Scanner says core files were modified? Open the diff. After wp2shell, that is often leftover access.

How to read it

Firewall & login

8G firewall rules

Security Ninja's free Filter Suspicious Queries feature uses the 8G Firewall ruleset by Jeff Starr. Background and links to setup docs.

Security Ninja includes a free request firewall based on the 8G Firewall ruleset from Perishable Press (Jeff Starr). In the plugin this appears as Filter Suspicious Queries on Security Ninja → Firewall → Settings.

What you get in the plugin

The 8G rules block many common attack patterns in:

  • Request URI
  • Query string
  • User agent
  • Referrer

Security Ninja adapts the rules for typical WordPress paths and plugins. You enable or disable the feature with one toggle. No Pro license is required.

For step-by-step setup and what runs by default (including hostname checks), see Filter Suspicious Queries.

Customizing rules

Developers can extend or disable individual filter lists:

Pro vs free

The 8G layer is the free firewall. Pro adds Cloud Firewall (600M+ known bad IPs), country blocking, login protection, 2FA, and related controls. See How to use the firewall and the Cloud Firewall overview.

Credit

Firewall rules are based on 8G Firewall by Jeff Starr: https://perishablepress.com/8g-firewall/

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image