BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection
BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection

BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection

5/5 (8 ratings) 300 active installs Updated Sep 24, 2026
Understand your traffic: review recorded requests, visitor information, and whether BitFire allowed or blocked the request.

Understand your traffic: review recorded requests, visitor information, and whether BitFire allowed or blocked the request.

Block malicious requests. Find suspicious files. Know what is happening.

Your WordPress site can look normal while bots probe for weak passwords, exposed files, and vulnerable plugins.

BitFire Free gives you a web application firewall, bot blocking, login protection, and manual malware scanning in one WordPress dashboard. See what reaches your site, review what BitFire blocks, and investigate suspicious files without switching between tools.

Start with BitFire Free: install the plugin, follow the setup guide, and run your first malware scan. No credit card required.

See BitFire in action in 2 minutes

Take a quick tour of request filtering and the additional runtime protection available with Pro.

Useful protection starts with Free

A web application firewall
Inspect incoming requests for malicious input, including SQL-injection attempts. Review blocked requests and traffic exceptions from your dashboard. You do not need Pro to use the WAF.

Bot blocking that looks beyond the browser name
Set policies for crawlers, scanners, and other automated visitors. BitFire uses browser verification, network information, and bot reputation to help distinguish legitimate traffic from unwanted automation. A bot claiming to be Googlebot is not the same as a verified Google crawler.

Protection for your WordPress login
Help block automated login abuse and brute-force attempts. Review suspicious login traffic alongside other requests to your site.

Malware scanning with evidence you can review
Find suspicious code and unexpected file changes with a manual malware scan. Compare findings with known-good versions and see the evidence behind each alert, so you can decide what to allow, repair, or remove.

AI assistance for suspicious findings
Free includes 12 AI analysis credits for the lifetime of the domain. Use them to help assess suspicious code and understand why it was flagged. Pro includes an expanded allowance of 1,000 credits.

Traffic visibility from your dashboard
Search recorded requests by URL, IP address, browser, time, or response code. See allowed and blocked activity, then review the decision alongside the request details.

Stay in control of what gets blocked

See what BitFire blocked and why, right from your dashboard. Approve legitimate requests and manage exceptions without digging through server logs.

Your traffic, your policies, your decisions – with the evidence in front of you.

Get started with BitFire

A site can look healthy while an attacker finds a way in

An attacker does not need to change your homepage to cause damage. A vulnerable plugin can become a route to a hidden administrator account, a malicious PHP file, or code that restores an infection after cleanup.

Watch: How hackers attack your site without you knowing 2 minutes
See why a normal-looking website is not proof that everything behind it is safe.

The firewall inspects incoming requests. Pro adds protection against unauthorized file changes and administrator access, plus tools to investigate what an attacker may have left behind.

Go deeper with BitFire Pro

Keep the firewall and scanning tools in Free. Upgrade to put protection ahead of WordPress, block unauthorized actions inside your site, and hunt down hidden threats.

Always-On Protection: put security first
BitFire Pro loads before WordPress, bringing firewall inspection to PHP requests that bypass the normal plugin loading process. Your security starts earlier, giving attacks another barrier to cross.

Runtime protection: stop unauthorized operations, not just suspicious requests
A request can look harmless while exploiting a vulnerable plugin. Runtime Application Self-Protection (RASP) checks what that request is authorized to do inside your site. BitFire Pro can block:

  • Unauthorized writes to PHP files that could install a backdoor.
  • Unauthorized administrator creation or privilege changes.
  • Attempts to impersonate an administrator without the required authorization.

RASP targets the unauthorized action, not just a known attack pattern. That means a new exploit can be stopped when it attempts a protected operation, without waiting for a rule written for that specific vulnerability.

Explore runtime protection

Threat Hunter: find what brings malware back
Deleting an infected file may not remove the mechanism that created it. Threat Hunter brings six investigation areas into one WordPress workspace:

  • Startup chain: review the files loaded as WordPress starts.
  • Scheduled tasks: inspect WordPress and system cron jobs for suspicious activity.
  • Must-use plugins: investigate code that loads early and may be easy to overlook.
  • Administrator access: review accounts, sessions, application passwords, and database triggers that could restore privileged access.
  • Background processes: look for long-running PHP processes that could recreate malware.
  • Database content: inspect scripts and iframes stored in WordPress data, with AI-assisted analysis.

Connect suspicious findings to the mechanisms behind them, then take action from one investigation workspace.

See how Threat Hunter investigates hidden persistence

More scanning capacity
Pro adds scheduled malware scanning and 1,000 AI malware analysis credits. Scan on a schedule, investigate more findings, and spend less time deciphering suspicious code.

Choose your next step

Want to see what is happening on your site?
Start with BitFire Free. Complete setup, run a malware scan, and review the traffic reaching WordPress.

Need Always-On Protection, RASP, or Threat Hunter?
View current Pro pricing and multi-site discounts.

Want help with deployment or ongoing tuning?
Choose self-managed Pro or add paid Managed Protection or Priority Support for hands-on help. Find the right support option.

Questions before installing? Visit the WordPress support forum or talk to the BitFire team.

Privacy / Monitoring / Data Collection

BitFire processes security data to inspect requests, check file integrity, and investigate suspicious activity. Some features communicate with BitFire services.

  • Local traffic logs. BitFire stores security logs on your server. Logs can include IP addresses, request URLs, headers, user-agent strings, filtered request data, and security decisions. Sensitive-value filtering is designed to redact passwords, payment details, tokens, and similar fields.
  • File hash checking. BitFire sends file fingerprints to its hash service to compare with known-good files. This check sends hashes rather than file contents.
  • AI analysis. Suspicious code snippets can be sent to BitFire’s servers for AI-assisted analysis. This is separate from hash checking and can include file contents.
  • Bot verification. BitFire may send bot-related IP addresses, user-agent strings, and filtered bot request samples to its services for verification, classification, and reputation checks.
  • Error reporting. BitFire can send plugin error reports to help diagnose software problems.
  • Local storage. Logs and configuration stay on your server.

Read the BitFire privacy policy | Service terms | Ask a privacy question