Just another contact form plugin. Simple but flexible.
About WP fail2ban – Advanced Security Plugin
WP fail2ban is a plugin that connects your WordPress site to fail2ban, a security measure that protects your site. It logs failed login attempts, blocks user enumeration, blocks username logins, and has many other features to enhance the security of your site. The premium version also includes a web application firewall, Akismet support, and the ability to block XML-RPC requests and countries, among other features.Frequently asked questions
What is fail2ban?
fail2ban is one of the simplest and most effective security measures you can implement to protect your WordPress site.
What does WP fail2ban do?
WP fail2ban provides the link between WordPress and fail2ban.
What are the three fail2ban filters provided by WPf2b?
The three fail2ban filters provided by WPf2b are wordpress-hard.conf, wordpress-soft.conf, and wordpress-extra.conf.
What are some features of WPf2b?
Some features of WPf2b include logging failed login attempts, blocking user enumeration, blocking username logins, blocking users based on usernames, logging empty username login attempts, logging spammer's IP addresses, detecting and logging attempted comments, rate-limiting potential attackers using pingbacks, blocking XML-RPC requests (Premium), blocking countries (Premium), working with Cloudflare, syslog dashboard widget, site health check, mu-plugins support, API to extend WPf2b, and event hooks (Premium).
What are some premium features of WPf2b?
Some premium features of WPf2b include web application firewall (WAF), Akismet support, blocking XML-RPC while allowing Jetpack and/or pingbacks, blocking countries, auto-updating Cloudflare IPs, event log, and event hooks.
Changelog
5.4.0-LTS
- Add support for Composer. [Canonical only]
- Add support for AspirePress Update. [Canonical only]
- Add support for GitHub Updater. [Canonical only]
- Improve i18n.
- Fix harmless warning in Site Health filters check (h/t Rodolphe).
- Update Freemius library.
5.3.4
- Improve Site Health filter messages (h/t @yardstudio).
- Update Freemius library.
5.3.3
- Fix activation bug when
$wp_scriptsis uninitialised. [Premium only] - Fix world map dashboard widget. [Premium only]
- Update Freemius library.
5.3.2
- Drop Site Health checks for free add‑ons.
5.3.1
- Fix regression in plugin message registration.
5.3.0
- Add
WP_FAIL2BAN_SYSLOG_TAG_HOSTto simplifyfail2banconfiguration withjournald. - Fix database upgrade when jQuery not loaded. [Premium only]
- Update Freemius library.
5.2.2
- Fix regression in Site Health when
execis disabled (h/t @ahardy42). - PHP 8.3: Fix harmless warning on About tab.
- WAF: Add support for themes that update image size options (h/t Jerker Wredenmark). [Premium only]
- Update Freemius library.
5.2.1
- Fix bug in WAF when not logged in (h/t Rudi Diedrich). [Premium only]
- Site Health: Add support for
open_basedir(h/t Jaroslav Huba). - Update Freemius library.
5.2.0
- WAF: Add new filter file for WAF events. [Premium only]
- WAF: Add feature: prevent unauthorised user deletion. [Premium only].
- Fix untrusted proxy message.
- Work-around for WooCommerce bug causing double logging of password reset requests (h/t @anuja).
- Site Health: Improve notifications.
5.1.1
- Update Freemius library.
5.1.0
- Web Application Firewall. [Premium only]
- Add PTR record lookup to event report. [Premium only]
- Improve report performance. [Premium only]
- Site Health: Check
fail2banis running. - Site Health: Obsolete Filters – Detect DigitalOcean Droplet and link to documentation.
- Fix harmless warning (h/t @Yavor).
- Fix warning caused by bug in Google Sitekit (h/t @DaWolfey).
- Update Freemius library.
5.0.1
- Tweak Site Health notifications.
- Update Freemius library.
5.0.0 “Delphi”
- IPv6 support.
- Akismet support. [Premium only]
- Auto-update Cloudflare IPs. [Premium only]
- Event hooks. [Premium only]
- Performance improvements:
- Improve reports. [Premium only]
- Cache IP lists. [Premium only]
- Cache Plugin API message registration. [Premium only]
- Site Health: Check installed filters against previous versions.
- Moved “Authentication attempt for unknown user” to
wordpress-soft.conf. - Moved “extra” Comment messages to
wordpress-soft.conf. - Show date/time in local timezone (h/t @geniusmedia). [Premium only]
- Deprecate
WP_FAIL2BAN_LOG_COMMENTS_EXTRAandWP_FAIL2BAN_COMMENT_EXTRA_LOG; useWP_FAIL2BAN_LOG_COMMENT_ATTEMPTSandWP_FAIL2BAN_COMMENT_ATTEMPT_LOGinstead. - Update Freemius library.
Please read the notes before upgrading.
4.4.0.9
- Preparation for v5: prevent auto-updating across major release.
- Update Freemius library.
4.4.0.8
- Back-port fix for
mu-pluginsactivation. - Update Freemius library.
4.4.0.7
- Back-port fix for type error in menu-fixer when viewing Event Log (h/t @geniusmedia). [Premium only]
- Back-port fixes for event summaries. [Premium only]
- Update Freemius library.
4.4.0.6
- Fix initialisation error in event log. [Premium only]
- Fix type error in event log when no events available. [Premium only]
- Update Freemius library.
4.4.0.5
- Fix type error on Remote IPs tab with no MaxMind database configured (h/t @Tobias‑Conrad). [Premium only]
- Update Freemius library.
4.4.0.4
- Fix warning with array of blocked users (h/t @Znuff).
- Fix reports. [Premium only]
4.4.0.3
- Fix type error (h/t @brianshim).
4.4.0.2
- Add
WP_FAIL2BAN_USE_AUTHPRIV– a single place to switch toLOG_AUTHPRIVfor systems withoutLOG_AUTH. - Add
WP_FAIL2BAN_FREE_ONLY. - Add
WP_FAIL2BAN_PLUGIN_LOG_OTHERandWP_FAIL2BAN_PLUGIN_OTHER_LOG. - Improve performance.
- Moved cron event to update trusted Cloudflare IP ranges to the Cloudflare add-on. [Premium only]
- Add support for Pingbacks while blocking XML‑RPC. [Premium only]
- Update Freemius library.
4.3.2.2
- Add cron event to update trusted Cloudflare IP ranges weekly. [Premium only]
- Add cron event to update trusted Jetpack IP ranges weekly. [Premium only]
- Add cron event to update MaxMind database weekly. [Premium only]
- Workaround for missing
syslogconstants in Windows (h/t @dmarkowicz). - Clarify upgrade message on Last 5 Messages widget. [Free only]
- Merge About and Status tabs. [Premium only]
- Update Freemius library.
4.3.2.1
- Add support for WP fail2ban Blocklist.
- Add new Standard Configurations.
- Improve Help links.
- Fix logging checkboxes [Premium only].
- Fix incorrect constant for disabling last messages (h/t @kermina).
- Fix false positive with blocking user enumeration when a Contributor tries to list posts by another user.
- Fix index issue with ancient versions of MySQL.
- Fix harmless warning with a defined but empty
WP_FAIL2BAN_PROXIES(h/t @stevegrunwell). - Back-port new Block event class.
- Update Freemius library.
- Change to GPLv3 with additional terms as per Section 7.
4.3.2.0
- Add support for blocking by Country. [Premium only]
- Add XML‑RPC blocking; allow trusted IPs and Jetpack (h/t @mhweb). [Premium only]
4.3.0.9
- Fix incorrect constant for disabling last messages (h/t @kermina).
- Fix false positive with blocking user enumeration when a Contributor tries to list posts by another user.
- Fix index issue with ancient versions of MySQL. [Premium only]
- Fix harmless warning with a defined but empty
WP_FAIL2BAN_PROXIES(h/t @stevegrunwell). - Back-port new Block event class.
- Update Freemius library.
4.3.0.8
- Workaround issue with user enumeration blocking being triggered by Gutenberg pre‑loading Author list. (h/t @brrrrrrrt) [WordPress only]
4.3.0.7
- Finish refactoring to allow inclusion of constants in
wp‑config.php(h/t @iCounsellor). - Fix MaxMind database update. [Premium only]
4.3.0.6
- Fix Forbidden error on Posts page for roles below Editor when user enumeration blocking enabled. [WordPress only]
4.3.0.5
- Fix empty username detection for multisite.
- Fix harmless warning when activating new multisite install.
- Fix esoteric edge-case where
wp‑load.phpis loaded via a script run from the CLI in a directory with afunctions.phpfile.
4.3.0.4 “Columbo”
- Add new dashboard widget: last 5
syslogmessages. - Add full multisite support.
- Add username login blocking (force login with email).
- Add separate logging for login attempts with an empty username.
- Improve user enumeration blocking compatibility with the WordPress block editor (Gutenberg).
- Bump the minimum PHP version to 5.6.
4.2.8
- Add link to new support forum.
- Fix user enumeration conflict with Gutenberg (h/t @dinghy).
- Fix notices wrt admin menu (h/t @marioivangf).
- Fix harmless XDebug notice (h/t @dinghy).
- Update Freemius library.
4.2.7.1
- Fix error when blocking user enumeration via
oembed(h/t @wordpressfab).
4.2.7
- Fix error when blocking user enumeration via REST.
- Fix buttons on Settings tabs.
4.2.6
- Add support for Remote Tools add-on.
- Add support for the new ClassicPress security page.
- Improved user enumeration blocking.
4.2.5.1
- Fix premium activation issue with PHP < 7.0.
4.2.5
- Properly fix PHP 5.3 support; tested on CentOS 6. Does not support any UI or Premium features.
- Fix potential issue with
WP_FAIL2BAN_BLOCK_USER_ENUMERATIONif calling REST API or XML‑RPC from admin area.
4.2.4
- Add filter for login failed message.
- Fix logging spam comments from admin area.
- Fix Settings link from Plugins page.
- Update Freemius library
4.2.3
- Workaround for some versions of PHP 7.x that would cause
define()s to be ignored. - Add config note to settings tabs.
- Fix documentation links.
4.2.2
- Fix 5.3 compatibility.
4.2.1
- Completed support for
WP_FAIL2BAN_COMMENT_EXTRA_LOG. - Add support for 3rd-party plugins; see Developers.
- Add-on for Contact Form 7 (experimental).
- Add-on for Gravity Forms (experimental).
- Change logging for known-user with incorrect password; previously logged as unknown user and matched by
hardfilters (due to limitations in older versions of WordPress), now logged as known user and matched bysoft. - Bug-fix for email-as-username – now logged correctly and matched by
soft, nothard, filters. - Bug-fix for regression in code to prevent Free/Premium conflict.
4.2.0
- Not released.
4.1.0
- Add separate logging for REST authentication.
- Fix conflict with earlier versions preinstalled in
mu‑plugins. See Is WPf2b Already Installed?.
4.0.5
- Add
WP_FAIL2BAN_COMMENT_EXTRA_LOG. - Add
WP_FAIL2BAN_PINGBACK_ERROR_LOG(future functionality). - Change
WP_FAIL2BAN_LOG_SPAMto useLOG_NOTICE. - Change
WP_FAIL2BAN_SPAM_LOGtoLOG_AUTH. - Change
WP_FAIL2BAN_LOG_COMMENTS_EXTRAevents to useLOG_NOTICEby default. - Fix conflict with 3.x in
mu-plugins.
4.0.2
- Fix PHP 5.3 compatibility.
- Bug-fix for
WP_FAIL2BAN_LOG_COMMENTS_EXTRA. - Bug-fix for
WP_FAIL2BAN_REMOTE_ADDRsummary.
4.0.1
- Add extra features via Freemius. This is entirely optional. WPf2b works as before, including new features listed here.
- Add settings summary page (Settings -> WP fail2ban).
- Add
WP_FAIL2BAN_PASSWORD_REQUEST_LOG. - Add
WP_FAIL2BAN_SPAM_LOG. - Add
WP_FAIL2BAN_LOG_COMMENTS_EXTRA– enable logging for attempted comments on posts which are:- not found,
- closed for commenting,
- in the trash,
- drafts,
- password protected
- Block user enumeration via REST API.
4.0.0
- Not released.
3.6.0
- The filter files are now generated from PHPDoc in the code. There were too many times when the filters were out of sync with the code (programmer error) – this should resolve that by bringing the patterns closer to the code that emits them.
- Added PHPUnit tests. Almost 100% code coverage, with the exception of
WP_FAIL2BAN_PROXIESwhich is quite hard to test properly. - Bug-fix for
wordpress-soft.conf. - Add
WP_FAIL2BAN_XMLRPC_LOG. - Add
WP_FAIL2BAN_REMOTE_ADDR. WP_FAIL2BAN_PROXIESnow supports an array of IPs with PHP 7.- Moved all documentation to https://docs.wp-fail2ban.com/.
3.5.3
- Bug-fix for
wordpress-hard.conf.
3.5.1
- Bug-fix for
WP_FAIL2BAN_BLOCK_USER_ENUMERATION.
3.5.0
- Add
WP_FAIL2BAN_OPENLOG_OPTIONS. - Add
WP_FAIL2BAN_LOG_COMMENTSandWP_FAIL2BAN_COMMENT_LOG. - Add
WP_FAIL2BAN_LOG_PASSWORD_REQUEST. - Add
WP_FAIL2BAN_LOG_SPAM. - Add
WP_FAIL2BAN_TRUNCATE_HOST. WP_FAIL2BAN_BLOCKED_USERSnow supports an array of users with PHP 7.
3.0.3
- Fix regex in
wordpress-hard.conf.
3.0.2
- Prevent double logging in WP 4.5.x for XML‑RPC authentication failure
3.0.1
- Fix regex in
wordpress-hard.conf.
3.0.0
- Add
WP_FAIL2BAN_SYSLOG_SHORT_TAG. - Add
WP_FAIL2BAN_HTTP_HOST. - Log XML‑RPC authentication failure.
- Add better support for MU deployment.
2.3.2
- Bug-fix
WP_FAIL2BAN_BLOCKED_USERS.
2.3.0
- Bug-fix in experimental
WP_FAIL2BAN_PROXIEScode (thanks to KyleCartmell).
2.2.1
- Fix stupid mistake with
WP_FAIL2BAN_BLOCKED_USERS.
2.2.0
- Custom authentication log is now called
WP_FAIL2BAN_AUTH_LOG. - Add logging for pingbacks; see
WP_FAIL2BAN_LOG_PINGBACKS. - Custom pingback log is called
WP_FAIL2BAN_PINGBACK_LOG.
2.1.1
- Minor bug-fix.
2.1.0
- Add support for blocking user enumeration; see
WP_FAIL2BAN_BLOCK_USER_ENUMERATION. - Add support for CIDR notation in
WP_FAIL2BAN_PROXIES.
2.0.1
- Bug-fix in experimental
WP_FAIL2BAN_PROXIEScode.
2.0.0
- Add experimental support for X-Forwarded-For header; see
WP_FAIL2BAN_PROXIES. - Add experimental support for regex-based login blocking; see
WP_FAIL2BAN_BLOCKED_USERS.
1.2.1
- Update FAQ.
1.2
- Fix harmless warning.
1.1
- Minor cosmetic updates.
1.0
- Initial release.
