Plugins and themes
95% of hacked WordPress sites were hacked through a vulnerable plugin or theme.
Every request is checked before WordPress executes anything — against rules learned from attacks on 400,000+ sites, usually before the same attack ever reaches you. Zero configuration, zero load on your server.






Your site runs whatever the internet sends it. Attack requests look almost exactly like visitor requests — until your site runs them.
POST /wp-admin/admin-ajax.php HTTP/1.1Host: yoursite.comContent-Type: application/x-www-form-urlencodedaction=profile_save&user_id=42&nickname=sam&role= subscribera member updates their profileadministratoraccount 42 becomes an administratorYour site cannot tell them apart after it runs them. The firewall tells them apart before.
95% of hacked WordPress sites were hacked through a vulnerable plugin or theme.
The exploit rides inside an ordinary-looking request, aimed at code — not at your password.
A firewall checks every request before your site executes anything.
Every request passes through the firewall first. Attacks get a 403. Everything else proceeds untouched.
Generic WAFs run generic rules that let WordPress-specific attacks through. MalCare's firewall does only WordPress, so its rules match how WordPress is actually attacked.
Every OWASP threat class, plus the WordPress attack patterns generic rules never cover.
A cloud WAF stands in front of your site. MalCare's firewall is inside the only request path there is.
Your server does one lightweight job: enforce verdicts. Rule building, threat correlation, and bot conviction run on MalCare's infrastructure.
The core firewall checks every request. Five specialist layers extend it — same network, same dashboard, all included.
Patches a plugin flaw the day it is disclosed — before you can update.
Explore shielding →Site-specific rules for flaws nobody has found yet.
Explore Atomic Security →Limits, captcha, and built-in 2FA on the login form and XML-RPC.
Explore login protection →The firewall reads your site and sets itself up when you connect. After that, rules arrive on their own.
A security expert will tell you exactly what MalCare blocks that your current setup does not. No obligation.
Real-time, WordPress-only rules. Part of your site. Zero configuration, zero added load.