Rules tailored to your site
Inspect malicious input, review traffic exceptions, and apply bot policies using available network evidence—not a user-agent alone.
Trust the network, not the name →Block malicious requests. With BitFire Pro, stop unauthorized file and database changes inside your application—even when an exploit is new.
Free for non-commercial sites. View Pro for business
Talk to a security engineerRuntime Application Self-Protection (RASP) checks what your application tries to do—not just the request that reached it. BitFire Pro adds authorization checks to protected file and database operations, complementing the firewall’s request filtering.
The 100% scores in this product example describe the controls assessed for that configuration—not protection against every vulnerability or independent certification.
Explore BitFire Pro runtime controls →“It works!”
See request filtering and Pro runtime protection in action.
Three jobs, with the evidence to review what happened.
Inspect malicious input, review traffic exceptions, and apply bot policies using available network evidence—not a user-agent alone.
Trust the network, not the name →Check authorization for protected PHP writes, database operations, and administrator changes. Coverage depends on enabled controls.
Review runtime controls →Behavioral scanning flags potentially malicious code. AI-assisted analysis helps you review what to allow, repair, or remove. A flag is not proof of infection, and AI analysis can be mistaken. Review evidence and back up files before changes.
Understand why it was flagged →Swipe or scroll across the image; expand for full-size details.
These BitFire-authored analyses map specific WordPress vulnerabilities to relevant request and runtime controls. They describe possible interruption points—not a guarantee that every exploit variant is blocked.
No reproduced exploit test is claimed here. Effectiveness depends on version, configuration, and the operation attempted; keep vulnerable software patched.
| Component | Official CVE record | CNA CVSS 3.1 | Assessed BitFire controls |
|---|---|---|---|
| Forminator Forms | CVE-2026-15748 official recordCVE published 2026-08-18 Metadata checked 2026-09-07 |
9.8 · Critical | Bot policy + Pro file protection Assesses automated submission blocking and unauthorized PHP file creation. Results depend on client policy, upload destination, and enabled controls. |
| Meta Box AIO: MB Frontend Submission | CVE-2026-14488 official recordCVE published 2026-07-29 Metadata checked 2026-09-07 |
9.1 · Critical | Pro database authorization controls Assesses authorization checks on post and page deletion. This is the article's mechanism-based assessment, not a reproduced exploit result. |
| WordPress Core: WP2Shell Security Vulnerability | CVE-2026-63030 official recordCVE published 2026-07-17 Metadata checked 2026-09-07 |
9.8 · Critical | Bot policy + WAF + Pro administrator controls Assesses client verification, SQL-injection inspection, and unauthorized administrator creation. Effectiveness depends on policy, payload, and protected operation. |
Bot policy + Pro file protection
Assesses automated submission blocking and unauthorized PHP file creation. Results depend on client policy, upload destination, and enabled controls.
Read analysis : Forminator FormsPro database authorization controls
Assesses authorization checks on post and page deletion. This is the article's mechanism-based assessment, not a reproduced exploit result.
Read analysis : Meta Box AIO: MB Frontend SubmissionBot policy + WAF + Pro administrator controls
Assesses client verification, SQL-injection inspection, and unauthorized administrator creation. Effectiveness depends on policy, payload, and protected operation.
Read analysis : WordPress Core: WP2Shell Security Vulnerability“The team at BitFire walked us through the entire install process, removed all the malware, and fully protected all our sites. I’ll never run a site without it again.”
BitFire integrates with WordPress and its PHP runtime, builds a baseline of legitimate traffic, and applies your configured protection controls.
Typical setup takes five minutes, followed by a traffic-learning period. Free for non-commercial sites; business sites require Pro.
Adaptive rules learn what your real visitors, applications, browsers, and approved bots need.
Review exceptions before enforcement. Pro adds runtime authorization checks to the firewall’s request filtering.
Choose a license, then decide who manages protection. Managed service is an add-on to Pro—not a separate firewall.
For personal blogs, charities, and other non-commercial sites.
Required for business, agency, client, and ecommerce sites.
Let BitFire handle installation and ongoing care.
Need offsite backups or a dedicated Security Operations Center (SOC)? Confirm availability and scope with a security engineer; neither is listed as a standard inclusion in these plans.
Explore the details: protection features · malware scanning · licensing and support.
For site owners, agencies, and security teams: explore portfolio and enterprise use cases →
This compares control boundaries—not named products, their current features, or test results.
| Control boundary | Request filtering | Runtime enforcement |
|---|---|---|
| Main question | Should this request reach the application? | Is this protected operation authorized? |
| Signals | Request content, client identity, and traffic policy | Application identity, permissions, and the operation attempted |
| Enforcement point | Before the request reaches the vulnerable handler | When application code attempts a protected action |
| Examples in BitFire | Bot policies and SQL-injection request inspection | Pro checks on protected PHP writes and administrator changes |
| Limits | Coverage depends on inspection, rules, and exceptions | Coverage depends on supported operations, configuration, and authorization context |
Neither layer replaces patching, access control, or recovery planning. Review BitFire’s documented controls and configuration requirements →
Need to evaluate BitFire for a specific stack? Talk directly with a security engineer.
Talk to a security engineerOverhead depends on hosting, PHP and plugin activity, enabled controls, traffic, and cache state. We do not publish a fixed latency figure here because a reproducible benchmark report is not available for this page.
Recommended measurement procedure—not a published test result:
Start protecting a site in minutes, or bring us your architecture and security requirements for a technical walkthrough.
Protect my site freeProtecting a business site? View Pro.