Wordfence · Setup & Tuning

Wordfence Set Up Properly — Most Installs Never Finish It

Wordfence is on millions of sites and a large share of them are running it in a weaker configuration than the owner believes. The firewall is usually loading after WordPress rather than in front of it, the free rules arrive a month behind, and behind a proxy its blocking can be aimed at the wrong address entirely. All three are fixable in an afternoon.

Ask about your Wordfence setup

Australian team

Based here, working your hours — not a timezone away

144+ projects delivered

Over 10+ years building and maintaining sites for Australian businesses

One developer, start to finish

The same person every time — no re-explaining your site

Straight answers, on your terms

We only take work we can finish. Ask us anything first — no obligation

If the site is already infected, cleaning it comes first and starts at $299 — a scanner is not a cleaner. If your problem is the volume of traffic rather than what it does once it arrives, the Cloudflare page is the cheaper answer. This page is about making Wordfence do what you already think it is doing.

On the free version, firewall rules arrive thirty days late

This is the fact that decides whether the free version is adequate for you, and it is not prominently advertised. New firewall rules and malware signatures go to paying customers first and reach free installations roughly a month later. For a brochure site that is usually an acceptable trade. For a site taking payments, holding customer data, or running a plugin that has just had a vulnerability disclosed, a month is precisely the window that matters — because attacks against a newly published vulnerability begin within days, not weeks.

Your firewall is probably running after WordPress has loaded

Wordfence can run in two ways. In its basic state it is a WordPress plugin, so a malicious request has already reached PHP and started WordPress before the firewall sees it. Its stronger mode loads before WordPress does, which is a server configuration step the installer prompts for and an enormous number of people never complete. The plugin will keep reporting itself as active either way. Checking which mode you are actually in, and finishing the setup, is the single biggest improvement available on most Wordfence sites and it costs nothing.

Behind a proxy it can be blocking the wrong address entirely

Wordfence has its own setting for how to determine a visitor's IP, and it has to match how your site is actually served. Get it wrong and one of two things happens: every visitor appears to share one address, so blocking an attacker locks out everybody, or the setting trusts a header that can be forged, so blocking can be evaded and rate limits mean nothing. Neither reports an error. This is the check we run first on any site sitting behind a CDN.

Scans cost real resources, and the schedule matters

A full scan reads every file on the site and compares core files against the official release. That is genuine work, and on modest shared hosting it can be the heaviest thing the server does all day — which is why some sites get slow at the same time every day for no apparent reason. The fix is not to stop scanning. It is to schedule it away from your traffic, choose a scan depth proportionate to the site, and stop scanning directories that never change.

Alert fatigue is a security problem, not an annoyance

Out of the box Wordfence emails a great deal, much of it routine, and the predictable outcome is a filter rule that files all of it away unread. At that point the alert that actually mattered goes to the same place as the noise. Tuning this properly means deciding which events are worth waking someone for — an administrator being created, a core file changing, a known vulnerability appearing in something you run — and turning the rest off so the remainder gets read.

What a scan finding actually means

Scan results need reading rather than reacting to. An unfamiliar file in a core directory is serious and is the one to look at first. A plugin flagged as abandoned is a planning matter, not an emergency. A file that differs from the official release is often a previous developer's edit rather than an intrusion. Treating everything as urgent leads to deleting something the site needed; treating everything as noise leads to missing the one that counted.

Free or paid, decided on your actual risk

The honest test is what a month-old rule set would cost you. A small brochure site kept properly updated is usually fine on the free version, and we will say so. A site handling payments or customer records, or one that cannot be patched quickly because changes need approval, is buying that month — which is the actual product. What we would not do is tell every site to upgrade, because for a good number of them the money is better spent on hosting or on keeping things up to date.

What this costs

A full configuration pass — firewall mode completed, IP detection matched to your setup, scans scheduled sensibly, alerts tuned, existing findings triaged and explained — starts at $300 and is fixed-quoted. A review of what you currently have, written down, is $249. Ongoing work is $165 an hour, or $750 for five hours and $1,400 for ten.

Free or Premium, on the things that actually differ

Feature Free Premium
New firewall rules About 30 days behind As released
New malware signatures About 30 days behind As released
Two-factor authentication Yes Yes
Firewall can run before WordPress loads Yes, once setup is finished Yes, once setup is finished
Blocking by country No Yes
The right choice when Updates are applied promptly and a breach would be embarrassing rather than costly You take payments or hold customer data, or changes need approval before they can ship

The product being sold is the thirty days. Everything else on this table is close enough that it should not decide the question.

Care plans

Plans, and what each one actually includes.

Month to month, no lock-in — change or cancel any time. Prices in AUD.

Essential

$159 /mo AUD

Keeping a site secure, updated and online. No development time included.

What is covered

  • WordPress core, theme & plugin check
  • Weekly off-site backupsA full copy of your site and database taken every week and stored on separate infrastructure, not on your own server — so a failure, a hack or a bad update cannot take the backups with it., restorable on request
  • Uptime & SSL monitoringYour site is checked from outside every few minutes. If it goes down, or the security certificate is about to expire, the alert reaches us — you are not the monitoring system. — alerts come to us, not you
  • Malware checkFiles and database are scanned for injected code, so anything that has been planted is found rather than waiting to be noticed. maintained
  • Broken-link and 404 checks
  • Monthly report of site status
  • Email support included
Start with Essential

Billed monthly in AUD. Cancel any time — no lock-in.

Dev

$700 /mo AUD

Your site stays up, stays secure and stays current — and when something breaks, a developer fixes it rather than logging it.

What is covered

  • Critical security & performance checksThe checks that catch the things that actually take a site down: outdated core and plugins with known vulnerabilities, injected code, error rates, and pages that have become slow enough to lose visitors. every week
  • Uptime & SSL monitoringYour site is checked from outside every few minutes. If it goes down, or the security certificate is about to expire, the alert reaches us — you are not the monitoring system. — alerts come to us, not you
  • Weekly off-site backupsA full copy of your site and database taken every week and stored on separate infrastructure, not on your own server — so a failure, a hack or a bad update cannot take the backups with it., restorable on request
  • Your developer emails you every month with what changed and what needs attention
  • Staging site for development changesA private copy of your site where changes are built and checked before anyone else sees them. Updates, new sections and design work go there first, get looked at on phone, tablet and desktop widths, and only reach the live site once you have said so. It matters most on page-builder sites, where a bad update does not error — it re-renders, and the page looks subtly wrong on a screen size nobody checked. — nothing reaches the live site unapproved
  • 5 hours of developer time a month
  • Fixes and small changes — not a build. Content, layout and design edits, plugin and integration setup (included in dev hours)
  • 1 basic page built to match your existing design (included in dev hours)
  • Weekly WordPress core, theme & plugin updates (included in dev hours)
  • Weekly malware and virus check, and fix (included in dev hours)
  • Speed & Core Web VitalsCore Web Vitals are the three loading and stability measures Google uses as a ranking signal — how fast the main content appears, how quickly the page responds to a tap, and whether it jumps around while loading. We measure and fix all three. check and fix (included in dev hours)
  • Priority queue — a developer is assigned and contacts you within 48 hours
  • Urgent issues covered for 1 hour of immediate debugging — you are told what we found, while we work and once it is fixed
Choose Dev

Billed monthly in AUD. Cancel any time — no lock-in.

Most popular

Master

$1,300 /mo AUD

Where Dev fixes and maintains, Master builds — pages, integrations, and the email and domain problems nobody else will own.

Everything in Dev Plan included +

  • Staging site for development changesA private copy of your site where changes are built and checked before anyone else sees them. Updates, new sections and design work go there first, get looked at on phone, tablet and desktop widths, and only reach the live site once you have said so. It matters most on page-builder sites, where a bad update does not error — it re-renders, and the page looks subtly wrong on a screen size nobody checked. — nothing reaches the live site unapproved
  • 10 hours of developer time a month
  • Everything in Dev — the same checks, monitoring, backups and monthly email
  • Up to 3 pages designed and built (included in dev hours)
  • CRM, accounting and API integrationsConnecting your site to the systems you already run — a CRM like HubSpot, accounting like Xero, or any service with an API — so data moves between them without anyone retyping it. (included in dev hours)
  • Email deliverability problemsWhen forms stop arriving, or your mail lands in spam. We work through the sending records — SPF, DKIM and DMARC — and the mail service itself, rather than telling you to check your junk folder. diagnosed and fixed (included in dev hours)
  • Domain and DNS issuesExpiring domains, records pointing at the wrong place, certificates that will not renew, a migration that left half the traffic behind. The infrastructure layer most agencies hand back to you. handled (included in dev hours)
  • Custom features and functionality (included in dev hours)
  • WooCommerce & payment gateway work (included in dev hours)
  • Same-day response on anything urgent — a developer will work outside business hours if needed
  • Quarterly performance and security checksEvery three months we re-run the full audit: load times and Core Web Vitals, plugin and PHP versions, user accounts and permissions, backup restores, and anything flagged since the last review. You get the findings in writing. (included in dev hours)
Choose Master

Billed monthly in AUD. Cancel any time — no lock-in.

Ultimate

Quoted scoped to the work

When the roadmap needs more than Master, or the work is better run as a project.

Get a quote

Everything in Master Plan included +

  • 20+ hours a month, or a fixed-price project
  • A standing slot in our schedule
  • Multi-site and white-label arrangementsWe look after several sites under one agreement, and — if you are an agency or consultancy — we can work under your brand, so your client only ever deals with you.
  • Architecture, infrastructure and hosting work
  • Direct access, no ticket queue
  • We will tell you honestly whether a retainer or a fixed quote costs you less
Why CloudyWP

Why Most Wordfence Installs Are Weaker Than Their Owners Think

The plugin reports itself active either way. That is the problem.

The Firewall Actually In Front

In its basic state Wordfence is a plugin, so a malicious request has already started WordPress before the firewall sees it. The stronger mode is a server step the installer prompts for and most people never finish.

The Thirty-Day Gap Explained

Free installs receive new firewall rules roughly a month after paying ones. Whether that matters depends entirely on what a month of exposure would cost you — so we tell you which side of that line your site is on.

Blocking the Right Address

Behind a CDN, Wordfence needs telling how to read a visitor IP. Set wrong, either everyone shares one address and a block locks out the office, or it trusts a forgeable header and the limits mean nothing.

Scans Off Your Busy Hours

A full scan reads every file on the site and is often the heaviest thing a shared host does all day. Scheduled badly it is why a site is slow at the same time daily for no apparent reason.

Alerts Worth Reading

Out of the box it emails constantly, so somebody files all of it unread — and the one that mattered goes to the same folder. We keep the events worth waking someone for and silence the rest.

Findings Triaged, Not Feared

An unknown file in core is serious. An abandoned plugin is a planning matter. A changed file is often a previous developer. Treating all three the same way is how sites get broken by their own cleanup.

What Wordfence users ask

Is the free version good enough?

For a well-maintained brochure site, usually. The thing you are giving up is about thirty days on new firewall rules, so the question is what could happen to your site in a month if something you run has a vulnerability disclosed tomorrow. If the answer is "we would lose customer data or the ability to trade", buy the month. If it is "our contact page would be defaced", the free version plus prompt updates is a reasonable position.

We run Cloudflare as well. Is Wordfence redundant?

No, they cover different ground. Cloudflare decides whether a request reaches you; Wordfence notices that a file changed, an administrator appeared, or a plugin you run has a known vulnerability — none of which is visible from outside. What does need attention when both are present is making sure Wordfence reads the real visitor address correctly, because otherwise its blocking is aimed at the proxy.

Wordfence says our site is clean. Does that settle it?

It is good evidence, not proof. A scan compares core files against the official release and looks for known patterns, which is exactly the right first check — but well-hidden code in a theme or a plugin directory can pass. If you have other signals, such as search results that differ from what visitors see or outbound mail you did not send, treat those as more informative than a clean scan.

It blocked one of our own staff.

Usually a failed-login threshold doing its job, and it is resolved by allowlisting the address or relaxing the rule. Worth checking at the same time whether IP detection is set correctly — if everyone on the site appears to share one address, a single person getting it wrong repeatedly can lock out the entire office, and that will happen again.

Is the scan making our site slow?

It can be, and there is an easy way to know: compare the time of day the site feels slow against the scan schedule. If they coincide, move the scan and reduce its scope. If they do not, something else is responsible and swapping security plugins would have been an expensive way to find that out.

Can you set up two-factor authentication for our team?

Yes, and it is included free, which makes it one of the better things available here. The parts worth doing carefully are enforcing it for administrator and editor accounts rather than leaving it optional, and making sure somebody keeps recovery codes somewhere sensible — the usual failure is not the attacker, it is a staff member with a new phone locking themselves out.

We have dozens of "abandoned plugin" warnings.

Those are planning information rather than emergencies. A plugin that has not been updated in a long time still works until something around it changes — a PHP version, a WordPress release — and then it stops, usually inconveniently. The useful response is a list of which ones are load-bearing, what would replace them, and roughly what that costs, so it becomes a scheduled decision instead of an outage.

Should we hide our login page as well?

It reduces automated noise and it is not a security control — anyone specifically interested in you will find it. It is worth doing if login attempts are consuming meaningful resources, provided the new address is recorded somewhere other than in one person's memory. It should never be the reason a weak administrator password is tolerated.

Can you manage this for us rather than configuring it once?

Yes — that is a care plan from $159/mo, where the alerts come to us and the updates that close vulnerabilities get applied rather than noticed. The configuration work on this page is worth doing either way, because a plan watching a badly configured firewall is still watching a badly configured firewall.

Ask about your Wordfence setup

A short call, a fixed quote, and no obligation either way.

Get a fixed quote

Why CloudyWP

Free Wordfence rules arrive 30 days late and most firewalls run after WordPress loads, not in front of it. We finish the setup properly. Melbourne-based.

Get a fixed quote

02 — How we work

From first call to live — four steps, no surprises.

Every CloudyWP project runs the same way, whether it is a one-page site or a store with a thousand SKUs. Here is exactly what happens.

01

We map what you actually need.

A single scoping call, then a written plan: what gets built, what it costs, and when it ships. No discovery-phase invoices, no moving targets.

Typically 48 hours

02

We design and build it properly.

Custom WordPress or Shopify on clean code you own outright. Every build ships fast, passes Core Web Vitals, and is handed over documented.

2–6 weeks typical

03

We automate the busywork.

Your site talks to the tools you already run — CRM, invoicing, email, stock. The repetitive admin stops being someone's job and starts running itself.

Average 15 hrs saved weekly

Scope A fixed quote, in writing

Deliverables, price and dates agreed before a line of code is written.

  • Free scoping call
  • Written scope document
  • Fixed price, no hourly creep

48 hrs to your quote

Get a quote