Wordfence

wpdeeply.com/plugins/wordfence/
LOW WPDeeply risk rating
Active installations
4 million+
WordPress.org status
Active
Known vulnerabilities
Few, historically
Open unresolved
0
Last vulnerability
None current
PHP compatibility
PHP 7.4+ supported
Maintenance frequency
Active — frequent releases and its own threat-intelligence programme
WPDeeply recommendationSafe to keep. Just be clear about what it covers: it blocks and detects, it does not tell you which installed software is out of date.

Data reviewed August 2026. Version numbers move weekly — the WordPress.org listing linked in the sidebar is always authoritative for the current release.

Current security status

Wordfence is actively maintained, runs its own vulnerability research and bug-bounty programme, and has no known unresolved vulnerabilities. WPDeeply rates it LOW risk.

What it covers

  • Firewall — blocks requests matching known attack patterns, which buys time between a disclosure and your patch.
  • Malware scanning — compares files against known-good versions and signatures, useful after a compromise.
  • Login protection — rate limiting and 2FA.

What it does not cover

A firewall is a mitigation, not an inventory. It will not tell you that a plugin you have not opened in two years was removed from WordPress.org, or that an inactive plugin still needs patching, or which of your components has a fix available right now. Rules for a brand-new vulnerability necessarily arrive after the vulnerability does.

That is the gap WPDeeply Risk Monitor fills, and the two are complementary rather than competing — see WordPress security plugins compared for how the categories fit together.

Practical notes

  • Do not run two firewall plugins. Pick one and put it at the edge if you can.
  • Scanning is resource-intensive on shared hosting; schedule it rather than running it constantly.
  • A clean Wordfence scan is not evidence that your software is up to date. Those are different questions.

Recommendation

Keep it if you want blocking and detection, and pair it with vulnerability monitoring and off-server backups.