A WordPress site on the open internet is probed constantly: bots guessing passwords, scanners hunting for known holes, crawlers scraping whatever they can. Most hosts don’t tell you. We stop it at the front door and show you the count.
Bot, scanner and login attacks turned away at the origin, before they reach any site.
Recon bots and exploit scanners are identified and refused at the server, before WordPress ever runs. They never touch your site, your database, or your PHP — which also keeps your site fast under attack.
Repeated password guessing against your login is stopped, and the usual back doors attackers try first are hardened. Two-factor authentication is available for every account that logs in.
Malware scanning and a hardened WordPress configuration are part of the platform, not a plugin you have to remember to renew — and every site runs isolated from every other, so one site’s problem is never your problem.
Every site is served over HTTPS with a certificate that renews itself. We monitor expiry anyway, so it can’t lapse quietly.
Blocking is precise. Search engines, real browsers, and the services you rely on are on a safelist — protection never means disappearing from Google.
This is the part most hosts skip: showing you. Threat protection has its own screen in your dashboard.
| Site | Protection | Blocked | Last activity |
|---|---|---|---|
| yourbusiness.com | 1,284 | Today | |
| shop.yourbusiness.com | 402 | Today |
A growing share of the traffic we turn away is AI scrapers and unwanted crawlers. Many are blocked by default alongside the other bots. But not every AI bot is unwanted — some businesses want to be findable in AI search the same way they want to be on Google — so this is a choice, not a blanket rule.
Bot and scanner protection can be tuned per site: which crawlers are refused and which are allowed. If you have a view on AI crawlers, tell us and we’ll set it that way. If you don’t, the sensible default already protects you.