Description
WP Cerber Security – Firewall, Anti-spam & Malware Scan allows WordPress site administrators to configure a firewall, anti-spam filter, and malware scanner, blocking intrusion attempts and unwanted comments in real time. With it, you monitor suspicious files, restrict access by IP, and enable reCAPTCHA on login, registration, and comment forms, strengthening protection without overloading the server.
Key Features of WP Cerber Security – Firewall, Anti-spam & Malware Scan
- Intelligent firewall
Blocks malicious requests before they reach WordPress, filtering by IP, user-agent, and attack patterns. - Advanced anti-spam
Filters comments and registrations based on customizable rules, eliminating spam without relying on external services. - Malware scanner
Scans core, theme, and plugin files for malicious code, generating alerts and corrective actions. - Brute force protection
Limits login attempts, blocks IPs after repeated failures, and displays reCAPTCHA for additional authentication. - Activity monitoring
Logs logins, file changes, and intrusion attempts, displaying a centralized audit dashboard.
Benefits of WP Cerber Security – Firewall, Anti-spam & Malware Scan
- Reduced attacks
Prevents unauthorized access and exploitation of common vulnerabilities on WordPress sites. - Resource savings
Replaces multiple security plugins with a unified, lightweight, optimized solution. - Continuous monitoring
Receives email notifications about suspicious activity, keeping you in control even outside the dashboard. - Easy configuration
Activates essential protections in a few clicks, without requiring advanced technical knowledge.
Who Is WP Cerber Security – Firewall, Anti-spam & Malware Scan For?
- WordPress site administrators looking for complete security without complexity.
- Developers who need an integrated firewall and scanner for multiple projects.
- Hosting agencies and providers who want to protect client instances from malware and intrusions.
How to Download WP Cerber Security – Firewall, Anti-spam & Malware Scan
WP Cerber Security – Firewall, Anti-spam & Malware Scan is available for download here at Ultrapack. After downloading the .zip file, go to Plugins > Add New > Upload Plugin, select the file, and activate it. The security dashboard will appear in the WordPress menu, ready for immediate configuration.
Combining an edge firewall, file scanner, and protection against spam and brute force, WP Cerber Security offers a robust layer of defense for any WordPress site, from personal blogs to online stores and corporate portals. Its streamlined interface lets you manage all threats in a single place, reducing the attack surface without compromising performance.
Frequently asked questions
Is WP Cerber Security – Firewall, Anti-spam & Malware Scan GPL-licensed?
Yes. WP Cerber Security – Firewall, Anti-spam & Malware Scan is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use WP Cerber Security – Firewall, Anti-spam & Malware Scan on multiple sites?
Yes. You can install WP Cerber Security – Firewall, Anti-spam & Malware Scan on as many sites as you want. Only automatic updates through Ultrapack Auto Updater have a limit: from 3 to 80 sites, depending on the plan.
How much does WP Cerber Security – Firewall, Anti-spam & Malware Scan cost at Ultrapack?
WP Cerber Security – Firewall, Anti-spam & Malware Scan costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does WP Cerber Security – Firewall, Anti-spam & Malware Scan include updates?
Yes. The current version of WP Cerber Security – Firewall, Anti-spam & Malware Scan is 9.9.5, published at Ultrapack on Aug 26, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is WP Cerber Security – Firewall, Anti-spam & Malware Scan scanned before publication?
Yes. Every version of WP Cerber Security – Firewall, Anti-spam & Malware Scan goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What are the requirements for the plugin WP Cerber Security – Firewall, Anti-spam & Malware Scan?
Requires WordPress 5.8 or higher and PHP 7.4 or higher. Tested up to WordPress 7.1.
What changed in this version
Version 9.9.5
- Improved: A setting link in admin UI now opens the matching role tab in the role-based settings and highlights the target setting, so you can jump from an Activity log event straight to the setting that affected WP Cerber's decision.
- Improved: Following a setting link from a popup explainer now centers the target WP Cerber setting in the browser window instead of aligning it with the top of the page, where the WordPress admin bar could cover it.
- Changed: URL escaping in the admin interface now accepts root-relative URLs that begin with a single slash, in addition to the already supported HTTP(S), FTP(S), and mailto URLs.
- Changed: Admin announcements are now stored as structured JSON instead of pre-rendered HTML markup. A stored announcement that does not match the supported format is rejected instead of being displayed incorrectly.
- Fixed: On the Activity log page, when several explainers described events for the same user and WP Cerber's decision was role-based, only the first setting link scrolled to and highlighted the target setting. The remaining links opened the settings page without scrolling to the target setting.
- Fixed: The "Mail Transport" settings section displayed the raw HTML markup for the "Available in the professional version of WP Cerber" link instead of a working link.
- Fixed: Non-ASCII characters in a URL path are no longer removed when WP Cerber escapes a URL, so URLs with non-ASCII path characters now point to the intended address.
- Fixed: A URL containing invalid UTF-8 no longer becomes an empty link address when WP Cerber escapes it.
- Changed: Quotes, angle brackets, and backticks are no longer deleted from URLs in admin pages. HTML escaping of the attribute value now handles these characters safely.
Version 9.9.3
- Fixed: When error logging was active, an uncaught PHP failure such as an unhandled exception, a type error, or a parse error could stop the standard PHP fatal error processing. WordPress can again show its critical error page, send the Recovery Mode email, and revert a broken PHP edit made in the built-in plugin or theme editor.
- Fixed: Uncaught PHP exceptions and other fatal failures could be missing from the WordPress `debug.log` file when `WP_DEBUG_LOG` was enabled.
- Fixed: Not all PHP errors were logged for a request. A fatal error that terminated the request could be replaced by a later diagnostic produced by WP Cerber's own shutdown routines, so the terminating error was missing from the request details in Traffic Inspector and from `cerber-errors.log`.
- Fixed: On a non-English website, the issue message reporting a failed email delivery could be shown in the language of the request that failed to send the email, which is usually an unattended request such as a scheduled report or a visitor-triggered alert. The message is now translated into the language of the administrator who reads it.
- Fixed: On a non-English website, the message reporting corrupted plugin settings and their recovery was shown untranslated. It is now translated at the moment it is displayed to the administrator.
- Fixed: Some messages in the "System Readiness" widget were missing localization support and could not be translated.
- Fixed: Rendering the quick navigation block in the admin area could produce `Array to string conversion` warnings when a query parameter carried more than one value. Depending on the PHP error configuration, these warnings could pollute the server logs, appear in the admin output, or corrupt an AJAX response.
- Fixed: Some valid IPv6 ranges written in dash or wildcard notation were rejected when adding an entry to the IP Access Lists or filtering records in the Activity log and the Traffic log. Reversed and zero-length ranges are still rejected.
- Fixed: IPv6 range matching now uses inclusive boundaries, so the first and the last address of a range are treated as part of that range.
Version 9.9
- New: WP Cerber now automatically maintains a backup copy of the last known valid plugin settings. The backup is refreshed after successful settings updates, settings imports, plugin upgrades, and during daily maintenance.
- New: If the stored plugin settings become corrupted, WP Cerber now restores them automatically from the settings backup and shows a dismissible admin notice explaining what happened, what action was taken, and what the administrator should review.
- New: The "System Readiness" widget now shows an advisory notice on servers where PHP is built without the modern `mysqlnd` database driver. The notice confirms that WP Cerber keeps working and recommends enabling `mysqlnd` for full compatibility and better performance.
- Improved: Traffic Inspector now detects additional high-confidence JavaScript obfuscation patterns, including fully escaped strings that use `\uNNNN` and `\u{...}` escape sequences and dangerous execution, DOM, network, and system code decoded from explicit `fromCharCode` calls, while preserving its low false-positive detection model.
- Compatibility: WP Cerber now runs correctly on legacy hosting environments where PHP is built without the modern `mysqlnd` database driver. On such servers, database query results are retrieved through a slower compatible method instead of triggering a fatal error.
- Fixed: A corrupted WP Cerber configuration value stored in the database could cause a fatal `TypeError` in `array_merge` at plugin load time on PHP 8, taking the whole website down. WP Cerber now detects the unreadable stored value, falls back to the default settings, and reports the failure as a critical issue until the administrator re-saves the settings.
- Fixed: A regression in the detection of obfuscated JavaScript by Traffic Inspector. JavaScript strings built entirely of `\xNN` hex escape sequences were not decoded, so obfuscated code such as `eval`, `script`, and `XMLHttpRequest` could go undetected when request fields were inspected.
Version 9.8.3
- New: The Activity log and Traffic log CSV exports now report the date range they cover, adding the oldest and newest record timestamps to the export header.
- Improved: Activity log and Traffic log CSV exports now stream matching rows in a single unbuffered pass, keeping memory usage flat and avoiding deep-offset scanning, which makes exporting large logs faster and more reliable.
- Improved: Activity log and Traffic log exports now send the `X-Accel-Buffering: no` response header so an Nginx proxy in front of PHP-FPM forwards each chunk immediately instead of buffering the whole export, improving time-to-first-byte on large exports.
- Improved: Decoding of stored Traffic Inspector request field data is now more robust, consistently treating nullable legacy values, empty values, invalid JSON, and unsupported serialized payloads as an empty array.
- Fixed: Corrected memory limit handling during Activity log and Traffic log exports, where a numeric limit such as `512` could be applied as bytes instead of megabytes, preventing WP Cerber from raising the available memory and causing exports to stop earlier than expected.
- Fixed: In the Traffic Inspector Log "Advanced Search", combining the "Any software error" option with other filters could return requests with recorded PHP errors that did not match the other criteria; results now match all selected filters.
- Fixed: Dashboard links in Activity alert notification emails could carry mismatched query parameters, for example the IP filter receiving an IP-range boundary value, which opened an unrelated filtered view; the links now use the correct values.
- Fixed: Activity alerts that match on a search string now resolve the user of the logged event instead of falling back to the current administrator, so user-based alert matching behaves correctly.
- Fixed: Prevented an undefined array key notice in `CRB_Activity::is_modified_since` when the `data_modified` status value was missing, and corrected an operator-precedence error so a missing modification timestamp is correctly treated as modified.
- Security: Sanitized user-controlled profile display names (first name, last name, and display name) before they are concatenated into `Name ` mail recipient strings, closing an email header injection vector that could add an extra recipient to the two-factor authentication PIN email and to Activity alert notification emails.
- Security: Plugin ownership-change messages on the scanner page are now rendered through WP Cerber's UI layer with contextual output escaping instead of raw HTML, removing a potential stored admin XSS vector from externally supplied plugin ownership metadata provided by the WordPress.org plugin repository.
- Security: Activity log and Traffic log CSV exports now send the `Cache-Control: no-store` response header to prevent a sensitive security-log export from being cached by the browser or an intermediate proxy.
Version 9.8
- Changed: Renamed the "White IP Access List" and "Black IP Access List" terms to "Allowed IP Access List" and "Blocked IP Access List" across the admin UI for clearer access-control terminology.
- Changed: Client IP address detection now converts IPv4-mapped IPv6 addresses to standard IPv4 notation in proxy and IPv6 environments. ACL entries using mapped IPv6 notation no longer match these normalized client IP addresses.
- Changed: Client IP address detection no longer falls back to the `HTTP_CLIENT_IP` header when the `X-Forwarded-For` proxy header is empty or does not contain a valid address.
- Improved: The integrity scanner now records detailed database error information in the log when diagnostic logging is enabled in the settings.
- Fixed: Geolocation data for IPv6 addresses is now cached correctly, so country names appear immediately in the Activity log and Traffic log instead of being re-fetched from the geolocation service on each view, which previously caused extra AJAX requests and a noticeable delay.
- Fixed: Eliminated the `ERROR 1062` ("Duplicate entry") messages that the IPv6 geolocation caching bug wrote to the server error log on each IPv6 lookup.
- Fixed: If more than one IPv6 range or IPv6 network defined in IP Access Lists, the Traffic and Activity logs could display comments or labels belonging to a different IPv6 Access List entry, for example showing the label "IP whitelisted" for a request that was actually denied. The logs now show details that match the Access List entry involved.
- Fixed: Database operations now compatible with WordPress table prefixes starts with a digit, such as `123_`. This resolves a regression introduced by the stricter database operation validation in WP Cerber 9.7.4, where affected sites could fail to run integrity scanner.
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
- Download the file
wp-cerber.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
wp-cerber.zipand click Install Now. - Click Activate.
Requirements: Requires WordPress 5.8 or higher and PHP 7.4 or higher. Tested up to WordPress 7.1.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready