BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection icon
Actively maintained Tested with WP 7.1 #2 in bot blocker

BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection

Free WordPress firewall, bot blocking, login protection, and malware scanning. See suspicious traffic and investigate threats from your dashboard.

Active installs300+100+ tier
Downloads · 30d1.2K▲ +75.3% vs prev. 30d
Rating5/58 reviews
Health score85/100Excellent
All-time downloads18.6KSince Jun 2022
Support resolved1 / 1100% in last 2 months
RequiresWP 6.1PHP 7.4+
Downloads · 7d599▲ +36.1% week over week
Our verdict

Safe pick

Yes — BitFire Security is a safe, well-maintained plugin to use in 2026. It runs on 300+ sites, is rated 5/5 and was last updated 1 week ago, and scores 85/100 on our health check.

  • Actively developed — last update 1 week ago
  • Tested with the latest WordPress (7.1)
  • Momentum — downloads up 75.3% vs the previous 30 days
  • Small user base (300+ active installs)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

67134201Jul 3Aug 16Sep 30
Yesterday21
Daily average (1y)16
Peak day269Jul 31, 2026
Last 12 months5.9K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where BitFire Security stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
bot blocker #4 180 Best bot blocker plugins →
firewall #23 964 Best firewall plugins →
malware scanner #14 246 Best malware scanner plugins →
security >100 10,000 Best security plugins →
WAF #21 299 Best WAF plugins →

Version adoption

Share of active sites per release.

  • 5.239.5%
  • 5.133.7%
  • 4.818.4%
  • 5.05.5%
  • 4.43.0%

Rating breakdown

★★★★★★★★★★ 5 from 8 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About BitFire Security

From the official readme · v5.2.4

Description

Block malicious requests. Find suspicious files. Know what is happening.

Your WordPress site can look normal while bots probe for weak passwords, exposed files, and vulnerable plugins.

BitFire Free gives you a web application firewall, bot blocking, login protection, and manual malware scanning in one WordPress dashboard. See what reaches your site, review what BitFire blocks, and investigate suspicious files without switching between tools.

Start with BitFire Free: install the plugin, follow the setup guide, and run your first malware scan. No credit card required.

See BitFire in action in 2 minutes

Take a quick tour of request filtering and the additional runtime protection available with Pro.

Useful protection starts with Free

A web application firewall
Inspect incoming requests for malicious input, including SQL-injection attempts. Review blocked requests and traffic exceptions from your dashboard. You do not need Pro to use the WAF.

Bot blocking that looks beyond the browser name
Set policies for crawlers, scanners, and other automated visitors. BitFire uses browser verification, network information, and bot reputation to help distinguish legitimate traffic from unwanted automation. A bot claiming to be Googlebot is not the same as a verified Google crawler.

Protection for your WordPress login
Help block automated login abuse and brute-force attempts. Review suspicious login traffic alongside other requests to your site.

Malware scanning with evidence you can review
Find suspicious code and unexpected file changes with a manual malware scan. Compare findings with known-good versions and see the evidence behind each alert, so you can decide what to allow, repair, or remove.

AI assistance for suspicious findings
Free includes 12 AI analysis credits for the lifetime of the domain. Use them to help assess suspicious code and understand why it was flagged. Pro includes an expanded allowance of 1,000 credits.

Traffic visibility from your dashboard
Search recorded requests by URL, IP address, browser, time, or response code. See allowed and blocked activity, then review the decision alongside the request details.

Stay in control of what gets blocked

See what BitFire blocked and why, right from your dashboard. Approve legitimate requests and manage exceptions without digging through server logs.

Your traffic, your policies, your decisions – with the evidence in front of you.

Get started with BitFire

A site can look healthy while an attacker finds a way in

An attacker does not need to change your homepage to cause damage. A vulnerable plugin can become a route to a hidden administrator account, a malicious PHP file, or code that restores an infection after cleanup.

Watch: How hackers attack your site without you knowing 2 minutes
See why a normal-looking website is not proof that everything behind it is safe.

The firewall inspects incoming requests. Pro adds protection against unauthorized file changes and administrator access, plus tools to investigate what an attacker may have left behind.

Go deeper with BitFire Pro

Keep the firewall and scanning tools in Free. Upgrade to put protection ahead of WordPress, block unauthorized actions inside your site, and hunt down hidden threats.

Always-On Protection: put security first
BitFire Pro loads before WordPress, bringing firewall inspection to PHP requests that bypass the normal plugin loading process. Your security starts earlier, giving attacks another barrier to cross.

Runtime protection: stop unauthorized operations, not just suspicious requests
A request can look harmless while exploiting a vulnerable plugin. Runtime Application Self-Protection (RASP) checks what that request is authorized to do inside your site. BitFire Pro can block:

  • Unauthorized writes to PHP files that could install a backdoor.
  • Unauthorized administrator creation or privilege changes.
  • Attempts to impersonate an administrator without the required authorization.

RASP targets the unauthorized action, not just a known attack pattern. That means a new exploit can be stopped when it attempts a protected operation, without waiting for a rule written for that specific vulnerability.

Explore runtime protection

Threat Hunter: find what brings malware back
Deleting an infected file may not remove the mechanism that created it. Threat Hunter brings six investigation areas into one WordPress workspace:

  • Startup chain: review the files loaded as WordPress starts.
  • Scheduled tasks: inspect WordPress and system cron jobs for suspicious activity.
  • Must-use plugins: investigate code that loads early and may be easy to overlook.
  • Administrator access: review accounts, sessions, application passwords, and database triggers that could restore privileged access.
  • Background processes: look for long-running PHP processes that could recreate malware.
  • Database content: inspect scripts and iframes stored in WordPress data, with AI-assisted analysis.

Connect suspicious findings to the mechanisms behind them, then take action from one investigation workspace.

See how Threat Hunter investigates hidden persistence

More scanning capacity
Pro adds scheduled malware scanning and 1,000 AI malware analysis credits. Scan on a schedule, investigate more findings, and spend less time deciphering suspicious code.

Choose your next step

Want to see what is happening on your site?
Start with BitFire Free. Complete setup, run a malware scan, and review the traffic reaching WordPress.

Need Always-On Protection, RASP, or Threat Hunter?
View current Pro pricing and multi-site discounts.

Want help with deployment or ongoing tuning?
Choose self-managed Pro or add paid Managed Protection or Priority Support for hands-on help. Find the right support option.

Questions before installing? Visit the WordPress support forum or talk to the BitFire team.

Privacy / Monitoring / Data Collection

BitFire processes security data to inspect requests, check file integrity, and investigate suspicious activity. Some features communicate with BitFire services.

  • Local traffic logs. BitFire stores security logs on your server. Logs can include IP addresses, request URLs, headers, user-agent strings, filtered request data, and security decisions. Sensitive-value filtering is designed to redact passwords, payment details, tokens, and similar fields.
  • File hash checking. BitFire sends file fingerprints to its hash service to compare with known-good files. This check sends hashes rather than file contents.
  • AI analysis. Suspicious code snippets can be sent to BitFire’s servers for AI-assisted analysis. This is separate from hash checking and can include file contents.
  • Bot verification. BitFire may send bot-related IP addresses, user-agent strings, and filtered bot request samples to its services for verification, classification, and reputation checks.
  • Error reporting. BitFire can send plugin error reports to help diagnose software problems.
  • Local storage. Logs and configuration stay on your server.

Read the BitFire privacy policy | Service terms | Ask a privacy question

Installation

  1. Install BitFire from the WordPress plugin directory, or upload the plugin files to /wp-content/plugins/bitfire/.
  2. Activate BitFire through the Plugins screen in WordPress. (this can take up to several minutes for the IP database to download)
  3. Open BitFire in your admin sidebar and follow the setup guide.
  4. Run your first malware scan and explore your traffic dashboard.

Read the setup guide and hosting requirements, including how to enable Pro Always-On Protection.

Need a hand? Talk to the BitFire team.

Frequently asked questions

Is the web application firewall included in Free?

Yes. BitFire Free includes the web application firewall, bot blocking, login protection, manual malware scanning, traffic monitoring, and 12 AI analysis credits for the lifetime of the domain. Pro adds Always-On Protection, RASP, Threat Hunter, scheduled malware scanning, and an expanded allowance of 1,000 AI analysis credits.

What does Always-On Protection add?

Free includes the firewall as a WordPress plugin. Pro Always-On Protection loads BitFire before WordPress, extending inspection to PHP requests that bypass normal plugin loading. It puts your security layer earlier in the path of an attack.

What is the difference between a firewall and RASP?

The firewall evaluates incoming requests. RASP checks whether selected operations inside the application are authorized, such as writing PHP files or creating an administrator account. They are complementary layers. An exploit that is unfamiliar to request filtering may still be blocked when it attempts an unauthorized operation covered by RASP.

Can BitFire protect against an unknown vulnerability?

Yes. Pro runtime protection can block an unknown exploit when it attempts an unauthorized PHP file write, administrator privilege change, or administrator impersonation. It checks authorization rather than waiting for a signature that identifies the specific exploit.

Can I control what gets blocked?

Yes. Review blocked requests in your dashboard, see why they were flagged, and approve legitimate traffic. Manage exceptions for your forms, store, and integrations from the same place you investigate suspicious activity.

Does BitFire block legitimate search-engine crawlers?

BitFire provides configurable bot policies. You can allow a bot, authenticate it using source-network information, or block it. Review your crawler policies during setup so the search engines and services your site relies on have the access they need.

Can I use BitFire with Cloudflare?

Yes. Keep your CDN and add protection inside WordPress. Pro RASP adds checks on unauthorized file writes and administrator changes, complementing the filtering at your site’s edge.

Can BitFire help investigate an infected site?

Start with a malware scan to find suspicious files. Then use Pro Threat Hunter to investigate what could bring the infection back: scheduled tasks, hidden administrator access, database content, startup files, and background processes. Need expert help? Talk to BitFire about cleanup and incident response.

How does AI malware analysis work?

Submit suspicious code to BitFire’s AI analysis service for help understanding what it does and why it was flagged. Use the assessment alongside scan evidence to decide what to allow, repair, or remove. Free includes 12 AI analysis credits for the lifetime of the domain. Pro includes 1,000 credits. See the malware scanning guide for workflow and usage details.

How much does Pro cost?

Pro is billed annually, with discounts for multiple sites. Optional paid Managed Protection and Priority Support packages add hands-on help. Find your plan and current pricing.

Where can I get help?

Use the WordPress support forum or the BitFire support documentation. For deployment assistance, managed protection, or questions about your hosting environment, contact the BitFire team.

Changelog

Major release with AI-powered malware analysis, reduced Pro pricing, and improved scanner performance. Recommended for all users.

5.2.4

  • Fix for support error on some pro configurations

5.2.3

  • Added recovery-safe protection that keeps WordPress accessible and alerts administrators if BitFire’s secure configuration storage becomes unavailable.
  • Hardened secure configuration discovery by validating configuration pointers as bounded data instead of executing them.
  • Improved browser verification reliability with persisted-state checks, temporary fail-open recovery, and clearer failure logging.
  • Improved verified crawler handling, including Storebot-Google authentication and better cached reverse-DNS identity.
  • Improved WooCommerce, newsletter, and anonymous REST API compatibility while keeping WordPress user endpoints protected.
  • Improved detection of HTML-entity-obfuscated request payloads.
  • Fixed malware diff handling for oversized or incomplete comparisons.
  • Improved traffic filtering and labels for browser challenge outcomes.
  • Fixed ok_apis handling and improved the auto-allow button for certain browser-verification block types.

5.2.1

  • Improved browser verification controls and challenge-page handling.
  • Fixed Elementor compatibility issue.
  • Improved/Fixed REST api catalog curation for some plugins that registered callbacks late.
  • Added dashboard filtering for JavaScript-verified browser traffic.
  • Improved fake bot and fake browser labeling in traffic views.
  • Improved bot identity hydration for fake crawler impersonation cases.
  • Updated plugin copy, privacy details, and WordPress compatibility metadata.
  • Fixed a bug that could prevent browser verification from running for some sites when the setting was toggled on and off repeatedly
  • Refactored browser verification path to make WordPress AI checks pass

5.1.5

  • Bots impersonating crawlers (bing, meta, google, etc) are not blocked for simple unrestricted GET requests
  • Added daily fetch data for supplemental crawler dns / cidr lists
  • Improved server IP address detection for allowing local server loop back calls
  • Added plugin inventory hiding to malware detection capabilities
  • Malware detections for plugins missing valid headers / plugin scripts
  • Malware detections for plugins with random identifiers in them
  • Improved logging of xmlrpc requests – now records list of method names – not raw xml
  • Added ability to allow users to delete / restore entire plugins if they are only malware (not official plugins with strong malware signals)
  • Binary files are excluded from malware diffs now
  • Reduced false positives for SQL injection
  • Bot Control panel links to dashboard filter user agents better
  • AI verdict results are now stored for future reference
  • Fix deprecation warning for http response headers on PHP 8.5
  • Removed dependency on filter_var extension
  • Added expert opinion check allowing admins to request a review of potential malware samples by BitFire staff

5.1.4

  • Fixed an issue that could allow some admin-ajax requests to recieve a browser challenge for the logged in admin on first install
  • Added additional filtering to cover unknown authorization values, provider keys, and hexadecimal tokens in log storage
  • Added daily updated list of allowed network ranges for core web and AI crawers
  • Improved chaching of DNS lookups for core web bots
  • Added additional bot telemetry gating for bitfire core enable flag

5.1.3

  • fixed an issue with bot triage recomendations that could generate fatal errors on some host in a background task

Full changelog on WordPress.org →

Screenshots

Understand your traffic: review recorded requests, visitor information, and whether BitFire allowed or blocked the request.
Understand your traffic: review recorded requests, visitor information, and whether…
Control bot access: review crawler policies and decide which automated visitors should reach your site.
Control bot access: review crawler policies and decide which automated visitors should…
Investigate suspicious files: compare scan findings with known-good files before deciding what to allow, repair, or remove.
Investigate suspicious files: compare scan findings with known-good files before deciding…
Find the request that matters: filter traffic by time, browser, URL, IP address, or response code.
Find the request that matters: filter traffic by time, browser, URL, IP address, or…
Review suspicious links: inspect database scan findings in posts and comments.
Review suspicious links: inspect database scan findings in posts and comments.
Keep up with security activity: review daily and weekly status emails.
Keep up with security activity: review daily and weekly status emails.
Manage protection settings: review available controls from the WordPress dashboard.
Manage protection settings: review available controls from the WordPress dashboard.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best BitFire Security alternatives

All bot blocker plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Better Robots.txt – AI-Ready Crawl Control & Bot Governance Better Robots.txt – AI-Ready Crawl Control & Bot Governance Replace the default WordPress robots.txt workflow with a smarter, structured version you… by Pagup 5K+ ★★★★★★★★★★ 4.5 (102) 2 weeks ago 87
3 Invisible Anti Spam for Contact Form 7 (Simple No-Bot) Invisible Anti Spam for Contact Form 7 (Simple No-Bot) Simple, lightweight, no captcha, no configuration. Just works. by lilaeamedia 200+ ★★★★★★★★★★ 2.3 (3) 7 years ago 25
4 AI Scraping Protector AI Scraping Protector Protect your WordPress content from AI scraping bots with advanced detection, rate… by Debashish Mondal 100+ ★★★★★★★★★★ 5 (2) 1 year ago 41
5 WhoKnew Shield — Email, Phone & Address Security WhoKnew Shield — Email, Phone & Address Security Security plugin blocking spam bots from harvesting email addresses, phone numbers &… by WhoKnew.io 20+ ★★★★★★★★★★ 5 (1) 1 month ago 70
6 AI Crawlers Visibility, Analytics & Control AI Crawlers Visibility, Analytics & Control Monitor AI crawlers and MCP traffic, inventory agents and tools, control access, and… by miniOrange 10+ ★★★★★★★★★★ 5 (1) 3 hours ago 68
7 Fstyle Honeypot Bot Blocker Fstyle Honeypot Bot Blocker Protect your site from malicious bots and scanners using a smart honeypot trap. by fstylegear09543 10+ ★★★★★★★★★★ No reviews 4 months ago 51
8 Nullis Shield Nullis Shield A Prevention-First security engine that eliminates bots before they hit your database… by Edward Samuel (Enigmaking) 10+ ★★★★★★★★★★ 5 (1) 1 month ago 64
9 Bravo Crawl Hunter – AI Crawl Blocker, Block AI Bots & Crawlers Bravo Crawl Hunter The best AI Crawl Blocker for WordPress. Block AI crawlers, AI scrapers, bad bots, spam… by Jumedeen khan <10 ★★★★★★★★★★ No reviews 3 weeks ago 64
10 Predax Security – VPN, Proxy, Tor, Bot Blocker & Firewall Predax Security – VPN, Proxy, Tor, Bot Blocker & Firewall Blocks VPNs, proxies, Tor, datacenter IPs and bad bots. Plus firewall, login protection and… by Predax <10 ★★★★★★★★★★ No reviews 1 week ago 64

FAQ

BitFire Security: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 1, 2026

Is BitFire Security free?

Yes. BitFire Security is free to download and use from the official WordPress.org plugin directory.

Is BitFire Security safe to use in 2026?

Yes — BitFire Security is a safe, well-maintained plugin to use in 2026. It runs on 300+ sites, is rated 5/5 and was last updated 1 week ago, and scores 85/100 on our health check.

How many websites use BitFire Security?

BitFire Security is active on 300+ WordPress websites and has been downloaded 18,555 times since it launched in June 2022. It was downloaded 1,220 times in the last 30 days.

Does BitFire Security work with WordPress 7.1?

Yes. The developer has tested BitFire Security up to WordPress 7.1.2, the latest release. It requires WordPress 6.1 or newer.

What PHP version does BitFire Security need?

BitFire Security requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was BitFire Security last updated?

The latest version, 5.2.4, was released on September 24, 2026 (1 week ago).

Who makes BitFire Security?

BitFire Security is developed and maintained by Cory Marsh.

What are the best alternatives to BitFire Security?

The most popular alternatives to BitFire Security are Better Robots.txt (5K+ installs), Invisible Anti Spam for Con… (200+ installs) and AI Scraping Protector (100+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.