Basic Config for Wordfence 7.1.1:
Scan / Manage Scans
Set to Standard Scan, then:
- General Options:
- Uncheck: Scan for publicly accessible configuration, backup, or log files
- Check: Scan theme files against repository versions for changes
- Check: Scan plugin files against repository versions for changes
- Uncheck: Scan for out of date, abandoned, and vulnerable plugins, themes, and WordPress versions
- Uncheck: Check the strength of passwords
BLUE SAVE
All Options / General Wordfence Options
Check: Update Wordfence automatically
BLUE SAVE
All Options / WF Global Options Email Alert Preferences
- Check: Email me when Wordfence is automatically updated
- Uncheck: Alert when the “lost password” form is used for a valid user
- Uncheck: Alert me when a non-admin user signs in
BLUE SAVE
All Options, Scan Options / Scan Scheduling
Confirm scheduling is Enabled
When Done the Scan level should say 46%
Basic Config for Wordfence 6.3.16:
Wordfence -> Options
- Basic Options
- all off except
- Enable automatic scheduled scans
- update Wordfence automatically
- fill in email address
- all off except
- SAVE
- Advanced Options
- Alerts
- check “Email me when Wordfence is automatically updated”
- check “Email me if Wordfence is deactivated”
- check “alert on critical problems”
- check “alert on warnings”
- check “Alert me when there’s a large increase in attacks detected on my site”
- max email alerts per hour: 3
- leave everything else unchecked
- Email Summary
- uncheck enable summary
- Live Traffic
- only check Don’t log signed-in users with publishing access
- Alerts
- Scans to Include
- check Scan for misconfigured How does Wordfence get IPs
- check Scan for publicly accessible configuration, backup, or log files
- check Scan for publicly accessible quarantined files
- check core files
- check theme
- check plugin
- check Scan wp-admin and wp-includes for files not bundled with WordPress
- check Scan for signatures
- check Scan for backdoors
- check Scan for files for malicious urls
- check Scan posts for dangerous urls
- check Scan comments for dangerous urls
- uncheck Scan for out of date
- uncheck scan for admin users created outside of WP
- uncheck password strength
- check monitor disk space
- check scan unauthorized DNS
- check check files outside WP
- in exclude files box put in:
- *importbuddy.php*
- *debug.log*
- Rate Limiting Rules (new as of 6.3.6)
- uncheck Immediately block fake Google crawlers
- everything else should be “unlimited”
- Login Security Options (new as of 6.3.6)
- Do not force users to use strong passwords
- lock out after 20 login failures
- lock out after 20 new password tries
- count failures over 5 min
- lock user out for 5 min
- uncheck Immediately lock out invalid usernames
- check donetlet WP reveal users in errors
- check prevent creation of admin user
- check Prevent discovery of usernames through ‘/?author=N’ scans, the oEmbed API, and the WordPress REST API
- Dashboard (new as of 6.3.6)
- uncheck updates needed
- Other Options
- uncheck everything incl Hide WP version (its needed for my versions script)
- check Pause live updates when window loses focus
- SAVE
Note: If scans don’t complete, set the “Maximum execution time for each scan stage” under “Other Options” to 15 (per <a href=”https://docs.wordfence.com/en/My_scans_don%27t_finish._What_would_cause_that%3F”>this article</a>)


