A firewall blocks the attack.BitFire blocks the damage.

BitFire Pro stops exploited plugins from changing your files, database, or administrator accounts - even when the vulnerability is brand new.

Typical setup: 5 minutes · No credit card required · View Pro runtime controls

Protection at every layer

Application Filesystem Database

See what is protected before you enforce it.

BitFire Pro checks protected file, database, and administrator operations inside WordPress, helping stop plugin and theme vulnerabilities before they become site damage.

Explore BitFire Pro runtime controls →
BitFire · Protection coverage
Example BitFire settings screen with configuration coverage scores and protection controls
  1. Coverage scores summarize assessed configuration controls.
  2. Protection switches show which controls are enabled.
Expand screenshot

Filter requests. Enforce outcomes.

Start with the edge. Add runtime controls where compromise actually happens.

Rules tailored to your site

Inspect malicious input, review traffic exceptions, and apply bot policies using available network evidence, not a user-agent alone.

Trust the network, not the name →

Protect operations with Pro

Check authorization for protected PHP writes, database operations, and administrator changes. Coverage depends on enabled controls.

Review runtime controls →

Find suspicious code

Behavioral scanning flags potentially malicious code. AI-assisted analysis helps you review what to allow, repair, or remove. A flag is not proof of infection, and AI analysis can be mistaken. Review evidence and back up files before changes.

Understand why it was flagged →
BitFire · Request activity

Swipe or scroll across the image; expand for full-size details.

Cropped BitFire request log showing search filters, blocked requests, client locations, and rule decisions
Understand your site’s trafficSearch blocked and allowed requests to see what reached your site, what BitFire stopped, and why.
  1. Filter requests to narrow the activity you review.
  2. Read the decision alongside the request and rule.
  3. Check the source alongside client and network information.
Expand screenshot

Real vulnerabilities, protected.

BitFire helps stop real WordPress attack paths before they become file changes, database damage, or administrator takeover.

Recent security vulnerabilities: 0-day protected
Protected by BitFire
Component CVE and install base CNA CVSS 3.1 Assessed BitFire controls
WordPress Double-Decode Template Include Security advisory technical analysis 7.1 · High Bot policy + WAF

WordPress Click2Shell Security advisory technical analysis 9.3 · Critical WAF mitigation + Pro runtime controls in evaluation

Assesses the disclosed theme-preview install chain, the firewall rule deployed against off-site admin-ajax POSTs, and runtime controls still in evaluation. Results depend on client rule deployment and pending PRO RASP hardening.

Ninja Forms CVE-2026-94504 technical analysis 7.2 · High Bot policy + WAF + Pro administrator controls

Assesses automated form-submission blocking, stored JavaScript-payload inspection, and unauthorized administrator outcomes. Results depend on client policy, payload shape, and enabled runtime controls.

Showing 3 of 21 protection records. Index rebuilt September 22, 2026. Official CVE records provide vulnerability details for each BitFire protection assessment. No reproduced exploit test is claimed here. View all protection records
Trond André
Trond André BitFire customer
“there is only one thing to say: It works! And this is the only firewall [to] realy do the job. In the pro version you [will] get all you need.”
Excerpt from the customer’s review.
Mark Sullivan
Mark Sullivan BitFire customer
“The team at BitFire walked us through the entire install process, removed all the malware, and fully protected all our sites. I’ll never run a site without it again.”

Start free. Upgrade when runtime enforcement matters.

Free covers the baseline. Pro is recommended for commercial sites that need protected file, database, and administrator operations checked inside WordPress.

Free

Essential firewall, bot, and malware scan tools for sites that need a simple protection baseline.

  • Firewall and bot blocking / verification
  • Manual malware scanning
  • 12 AI credits for the lifetime of the domain
  • Self-managed setup with a fast path to protection
Protect my site free

Pro

Recommended for commercial and business-critical sites that need runtime enforcement, scheduled scanning, and deeper security visibility.

  • Firewall and bot protection, plus Always-On Protection
  • Runtime file, database, and administrator protection
  • Scheduled malware scans and Threat Hunter
  • 1,000 AI malware analysis credits; self-managed by default
View Pro

Questions before installing.

BitFire filters requests, Pro adds runtime checks, and no layer replaces patching, access control, backups, or recovery planning.

How do BitFire’s firewall and runtime controls work together?
The firewall evaluates incoming requests. BitFire Pro also checks authorization when WordPress attempts protected file, database, or administrator operations. These are complementary controls; capabilities vary across security products and configurations.
Does BitFire only work with WordPress?
The current product is for WordPress and its PHP runtime. For a standalone PHP application, contact the team to confirm availability and compatibility before planning a deployment.
Can BitFire help with an already hacked website?
The scanner can help you investigate suspicious files. For cleanup or incident-response assistance, contact a security engineer to confirm the work and service scope. Installing a firewall does not by itself remove an existing compromise.
How does BitFire handle legitimate bots?
BitFire can allow a bot from anywhere, authenticate it by source network, or block it completely. Network validation makes it harder for an attacker to bypass controls using a spoofed user-agent string.
How should we measure protection overhead?

Overhead depends on hosting, PHP and plugin activity, enabled controls, traffic, and cache state.

Recommended measurement procedure, not a published test result: use an isolated staging copy, record versions and enabled controls, run the same representative requests, and compare baseline, firewall/bot controls, and Pro runtime controls separately.

Start protecting your site.

Install the free baseline now, or send your site context for a focused technical walkthrough.

Protect my site free

Running a commercial site? You can start free, but we recommend Pro for runtime controls.

Request a technical walkthrough

Tell us what you need to protect.

Up to 5,000 characters. Do not include passwords or credentials.

We use your details to respond and keep relevant support records, including request time, IP address, and browser information. Privacy policy. You can also contact the team directly.

Product screenshot

Full-resolution image. Scroll to inspect details; press Escape or Close screenshot to return.

Open original image in a new tab ↗
Protect my site free →