RASP protection
BitFire follows authorization into the application and blocks protected operations when the request does not have administrator authority—even when the exploit is new.
See the three controlsUpgrade to runtime protection that stops unauthorized PHP file writes, administrator account changes, and admin impersonation, then investigate hidden persistence with Threat Hunter and AI malware analysis.
BitFire FREE is for non-commercial use only: personal blogs, charity websites, and other sites that do not support commercial activity. Business, agency, client, lead-generation, membership, and ecommerce sites require a commercial license.
Review license guidancePRO combines enforcement during an attack with deeper investigation after suspicious activity. It is designed for sites where compromise has a real business cost.
BitFire follows authorization into the application and blocks protected operations when the request does not have administrator authority—even when the exploit is new.
See the three controlsInspect database content, WordPress cron jobs, database triggers, must-use plugins, the startup chain, and background PHP processes for persistence normal file scans do not see.
Explore Threat HunterUse 1,000 AI credits to review suspicious code with frontier models, understand why it was flagged, and make a more confident allow, repair, or delete decision.
Read the scanner guideA WAF asks whether a request looks malicious. BitFire RASP also asks whether that request is authorized to perform a dangerous operation inside WordPress.
BitFire installs a PHP stream wrapper around the filesystem and inspects every write to a .php file. If the active request does not have administrator authorization, the write is blocked before a web shell or backdoor reaches disk.
BitFire monitors database queries for user creation and privilege changes, with special attention to administrator access. If the request lacks admin-level authorization, the database update is blocked.
BLOCKS ROGUE ADMIN ACCOUNTSBitFire monitors attempts to impersonate an administrator. When the requesting session is not authorized for admin access, impersonation fails—blocking WP2Shell and other admin-level access-control failures.
BLOCKS AUTHENTICATION BYPASSThreat Hunter goes beyond a normal filesystem scan to find the mechanisms attackers use to survive cleanup and regain control later.
Why it matters: a background process, scheduled task, trigger, or stored script can reinfect a site after every malicious PHP file appears to be removed.
Enter the commercial WordPress domains you need to protect, then choose self-management, BitFire-managed operation, or around-the-clock priority support.
Have a licensing or compatibility question we have not covered? Talk directly with the BitFire team.
Contact BitFirePRO unlocks 1,000 AI malware analysis credits, advanced Threat Hunter audits, and runtime RASP enforcement for protected filesystem, database, and administrator impersonation operations.
Yes. BitFire FREE is licensed only for personal blogs, charities, and other non-commercial sites. A website used by a business, agency, client, store, membership program, or other commercial operation requires a commercial license.
One license covers one domain. Portfolio discounts begin at 2 sites, and the matching tier applies to every license in the purchase. The domain list controls the quantity so there are no unassigned licenses. For example, 10 sites at $28.00 per site is $280.00 per year before an optional per-site management package.
BitFire uses a block-by-default security model. This reduces the chance that unknown or unauthorized activity is allowed, but some legitimate traffic may initially be blocked. Those requests must be reviewed and approved so the site can perform its expected functions without weakening protection unnecessarily.
Self-managed is for teams that will install BitFire, monitor blocks, and approve legitimate traffic themselves. Managed Protection adds BitFire installation, configuration, maintenance, monitoring, and operational tuning during normal U.S. business hours for $200 per site per year. Priority Support includes managed installation and monitoring plus 24/7 coverage and a one-hour response time for any issue for $450 per site per year.
Yes. The annual single-site rate is $40 in September 2026, $50 in October, $60 in November, $70 in December, and $90 beginning January 2027. The portfolio discounts shown in the calculator are applied to those rates. A purchased license remains valid for one year; renewal pricing is handled separately.
No. RASP evaluates the authorization behind a protected operation. An unknown exploit can still be stopped when it tries to write PHP, create or elevate an administrator, or impersonate an admin without the required authorization.
Threat Hunter checks persistence outside ordinary malware files, including database content, cron tasks, MySQL triggers, the WordPress startup chain, must-use plugins, administrator accounts, and background PHP processes.
Add authorization-aware RASP, deeper persistence hunting, and AI-assisted malware analysis to every site you manage.