| Web application firewallInspect and block hostile requests | Full General firewall rules plus threat intelligence and product-specific protections. | Full Behavior-based WAF rules combined with a site-specific adaptive allow model. |
| Malware scanningFind and investigate suspicious files | Full Signature, integrity, and reputation checks with repair workflows for supported files. | Full Action-focused scanning with AI-assisted analysis to explain suspicious PHP. |
| Login and account securityProtect authentication and privileged access | Full Two-factor authentication, login controls, auditing, and brute-force protection. | Full Login controls plus PRO runtime checks for unauthorized administrator access and privilege changes. |
| Bot and browser controlsRestrict automated clients and fake identities | Partial Rate limiting, blocking, and crawler-related controls; not the same verified-client allow model. | Full Network verification for known bots, browser checks, and restricted access for unknown automation. |
| Centralized managementApply or review configuration across sites | Full Wordfence Central provides remote monitoring and management for multiple installations. | Partial Configurations can be reused by copying config.json files, but BitFire does not provide an equivalent central web console. |
| Specific vulnerability patchingRules written for disclosed product flaws | Full A core part of the threat-intelligence model; rule availability and timing can vary by plan. | Partial Selected rules and policies address known issues, but BitFire primarily blocks exploit classes and dangerous outcomes rather than patching every CVE individually. |
| File runtime enforcementStop unauthorized PHP writes during execution | Not included Scanning and file-change detection do not enforce authorization on each PHP write. | Full · PRO RASP checks PHP file writes and blocks unauthorized backdoor or malware creation. |
| Database runtime enforcementStop unauthorized privileged changes | Not included The firewall can stop exploit requests, but it does not authorize database operations as they execute. | Full · PRO RASP monitors sensitive account and privilege changes and can deny unauthorized updates. |
| Network runtime enforcementRestrict dangerous outbound activity | Not included The firewall inspects inbound web requests rather than application network calls during execution. | Full · PRO Runtime policies inspect outbound activity and can stop calls to known malicious infrastructure. |
| Browser security policyHarden how browsers interact with the site | Not included Wordfence focuses on firewall, malware, and login controls rather than site-wide browser header policy. | Full Configurable security headers, permissions policy, cross-origin controls, and HTTPS enforcement. |
| Unknown-exploit resilienceProtection before a CVE-specific rule exists | Partial Generic WAF rules, rate limits, and hardening can stop unknown attacks that match known behaviors. | Full · layered Adaptive request controls and PRO runtime enforcement protect both entry and outcome. |