BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection
Free WordPress firewall, bot blocking, login protection, and malware scanning. See suspicious traffic and investigate threats from your dashboard.
Safe pick
Yes — BitFire Security is a safe, well-maintained plugin to use in 2026. It runs on 300+ sites, is rated 5/5 and was last updated 1 week ago, and scores 85/100 on our health check.
- Actively developed — last update 1 week ago
- Tested with the latest WordPress (7.1)
- Momentum — downloads up 75.3% vs the previous 30 days
- Small user base (300+ active installs)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where BitFire Security stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| bot blocker | #4 |
| firewall | #23 |
| malware scanner | #14 |
| security | >100 |
| WAF | #21 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 8 reviews
About BitFire Security
From the official readme · v5.2.4Description
Block malicious requests. Find suspicious files. Know what is happening.
Your WordPress site can look normal while bots probe for weak passwords, exposed files, and vulnerable plugins.
BitFire Free gives you a web application firewall, bot blocking, login protection, and manual malware scanning in one WordPress dashboard. See what reaches your site, review what BitFire blocks, and investigate suspicious files without switching between tools.
Start with BitFire Free: install the plugin, follow the setup guide, and run your first malware scan. No credit card required.
See BitFire in action in 2 minutes
Take a quick tour of request filtering and the additional runtime protection available with Pro.
Useful protection starts with Free
A web application firewall
Inspect incoming requests for malicious input, including SQL-injection attempts. Review blocked requests and traffic exceptions from your dashboard. You do not need Pro to use the WAF.
Bot blocking that looks beyond the browser name
Set policies for crawlers, scanners, and other automated visitors. BitFire uses browser verification, network information, and bot reputation to help distinguish legitimate traffic from unwanted automation. A bot claiming to be Googlebot is not the same as a verified Google crawler.
Protection for your WordPress login
Help block automated login abuse and brute-force attempts. Review suspicious login traffic alongside other requests to your site.
Malware scanning with evidence you can review
Find suspicious code and unexpected file changes with a manual malware scan. Compare findings with known-good versions and see the evidence behind each alert, so you can decide what to allow, repair, or remove.
AI assistance for suspicious findings
Free includes 12 AI analysis credits for the lifetime of the domain. Use them to help assess suspicious code and understand why it was flagged. Pro includes an expanded allowance of 1,000 credits.
Traffic visibility from your dashboard
Search recorded requests by URL, IP address, browser, time, or response code. See allowed and blocked activity, then review the decision alongside the request details.
Stay in control of what gets blocked
See what BitFire blocked and why, right from your dashboard. Approve legitimate requests and manage exceptions without digging through server logs.
Your traffic, your policies, your decisions – with the evidence in front of you.
A site can look healthy while an attacker finds a way in
An attacker does not need to change your homepage to cause damage. A vulnerable plugin can become a route to a hidden administrator account, a malicious PHP file, or code that restores an infection after cleanup.
Watch: How hackers attack your site without you knowing 2 minutes
See why a normal-looking website is not proof that everything behind it is safe.
The firewall inspects incoming requests. Pro adds protection against unauthorized file changes and administrator access, plus tools to investigate what an attacker may have left behind.
Go deeper with BitFire Pro
Keep the firewall and scanning tools in Free. Upgrade to put protection ahead of WordPress, block unauthorized actions inside your site, and hunt down hidden threats.
Always-On Protection: put security first
BitFire Pro loads before WordPress, bringing firewall inspection to PHP requests that bypass the normal plugin loading process. Your security starts earlier, giving attacks another barrier to cross.
Runtime protection: stop unauthorized operations, not just suspicious requests
A request can look harmless while exploiting a vulnerable plugin. Runtime Application Self-Protection (RASP) checks what that request is authorized to do inside your site. BitFire Pro can block:
- Unauthorized writes to PHP files that could install a backdoor.
- Unauthorized administrator creation or privilege changes.
- Attempts to impersonate an administrator without the required authorization.
RASP targets the unauthorized action, not just a known attack pattern. That means a new exploit can be stopped when it attempts a protected operation, without waiting for a rule written for that specific vulnerability.
Threat Hunter: find what brings malware back
Deleting an infected file may not remove the mechanism that created it. Threat Hunter brings six investigation areas into one WordPress workspace:
- Startup chain: review the files loaded as WordPress starts.
- Scheduled tasks: inspect WordPress and system cron jobs for suspicious activity.
- Must-use plugins: investigate code that loads early and may be easy to overlook.
- Administrator access: review accounts, sessions, application passwords, and database triggers that could restore privileged access.
- Background processes: look for long-running PHP processes that could recreate malware.
- Database content: inspect scripts and iframes stored in WordPress data, with AI-assisted analysis.
Connect suspicious findings to the mechanisms behind them, then take action from one investigation workspace.
See how Threat Hunter investigates hidden persistence
More scanning capacity
Pro adds scheduled malware scanning and 1,000 AI malware analysis credits. Scan on a schedule, investigate more findings, and spend less time deciphering suspicious code.
Choose your next step
Want to see what is happening on your site?
Start with BitFire Free. Complete setup, run a malware scan, and review the traffic reaching WordPress.
Need Always-On Protection, RASP, or Threat Hunter?
View current Pro pricing and multi-site discounts.
Want help with deployment or ongoing tuning?
Choose self-managed Pro or add paid Managed Protection or Priority Support for hands-on help. Find the right support option.
Questions before installing? Visit the WordPress support forum or talk to the BitFire team.
Privacy / Monitoring / Data Collection
BitFire processes security data to inspect requests, check file integrity, and investigate suspicious activity. Some features communicate with BitFire services.
- Local traffic logs. BitFire stores security logs on your server. Logs can include IP addresses, request URLs, headers, user-agent strings, filtered request data, and security decisions. Sensitive-value filtering is designed to redact passwords, payment details, tokens, and similar fields.
- File hash checking. BitFire sends file fingerprints to its hash service to compare with known-good files. This check sends hashes rather than file contents.
- AI analysis. Suspicious code snippets can be sent to BitFire’s servers for AI-assisted analysis. This is separate from hash checking and can include file contents.
- Bot verification. BitFire may send bot-related IP addresses, user-agent strings, and filtered bot request samples to its services for verification, classification, and reputation checks.
- Error reporting. BitFire can send plugin error reports to help diagnose software problems.
- Local storage. Logs and configuration stay on your server.
Read the BitFire privacy policy | Service terms | Ask a privacy question
Installation
- Install BitFire from the WordPress plugin directory, or upload the plugin files to
/wp-content/plugins/bitfire/. - Activate BitFire through the Plugins screen in WordPress. (this can take up to several minutes for the IP database to download)
- Open BitFire in your admin sidebar and follow the setup guide.
- Run your first malware scan and explore your traffic dashboard.
Read the setup guide and hosting requirements, including how to enable Pro Always-On Protection.
Need a hand? Talk to the BitFire team.
Frequently asked questions
Is the web application firewall included in Free?
Yes. BitFire Free includes the web application firewall, bot blocking, login protection, manual malware scanning, traffic monitoring, and 12 AI analysis credits for the lifetime of the domain. Pro adds Always-On Protection, RASP, Threat Hunter, scheduled malware scanning, and an expanded allowance of 1,000 AI analysis credits.
What does Always-On Protection add?
Free includes the firewall as a WordPress plugin. Pro Always-On Protection loads BitFire before WordPress, extending inspection to PHP requests that bypass normal plugin loading. It puts your security layer earlier in the path of an attack.
What is the difference between a firewall and RASP?
The firewall evaluates incoming requests. RASP checks whether selected operations inside the application are authorized, such as writing PHP files or creating an administrator account. They are complementary layers. An exploit that is unfamiliar to request filtering may still be blocked when it attempts an unauthorized operation covered by RASP.
Can BitFire protect against an unknown vulnerability?
Yes. Pro runtime protection can block an unknown exploit when it attempts an unauthorized PHP file write, administrator privilege change, or administrator impersonation. It checks authorization rather than waiting for a signature that identifies the specific exploit.
Can I control what gets blocked?
Yes. Review blocked requests in your dashboard, see why they were flagged, and approve legitimate traffic. Manage exceptions for your forms, store, and integrations from the same place you investigate suspicious activity.
Does BitFire block legitimate search-engine crawlers?
BitFire provides configurable bot policies. You can allow a bot, authenticate it using source-network information, or block it. Review your crawler policies during setup so the search engines and services your site relies on have the access they need.
Can I use BitFire with Cloudflare?
Yes. Keep your CDN and add protection inside WordPress. Pro RASP adds checks on unauthorized file writes and administrator changes, complementing the filtering at your site’s edge.
Can BitFire help investigate an infected site?
Start with a malware scan to find suspicious files. Then use Pro Threat Hunter to investigate what could bring the infection back: scheduled tasks, hidden administrator access, database content, startup files, and background processes. Need expert help? Talk to BitFire about cleanup and incident response.
How does AI malware analysis work?
Submit suspicious code to BitFire’s AI analysis service for help understanding what it does and why it was flagged. Use the assessment alongside scan evidence to decide what to allow, repair, or remove. Free includes 12 AI analysis credits for the lifetime of the domain. Pro includes 1,000 credits. See the malware scanning guide for workflow and usage details.
How much does Pro cost?
Pro is billed annually, with discounts for multiple sites. Optional paid Managed Protection and Priority Support packages add hands-on help. Find your plan and current pricing.
Where can I get help?
Use the WordPress support forum or the BitFire support documentation. For deployment assistance, managed protection, or questions about your hosting environment, contact the BitFire team.
Changelog
Major release with AI-powered malware analysis, reduced Pro pricing, and improved scanner performance. Recommended for all users.
5.2.4
- Fix for support error on some pro configurations
5.2.3
- Added recovery-safe protection that keeps WordPress accessible and alerts administrators if BitFire’s secure configuration storage becomes unavailable.
- Hardened secure configuration discovery by validating configuration pointers as bounded data instead of executing them.
- Improved browser verification reliability with persisted-state checks, temporary fail-open recovery, and clearer failure logging.
- Improved verified crawler handling, including Storebot-Google authentication and better cached reverse-DNS identity.
- Improved WooCommerce, newsletter, and anonymous REST API compatibility while keeping WordPress user endpoints protected.
- Improved detection of HTML-entity-obfuscated request payloads.
- Fixed malware diff handling for oversized or incomplete comparisons.
- Improved traffic filtering and labels for browser challenge outcomes.
- Fixed
ok_apishandling and improved the auto-allow button for certain browser-verification block types.
5.2.1
- Improved browser verification controls and challenge-page handling.
- Fixed Elementor compatibility issue.
- Improved/Fixed REST api catalog curation for some plugins that registered callbacks late.
- Added dashboard filtering for JavaScript-verified browser traffic.
- Improved fake bot and fake browser labeling in traffic views.
- Improved bot identity hydration for fake crawler impersonation cases.
- Updated plugin copy, privacy details, and WordPress compatibility metadata.
- Fixed a bug that could prevent browser verification from running for some sites when the setting was toggled on and off repeatedly
- Refactored browser verification path to make WordPress AI checks pass
5.1.5
- Bots impersonating crawlers (bing, meta, google, etc) are not blocked for simple unrestricted GET requests
- Added daily fetch data for supplemental crawler dns / cidr lists
- Improved server IP address detection for allowing local server loop back calls
- Added plugin inventory hiding to malware detection capabilities
- Malware detections for plugins missing valid headers / plugin scripts
- Malware detections for plugins with random identifiers in them
- Improved logging of xmlrpc requests – now records list of method names – not raw xml
- Added ability to allow users to delete / restore entire plugins if they are only malware (not official plugins with strong malware signals)
- Binary files are excluded from malware diffs now
- Reduced false positives for SQL injection
- Bot Control panel links to dashboard filter user agents better
- AI verdict results are now stored for future reference
- Fix deprecation warning for http response headers on PHP 8.5
- Removed dependency on filter_var extension
- Added expert opinion check allowing admins to request a review of potential malware samples by BitFire staff
5.1.4
- Fixed an issue that could allow some admin-ajax requests to recieve a browser challenge for the logged in admin on first install
- Added additional filtering to cover unknown authorization values, provider keys, and hexadecimal tokens in log storage
- Added daily updated list of allowed network ranges for core web and AI crawers
- Improved chaching of DNS lookups for core web bots
- Added additional bot telemetry gating for bitfire core enable flag
5.1.3
- fixed an issue with bot triage recomendations that could generate fatal errors on some host in a background task
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best BitFire Security alternatives
All bot blocker plugins →FAQ
BitFire Security: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 1, 2026
Is BitFire Security free?
Yes. BitFire Security is free to download and use from the official WordPress.org plugin directory.
Is BitFire Security safe to use in 2026?
Yes — BitFire Security is a safe, well-maintained plugin to use in 2026. It runs on 300+ sites, is rated 5/5 and was last updated 1 week ago, and scores 85/100 on our health check.
How many websites use BitFire Security?
BitFire Security is active on 300+ WordPress websites and has been downloaded 18,555 times since it launched in June 2022. It was downloaded 1,220 times in the last 30 days.
Does BitFire Security work with WordPress 7.1?
Yes. The developer has tested BitFire Security up to WordPress 7.1.2, the latest release. It requires WordPress 6.1 or newer.
What PHP version does BitFire Security need?
BitFire Security requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was BitFire Security last updated?
The latest version, 5.2.4, was released on September 24, 2026 (1 week ago).
Who makes BitFire Security?
BitFire Security is developed and maintained by Cory Marsh.
What are the best alternatives to BitFire Security?
The most popular alternatives to BitFire Security are Better Robots.txt (5K+ installs), Invisible Anti Spam for Con… (200+ installs) and AI Scraping Protector (100+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card