecated as of MySQL 8.0.17
  • Fix: Fixed an issue where final scan summary counts in some instances were not sent to Central
  • Fix: Fixed a deprecation notice for get_class in PHP 8.3.0
  • Fix: Corrected an output error in the connectivity section of Diagnostics in text mode

7.10.7 – November 6, 2023

  • Fix: Compatibility fix for WordPress 6.4 on the login page styling

7.10.6 – October 30, 2023

  • Fix: Addressed an issue with multisite installations when the wp_options tables had different encodings/collations

7.10.5 – October 23, 2023

  • Improvement: Updated the bundled GeoIP database
  • Improvement: Added detection for Cloudflare reverse proxies blocking callbacks to the site
  • Change: Files are no longer excluded from future scans if a previous scan stopped during their processing
  • Fix: Added handling for the pending WordPress 6.4 change that removes $wpdb->use_mysqli
  • Fix: The WAF MySQLi storage engine will now work correctly when either DB_COLLATE or DB_CHARSET are not defined
  • Fix: Added additional error handling to Central calls to better handle request failures or conflicts
  • Fix: Addressed a warning that would occur if a non-repo plugin update hook did not provide a last updated date
  • Fix: Fixed an error in PHP 8 that could occur if the time correction offset was not numeric
  • Fix: 2FA AJAX calls now use an absolute path rather than a full URL to avoid CORS issues on sites that do not canonicalize www and non-www requests
  • Fix: Addressed a race condition where multiple concurrent hits on multisite could trigger overlapping role sync tasks
  • Fix: Improved performance when viewing the user list on large multisites
  • Fix: Fixed a UI bug where an invalid code on 2FA activation would leave the activate button disabled
  • Fix: Reverted a change on error modals to bring back the additional close button for better accessibility

7.10.4 – September 25, 2023

  • Improvement: “Admin created outside of WordPress” scan results may now be reviewed and approved
  • Improvement: The WAF storage engine may now be specified by setting the environmental variable “WFWAF_STORAGE_ENGINE”
  • Improvement: Detect when a plugin or theme with a custom update handler is broken and blocking update version checks
  • Change: Deprecated support for WordPress versions lower than 4.7.0
  • Change: Exclude parse errors of a damaged compiled rules file from reporting
  • Fix: Suppress PHP notices related to rule loading when running WP-CLI
  • Fix: Fixed an issue with the scan monitor cron that could leave it running unnecessarily

7.10.3 – July 31, 2023

  • Improvement: Updated GeoIP database
  • Fix: Added missing text domain to translation function call
  • Fix: Corrected inconsistent styling of switch controls
  • Change: Made MySQLi storage engine the default for Flywheel hosted sites

7.10.2 – July 17, 2023

  • Fix: Prevented bundled sodium_compat library from conflicting with versions included with older WordPress versions

7.10.1 – July 12, 2023

  • Improvement: Added support for processing arrays of files in the WAF
  • Improvement: Refactored security event processing to send events in bulk
  • Improvement: Updated bundled sodium_compat and random_compat libraries
  • Fix: Prevented deprecation warning caused by dynamic property creation
  • Fix: Added translation support for additional strings
  • Change: Adjusted Wordfence registration UI

7.10.0 – June 21, 2023

  • Improvement: Added translation support for strings from login security plugin
  • Improvement: Added translator notes regarding word order and hidden text
  • Improvement: Added translation support for additional strings
  • Improvement: Prevented scans from failing if unreadable directories are encountered
  • Improvement: Added help link to IPv4 scan option
  • Improvement: Updated scan result text to clarify meaning of plugins removed from wordpress.org
  • Improvement: Made “Increased Attack Rate” emails actionable
  • Improvement: Updated GeoIP database
  • Improvement: Updated JavaScript libraries
  • Fix: Corrected IPv6 address expansion
  • Fix: Ensured long request payloads for malicious requests are recorded in live traffic
  • Fix: Prevented “commands out of sync” database error messages when the database connection has failed
  • Fix: Prevented rare JSON encoding issues from breaking free license registration
  • Fix: Prevented PHP notice from being logged when request parameter is missing
  • Fix: Prevented deprecation warning in PHP 8.1
  • Change: Moved detection for old TimThumb files to malware signature
  • Change: Moved translation file from .po to .pot
  • Change: Renamed “Macedonia” to “North Macedonia, Republic of”

7.9.3 – May 31, 2023

  • Improvement: Added exception handling to prevent WAF errors from being fatal
  • Fix: Corrected error caused by method call on null in WAF
  • Change: Deprecated support for PHP 5.5 and 5.6, ended support for PHP 5.3 and 5.4
  • Change: Specified WAF version parameter when requesting firewall rules

7.9.2 – March 27, 2023

  • Improvement: The vulnerability severity score (CVSS) is now shown with any vulnerability findings from the scanner
  • Improvement: Changed several links during initial setup to open in a new window/tab so it doesn’t interrupt installation
  • Change: Removed the non-https callback test to the Wordfence servers
  • Fix: Fixed an error on PHP 8 that could occur when checking for plugin updates and another plugin has a broken hook
  • Fix: Added a check for disabled functions when generating support diagnostics to avoid an error on PHP 8
  • Fix: Prevent double-clicking when activating 2FA to avoid an “already set up” error

7.9.1 – March 1, 2023

  • Improvement: Further improved performance when viewing 2FA settings and hid user counts by default on sites with many users
  • Fix: Adjusted style inclusion and usage to prevent missing icons
  • Fix: Avoided using the ctype extension as it may not be enabled
  • Fix: Prevented fatal errors caused by malformed Central keys

7.9.0 – February 14, 2023

  • Improvement: Added 2FA management shortcode and WooCommerce account integration
  • Improvement: Improved performance when viewing 2FA settings on sites with many users
  • Improvement: Updated GeoIP database
  • Fix: Ensured Captcha and 2FA scripts load on WooCommerce when activated on a sub-site in multisite
  • Fix: Prevented reCAPTCHA logo from being obscured by some themes
  • Fix: Enabled wfls_registration_blocked_message filter support for WooCommerce integration

7.8.2 – December 13, 2022

  • Fix: Releasing same changes as 7.8.1, due to wordpress.org error

7.8.1 – December 13, 2022

  • Improvement: Added more granualar data deletion options to deactivation prompt
  • Improvement: Allowed accessing diagnostics prior to completing registration
  • Fix: Prevented installation prompt from displaying when a license key is already installed but the alert email address has been removed

7.8.0 – November 28, 2022

  • Improvement: Added feedback when login form is submitted with 2FA
  • Fix: Restored click support on login button when using 2FA with WooCommerce
  • Fix: Corrected display issue with reCAPTCHA score history graph
  • Fix: Prevented errors on PHP caused by corrupted login timestamps
  • Fix: Prevented deprecation notices on PHP 8.2 related to dynamic properties
  • Change: Updated Wordfence registration workflow

7.7.1 – October 4, 2022

  • Fix: Prevented scan resume attempts from repeating indefinitely when the initial scan stage fails

7.7.0 – October 3, 2022

  • Improvement: Added configurable scan resume functionality to prevent scan failures on sites with intermittent connectivity issues
  • Improvement: Added new scan result for vulnerabilities found in plugins that do not have patched versions available via WordPress.org
  • Improvement: Implemented stand-alone MMDB reader for IP address lookups to prevent plugin conflicts and support additional PHP versions
  • Improvement: Added option to disable looking up IP address locations via the Wordfence API
  • Improvement: Prevented successful logins from resetting brute force counters
  • Improvement: Clarified IPv6 diagnostic
  • Improvement: Included maximum number of days in live traffic option text
  • Fix: Made timezones consistent on firewall page
  • Fix: Added “Use only IPv4 to start scans” option to search
  • Fix: Prevented deprecation notices on PHP 8.1 when emailing the activity log
  • Fix: Prevented warning on PHP 8 related to process owner diagnostic
  • Fix: Prevented PHP Code Sniffer false positive related to T_BAD_CHARACTER
  • Fix: Removed unsupported beta feed option

7.6.2 – September 19, 2022

  • Improvement: Hardened 2FA login flow to reduce exposure in cases where an attacker is able to obtain privileged information from the database

7.6.1 – September 6, 2022

  • Fix: Prevented XSS that would have required admin privileges to exploit (CVE-2022-3144)

7.6.0 – July 28, 2022

  • Improvement: Added option to start scans using only IPv4
  • Improvement: Added diagnostic for internal IPv6 connectivity to site
  • Improvement: Added AUTOMATIC_UPDATER_DISABLED diagnostic
  • Improvement: Updated password strength check
  • Improvement: Added support for scanning plugin/theme files in when using the WP_CONTENT_DIR/WP_PLUGIN_DIR constants
  • Improvement: Updated GeoIP database
  • Improvement: Made DISABLE_WP_CRON diagnostic more clear
  • Improvement: Added “Hostname” to Live Traffic message displayed for hostname blocking
  • Improvement: Improved compatibility with Flywheel hosting
  • Improvement: Adopted semantic versioning
  • Improvement: Added support for dynamic cookie redaction patterns when logging requests
  • Fix: Prevented scanned paths from being displayed as skipped in rare cases
  • Fix: Corrected indexed files count in scan messages
  • Fix: Prevented overlapping AJAX requests when viewing Live Traffic on slower servers
  • Fix: Corrected WP_DEBUG_DISPLAY diagnostic
  • Fix: Prevented extraneous warnings caused by DNS resolution failures
  • Fix: Corrected display issue with Save/Cancel buttons on All Options page
  • Fix: Prevented errors caused by WHOIS searches for invalid values

7.5.11 – June 14, 2022

  • Improvement: Added option to toggle display of last login column on WP Users page
  • Improvement: Improved autocomplete support for 2FA code on Apple devices
  • Improvement: Prevented Batcache from caching block pages
  • Improvement: Updated GeoIP database
  • Fix: Prevented extraneous scan results when non-existent paths are configured using UPLOADS and related constants
  • Fix: Corrected issue that prevented reCAPTCHA scores from being recorded
  • Fix: Prevented invalid JSON setting values from triggering fatal errors
  • Fix: Made text domains consistent for translation support
  • Fix: Clarified that allowlisted IP addresses also bypass reCAPTCHA

7.5.10 – May 17, 2022

  • Improvement: Improved scan support for sites with non-standard directory structures
  • Improvement: Increased accuracy of executable PHP upload detection
  • Improvement: Addressed various deprecation notices with PHP 8.1
  • Improvement: Improved handling of invalidated license keys
  • Fix: Corrected lost password redirect URL when used with WooCommerce
  • Fix: Prevented errors when live traffic data exceeds database column length
  • Fix: Prevented bulk password resets from locking out admins
  • Fix: Corrected issue that prevented saving country blocking settings in certain cases
  • Change: Updated copyright information

7.5.9 – March 22, 2022

  • Improvement: Updated GeoIP database
  • Improvement: Removed blocking data update logic in order to reduce timeouts
  • Improvement: Increased timeout value for API calls in order to reduce timeouts
  • Improvement: Clarified notification count on Wordfence menu
  • Improvement: Improved scan compatibility with WooCommerce
  • Improvement: Added messaging when application passwords are disabled
  • Fix: Prevented warnings and errors when constants are defined based on the value of other constants in wp-config.php
  • Fix: Corrected redundant escaping that prevented viewing or repairing files in scan results

7.5.8 – February 1, 2022

  • Launch of Wordfence Care and Wordfence Response

7.5.7 – November 22, 2021

  • Improvement: Made preliminary changes for compatibility with PHP 8.1
  • Change: Added GPLv3 license and updated EULA

7.5.6 – October 18, 2021

  • Fix: Prevented login errors with WooCommerce integration when manual username entry is enabled on the WooCommerce registration form
  • Fix: Corrected theme incompatibilities with WooCommerce integration

7.5.5 – August 16, 2021

  • Improvement: Enhanced accessibility
  • Improvement: Replaced regex in scan log with signature ID
  • Improvement: Updated Knockout JS dependency to version 3.5.1
  • Improvement: Removed PHP 8 compatibility notice
  • Improvement: Added NTP status for Login Security to Diagnostics
  • Improvement: Updated plugin headers for compatibility with WordPress 5.8
  • Improvement: Updated Nginx documentation links to HTTPS
  • Improvement: Updated IP address geolocation database
  • Improvement: Expanded WAF SQL syntax support
  • Improvement: Added optional constants to configure WAF database connection
  • Improvement: Added support for matching punycode domain names
  • Improvement: Updated Wordfence install count
  • Improvement: Deprecated support for WordPress versions older than 4.4.0
  • Improvement: Added warning messages when blocking U.S.
  • Improvement: Added MYSQLI_CLIENT_SSL support to WAF database connection
  • Improvement: Added 2FA and reCAPTCHA support for WooCommerce login and registration forms
  • Improvement: Added option to require 2FA for any role
  • Improvement: Added logic to automatically disable NTP after repeated failures and option to manually disable NTP
  • Improvement: Updated reCAPTCHA setup note
  • Fix: Prevented issue where country blocking changes are not saved
  • Fix: Corrected string placeholder
  • Fix: Added missing text domain to translation calls
  • Fix: Corrected warning about sprintf arguments on Central setup page
  • Fix: Prevented lost password functionality from revealing valid logins

7.5.4 – June 7, 2021

  • Fix: Resolve conflict with woocommerce-gateway-amazon-payments-advanced plugin

7.5.3 – May 10, 2021

  • Improvement: Expanded WAF capabilities including better JSON and user permission handling
  • Improvement: Switched to relative paths in WAF auto_prepend file to increase portability
  • Improvement: Eliminated unnecessary calls to Wordfence servers
  • Fix: Prevented errors on PHP 8.0 when disk_free_space and/or disk_total_space are included in disabled_functions
  • Fix: Fixed PHP notices caused by unexpected plugin version data
  • Fix: Gracefully handle unexpected responses from Wordfence servers
  • Fix: Time field now displays correctly on “See Recent Traffic” overlay
  • Fix: Corrected typo on Diagnostics page
  • Fix: Corrected IP counts on activity report
  • Fix: Added missing line break in scan result emails
  • Fix: Sending test activity report now provides success/failure response
  • Fix: Reduced SQLi false positives caused by comma-separated strings
  • Fix: Fixed JS error when resolving last scan result

7.5.2 – March 24, 2021

  • Fix: Fixed fatal error on single-sites running WordPress <4.9.

7.5.1 – March 24, 2021

  • Fix: Fixed fatal error when viewing the Login Security settings page from an allowlisted IP.

7.5.0 – March 24, 2021

  • Improvement: Translation-readiness: All user-facing strings are now run through WordPress’s i18n functions.
  • Improvement: Remove legacy admin functions no longer used within the UI.
  • Improvement: Local GeoIP database update.
  • Improvement: Remove Lynwood IP range from allowlist, and add new AWS IP range.
  • Fix: Fixed bug with unlocking a locked out IP without correctly resetting its failure counters.
  • Fix: Sites using deleted premium licenses correctly revert to free license behavior.
  • Fix: When enabled, cookies are now set for the correct roles on previously used devices.
  • Fix: WAF cron jobs are now skipped when running on the CLI.
  • Fix: PHP 8.0 compatibility – prevent syntax error when linting files.
  • Fix: Fixed issue where PHP 8 notice sometimes cannot be dismissed.

7.4.14 – December 3, 2020

  • Improvement: Added option to disable application passwords.
  • Improvement: Updated site cleaning callout with 1-year guarantee.
  • Improvement: Upgraded sodium_compat library to 1.13.0.
  • Improvement: Replaced the terms whitelist and blacklist with allowlist and blocklist.
  • Improvement: Made a number of WordPress 5.6 and jQuery 3.x compatibility improvements.
  • Improvement: Made a number of PHP8 compatilibility improvements.
  • Improvement: Added dismissable notice informing users of possible PHP8 compatibility issues.

7.4.12 – October 21, 2020

  • Improvement: Initial integration of i18n in Wordfence.
  • Improvement: Prevent Wordfence from loading under <PHP 5.3.
  • Improvement: Updated GeoIP database.
  • Improvement: Prevented wildcard from running/saving for scan’s excluded files pattern.
  • Improvement: Included Wordfence Login Security tables in diagnostics missing table list.
  • Fix: Removed new scan issues when WordPress update occurs mid-scan.
  • Fix: Specified category when saving whitelistedServiceIPs to WAF storage engine.
  • Fix: Removed localhost IP for auto-update email alerts.
  • Fix: Fixed broken message in Live Traffic with MySQLi storage engine for blocklisted hits.
  • Fix: Removed optional parameter values for PHP 8 compatibility.

You can find a complete changelog on our documentation site.