{"id":349058,"date":"2026-08-14T15:08:47","date_gmt":"2026-08-14T15:08:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/techbox-firewall\/"},"modified":"2026-08-14T15:08:23","modified_gmt":"2026-08-14T15:08:23","slug":"techbox-firewall","status":"publish","type":"plugin","link":"https:\/\/ast.wordpress.org\/plugins\/techbox-firewall\/","author":23523312,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.3","stable_tag":"1.0.3","tested":"7.0.4","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Techbox Firewall","header_author":"Techbox Design","header_description":"Web Application Firewall for WordPress \u2014 blocks SQL injection, XSS, malicious bots, and bad requests before they reach your site. Part of Techbox Shield; pairs with Techbox Login Security.","assets_banners_color":"","last_updated":"2026-08-14 15:08:23","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/techbox-firewall\/","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":36,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.3":{"tag":"1.0.3","author":"techboxdesign","date":"2026-08-14 15:08:23"}},"upgrade_notice":{"1.0.3":"<p>Adds control over proxy headers and the optional rule feed, keeps logs for the full retention range, and hardens security and reliability.<\/p>","1.0.2":"<p>Hardens admin output escaping.<\/p>","1.0.1":"<p>Clarifies external-service Privacy\/Terms links for WordPress.org review.<\/p>","1.0.0":"<p>First public release of Techbox Firewall.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.3"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[166108,1174,1184,18199,18201],"plugin_category":[54],"plugin_contributors":[271641],"plugin_business_model":[],"class_list":["post-349058","plugin","type-plugin","status-publish","hentry","plugin_tags-bot-protection","plugin_tags-firewall","plugin_tags-malware","plugin_tags-waf","plugin_tags-web-application-firewall","plugin_category-security-and-spam-protection","plugin_contributors-techboxdesign","plugin_committers-techboxdesign"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/techbox-firewall.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Techbox Firewall is a fast, lightweight Web Application Firewall (WAF) for WordPress. It inspects every\nrequest and blocks common attacks \u2014 SQL injection, cross-site scripting (XSS), remote code execution,\ndirectory traversal, malicious bots, and bad requests.<\/p>\n\n<p>Techbox Firewall is part of the <strong>Techbox Shield<\/strong> family and is designed to pair with\n<a href=\"https:\/\/wordpress.org\/plugins\/techbox-login-security\/\">Techbox Login Security<\/a> for complete front-door\nprotection: the firewall stops malicious requests, while Login Security guards the login itself.<\/p>\n\n<h4>What you get<\/h4>\n\n<ul>\n<li><strong>WordPress-layer WAF<\/strong> \u2014 loads early and screens every request, on any host, no <code>.htaccess<\/code> or server\nchanges required.<\/li>\n<li><strong>Core attack rules<\/strong> \u2014 SQL injection, XSS, RCE, LFI\/RFI, path traversal, malicious user-agents and\nbad bots, and anomalous requests.<\/li>\n<li><strong>Signed rule updates<\/strong> \u2014 optional (off by default); enable weekly or daily when you want fresher rules, verified before apply.<\/li>\n<li><strong>Learning mode<\/strong> \u2014 on by default so you can watch and log before you enforce.<\/li>\n<li><strong>IP allow \/ block lists<\/strong> \u2014 block known-bad addresses and allow-list your own office or VPN.<\/li>\n<li><strong>Activity log<\/strong> \u2014 see exactly what was blocked and why, with a clean, plain-English record.<\/li>\n<li><strong>Safe-mode recovery<\/strong> \u2014 a built-in way back if a rule or setting ever gets in your way.<\/li>\n<\/ul>\n\n<h4>Built for real people, not just developers<\/h4>\n\n<p>Security software is often written for experts. Techbox Firewall is different: smart defaults,\nplain-English settings, and a clear view of what it is blocking \u2014 so first-time site owners and seasoned\nagencies both feel at home.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Firewall logs, IP lists, and settings stay on your WordPress site. Logs may include IP addresses,\nrequest paths, and matched rule IDs so you can audit blocks \u2014 remove or restrict access if your\npolicies require it.<\/p>\n\n<p>Our website Privacy Policy: https:\/\/techboxdesign.com\/privacy-policy\/<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin can optionally download fresher attack-detection signatures from a feed service\noperated by Techbox Design. It is off on a fresh install and stays off until you switch it on.<\/p>\n\n<ul>\n<li><strong>Service:<\/strong> <code>https:\/\/feeds.techboxdesign.com\/firewall\/v1\/<\/code> \u2014 a JSON signature document plus a\ndetached signature file.<\/li>\n<li><strong>When:<\/strong> Only after an administrator turns on <strong>Allow this site to contact the Techbox\nsignature feed<\/strong> under Firewall \u2192 Rule updates. With that off, the plugin makes no request to\nthe service at all, from any trigger. With it on, you choose between manual checks only, weekly,\nor daily.<\/li>\n<li><strong>Data sent:<\/strong> An ordinary HTTPS GET via the WordPress HTTP API. No account, no licence key, and\nno visitor personal data.<\/li>\n<li><strong>What comes back:<\/strong> Detection signature <em>data<\/em> \u2014 a match expression per entry, plus a category,\na score, and which parts of a request to inspect. Every field is validated against an allow-list\nand the document\u2019s signature is verified before anything is stored. Nothing downloaded is\nexecuted, evaluated, included, or unserialised, and no plugin, theme, or add-on is installed or\nupdated by this service. Plugin updates come from WordPress.org only.<\/li>\n<li><strong>If it is unavailable:<\/strong> The signatures bundled with the plugin are always active, so protection\ndoes not depend on this service being reachable or enabled.<\/li>\n<li><strong>Terms of Use:<\/strong> https:\/\/techboxdesign.com\/terms-and-conditions\/ (see \u201cOptional signed rule\nfeed\u201d)<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/techboxdesign.com\/privacy-policy\/<\/li>\n<\/ul>\n\n<p>You can withdraw permission at any time; doing so also cancels any schedule.<\/p>\n\n<h3>Third-party notices<\/h3>\n\n<p>This plugin may receive <strong>translated derivatives<\/strong> of the <a href=\"https:\/\/coreruleset.org\/\">OWASP Core Rule Set<\/a>\n(Apache License 2.0) through its signed rule feed. Upstream project:\nhttps:\/\/github.com\/coreruleset\/coreruleset \u2014 copyright CRS project contributors; see the upstream\n    LICENSE for the full Apache License 2.0 text. We do not embed ModSecurity; only portable\nsignatures are translated into Techbox\u2019s JSON rule format and delivered via the signed feed.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/<\/code> or install it from the Plugins screen in WordPress.<\/li>\n<li>Activate <strong>Techbox Firewall<\/strong> through the <em>Plugins<\/em> menu.<\/li>\n<li>Open <strong>Techbox Firewall<\/strong> in the admin sidebar. Screening starts in <strong>Monitor<\/strong> mode on the <strong>Basic<\/strong>\nprotection level \u2014 requests are logged, not blocked, until you switch to Enforce.<\/li>\n<li>Allow-list your IP under IP Access, review the Logs, then turn on <strong>Enforce<\/strong> when ready.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20break%20my%20site%20or%20block%20real%20visitors%3F\"><h3>Will this break my site or block real visitors?<\/h3><\/dt>\n<dd><p>Techbox Firewall ships with conservative defaults and a <strong>learning mode<\/strong> so you can review what it would\nblock before it enforces anything. If a rule ever gets in your way, a <strong>safe-mode recovery<\/strong> option and\nper-rule controls let you fix it quickly.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20any%20host%3F\"><h3>Does it work on any host?<\/h3><\/dt>\n<dd><p>Yes. Techbox Firewall runs inside WordPress (no <code>.htaccess<\/code> or server configuration needed), so it works\non shared, managed, and VPS hosting alike.<\/p><\/dd>\n<dt id=\"do%20i%20still%20need%20a%20login%20security%20plugin%3F\"><h3>Do I still need a login security plugin?<\/h3><\/dt>\n<dd><p>A firewall and login protection solve different problems. Techbox Firewall blocks malicious requests;\n<a href=\"https:\/\/wordpress.org\/plugins\/techbox-login-security\/\">Techbox Login Security<\/a> protects the login itself\n(limit login attempts, lockouts, activity logging). They are designed to work together.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Log retention now keeps events for the full 1\u2013365 days offered in settings.<\/li>\n<li>Choose which header carries the visitor IP behind a proxy or CDN, or leave it on automatic detection.<\/li>\n<li>The optional rule feed now asks before its first check and names the service it contacts.<\/li>\n<li>The IP block list explains what it does in the firewall mode you are actually running.<\/li>\n<li>Security and reliability hardening.<\/li>\n<li>Compatibility fixes for recent WordPress releases.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Harden admin output escaping.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Document Privacy Policy and Terms links for the optional signed rule feed.<\/li>\n<li>Point Plugin URI at the WordPress.org listing and trim outbound marketing links.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release: WordPress-layer WAF with Basic \/ Balanced \/ Strict levels.<\/li>\n<li>Ships in Monitor mode on Basic by default; switch to Enforce when ready.<\/li>\n<li>Optional signed rule feed (off by default; weekly or daily when enabled), seed fallback, IP lists, logs, and safe-mode recovery.<\/li>\n<\/ul>","raw_excerpt":"Web Application Firewall for WordPress. Blocks SQL injection, XSS, malicious bots, and bad requests.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/349058","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=349058"}],"author":[{"embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/techboxdesign"}],"wp:attachment":[{"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=349058"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=349058"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=349058"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=349058"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=349058"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=349058"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}