Getting started
What BitFire does, what you need before installation, and what to expect during the first few days.
What is BitFire?
BitFire is a WordPress security plugin that combines bot verification, a web application firewall, HTTP hardening, malware scanning, and runtime controls. These layers work together to restrict hostile traffic and prevent dangerous application operations.
How do I install BitFire?
In WordPress, open Plugins → Add New Plugin, search for BitFire, install the official plugin, and activate it. Then open BitFire → Settings, complete the compatibility check, and activate website protection.
Do I need server administration or security experience?
No. Most websites can use the detected defaults and guided setup. You need a WordPress Administrator account, a current website backup, and access to test important features such as login, forms, checkout, and uploads.
Does BitFire support WordPress Multisite?
Yes. Sign in as a Super Admin and install BitFire from Network Admin on the main network site.
What happens during the learning period?
For roughly the first three days, BitFire observes normal pages, request parameters, and API endpoints while continuing to block known attack tools and clearly hostile requests. Afterward, full policy is enforced. Most visitors notice nothing; an unusual request may briefly receive browser verification.
Protection, bots, and performance
How BitFire evaluates visitors, requests, and protected operations without relying on one security technique.
What is the difference between bot protection, the WAF, and RASP?
Bot protection evaluates who is interacting with the site. The web application firewall inspects what a request contains. RASP watches what WordPress and PHP attempt to do and blocks unauthorized protected operations at runtime.
Can BitFire stop an exploit before a vulnerability-specific rule exists?
BitFire PRO runtime controls do not need to recognize every exploit signature. They can stop an unknown exploit when it attempts an unauthorized protected operation such as writing PHP, changing administrator privileges, or impersonating an administrator.
Will BitFire block Google and other legitimate bots?
BitFire verifies major services using expected network and DNS information rather than trusting a bot name. Verified services can be allowed by policy while fake search bots and unidentified automation remain restricted.
What should I do if a trusted integration is blocked?
Confirm that your website uses the service, that the blocked request caused the failure, and that the observed network details match the provider. Then allow only that service or request instead of disabling bot or firewall protection globally.
Will visitors notice BitFire?
Normal visitors should notice little or no change. A new visitor may briefly receive a lightweight browser check before a sensitive action. Test login, forms, checkout, memberships, APIs, and uploads after activation because every WordPress stack is different.
Does BitFire work behind Cloudflare or another CDN?
Yes, but Remote IP Source must identify the real visitor address. After changing a CDN, host, or reverse proxy, confirm that dashboard requests show varied visitor IP addresses rather than one shared proxy address.
Malware scanning
How to interpret findings, choose safe actions, and understand what a file scan can and cannot prove.
Does every flagged file contain malware?
No. Paid plugins, custom themes, and third-party software may contain powerful or unfamiliar code. A flagged result is a request for review, not proof of infection. Check the file path, scanner evidence, DIFF view, and available analysis before acting.
Is the FREE scanner less thorough than the PRO scanner?
No. FREE and PRO use the same malware scanner. PRO adds automated scheduling, Threat Hunter, runtime protection, and more AI malware-analysis credits.
How often should I scan WordPress for malware?
Run a manual FREE scan at least monthly and after suspicious activity or major software changes. PRO can schedule automated scans up to twice daily. A scan normally continues in the background if you leave the page.
Does AI malware analysis receive my domain name?
No. BitFire sends suspicious sections of a file for analysis without the domain or other site-identifying information. AI analysis is a second opinion, not a guarantee; re-analyze an unclear result or ask support before deleting an important file.
Should I allow, repair, or delete a suspicious file?
Allow only a file version you recognize as safe. Repair a modified known file from a verified source when possible. Delete only confirmed malware when no clean replacement is available. Create a backup first and test the site afterward.
Does a clean scan guarantee the server is safe?
No scanner can guarantee every part of a server is clean. Confirmed compromises can also involve cron tasks, database content, rogue users, active sessions, background processes, or stolen hosting credentials. Threat Hunter extends the investigation beyond ordinary files.
Plans and licensing
Choosing between FREE and PRO and licensing the websites you operate.
What is the difference between BitFire FREE and PRO?
FREE provides bot controls, request filtering, HTTP protection, and the core malware scanner for eligible non-commercial websites. PRO adds early loading, runtime RASP controls, scheduled malware scans, Threat Hunter, and expanded AI analysis for commercial and business-critical sites.
Which websites need a commercial license?
Business, agency, client, lead-generation, membership, ecommerce, and other commercially used sites require a commercial license. FREE is for eligible personal, charity, and other non-commercial websites.
How many websites does one license protect?
One license protects one website. Portfolio discounts apply when purchasing licenses for multiple sites. Use the pricing calculator for the current annual rate because pricing can change over time.
What management options are available?
Self-managed is for teams that install, monitor, and tune BitFire themselves. Managed Protection adds BitFire installation and ongoing operation during normal U.S. business hours. Priority Support adds around-the-clock coverage. Review the upgrade page for current scope and pricing.
Troubleshooting and support
The safest next steps when a visitor, integration, scan, or cleanup action does not work as expected.
What should I do when BitFire blocks a real visitor?
Reproduce the action in a normal browser, locate the request on the BitFire dashboard, and review why it was blocked. If the action is expected and safe, use Allow to create the narrowest applicable exception.
What if the website stops loading after I delete a file?
Use the emergency recovery prompt and enter the recovery code you saved before cleanup. The code remains active for 24 hours. If the prompt is unavailable or the code has expired, contact support for manual recovery.
What if a scan, repair, or deletion fails?
For a failed scan, send support the domain and browser console log. For a failed repair or deletion, include the domain, full file path, and exact error. Your host may prevent WordPress from changing the file.
What should I do during an active attack?
Contact BitFire Support immediately. If an attacker is still changing files, ordinary cleanup may not regain control. Support can help lock down the installation and provide an offline recovery process before scanning and repair continue.
What should I send to BitFire Support?
Include the domain, what you attempted, what happened, and any request ID, error message, file path, screenshot, or browser console log shown by BitFire. Never send passwords, secret keys, or payment credentials.