BBQ Firewall – Fast & Powerful Firewall Security
🔥 Install, activate, and done! 🔥 Powerful protection from WP’s fastest firewall plugin. BBQ Firewall is a lightweight, blazing-fast firewall plugin that protects your site against a wide range of threats. BBQ checks all incoming traffic and quietly blocks bad requests containing nasty stuff like eval(, base64_, and excessively long request-strings. This is a simple yet solid solution for sites that are unable to use a strong Apache/.htaccess firewall. 🔥 Adds a strong firewall to ANY WordPress site 🔥 Works with all WordPress plugins and themes Powerful Protection BBQ protects your site against many threats: SQL injection attacks Executable file uploads Directory traversal attacks Unsafe character requests Excessively long requests PHP remote/file execution XSS, XXE, and related attacks Protects against bad bots Protects against bad referrers Protects against bad POST content Protects against many other bad requests 🔥 Works great with Blackhole for Bad Bots and Banhammer Awesome Features BBQ provides all the best firewall features: Rated 5 stars at WordPress.org 100% plug-&-play, zero configuration 100% focused on security and performance Blocks a wide range of malicious URL requests Fastest Web Application Firewall (WAF) for WordPress Based on the 7G/8G Firewall Scans all incoming traffic and blocks bad requests Scans all types of requests: GET, POST, PUT, DELETE, etc. Protects against known bad bots and referrers Works silently behind the scenes to protect your site Hassle-free security plugin that’s easy to use Thoroughly tested, error-free performance Extremely low rate of false positives Compatible with other security plugins Regularly updated and “future proof” Firewall < 10 kilobytes in size Lightweight, fast and flexible 🔥 For advanced protection and features, check out BBQ Pro » Exclusive Pro Features Customize firewall via plugin settings Easily add or remove firewall patterns Easily add Jeff Starr’s AI Block List Send Email Alerts for blocked requests Quickly enable/disable firewall rules Disable firewall for logged-in users Block excessively long URI requests Protect against XML-RPC exploits Block any individual IP address Block entire ranges of IP addresses Protect against user-ID phishing Redirect all blocked requests Display a custom “blocked” message Set your own response status code Complete inline documentation Statistics for blocked requests Tools to reset options and patterns Import and Export firewall patterns One-click pattern testing Whitelist IP addresses ..plus everything the free version can do and more. 🔥 Learn more and get BBQ Pro » Privacy This plugin does not collect or store any user data. It does not set any cookies, and it does not connect to any third-party locations. Thus, this plugin does not affect user privacy in any way. BBQ Firewall is developed and maintained by Jeff Starr, 15-year WordPress developer and book author. 🔥 BBQ = Block Bad Queries Support development I develop and maintain this free plugin with love for the WordPress community. To show support, you can make a donation or purchase one of my books: The Tao of WordPress Digging into WordPress .htaccess made easy WordPress Themes In Depth Wizard’s SQL Recipes for WordPress And/or purchase one of my premium WordPress plugins: BBQ Pro – Blazing fast WordPress firewall Blackhole Pro – Automatically block bad bots Banhammer Pro – Monitor traffic and ban the bad guys GA Google Analytics Pro – Connect WordPress to Google Analytics Head Meta Pro – Ultimate Meta Tags for WordPress REST Pro Tools – Awesome tools for managing the WP REST API Simple Ajax Chat Pro – Unlimited chat rooms USP Pro – Unlimited front-end forms Links, tweets and likes also appreciated. Thank you! 🙂
Top keywords
- firewall16×2.79%
- wordpress14×2.44%
- bad11×1.92%
- pro11×1.92%
- requests11×1.92%
- against9×1.57%
- bbq9×1.57%
- protects7×1.22%
- block6×1.05%
- protects against5×0.87%
- bad bots4×0.70%
- blocked4×0.70%
Block Comment Spam Bots
Professional spammers use programs to automate their spamming. The ‘Block Comment Spam Bots’ (BCSB) plugin efficiently blocks their process. No more comment spam! As no legitimate user will use the professional spammer’s automated process which relies on cURL and WGET commands, real users will never notice the BCSB plugin at work. There are no CAPTCHAS for your visitors to interact with. No silly questions. Just the comment form as designed in any theme. On the admin side, there are no blacklists, special keys (like Askimet), overloaded spam queues, or overworked databases that store spam comments until you manually delete them. Install the plugin and that’s it. Invisible, to you and your visitors. The only change you will notice is in your admin area. The list of comments now has a green check next to them. That way you know that comment was made on your website by a real person and was not bypassed by hacking spammers connecting directly to your server. All that remains is comments made by real people, and while real people can spam, it takes them time and effort. The amount of spam from real people is a lot more manageable than the tsunami from automated spammers, saving you time to concentrate on the important things in life, like your readers, and making connections. We’ve tested it on multiple websites and it wipes out automated spam completely. If it doesn’t on your site, please let us know. ** Geeky Stuff ** …in case you are interested in how it works… tl;dr – This provides a total and easy solution to comment spam from spam bots. Comments are processed by the WordPress wp-post-comments.php file. Automated spammers (‘spam bots’) can provide (‘post’) data directly to that page, bypassing any comment processing, by using CURL/WGET commands. Bypassing the comment form by posting directly (via CURL or WGET commands), is quite easy. Just send the post ID number, and the bot’s fake name and email, and the spammy content. Boom! Comment spam is on your site! The result is comment spam – and that is not always caught by other comment spam checkers. Even if it is caught by programs such as Akismet, processing that spam takes some server resources, including writing to the database. This plugin uses several techniques to ‘sense’ a spambot. There are hidden fields that are changed after a delay. There is a delay in displaying the submit button. And it blocks direct access to the WordPress post/processing functions. The techniques, also used in our standalone “FormSpemmerTrap” (FST) program, and our other anti-spam plugins (like FormSpammerTrap for Comments), are very effective. They use a bit of JavaScript to block spambots – since automated processes via CURL/WGET/etc cannot process JS code. It’s simple: you install this plugin, activate it, and bot comments will stop. Immediately. And it doesn’t add any visual impediments to your comments. No reCaptcha things (which many see as a pain). No silly questions (‘what is 2+8’) on the form. Your comment form does not change. Regular users will not notice a difference. But you will. No more spam comments for you! This is the best solution to block comment spam. We’ve tested it on a site that had 20-40 spam comments a day. With this plugin enabled, the spam comment stopped. Immediately. And there have been none since installing this plugin. ** Not one. Zero.** The Admin, Comments list page is modified to show a column with a green checkmark icon if the comment was entered by a real person and not a bot. This is an assurance that the comment was not entered via an automated CURL/WGET to the wp-comments-post.php file. A comment that is on the list that does not show the checkmark was done by a bot. But you won’t see those blocked comments with this plugin enabled. They never get into your database. You can hover over the checkmark icon to see the GUID value indicating a person entered the comment. The plugins ‘Settings’ screen has no settings. You don’t even need to look at the Settings screen. If you do, you’ll see information about the plugin. And there is a CURL command you can use to test the effectiveness of blocking (or not blocking) direct access to the wp-comments-post.php file. The plugin also adds the hidden GUID field to the comment form after a delay to help block bots that are using the comment form to submit. If the hidden field is not submitted then a bot tried to bypass the comment form. And a short delay happens before the comment submit button is displayed – another bot protection.