WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: bitfire (Used by 88 domains)

BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security

πŸ‘€ Cory Marsh πŸ“¦ v4.8.2 πŸ”— Plugin Homepage

Real-Time Security for WordPress

BitFire protects your website from bots, hackers, malware, and critical vulnerabilities – before they can cause damage.

This plugin brings advanced security technology used by large enterprises to your WordPress site, now available in a free version. Whether you manage a business website, blog, or WooCommerce store, BitFire gives you powerful protection and visibility into your traffic.

Smarter Protection with AI

Most security plugins wait for updates to detect new threats. BitFire takes a different approach: it uses artificial intelligence and real-time request analysis to stop zero-day attacks, bots, and malicious users before they get access to your site.

Our AI learns what normal traffic looks like for your site and blocks anything suspicious – without you needing to configure endless rules.

β€œUnlike traditional firewalls that allow everything by default and react to known threats, BitFire only allows verified traffic – stopping new and unknown attacks instantly.”

Key Features

πŸ” Security Highlights (Free & Pro)

  • Stop Bots Automatically – Block fake users, spam bots, and scanners (no captchas needed).
  • Malware Scanner – Scan your site for infected or unknown files using a fast hash-based scanner.
  • Real-Time Traffic Monitor – See who’s visiting your site, including IP, city, browser, request rate, and referrer.
  • Login Protection – Block bots from abusing your login page, detect phishing attacks, and stop brute-force attempts.
  • Human / Bot Detection – BitFire can tell the difference between real users and fake browsers with 99.7% accuracy.
  • IP Reputation – Block over 300,000 known malicious IPs with real-time threat intelligence.

πŸš€ Built for Speed

  • BitFire logs traffic in under 2ms per request, thanks to a high-performance binary logging engine.
  • Unlike bulky WAFs that rely on large rule sets, BitFire looks at the intent behind every request – giving you faster speeds and fewer false positives.

πŸ” Live Traffic Monitoring

  • Track every visitor request in real time
  • Remove blind spots and gain confidence in your site security
  • Filter traffic by IP, URL, response code, or user-agent
  • View bot fingerprints from over 3,000 known bots and 180 real browsers
  • See what was blocked and why

πŸ›‘ Runtime Protection (PRO)

BitFire includes WordPress’s first Runtime Application Self Protection (RASP) firewall.

This means BitFire watches what your plugins and code are doing in real time and blocks anything suspicious – including:
– Unauthorized file modifications (File RASP)
– Suspicious database queries (Database RASP)
– Unauthorized account creation or privilege escalation (Authentication RASP)
– Dangerous outbound network requests (Network RASP)

β€œIt’s like a bodyguard inside your WordPress server – watching every move and stopping threats before they execute.”

What’s Included in the Free Version?

  • Traffic logger (current day only)
  • Real-time bot and malware detection
  • File scanner with fast hash matching
  • Block plugin and theme enumeration tools
  • Live IP and user-agent request viewer
  • Block hacking tools like WPScan, Nmap, Nikto, etc.

What’s in BitFire Pro?

  • Web Firewall rated A+ by cloudbric with real-time updates
  • Full Runtime Self Protection engine (File, Database, Account, and Network protection)
  • Advanced login protection and phishing detection
  • Malware scanner with 14 million+ clean file hashes
  • Automatic browser fingerprinting and allowlists
  • Auto-configured CSP and security headers (A+ rating)
  • Increased traffic logging and historical view to 30 days

    ** Independent WAF testing by Cloudbric https://labs.cloudbric.com/wafer **

  • BitFire [PRO] – πŸ‡¦ (94%)

  • MalCare [PRO] – πŸ‡« (34%)
  • WordFence [PRO] – πŸ‡© (41%)
  • iThemes Security – πŸ‡« (2%)
  • Ninja Firewall [PRO] – πŸ‡© (67%)
  • Site Ground Security – πŸ‡« (2%)
  • Shield Security [PRO] – πŸ‡« (2%)

Trusted by Enterprises, Now Available to You

BitFire is used by major organizations on our managed enterprise platform and developed by a veteran security architect with over 20 years of experience defending Fortune 500s and critical infrastructure.

This free release brings our best bot detection and traffic logging features to the WordPress community – at no cost.

Learn More

Visit https://bitfire.co for:
– Full product comparison
– Malware removal services
– Pro pricing
– Support

Privacy / Monitoring / Data Collection

  1. Privacy. We take privacy very seriously. BitFire inspects all traffic going to the webserver and takes care to filter out any potentially sensitive information by replacing it with redacted. The config.ini file includes a list of common sensitive field names under the β€œfiltered_logging” section. You can add additional fields to filter in the config file by adding a line β€œfiltered_logging[field_name] = true” and replacing β€œfield_name” with the name of the desired parameter to filter.

  2. BitFire includes an error handler which monitors it’s operation. In the event an error is detected in the BitFire software; including during install, an alert can be sent to BitFire’s developer team. The development team monitors these errors in real time and includes fixes for any detected errors in each new release.

  3. Malware scanner. BitFire sends tiny 64bit hashes (signatures, or fingerprints) of every file to our hash database. For instance, index.php may hash to the number: 812612388126487. The database is many gigabytes and centrally located on our servers. BitFire uses that information to determine if a file has been modified or is a known good file and sends the results back to your site. Client hashes are never stored off your server.

  4. Log data and configuration data is stored locally on the filesystem in the wp-content/uploads/bitfire_RANDOM directory. This directory is unique and hidden from the Internet and protected by an .htaccess file. Web servers that are configured to allow directory listings will want to ensure that the file wp-content/uploads/index.php is present to prevent directory listings. The random directory name is 12 characters long and is generated on install. The directory is not accessible from the Internet and is protected by a .htaccess file.

DomainExposuresHeadersLast Checked
m*l*f*i*b*l*n*e.co βœ… C 2026-06-07 10:21:00
l*f*o*k*n*s*r*.com βœ… F 2026-06-07 10:21:00
b*e*a*n*m.com (WP 6.8.5) βœ… B 2026-06-04 04:33:47
i*s*m.com (WP 6.9) βœ… F 2026-06-03 23:15:34
s*m*y*p*e*e*c*.com (WP 6.9.4) βœ… C 2026-06-03 00:04:33
i*t*e*.com (WP 6.9.4) βœ… F 2026-06-02 13:22:14
a*t*o*d*a*e*i*l.com βœ… C 2026-06-02 08:34:30
s*4*3*7*1*.o*l*n*h*m*.us (WP 7.0) βœ… C 2026-06-01 23:52:28
s*h*e*c*a.com βœ… C 2026-06-01 03:32:06
f*o*f*r*a*a.com (WP 6.8.5) βœ… C 2026-06-01 02:14:45
r*-*h*o*i*l*s.com βœ… C 2026-05-31 22:27:43
a*l*n*i*f*c*o*i*l.com βœ… C 2026-05-31 13:22:03
c*s*a.ca (WP 6.9.4) βœ… C 2026-05-30 09:45:12
g*e*n*o*a*i*n*s*l*t*o*s.com (WP 7.0) βœ… F 2026-05-30 06:22:16
r*t*h*s*p*r*e*c*e*.com (WP 7.0) βœ… C 2026-05-30 00:43:05
f*r*a*d*u*.com (WP 7.0) βœ… F 2026-05-28 04:57:09
i*k*t*r*m*d*a.com βœ… F 2026-05-27 07:17:10
e*m*g*z*n*.es (WP 7.0) βœ… A 2026-05-26 17:54:25
a*t*s*a*l*a*c*.ca (WP 6.9.4) βœ… C 2026-05-25 16:38:03
c*e*a*e*k*r*a*s.com (WP 7.0) βœ… C 2026-05-25 14:45:14
c*e*a*e*k*c*u*t*y*o*d*.com (WP 7.0) βœ… C 2026-05-25 14:40:26
s*a*s*w*t*h.com (WP 7.0) βœ… C 2026-05-25 13:40:57
e*i*p*a*f*r*.eu (WP 7.0) βœ… C 2026-05-24 20:59:19
f*n*a*j*c*r*l*.eu (WP 6.9.4) βœ… C 2026-05-24 19:37:51
e*i*e*r*p*.com (WP 7.0) βœ… C 2026-05-24 16:50:58
k*a*s*a*o*k*.com βœ… C 2026-05-24 09:08:08
p*s*t*v*l*t*l*s*u*.com (WP 7.0) βœ… C 2026-05-24 01:21:56
k*e*b*t*.app βœ… B 2026-05-22 20:04:38
d*c*n*l*n*i*.com (WP 7.0) βœ… C 2026-05-22 18:11:35
h*s*x*o*.com (WP 6.9.4) βœ… F 2026-05-22 12:42:07
s*u*h*e*t*a*i*o*i*l.com βœ… C 2026-05-21 16:13:34
h*g*s*x.com (WP 6.9.4) βœ… F 2026-05-21 10:28:31
t*a*o*y*e*t*v*l.c*m.au βœ… B 2026-05-20 19:37:10
g*.w*w*r*e*o*.com (WP 6.9.4) βœ… C 2026-05-20 09:02:50
c*m*u*i*y*a*k*t*i*c.org βœ… F 2026-05-20 05:47:05
h*r*a*u*.com βœ… F 2026-05-19 21:58:38
a*e*h*a*t*j*u*n*y.com βœ… C 2026-05-19 21:24:08
y*g*l*i*a*e*o*o.com (WP 6.9.4) βœ… F 2026-05-19 16:48:02
e*e*y*h*n*g*i*l*e*i*w*.com βœ… C 2026-05-19 13:00:38
e*p*o*e*h*s*p*a*e*o*n*r*.com (WP 6.9.4) βœ… C 2026-05-19 10:35:19
g*m*l*n*.t*e*p*t*i*t*r*.io (WP 6.8.5) βœ… B 2026-05-18 17:04:51
d*i*p*r*v*p*s*o*.com (WP 6.9.4) βœ… C 2026-05-18 04:12:55
d*i*p*r*v*p*a*d*e*p.com (WP 6.9.4) βœ… C 2026-05-18 04:12:55
d*i*p*r*c*d.com (WP 6.9.4) βœ… C 2026-05-18 04:12:55
c*t*z*n*f*r*c*e*n*o*u*b*a.org βœ… B 2026-05-17 13:39:25
d*s*o*e*c*e*a*e*k*c*u*t*y.com (WP 6.9.4) βœ… C 2026-05-17 10:56:05
n*r*h*i*e*l*c*.w*e*g*n*.com βœ… C 2026-05-16 21:14:23
n*r*h*i*l*f*r*p*a*e*n*g*i*l*.com βœ… C 2026-05-16 00:03:53
n*r*h*i*l*f*r*p*a*e.com βœ… F 2026-05-16 00:03:53
b*a*e*a*g*i*l*.com βœ… C 2026-05-15 12:11:11
e*s*l*n.com (WP 6.9.4) πŸ“‘ C 2026-05-15 07:51:58
e*t*t*p*y*u*.com (WP 6.9.4) βœ… C 2026-05-14 12:44:15
b*o*.l*g*t*p*r*a*e.fr βœ… C 2026-05-14 08:30:51
b*o*.s*m*l*t*u*-*o*t*g*-*a*a*i*l.fr βœ… C 2026-05-14 08:30:51
w*w*r*e*o*.com (WP 6.9.4) βœ… C 2026-05-14 03:42:24
b*e*c*e*.ai βœ… A 2026-05-14 00:49:22
j*h*k*m*r*.com βœ… C 2026-05-13 19:28:12
g*l*s*t*i*.com (WP 6.9.4) βœ… C 2026-05-13 08:44:16
l*v*a*d*o*a*a*a*i*n*.com (WP 6.9) βœ… F 2026-05-12 18:26:53
q*i*k*n*e*z*d*s.com βœ… F 2026-05-12 18:22:37
h*s*h*l*e*.pl βœ… F 2026-05-12 09:15:36
m*l*v*l*n*m*l*i*e*s*.com βœ… B 2026-05-12 03:41:50
s*i*i*g*u*u*t*.com (WP 6.9.4) βœ… C 2026-05-12 01:54:35
g*l*v*l*e*i*e.com βœ… B 2026-05-11 12:04:00
j*k*n*l*s*.com (WP 6.9.4) βœ… C 2026-05-11 07:00:37
e*p*s*m*x*c*n*r*l*p*n*o*k*d.com (WP 6.9.4) βœ… F 2026-05-11 05:52:03
s*u*i*s*o*a*s*r*n*e*i*.ca βœ… F 2026-05-11 04:39:46
a*a*t*o*-*i*f*e*d.com (WP 6.9.4) βœ… B 2026-05-10 18:18:30
a*a*d*l*h*h*b*.com (WP 6.9.4) βœ… B 2026-05-10 10:53:47
n*c*o*e*l*d*.com (WP 6.5.8) βœ… A 2026-05-10 08:33:38
s*a*r*n*p*c*.com βœ… F 2026-05-10 06:30:44
c*o*w*a*m*t*e*s.com βœ… B 2026-05-09 14:48:52
b*l*v*d*i*t*a*t.com (WP 6.9.4) βœ… F 2026-05-09 12:41:27
h*s*i*g*o*p*n*.be (WP 6.9.4) βœ… C 2026-05-09 04:13:01
t*e*i*h*b*a*n*c*d*m*.com (WP 6.9.4) βœ… F 2026-05-08 16:04:33
k*e*b*t*.berlin βœ… B 2026-05-08 14:40:07
p*a*i*u*-*e*i*a*.com (WP 6.9.4) βœ… C 2026-05-08 11:30:25
a*d*o*.com (WP 6.9) βœ… F 2026-05-08 04:08:28
b*a*t*f*l*i*t*r*w*e*l*f*.com βœ… B 2026-05-07 22:06:07
l*n*k*n.com βœ… D 2026-05-07 13:08:55
s*o*e.g*e*c*e*.com (WP 6.9.4) βœ… C 2026-05-04 08:03:34
l*m*n*r.com (WP 6.9.4) βœ… B 2026-05-04 00:30:03
i*a*c*n*r*r*d*o*o*i*o.com (WP 6.9.4) βœ… B 2026-05-03 19:31:01
p*t*i*k*a*i*.com (WP 6.9.4) πŸ”“ C 2026-05-03 09:47:13
a*m*l*b*l*n*.com (WP 6.7.1) πŸ“‘ C 2026-05-02 22:47:23
i*o*e*.com (WP 6.9.4) βœ… F 2026-05-02 16:10:22
l*n*m*c*e*l*.com βœ… C 2026-05-02 12:52:06
m*l*o*m*n*i*a.c*m.br (WP 6.9.4) βœ… B 2026-04-23 16:56:05

Top 50 Plugins

Plugin Count
elementor 1,800,450
contact-form-7 1,770,416
elementor-pro 1,049,481
woocommerce 816,578
revslider 617,763
jetpack 467,002
js_composer 432,362
wp-rocket 334,096
essential-addons-for-elementor-lite 293,692
gravityforms 267,060
complianz-gdpr 256,646
cookie-law-info 231,313
instagram-feed 228,088
google-site-kit 222,053
sitepress-multilingual-cms 221,190
google-analytics-for-wordpress 214,049
header-footer-elementor 210,208
elementskit-lite 206,911
bluehost-wordpress-plugin 190,775
gutenberg 162,337
gutenberg-core 159,507
cookie-notice 151,371
the-events-calendar 131,527
litespeed-cache 130,994
wpforms-lite 129,550
gtranslate 127,925
astra-sites 119,573
popup-maker 116,091
woocommerce-payments 112,960
tablepress 109,187
coblocks 99,539
honeypot 97,392
astra-addon 95,313
duracelltomi-google-tag-manager 93,533
wp-smushit 93,516
all-in-one-seo-pack 93,320
LayerSlider 91,657
bb-plugin 90,822
premium-addons-for-elementor 86,880
megamenu 86,508
akismet 86,074
cleantalk-spam-protect 83,880
mailchimp-for-wp 83,756
woocommerce-gateway-stripe 83,116
ml-slider 81,034
fusion-builder 79,664
borlabs-cookie 79,520
ewww-image-optimizer 79,050
wp-pagenavi 78,797
formidable 78,063

Top 50 Themes

Theme Count
hello-elementor 615,573
Divi 510,726
astra 423,626
flatsome 133,744
Avada 124,341
generatepress 119,948
pub 109,942
oceanwp 83,460
kadence 78,474
enfold 71,844
salient 66,714
twentytwentyfour 58,958
h4 56,410
twentyseventeen 56,190
bb-theme 55,281
cocoon-master 52,095
betheme 51,820
blocksy 50,688
dt-the7 46,160
twentytwentyfive 43,814
neve 39,351
Avada-Child-Theme 37,622
gox 33,449
woodmart 33,292
bridge 32,878
twentytwentyone 32,115
lightning 31,449
twentytwenty 30,045
swell 28,597
Impreza 26,441
bricks 26,019
sydney 25,643
twentytwentythree 24,026
Newspaper 23,472
voxel 22,440
twentytwentytwo 19,980
epik-redesign 19,270
kubio 19,178
uncode 19,113
sinatra 18,819
twentysixteen 18,221
storefront 17,869
pro 17,861
Total 14,730
extendable 14,595
yith-wonder 14,041
hello-theme-child-master 13,356
themify-ultra 12,983
yootheme 12,936
factory-templates-4 12,927