• Resolved dimal

    (@dimalifragis)


    Hi.

    Wordfence (and Ninja Firewall from what i know) have both a “prepend” mode. I guess you know what that means. I think Wordfence calls it Extended mode, it loads some parts of the firewall before WordPress.

    Do you plan to add this ? or it is not needed with your plugin?

    I ask that, because i would love to replace the heavy Wordfence.

    Thanks

Viewing 4 replies - 1 through 4 (of 4 total)
  • Plugin Author Fernando Tellado

    (@fernandot)

    Hi @dimalifragis 🙂

    Vigilant has a system that serves a similar and very powerful purpose, but it works differently from plugins like others.

    Instead of relying solely on the PHP auto_prepend_file directive (which can sometimes cause 500 errors if not configured properly), Vigilant injects rules directly into the .htaccess file (if you’re using Apache or LiteSpeed servers)

    How is this similar to Prepend Mode? The .htaccess rules are executed at the web server level before PHP even starts up. This means that if a malicious bot attempts an SQL injection, XSS, or known vulnerability exploit, the server itself blocks the request before it consumes RAM by executing WordPress code.

    Vigilant includes a built-in feature called “Under Attack Mode.” If your website is under a massive attack, activating this feature raises an emergency shield.

    • Applies a JavaScript verification screen to block suspicious visits.
    • Enables extremely aggressive rate limiting.
    • Blocks certain vulnerable HTTP methods.

    Is it worth implementing the traditional auto_prepend_file?

    It is not strictly necessary, since Vigilant’s current approach is geared toward optimal performance and stability without risking a website crash due to absolute path issues (the arch-enemy of classic prepend mode). By intercepting malicious traffic using a combination of optimized PHP code and web server rules (.htaccess), they achieve the same early protection.

    In addition, Vigilant includes a unique self-protection system: it constantly monitors its own files against SHA-256 signatures from WordPress.org, a database fingerprint, and an included MANIFEST file, to ensure that no attacker can modify or disable the plugin from within. No other plugin currently offers anything similar.

    Of course, it’s my baby, and I’m not going to say anything bad about the plugin, but I don’t stand to gain anything from it, as you probably know, it’s 100% free. But yes, I would encourage you to switch to Vigilant, it will give you the same defensive robustness but with a much more modern, lighter system that will never break your website due to file path issues.

    In summary:

    • Same protection without the risk of downtime: Vigilant doesn’t use the traditional (PHP) auto_prepend_file because it prefers to block attacks one step earlier: directly on the web server (.htaccess).
    • It achieves the same immediate shielding effect but without the risk of the website encountering a 500 Error if you switch hosting providers or change your site paths.
    • Zero consumption of actual resources: By blocking malicious traffic at the server level, attacks don’t even wake up WordPress or the database, achieving the same RAM and CPU savings as Ninja or Wordfence’s prepend mode.
    • The “Under Attack” mode bonus: If the website suffers a massive attack, Vigilante has a built-in emergency button that raises an instant JavaScript verification wall, something that other plugins typically delegate to external services like Cloudflare (of course, this doesn’t mean you have to do without Cloudflare or a similar CDN that offers this type of security tool, as it’s always better to stop attacks in as many layers as possible, starting from the outermost ones).

    End of self-promotion 😀

    If you’re not familiar with it or aren’t sure about the change yet, don’t implement it without testing it first. Try it out on a secondary website and check how it works, what it detects, how it does it, its resource usage, etc. Choosing a security plugin isn’t a trivial matter, it’s one of the most important decisions for any website. Don’t base your choice solely on performance, security should be your top priority.

    Thanks for giving it a try, and if you have any questions, we/I are here to help with whatever you need.

    Fernando

    Thread Starter dimal

    (@dimalifragis)

    Thank you for the reply !

    Crystal Clear.

    Along with Wordfence i use also IP Location Block. And i have Enabled in that plugin “Validation timing / Runs earlier as a mu-plugin. Blocks before other plugins load, but is more invasive.”.

    Questions: can i use IP Location Block at all ? Mus i disable some options (i guess so). Shall i keep only the ASN/Countries block ?

    Plugin Author Fernando Tellado

    (@fernandot)

    I’m not familiar with that plugin, but it’s always best to block IPs by country before they reach the application, i.e., WordPress, and that way it doesn’t use up resources where they’re already scarce. If I had a choice, I’d block IPs or even entire countries in Cloudflare, or else on your hosting provider if it offers that feature; doing it in the WordPress plugin is too late.

    Regarding the “Validation timing / Runs before” mu-plugin, which loads before other plugins but is more “wireless”, it looks like a workaround designed to run before other processes, but it avoids having to write to the server files, which is exactly what we were talking about earlier.

    As for your question about whether you should disable certain options, the answer is definitely yes. Contrary to popular belief, it is actually possible to use multiple security plugins at the same time, but you should always make sure not to duplicate functionality.

    In any case, my advice is that, regardless of which plugin you choose, don’t initially install several and try to make them work together. First, choose the one you’re (almost) certain will be your main security plugin, and only after you’re clear on its features should you supplement your needs with other plugins or services (preferably an external service) and always avoid duplicating functionality.

    Hugs!

    Fernando

    Thread Starter dimal

    (@dimalifragis)

    thank you !

Viewing 4 replies - 1 through 4 (of 4 total)

You must be logged in to reply to this topic.