Title: VMP Security &#8211; Firewall, Malware Scan, and Login Security
Author: VMP™
Published: <strong>October 30, 2025</strong>
Last modified: May 14, 2026

---

Search plugins

![](https://ps.w.org/vmpfence-security/assets/banner-772x250.png?rev=3477795)

![](https://ps.w.org/vmpfence-security/assets/icon.svg?rev=3475410)

# VMP Security – Firewall, Malware Scan, and Login Security

 By [VMP™](https://profiles.wordpress.org/tanveer269/)

[Download](https://downloads.wordpress.org/plugin/vmpfence-security.2.3.0.zip)

 * [Details](https://test.wordpress.org/plugins/vmpfence-security/#description)
 * [Reviews](https://test.wordpress.org/plugins/vmpfence-security/#reviews)
 *  [Installation](https://test.wordpress.org/plugins/vmpfence-security/#installation)
 * [Development](https://test.wordpress.org/plugins/vmpfence-security/#developers)

 [Support](https://wordpress.org/support/plugin/vmpfence-security/)

## Description

**POWERFUL WORDPRESS SECURITY, FIREWALL & MALWARE SCANNER PLUGIN**

Every day, 3,500 websites are **hacked** or infected with **malware**. Don’t leave
your site exposed. VMP Security is a powerful WordPress security plugin that gives
you 750+ **firewall rules**, 9 specialized **malware scanners**, 170,000+ threat
signatures, country blocking, audit log preview, **two-factor authentication**, 
and **brute force protection**. Free runs the full rule set and signature corpus
on your site — new additions reach Free 30 days after Premium. Everything runs on
your server, ensuring full website security and data privacy. Your files and database
never leave your hosting environment.

Remember, most WordPress security plugins hold back critical protection behind paywalls
or delay updates for free users.
 [VMP Security](https://vmpsecurity.com/) doesn’t.

### What’s Included

✅ **Web Application Firewall** — 750+ rules running on your site (new rule additions
reach Free 30 days after Premium), zero-day detection, pre-WordPress execution mode

✅ **9 Malware Scanners** — Malware, file integrity, CVE, user accounts, content,
public files, server state, binary, domain reputation ✅ **Country Blocking** — 
Block by country, login-only or full-site (free — competitors charge for this) ✅**
Brute Force & Rate Limiting** — Login limits, leaked password detection, bot throttling
✅ **Two-Factor Authentication** — QR setup, backup codes, role enforcement, WooCommerce
support ✅ **Audit Log & Live Traffic** — Complete security event history with real-
time monitoring ✅ **Privacy-First** — All scanning on your server. Files and database
never sent externally.

### See It In Action

### How VMP Security Compares

    ```
    +------------------------------+-------------------+-------------------+----------------------------+
    | Feature                      | VMP Security Free | Wordfence Free    | Wordfence Premium ($149/yr)|
    +------------------------------+-------------------+-------------------+----------------------------+
    | Firewall rules               | ✅ - 750+        | ✅                 | ✅                         |
    | Real-time rule updates       | ❌ - 30-day delay| ❌ - 30-day delay | ✅                         |
    | Malware signatures           | ✅ - 170,000+    | ✅                 | ✅ - 195,000+              |
    | Real-time signature updates  | ❌ - 30-day delay| ❌ - 30-day delay | ✅                         |
    | Malware scanners             | ✅ 9 specialized | ✅ 1 general      | ✅ 1 general               |
    | Country blocking             | ✅               | ❌                | ✅                         | 
    | Audit log                    | ✅               | ❌                | ✅                         |
    | IP blocklist                 | ✅               | ❌                | ✅                         |
    | Two-factor authentication    | ✅               | ✅                | ✅                         |
    +------------------------------+-------------------+-------------------+----------------------------+
    ```

### 🔥 Web Application Firewall (WAF)

Your first line of defense. Every request is inspected before it reaches WordPress.
Blocks malicious traffic in real time, stopping threats before they can execute 
or exploit vulnerabilities. Runs before WordPress loads, reducing attack surface
and protecting plugins, themes, and core files.

### What It Stops:

 * **SQL injection, cross-site scripting, code injection, file inclusion attacks,
   and more** — all major attack types covered
 * **750+ built-in security rules** — full rule set running on Free; new rule additions
   reach Free 30 days after Premium
 * **Zero-day protection** — pattern-based detection catches new, unknown threats
 * **Custom rules** — add your own blocking patterns
 * **Attack logging** — full audit trail of every blocked request

### Extended Protection (WAF Optimizer)

Run the firewall _before_ WordPress loads, so malicious requests are blocked before
any vulnerable plugin or theme code can execute. One-click setup with automatic 
server detection for Apache and LiteSpeed, and built-in backup for safe configuration.
Improves WordPress security by reducing attack surface, preventing exploit execution,
and strengthening overall firewall protection at the earliest entry point.

### 🔍 9 Specialized Malware Scanners

Not just a basic malware scanner. This is a complete **WordPress malware scanner
and website security system** with 9 specialized scanners, each focused on a different
threat type to ensure full protection.
 Detect, analyze, and remove threats with
advanced scanning built for modern **WordPress security vulnerabilities and malware
attacks**.

 1.  **Malware Scanner** — 170,000+ signatures detect backdoors, trojans, and malicious
     code
 2.  **File Integrity Monitor** — Compares your files against official WordPress checksums
 3.  **Vulnerability Scanner** — Checks plugins and themes against known CVEs
 4.  **User Security Scanner** — Finds suspicious admin accounts and weak credentials
 5.  **Content Safety Scanner** — Detects malicious content injected into posts and
     comments
 6.  **Public Files Scanner** — Finds exposed configuration files (wp-config backups,.
     env, debug logs)
 7.  **Server State Scanner** — Audits PHP settings, file permissions, and server configuration
 8.  **Binary Scanner** — Detects malware embedded in images and executables
 9.  **Domain Reputation Scanner** — Checks URLs against Google Safe Browsing and threat
     databases

Advanced detection goes beyond traditional malware scanners by using multiple analysis
layers to identify both known and unknown threats. Obfuscation analysis detects 
encoded and hidden malware that basic security plugins often miss, while behavior
analysis identifies suspicious file activity and unusual patterns that may indicate
new or evolving attacks. A built-in legitimacy assessment helps reduce false positives,
ensuring more accurate and reliable malware detection.
 You can choose from quick
scan, standard scan, high sensitivity scan, or fully custom scan modes based on 
your website security needs. This system is designed for complete WordPress malware
removal, vulnerability detection, and full website protection, all running directly
on your server without relying on external scanning services.

### 🌍 Country Blocking & IP Management

Block entire countries or fine-tune access with advanced pattern rules. Strengthen
your **WordPress security** by controlling who can access your site based on location,
IP address, and request behavior, helping prevent **brute force attacks**, spam 
traffic, and malicious bot activity.

 * **Geo-Blocking** — Block any country, login-only or full site access
 * **IP Blocking** — Block individual IPs or IP ranges, temporary or permanent
 * **Custom Patterns** — Block by hostname, user agent, referrer, or IP range with
   wildcard and regex support
 * **Attack Analytics** — See which countries attack you most with visual reports
 * **Allowlist** — Whitelist trusted IPs and services to bypass all blocks
 * **GeoIP Integration** — Automatic IP-to-country lookup with auto-updating database

### 🛡️ Brute Force Protection & Rate Limiting

Stop password guessing and resource exhaustion attacks. Strengthen your **WordPress
login security** with advanced **brute force protection, rate limiting, and bot 
blocking** to prevent unauthorized access, credential stuffing, and automated attacks.

 * **Smart Login Limiting** — Lock out IPs after too many failed login attempts
 * **Leaked Password Detection** — Check passwords against known breach databases
 * **Strong Password Enforcement** — Require secure passwords for all user roles
 * **Username Blacklist** — Block common attack usernames instantly
 * **Rate Limiting** — Cap requests per IP to stop scrapers and vulnerability scanners
 * **Human vs Bot Detection** — Smart traffic classification with 404 monitoring

### 🔐 Two-Factor Authentication (2FA)

Even if someone steals your password, they can’t get in. Add an extra layer of WordPress**
login security** with secure **two-factor authentication** to prevent unauthorized
access, account takeovers, and brute force login attacks.

 * **QR Code Setup** — Works with Google Authenticator, Authy, 1Password, and more
 * **Backup Codes** — Never get locked out of your own site
 * **Role Enforcement** — Require 2FA for admins or specific user roles
 * **Frontend Management** — Users manage their own 2FA via shortcode
 * **WooCommerce & XML-RPC** — Covers your store and API endpoints

### 📊 Dashboard, Monitoring & Tools

Set it up in 5 minutes. Go deep when you want to. Manage your **WordPress security
dashboard** with real-time monitoring, detailed **audit logs**, and advanced security
tools to track threats, analyze activity, and take instant action.

 * **Security Status** — Green, yellow, or red — know your protection level at a
   glance
 * **Live Traffic View** — Watch visitors and attacks in real-time with human vs.
   bot classification
 * **Complete Audit Log** — Every security event tracked with timestamps and IP 
   intelligence
 * **Scheduled Scans** — Daily, weekly, or custom scan schedules
 * **One-Click Actions** — Block IPs, ignore false positives, repair infected files
 * **Diagnostics** — 15+ system health checks for troubleshooting
 * **Settings Export/Import** — Backup and migrate security configuration between
   sites
 * **Multi-Site Sync** — Manage security across multiple WordPress sites from one
   place

### 🔒 Privacy-First Security

All scanning happens on YOUR server. Period. Protect your **WordPress website security
and data privacy** with local malware scanning and firewall processing, ensuring
your files, database, and user data never leave your hosting environment.

### What We DON’T Do:

❌ We don’t send your file content or database data to external servers
 ❌ We don’t
track your users ❌ We don’t collect analytics about your site ❌ We don’t send 
data without your knowledge

### 🚀 Premium Features (Upgrade for Advanced Protection)

Unlock advanced **WordPress security, firewall protection, and malware detection**
with powerful [premium features](https://vmpsecurity.com/pricing/) designed for 
complete website protection:
 * **Real-Time Firewall Rules** – Get instant protection
with continuously updated WAF rules (no delays) * **Real-Time Malware Signatures**–
Detect the latest threats with up-to-date malware intelligence * **Advanced Malware
Detection** – Enhanced scanning for hidden, obfuscated, and zero-day threats * **
Full Audit Log** – Complete security event history with extended tracking and detailed
insights * **Country Blocking (GeoIP)** – Block traffic by country for better control
and attack prevention * **Advanced Analytics & Reporting** – Deeper insights into
attacks, traffic patterns, and security events * **Priority Support** – Faster assistance
from our security team * **Off-Site Audit Log Sync** – Tamper-proof off-site logging
via VMP Security Portal * **Continuous Updates & New Features** – Stay protected
with the latest security improvements

### External Services (Optional):

We use external services only when necessary for specific security features. You
can see exactly what’s sent:

**VMP Security Servers**
 * License activation and validation (free/premium) * WAF
rules synchronization and updates * Malware signature database updates * Two-Factor
Authentication (2FA) system management * Settings export/import cloud storage (optional)*
Privacy: Your site data remains on your server — only configuration and security
rules are synced

**Google Services** (safebrowsing.googleapis.com, www.google.com/recaptcha)
 * URL
threat detection and reCAPTCHA spam protection * Privacy: https://policies.google.
com/privacy

**WordPress.org APIs** (api.wordpress.org, downloads.wordpress.org, core.svn.wordpress.
org)
 * Download original files for integrity checking during malware scans * Privacy:
https://wordpress.org/about/privacy/

**GitHub** (raw.githubusercontent.com)
 * Download WordPress core files for file
comparison

**IP Lookup Services** (api.ipify.org, ifconfig.me, icanhazip.com, ip-api.com, ipwhois.
app, download.ip2location.com)
 * Server IP detection, geolocation, and country 
blocking features

**Threat Intelligence** (api.urlvoid.com, www.virustotal.com, checkurl.phishtank.
com)
 * URL reputation checking and threat validation

**Vulnerability Databases** (services.nvd.nist.gov, wpscan.com, cvedetails.com, 
cve.mitre.org)
 * Check for known security vulnerabilities during scans

**All malware scanning happens on YOUR server.** We do not upload your files or 
database content to external services.

## Screenshots

 * [[
 * **Security Dashboard** – Your security status at a glance with firewall protection,
   scan results, and threat overview
 * [[
 * **Active Scan Interface** – Real-time scan progress with detailed statistics 
   and threat detection
 * [[
 * **Scan Results** – Complete threat analysis with actionable remediation options
 * [[
 * **Firewall Dashboard** – WAF protection status, attack statistics, and blocked
   threats
 * [[
 * **Attack Log** – Detailed view of blocked attacks with IP, attack type, and violated
   rules
 * [[
 * **Firewall Summary & Attack Graph** – Firewall attack summary and global network
   attack graph
 * [[
 * **Firewall Configuration** – Comprehensive settings for WAF, brute force, and
   rate limiting
 * [[
 * **2FA Setup Screen** – QR code setup for two-factor authentication
 * [[
 * **Live Traffic Monitor** – Real-time traffic view with human vs bot classification

## Installation

 1. Install from the WordPress plugin directory or upload the plugin files
 2. Activate the plugin
 3. Go to **VMP Security > Dashboard** and run your first scan
 4. Enable 2FA for your admin account
 5. That’s it — the firewall and all protection features are active by default

## FAQ

### How is VMP Security different from Wordfence?

VMP Security includes country blocking, audit log preview, IP blocklists, and 750
+ WAF rules in the **free** version (new rule additions reach Free 30 days after
Premium, same delay model as Wordfence Free). Wordfence gates country blocking and
audit logs behind the $149/year premium plan. VMP Security also runs 9 specialized
malware scanners (vs. Wordfence’s 1 general scanner) and performs all scanning on
your server — no file data is sent externally.

### What advanced features are available in VMP Security Premium?

VMP Security Premium includes powerful **premium features** like real-time firewall
rules and malware signatures for instant protection, along with advanced security
features and a complete audit log with **1 year of history**. It also offers off-
site audit log sync via VMP Security Portal, advanced analytics and reporting, and
priority support. With regular updates, vulnerability monitoring, and enhanced WordPress
security controls, it delivers complete website protection. Premium is licensed 
per site.

### Is VMP Security completely free?

**Yes.** The free version includes the full firewall (750+ rules), all 9 malware
scanners (170,000+ signatures), country blocking, 50-entry audit log preview, 2FA,
brute force protection, and live traffic monitoring — new rule and signature additions
reach Free 30 days after Premium. Premium adds real-time WAF and signature updates(
195,000+ signatures), full audit log history with off-site portal sync, and YARA
scanning with 1,000+ rules.

### Will this slow down my website?

**Nope.** We’re obsessed with performance. The firewall uses efficient pattern matching,
scanners run in the background, and we optimize memory usage. Your visitors won’t
notice any slowdown.

### Do I need to configure anything?

**Not really.** It works great out of the box with secure defaults. But if you want
to customize, we give you full control over every feature.

### What happens when an attack is blocked?

The attacker gets a 403 Forbidden page. We log the attack details (IP, type, time,
violated rules) so you can see what happened. Repeat offenders get permanently banned.

### Can I whitelist my own IP address?

**Yes!** Go to Firewall > Options and add your IP to the allowlist. You’ll bypass
all firewall rules (useful for testing).

### How does 2FA work?

Use any authenticator app (Google Authenticator, Authy, 1Password, etc.). Scan the
QR code during setup, and you’re done. You’ll enter a 6-digit code when logging 
in.

### Will it detect all malware?

**No security tool catches 100% of threats.** But our specialized scanners with 
pattern matching, behavior analysis, and reputation checking catch the vast majority.
We’re constantly updating our detection signatures.

### Can it help with malware removal?

Yes. When we find infected WordPress core files, you can restore the original clean
version with one click. For plugins and themes, we guide you through reinstalling
from official sources. Our 9 scanners detect the malware — you control the cleanup.

### Does it work with WooCommerce?

**Yes!** We have special integrations for WooCommerce to protect your store and 
customer data.

### How do I update firewall rules?

Rules are updated automatically with plugin updates. You can also add custom rules
in Firewall > WAF Rules.

### Can I schedule automatic scans?

**Absolutely.** Daily, twice daily, weekly, weekdays only, weekends only, or custom
schedules. The scan monitor ensures they complete successfully.

### What if I get locked out?

2FA includes backup codes that you save during setup. For firewall lockouts, you
can disable the plugin via FTP or use WordPress recovery mode.

### Do you offer support?

Yes! We provide support through the WordPress.org forums. Premium support options
coming soon.

## Reviews

![](https://secure.gravatar.com/avatar/ddc840f83e5d8879f548d204f4ed1fe79a4660c6b9aa430d4d03e5731f59fe78?
s=60&d=retro&r=g)

### 󠀁[Strong Security, Better Performance Than Other Plugins](https://wordpress.org/support/topic/strong-security-better-performance-than-other-plugins/)󠁿

 [Forhad](https://profiles.wordpress.org/forhad/) May 4, 2026 1 reply

A solid and reliable WordPress security plugin. Compared to other plugins, it’s 
easier to set up, runs smoothly without slowing down the site, and offers powerful
features like firewall protection and malware scanning all in one place.

![](https://secure.gravatar.com/avatar/4b1a1667957875526582421e3ccaeb6b3d56d2db7abde3d2d6ce828a9f9250b6?
s=60&d=retro&r=g)

### 󠀁[Useful for the Alerts, but don’t expect enterprise-grade protection for free](https://wordpress.org/support/topic/useful-for-the-alerts-but-dont-expect-enterprise-grade-protection-for-free/)󠁿

 [Galib Hayder](https://profiles.wordpress.org/galibh/) April 30, 2026 1 reply

I have been using it more then 2 months now, If you have the technical skills to
harden your site and monitor logs manually, you probably don’t need this. however,
for most users, the peace of mind provided by the alerts justifies the install. 
It acts as a watchful eye that tells you when to worry, even if the actual “protection”
it offers is fairly standard.

 [ Read all 2 reviews ](https://wordpress.org/support/plugin/vmpfence-security/reviews/)

## Contributors & Developers

“VMP Security – Firewall, Malware Scan, and Login Security” is open source software.
The following people have contributed to this plugin.

Contributors

 *   [ VMPâ„¢ ](https://profiles.wordpress.org/tanveer269/)

“VMP Security – Firewall, Malware Scan, and Login Security” has been translated 
into 6 locales. Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/vmpfence-security/contributors)
for their contributions.

[Translate “VMP Security – Firewall, Malware Scan, and Login Security” into your language.](https://translate.wordpress.org/projects/wp-plugins/vmpfence-security)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/vmpfence-security/),
check out the [SVN repository](https://plugins.svn.wordpress.org/vmpfence-security/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/vmpfence-security/)
by [RSS](https://plugins.trac.wordpress.org/log/vmpfence-security/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.3.0 – May 14, 2026

**Firewall Summary Pagination, Performance & Security Hardening**

 * **Pagination:** Firewall Detailed Summary table now supports pagination so you
   can browse the full attack history instead of just the latest 50
 * **Performance:** Faster Firewall and Dashboard page loads through smarter caching
   of attack stats
 * **Security:** Hardened the firewall summary with stricter permission checks and
   safer filter handling
 * **Reliability:** Dashboard and Firewall now display your site name more reliably
   across different hosting setups
 * **UI:** Refreshed the Premium upgrade box on the Country Blocking section with
   clearer messaging and a working “Learn More” link

#### 2.2.9 – May 4, 2026

**Help Page Redesign & Translation Improvements**

 * **Help Page:** Complete layout redesign with improved navigation, clearer structure,
   and a dedicated stylesheet for a better support experience
 * **Dashboard:** Minor refinements to the dashboard view
 * **Internationalization:** Added translator comments across the plugin for better
   translation accuracy and updated POT file

#### 2.2.8 – April 22, 2026

**Blocked IPs Management, WAF Reliability & Custom Login Compatibility**

 * **Export Blocked IPs:** Added one-click export of all blocked IPs to a .txt file
 * **Bulk Actions:** Added bulk selection, bulk unblock, and bulk make permanent
   buttons on the Blocked IPs page
 * **WAF Safety Sync:** WAF rules now self-heal on page visit when WP-Cron is broken
   or delayed — no manual action needed if sync has been silent for too long
 * **Custom Login Compatibility:** WAF now correctly detects custom login URLs set
   by plugins like WPS Hide Login and Rename wp-login or custom code, preventing
   false blocks
 * **Review Prompt:** Added post-activation review prompt for eligible users
 * **WAF Rules Curated:** Improved WAF rule set quality and coverage

#### 2.2.7 – April 1, 2026

**Translation Support & Portal Connection**

 * **Internationalization:** Added full translation support with translatable strings
   across the entire plugin
 * **Portal Connection:** Added portal connection and add site flow

#### 2.2.6 – March 16, 2026

**Email Alerts, Audit Log & Scan Results Update**

 * **Email Alerts:** Updated email alert functionality with improved delivery and
   formatting
 * **Audit Log:** Enhanced audit log with additional event tracking and better data
   capture
 * **Scan Results:** Improved scan result curation for clearer and more actionable
   findings

#### 2.2.5 – March 5, 2026

**All Options, Update Notice & Audit Log Update**

 * **All Options Page:** Completed All Options page UI with full functionality
 * **Update Notice:** Added update notification for new plugin versions
 * **Audit Log Integration:** Enhanced audit log integration for all critical actions
   across the plugin

#### 2.2.4 – February 18, 2026

**WAF Optimizer, Onboarding, Performance & UX Update**

** New Features:**
 * **WAF Optimizer:** New optimization and removal wizards for
extended firewall protection with built-in backup and download support * **Onboarding
Tours:** Guided walkthroughs on each page help new users get started quickly * **
Activation Flow Redesign:** Polished license activation experience with clear success
and error feedback

** Performance Improvements:**
 * **Faster Signature Loading:** Malware signatures
now load significantly faster with optimized caching * **Reduced Memory Usage:**
Scanner and detection modules now load resources on demand instead of upfront * **
Improved Signature Sync:** Faster and more reliable signature downloads, even for
large databases

** Enhancements:**
 * **Better Facebook Compatibility:** Reduced false blocks for
traffic coming from Facebook links * **License Validation:** Periodic license status
checks keep your license accurate and up to date * **Fewer False Positives:** Internal
signature files are now excluded from scan results * **All Options Page:** Added
firewall options section and improved error handling * **Setup Wizard:** Smoother
first-time activation and license setup experience * **Extended Protection:** Improved
safeguards to prevent duplicate firewall rule loading

** Bug Fixes:**
 * Fixed dashboard notification overlay not appearing in certain
scenarios * Fixed extended protection management to use a more reliable update process*
Fixed background signature sync running out of memory on some hosts

#### 2.2.3 – January 31, 2026

**Maintenance & Optimization Update**

 * **Cleanup Improvements:** Added metadata cleanup on deactivation for cleaner 
   uninstalls
 * **Cron Management:** Clear scheduled crons on uninstall to prevent orphaned tasks
 * **Performance:** Added API key local validation before making external API calls
 * **UI Enhancements:** Improved UI design and branding color for different pages
 * **Bug Fixes:** Fixed redirect URLs for Import/Export and Login Security buttons
   in All Options page, Fixed bug for some cases where user can’t see the install
   license overlay modal after closing the activation form during fresh installation.

#### 2.2.2 – January 20, 2026

**Enhanced Features Performance, Branding & UI Consistency Update**

 * **UI Updates:** Updated plugin name and branding across all view pages for consistency
 * **Auto Updates:** Added automatic plugin update option in All Options page
 * **Dynamic Updates:** Dynamic update intervals for audit log and dashboard live
   updates
 * **Data Retention:** Added data retention choice on deactivation option
 * **Dashboard Widget:** Added WordPress dashboard widget for quick security overview
 * **Auto Sync:** Blocked IPs, WAF rules, and malware signatures now auto-sync after
   activation
 * **HTAccess Management:** Improved .htaccess modification, removal, and activation
   notice handling

#### 2.2.1 – January 19, 2026

**WordPress.org Compliance Update**

 * **Naming:** Updated plugin display name
 * **Text Domain:** Verified text domain consistency using ‘vmpfence-security’ throughout
 * **Documentation:** Added comprehensive External Services section documenting 
   all API connections
 * **Restore Default:** Restore default button in firewall options page now working

#### 2.2.0 – January 18, 2026

**MAJOR UPDATE: Country Blocking, Custom Pattern Matching, Export/Import & Diagnostics
Tools**

** New Features:**
 * Added Country Blocking system with comprehensive geo-blocking
capabilities * Implemented Custom Pattern Matching for advanced blocking rules (
hostname, user agent, referrer, IP ranges) * Added attack statistics showing top
attacking countries * Implemented Settings Export/Import system for easy configuration
backup and migration * Added comprehensive Diagnostics tool with 15+ system health
checks * Created GeoIP database integration with automatic updates

** Blocking Enhancements:**
 * Block entire countries from accessing your site *
Create pattern-based blocking rules with wildcard and regex support * Choose granular
blocking options (block login only or entire site) * Set temporary or permanent 
country blocks * Track block statistics and attempt counts * View detailed block
logs with IP, country, and request information

** Tools & Management:**
 * Full-featured Diagnostics tool for troubleshooting site
issues * Export and import your security settings for easy site migration * Backup
and restore your configuration with one click * System health monitoring with connectivity
tests * Time synchronization checks to ensure security features work properly * 
Complete WordPress settings and plugins audit * Cron job monitoring to verify scheduled
scans run correctly

** Improvements:**
 * Enhanced security scanning performance * Improved plugin stability
and reliability * Better error handling and user notifications * Optimized database
operations for faster performance

#### 2.1.2 – January 10, 2026

 * Fixed scan status persistence and auto-refresh issues
 * Fixed browser close handling during active scans
 * Fixed file cleanup for certain files during uninstallation
 * Fixed auto sync of malware signature and waf rule
 * Fixed status calculation hover issue
 * Fixed firewall detailed summary table and responsive layout issues
 * Fixed debug log handling and dashboard path resolution
 * Fixed global options page loading issue

#### 2.1.1 – January 9, 2026

 * Major scanner engine overhaul with memory optimization
 * Added batching and checkpointing for large scans
 * Fixed concurrent scan prevention mechanism
 * Fixed async scan worker cleanup on deactivation
 * Enhanced scan forking and interruption handling
 * Improved progress tracking reliability
 * Optimized memory usage for large file scans

#### 2.1.0 – January 7, 2026

**MAJOR UPDATE: Two-Factor Authentication, Enhanced Blocking, Tools & Advanced Features**

** New Features:**
 * Added complete Two-Factor Authentication (2FA) system with
QR code setup * Created live traffic monitoring with real-time request logging *
Added event tracking system for comprehensive security auditing * Implemented sync
service for centralized multi-site management * Added WHOIS lookup and IP intelligence
tools * Created frontend 2FA management interface with shortcode support * Added
reCAPTCHA integration for enhanced bot protection * Implemented WooCommerce security
integration * Added XML-RPC security with 2FA enforcement * Implemented Audit log

** Security Enhancements:**
 * Improved IP blocking with granular control and temporary/
permanent options * Implemented advanced file repair engine for infected file recovery*
Added binary file detection for embedded malware in images * Improved legitimacy
assessment to reduce false positives * Enhanced user security scanning for suspicious
accounts

** Performance & UX:**
 * Improved progress tracking with detailed status updates*
Enhanced exclusion system with pattern-based file filtering * Optimized memory management
for large site scans

** Technical Improvements:**
 * Added comprehensive audit logging for all security
events * Added signature sync service for automatic updates * Improved file type
detection and handling * Added IP allowlist system for trusted services

** Bug Fixes:**
 * Improved text domain consistency across translation strings *
Fixed edge cases in IP address validation and blocking * Improved compatibility 
with WordPress 6.9

#### 2.0.0 – December 11, 2025

**MAJOR UPDATE: Advanced Firewall Protection & Attack Prevention**

** Firewall Features:**
 * Added complete Web Application Firewall (WAF) with 280
+ security rules * Implemented real-time attack detection for XSS, SQLi, RFI, LFI,
and RCE * Created WAF rules management interface with filtering capabilities * Added
comprehensive attack logging and statistics * Implemented early bootstrap protection(
loads before WordPress)

** Brute Force Protection:**
 * Added login attempt limiting with configurable thresholds*
Implemented invalid username blocking for user enumeration prevention * Added leaked
password checking against breach databases * Created strong password enforcement
system * Added username blacklisting for instant blocking

** Rate Limiting:**
 * Implemented request rate limiting for humans and crawlers*
Added 404 error monitoring to detect scanning attempts * Created Google crawler 
verification and handling * Added intelligent traffic classification * Implemented
throttling and blocking actions

** Advanced Blocking:**
 * Added IP address blocking with CIDR range support * Implemented
user agent and referrer blocking * Created URL pattern blocking with instant bans*
Added IP whitelist for trusted services * Implemented permanent ban system for repeat
offenders

** Dashboard & Reporting:**
 * Created firewall dashboard with visual status indicators*
Added attack statistics by time period * Implemented blocked attacks table with 
filtering * Created comprehensive firewall options page * Added custom security 
block messages

#### 1.0.0 – September 29, 2025

**Initial Release – Comprehensive Security Scanner**

 * Released specialized security scanner modules
 * Added malware detection with advanced pattern matching
 * Integrated Google Safe Browsing API for URL reputation
 * Created multi-scan type support (Quick, Standard, Deep, Custom)
 * Implemented file integrity monitoring against WordPress.org
 * Added vulnerability scanning for plugins, themes, and core
 * Created user security analysis and admin monitoring
 * Implemented content safety scanning
 * Added public files scanner for exposed configurations
 * Created scheduled scanning with automatic recovery
 * Implemented comprehensive audit logging
 * Added flexible file exclusion system
 * Created dashboard with detailed security reporting

## Meta

 *  Version **2.3.0**
 *  Last updated **16 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.0 or higher **
 *  Tested up to **6.9.4**
 *  PHP version ** 7.4 or higher **
 *  Languages
 * [Czech](https://cs.wordpress.org/plugins/vmpfence-security/), [Dutch](https://nl.wordpress.org/plugins/vmpfence-security/),
   [English (US)](https://wordpress.org/plugins/vmpfence-security/), [Lao](https://lo.wordpress.org/plugins/vmpfence-security/),
   [Russian](https://ru.wordpress.org/plugins/vmpfence-security/), [Spanish (Colombia)](https://es-co.wordpress.org/plugins/vmpfence-security/),
   and [Spanish (Mexico)](https://es-mx.wordpress.org/plugins/vmpfence-security/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/vmpfence-security)
 * Tags
 * [brute force protection](https://test.wordpress.org/plugins/tags/brute-force-protection/)
   [firewall](https://test.wordpress.org/plugins/tags/firewall/)[malware](https://test.wordpress.org/plugins/tags/malware/)
   [security](https://test.wordpress.org/plugins/tags/security/)[two factor authentication](https://test.wordpress.org/plugins/tags/two-factor-authentication/)
 *  [Advanced View](https://test.wordpress.org/plugins/vmpfence-security/advanced/)

## Ratings

 4 out of 5 stars.

 *  [  1 5-star review     ](https://wordpress.org/support/plugin/vmpfence-security/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/vmpfence-security/reviews/?filter=4)
 *  [  1 3-star review     ](https://wordpress.org/support/plugin/vmpfence-security/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/vmpfence-security/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/vmpfence-security/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/vmpfence-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/vmpfence-security/reviews/)

## Contributors

 *   [ VMPâ„¢ ](https://profiles.wordpress.org/tanveer269/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/vmpfence-security/)