Linux 软件免费装
Banner图

BitFire Security - Firewall, WAF, Bot/Spam Blocker, Login Security

开发者 BitSlip6
LLC
更新时间 2025年9月22日 07:43
捐献地址: 去捐款
PHP版本: 7.4 及以上
WordPress版本: 6.8.2
版权: AGPLv3 or later
版权网址: 版权信息

标签

security activity log firewall malware scanner waf

下载

4.4.18 4.4.12 4.0.10 4.0.6 4.1.15 2.0.1 3.9.8 4.1.2 4.4.17 4.7.2 4.0.5 3.0.9 3.7.6 4.1.9 4.7.3 4.0.4 4.1.4 4.4.19 4.1.12 2.3.3 4.8.1 4.8.2 3.7.4 3.9.6 3.7.2 3.6.2 3.9.13 4.1.13 4.1.14 4.1.6 4.4.11 4.1.0 4.4.15 4.4.14 4.1.5 4.4.13 4.5.0 3.9.1 2.0.9 4.0.1 4.1.8 4.6.1 4.7.0

详情介绍:

Real-Time Security for WordPress BitFire protects your website from bots, hackers, malware, and critical vulnerabilities - before they can cause damage. This plugin brings advanced security technology used by large enterprises to your WordPress site, now available in a free version. Whether you manage a business website, blog, or WooCommerce store, BitFire gives you powerful protection and visibility into your traffic. Smarter Protection with AI Most security plugins wait for updates to detect new threats. BitFire takes a different approach: it uses artificial intelligence and real-time request analysis to stop zero-day attacks, bots, and malicious users before they get access to your site. Our AI learns what normal traffic looks like for your site and blocks anything suspicious - without you needing to configure endless rules.
“Unlike traditional firewalls that allow everything by default and react to known threats, BitFire only allows verified traffic - stopping new and unknown attacks instantly.”

安装:

After installing, you can configure the plugin by clicking the "BitFire" -> "Settings" menu item in the WordPress admin dashboard. Note, not compatible with Windows Operating systems. Hosting Requirements Visit our website to access our official documentation, which includes in-depth descriptions of security features, common solutions, and comprehensive help.

屏幕截图:

  • Bot Control page allows instant authentication of over 3,000 known bots and 300,000 malicious IPs.
  • Detailed malware scanner contains over 20 million data-points and scans 10,000 PHP files per minute.
  • Search for any web traffic by time, user-agent, url, IP or response. Identify correct web blocking and website functionality.
  • Database malware scanner with backup and restore points can identify malware comments and posts from over 2.5 million domains.
  • Plugin monitoring alerts you within the hour when new plugin vulnerabilities effecting your site are released so you can stay on top of important security updates.
  • Simple on/off configuration with granular rules can be set to alert to test new rules before actually blocking.

升级注意事项:

4.4.9 Tested on over a dozen sites from new installs to upgrades. All issues resolved in testing prior to release. Release 4.4.9 is the end of our Free firewall. All releases after 4.4.9 will allow site administrators to view OFFLINE what the pro firewall would block REALTIME. All existing Free clients will receive an 80% discount for early adoption. If you did not receive a discount email, contact BitFire directly on our website https://bitfire.co to receive discount codes. 3.0.8 No incompatibilities

常见问题:

What is the difference between FREE and PRO versions?

= Will this slow down my site? =\ No — BitFire is built for speed. It adds less than 2ms of overhead per request and uses optimized binary logging. = Do I need to configure anything? =\ BitFire works out of the box with default settings. Advanced users can fine-tune rules and view deep request logs. = Can I use this with a CDN or other firewall? =\ Yes — BitFire recommends running alongside CDNs like Cloudflare. It is not recommended to run multiple firewall products at the same time, but they should be compatible. Do not use always-on-mode if running with another firewall as this can create conflicts. = Is there a free version? =\ Yes! The plugin on WordPress.org includes bot protection features and traffic analysis. = How do I upgrade to Pro? =\ Visit bitfire.io/pricing to compare features and purchase a license. Pro unlocks RASP, WAF, and advanced traffic logging. BitFire free includes our real-time event log, A+ rated security headers, malware scanner, and complete bot blocking which blocks 99% of all Internet threats. PRO includes our Runtime Application Self Protection (RASP) firewall to prevent vulnerable plugins and themes from executing on your site along with our A+ rated WAF.

Can BitFire RASP protect my website against zero-day vulnerabilities?

BitFire has a 100% track record for protecting against every critical 0-day WordPress security vulnerability since 2022 with 0 new signatures required.

Why do other plugins focus so much for Malware Scanning and Cleaning?

Great question. Notice how much extra other plugins charge you to clean up malware and how much of their product is focused on finding malware on your system? They don't do a great job of keeping malware off your site, and then charge you extra when their security fails.

How much is PRO Version?

complete WAF & RASP protection is $99.00 / year.

If other security plugins live up to their hype, why do they scan my site for malware daily?

That's an excellent question. The majority of popular security plugins create custom signatures for each WordPress plugin vulnerability as they are publicly disclosed. With over 10,000 known WordPress security vulnerabilities and less than 200 signatures, they miss blocking a lot of hacks. They are also unable to block the most common security flaws (access control errors) for anything they do not have a pre-built signature for. To make the situation more difficult, they delay these rules by up to a month for non-paying customers.

How does Redirection Protection work?

Our unique software keeps track of every 3rd party domain your web page uses (Facebook, Google, JavaScript APIS, themes, etc.). After several weeks of learning, CSP security headers are sent to visitors instructing their browsers to only use or redirect to your approved domain list.

Does BitFire prevent Cross-Site Scripting (XSS)?

BitFire includes outstanding XSS protection, including HTTP headers and content filtering for persistent, reflected, and DOM-based XSS attacks.

Does BitFire block SQL Injection attacks (SQLi)?

Yes. BitFire has advanced SQL parsing similar to MySQL syntax parsing and can understand SQL queries regardless of encoding, injected comments, and other evasion techniques.

What are some examples of RASP blocks?

  • Adding a new administrator account? BitFire checks that the current user has the administrator privilege before allowing the account creation.
  • Making a network connection? BitFire checks the remote system against a list of over 2.5 million malware domains before allowing the connection.
  • Adding or editing a file? BitFire inspects the filename and content to ensure that it does not edit a PHP file or inject backdoor code.
  • Redirecting the visitor to another website? First check the malware domain list before sending the redirect.
  • Is a plugin eval() dynamic PHP Code? Inspect the code being passed to eval() and block malicious code before executing it.

Why shouldn't I use WordFence?

If you use WordFence, you should only use the paid version. WordFence has a team monitoring emerging WordPress vulnerabilities and writing custom rules to block specific exploits. They are very good at it and run a great blog on their work. Paying customers receive these virtual patches as soon as they are available. Free customers receive the patches 30 days later. If your website is vulnerable, it is almost guaranteed to be hacked before the patch is available to free customers. Don't leave your site at risk.

Is BitFire RASP easy to install?

Yes, BitFire RASP offers a seamless integration process tailored for WordPress. The setup is user-friendly, and our support team is always ready to assist.

How is BitFire RASP different from other security plugins?

BitFire RASP is the only RASP firewall available for WordPress. It's crafted to provide real-time protection by deeply inspecting your site's activity, ensuring comprehensive security without compromising performance.

Can BitFire block bots and automated attacks?

BitFire's primary feature is bot blocking which is 100% functional in the free version. 99% of WordPress attacks are from automated tools scanning every domain and IP address for known vulnerabilities. BitFire verifies human web browsers with a JavaScript challenge similar to Cloudflare but over 50 times faster (1/10 second VS 6 seconds). BitFire also includes a list of over 80 search engines and SEO tools that are network verified to ensure only valid bot traffic reaches your site.

How do I get support if I encounter issues with BitFire RASP?

You can use the WordPress support form or visit our website to access our official documentation, which includes in-depth descriptions of security features, common solutions, and comprehensive help. Our dedicated support team is also available to assist you. You can reach out through our support channels, and we'll promptly address any questions or concerns you have.

Why is BitFire better than WordFence?

Read the detailed comparison with WordFence

更新日志:

4.8.2 4.8.0 4.7.4 4.7.3 4.7.2 4.7.0 4.6.1 4.6 4.5 4.4.19 4.4.18 4.4.17 4.4.16 4.4.14 4.4.12 4.4.11 4.4.10 4.4.9 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.9 4.1.8 4.1.7 4.1.5 4.1.4 4.1.3 4.1.2 4.1.0 4.0.10 4.0.9 4.0.8 4.0.7 4.0.6 4.0.1 3.9.12 3.9.10 3.9.9 3.9.6 3.9.5 3.9.4 3.9.3 3.9.2 3.7.1 3.6.4 3.6.3 3.6.2 3.6.1 3.5.3 3.0.8 3.0.6 3.0.4 3.0.1 2.3.5 2.3.4 2.3.3 2.1.2 2.1.0 2.0.1 1.9.7 1.9.6 1.9.5 1.9.4 1.9.3 1.9.2 1.9.1 1.9.0 1.8.9 1.8.6 1.8.5 1.8.3 1.8.0 1.7.3