Title: &#8220;Prepend Mode&#8221; ?
Last modified: September 24, 2026

---

# “Prepend Mode” ?

 *  Resolved [dimal](https://wordpress.org/support/users/dimalifragis/)
 * (@dimalifragis)
 * [1 week, 3 days ago](https://wordpress.org/support/topic/prepend-mode/)
 * Hi.
 * Wordfence (and Ninja Firewall from what i know) have both a “prepend” mode. I
   guess you know what that means. I think Wordfence calls it Extended mode, it 
   loads some parts of the firewall before WordPress.
 * Do you plan to add this ? or it is not needed with your plugin?
 * I ask that, because i would love to replace the heavy Wordfence.
 * Thanks

Viewing 4 replies - 1 through 4 (of 4 total)

 *  Plugin Author [Fernando Tellado](https://wordpress.org/support/users/fernandot/)
 * (@fernandot)
 * [1 week, 3 days ago](https://wordpress.org/support/topic/prepend-mode/#post-19028693)
 * Hi [@dimalifragis](https://wordpress.org/support/users/dimalifragis/) 🙂
 * Vigilant has a system that serves a similar and very powerful purpose, but it
   works differently from plugins like others.
 * Instead of relying solely on the PHP `auto_prepend_file` directive (which can
   sometimes cause 500 errors if not configured properly), Vigilant injects rules
   directly into the .htaccess file (if you’re using Apache or LiteSpeed servers)
 * How is this similar to Prepend Mode? The .htaccess rules are executed at the 
   web server level before PHP even starts up. This means that if a malicious bot
   attempts an SQL injection, XSS, or known vulnerability exploit, the server itself
   blocks the request before it consumes RAM by executing WordPress code.
 * Vigilant includes a built-in feature called “Under Attack Mode.” If your website
   is under a massive attack, activating this feature raises an emergency shield.
    - Applies a JavaScript verification screen to block suspicious visits.
    - Enables extremely aggressive rate limiting.
    - Blocks certain vulnerable HTTP methods.
 * Is it worth implementing the traditional `auto_prepend_file`?
 * It is not strictly necessary, since Vigilant’s current approach is geared toward
   optimal performance and stability without risking a website crash due to absolute
   path issues (the arch-enemy of classic prepend mode). By intercepting malicious
   traffic using a combination of optimized PHP code and web server rules (.htaccess),
   they achieve the same early protection.
 * In addition, Vigilant includes a unique self-protection system: it constantly
   monitors its own files against SHA-256 signatures from WordPress.org, a database
   fingerprint, and an included MANIFEST file, to ensure that no attacker can modify
   or disable the plugin from within. No other plugin currently offers anything 
   similar.
 * Of course, it’s my baby, and I’m not going to say anything bad about the plugin,
   but I don’t stand to gain anything from it, as you probably know, it’s 100% free.
   But yes, I would encourage you to switch to Vigilant, it will give you the same
   defensive robustness but with a much more modern, lighter system that will never
   break your website due to file path issues.
 * In summary:
    - Same protection without the risk of downtime: Vigilant doesn’t use the traditional(
      PHP) `auto_prepend_file` because it prefers to block attacks one step earlier:
      directly on the web server (.htaccess).
    - It achieves the same immediate shielding effect but without the risk of the
      website encountering a 500 Error if you switch hosting providers or change
      your site paths.
    - Zero consumption of actual resources: By blocking malicious traffic at the
      server level, attacks don’t even wake up WordPress or the database, achieving
      the same RAM and CPU savings as Ninja or Wordfence’s prepend mode.
    - The “Under Attack” mode bonus: If the website suffers a massive attack, Vigilante
      has a built-in emergency button that raises an instant JavaScript verification
      wall, something that other plugins typically delegate to external services
      like Cloudflare (of course, this doesn’t mean you have to do without Cloudflare
      or a similar CDN that offers this type of security tool, as it’s always better
      to stop attacks in as many layers as possible, starting from the outermost
      ones).
 * End of self-promotion 😀
 * If you’re not familiar with it or aren’t sure about the change yet, don’t implement
   it without testing it first. Try it out on a secondary website and check how 
   it works, what it detects, how it does it, its resource usage, etc. Choosing 
   a security plugin isn’t a trivial matter, it’s one of the most important decisions
   for any website. Don’t base your choice solely on performance, security should
   be your top priority.
 * Thanks for giving it a try, and if you have any questions, we/I are here to help
   with whatever you need.
 * Fernando
 *  Thread Starter [dimal](https://wordpress.org/support/users/dimalifragis/)
 * (@dimalifragis)
 * [1 week, 3 days ago](https://wordpress.org/support/topic/prepend-mode/#post-19028750)
 * Thank you for the reply !
 * Crystal Clear.
 * Along with Wordfence i use also IP Location Block. And i have Enabled in that
   plugin “Validation timing / Runs earlier as a mu-plugin. Blocks before other 
   plugins load, but is more invasive.”.
 * Questions: can i use IP Location Block at all ? Mus i disable some options (i
   guess so). Shall i keep only the ASN/Countries block ?
 *  Plugin Author [Fernando Tellado](https://wordpress.org/support/users/fernandot/)
 * (@fernandot)
 * [1 week, 3 days ago](https://wordpress.org/support/topic/prepend-mode/#post-19028757)
 * I’m not familiar with that plugin, but it’s always best to block IPs by country
   before they reach the application, i.e., WordPress, and that way it doesn’t use
   up resources where they’re already scarce. If I had a choice, I’d block IPs or
   even entire countries in Cloudflare, or else on your hosting provider if it offers
   that feature; doing it in the WordPress plugin is too late.
 * Regarding the “Validation timing / Runs before” mu-plugin, which loads before
   other plugins but is more “wireless”, it looks like a workaround designed to 
   run before other processes, but it avoids having to write to the server files,
   which is exactly what we were talking about earlier.
 * As for your question about whether you should disable certain options, the answer
   is definitely yes. Contrary to popular belief, it is actually possible to use
   multiple security plugins at the same time, but you should always make sure not
   to duplicate functionality.
 * In any case, my advice is that, regardless of which plugin you choose, don’t 
   initially install several and try to make them work together. First, choose the
   one you’re (almost) certain will be your main security plugin, and only after
   you’re clear on its features should you supplement your needs with other plugins
   or services (preferably an external service) and always avoid duplicating functionality.
 * Hugs!
 * Fernando
 *  Thread Starter [dimal](https://wordpress.org/support/users/dimalifragis/)
 * (@dimalifragis)
 * [1 week, 3 days ago](https://wordpress.org/support/topic/prepend-mode/#post-19028784)
 * thank you !

Viewing 4 replies - 1 through 4 (of 4 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fprepend-mode%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/vigilante/assets/icon-256x256.png?rev=3482619)
 * [Vigilant - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…](https://wordpress.org/plugins/vigilante/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/vigilante/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/vigilante/)
 * [Active Topics](https://wordpress.org/support/plugin/vigilante/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/vigilante/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/vigilante/reviews/)

 * 4 replies
 * 2 participants
 * Last reply from: [dimal](https://wordpress.org/support/users/dimalifragis/)
 * Last activity: [1 week, 3 days ago](https://wordpress.org/support/topic/prepend-mode/#post-19028784)
 * Status: resolved