NewThe agent now reads your files and links, and can search the web.Files, links and web search in the agent.See how

DocsSecurity

Turn on Security and the firewall

Security is an optional feature with a firewall that checks every request for attacks — learning for a week, then blocking — plus blocked addresses and countries, and extended protection before WordPress loads.

  1. Switch it onGo to Native AI → Settings → Features and switch on Security. Your current address is added to the allowed addresses, so you can never block yourself, and a Security screen appears in the Native AI menu.
  2. Let it learnThe firewall starts in Learning mode for a week: it logs what it would block and learns what your editors legitimately do. Then it switches to Protecting by itself (or switch it now in Firewall).
  3. Work through the checklistDashboard → Needs attention lists what to fix, with one-click fixes where possible. Then run a scan.
Native AI Security: the security score, attacks blocked this week, what needs attention, the scan’s findings and the addresses blocked most
The Security dashboard: the score, attacks blocked this week, what needs attention and the scan’s findings.

What the firewall looks for#

GroupExamples
SQL injectionUNION SELECT, always-true conditions (' or '1'='1), time-based attacks (SLEEP), reading the database’s schema
Cross-site scripting<script> tags, event handlers like onerror=, javascript: addresses, hidden frames, cookie theft
Path traversal and file inclusion../../etc/passwd, wp-config.php through ../, php://filter, remote files
PHP code and object injection<?php in a field, eval(base64_decode(…)), serialized PHP objects
Shell commands; cat /etc/passwd, | wget, ${jndi:…}, template injection
Attack toolssqlmap, Nikto, WPScan, Acunetix and other scanners
Sensitive files.env, wp-config.php backups, .git, debug.log, backups in the site’s root, PHP in uploads
Malformed requestsNull bytes, unknown HTTP methods

Requests from people who can edit content are checked once WordPress knows who they are, so editors writing HTML aren’t stopped. Switch groups off, or allow a rule for one field or address under Firewall → Exceptions — the log shows the rule and the field of everything blocked.

Blocking addresses#

  • Repeat attackers: an address that trips the firewall 5 times in 5 minutes is blocked for an hour (both adjustable).
  • Missing-page probing: bots ask for many pages that don’t exist looking for weak files; 30 in 30 minutes blocks the address (not signed-in people, real search engines or images).
  • Fake search engines: visitors calling themselves Googlebot or Bingbot are checked with Google’s and Microsoft’s DNS.
  • By hand: block an address or range (203.0.113.0/24), for a time or until you remove it, in Firewall → Blocked addresses or from any row of the log.
  • Countries: block some countries, or allow only some. This needs a CDN that tells visitors’ countries, like Cloudflare.

Extended protection#

Firewall → Extended protection runs the rules before WordPress loads, for every PHP file on the site — a script dropped into uploads, or a plugin file called directly, is checked too. It adds a line to the site’s .user.ini (PHP-FPM) or .htaccess (Apache, LiteSpeed); PHP can take up to five minutes to pick it up. It isn’t available on servers that don’t allow it, or when another firewall (like Wordfence’s) already runs first.

If you’re ever locked out#