{"repo":"szepeviktor/waf4wordpress","free":true,"listed":false,"github":"https://github.com/szepeviktor/waf4wordpress","clone":"git clone https://github.com/szepeviktor/waf4wordpress.git","description":"WAF for WordPress 🔥 with 60+ security checks and weekly updates","language":"PHP","stars":143,"topics":["wordpress","fail2ban","plugin","waf","firewall","security","wordpress-security"],"license":"MIT","category":"security-tools","readme_excerpt":"WAF for WordPress [![License][src-packagist-license]][href-license-file] [![PHP Version][src-php-version]][href-composer-file] [![Packagist stats][src-packagist-downloads]][href-packagist-stats] [![Latest version][src-latest-version]][href-packagist] [![PHPStan enabled][src-phpstan-enabled]][href-phpstan-org] Stop real-life attacks on your WordPress website and trigger Fail2Ban. :bulb: Before using this WAF you have to clean your website, get rid of even tiny errors. See your access and error logs daily and run this WAF without Fail2ban for a week. This WAF does not give proper HTTP responses to unusual requests. It blocks the attacking IP address instantly, the purpose of this are the following. 1. Prevent website compromise in further requests 1. Prevent DoS attacks Shared hosting has no server-wide banning (because of trust issues) but you can still install this software without Fail2Ban to stop attacks by using one of the Miniban methods. Support my work Please consider sponsoring me monthly if you use my packages in an agency. Theory Your WordPress - really general HTTP - security consists of the followings. 1. Use HTTPS 1. Have daily backups 1. Block known hostile networks 1. Have Fail2Ban installed (controls the firewall) 1. Maintain your website and use strict Fail2Ban filters which ban on the first suspicious request instantly 1. Deny direct access to core WordPress files, themes and plugins 1. Install WAF for WordPress (this project) 1. Use Leanmail for filtering Fa","default_branch":null,"files":null,"tree":[],"storefront":"/r/szepeviktor","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/szepeviktor/waf4wordpress/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}