Апісанне
THE MOST PROMISING WORDPRESS FIREWALL & SECURITY SCANNER
Tired of worrying about your WordPress site getting hacked?
VMP WordPress Security is like having a professional security team watching your website 24/7. We combine a powerful firewall, intelligent malware scanner, and advanced threat detection to keep your site safe from hackers, malware, and security vulnerabilities.
Why Choose VMP WordPress Security?
✅ Real Protection That Actually Works – Not just another security plugin with flashy dashboards. We stop real attacks in real-time.
✅ Easy to Use – Set it up in 5 minutes. No security degree required.
✅ Performance Optimized – Won’t slow down your site. Runs efficiently in the background.
✅ Always Up-to-Date – Our 280+ firewall rules and malware signatures are constantly updated.
✅ Complete Coverage – Firewall, malware scanner, 2FA, brute force protection, and more in one plugin.
🔥 Web Application Firewall (WAF)
Think of it as a security guard for your website.
Our firewall inspects every visitor before they reach your WordPress site. Bad guys? Blocked instantly. Legitimate visitors? They won’t even notice we’re there.
What It Protects Against:
- SQL Injection – Hackers trying to steal your database
- Cross-Site Scripting (XSS) – Malicious code injection
- Remote File Inclusion (RFI) – Attempts to upload backdoors
- Local File Inclusion (LFI) – Unauthorized file access
- Command Injection – Server takeover attempts
- Path Traversal – Directory browsing attacks
Key Features:
- 280+ Built-in Security Rules – Covering all major attack types
- Zero-Day Protection – Pattern-based detection catches new threats
- Attack Logging – See exactly who’s trying to hack you
- Custom Rules – Add your own protection patterns
- Learning Mode – Fine-tune rules based on your legitimate traffic
- IP Blocking – Automatic permanent bans for repeat offenders
🛡️ Brute Force Protection
Stop password guessing attacks before they succeed.
Hackers use bots to try thousands of password combinations. We stop them cold.
Features:
- Smart Login Limiting – Lock out IPs after failed attempts
- Invalid Username Blocking – Instant block for fake usernames
- Leaked Password Detection – Check credentials against breach databases
- Strong Password Enforcement – Force admins and users to use secure passwords
- Username Blacklist – Block known malicious usernames instantly
- Permanent Bans – Get rid of persistent attackers for good
⚡ Rate Limiting & Bot Protection
Prevent site scraping, resource exhaustion, and vulnerability scanning.
Not all attacks are malicious code. Some attackers just overwhelm your site with requests. We stop that too.
What We Control:
- Request Limits – Maximum requests per IP per time period
- Human vs Bot Detection – Smart classification of traffic
- 404 Error Monitoring – Detect scanning attempts
- Google Crawler Handling – Special treatment for legitimate search engines
- Throttling or Blocking – Slow down or stop violators
- Allowlist Support – Whitelist your own IPs and trusted services
🔐 Two-Factor Authentication (2FA)
Add an extra layer of security to your WordPress login.
Even if someone steals your password, they can’t get in without the second factor.
Features:
- QR Code Setup – Easy configuration with any authenticator app
- Backup Codes – Never get locked out of your own site
- User Management – Force 2FA for admins or specific roles
- Frontend 2FA Management – Users can manage their own 2FA settings
- Email Notifications – Get notified when 2FA is enabled/disabled
- Shortcode Support – Add 2FA controls anywhere on your site
- XML-RPC Protection – Require 2FA for XML-RPC requests
- WooCommerce Integration – Secure your online store checkout
🔍 Advanced Malware Scanner
Multiple specialized scanners working together to find threats.
We don’t just look for known malware. Our intelligent scanner detects suspicious patterns, unauthorized changes, and hidden backdoors.
Our Security Scanners:
- Malware Scanner – Detects backdoors, trojans, and malicious code from our 40,000+ malware scanner
- File Integrity Monitor – Compares files against official WordPress versions
- Vulnerability Scanner – Identifies security flaws in plugins and themes
- User Security Scanner – Finds suspicious admin accounts
- Content Safety Scanner – Analyzes posts/comments for malicious content
- Public Files Scanner – Detects exposed configuration files
- Server State Scanner – Monitors server security settings
- Binary Scanner – Checks images and executables for embedded malware
- Domain Reputation Scanner – Verifies URLs against threat databases
Scan Types:
- Quick Scan – Critical files only (2-5 minutes)
- Standard Scan – Balanced coverage (6-12 minutes)
- High Sensitivity Scan – Complete site analysis (10-25 minutes)
- Custom Scan – Choose exactly what to scan
🚨 Advanced Threat Detection
We catch what other plugins miss.
Intelligent Detection:
- Pattern Analysis – Detects obfuscated and encrypted malware
- Behavior Analysis – Identifies suspicious file operations
- Reputation Checking – Validates URLs against Google Safe Browsing
- Legitimacy Assessment – Distinguishes real threats from false positives
- Unknown File Detection – Flags files that shouldn’t be there
- Password Breach Checking – Scans for compromised credentials
📊 Live Traffic Monitor & Event Tracking
See exactly what’s happening on your site in real-time.
Features:
- Real-Time Traffic View – Watch visitors and attacks as they happen
- Event Logging – Complete audit trail of security events
- Attack Statistics – Visual dashboards showing threats over time
- IP Intelligence – WHOIS lookup and IP reputation checking
- Human vs Bot Tracking – Classify and analyze traffic patterns
- Export Capabilities – Download logs and reports for analysis
🎛️ Easy-to-Use Dashboard
All your security in one place. No tech degree required.
What You Get:
- Security Status – Green, yellow, or red. Know your status at a glance
- Recent Attacks – See who’s trying to hack you
- Scan Results – Detailed reports with clear action items
- Firewall Status – Protection levels and rule statistics
- One-Click Actions – Block IPs, ignore false positives, repair files
- Scheduled Scans – Set it and forget it
⚙️ Advanced Features for Power Users
Need more control? We’ve got you covered.
- Custom Firewall Rules – Write your own protection patterns
- File Exclusions – Skip certain directories or file types
- Performance Tuning – Adjust memory limits and timeouts
- API Integrations – Google Safe Browsing, IP reputation databases
- IPv4/IPv6 Support – Dual-stack or IPv4-only mode
- Multisite Compatible – Works perfectly with WordPress networks
- Developer Friendly – Hooks and filters for customization
- Sync Service – Central management for multiple sites
🔒 Privacy & Your Data
Your site data stays on YOUR server. Period.
What We DON’T Do:
❌ We don’t send your content anywhere
❌ We don’t track your users
❌ We don’t collect analytics
❌ We don’t phone home
External Services (Optional):
We only use external services when necessary for security checks, and you can see exactly what’s sent:
Google Safe Browsing API
* Purpose: Check URLs against malware/phishing databases
* What’s sent: Just the URLs (no content, no user data)
* When: During URL reputation scans
* Privacy: https://policies.google.com/privacy
GitHub/WordPress.org
* Purpose: Download original WordPress files for comparison
* What’s sent: Version number and file path (public data only)
* When: Only when you click “View Differences” button
* Privacy: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement
All other processing happens on your server. Attack logs, scan results, and security data never leave your site.
Screenshots

Security Dashboard – Your security status at a glance with firewall protection, scan results, and threat overview 
Active Scan Interface – Real-time scan progress with detailed statistics and threat detection 
Scan Results – Complete threat analysis with actionable remediation options 
Firewall Dashboard – WAF protection status, attack statistics, and blocked threats 
Attack Log – Detailed view of blocked attacks with IP, attack type, and violated rules 
Firewall Summary & Attack Graph – Firewall attack summary and global network attack graph 
Firewall Configuration – Comprehensive settings for WAF, brute force, and rate limiting 
2FA Setup Screen – QR code setup for two-factor authentication 
Live Traffic Monitor – Real-time traffic view with human vs bot classification
Ўсталёўка
Get protected in 5 minutes:
- Install VMP WordPress Security from the WordPress plugin directory
- Activate the plugin
- Go to VMP Security > Dashboard
- Run your first security scan
- Configure firewall settings (or use our secure defaults)
- Enable 2FA for your admin account
- Set up scheduled scans
- Relax. You’re protected.
Часта задаваныя пытанні
-
Will this slow down my website?
-
Nope. We’re obsessed with performance. The firewall uses efficient pattern matching, scanners run in the background, and we optimize memory usage. Your visitors won’t notice any slowdown.
-
Do I need to configure anything?
-
Not really. It works great out of the box with secure defaults. But if you want to customize, we give you full control over every feature.
-
What happens when an attack is blocked?
-
The attacker gets a 403 Forbidden page. We log the attack details (IP, type, time, violated rules) so you can see what happened. Repeat offenders get permanently banned.
-
Can I whitelist my own IP address?
-
Yes! Go to Firewall > Options and add your IP to the allowlist. You’ll bypass all firewall rules (useful for testing).
-
How does 2FA work?
-
Use any authenticator app (Google Authenticator, Authy, 1Password, etc.). Scan the QR code during setup, and you’re done. You’ll enter a 6-digit code when logging in.
-
Will it detect all malware?
-
No security tool catches 100% of threats. But our specialized scanners with pattern matching, behavior analysis, and reputation checking catch the vast majority. We’re constantly updating our detection signatures.
-
Can it repair infected files automatically?
-
We focus on detection and give you safe repair options that you control. When we find infected WordPress core files, you can restore the original version with one click. For plugins/themes, we recommend reinstalling from official sources.
-
Does it work with WooCommerce?
-
Yes! We have special integrations for WooCommerce to protect your store and customer data.
-
How do I update firewall rules?
-
Rules are updated automatically with plugin updates. You can also add custom rules in Firewall > WAF Rules.
-
Can I schedule automatic scans?
-
Absolutely. Daily, twice daily, weekly, weekdays only, weekends only, or custom schedules. The scan monitor ensures they complete successfully.
-
What if I get locked out?
-
2FA includes backup codes that you save during setup. For firewall lockouts, you can disable the plugin via FTP or use WordPress recovery mode.
-
Do you offer support?
-
Yes! We provide support through the WordPress.org forums. Premium support options coming soon.
Водгукі
На гэты плагін няма водгукаў.
Удзельнікі і распрацоўшчыкі
“VMP WordPress Security – Firewall, Malware Scan, and Login Security” is open source software. The following people have contributed to this plugin.
УдзельнікіПеракласці “VMP WordPress Security – Firewall, Malware Scan, and Login Security” на вашу мову.
Зацікаўлены ў распрацоўцы?
Праглядзіце код, праверце SVN рэпазітарый, або падпішыцеся на журнал распрацоўкі па RSS.
Журнал змяненняў
2.1.2 – January 10, 2026
- Fixed scan status persistence and auto-refresh issues
- Fixed browser close handling during active scans
- Fixed file cleanup for certain files during uninstallation
- Fixed auto sync of malware signature and waf rule
- Fixed status calculation hover issue
- Fixed firewall detailed summary table and responsive layout issues
- Fixed debug log handling and dashboard path resolution
- Fixed global options page loading issue
2.1.1 – January 9, 2026
- Major scanner engine overhaul with memory optimization
- Added batching and checkpointing for large scans
- Fixed concurrent scan prevention mechanism
- Fixed async scan worker cleanup on deactivation
- Enhanced scan forking and interruption handling
- Improved progress tracking reliability
- Optimized memory usage for large file scans
2.1.0 – January 7, 2026
MAJOR UPDATE: Two-Factor Authentication, Enhanced Blocking, Tools & Advanced Features
** New Features:**
* Added complete Two-Factor Authentication (2FA) system with QR code setup
* Created live traffic monitoring with real-time request logging
* Added event tracking system for comprehensive security auditing
* Implemented sync service for centralized multi-site management
* Added WHOIS lookup and IP intelligence tools
* Created frontend 2FA management interface with shortcode support
* Added reCAPTCHA integration for enhanced bot protection
* Implemented WooCommerce security integration
* Added XML-RPC security with 2FA enforcement
* Implemented Audit log
** Security Enhancements:**
* Improved IP blocking with granular control and temporary/permanent options
* Implemented advanced file repair engine for infected file recovery
* Added binary file detection for embedded malware in images
* Improved legitimacy assessment to reduce false positives
* Enhanced user security scanning for suspicious accounts
** Performance & UX:**
* Improved progress tracking with detailed status updates
* Enhanced exclusion system with pattern-based file filtering
* Optimized memory management for large site scans
** Technical Improvements:**
* Added comprehensive audit logging for all security events
** Added signature sync service for automatic updates
* Improved file type detection and handling
* Added IP allowlist system for trusted services
** Bug Fixes:**
* Improved text domain consistency across translation strings
* Fixed edge cases in IP address validation and blocking
* Improved compatibility with WordPress 6.9
2.0.0 – December 11, 2025
MAJOR UPDATE: Advanced Firewall Protection & Attack Prevention
** Firewall Features:**
* Added complete Web Application Firewall (WAF) with 280+ security rules
* Implemented real-time attack detection for XSS, SQLi, RFI, LFI, and RCE
* Created WAF rules management interface with filtering capabilities
* Added comprehensive attack logging and statistics
* Implemented early bootstrap protection (loads before WordPress)
** Brute Force Protection:**
* Added login attempt limiting with configurable thresholds
* Implemented invalid username blocking for user enumeration prevention
* Added leaked password checking against breach databases
* Created strong password enforcement system
* Added username blacklisting for instant blocking
** Rate Limiting:**
* Implemented request rate limiting for humans and crawlers
* Added 404 error monitoring to detect scanning attempts
* Created Google crawler verification and handling
* Added intelligent traffic classification
* Implemented throttling and blocking actions
** Advanced Blocking:**
* Added IP address blocking with CIDR range support
* Implemented user agent and referrer blocking
* Created URL pattern blocking with instant bans
* Added IP whitelist for trusted services
* Implemented permanent ban system for repeat offenders
** Dashboard & Reporting:**
* Created firewall dashboard with visual status indicators
* Added attack statistics by time period
* Implemented blocked attacks table with filtering
* Created comprehensive firewall options page
* Added custom security block messages
1.0.0 – September 29, 2025
Initial Release – Comprehensive Security Scanner
- Released specialized security scanner modules
- Added malware detection with advanced pattern matching
- Integrated Google Safe Browsing API for URL reputation
- Created multi-scan type support (Quick, Standard, Deep, Custom)
- Implemented file integrity monitoring against WordPress.org
- Added vulnerability scanning for plugins, themes, and core
- Created user security analysis and admin monitoring
- Implemented content safety scanning
- Added public files scanner for exposed configurations
- Created scheduled scanning with automatic recovery
- Implemented comprehensive audit logging
- Added flexible file exclusion system
- Created dashboard with detailed security reporting