On the free version, firewall rules arrive thirty days late
This is the fact that decides whether the free version is adequate for you, and it is not prominently advertised. New firewall rules and malware signatures go to paying customers first and reach free installations roughly a month later. For a brochure site that is usually an acceptable trade. For a site taking payments, holding customer data, or running a plugin that has just had a vulnerability disclosed, a month is precisely the window that matters — because attacks against a newly published vulnerability begin within days, not weeks.
Your firewall is probably running after WordPress has loaded
Wordfence can run in two ways. In its basic state it is a WordPress plugin, so a malicious request has already reached PHP and started WordPress before the firewall sees it. Its stronger mode loads before WordPress does, which is a server configuration step the installer prompts for and an enormous number of people never complete. The plugin will keep reporting itself as active either way. Checking which mode you are actually in, and finishing the setup, is the single biggest improvement available on most Wordfence sites and it costs nothing.
Behind a proxy it can be blocking the wrong address entirely
Wordfence has its own setting for how to determine a visitor's IP, and it has to match how your site is actually served. Get it wrong and one of two things happens: every visitor appears to share one address, so blocking an attacker locks out everybody, or the setting trusts a header that can be forged, so blocking can be evaded and rate limits mean nothing. Neither reports an error. This is the check we run first on any site sitting behind a CDN.
Scans cost real resources, and the schedule matters
A full scan reads every file on the site and compares core files against the official release. That is genuine work, and on modest shared hosting it can be the heaviest thing the server does all day — which is why some sites get slow at the same time every day for no apparent reason. The fix is not to stop scanning. It is to schedule it away from your traffic, choose a scan depth proportionate to the site, and stop scanning directories that never change.
Alert fatigue is a security problem, not an annoyance
Out of the box Wordfence emails a great deal, much of it routine, and the predictable outcome is a filter rule that files all of it away unread. At that point the alert that actually mattered goes to the same place as the noise. Tuning this properly means deciding which events are worth waking someone for — an administrator being created, a core file changing, a known vulnerability appearing in something you run — and turning the rest off so the remainder gets read.
What a scan finding actually means
Scan results need reading rather than reacting to. An unfamiliar file in a core directory is serious and is the one to look at first. A plugin flagged as abandoned is a planning matter, not an emergency. A file that differs from the official release is often a previous developer's edit rather than an intrusion. Treating everything as urgent leads to deleting something the site needed; treating everything as noise leads to missing the one that counted.
Free or paid, decided on your actual risk
The honest test is what a month-old rule set would cost you. A small brochure site kept properly updated is usually fine on the free version, and we will say so. A site handling payments or customer records, or one that cannot be patched quickly because changes need approval, is buying that month — which is the actual product. What we would not do is tell every site to upgrade, because for a good number of them the money is better spent on hosting or on keeping things up to date.
What this costs
A full configuration pass — firewall mode completed, IP detection matched to your setup, scans scheduled sensibly, alerts tuned, existing findings triaged and explained — starts at $300 and is fixed-quoted. A review of what you currently have, written down, is $249. Ongoing work is $165 an hour, or $750 for five hours and $1,400 for ten.