Title: SiteFort &#8212; Advanced Security, Firewall &amp; Malware Scanner
Author: securewpteam
Published: <strong>19.05.2026</strong>
Last modified: 07.06.2026

---

Поиск плагинов

![](https://ps.w.org/sitefort/assets/banner-772x250.png?rev=3537228)

![](https://ps.w.org/sitefort/assets/icon.svg?rev=3536884)

# SiteFort — Advanced Security, Firewall & Malware Scanner

 Автор: [securewpteam](https://profiles.wordpress.org/securewpteam/)

[Скачать](https://downloads.wordpress.org/plugin/sitefort.1.5.2.zip)

 * [Детали](https://ru.wordpress.org/plugins/sitefort/#description)
 * [Отзывы](https://ru.wordpress.org/plugins/sitefort/#reviews)
 *  [Установка](https://ru.wordpress.org/plugins/sitefort/#installation)
 * [Разработка](https://ru.wordpress.org/plugins/sitefort/#developers)

 [Поддержка](https://wordpress.org/support/plugin/sitefort/)

## Описание

SiteFort brings firewall protection, bot blocking, 2FA, vulnerability checks, hardening,
audit logs, and malware scanning into one lightweight security dashboard.

Shaped by real hacked-site recovery experience, SiteFort closes weak points before
attackers use them. It checks for backdoors, web shells, injected scripts, SEO spam,
suspicious redirects, hidden admin risks, breached passwords, exposed sensitive 
files, and vulnerable plugins or themes.

**Helpful links:** [SiteFort Features](https://securewp.net/wordpress-security-plugin/)
| [Free Remote Scan](https://securewp.net/security-checker/) | [Pro Pricing](https://securewp.net/pricing/)
| [Documentation](https://securewp.net/docs/) | [Malware Removal Help](https://securewp.net/wordpress-malware-removal/)

### Comprehensive WordPress Protection

 * **WordPress Hardening:** Lock down XML-RPC, user enumeration, file editing, and
   sensitive file exposure.
 * **Firewall & Traffic Protection:** Block abusive IPs, rate-limit requests, and
   restrict country traffic.
 * **Cloud-Assisted Malware Scanner:** Detect backdoors, web shells, and injected
   scripts using fast hash checks and selective cloud analysis.
 * **Login Security & 2FA:** Prevent account takeover with authenticator apps, custom
   login URLs, CAPTCHA, and brute-force lockouts.
 * **Vulnerability Scanner:** Identify outdated plugins, themes, and core files 
   with CVE references and fix guidance.
 * **Password Protection:** Enforce strong passwords and block compromised or reused
   credentials.
 * **Bot Filter Policy:** SEO-safe bot protection with adjustable strictness levels.
 * **Cloudflare Rule Sync:** Push IP and country blocks to Cloudflare for edge-level
   enforcement.
 * **Full-Site Security Review:** Evaluate server state, database safety, security
   headers, and hidden admin risks.
 * **Audit Log & Console:** Track event history, manage multi-site workflows, and
   route security alerts.

### Built For Performance

SiteFort is designed to protect sites without adding unnecessary server load, including
on shared and managed hosting.

 * **Hash-First Scanning** checks known files quickly before deeper analysis is 
   needed.
 * **Selective Cloud Analysis** reviews only unknown or suspicious files so the 
   server handles less malware work.
 * **On-Site Database Checks** inspect database safety without uploading database
   content to the cloud.
 * **Bad-Bot Blocking** reduces scraping, automated abuse, repeated 404 hits, and
   bots hunting for weak points.
 * **Cloudflare Sync** pushes supported firewall rules to Cloudflare before traffic
   reaches WordPress.

### ◈ WordPress Security Scanner

SiteFort runs a layered security review and organizes findings by severity across
files, accounts, content, reputation, and server state.

 * **Hash-First File Analysis:** Resolves known clean and known malicious files 
   quickly using local hashes before any cloud work is needed.
 * **Deep Malware Detection:** Sends only unknown or suspicious files for cloud 
   analysis to detect backdoors, web shells, malware variants, injected code, SEO
   spam, malicious redirects, and exposed sensitive files.
 * **File Integrity Checks:** Reviews WordPress core, plugins, themes, uploads, 
   and custom files for unauthorized changes, with clean-file restore opportunities
   on supported plans.
 * **User Account Security:** Detects weak account posture, breached passwords, 
   risky roles, suspicious user data, and administrator accounts that need review.
 * **Ghost Administrator Detection:** Flags hidden or unexpected administrator accounts
   created outside normal site workflows.
 * **Content & Database Safety:** Checks WordPress data locally for injected content,
   suspicious options, unsafe URLs, spam injections, and malicious redirect indicators.
 * **Domain & IP Reputation:** Surfaces blocklist and abuse signals for the site
   domain and server IP before they affect trust.
 * **Sensitive File Exposure:** Finds exposed backups, logs, config files, debug
   files, and other files attackers commonly target.
 * **Vulnerability Scanner:** Checks WordPress core, plugins, and themes for known
   vulnerabilities, affected versions, severity, and CVE references where available.
 * **Server State Checks:** Reviews public paths, security headers, file exposure,
   and server conditions that increase compromise risk.

_Cloud-assisted file scanning reduces server load. Content and database checks run
on the site. Database content never leaves._

### ◈ WordPress Security Hardening

SiteFort closes the exposure points attackers check first, then verifies whether
those protections are actually enforced — not just enabled in the dashboard.

 * **XML-RPC Controls:** Disable XML-RPC, restrict authentication, or block pingback
   abuse.
 * **User Enumeration Blocking:** Reduces username leaks from author archives, REST
   endpoints, and common discovery paths.
 * **Sensitive File Protection:** Blocks public access to `.env`, backups, logs,
   debug files, `.git` metadata, lock files, sample configs, and server fragments.
 * **PHP Execution Protection:** Blocks PHP execution in uploads and direct PHP 
   access inside plugin and theme folders where supported.
 * **Directory Listing Protection:** Reduces exposure from browsable upload, plugin,
   theme, or backup directories.
 * **File Editor Protection:** Disables the built-in theme and plugin file editor
   to limit damage from compromised admin accounts.
 * **REST & Application Password Controls:** Restricts risky REST access and application
   password behavior based on site needs.
 * **Version & Metadata Cleanup:** Hides WordPress version output and reduces exposed
   generator and header signals.
 * **Security Headers:** Analyze and manage CSP, HSTS, X-Frame-Options, X-Content-
   Type-Options, Referrer-Policy, Permissions-Policy, and disclosure headers.
 * **Verified Hardening:** SiteFort checks whether supported hardening rules are
   actually enforced — items that require manual hosting or server configuration
   are flagged separately.

### ◈ Login Security & 2FA

Account takeover is one of the fastest ways to lose control of a WordPress site.
SiteFort adds layered login protection without requiring separate plugins.

**Prevention**
 * Brute-force lockouts * CAPTCHA protection * Custom login URL *
Generic login errors to reduce username guessing * XML-RPC and REST authentication
controls

**Authentication**
 * Role-based two-factor authentication * Authenticator app codes*
Email verification codes * Recovery codes

**Password Controls**
 * Weak password detection * Breached-password detection *
Strong-password enforcement * Password reuse prevention * Password expiration policies

### ◈ WordPress Firewall

SiteFort helps block unwanted traffic before it consumes server resources. Firewall
rules cover IPs, countries, bots, crawlers, and user agents without requiring custom
rule syntax.

 * **IP & Country Rules:** Block or allow traffic by IP address, CIDR range, country,
   bot, crawler, or user agent.
 * **Country Blocking:** Supports both block-selected and allow-only modes.
 * **Sensitive File Protection:** Stops bots probing for `.env`, `.git`, `wp-config.
   php` backups, SQL dumps, debug logs, installer files, and other risky paths.
 * **Cloudflare Sync:** Pushes supported IP, country, and user-agent rules to Cloudflare
   so high-volume blocks happen at the edge.
 * **Temporary Edge Blocks:** Blocks repeat attackers at Cloudflare when Cloudflare
   Sync is configured.
 * **Rate Limiting & 404 Controls:** Reduces abusive traffic spikes, repeated missing-
   page requests, and automated noise.
 * **Community Threat Intelligence:** Blocks traffic from malicious IPs seen across
   the SiteFort network.
 * **Vulnerability-Hunting Bot Protection:** Blocks bots probing for vulnerable 
   plugins, themes, backup files, and configuration leaks.

### ◈ Bot Filter Policy

Not all bots are bad. SiteFort provides three protection levels that block unwanted
automation while keeping trusted search engines, social previews, and major crawlers
allowed.

 * ** Basic:** Blocks known hacking tools and bots probing for vulnerable files.
 * ** Balanced:** Blocks hacking tools, scraping bots, and automated scripts. Recommended
   for most sites.
 * ** Maximum:** Blocks hacking tools, scrapers, automated scripts, and unrecognized
   bot traffic.

_Choose the level that fits the site, then adjust individual rules from the firewall
dashboard._

### ◈ Vulnerability Management

SiteFort checks installed WordPress core, plugin, and theme versions against vulnerability
intelligence and shows affected assets, severity, CVE references where available,
and recommended fixes.

SiteFort does not claim to virtually patch vulnerable code. It identifies affected
components, surfaces severity and CVE data, and helps reduce automated discovery
attempts while updates are applied.

**Pro:** Automated vulnerability alerts notify teams when a known vulnerability 
affects an installed plugin, theme, or WordPress core version.

### ◈ One-Click Repair & Restore

**Pro:** Guided repair workflows let teams act on scan findings without manually
editing files over FTP or SSH.

 * Repair or delete malicious files directly from scan results.
 * Restore clean WordPress core, plugin, and theme files when a trusted clean source
   is available.
 * Repair supported paid plugin and theme files when clean-source matching is available.
 * Quarantine suspicious files and restore them later if needed.

_For active compromise, [Securewp expert cleanup](https://securewp.net/wordpress-malware-removal/)
and managed security services are available when hands-on investigation, root-cause
patching, blocklist help, or post-cleanup review is needed._

### ◈ Audit Log & SiteFort Console

SiteFort keeps a security event history so teams can quickly see what changed, what
was blocked, and what needs attention.

 * ** Login Activity:** Successful logins, failed attempts, lockouts, 2FA events,
   and account-related actions.
 * ** User & Site Changes:** User updates, plugin and theme changes, settings changes,
   and sensitive admin actions.
 * ** Firewall Activity:** Blocked IPs, country rules, bot blocks, rate-limit events,
   and suspicious request activity.
 * ** Scanner Results:** Malware findings, vulnerability findings, reputation checks,
   hardening issues, and scan history.
 * ** Hardening Changes:** Applied rules, failed rules, verified protections, and
   items needing manual review.

Site-level security features are available from the WordPress dashboard. SiteFort
Console is optional for teams that need centralized visibility across multiple sites.

 * Multi-site status for connected websites.
 * Downloadable reports for clients or internal review.
 * Team roles and support workflows.
 * **Pro:** Remote scan history and vulnerability tracking.
 * **Pro:** Uptime and SSL expiry monitoring.
 * **Pro:** Email, Slack, Discord, and webhook alerts.
 * **Pro:** White-label options for agencies on supported plans.

### ◈ Hosting Compatibility

SiteFort is built for real WordPress environments including shared hosting, managed
hosting, VPS, and Cloudflare-proxied sites.

 * Works with Apache, Nginx, and LiteSpeed.
 * Compatible with shared hosting, managed WordPress hosting, VPS, and dedicated
   servers.
 * Cloudflare-friendly: supports proxied sites and optional Cloudflare rule sync.
 * Cloud-assisted scanning reduces heavy scan work on lower-resource hosting plans.
 * Verified hardening confirms whether key rules are actually enforced, not just
   toggled on.

### ◈ Pro & Managed Security

Core protection is available in the free plugin. Paid plans are built for infected
sites, agencies, and teams that need continuous scanning, automated alerts, deeper
file analysis, repair workflows, and post-cleanup coverage.

**Pro plans add:**
 * Unlimited cloud deep threat analysis * Scheduled malware scans*
Automated vulnerability alerts * One-click malware repair and restore * Clean-file
restoration for core, plugin, and theme files * Uptime and SSL monitoring * Slack,
Discord, email, and webhook alerts * Advanced reports and Console workflows * White-
label options for agencies * Expert cleanup discounts

**Managed security** adds hands-on monitoring, response workflows, and expert cleanup
coverage.

Looking for a market comparison? See the [WordPress Security Plugin Comparison](https://securewp.net/wordpress-security-plugin-comparison/).

### External services

SiteFort connects to external services only when needed for license activation, 
cloud-assisted malware analysis, vulnerability intelligence, firewall intelligence,
optional Console sync, optional CAPTCHA, optional GeoIP, optional IP lookup, Cloudflare
sync, and administrator-enabled notifications.

Optional integrations are not contacted unless they are configured or used.

#### SiteFort Cloud

 * **Servers:** securewp.net, intel.securewp.net, console.securewp.net
 * **Used for:** License activation, service metadata, cloud malware analysis, vulnerability
   intelligence, firewall intelligence, reputation checks, community blocklist sync,
   clean-file repair, and optional Console sync.
 * **Data sent:** Email address, license key/token, site URL, WordPress/plugin versions,
   installed plugin/theme names and versions, file hashes, scan results, vulnerability
   findings, reputation status, firewall metadata, blocked IPs, and security configuration
   metadata.
 * **Malware scanning:** File hashes are sent first. Only unknown or suspicious 
   files may be uploaded for deeper analysis and are deleted after processing. Database
   and content checks run on your website. SiteFort does not upload your database
   or database-stored content to the cloud. If wp-config.php requires analysis, 
   sensitive configuration values are removed before upload.
 * **Temporary storage:** SiteFort Cloud may return temporary upload/download URLs
   on *.amazonaws.com or *.r2.cloudflarestorage.com for scan uploads or clean-file
   repair downloads.
 * **Privacy:** https://securewp.net/privacy-policy/
 * **Terms:** https://securewp.net/terms-and-conditions/
 * **Storage provider policies:** AWS privacy https://aws.amazon.com/privacy/ and
   terms https://aws.amazon.com/service-terms/; Cloudflare privacy https://www.cloudflare.
   com/privacypolicy/ and terms https://www.cloudflare.com/website-terms/

#### Optional integrations

 * **MaxMind GeoLite2** (download.maxmind.com) is used only when an administrator
   downloads or updates the local GeoIP database. It sends the configured MaxMind
   account ID and license key. Visitor IPs are resolved locally and are not sent
   to MaxMind during normal requests. Privacy: https://www.maxmind.com/en/privacy-
   policy Terms: https://www.maxmind.com/en/geolite2/eula
 * **Have I Been Pwned Passwords** (api.pwnedpasswords.com) is used for breached-
   password checks when enabled. SiteFort sends only the first 5 characters of the
   SHA-1 password hash. Full passwords and full hashes are never sent. Privacy: 
   https://haveibeenpwned.com/Privacy Terms: https://haveibeenpwned.com/TermsOfUse
 * **RIPE NCC / ARIN RDAP** (rdap.db.ripe.net, rdap.arin.net) is used only when 
   an administrator requests an IP ownership lookup. The queried IP address is sent.
   Site credentials, users, scan results, and plugin settings are not sent. Privacy/
   terms: https://www.ripe.net/about-us/legal/ripe-ncc-privacy-statement/ https://
   docs.db.ripe.net/HTML-Terms-And-Conditions https://www.arin.net/about/privacy/
   https://www.arin.net/resources/registry/whois/tou/
 * **Google reCAPTCHA** (www.google.com) and **Cloudflare Turnstile** (challenges.
   cloudflare.com) are used only when selected and configured for CAPTCHA protection.
   They receive the challenge token, site key, and visitor/browser data required
   by the selected provider. Policies: https://policies.google.com/privacy https://
   policies.google.com/terms https://www.cloudflare.com/turnstile-privacy-policy/
   https://www.cloudflare.com/website-terms/
 * **Cloudflare API** (api.cloudflare.com) is used only when Cloudflare Sync is 
   enabled. It sends Zone ID, API token/credentials, zone details, blocked IPs, 
   country rules, selected user-agent rules, and firewall rule data. Privacy: https://
   www.cloudflare.com/privacypolicy/ Terms: https://www.cloudflare.com/website-terms/
 * **Notification webhooks** may send security alerts to Slack (hooks.slack.com),
   Discord (discord.com, discordapp.com), or a custom HTTPS webhook entered by the
   administrator. Webhook payloads may include site name, site URL, event type, 
   severity, scan counts, vulnerability names, CVE identifiers, firewall counts,
   usernames, IP addresses, browser names, action URLs, timestamps, and event details.
   Slack policies: https://slack.com/trust/privacy/privacy-policy https://slack.
   com/terms-of-service/user Discord policies: https://discord.com/privacy https://
   discord.com/terms

#### Local site checks

Some requests are loopback checks against the protected site’s own public URL, such
as security-header checks, public-file exposure checks, and homepage link collection.
These contact the site being protected, not a third-party service.

## Скриншоты

[⌊SiteFort Dashboard: Site health, security status, firewall activity, vulnerability
count and action center.⌉⌊SiteFort Dashboard: Site health, security status, firewall
activity, vulnerability count and action center.⌉[

**SiteFort Dashboard:** Site health, security status, firewall activity, vulnerability
count and action center.

[⌊Security Scanner: Staged scan progress across files, malware, accounts, database/
content safety, reputation, vulnerabilities, severity, detection type, and remediation
actions.⌉⌊Security Scanner: Staged scan progress across files, malware, accounts,
database/content safety, reputation, vulnerabilities, severity, detection type, 
and remediation actions.⌉[

**Security Scanner:** Staged scan progress across files, malware, accounts, database/
content safety, reputation, vulnerabilities, severity, detection type, and remediation
actions.

[⌊Firewall Controls: Easy bot/crawler policy, rate limits, community blocklist, 
and Cloudflare Sync.⌉⌊Firewall Controls: Easy bot/crawler policy, rate limits, community
blocklist, and Cloudflare Sync.⌉[

**Firewall Controls:** Easy bot/crawler policy, rate limits, community blocklist,
and Cloudflare Sync.

[⌊Firewall Rule Builder: IP rules, country blocking, and bot/crawler firewall rules.⌉⌊
Firewall Rule Builder: IP rules, country blocking, and bot/crawler firewall rules
.⌉[

**Firewall Rule Builder:** IP rules, country blocking, and bot/crawler firewall 
rules.

[⌊Login Security: Custom login URL, lockouts, CAPTCHA protection, and password controls.⌉⌊
Login Security: Custom login URL, lockouts, CAPTCHA protection, and password controls
.⌉[

**Login Security:** Custom login URL, lockouts, CAPTCHA protection, and password
controls.

[⌊2FA: Role enforcement, authenticator app setup, email codes, recovery codes.⌉⌊
2FA: Role enforcement, authenticator app setup, email codes, recovery codes.⌉[

**2FA:** Role enforcement, authenticator app setup, email codes, recovery codes.

[⌊Server Hardening: Sensitive file protection, PHP execution controls, XML-RPC and
security headers.⌉⌊Server Hardening: Sensitive file protection, PHP execution controls,
XML-RPC and security headers.⌉[

**Server Hardening:** Sensitive file protection, PHP execution controls, XML-RPC
and security headers.

[⌊WordPress Hardening: REST API, user enumeration, file editor protection.⌉⌊WordPress
Hardening: REST API, user enumeration, file editor protection.⌉[

**WordPress Hardening:** REST API, user enumeration, file editor protection.

[⌊Vulnerability Scanner: Affected plugins, themes, WordPress core, CVE references,
severity, and fix guidance.⌉⌊Vulnerability Scanner: Affected plugins, themes, WordPress
core, CVE references, severity, and fix guidance.⌉[

**Vulnerability Scanner:** Affected plugins, themes, WordPress core, CVE references,
severity, and fix guidance.

[⌊Security Headers: Security header analyzer and configuration.⌉⌊Security Headers:
Security header analyzer and configuration.⌉[

**Security Headers:** Security header analyzer and configuration.

[⌊Audit Log: Searchable security events, user activity, firewall actions, scan results,
and sensitive changes.⌉⌊Audit Log: Searchable security events, user activity, firewall
actions, scan results, and sensitive changes.⌉[

**Audit Log:** Searchable security events, user activity, firewall actions, scan
results, and sensitive changes.

[⌊SiteFort Console: Multi-site status, scans, alerts, reports, uptime, SSL, team
workflows, and support options.⌉⌊SiteFort Console: Multi-site status, scans, alerts,
reports, uptime, SSL, team workflows, and support options.⌉[

**SiteFort Console:** Multi-site status, scans, alerts, reports, uptime, SSL, team
workflows, and support options.

## Установка

 1. Install SiteFort from the WordPress plugin directory, or upload the plugin ZIP 
    file.
 2. For manual installation, upload the unzipped `sitefort` folder to `/wp-content/
    plugins/`.
 3. Activate the plugin from the **Plugins** screen and open **SiteFort** in wp-admin.
 4. Complete the setup wizard, or open **SiteFort > Settings > License and Plan**.
 5. Activate with your email address or license key.
 6. Review scanner, firewall, country blocking, bot policy, login security, 2FA, and
    hardening settings.
 7. Connect Cloudflare from **Settings > Integrations** if you want edge-level firewall
    enforcement.
 8. Run your first security scan and review malware, account, database, reputation,
    vulnerability, and hardening findings.

_Note: SiteFort requires outbound HTTPS for license activation, cloud malware analysis,
vulnerability intelligence, firewall intelligence, community blocklist updates, 
reputation checks, clean-file repair, and optional Console sync._

## Часто задаваемые вопросы

### How does SiteFort help secure my website?

SiteFort adds practical protection layers for WordPress: firewall rules, bad-bot
blocking, country controls, login security, 2FA, CAPTCHA, password protection, vulnerability
checks, security hardening, audit logs, and cloud-assisted malware scanning.

It is built to help you close weak points, reduce automated abuse, detect malware,
and monitor security risks from your WordPress dashboard.

### What security risks can SiteFort find?

SiteFort checks for malware, backdoors, web shells, malicious PHP scripts, injected
scripts, SEO spam, suspicious redirects, exposed sensitive files, hidden administrator
risks, weak or breached passwords, vulnerable plugins and themes, reputation issues,
unsafe database/content indicators, and weak hardening rules.

### How does SiteFort keep scans lightweight?

SiteFort uses hash-first file checks so known files can be resolved quickly. Only
unknown or suspicious files may be sent for deeper cloud analysis when needed. Database
and content checks run on your own website, and scan results are cached where possible
so unchanged files do not need the same work again.

### Does SiteFort send my database content to the cloud?

No. Database and content safety checks run on your own website. Your database content
never leaves your site. For file scanning, SiteFort sends file hashes first. Only
files that cannot be verified by hash alone may be uploaded for deeper malware analysis.
If `wp-config.php` requires analysis, sensitive configuration values are removed
before upload.

### Does SiteFort include firewall protection?

Yes. SiteFort includes firewall rules for IP addresses, CIDR ranges, countries, 
bots, crawlers, user agents, rate limits, suspicious requests, and bots looking 
for exposed files or weak points. SiteFort also supports community threat intelligence
and optional Cloudflare Sync for supported firewall rules.

### Does SiteFort support country blocking and Cloudflare?

Yes. Country blocking supports both block-selected and allow-only modes. Country
detection can use Cloudflare country data for proxied sites, Cloudflare integration
when configured in SiteFort, or a local MaxMind GeoLite2 database when a free MaxMind
license is configured. SiteFort can also sync supported IP, country, and user-agent
firewall rules to Cloudflare when the domain is proxied through Cloudflare and a
scoped API token is configured.

### Will bot protection block Google or search engines?

SiteFort’s easy bot filter policy is designed to block unwanted automation while
allowing trusted search engines, social previews, and major crawlers. You can choose
Basic, Balanced, or Maximum protection depending on how aggressively you want to
filter bots, scraping tools, automated scripts, and traffic looking for vulnerable
files.

### Does SiteFort protect WordPress logins?

Yes. SiteFort includes login security controls such as role-based 2FA, authenticator
app codes, email codes, recovery codes, brute-force lockouts, CAPTCHA, custom login
URL, generic login errors, weak-password detection, strong-password enforcement,
breached-password checks, password reuse prevention, and password expiration policies.

### What hardening protections are included?

SiteFort helps reduce common WordPress exposure by protecting sensitive files, blocking
PHP execution in risky locations, disabling directory listing, controlling XML-RPC,
blocking user enumeration, hiding version output, restricting REST access where 
appropriate, disabling application passwords, disabling the theme/plugin file editor,
and managing security headers. Where possible, SiteFort also checks whether hardening
rules are actually enforced, not just enabled in the dashboard.

### How does SiteFort handle vulnerable plugins and themes?

SiteFort checks installed WordPress core, plugin, and theme versions against known
vulnerability intelligence. It shows affected assets, severity, CVE references where
available, and recommended actions. SiteFort does not claim to virtually patch vulnerable
code. It helps you identify vulnerable components and reduce automated discovery
attempts while you update, replace, or remove affected software.

### Can SiteFort help after a site is already hacked?

Yes. SiteFort can scan for malware, suspicious users, injected content, reputation
issues, exposed files, vulnerable components, and weak hardening rules. Supported
plans add one-click malware repair/restore. Expert cleanup and managed security 
services are also available when hands-on response is needed.

### What features require a paid plan?

Paid plans add unlimited cloud deep threat analysis, scheduled scans, automated 
vulnerability alerts, one-click malware repair/restore, supported clean-file restoration,
uptime/SSL monitoring, Slack/Discord/email/webhook alerts, advanced reports, white-
label options, expert cleanup discounts, and managed security options.

### Do I need SiteFort Console?

No. Site-level security features are available from your WordPress dashboard. SiteFort
Console is optional for users who want centralized visibility, multi-site management,
remote workflows, reports, alert routing, uptime/SSL monitoring, team access, and
support workflows.

### Is SiteFort suitable for shared or managed hosting?

Yes. SiteFort is designed for shared hosting, managed WordPress hosting, VPS setups,
Apache, Nginx, LiteSpeed, and Cloudflare-proxied sites. Hash-first file checks, 
selective cloud analysis, on-site database checks, bot blocking, rate limits, and
Cloudflare Sync help reduce unnecessary server work on lower-resource hosting.

### How do I activate SiteFort Pro?

Open **SiteFort > Settings > License and Plan** in your WordPress dashboard. You
can activate with the email address used at checkout or a license key. If you already
have a free license under the same email, the site can upgrade to Pro from the License
and Plan screen.

## Отзывы

![](https://secure.gravatar.com/avatar/bacb8e8e47e555458afdcc55c7692771af840d528715bd100063692c86371b3d?
s=60&d=retro&r=g)

### 󠀁[Excellent Security Plugin](https://wordpress.org/support/topic/excellent-security-plugin-52/)󠁿

 [mfheroic](https://profiles.wordpress.org/mfheroic/) 22.05.2026

It’s a lightweight option that packs in malware scanning, a web application firewall,
and solid hardening features. Overall, I’d say it’s a great choice if you want strong
security that doesn’t drag your site down. Definitely worth trying if you’re looking
for a modern, efficient alternative.

![](https://secure.gravatar.com/avatar/16fa23963bd70ca45b4495aaa389eb43a3f11d01c60553e5765a32df52d04f90?
s=60&d=retro&r=g)

### 󠀁[My experience on SiteFort.](https://wordpress.org/support/topic/my-experience-on-sitefort/)󠁿

 [anwarhossain33](https://profiles.wordpress.org/anwarhossain33/) 20.05.2026

This is too good! Highly recommended!

![](https://secure.gravatar.com/avatar/6661e0eb6410ef62b3bd49d24e0d08ae4381ec61a09bc42bfaa6118868f3a0d8?
s=60&d=retro&r=g)

### 󠀁[Finally a full package security plugin](https://wordpress.org/support/topic/finally-a-full-package-security-plugin/)󠁿

 [2h1n846](https://profiles.wordpress.org/2h1n846/) 19.05.2026

For years, my workflow for WordPress security was frustrating. I would install one
plugin to scan for malware, remove it after cleanup, then install and configure 
another plugin just for security hardening because the one I used for malware scanner
were too heavy to keep running all the time.SiteFort is the first plugin I’ve used
that combines both in a clean and lightweight way. Fast malware scanning, practical
hardening features, and an easy-to-use interface without slowing down the website.
Good luck to the SiteFort team 🤞

 [ Посмотреть все 3 отзыва ](https://wordpress.org/support/plugin/sitefort/reviews/)

## Участники и разработчики

«SiteFort — Advanced Security, Firewall & Malware Scanner» — проект с открытым исходным
кодом. В развитие плагина внесли свой вклад следующие участники:

Участники

 *   [ securewpteam ](https://profiles.wordpress.org/securewpteam/)

[Перевести «SiteFort — Advanced Security, Firewall & Malware Scanner» на ваш язык.](https://translate.wordpress.org/projects/wp-plugins/sitefort)

### Заинтересованы в разработке?

[Посмотрите код](https://plugins.trac.wordpress.org/browser/sitefort/), проверьте
[SVN репозиторий](https://plugins.svn.wordpress.org/sitefort/), или подпишитесь 
на [журнал разработки](https://plugins.trac.wordpress.org/log/sitefort/) по [RSS](https://plugins.trac.wordpress.org/log/sitefort/?limit=100&mode=stop_on_copy&format=rss).

## Журнал изменений

#### 1.5.2

 * Improved scanner compatibility with refreshed WordPress.org file baselines.
 * Improved activation validation for invalid email addresses and license keys.

#### 1.5.1

 * Added an admin compatibility notice for security plugins that may overlap with
   SiteFort server hardening.

#### 1.5.0

 * Improved scanner worker wakeup reliability on hosts that interrupt one-second
   loopback requests.
 * Improved scanner cloud queue utilization and final scan log hydration on managed
   hosting.
 * Added a secure tool to rename the default admin username with locking, transactions,
   multisite handling, and audit logging.

#### 1.4.0

 * Improved scanner cloud upload reliability with streamed S3 batch uploads and 
   safer fallback handling.
 * Prevented SiteFort runtime data files from delaying scan completion while preserving
   malicious hash detections.

#### 1.3.0

 * Improved cloud wakeup handling so completed cloud scan jobs can securely resume
   site polling without requiring the admin console.

#### 1.2.0

 * Fixed scan finding notification actions to open the scanner page instead of the
   dashboard.
 * Added concise contextual copy to SiteFort notification emails before scan, firewall,
   vulnerability, digest, and fallback event details.
 * Improved scanner findings empty states and vulnerability remediation card updates
   during active scans.

#### 1.1.0

 * Improved scanner worker recovery and server-load interruption messaging.
 * Optimized setup wizard two-factor loading with a consolidated overview request.
 * Hardened command queue and login lockout cleanup to prevent stale database growth.

#### 1.0.2

 * Bundled shared timestamp parsing into the admin shared asset to avoid a separate
   time chunk.

#### 1.0.1

 * Hardened automated scan scheduling with scanner-owned cron intervals, boot-time
   reconciliation, site-time run alignment, and stale schedule cleanup.
 * Fixed audit log, dashboard, and firewall timestamps to use UTC event time consistently.
 * Fixed dashboard and report daily totals to respect the WordPress site timezone
   instead of the server or database timezone.
 * Added site-time display and CSV export fields for audit events while keeping 
   UTC as the canonical timestamp.
 * Updated file logs to write ISO-8601 UTC timestamps and retain legacy UTC log 
   parsing.

#### 1.0.0

 * Initial release

## Мета

 *  Версия **1.5.2**
 *  Обновление: **2 дня назад**
 *  Активных установок: **10+**
 *  Версия WordPress ** 6.0 или выше **
 *  Совместим вплоть до: **7.0**
 *  Версия PHP ** 7.4 или выше **
 *  Язык
 * [English (US)](https://wordpress.org/plugins/sitefort/)
 * Метки:
 * [2FA](https://ru.wordpress.org/plugins/tags/2fa/)[firewall](https://ru.wordpress.org/plugins/tags/firewall/)
   [malware scanner](https://ru.wordpress.org/plugins/tags/malware-scanner/)[security](https://ru.wordpress.org/plugins/tags/security/)
   [vulnerability](https://ru.wordpress.org/plugins/tags/vulnerability/)
 *  [Дополнительно](https://ru.wordpress.org/plugins/sitefort/advanced/)

## Оценки

 5 из 5 звёзд.

 *  [  3 5-звездный отзыв     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=5)
 *  [  0 4-звездный отзыв     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=4)
 *  [  0 3-звездный отзыв     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=3)
 *  [  0 2-звездный отзыв     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=2)
 *  [  0 1-звездный отзыв     ](https://wordpress.org/support/plugin/sitefort/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/sitefort/reviews/#new-post)

[Посмотреть всеотзывы](https://wordpress.org/support/plugin/sitefort/reviews/)

## Участники

 *   [ securewpteam ](https://profiles.wordpress.org/securewpteam/)

## Поддержка

Есть что сказать? Нужна помощь?

 [Перейти в форум поддержки](https://wordpress.org/support/plugin/sitefort/)