Hardening vs a Firewall

People ask whether the Hardening module replaces Wordfence, Sucuri, or one of the other WordPress security plugins. It doesn't, and it isn't trying to. The two approaches answer different questions.

A firewall plugin is a guard. It stands at the doors your site has and watches who walks through: a web application firewall filtering requests against known attack patterns, a malware scanner checking your files for changes, integrity monitoring, IP blocklists, alerts. It's a detection system, and it needs constant feeding, because yesterday's attack patterns don't match today's.

Torii's hardening is demolition. Instead of watching the doors, it removes them. WordPress ships with every feature enabled so any conceivable site can work, and a membership site doesn't want most of them. Public feeds that syndicate your paid content. A REST endpoint that lists your member usernames. An XML-RPC service that exists to serve blogging tools from 2005. Hardening turns those off. There's nothing to detect afterwards, because there's nothing there.

Why a membership site needs both

A generic firewall can't make membership-specific judgments. It doesn't know that:

  • Your RSS feed is a paywall bypass, because feeds hand your content to anyone who asks, logged in or not.
  • /wp/v2/users is a privacy leak, because on your site that endpoint enumerates your paying members.
  • Comments are pure attack surface, because your community lives elsewhere.

A WAF protecting "a WordPress site" protects the feeds and the user listings along with everything else. Hardening starts from what a membership site actually is and removes what it doesn't need. That opinion is the product.

Running them together

Nothing conflicts. Demolish first, then guard what remains, and the guard has less to watch. One practical note: Wordfence also rate-limits logins, and so does the Hardening module's limit login attempts toggle. Running both isn't harmful, but you'll get two different lockout messages and two places to configure thresholds. Pick one limiter, disable the other, and keep the story simple for the day a member emails you saying they're locked out.

What hardening doesn't do, ever: scan files, clean malware, or recover a hacked site. If you're recovering from an incident, that's the firewall company's job. If you're making sure there's less to hack tomorrow, that's this module.