<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: WordFence Security Plugin &#8211; Why It&#8217;s The Best	</title>
	<atom:link href="https://blog.tbwhs.com/wordfence-security-wordpress-plugin/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/</link>
	<description></description>
	<lastBuildDate>Tue, 07 Nov 2017 19:30:14 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.1</generator>
	<item>
		<title>
		By: tbwhs		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27527</link>

		<dc:creator><![CDATA[tbwhs]]></dc:creator>
		<pubDate>Tue, 07 Nov 2017 19:30:14 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-27527</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27294&quot;&gt;Kat Chang&lt;/a&gt;.

Sometimes there are backdoors on your site or the server you are hosting your website on that security plugins would not be able to detect. There is a vulnerability somewhere that needs to be fixed. Have you asked your web host for help? Best of luck to you!]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27294">Kat Chang</a>.</p>
<p>Sometimes there are backdoors on your site or the server you are hosting your website on that security plugins would not be able to detect. There is a vulnerability somewhere that needs to be fixed. Have you asked your web host for help? Best of luck to you!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Kat Chang		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27294</link>

		<dc:creator><![CDATA[Kat Chang]]></dc:creator>
		<pubDate>Thu, 19 Oct 2017 10:34:47 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-27294</guid>

					<description><![CDATA[Hi Garen, thanks for the article! I have been using Wordfence for a month now, however, my sites have been hacked everyday this week despite having Wordfence on. I know its not 100%, and we can revert to the backup. It took the entire day to work out where the malware was (WF did not find it). 

Will the premium version work better? What would your advice be?]]></description>
			<content:encoded><![CDATA[<p>Hi Garen, thanks for the article! I have been using Wordfence for a month now, however, my sites have been hacked everyday this week despite having Wordfence on. I know its not 100%, and we can revert to the backup. It took the entire day to work out where the malware was (WF did not find it). </p>
<p>Will the premium version work better? What would your advice be?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Garen		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27100</link>

		<dc:creator><![CDATA[Garen]]></dc:creator>
		<pubDate>Sat, 15 Apr 2017 19:12:30 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-27100</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27055&quot;&gt;Howard&lt;/a&gt;.

I haven&#039;t noticed that WordFence slows down your website. Sometimes the live traffic feature can use too many resources for your setup and cause problems. Maybe try disabling that option if you haven&#039;t already.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27055">Howard</a>.</p>
<p>I haven&#8217;t noticed that WordFence slows down your website. Sometimes the live traffic feature can use too many resources for your setup and cause problems. Maybe try disabling that option if you haven&#8217;t already.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Howard		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27055</link>

		<dc:creator><![CDATA[Howard]]></dc:creator>
		<pubDate>Thu, 09 Mar 2017 17:11:03 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-27055</guid>

					<description><![CDATA[I read that that wordfence slows down your website; what do you make of this?
Thanks]]></description>
			<content:encoded><![CDATA[<p>I read that that wordfence slows down your website; what do you make of this?<br />
Thanks</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Garen		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-27006</link>

		<dc:creator><![CDATA[Garen]]></dc:creator>
		<pubDate>Tue, 21 Feb 2017 10:14:17 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-27006</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-26999&quot;&gt;Farzana&lt;/a&gt;.

Yeah, I know what you mean about Wordfence telling you .txt files have been changed.  There is a button that you can click that will just ignore them in the future.  I have used this for years.  Never do I see those messages again!]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-26999">Farzana</a>.</p>
<p>Yeah, I know what you mean about Wordfence telling you .txt files have been changed.  There is a button that you can click that will just ignore them in the future.  I have used this for years.  Never do I see those messages again!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Farzana		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-26999</link>

		<dc:creator><![CDATA[Farzana]]></dc:creator>
		<pubDate>Mon, 20 Feb 2017 10:36:13 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-26999</guid>

					<description><![CDATA[I have used WordFence for several years now.  This plugin has saved me time and time again.  When files get infected, I really like how you can revert back to a previous version.  It’s very easy to do and is a lifesaver.  However, WordFence does let you know when text files are changed.  These are mostly just read me files with plugins or themes.  It’s kind of annoying, but I always just disregard those.]]></description>
			<content:encoded><![CDATA[<p>I have used WordFence for several years now.  This plugin has saved me time and time again.  When files get infected, I really like how you can revert back to a previous version.  It’s very easy to do and is a lifesaver.  However, WordFence does let you know when text files are changed.  These are mostly just read me files with plugins or themes.  It’s kind of annoying, but I always just disregard those.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Mats Schmid		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-26715</link>

		<dc:creator><![CDATA[Mats Schmid]]></dc:creator>
		<pubDate>Sat, 10 Dec 2016 13:01:24 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-26715</guid>

					<description><![CDATA[Outstanding article! Wordfence is definitely a must have plugin. I am using it for all my Wordpress websites upon recommendation from my hosting provider. It has very useful features to protect my site from hackers.

Going to certainly make a couple adjustments that you have suggested.  I am even using the Premium version, too.  Love it!]]></description>
			<content:encoded><![CDATA[<p>Outstanding article! Wordfence is definitely a must have plugin. I am using it for all my WordPress websites upon recommendation from my hosting provider. It has very useful features to protect my site from hackers.</p>
<p>Going to certainly make a couple adjustments that you have suggested.  I am even using the Premium version, too.  Love it!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Garen		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-26182</link>

		<dc:creator><![CDATA[Garen]]></dc:creator>
		<pubDate>Mon, 29 Feb 2016 17:42:00 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-26182</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-26180&quot;&gt;Kim D.&lt;/a&gt;.

I would have to say that I am really not a fan of Wordfences caching system.  I do not use them  It doesn’t seem to be quite as effective as &lt;a href=&quot;https://tbwhs.com/blog/setting-up-wp-super-cache/&quot; rel=&quot;nofollow&quot;&gt;WP Super Cache&lt;/a&gt;.

I would recommend disabling the caching for Wordfence.  But, Wordfence is great for security!]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-26180">Kim D.</a>.</p>
<p>I would have to say that I am really not a fan of Wordfences caching system.  I do not use them  It doesn’t seem to be quite as effective as <a href="https://tbwhs.com/blog/setting-up-wp-super-cache/" rel="nofollow">WP Super Cache</a>.</p>
<p>I would recommend disabling the caching for Wordfence.  But, Wordfence is great for security!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Kim D.		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-26180</link>

		<dc:creator><![CDATA[Kim D.]]></dc:creator>
		<pubDate>Mon, 29 Feb 2016 02:55:00 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-26180</guid>

					<description><![CDATA[I was wondering what do you think of the caching settings for Wordfence.  I have used them in the past but they really don’t seem to be all that great?  It seems to have conflicts with some other Wordpress plugins.]]></description>
			<content:encoded><![CDATA[<p>I was wondering what do you think of the caching settings for Wordfence.  I have used them in the past but they really don’t seem to be all that great?  It seems to have conflicts with some other WordPress plugins.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Garen		</title>
		<link>https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-25847</link>

		<dc:creator><![CDATA[Garen]]></dc:creator>
		<pubDate>Sun, 12 Apr 2015 22:08:00 +0000</pubDate>
		<guid isPermaLink="false">https://tbwhs.com/blog/?p=2386#comment-25847</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-25844&quot;&gt;Teresa&lt;/a&gt;.

&lt;strong&gt;Under “alerts” make sure the following are checked:&lt;/strong&gt;

“Alert on critical problems”

“Alert on warnings”

“Alert when IP address is blocked”

“Alert when some is locked out from login”

“Alert when the “lost password” form is used for valid user”

“Alert me when a non-admin user signs in”

&lt;strong&gt;With “scans” make sure everything is checked&lt;/strong&gt;

&lt;strong&gt;Under “firewall rules” configure these settings:&lt;/strong&gt;

Check “Immediately block fake Google crawlers”

Make sure “Verified Google crawlers have unlimited access to the site”

If anyone&#039;s requests exceed: 240 per minute (4 per  second) then throttle it 

If a crawler&#039;s page views exceed: 960 per minute (16 per second) then throttle it 

If a crawler&#039;s pages not found (404s) exceed: 960 per minute (16 per second)	 then throttle it 

If a human&#039;s page views exceed: 240 per minute (4 per  second) then throttle it 

If a human&#039;s pages not found (404s) exceed: 240 per minute (4 per  second) then throttle it 

If 404&#039;s for known vulnerable URL&#039;s exceed: 120 per minute (2 per second) then throttle it 

How long is an IP address blocked when it breaks a rule: 12 hours

&lt;strong&gt;For “login security options” options configure these settings:&lt;/strong&gt;

Force admins and publishers to use strong passwords

Limited login failures and forgot password attempts to 5

Count failures and amount of time a user is locked out to 6 hours.

Make sure these are checked:

Immediately lock out invalid usernames	

Don&#039;t let WordPress reveal valid users in login errors	

Prevent users registering &#039;admin&#039; username if it doesn&#039;t exist	

Prevent discovery of usernames through &#039;?/author=N&#039; scans



Hope this helps :)]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://blog.tbwhs.com/wordfence-security-wordpress-plugin/#comment-25844">Teresa</a>.</p>
<p><strong>Under “alerts” make sure the following are checked:</strong></p>
<p>“Alert on critical problems”</p>
<p>“Alert on warnings”</p>
<p>“Alert when IP address is blocked”</p>
<p>“Alert when some is locked out from login”</p>
<p>“Alert when the “lost password” form is used for valid user”</p>
<p>“Alert me when a non-admin user signs in”</p>
<p><strong>With “scans” make sure everything is checked</strong></p>
<p><strong>Under “firewall rules” configure these settings:</strong></p>
<p>Check “Immediately block fake Google crawlers”</p>
<p>Make sure “Verified Google crawlers have unlimited access to the site”</p>
<p>If anyone&#8217;s requests exceed: 240 per minute (4 per  second) then throttle it </p>
<p>If a crawler&#8217;s page views exceed: 960 per minute (16 per second) then throttle it </p>
<p>If a crawler&#8217;s pages not found (404s) exceed: 960 per minute (16 per second)	 then throttle it </p>
<p>If a human&#8217;s page views exceed: 240 per minute (4 per  second) then throttle it </p>
<p>If a human&#8217;s pages not found (404s) exceed: 240 per minute (4 per  second) then throttle it </p>
<p>If 404&#8217;s for known vulnerable URL&#8217;s exceed: 120 per minute (2 per second) then throttle it </p>
<p>How long is an IP address blocked when it breaks a rule: 12 hours</p>
<p><strong>For “login security options” options configure these settings:</strong></p>
<p>Force admins and publishers to use strong passwords</p>
<p>Limited login failures and forgot password attempts to 5</p>
<p>Count failures and amount of time a user is locked out to 6 hours.</p>
<p>Make sure these are checked:</p>
<p>Immediately lock out invalid usernames	</p>
<p>Don&#8217;t let WordPress reveal valid users in login errors	</p>
<p>Prevent users registering &#8216;admin&#8217; username if it doesn&#8217;t exist	</p>
<p>Prevent discovery of usernames through &#8216;?/author=N&#8217; scans</p>
<p>Hope this helps 🙂</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
