Description
Wordfence Premium blocks malicious traffic in real time through a web application firewall, a list of malicious IP addresses, and malware signatures continuously updated by the Threat Defense Feed, while the free version receives those same rules only after 30 days. Designed for those who manage WordPress sites exposed to hacking attempts, the plugin combines a firewall, malware scanner, and enhanced authentication in a single layer of protection on the server.
Key Features of Wordfence Premium
- Web application firewall
Filters requests at the site’s edge and blocks known attack patterns before they reach WordPress. - Real-time updates
Receives new firewall rules and malware signatures as soon as they are published by the Threat Defense Feed. - Malicious IP blocking
Automatically denies access to addresses already identified as sources of attacks by the monitoring network. - Malware scanner
Scans site files for malicious code and suspicious changes to the core, themes, and plugins. - Two-step authentication and passkeys
Adds an extra layer of verification at login, reducing the risk of unauthorized access through a compromised password.
Benefits of Wordfence Premium
- Faster response to new threats
Eliminates the wait of several days between the discovery of a vulnerability and effective site protection. - Less processing power wasted on bots
Reduces the processing of useless requests by blocking malicious traffic before it reaches the application. - A login that is harder to breach
Reduces the chance of accounts being compromised through leaked or reused credentials. - Visibility into what happens on the site
Shows in real time who accesses the site and which attack attempts have been blocked.
Who Is Wordfence Premium For?
- Those who maintain WordPress sites that have already experienced hacking attempts or login spam.
- Those who need automatic blocking of malicious IP addresses without relying on an external firewall.
- Those of you who manage multiple sites and want firewall rules updated as soon as a threat is identified, without delay.
How to Download Wordfence Premium
Wordfence Premium is available for download right here on Ultrapack. After downloading the .zip file, install it under Plugins > Add New > Upload Plugin, select the file, and activate it; the firewall and scanner will then appear in a new menu in the admin dashboard.
The firewall and scanner work side by side within the same dashboard, eliminating the need to install separate plugins for each layer of protection. For those who handle security for one or more WordPress sites, this combination reduces the time between detecting a threat and effectively blocking it.
Frequently asked questions
Is Wordfence Premium GPL-licensed?
Yes. Wordfence Premium is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use Wordfence Premium on multiple sites?
Yes. You can use Wordfence Premium on multiple sites. The number of sites connected to Ultrapack Auto Updater is limited by your plan.
How much does Wordfence Premium cost at Ultrapack?
Wordfence Premium costs US$4.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does Wordfence Premium include updates?
Yes. The current version of Wordfence Premium is 9.0.1, published at Ultrapack on Sep 9, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is Wordfence Premium scanned before publication?
Yes. Every version of Wordfence Premium goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What are the requirements for the plugin Wordfence Premium?
Requires WordPress 4.7 or higher and PHP 7.0 or higher. Tested up to WordPress 7.1.
What changed in this version
Version 9.0.1
- Improvement: UX enhancements for passkey authentication and general login security
- Improvement: GeoIP database updated
- Fix: Improved error handling in WAF request handlers and XML-RPC parser
- Fix: Fixed an issue with translations not showing on the Login Security Settings tab
- Fix: Addressed several potential PHP 8.5+ deprecation notices
- Fix: Reworked MD5 hash use in MySQL to avoid deprecation in 9.7+
Version 9.0.0
- Improvement: Added support for passkey authentication
- Available for both free and premium installations
- Can be enabled for any user role (multisite support is currently limited)
- WooCommerce integration
- Support for custom authentication integrations
- Improvement: GeoIP database updated
- Improvement: Several mobile styling and layout improvements on the login security page
- Improvement: Added diagnostics info for authentication hooks to assist with login-related troubleshooting
- Change: Hardened 2FA flow when installed next to plugins with non-standard authentication (credit: Austin Ginder of Anchor Hosting)
- Change: Hardened 2FA remember cookie handling
- Change: The scanner will now display an issue when the standalone Wordfence Login Security plugin is installed because all functionality is already provided by Wordfence itself
- Change: Updated internal libraries used by the Vue UI
- Change: Login error masking setting now also applies to the Login Security functionality
Version 8.2.2
- Improvement: Better presentation of Live Traffic data on wide screens
- Improvement: Increased legibility of token fields
- Improvement: Reworked the pagination of the Blocking page for a better UX
- Improvement: Country blocking token field can now expand to show all entries
- Improvement: Performance improvements for the activity log and better pause behavior on window blur/focus
- Improvement: GeoIP database updated
- Change: Removed deprecated Central endpoint
- Fix: Addressed issue where the last activity log entry could repeatedly appear
- Fix: Using the embedded shortcode for the 2FA form now correctly enqueues core JavaScript dependencies
- Fix: Modals with content that overflows on smaller viewports can now be scrolled
- Fix: The changelog link in plugin upgrade scan issues now links correctly
Version 8.2.1
- Fix: Fixed issue with some i18n plugins/themes when a user has no 2FA recovery codes
- Fix: Toggled options with additional help links now correctly open the link rather than toggling the option
- Fix: Country Blocking editing fixed when there are multiple pages of block rules
- Fix: Added better error handling to the initial Vue data load
- Fix: Handled error when logging in using legacy 2FA with separate prompts enabled
Version 8.2.0
- Improvement: Migrated all deprecated JavaScript libraries in use to a Vue-based infrastructure
- Improvement: GeoIP database update
- Improvement: Better coverage of `aria-` accessibility attributes
- Improvement: Added `translators` comments to translatable strings where previously missing
- Fix: WordPress 7.0 compatibility fixes
- Note: Legacy two factor authentication using SMS-based codes will be discontinued around July 1, 2026. Sites using this functionality should migrate users to the TOTP-based two factor authentication on the Login Security page of the plugin
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
- Download the file
wordfence.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
wordfence.zipand click Install Now. - Click Activate.
Requirements: Requires WordPress 4.7 or higher and PHP 7.0 or higher. Tested up to WordPress 7.1.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready