{"id":301968,"date":"2026-05-19T08:35:27","date_gmt":"2026-05-19T08:35:27","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/securewp\/"},"modified":"2026-05-19T08:34:57","modified_gmt":"2026-05-19T08:34:57","slug":"sitefort","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/sitefort\/","author":23472870,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.0","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"SiteFort - Advanced Security, Firewall & Malware Scanner","header_author":"Securewp","header_description":"WordPress malware scanner and firewall with 2FA login protection, vulnerability alerts and advanced security hardening.","assets_banners_color":"","last_updated":"2026-05-19 08:34:57","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/securewp.net\/wordpress-security-plugin\/","header_author_uri":"https:\/\/securewp.net","rating":0,"author_block_rating":0,"active_installs":0,"downloads":25,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq"],"tags":{"1.0.0":{"tag":"1.0.0","author":"securewpteam","date":"2026-05-19 08:34:57"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3536885,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3536886,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon-512x512.png":{"filename":"icon-512x512.png","revision":3536888,"resolution":"512x512","location":"assets","locale":"","width":512,"height":512},"icon.svg":{"filename":"icon.svg","revision":3536884,"resolution":false,"location":"assets","locale":false}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"<strong>Security Overview<\/strong> - malware status, firewall activity, vulnerability count, login protection, and action center.","2":"<strong>Security Scanner<\/strong> - staged scan progress across files, malware, accounts, database\/content safety, reputation, vulnerabilities, and server exposure.","3":"<strong>Malware Findings<\/strong> - affected files, severity, detection type, file integrity status, and remediation actions.","4":"<strong>Firewall Controls<\/strong> - IP rules, country blocking, bot\/crawler policy, rate limits, community blocklist, and Cloudflare Sync.","5":"<strong>Login Security and 2FA<\/strong> - role enforcement, authenticator app setup, lockouts, CAPTCHA, custom login URL, and password policy controls.","6":"<strong>Security Hardening<\/strong> - sensitive file protection, PHP execution controls, XML-RPC, REST API, user enumeration, file editor, and headers.","7":"<strong>Vulnerability Scanner<\/strong> - affected plugins, themes, WordPress core, CVE references, severity, and fix guidance.","8":"<strong>Audit Log<\/strong> - searchable security events, user activity, firewall actions, scan results, and sensitive changes.","9":"<strong>SiteFort Console<\/strong> - multi-site status, scans, alerts, reports, uptime, SSL, and team workflows."},"jetpack_post_was_ever_published":false},"plugin_section":[],"plugin_tags":[9211,1174,55021,600,6460],"plugin_category":[54],"plugin_contributors":[263486],"plugin_business_model":[],"class_list":["post-301968","plugin","type-plugin","status-publish","hentry","plugin_tags-2fa","plugin_tags-firewall","plugin_tags-malware-scanner","plugin_tags-security","plugin_tags-vulnerability","plugin_category-security-and-spam-protection","plugin_contributors-securewpteam","plugin_committers-securewpteam"],"banners":[],"icons":{"svg":"https:\/\/ps.w.org\/sitefort\/assets\/icon.svg?rev=3536884","icon":"https:\/\/ps.w.org\/sitefort\/assets\/icon.svg?rev=3536884","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<h3>ENTERPRISE WORDPRESS SECURITY, FIREWALL &amp; MALWARE SCANNER<\/h3>\n\n<p>SiteFort protects WordPress sites with a full-site security scanner, malware detection, firewall rules, country blocking, Cloudflare edge blocking, login security, 2FA, vulnerability checks, hardening controls, audit logging, and optional centralized management.<\/p>\n\n<p>Run SiteFort from <strong>wp-admin<\/strong> for one site. Connect sites to <strong>SiteFort Console<\/strong> when you want one panel for multiple websites, remote workflows, alerts, reports, uptime, SSL, and team access.<\/p>\n\n<p><strong>Helpful links:<\/strong> <a href=\"https:\/\/securewp.net\/wordpress-security-plugin\/\">Plugin Features<\/a> | <a href=\"https:\/\/securewp.net\/security-checker\/\">Free Remote Scan<\/a> | <a href=\"https:\/\/securewp.net\/pricing\/\">Pricing<\/a> | <a href=\"https:\/\/securewp.net\/docs\/\">Documentation<\/a><\/p>\n\n<h4>CORE SECURITY FEATURES<\/h4>\n\n<ul>\n<li><strong>Full-site WordPress security scanner<\/strong> checks files, accounts, content, database safety, reputation, vulnerabilities, and hidden administrator risks.<\/li>\n<li><strong>WordPress malware scanner<\/strong> detects backdoors, web shells, malicious PHP, injected scripts, SEO spam, suspicious redirects, modified files, and exposed sensitive files.<\/li>\n<li><strong>Firewall with country blocking<\/strong> blocks unwanted traffic by IP, CIDR, country, bot, crawler, user agent, rate limit, scanner behavior, and threat intelligence.<\/li>\n<li><strong>Cloudflare edge blocking<\/strong> syncs supported firewall rules to Cloudflare so high-volume blocks can happen before traffic reaches WordPress.<\/li>\n<li><strong>Easy bot filter policy<\/strong> gives you Basic, Balanced, and Maximum bot protection without writing manual rules.<\/li>\n<li><strong>Login security and 2FA<\/strong> protect users with authenticator apps, email codes, recovery codes, brute-force protection, CAPTCHA, custom login URLs, weak password checks, and breached-password detection.<\/li>\n<li><strong>Security hardening<\/strong> reduces exposure from XML-RPC, user enumeration, PHP execution in uploads, sensitive files, file editing, REST access, application passwords, version output, and missing security headers.<\/li>\n<li><strong>Audit log and Console<\/strong> provide event history, security evidence, multi-site visibility, remote workflows, reports, team access, and alert routing.<\/li>\n<\/ul>\n\n<h4>WORDPRESS SECURITY SCANNER<\/h4>\n\n<p>SiteFort is not limited to file scanning. It runs a layered review of the WordPress site and groups findings by risk so administrators can act quickly.<\/p>\n\n<ul>\n<li><strong>File integrity and malware detection<\/strong> - checks WordPress core, plugins, themes, uploads, and custom files for unauthorized changes, backdoors, web shells, malware variants, suspicious PHP, injected code, SEO spam, malicious redirects, and exposed sensitive files.<\/li>\n<li><strong>User account security<\/strong> - detects weak account posture, breached passwords, risky roles, suspicious user data, and administrator accounts that need review.<\/li>\n<li><strong>Ghost administrator detection<\/strong> - flags hidden or unexpected administrator accounts, including suspicious admin users created outside normal site workflows.<\/li>\n<li><strong>Content and database safety<\/strong> - checks WordPress data for injected malicious content, suspicious options, unsafe URLs, spam injections, and malicious redirect indicators.<\/li>\n<li><strong>Domain and IP reputation<\/strong> - checks reputation context for the website domain and server IP so blocklist or abuse signals are visible before they affect trust.<\/li>\n<li><strong>Vulnerability scanner<\/strong> - checks WordPress core, plugins, and themes for known vulnerabilities, affected versions, severity, CVE references where available, and recommended action.<\/li>\n<li><strong>Server state and exposure checks<\/strong> - finds public paths, backups, logs, configuration files, and server conditions that can expose secrets or make compromise easier.<\/li>\n<\/ul>\n\n<h4>WORDPRESS FIREWALL<\/h4>\n\n<p>SiteFort provides practical firewall controls for production sites without requiring custom WAF rule writing.<\/p>\n\n<ul>\n<li>Block or allow by <strong>IP address, CIDR range, country, bot, crawler, or user agent<\/strong>.<\/li>\n<li>Use <strong>country blocking<\/strong> in block-selected or allow-only mode.<\/li>\n<li>Detect probes for <code>.env<\/code>, <code>.git<\/code>, <code>wp-config.php<\/code> backups, SQL dumps, debug logs, installer files, and sensitive paths.<\/li>\n<li>Enable <strong>Cloudflare Sync<\/strong> to push supported IP, country, and user-agent rules to Cloudflare's edge.<\/li>\n<li>Escalate repeated active attacks to temporary edge blocks when Cloudflare sync is configured.<\/li>\n<li>Reduce abusive spikes with rate limiting, 404 probe controls, and community threat intelligence.<\/li>\n<\/ul>\n\n<h4>BOT AND CRAWLER POLICY<\/h4>\n\n<p>Choose <strong>Basic<\/strong>, <strong>Balanced<\/strong>, or <strong>Maximum<\/strong> protection to block hacking tools, vulnerability scanners, scrapers, automated scripts, and unrecognized bots. Trusted search engines, social previews, and major crawlers can stay allowed while unwanted automation is filtered.<\/p>\n\n<h4>LOGIN SECURITY AND 2FA<\/h4>\n\n<p>Account takeover is one of the fastest ways to lose control of a WordPress site. SiteFort adds role-based 2FA, authenticator app codes, email codes, recovery codes, brute-force lockouts, CAPTCHA, custom login URLs, weak password enforcement, breached-password detection, safer login responses, and XML-RPC\/REST authentication controls.<\/p>\n\n<h4>WORDPRESS SECURITY HARDENING<\/h4>\n\n<p>Close common WordPress exposure points from the dashboard: block PHP execution in uploads, protect sensitive files, disable directory listing, disable the theme\/plugin file editor, disable or restrict XML-RPC and application passwords, block username enumeration, hide WordPress version output, restrict REST access where appropriate, and apply security headers where supported.<\/p>\n\n<h4>VULNERABILITY MANAGEMENT<\/h4>\n\n<p>SiteFort checks installed WordPress core, plugin, and theme versions against vulnerability intelligence and shows affected assets, severity, CVE references where available, and recommended fixes.<\/p>\n\n<p><strong>Pro:<\/strong> automated vulnerability alerts notify teams when a known vulnerability affects an installed plugin, theme, or WordPress core version.<\/p>\n\n<h4>AUDIT LOG AND SITEFORT CONSOLE<\/h4>\n\n<p>Track logins, failed logins, lockouts, user changes, plugin\/theme changes, firewall blocks, scan results, hardening changes, and sensitive actions.<\/p>\n\n<p>Use SiteFort from wp-admin for site-level protection. Connect to <strong>SiteFort Console<\/strong> for multi-site status, scan history, vulnerability tracking, uptime monitoring, SSL expiry checks, remote website scanning, alert routing, downloadable reports, team roles, and support workflows.<\/p>\n\n<h4>PRO AND MANAGED SECURITY FEATURES<\/h4>\n\n<p>Core protection is available in the plugin. Paid plans add <strong>unlimited cloud deep threat analysis<\/strong>, <strong>scheduled malware scans<\/strong>, <strong>automated vulnerability alerts<\/strong>, <strong>one-click malware repair<\/strong>, uptime\/SSL monitoring, Slack\/Discord\/email alert workflows, expert cleanup discounts, and managed security options.<\/p>\n\n<h3>External services<\/h3>\n\n<p>SiteFort connects to external services for licensing, cloud-assisted security analysis, optional Console sync, optional CAPTCHA checks, optional GeoIP downloads, optional IP ownership lookups, and integrations you enable. If an optional feature or integration is not configured or used, SiteFort does not contact that service for that feature.<\/p>\n\n<h4>SiteFort Cloud<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> SiteFort Cloud<\/li>\n<li><strong>Endpoints:<\/strong> <code>securewp.net<\/code>, <code>intel.securewp.net<\/code>, <code>console.securewp.net<\/code><\/li>\n<li><strong>Purpose:<\/strong> license activation, plugin service metadata, cloud malware analysis, vulnerability intelligence, firewall intelligence, community blocklist sync, reputation context, clean-file repair, and optional Console sync.<\/li>\n<li><strong>When\/data:<\/strong> used during license activation, malware scans, vulnerability checks, firewall intelligence updates, blocklist sync, reputation checks, and optional Console sync. Data may include email address, license key\/token, site URL, WordPress\/plugin versions, installed plugin\/theme names and versions, file hashes, scan results, vulnerability findings, reputation status, firewall metadata, blocked IPs, and security configuration metadata.<\/li>\n<li><strong>Malware scanning:<\/strong> file hashes are sent first. Only files that cannot be verified by hash alone may be uploaded for deeper analysis and are deleted after processing. Posts, pages, comments, WooCommerce orders, customer data, and full database content are not sent for malware scanning. If <code>wp-config.php<\/code> requires analysis, sensitive configuration values are removed before upload.<\/li>\n<li><strong>Temporary storage URLs:<\/strong> SiteFort Cloud may return temporary upload or download URLs on object-storage hosts such as <code>*.amazonaws.com<\/code> or <code>*.r2.cloudflarestorage.com<\/code>. These URLs are used only for the specific scan upload or clean-file repair download requested by SiteFort Cloud.<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/securewp.net\/privacy-policy\/<\/li>\n<li><strong>Terms:<\/strong> https:\/\/securewp.net\/terms-and-conditions\/<\/li>\n<li><strong>Storage provider policies:<\/strong> Amazon Web Services privacy policy https:\/\/aws.amazon.com\/privacy\/ and service terms https:\/\/aws.amazon.com\/service-terms\/; Cloudflare privacy policy https:\/\/www.cloudflare.com\/privacypolicy\/ and terms https:\/\/www.cloudflare.com\/website-terms\/<\/li>\n<\/ul>\n\n<h4>MaxMind GeoLite2<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> MaxMind GeoLite2, https:\/\/dev.maxmind.com\/geoip\/geolite2-free-geolocation-data\/<\/li>\n<li><strong>Endpoints:<\/strong> <code>download.maxmind.com<\/code>; MaxMind may redirect downloads to temporary storage URLs such as <code>*.amazonaws.com<\/code> or <code>*.r2.cloudflarestorage.com<\/code>.<\/li>\n<li><strong>Purpose:<\/strong> local GeoIP country lookups when MaxMind is configured.<\/li>\n<li><strong>When\/data:<\/strong> used when an administrator downloads or updates the GeoLite2 database. Sends the configured MaxMind account ID and license key to MaxMind for authentication. Visitor IPs are resolved locally against the downloaded database and are not sent to MaxMind during normal visitor requests.<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/www.maxmind.com\/en\/privacy-policy<\/li>\n<li><strong>Terms\/EULA:<\/strong> https:\/\/www.maxmind.com\/en\/geolite2\/eula<\/li>\n<\/ul>\n\n<h4>Have I Been Pwned<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> https:\/\/haveibeenpwned.com\/Passwords<\/li>\n<li><strong>Endpoint:<\/strong> <code>api.pwnedpasswords.com<\/code><\/li>\n<li><strong>Purpose:<\/strong> breached-password detection when enabled.<\/li>\n<li><strong>When\/data:<\/strong> during login or password validation. Sends only the first 5 characters of the SHA-1 password hash. Full passwords and full hashes are never sent.<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/haveibeenpwned.com\/Privacy<\/li>\n<li><strong>Terms:<\/strong> https:\/\/haveibeenpwned.com\/TermsOfUse<\/li>\n<\/ul>\n\n<h4>RIPE NCC and ARIN RDAP<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> RIPE NCC RDAP and ARIN RDAP public registry lookup services.<\/li>\n<li><strong>Endpoints:<\/strong> <code>rdap.db.ripe.net<\/code>, <code>rdap.arin.net<\/code><\/li>\n<li><strong>Purpose:<\/strong> IP ownership, network, country, and abuse-contact lookups in the firewall tools.<\/li>\n<li><strong>When\/data:<\/strong> used only when an administrator requests a WHOIS\/RDAP lookup for an IP address from the firewall interface or API. Sends the queried IP address to RIPE NCC first and falls back to ARIN if RIPE does not return a result. Site credentials, user records, scan results, and plugin settings are not sent. Results are cached locally for one hour.<\/li>\n<li><strong>RIPE NCC privacy policy:<\/strong> https:\/\/www.ripe.net\/about-us\/legal\/ripe-ncc-privacy-statement\/<\/li>\n<li><strong>RIPE Database terms:<\/strong> https:\/\/docs.db.ripe.net\/HTML-Terms-And-Conditions<\/li>\n<li><strong>ARIN privacy policy:<\/strong> https:\/\/www.arin.net\/about\/privacy\/<\/li>\n<li><strong>ARIN Whois\/RDAP terms:<\/strong> https:\/\/www.arin.net\/resources\/registry\/whois\/tou\/<\/li>\n<\/ul>\n\n<h4>Google reCAPTCHA<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> https:\/\/www.google.com\/recaptcha\/about\/<\/li>\n<li><strong>Endpoints:<\/strong> <code>www.google.com<\/code>, including <code>www.google.com\/recaptcha\/api.js<\/code> and <code>www.google.com\/recaptcha\/api\/siteverify<\/code><\/li>\n<li><strong>Purpose:<\/strong> CAPTCHA protection when selected and configured.<\/li>\n<li><strong>When\/data:<\/strong> protected login form load or challenge verification. Sends CAPTCHA token, site key, and visitor\/browser data required by Google.<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/policies.google.com\/privacy<\/li>\n<li><strong>Terms:<\/strong> https:\/\/policies.google.com\/terms<\/li>\n<\/ul>\n\n<h4>Cloudflare Turnstile<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> https:\/\/developers.cloudflare.com\/turnstile\/<\/li>\n<li><strong>Endpoints:<\/strong> <code>challenges.cloudflare.com<\/code>, including <code>challenges.cloudflare.com\/turnstile\/v0\/api.js<\/code> and <code>challenges.cloudflare.com\/turnstile\/v0\/siteverify<\/code><\/li>\n<li><strong>Purpose:<\/strong> CAPTCHA protection when selected and configured.<\/li>\n<li><strong>When\/data:<\/strong> protected login form load or challenge verification. Sends challenge token, site key, and visitor\/browser data required by Cloudflare.<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/www.cloudflare.com\/turnstile-privacy-policy\/<\/li>\n<li><strong>Terms:<\/strong> https:\/\/www.cloudflare.com\/website-terms\/<\/li>\n<\/ul>\n\n<h4>Cloudflare API<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> https:\/\/api.cloudflare.com\/<\/li>\n<li><strong>Endpoint:<\/strong> <code>api.cloudflare.com<\/code><\/li>\n<li><strong>Purpose:<\/strong> Cloudflare edge blocking and WAF rule sync when enabled.<\/li>\n<li><strong>When\/data:<\/strong> when Cloudflare settings are saved, verified, or synced. Sends Zone ID, API token\/credentials, zone details, blocked IPs, country rules, selected user-agent rules, and firewall rule data.<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<li><strong>Terms:<\/strong> https:\/\/www.cloudflare.com\/website-terms\/<\/li>\n<\/ul>\n\n<h4>Slack Webhooks<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> Slack incoming webhooks, https:\/\/api.slack.com\/messaging\/webhooks<\/li>\n<li><strong>Endpoint:<\/strong> <code>hooks.slack.com<\/code><\/li>\n<li><strong>Purpose:<\/strong> optional delivery of SiteFort security notifications to a Slack workspace selected by the administrator.<\/li>\n<li><strong>When\/data:<\/strong> only when webhook notifications are enabled, a Slack webhook URL is saved, and a notification event or test notification is sent. Data may include site name, site URL, event type, severity, scan counts, vulnerability component names, CVE identifiers, firewall digest counts, lockout identifiers, usernames, IP addresses, browser names, action URLs, timestamps, and other event details included in the selected notification.<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/slack.com\/trust\/privacy\/privacy-policy<\/li>\n<li><strong>Terms:<\/strong> https:\/\/slack.com\/terms-of-service\/user<\/li>\n<\/ul>\n\n<h4>Discord Webhooks<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> Discord webhooks, https:\/\/docs.discord.com\/developers\/resources\/webhook<\/li>\n<li><strong>Endpoints:<\/strong> <code>discord.com<\/code>, <code>discordapp.com<\/code><\/li>\n<li><strong>Purpose:<\/strong> optional delivery of SiteFort security notifications to a Discord channel selected by the administrator.<\/li>\n<li><strong>When\/data:<\/strong> only when webhook notifications are enabled, a Discord webhook URL is saved, and a notification event or test notification is sent. Data may include site name, site URL, event type, severity, scan counts, vulnerability component names, CVE identifiers, firewall digest counts, lockout identifiers, usernames, IP addresses, browser names, action URLs, timestamps, and other event details included in the selected notification.<\/li>\n<li><strong>Privacy policy:<\/strong> https:\/\/discord.com\/privacy<\/li>\n<li><strong>Terms:<\/strong> https:\/\/discord.com\/terms<\/li>\n<\/ul>\n\n<h4>Generic Webhooks<\/h4>\n\n<ul>\n<li><strong>Service:<\/strong> Administrator-configured HTTPS webhook endpoint.<\/li>\n<li><strong>Endpoint:<\/strong> the HTTPS URL entered by the administrator.<\/li>\n<li><strong>Purpose:<\/strong> optional delivery of SiteFort security notifications to a custom endpoint controlled by the site owner or their chosen provider.<\/li>\n<li><strong>When\/data:<\/strong> only when webhook notifications are enabled, a generic webhook URL is saved, and a notification event or test notification is sent. Data may include site name, site URL, event type, severity, scan counts, vulnerability component names, CVE identifiers, firewall digest counts, lockout identifiers, usernames, IP addresses, browser names, action URLs, timestamps, and other event details included in the selected notification. Generic webhook payloads may include an <code>X-SiteFort-Signature<\/code> header.<\/li>\n<li><strong>Placeholder:<\/strong> <code>https:\/\/your-endpoint.com\/webhook<\/code> is an example shown in the settings UI. It is not contacted unless an administrator replaces it with a real URL and enables generic webhook delivery.<\/li>\n<li><strong>Privacy policy and terms:<\/strong> determined by the endpoint or provider configured by the administrator. Site administrators should review and disclose the policies for their chosen webhook receiver.<\/li>\n<\/ul>\n\n<h4>Local or user-supplied URL checks<\/h4>\n\n<p>Some HTTP requests are loopback checks against the WordPress site's own public URL, for example security-header checks, public-file exposure checks, and scanner collection of links from the site's homepage. These requests contact the site being protected, not a third-party service.<\/p>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Install SiteFort from the WordPress plugin directory, or upload the plugin ZIP file.<\/li>\n<li>For manual installation, upload the unzipped <code>sitefort<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin from the <strong>Plugins<\/strong> screen and open <strong>SiteFort<\/strong> in wp-admin.<\/li>\n<li>Activate protection using email verification, a license key, or SiteFort Console authorization.<\/li>\n<li>Review scanner, firewall, country blocking, bot policy, login security, 2FA, and hardening settings.<\/li>\n<li>Connect Cloudflare from <strong>Settings &gt; Integrations<\/strong> if you want edge-level firewall enforcement.<\/li>\n<li>Run your first security scan and review malware, account, database, reputation, vulnerability, and hardening findings.<\/li>\n<\/ol>\n\n<p>SiteFort requires outbound HTTPS for license activation, cloud malware analysis, vulnerability intelligence, firewall intelligence, community blocklist updates, and optional Console sync.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20i%20use%20sitefort%20only%20from%20my%20wordpress%20dashboard%3F\"><h3>Can I use SiteFort only from my WordPress dashboard?<\/h3><\/dt>\n<dd><p>Yes. Scanner, malware detection, firewall rules, country blocking, bot policy, login security, 2FA, vulnerability scanning, hardening, audit log, and settings are available from wp-admin. The SiteFort Console is optional for centralized management, remote workflows, reports, alert routing, uptime\/SSL monitoring, team access, and support workflows.<\/p><\/dd>\n<dt id=\"what%20does%20the%20sitefort%20scanner%20check%3F\"><h3>What does the SiteFort scanner check?<\/h3><\/dt>\n<dd><p>SiteFort scans files, file integrity, malware indicators, user account security, weak and breached passwords, hidden administrator accounts, content and database safety, suspicious URLs, injected content, domain\/IP reputation, exposed sensitive files, server state, and known vulnerabilities in WordPress core, plugins, and themes.<\/p><\/dd>\n<dt id=\"what%20features%20require%20a%20paid%20plan%3F\"><h3>What features require a paid plan?<\/h3><\/dt>\n<dd><p>Paid plans add unlimited cloud deep threat analysis, scheduled and automated scans, automated vulnerability alerts, one-click malware repair, uptime\/SSL monitoring, Slack\/Discord\/email alert workflows, expert cleanup discounts, and managed security options.<\/p><\/dd>\n<dt id=\"how%20does%20cloud-assisted%20malware%20scanning%20work%3F\"><h3>How does cloud-assisted malware scanning work?<\/h3><\/dt>\n<dd><p>SiteFort hashes files locally and checks known signatures first. Known clean or known malicious files can be resolved quickly. Unknown or suspicious files may be analyzed more deeply when needed. Results are cached so unchanged files do not need the same work again.<\/p><\/dd>\n<dt id=\"does%20sitefort%20send%20my%20site%27s%20database%20content%20to%20the%20cloud%3F\"><h3>Does SiteFort send my site's database content to the cloud?<\/h3><\/dt>\n<dd><p>No. Database and content safety checks run from the WordPress site. SiteFort does not upload posts, pages, comments, WooCommerce orders, customer records, or full database content for malware scanning.<\/p>\n\n<p>For file scanning, file hashes are sent first. Only files that cannot be verified by hash alone may be uploaded for deeper malware analysis. If <code>wp-config.php<\/code> requires analysis, sensitive configuration values are removed before upload.<\/p><\/dd>\n<dt id=\"does%20sitefort%20include%20country%20blocking%20and%20cloudflare%20support%3F\"><h3>Does SiteFort include country blocking and Cloudflare support?<\/h3><\/dt>\n<dd><p>Yes. Country blocking is part of the firewall rules. SiteFort can also sync supported IP, country, and user-agent firewall rules to Cloudflare when the domain is proxied through Cloudflare and a scoped API token is configured.<\/p><\/dd>\n<dt id=\"can%20sitefort%20help%20after%20a%20site%20is%20already%20hacked%3F\"><h3>Can SiteFort help after a site is already hacked?<\/h3><\/dt>\n<dd><p>Yes. SiteFort can scan for malware, suspicious users, injected content, reputation issues, exposed files, and vulnerable components. Supported plans add one-click malware repair, and expert cleanup or managed security services are available when hands-on response is needed.<\/p><\/dd>\n\n<\/dl>","raw_excerpt":"Enterprise-grade WordPress malware scanner and firewall with 2FA, country blocking, vulnerability scanner and hardening.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/301968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=301968"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/securewpteam"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=301968"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=301968"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=301968"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=301968"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=301968"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=301968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}