{"id":17,"date":"2026-09-15T12:05:29","date_gmt":"2026-09-15T12:05:29","guid":{"rendered":"https:\/\/microupdate.co.uk\/articles\/?p=17"},"modified":"2026-09-15T12:07:01","modified_gmt":"2026-09-15T12:07:01","slug":"wordfence-aios-a-practical-wordpress-security-setup-without-the-overlap","status":"publish","type":"post","link":"https:\/\/microupdate.co.uk\/articles\/wordpress\/wordfence-aios-a-practical-wordpress-security-setup-without-the-overlap\/","title":{"rendered":"Wordfence + AIOS: A Practical WordPress Security Setup Without the Overlap"},"content":{"rendered":"\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">Wordfence and All In One WP Security can work very well together, but there is a lot of overlap between them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Both plugins can protect logins, block malicious requests, restrict access, monitor activity and apply additional WordPress security controls. Simply enabling everything in both plugins is not a good strategy. It can create duplicate protection, conflicting rules, unnecessary processing and make it much harder to work out which plugin has blocked something when a problem occurs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A better approach is to give each plugin a clear job.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Wordfence<\/strong> is the primary security system for the firewall, malware scanning, file comparison, brute-force protection, rate limiting and attack monitoring.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>AIOS<\/strong> complements Wordfence with file and server hardening, permission checks, protection for sensitive files and a number of useful WordPress-specific security controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The tables below show how I would configure the two plugins together. They identify which plugin should handle each security feature, which overlapping settings should normally be disabled, and where the two plugins can safely complement each other.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The aim is simple: <strong>strong everyday WordPress protection without running two competing security systems.<\/strong><\/p>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Plugins covered<\/h2>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h3 class=\"wp-block-heading\">Wordfence Security \u2013 Firewall, Malware Scan, and Login Security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Developer:<\/strong> Wordfence<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Availability:<\/strong> Free plugin with paid Premium, Care and Response options.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Official plugin page:<\/strong> <a href=\"https:\/\/wordpress.org\/plugins\/wordfence\/\">Wordfence on WordPress.org<\/a><\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h3 class=\"wp-block-heading\">All-In-One Security (AIOS) \u2013 Security and Firewall<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Developer:<\/strong> Team Updraft<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Availability:<\/strong> Free plugin with Premium upgrade available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Official plugin page:<\/strong> <a href=\"https:\/\/wordpress.org\/plugins\/all-in-one-wp-security-and-firewall\/\">AIOS on WordPress.org<\/a><\/p>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This guide covers the current Wordfence and AIOS plugin interfaces. Menu names and option locations can change between releases, so check the official plugin documentation if a setting has moved.<\/p>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Firewall and request protection<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>Web Application Firewall<\/strong><\/td><td>Firewall Status: <strong>Enabled and Protecting<\/strong>. Protection Level: <strong>Extended Protection<\/strong>.<\/td><td>6G \/ 8G firewall rules: <strong>OFF<\/strong>. Basic <code>.htaccess<\/code> protection: <strong>ON<\/strong>.<\/td><td>Use Wordfence as the primary WAF. Keep AIOS basic server-level hardening enabled, but avoid overlapping broad firewall rule sets.<\/td><\/tr><tr><td><strong>Fake Googlebots<\/strong><\/td><td>No separate setting required here.<\/td><td>Block Fake Googlebots: <strong>ON<\/strong>.<\/td><td>Let AIOS handle this specific check.<\/td><\/tr><tr><td><strong>Blank User-Agent \/ Referer POST attacks<\/strong><\/td><td>Equivalent rule: <strong>OFF if AIOS handles it<\/strong>.<\/td><td>Block POST requests with blank User-Agent and Referer: <strong>ON, normally<\/strong>.<\/td><td>Enable this in one plugin only. Use AIOS for this specific rule.<\/td><\/tr><tr><td><strong>Rate limiting<\/strong><\/td><td>Enable Rate Limiting and Blocking: <strong>ON<\/strong>.<\/td><td>Equivalent rate \/ lock controls: <strong>OFF<\/strong>.<\/td><td>Keep request throttling with Wordfence.<\/td><\/tr><tr><td><strong>Country blocking<\/strong><\/td><td>Use Wordfence if Premium.<\/td><td><strong>OFF if Wordfence handles it<\/strong>.<\/td><td>Use one country-blocking system only.<\/td><\/tr><tr><td><strong>404 attack detection<\/strong><\/td><td>Rate limiting \/ WAF: <strong>Primary defence<\/strong>.<\/td><td>Smart 404 Blocking: <strong>Optional, Premium<\/strong>.<\/td><td>Wordfence is normally sufficient. Add AIOS Smart 404 Blocking only if there is a clear need.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Malware scanning and file integrity<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>Malware scanning<\/strong><\/td><td>Standard Scan: <strong>ON<\/strong>. Scheduled scans: <strong>ON \/ Daily<\/strong>.<\/td><td>Malware scanner: <strong>OFF<\/strong>.<\/td><td>Use Wordfence as the primary malware scanner.<\/td><\/tr><tr><td><strong>WordPress core comparison<\/strong><\/td><td>Scan core against repository: <strong>ON<\/strong>.<\/td><td>No equivalent required.<\/td><td>Use Wordfence repository comparison to detect modified core files.<\/td><\/tr><tr><td><strong>Plugin comparison<\/strong><\/td><td>Scan plugins against repository: <strong>ON<\/strong>.<\/td><td>No equivalent required.<\/td><td>Use Wordfence for repository-backed plugin comparison.<\/td><\/tr><tr><td><strong>Theme comparison<\/strong><\/td><td>Scan themes against repository: <strong>ON<\/strong>.<\/td><td>No equivalent required.<\/td><td>Use Wordfence for supported repository themes.<\/td><\/tr><tr><td><strong>File change detection<\/strong><\/td><td>File scanning: <strong>Primary<\/strong>.<\/td><td>File Change Detection: <strong>Optional<\/strong>.<\/td><td>Wordfence should remain the main file-integrity system. AIOS can provide an additional notification layer if wanted.<\/td><\/tr><tr><td><strong>PHP execution in uploads<\/strong><\/td><td>Disable Code Execution for Uploads directory: <strong>ON<\/strong>.<\/td><td>No duplicate control required.<\/td><td>Enable in Wordfence. This is a valuable protection against executable files being run from <code>\/uploads\/<\/code>.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Login and brute-force protection<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>Brute-force protection<\/strong><\/td><td>Enable brute force protection: <strong>ON<\/strong>.<\/td><td>Login Lockout: <strong>OFF<\/strong>.<\/td><td>Let Wordfence own login throttling and lockouts.<\/td><\/tr><tr><td><strong>Failed login threshold<\/strong><\/td><td>Lock out after login failures: <strong>20<\/strong>.<\/td><td><strong>OFF<\/strong>.<\/td><td>Use the Wordfence threshold only.<\/td><\/tr><tr><td><strong>Forgot-password threshold<\/strong><\/td><td>Lock out after forgot-password attempts: <strong>5<\/strong>.<\/td><td><strong>OFF<\/strong>.<\/td><td>Keep this under Wordfence.<\/td><\/tr><tr><td><strong>Failure counting window<\/strong><\/td><td>Count failures over: <strong>5 minutes<\/strong>.<\/td><td><strong>OFF<\/strong>.<\/td><td>Use the Wordfence setting.<\/td><\/tr><tr><td><strong>Lockout duration<\/strong><\/td><td><strong>1 hour<\/strong>.<\/td><td><strong>OFF<\/strong>.<\/td><td>A reasonable starting point for a small business site.<\/td><\/tr><tr><td><strong>Invalid usernames<\/strong><\/td><td>Immediately lock out invalid usernames: <strong>ON<\/strong>.<\/td><td>No duplicate rule required.<\/td><td>Useful where there are only a few legitimate users.<\/td><\/tr><tr><td><strong>Blocked usernames<\/strong><\/td><td>Immediately block usernames: <strong>admin plus known bogus names<\/strong>.<\/td><td>No duplicate rule required.<\/td><td>Never add a real username to the blocked list.<\/td><\/tr><tr><td><strong>Cookie-based brute-force prevention<\/strong><\/td><td>Wordfence handles brute-force defence.<\/td><td><strong>OFF<\/strong>.<\/td><td>Avoid running a second independent brute-force system.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Passwords, 2FA and login CAPTCHA<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>Breached passwords<\/strong><\/td><td>Prevent use of breached passwords: <strong>ON<\/strong>.<\/td><td>No duplicate required.<\/td><td>Use Wordfence.<\/td><\/tr><tr><td><strong>Strong passwords<\/strong><\/td><td>Enforce strong passwords: <strong>Admins and publishers<\/strong>.<\/td><td>No duplicate required.<\/td><td>Keep password enforcement with Wordfence.<\/td><\/tr><tr><td><strong>Two-factor authentication<\/strong><\/td><td>2FA: <strong>ON for administrators<\/strong>.<\/td><td>Two-factor authentication: <strong>OFF<\/strong>.<\/td><td>Use one 2FA system only.<\/td><\/tr><tr><td><strong>Login CAPTCHA<\/strong><\/td><td>Use Wordfence if required.<\/td><td>Login CAPTCHA: <strong>OFF<\/strong>.<\/td><td>Avoid two CAPTCHA systems on the same login form.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Username and account protection<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>Login error disclosure<\/strong><\/td><td>Don&#8217;t reveal valid users in login errors: <strong>ON<\/strong>.<\/td><td>No duplicate required.<\/td><td>Use Wordfence.<\/td><\/tr><tr><td><strong>Username discovery<\/strong><\/td><td>Prevent username discovery through author scans \/ REST \/ oEmbed \/ XML sitemaps: <strong>ON<\/strong>.<\/td><td>Prevent User Enumeration: <strong>OFF<\/strong>.<\/td><td>Keep enumeration protection with Wordfence.<\/td><\/tr><tr><td><strong><code>admin<\/code> username registration<\/strong><\/td><td>Prevent registration of <code>admin<\/code>: <strong>ON<\/strong>.<\/td><td>Detect admin username: <strong>Use as audit only<\/strong>.<\/td><td>Wordfence blocks future registration. AIOS can be used as a check for an existing account.<\/td><\/tr><tr><td><strong>Display name = username<\/strong><\/td><td>No specific role required.<\/td><td>Detect identical login\/display names: <strong>ON \/ check<\/strong>.<\/td><td>Use AIOS as an account-hardening audit.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">File and server hardening<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>PHP file editor<\/strong><\/td><td>No separate control required.<\/td><td>Disable PHP File Editing: <strong>ON<\/strong>.<\/td><td>Use AIOS to disable theme\/plugin editing from WordPress admin.<\/td><\/tr><tr><td><strong>File permissions<\/strong><\/td><td>No primary role here.<\/td><td>File Permissions scanner: <strong>ON \/ review<\/strong>.<\/td><td>Use AIOS as an audit tool.<\/td><\/tr><tr><td><strong>Sensitive WordPress files<\/strong><\/td><td>No duplicate required.<\/td><td>Protect sensitive files: <strong>ON<\/strong>.<\/td><td>Use AIOS.<\/td><\/tr><tr><td><strong>Directory browsing<\/strong><\/td><td>No duplicate required.<\/td><td>Disable directory listing: <strong>ON<\/strong>.<\/td><td>Use AIOS.<\/td><\/tr><tr><td><strong>Server signature<\/strong><\/td><td>No duplicate required.<\/td><td>Disable server signature: <strong>ON<\/strong>.<\/td><td>Use AIOS.<\/td><\/tr><tr><td><strong><code>debug.log<\/code> exposure<\/strong><\/td><td>No duplicate required.<\/td><td>Block access to <code>debug.log<\/code>: <strong>ON<\/strong>.<\/td><td>Use AIOS.<\/td><\/tr><tr><td><strong>WordPress salts<\/strong><\/td><td>No direct equivalent.<\/td><td>Salt postfix \/ enhanced salts: <strong>ON<\/strong>.<\/td><td>Use AIOS.<\/td><\/tr><tr><td><strong>Database prefix<\/strong><\/td><td>No action required.<\/td><td>Change <code>wp_<\/code> database prefix: <strong>Do not change purely for security<\/strong>.<\/td><td>Avoid unnecessary database modification on an established site.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">REST API, XML-RPC and application passwords<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>REST API restrictions<\/strong><\/td><td>Username enumeration protection: <strong>ON<\/strong>.<\/td><td>Disallow unauthorised REST requests: <strong>Usually OFF<\/strong>.<\/td><td>Protect sensitive user discovery rather than blocking REST generally.<\/td><\/tr><tr><td><strong>XML-RPC authentication<\/strong><\/td><td>XML-RPC authentication protection: <strong>ON<\/strong>.<\/td><td>Disable XML-RPC completely: <strong>OFF normally<\/strong>.<\/td><td>Keep XML-RPC available where required, but protect authentication abuse with Wordfence.<\/td><\/tr><tr><td><strong>XML-RPC pingbacks<\/strong><\/td><td>No separate setting required.<\/td><td>Disable XML-RPC pingbacks: <strong>ON if available and not needed<\/strong>.<\/td><td>Safer than disabling XML-RPC completely.<\/td><\/tr><tr><td><strong>Application passwords<\/strong><\/td><td>Disable WordPress application passwords: <strong>ON unless required<\/strong>.<\/td><td>No duplicate required.<\/td><td>Disable unless a genuine integration needs them.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">IP blocking and traffic control<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>IP blocking<\/strong><\/td><td>Manual IP blocks: <strong>Use here<\/strong>.<\/td><td>IP Blacklist: <strong>Normally OFF<\/strong>.<\/td><td>Keep IP blocking in one place, preferably Wordfence.<\/td><\/tr><tr><td><strong>Rate limiting<\/strong><\/td><td><strong>ON<\/strong>.<\/td><td>Equivalent controls: <strong>OFF<\/strong>.<\/td><td>Keep traffic throttling with the primary firewall.<\/td><\/tr><tr><td><strong>404 probing<\/strong><\/td><td>WAF \/ Rate Limiting: <strong>Primary defence<\/strong>.<\/td><td>Smart 404 Blocking: <strong>Optional, Premium<\/strong>.<\/td><td>Use Wordfence by default. Add AIOS only if needed.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Logging and monitoring<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>404 logging<\/strong><\/td><td>Live Traffic: <strong>Security Only<\/strong>.<\/td><td>No duplicate required.<\/td><td>Avoid logging every visit. Security Only reduces unnecessary database writes.<\/td><\/tr><tr><td><strong>Security traffic logging<\/strong><\/td><td>Live Traffic: <strong>Security Only<\/strong>.<\/td><td>Audit Log: <strong>ON<\/strong>.<\/td><td>These serve different purposes and can coexist. Wordfence records attack activity. AIOS records WordPress security and administrative events.<\/td><\/tr><tr><td><strong>File change monitoring<\/strong><\/td><td>File scanning: <strong>Primary<\/strong>.<\/td><td>File Change Detection: <strong>Optional<\/strong>.<\/td><td>Wordfence remains the main file-integrity tool.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Additional hardening and optional controls<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Security feature<\/th><th>Wordfence<\/th><th>AIOS<\/th><th>Recommended approach<\/th><\/tr><\/thead><tbody><tr><td><strong>Rename login page<\/strong><\/td><td>Normal login URL is protected by Wordfence.<\/td><td>Rename Login Page: <strong>OFF normally<\/strong>.<\/td><td>Usually unnecessary and can complicate integrations and password resets.<\/td><\/tr><tr><td><strong>Login whitelist<\/strong><\/td><td>No need in normal use.<\/td><td>Login whitelist: <strong>OFF normally<\/strong>.<\/td><td>Avoid unless you have a fixed and reliable IP.<\/td><\/tr><tr><td><strong>Force logout<\/strong><\/td><td>No specific requirement.<\/td><td>Force User Logout: <strong>Optional<\/strong>.<\/td><td>Useful on shared machines or multi-user sites, but not essential for a small admin-only site.<\/td><\/tr><tr><td><strong>Manual registration approval<\/strong><\/td><td>No specific requirement.<\/td><td><strong>ON only if registration is enabled and approval makes sense<\/strong>.<\/td><td>Useful where public registration exists.<\/td><\/tr><tr><td><strong>Comment spam protection<\/strong><\/td><td>No primary role here.<\/td><td><strong>ON if comments are enabled<\/strong>.<\/td><td>Useful and does not conflict with Wordfence malware protection.<\/td><\/tr><tr><td><strong>Image hotlink protection<\/strong><\/td><td>No primary role here.<\/td><td><strong>Optional<\/strong>.<\/td><td>Bandwidth protection rather than a major security control.<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Why this configuration works<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Wordfence and AIOS can work very well together, but only when they are given clearly separated responsibilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wordfence should handle the main defensive tasks:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Web Application Firewall<\/li>\n\n\n\n<li>malware scanning<\/li>\n\n\n\n<li>file integrity checking<\/li>\n\n\n\n<li>brute-force protection<\/li>\n\n\n\n<li>rate limiting<\/li>\n\n\n\n<li>login security<\/li>\n\n\n\n<li>attack monitoring<\/li>\n\n\n\n<li>IP blocking<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">AIOS then complements Wordfence with additional WordPress and server hardening:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>file permission checks<\/li>\n\n\n\n<li>sensitive file protection<\/li>\n\n\n\n<li>disabling PHP file editing<\/li>\n\n\n\n<li>directory listing protection<\/li>\n\n\n\n<li><code>debug.log<\/code> protection<\/li>\n\n\n\n<li>selected account security checks<\/li>\n\n\n\n<li>additional WordPress hardening<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The important point is that the two plugins should complement each other rather than compete with each other.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Avoid duplicate protection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Enabling the same protection in both plugins rarely makes the site twice as secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, it can result in:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>conflicting lockout rules<\/li>\n\n\n\n<li>duplicate CAPTCHA checks<\/li>\n\n\n\n<li>overlapping firewall rules<\/li>\n\n\n\n<li>unnecessary processing<\/li>\n\n\n\n<li>confusing logs<\/li>\n\n\n\n<li>difficulty identifying which plugin blocked a legitimate request<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Where both plugins offer the same feature, choose one plugin to handle it and disable the equivalent control in the other.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That also makes future troubleshooting much easier.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Some settings depend on the website<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The recommendations in the tables are a strong starting point for a normal WordPress business website, but some sites will need different settings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Take particular care with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>XML-RPC<\/strong> if the site uses Jetpack, mobile applications or remote publishing<\/li>\n\n\n\n<li><strong>REST API restrictions<\/strong> because many plugins and external services depend on the WordPress REST API<\/li>\n\n\n\n<li><strong>Application passwords<\/strong> if external systems connect to WordPress<\/li>\n\n\n\n<li><strong>Registration controls<\/strong> if visitors are allowed to create accounts<\/li>\n\n\n\n<li><strong>CAPTCHA and login protection<\/strong> if another service already protects the login page<\/li>\n\n\n\n<li><strong>Country blocking<\/strong> where legitimate visitors or administrators may connect from different countries<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Security settings should always reflect how the website is actually being used.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Security plugins are only one part of WordPress security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Wordfence and AIOS provide useful protection, but they cannot compensate for an abandoned plugin, weak passwords or an unmaintained WordPress installation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A secure WordPress site should also have:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>WordPress core kept up to date<\/li>\n\n\n\n<li>plugins and themes updated regularly<\/li>\n\n\n\n<li>unused plugins and themes removed<\/li>\n\n\n\n<li>abandoned software replaced<\/li>\n\n\n\n<li>strong, unique passwords<\/li>\n\n\n\n<li>two-factor authentication for administrator accounts<\/li>\n\n\n\n<li>regular off-site backups<\/li>\n\n\n\n<li>periodic review of administrator accounts<\/li>\n\n\n\n<li>security alerts that are actually monitored<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The objective is not to switch on every available security option.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is to create a <strong>simple, understandable security configuration that can be maintained and monitored over time<\/strong>.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-831b2db5 wp-block-group-is-layout-flex\">\n<h2 class=\"wp-block-heading\">Final check<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After configuring both plugins, test the website normally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>administrator login<\/li>\n\n\n\n<li>password reset<\/li>\n\n\n\n<li>contact forms<\/li>\n\n\n\n<li>search<\/li>\n\n\n\n<li>front-end forms<\/li>\n\n\n\n<li>REST-dependent functionality<\/li>\n\n\n\n<li>Jetpack or remote management if used<\/li>\n\n\n\n<li>scheduled jobs<\/li>\n\n\n\n<li>external integrations<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Then review both Wordfence and AIOS logs for unexpected blocks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A security configuration is only useful if it protects the site without preventing legitimate users and services from using it.<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Wordfence and All In One WP Security can work very well together, but there is a lot of overlap between them.<\/p>\n<p>Both plugins can protect logins, block malicious requests, restrict access, monitor activity and apply additional WordPress security controls. Simply enabling everything in both plugins is not a good strategy. It can create duplicate protection, conflicting rules, unnecessary processing and make it much harder to work out which plugin has blocked something when a problem occurs.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"footnotes":""},"categories":[7,6],"tags":[],"class_list":["post-17","post","type-post","status-publish","format-standard","hentry","category-malware","category-wordpress"],"_links":{"self":[{"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/posts\/17","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/comments?post=17"}],"version-history":[{"count":6,"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/posts\/17\/revisions"}],"predecessor-version":[{"id":41,"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/posts\/17\/revisions\/41"}],"wp:attachment":[{"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/media?parent=17"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/categories?post=17"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microupdate.co.uk\/articles\/wp-json\/wp\/v2\/tags?post=17"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}