=== BitFire Security - Firewall, Malware Scanner, Bot Blocker, Login Protection ===
Contributors: BitSlip6
Donate link: https://bitfire.co/en/upgrade
Tags: security, firewall, malware scanner, waf, bot blocker
Requires at least: 6.1
Tested up to: 7.1.1
Stable tag: 5.2.3
Requires PHP: 7.4
License: AGPLv3 or later
License URI: https://www.gnu.org/licenses/agpl-3.0.en.html

Free WordPress firewall, bot blocking, login protection, and malware scanning. See suspicious traffic and investigate threats from your dashboard.

== Description ==

= Block malicious requests. Find suspicious files. Know what is happening. =

Your WordPress site can look normal while bots probe for weak passwords, exposed files, and vulnerable plugins.

BitFire Free gives you a web application firewall, bot blocking, login protection, and manual malware scanning in one WordPress dashboard. See what reaches your site, review what BitFire blocks, and investigate suspicious files without switching between tools.

**Start with BitFire Free:** install the plugin, follow the setup guide, and run your first malware scan. No credit card required.

= See BitFire in action in 2 minutes =

Take a quick tour of request filtering and the additional runtime protection available with Pro.

https://youtu.be/dSnlE_xzuRg

= Useful protection starts with Free =

**A web application firewall**
Inspect incoming requests for malicious input, including SQL-injection attempts. Review blocked requests and traffic exceptions from your dashboard. You do not need Pro to use the WAF.

**Bot blocking that looks beyond the browser name**
Set policies for crawlers, scanners, and other automated visitors. BitFire uses browser verification, network information, and bot reputation to help distinguish legitimate traffic from unwanted automation. A bot claiming to be Googlebot is not the same as a verified Google crawler.

**Protection for your WordPress login**
Help block automated login abuse and brute-force attempts. Review suspicious login traffic alongside other requests to your site.

**Malware scanning with evidence you can review**
Find suspicious code and unexpected file changes with a manual malware scan. Compare findings with known-good versions and see the evidence behind each alert, so you can decide what to allow, repair, or remove.

**AI assistance for suspicious findings**
Free includes 12 AI analysis credits for the lifetime of the domain. Use them to help assess suspicious code and understand why it was flagged. Pro includes an expanded allowance of 1,000 credits.

**Traffic visibility from your dashboard**
Search recorded requests by URL, IP address, browser, time, or response code. See allowed and blocked activity, then review the decision alongside the request details.

= Stay in control of what gets blocked =

See what BitFire blocked and why, right from your dashboard. Approve legitimate requests and manage exceptions without digging through server logs.

Your traffic, your policies, your decisions - with the evidence in front of you.

[Get started with BitFire](https://bitfire.co/en/support-install-guide)

= A site can look healthy while an attacker finds a way in =


An attacker does not need to change your homepage to cause damage. A vulnerable plugin can become a route to a hidden administrator account, a malicious PHP file, or code that restores an infection after cleanup.

**Watch: How hackers attack your site without you knowing 2 minutes**
See why a normal-looking website is not proof that everything behind it is safe.

https://youtu.be/KxuX1rm4KUM

The firewall inspects incoming requests. Pro adds protection against unauthorized file changes and administrator access, plus tools to investigate what an attacker may have left behind.

= Go deeper with BitFire Pro =

Keep the firewall and scanning tools in Free. Upgrade to put protection ahead of WordPress, block unauthorized actions inside your site, and hunt down hidden threats.

**Always-On Protection: put security first**
BitFire Pro loads before WordPress, bringing firewall inspection to PHP requests that bypass the normal plugin loading process. Your security starts earlier, giving attacks another barrier to cross.

**Runtime protection: stop unauthorized operations, not just suspicious requests**
A request can look harmless while exploiting a vulnerable plugin. Runtime Application Self-Protection (RASP) checks what that request is authorized to do inside your site. BitFire Pro can block:

* Unauthorized writes to PHP files that could install a backdoor.
* Unauthorized administrator creation or privilege changes.
* Attempts to impersonate an administrator without the required authorization.

RASP targets the unauthorized action, not just a known attack pattern. That means a new exploit can be stopped when it attempts a protected operation, without waiting for a rule written for that specific vulnerability.

[Explore runtime protection](https://bitfire.co/en/support-core-settings#rasp)

**Threat Hunter: find what brings malware back**
Deleting an infected file may not remove the mechanism that created it. Threat Hunter brings six investigation areas into one WordPress workspace:

* **Startup chain:** review the files loaded as WordPress starts.
* **Scheduled tasks:** inspect WordPress and system cron jobs for suspicious activity.
* **Must-use plugins:** investigate code that loads early and may be easy to overlook.
* **Administrator access:** review accounts, sessions, application passwords, and database triggers that could restore privileged access.
* **Background processes:** look for long-running PHP processes that could recreate malware.
* **Database content:** inspect scripts and iframes stored in WordPress data, with AI-assisted analysis.

Connect suspicious findings to the mechanisms behind them, then take action from one investigation workspace.

[See how Threat Hunter investigates hidden persistence](https://bitfire.co/en/support-threat-hunter)

**More scanning capacity**
Pro adds scheduled malware scanning and 1,000 AI malware analysis credits. Scan on a schedule, investigate more findings, and spend less time deciphering suspicious code.

= Choose your next step =

**Want to see what is happening on your site?**
Start with BitFire Free. Complete setup, run a malware scan, and review the traffic reaching WordPress.

**Need Always-On Protection, RASP, or Threat Hunter?**
[View current Pro pricing and multi-site discounts](https://bitfire.co/en/upgrade).

**Want help with deployment or ongoing tuning?**
Choose self-managed Pro or add paid Managed Protection or Priority Support for hands-on help. [Find the right support option](https://bitfire.co/en/upgrade#pricing).

Questions before installing? Visit the [WordPress support forum](https://wordpress.org/support/plugin/bitfire/) or [talk to the BitFire team](https://bitfire.co/en/contact).

== Installation ==

1. Install BitFire from the WordPress plugin directory, or upload the plugin files to `/wp-content/plugins/bitfire/`.
2. Activate BitFire through the Plugins screen in WordPress.
3. Open BitFire in your admin sidebar and follow the setup guide.
4. Run your first malware scan and explore your traffic dashboard.

[Read the setup guide and hosting requirements](https://bitfire.co/en/support-install-guide), including how to enable Pro Always-On Protection.

Need a hand? [Talk to the BitFire team](https://bitfire.co/en/contact).

== Frequently Asked Questions ==

= Is the web application firewall included in Free? =

Yes. BitFire Free includes the web application firewall, bot blocking, login protection, manual malware scanning, traffic monitoring, and 12 AI analysis credits for the lifetime of the domain.

Pro adds Always-On Protection, RASP, Threat Hunter, scheduled malware scanning, and an expanded allowance of 1,000 AI analysis credits.

= What does Always-On Protection add? =

Free includes the firewall as a WordPress plugin. Pro Always-On Protection loads BitFire before WordPress, extending inspection to PHP requests that bypass normal plugin loading. It puts your security layer earlier in the path of an attack.

= What is the difference between a firewall and RASP? =

The firewall evaluates incoming requests. RASP checks whether selected operations inside the application are authorized, such as writing PHP files or creating an administrator account.

They are complementary layers. An exploit that is unfamiliar to request filtering may still be blocked when it attempts an unauthorized operation covered by RASP.

= Can BitFire protect against an unknown vulnerability? =

Yes. Pro runtime protection can block an unknown exploit when it attempts an unauthorized PHP file write, administrator privilege change, or administrator impersonation. It checks authorization rather than waiting for a signature that identifies the specific exploit.

= Can I control what gets blocked? =

Yes. Review blocked requests in your dashboard, see why they were flagged, and approve legitimate traffic. Manage exceptions for your forms, store, and integrations from the same place you investigate suspicious activity.

= Does BitFire block legitimate search-engine crawlers? =

BitFire provides configurable bot policies. You can allow a bot, authenticate it using source-network information, or block it. Review your crawler policies during setup so the search engines and services your site relies on have the access they need.

= Can I use BitFire with Cloudflare? =

Yes. Keep your CDN and add protection inside WordPress. Pro RASP adds checks on unauthorized file writes and administrator changes, complementing the filtering at your site's edge.

= Can BitFire help investigate an infected site? =

Start with a malware scan to find suspicious files. Then use Pro Threat Hunter to investigate what could bring the infection back: scheduled tasks, hidden administrator access, database content, startup files, and background processes.

Need expert help? [Talk to BitFire about cleanup and incident response](https://bitfire.co/en/contact).

= How does AI malware analysis work? =

Submit suspicious code to BitFire's AI analysis service for help understanding what it does and why it was flagged. Use the assessment alongside scan evidence to decide what to allow, repair, or remove.

Free includes 12 AI analysis credits for the lifetime of the domain. Pro includes 1,000 credits. See the [malware scanning guide](https://bitfire.co/en/support-malware-scan#ai-analysis) for workflow and usage details.

= How much does Pro cost? =

Pro is billed annually, with discounts for multiple sites. Optional paid Managed Protection and Priority Support packages add hands-on help. [Find your plan and current pricing](https://bitfire.co/en/upgrade).

= Where can I get help? =

Use the [WordPress support forum](https://wordpress.org/support/plugin/bitfire/) or the [BitFire support documentation](https://bitfire.co/en/support). For deployment assistance, managed protection, or questions about your hosting environment, [contact the BitFire team](https://bitfire.co/en/contact).

== Screenshots ==

1. Understand your traffic: review recorded requests, visitor information, and whether BitFire allowed or blocked the request.
2. Control bot access: review crawler policies and decide which automated visitors should reach your site.
3. Investigate suspicious files: compare scan findings with known-good files before deciding what to allow, repair, or remove.
4. Find the request that matters: filter traffic by time, browser, URL, IP address, or response code.
5. Review suspicious links: inspect database scan findings in posts and comments.
6. Keep up with security activity: review daily and weekly status emails.
7. Manage protection settings: review available controls from the WordPress dashboard.

== Privacy / Monitoring / Data Collection ==

BitFire processes security data to inspect requests, check file integrity, and investigate suspicious activity. Some features communicate with BitFire services.

* **Local traffic logs.** BitFire stores security logs on your server. Logs can include IP addresses, request URLs, headers, user-agent strings, filtered request data, and security decisions. Sensitive-value filtering is designed to redact passwords, payment details, tokens, and similar fields.
* **File hash checking.** BitFire sends file fingerprints to its hash service to compare with known-good files. This check sends hashes rather than file contents.
* **AI analysis.** Suspicious code snippets can be sent to BitFire's servers for AI-assisted analysis. This is separate from hash checking and can include file contents.
* **Bot verification.** BitFire may send bot-related IP addresses, user-agent strings, and filtered bot request samples to its services for verification, classification, and reputation checks.
* **Error reporting.** BitFire can send plugin error reports to help diagnose software problems.
* **Local storage.** Logs and configuration stay on your server.

[Read the BitFire privacy policy](https://bitfire.co/privacy) | [Service terms](https://bitfire.co/terms) | [Ask a privacy question](https://bitfire.co/en/contact)

== Changelog ==

= 5.2.3 =
 * Added recovery-safe protection that keeps WordPress accessible and alerts administrators if BitFire's secure configuration storage becomes unavailable.
 * Hardened secure configuration discovery by validating configuration pointers as bounded data instead of executing them.
 * Improved browser verification reliability with persisted-state checks, temporary fail-open recovery, and clearer failure logging.
 * Improved verified crawler handling, including Storebot-Google authentication and better cached reverse-DNS identity.
 * Improved WooCommerce, newsletter, and anonymous REST API compatibility while keeping WordPress user endpoints protected.
 * Improved detection of HTML-entity-obfuscated request payloads.
 * Fixed malware diff handling for oversized or incomplete comparisons.
 * Improved traffic filtering and labels for browser challenge outcomes.
 * Fixed `ok_apis` handling and improved the auto-allow button for certain browser-verification block types.

= 5.2.1 =
 * Improved browser verification controls and challenge-page handling.
 * Fixed Elementor compatibility issue.
 * Improved/Fixed REST api catalog curation for some plugins that registered callbacks late.
 * Added dashboard filtering for JavaScript-verified browser traffic.
 * Improved fake bot and fake browser labeling in traffic views.
 * Improved bot identity hydration for fake crawler impersonation cases.
 * Updated plugin copy, privacy details, and WordPress compatibility metadata.
 * Fixed a bug that could prevent browser verification from running for some sites when the setting was toggled on and off repeatedly
 * Refactored browser verification path to make WordPress AI checks pass

= 5.1.5 =
 * Bots impersonating crawlers (bing, meta, google, etc) are not blocked for simple unrestricted GET requests
 * Added daily fetch data for supplemental crawler dns / cidr lists
 * Improved server IP address detection for allowing local server loop back calls
 * Added plugin inventory hiding to malware detection capabilities
 * Malware detections for plugins missing valid headers / plugin scripts
 * Malware detections for plugins with random identifiers in them
 * Improved logging of xmlrpc requests - now records list of method names - not raw xml
 * Added ability to allow users to delete / restore entire plugins if they are only malware (not official plugins with strong malware signals)
 * Binary files are excluded from malware diffs now
 * Reduced false positives for SQL injection
 * Bot Control panel links to dashboard filter user agents better
 * AI verdict results are now stored for future reference
 * Fix deprecation warning for http response headers on PHP 8.5
 * Removed dependency on filter_var extension
 * Added expert opinion check allowing admins to request a review of potential malware samples by BitFire staff

= 5.1.4 =
 * Fixed an issue that could allow some admin-ajax requests to recieve a browser challenge for the logged in admin on first install
 * Added additional filtering to cover unknown authorization values, provider keys, and hexadecimal tokens in log storage
 * Added daily updated list of allowed network ranges for core web and AI crawers
 * Improved chaching of DNS lookups for core web bots
 * Added additional bot telemetry gating for bitfire core enable flag

= 5.1.3 =
 * fixed an issue with bot triage recomendations that could generate fatal errors on some host in a background task

= 5.1.1 =
 * Added traffic percent blocking for large sites to sample blocking behavior before fully commiting
 * Increased free AI usage credits from 10 to 12
 * Improved bot/browser verification compatibility with ModSecurity
 * Added buttons for allowing traffic on the dashboard
 * Fixed an issue that was blocking obviously malicious bots even when bot whitelist setting was not enabled
 * Added reasonable limit for max malware file size to prevent resource exchaustion on servers with very large files
 * Expanded bot source and threat intel data
 * Older versions could label some woocommerce user-agents that were completely random as 
 * Improved detection of when to load wordpress vs when to inspect early
 * Bots can be configured directly from the dahboard by clicking on their link to the bot control page
 * False positives can now have execptions added on the dashboard with a single button click
 * AI Malware change for OpenAI compliance - previous versions will no longer support AI analysis
 * Threat hunter content scanner reduced false positiveso
 * Basic harending (size limits, shape constraints) for inputs, moved some requests to POST
 * Expanded learning to support sites that accept POSTs from off site for validated web browsers
 * Bot triage moves from hourly to every 3 hours
 * Expanded runtime protection to ensure environemnt loaded successfull before registering wordpress hooks
 * Improved malware input tainting tracing which detects additional potential malware, reduced false positives
 * Added an exclude list of allowed files in the root for the malware scanner
 * Bots who have been repeat visitors with an AI recomendation different different than current mode now show up on to_review tab


= 5.1.0 =
 * Reduced false positvies for malware scan
 * Improved AI scan results with greatly reduced false positives
 * Implemented quarantine restore for deleted malware files in case of site breakage with 
 * Add quarantine restore in case core files are deleted from malware cleanup using new mu-plugin error handler bitfire.php
 * Improved RASP compatibility with fewer exceptions
 * UI improvements
 * Add quick links to wafer firewall scan and securityheaders.com tests
 * Hardening for bot domain verification
 * Improved UI browser and bot icons
 * Support auto-updating BitFire PRO plugin
 * Improved fallbacks for caching
 * Minor refactoring to improve AI analysis of codebase
 * Added special handling for servers with low available memory (< 10MB)
 * Added support for servers that have getmypid() disabled

= 5.0.9 =
 * Add security posture to settings page
 * Improved bot identification
 * Improved loading order decreases block time
 * Multi-Site support!
 * Few bug fixes
 * Fixed an issue with support for PHP 7.4
 * Links to header and WAF 3rd party verification checks on settings page
 * Display hardening for malformed malware 
 * Fix for header signatures on 32bit systems

= 5.0.0 =
 * New AI-powered malware analysis for suspicious files
 * Reduced Pro pricing to $60/year with volume discounts
 * Improved malware scanner performance and accuracy
 * Updated bot and browser fingerprint databases
 * Improved dashboard and settings UI

= 4.8.3 =
 * Fix an issue that could reset the configuration on upgrade

= 4.8.2 =
 * Improvements to the malware scanning UI
 * Fixes for downloading non-PHP files
 * Additional guards to handle corner cases

= 4.8.0 =
 * Improved malware detection and reduced false positives
 * Added 3 new file hash servers in US, DE, and KR
 * Added support for checking for backups and files that could contain sensitive data
 * New daily/weekly status emails
 * Added daily malware scan scheduling
 * Various stability and configuration improvements

= 4.7.4 =
 * Improved dashboard messaging for IP and user-agent blocking
 * Fixed toggle behavior on the exceptions page
 * Fixed deprecation warnings
 * Fixed an issue that could prevent uploading plugins when bot blocking was enabled

= 4.7.3 =
 * Initial WP-CLI support: review logs, check metrics, manage blocks
 * Configuration file reliability improvements
 * PHP 8.3 compatibility fix

= 4.7.2 =
 * Improved traffic monitoring and logging
 * Added "Fake Browser" detection badges
 * Added DoS protection for rate-limited IPs
 * New traffic filter keywords: BLOCKED, RESTRICTED, ADMIN, LOGINS, and more
 * Added email notifications for server health
 * Performance improvements across the board

= 4.7.0 =
 * Added AI verification framework for block accuracy
 * Reduced server communication timeout for faster responses
 * Additional blocking class types for exclusions
 * PHP 8.4 compatibility
 * Updated Google, Bing, and Cloudflare IP lists

= 4.6.1 =
 * Improved dashboard log searching
 * Fixed a rare memory issue with log writing

= 4.6 =
 * Moved configuration and log storage to a more secure location
 * Added .htaccess protection for data directories
 * Resolved several minor PHP warnings

= 4.5 =
 * Fixed filtering on blocked requests
 * Fixed handling of malformed file uploads
 * Added additional browser support

= 4.4.9 =
 * Major quality and performance improvements
 * Daily report emails
 * Complete rewrite of caching and statistics
 * Full support for cached websites (Cloudflare, etc.)
 * Log up to 30 days and 2 million requests per month

= 4.0.1 =
 * Major overhaul of browser and bot detection
 * Added 180+ browsers and 300+ browser icons
 * Switched to high-performance binary log format
 * Added commercial IP reputation database with 300K+ abusive IPs
 * Simplified user interface


== Upgrade Notice ==

= 5.0.0 =
Major release with AI-powered malware analysis, reduced Pro pricing, and improved scanner performance. Recommended for all users.

