As you install WP Ultimate Firewall for the first time, you get a dashboard section showing you a summary of your options and your system and admin settings.
If you are a complete WordPress beginner, I advise using security presets, then navigating through the options and see what each one does.
Installation Steps
1. Download this plugin from Codecanyon.
2. Unzip the wp-ultimate-firewall.zip
3. Upload all the files to your plugin directory. (your site directory / wp-content / plugins / ..)
4. Activate the plugin through the ‘Plugins’ menu in WordPress.
5. For customizing the plugin’s settings, click on "Ultimate Firewall" menu in WordPress admin menu.
With user friendly admin panel, you can make special adjustments, or you can automatically protect your website by setting the security level. These settings are located in the Ultimate Firewall - Admin Settings section.
Sections:
-
Dashboard (Website Summary, Security and Optimization Status, Uptime Status)
-
Admin Settings (Security Presets, API settings, Mail Settings)
-
Optimization Settings (General Website Speed Optimizations)
-
Security & Firewall Settings (General Security and Firewall Settings)
-
Access (Manual Firewall) Settings (IP, Location and Useragent / Bot Access Settings)
API Settings
Create API key for the reCAPTCHA: https://www.google.com/recaptcha/
Create API key for the Uptime Robot: Login to the Uptime Robot and follow the steps:
=> My Settings (in header)
=> API Settings
=> Monitor-Specific API Keys
=> Click "Show/hide it" Button
=> Enter your Monitor Name (example: My Monitor)
=> Click "Create API key for the monitor"
Mail Settings
Mail system, it may require SMTP plugins. If you have trouble receiving email; install WP Mail SMTP plugin to your website.
> User-friendly Management Feature
- In admin panel of plugin, you can review your website’s status and plugin settings.
> Multi-Language Feature
- Ultimate Firewall is coded as compatible with 100% translation into other languages. You should have POEdit program for this feature. Further information regarding language translation is available at this link:
https://codex.wordpress.org/Multilingual_WordPress
For Experts.
> Admin Report System (WP Ultimate Firewall => Dashboard)
- With the admin report system in the admin panel of the plugin, you can see the IP address and login time of the last user that logged in to your web site; and you can get email notification when an admin log in the admin panel in order to maximize your security.
> E-mail Notification System (WP Ultimate Firewall => Admin Settings)
- With the email notification system, you can receive emails for hacker attacks, Brute-Force attacks, Proxy Attacks, Spam attacks and spam comment attacks. (In some cases, it may require SMTP settings.)
> Security Level (WP Ultimate Firewall => Admin Settings)
- Instead of making security changes one by one, you can set your security level automatically from the admin settings section, or you can ensure your security by using special settings.
This option sets the automatic security level.
> Prevention Method System (WP Ultimate Firewall => Admin Settings)
- You can prevent attacks to your website whether by blocking the access or by using strong reCAPTCHA protection.
This option sets prevention method. (1- Direct Block, 2- reCaptcha)
> Website Monitoring with Uptime Robot (WP Ultimate Firewall => Admin Settings)
- Via Uptime Robot API you can monitor your website in details. It requires free Uptime Robot account.
This option sets the Uptime Robot API for Website Monitoring.
> Website Optimization (WP Ultimate Firewall => Optimization Settings)
- Both protect your website and at the same time speed it up. Ultimate Firewall plugin provides also speed increase service besides the protection. Optimization Options:
-GZip Compression
-HTML Compression
-Browser Caching
-Lazy Load Images
-Author Archives & Links Remover
-Shortlink Remover
-RSS Feed Editor
-ASYNC and DEFER Settings (for JavaScripts)
-Query String Editor
-Move All Scripts to Footer
-Emoji remover
-jQuery Migrate Remover
-WooCommerce, BBPress and BuddyPress Speed Optimization
> Security & Firewall - Real-Time Firewall Protection (WP Ultimate Firewall => Firewall & Security Settings)
- Advanced Firewall protection detects fake, spam and attacking users and protects your website. Indeed, it cannot be blocked by Google or other search engine detections and does not harm your website in terms of SEO. Real-time firewall protection works according to the two options; one is blocking attacks when it is detected and the other one is checking it with reCAPTHCA. You can arrange these settings with Prevention Method System.
This option enables the Firewall to prevent DDoS and Flood / Spam Hacks.
> HTTP Security Headers (WP Ultimate Firewall => Firewall & Security Settings)
- Prevent HTTP attacks to your website via HTTP Security Headers settings.
For Experts.
This option enables X-Content-Type-Options, X-XSS-Protection and X-Frame-Options in your server.
> XML-RPC and REST-API Security (WP Ultimate Firewall => Firewall & Security Settings)
- Prevent Wordpress based attacks by disabling XML-RPC and REST-API.
For Experts.
> File Editor Settings (WP Ultimate Firewall => Firewall & Security Settings)
- Disable the file editing feature in the Wordpress admin panel.
> Captcha Protection (WP Ultimate Firewall => Firewall & Security Settings)
- With the advanced reCAPTCHA protection, protect Wordpress comment section, login form, membership form and password reset form with reCAPTCHA.
> Comment Protection (WP Ultimate Firewall => Firewall & Security Settings)
- Start protecting your comments with Honeypot or reCAPTCHA, and prevent spam comment attacks immediately!
> Content Protection (WP Ultimate Firewall => Firewall & Security Settings)
- Prevent your content from being stolen with the content protection system. And it's also compatible with Google!
> WPScan and Generator Tag Protection (WP Ultimate Firewall => Firewall & Security Settings)
- To be protected from WPScan, you can activate the version hiding system and prevent the deficit on your website from being detected.
This option removes the Wordpress Generator (version) tags.
> Tor Detection (WP Ultimate Firewall => Firewall & Security Settings)
- You can prevent people who log in your website through tor browser or servers.
For Experts.
> Proxy Protection (WP Ultimate Firewall => Firewall & Security Settings)
- You can prevent people to logging in your website by using proxy or a free VPN software.
For Experts.
> Access Security (WP Ultimate Firewall => Firewall & Security Settings)
- If an attack is made to your website, by enabling this setting you can check first time users through reCAPTCHA control.
> Hacker Protection (WP Ultimate Firewall => Firewall & Security Settings)
- By SQL Injection Protection, you can provide protection against bad (virus) bots and fake search engine bots.
> Access Settings (WP Ultimate Firewall => Access Settings)
- With access security settings you can block IP address, country and User Agent information.