A high-performance firewall, built into your site.

Every hack starts as a request. MalCare's real-time firewall inspects every single one with rules built only for WordPress — kept current by a 400,000-site threat network — and blocks attacks before your site runs them. It's integrated with your site, so there's no path around it. It configures itself. And the heavy lifting runs on our servers, so yours stays fast.

2B+attacks blocked / mo
18B+requests analyzed / mo
0 configreal-time · included
THE PERIMETER · LIVEFIG. 0 · THE FUSED RINGattacks blocked today · 31,264sql injectionplugin exploitxss payloadbot floodrfi attemptvisitorsYOUR SITEfirewall · fusedlooking for a way around…no seam · no way aroundattacks — blocked at the ringvisitors — served, untouched
the perimeter · decisionslive

Trusted by 400,000+ websites across 120 countries

Intel
Toshiba
eBay
Manthan
SiteCare
NMU
01Why a firewall

Every hack starts as a request.

Your site is code that runs what the internet sends it. Most requests are visitors. Some are attacks — and by MalCare's numbers, 95% of WordPress hacks come through vulnerable plugins and themes, exploited by crafted requests, not guessed passwords. A firewall reads every request before your site executes anything, and turns the attacks away. Strong passwords lock the door; a firewall checks everything that comes through the mail slot.

FIG. 1Two requests — same shape on the wire, different cargo
A VISITORGET /product/42serve ✓AN ATTACKPOST /?page=PAYLOADblock ✕ · 403the exploit rides inside an ordinary-looking requestyour site can't tell them apart after it runs them. the firewall tells them apart before.

Read: the attacks that take sites over aren't password guesses — they're crafted requests aimed at vulnerable plugin and theme code. That's why login-focused plugins alone give a false sense of security.

FIG. 1Two requests

A visitor

GET /product/42 — served, untouched.

SERVE

An attack

Same shape on the wire — with an exploit payload inside.

BLOCK · 403
02How it works

Inspected before your site runs a single line.

Every request passes through the firewall first. It's checked against WordPress-specialized rules, known attack signatures, and behavioral signals from the network — verdict immediate. Attacks get a 403. Everything else proceeds untouched. The rules update continuously; you never write or tune one.

FIG. 2The checkpoint
request · visitorrequest · attackTHE FIREWALL · VERDICT IMMEDIATErules · wordpress-specificsignatures · known attacksbehavior · network signalsYOUR SITE403 · blocked — your site never saw itchecked before your site runs anything — not cleaned up after.

Read: the firewall sits in the request path — inspection happens before execution, so a blocked attack costs your site nothing. Rules, signatures, and behavior signals arrive continuously from the threat network.

FIG. 2The checkpoint
1

Request arrives

Visitor or attack — every request enters the same checkpoint.

INSPECTED
2

Checked in real time

WordPress rules · known signatures · network behavior signals.

IMMEDIATE
3

Verdict

Attacks get a 403 before your site runs anything. Everything else proceeds untouched.

403 / SERVE
03Coverage

Rules built only for WordPress. Coverage for the attacks that matter.

Generic WAFs run generic rules — in MalCare's words, "WAFs such as Cloudflare have generic rules which allow most attacks to pass through." MalCare's firewall does one platform, so its rules match how WordPress is actually attacked — covering the OWASP Top 10, the threat classes behind the vast majority of attacks.

FIG. 3The coverage board · OWASP Top 10 + WordPress-specific rules
InjectionSQL, command & code injection
Broken access controlprivilege & path abuse
Cross-site scriptingstored & reflected XSS
Insecure designabusable flows & logic
Security misconfigurationexposed surfaces
Vulnerable componentsplugin & theme exploits
Authentication failurescredential attacks
Integrity failurestampered updates & data
Logging & monitoring gapscovered by the activity log
Server-side request forgerySSRF patterns
+WordPress-specific rulesthe attack patterns generic WAFs don't describe — built from how WordPress is actually attacked

Read: the OWASP Top 10 are the industry's canonical threat classes — responsible for the vast majority of attacks WordPress sites face. Specialization is what covers the rest.

04Integrated

Part of your site. So there's no way around it.

A cloud WAF sits in front of your DNS — traffic is supposed to pass through it, but your site still answers on its own address, and an attacker who finds that address talks to your site directly. MalCare's firewall is integrated with the site: it's in the only request path there is. Every request that reaches WordPress passes through it — by construction, not by routing.

FIG. 4Two architectures
CLOUD WAF · IN FRONTTHE WALLSITEorigin found · wall skippedhitMALCARE · PART OF THE SITESITE · FIREWALL FUSEDno separate address · no seama wall in front can be walked around. a wall that's part of the site can't.

Read: this is architecture, not bravado — an integrated firewall is in the request path by construction. There's no origin address to discover and no seam to slip through, because there is no route to WordPress that skips it.

FIG. 4Two architectures

Cloud WAF · in front

Your site still answers on its own address — find it, and the wall never sees you.

BYPASSABLE

MalCare · part of the site

In the only request path there is. No separate address, no seam.

NO WAY AROUND
05Performance

The heavy lifting runs on our servers. Not yours.

Rule building, threat correlation, and bot conviction happen on MalCare's infrastructure — your site does only lightweight enforcement, so it "will only be serving customers." And because the firewall turns away bot floods, sites typically get lighter when it goes on — MalCare is the only security plugin which makes your site faster.

FIG. 5Where the work happens
MALCARE SERVERSrule updates · continuousthreat correlation · 400,000+ sitesnetwork conviction · bots & actorssignature builds · new attacksverdict intelligence · behaviorrules & verdicts, deliveredYOUR SERVERserve customersenforce verdicts · lightweight— nothing else —load · lowhigh-performance by architecture — the firewall adds intelligence to your site, not weight.

Read: with bot floods turned away at the perimeter, most sites see server load drop when the firewall goes on — up to 70% lighter, per sites moving to MalCare.

FIG. 5Where the work happens
1

MalCare servers

Rule updates, threat correlation, network conviction, signature builds — all the heavy jobs.

THE HEAVY LIFTING
2

Your server

Serves customers, enforces verdicts. Nothing else.

LOAD · LOW
3

The bonus

Bot floods turned away — sites typically get lighter, up to 70%.

FASTER
06The network

400,000 sites teach your firewall. Continuously.

Every attack anywhere in the network becomes protection everywhere. The same threat intelligence powers bot conviction, vulnerability response, and the rules on your perimeter — 18B+ requests analyzed and 2B+ attacks blocked every month (as of July 2026).

6.1

An attack is seen

On any one of 400,000+ sites — a new exploit pattern, a new bad actor.

DETECTED
6.2

A rule is built

On MalCare's servers, from the real attack — not a generic template.

BUILT
6.3

The network updates

Every site's firewall learns it, automatically.

DEPLOYED
6.4

Your site was ready

Before that attack ever reached you. You did nothing.

ALREADY PROTECTED
07The family

Not one wall. A stack of specialists.

The core firewall inspects every request — and a family of specialist layers extends it, same network, same dashboard, all included.

SPECIALIST

Vulnerability Shield

Virtual patches built from the actual vulnerable code — live at disclosure. Covers the update gap. How shielding works →

SPECIALIST

Atomic Security

Site-specific rules that guard even undiscovered flaws. Covers the window before disclosure. How it works →

SPECIALIST

Bot Protection

The non-human crowd, convicted network-wide — good bots always pass. Covers the volume. How bots are identified →

SPECIALIST

Geoblocking

Countries you don't serve, switched off in a few clicks. Covers the surface you choose. How blocking works →

SPECIALIST

Login Protection

Limits, captcha recovery, IP whitelist, and built-in 2FA — on the form and XML-RPC. Covers the door. The five layers →

THE CORE

The firewall

OWASP + WordPress-specialized rules on every request, real-time. This page — the wall the specialists extend.

08Zero config

It configures itself. And it never blocks a customer.

Traditional firewalls need to be manually tuned with rules and more. MalCare understands your site and then auto-configures itself — instant setup, no maintenance, no rule-writing. Ever.

8.1

Setup

Connect your site. The firewall understands it and configures itself — that's the whole job.

INSTANT
8.2

Maintenance

None. Rules arrive continuously from the network; nothing for you to tune or update.

NONE
8.3

False positives

Losing a customer to your own firewall costs more than most attacks. Ensuring that doesn't happen is a design goal, not an afterthought.

DESIGNED OUT
8.4

Watching it work

Open the firewall section anytime — every blocked attack is on the record, quietly.

STRONG & SILENT
09Voices

What customers say.

Real customers — quotes from our reviews and case studies.

"

MalCare sends few security notifications, so one day out of curiosity I checked their firewall section. I was pleasantly surprised that hundreds of attacks were being quietly thwarted! I really like this "strong & silent" protection.

Jo WalthamCallia Web
"

I was on the beach with my family when MalCare notified me of a plugin vulnerability across 50 of my sites. With one click on my smartphone, all sites were fixed within minutes.

Paul LaceyPaul LaceyWordPress Expert
Watch case study →
"

I had been running iThemes, WordFence & Sucuri, but they kept getting hacked. Then I installed MalCare, which quickly found the malware and cleaned up the entire site.

Adam SilverAdam SilverConciergeWP · Founder
Watch case study →
10Questions

Answered straight.

Do I need a firewall if I keep everything updated and use strong passwords?+

Yes. Updates close known holes on your schedule; attacks arrive as requests on theirs — and 95% of WordPress hacks exploit plugin and theme vulnerabilities, not passwords. The firewall covers the gap between the two, in real time.

How is this different from Cloudflare or my host's WAF?+

Three ways. Generic WAFs run generic rules that let WordPress-specific attacks pass; MalCare's rules are built only for WordPress. A cloud WAF sits in front of your site and can be bypassed by finding the origin address; MalCare is part of the site, in the only request path there is. And there's nothing to configure — it tunes itself.

Will it slow my site down?+

No. Enforcement on your site is lightweight — the heavy lifting (rule building, threat correlation, bot conviction) runs on MalCare's servers. And because the firewall turns away bot floods, sites typically get lighter when it goes on, by up to 70%.

Can attackers get around it?+

There's no separate address to find and no seam to slip through — the firewall is integrated with your site, so every request that reaches WordPress passes through it by construction.

Will it ever block my real visitors?+

Preventing false positives is a design goal — losing a customer to your own firewall costs more than most attacks. Good bots, APIs, and integrations are recognized and allowed too.

What exactly does it block?+

The OWASP Top 10 threat classes (injection, XSS, broken access control, and the rest), WordPress-specific exploit patterns against vulnerable plugins and themes, bot floods, and login attacks — plus everything the specialist layers cover: virtual patching, site-specific atomic rules, geoblocking, and login protection.

Do I have to configure or maintain rules?+

No. The firewall auto-configures when you connect your site, and rules update continuously from the 400,000-site network. There is nothing to tune, ever.

Is the firewall included, or an add-on?+

Included — along with every specialist layer on this page. One plugin, one dashboard.

11Start

Put a real firewall between your site and the internet.

Real-time, WordPress-specialized, integrated with your site — zero configuration, zero added load.

Auto-configures on connect · no way around it · included in every plan