Wordfence Configuration

Basic Config for Wordfence 7.1.1:

Scan / Manage Scans

Set to Standard Scan, then:

  • General Options:
    • Uncheck: Scan for publicly accessible configuration, backup, or log files
    • Check: Scan theme files against repository versions for changes
    • Check: Scan plugin files against repository versions for changes
    • Uncheck: Scan for out of date, abandoned, and vulnerable plugins, themes, and WordPress versions
    • Uncheck: Check the strength of passwords

BLUE SAVE

All Options / General Wordfence Options 

Check: Update Wordfence automatically

BLUE SAVE

All Options / WF Global Options Email Alert Preferences

  • Check: Email me when Wordfence is automatically updated
  • Uncheck: Alert when the “lost password” form is used for a valid user
  • Uncheck: Alert me when a non-admin user signs in

BLUE SAVE

All Options, Scan Options / Scan Scheduling

Confirm scheduling is Enabled

When Done the Scan level should say 46%

 

Basic Config for Wordfence 6.3.16:

Wordfence -> Options

  • Basic Options
    • all off except
      • Enable automatic scheduled scans
      • update Wordfence automatically
    • fill in email address
  • SAVE
  • Advanced Options
    • Alerts
      • check “Email me when Wordfence is automatically updated”
      • check “Email me if Wordfence is deactivated”
      • check “alert on critical problems”
      • check “alert on warnings”
      • check “Alert me when there’s a large increase in attacks detected on my site”
      • max email alerts per hour: 3
      • leave everything else unchecked
    • Email Summary
      • uncheck enable summary
    • Live Traffic
      • only check Don’t log signed-in users with publishing access
  • Scans to Include
    • check Scan for misconfigured How does Wordfence get IPs
    • check Scan for publicly accessible configuration, backup, or log files
    • check Scan for publicly accessible quarantined files
    • check core files
    • check theme
    • check plugin
    • check Scan wp-admin and wp-includes for files not bundled with WordPress
    • check Scan for signatures
    • check Scan for backdoors
    • check Scan for files for malicious urls
    • check Scan posts for dangerous urls
    • check Scan comments for dangerous urls
    • uncheck Scan for out of date
    • uncheck scan for admin users created outside of WP
    • uncheck password strength
    • check monitor disk space
    • check scan unauthorized DNS
    • check check files outside WP
    • in exclude files box put in:
      • *importbuddy.php*
      • *debug.log*
  • Rate Limiting Rules (new as of 6.3.6)
    • uncheck Immediately block fake Google crawlers
    • everything else should be “unlimited”
  • Login Security Options (new as of 6.3.6)
    • Do not force users to use strong passwords
    • lock out after 20 login failures
    • lock out after 20 new password tries
    • count failures over 5 min
    • lock user out for 5 min
    • uncheck Immediately lock out invalid usernames
    • check donetlet WP reveal users in errors
    • check prevent creation of admin user
    • check Prevent discovery of usernames through ‘/?author=N’ scans, the oEmbed API, and the WordPress REST API
  • Dashboard (new as of 6.3.6)
    • uncheck updates needed
  • Other Options
    • uncheck everything incl Hide WP version (its needed for my versions script)
    • check Pause live updates when window loses focus
  • SAVE

 

Note:  If scans don’t complete, set the “Maximum execution time for each scan stage” under “Other Options” to 15 (per <a href=”https://docs.wordfence.com/en/My_scans_don%27t_finish._What_would_cause_that%3F”>this article</a>)