This page breaks down the Firewall Security screen section by section so site owners and support teams know what each control means, when to use it, and how to tune it without breaking checkout, logins, REST requests, or legitimate visitors.
Temporary attack response when the site is under pressure.
Cloudflare Integration
Restore real visitor IPs and push confirmed blocks to Cloudflare edge rules.
WooCommerce Ready
Checkout, cart, payment callbacks, and Store API traffic stay compatible.
Event Logging
Timeline records and email alerts show what was blocked and why.
Feature Breakdown
Emergency Shield Protection
Emergency Shield is the temporary lockdown control for active pressure events. It is designed to reduce abusive public traffic quickly while still allowing trusted access paths to continue.
Emergency Shield Protection
What it means: Emergency Shield is an urgent protection mode for live attack pressure, heavy probing, or a situation where the public site needs stricter temporary access control. When active, it blocks public site traffic, including login attempts, unless the visitor is already trusted or already authenticated as an administrator.
How to use it: Enable it only when the site is under active pressure. Confirm trusted IPs first so developers, support staff, and critical operational access are not locked out. Watch the timeline and support reports while it is on, then return to the normal firewall mode after the event settles.
Firewall Mode
Choose how aggressively the firewall responds
The response mode controls whether the firewall quietly observes, blocks only high-confidence threats, or escalates repeat suspicious behavior.
Recommended
What it means: Smart blocking with core protections, logging, and safe defaults.
How to use it: Use this as the default starting point for most production sites.
Basic
What it means: Monitor-first setup for tuning without blocking traffic.
How to use it: Use it while learning traffic patterns, checking integrations, or tuning a site before stronger enforcement.
WooCommerce Safe
What it means: Automatic firewall bypass for checkout, cart, and payment traffic.
How to use it: Use this on WooCommerce stores so legitimate checkout and payment gateway requests are not blocked by firewall enforcement.
Off
What it means: The firewall does not inspect or log firewall requests.
How to use it: Use only for troubleshooting or temporary testing, then return to an active mode once the issue is confirmed.
Monitor Only
What it means: Logs matching threats without blocking them.
How to use it: Use it before enforcement to confirm the firewall is seeing suspicious traffic without disrupting legitimate visitors.
Smart Block
What it means: Blocks high-confidence WordPress attack traffic while keeping compatibility in mind.
How to use it: Use it as the active protection mode after Monitor Only confirms normal workflows are not being flagged.
Blocked Visitor Experience
Blocked Request Page settings
These settings control the page a visitor sees when the firewall blocks a request. They are useful for support clarity, branding, and making sure legitimate users know what happened.
Color Theme
What it means: The visual theme for the blocked request page, with light and dark options.
How to use it: Choose Light for a clean default page, or Dark when it better matches the site or security branding.
Access Denied Title And Message
What it means: The headline and short explanation shown when access is denied.
How to use it: Keep the message calm and clear. Do not reveal detailed firewall logic or rule names to the blocked visitor.
Request Blocked Title And Message
What it means: The text shown for a blocked suspicious request.
How to use it: Include a simple instruction like contacting site support if the user believes the block was a mistake.
Footer Label And Footer URL
What it means: Optional footer branding and a support or home page link.
How to use it: Point it to your support page, agency site, or client help page. Avoid linking to sensitive admin pages.
IP Controls
Trusted IP allowlist and immediate IP blocklist
The IP list tools let you explicitly allow trusted traffic or block known bad sources before relying only on behavior-based rules.
Trusted IP Allowlist
What it means: A list of IP addresses that should be trusted by the firewall.
How to use it: Add agency, developer, office, uptime monitor, security scanner, and payment provider IPs when you know they are legitimate. Keep the list narrow and remove old entries.
Immediate IP Blocklist
What it means: A list of IP addresses that should be blocked right away.
How to use it: Add repeat offenders from the timeline or known hostile IPs. Review the list periodically so temporary attack IPs do not become permanent clutter.
Cloudflare IP Access Rules
What it means: The timeline can assign Cloudflare access actions to IPs when Cloudflare integration is enabled.
How to use it: Use edge actions for confirmed repeat bad traffic so Cloudflare challenges or blocks the source before requests reach WordPress.
Escalation Memory
Remember repeat offenders and escalate response
Escalation Memory lets the firewall treat repeated suspicious behavior differently from a single isolated event.
Enable Escalation Memory
What it means: The firewall remembers suspicious IP behavior over a defined period.
How to use it: Enable it when you want repeat probes to become more serious than one-off noise.
Block After Threshold
What it means: The number of suspicious events allowed before the firewall blocks the IP.
How to use it: Lower the number during active attacks. Raise it if legitimate scanners, monitors, or API clients are being caught too quickly.
Window In Hours
What it means: How long suspicious behavior is remembered.
How to use it: Use a shorter window for busy sites with lots of legitimate traffic. Use a longer window for persistent brute-force or scanner campaigns.
Auto IP Escalation Limit
What it means: A cap that keeps automatic escalation from going too far.
How to use it: Keep a reasonable cap so automation helps without creating a large unmanaged blocklist.
Exploit And Bot Defense
Request filtering features
These rules protect common WordPress attack paths, abusive request patterns, and discovery techniques used by bots and scanners.
Exploit Payload Firewall
What it means: Blocks suspicious payloads often seen in exploit attempts, including dangerous encoded strings and attack patterns.
How to use it: Keep it enabled unless a custom integration is falsely flagged. If that happens, use Monitor Only to confirm the exact request before relaxing protection.
Dangerous HTTP Methods
What it means: Blocks risky request methods that most WordPress sites do not need publicly exposed.
How to use it: Keep enabled for normal sites. Verify custom APIs if they rely on uncommon methods.
Scanner And Bot Signatures
What it means: Detects known scanner, crawler, and probing behavior.
How to use it: Enable it for public sites. Review events if a legitimate security tool is being flagged and allowlist that scanner IP if appropriate.
Author Enumeration Shield
What it means: Helps block requests that try to discover WordPress usernames.
How to use it: Keep enabled to reduce account discovery. Test author archive pages if the site intentionally uses them publicly.
Disable XML-RPC
What it means: Turns off XML-RPC access, a common target for brute-force and pingback abuse.
How to use it: Enable it unless the site depends on Jetpack, remote publishing, mobile app posting, or another XML-RPC workflow.
Block XML-RPC Multicall
What it means: Blocks XML-RPC multicall requests that can bundle many login attempts or actions into one request.
How to use it: Enable it when XML-RPC must remain available but you still want to limit high-risk abuse.
Protect REST Users
What it means: Protects REST endpoints that can expose user information.
How to use it: Keep enabled for most sites. Test headless, membership, mobile app, and custom dashboard integrations before enforcing on complex builds.
Long URL & Query Shield
What it means: Catches suspicious URL and query string patterns that do not fit normal visitor behavior.
How to use it: Use it for broad bot and exploit noise. If a marketing tool or tracking link is flagged, review the exact query and tune around the legitimate pattern.
Per-IP Request Rate Limit
What it means: Limits how many requests one IP can make in a time window.
How to use it: Set a higher value for busy stores, membership sites, AJAX-heavy themes, and logged-in portals. Set a lower value during attacks or on simple brochure sites.
Checkout Safety
WooCommerce Compatibility Mode
WooCommerce Compatibility Mode is designed to keep checkout, cart, payment gateway callbacks, and order flows from being blocked by firewall enforcement.
Enable WooCommerce Compatibility Mode
What it means: The firewall avoids interfering with known WooCommerce and payment-related paths.
How to use it: Turn it on for WooCommerce stores, especially if Stripe, PayPal, subscriptions, order-pay links, webhooks, or hosted payment flows are active.
Predefined WooCommerce Exclusions
What it means: Built-in exclusions for common WooCommerce endpoints and checkout actions.
How to use it: Keep enabled unless you are testing a very specific issue. These exclusions reduce false positives on core store flows.
Payment Gateway Compatibility Checks
What it means: Extra checks that recognize payment gateway traffic and reduce accidental blocking.
How to use it: Enable it when using Stripe, PayPal, Authorize.Net, Klarna, Square, subscriptions, wallets, or any gateway that sends callbacks.
Trusted Payment Provider IPs
What it means: Known payment provider IPs can be trusted so gateway traffic reaches WooCommerce.
How to use it: Add official provider IPs only when you know the source. Do not broadly trust random IPs because they appeared during checkout testing.
WooCommerce-Aware Logging
What it means: The firewall can mark or log WooCommerce-related events so checkout traffic is easier to identify.
How to use it: Use it while testing checkout issues so you can distinguish payment flow traffic from attack traffic.
Compatibility Verification
What it means: The settings help verify whether WooCommerce protections are active.
How to use it: After saving compatibility settings, run a real test order, a failed payment, a webhook callback if possible, and a refund or subscription renewal workflow.
Store guidance: For WooCommerce sites, compatibility settings should usually be enabled before Smart Block is used for active enforcement.
Edge Protection
Cloudflare Integration
Cloudflare integration lets the firewall understand the real visitor IP and push confirmed bad traffic toward edge-level handling.
Cloudflare-Aware IP Detection
What it means: Restores the real visitor IP when Cloudflare is proxying traffic.
How to use it: Enable it on Cloudflare-proxied sites so allowlists, blocklists, rate limits, and event logs use the visitor IP instead of a Cloudflare proxy IP.
Auto-Push Confirmed Firewall Blocks
What it means: Confirmed bad IPs can be sent to Cloudflare for challenge or block actions.
How to use it: Start with challenge-style actions before full blocks if you are still tuning. Use stronger actions for repeat confirmed abuse.
Cloudflare Quick Modes
What it means: Fast presets for changing Cloudflare behavior during a security event.
How to use it: Use challenge or stricter modes during attacks. Return to normal settings once the event is handled.
Cloudflare API Credentials
What it means: The API token details used to connect WP Site Lockdown to Cloudflare.
How to use it: Use the least-privilege API token needed for zone and firewall actions. Store credentials carefully and rotate them if staff access changes.
Logs And Notifications
Firewall timeline and email notifications
The timeline and notification settings make firewall decisions visible so support teams can respond instead of guessing.
Local Event Timeline
What it means: Stores recent firewall events locally for review.
How to use it: Keep it enabled so you can investigate blocks, IP status, URI patterns, and severity after a report or spike.
Keep Events For Days
What it means: Controls how long firewall events are retained.
How to use it: Use a shorter retention window on very busy sites and a longer one when you need more history for support or incident review.
Alert Recipient And Events
What it means: Chooses who receives firewall notifications and which events trigger emails.
How to use it: Send alerts to a monitored support inbox. Alert on emergency shield changes, blocked threshold events, and critical firewall changes instead of every low-risk event.
Firewall Event Timeline
What it means: A detailed table of request events, action taken, URI, IP, country, status, method, and severity.
How to use it: Use it to identify repeated attack paths, false positives, and IPs that should be trusted, challenged, or blocked.
GET PROTECTED
Lock down WordPress without opening your wallet
Install Site Lockdown Security and get Premium WordPress protection at no cost.