wordfence
Last commit date
css
14 years ago
images
14 years ago
js
14 years ago
lib
14 years ago
readme.txt
14 years ago
screenshot-1.png
14 years ago
screenshot-2.png
14 years ago
screenshot-3.png
14 years ago
screenshot-4.png
14 years ago
screenshot-5.png
14 years ago
visitor.php
14 years ago
wfscan.php
14 years ago
wordfence.php
14 years ago
readme.txt
181 lines
| 1 | === Wordfence Security === |
| 2 | Contributors: mmaunder |
| 3 | Tags: wordpress, security, wordpress security, security plugin, secure, anti-virus, malware, firewall, antivirus, virus, google safe browsing, phishing, scrapers, hacking, wordfence, securty, secrity, secure |
| 4 | Requires at least: 3.3.1 |
| 5 | Tested up to: 3.3.2 |
| 6 | Stable tag: 1.4.2 |
| 7 | |
| 8 | Wordfence Security is a free enterprise class security plugin that includes a firewall, virus scanning, real-time traffic with geolocation and more. |
| 9 | |
| 10 | == Description == |
| 11 | |
| 12 | Wordfence Security is a free enterprise class security plugin that includes a firewall and anti-virus scanning for WordPress websites. |
| 13 | |
| 14 | [Remember to visit our support forums if you have questions or comments.](http://wordfence.com/forums/) |
| 15 | |
| 16 | Wordfence is 100% free. You need to sign up on Wordfence.com to get a free API key. |
| 17 | We also offer a Premium API key that adds additional scanning capabilities. See below for details. |
| 18 | |
| 19 | Wordfence: |
| 20 | |
| 21 | * Scans core files against repository versions to check their integrity. |
| 22 | * Premium API key also scans themes and plugins against repository versions. This is currently the only difference between free and premium API keys. |
| 23 | * See how files have changed. Optionally repair changed files. |
| 24 | * Scans for signatures of over 44,000 known malware variants that are known security threats. |
| 25 | * Continuously scans for malware and phishing URL's in all your comments, posts and files that are security threats. |
| 26 | * Scans for heuristics of backdoors, trojans, suspicious code and other security issues. |
| 27 | * Checks the strength of all user and admin passwords to enhance login security. |
| 28 | * Monitor for unauthorized DNS changes. |
| 29 | * Includes a firewall to block common security threats like fake Googlebots, malicious scans from hackers and botnets. |
| 30 | * Rate limit or block security threats like aggressive crawlers, scrapers and bots doing security scans for vulnerabilities in your site. |
| 31 | * Choose whether you want to block or throttle users and robots who break your security rules. |
| 32 | * Includes login security to lock out brute force hacks and to stop WordPress from revealing info that will compromise security. |
| 33 | * See all your traffic in real-time, including robots, humans, 404 errors, logins and logouts and who is consuming most of your content. Enhances your situational awareness of which security threats your site is facing. |
| 34 | * A real-time view of all traffic including automated bots that often constitute security threats that Javascript analytics packages never show you. |
| 35 | * Real-time traffic includes reverse DNS and city-level geolocation. Know which geographic area security threats originate from. |
| 36 | * Monitors disk space which is related to security because many DDoS attacks attempt to consume all disk space to create denial of service. |
| 37 | |
| 38 | Wordfence Security is full-featured and constantly updated by our team to incorporate the latest security features and to hunt for the |
| 39 | newest security threats to your WordPress website. |
| 40 | |
| 41 | == Installation == |
| 42 | |
| 43 | To install Wordfence Security and start protecting your WordPress website: |
| 44 | |
| 45 | [Remember to visit our support forums if you have questions or comments.](http://wordfence.com/forums/) |
| 46 | |
| 47 | 1. Install Wordfence Security automatically or by uploading the ZIP file. |
| 48 | 1. Activate the security plugin through the 'Plugins' menu in WordPress. |
| 49 | 1. Visit [Wordfence.com to get an API key](http://wordfence.com/) which you need to security scans. |
| 50 | 1. Go to the Wordfence menu option that appears on the left or your site's admin section. |
| 51 | 1. Enter your API key and click the button. |
| 52 | 1. Wordfence is now activated. Your first security scan will start automatically and scheduled security scanning will also be enabled. |
| 53 | 1. Visit the Wordfence options page to enter your email address so that you can receive email security alerts. |
| 54 | 1. Optionally change your security level or click the advanced options link to see individual security scanning and protection options. |
| 55 | 1. Click the "Live Traffic" menu option to watch your site activity in real-time. |
| 56 | |
| 57 | == Frequently Asked Questions == |
| 58 | |
| 59 | [Remember to visit our support forums if you have questions or comments.](http://wordfence.com/forums/) |
| 60 | |
| 61 | = Why does Wordfence Security need an API key? = |
| 62 | |
| 63 | Wordfence securely contacts our servers when doing a security scan. These include: comparing the hashes of your core, theme and plugin files |
| 64 | against the official versions to see if security has been compromised, checking if URL's in your comments, posts and files are on any known list of dangerous URL's and checking |
| 65 | if any of your file signatures match a large list of known malware files that constitute a security threat. |
| 66 | |
| 67 | = Will Wordfence slow my site down? = |
| 68 | |
| 69 | We have spent a lot of time making sure Wordfence runs very quickly and securely. Wordfence uses its own database |
| 70 | tables and advanced mysql features to ensure it runs as fast as possible. The creators of Wordfence |
| 71 | also run a large scale real-time analytics product and much of the technology and knowledge from |
| 72 | our real-time analytics products is built into Wordfence. |
| 73 | |
| 74 | = How often is Wordfence updated? = |
| 75 | |
| 76 | The Wordfence security plugin is frequently updated and we update the code on our security scanning servers |
| 77 | more frequently. Our cloud servers are continually updated with the latest known security threats and vulnerabilities so |
| 78 | that we can blog any security threat as soon as it emerges in the wild. |
| 79 | |
| 80 | = What if I need support? = |
| 81 | |
| 82 | All our paid customers receive priority support. Excellent customer service is a key part |
| 83 | of being a Wordfence member. You can also [visit our support forums where we provide free support for all Wordfence users](http://wordfence.com/forums/) and answer any security releated questions you may have. |
| 84 | |
| 85 | = Can I disable certain security features of Wordfence? = |
| 86 | |
| 87 | Yes! Simply visit the Options page, click on advanced options and enable or disable the security features you want. |
| 88 | |
| 89 | = What if my site security has already been compromised by a hacker? = |
| 90 | |
| 91 | Wordfence is the only security plugin that is able to repair core files, themes and plugins on sites where security is already compromised. |
| 92 | However, please note that site security can not be assured unless you do a full reinstall if your site has been hacked. We recommend you only |
| 93 | use Wordfence to get your site into a running state in order to recover the data you need to do a full reinstall. A full reinstall is the only |
| 94 | way to ensure site security once you have been hacked. |
| 95 | |
| 96 | = How will I be alerted that my site has a security problem? = |
| 97 | |
| 98 | Wordfence sends security alerts via email. Once you install Wordfence, you will configure a list of email addresses where security alerts will be sent. |
| 99 | When you receive a security alert, make sure you deal with it promptly to ensure your site stays secure. |
| 100 | |
| 101 | = My WordPress site is behind a firewall. Doesn't that make it secure? = |
| 102 | |
| 103 | If your site is accessible from the web, it means that people you don't know can execute PHP code on your site. |
| 104 | They have to be able to execute PHP code, like the core WordPress code, in order for your site to work. |
| 105 | Most WordPress security threats allow a hacker to execute PHP code on your website. The challenge hackers |
| 106 | face is how to get their malicious PHP code onto your site to compromise your security. There |
| 107 | are many upload mechanisms that WordPress itself, themes and plugins offer and the vast majority of these |
| 108 | are secure. However, every now and then a hacker discovers an upload mechanism that is not secure or |
| 109 | a way of fooling your site into allowing an upload. That is usually when security is compromised. Even |
| 110 | though your site is behind a commercial firewall, it still accepts web requests that include uploads and executes PHP code |
| 111 | and as long as it does that, it may become face a security vulnerability at some point. |
| 112 | |
| 113 | = Will Wordfence protect me against the Timthumb security problem? = |
| 114 | |
| 115 | The timthumb security exploit occured in 2011 and all good plugins and themes now use an updated |
| 116 | version of timthumb (which the creator of Wordfence wrote and donated to the timthumb author) which closes the security hole that |
| 117 | caused the problem. However we do scan for old version of timthumb for good measure to make sure they don't |
| 118 | cause a security hole on your site. |
| 119 | |
| 120 | = People keep telling me that WordPress itself has security problems. Is that true? = |
| 121 | |
| 122 | In general, no it's not. The WordPress team work very hard to keep the awesome software they have produced secure and in the |
| 123 | rare cases when a security hole is found, they fix it very quickly. Most responsible plugin authors also fix security holes |
| 124 | as soon as they are told about them. That's why Wordfence will warn you if you're running an old version of WordPress, a plugin |
| 125 | or a theme, because often these have been updated to fix a security hole. |
| 126 | |
| 127 | |
| 128 | == Screenshots == |
| 129 | |
| 130 | 1. The home screen of Wordfence where you can see a summary, manage security issues and do a manual security scan. |
| 131 | 2. The Live Traffic view of Wordfence where you can see real-time activity on your site. |
| 132 | 3. The "Blocked IPs" page where you can manage blocked IP's, locked out IP's and see recently throttled IPs that violated security rules. |
| 133 | 4. The basic view of Wordfence options. There is very little to configure other than your alert email address and security level. |
| 134 | 5. If you're technically minded, this is the under-the-hood view of Wordfence options where you can fine-tune your security settings. |
| 135 | |
| 136 | == Changelog == |
| 137 | = 1.4.2 = |
| 138 | * Email to send security alerts to is now configured at the same time an API key is entered. |
| 139 | * phpinfo is emailed along with activity log when user requests to send us activity log so that we can see things like PHP max execution time and other relevant data |
| 140 | * Now writing individual files to activity log during security scans for better diagnostics. |
| 141 | * Login security message. |
| 142 | * Updated readme.txt FAQ and description. |
| 143 | * Fixed bug where sites with self signed SSL security certificate never start scan because cert fails security check. |
| 144 | * Increased API curl timeout to 300 for slower hosts that seem affected during URL security scans. |
| 145 | |
| 146 | = 1.4.1 = |
| 147 | * This is a major release, please upgrade immediately. |
| 148 | * Only scan files in the WordPress ABSPATH root directory and known WordPress subdirectories. Prevents potentially massive scans on hosts that have large dirs off their wordpress root. |
| 149 | * Don't generate plain SHA hashes anymore because we don't currently use them on the server side for scanning. (Still generates md5's and SHAC) |
| 150 | * No longer do change tracking on files before scans because the change tracking does almost the same amount of work when generating hashes as the actual scan. So just do the scan, which is now faster. |
| 151 | * Updated internal version to 1.2 to use new code on the server side which sends back a list of unknown files rather than known files, which is usually smaller and more network efficient. |
| 152 | * Improved logging in activity log. |
| 153 | * Removed SSL peer verification because some hosts have bad cert config. Connection to our servers is still via SSL. |
| 154 | * Fixed a few minor issues. Overall you should notice that scans are much faster now. |
| 155 | |
| 156 | = 1.3.3 = |
| 157 | * Made real-time server polling more efficient. |
| 158 | * Entering your API key now automatically starts your first scan. Was causing some confusion. |
| 159 | * Link to forums added for free customer support. |
| 160 | |
| 161 | = 1.3.2 = |
| 162 | * Reduced the number of database connections that Wordfence makes to one. |
| 163 | * Modified the memory efficient unbuffered queries we use to only use a single DB connection. |
| 164 | * Removed status updates during post and comment scans which prevents interference with unbuffered queries and makes the scans even faster. |
| 165 | |
| 166 | = 1.3.1 = |
| 167 | * Fixed a bug where if you have the plugin "secure-wordpress" installed, you can't do a Wordfence scan because it says you have the wrong version. This is because secure-wordpress trashes the $wp_version global variable to hide your version rather than using the filters provided by WordPress. So coded a workaround so that your Wordfence scans will work with that plugin installed. |
| 168 | |
| 169 | = 1.3 = |
| 170 | * Minor fix to point to the correct binary API URL on the Wordfence cloud servers. |
| 171 | |
| 172 | = 1.2 = |
| 173 | * It is now free to get a Wordfence API key. |
| 174 | * Premium keys include theme and plugin file verification which consumes resources on the Wordfence servers. |
| 175 | * Various bugfixes and performance enhancements. |
| 176 | |
| 177 | = 1.1 = |
| 178 | * Initial public release of Wordfence. |
| 179 | |
| 180 | |
| 181 |