WordPress administrator guide

Install and configure BitFire

Set up enterprise-level WordPress protection with a clear, practical process—no server administration or security experience required.

01PrepareBackup and access
02InstallAdd the plugin
03ConfigureCheck compatibility
04ScanReview site files
05MonitorConfirm protection
Before you begin

Prepare for a safe installation.

A few simple checks make setup faster and give you a safe way back if your website has an unrelated problem during installation.

Using WordPress Multisite?

Sign in as a Super Admin and install BitFire from Network Admin on the main network site.

Pre-installation checklist

Have these ready

  • An Administrator account
  • A current website backup
  • Access to test login, forms, checkout, and uploads
  • An email address for security reports
01
WordPress setup

Install BitFire

Install BitFire directly from the WordPress plugin directory, then open its settings to begin the security setup.

1

Sign in to WordPress

Open your WordPress administration area and sign in with an Administrator account.

https://your-website.com/wp-admin/
2

Find the BitFire plugin

  1. Select Plugins.
  2. Select Add New Plugin.
  3. Search for BitFire.
  4. Locate the official BitFire plugin and select Install Now.

BitFire may download supporting IP and location data. This can take approximately one minute. Keep the page open while installation finishes.

3

Activate the plugin

When WordPress confirms installation is complete, select Activate. A BitFire shield should appear in the administration menu. Open it and select Settings.

02
Hosting check

Complete the compatibility check

BitFire verifies that your hosting environment supports the security features required to protect the site.

CriticalResolve before activation

BitFire needs this item corrected before protection can safely begin.

PassedNo action required

Your server has met this requirement.

1

Review every critical result

Some items provide a Fix button. Select it to let BitFire apply the required change, then confirm the check passes.

2

Keep the detected cache setting

If the PHP SHMOP extension is available, BitFire uses it for strong performance. If it is unavailable, leave the detected fallback unchanged unless your host or BitFire support advises otherwise.

3

Activate website protection

After all critical checks pass, scroll to the bottom of the setup page, select the BitFire Activate button, and wait for confirmation.

03
Safe rollout

Configure initial protection

Enable the main protection layers, choose a rollout level, and test the website as a visitor would.

Enable protection

Turn on available General, HTTP, Bot, WAF, and RASP controls.

Keep system defaults

Leave advanced settings unchanged unless support advises otherwise.

Set up reporting

Send security reports to an email address you check regularly.

Related guideReview every BitFire core setting

Choose an initial traffic percentage

100%
Low-traffic websites

Protect all traffic from the start. A lower setting may not collect enough activity for a useful learning period.

10%
High-traffic or business-critical websites

Begin with a cautious sample, monitor results, and increase coverage after successful testing. The final goal is 100%.

Test the visitor experience

Homepage and contentWordPress loginContact and registration formsSearchCheckout and paymentsCustomer or member accountsFile uploadsExternal services
04
File review

Run your first malware scan

Check WordPress files for suspicious code, hidden backdoors, droppers, and persistence mechanisms.

01

Save the recovery code

Open Malware Scanner, copy the emergency recovery code, and save it outside WordPress—preferably in a password manager. Then select I Understand.

The code can restore a recently quarantined file and remains active for 24 hours.
02

Start the scan

Wait for file signatures to synchronize, then select Scan Files Now. Most scans finish within several minutes; larger sites may take longer.

03

Review each result

Open Scanner to understand why a file was flagged and Diff to inspect relevant code. Allow only files you confidently recognize as safe.

04

Use AI-assisted analysis

Select the files of greatest concern, up to the limit shown by the scanner, and select Analyze Files. The free scanner supports up to 12 selected files.

Safe

The file appears legitimate and may be automatically allowed.

Suspicious

The code needs a closer review and more context.

Malware

The file contains behavior strongly associated with compromise.

AI analysis is an additional review tool, not a replacement for administrator judgment. If a first analysis reports suspicious or malicious behavior, select Re-analyze for a more detailed review. If a second analysis confirms malware, contact support@bitfire.co before making broad file changes.

BitFire · Malware analysis
BitFire malware scanner showing AI-assisted analysis of a confirmed threat
Evidence before actionReview the finding, confidence, explanation, and file details.
Quarantine and recovery

BitFire keeps a recoverable copy.

If deleting an infected file causes the website to fail, BitFire attempts to identify the recently quarantined file and asks for your recovery code.

When uncertain, do not delete the file. Professional review is safer than removing a required plugin, theme, or WordPress file without a recovery plan.

05
First three days

Understand the learning period

BitFire observes normal pages, request parameters, and API endpoints while continuing to block clearly malicious activity.

Day 1Protection begins

Known attack tools and clearly hostile requests are blocked immediately.

Days 1–3Normal activity is learned

BitFire records how visitors, plugins, and approved services use the website.

After day 3Full policy is enforced

Unknown bots receive restricted access and unusual browser requests may be verified.

What visitors may notice

Most people notice nothing. Someone opening an unusual URL may briefly see a browser verification screen. A real browser normally passes automatically.

What BitFire does not learn

Learning mode never teaches BitFire to allow known exploit attempts, hostile scans, or attack tools. They remain blocked.

06
Confirm operation

Review protection

After the learning period, spend a few minutes confirming that BitFire is blocking hostile traffic without interrupting the website.

  1. 1

    Open the BitFire dashboard.

  2. 2

    Select the All Blocks quick filter.

  3. 3

    Review two or three pages of recent requests.

  4. 4

    Look for website features and services you recognize.

  5. 5

    Review browser requests with a green Verified badge.

BitFire · Access log
BitFire dashboard showing blocked requests and verified browser traffic
Review every requestFilter blocked traffic and inspect the visitor, agent, and result.
07
Connected systems

Review services and bots

External services may need to connect automatically. Keep them restricted unless you confirm that additional access is required.

Needs Review

A bot tried to use a real endpoint and may need a decision.

Restricted

The bot can view allowed content but cannot change the website.

Allowed

A verified service can bypass applicable bot restrictions.

Suspicious

The bot sent requests that were classified as obviously malicious.

Before allowing a service

  1. 01

    Confirm that your website uses the service.

  2. 02

    Confirm that a feature is failing because its request is blocked.

  3. 03

    Review the IP address and any available AbuseIPDB information.

  4. 04

    Check that observed IP and DNS details match the provider.

  5. 05

    Allow only the specific service that requires access.

Do not trust a bot's name by itself.

Attackers often call themselves Googlebot, Bingbot, Chrome, or Safari. BitFire checks major services against expected networks and DNS records. Never create a broad exception based only on a familiar name or browser icon.

08
Ongoing operation

Maintain protection

BitFire needs little daily administration. Review it when the website changes and periodically over the year.

Every Other week / monthly
  • Review recent blocked requests.
  • Check malware and security reports.
  • Confirm email reports are arriving.
After large plugin or theme changes
  • Test the affected feature.
  • Review "All Blocks".
  • Check Needs Review for integrations.
  • Scan software from outside official sources.
After connecting a service
  • Test the integration.
  • Review its dashboard requests.
  • Keep it restricted when possible.
  • Create only the exception it needs.
After changing host, CDN, or proxy
  • Confirm Remote IP Source.
  • Clear cache if advised.
  • Check that visitor IPs are accurate.
09
Common questions

Troubleshooting

Resolve the narrowest issue first rather than disabling all website protection.

A critical compatibility check does not pass

Use the provided Fix action when available. If it still fails, send the exact message to support@bitfire.co.

A visitor cannot submit a form or sign in

Find the request on the dashboard and check Bot Control. If you recognize the action and it is safe, use Allow to create a narrow exception.

A connected service stopped working

Look under Needs Review in Bot Control. Confirm the service and its IP details before allowing it.

A malware result is unclear

Review the Scanner and Diff tabs, then use AI-assisted analysis. Do not delete an uncertain file. Contact support if a second analysis confirms malware.

The website stopped loading after a file was deleted

Use the emergency recovery prompt and enter the saved code. If the prompt is unavailable or the code expired, contact support for manual recovery.

Too many legitimate requests are blocked

On a high-traffic site, temporarily reduce traffic coverage while reviewing requests. Allow only verified website functions and trusted integrations—never broad browser names or unknown IP ranges.

Final review

Installation checklist

Your setup is complete when every applicable item is checked.

  • Plugin installed and active
  • Critical checks passed
  • Website protection activated
  • Email reporting configured
  • Important website features tested
  • Recovery code stored securely
  • First malware scan complete
  • Learning period complete
  • Blocks and bots reviewed
  • Traffic coverage at 100%
Need a hand?

Installation support is available.

Contact BitFire if a compatibility check fails, malware is confirmed, or an important website feature remains blocked.

Protect my site free →