Vardalion Security · WordPress Security Firewall

Your WordPress site is being scanned. Vardalion Security is watching back.

Detect brute-force attacks, malicious requests, bot abuse, username enumeration, exploit probes and suspicious traffic — then automatically block repeat offenders before they become a bigger problem.

New to Vardalion Security? Download it from the official WordPress.org Plugin Directory. The 28-day Pro trial starts after installation.

28-day full Pro trial Automatic threat scoring No cloud dashboard required
LIVE PROTECTION
50env_probe/.env
50git_probe/.git/config
100auto_blockHTTP 403
30repeated_404/identity.php
30rapid_php_probe/ssh3ll.php
60auto_blockHTTP 403

Built from real WordPress attack behaviour. Vardalion Security has been exercised across live WordPress installations against automated scanners, login attacks, sensitive-file probes and PHP backdoor hunting.

REAL-WORLD PROTECTION

The internet does not wait for your site to become popular.

Automated systems scan WordPress websites continuously. Vardalion Security combines individual security signals into a threat score so suspicious behaviour can be identified and stopped automatically.

01

Sensitive file probing

Scanners searching for exposed environment files and development repositories are detected before they can continue probing.

/.env+50
/.git/config+50
02

Backdoor and PHP scanning

Rapid requests for suspicious PHP files, web shells and missing files contribute stronger behavioural evidence instead of relying on one weak signal.

/ssh3ll.phpDetected
/wp_filemanager.phpDetected
03

Slow brute-force attacks

Attackers can space login attempts apart to evade basic rate limits. Vardalion Security retains meaningful authentication signals and can still reach a blocking threshold.

wp-login.php+12
repeat attempt+12
BEHAVIOURAL THREAT SCORING

One suspicious request is a clue. A pattern is evidence.

1Request arrivesIP, endpoint and request behaviour evaluated
→
2Signals detectedLogin failures, exploit probes, bots, scans
→
3Threat score risesDifferent evidence contributes appropriate weight
→
4Vardalion Security respondsMonitor, rate limit or automatically block
0–19Monitor
20–39Enhanced logging
40–59Rate control
60–79Temporary block
80+Extended response
REPEAT OFFENDERS

Keep coming back. Keep staying out.

Vardalion Security can progressively increase restrictions for repeat offenders instead of treating every return as a first offence.

1First offence15 minutes
2Second offence1 hour
3Third offence24 hours
4Fourth offence7 days
5+Persistent offenderPermanent
403

Security that responds automatically.

The goal is not simply to maintain a list of bad addresses. Vardalion Security evaluates what a visitor is actually doing and responds according to the evidence.

WHEN VARDALION SAYS NO

Blocked visitors know the site is protected.

A branded 403 experience gives legitimate visitors a reference ID while deliberately withholding the detection rule, threat score and other security internals.

Concept of the Vardalion Security permanent HTTP 403 block page
Vardalion Security permanent block page concept.
WHAT VARDALION PROTECTS

WordPress-focused protection without the noise.

✓Brute-force & authentication attacks
✓WordPress user enumeration
✓Sensitive file probing
✓.env and .git discovery attempts
✓PHP and web-shell scanning
✓Repeated 404 reconnaissance
✓Suspicious bot behaviour
✓Rate-based request abuse
✓Automatic IP blocking
✓Repeat-offender escalation
✓Security event logging
✓Behavioural threat scoring
FROM THE VARDALION DEVELOPMENT LOG

Vardalion Security is already blocking real-world WordPress attacks.

Live deployments have shown how quickly WordPress sites receive automated probes — including sites that were only days old. Scanners do not need to know who owns a website or whether it is popular. They are searching for opportunities.

That live traffic is helping refine Vardalion Security around the behaviour that actually matters: combining strong evidence, reducing weak-signal false positives, and escalating persistent offenders.

The internet does not wait for your website to become popular before it starts knocking on the door. Vardalion Security is built to make sure the wrong visitors do not get in.
User feedback

What people are saying about Vardalion Security.

★★★★★

“OMG! I installed Vardalion Security on a brand-new WordPress site and I can’t believe how many attacks it detected after just one week. Superb. 5 out of 5 stars.”

— Baz
Free vs Pro

Start protected. Upgrade when you need the complete suite.

Every new installation starts with 28 days of full Pro protection. After the trial, baseline protection continues free, or upgrade to keep every Pro feature and licensed updates.

FeatureFree / BaselinePro
Firewall request inspection✓✓
Login / brute-force protection✓✓
User enumeration & REST user protection✓✓
Bot and scanner detection✓✓
Threat scoring & automatic IP blocking✓✓
Repeat-offender escalation✓✓
Manual IP and CIDR/network blocking✓✓
Security dashboard and essential logs✓✓
Emergency Mode / recovery✓✓
Advanced request-rate enforcement—✓
Country access enforcement—✓
Automatic subnet blocking—✓
Daily security digest—✓
Licensed automatic updates—✓
Documentation

Vardalion Security Complete User Guide

Installation, configuration, threat scoring, blocking, IP Intelligence, Emergency Mode, licensing, updates, troubleshooting and administrator guidance.

Free. No registration required.

LICENSING

Choose the coverage that fits your WordPress estate.

Every installation starts with a 28-day full Pro trial. One licence can cover the number of sites shown for its plan.

25 SITES

£399/year

For agencies and larger WordPress portfolios.

Protect 25 sites
100 SITES

£799/year

For agencies and large managed WordPress estates.

Protect 100 sites
FAQ

A few things worth knowing.

Does Vardalion Security only protect the login page?

No. Authentication protection is one part of the firewall. Vardalion Security also evaluates malicious requests, probes, scanning behaviour, user enumeration, bots and repeated reconnaissance.

What happens when an attacker is blocked?

The request receives an HTTP 403 response. Repeat offenders can receive progressively longer restrictions, up to permanent blocking.

Will Vardalion Security tell attackers why they were blocked?

No. The public block page can provide a neutral reference ID for support, but it does not reveal the detection rule, internal score or security configuration.

Can I try Pro before buying?

Yes. New installations include a 28-day full Pro trial before a paid licence is required for premium functionality.

VARDALION

Your WordPress site already has visitors you never invited.

Give it a firewall designed to recognise them.