The Wordfence Security plugin is a security plug that I always recommend to people who start a WordPress website . WordPress is not always as safe and there are regular security vulnerabilities that make it easy for hackers to hack your website.
In the past, I once learned that a website worth a few hundred euros per month washacked, after which my accumulated income from that website was suddenly gone.
Here I learned a good lesson: Always protect your WordPress website as well as possible!
What is Wordfence?
The Wordfence Security plugin is, in my opinion, the best choice to protect your WordPress website. It's a very versatile antivirus and firewall package that not only protects your website, but also keeps you from Google's blacklist, and helps repair hacked files even when you do not have any backups. There are also features such as Login Brute Force Protection, a Hider that hides your WordPress version, a Fake Crawler Blocker and more.
Of all the security plugins I've used for WordPress, Wordfence is by far my favorite. Both in terms of security and ease of use. It is therefore the most popular firewall plugin for WordPress and has over 1 million active installations.
Wordfence is free, but they also offer a premium version that offers some more options including Premium Scanning, Advanced Comment Spam Filter, Spamvertise Check, IP Spam Checker, Two Factor Authentication and Country Blocking. These features can be very useful but are not necessary. The free version actually offers everything you need.
How Good Does Wordfence Protect Your Website?
Below are some key features of the plugin:
- Scan to known malware
- Check if your theme, plugins or core files are still up to date
- Check your disk space to prevent DDoS attacks
- Scan DNS for unauthorized changes
- Plugins and open source themes compare with original versions
- Scan files to see if they are infected with malware, trojans, viruses, and other dangerous code
- Scan comments and files to see they match URLs in Google's Safe Browsing List
- Compares WordPress core files with the originals in the server file
- Scan files outside of your WordPress installation
- Scan your site for heartble vulnerabilities
- Scan weak passwords
Brute Force Login Security:
- Exit visitors with too much failed login attempts
- Visitors who enter an incorrect admin username are excluded
Firewall:
- Hardly blocks Google crawlers
- Blockes anyone who suspects your website quickly
- Blocks anyone requesting too much 404 pages
Other options:
- Hides your WordPress version so that bots do not know if your site is hackable
As you can see, Wordfence offers a long list of all important security features. If you still do not understand what Wordfence is doing right now: All of these features make sure your website is sealed and can not be penetrated by annoying hackers and bots.
Keeping your website constantly monitored and monitored for minor changes knows Wordfence exactly when hack attempts are done and will work immediately without having to do anything.
Set Wordfence
Before you can use the plugin, you must first download and install them. On the left side of your menu, click WordPress on Plugins, and then click New Plugin . In the search bar, type "wordfence", click Install, and then when it's ready for Activate .
When you have Wordfence installed in WordPress, click Wordfence on the left side of the menu and then Options . At first glance, it looks very complicated and all of the words are used, which you probably do not understand (do not worry, I do not understand half myself either). Below, I will show you how to configure Wordfence on all of my websites. Wordfence with these settings made sure that I have not been hacked for 4 years, apparently it works very well. Just take a look at me:
Basic Options
Enter your email address and switch This option enable block live traffic logging option out . Live traffic view stores all visitors' logs and makes your site a lot slower.
Set the other options as follows:
You can choose to check the auto-update option if you find this convenient.
Advanced Options
If, like me, I do not want to be bombarded every minute with emails, set the following options:
You can choose to also note Alert on critical issues and Alert on Warnings , but it is not necessarily necessary.
Scans to include
Set the Scans to include options as follows:
Rate Limiting RulesThe Rate Limiting Rules allow you to set different rules for human visitors and crawlers who are trying to penetrate your site. If someone violates these rules, you can temporarily block them ( throttle ) or block them completely.
These firewall rules should be carefully adjusted depending on your traffic traffic. If you know little about it, then leave the settings just as they are. I set them up so that only visitors who retrieve over 404 pages are temporarily blocked:
Login Security Options
I have set the Login Security Options .
You can also choose to Enforce strong passwords the CRM admins and publishers to use strong passwords to use option. So major users are required to create a strong password.
Other Options
Enter Whitelisted IP addresses that bypass all rules, then enter your own IP address so that you do not block yourself. If you do not know your own IP address please click on this link . Click Save Changes, and Finish!
Last word
Keep in mind that the configuration I've shown is a suggestion, if you still do not find it safe enough or receive more alerts, you can always increase your security by checking more options and setting firmer firewall rules. This configuration has made sure that I have not been hacked for more than 4 years on WordPress, so it works for me. If you have any questions or do not understand, please feel free to mention them in the comments below.