WordPress

Installing Wordfence and Implementing Two-Factor Authentication

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (10 sections)

Wordfence is one of the most widely used WordPress security plugins. Its free version adds a firewall inside WordPress, a malware and file-change scanner, brute-force protection and two-factor authentication (2FA) for your logins. This guide shows how to install it, set up each part without slowing your site, turn on 2FA for every administrator, and get back in if something locks you out.

Key takeaways

Install Wordfence Security from Plugins › Add New Plugin, register the free licence in its setup, and run Optimize the Wordfence Firewall, choosing the PHP-FPM option that writes .user.ini, not a php_value line in .htaccess. Then open Wordfence › Login Security, scan the QR code with an authenticator app, save the recovery codes and click Activate, and require 2FA for administrators. Use Wordfence as your only security plugin; on Domain India cPanel hosting a server-side firewall and malware cleanup already run underneath it.

1. What Wordfence does, free and paid

FeatureFreePremium (paid)
Web application firewall inside WordPressYes; new firewall rules arrive about 30 days after paid usersRules in real time
Malware and file-change scannerYesYes, with signatures in real time
Brute-force protection and login limitsYesYes
Two-factor authenticationYesYes
Real-time IP blocklistNoYes
Choose the time of scheduled scansNoYes

The free version is enough for most small business sites. Don't install a second security plugin alongside it: two firewalls or two login limiters often conflict, lock out real users or slow every page. Our guide to WordPress security plugins compares Wordfence with the alternatives.

2. Install Wordfence

  1. Back up first.
    Take a copy of your site before adding any security plugin. On Domain India cPanel and DirectAdmin hosting you can also restore from JetBackup; see backup and restore with JetBackup.
  2. Add the plugin.
    In WordPress, go to Plugins › Add New Plugin, search for Wordfence Security, check that the author is Wordfence, then click Install Now and Activate.
  3. Complete the setup.
    Wordfence asks for an email address for security alerts and offers a licence. Choose the free licence, register it with your email, and paste the key in when asked.
  4. Update WordPress, themes and plugins.
    Wordfence's first scan flags anything out of date; clearing those updates does more for security than any setting.

3. Optimise the firewall

Out of the box, the Wordfence firewall runs only when WordPress loads. Extended protection makes it run before any PHP file on your site, including vulnerable plugin files that attackers call directly.

  1. Open the firewall.
    Go to Wordfence › Firewall and click Optimize the Wordfence Firewall (on some versions it's under Manage Firewall).
  2. Pick the server configuration.
    Wordfence suggests one. On Domain India shared hosting, PHP runs through PHP-FPM, not as an Apache module, so choose the PHP-FPM option that uses a .user.ini file.
  3. Download the backup
    of your .htaccess and .user.ini files when Wordfence offers it, then continue.
  4. Wait a few minutes.
    PHP re-reads .user.ini only every few minutes, so Wordfence may show the change as pending at first. Reload the Firewall page after about five minutes.
If the site shows a 500 error after this step

Our servers don't run PHP as an Apache module, so a php_value or php_flag line in .htaccess gives a 500 Internal Server Error. If Wordfence added one, open .htaccess in your control panel's File Manager, delete the php_value auto_prepend_file line inside the Wordfence WAF section, save, and run the optimisation again with the PHP-FPM option.

New firewalls start in Learning Mode for about a week, so Wordfence can learn your site's normal traffic before it blocks anything. Leave it there, then check that Protection Level shows Extended Protection and the status is Enabled and Protecting.

4. Brute-force protection

Most login attacks are bots guessing passwords. In Wordfence › All Options › Brute Force Protection:

  • Lock out after a small number of failed logins, such as 5, and set a lockout period of a few hours.
  • Immediately lock out invalid usernames, so bots trying admin are blocked at once. Don't use admin as a real username.
  • Prevent the use of passwords leaked in data breaches for administrators.
  • Don't let WordPress reveal valid usernames in its login error messages.

If you lock yourself out, Wordfence's block page offers to email an unlock link to the administrator address.

5. Scans

Go to Wordfence › Scan and click Start New Scan once after installing. The free version then runs scheduled scans automatically; choosing the time is a Premium feature.

  • Keep the Standard scan. High Sensitivity finds more but raises false alarms and uses more server time.
  • On shared hosting, turn on Use low resource scanning under All Options › Scan Options if scans make your site slow. A full scan counts towards your account's CPU and memory limits like any other PHP work; see understanding hosting resource limits.
  • Read each result before acting. "Modified core file" and "unknown file in WordPress core" deserve a close look; an out-of-date plugin just needs updating.

6. Set up two-factor authentication

With 2FA, a stolen password is no longer enough to log in. You need a free authenticator app on your phone, such as Google Authenticator, Microsoft Authenticator or Authy; see popular 2FA apps.

  1. Open Login Security.
    In WordPress, go to Wordfence › Login Security, on the Two-Factor Authentication tab.
  2. Scan the QR code
    with your authenticator app, or type in the key shown beside it.
  3. Save the recovery codes.
    Click Download and keep the file somewhere safe, away from the website. Each code lets you in once if you lose your phone.
  4. Enter the 6-digit code
    from the app and click Activate.
  5. Test it.
    In a private browser window, log out and back in with your password and a fresh code before you close your current session.

Then open the Settings tab of Login Security:

  • Require 2FA for the Administrator role at least, and for editors and shop managers too if they can publish or see orders.
  • Give each person their own account; 2FA is per user, so a shared login can't be protected properly.
  • Leave XML-RPC covered by 2FA, or disable XML-RPC authentication if you don't use the WordPress mobile app or Jetpack.
  • Optionally turn on reCAPTCHA for the login page to cut bot traffic further.

This protects your WordPress logins. Your Domain India client area has its own two-factor authentication; turn that on too with enable two-factor authentication.

7. Alerts and Live Traffic

  • Email alerts: in All Options › Email Alert Preferences, keep alerts for an administrator login from a new device, a new administrator account, scan problems and plugin updates. Switch off noisy ones, such as every single blocked IP address, so you still read the important ones.
  • Live Traffic: under Wordfence › Tools › Live Traffic, the default logs security-related traffic only. Keep it that way on shared hosting; logging all traffic writes to your database on every visit.

Order confirmations and Wordfence alerts both leave through PHP mail(). On our cPanel servers, most SMTP mail plugins can't connect because the socket functions they need are disabled; see PHP sendmail settings.

8. If Wordfence locks you out

  • Blocked by the firewall or a lockout: use the unlock email link on the block page, or wait for the lockout to expire.
  • Lost your phone: log in with a recovery code, then set up 2FA again. Another administrator can also reset 2FA for your account.
  • Nothing else works: in your control panel's File Manager, rename wp-content/plugins/wordfence to wordfence-off. WordPress deactivates Wordfence, including its 2FA, and you can log in. If you used extended protection, also remove the auto_prepend_file line from .user.ini in your site's main folder. Rename the folder back afterwards and fix the setting.

9. What Domain India hosting already does

Measured on our servers on 20 September 2026, cPanel accounts get Imunify360 with a web application firewall and WordPress protection switched on, and automatic removal of malicious code from infected files, keeping the originals for 14 days. You aren't emailed when it removes something, so Wordfence's alerts fill that gap. CloudLinux CageFS isolates each account on cPanel and DirectAdmin, and JetBackup 5 takes a weekly backup every Sunday, keeping 5 copies you can restore yourself.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

Prices on the card are live and exclude 18% GST. If your site has already been hacked, follow the security checklist for hacked websites first: a plugin installed after a hack won't remove a backdoor that is already there.

Frequently asked questions

Is Wordfence free?

Yes. The free version includes the firewall, malware scanner, brute-force protection and two-factor authentication. Premium adds real-time firewall rules and malware signatures, a real-time IP blocklist and scan scheduling.

Why did my site show a 500 error after optimising the Wordfence firewall?

The optimisation probably added a php_value line to .htaccess. Domain India servers run PHP through PHP-FPM, where php_value in .htaccess causes a 500 error. Remove that line and run the optimisation again, choosing the PHP-FPM option that uses .user.ini.

How do I turn on two-factor authentication in Wordfence?

Go to Wordfence › Login Security, scan the QR code with an authenticator app, download the recovery codes, enter the 6-digit code and click Activate. Then require 2FA for administrators on the Settings tab.

What if I lose the phone with my authenticator app?

Log in with one of the recovery codes you downloaded, then set up 2FA again on your new phone. If you have no codes, another administrator can reset your 2FA, or you can rename the wordfence plugin folder in File Manager to deactivate it.

Can I use Wordfence with another security plugin?

It is better not to. Two plugins that both run a firewall, login limits or malware scans often conflict and slow your site. Use Wordfence alone, plus tools that do a different job, such as backups or anti-spam.

Does Wordfence slow down WordPress?

A single, well-configured Wordfence install has a small effect on most sites. Full scans use the most resources; on shared hosting, keep the Standard scan, enable low resource scanning if needed, and keep Live Traffic on security-related traffic only.

Ready to lock down your site? Install Wordfence, turn on 2FA for every administrator today, and read the WordPress hardening guide for the next steps. Need help with your hosting account? Open a support ticket or use our 24/7 live chat.

Host WordPress with server-side protection built in

A web application firewall, automatic malware cleanup, account isolation and weekly backups on every cPanel plan.

See cPanel plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app