Title: Wordfence Security &#8211; Firewall, Malware Scan, and Login Security
Author: Mark Maunder
Published: <strong>Aprel 21, 2012</strong>
Last modified: May 13, 2026

---

Search plugins

![](https://ps.w.org/wordfence/assets/banner-772x250.jpg?rev=2124102)

![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)

# Wordfence Security – Firewall, Malware Scan, and Login Security

 By [Mark Maunder](https://profiles.wordpress.org/mmaunder/)

[Download](https://downloads.wordpress.org/plugin/wordfence.8.2.2.zip)

 * [Details](https://uz.wordpress.org/plugins/wordfence/#description)
 * [Reviews](https://uz.wordpress.org/plugins/wordfence/#reviews)
 *  [Installation](https://uz.wordpress.org/plugins/wordfence/#installation)
 * [Development](https://uz.wordpress.org/plugins/wordfence/#developers)

 [Support](https://wordpress.org/support/plugin/wordfence/)

## Description

#### DUNYoNING ENG ZO’R VAZIFALARI FIREWALL & amp; XAVFSIZLIK Skaneri

WordPress security requires a team of dedicated analysts researching the latest 
malware variants and WordPress exploits, turning them into firewall rules and malware
signatures, and releasing those to customers in real-time.

Choose the right protection for you: [Wordfence Free, Premium, Care or Response](https://www.wordfence.com/products/pricing/)

Wordfence is widely acknowledged as the number one WordPress security research team
in the World. Our plugin provides a comprehensive suite of security features, and
our team’s research is what powers our plugin and provides the level of security
that we are known for.

At Wordfence, WordPress security isn’t a division of our business – WordPress security
is all we do. We employ a global 24-hour dedicated incident response team that provides
our priority customers with a 1 hour response time for any security incident.

The sun never sets on our global security team and we run a sophisticated threat
intelligence platform to aggregate, analyze and produce ground breaking security
research on the newest security threats.

**Wordfence Security includes an endpoint firewall, malware scanner, robust login
security features, live traffic views, and more.** Our [Threat Defense Feed](https://www.wordfence.com/threat-intel/)
arms Wordfence with the newest firewall rules, malware signatures, and malicious
IP addresses it needs to keep your website safe.

Rounded out by 2FA and a suite of additional features, Wordfence is the most comprehensive
WordPress security solution available.

### 🔥 WORDPRESS FIREWALL

 * **[Web Application Firewall](https://www.wordfence.com/help/firewall/)** identifies
   and blocks malicious traffic. Built and maintained by a large team focused 100%
   on WordPress security.
 * **Real-time firewall rule and malware signature [Premium]** updates via the Threat
   Defense Feed (free version is delayed by 30 days).
 * **[Real-time IP Blocklist](https://www.wordfence.com/help/blocking/) [Premium]**
   blocks all requests from the most malicious IPs, protecting your site while reducing
   load.
 * **Protects your site at the endpoint**, enabling deep integration with WordPress.
   Unlike cloud alternatives, it does not break encryption, cannot be bypassed and
   cannot leak data.
 * **[Integrated malware scanner](https://www.wordfence.com/help/scan/)** blocks
   requests that include malicious code or content.
 * **[Protection from brute force](https://www.wordfence.com/help/firewall/brute-force/)**
   attacks by limiting login attempts.

### 📡 WORDPRESS SECURITY SCANNER

 * **Malware scanner** checks core files, themes and plugins for malware, bad URLs,
   backdoors, SEO spam, malicious redirects and code injections.
 * **Real-time malware signature updates [Premium]** via the Threat Defense Feed(
   free version is delayed by 30 days).
 * **Compares with WordPress.org repository** your core files, themes and plugins,
   checking their integrity and reporting any changes to you.
 * **Repair WordPress core, theme, and plugin files** that have changed by overwriting
   them with a pristine, original version. Delete any files that don’t belong easily
   within the Wordfence interface.
 * **Malware Removal Tools** «Delete File» and «Delete All Deletable Files» options
   allow for efficient malware removal. Remember to investigate the scan results
   and backup files first!
 * **Checks your site for known security vulnerabilities** and alerts you to any
   issues. Also alerts you to potential security issues when a plugin has been closed
   or abandoned.
 * **Checks your content safety** by scanning file contents, posts and comments 
   for dangerous URLs and suspicious content.
 * **Checks to see if your site or IP have been blocklisted [Premium]** for malicious
   activity, generating spam or other security issues.

### 🔒 LOGIN SECURITY

 * **[Two-factor authentication (2FA)](https://www.wordfence.com/help/tools/two-factor-authentication/)**,
   one of the most secure forms of remote system authentication available via any
   TOTP-based authenticator app or service.
 * **[Login Page CAPTCHA](https://www.wordfence.com/help/login-security/)** stops
   bots from logging in.
 * **[2FA for WooCommerce and custom integrations](https://www.wordfence.com/help/login-security/#woocommerce-and-custom-integrations)**
   allow for 2FA to be setup on custom account pages
 * **XML-RPC** options including disabling or adding 2FA.
 * **Password Security:** Block logins for administrators using known compromised
   passwords.

### 📋 SECURITY AUDIT LOG [Premium]

 * **[The Audit Log](https://www.wordfence.com/help/audit-log)** monitors all changes
   and actions in security-sensitive areas of the site.
 * **Remote tamper-proof data storage** via Wordfence Central.
 * **Monitor events and actions** ranging from user creation and editing to plugin/
   theme installation and updates to post and page changes.
 * **Configurable** to log all events or significant events only, which includes
   all authentication, site configuration, and site functionality events.

### 🌐 WORDFENCE CENTRAL

 * **[Wordfence Central](https://www.wordfence.com/products/wordfence-central/)**
   is a powerful and efficient way to manage the security for multiple sites in 
   one place.
 * **Centralized management:** Efficiently assess the security status of all your
   websites in one view. View detailed security findings without leaving Wordfence
   Central.
 * **Powerful templates** make configuring Wordfence a breeze.
 * **Highly configurable alerts** can be delivered via email, SMS or Slack. Improve
   the signal to noise ratio by leveraging severity level options and a daily digest
   option.
 * **Track and alert on important security events** including administrator logins,
   breached password usage and surges in attack activity.
 * **Free to use** for unlimited sites.

### 🛠️ SECURITY TOOLS

 * **[Live Traffic](https://www.wordfence.com/help/tools/live-traffic/)** monitors
   visits and hack attempts not shown in other analytics packages in real time; 
   including origin, their IP address, the time of day and time spent on your site.
 * **Block attackers by IP** or build advanced rules based on IP Range, Hostname,
   User Agent and Referrer.
 * **[Country blocking](https://www.wordfence.com/help/blocking/country-blocking/)**
   available with Wordfence Premium.

## Screenshots

[⌊Nazorat panelida sizning saytingiz xavfsizligi, shu jumladan bildirishnomalar,
hujumlar statistikasi va Wordfence xususiyati holati haqida umumiy ma'lumotlar mavjud.⌉⌊
Nazorat panelida sizning saytingiz xavfsizligi, shu jumladan bildirishnomalar, hujumlar
statistikasi va Wordfence xususiyati holati haqida umumiy ma'lumotlar mavjud.⌉[

Nazorat panelida sizning saytingiz xavfsizligi, shu jumladan bildirishnomalar, hujumlar
statistikasi va Wordfence xususiyati holati haqida umumiy ma’lumotlar mavjud.

[⌊Xavfsizlik devori sizning saytingizni keng tarqalgan xurujlardan va xavfsizlikning
ma'lum zaifliklaridan himoya qiladi.⌉⌊Xavfsizlik devori sizning saytingizni keng
tarqalgan xurujlardan va xavfsizlikning ma'lum zaifliklaridan himoya qiladi.⌉[

Xavfsizlik devori sizning saytingizni keng tarqalgan xurujlardan va xavfsizlikning
ma’lum zaifliklaridan himoya qiladi.

[⌊Wordfence havfsizlik skaneri sizning saytingiz buzilgan yoki yo'qligini aniqlashga
imkon beradi va sizni boshqa xavfsizlik muammolari to'g'risida ogohlantiradi.⌉⌊Wordfence
havfsizlik skaneri sizning saytingiz buzilgan yoki yo'qligini aniqlashga imkon beradi
va sizni boshqa xavfsizlik muammolari to'g'risida ogohlantiradi.⌉[

Wordfence havfsizlik skaneri sizning saytingiz buzilgan yoki yo’qligini aniqlashga
imkon beradi va sizni boshqa xavfsizlik muammolari to’g’risida ogohlantiradi.

[⌊Wordfence juda sozlangan, har bir xususiyat uchun keng imkoniyatlar to'plami mavjud.
Yuqori darajadagi skanerlash imkoniyatlari yuqorida ko'rsatilgan.⌉⌊Wordfence juda
sozlangan, har bir xususiyat uchun keng imkoniyatlar to'plami mavjud. Yuqori darajadagi
skanerlash imkoniyatlari yuqorida ko'rsatilgan.⌉[

Wordfence juda sozlangan, har bir xususiyat uchun keng imkoniyatlar to’plami mavjud.
Yuqori darajadagi skanerlash imkoniyatlari yuqorida ko’rsatilgan.

[⌊Brute Force Protection xususiyatlari parolni taxmin qilish hujumlaridan himoya
qiladi.⌉⌊Brute Force Protection xususiyatlari parolni taxmin qilish hujumlaridan
himoya qiladi.⌉[

Brute Force Protection xususiyatlari parolni taxmin qilish hujumlaridan himoya qiladi.

[⌊Hujumchilarni IP, mamlakat, IP diapazoni, Xost nomi, Brauzer yoki Yo'naltiruvchi
tomonidan bloklang.⌉⌊Hujumchilarni IP, mamlakat, IP diapazoni, Xost nomi, Brauzer
yoki Yo'naltiruvchi tomonidan bloklang.⌉[

Hujumchilarni IP, mamlakat, IP diapazoni, Xost nomi, Brauzer yoki Yo’naltiruvchi
tomonidan bloklang.

[⌊Wordfence Live Traffic ko'rinishi sizning saytingizda real vaqtdagi faollikni,
shu jumladan bot-trafikni va ekspluatatsiya harakatlarini ko'rsatadi.⌉⌊Wordfence
Live Traffic ko'rinishi sizning saytingizda real vaqtdagi faollikni, shu jumladan
bot-trafikni va ekspluatatsiya harakatlarini ko'rsatadi.⌉[

Wordfence Live Traffic ko’rinishi sizning saytingizda real vaqtdagi faollikni, shu
jumladan bot-trafikni va ekspluatatsiya harakatlarini ko’rsatadi.

[⌊Ikki faktorli autentifikatsiya yordamida kirish xavfsizligini keyingi bosqichga
o'ting.⌉⌊Ikki faktorli autentifikatsiya yordamida kirish xavfsizligini keyingi bosqichga
o'ting.⌉[

Ikki faktorli autentifikatsiya yordamida kirish xavfsizligini keyingi bosqichga 
o’ting.

[⌊Wordfence 2FA yordamida kirish oson.⌉⌊Wordfence 2FA yordamida kirish oson.⌉[

Wordfence 2FA yordamida kirish oson.

## Installation

Wordfence-ni o’rnatish uchun quyidagi qadamlar yordamida veb-saytingizni xavfsiz
qiling:

 1. Install Wordfence automatically or by uploading the ZIP file.
 2. WordPress-dagi «Plaginlar» menyusi orqali Wordfence-ni faollashtiring. Wordfence
    endi faollashtirildi.
 3. Tekshirish menyusiga o’ting va birinchi tekshiruvni boshlang. Rejalashtirilgan 
    skanerlash ham yoqiladi.
 4. Birinchi tekshiruvingiz tugagandan so’ng, tahdidlar ro’yxati paydo bo’ladi. O’zingizning
    saytingizni himoya qilish uchun ularni birma-bir ko’rib chiqing.
 5. Elektron pochta manzilingizni kiritish uchun Wordfence parametrlari sahifasiga 
    tashrif buyuring, shunda siz elektron pochta orqali xavfsizlik to’g’risida ogohlantirish
    olasiz.
 6. Ixtiyoriy ravishda, sizning saytingiz uchun individual skanerlash va himoya qilish
    parametrlarini o’rnatish uchun xavfsizlik darajasini o’zgartiring yoki kengaytirilgan
    parametrlarni sozlang.
 7. Real vaqt rejimida saytingiz faoliyatini ko’rish uchun «Jonli trafik» menyusini
    bosing. Situatsion xabardorlik veb-sayt xavfsizligining muhim qismidir.

Wordfress-ni WordPress ko’p saytli o’rnatmalariga o’rnatish uchun:

 1. Wordfence-ni plagin katalogi orqali yoki ZIP-faylni yuklash orqali o’rnating.
 2. Network Activate Wordfence. This step is important because until you network activate
    it, your sites will see the plugin option on their plugins menu. Once activated
    that option disappears.
 3. Now that Wordfence is network activated it will appear on your Network Admin menu.
    Wordfence will not appear on any individual site’s menu.
 4. Go to the «Scan» menu and start your first scan.
 5. Wordfence will do a scan of all files in your WordPress installation including 
    those in the blogs.dir directory of your individual sites.
 6. Live Traffic will appear for ALL sites in your network. If you have a heavily trafficked
    system you may want to disable live traffic which will stop logging to the DB.
 7. Firewall qoidalari va kirish qoidalari WHOLE tizimiga qo’llaniladi. Shunday qilib,
    agar siz saytga kirish 1.example.com va site2.example.com saytida tizimga kira 
    olmasangiz, bu 2 ta muvaffaqiyatsiz deb hisoblanadi. Crawler trafigi bloglar orasida
    hisobga olinadi, shuning uchun agar siz tarmoqdagi uchta saytni ursangiz, barcha
    xitlar jamlangan va bu tizimga kirish tezligingiz deb hisoblanadi.

## FAQ

[Visit our website to access our official documentation which includes security feature descriptions, common solutions and comprehensive help.](https://www.wordfence.com/help/)

### Wordfence Security qanday qilib saytlarni tajovuzkorlardan himoya qiladi?

WordPress xavfsizlik plagini veb-saytingiz uchun eng yaxshi himoyani ta’minlaydi.
Doimiy yangilanib turadigan tahdidlardan himoya qilish xizmati tomonidan yaratilgan
Wordfence Firewall sizni xakerlik hujumidan himoya qiladi. Wordfence Scan, xavfsizlik
muammolari haqida tezkor ogohlantiradigan yoki saytingiz buzilgan taqdirda sizni
ogohlantiradigan bir xil xususiy tasma vositasidan foydalanadi. Jonli tirbandlik
ko’rinishi sizga real vaqt rejimida trafikni ko’rish va veb-saytingizdagi xakerlik
urinishlarini ko’rish imkonini beradi. Mavjud WordPress-ning eng to’liq xavfsizlik
yechimini ishlab chiqadigan qo’shimcha vositalar to’plami.

### Wordfence Premium qanday xususiyatlarni yoqadi?

We offer a Premium API key that gives you real-time updates to the Threat Defense
Feed which includes a real-time IP blocklist, firewall rules, and malware signatures.
Premium support, country blocking, more frequent scans, and spam and spamvertising
checks are also included. [Click here to sign-up for Wordfence Premium now](https://www.wordfence.com/)
or simply install Wordfence free and start protecting your website.

### Wordfence WordPress Xavfsizlik devori veb-saytlarni qanday himoya qiladi?

 * Veb-dasturlar devori sizni zararli trafikni aniqlash va buzg’unchilar veb-saytingizga
   kirishdan oldin blokirovka qilish orqali sizni buzadi.
 * Threat Defense Feed avtomatik ravishda sizni so’nggi tahdidlardan himoya qiladigan
   xavfsizlik devori qoidalarini yangilaydi. Premium a’zolar real vaqtda versiyasini
   olishadi.
 * Soxta Googlebotlar, xakerlar va botnetlardan zararli skanerlar kabi umumiy WordPress
   xavfsizlik tahdidlarini bloklang.

### Wordfence Security Scanner qanday tekshiruvlarni amalga oshiradi?

 * Ularning yaxlitligini tekshirish uchun asosiy fayllarni, mavzularni va plaginlarni
   WordPress.org ombori versiyalariga skanerlaydi. Manbangiz xavfsizligini tekshiring.
 * Fayllar qanday o’zgarganiga qarang. Xavfsizlikka tahdid soluvchi o’zgartirilgan
   fayllarni ixtiyoriy ravishda tuzating.
 * 44,000 dan ortiq ma’lum zararli dasturlarning imzolarini skanerlash, ma’lum WordPress
   xavfsizlik tahdidlari.
 * C99, R57, RootShell, Crystal Shell, Matamu, Cybershell, W4cking, Snayper, Predator,
   Jackal, Phantasma, GFS, Dive, Dx va boshqa ko’plab xavfsizlik teshiklarini yaratadigan
   ko’plab skanerlash.
 * Doimiy ravishda zararli dasturlar va фишинг URL-larini, shu jumladan, barcha 
   havf-xatolar, xabarlar va fayllaringizda Google-ning xavfsiz ko’rib chiqish ro’yxatidagi
   barcha URL-larni tekshiradi.
 * Orqa eshiklar, troyanlar, shubhali kodlar va xavfsizlikning boshqa muammolari
   evristikasini tekshiradi.

### Wordfence xavfsizlikni qanday kuzatishni o’z ichiga oladi?

 * Real vaqt rejimida barcha trafikingizni ko’ring, shu jumladan robotlar, odamlar,
   404 xato, kirish va chiqish. Saytingiz xavfsizlikka qanday tahdid solishi to’g’risida
   vaziyatni anglashni yaxshilaydi.
 * Barcha trafikni, shu jumladan Javascript analitik to’plamlari sizni hech qachon
   ko’rsatmaydigan xavfsizlikka tahdid soladigan avtomatik botlarning real vaqtda
   ko’rinishi.
 * Real vaqtda trafik teskari DNS va shahar darajasidagi geolokatsiyani o’z ichiga
   oladi. Xavfsizlik tahdidi qaysi jug’rofiy hududdan kelib chiqqanligini biling.
 * Xavfsizlik bilan bog’liq disk maydonini kuzatib boradi, chunki ko’plab DDoS hujumlari
   xizmatdan voz kechish uchun barcha disk maydonini iste’mol qilishga harakat qiladi.

### Kirish xavfsizligining qanday xususiyatlari mavjud

 * Real vaqt rejimida barcha trafikingizni ko’ring, shu jumladan robotlar, odamlar,
   404 xato, kirish va chiqish. Saytingiz xavfsizlikka qanday tahdid solishi to’g’risida
   vaziyatni anglashni yaxshilaydi.
 * Barcha trafikni, shu jumladan Javascript analitik to’plamlari sizni hech qachon
   ko’rsatmaydigan xavfsizlikka tahdid soladigan avtomatik botlarning real vaqtda
   ko’rinishi.
 * Real vaqtda trafik teskari DNS va shahar darajasidagi geolokatsiyani o’z ichiga
   oladi. Xavfsizlik tahdidi qaysi jug’rofiy hududdan kelib chiqqanligini biling.
 * Xavfsizlik bilan bog’liq disk maydonini kuzatib boradi, chunki ko’plab DDoS hujumlari
   xizmatdan voz kechish uchun barcha disk maydonini iste’mol qilishga harakat qiladi.

### Agar saytimda xavfsizlik muammosi bo’lsa, qanday ogohlantirish olaman?

Wordfence elektron pochta orqali xavfsizlik haqida ogohlantirishlarni yuboradi. 
Wordfence-ni o’rnatganingizdan so’ng, xavfsizlik to’g’risida ogohlantirishlar yuboriladigan
elektron pochta manzillari ro’yxatini tuzasiz. Xavfsizlik haqida ogohlantirish olsangiz,
saytingiz xavfsizligini ta’minlash uchun zudlik bilan harakat qiling.

### Agar men bulutli xavfsizlik devori (WAF) dan foydalansam, menga Wordfence kabi plagin kerakmi?

Wordfence sizning WordPress veb-saytingiz uchun haqiqiy nuqta xavfsizligini ta’minlaydi.
Bulutli xavfsizlik devorlaridan farqli o’laroq, Wordfence WordPress muhitida ishlaydi
va unga foydalanuvchi kirgan-kirmaganligi, kimligi va qanday kirish darajasi kabi
ma’lumotlarni beradi. Wordfence WordPress veb-saytlarini himoya qilish uchun foydalanadigan
xavfsizlik devori qoidalarining 80% dan ortig’ida foydalanuvchining kirish darajasidan
foydalanadi. [Cloud WAF identifikatsiya muammosi](https://www.wordfence.com/blog/2016/10/endpoint-vs-cloud-security-cloud-waf-user-identity-problem/)
haqida ko’proq bilib oling. Bundan tashqari, bulutli xavfsizlik devorlarini chetlab
o’tish mumkin, bu sizning saytingizni tajovuzkorlarga duchor qiladi. Wordfence so’nggi
nuqtaning (sizning WordPress veb-saytingiz) ajralmas qismi bo’lgani uchun uni chetlab
o’tib bo’lmaydi. [Cloud WAF chetlab o’tish muammosi](https://www.wordfence.com/blog/2016/10/endpoint-vs-cloud-security-cloud-waf-bypass-problem/)
haqida ko’proq bilib oling. O’zingizning veb-saytingizga kiritgan sarmoyangizni 
to’liq himoya qilish uchun siz xavfsizlikka chuqur yondoshishingiz kerak. Wordfence
ushbu yondashuvni qo’llaydi.

### Wordfence qanday bloklash xususiyatlarini o’z ichiga oladi?

 * Haqiqiy vaqtda ma’lum tajovuzkorlarni blokirovka qilish. Agar Wordfence-dan foydalanuvchi
   boshqa saytga hujum qilinsa va tajovuzkorni bloklasa, saytingiz avtomatik ravishda
   himoyalanadi.
 * Barcha zararli tarmoqlarni blokirovka qiling. Yomon IP yoki tarmoqlarni xabar
   qilish va xavfsizlik devori yordamida butun tarmoqlarni blokirovka qilish uchun
   rivojlangan IP va WHOIS domenlarini o’z ichiga oladi. Tarmoq egasiga WordPress
   xavfsizlik tahdidlari to’g’risida xabar bering.
 * O’zingizning saytingizdagi zaifliklar uchun skanerlash bilan shug’ullanadigan
   tajovuzkor tarayıcılar, kazıyıcılar va botlar kabi WordPress xavfsizlik tahdidlarini
   cheklang yoki bloklang.
 * WordPress xavfsizlik qoidalarini buzadigan foydalanuvchilar va robotlarni blokirovka
   qilish yoki blokirovka qilishni xohlaysizmi, tanlang.
 * Premium foydalanuvchilar shuningdek, mamlakatlarni blokirovka qilishlari va ma’lum
   vaqt va undan yuqori chastotalarni skanerlashni rejalashtirishlari mumkin.

### Wordfence-ni boshqa WordPress Security plaginlaridan nimasi bilan farq qiladi?

 * Wordfence Security WordPress uchun maxsus ishlab chiqilgan WordPress xavfsizlik
   devori bilan ta’minlaydi va saytingizda zaiflik izlayotgan tajovuzkorlarni bloklaydi.
   Xavfsizlik devori bizning yangi tahdidlar paydo bo’lishi bilan doimiy ravishda
   yangilab turiladigan tahdidlarga qarshi mudofaa kanalimiz orqali ishlaydi. Premium
   mijozlar yangilanishlarni real vaqt rejimida olishadi.
 * Wordfence verifies your website source code integrity against the official WordPress
   repository and shows you the changes.
 * Wordfence skanerlashi sizning barcha fayllaringiz, sharhlaringiz va Google-ning
   havfsiz brauzerlari ro’yxatidagi URL-lar uchun yozuvlarni tekshiradi. Biz ushbu
   juda muhim xavfsizlikni taklif qiladigan yagona plaginmiz.
 * Wordfence skanerlari sizning keng tarmoqli kengligingizdan foydalanmaydi, chunki
   barcha xavfsizlik tekshiruvi veb-serveringizda juda tez sodir bo’ladi.
 * Wordfence WordPress Multi-Site-ni to’liq qo’llab-quvvatlaydi, bu sizning ko’p
   sahifali o’rnatilishingizda har bir blogni bir marta bosish orqali skanerlashingiz
   mumkinligini anglatadi.
 * Wordfence ikki faktorli autentifikatsiyani o’z ichiga oladi.
 * Wordfence IPv6-ni to’liq qo’llab-quvvatlaydi, shu jumladan sizga IPv6 manzillarini
   qidirish, IPv6 diapazonlarini blokirovka qilish, IPv6 mamlakatini aniqlash va
   IPv6 manzillarida kimnidir qidirish va boshqalar.

### Wordfence veb-saytimni sekinlashtiradimi?

Yo’q. Wordfence Security juda tezkor va ma’lumotlar bazasini qidirishni oldini olish
va saytingizni sekinlashtiradigan zararli hujumlarni blokirovka qilish uchun o’z
konfiguratsiya ma’lumotlarini keshlash kabi usullardan foydalanadi.

### Mening saytim allaqachon buzilgan bo’lsa-chi?

Wordfence Security is able to repair core files, themes and plugins on sites where
security is already compromised. You can follow this guide on [how to clean a hacked website using Wordfence](https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/).
If you are cleaning your own site after a hack, note that site security cannot be
assured unless you do a full reinstall if your site has been hacked. We recommend
you only use Wordfence Security to get your site into a running state in order to
recover the data you need to do a full reinstall. If you need help with a security
issue, check out [Wordfence Care](https://www.wordfence.com/products/wordfence-care/),
which offers hands-on support from our team, including dealing with a hacked site.
For mission-critical sites, check out [Wordfence Response](https://www.wordfence.com/products/wordfence-response/).

### Wordfence Security IPv6-ni qo’llab-quvvatlaydimi?

Ha. Biz IPv6-ni barcha xavfsizlik funktsiyalari, jumladan, mamlakatni blokirovka
qilish, hududni blokirovka qilish, shaharni obodonlashtirish, kimni qidirish va 
boshqa barcha xavfsizlik funktsiyalari bilan to’liq qo’llab-quvvatlaymiz. Agar siz
IPv6-ni ishlamasangiz, Wordfence saytingizda ham juda yaxshi ishlaydi. Ikkala IPv4
va IPv6 bilan ikkalasiga ham, bitta manzil sxemasiga ham to’la mos kelamiz.

### Wordfence Security ko’p saytlarni o’rnatishni qo’llab-quvvatlaydimi?

Yes. WordPress Multi-Site is fully supported. Using Wordfence you can scan every
blog in your network for malware with one click. If one of your customers posts 
a page or post with a known malware URL that threatens your whole domain with being
blocklisted by Google, we will alert you in the next scan.

### Wordfence foydalanuvchilari uchun qanday qo’llab-quvvatlash imkoniyatlari mavjud?

Providing excellent customer service is very important to us. Our free users receive
volunteer-level support in our [support forums](https://wordpress.org/support/plugin/wordfence).
[Wordfence Premium](https://www.wordfence.com/products/wordfence-premium/) customers
get paid ticket-based support. [Wordfence Care](https://www.wordfence.com/products/wordfence-care/)
customers receive hands-on support including help with security incidents and a 
yearly security audit. [Wordfence Response](https://www.wordfence.com/products/wordfence-response/)
customers get 24/7/365 support from our incident response team, with a 1 hour response
time, and a maximum of 24 hours to resolve a security issue.

### WordPress xavfsizligi haqida qaerdan ko’proq ma’lumot olishim mumkin?

Har bir mahorat darajasi uchun ishlab chiqilgan [WordPress Xavfsizlik O’quv Markazi](https://www.wordfence.com/learn/),
foydalanuvchilarning xavfsizlikka oid eng yaxshi amaliyotlar to’g’risida tushunchalarini
chuqurlashtirishga, kirish darajasidagi maqolalarga, chuqur maqolalarga, videolarga,
sanoatni o’rganish natijalariga, grafikalarga va boshqalarga bepul kirishni ta’minlaydi.

### Where can I find the Wordfence Terms of Service and Privacy Policy?

These are available on our website: [Terms of Service](https://www.wordfence.com/terms-of-service/)
and [Privacy Policy](https://www.wordfence.com/privacy-policy/)

## Reviews

![](https://secure.gravatar.com/avatar/64854f88cb0275b6063b8995d6b2864587861996d450699a9713e4dc72a458f3?
s=60&d=retro&r=g)

### 󠀁[Excellent Security Plugin](https://wordpress.org/support/topic/excellent-security-plugin-54/)󠁿

 [battal merk](https://profiles.wordpress.org/battal46ede/) Iyul 20, 2026

I’ve had a great experience with Wordfence. The installation was straightforward,
the firewall is powerful, and the malware scanning works reliably. It gives me confidence
that my site is well protected. Thank you to the development team.

![](https://secure.gravatar.com/avatar/efa6ca0fcefdc47c6dcf6071eae501c8ec87065fb52a9dd787974da294a9bc6f?
s=60&d=retro&r=g)

### 󠀁[Very strong, I feel secure 🙂](https://wordpress.org/support/topic/very-strong-i-feel-secure/)󠁿

 [gillessauliere](https://profiles.wordpress.org/gillessauliere/) Iyul 20, 2026

My website is quiet.

![](https://secure.gravatar.com/avatar/aca3f400b378c2c4a86b980f0552a9dc4bd3a612fee13aea641d94da457be02f?
s=60&d=retro&r=g)

### 󠀁[Longevity](https://wordpress.org/support/topic/longevity-4/)󠁿

 [ddwijtyk](https://profiles.wordpress.org/ddwijtyk/) Iyul 17, 2026 1 reply

We have been using Wordfence for many years and the upgrades and defenses are very
effective. The latest Wordfence seems to cover the areas of attack on websites in
a very layered fashion.

![](https://secure.gravatar.com/avatar/21921a02ac76af224849835e5fb6f6064cc2c745074b04137ef3766fde8da175?
s=60&d=retro&r=g)

### 󠀁[best security for websites](https://wordpress.org/support/topic/best-1371/)󠁿

 [shopnowbd](https://profiles.wordpress.org/shopnowbd/) Iyul 17, 2026 1 reply

i’m using free plan but i i’m satisfied .

![](https://secure.gravatar.com/avatar/3d39e9783d953b7d57008f9e56319a3efc312e427f42ab0e5e4ae5c457b20cd6?
s=60&d=retro&r=g)

### 󠀁[Useful plugin](https://wordpress.org/support/topic/useful-plugin-1148/)󠁿

 [gusbravo](https://profiles.wordpress.org/gusbravo/) Iyul 15, 2026 1 reply

Great and useful plugin to control attacks on my website

![](https://secure.gravatar.com/avatar/2a55fcc637fbe9ff239abe2cbad3aeff9608814ffef62bbbbcff4b6359336152?
s=60&d=retro&r=g)

### 󠀁[A great assistant](https://wordpress.org/support/topic/a-great-assistant/)󠁿

 [Atef G](https://profiles.wordpress.org/atefgomaa/) Iyul 14, 2026 1 reply

This is a great assistant and reliable partner securing and protecting our website–
Thank you Atef G.

 [ Read all 4 957 reviews ](https://wordpress.org/support/plugin/wordfence/reviews/)

## Contributors & Developers

“Wordfence Security – Firewall, Malware Scan, and Login Security” is open source
software. The following people have contributed to this plugin.

Contributors

 *   [ Mark Maunder ](https://profiles.wordpress.org/mmaunder/)
 *   [ wfryan ](https://profiles.wordpress.org/wfryan/)
 *   [ wfmatt ](https://profiles.wordpress.org/wfmatt/)
 *   [ WFMattR ](https://profiles.wordpress.org/wfmattr/)

“Wordfence Security – Firewall, Malware Scan, and Login Security” has been translated
into 27 locales. Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/wordfence/contributors)
for their contributions.

[Translate “Wordfence Security – Firewall, Malware Scan, and Login Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/wordfence)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/wordfence/), check 
out the [SVN repository](https://plugins.svn.wordpress.org/wordfence/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/wordfence/) by [RSS](https://plugins.trac.wordpress.org/log/wordfence/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 8.2.2 – May 13, 2026

 * Improvement: Better presentation of Live Traffic data on wide screens
 * Improvement: Increased legibility of token fields
 * Improvement: Reworked the pagination of the Blocking page for a better UX
 * Improvement: Country blocking token field can now expand to show all entries
 * Improvement: Performance improvements for the activity log and better pause behavior
   on window blur/focus
 * Improvement: GeoIP database updated
 * Change: Removed deprecated Central endpoint
 * Fix: Addressed issue where the last activity log entry could repeatedly appear
 * Fix: Using the embedded shortcode for the 2FA form now correctly enqueues core
   JavaScript dependencies
 * Fix: Modals with content that overflows on smaller viewports can now be scrolled
 * Fix: The changelog link in plugin upgrade scan issues now links correctly

#### 8.2.1 – May 6, 2026

 * Fix: Fixed issue with some i18n plugins/themes when a user has no 2FA recovery
   codes
 * Fix: Toggled options with additional help links now correctly open the link rather
   than toggling the option
 * Fix: Country Blocking editing fixed when there are multiple pages of block rules
 * Fix: Added better error handling to the initial Vue data load
 * Fix: Handled error when logging in using legacy 2FA with separate prompts enabled

#### 8.2.0 – April 29, 2026

 * Improvement: Migrated all deprecated JavaScript libraries in use to a Vue-based
   infrastructure
 * Improvement: GeoIP database update
 * Improvement: Better coverage of `aria-` accessibility attributes
 * Improvement: Added `translators` comments to translatable strings where previously
   missing
 * Fix: WordPress 7.0 compatibility fixes
 * Note: Legacy two factor authentication using SMS-based codes will be discontinued
   around July 1, 2026. Sites using this functionality should migrate users to the
   TOTP-based two factor authentication on the Login Security page of the plugin

#### 8.1.4 – December 20, 2025

 * Fix: Fixed an issue with `inet_pton` introduced by a recent patch to PHP 8.1+
   that could cause a fatal error if a malformed IP address was passed to the call

#### 8.1.3 – December 3, 2025

 * Improvement: Updated the bundled geoip database
 * Note: Verified compatibility with WordPress 6.9

#### 8.1.2 – November 12, 2025

 * Improvement: Updated the bundled geoip database

#### 8.1.1 – November 5, 2025

 * Improvement: Improved localization support for the various block screens and 
   messages
 * Improvement: Updated the bundled geoip database
 * Improvement: Prioritized Wordfence tables in the diagnostics tool when large 
   numbers of tables exist
 * Improvement: Allow non-US Google crawler IP addresses to pass country blocking
 * Improvement: Enforcement of password strength requirements is now applied on 
   the corresponding REST API endpoints
 * Fix: Fixed detection for first-time logins and overall sending for login alerts
   when the corresponding settings are enabled
 * Fix: When the WAF is using the mysql storage engine, fixed an issue with exclusion
   rules for the WAF not running correctly
 * Fix: Reduced per-hit database query load around checking license status for free
   installations
 * Fix: Optimized data sync with the WAF to better detect when the known server 
   IP address list has changed

#### 8.1.0 – August 25, 2025

 * Improvement: Added password scanning support for WordPress 6.8 and later
 * Improvement: Limited email alerts to 5 per hour by default and added notification
   when limit has been reached
 * Improvement: Improved URL scanning performance
 * Improvement: Updated GeoIP database
 * Change: Reduced scan result severity for vulnerabilities with high attack complexity
   or required privileges
 * Change: Added messaging around WAF support when NGINX Unit is detected
 * Change: Added notice and scan result about Wordfence Assistant
 * Change: Adjusted IPv6 connection issue message and appearance
 * Fix: Prevented deprecation notice about calling base64_encode with null parameter
 * Fix: Prevented deprecation message about calling preg_match with null parameter
 * Fix: Corrected license type shown on dashboard when expiring
 * Fix: Prevented disabled getmyuid function from causing fatal error
 * Fix: Prevented disabled get_current_user function from causing fatal error
 * Fix: Prevented notice about _load_textdomain_just_in_time being called incorrectly

#### 8.0.5 – April 8, 2025

 * Fix: Compatibility fixes for WordPress 6.8

#### 8.0.4 – March 19, 2025

 * Improvement: Improved error handling and messaging for some responses from our
   servers
 * Improvement: Added messaging when a site may be using the same free license shared
   among multiple sites because it can cause the sites to use the same scan schedule
   rather than spreading out the load
 * Improvement: Updated the readme content and formatting

#### 8.0.3 – January 15, 2025

 * Improvement: Added support for hosts relocating the WAF’s auto-prepend file via
   the constant/envvar WORDFENCE_WAF_PREPEND_DIRECTORY
 * Improvement: Added detection for non-repo plugins and themes to avoid the scanner
   reporting changes when the same slug + version exists within the wordpress.org
   repo
 * Improvement: Messaging for Central disconnections now better reflects the user
   making the change
 * Improvement: Scan errors due to unreachable Wordfence servers will now provide
   a link to our status page to check for outages
 * Improvement: Reduced the number of network calls created to sync scan issues 
   when updates are performed in bulk
 * Change: Reworked setting caching to avoid issues with some object caches
 * Change: Reworked cURL check to avoid using WP_Http_Curl, which has been deprecated
 * Fix: Normalized all wordfence.com links to be https
 * Fix: Fixed a rare error that could occur on the diagnostics page when displaying
   a list of error logs
 * Fix: Removed the «back to top» button and related script block from emailed diagnostics
 * Fix: Fixed some UI coloring that did not correctly reflect the license type in
   use

#### 8.0.2 – January 2, 2025

 * Improvement: General compatibility improvements and better error handling for
   PHP 8+
 * Improvement: Added audit log status to the plugin dashboard
 * Change: Increased width of diagnostics text export for better legibility
 * Fix: Addressed an error with mail hooks and the audit log when third party plugins
   send unexpected value types

#### 8.0.1 – November 14, 2024

 * Improvement: Updated GeoIP database
 * Change: Revised some help text related to the audit log to be more clear
 * Fix: Improved audit log compatibility with some plugins that would cause excessive
   noise due to their behaviors around setting up user roles and capabilities
 * Fix: Fixed a log notice that could occur when deactivating Wordfence with audit
   log events still pending and a broken Wordfence Central link

#### 8.0.0 – November 4, 2024

 * Improvement: Introduced the Wordfence Audit Log, a new premium feature to monitor
   all changes and actions in security-sensitive areas of the site with remote tamper-
   proof data storage via Wordfence Central
 * Change: Increased the minimum supported WordPress version to 4.7
 * Change: Increased the minimum supported PHP version to 7.0

#### 7.11.7 – July 29, 2024

 * Improvement: Optimized scan performance by reducing database queries by approximately
   38% along with CPU usage
 * Fix: Added translation support for «Page not found» string when viewing recent
   traffic

#### 7.11.6 – June 6, 2024

 * Improvement: Revised the strong password requirements notice to be more readable
 * Improvement: Removed unnecessary calls for the plugin and theme vulnerability
   checks
 * Improvement: Reduced the frequency of calls to Wordfence Central during some 
   operations where the values do not need to be synced
 * Improvement: Refactored some queries to avoid the automatic SHOW FULL COLUMNS
   queries that WordPress performs to verify database encodings
 * Improvement: Infrequently-used config values are no longer automatically loaded
   into memory and instead loaded only on demand
 * Fix: Fixed an issue where multisite installations using the WAF mysqli storage
   engine could repeatedly attempt to update WAF rules when not in optimized mode
 * Improvement: Updated the bundled GeoIP database
 * Change: Revised the formatting of TOTP app URLs to prioritize the site’s own 
   URL for better sorting and display
 * Fix: Fixed the last captcha column in the users page so it no longer displays«(
   not required)» on 2FA users since that no longer applies
 * Fix: Added a check in wflogs/rules.php to only run when within the WAF’s bootstrap
   stage when hosted behind nginx

#### 7.11.5 – April 3, 2024

 * Fix: Revised the behavior of the reCAPTCHA verification to use the documented
   expiration period of the token and response to avoid sending verification requests
   too frequently, which could artificially lower scores in some circumstances
 * Fix: Addressed PHP 8 deprecation notices in the file differ used by file changed
   scan results
 * Fix: Reduced the frequency of Wordfence Central status update callbacks in sections
   of the scan that occur quickly in sequence

#### 7.11.4 – March 11, 2024

 * Change: CAPTCHA verification when enabled now additionally applies to 2FA logins(
   may send an email verification on low scores) and no longer reveals whether a
   user exists for the submitted account credentials (credit: Raxis)
 * Fix: Addressed a potential PHP 8 notice in the human/bot detection AJAX call
 * Fix: Addressed a potential PHP 8 notice when requesting a lockout unlock verification
   email
 * Fix: Fixed the emailed diagnostics view not showing the missing table information
   when applicable
 * Fix: Improved quick scan logic to base timing on regular scans so they’re more
   evenly distributed

#### 7.11.3 – February 15, 2024

 * Fix: Fixed an issue with sites containing invalid Wordfence Central site data
   where they could throw an error when viewing Wordfence pages

#### 7.11.2 – February 14, 2024

 * Improvement: Enhanced the vulnerability scan to check and alert for WordPress
   core vulnerabilities and to adjust the severity of the scan result based on findings
   or available updates
 * Improvement: Updated the bundled GeoIP database
 * Improvement: Increased compatibility of brute force protection with plugins that
   override the normal login flow and omit traditional hooks
 * Change: Adjusted the behavior of automatic quick scans to schedule themselves
   further away from full scans
 * Fix: Added detection for a site being linked to a non-matching Wordfence Central
   record (e.g., when cloning the database to a staging site)
 * Fix: Streamlined the license and terms of use installation flow to avoid unnecessary
   prompting
 * Fix: Fixed an issue where user profiles with a selected locale different from
   the site itself could end up loading the site’s locale instead

#### 7.11.1 – January 2, 2024

 * Improvement: Added «.env» to the files checked for «Scan for publicly accessible
   configuration, backup, or log files»
 * Improvement: Provided better descriptive text for the option «Block IPs who send
   POST requests with blank User-Agent and Referer»
 * Improvement: The diagnostics page now displays the contents of any `auto_prepend_file`.
   htaccess/.user.ini block for troubleshooting
 * Fix: Fixed an issue where a login lockout on a WooCommerce login form could fail
   silently
 * Fix: The scan result for abandoned plugins no longer states it has been removed
   from wordpress.org if it is still listed
 * Fix: Addressed an exception parsing date information in non-repo plugins that
   have a bad `last_updated` value
 * Fix: The URL scanner no longer generates a log warning when matching a potential
   URL fragment that ends up not being a valid URL

#### 7.11.0 – November 28, 2023

 * Improvement: Added new functionality for trusted proxy presets to support proxies
   such as Amazon CloudFront, Ezoic, and Quic.cloud
 * Improvement: WAF rule and malware signature updates are now signed with SHA-256
   as well for hosts that no longer build SHA1 support
 * Improvement: Updated the bundled trusted CA certificates
 * Change: The WAF will no longer attempt to fetch rule or blocklist updates when
   run via WP-CLI
 * Fix: Removed uses of SQL_CALC_FOUND_ROWS, which is deprecated as of MySQL 8.0.17
 * Fix: Fixed an issue where final scan summary counts in some instances were not
   sent to Central
 * Fix: Fixed a deprecation notice for get_class in PHP 8.3.0
 * Fix: Corrected an output error in the connectivity section of Diagnostics in 
   text mode

#### 7.10.7 – November 6, 2023

 * Fix: Compatibility fix for WordPress 6.4 on the login page styling

#### 7.10.6 – October 30, 2023

 * Fix: Addressed an issue with multisite installations when the wp_options tables
   had different encodings/collations

#### 7.10.5 – October 23, 2023

 * Improvement: Updated the bundled GeoIP database
 * Improvement: Added detection for Cloudflare reverse proxies blocking callbacks
   to the site
 * Change: Files are no longer excluded from future scans if a previous scan stopped
   during their processing
 * Fix: Added handling for the pending WordPress 6.4 change that removes $wpdb->
   use_mysqli
 * Fix: The WAF MySQLi storage engine will now work correctly when either DB_COLLATE
   or DB_CHARSET are not defined
 * Fix: Added additional error handling to Central calls to better handle request
   failures or conflicts
 * Fix: Addressed a warning that would occur if a non-repo plugin update hook did
   not provide a last updated date
 * Fix: Fixed an error in PHP 8 that could occur if the time correction offset was
   not numeric
 * Fix: 2FA AJAX calls now use an absolute path rather than a full URL to avoid 
   CORS issues on sites that do not canonicalize www and non-www requests
 * Fix: Addressed a race condition where multiple concurrent hits on multisite could
   trigger overlapping role sync tasks
 * Fix: Improved performance when viewing the user list on large multisites
 * Fix: Fixed a UI bug where an invalid code on 2FA activation would leave the activate
   button disabled
 * Fix: Reverted a change on error modals to bring back the additional close button
   for better accessibility

#### 7.10.4 – September 25, 2023

 * Improvement: «Admin created outside of WordPress» scan results may now be reviewed
   and approved
 * Improvement: The WAF storage engine may now be specified by setting the environmental
   variable «WFWAF_STORAGE_ENGINE»
 * Improvement: Detect when a plugin or theme with a custom update handler is broken
   and blocking update version checks
 * Change: Deprecated support for WordPress versions lower than 4.7.0
 * Change: Exclude parse errors of a damaged compiled rules file from reporting
 * Fix: Suppress PHP notices related to rule loading when running WP-CLI
 * Fix: Fixed an issue with the scan monitor cron that could leave it running unnecessarily

#### 7.10.3 – July 31, 2023

 * Improvement: Updated GeoIP database
 * Fix: Added missing text domain to translation function call
 * Fix: Corrected inconsistent styling of switch controls
 * Change: Made MySQLi storage engine the default for Flywheel hosted sites

#### 7.10.2 – July 17, 2023

 * Fix: Prevented bundled sodium_compat library from conflicting with versions included
   with older WordPress versions

#### 7.10.1 – July 12, 2023

 * Improvement: Added support for processing arrays of files in the WAF
 * Improvement: Refactored security event processing to send events in bulk
 * Improvement: Updated bundled sodium_compat and random_compat libraries
 * Fix: Prevented deprecation warning caused by dynamic property creation
 * Fix: Added translation support for additional strings
 * Change: Adjusted Wordfence registration UI

#### 7.10.0 – June 21, 2023

 * Improvement: Added translation support for strings from login security plugin
 * Improvement: Added translator notes regarding word order and hidden text
 * Improvement: Added translation support for additional strings
 * Improvement: Prevented scans from failing if unreadable directories are encountered
 * Improvement: Added help link to IPv4 scan option
 * Improvement: Updated scan result text to clarify meaning of plugins removed from
   wordpress.org
 * Improvement: Made «Increased Attack Rate» emails actionable
 * Improvement: Updated GeoIP database
 * Improvement: Updated JavaScript libraries
 * Fix: Corrected IPv6 address expansion
 * Fix: Ensured long request payloads for malicious requests are recorded in live
   traffic
 * Fix: Prevented «commands out of sync» database error messages when the database
   connection has failed
 * Fix: Prevented rare JSON encoding issues from breaking free license registration
 * Fix: Prevented PHP notice from being logged when request parameter is missing
 * Fix: Prevented deprecation warning in PHP 8.1
 * Change: Moved detection for old TimThumb files to malware signature
 * Change: Moved translation file from .po to .pot
 * Change: Renamed «Macedonia» to «North Macedonia, Republic of»

#### 7.9.3 – May 31, 2023

 * Improvement: Added exception handling to prevent WAF errors from being fatal
 * Fix: Corrected error caused by method call on null in WAF
 * Change: Deprecated support for PHP 5.5 and 5.6, ended support for PHP 5.3 and
   5.4
 * Change: Specified WAF version parameter when requesting firewall rules

#### 7.9.2 – March 27, 2023

 * Improvement: The vulnerability severity score (CVSS) is now shown with any vulnerability
   findings from the scanner
 * Improvement: Changed several links during initial setup to open in a new window/
   tab so it doesn’t interrupt installation
 * Change: Removed the non-https callback test to the Wordfence servers
 * Fix: Fixed an error on PHP 8 that could occur when checking for plugin updates
   and another plugin has a broken hook
 * Fix: Added a check for disabled functions when generating support diagnostics
   to avoid an error on PHP 8
 * Fix: Prevent double-clicking when activating 2FA to avoid an «already set up»
   error

#### 7.9.1 – March 1, 2023

 * Improvement: Further improved performance when viewing 2FA settings and hid user
   counts by default on sites with many users
 * Fix: Adjusted style inclusion and usage to prevent missing icons
 * Fix: Avoided using the ctype extension as it may not be enabled
 * Fix: Prevented fatal errors caused by malformed Central keys

#### 7.9.0 – February 14, 2023

 * Improvement: Added 2FA management shortcode and WooCommerce account integration
 * Improvement: Improved performance when viewing 2FA settings on sites with many
   users
 * Improvement: Updated GeoIP database
 * Fix: Ensured Captcha and 2FA scripts load on WooCommerce when activated on a 
   sub-site in multisite
 * Fix: Prevented reCAPTCHA logo from being obscured by some themes
 * Fix: Enabled wfls_registration_blocked_message filter support for WooCommerce
   integration

#### 7.8.2 – December 13, 2022

 * Fix: Releasing same changes as 7.8.1, due to wordpress.org error

#### 7.8.1 – December 13, 2022

 * Improvement: Added more granualar data deletion options to deactivation prompt
 * Improvement: Allowed accessing diagnostics prior to completing registration
 * Fix: Prevented installation prompt from displaying when a license key is already
   installed but the alert email address has been removed

#### 7.8.0 – November 28, 2022

 * Improvement: Added feedback when login form is submitted with 2FA
 * Fix: Restored click support on login button when using 2FA with WooCommerce
 * Fix: Corrected display issue with reCAPTCHA score history graph
 * Fix: Prevented errors on PHP caused by corrupted login timestamps
 * Fix: Prevented deprecation notices on PHP 8.2 related to dynamic properties
 * Change: Updated Wordfence registration workflow

#### 7.7.1 – October 4, 2022

 * Fix: Prevented scan resume attempts from repeating indefinitely when the initial
   scan stage fails

#### 7.7.0 – October 3, 2022

 * Improvement: Added configurable scan resume functionality to prevent scan failures
   on sites with intermittent connectivity issues
 * Improvement: Added new scan result for vulnerabilities found in plugins that 
   do not have patched versions available via WordPress.org
 * Improvement: Implemented stand-alone MMDB reader for IP address lookups to prevent
   plugin conflicts and support additional PHP versions
 * Improvement: Added option to disable looking up IP address locations via the 
   Wordfence API
 * Improvement: Prevented successful logins from resetting brute force counters
 * Improvement: Clarified IPv6 diagnostic
 * Improvement: Included maximum number of days in live traffic option text
 * Fix: Made timezones consistent on firewall page
 * Fix: Added «Use only IPv4 to start scans» option to search
 * Fix: Prevented deprecation notices on PHP 8.1 when emailing the activity log
 * Fix: Prevented warning on PHP 8 related to process owner diagnostic
 * Fix: Prevented PHP Code Sniffer false positive related to T_BAD_CHARACTER
 * Fix: Removed unsupported beta feed option

#### 7.6.2 – September 19, 2022

 * Improvement: Hardened 2FA login flow to reduce exposure in cases where an attacker
   is able to obtain privileged information from the database

#### 7.6.1 – September 6, 2022

 * Fix: Prevented XSS that would have required admin privileges to exploit (CVE-
   2022-3144)

#### 7.6.0 – July 28, 2022

 * Improvement: Added option to start scans using only IPv4
 * Improvement: Added diagnostic for internal IPv6 connectivity to site
 * Improvement: Added AUTOMATIC_UPDATER_DISABLED diagnostic
 * Improvement: Updated password strength check
 * Improvement: Added support for scanning plugin/theme files in when using the 
   WP_CONTENT_DIR/WP_PLUGIN_DIR constants
 * Improvement: Updated GeoIP database
 * Improvement: Made DISABLE_WP_CRON diagnostic more clear
 * Improvement: Added «Hostname» to Live Traffic message displayed for hostname 
   blocking
 * Improvement: Improved compatibility with Flywheel hosting
 * Improvement: Adopted semantic versioning
 * Improvement: Added support for dynamic cookie redaction patterns when logging
   requests
 * Fix: Prevented scanned paths from being displayed as skipped in rare cases
 * Fix: Corrected indexed files count in scan messages
 * Fix: Prevented overlapping AJAX requests when viewing Live Traffic on slower 
   servers
 * Fix: Corrected WP_DEBUG_DISPLAY diagnostic
 * Fix: Prevented extraneous warnings caused by DNS resolution failures
 * Fix: Corrected display issue with Save/Cancel buttons on All Options page
 * Fix: Prevented errors caused by WHOIS searches for invalid values

#### 7.5.11 – June 14, 2022

 * Improvement: Added option to toggle display of last login column on WP Users 
   page
 * Improvement: Improved autocomplete support for 2FA code on Apple devices
 * Improvement: Prevented Batcache from caching block pages
 * Improvement: Updated GeoIP database
 * Fix: Prevented extraneous scan results when non-existent paths are configured
   using UPLOADS and related constants
 * Fix: Corrected issue that prevented reCAPTCHA scores from being recorded
 * Fix: Prevented invalid JSON setting values from triggering fatal errors
 * Fix: Made text domains consistent for translation support
 * Fix: Clarified that allowlisted IP addresses also bypass reCAPTCHA

#### 7.5.10 – May 17, 2022

 * Improvement: Improved scan support for sites with non-standard directory structures
 * Improvement: Increased accuracy of executable PHP upload detection
 * Improvement: Addressed various deprecation notices with PHP 8.1
 * Improvement: Improved handling of invalidated license keys
 * Fix: Corrected lost password redirect URL when used with WooCommerce
 * Fix: Prevented errors when live traffic data exceeds database column length
 * Fix: Prevented bulk password resets from locking out admins
 * Fix: Corrected issue that prevented saving country blocking settings in certain
   cases
 * Change: Updated copyright information

#### 7.5.9 – March 22, 2022

 * Improvement: Updated GeoIP database
 * Improvement: Removed blocking data update logic in order to reduce timeouts
 * Improvement: Increased timeout value for API calls in order to reduce timeouts
 * Improvement: Clarified notification count on Wordfence menu
 * Improvement: Improved scan compatibility with WooCommerce
 * Improvement: Added messaging when application passwords are disabled
 * Fix: Prevented warnings and errors when constants are defined based on the value
   of other constants in wp-config.php
 * Fix: Corrected redundant escaping that prevented viewing or repairing files in
   scan results

#### 7.5.8 – February 1, 2022

 * Launch of Wordfence Care and Wordfence Response

#### 7.5.7 – November 22, 2021

 * Improvement: Made preliminary changes for compatibility with PHP 8.1
 * Change: Added GPLv3 license and updated EULA

#### 7.5.6 – October 18, 2021

 * Fix: Prevented login errors with WooCommerce integration when manual username
   entry is enabled on the WooCommerce registration form
 * Fix: Corrected theme incompatibilities with WooCommerce integration

#### 7.5.5 – August 16, 2021

 * Improvement: Enhanced accessibility
 * Improvement: Replaced regex in scan log with signature ID
 * Improvement: Updated Knockout JS dependency to version 3.5.1
 * Improvement: Removed PHP 8 compatibility notice
 * Improvement: Added NTP status for Login Security to Diagnostics
 * Improvement: Updated plugin headers for compatibility with WordPress 5.8
 * Improvement: Updated Nginx documentation links to HTTPS
 * Improvement: Updated IP address geolocation database
 * Improvement: Expanded WAF SQL syntax support
 * Improvement: Added optional constants to configure WAF database connection
 * Improvement: Added support for matching punycode domain names
 * Improvement: Updated Wordfence install count
 * Improvement: Deprecated support for WordPress versions older than 4.4.0
 * Improvement: Added warning messages when blocking U.S.
 * Improvement: Added MYSQLI_CLIENT_SSL support to WAF database connection
 * Improvement: Added 2FA and reCAPTCHA support for WooCommerce login and registration
   forms
 * Improvement: Added option to require 2FA for any role
 * Improvement: Added logic to automatically disable NTP after repeated failures
   and option to manually disable NTP
 * Improvement: Updated reCAPTCHA setup note
 * Fix: Prevented issue where country blocking changes are not saved
 * Fix: Corrected string placeholder
 * Fix: Added missing text domain to translation calls
 * Fix: Corrected warning about sprintf arguments on Central setup page
 * Fix: Prevented lost password functionality from revealing valid logins

#### 7.5.4 – June 7, 2021

 * Fix: Resolve conflict with woocommerce-gateway-amazon-payments-advanced plugin

#### 7.5.3 – May 10, 2021

 * Improvement: Expanded WAF capabilities including better JSON and user permission
   handling
 * Improvement: Switched to relative paths in WAF auto_prepend file to increase 
   portability
 * Improvement: Eliminated unnecessary calls to Wordfence servers
 * Fix: Prevented errors on PHP 8.0 when disk_free_space and/or disk_total_space
   are included in disabled_functions
 * Fix: Fixed PHP notices caused by unexpected plugin version data
 * Fix: Gracefully handle unexpected responses from Wordfence servers
 * Fix: Time field now displays correctly on «See Recent Traffic» overlay
 * Fix: Corrected typo on Diagnostics page
 * Fix: Corrected IP counts on activity report
 * Fix: Added missing line break in scan result emails
 * Fix: Sending test activity report now provides success/failure response
 * Fix: Reduced SQLi false positives caused by comma-separated strings
 * Fix: Fixed JS error when resolving last scan result

#### 7.5.2 – March 24, 2021

 * Fix: Fixed fatal error on single-sites running WordPress <4.9.

#### 7.5.1 – March 24, 2021

 * Fix: Fixed fatal error when viewing the Login Security settings page from an 
   allowlisted IP.

#### 7.5.0 – March 24, 2021

 * Improvement: Translation-readiness: All user-facing strings are now run through
   WordPress’s i18n functions.
 * Improvement: Remove legacy admin functions no longer used within the UI.
 * Improvement: Local GeoIP database update.
 * Improvement: Remove Lynwood IP range from allowlist, and add new AWS IP range.
 * Fix: Fixed bug with unlocking a locked out IP without correctly resetting its
   failure counters.
 * Fix: Sites using deleted premium licenses correctly revert to free license behavior.
 * Fix: When enabled, cookies are now set for the correct roles on previously used
   devices.
 * Fix: WAF cron jobs are now skipped when running on the CLI.
 * Fix: PHP 8.0 compatibility – prevent syntax error when linting files.
 * Fix: Fixed issue where PHP 8 notice sometimes cannot be dismissed.

#### 7.4.14 – December 3, 2020

 * Improvement: Added option to disable application passwords.
 * Improvement: Updated site cleaning callout with 1-year guarantee.
 * Improvement: Upgraded sodium_compat library to 1.13.0.
 * Improvement: Replaced the terms whitelist and blacklist with allowlist and blocklist.
 * Improvement: Made a number of WordPress 5.6 and jQuery 3.x compatibility improvements.
 * Improvement: Made a number of PHP8 compatilibility improvements.
 * Improvement: Added dismissable notice informing users of possible PHP8 compatibility
   issues.

#### 7.4.12 – October 21, 2020

 * Improvement: Initial integration of i18n in Wordfence.
 * Improvement: Prevent Wordfence from loading under <PHP 5.3.
 * Yaxshilash: yangilangan GeoIP ma’lumotlar bazasi.
 * Improvement: Prevented wildcard from running/saving for scan’s excluded files
   pattern.
 * Improvement: Included Wordfence Login Security tables in diagnostics missing 
   table list.
 * Fix: Removed new scan issues when WordPress update occurs mid-scan.
 * Fix: Specified category when saving `whitelistedServiceIPs` to WAF storage engine.
 * Fix: Removed localhost IP for auto-update email alerts.
 * Fix: Fixed broken message in Live Traffic with MySQLi storage engine for blocklisted
   hits.
 * Fix: Removed optional parameter values for PHP 8 compatibility.

[O’zgarish](https://www.wordfence.com/help/advanced/changelog/) ma’lumotlarini bizning
hujjatlarimiz saytidan topishingiz mumkin.

## Commercial plugin

This plugin is free but offers additional paid commercial upgrades or support. [View support](https://support.wordfence.com/)

## Meta

 *  Version **8.2.2**
 *  Last updated **2 oy ago**
 *  Active installations **5+ million**
 *  WordPress version ** 4.7 or higher **
 *  Tested up to **7.0.2**
 *  PHP version ** 7.0 or higher **
 *  Languages
 * [Chinese (China)](https://cn.wordpress.org/plugins/wordfence/), [Chinese (Taiwan)](https://tw.wordpress.org/plugins/wordfence/),
   [Czech](https://cs.wordpress.org/plugins/wordfence/), [Dutch](https://nl.wordpress.org/plugins/wordfence/),
   [Dutch (Belgium)](https://nl-be.wordpress.org/plugins/wordfence/), [English (Canada)](https://en-ca.wordpress.org/plugins/wordfence/),
   [English (South Africa)](https://en-za.wordpress.org/plugins/wordfence/), [English (UK)](https://en-gb.wordpress.org/plugins/wordfence/),
   [English (US)](https://wordpress.org/plugins/wordfence/), [French (Canada)](https://fr-ca.wordpress.org/plugins/wordfence/),
   [Gujarati](https://gu.wordpress.org/plugins/wordfence/), [Hungarian](https://hu.wordpress.org/plugins/wordfence/),
   [Japanese](https://ja.wordpress.org/plugins/wordfence/), [Korean](https://ko.wordpress.org/plugins/wordfence/),
   [Lao](https://lo.wordpress.org/plugins/wordfence/), [Persian](https://fa.wordpress.org/plugins/wordfence/),
   [Polish](https://pl.wordpress.org/plugins/wordfence/), [Portuguese (Brazil)](https://br.wordpress.org/plugins/wordfence/),
   [Russian](https://ru.wordpress.org/plugins/wordfence/), [Spanish (Argentina)](https://es-ar.wordpress.org/plugins/wordfence/),
   [Spanish (Chile)](https://cl.wordpress.org/plugins/wordfence/), [Spanish (Colombia)](https://es-co.wordpress.org/plugins/wordfence/),
   [Spanish (Ecuador)](https://es-ec.wordpress.org/plugins/wordfence/), [Spanish (Mexico)](https://es-mx.wordpress.org/plugins/wordfence/),
   [Spanish (Spain)](https://es.wordpress.org/plugins/wordfence/), [Spanish (Venezuela)](https://ve.wordpress.org/plugins/wordfence/),
   [Turkish](https://tr.wordpress.org/plugins/wordfence/) va [Vietnamese](https://vi.wordpress.org/plugins/wordfence/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/wordfence)
 * Tags
 * [2FA](https://uz.wordpress.org/plugins/tags/2fa/)[firewall](https://uz.wordpress.org/plugins/tags/firewall/)
   [malware](https://uz.wordpress.org/plugins/tags/malware/)[scanner](https://uz.wordpress.org/plugins/tags/scanner/)
   [security](https://uz.wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://uz.wordpress.org/plugins/wordfence/advanced/)

## Ratings

 4.7 out of 5 stars.

 *  [  4 469 5-star reviews     ](https://wordpress.org/support/plugin/wordfence/reviews/?filter=5)
 *  [  118 4-star reviews     ](https://wordpress.org/support/plugin/wordfence/reviews/?filter=4)
 *  [  69 3-star reviews     ](https://wordpress.org/support/plugin/wordfence/reviews/?filter=3)
 *  [  45 2-star reviews     ](https://wordpress.org/support/plugin/wordfence/reviews/?filter=2)
 *  [  256 1-star reviews     ](https://wordpress.org/support/plugin/wordfence/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/wordfence/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

## Contributors

 *   [ Mark Maunder ](https://profiles.wordpress.org/mmaunder/)
 *   [ wfryan ](https://profiles.wordpress.org/wfryan/)
 *   [ wfmatt ](https://profiles.wordpress.org/wfmatt/)
 *   [ WFMattR ](https://profiles.wordpress.org/wfmattr/)

## Support

Issues resolved in last two months:

     101 out of 137

 [View support forum](https://wordpress.org/support/plugin/wordfence/)