Forum Replies Created

Viewing 2 replies - 1 through 2 (of 2 total)
  • Thread Starter btljournaldarren

    (@btljournaldarren)

    Hi Margaret,

    Namecheap has completed a controlled test and confirmed that its server-side browser challenge is causing the Wordfence self-callback failure.

    During a temporary 30-minute domain exception:

    • Wordfence Diagnostics showed green OK for “Connecting back to this site” at 209.74.74.4.
    • A complete Wordfence scan started and all standard stages finished successfully.

    After Namecheap removed the exception and restored normal firewall protection:

    • The connection to Wordfence’s servers remained OK.
    • The self-callback immediately failed again with the same 200 OK browser-challenge response.

    Namecheap cannot create an exception limited to server-originated self-callback traffic. It can only exempt the entire domain or possibly a specific path. Wordfence’s documentation identifies /wp-admin/admin-ajax.php as the relevant WordPress AJAX handler, but that is a shared endpoint used by WordPress and other plugins, so I do not want to exempt the whole path without narrowing it further.

    Could you please confirm:

    1. The precise callback URL or path used by the current Wordfence scanner.
    2. The specific AJAX action value or values used for the initial scan and subsequent scan forks.
    3. Whether those action values are stable and could be used by the host to restrict an exception more narrowly than the whole admin-ajax.php path.
    4. Whether enabling “Start all scans remotely” is the recommended alternative in this situation.
    5. If remote scanning is appropriate, whether the browser challenge would need to allow specific Wordfence scanning-server IP addresses and which current addresses should be used.

    No permanent firewall exception or Wordfence setting has been changed.

    Thanks,
    Darren

    Thread Starter btljournaldarren

    (@btljournaldarren)

    Hi Margaret,

    Thank you. I have now sent the diagnostic report to wftest@wordfence.com using the Send Report by Email option in Wordfence > Tools > Diagnostics.

    My forum username, btljournaldarren, was included with the report.

    No hosting protection, whitelist, WordPress files or Wordfence settings have been changed.

    Kind regards,
    Darren

Viewing 2 replies - 1 through 2 (of 2 total)