Every hack starts as a request. MalCare's real-time firewall inspects every single one with rules built only for WordPress — kept current by a 400,000-site threat network — and blocks attacks before your site runs them. It's integrated with your site, so there's no path around it. It configures itself. And the heavy lifting runs on our servers, so yours stays fast.
Your site is code that runs what the internet sends it. Most requests are visitors. Some are attacks — and by MalCare's numbers, 95% of WordPress hacks come through vulnerable plugins and themes, exploited by crafted requests, not guessed passwords. A firewall reads every request before your site executes anything, and turns the attacks away. Strong passwords lock the door; a firewall checks everything that comes through the mail slot.
Read: the attacks that take sites over aren't password guesses — they're crafted requests aimed at vulnerable plugin and theme code. That's why login-focused plugins alone give a false sense of security.
GET /product/42 — served, untouched.
SERVESame shape on the wire — with an exploit payload inside.
BLOCK · 403Every request passes through the firewall first. It's checked against WordPress-specialized rules, known attack signatures, and behavioral signals from the network — verdict immediate. Attacks get a 403. Everything else proceeds untouched. The rules update continuously; you never write or tune one.
Read: the firewall sits in the request path — inspection happens before execution, so a blocked attack costs your site nothing. Rules, signatures, and behavior signals arrive continuously from the threat network.
Visitor or attack — every request enters the same checkpoint.
INSPECTEDWordPress rules · known signatures · network behavior signals.
IMMEDIATEAttacks get a 403 before your site runs anything. Everything else proceeds untouched.
403 / SERVEGeneric WAFs run generic rules — in MalCare's words, "WAFs such as Cloudflare have generic rules which allow most attacks to pass through." MalCare's firewall does one platform, so its rules match how WordPress is actually attacked — covering the OWASP Top 10, the threat classes behind the vast majority of attacks.
Read: the OWASP Top 10 are the industry's canonical threat classes — responsible for the vast majority of attacks WordPress sites face. Specialization is what covers the rest.
A cloud WAF sits in front of your DNS — traffic is supposed to pass through it, but your site still answers on its own address, and an attacker who finds that address talks to your site directly. MalCare's firewall is integrated with the site: it's in the only request path there is. Every request that reaches WordPress passes through it — by construction, not by routing.
Read: this is architecture, not bravado — an integrated firewall is in the request path by construction. There's no origin address to discover and no seam to slip through, because there is no route to WordPress that skips it.
Your site still answers on its own address — find it, and the wall never sees you.
BYPASSABLEIn the only request path there is. No separate address, no seam.
NO WAY AROUNDRule building, threat correlation, and bot conviction happen on MalCare's infrastructure — your site does only lightweight enforcement, so it "will only be serving customers." And because the firewall turns away bot floods, sites typically get lighter when it goes on — MalCare is the only security plugin which makes your site faster.
Read: with bot floods turned away at the perimeter, most sites see server load drop when the firewall goes on — up to 70% lighter, per sites moving to MalCare.
Rule updates, threat correlation, network conviction, signature builds — all the heavy jobs.
THE HEAVY LIFTINGServes customers, enforces verdicts. Nothing else.
LOAD · LOWBot floods turned away — sites typically get lighter, up to 70%.
FASTEREvery attack anywhere in the network becomes protection everywhere. The same threat intelligence powers bot conviction, vulnerability response, and the rules on your perimeter — 18B+ requests analyzed and 2B+ attacks blocked every month (as of July 2026).
On any one of 400,000+ sites — a new exploit pattern, a new bad actor.
DETECTEDOn MalCare's servers, from the real attack — not a generic template.
BUILTEvery site's firewall learns it, automatically.
DEPLOYEDBefore that attack ever reached you. You did nothing.
ALREADY PROTECTEDThe core firewall inspects every request — and a family of specialist layers extends it, same network, same dashboard, all included.
Virtual patches built from the actual vulnerable code — live at disclosure. Covers the update gap. How shielding works →
Site-specific rules that guard even undiscovered flaws. Covers the window before disclosure. How it works →
The non-human crowd, convicted network-wide — good bots always pass. Covers the volume. How bots are identified →
Countries you don't serve, switched off in a few clicks. Covers the surface you choose. How blocking works →
Limits, captcha recovery, IP whitelist, and built-in 2FA — on the form and XML-RPC. Covers the door. The five layers →
OWASP + WordPress-specialized rules on every request, real-time. This page — the wall the specialists extend.
Traditional firewalls need to be manually tuned with rules and more. MalCare understands your site and then auto-configures itself — instant setup, no maintenance, no rule-writing. Ever.
Connect your site. The firewall understands it and configures itself — that's the whole job.
INSTANTNone. Rules arrive continuously from the network; nothing for you to tune or update.
NONELosing a customer to your own firewall costs more than most attacks. Ensuring that doesn't happen is a design goal, not an afterthought.
DESIGNED OUTOpen the firewall section anytime — every blocked attack is on the record, quietly.
STRONG & SILENTReal customers — quotes from our reviews and case studies.
MalCare sends few security notifications, so one day out of curiosity I checked their firewall section. I was pleasantly surprised that hundreds of attacks were being quietly thwarted! I really like this "strong & silent" protection.
I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.
Paul LaceyWordPress ExpertI had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.
Adam SilverConciergeWP · FounderYes. Updates close known holes on your schedule; attacks arrive as requests on theirs — and 95% of WordPress hacks exploit plugin and theme vulnerabilities, not passwords. The firewall covers the gap between the two, in real time.
Three ways. Generic WAFs run generic rules that let WordPress-specific attacks pass; MalCare's rules are built only for WordPress. A cloud WAF sits in front of your site and can be bypassed by finding the origin address; MalCare is part of the site, in the only request path there is. And there's nothing to configure — it tunes itself.
No. Enforcement on your site is lightweight — the heavy lifting (rule building, threat correlation, bot conviction) runs on MalCare's servers. And because the firewall turns away bot floods, sites typically get lighter when it goes on, by up to 70%.
There's no separate address to find and no seam to slip through — the firewall is integrated with your site, so every request that reaches WordPress passes through it by construction.
Preventing false positives is a design goal — losing a customer to your own firewall costs more than most attacks. Good bots, APIs, and integrations are recognized and allowed too.
The OWASP Top 10 threat classes (injection, XSS, broken access control, and the rest), WordPress-specific exploit patterns against vulnerable plugins and themes, bot floods, and login attacks — plus everything the specialist layers cover: virtual patching, site-specific atomic rules, geoblocking, and login protection.
No. The firewall auto-configures when you connect your site, and rules update continuously from the 400,000-site network. There is nothing to tune, ever.
Included — along with every specialist layer on this page. One plugin, one dashboard.
Real-time, WordPress-specialized, integrated with your site — zero configuration, zero added load.
Auto-configures on connect · no way around it · included in every plan