plugin-icon

SiteFort – Advanced Security, Firewall & Malware Scanner

제작자: securewpteam·
Secure WordPress with firewall protection, 2FA login security, hardening, vulnerability scanning, bot blocking, and fast cloud-assisted malware scans.
평가
5
버전
1.6.4
활성화된 설치 항목
10
최근 업데이트일
Jun 22, 2026
SiteFort – Advanced Security, Firewall & Malware Scanner

SiteFort brings firewall protection, bot blocking, 2FA, vulnerability checks, hardening, audit logs, and malware scanning into one lightweight security dashboard.

Shaped by real hacked-site recovery experience, SiteFort closes weak points before attackers use them. It checks for backdoors, web shells, injected scripts, SEO spam, suspicious redirects, hidden admin risks, breached passwords, exposed sensitive files, and vulnerable plugins or themes.

Helpful links: Live Demo | SiteFort Features | Free Remote Scan | Documentation | Malware Removal Help

Comprehensive WordPress Protection

  • WordPress Hardening: Lock down XML-RPC, user enumeration, file editing, and sensitive file exposure.
  • Firewall & Traffic Protection: Block abusive IPs, rate-limit requests, and restrict country traffic.
  • Cloud-Assisted Malware Scanner: Detect backdoors, web shells, and injected scripts using fast hash checks and selective cloud analysis.
  • Login Security & 2FA: Prevent account takeover with authenticator apps, custom login URLs, CAPTCHA, and brute-force lockouts.
  • Vulnerability Scanner: Identify outdated plugins, themes, and core files with CVE references and fix guidance.
  • Password Protection: Enforce strong passwords by user role and block compromised credentials.
  • Bot Filter Policy: SEO-safe bot protection with adjustable strictness levels and an optional AI training crawler block.
  • Cloudflare Rule Sync: Push IP and country blocks to Cloudflare for edge-level enforcement.
  • Full-Site Security Review: Evaluate server state, database safety, security headers, and hidden admin risks.
  • Audit Log & Console: Track event history, manage multi-site workflows, and route security alerts.

Built For Performance

SiteFort is designed to protect sites without adding unnecessary server load, including on shared and managed hosting.

  • Hash-First Scanning checks known files quickly before deeper analysis is needed.
  • Selective Cloud Analysis reviews only unknown or suspicious files so the server handles less malware work.
  • On-Site Database Checks inspect database safety without uploading database content to the cloud.
  • Bad-Bot Blocking reduces scraping, automated abuse, repeated 404 hits, and bots hunting for weak points.
  • Cloudflare Sync pushes supported firewall rules to Cloudflare before traffic reaches WordPress.

◈ WordPress Security Scanner

SiteFort runs a layered security review and organizes findings by severity across files, accounts, content, reputation, and server state.

  • Hash-First File Analysis: Resolves known clean and known malicious files quickly using local hashes before any cloud work is needed.
  • Deep Malware Detection: Sends only unknown or suspicious files for cloud analysis to detect backdoors, web shells, malware variants, injected code, SEO spam, malicious redirects, and exposed sensitive files.
  • File Integrity Checks: Reviews WordPress core, plugins, themes, uploads, and custom files for unauthorized changes, with clean-file restore opportunities on supported plans.
  • User Account Security: Detects weak account posture, breached passwords, risky roles, suspicious user data, and administrator accounts that need review.
  • Ghost Administrator Detection: Flags hidden or unexpected administrator accounts created outside normal site workflows.
  • Content & Database Safety: Checks WordPress data locally for injected content, suspicious options, unsafe URLs, spam injections, and malicious redirect indicators.
  • Domain & IP Reputation: Surfaces blocklist and abuse signals for the site domain and server IP before they affect trust.
  • Sensitive File Exposure: Finds exposed backups, logs, config files, debug files, and other files attackers commonly target.
  • Vulnerability Scanner: Checks WordPress core, plugins, and themes for known vulnerabilities, affected versions, severity, and CVE references where available.
  • Server State Checks: Reviews public paths, security headers, file exposure, and server conditions that increase compromise risk.

Cloud-assisted file scanning reduces server load. Content and database checks run on the site. Database content never leaves.

◈ WordPress Security Hardening

SiteFort closes the exposure points attackers check first, then verifies whether those protections are actually enforced – not just enabled in the dashboard.

  • XML-RPC Controls: Disable XML-RPC, restrict authentication, or block pingback abuse.
  • User Enumeration Blocking: Reduces username leaks from author archives, REST endpoints, and common discovery paths.
  • Sensitive File Protection: Blocks public access to .env, backups, logs, debug files, .git metadata, lock files, sample configs, and server fragments.
  • PHP Execution Protection: Blocks PHP execution in uploads and direct PHP access inside plugin and theme folders where supported.
  • Directory Listing Protection: Reduces exposure from browsable upload, plugin, theme, or backup directories.
  • File Editor Protection: Disables the built-in theme and plugin file editor to limit damage from compromised admin accounts.
  • REST & Application Password Controls: Restricts risky REST access and application password behavior based on site needs.
  • Version & Metadata Cleanup: Hides WordPress version output and reduces exposed generator and header signals.
  • Security Headers: Analyze and manage CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and disclosure headers.
  • Verified Hardening: SiteFort checks whether supported hardening rules are actually enforced; items that require manual hosting or server configuration are flagged separately.

◈ Login Security & 2FA

Account takeover is one of the fastest ways to lose control of a WordPress site. SiteFort adds layered login protection without requiring separate plugins.

Prevention * Brute-force lockouts * CAPTCHA protection * Custom login URL * Generic login errors to reduce username guessing * XML-RPC and REST authentication controls

Authentication * Role-based two-factor authentication * Authenticator app codes * Email verification codes * Recovery codes

Password Controls * Weak password detection * Breached-password detection * Role-based strong-password enforcement * Password expiration policies

◈ WordPress Firewall

SiteFort helps block unwanted traffic before it consumes server resources. Firewall rules cover IPs, countries, bots, crawlers, and user agents without requiring custom rule syntax.

  • IP & Country Rules: Block or allow traffic by IP address, CIDR range, country, bot, crawler, or user agent.
  • Country Blocking: Supports both block-selected and allow-only modes.
  • Sensitive File Protection: Stops bots probing for .env, .git, wp-config.php backups, SQL dumps, debug logs, installer files, and other risky paths.
  • Cloudflare Sync: Pushes supported IP, country, and user-agent rules to Cloudflare so high-volume blocks happen at the edge.
  • Temporary Edge Blocks: Blocks repeat attackers at Cloudflare when Cloudflare Sync is configured.
  • Rate Limiting & 404 Controls: Reduces abusive traffic spikes, repeated missing-page requests, and automated noise.
  • Community Threat Intelligence: Blocks traffic from malicious IPs seen across the SiteFort network.
  • Vulnerability-Hunting Bot Protection: Blocks bots probing for vulnerable plugins, themes, backup files, and configuration leaks.

◈ Bot Filter Policy

Not all bots are bad. SiteFort provides three protection levels that block unwanted automation while keeping trusted search engines, social previews, and major crawlers allowed.

  • Basic: Blocks known hacking tools and bots probing for vulnerable files.
  • Balanced: Blocks hacking tools, scraping bots, and automated scripts. Recommended for most sites.
  • Maximum: Blocks hacking tools, scrapers, automated scripts, and unrecognized bot traffic.
  • Block AI Training Crawlers: Optional block for AI scrapers that harvest content for model training (GPTBot, ClaudeBot, CCBot, Bytespider). AI assistants and search crawlers stay allowed.

Choose the level that fits the site, then adjust individual rules from the firewall dashboard.

◈ Vulnerability Management

SiteFort checks installed WordPress core, plugin, and theme versions against vulnerability intelligence and shows affected assets, severity, CVE references where available, and recommended fixes.

SiteFort does not claim to virtually patch vulnerable code. It identifies affected components, surfaces severity and CVE data, and helps reduce automated discovery attempts while updates are applied.

Pro: Automated vulnerability alerts notify teams when a known vulnerability affects an installed plugin, theme, or WordPress core version.

◈ One-Click Repair & Restore

Pro: Guided repair workflows let teams act on scan findings without manually editing files over FTP or SSH.

  • Repair or delete malicious files directly from scan results.
  • Restore clean WordPress core, plugin, and theme files when a trusted clean source is available.
  • Repair supported paid plugin and theme files when clean-source matching is available.
  • Quarantine suspicious files and restore them later if needed.

For active compromise, Securewp expert cleanup and managed security services are available when hands-on investigation, root-cause patching, blocklist help, or post-cleanup review is needed.

◈ Audit Log & SiteFort Console

SiteFort keeps a security event history so teams can quickly see what changed, what was blocked, and what needs attention.

  • Login Activity: Successful logins, failed attempts, lockouts, 2FA events, and account-related actions.
  • User & Site Changes: User updates, plugin and theme changes, settings changes, and sensitive admin actions.
  • Firewall Activity: Blocked IPs, country rules, bot blocks, rate-limit events, and suspicious request activity.
  • Scanner Results: Malware findings, vulnerability findings, reputation checks, hardening issues, and scan history.
  • Hardening Changes: Applied rules, failed rules, verified protections, and items needing manual review.

Site-level security features are available from the WordPress dashboard. SiteFort Console is optional for teams that need centralized visibility across multiple sites.

  • Multi-site status for connected websites.
  • Downloadable reports for clients or internal review.
  • Team roles and support workflows.
  • Pro: Remote scan history and vulnerability tracking.
  • Pro: Uptime and SSL expiry monitoring.
  • Pro: Email, Slack, Discord, and webhook alerts.
  • Pro: White-label options for agencies on supported plans.

◈ Hosting Compatibility

SiteFort is built for real WordPress environments including shared hosting, managed hosting, VPS, and Cloudflare-proxied sites.

  • Works with Apache, Nginx, and LiteSpeed.
  • Compatible with shared hosting, managed WordPress hosting, VPS, and dedicated servers.
  • Cloudflare-friendly: supports proxied sites and optional Cloudflare rule sync.
  • Cloud-assisted scanning reduces heavy scan work on lower-resource hosting plans.
  • Verified hardening confirms whether key rules are actually enforced, not just toggled on.

◈ Pro & Managed Security

Core protection is available in the free plugin. Paid plans are built for infected sites, agencies, and teams that need continuous scanning, automated alerts, deeper file analysis, repair workflows, and post-cleanup coverage.

Pro plans add: * Unlimited cloud deep threat analysis * Scheduled malware scans * Automated vulnerability alerts * One-click malware repair and restore * Clean-file restoration for core, plugin, and theme files * Uptime and SSL monitoring * Slack, Discord, email, and webhook alerts * Advanced reports and Console workflows * White-label options for agencies * Expert cleanup discounts

Managed security adds hands-on monitoring, response workflows, and expert cleanup coverage.

Looking for a market comparison? See the WordPress Security Plugin Comparison.

External services

SiteFort connects to external services only when needed for license activation, cloud-assisted malware analysis, vulnerability intelligence, firewall intelligence, optional Console sync, optional CAPTCHA, optional GeoIP, optional IP lookup, Cloudflare sync, and administrator-enabled notifications.

Optional integrations are not contacted unless they are configured or used.

SiteFort Cloud

  • Servers: securewp.net, intel.securewp.net, console.securewp.net
  • Used for: License activation, service metadata, cloud malware analysis, vulnerability intelligence, firewall intelligence, reputation checks, community blocklist sync, clean-file repair, and optional Console sync.
  • Data sent: Email address, license key/token, site URL, WordPress/plugin versions, installed plugin/theme names and versions, file hashes, scan results, vulnerability findings, reputation status, firewall metadata, blocked IPs, and security configuration metadata.
  • Malware scanning: File hashes are sent first. Only unknown or suspicious files may be uploaded for deeper analysis and are deleted after processing. Database and content checks run on your website. SiteFort does not upload your database or database-stored content to the cloud. If wp-config.php requires analysis, sensitive configuration values are removed before upload.
  • Temporary storage: SiteFort Cloud may return temporary upload/download URLs on *.amazonaws.com or *.r2.cloudflarestorage.com for scan uploads or clean-file repair downloads.
  • Privacy: https://securewp.net/privacy-policy/
  • Terms: https://securewp.net/terms-and-conditions/
  • Storage provider policies: AWS privacy https://aws.amazon.com/privacy/ and terms https://aws.amazon.com/service-terms/; Cloudflare privacy https://www.cloudflare.com/privacypolicy/ and terms https://www.cloudflare.com/website-terms/

Optional integrations

  • MaxMind GeoLite2 (download.maxmind.com) is used only when an administrator downloads or updates the local GeoIP database. It sends the configured MaxMind account ID and license key. Visitor IPs are resolved locally and are not sent to MaxMind during normal requests. Privacy: https://www.maxmind.com/en/privacy-policy Terms: https://www.maxmind.com/en/geolite2/eula
  • Have I Been Pwned Passwords (api.pwnedpasswords.com) is used for breached-password checks when enabled. SiteFort sends only the first 5 characters of the SHA-1 password hash. Full passwords and full hashes are never sent. Privacy: https://haveibeenpwned.com/Privacy Terms: https://haveibeenpwned.com/TermsOfUse
  • RIPE NCC / ARIN RDAP (rdap.db.ripe.net, rdap.arin.net) is used only when an administrator requests an IP ownership lookup. The queried IP address is sent. Site credentials, users, scan results, and plugin settings are not sent. Privacy/terms: https://www.ripe.net/about-us/legal/ripe-ncc-privacy-statement/ https://docs.db.ripe.net/HTML-Terms-And-Conditions https://www.arin.net/about/privacy/ https://www.arin.net/resources/registry/whois/tou/
  • Google reCAPTCHA (www.google.com) and Cloudflare Turnstile (challenges.cloudflare.com) are used only when selected and configured for CAPTCHA protection. They receive the challenge token, site key, and visitor/browser data required by the selected provider. Policies: https://policies.google.com/privacy https://policies.google.com/terms https://www.cloudflare.com/turnstile-privacy-policy/ https://www.cloudflare.com/website-terms/
  • Cloudflare API (api.cloudflare.com) is used only when Cloudflare Sync is enabled. It sends Zone ID, API token/credentials, zone details, blocked IPs, country rules, selected user-agent rules, and firewall rule data. Privacy: https://www.cloudflare.com/privacypolicy/ Terms: https://www.cloudflare.com/website-terms/
  • Notification webhooks may send security alerts to Slack (hooks.slack.com), Discord (discord.com, discordapp.com), or a custom HTTPS webhook entered by the administrator. Webhook payloads may include site name, site URL, event type, severity, scan counts, vulnerability names, CVE identifiers, firewall counts, usernames, IP addresses, browser names, action URLs, timestamps, and event details. Slack policies: https://slack.com/trust/privacy/privacy-policy https://slack.com/terms-of-service/user Discord policies: https://discord.com/privacy https://discord.com/terms

Local site checks

Some requests are loopback checks against the protected site’s own public URL, such as security-header checks, public-file exposure checks, and homepage link collection. These contact the site being protected, not a third-party service.

무료유료 요금제에서
설치하면 WordPress.com 서비스 약관서드파티 플러그인 약관에 동의하게 됩니다.
테스트된 버전
WordPress 7.0
이 플러그인은 다운로드할 수 있으며 에서 사용할 수 있습니다.