Complete and Simple WordPress Security. Unrestricted, with no premium features.
The WordPress Simple Firewall is the only WordPress security plugin that protects itself - this plugin will prevent access to itself so that unauthorized users can't deactivate or screw with your security settings.
A basic intro to all the features:
Protects your WordPress site in 5 main ways:
This plugins locks itself down - you can add access restriction to the plugin itself!
Builds upon the simplicity and effectiveness of the WordPress Firewall 2 plugin.
Adds several layers of protection to the WordPress login screen through identity verification and Brute Force Login hacking prevention.
Uses and builds upon tried and tested SPAM prevention and filtering techniques with some unique approaches found only in this plugin.
Provides options for locking down your WordPress site from both legitimate users and people who may have gained unauthorized access.
Read more on each section below...
The WordPress Simple Firewall is built to be reliable, and easy to use by anyone. Seriously, the interface is simple! :)
It adds extra features over WordPress Firewall 2, including:
Basic functionality is based on the principles employed by the WordPress Firewall 2 plugin.
Note: Login Protection is a completely independent feature to the Firewall. IP Address whitelists are not shared.
With our Login Protection features this plugin will single-handling prevent brute force login attack on all your WordPress sites.
It doesn't need IP Address Ban Lists (which are actually useless anyway), and instead puts hard limits on your WordPress site, and force users to verify themselves when they login.
As of version 1.2.0+ you now have several ways to add simple protection to your WordPress Login system.
These options alone will protect your WordPress sites from nearly all forms of Brute Force login attacks.
And you hardly need to configure anything! Simply check the options to turn them on, set a cooldown interval and you're instantly protected.
As of version 1.6, this plugin integrates GASP Spambot Protection.
We have taken this functionality a level further and added the concept of unique, per-page visit, Comment Tokens.
Comment Tokens are unique keys that are created every time a page loads and they are uniquely generated based on 3 factors:
This is all handle automatically and your users will not be affected - they'll still just have a checkbox like the original GASP plugin.
These comment tokens are then embedded in the comment form and must be presented to your WordPress site when a comment is posted. The plugin will then examine the token, the IP address from which the comment is coming, and page upon which the comment is being posted. They must all match before the comment is accepted.
Furthermore, we place a cooldown (i.e. you must wait X seconds before you can post using that token) and an expiration on these comment tokens. The reasons for this are:
This all combines to make it much more difficult for spambots (and also human spammers as they have to now wait) to work their dirty magic :)
Requires: 3.2.0 or higher
Compatible up to: 3.7.1
Last Updated: 2013-11-19
5 of 6 support threads in the last two months have been resolved.
Got something to say? Need help?