[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQoffrvt4-WLuPlgvDUkfPC4frwtJPiZAllrEOrHDpLY":3,"$fMxVHxuNFBG27kj2nffJFH9CtLMagG1L1zoaPhTUKXzM":135,"$frFHnj-JPJIfm-ucG4G_GRZKcOORWI5cLOlxwqvXjDH4":140},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":16,"download_link":23,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26,"discovery_status":27,"vulnerabilities":28,"developer":29,"crawl_stats":25,"alternatives":34,"analysis":25,"fingerprints":25},"fstyle-honeypot-bot-blocker","Fstyle Honeypot Bot Blocker","1.1.1","fstylegear09543","https:\u002F\u002Fprofiles.wordpress.org\u002Ffstylegear09543\u002F","\u003Cp>Stop malicious bots and scanners instantly using a smart honeypot trap.\u003C\u002Fp>\n\u003Cp>Protect your website from unauthorized crawlers and malicious bots that ignore your site’s robots.txt directives. Fstyle Honeypot Bot Blocker provides a lightweight yet powerful security layer by automatically detecting and blocking intruders.\u003C\u002Fp>\n\u003Cp>Once installed, it sets a hidden trap path in your robots.txt. If a bot attempts to access this forbidden area, its IP address is immediately captured and blocked from accessing your entire site.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Instant Honeypot Block\u003C\u002Fstrong>: Automatically adds a trap path to your robots.txt.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP Management Dashboard\u003C\u002Fstrong>: View detailed logs of blocked IP addresses and manage them easily.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Whitelist\u003C\u002Fstrong>: Add trusted service IPs to prevent accidental lockouts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ultra-Lightweight\u003C\u002Fstrong>: Built for performance with minimal database impact.\u003C\u002Fli>\n\u003C\u002Ful>\n","Protect your site from malicious bots and scanners using a smart honeypot trap.",0,144,"2026-05-21T12:00:00.000Z","7.0.2","5.0","",[18,19,20,21,22],"anti-spam","bot-blocker","firewall","honeypot","security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffstyle-honeypot-bot-blocker.1.1.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":30,"total_installs":11,"avg_security_score":24,"avg_patch_time_days":31,"trust_score":32,"computed_at":33},2,30,94,"2026-08-28T18:52:22.752Z",[35,56,77,95,115],{"slug":36,"name":37,"version":38,"author":39,"author_profile":40,"description":41,"short_description":42,"active_installs":43,"downloaded":44,"rating":32,"num_ratings":45,"last_updated":46,"tested_up_to":14,"requires_at_least":47,"requires_php":48,"tags":49,"homepage":52,"download_link":53,"security_score":54,"vuln_count":30,"unpatched_count":11,"last_vuln_date":55,"fetched_at":26},"blackhole-bad-bots","Blackhole for Bad Bots","3.8.2","Jeff Starr","https:\u002F\u002Fprofiles.wordpress.org\u002Fspecialk\u002F","\u003Cblockquote>\n\u003Cp>✨ Trap bad bots in a virtual black hole\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>Important:\u003C\u002Fstrong> Do NOT use this plugin on sites with caching. \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fimportant-do-not-use-on-sites-with-caching\u002F\" rel=\"ugc\">Learn more&nbsp;&raquo;\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>👾 Bye bye bad bots..\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Bad bots are the worst. They do all sorts of nasty stuff and waste server resources. The Blackhole plugin helps to stop bad bots and save precious resources for legit visitors.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>👾 How does it work?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>First the plugin adds a hidden trigger link to the footer of your pages. You then add a line to your robots.txt file that forbids all bots from following the hidden link. Bots that then ignore or disobey your robots rules will crawl the link and fall into the trap. Once trapped, bad bots are denied further access to your WordPress site.\u003C\u002Fp>\n\u003Cp>I call it the “one-strike” rule: bots have one chance to obey your site’s robots.txt rule. Failure to comply results in immediate banishment. The best part is that the Blackhole only affects bad bots: human users never see the hidden link, and good bots obey the robots rules in the first place. Win-win! 🙂\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>✨ Add a blackhole trap to help stop bad bots\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>Important:\u003C\u002Fstrong> Do NOT use this plugin on sites with caching. \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fimportant-do-not-use-on-sites-with-caching\u002F\" rel=\"ugc\">Learn more&nbsp;&raquo;\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>👾 Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Easy to set up\u003C\u002Fli>\n\u003Cli>Squeaky clean code\u003C\u002Fli>\n\u003Cli>Focused and modular\u003C\u002Fli>\n\u003Cli>Lightweight, fast and flexible\u003C\u002Fli>\n\u003Cli>Built with the WordPress API\u003C\u002Fli>\n\u003Cli>Works with other security plugins\u003C\u002Fli>\n\u003Cli>Easy to reset the list of bad bots\u003C\u002Fli>\n\u003Cli>Easy to delete any bot from the list\u003C\u002Fli>\n\u003Cli>Regularly updated and “future proof”\u003C\u002Fli>\n\u003Cli>Blackhole link includes “nofollow” attribute\u003C\u002Fli>\n\u003Cli>Plugin options configurable via settings screen\u003C\u002Fli>\n\u003Cli>Works silently behind the scenes to protect your site\u003C\u002Fli>\n\u003Cli>Whitelists all major search engines to never block\u003C\u002Fli>\n\u003Cli>Focused on flexibility, performance, and security\u003C\u002Fli>\n\u003Cli>Email alerts with WHOIS lookup for blocked bots\u003C\u002Fli>\n\u003Cli>Complete inline documentation via the Help tab\u003C\u002Fli>\n\u003Cli>Provides setting to whitelist any IP addresses\u003C\u002Fli>\n\u003Cli>Customize the message displayed to bad bots 😉\u003C\u002Fli>\n\u003Cli>One-click restore the plugin default options\u003C\u002Fli>\n\u003Cli>Does NOT use or require any .htaccess rules\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Blackhole for Bad Bots protects your site against bad bots, spammers, scrapers, scanners, and other automated threats.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>✨ Not using WordPress? Check out the \u003Ca href=\"https:\u002F\u002Fperishablepress.com\u002Fblackhole-bad-bots\u002F\" rel=\"nofollow ugc\">standalone PHP version of Blackhole\u003C\u002Fa>!\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>👾 Whitelist\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>By default, this plugin does NOT block any of the major search engines (user agents):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>AOL.com\u003C\u002Fli>\n\u003Cli>Baidu\u003C\u002Fli>\n\u003Cli>Bingbot\u002FMSN\u003C\u002Fli>\n\u003Cli>DuckDuckGo\u003C\u002Fli>\n\u003Cli>Googlebot\u003C\u002Fli>\n\u003Cli>Teoma\u003C\u002Fli>\n\u003Cli>Yahoo!\u003C\u002Fli>\n\u003Cli>Yandex\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>These search engines (and all of their myriad variations) are whitelisted via user agent. So are a bunch of other “useful” bots. They always are allowed full access to your site, even if they disobey your robots.txt rules. This list can be customized in the plugin settings. For a complete list of whitelisted bots, visit the Help tab in the plugin settings (under “Whitelist Settings”).\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>✨ Check out \u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fblackhole-pro\u002F\" rel=\"nofollow ugc\">Blackhole Pro\u003C\u002Fa> and level up with advanced features!\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>👾 Exclusive Pro Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Option to disable for logged-in users\u003C\u002Fli>\n\u003Cli>Threshold control (number of allowed hits)\u003C\u002Fli>\n\u003Cli>Custom email alerts\u003C\u002Fli>\n\u003Cli>Custom messages for blocked bots\u003C\u002Fli>\n\u003Cli>Custom redirect for blocked bots\u003C\u002Fli>\n\u003Cli>Custom blackhole trigger links\u003C\u002Fli>\n\u003Cli>Complete inline documentation\u003C\u002Fli>\n\u003Cli>Block bots based on user agent\u003C\u002Fli>\n\u003Cli>Block bots based on IP address\u003C\u002Fli>\n\u003Cli>Whitelist\u002Fallow bots by user agent\u003C\u002Fli>\n\u003Cli>Whitelist\u002Fallow bots by IP address\u003C\u002Fli>\n\u003Cli>Redirect whitelisted bots\u003C\u002Fli>\n\u003Cli>Set custom HTTP Status Code\u003C\u002Fli>\n\u003Cli>Full-featured Bad Bot Log with paging, sorting, and field search\u003C\u002Fli>\n\u003Cli>Manually add bad bots to the Bad Bot Log\u003C\u002Fli>\n\u003Cli>Geo\u002FIP location lookups for each bad bot\u003C\u002Fli>\n\u003Cli>Logs number of blocked hits for each bot\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>..plus everything the free version can do and more.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>✨ Learn more and \u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fblackhole-pro\u002F\" rel=\"nofollow ugc\">get Blackhole Pro &raquo;\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>👾 Privacy\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>User Data:\u003C\u002Fstrong> This plugin automatically blocks bad bots. When bad bots fall into the trap, their IP address, user agent, and other request data are stored in the WP database. No other user data is collected by this plugin. At any time, the administrator may delete all saved data via the plugin settings.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Services:\u003C\u002Fstrong> This plugin does not connect to any third-party locations or services.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Cookies:\u003C\u002Fstrong> This plugin does not set any cookies.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Credit:\u003C\u002Fstrong> Header Image Courtesy NASA\u002FJPL-Caltech.\u003C\u002Fp>\n\u003Cp>Blackhole for Bad Bots is developed and maintained by \u003Ca href=\"https:\u002F\u002Fx.com\u002Fperishable\" rel=\"nofollow ugc\">Jeff Starr\u003C\u002Fa>, 15-year \u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002F\" rel=\"nofollow ugc\">WordPress developer\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fbooks.perishablepress.com\u002F\" rel=\"nofollow ugc\">book author\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>👾 Support development\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>I develop and maintain this free plugin with love for the WordPress community. To show support, you can \u003Ca href=\"https:\u002F\u002Fmonzillamedia.com\u002Fdonate.html\" rel=\"nofollow ugc\">make a donation\u003C\u002Fa> or purchase one of my books:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwp-tao.com\u002F\" rel=\"nofollow ugc\">The Tao of WordPress\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdigwp.com\u002F\" rel=\"nofollow ugc\">Digging into WordPress\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fhtaccessbook.com\u002F\" rel=\"nofollow ugc\">.htaccess made easy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwp-tao.com\u002Fwordpress-themes-book\u002F\" rel=\"nofollow ugc\">WordPress Themes In Depth\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fbooks.perishablepress.com\u002Fdownloads\u002Fwizards-collection-sql-recipes-wordpress\u002F\" rel=\"nofollow ugc\">Wizard’s SQL Recipes for WordPress\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>And\u002For purchase one of my premium WordPress plugins:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fbbq-pro\u002F\" rel=\"nofollow ugc\">BBQ Pro\u003C\u002Fa> – Blazing fast WordPress firewall\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fblackhole-pro\u002F\" rel=\"nofollow ugc\">Blackhole Pro\u003C\u002Fa> – Automatically block bad bots\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fbanhammer-pro\u002F\" rel=\"nofollow ugc\">Banhammer Pro\u003C\u002Fa> – Monitor traffic and ban the bad guys\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fga-google-analytics-pro\u002F\" rel=\"nofollow ugc\">GA Google Analytics Pro\u003C\u002Fa> – Connect WordPress to Google Analytics\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fhead-meta-pro\u002F\" rel=\"nofollow ugc\">Head Meta Pro\u003C\u002Fa> – Ultimate Meta Tags for WordPress\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Frest-pro-tools\u002F\" rel=\"nofollow ugc\">REST Pro Tools\u003C\u002Fa> – Awesome tools for managing the WP REST API\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fsimple-ajax-chat-pro\u002F\" rel=\"nofollow ugc\">Simple Ajax Chat Pro\u003C\u002Fa> – Unlimited chat rooms\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fplugin-planet.com\u002Fusp-pro\u002F\" rel=\"nofollow ugc\">USP Pro\u003C\u002Fa> – Unlimited front-end forms\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Links, tweets and likes also appreciated. Thank you! 🙂\u003C\u002Fp>\n","Blackhole is a WordPress security plugin that detects and traps bad bots in a virtual black hole, where they are denied access to your entire site.",30000,929063,148,"2026-04-21T17:48:00.000Z","4.7","5.6.20",[18,50,51,21,22],"blackhole","bots","https:\u002F\u002Fperishablepress.com\u002Fblackhole-bad-bots\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fblackhole-bad-bots.3.8.2.zip",91,"2026-03-25 00:00:00",{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":64,"downloaded":65,"rating":24,"num_ratings":66,"last_updated":67,"tested_up_to":68,"requires_at_least":69,"requires_php":70,"tags":71,"homepage":74,"download_link":75,"security_score":76,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"forget-spam-comment","Forget Spam Comment","1.1.9","Gulshan Kumar","https:\u002F\u002Fprofiles.wordpress.org\u002Fthegulshankumar\u002F","\u003Cp>The fastest and GDPR compliant Anti-Spam plugin to prevent bot spam in the \u003Cstrong>Default Commenting System\u003C\u002Fstrong> of WordPress.\u003C\u002Fp>\n\u003Ch3>Important\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Please clear page cache after plugin activation.\u003C\u002Fli>\n\u003Cli>Only for default commenting system. Not for AMP.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>100% GDPR Compliant.\u003C\u002Fli>\n\u003Cli>Captcha-Free solution.\u003C\u002Fli>\n\u003Cli>Requires no settings.\u003C\u002Fli>\n\u003Cli>Automatic. No need of false-positive comment moderation.\u003C\u002Fli>\n\u003Cli>Compatible with all page caching and performance optimization plugins.\u003C\u002Fli>\n\u003Cli>Fastest ever. A tiny inline JavaScript in just ~200 bytes does all magic.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How does it work?\u003C\u002Fh4>\n\u003Cp>To prevent spam comments plugin blocks the default action path (wp-comments-post.php) for bots and make it accessible over unique hash query string when a visitor scroll to leave a comment. This way it prevents automated spam comment done by bots.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Video Demonstration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FuwIfk08GSwk?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003Cbr \u002F>\nWatch on \u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=uwIfk08GSwk\" rel=\"nofollow ugc\">YouTube\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Let’s support each other 🙏\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Please Upvote Forget Spam Comment plugin at \u003Ca href=\"https:\u002F\u002Fwww.producthunt.com\u002Fproducts\u002Fforget-spam-comment#forget-spam-comment\" rel=\"nofollow ugc\">Product Hunt\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>You can \u003Ca href=\"https:\u002F\u002Fwww.gulshankumar.net\u002Fcontact\u002F\" rel=\"nofollow ugc\">contact me\u003C\u002Fa> to report any issues. I’d be happy to assist.\u003C\u002Fli>\n\u003C\u002Ful>\n","The ultimate solution to stop spam comments in the default commenting system of WordPress",10000,77944,46,"2025-06-07T14:20:00.000Z","6.8.6","4.5","5.6",[18,20,72,22,73],"gdpr","stop-spam","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fforget-spam-comment\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fforget-spam-comment.1.1.9.zip",92,{"slug":78,"name":79,"version":80,"author":81,"author_profile":82,"description":83,"short_description":84,"active_installs":85,"downloaded":86,"rating":24,"num_ratings":87,"last_updated":88,"tested_up_to":14,"requires_at_least":15,"requires_php":89,"tags":90,"homepage":93,"download_link":94,"security_score":24,"vuln_count":11,"unpatched_count":11,"last_vuln_date":25,"fetched_at":26},"botblocker-security","BotBlocker Security – Firewall & Bot Protection","1.6.21","Yevhen Leonidov","https:\u002F\u002Fprofiles.wordpress.org\u002Fglobusstudio\u002F","\u003Cp>\u003Cstrong>BotBlocker Security blocks 99% of automated attacks before WordPress even loads.\u003C\u002Fstrong> No bloat, no slowdowns, no monthly fees for core protection.\u003C\u002Fp>\n\u003Cp>If your site is hit by login brute force, spam comments, fake Googlebots, content scrapers, or XML-RPC floods, you are not alone: bots generate over 47% of all web traffic. Most security plugins react after WordPress boots, wasting CPU and memory on every bad request. \u003Cstrong>BotBlocker stops them at the door.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch4>Why site owners switch to BotBlocker\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Faster than the competition.\u003C\u002Fstrong> Runs on early init through three interception layers, before themes and plugins load. Server load drops during attacks instead of spiking.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smarter CAPTCHA.\u003C\u002Fstrong> 9 modes including Silent Auto-Verify – zero clicks for humans, hard wall for bots. Proprietary CAPTCHAs defeat AI-based solvers that crack reCAPTCHA for $2-3 per 1 000.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Honest free version.\u003C\u002Fstrong> Full firewall, all 9 CAPTCHA modes, full 2FA, full logging, full Multisite support. No nag screens, no crippled features.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy-first.\u003C\u002Fstrong> No visitor data leaves your server. GDPR and CCPA compliant out of the box.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works with everything.\u003C\u002Fstrong> Cloudflare, WP Rocket, LiteSpeed, WooCommerce, Elementor, multisite, IPv6, PHP 7.4 to 8.5.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🛡️ Core Firewall (Free)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Three-Layer Architecture\u003C\u002Fstrong> – intercepts traffic at wp-config.php (before WordPress), MU-plugin phase, and main shield. The first layer blocks known threats without loading WordPress at all, saving 30-100ms and 5-20MB RAM per blocked request.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Web Application Firewall (WAF)\u003C\u002Fstrong> with real-time rule updates via the BotBlocker Threat Defense Feed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>2 899 User-Agent signatures\u003C\u002Fstrong> – largest blacklist among WordPress plugins – covering Scrapy, Selenium, Puppeteer, PhantomJS, curl, wget, Python, Java, Perl, and SQL injection tools\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute force protection\u003C\u002Fstrong> with progressive lockouts – 5 attempts per 15 minutes, escalating bans for repeat offenders\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anti-spam\u003C\u002Fstrong> for comments, registration, contact forms – spammers blocked before they connect\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC and REST API\u003C\u002Fstrong> locked down by default with allowlist for trusted services\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Fake crawler detection\u003C\u002Fstrong> via FCrDNS (dual-direction DNS verification), ASN tokens, and published IP ranges – 95% effective, impossible to spoof without controlling the provider’s DNS zone\u003C\u002Fli>\n\u003Cli>\u003Cstrong>LLM \u002F AI crawler management\u003C\u002Fstrong> – allow or block GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot, Bytespider via CIDR-verified IP ranges. Trusted crawlers verified, impersonators blocked.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Country, ASN, IP range, User-Agent, Referer\u003C\u002Fstrong> blocking rules with instant enforcement\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cloudflare-aware\u003C\u002Fstrong> real-IP resolution and origin bypass protection\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Full IPv6 support\u003C\u002Fstrong> – separate tables and logic for IPv4 and IPv6, every feature works with both\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Live traffic monitor\u003C\u002Fstrong> with attack map, country, ASN, device, browser, and exact block reason for every request\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in caching\u003C\u002Fstrong> via Redis and Memcached – free, auto-disable on connection failure\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🔒 Login Security & 2FA (Free)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Two-Factor Authentication\u003C\u002Fstrong> compatible with Google Authenticator, Authy, 1Password, Bitwarden – TOTP standard with 10 backup codes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>9 CAPTCHA modes\u003C\u002Fstrong>: Silent Auto-Verify, Single Button, Color CAPTCHA, Images CAPTCHA, Shapes CAPTCHA (60fps Canvas), Digits CAPTCHA, Hold Button CAPTCHA, plus Google reCAPTCHA v2 and v3\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hybrid Mode\u003C\u002Fstrong> – combine any internal CAPTCHA with reCAPTCHA v3 for two-layer invisible defense\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide login URL\u003C\u002Fstrong> \u003Cem>(PRO)\u003C\u002Fem>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable lockout durations\u003C\u002Fstrong> with escalation for repeat offenders – failed CAPTCHA triggers short ban, repeated failure triggers 24-hour ban\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>💳 Payment Gateway Bypass (Free)\u003C\u002Fh4>\n\u003Cp>Auto-detects 25+ e-commerce platforms (WooCommerce, Easy Digital Downloads, SureCart, MemberPress, Paid Memberships Pro, Give, Dokan, CartFlows, FunnelKit, and more) and 150+ payment providers (Stripe, PayPal, Mollie, Adyen, Braintree, Square, Razorpay, Klarna, Paddle, Authorize.Net, 2Checkout, YooKassa, LiqPay, and more). \u003Cstrong>Webhooks, IPN callbacks, and payment notifications never get blocked.\u003C\u002Fstrong> Four detection layers ensure zero false positives on payment traffic.\u003C\u002Fp>\n\u003Ch4>📊 Visibility & Control (Free)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Visual dashboard with attack map, top offenders, blocked-vs-allowed ratio, world traffic map\u003C\u002Fli>\n\u003Cli>Detailed event log with IP, country, ASN, User-Agent, and exact block reason – 54 unique event codes\u003C\u002Fli>\n\u003Cli>Health Score gauge – 42 parameters across 3 categories, 5 security levels from Critical to Secure\u003C\u002Fli>\n\u003Cli>3 security presets – Light, Strong, Full – one-click configuration\u003C\u002Fli>\n\u003Cli>Setup Wizard – 8 steps from welcome to test attack, setup in under 5 minutes\u003C\u002Fli>\n\u003Cli>8 interface languages – English, Deutsch, Español, Français, Polski, Русский, Українська + POT template\u003C\u002Fli>\n\u003Cli>Configurable retention with timezone and DST awareness\u003C\u002Fli>\n\u003Cli>Clean uninstall – drops all 16 tables, removes 40+ options, clears cron hooks. Zero leftover data.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🚀 PRO Adds (Premium \u002F Pro \u002F Ultimate)\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Real-time cloud threat intelligence cross-checked against global databases – 5M+ attack IPs, hundreds of thousands of bot signatures, updated daily\u003C\u002Fli>\n\u003Cli>Zero-day behavioral and heuristic detection – catches unknown attack patterns before signatures exist\u003C\u002Fli>\n\u003Cli>VPN, Tor, proxy, ASN, and hosting reputation checks\u003C\u002Fli>\n\u003Cli>Early Init Mode – filtering before WordPress Core loads, maximum resource savings during attacks\u003C\u002Fli>\n\u003Cli>Hide Login URL addon – custom admin URL, hardened wp-login.php protection\u003C\u002Fli>\n\u003Cli>Security Headers addon – HSTS, CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy, X-Content-Type-Options\u003C\u002Fli>\n\u003Cli>Speed Up WordPress addon – 14 frontend and server optimizations\u003C\u002Fli>\n\u003Cli>Malware Scanner addon – 25 patterns scanning files + 7 database tables, detects webshells, eval injections, base64-obfuscated code hidden in wp_options and post_content\u003C\u002Fli>\n\u003Cli>Priority support – 24-hour response time\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Four plans to match your traffic: \u003Cstrong>Premium\u003C\u002Fstrong> ($12\u002Fmonth, 25k cloud checks), \u003Cstrong>Pro\u003C\u002Fstrong> ($50\u002Fmonth, 100k cloud checks), \u003Cstrong>Ultimate\u003C\u002Fstrong> ($100\u002Fmonth, 250k cloud checks + emergency 24h support). Annual billing includes 1 month free. 30-day refund policy. Licensed per domain, billed securely via Freemius.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fpricing\u002F\" rel=\"nofollow ugc\">Compare plans \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>⚡ Performance & Compatibility\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero database queries\u003C\u002Fstrong> for returning visitors – 9 runtime PHP files with SHA-256 integrity signatures, loaded via \u003Ccode>include\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Measured overhead: \u003Cstrong>+3-15ms\u003C\u002Fstrong> TTFB for cached visitors, \u003Cstrong>+50-200ms\u003C\u002Fstrong> for first-time PTR lookups, \u003Cstrong>+2-4MB\u003C\u002Fstrong> memory\u003C\u002Fli>\n\u003Cli>Redis and Memcached support – free, auto-disables gracefully on connection failure\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cache plugin compatibility\u003C\u002Fstrong> – automatic \u003Ccode>DONOTCACHEPAGE\u003C\u002Fcode> and \u003Ccode>Cache-Control: no-store\u003C\u002Fcode> on verification pages. Works with WP Super Cache, W3 Total Cache, WP Rocket, LiteSpeed Cache, Hummingbird, WP Fastest Cache, Cache Enabler\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CDN and WAF compatibility\u003C\u002Fstrong> – Cloudflare, Sucuri, Incapsula, AWS CloudFront, Fastly, KeyCDN, StackPath. Multi-header real-IP resolution (CF-Connecting-IP, X-Forwarded-For, X-Real-IP)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DDoS Protection Compatibility\u003C\u002Fstrong> – automatic detection of JS-challenges from DDoS-Guard, Stormwall, Qrator. HMAC-signed AJAX responses, Circuit Breaker with automatic retry and backoff. BotBlocker is the only WordPress plugin that works correctly behind aggressive DDoS protection without manual configuration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multisite Support\u003C\u002Fstrong> – network activation, per-site data, per-site cleanup. Free on all plans.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP 7.4 – 8.5\u003C\u002Fstrong> – tested across 7 PHP versions. \u003Cstrong>WordPress 5.0 – 7.0+\u003C\u002Fstrong>. Linux and Windows.\u003C\u002Fli>\n\u003Cli>GDPR and CCPA compliant – no PII collected, technical parameters only, Legitimate Interest basis (Art. 6(1)(f))\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>🤝 Trusted by\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>3 000+ active installations\u003C\u002Fli>\n\u003Cli>Translated into 8 languages\u003C\u002Fli>\n\u003Cli>Tested up to WordPress 7.0 and PHP 8.5\u003C\u002Fli>\n\u003Cli>Developed and maintained by GLOBUS.studio\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>“Replaced two security plugins and a CAPTCHA plugin with one. Site is faster and the spam stopped overnight.” – WordPress.org user\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>BotBlocker Security does \u003Cstrong>not\u003C\u002Fstrong> collect or process personal data of your visitors. All cloud analysis is performed on technical parameters only (IP, headers, User-Agent). No personally identifiable information is collected, stored, or transmitted to any external service.\u003C\u002Fp>\n\u003Ch3>Support and Documentation\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Product site: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fproducts\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fproducts\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Pricing and PRO plans: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fpricing\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fpricing\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Documentation: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fdocs\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fdocs\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Contact\u002Fsupport: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fcontacts\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fcontacts\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Community: \u003Ca href=\"https:\u002F\u002Fbotblocker.top\u002Fcommunity\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fbotblocker.top\u002Fcommunity\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under the GPLv2 or later. See LICENSE.txt for details.\u003C\u002Fp>\n\u003Ch3>Credits & Authors\u003C\u002Fh3>\n\u003Cp>BotBlocker Security is developed and maintained by GLOBUS.studio.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Concept, architecture & code – Yevhen Leonidov: \u003Ca href=\"https:\u002F\u002Fleonidov.dev\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fleonidov.dev\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Code, code review – Andrii Lukashevych\u003C\u002Fli>\n\u003Cli>Code, translations – Aleksandr Kinakh\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>BotBlocker Security – The first line of defense for your WordPress site.\u003C\u002Fstrong>\u003C\u002Fp>\n","Stop bots, brute force, spam, and fake crawlers before they reach WordPress. Three-layer firewall, 9 CAPTCHAs, FCrDNS, 2FA. Setup in 60 seconds.",3000,8224,9,"2026-06-17T18:31:00.000Z","7.4",[18,91,92,20,22],"brute-force","captcha","https:\u002F\u002Fbotblocker.top\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbotblocker-security.1.6.21.zip",{"slug":96,"name":97,"version":98,"author":99,"author_profile":100,"description":101,"short_description":102,"active_installs":103,"downloaded":104,"rating":24,"num_ratings":105,"last_updated":106,"tested_up_to":14,"requires_at_least":107,"requires_php":89,"tags":108,"homepage":111,"download_link":112,"security_score":113,"vuln_count":30,"unpatched_count":11,"last_vuln_date":114,"fetched_at":26},"bitfire","BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection","5.1.0","Cory Marsh","https:\u002F\u002Fprofiles.wordpress.org\u002Fbitslip6\u002F","\u003Ch3>Your Site Deserves Real Protection\u003C\u002Fh3>\n\u003Cp>You built your WordPress site to grow your business, share your ideas, or connect with your community. You shouldn’t have to become a security expert to keep it safe.\u003C\u002Fp>\n\u003Cp>BitFire stops hackers, bots, and malware automatically so you can focus on what matters: running your site. And when you have a question, a real person on our US-based support team is here to help, 12 hours a day.\u003C\u002Fp>\n\u003Ch3>How BitFire Keeps You Safe\u003C\u002Fh3>\n\u003Cp>Most security plugins wait until something goes wrong and then try to clean up the mess. BitFire works the other way around: it stops threats before they ever reach your site.\u003C\u002Fp>\n\u003Cp>Think of it like a lock on your front door versus a camera that records a break-in. BitFire is the lock.\u003C\u002Fp>\n\u003Cp>Our AI-powered scanner watches your files and traffic in real time, catching new threats that other plugins miss because they are still waiting for someone to write a rule for it.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>“Traditional firewalls allow everything by default and react to known threats. BitFire flips that: it verifies traffic first and only lets the good stuff through.”\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>Key Features\u003C\u002Fh3>\n\u003Ch3>What BitFire Does For You (Free)\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Stops Bots Automatically\u003C\u002Fstrong>\u003Cbr \u002F>\nSpam bots, scrapers, and scanners get blocked before they waste your server resources or fill your forms with junk. No CAPTCHAs, no puzzles for your visitors.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Scans for Malware\u003C\u002Fstrong>\u003Cbr \u002F>\nBitFire checks every file on your site against a database of over 20 million known-good files. If something does not belong, you will know about it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Shows You Who is Visiting\u003C\u002Fstrong>\u003Cbr \u002F>\nSee every request to your site in real time: where visitors are from, what browser they are using, and whether they are a real person or a bot. No more guessing.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Protects Your Login Page\u003C\u002Fstrong>\u003Cbr \u002F>\nBrute-force attacks, password stuffing, and login bots are stopped cold. Your admin area stays locked down.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Tells Real People from Fake Browsers\u003C\u002Fstrong>\u003Cbr \u002F>\nBitFire verifies visitors with 99.7% accuracy, 50 times faster than Cloudflare’s challenge pages. Real visitors never notice. Bots get stopped instantly.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Blocks Known Bad Actors\u003C\u002Fstrong>\u003Cbr \u002F>\nOver 300,000 known malicious IPs are blocked before they can even connect to your site.\u003C\u002Fp>\n\u003Ch3>What You Get with BitFire Pro\u003C\u002Fh3>\n\u003Cp>Everything in Free, plus the protections that stop even zero-day attacks on vulnerable plugins and themes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Runtime Protection (RASP)\u003C\u002Fstrong>\u003Cbr \u002F>\nBitFire is the only WordPress security plugin with Runtime Application Self Protection. It watches what your plugins and themes are actually doing and stops anything suspicious:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A plugin tries to create a secret admin account? Blocked.\u003C\u002Fli>\n\u003Cli>Malware tries to edit your PHP files? Blocked.\u003C\u002Fli>\n\u003Cli>A hacked plugin tries to phone home to a malware server? Blocked.\u003C\u002Fli>\n\u003Cli>Code tries to redirect your visitors to a scam site? Blocked.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>BitFire has blocked 100% of critical WordPress zero-day vulnerabilities since 2022, with zero new rules required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>A+ Rated Web Application Firewall\u003C\u002Fstrong>\u003Cbr \u002F>\nIndependent testing by Cloudbric rated BitFire’s WAF at 94% (A+). See how that compares:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>BitFire [PRO]: \u003Cstrong>94% (A+)\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Ninja Firewall [PRO]: 67% (D)\u003C\u002Fli>\n\u003Cli>WordFence [PRO]: 41% (D)\u003C\u002Fli>\n\u003Cli>MalCare [PRO]: 34% (F)\u003C\u002Fli>\n\u003Cli>iThemes Security: 2% (F)\u003C\u002Fli>\n\u003Cli>Shield Security [PRO]: 2% (F)\u003C\u002Fli>\n\u003Cli>SiteGround Security: 2% (F)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Flabs.cloudbric.com\u002Fwafer\" rel=\"nofollow ugc\">View the full independent test results at Cloudbric Labs\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>AI-Powered Malware Analysis\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen the scanner finds something suspicious, BitFire’s AI analyzes it in real time to determine if it is actually malicious or just unusual code. Pro users get results in about 2 minutes. Free users can submit files for batch analysis.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Automatic Security Headers\u003C\u002Fstrong>\u003Cbr \u002F>\nBitFire learns which domains your site uses (Google Fonts, your CDN, analytics, etc.) and automatically sets up Content Security Policy headers that earn an A+ rating. This protects your visitors from cross-site scripting and redirect attacks without you having to configure a thing.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>30 Days of Traffic History\u003C\u002Fstrong>\u003Cbr \u002F>\nLook back through a full month of traffic data to investigate issues, spot patterns, or just understand how your site is being used.\u003C\u002Fp>\n\u003Ch3>Real Human Support\u003C\u002Fh3>\n\u003Cp>This is what makes BitFire different from the big-name security plugins: when you need help, you talk to a real person.\u003C\u002Fp>\n\u003Cp>Our US-based support team is available 12 hours a day. No ticket queues that take days. No chatbots. No copy-paste answers. Just experienced people who will make sure your site is secure.\u003C\u002Fp>\n\u003Cp>Whether you need help with setup, have a question about a block, or want someone to look at a suspicious file, we are here.\u003C\u002Fp>\n\u003Ch3>Pricing\u003C\u002Fh3>\n\u003Ch3>Free\u003C\u002Fh3>\n\u003Cp>$0 forever. Bot blocking, malware scanning, login protection, and real-time traffic monitoring. Everything you need to stop the vast majority of automated attacks.\u003C\u002Fp>\n\u003Ch3>Pro – Single Site\u003C\u002Fh3>\n\u003Cp>$60\u002Fyear. Full RASP protection, A+ rated WAF, AI malware analysis, 30-day logs, and priority human support.\u003C\u002Fp>\n\u003Ch3>Pro – Multi-Site Volume Pricing\u003C\u002Fh3>\n\u003Cp>Managing multiple sites? The more you protect, the less you pay:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>2-4 sites: $50\u002Fsite per year\u003C\u002Fli>\n\u003Cli>5-9 sites: $45\u002Fsite per year\u003C\u002Fli>\n\u003Cli>10-24 sites: $35\u002Fsite per year\u003C\u002Fli>\n\u003Cli>25-49 sites: $25\u002Fsite per year\u003C\u002Fli>\n\u003Cli>50+ sites: $20\u002Fsite per year\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Volume pricing is perfect for freelancers, agencies, and anyone managing WordPress sites for clients. \u003Ca href=\"https:\u002F\u002Fbitfire.co\u002Fpricing\" rel=\"nofollow ugc\">Contact us for volume licensing\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>How BitFire Compares\u003C\u002Fh3>\n\u003Ch3>BitFire vs WordFence\u003C\u002Fh3>\n\u003Cp>WordFence is a solid product with a large team writing custom rules for known vulnerabilities. But there are two things you should know:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Free WordFence delays protection by 30 days.\u003C\u002Fstrong> When a new vulnerability is found, paying WordFence customers get the fix immediately. Free users wait a full month. If your site is vulnerable, it will almost certainly be attacked before the free patch arrives.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>WordFence relies on knowing about attacks in advance.\u003C\u002Fstrong> With over 10,000 known WordPress vulnerabilities and fewer than 200 signatures, they simply cannot cover everything. BitFire’s RASP does not need to know about an attack in advance. It watches what code is actually doing and stops anything malicious, even brand-new attacks nobody has seen before.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>If you do use WordFence, we strongly recommend only using the paid version.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fbitfire.co\u002Fen\u002Fwordfence-vs-bitfire\" rel=\"nofollow ugc\">Read the detailed BitFire vs WordFence comparison\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Why Do Other Plugins Focus So Much on Cleaning Up Malware?\u003C\u002Fh3>\n\u003Cp>Good question. Notice how much other security plugins charge for malware removal and how much of their marketing is about finding infections?\u003C\u002Fp>\n\u003Cp>A security plugin that does its job well should not need to clean malware off your site very often. If a plugin spends most of its energy on cleanup, that tells you something about how well it prevents attacks in the first place.\u003C\u002Fp>\n\u003Cp>BitFire focuses on keeping malware off your site so you do not need to pay someone to remove it.\u003C\u002Fp>\n\u003Ch3>Privacy \u002F Monitoring \u002F Data Collection\u003C\u002Fh3>\n\u003Cp>We take your privacy seriously. Here is exactly what BitFire does with data:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Traffic inspection.\u003C\u002Fstrong> BitFire inspects web traffic to your site to identify threats. Sensitive data like passwords and credit card numbers is automatically replaced with \u003Cstrong>\u003Cem>redacted\u003C\u002Fem>\u003C\u002Fstrong> in logs. You can add additional fields to filter in the settings.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Error reporting.\u003C\u002Fstrong> If BitFire encounters a software error, it can send a report to our development team so we can fix it in the next release. No visitor data is included in these reports.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Malware hash checking.\u003C\u002Fstrong> BitFire sends tiny numeric fingerprints (64-bit hashes) of your files to our hash server to check them against our database of known-good files. For example, a file might hash to the number 812612388126487. We never see your actual file contents, and your hashes are never stored on our servers.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Local data storage.\u003C\u002Fstrong> All log data and configuration files are stored locally on your server in a hidden, randomly-named directory under \u003Ccode>wp-content\u002Fuploads\u002F\u003C\u002Fcode>. This directory is protected by an \u003Ccode>.htaccess\u003C\u002Fcode> file and is not accessible from the web.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n","Stop hackers, bots, and malware before they touch your site. AI-powered security with real human support when you need it.",300,16002,7,"2026-07-17T22:13:00.000Z","6.1",[19,20,109,22,110],"malware-scanner","waf","https:\u002F\u002Fbitfire.co\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbitfire.5.1.0.zip",98,"2026-06-23 00:00:00",{"slug":116,"name":117,"version":70,"author":118,"author_profile":119,"description":120,"short_description":121,"active_installs":122,"downloaded":123,"rating":124,"num_ratings":105,"last_updated":125,"tested_up_to":68,"requires_at_least":126,"requires_php":127,"tags":128,"homepage":16,"download_link":131,"security_score":132,"vuln_count":133,"unpatched_count":11,"last_vuln_date":134,"fetched_at":26},"wp-limit-failed-login-attempts","Limit Login Attempts (Spam Protection)","wp-buy","https:\u002F\u002Fprofiles.wordpress.org\u002Fwp-buy\u002F","\u003Cp>Limit the number of login attempts possible both through normal login as well as using auth cookies.\u003C\u002Fp>\n\u003Cp>By default WordPress allows unlimited login attempts either through the login page or by sending special cookies. This allows passwords (or hashes) to be brute-force cracked with relative ease.\u003C\u002Fp>\n\u003Cp>Limit Login Attempts blocks an Internet address from making further attempts after a specified limit on retries is reached, making a brute-force attack difficult or impossible.\u003C\u002Fp>\n\u003Ch3>Basic Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Limit the number of retry attempts when logging in.\u003C\u002Fli>\n\u003Cli>Configurable lockout timings.\u003C\u002Fli>\n\u003Cli>Email notification of blocked attempts (Detailed email containing all necessary information).\u003C\u002Fli>\n\u003Cli>Notify the user of remaining attempts.\u003C\u002Fli>\n\u003Cli>Report containing all blocked attempts.\u003C\u002Fli>\n\u003Cli>Whitelist\u002FBlocklist of IPs (Support IP ranges).\u003C\u002Fli>\n\u003Cli>Allow\u002FBlock Countries.\u003C\u002Fli>\n\u003Cli>Automatically block IP addresses that exceed limit login attempts\u003C\u002Fli>\n\u003Cli>Automatically add IP addresses that exceed blocks limit to the deny list\u003C\u002Fli>\n\u003Cli>Send notifications about blocked retry (Email sent to admins)\u003C\u002Fli>\n\u003Cli>Inform the user about the remaining retries or lockout time on the login page.\u003C\u002Fli>\n\u003Cli>Unlock The Locked users – Easily unlock the locked admin through the email or dashboard.\u003C\u002Fli>\n\u003Cli>Limit the number of retry attempts when logging in per IP.\u003C\u002Fli>\n\u003Cli>Limit the number of attempts to log in using cookies.\u003C\u002Fli>\n\u003Cli>Optional logging and optional email notification.\u003C\u002Fli>\n\u003Cli>Compatible with Google captcha, Captcha Plus & reCaptcha.\u003C\u002Fli>\n\u003Cli>Dashboard gives you an overview of your site’s security.\u003C\u002Fli>\n\u003Cli>Enable or disable the plugin functionality\u003C\u002Fli>\n\u003Cli>Enable to disable email notifications\u003C\u002Fli>\n\u003Cli>Compatible with latest WordPress version\u003C\u002Fli>\n\u003Cli>Woocommerce login page protection.\u003C\u002Fli>\n\u003Cli>Wordfence & Sucuri compatibility.\u003C\u002Fli>\n\u003Cli>GDPR compliant.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Advanced Features (PRO)\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>All Basic features included.\u003C\u002Fli>\n\u003Cli>Save the password that was used by the hacker (Save part of the password and hide the last three digits).\u003C\u002Fli>\n\u003Cli>Advanced dashboard gives you an overview of your site’s security (Charts for the most important reports).\u003C\u002Fli>\n\u003Cli>Block attackers by IP, Country, IP range.\u003C\u002Fli>\n\u003Cli>Mobile Application for the admins to follow up the site security (\u003Ca href=\"https:\u002F\u002Fwww.wp-buy.com\u002Fwp-content\u002Fuploads\u002Fapps\u002Flogin-attempts-app.apk\" rel=\"nofollow ugc\">Download APK\u003C\u002Fa>).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Video Description\u003C\u002Fh3>\n\u003Cdiv class=\"embed-vimeo\" style=\"text-align: center;\">\u003Ciframe loading=\"lazy\" src=\"https:\u002F\u002Fplayer.vimeo.com\u002Fvideo\u002F585819426\" width=\"750\" height=\"422\" frameborder=\"0\" webkitallowfullscreen mozallowfullscreen allowfullscreen>\u003C\u002Fiframe>\u003C\u002Fdiv>\n\u003Ch3>Plugin Settings and Reports\u003C\u002Fh3>\n\u003Cdiv class=\"embed-vimeo\" style=\"text-align: center;\">\u003Ciframe loading=\"lazy\" src=\"https:\u002F\u002Fplayer.vimeo.com\u002Fvideo\u002F585820422\" width=\"750\" height=\"422\" frameborder=\"0\" webkitallowfullscreen mozallowfullscreen allowfullscreen>\u003C\u002Fiframe>\u003C\u002Fdiv>\n","Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.",200,14295,78,"2025-06-15T19:08:00.000Z","4.6","7.2",[18,20,129,130,22],"login-attempts","protection","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-limit-failed-login-attempts.5.6.zip",84,5,"2024-12-05 00:00:00",{"error":136,"url":137,"statusCode":138,"statusMessage":139,"message":139},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Ffstyle-honeypot-bot-blocker\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":30,"versions":141},[142,148],{"version":6,"download_url":23,"svn_tag_url":143,"released_at":25,"has_diff":144,"diff_files_changed":145,"diff_lines":25,"trac_diff_url":146,"vulnerabilities":147,"is_current":136},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Ffstyle-honeypot-bot-blocker\u002Ftags\u002F1.1.1\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ffstyle-honeypot-bot-blocker%2Ftags%2F1.1&new_path=%2Ffstyle-honeypot-bot-blocker%2Ftags%2F1.1.1",[],{"version":149,"download_url":150,"svn_tag_url":151,"released_at":25,"has_diff":144,"diff_files_changed":152,"diff_lines":25,"trac_diff_url":25,"vulnerabilities":153,"is_current":144},"1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffstyle-honeypot-bot-blocker.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ffstyle-honeypot-bot-blocker\u002Ftags\u002F1.1\u002F",[],[]]