WordPress 和 PHP 安全

A firewall blocks the attack.BitFire blocks the damage.

BitFire Pro stops exploited plugins from changing your files, database, or administrator accounts - even when the vulnerability is brand new.

  • 典型设置:5 分钟
  • 无需信用卡

查看 Pro 商务版

Talk to a security engineer

Protection at every layer

Application Filesystem Database
Write Lock
Prevent any vulnerability from infecting your site with malware
4,000+
Configurable bots with pre-configured access controls
A+
Rated WAF & RASP · rated by Cloudbric
< 5 min
Setup time · Click configure or copy config files
您可以验证的保护

准确查看受保护的内容。

Runtime Application Self-Protection (RASP) checks what your application tries to do, not just the request that reached it. BitFire Pro adds authorization checks to protected file and database operations, complementing the firewall’s request filtering.

The 100% scores in this product example describe the controls assessed for that configuration, not protection against every vulnerability, and not independent certification.

探索 BitFire Pro 运行时控件 →
BitFire · 防护范围
示例 BitFire 设置屏幕,包含配置覆盖率分数和保护控制
保护设置示例覆盖率分数描述了评估的控制措施,但不能保证抵御每次攻击。
  1. 覆盖率分数 总结评估的配置控制。
  2. Pro保护开关 显示哪些控件已启用。
展开截图
观看 BitFire 的实际操作

两分钟的产品导览。

查看实际的请求过滤和 Pro 运行时保护。

一层保护层是不够的

筛选。执行。调查。

三份工作,有证据来回顾所发生的事情。

为您的网站量身定制的规则

Inspect malicious input, review traffic exceptions, and apply bot policies using available network evidence, not a user-agent alone.

相信网络,而不是名字 →

Protect 与 Pro 的操作

检查受保护的 PHP 写入、数据库操作和管理员更改的授权。覆盖范围取决于启用的控件。

查看运行时控制 →

查找可疑代码

行为扫描标记潜在的恶意代码。 AI 辅助分析可帮助您查看允许、修复或删除的内容。标记并不能证明感染,人工智能分析可能会出错。在更改之前查看证据并备份文件。

了解为什么它被标记 →
BitFire · 请求活动

滑动或滚动图像;展开以查看全尺寸详细信息。

裁剪后的 BitFire 请求日志显示搜索过滤器、阻止的请求、客户端位置和规则决策
了解您网站的流量搜索已阻止和允许请求,以查看哪些内容到达了您的网站、BitFire 停止了哪些内容以及原因。
  1. 过滤请求 缩小您审查的活动范围。
  2. 阅读决定 与请求和规则一起。
  3. 检查来源 以及客户和网络信息。
展开截图
Vulnerability protection

Built for real WordPress attack paths.

BitFire is designed to protect the places attackers target most: malicious requests, unauthorized file changes, suspicious database activity, and abusive bot traffic. Our vulnerability writeups show how those protection layers apply to real WordPress security issues.

Selected protection examples Real WordPress vulnerabilities from the 2024–2026 article collection
Mapped to BitFire controls

Each example connects a known vulnerability pattern to BitFire controls that can help block exploitation, limit damage, and surface evidence for review. Use BitFire as an active protection layer while keeping WordPress, themes, and plugins updated.

组件 官方CVE记录 CNA CVSS 3.1 评估 BitFire 控制
Forminator Forms CVE-2026-15748 正式记录 9.8 · 严重 机器人策略+Pro文件保护

评估自动提交阻止和未经授权的 PHP 文件创建。结果取决于客户端策略、上传目的地和启用的控件。

Meta Box AIO: MB Frontend Submission CVE-2026-14488 正式记录 9.1 · 严重 Pro 数据库授权控制

评估对帖子和页面删除的授权检查。这是本文基于机制的评估,而不是重现的利用结果。

WordPress Core: WP2Shell Security Vulnerability CVE-2026-63030 正式记录 9.8 · 严重 机器人策略 + WAF + Pro 管理员控制

评估客户端验证、SQL 注入检查和未经授权的管理员创建。有效性取决于策略、有效负载和受保护的操作。

Showing 3 of 12 protection records. Index rebuilt 九月 4, 2026. Official CVE records provide vulnerability details used to map relevant BitFire request, bot, file, and database protections. 查看所有保护记录
Customer confidence

Trusted by site owners who need real protection.

BitFire helps teams secure WordPress sites, recover from threats, and keep protection in place as attacks evolve.

特隆德·安德烈
特隆德·安德烈 BitFire customer
“有用!”
Mark Sullivan
Mark Sullivan BitFire customer
“The team at BitFire walked us through the entire install process, removed all the malware, and fully protected all our sites. I’ll never run a site without it again.”
Fast path to protection

从安装到执行。

BitFire 与 WordPress 及其 PHP 运行时集成,构建合法流量的基线,并应用您配置的保护控制。

01

Connect your website

典型的设置需要五分钟,然后是流量学习期。非商业网站免费;商业站点需要Pro。

02

Build a site-specific baseline

Adaptive rules learn what your real visitors, applications, browsers, and approved bots need.

03

审查,然后执行

在执行前审查例外情况。 Pro 在防火墙的请求过滤中添加运行时授权检查。

按照安装指南进行操作 →
选择您的保护

Start with basic protection. Upgrade for stronger security.

BitFire Free helps add essential protection to a site. BitFire Pro adds deeper safeguards for sites where security, uptime, and active enforcement matter most.

Basic protection

自由的

Essential firewall, bot, and malware scan tools for sites that need a simple protection baseline.

  • 防火墙和机器人阻止/验证
  • 手动恶意软件扫描
  • 域名生命周期内 12 个 AI 积分
  • Self-managed setup with a fast path to protection
Protect my site free
Advanced site security

Pro

Deeper protection for sites that want stronger assurance, runtime enforcement, scheduled scanning, and more security visibility.

  • 防火墙和机器人防护,以及 Always-On Protection
  • 运行时文件、数据库和管理员保护
  • 计划的恶意软件扫描和 Threat Hunter
  • 1,000 个 AI 恶意软件分析积分;默认自行管理
查看Pro
付费 Pro 附加组件

托管

让 BitFire 负责安装和持续维护。

  • 安装、配置和操作调整
  • 持续监控和合法流量审查
  • Managed Protection:正常U.S.营业时间
  • Priority Support:24/7 覆盖和一小时响应时间
比较支持选项

Want help choosing the right protection level or support option? Talk with a security engineer about your site, risks, and operating needs.

探索细节: 保护功能 · 恶意软件扫描 · 许可和支持.

对于网站所有者、机构和安全团队: 探索产品组合和企业用例 →

比较请求过滤和运行时强制

This compares control boundaries, not named products, their current features, or test results.

补充控制边界,而不是产品排名
控制边界请求过滤Runtime enforcement
主要问题该请求是否应该到达应用程序?这个受保护的操作是否被授权?
信号请求内容、客户端身份和流量策略应用程序身份、权限和尝试的操作
执行点在请求到达易受攻击的处理程序之前当应用程序代码尝试受保护的操作时
BitFire 中的示例机器人策略和 SQL-注入请求检查Pro 检查受保护的 PHP 写入和管理员更改
限制覆盖范围取决于检查、规则和例外情况覆盖范围取决于支持的操作、配置和授权上下文

这两层都不能取代修补、访问控制或恢复计划。 查看 BitFire 记录的控制和配置要求 →

Questions, answered

What teams ask before installing.

Need to evaluate BitFire for a specific stack? Talk directly with a security engineer.

Talk to a security engineer
BitFire的防火墙和运行时控制如何协同工作?
防火墙评估传入的请求。当 WordPress 尝试受保护的文件、数据库或管理员操作时,BitFire Pro 还会检查授权。这些是补充控制;功能因安全产品和配置而异。
Does BitFire only work with WordPress?
当前产品适用于 WordPress 及其 PHP 运行时。对于独立的 PHP 应用程序,请在规划部署之前联系团队以确认可用性和兼容性。
Can BitFire help with an already hacked website?
扫描仪可以帮助您调查可疑文件。如需清理或事件响应协助,请联系安全工程师以确认工作和服务范围。安装防火墙本身并不能消除现有的危害。
我们应该如何衡量保护开销?

开销取决于托管、PHP 和插件活动、启用的控件、流量和缓存状态。我们不会在这里发布固定的延迟数字,因为此页面没有可重复的基准报告。

Recommended measurement procedure, not a published test result:

  1. 使用独立的暂存副本。记录 CPU、内存、PHP、WordPress 和 BitFire 版本、插件、缓存设置、启用的控件和流量学习状态。
  2. 以固定请求率使用相同的代表性页面、登录、表单和 API 请求。记录缓存状态、预热、持续时间、重复次数和样本计数。
  3. 分别比较基线、防火墙/机器人控制和 Pro 运行时控制。记录每次运行的服务器处理时间、中值和 95% 响应时间、错误和 CPU 使用情况。
  4. 报告配置和原始结果的差异。不要在实时站点上禁用保护以进行基准测试。
设置后检查保护和兼容性 →
How does BitFire handle legitimate bots?
BitFire can allow a bot from anywhere, authenticate it by source network, or block it completely. Network validation makes it harder for an attacker to bypass controls using a spoofed user-agent string.
Can we keep our current edge firewall or CDN?
BitFire’s runtime protection is designed to add application-level enforcement behind the edge. For enterprise environments, confirm the exact deployment pattern and compatibility requirements with the BitFire team.
Choose your next step

开始保护您的网站。

Start protecting a site in minutes, or bring us your architecture and security requirements for a technical walkthrough.

Ready to install? 对于非商业网站免费。无需信用卡。
Evaluating for a team? Request a focused technical demo.
Protect my site free

Pro正在保护商业网站吗? 查看Pro.

Talk to a security engineer

Tell us where you need stronger application protection.

最多 5,000 个字符。请勿包含密码或凭据。

我们使用您的详细信息来响应并保留相关支持记录,包括请求时间、IP 地址和浏览器信息。 Privacy policy。您还可以 直接联系团队.

Pro管道截图

全分辨率图像。滚动查看详细信息;按 Esc 键或关闭屏幕截图返回。

在新选项卡中打开原始图像 ↗
免费保护我的网站 →